From 87394c3d87a8a5816baa78fb0178d52933835127 Mon Sep 17 00:00:00 2001 From: Hosted Weblate Date: Sun, 2 Aug 2026 07:18:09 +0000 Subject: [PATCH] po: update translations (Georgian) currently translated at 37.5% (1061 of 2824 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ka/ po: update translations (Georgian) currently translated at 15.5% (114 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/ka/ po: update translations (Georgian) currently translated at 27.6% (782 of 2824 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ka/ po: update translations (Georgian) currently translated at 27.6% (782 of 2824 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ka/ po: update translations (Georgian) currently translated at 27.6% (782 of 2824 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ka/ po: update translations (Georgian) currently translated at 27.6% (782 of 2824 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ka/ po: update translations (Georgian) currently translated at 27.6% (782 of 2824 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ka/ po: update translations (Georgian) currently translated at 27.6% (782 of 2824 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ka/ po: update translations (Georgian) currently translated at 26.6% (753 of 2824 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ka/ po: update translations (Chinese (Traditional) (zh_TW)) currently translated at 100.0% (2799 of 2799 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/zh_TW/ po: update translations (Chinese (Traditional) (zh_TW)) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/zh_TW/ po: update translations (Chinese (Traditional) (zh_TW)) currently translated at 0.8% (25 of 2799 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/zh_TW/ po: update translations (Chinese (Traditional) (zh_TW)) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/zh_TW/ po: update translations (French) currently translated at 55.9% (1589 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/fr/ po: update translations (Georgian) currently translated at 15.2% (112 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/ka/ po: update translations (Georgian) currently translated at 25.4% (720 of 2824 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ka/ po: update translations (Georgian) currently translated at 1.8% (53 of 2824 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ka/ po: update translations (Georgian) currently translated at 14.0% (103 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/ka/ po: update translations (Georgian) currently translated at 0.6% (17 of 2824 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ka/ po: update translations (Korean) currently translated at 66.9% (1890 of 2821 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ko/ po: update translations (Portuguese (Brazil)) currently translated at 32.2% (237 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/pt_BR/ po: update translations (Portuguese (Brazil)) currently translated at 0.8% (25 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/pt_BR/ po: update translations (Spanish) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/es/ po: update translations (Portuguese (Brazil)) currently translated at 17.5% (129 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/pt_BR/ po: update translations (Portuguese (Brazil)) currently translated at 0.5% (16 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/pt_BR/ po: update translations (Spanish) currently translated at 99.8% (734 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/es/ po: update translations (Korean) currently translated at 66.2% (1869 of 2821 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ko/ po: update translations (Korean) currently translated at 66.2% (1869 of 2821 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ko/ po: update translations (Korean) currently translated at 66.2% (1869 of 2821 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ko/ po: update translations (Korean) currently translated at 66.2% (1869 of 2821 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ko/ po: update translations (Korean) currently translated at 66.2% (1869 of 2821 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ko/ po: update translations (French) currently translated at 55.9% (1589 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/fr/ po: update translations (French) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/fr/ po: update translations (French) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/fr/ po: update translations (French) currently translated at 46.2% (1313 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/fr/ po: update translations (Spanish) currently translated at 100.0% (2838 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/es/ po: update translations (Korean) currently translated at 66.1% (1865 of 2821 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ko/ po: update translations (Spanish) currently translated at 100.0% (735 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/es/ po: update translations (Romanian) currently translated at 0.2% (6 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/ro/ po: update translations (Portuguese) currently translated at 100.0% (2838 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/pt/ Added translation using Weblate (Romanian) Added translation using Weblate (Romanian) po: update translations (Finnish) currently translated at 3.4% (98 of 2838 strings) Translation: SSSD/sssd-manpage Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-manpage-master/fi/ po: update translations (Indonesian) currently translated at 7.6% (56 of 735 strings) Translation: SSSD/sssd Translate-URL: https://translate.fedoraproject.org/projects/sssd/sssd-master/id/ --- po/LINGUAS | 1 + po/es.po | 12 +- po/fr.po | 37 +- po/id.po | 11 +- po/ka.po | 28 +- po/pt_BR.po | 468 +- po/ro.po | 3242 ++++++++ po/zh_TW.po | 1408 ++-- src/man/po/es.po | 39 +- src/man/po/fi.po | 53 +- src/man/po/fr.po | 1337 ++- src/man/po/ka.po | 2093 ++--- src/man/po/ko.po | 307 +- src/man/po/pt.po | 8 +- src/man/po/pt_BR.po | 43 +- src/man/po/ro.po | 18798 ++++++++++++++++++++++++++++++++++++++++++ src/man/po/zh_TW.po | 6508 ++++++++++----- 17 files changed, 30334 insertions(+), 4059 deletions(-) create mode 100644 po/ro.po create mode 100644 src/man/po/ro.po diff --git a/po/LINGUAS b/po/LINGUAS index 724bb868bf4..ef829f339a7 100644 --- a/po/LINGUAS +++ b/po/LINGUAS @@ -27,3 +27,4 @@ ko ka lv br +ro diff --git a/po/es.po b/po/es.po index be4e08071d7..fea69e3c2ed 100644 --- a/po/es.po +++ b/po/es.po @@ -18,14 +18,14 @@ # Pavel Brezina , 2025, 2026. # "Fco. Javier F. Serrador" , 2025, 2026. # Weblate Translation Memory , 2025, 2026. +# Rafael Fontenelle , 2026. msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" "POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 16:39+0000\n" -"Last-Translator: Weblate Translation Memory \n" +"PO-Revision-Date: 2026-06-18 20:10+0000\n" +"Last-Translator: \"Fco. Javier F. Serrador\" \n" "Language-Team: Spanish \n" "Language: es\n" @@ -33,7 +33,7 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n != 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.6.1\n" #: src/config/SSSDConfig/sssdoptions.py:20 #: src/config/SSSDConfig/sssdoptions.py:21 @@ -182,7 +182,7 @@ msgstr "" #: src/config/SSSDConfig/sssdoptions.py:55 msgid "Tune passkey verification behavior" -msgstr "Ajustar la verificación del certificado" +msgstr "Ajustar el comportamiento de verificación de la clave de acceso" #: src/config/SSSDConfig/sssdoptions.py:58 msgid "Enumeration cache timeout length (seconds)" @@ -417,7 +417,7 @@ msgstr "" #: src/config/SSSDConfig/sssdoptions.py:113 msgid "Allow passkey device authentication." -msgstr "Permitir la autentificación del dispositivo con clave de acceso." +msgstr "Permitir la autenticación del dispositivo con clave de acceso." #: src/config/SSSDConfig/sssdoptions.py:114 msgid "How many seconds will pam_sss wait for passkey_child to finish" diff --git a/po/fr.po b/po/fr.po index 4f36b648661..ad6c4de2307 100644 --- a/po/fr.po +++ b/po/fr.po @@ -15,13 +15,14 @@ # Transtats , 2022, 2026. # grimst , 2023, 2026. # Léane GRASSER , 2024, 2025, 2026. +# Mattia Sasselli , 2026. msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" "POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 17:00+0000\n" -"Last-Translator: Jean-Baptiste Holcroft \n" +"PO-Revision-Date: 2026-06-08 07:01+0000\n" +"Last-Translator: Mattia Sasselli \n" "Language-Team: French \n" "Language: fr\n" @@ -29,7 +30,7 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n > 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.6.1\n" #: src/config/SSSDConfig/sssdoptions.py:20 #: src/config/SSSDConfig/sssdoptions.py:21 @@ -148,8 +149,8 @@ msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" -"Contrôle si le SSSD doit surveiller l'état de resolv.conf pour identifier " -"quand il doit mettre à jour son résolveur DNS interne." +"Contrôle si SSSD doit surveiller l'état de resolv.conf pour identifier quand " +"il doit mettre à jour son résolveur DNS interne." #: src/config/SSSDConfig/sssdoptions.py:50 msgid "" @@ -513,10 +514,10 @@ msgid "" "Matches user names as returned by NSS. I.e. after the possible space " "replacement, case changes, etc." msgstr "" -"Une liste d'utilisateurs, séparés par des virgules, dont l'enregistrement de " -"session devrait être activé. Correspond aux noms d'utilisateurs renvoyés par " -"le NSS. C'est-à-dire après le remplacement éventuel de l'espace, les " -"changements de casse, etc." +"Liste d'utilisateurs, séparés par des virgules, pour lesquels " +"l'enregistrement de session doit être activé. Les noms d'utilisateur doivent " +"correspondre à ceux renvoyés par NSS, c'est-à-dire après les éventuelles " +"modifications d'espaces, de casse, etc." #: src/config/SSSDConfig/sssdoptions.py:150 msgid "" @@ -524,10 +525,10 @@ msgid "" "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" -"Une liste de groupes séparés par des virgules, dont les membres doivent " -"avoir l'enregistrement de session activé. Correspond aux noms des groupes " -"renvoyés par le NSS, c-à-d après le remplacement éventuel de l'espace, les " -"changements de cas, etc." +"Liste de groupes, séparés par des virgules, dont les membres doivent avoir " +"l'enregistrement de session activé. Les noms de groupes doivent correspondre " +"à ceux renvoyés par NSS, c'est-à-dire après les éventuelles modifications " +"d'espaces, de casse, etc." #: src/config/SSSDConfig/sssdoptions.py:153 msgid "" @@ -820,11 +821,11 @@ msgid "" "this value determines the minimal length the first authentication factor " "(long term password) must have to be saved as SHA512 hash into the cache." msgstr "" -"Si l'authentification à 2 facteurs (2FA) est utilisée et que les " -"informations d'identification sont sauvegardées, cette valeur détermine la " -"longueur minimale à laquelle le premier facteur d'authentification (mot de " -"passe à long terme) doit être sauvegardé en tant que hachage SHA512 dans le " -"cache." +"Si l'authentification à deux facteurs (2FA) est utilisée et que les " +"informations d'identification doivent être enregistrées, cette valeur " +"détermine la longueur minimale que le premier facteur d'authentification " +"(mot de passe à long terme) doit avoir pour être enregistré sous forme de " +"hachage SHA512 dans le cache." #: src/config/SSSDConfig/sssdoptions.py:230 msgid "Local authentication methods policy " diff --git a/po/id.po b/po/id.po index 05dd4f0218b..ca9da4d77d1 100644 --- a/po/id.po +++ b/po/id.po @@ -3,13 +3,14 @@ # This file is distributed under the same license as the PACKAGE package. # # Translators: +# Glenn Mandagi , 2026. msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" "POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 16:47+0000\n" -"Last-Translator: Anonymous \n" +"PO-Revision-Date: 2026-05-08 05:45+0000\n" +"Last-Translator: Glenn Mandagi \n" "Language-Team: Indonesian \n" "Language: id\n" @@ -17,7 +18,7 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=1; plural=0;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 5.17.1\n" #: src/config/SSSDConfig/sssdoptions.py:20 #: src/config/SSSDConfig/sssdoptions.py:21 @@ -30,11 +31,11 @@ msgstr "Sertakan cap waktu di pencatatan debug" #: src/config/SSSDConfig/sssdoptions.py:23 msgid "Include microseconds in timestamps in debug logs" -msgstr "" +msgstr "Sertakan mikrosekon dalam timestamp di log debug." #: src/config/SSSDConfig/sssdoptions.py:24 msgid "Enable/disable debug backtrace" -msgstr "" +msgstr "Aktifkan/nonaktifkan debug backtrace" #: src/config/SSSDConfig/sssdoptions.py:25 msgid "Watchdog timeout before restarting service" diff --git a/po/ka.po b/po/ka.po index 21068ce2abf..f974e3078cd 100644 --- a/po/ka.po +++ b/po/ka.po @@ -8,7 +8,7 @@ msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" "POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 16:48+0000\n" +"PO-Revision-Date: 2026-08-02 07:17+0000\n" "Last-Translator: Weblate Translation Memory \n" "Language-Team: Georgian , 2015. #zanata # Nari Ivy , 2025, 2026. +# Rafael Fontenelle , 2026. msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" "POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 16:26+0000\n" -"Last-Translator: Nari Ivy \n" +"PO-Revision-Date: 2026-06-18 20:10+0000\n" +"Last-Translator: Rafael Fontenelle \n" "Language-Team: Portuguese (Brazil) \n" "Language: pt_BR\n" @@ -14,24 +15,24 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=(n != 1);\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.6.1\n" #: src/config/SSSDConfig/sssdoptions.py:20 #: src/config/SSSDConfig/sssdoptions.py:21 msgid "Set the verbosity of the debug logging" -msgstr "Definir a verbosidade do log de depuração" +msgstr "Define a verbosidade do log de depuração" #: src/config/SSSDConfig/sssdoptions.py:22 msgid "Include timestamps in debug logs" -msgstr "Incluir timestamps em logs de depuração" +msgstr "Inclui timestamps em logs de depuração" #: src/config/SSSDConfig/sssdoptions.py:23 msgid "Include microseconds in timestamps in debug logs" -msgstr "Incluir microssegundos em timestamps em logs de depuração" +msgstr "Inclui microssegundos em timestamps em logs de depuração" #: src/config/SSSDConfig/sssdoptions.py:24 msgid "Enable/disable debug backtrace" -msgstr "Ativar/desativar rastreamento de depuração" +msgstr "Ativa/desativa rastreamento de depuração" #: src/config/SSSDConfig/sssdoptions.py:25 msgid "Watchdog timeout before restarting service" @@ -48,15 +49,16 @@ msgstr "" #: src/config/SSSDConfig/sssdoptions.py:28 msgid "Idle time before automatic disconnection of a client" -msgstr "" +msgstr "Tempo de inatividade antes da desconexão automática de um cliente" #: src/config/SSSDConfig/sssdoptions.py:29 msgid "Idle time before automatic shutdown of the responder" -msgstr "" +msgstr "Tempo de inatividade antes do desligamento automático do respondedor" #: src/config/SSSDConfig/sssdoptions.py:30 msgid "Always query all the caches before querying the Data Providers" msgstr "" +"Sempre consulta todos os caches antes de consultar os Provedores de Dados" #: src/config/SSSDConfig/sssdoptions.py:31 msgid "" @@ -65,6 +67,10 @@ msgid "" "is in seconds and calculated by the following: offline_timeout + " "random_offset." msgstr "" +"Quando o SSSD entra em modo offline, o tempo limite antes de tentar voltar a " +"ficar online aumenta com base no tempo em que esteve desconectado. Esse " +"valor é em segundos e calculado da seguinte forma: tempolimite_offline + " +"deslocamento_aleatório." #: src/config/SSSDConfig/sssdoptions.py:36 msgid "SSSD Services to start" @@ -72,55 +78,62 @@ msgstr "Serviços SSSD para iniciar" #: src/config/SSSDConfig/sssdoptions.py:37 msgid "SSSD Domains to start" -msgstr "" +msgstr "Domínios SSSD para iniciar" #: src/config/SSSDConfig/sssdoptions.py:38 msgid "Regex to parse username and domain" -msgstr "" +msgstr "Expressão regular para analisar nome de usuário e domínio" #: src/config/SSSDConfig/sssdoptions.py:39 msgid "Printf-compatible format for displaying fully-qualified names" msgstr "" +"Formato compatível com printf para exibir nomes completamente qualificados" #: src/config/SSSDConfig/sssdoptions.py:40 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." msgstr "" +"Diretório no sistema de arquivos no qual SSSD deve armazenar arquivos cache " +"de reprodução de Kerberos." #: src/config/SSSDConfig/sssdoptions.py:41 msgid "Domain to add to names without a domain component." -msgstr "" +msgstr "Domínio para adicionar a nomes sem um componente de domínio." #: src/config/SSSDConfig/sssdoptions.py:42 msgid "The user to drop privileges to" -msgstr "" +msgstr "O usuário para retirar privilégios" #: src/config/SSSDConfig/sssdoptions.py:43 msgid "Tune certificate verification" -msgstr "" +msgstr "Ajusta a verificação de certificado" #: src/config/SSSDConfig/sssdoptions.py:44 msgid "All spaces in group or user names will be replaced with this character" msgstr "" +"Todos espaços em nomes de usuário e de grupo serão substituídos por este " +"caractere" #: src/config/SSSDConfig/sssdoptions.py:45 msgid "Tune sssd to honor or ignore netlink state changes" -msgstr "" +msgstr "Ajusta sssd para honrar ou ignorar alterações de estado de netlink" #: src/config/SSSDConfig/sssdoptions.py:46 msgid "Enable or disable the implicit files domain" -msgstr "" +msgstr "Habilita ou desabilita o domínio implícito de arquivos" #: src/config/SSSDConfig/sssdoptions.py:47 msgid "A specific order of the domains to be looked up" -msgstr "" +msgstr "Uma ordem específica de domínios para procurar" #: src/config/SSSDConfig/sssdoptions.py:48 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" +"Controla se SSSD deve monitorar o estado de resolv.conf para identificar " +"quando ele precisa atualizar seu resolvedor interno de DNS." #: src/config/SSSDConfig/sssdoptions.py:50 msgid "" @@ -129,113 +142,135 @@ msgid "" "this, and will fall back to polling resolv.conf every five seconds if " "inotify cannot be used." msgstr "" +"SSSD monitora o estado de resolv.conf para identificar quando ele precisa " +"atualizar seu resolvedor interno de DNS. Por padrão, tentaremos usar inotify " +"para isso e, alternativamente, pode recorrer a consultar resolv.conf a cada " +"cinco segundos se inotify não