From: Stefan Metzmacher Date: Mon, 15 Feb 2016 08:10:54 +0000 (+0100) Subject: docs-xml/smbdotconf: add "password hash gpg key ids" option X-Git-Tag: tdb-1.3.10~194 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=f28d0038c857368f9b30449b5a091af6aeebbff4;p=thirdparty%2Fsamba.git docs-xml/smbdotconf: add "password hash gpg key ids" option Signed-off-by: Stefan Metzmacher Reviewed-by: Alexander Bokovoy --- diff --git a/docs-xml/smbdotconf/security/passwordhashgpgkeyids.xml b/docs-xml/smbdotconf/security/passwordhashgpgkeyids.xml new file mode 100644 index 00000000000..e53cdbe3398 --- /dev/null +++ b/docs-xml/smbdotconf/security/passwordhashgpgkeyids.xml @@ -0,0 +1,45 @@ + + + If samba is running as an + active directory domain controller, it is possible to store the + cleartext password of accounts in a PGP/OpenGPG encrypted form. + + You can specify one or more recipients by key id or user id. + Note that 32bit key ids are not allowed, specify at least 64bit. + + The value is stored as 'Primary:SambaGPG' in the + supplementalCredentials attribute. + + As password changes can occur on any domain controller, + you should configure this on each of them. Note that this feature is currently + available only on Samba domain controllers. + + This option is only available if samba + was compiled with gpgme support. + + You may need to export the GNUPGHOME + environment variable before starting samba. + It is strongly recommended to only store the public key in this + location. The private key is not used for encryption and should be + only stored where decryption is required. + + Being able to restore the cleartext password helps, when they need to be imported + into other authentication systems later (see samba-tool user getpassword) + or you want to keep the passwords in sync with another system, e.g. an OpenLDAP server + (see samba-tool user syncpasswords). + + While this option needs to be configured on all domain controllers, the + samba-tool user syncpasswords command should + run on a single domain controller only (typically the PDC-emulator). + + +unix password sync + + +4952E40301FAB41A +selftest@samba.example.com +selftest@samba.example.com, 4952E40301FAB41A +