puder ser usado." #: src/config/SSSDConfig/sssdoptions.py:53 msgid "Run PAC responder automatically for AD and IPA provider" -msgstr "" +msgstr "Executa respondedor PAC automaticamente para provedor de AD e IPA" #: src/config/SSSDConfig/sssdoptions.py:54 msgid "Enable or disable core dumps for all SSSD processes." msgstr "" +"Habilita ou desabilita despejos de núcleo para todos os processos de SSSD." #: src/config/SSSDConfig/sssdoptions.py:55 msgid "Tune passkey verification behavior" -msgstr "" +msgstr "Ajusta o comportamento da verificação da chave de acesso" #: src/config/SSSDConfig/sssdoptions.py:58 msgid "Enumeration cache timeout length (seconds)" -msgstr "" +msgstr "Tempo limite (em segundos) do cache de enumeração" #: src/config/SSSDConfig/sssdoptions.py:59 msgid "Entry cache background update timeout length (seconds)" msgstr "" +"Tempo limite (em segundos) da atualização em segundo plano do cacho de " +"entrada" #: src/config/SSSDConfig/sssdoptions.py:60 #: src/config/SSSDConfig/sssdoptions.py:125 msgid "Negative cache timeout length (seconds)" -msgstr "" +msgstr "Tempo limite (em segundos) do cache negativo" #: src/config/SSSDConfig/sssdoptions.py:61 msgid "Users that SSSD should explicitly ignore" -msgstr "" +msgstr "Usuários que SSSD deve explicitamente ignorar" #: src/config/SSSDConfig/sssdoptions.py:62 msgid "Groups that SSSD should explicitly ignore" -msgstr "" +msgstr "Grupos que SSSD deve explicitamente ignorar" #: src/config/SSSDConfig/sssdoptions.py:63 msgid "Should filtered users appear in groups" -msgstr "" +msgstr "Se usuários filtrados devem aparecer nos grupos" #: src/config/SSSDConfig/sssdoptions.py:64 msgid "The value of the password field the NSS provider should return" -msgstr "" +msgstr "O valor do campo de senha que o provedor NSS deve devolver" #: src/config/SSSDConfig/sssdoptions.py:65 msgid "Override homedir value from the identity provider with this value" -msgstr "" +msgstr "Substitui o valor de homedir do provedor de identidade com este valor" #: src/config/SSSDConfig/sssdoptions.py:66 msgid "" "Substitute empty homedir value from the identity provider with this value" msgstr "" +"Substitui um valor vazio de homedir do provedor de identidade com este valor" #: src/config/SSSDConfig/sssdoptions.py:67 msgid "Override shell value from the identity provider with this value" -msgstr "" +msgstr "Substitui o valor shell do provedor de identidade com este valor" #: src/config/SSSDConfig/sssdoptions.py:68 msgid "The list of shells users are allowed to log in with" -msgstr "" +msgstr "A lista de shells com os quais os usuários são permitidos se autenticar" #: src/config/SSSDConfig/sssdoptions.py:69 msgid "" "The list of shells that will be vetoed, and replaced with the fallback shell" msgstr "" +"A lista de shells que serão vetados e substituídos com este shell como " +"reserva" #: src/config/SSSDConfig/sssdoptions.py:70 msgid "" "If a shell stored in central directory is allowed but not available, use " "this fallback" msgstr "" +"Se um shell armazenado no diretório central é permitido, mas não está " +"disponível, usa este reserva" #: src/config/SSSDConfig/sssdoptions.py:71 msgid "Shell to use if the provider does not list one" -msgstr "" +msgstr "Shell para usar se o provedor não lista um" #: src/config/SSSDConfig/sssdoptions.py:72 msgid "How long will be in-memory cache records valid" -msgstr "" +msgstr "Por quanto tempo os registros de cacho na memória serão válidos" #: src/config/SSSDConfig/sssdoptions.py:74 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests" msgstr "" +"Tamanho (em megabytes) da tabela de dados alocada dentro do cache rápido em " +"memória para requisições de passwd" #: src/config/SSSDConfig/sssdoptions.py:76 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests" msgstr "" +"Tamanho (em megabytes) da tabela de dados alocada dentro do cache rápido em " +"memória para requisições de grupo" #: src/config/SSSDConfig/sssdoptions.py:78 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests" msgstr "" +"Tamanho (em megabytes) da tabela de dados alocada dentro do cache rápido em " +"memória para requisições de initgroups" #: src/config/SSSDConfig/sssdoptions.py:79 msgid "" "The value of this option will be used in the expansion of the " "override_homedir option if the template contains the format string %H." msgstr "" +"O valor desta opção será usada na expansão da opção override_homedir se o " +"modelo contiver a string de formato %H." #: src/config/SSSDConfig/sssdoptions.py:81 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "" +"Especifica o tempo em segundos pelo qual a lista de subdomínios será " +"considerada válida." #: src/config/SSSDConfig/sssdoptions.py:83 msgid "" @@ -243,173 +278,194 @@ msgid "" "if they are requested beyond a percentage of the entry_cache_timeout value " "for the domain." msgstr "" +"O cache de entrada pode ser definido para atualizar automaticamente entradas " +"em segundo plano se elas forem solicitadas além de uma porcentagem do valor " +"entry_cache_timeout para o domínio." #: src/config/SSSDConfig/sssdoptions.py:88 msgid "How long to allow cached logins between online logins (days)" -msgstr "" +msgstr "Por quanto tempo permitir logins em cache entre logins online (dias)" #: src/config/SSSDConfig/sssdoptions.py:89 msgid "How many failed logins attempts are allowed when offline" msgstr "" +"Quantas tentativas de login com falha são permitidas quando se está offline" #: src/config/SSSDConfig/sssdoptions.py:91 msgid "" "How long (minutes) to deny login after offline_failed_login_attempts has " "been reached" msgstr "" +"Por quantos minutos negar login após offline_failed_login_attempts ter sido " +"atingido" #: src/config/SSSDConfig/sssdoptions.py:92 msgid "What kind of messages are displayed to the user during authentication" -msgstr "" +msgstr "Que tipo de mensagens é exigido ao usuário durante a autenticação" #: src/config/SSSDConfig/sssdoptions.py:93 msgid "Filter PAM responses sent to the pam_sss" -msgstr "" +msgstr "Filtra as respostas PAM enviadas para pam_sss" #: src/config/SSSDConfig/sssdoptions.py:94 msgid "How many seconds to keep identity information cached for PAM requests" msgstr "" +"Por quantos segundos manter informações de identidade em cache para " +"requisições PAM" #: src/config/SSSDConfig/sssdoptions.py:95 msgid "How many days before password expiration a warning should be displayed" -msgstr "" +msgstr "Por quantos dias um aviso deve ser exibido antes de expirar a senha" #: src/config/SSSDConfig/sssdoptions.py:96 msgid "List of trusted uids or user's name" -msgstr "" +msgstr "Lista de uids ou nome do usuário confiados" #: src/config/SSSDConfig/sssdoptions.py:97 msgid "List of domains accessible even for untrusted users." -msgstr "" +msgstr "Lista de domínios acessíveis mesmo para usuário não confiados." #: src/config/SSSDConfig/sssdoptions.py:98 msgid "Message printed when user account is expired." -msgstr "" +msgstr "Mensagem exibida quando a conta do usuário expirou." #: src/config/SSSDConfig/sssdoptions.py:99 msgid "Message printed when user account is locked." -msgstr "" +msgstr "Mensagem exibida quando a conta do usuário está bloqueada." #: src/config/SSSDConfig/sssdoptions.py:100 msgid "Allow certificate based/Smartcard authentication." -msgstr "" +msgstr "Permite autenticação por cartão inteligente / com base em certificado." #: src/config/SSSDConfig/sssdoptions.py:101 msgid "Path to certificate database with PKCS#11 modules." -msgstr "" +msgstr "Caminho do banco de dados de certificado com módulos PKCS#11." #: src/config/SSSDConfig/sssdoptions.py:102 msgid "Tune certificate verification for PAM authentication." -msgstr "" +msgstr "Ajusta a verificação de certificado para autenticação PAM." #: src/config/SSSDConfig/sssdoptions.py:103 msgid "How many seconds will pam_sss wait for p11_child to finish" -msgstr "" +msgstr "Por quanto tempo pam_sss vai esperar até p11_child terminar" #: src/config/SSSDConfig/sssdoptions.py:104 msgid "Which PAM services are permitted to contact application domains" -msgstr "" +msgstr "Quais serviços PAM têm permissão para contatar domínios de aplicativos" #: src/config/SSSDConfig/sssdoptions.py:105 msgid "Allowed services for using smartcards" -msgstr "" +msgstr "Serviços permitidos a usar cartões inteligentes" #: src/config/SSSDConfig/sssdoptions.py:106 msgid "Additional timeout to wait for a card if requested" -msgstr "" +msgstr "Tempo limite adicional para esperar por um cartão se solicitado" #: src/config/SSSDConfig/sssdoptions.py:107 msgid "" "PKCS#11 URI to restrict the selection of devices for Smartcard authentication" msgstr "" +"URI PKCS#11 para restringir a seleção de dispositivos para autenticação por " +"cartão inteligente" #: src/config/SSSDConfig/sssdoptions.py:108 msgid "When shall the PAM responder force an initgroups request" -msgstr "" +msgstr "Quando o respondedor PAM deve forçar uma requisição de initgroups" #: src/config/SSSDConfig/sssdoptions.py:109 msgid "List of PAM services that are allowed to authenticate with GSSAPI." -msgstr "" +msgstr "Lista de serviços PAM que têm permissão para autenticar com GSSAPI." #: src/config/SSSDConfig/sssdoptions.py:110 msgid "Whether to match authenticated UPN with target user" -msgstr "" +msgstr "Se deve corresponder UPN não autenticado com usuário alvo" #: src/config/SSSDConfig/sssdoptions.py:111 msgid "" "List of pairs : that must be enforced " "for PAM access with GSSAPI authentication" msgstr "" +"Lista de pares : que deve ser " +"forçado para acesso PAM com autenticação GSSAPI" #: src/config/SSSDConfig/sssdoptions.py:113 msgid "Allow passkey device authentication." -msgstr "" +msgstr "Permite autenticação de dispositivo de chave de acesso." #: src/config/SSSDConfig/sssdoptions.py:114 msgid "How many seconds will pam_sss wait for passkey_child to finish" -msgstr "" +msgstr "Por quantos segundos pam_sss vai esperar passkey_child terminar" #: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable debugging in the libfido2 library" -msgstr "" +msgstr "Habilita depuração na biblioteca de libfido2" #: src/config/SSSDConfig/sssdoptions.py:116 msgid "Enable JSON protocol for authentication methods selection." -msgstr "" +msgstr "Habilita protocolo JSON para seleção de métodos de autenticação." #: src/config/SSSDConfig/sssdoptions.py:119 msgid "Whether to evaluate the time-based attributes in sudo rules" -msgstr "" +msgstr "Se deve avaliar os atributos baseados em tempo em regras do sudo" #: src/config/SSSDConfig/sssdoptions.py:120 msgid "If true, SSSD will switch back to lower-wins ordering logic" msgstr "" +"Se verdadeiro, SSSD voltará a usar a lógica de ordenação \"lower wins\"." #: src/config/SSSDConfig/sssdoptions.py:121 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." msgstr "" +"Número máximo de regras que podem ser atualizados de uma vez. Se esse número " +"for excedido, atualização total é realizada." #: src/config/SSSDConfig/sssdoptions.py:128 msgid "Whether to hash host names and addresses in the known_hosts file" msgstr "" +"Se deve gerar hashes de nomes de host e endereços no arquivo known_hosts" #: src/config/SSSDConfig/sssdoptions.py:129 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" msgstr "" +"Por quantos segundos manter um host no arquivo known_hosts após suas chaves " +"de host terem sido solicitadas" #: src/config/SSSDConfig/sssdoptions.py:131 msgid "Path to storage of trusted CA certificates" -msgstr "" +msgstr "Caminho para o armazenamento de certificados de AC confiáveis" #: src/config/SSSDConfig/sssdoptions.py:132 msgid "Allow to generate ssh-keys from certificates" -msgstr "" +msgstr "Permite gerar chaves ssh a partir de certificados" #: src/config/SSSDConfig/sssdoptions.py:133 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" msgstr "" +"Usa as seguintes regras de correspondência para filtrar os certificados para " +"geração de chave ssh" #: src/config/SSSDConfig/sssdoptions.py:137 msgid "List of UIDs or user names allowed to access the PAC responder" msgstr "" +"Lista de UIDs ou nomes de usuários permitidos a acessar o respondedor PAC" #: src/config/SSSDConfig/sssdoptions.py:138 msgid "How long the PAC data is considered valid" -msgstr "" +msgstr "Por quanto tempo os dados PAC são considerados válidos" #: src/config/SSSDConfig/sssdoptions.py:139 msgid "Validate the PAC" -msgstr "" +msgstr "Valida o PAC" #: src/config/SSSDConfig/sssdoptions.py:142 msgid "List of user attributes the InfoPipe is allowed to publish" -msgstr "" +msgstr "Lista de atributos de usuário que o InfoPipe é permitido publicar" #: src/config/SSSDConfig/sssdoptions.py:145 msgid "" @@ -417,6 +473,9 @@ msgid "" "- No users are recorded. some - Users/groups specified by users and groups " "options are recorded. all - All users are recorded." msgstr "" +"Uma das seguintes strings especifica o escopo da gravação da sessão: none - " +"Nenhum usuário é gravado. some - Usuários/grupos especificados pelas opções " +"users e groups são gravados. all - Todos os usuários são gravados." #: src/config/SSSDConfig/sssdoptions.py:148 msgid "" @@ -424,6 +483,10 @@ msgid "" "Matches user names as returned by NSS. I.e. after the possible space " "replacement, case changes, etc." msgstr "" +"Uma lista de usuários separados por vírgula que devem ter a gravação de " +"sessão ativada. Corresponde aos nomes de usuário retornados pelo NSS, ou " +"seja, após possíveis substituições de espaços, alterações de maiúsculas e " +"minúsculas, etc." #: src/config/SSSDConfig/sssdoptions.py:150 msgid "" @@ -431,90 +494,98 @@ msgid "" "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" +"Uma lista de grupos separados por vírgulas, cujos membros devem ter a " +"gravação de sessão ativada. Corresponde aos nomes dos grupos conforme " +"retornados pelo NSS, ou seja, após a possível substituição de espaços, " +"alterações de maiúsculas e minúsculas, etc." #: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" msgstr "" +"Uma lista de usuários separados por vírgula a serem excluídos da gravação, " +"somente quando scope=all" #: src/config/SSSDConfig/sssdoptions.py:154 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " msgstr "" +"Uma lista de grupos separados por vírgulas, cujos membros devem ser " +"excluídos da gravação somente quando scope=all. " #: src/config/SSSDConfig/sssdoptions.py:158 msgid "Identity provider" -msgstr "" +msgstr "Provedor de identidade" #: src/config/SSSDConfig/sssdoptions.py:159 msgid "Authentication provider" -msgstr "" +msgstr "Provedor de autenticação" #: src/config/SSSDConfig/sssdoptions.py:160 msgid "Access control provider" -msgstr "" +msgstr "Provedor de controle de acesso" #: src/config/SSSDConfig/sssdoptions.py:161 msgid "Password change provider" -msgstr "" +msgstr "Provedor de alteração de senha" #: src/config/SSSDConfig/sssdoptions.py:162 msgid "SUDO provider" -msgstr "" +msgstr "Provedor de SUDO" #: src/config/SSSDConfig/sssdoptions.py:163 msgid "Autofs provider" -msgstr "" +msgstr "Provedor de Autofs" #: src/config/SSSDConfig/sssdoptions.py:164 msgid "Host identity provider" -msgstr "" +msgstr "Provedor de identidade de host" #: src/config/SSSDConfig/sssdoptions.py:165 msgid "SELinux provider" -msgstr "" +msgstr "Provedor de SELinux" #: src/config/SSSDConfig/sssdoptions.py:166 msgid "Session management provider" -msgstr "" +msgstr "Provedor de gerenciamento de sessão" #: src/config/SSSDConfig/sssdoptions.py:167 msgid "Resolver provider" -msgstr "" +msgstr "Provedor de resolvedor" #: src/config/SSSDConfig/sssdoptions.py:170 msgid "Whether the domain is usable by the OS or by applications" -msgstr "" +msgstr "Se o domínio é usável pelo sistema operacional ou pelos aplicativos" #: src/config/SSSDConfig/sssdoptions.py:171 msgid "Enable or disable the domain" -msgstr "" +msgstr "Habilita ou desabilita o domínio" #: src/config/SSSDConfig/sssdoptions.py:172 msgid "Minimum user ID" -msgstr "" +msgstr "ID mínimo de usuário" #: src/config/SSSDConfig/sssdoptions.py:173 msgid "Maximum user ID" -msgstr "" +msgstr "ID máximo de usuário" #: src/config/SSSDConfig/sssdoptions.py:174 msgid "Enable enumerating all users/groups" -msgstr "" +msgstr "Habilita enumeração de todos os usuários/grupos" #: src/config/SSSDConfig/sssdoptions.py:175 msgid "Cache credentials for offline login" -msgstr "" +msgstr "Faz cache de credenciais para login offline" #: src/config/SSSDConfig/sssdoptions.py:176 msgid "Display users/groups in fully-qualified form" -msgstr "" +msgstr "Exibe usuários/grupos na forma completamente qualificada" #: src/config/SSSDConfig/sssdoptions.py:177 msgid "Don't include group members in group lookups" -msgstr "" +msgstr "Não inclui membros de grupo ao procurar grupos" #: src/config/SSSDConfig/sssdoptions.py:178 #: src/config/SSSDConfig/sssdoptions.py:190 @@ -525,34 +596,44 @@ msgstr "" #: src/config/SSSDConfig/sssdoptions.py:195 #: src/config/SSSDConfig/sssdoptions.py:196 msgid "Entry cache timeout length (seconds)" -msgstr "" +msgstr "Tempo limite (em segundos) de cache de entrada" #: src/config/SSSDConfig/sssdoptions.py:179 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" msgstr "" +"Restringe ou prefere uma família de endereço específica ao realizar " +"pesquisas de DNS" #: src/config/SSSDConfig/sssdoptions.py:180 msgid "How long to keep cached entries after last successful login (days)" msgstr "" +"Por quanto tempo manter entradas em cache após o último login bem-sucedido " +"(dias)" #: src/config/SSSDConfig/sssdoptions.py:181 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" msgstr "" +"Por quanto tempo SSSD deve falar com um único serviço DNS antes de tentar o " +"próximo servidor (milissegundos)" #: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long should keep trying to resolve single DNS query (seconds)" msgstr "" +"Por quanto tempo deve continuar tentando resolver uma única consulta DNS " +"(segundos)" #: src/config/SSSDConfig/sssdoptions.py:184 msgid "How long to wait for replies from DNS when resolving servers (seconds)" msgstr "" +"Por quanto tempo deve esperar por respostas do DNS ao resolver servidores " +"(segundos)" #: src/config/SSSDConfig/sssdoptions.py:185 msgid "The domain part of service discovery DNS query" -msgstr "" +msgstr "A parte do domínio da consulta DNS de descoberta de serviços" #: src/config/SSSDConfig/sssdoptions.py:186 msgid "" @@ -560,125 +641,143 @@ msgid "" "reconnect to the primary server after a successful connection to the backup " "server" msgstr "" +"Especifica o intervalo, em segundos, que SSSD espera antes de tentar " +"reconectar o servidor principal após uma conexão bem-sucedida ao servidor " +"backup" #: src/config/SSSDConfig/sssdoptions.py:188 msgid "Override GID value from the identity provider with this value" -msgstr "" +msgstr "Substitui o valor de GID do provedor de identidade com este valor" #: src/config/SSSDConfig/sssdoptions.py:189 msgid "Treat usernames as case sensitive" -msgstr "" +msgstr "Trata nomes de usuários diferenciando maiúsculo de minúsculo" #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" msgstr "" +"Com qual frequência entradas expiradas devem ser atualizadas em segundo plano" #: src/config/SSSDConfig/sssdoptions.py:198 msgid "Maximum period deviation when refreshing expired entries in background" msgstr "" +"Desvio máximo do período ao atualizar entradas expiradas em segundo plano" #: src/config/SSSDConfig/sssdoptions.py:199 msgid "Whether to automatically update the client's DNS entry" -msgstr "" +msgstr "Se deve atualizar automaticamente entrada de DNS do cliente" #: src/config/SSSDConfig/sssdoptions.py:200 msgid "" "Whether DNS update of A and AAAA record should be performed in one update or " "in two separate updates" msgstr "" +"Se atualização de DNS dos registros A e AAAA deve ser realizada em uma única " +"atualização ou em duas atualizações separadas" #: src/config/SSSDConfig/sssdoptions.py:202 msgid "The TTL to apply to the client's DNS entry after updating it" -msgstr "" +msgstr "O TTL para aplicar à entrada de DNS do cliente após atualizá-la" #: src/config/SSSDConfig/sssdoptions.py:203 msgid "The interface whose IP should be used for dynamic DNS updates" -msgstr "" +msgstr "A interface cujo IP deve ser usado para atualizações DNS dinâmicas" #: src/config/SSSDConfig/sssdoptions.py:204 msgid "The list of IP addresses that should be used for dynamic DNS updates" msgstr "" +"A lista de endereços IP que deve ser usada para atualizações DNS dinâmicas" #: src/config/SSSDConfig/sssdoptions.py:205 msgid "How often to periodically update the client's DNS entry" msgstr "" +"Com qual frequência atualizar periodicamente a entrada de DNS do cliente" #: src/config/SSSDConfig/sssdoptions.py:206 msgid "Maximum period deviation when updating the client's DNS entry" -msgstr "" +msgstr "Desvio máximo do período ao atualizar a entrada DNS do cliente" #: src/config/SSSDConfig/sssdoptions.py:207 msgid "Whether the provider should explicitly update the PTR record as well" -msgstr "" +msgstr "Se o provedor deve atualizar explicitamente o registro PTR também" #: src/config/SSSDConfig/sssdoptions.py:208 msgid "Whether the nsupdate utility should default to using TCP" -msgstr "" +msgstr "Se o utilitário nsupdate deve usar TCP por padrão" #: src/config/SSSDConfig/sssdoptions.py:209 msgid "What kind of authentication should be used to perform the DNS update" msgstr "" +"Qual tipo de autenticação deve ser usado para realizar a atualização DNS" #: src/config/SSSDConfig/sssdoptions.py:210 msgid "Override the DNS server used to perform the DNS update" -msgstr "" +msgstr "Substitui o servidor DNS usado para realizar a atualização DNS" #: src/config/SSSDConfig/sssdoptions.py:211 msgid "The file of the certificate authorities certificates for DoT" -msgstr "" +msgstr "O arquivo de certificados das autoridades de certificação para DoT" #: src/config/SSSDConfig/sssdoptions.py:212 msgid "The certificate(s) file for authentication for the DoT transport" -msgstr "" +msgstr "O arquivo de certificado(s) para autenticação para o transporte DoT" #: src/config/SSSDConfig/sssdoptions.py:213 msgid "The key file for authenticated encryption for the DoT transport" -msgstr "" +msgstr "O arquivo de chave para criptografia autenticada para o transporte DoT" #: src/config/SSSDConfig/sssdoptions.py:214 msgid "How often should subdomains list be refreshed" -msgstr "" +msgstr "Com que frequência a lista de subdomínios deve ser atualizada" #: src/config/SSSDConfig/sssdoptions.py:215 msgid "Maximum period deviation when refreshing the subdomain list" -msgstr "" +msgstr "Desvio máximo do período ao atualizar a lista de subdomínios" #: src/config/SSSDConfig/sssdoptions.py:216 msgid "List of options that should be inherited into a subdomain" -msgstr "" +msgstr "Lista de opções que devem ser herdadas em um subdomínio" #: src/config/SSSDConfig/sssdoptions.py:217 msgid "Default subdomain homedir value" -msgstr "" +msgstr "Valor padrão de homedir do subdomínio" #: src/config/SSSDConfig/sssdoptions.py:218 msgid "How long can cached credentials be used for cached authentication" msgstr "" +"Por quanto tempo as credenciais em cache podem ser usadas para autenticação " +"em cache" #: src/config/SSSDConfig/sssdoptions.py:219 msgid "Whether to automatically create private groups for users" -msgstr "" +msgstr "Se deve criar automaticamente grupos privados para usuários" #: src/config/SSSDConfig/sssdoptions.py:220 msgid "Display a warning N days before the password expires." -msgstr "" +msgstr "Exibe um aviso N dias antes da expiração da senha." #: src/config/SSSDConfig/sssdoptions.py:221 msgid "" "Various tags stored by the realmd configuration service for this domain." msgstr "" +"Várias tags armazenadas pelo serviço de configuração realmd para este " +"domínio." #: src/config/SSSDConfig/sssdoptions.py:222 msgid "" "The provider which should handle fetching of subdomains. This value should " "be always the same as id_provider." msgstr "" +"O provedor que deve lidar com a busca de subdomínios. Este valor deve ser " +"sempre o mesmo que id_provider." #: src/config/SSSDConfig/sssdoptions.py:224 msgid "" "How many seconds to keep a host ssh key after refresh. IE how long to cache " "the host key for." msgstr "" +"Por quantos segundos manter uma chave SSH do host após a atualização. Ou " +"seja, por quanto tempo armazenar a chave do host em cache." #: src/config/SSSDConfig/sssdoptions.py:226 msgid "" @@ -686,401 +785,444 @@ msgid "" "this value determines the minimal length the first authentication factor " "(long term password) must have to be saved as SHA512 hash into the cache." msgstr "" +"Se a autenticação de dois fatores (2FA) for usada e as credenciais devem ser " +"salvas, este valor determina o comprimento mínimo que o primeiro fator de " +"autenticação (senha de longo prazo) deve ter para ser salvo como hash SHA512 " +"no cache." #: src/config/SSSDConfig/sssdoptions.py:230 msgid "Local authentication methods policy " -msgstr "" +msgstr "Política de métodos de autenticação local " #: src/config/SSSDConfig/sssdoptions.py:233 msgid "IPA domain" -msgstr "" +msgstr "Domínio IPA" #: src/config/SSSDConfig/sssdoptions.py:234 msgid "IPA server address" -msgstr "" +msgstr "Endereço do servidor IPA" #: src/config/SSSDConfig/sssdoptions.py:235 msgid "Address of backup IPA server" -msgstr "" +msgstr "Endereço do servidor IPA de backup" #: src/config/SSSDConfig/sssdoptions.py:236 msgid "IPA client hostname" -msgstr "" +msgstr "Nome do host do cliente IPA" #: src/config/SSSDConfig/sssdoptions.py:237 msgid "Search base for HBAC related objects" -msgstr "" +msgstr "Base de pesquisa para objetos relacionados a HBAC" #: src/config/SSSDConfig/sssdoptions.py:238 msgid "" "The amount of time between lookups of the HBAC rules against the IPA server" -msgstr "" +msgstr "Tempo entre as consultas das regras HBAC no servidor IPA" #: src/config/SSSDConfig/sssdoptions.py:239 msgid "" "The amount of time in seconds between lookups of the SELinux maps against " "the IPA server" -msgstr "" +msgstr "Tempo em segundos entre as consultas dos mapas SELinux no servidor IPA" #: src/config/SSSDConfig/sssdoptions.py:241 msgid "If set to false, host argument given by PAM will be ignored" msgstr "" +"Se definido como falso, o argumento de host fornecido pelo PAM será ignorado" #: src/config/SSSDConfig/sssdoptions.py:242 msgid "The automounter location this IPA client is using" -msgstr "" +msgstr "Local de montagem automática que este cliente IPA está usando" #: src/config/SSSDConfig/sssdoptions.py:243 msgid "Search base for object containing info about IPA domain" -msgstr "" +msgstr "Base de pesquisa para objetos contendo informações sobre o domínio IPA" #: src/config/SSSDConfig/sssdoptions.py:244 msgid "Search base for objects containing info about ID ranges" msgstr "" +"Base de pesquisa para objetos contendo informações sobre intervalos de ID" #: src/config/SSSDConfig/sssdoptions.py:245 msgid "Search base for view containers" -msgstr "" +msgstr "Base de pesquisa para contêineres de visualização" #: src/config/SSSDConfig/sssdoptions.py:246 msgid "Objectclass for view containers" -msgstr "" +msgstr "Objectclass para contêineres de visualização" #: src/config/SSSDConfig/sssdoptions.py:247 msgid "Attribute with the name of the view" -msgstr "" +msgstr "Atributo com o nome da visualização" #: src/config/SSSDConfig/sssdoptions.py:248 msgid "Objectclass for override objects" -msgstr "" +msgstr "Objectclass para objetos de substituição" #: src/config/SSSDConfig/sssdoptions.py:249 msgid "Attribute with the reference to the original object" -msgstr "" +msgstr "Atributo com a referência ao objeto original" #: src/config/SSSDConfig/sssdoptions.py:250 msgid "Objectclass for user override objects" -msgstr "" +msgstr "Objectclass para objetos de substituição de usuário" #: src/config/SSSDConfig/sssdoptions.py:251 msgid "Objectclass for group override objects" -msgstr "" +msgstr "Objectclass para objetos de substituição de grupo" #: src/config/SSSDConfig/sssdoptions.py:252 msgid "Search base for Desktop Profile related objects" -msgstr "" +msgstr "Base de pesquisa para objetos relacionados ao Perfil Desktop" #: src/config/SSSDConfig/sssdoptions.py:253 msgid "" "The amount of time in seconds between lookups of the Desktop Profile rules " "against the IPA server" msgstr "" +"O tempo em segundos entre as pesquisas das regras do Perfil Desktop no " +"servidor IPA" #: src/config/SSSDConfig/sssdoptions.py:255 msgid "" "The amount of time in minutes between lookups of Desktop Profiles rules " "against the IPA server when the last request did not find any rule" msgstr "" +"O tempo em minutos entre as pesquisas das regras do Perfil Desktop no " +"servidor IPA quando a última solicitação não encontrou nenhuma regra" #: src/config/SSSDConfig/sssdoptions.py:258 #: src/config/SSSDConfig/sssdoptions.py:455 msgid "Search base for SUBID ranges" -msgstr "" +msgstr "Base de pesquisa para intervalos de SUBID" #: src/config/SSSDConfig/sssdoptions.py:259 #: src/config/SSSDConfig/sssdoptions.py:506 msgid "Which rules should be used to evaluate access control" -msgstr "" +msgstr "Quais regras devem ser usadas para avaliar o controle de acesso" #: src/config/SSSDConfig/sssdoptions.py:260 msgid "The LDAP attribute that contains FQDN of the host." -msgstr "" +msgstr "O atributo LDAP que contém o FQDN do host." #: src/config/SSSDConfig/sssdoptions.py:261 #: src/config/SSSDConfig/sssdoptions.py:284 msgid "The object class of a host entry in LDAP." -msgstr "" +msgstr "A classe de objeto de uma entrada de host no LDAP." #: src/config/SSSDConfig/sssdoptions.py:262 msgid "Use the given string as search base for host objects." -msgstr "" +msgstr "Usa a string fornecida como base de pesquisa para objetos de host." #: src/config/SSSDConfig/sssdoptions.py:263 msgid "The LDAP attribute that contains the host's SSH public keys." -msgstr "" +msgstr "O atributo LDAP que contém as chaves públicas SSH do host." #: src/config/SSSDConfig/sssdoptions.py:264 msgid "The LDAP attribute that contains NIS domain name of the netgroup." -msgstr "" +msgstr "O atributo LDAP que contém o nome de domínio NIS do grupo de rede." #: src/config/SSSDConfig/sssdoptions.py:265 msgid "The LDAP attribute that contains the names of the netgroup's members." -msgstr "" +msgstr "O atributo LDAP que contém os nomes dos membros do grupo de rede." #: src/config/SSSDConfig/sssdoptions.py:266 msgid "" "The LDAP attribute that lists FQDNs of hosts and host groups that are " "members of the netgroup." msgstr "" +"O atributo LDAP que lista os FQDNs de hosts e grupos de hosts que são " +"membros do grupo de rede." #: src/config/SSSDConfig/sssdoptions.py:268 msgid "" "The LDAP attribute that lists hosts and host groups that are direct members " "of the netgroup." msgstr "" +"O atributo LDAP que lista os hosts e grupos de hosts que são membros diretos " +"do grupo de rede." #: src/config/SSSDConfig/sssdoptions.py:270 msgid "The LDAP attribute that lists netgroup's memberships." -msgstr "" +msgstr "O atributo LDAP que lista as associações do grupo de rede." #: src/config/SSSDConfig/sssdoptions.py:271 msgid "" "The LDAP attribute that lists system users and groups that are direct " "members of the netgroup." msgstr "" +"O atributo LDAP que lista os usuários e grupos do sistema que são membros " +"diretos do grupo de rede." #: src/config/SSSDConfig/sssdoptions.py:273 msgid "The LDAP attribute that corresponds to the netgroup name." -msgstr "" +msgstr "O atributo LDAP que corresponde ao nome do grupo de rede." #: src/config/SSSDConfig/sssdoptions.py:274 msgid "The object class of a netgroup entry in LDAP." -msgstr "" +msgstr "A classe de objeto de uma entrada de grupo de rede no LDAP." #: src/config/SSSDConfig/sssdoptions.py:275 msgid "" "The LDAP attribute that contains the UUID/GUID of an LDAP netgroup object." msgstr "" +"O atributo LDAP que contém o UUID/GUID de um objeto de grupo de rede LDAP." #: src/config/SSSDConfig/sssdoptions.py:276 msgid "" "The LDAP attribute that contains whether or not is user map enabled for " "usage." msgstr "" +"O atributo LDAP que indica se o mapeamento de usuários está habilitado para " +"uso." #: src/config/SSSDConfig/sssdoptions.py:278 msgid "The LDAP attribute that contains host category such as 'all'." -msgstr "" +msgstr "O atributo LDAP que contém a categoria do host, como 'all'." #: src/config/SSSDConfig/sssdoptions.py:279 msgid "" "The LDAP attribute that contains all hosts / hostgroups this rule match " "against." msgstr "" +"O atributo LDAP que contém todos os hosts/grupos de hosts com os quais esta " +"regra corresponde." #: src/config/SSSDConfig/sssdoptions.py:281 msgid "" "The LDAP attribute that contains all users / groups this rule match against." msgstr "" +"O atributo LDAP que contém todos os usuários/grupos com os quais esta regra " +"corresponde." #: src/config/SSSDConfig/sssdoptions.py:283 msgid "The LDAP attribute that contains the name of SELinux usermap." -msgstr "" +msgstr "O atributo LDAP que contém o nome do mapeamento de usuários SELinux." #: src/config/SSSDConfig/sssdoptions.py:285 msgid "" "The LDAP attribute that contains DN of HBAC rule which can be used for " "matching instead of memberUser and memberHost." msgstr "" +"O atributo LDAP que contém o DN da regra HBAC que pode ser usada para " +"correspondência em vez de memberUser e memberHost." #: src/config/SSSDConfig/sssdoptions.py:287 msgid "The LDAP attribute that contains SELinux user string itself." -msgstr "" +msgstr "O atributo LDAP que contém a própria string do usuário SELinux." #: src/config/SSSDConfig/sssdoptions.py:288 msgid "The LDAP attribute that contains user category such as 'all'." -msgstr "" +msgstr "O atributo LDAP que contém a categoria do usuário, como 'all'." #: src/config/SSSDConfig/sssdoptions.py:289 msgid "The LDAP attribute that contains unique ID of the user map." -msgstr "" +msgstr "O atributo LDAP que contém o ID exclusivo do mapeamento de usuários." #: src/config/SSSDConfig/sssdoptions.py:290 msgid "" "The option denotes that the SSSD is running on IPA server and should perform " "lookups of users and groups from trusted domains differently." msgstr "" +"Esta opção indica que o SSSD está sendo executado no servidor IPA e deve " +"realizar pesquisas de usuários e grupos de domínios confiáveis de forma " +"diferente." #: src/config/SSSDConfig/sssdoptions.py:292 msgid "Use the given string as search base for trusted domains." -msgstr "" +msgstr "Use a string fornecida como base de pesquisa para domínios confiáveis." #: src/config/SSSDConfig/sssdoptions.py:295 msgid "Active Directory domain" -msgstr "" +msgstr "Domínio Active Directory" #: src/config/SSSDConfig/sssdoptions.py:296 msgid "Enabled Active Directory domains" -msgstr "" +msgstr "Domínios Active Directory habilitados" #: src/config/SSSDConfig/sssdoptions.py:297 msgid "Active Directory server address" -msgstr "" +msgstr "Endereço do servidor do Active Directory" #: src/config/SSSDConfig/sssdoptions.py:298 msgid "Active Directory backup server address" -msgstr "" +msgstr "Endereço do servidor de backup do Active Directory" #: src/config/SSSDConfig/sssdoptions.py:299 msgid "Active Directory client hostname" -msgstr "" +msgstr "Nome do host do cliente do Active Directory" #: src/config/SSSDConfig/sssdoptions.py:300 msgid "Enable DNS sites - location based service discovery" -msgstr "" +msgstr "Habilita sites DNS - descoberta de serviços baseada em localização" #: src/config/SSSDConfig/sssdoptions.py:301 #: src/config/SSSDConfig/sssdoptions.py:504 msgid "LDAP filter to determine access privileges" -msgstr "" +msgstr "Filtro LDAP para determinar privilégios de acesso" #: src/config/SSSDConfig/sssdoptions.py:302 msgid "Whether to use the Global Catalog for lookups" -msgstr "" +msgstr "Usa o Catálogo Global para pesquisas" #: src/config/SSSDConfig/sssdoptions.py:303 msgid "Operation mode for GPO-based access control" -msgstr "" +msgstr "Modo de operação para controle de acesso baseado em GPO" #: src/config/SSSDConfig/sssdoptions.py:304 msgid "" "The amount of time between lookups of the GPO policy files against the AD " "server" -msgstr "" +msgstr "Tempo entre pesquisas dos arquivos de política de GPO no servidor AD" #: src/config/SSSDConfig/sssdoptions.py:305 msgid "" "PAM service names that map to the GPO (Deny)InteractiveLogonRight policy " "settings" msgstr "" +"Nomes de serviço PAM que mapeiam para as configurações de política (Deny)" +"InteractiveLogonRight do GPO" #: src/config/SSSDConfig/sssdoptions.py:307 msgid "" "PAM service names that map to the GPO (Deny)RemoteInteractiveLogonRight " "policy settings" msgstr "" +"Nomes de serviço PAM que mapeiam para as configurações de política (Deny)" +"RemoteInteractiveLogonRight do GPO" #: src/config/SSSDConfig/sssdoptions.py:309 msgid "" "PAM service names that map to the GPO (Deny)NetworkLogonRight policy settings" msgstr "" +"Nomes de serviço PAM que mapeiam para as configurações de política (Deny)" +"NetworkLogonRight do GPO" #: src/config/SSSDConfig/sssdoptions.py:310 msgid "" "PAM service names that map to the GPO (Deny)BatchLogonRight policy settings" msgstr "" +"Nomes de serviço PAM que mapeiam para as configurações de política (Deny)" +"BatchLogonRight do GPO" #: src/config/SSSDConfig/sssdoptions.py:311 msgid "" "PAM service names that map to the GPO (Deny)ServiceLogonRight policy settings" msgstr "" +"Nomes de serviço PAM que mapeiam para as configurações de política (Deny)" +"ServiceLogonRight do GPO" #: src/config/SSSDConfig/sssdoptions.py:312 msgid "PAM service names for which GPO-based access is always granted" msgstr "" +"Nomes de serviço PAM para os quais o acesso baseado em GPO é sempre concedido" #: src/config/SSSDConfig/sssdoptions.py:313 msgid "PAM service names for which GPO-based access is always denied" msgstr "" +"Nomes de serviço PAM para os quais o acesso baseado em GPO é sempre negado" #: src/config/SSSDConfig/sssdoptions.py:314 msgid "" "Default logon right (or permit/deny) to use for unmapped PAM service names" msgstr "" +"Direito de logon padrão (ou permitir/negar) o uso para nomes de serviço PAM " +"não mapeados" #: src/config/SSSDConfig/sssdoptions.py:315 msgid "a particular site to be used by the client" -msgstr "" +msgstr "um site específico a ser usado pelo cliente" #: src/config/SSSDConfig/sssdoptions.py:316 msgid "" "Maximum age in days before the machine account password should be renewed" -msgstr "" +msgstr "Idade máxima em dias antes da renovação da senha da conta da máquina" #: src/config/SSSDConfig/sssdoptions.py:318 msgid "Option for tuning the machine account renewal task" -msgstr "" +msgstr "Opção para ajustar a tarefa de renovação da conta da máquina" #: src/config/SSSDConfig/sssdoptions.py:319 msgid "Whether to update the machine account password in the Samba database" msgstr "" +"Se a senha da conta da máquina deve ser atualizada no banco de dados Samba" #: src/config/SSSDConfig/sssdoptions.py:321 msgid "Use LDAPS port for LDAP and Global Catalog requests" -msgstr "" +msgstr "Usa a porta LDAPS para solicitações LDAP e Global Catalog" #: src/config/SSSDConfig/sssdoptions.py:324 #: src/config/SSSDConfig/sssdoptions.py:325 msgid "Kerberos server address" -msgstr "" +msgstr "Endereço do servidor Kerberos" #: src/config/SSSDConfig/sssdoptions.py:326 msgid "Kerberos backup server address" -msgstr "" +msgstr "Endereço do servidor de backup Kerberos" #: src/config/SSSDConfig/sssdoptions.py:327 msgid "Kerberos realm" -msgstr "" +msgstr "Reino Kerberos" #: src/config/SSSDConfig/sssdoptions.py:328 msgid "Authentication timeout" -msgstr "" +msgstr "Tempo limite de autenticação" #: src/config/SSSDConfig/sssdoptions.py:329 msgid "Whether to create kdcinfo files" -msgstr "" +msgstr "Se os arquivos kdcinfo devem ser criados" #: src/config/SSSDConfig/sssdoptions.py:330 msgid "Where to drop krb5 config snippets" -msgstr "" +msgstr "Onde colocar os trechos de configuração krb5" #: src/config/SSSDConfig/sssdoptions.py:333 msgid "Directory to store credential caches" -msgstr "" +msgstr "Diretório para armazenar caches de credenciais" #: src/config/SSSDConfig/sssdoptions.py:334 msgid "Location of the user's credential cache" -msgstr "" +msgstr "Local do cache de credenciais do usuário" #: src/config/SSSDConfig/sssdoptions.py:335 msgid "Location of the keytab to validate credentials" -msgstr "" +msgstr "Local da tabela de chaves para validar credenciais" #: src/config/SSSDConfig/sssdoptions.py:336 msgid "Enable credential validation" -msgstr "" +msgstr "Habilita validação de credenciais" #: src/config/SSSDConfig/sssdoptions.py:337 msgid "Store password if offline for later online authentication" -msgstr "" +msgstr "Armazena senha se estiver offline para autenticação online posterior" #: src/config/SSSDConfig/sssdoptions.py:338 msgid "Renewable lifetime of the TGT" -msgstr "" +msgstr "Tempo de vida renovável do TGT" #: src/config/SSSDConfig/sssdoptions.py:339 msgid "Lifetime of the TGT" -msgstr "" +msgstr "Tempo de vida do TGT" #: src/config/SSSDConfig/sssdoptions.py:340 msgid "Time between two checks for renewal" -msgstr "" +msgstr "Tempo entre duas verificações de renovação" #: src/config/SSSDConfig/sssdoptions.py:341 msgid "Enables FAST" -msgstr "" +msgstr "Habilita FAST" #: src/config/SSSDConfig/sssdoptions.py:342 msgid "Selects the principal to use for FAST" -msgstr "" +msgstr "Seleciona a entidade principal a ser usada para FAST" #: src/config/SSSDConfig/sssdoptions.py:343 msgid "Use anonymous PKINIT to request FAST credentials" -msgstr "" +msgstr "Usa PKINIT anônimo para solicitar credenciais FAST" #: src/config/SSSDConfig/sssdoptions.py:344 msgid "Enables principal canonicalization" -msgstr "" +msgstr "Habilita a canonicalização da entidade principal" #: src/config/SSSDConfig/sssdoptions.py:345 msgid "Enables enterprise principals" diff --git a/po/ro.po b/po/ro.po new file mode 100644 index 00000000000..c0a44168316 --- /dev/null +++ b/po/ro.po @@ -0,0 +1,3242 @@ +# SOME DESCRIPTIVE TITLE. +# Copyright (C) YEAR Red Hat, Inc. +# This file is distributed under the same license as the PACKAGE package. +# Petru Rebeja , 2026. +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" +"POT-Creation-Date: 2026-01-14 14:57+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: Automatically generated\n" +"Language-Team: none\n" +"Language: ro\n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" +"Plural-Forms: nplurals=3; plural=n==1 ? 0 : (n==0 || (n%100 > 0 && n%100 < " +"20)) ? 1 : 2;\n" + +#: src/config/SSSDConfig/sssdoptions.py:20 +#: src/config/SSSDConfig/sssdoptions.py:21 +msgid "Set the verbosity of the debug logging" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:22 +msgid "Include timestamps in debug logs" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:23 +msgid "Include microseconds in timestamps in debug logs" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:24 +msgid "Enable/disable debug backtrace" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:25 +msgid "Watchdog timeout before restarting service" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:26 +msgid "Command to start service" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:27 +msgid "The number of file descriptors that may be opened by this responder" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:28 +msgid "Idle time before automatic disconnection of a client" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:29 +msgid "Idle time before automatic shutdown of the responder" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:30 +msgid "Always query all the caches before querying the Data Providers" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:31 +msgid "" +"When SSSD switches to offline mode the amount of time before it tries to go " +"back online will increase based upon the time spent disconnected. This value " +"is in seconds and calculated by the following: offline_timeout + " +"random_offset." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:36 +msgid "SSSD Services to start" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:37 +msgid "SSSD Domains to start" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:38 +msgid "Regex to parse username and domain" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:39 +msgid "Printf-compatible format for displaying fully-qualified names" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:40 +msgid "" +"Directory on the filesystem where SSSD should store Kerberos replay cache " +"files." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:41 +msgid "Domain to add to names without a domain component." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:42 +msgid "The user to drop privileges to" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:43 +msgid "Tune certificate verification" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:44 +msgid "All spaces in group or user names will be replaced with this character" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:45 +msgid "Tune sssd to honor or ignore netlink state changes" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:46 +msgid "Enable or disable the implicit files domain" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:47 +msgid "A specific order of the domains to be looked up" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:48 +msgid "" +"Controls if SSSD should monitor the state of resolv.conf to identify when it " +"needs to update its internal DNS resolver." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:50 +msgid "" +"SSSD monitors the state of resolv.conf to identify when it needs to update " +"its internal DNS resolver. By default, we will attempt to use inotify for " +"this, and will fall back to polling resolv.conf every five seconds if " +"inotify cannot be used." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:53 +msgid "Run PAC responder automatically for AD and IPA provider" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:54 +msgid "Enable or disable core dumps for all SSSD processes." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:55 +msgid "Tune passkey verification behavior" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:58 +msgid "Enumeration cache timeout length (seconds)" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:59 +msgid "Entry cache background update timeout length (seconds)" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:60 +#: src/config/SSSDConfig/sssdoptions.py:125 +msgid "Negative cache timeout length (seconds)" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:61 +msgid "Users that SSSD should explicitly ignore" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:62 +msgid "Groups that SSSD should explicitly ignore" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:63 +msgid "Should filtered users appear in groups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:64 +msgid "The value of the password field the NSS provider should return" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:65 +msgid "Override homedir value from the identity provider with this value" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:66 +msgid "" +"Substitute empty homedir value from the identity provider with this value" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:67 +msgid "Override shell value from the identity provider with this value" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:68 +msgid "The list of shells users are allowed to log in with" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:69 +msgid "" +"The list of shells that will be vetoed, and replaced with the fallback shell" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:70 +msgid "" +"If a shell stored in central directory is allowed but not available, use " +"this fallback" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:71 +msgid "Shell to use if the provider does not list one" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:72 +msgid "How long will be in-memory cache records valid" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:74 +msgid "" +"Size (in megabytes) of the data table allocated inside fast in-memory cache " +"for passwd requests" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:76 +msgid "" +"Size (in megabytes) of the data table allocated inside fast in-memory cache " +"for group requests" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:78 +msgid "" +"Size (in megabytes) of the data table allocated inside fast in-memory cache " +"for initgroups requests" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:79 +msgid "" +"The value of this option will be used in the expansion of the " +"override_homedir option if the template contains the format string %H." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:81 +msgid "" +"Specifies time in seconds for which the list of subdomains will be " +"considered valid." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:83 +msgid "" +"The entry cache can be set to automatically update entries in the background " +"if they are requested beyond a percentage of the entry_cache_timeout value " +"for the domain." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:88 +msgid "How long to allow cached logins between online logins (days)" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:89 +msgid "How many failed logins attempts are allowed when offline" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:91 +msgid "" +"How long (minutes) to deny login after offline_failed_login_attempts has " +"been reached" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:92 +msgid "What kind of messages are displayed to the user during authentication" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:93 +msgid "Filter PAM responses sent to the pam_sss" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:94 +msgid "How many seconds to keep identity information cached for PAM requests" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:95 +msgid "How many days before password expiration a warning should be displayed" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:96 +msgid "List of trusted uids or user's name" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:97 +msgid "List of domains accessible even for untrusted users." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:98 +msgid "Message printed when user account is expired." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:99 +msgid "Message printed when user account is locked." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:100 +msgid "Allow certificate based/Smartcard authentication." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:101 +msgid "Path to certificate database with PKCS#11 modules." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:102 +msgid "Tune certificate verification for PAM authentication." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:103 +msgid "How many seconds will pam_sss wait for p11_child to finish" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:104 +msgid "Which PAM services are permitted to contact application domains" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:105 +msgid "Allowed services for using smartcards" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:106 +msgid "Additional timeout to wait for a card if requested" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:107 +msgid "" +"PKCS#11 URI to restrict the selection of devices for Smartcard authentication" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:108 +msgid "When shall the PAM responder force an initgroups request" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:109 +msgid "List of PAM services that are allowed to authenticate with GSSAPI." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:110 +msgid "Whether to match authenticated UPN with target user" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:111 +msgid "" +"List of pairs : that must be enforced " +"for PAM access with GSSAPI authentication" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:113 +msgid "Allow passkey device authentication." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:114 +msgid "How many seconds will pam_sss wait for passkey_child to finish" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:115 +msgid "Enable debugging in the libfido2 library" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:116 +msgid "Enable JSON protocol for authentication methods selection." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:119 +msgid "Whether to evaluate the time-based attributes in sudo rules" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:120 +msgid "If true, SSSD will switch back to lower-wins ordering logic" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:121 +msgid "" +"Maximum number of rules that can be refreshed at once. If this is exceeded, " +"full refresh is performed." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:128 +msgid "Whether to hash host names and addresses in the known_hosts file" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:129 +msgid "" +"How many seconds to keep a host in the known_hosts file after its host keys " +"were requested" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:131 +msgid "Path to storage of trusted CA certificates" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:132 +msgid "Allow to generate ssh-keys from certificates" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:133 +msgid "" +"Use the following matching rules to filter the certificates for ssh-key " +"generation" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:137 +msgid "List of UIDs or user names allowed to access the PAC responder" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:138 +msgid "How long the PAC data is considered valid" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:139 +msgid "Validate the PAC" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:142 +msgid "List of user attributes the InfoPipe is allowed to publish" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:145 +msgid "" +"One of the following strings specifying the scope of session recording: none " +"- No users are recorded. some - Users/groups specified by users and groups " +"options are recorded. all - All users are recorded." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:148 +msgid "" +"A comma-separated list of users which should have session recording enabled. " +"Matches user names as returned by NSS. I.e. after the possible space " +"replacement, case changes, etc." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:150 +msgid "" +"A comma-separated list of groups, members of which should have session " +"recording enabled. Matches group names as returned by NSS. I.e. after the " +"possible space replacement, case changes, etc." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:153 +msgid "" +"A comma-separated list of users to be excluded from recording, only when " +"scope=all" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:154 +msgid "" +"A comma-separated list of groups, members of which should be excluded from " +"recording, only when scope=all. " +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:158 +msgid "Identity provider" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:159 +msgid "Authentication provider" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:160 +msgid "Access control provider" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:161 +msgid "Password change provider" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:162 +msgid "SUDO provider" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:163 +msgid "Autofs provider" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:164 +msgid "Host identity provider" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:165 +msgid "SELinux provider" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:166 +msgid "Session management provider" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:167 +msgid "Resolver provider" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:170 +msgid "Whether the domain is usable by the OS or by applications" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:171 +msgid "Enable or disable the domain" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:172 +msgid "Minimum user ID" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:173 +msgid "Maximum user ID" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:174 +msgid "Enable enumerating all users/groups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:175 +msgid "Cache credentials for offline login" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:176 +msgid "Display users/groups in fully-qualified form" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:177 +msgid "Don't include group members in group lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:178 +#: src/config/SSSDConfig/sssdoptions.py:190 +#: src/config/SSSDConfig/sssdoptions.py:191 +#: src/config/SSSDConfig/sssdoptions.py:192 +#: src/config/SSSDConfig/sssdoptions.py:193 +#: src/config/SSSDConfig/sssdoptions.py:194 +#: src/config/SSSDConfig/sssdoptions.py:195 +#: src/config/SSSDConfig/sssdoptions.py:196 +msgid "Entry cache timeout length (seconds)" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:179 +msgid "" +"Restrict or prefer a specific address family when performing DNS lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:180 +msgid "How long to keep cached entries after last successful login (days)" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:181 +msgid "" +"How long should SSSD talk to single DNS server before trying next server " +"(miliseconds)" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:183 +msgid "How long should keep trying to resolve single DNS query (seconds)" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:184 +msgid "How long to wait for replies from DNS when resolving servers (seconds)" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:185 +msgid "The domain part of service discovery DNS query" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:186 +msgid "" +"Specifies the interval, in seconds, that SSSD waits before attempting to " +"reconnect to the primary server after a successful connection to the backup " +"server" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:188 +msgid "Override GID value from the identity provider with this value" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:189 +msgid "Treat usernames as case sensitive" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:197 +msgid "How often should expired entries be refreshed in background" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:198 +msgid "Maximum period deviation when refreshing expired entries in background" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:199 +msgid "Whether to automatically update the client's DNS entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:200 +msgid "" +"Whether DNS update of A and AAAA record should be performed in one update or " +"in two separate updates" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:202 +msgid "The TTL to apply to the client's DNS entry after updating it" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:203 +msgid "The interface whose IP should be used for dynamic DNS updates" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:204 +msgid "The list of IP addresses that should be used for dynamic DNS updates" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:205 +msgid "How often to periodically update the client's DNS entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:206 +msgid "Maximum period deviation when updating the client's DNS entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:207 +msgid "Whether the provider should explicitly update the PTR record as well" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:208 +msgid "Whether the nsupdate utility should default to using TCP" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:209 +msgid "What kind of authentication should be used to perform the DNS update" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:210 +msgid "Override the DNS server used to perform the DNS update" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:211 +msgid "The file of the certificate authorities certificates for DoT" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:212 +msgid "The certificate(s) file for authentication for the DoT transport" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:213 +msgid "The key file for authenticated encryption for the DoT transport" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:214 +msgid "How often should subdomains list be refreshed" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:215 +msgid "Maximum period deviation when refreshing the subdomain list" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:216 +msgid "List of options that should be inherited into a subdomain" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:217 +msgid "Default subdomain homedir value" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:218 +msgid "How long can cached credentials be used for cached authentication" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:219 +msgid "Whether to automatically create private groups for users" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:220 +msgid "Display a warning N days before the password expires." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:221 +msgid "" +"Various tags stored by the realmd configuration service for this domain." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:222 +msgid "" +"The provider which should handle fetching of subdomains. This value should " +"be always the same as id_provider." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:224 +msgid "" +"How many seconds to keep a host ssh key after refresh. IE how long to cache " +"the host key for." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:226 +msgid "" +"If 2-Factor-Authentication (2FA) is used and credentials should be saved " +"this value determines the minimal length the first authentication factor " +"(long term password) must have to be saved as SHA512 hash into the cache." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:230 +msgid "Local authentication methods policy " +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:233 +msgid "IPA domain" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:234 +msgid "IPA server address" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:235 +msgid "Address of backup IPA server" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:236 +msgid "IPA client hostname" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:237 +msgid "Search base for HBAC related objects" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:238 +msgid "" +"The amount of time between lookups of the HBAC rules against the IPA server" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:239 +msgid "" +"The amount of time in seconds between lookups of the SELinux maps against " +"the IPA server" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:241 +msgid "If set to false, host argument given by PAM will be ignored" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:242 +msgid "The automounter location this IPA client is using" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:243 +msgid "Search base for object containing info about IPA domain" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:244 +msgid "Search base for objects containing info about ID ranges" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:245 +msgid "Search base for view containers" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:246 +msgid "Objectclass for view containers" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:247 +msgid "Attribute with the name of the view" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:248 +msgid "Objectclass for override objects" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:249 +msgid "Attribute with the reference to the original object" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:250 +msgid "Objectclass for user override objects" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:251 +msgid "Objectclass for group override objects" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:252 +msgid "Search base for Desktop Profile related objects" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:253 +msgid "" +"The amount of time in seconds between lookups of the Desktop Profile rules " +"against the IPA server" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:255 +msgid "" +"The amount of time in minutes between lookups of Desktop Profiles rules " +"against the IPA server when the last request did not find any rule" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:258 +#: src/config/SSSDConfig/sssdoptions.py:455 +msgid "Search base for SUBID ranges" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:259 +#: src/config/SSSDConfig/sssdoptions.py:506 +msgid "Which rules should be used to evaluate access control" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:260 +msgid "The LDAP attribute that contains FQDN of the host." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:261 +#: src/config/SSSDConfig/sssdoptions.py:284 +msgid "The object class of a host entry in LDAP." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:262 +msgid "Use the given string as search base for host objects." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:263 +msgid "The LDAP attribute that contains the host's SSH public keys." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:264 +msgid "The LDAP attribute that contains NIS domain name of the netgroup." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:265 +msgid "The LDAP attribute that contains the names of the netgroup's members." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:266 +msgid "" +"The LDAP attribute that lists FQDNs of hosts and host groups that are " +"members of the netgroup." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:268 +msgid "" +"The LDAP attribute that lists hosts and host groups that are direct members " +"of the netgroup." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:270 +msgid "The LDAP attribute that lists netgroup's memberships." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:271 +msgid "" +"The LDAP attribute that lists system users and groups that are direct " +"members of the netgroup." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:273 +msgid "The LDAP attribute that corresponds to the netgroup name." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:274 +msgid "The object class of a netgroup entry in LDAP." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:275 +msgid "" +"The LDAP attribute that contains the UUID/GUID of an LDAP netgroup object." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:276 +msgid "" +"The LDAP attribute that contains whether or not is user map enabled for " +"usage." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:278 +msgid "The LDAP attribute that contains host category such as 'all'." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:279 +msgid "" +"The LDAP attribute that contains all hosts / hostgroups this rule match " +"against." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:281 +msgid "" +"The LDAP attribute that contains all users / groups this rule match against." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:283 +msgid "The LDAP attribute that contains the name of SELinux usermap." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:285 +msgid "" +"The LDAP attribute that contains DN of HBAC rule which can be used for " +"matching instead of memberUser and memberHost." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:287 +msgid "The LDAP attribute that contains SELinux user string itself." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:288 +msgid "The LDAP attribute that contains user category such as 'all'." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:289 +msgid "The LDAP attribute that contains unique ID of the user map." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:290 +msgid "" +"The option denotes that the SSSD is running on IPA server and should perform " +"lookups of users and groups from trusted domains differently." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:292 +msgid "Use the given string as search base for trusted domains." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:295 +msgid "Active Directory domain" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:296 +msgid "Enabled Active Directory domains" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:297 +msgid "Active Directory server address" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:298 +msgid "Active Directory backup server address" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:299 +msgid "Active Directory client hostname" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:300 +msgid "Enable DNS sites - location based service discovery" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:301 +#: src/config/SSSDConfig/sssdoptions.py:504 +msgid "LDAP filter to determine access privileges" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:302 +msgid "Whether to use the Global Catalog for lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:303 +msgid "Operation mode for GPO-based access control" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:304 +msgid "" +"The amount of time between lookups of the GPO policy files against the AD " +"server" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:305 +msgid "" +"PAM service names that map to the GPO (Deny)InteractiveLogonRight policy " +"settings" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:307 +msgid "" +"PAM service names that map to the GPO (Deny)RemoteInteractiveLogonRight " +"policy settings" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:309 +msgid "" +"PAM service names that map to the GPO (Deny)NetworkLogonRight policy settings" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:310 +msgid "" +"PAM service names that map to the GPO (Deny)BatchLogonRight policy settings" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:311 +msgid "" +"PAM service names that map to the GPO (Deny)ServiceLogonRight policy settings" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:312 +msgid "PAM service names for which GPO-based access is always granted" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:313 +msgid "PAM service names for which GPO-based access is always denied" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:314 +msgid "" +"Default logon right (or permit/deny) to use for unmapped PAM service names" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:315 +msgid "a particular site to be used by the client" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:316 +msgid "" +"Maximum age in days before the machine account password should be renewed" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:318 +msgid "Option for tuning the machine account renewal task" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:319 +msgid "Whether to update the machine account password in the Samba database" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:321 +msgid "Use LDAPS port for LDAP and Global Catalog requests" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:324 +#: src/config/SSSDConfig/sssdoptions.py:325 +msgid "Kerberos server address" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:326 +msgid "Kerberos backup server address" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:327 +msgid "Kerberos realm" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:328 +msgid "Authentication timeout" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:329 +msgid "Whether to create kdcinfo files" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:330 +msgid "Where to drop krb5 config snippets" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:333 +msgid "Directory to store credential caches" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:334 +msgid "Location of the user's credential cache" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:335 +msgid "Location of the keytab to validate credentials" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:336 +msgid "Enable credential validation" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:337 +msgid "Store password if offline for later online authentication" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:338 +msgid "Renewable lifetime of the TGT" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:339 +msgid "Lifetime of the TGT" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:340 +msgid "Time between two checks for renewal" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:341 +msgid "Enables FAST" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:342 +msgid "Selects the principal to use for FAST" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:343 +msgid "Use anonymous PKINIT to request FAST credentials" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:344 +msgid "Enables principal canonicalization" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:345 +msgid "Enables enterprise principals" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:346 +msgid "Enables using of subdomains realms for authentication" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:347 +msgid "A mapping from user names to Kerberos principal names" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:350 +#: src/config/SSSDConfig/sssdoptions.py:351 +msgid "Server where the change password service is running if not on the KDC" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:354 +msgid "ldap_uri, The URI of the LDAP server" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:355 +msgid "ldap_backup_uri, The URI of the LDAP server" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:356 +msgid "The default base DN" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:357 +msgid "How to read rootDSE from LDAP server" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:358 +msgid "The Schema Type in use on the LDAP server, rfc2307" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:359 +msgid "Mode used to change user password" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:360 +msgid "The default bind DN" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:361 +msgid "The type of the authentication token of the default bind DN" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:362 +msgid "The authentication token of the default bind DN" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:363 +msgid "Length of time to attempt connection" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:364 +msgid "Length of time to attempt synchronous LDAP operations" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:365 +msgid "Length of time between attempts to reconnect while offline" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:366 +msgid "Use only the upper case for realm names" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:367 +msgid "File that contains CA certificates" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:368 +msgid "Path to CA certificate directory" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:369 +msgid "File that contains the client certificate" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:370 +msgid "File that contains the client key" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:371 +msgid "List of possible ciphers suites" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:372 +msgid "Require TLS certificate verification" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:373 +msgid "Specify the sasl mechanism to use" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:374 +msgid "Specify the sasl authorization id to use" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:375 +msgid "Specify the sasl authorization realm to use" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:376 +msgid "Specify the minimal SSF for LDAP sasl authorization" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:377 +msgid "Specify the maximal SSF for LDAP sasl authorization" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:378 +msgid "Kerberos service keytab" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:379 +msgid "Use Kerberos auth for LDAP connection" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:380 +msgid "Follow LDAP referrals" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:381 +msgid "Lifetime of TGT for LDAP connection" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:382 +msgid "How to dereference aliases" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:383 +msgid "Service name for DNS service lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:384 +msgid "The number of records to retrieve in a single LDAP query" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:385 +msgid "The number of members that must be missing to trigger a full deref" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:386 +msgid "Ignore unreadable LDAP references" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:387 +msgid "" +"Whether the LDAP library should perform a reverse lookup to canonicalize the " +"host name during a SASL bind" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:389 +msgid "" +"Allows to retain local users as members of an LDAP group for servers that " +"use the RFC2307 schema." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:392 +msgid "entryUSN attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:393 +msgid "lastUSN attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:395 +msgid "How long to retain a connection to the LDAP server before disconnecting" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:398 +msgid "Disable the LDAP paging control" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:399 +msgid "Disable Active Directory range retrieval" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:400 +msgid "Use the ppolicy extension" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:401 +msgid "" +"Force a password change when remaining grace logins reach or go below this " +"threshold" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:404 +msgid "Length of time to wait for a search request" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:405 +msgid "Length of time to wait for a enumeration request" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:406 +msgid "Length of time between enumeration updates" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:407 +msgid "Maximum period deviation between enumeration updates" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:408 +msgid "Length of time between cache cleanups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:409 +msgid "Maximum time deviation between cache cleanups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:410 +msgid "Require TLS for ID lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:411 +msgid "Use ID-mapping of objectSID instead of pre-set IDs" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:412 +msgid "Base DN for user lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:413 +msgid "Scope of user lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:414 +msgid "Filter for user lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:415 +msgid "Objectclass for users" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:416 +msgid "Username attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:417 +msgid "UID attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:418 +msgid "Primary GID attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:419 +msgid "GECOS attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:420 +msgid "Home directory attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:421 +msgid "Shell attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:422 +msgid "UUID attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:423 +#: src/config/SSSDConfig/sssdoptions.py:464 +msgid "objectSID attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:424 +msgid "Active Directory primary group attribute for ID-mapping" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:425 +msgid "User principal attribute (for Kerberos)" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:426 +msgid "Full Name" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:427 +msgid "memberOf attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:428 +msgid "Modification time attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:429 +msgid "shadowLastChange attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:430 +msgid "shadowMin attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:431 +msgid "shadowMax attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:432 +msgid "shadowWarning attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:433 +msgid "shadowInactive attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:434 +msgid "shadowExpire attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:435 +msgid "shadowFlag attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:436 +msgid "Attribute listing authorized PAM services" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:437 +msgid "Attribute listing authorized server hosts" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:438 +msgid "Attribute listing authorized server rhosts" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:439 +msgid "krbLastPwdChange attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:440 +msgid "krbPasswordExpiration attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:441 +msgid "Attribute indicating that server side password policies are active" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:442 +msgid "accountExpires attribute of AD" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:443 +msgid "userAccountControl attribute of AD" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:444 +msgid "nsAccountLock attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:445 +msgid "loginDisabled attribute of NDS" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:446 +msgid "loginExpirationTime attribute of NDS" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:447 +msgid "loginAllowedTimeMap attribute of NDS" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:448 +msgid "SSH public key attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:449 +msgid "attribute listing allowed authentication types for a user" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:450 +msgid "attribute containing the X509 certificate of the user" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:451 +msgid "attribute containing the email address of the user" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:452 +msgid "attribute containing the passkey mapping data of the user" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:453 +msgid "A list of extra attributes to download along with the user entry" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:457 +msgid "Base DN for group lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:458 +msgid "Objectclass for groups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:459 +msgid "Group name" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:460 +msgid "Group password" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:461 +msgid "GID attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:462 +msgid "Group member attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:463 +msgid "Group UUID attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:465 +msgid "Modification time attribute for groups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:466 +msgid "Type of the group and other flags" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:467 +msgid "The LDAP group external member attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:468 +msgid "Maximum nesting level SSSD will follow" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:469 +msgid "Filter for group lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:470 +msgid "Scope of group lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:472 +msgid "Base DN for netgroup lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:473 +msgid "Objectclass for netgroups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:474 +msgid "Netgroup name" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:475 +msgid "Netgroups members attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:476 +msgid "Netgroup triple attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:477 +msgid "Modification time attribute for netgroups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:479 +msgid "Base DN for service lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:480 +msgid "Objectclass for services" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:481 +msgid "Service name attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:482 +msgid "Service port attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:483 +msgid "Service protocol attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:485 +msgid "Lower bound for ID-mapping" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:486 +msgid "Upper bound for ID-mapping" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:487 +msgid "Number of IDs for each slice when ID-mapping" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:488 +msgid "Use autorid-compatible algorithm for ID-mapping" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:489 +msgid "Name of the default domain for ID-mapping" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:490 +msgid "SID of the default domain for ID-mapping" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:491 +msgid "Number of secondary slices" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:493 +msgid "Whether to use Token-Groups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:494 +msgid "Set lower boundary for allowed IDs from the LDAP server" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:495 +msgid "Set upper boundary for allowed IDs from the LDAP server" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:496 +msgid "DN for ppolicy queries" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:497 +msgid "How many maximum entries to fetch during a wildcard request" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:498 +msgid "Set libldap debug level" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:501 +msgid "Policy to evaluate the password expiration" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:505 +msgid "Which attributes shall be used to evaluate if an account is expired" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:509 +msgid "URI of an LDAP server where password changes are allowed" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:510 +msgid "URI of a backup LDAP server where password changes are allowed" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:511 +msgid "DNS service name for LDAP password change server" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:512 +msgid "" +"Whether to update the ldap_user_shadow_last_change attribute after a " +"password change" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:516 +msgid "Base DN for sudo rules lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:517 +msgid "Automatic full refresh period" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:518 +msgid "Automatic smart refresh period" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:519 +msgid "Smart and full refresh random offset" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:520 +msgid "Whether to filter rules by hostname, IP addresses and network" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:521 +msgid "" +"Hostnames and/or fully qualified domain names of this machine to filter sudo " +"rules" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:522 +msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:523 +msgid "Whether to include rules that contains netgroup in host attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:524 +msgid "" +"Whether to include rules that contains regular expression in host attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:525 +msgid "Object class for sudo rules" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:526 +msgid "Name of attribute that is used as object class for sudo rules" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:527 +msgid "Sudo rule name" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:528 +msgid "Sudo rule command attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:529 +msgid "Sudo rule host attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:530 +msgid "Sudo rule user attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:531 +msgid "Sudo rule option attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:532 +msgid "Sudo rule runas attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:533 +msgid "Sudo rule runasuser attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:534 +msgid "Sudo rule runasgroup attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:535 +msgid "Sudo rule notbefore attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:536 +msgid "Sudo rule notafter attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:537 +msgid "Sudo rule order attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:540 +msgid "Object class for automounter maps" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:541 +msgid "Automounter map name attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:542 +msgid "Object class for automounter map entries" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:543 +msgid "Automounter map entry key attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:544 +msgid "Automounter map entry value attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:545 +msgid "Base DN for automounter map lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:546 +msgid "The name of the automount master map in LDAP." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:549 +msgid "Base DN for IP hosts lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:550 +msgid "Object class for IP hosts" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:551 +msgid "IP host name attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:552 +msgid "IP host number (address) attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:553 +msgid "IP host entryUSN attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:554 +msgid "Base DN for IP networks lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:555 +msgid "Object class for IP networks" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:556 +msgid "IP network name attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:557 +msgid "IP network number (address) attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:558 +msgid "IP network entryUSN attribute" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:561 +msgid "Comma separated list of allowed users" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:562 +msgid "Comma separated list of prohibited users" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:563 +msgid "" +"Comma separated list of groups that are allowed to log in. This applies only " +"to groups within this SSSD domain. Local groups are not evaluated." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:565 +msgid "" +"Comma separated list of groups that are explicitly denied access. This " +"applies only to groups within this SSSD domain. Local groups are not " +"evaluated." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:569 +msgid "The number of preforked proxy children." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:572 +msgid "The name of the NSS library to use" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:573 +msgid "The name of the NSS library to use for hosts and networks lookups" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:574 +msgid "Whether to look up canonical group name from cache if possible" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:577 +msgid "PAM stack to use" +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:580 +msgid "Path of passwd file sources." +msgstr "" + +#: src/config/SSSDConfig/sssdoptions.py:581 +msgid "Path of group file sources." +msgstr "" + +#: src/monitor/monitor.c:1757 +msgid "Become a daemon (default)" +msgstr "" + +#: src/monitor/monitor.c:1759 +msgid "Run interactive (not a daemon)" +msgstr "" + +#: src/monitor/monitor.c:1761 +msgid "Print version number and exit" +msgstr "" + +#: src/monitor/monitor.c:1772 +#, c-format +msgid "" +"\n" +"Invalid option %s: %s\n" +"\n" +msgstr "" + +#: src/monitor/monitor.c:1794 +msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" +msgstr "" + +#: src/monitor/monitor.c:1836 +msgid "Failed to get initial capabilities\n" +msgstr "" + +#: src/monitor/monitor.c:1847 +msgid "Non-root service user support isn't built. Can't run under %" +msgstr "" + +#: src/monitor/monitor.c:1864 +#, c-format +msgid "Can't read config: '%s'\n" +msgstr "" + +#: src/monitor/monitor.c:1876 +#, c-format +msgid "Failed to boostrap SSSD 'monitor' process: %s" +msgstr "" + +#: src/monitor/monitor.c:1971 +msgid "Out of memory\n" +msgstr "" + +#: src/providers/krb5/krb5_child.c:4221 +msgid "Use anonymous PKINIT to request FAST armor ticket" +msgstr "" + +#: src/providers/krb5/krb5_child.c:4223 +msgid "Kerberos realm to use" +msgstr "" + +#: src/providers/krb5/krb5_child.c:4225 +msgid "Requested lifetime of the ticket" +msgstr "" + +#: src/providers/krb5/krb5_child.c:4227 +msgid "Requested renewable lifetime of the ticket" +msgstr "" + +#: src/providers/krb5/krb5_child.c:4229 +msgid "FAST options ('never', 'try', 'demand')" +msgstr "" + +#: src/providers/krb5/krb5_child.c:4232 +msgid "Specifies the server principal to use for FAST" +msgstr "" + +#: src/providers/krb5/krb5_child.c:4234 +msgid "Requests canonicalization of the principal name" +msgstr "" + +#: src/providers/krb5/krb5_child.c:4236 +msgid "Use custom version of krb5_get_init_creds_password" +msgstr "" + +#: src/providers/krb5/krb5_child.c:4238 +msgid "Check PAC flags" +msgstr "" + +#: src/providers/data_provider_be.c:790 +msgid "Domain of the information provider (mandatory)" +msgstr "" + +#: src/sss_client/common.c:1165 +msgid "Socket has wrong ownership or permissions." +msgstr "" + +#: src/sss_client/common.c:1168 +msgid "Unexpected format of the server credential message." +msgstr "" + +#: src/sss_client/common.c:1171 +msgid "SSSD is not run by trusted user." +msgstr "" + +#: src/sss_client/common.c:1174 +msgid "SSSD socket does not exist." +msgstr "" + +#: src/sss_client/common.c:1177 +msgid "Cannot get stat of SSSD socket." +msgstr "" + +#: src/sss_client/common.c:1182 +msgid "An error occurred, but no description can be found." +msgstr "" + +#: src/sss_client/common.c:1188 +msgid "Unexpected error while looking for an error description" +msgstr "" + +#: src/sss_client/pam_sss.c:74 +msgid "Permission denied. " +msgstr "" + +#: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 +#: src/sss_client/pam_sss.c:854 +msgid "Server message: " +msgstr "" + +#: src/sss_client/pam_sss.c:76 +msgid "" +"Kerberos TGT will not be granted upon login, user experience will be " +"affected." +msgstr "" + +#: src/sss_client/pam_sss.c:77 +msgid "Enter PIN:" +msgstr "" + +#: src/sss_client/pam_sss.c:320 +msgid "Passwords do not match" +msgstr "" + +#: src/sss_client/pam_sss.c:508 +msgid "Password reset by root is not supported." +msgstr "" + +#: src/sss_client/pam_sss.c:549 +msgid "Authenticated with cached credentials" +msgstr "" + +#: src/sss_client/pam_sss.c:550 +msgid ", your cached password will expire at: " +msgstr "" + +#: src/sss_client/pam_sss.c:580 +#, c-format +msgid "Your password has expired. You have %1$d grace login(s) remaining." +msgstr "" + +#: src/sss_client/pam_sss.c:630 +#, c-format +msgid "Your password will expire in %1$d %2$s." +msgstr "" + +#: src/sss_client/pam_sss.c:633 +#, c-format +msgid "Your password has expired." +msgstr "" + +#: src/sss_client/pam_sss.c:684 +msgid "Authentication is denied until: " +msgstr "" + +#: src/sss_client/pam_sss.c:705 +msgid "System is offline, password change not possible" +msgstr "" + +#: src/sss_client/pam_sss.c:720 +msgid "" +"After changing the OTP password, you need to log out and back in order to " +"acquire a ticket" +msgstr "" + +#: src/sss_client/pam_sss.c:735 +msgid "PIN locked" +msgstr "" + +#: src/sss_client/pam_sss.c:750 +msgid "" +"No Kerberos TGT granted as the server does not support this method. Your " +"single-sign on(SSO) experience will be affected." +msgstr "" + +#: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 +msgid "Password change failed. " +msgstr "" + +#: src/sss_client/pam_sss.c:1859 +#, c-format +msgid "Authenticate at %1$s and press ENTER." +msgstr "" + +#: src/sss_client/pam_sss.c:1862 +#, c-format +msgid "Authenticate with PIN %1$s at %2$s and press ENTER." +msgstr "" + +#: src/sss_client/pam_sss.c:2281 +msgid "Please (re)insert (different) Smartcard" +msgstr "" + +#: src/sss_client/pam_sss.c:2482 +msgid "New Password: " +msgstr "" + +#: src/sss_client/pam_sss.c:2483 +msgid "Reenter new Password: " +msgstr "" + +#: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 +msgid "First Factor: " +msgstr "" + +#: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 +msgid "Second Factor (optional): " +msgstr "" + +#: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 +msgid "Second Factor: " +msgstr "" + +#: src/sss_client/pam_sss.c:2684 +msgid "Insert your passkey device, then press ENTER." +msgstr "" + +#: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 +msgid "Password: " +msgstr "" + +#: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 +msgid "First Factor (Current Password): " +msgstr "" + +#: src/sss_client/pam_sss.c:2874 +msgid "Current Password: " +msgstr "" + +#: src/sss_client/pam_sss.c:3248 +msgid "Password expired. Change your password now." +msgstr "" + +#: src/sss_client/ssh/sss_ssh_authorizedkeys.c:41 src/tools/sss_cache.c:707 +msgid "The debug level to run with" +msgstr "" + +#: src/sss_client/ssh/sss_ssh_authorizedkeys.c:43 +msgid "The SSSD domain to use" +msgstr "" + +#: src/sss_client/ssh/sss_ssh_authorizedkeys.c:57 src/tools/sss_cache.c:753 +msgid "Error setting the locale\n" +msgstr "" + +#: src/sss_client/ssh/sss_ssh_authorizedkeys.c:64 +msgid "Not enough memory\n" +msgstr "" + +#: src/sss_client/ssh/sss_ssh_authorizedkeys.c:83 +msgid "User not specified\n" +msgstr "" + +#: src/sss_client/ssh/sss_ssh_authorizedkeys.c:97 +msgid "Error looking up public keys\n" +msgstr "" + +#: src/sss_client/ssh/sss_ssh_knownhostsproxy.c:27 +msgid "" +"\n" +"******************************************************************************\n" +"Your system is configured to use the obsolete tool sss_ssh_knownhostsproxy.\n" +"Please read the sss_ssh_knownhosts(1) man page to learn about its " +"replacement.\n" +"******************************************************************************\n" +"\n" +msgstr "" + +#: src/tools/sss_cache.c:229 +msgid "No cache object matched the specified search\n" +msgstr "" + +#: src/tools/sss_cache.c:520 +#, c-format +msgid "Couldn't invalidate %1$s\n" +msgstr "" + +#: src/tools/sss_cache.c:527 +#, c-format +msgid "Couldn't invalidate %1$s %2$s\n" +msgstr "" + +#: src/tools/sss_cache.c:653 +msgid "Can't find configuration db, was SSSD configured and run?\n" +msgstr "" + +#: src/tools/sss_cache.c:709 +msgid "Invalidate all cached entries" +msgstr "" + +#: src/tools/sss_cache.c:711 +msgid "Invalidate particular user" +msgstr "" + +#: src/tools/sss_cache.c:713 +msgid "Invalidate all users" +msgstr "" + +#: src/tools/sss_cache.c:715 +msgid "Invalidate particular group" +msgstr "" + +#: src/tools/sss_cache.c:717 +msgid "Invalidate all groups" +msgstr "" + +#: src/tools/sss_cache.c:719 +msgid "Invalidate particular netgroup" +msgstr "" + +#: src/tools/sss_cache.c:721 +msgid "Invalidate all netgroups" +msgstr "" + +#: src/tools/sss_cache.c:723 +msgid "Invalidate particular service" +msgstr "" + +#: src/tools/sss_cache.c:725 +msgid "Invalidate all services" +msgstr "" + +#: src/tools/sss_cache.c:728 +msgid "Invalidate particular autofs map" +msgstr "" + +#: src/tools/sss_cache.c:730 +msgid "Invalidate all autofs maps" +msgstr "" + +#: src/tools/sss_cache.c:734 +msgid "Invalidate particular SSH host" +msgstr "" + +#: src/tools/sss_cache.c:736 +msgid "Invalidate all SSH hosts" +msgstr "" + +#: src/tools/sss_cache.c:740 +msgid "Invalidate particular sudo rule" +msgstr "" + +#: src/tools/sss_cache.c:742 +msgid "Invalidate all cached sudo rules" +msgstr "" + +#: src/tools/sss_cache.c:745 +msgid "Only invalidate entries from a particular domain" +msgstr "" + +#: src/tools/sss_cache.c:799 +msgid "" +"Unexpected argument(s) provided, options that invalidate a single object " +"only accept a single provided argument.\n" +msgstr "" + +#: src/tools/sss_cache.c:809 +msgid "Please select at least one object to invalidate\n" +msgstr "" + +#: src/tools/sss_cache.c:892 +#, c-format +msgid "" +"Could not open domain %1$s. If the domain is a subdomain (trusted domain), " +"use fully qualified name instead of --domain/-d parameter.\n" +msgstr "" + +#: src/tools/sss_cache.c:897 +msgid "Could not open available domains\n" +msgstr "" + +#: src/tools/tools_util.h:36 +#, c-format +msgid "%1$s must be run as root\n" +msgstr "" + +#: src/tools/sssctl/sssctl.c:35 +msgid "yes" +msgstr "" + +#: src/tools/sssctl/sssctl.c:37 +msgid "no" +msgstr "" + +#: src/tools/sssctl/sssctl.c:39 +msgid "error" +msgstr "" + +#: src/tools/sssctl/sssctl.c:42 +msgid "Invalid result." +msgstr "" + +#: src/tools/sssctl/sssctl.c:78 +msgid "Unable to read user input\n" +msgstr "" + +#: src/tools/sssctl/sssctl.c:91 +#, c-format +msgid "Invalid input, please provide either '%s' or '%s'.\n" +msgstr "" + +#: src/tools/sssctl/sssctl.c:151 src/tools/sssctl/sssctl.c:161 +msgid "Error while executing external command\n" +msgstr "" + +#: src/tools/sssctl/sssctl.c:165 +#, c-format +msgid "Error while executing external command '%s'\n" +msgstr "" + +#: src/tools/sssctl/sssctl.c:168 +#, c-format +msgid "Command '%s' failed with [%d]\n" +msgstr "" + +#: src/tools/sssctl/sssctl.c:215 +msgid "SSSD needs to be running. Start SSSD now?" +msgstr "" + +#: src/tools/sssctl/sssctl.c:254 +msgid "SSSD must not be running. Stop SSSD now?" +msgstr "" + +#: src/tools/sssctl/sssctl.c:290 +msgid "SSSD needs to be restarted. Restart SSSD now?" +msgstr "" + +#: src/tools/sssctl/sssctl.c:322 +msgid "SSSD Status:" +msgstr "" + +#: src/tools/sssctl/sssctl.c:323 +msgid "List available domains" +msgstr "" + +#: src/tools/sssctl/sssctl.c:324 +msgid "Print information about domain" +msgstr "" + +#: src/tools/sssctl/sssctl.c:325 +msgid "Print information about a user and check authentication" +msgstr "" + +#: src/tools/sssctl/sssctl.c:326 +msgid "Generate access report for a domain" +msgstr "" + +#: src/tools/sssctl/sssctl.c:327 +msgid "Information about cached content:" +msgstr "" + +#: src/tools/sssctl/sssctl.c:328 +msgid "Information about cached user" +msgstr "" + +#: src/tools/sssctl/sssctl.c:329 +msgid "Information about cached group" +msgstr "" + +#: src/tools/sssctl/sssctl.c:330 +msgid "Information about cached netgroup" +msgstr "" + +#: src/tools/sssctl/sssctl.c:331 +msgid "Local data tools:" +msgstr "" + +#: src/tools/sssctl/sssctl.c:332 +msgid "Backup local data" +msgstr "" + +#: src/tools/sssctl/sssctl.c:333 +msgid "Restore local data from backup" +msgstr "" + +#: src/tools/sssctl/sssctl.c:334 +msgid "Backup local data and remove cached content" +msgstr "" + +#: src/tools/sssctl/sssctl.c:335 +msgid "Invalidate cached objects" +msgstr "" + +#: src/tools/sssctl/sssctl.c:336 +msgid "Manage cache indexes" +msgstr "" + +#: src/tools/sssctl/sssctl.c:337 +msgid "Log files tools:" +msgstr "" + +#: src/tools/sssctl/sssctl.c:338 +msgid "Remove existing SSSD log files" +msgstr "" + +#: src/tools/sssctl/sssctl.c:339 +msgid "Archive SSSD log files in tarball" +msgstr "" + +#: src/tools/sssctl/sssctl.c:340 +msgid "Change or print information about SSSD debug level" +msgstr "" + +#: src/tools/sssctl/sssctl.c:341 +msgid "Analyze logged data" +msgstr "" + +#: src/tools/sssctl/sssctl.c:342 +msgid "Configuration files tools:" +msgstr "" + +#: src/tools/sssctl/sssctl.c:343 +msgid "Perform static analysis of SSSD configuration" +msgstr "" + +#: src/tools/sssctl/sssctl.c:344 +msgid "Certificate related tools:" +msgstr "" + +#: src/tools/sssctl/sssctl.c:345 +msgid "Print information about the certificate" +msgstr "" + +#: src/tools/sssctl/sssctl.c:346 +msgid "Show users mapped to the certificate" +msgstr "" + +#: src/tools/sssctl/sssctl.c:347 +msgid "Check mapping and matching rule with a certificate" +msgstr "" + +#: src/tools/sssctl/sssctl.c:348 +msgid "GPOs related tools:" +msgstr "" + +#: src/tools/sssctl/sssctl.c:349 +msgid "Information about cached GPO" +msgstr "" + +#: src/tools/sssctl/sssctl.c:350 +msgid "Enumerate cached GPOs" +msgstr "" + +#: src/tools/sssctl/sssctl.c:351 +msgid "Remove cached GPO" +msgstr "" + +#: src/tools/sssctl/sssctl.c:352 +msgid "Remove all cached GPOs" +msgstr "" + +#: src/tools/sssctl/sssctl.c:354 +msgid "Passkey related tools:" +msgstr "" + +#: src/tools/sssctl/sssctl.c:355 +msgid "Perform passkey registration" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:31 +#, c-format +msgid " %s is not present in cache.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:33 +msgid "Name" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:34 +msgid "Cache entry creation date" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:35 +msgid "Cache entry last update time" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:36 +msgid "Cache entry expiration time" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:37 +msgid "Cached in InfoPipe" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:38 +msgid "Policy Name" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:39 +msgid "Policy GUID" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:40 +msgid "Policy Path" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:41 +msgid "Policy file timeout" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:42 +msgid "Policy version" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:556 +#, c-format +msgid "Error: Unable to get object [%d]: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:572 src/tools/sssctl/sssctl_cache.c:927 +#, c-format +msgid "%s: Unable to read value [%d]: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:602 +msgid "Specify name." +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:612 +#, c-format +msgid "Unable to parse name %s.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:641 src/tools/sssctl/sssctl_cache.c:688 +msgid "Search by SID" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:642 +msgid "Search by user ID" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:651 +msgid "Initgroups expiration time" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:689 +msgid "Search by group ID" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:778 src/tools/sssctl/sssctl_cache.c:1126 +msgid "Search by GPO guid" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:785 src/tools/sssctl/sssctl_cache.c:1143 +#, c-format +msgid "Failed to parse command line: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:790 src/tools/sssctl/sssctl_cache.c:1148 +#, c-format +msgid "%s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:803 +#, c-format +msgid "Failed to print object: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 +#: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 +#: src/tools/sssctl/sssctl_cache.c:1010 src/tools/sssctl/sssctl_cache.c:1034 +#: src/tools/sssctl/sssctl_cache.c:1085 src/tools/sssctl/sssctl_cache.c:1194 +#: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 +#: src/tools/sssctl/sssctl_cache.c:1244 +msgid "talloc failed\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:841 +msgid "Unable to get attribute list!\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:848 +msgid "Unable to create filter\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:861 +#, c-format +msgid "%s [%s]:\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:866 +msgid "Unable to get GPOs base DN\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:876 +#, c-format +msgid "Unable to search sysdb: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:882 +#, c-format +msgid "Unable to convert message to sysdb attrs: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:931 +#, c-format +msgid "\t%s: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:933 src/tools/sssctl/sssctl_logs.c:50 +msgid "\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:1016 +msgid "Could not find GUID attribute from GPO entry\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:1023 +msgid "Could not find description attribute from GPO entry\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:1047 +msgid "Could not delete GPO entry from cache\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:1053 +#, c-format +msgid "" +"The GPO path was not yet stored in cache. Please remove files manually from " +"[%s]\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:1062 src/tools/sssctl/sssctl_cache.c:1068 +#, c-format +msgid "Could not determine real path for [%s]: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:1073 +#, c-format +msgid "The cached GPO path [%s] is not under [%s], ignoring.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:1098 +#, c-format +msgid "Unable to remove downloaded GPO files: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:1165 +#, c-format +msgid "Failed to fetch cache entry: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:1170 +msgid "Could not determine object domain\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:1200 +msgid "Could not find GUID attribute in GPO entry\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:1206 +#, c-format +msgid "Failed to delete GPO: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cache.c:1210 +#, c-format +msgid "%s removed from cache\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:50 src/tools/sssctl/sssctl_cert.c:108 +#: src/tools/sssctl/sssctl_cert.c:214 +msgid "Show debug information" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:56 src/tools/sssctl/sssctl_cert.c:114 +#: src/tools/sssctl/sssctl_cert.c:220 +msgid "Specify base64 encoded certificate." +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:138 src/tools/sssctl/sssctl_domains.c:104 +#: src/tools/sssctl/sssctl_domains.c:366 +#: src/tools/sssctl/sssctl_user_checks.c:99 +msgid "Unable to connect to system bus!\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:164 +msgid " - no mapped users found -" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:212 +msgid "Mapping rule" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:213 +msgid "Matching rule" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:223 +msgid "Unable to parse command arguments\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:229 src/tools/sssctl/sssctl_domains.c:354 +msgid "Out of memory!\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:238 +msgid "Failed to setup certmap context.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:244 +#, c-format +msgid "Failed to add mapping and matching rules with error [%d][%s].\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:251 +msgid "Failed to decode base64 string.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:259 +msgid "Certificate matches rule.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:262 +msgid "Certificate does not match rule.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:265 +#, c-format +msgid "Error during certificate matching [%d][%s].\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:272 +#, c-format +msgid "Failed to generate mapping filter [%d][%s].\n" +msgstr "" + +#: src/tools/sssctl/sssctl_cert.c:276 +#, c-format +msgid "" +"Mapping filter:\n" +"\n" +" %s\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_config.c:75 +msgid "" +"Specify a non-default snippet dir (The default is to look in the same place " +"where the main config file is located. For example if the config is set to " +"\"/my/path/sssd.conf\", the snippet dir \"/my/path/conf.d\" is used)" +msgstr "" + +#: src/tools/sssctl/sssctl_config.c:114 +#, c-format +msgid "File %1$s does not exist.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_config.c:115 +msgid "There is no configuration.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_config.c:120 +#, c-format +msgid "Configuration validation failed: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_config.c:121 +msgid "Run with high debug level to see details.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_config.c:130 +msgid "Failed to run validators" +msgstr "" + +#: src/tools/sssctl/sssctl_config.c:134 +#, c-format +msgid "Issues identified by validators: %zu\n" +msgstr "" + +#: src/tools/sssctl/sssctl_config.c:145 +#, c-format +msgid "Messages generated during configuration merging: %zu\n" +msgstr "" + +#: src/tools/sssctl/sssctl_config.c:158 +#, c-format +msgid "Used configuration snippet files: %zu\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:91 +#, c-format +msgid "Unable to create backup directory [%d]: %s" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:97 +msgid "SSSD backup of local data already exists, override?" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:113 +msgid "Unable to export user overrides\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:120 +msgid "Unable to export group overrides\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:135 src/tools/sssctl/sssctl_data.c:216 +msgid "Override existing backup" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:165 +msgid "Unable to import user overrides\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:174 +msgid "Unable to import group overrides\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:194 src/tools/sssctl/sssctl_domains.c:81 +#: src/tools/sssctl/sssctl_domains.c:326 +msgid "Start SSSD if it is not running" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:195 +msgid "Restart SSSD after data import" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:217 +msgid "Create clean cache files and import local data" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:218 +msgid "Stop SSSD before removing the cache" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:219 +msgid "Start SSSD when the cache is removed" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:234 +msgid "Creating backup of local data...\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:237 +msgid "Unable to create backup of local data, can not remove the cache.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:242 +msgid "Removing cache files...\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:245 +msgid "Unable to remove cache files\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:250 +msgid "Restoring local data...\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:377 +#, c-format +msgid "Creating cache index for domain %1$s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:379 +#, c-format +msgid "Deleting cache index for domain %1$s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:381 +#, c-format +msgid "Indexes for domain %1$s:\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:401 +#, c-format +msgid " Attribute: %1$s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:428 src/tools/sssctl/sssctl_logs.c:525 +msgid "Target a specific domain" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:428 src/tools/sssctl/sssctl_logs.c:525 +msgid "domain" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:430 +msgid "Attribute to index" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:430 +msgid "attribute" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:443 +msgid "Action not provided\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:456 +#, c-format +msgid "" +"Unknown action: %1$s\n" +"Valid actions are \"%2$s\", \"%3$s and \"%4$s\"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:464 +msgid "Attribute (-a) not provided\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:472 +#, c-format +msgid "Attribute %1$s not indexed.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:475 +#, c-format +msgid "Attribute %1$s already indexed.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:478 +#, c-format +msgid "Index operation failed: %1$s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_data.c:483 +msgid "Don't forget to also update the indexes on the remote providers.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:82 +msgid "Show domain list including primary or trusted domain type" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:166 +msgid "Online" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:166 +msgid "Offline" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:166 +#, c-format +msgid "Online status: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:212 +msgid "This domain has no active servers.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:217 +msgid "Active servers:\n" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:229 +msgid "not connected" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:266 +msgid "No servers discovered.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:272 +#, c-format +msgid "Discovered %s servers:\n" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:284 +msgid "None so far.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:323 +msgid "Show online status" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:324 +msgid "Show information about active server" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:325 +msgid "Show list of discovered servers" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:331 +msgid "Specify domain name." +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:374 src/tools/sssctl/sssctl_domains.c:384 +msgid "Unable to get online status\n" +msgstr "" + +#: src/tools/sssctl/sssctl_domains.c:394 +msgid "Unable to get server list\n" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:214 +msgid "SSSD is not running.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:231 +#, c-format +msgid "%1$-25s %2$#.4x\n" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:235 +#, c-format +msgid "%1$-25s Unknown domain\n" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:237 +#, c-format +msgid "%1$-25s Unreachable service\n" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:429 +msgid "Delete log files instead of truncating" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:440 +msgid "Deleting log files...\n" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:443 +msgid "Unable to remove log files\n" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:460 +msgid "Truncating log files...\n" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:464 +msgid "Unable to truncate log files\n" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:498 +#, c-format +msgid "Archiving log files into %s...\n" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:502 +msgid "Unable to archive log files\n" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:526 +msgid "Target the SSSD service" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:527 +msgid "Target the NSS service" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:528 +msgid "Target the PAM service" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:529 +msgid "Target the SUDO service" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:530 +msgid "Target the AUTOFS service" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:531 +msgid "Target the SSH service" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:532 +msgid "Target the PAC service" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:533 +msgid "Target the IFP service" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:548 +msgid "Specify debug level you want to set" +msgstr "" + +#: src/tools/sssctl/sssctl_logs.c:593 +msgid "ERROR: Tevent chain ID support missing, log analyzer is unsupported.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:121 +msgid "SSSD InfoPipe user lookup result:\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:171 +#, c-format +msgid "dlopen failed with [%s].\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:178 +#, c-format +msgid "dlsym failed with [%s].\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:186 +msgid "malloc failed.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:193 +#, c-format +msgid "sss_getpwnam_r failed with [%d].\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:198 +msgid "SSSD nss user lookup result:\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:199 +#, c-format +msgid " - user name: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:200 +#, c-format +msgid " - user id: %d\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:201 +#, c-format +msgid " - group id: %d\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:202 +#, c-format +msgid " - gecos: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:203 +#, c-format +msgid " - home directory: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:204 +#, c-format +msgid "" +" - shell: %s\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:235 +msgid "PAM action [auth|acct|setc|chau|open|clos], default: " +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:238 +msgid "PAM service, default: " +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:243 +msgid "Specify user name." +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:250 +#, c-format +msgid "" +"user: %s\n" +"action: %s\n" +"service: %s\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:255 +#, c-format +msgid "User name lookup with [%s] failed.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:260 +#, c-format +msgid "InfoPipe User lookup with [%s] failed.\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:266 +#, c-format +msgid "pam_start failed: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:272 +msgid "" +"testing pam_authenticate\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:276 +#, c-format +msgid "pam_get_item failed: %s\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:279 +#, c-format +msgid "" +"pam_authenticate for user [%s]: %s\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:282 +msgid "" +"testing pam_chauthtok\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:284 +#, c-format +msgid "" +"pam_chauthtok: %s\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:286 +msgid "" +"testing pam_acct_mgmt\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:288 +#, c-format +msgid "" +"pam_acct_mgmt: %s\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:290 +msgid "" +"testing pam_setcred\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:292 +#, c-format +msgid "" +"pam_setcred: [%s]\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:294 +msgid "" +"testing pam_open_session\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:296 +#, c-format +msgid "" +"pam_open_session: %s\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:298 +msgid "" +"testing pam_close_session\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:300 +#, c-format +msgid "" +"pam_close_session: %s\n" +"\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:302 +msgid "unknown action\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:305 +msgid "PAM Environment:\n" +msgstr "" + +#: src/tools/sssctl/sssctl_user_checks.c:313 +msgid " - no env -\n" +msgstr "" + +#: src/util/util.h:100 +msgid "Specify a non-default config file" +msgstr "" + +#: src/util/util.h:107 +msgid "Informs that the responder has been socket-activated" +msgstr "" diff --git a/po/zh_TW.po b/po/zh_TW.po index 732d587337c..c6669579d14 100644 --- a/po/zh_TW.po +++ b/po/zh_TW.po @@ -4,13 +4,14 @@ # # Translators: # hsu zangmen , 2025, 2026. +# Alang Hsu , 2026. msgid "" msgstr "" "Project-Id-Version: PACKAGE VERSION\n" "Report-Msgid-Bugs-To: sssd-devel@lists.fedorahosted.org\n" "POT-Creation-Date: 2026-01-14 14:57+0000\n" -"PO-Revision-Date: 2026-04-23 16:30+0000\n" -"Last-Translator: hsu zangmen \n" +"PO-Revision-Date: 2026-08-01 06:27+0000\n" +"Last-Translator: Alang Hsu \n" "Language-Team: Chinese (Traditional) \n" "Language: zh_TW\n" @@ -18,7 +19,7 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=1; plural=0;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.7.1\n" #: src/config/SSSDConfig/sssdoptions.py:20 #: src/config/SSSDConfig/sssdoptions.py:21 @@ -31,15 +32,15 @@ msgstr "在除錯日誌內加入時間戳記" #: src/config/SSSDConfig/sssdoptions.py:23 msgid "Include microseconds in timestamps in debug logs" -msgstr "" +msgstr "在除錯日誌內的時間戳記中加入微秒" #: src/config/SSSDConfig/sssdoptions.py:24 msgid "Enable/disable debug backtrace" -msgstr "" +msgstr "啟用或停用除錯回溯" #: src/config/SSSDConfig/sssdoptions.py:25 msgid "Watchdog timeout before restarting service" -msgstr "" +msgstr "重新啟動服務前的看門狗逾時" #: src/config/SSSDConfig/sssdoptions.py:26 msgid "Command to start service" @@ -47,19 +48,19 @@ msgstr "啟動服務的指令" #: src/config/SSSDConfig/sssdoptions.py:27 msgid "The number of file descriptors that may be opened by this responder" -msgstr "" +msgstr "此回應器可開啟的檔案描述符數量" #: src/config/SSSDConfig/sssdoptions.py:28 msgid "Idle time before automatic disconnection of a client" -msgstr "" +msgstr "自動中斷用戶端連線前的閒置時間" #: src/config/SSSDConfig/sssdoptions.py:29 msgid "Idle time before automatic shutdown of the responder" -msgstr "" +msgstr "自動關閉回應器前的閒置時間" #: src/config/SSSDConfig/sssdoptions.py:30 msgid "Always query all the caches before querying the Data Providers" -msgstr "" +msgstr "在查詢資料提供者之前,一律先查詢所有快取" #: src/config/SSSDConfig/sssdoptions.py:31 msgid "" @@ -68,6 +69,8 @@ msgid "" "is in seconds and calculated by the following: offline_timeout + " "random_offset." msgstr "" +"當 SSSD 切換到離線模式時,嘗試重新上線前等待的時間會依離線時間長度而增加。此" +"值以秒為單位,計算方式如下:offline_timeout + random_offset。" #: src/config/SSSDConfig/sssdoptions.py:36 msgid "SSSD Services to start" @@ -83,47 +86,49 @@ msgstr "用來解析使用者名稱與網域的正規表示式" #: src/config/SSSDConfig/sssdoptions.py:39 msgid "Printf-compatible format for displaying fully-qualified names" -msgstr "" +msgstr "顯示完整限定名稱的 printf 相容格式" #: src/config/SSSDConfig/sssdoptions.py:40 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." -msgstr "" +msgstr "SSSD 應在檔案系統上儲存 Kerberos 重播快取檔案的目錄。" #: src/config/SSSDConfig/sssdoptions.py:41 msgid "Domain to add to names without a domain component." -msgstr "" +msgstr "要附加到沒有網域部分之名稱上的網域。" #: src/config/SSSDConfig/sssdoptions.py:42 msgid "The user to drop privileges to" -msgstr "" +msgstr "要降低權限至的使用者" #: src/config/SSSDConfig/sssdoptions.py:43 msgid "Tune certificate verification" -msgstr "" +msgstr "調整憑證驗證" #: src/config/SSSDConfig/sssdoptions.py:44 msgid "All spaces in group or user names will be replaced with this character" -msgstr "" +msgstr "群組或使用者名稱中的所有空格將以這個字元取代" #: src/config/SSSDConfig/sssdoptions.py:45 msgid "Tune sssd to honor or ignore netlink state changes" -msgstr "" +msgstr "調整 sssd 以採用或忽略 netlink 狀態變更" #: src/config/SSSDConfig/sssdoptions.py:46 msgid "Enable or disable the implicit files domain" -msgstr "" +msgstr "啟用或停用隱含的 files 網域" #: src/config/SSSDConfig/sssdoptions.py:47 msgid "A specific order of the domains to be looked up" -msgstr "" +msgstr "要查詢的網域之特定順序" #: src/config/SSSDConfig/sssdoptions.py:48 msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" +"控制 SSSD 是否應監控 resolv.conf 的狀態,以判斷何時需要更新其內部的 DNS 解析" +"器。" #: src/config/SSSDConfig/sssdoptions.py:50 msgid "" @@ -132,31 +137,33 @@ msgid "" "this, and will fall back to polling resolv.conf every five seconds if " "inotify cannot be used." msgstr "" +"SSSD 監控 resolv.conf 的狀態,以判斷何時需要更新其內部的 DNS 解析器。預設會嘗" +"試使用 inotify 達成,若無法使用 inotify,則改為每五秒輪詢 resolv.conf。" #: src/config/SSSDConfig/sssdoptions.py:53 msgid "Run PAC responder automatically for AD and IPA provider" -msgstr "" +msgstr "自動為 AD 與 IPA 提供者執行 PAC 回應器" #: src/config/SSSDConfig/sssdoptions.py:54 msgid "Enable or disable core dumps for all SSSD processes." -msgstr "" +msgstr "啟用或停用所有 SSSD 處理程式的核心傾印。" #: src/config/SSSDConfig/sssdoptions.py:55 msgid "Tune passkey verification behavior" -msgstr "" +msgstr "調整金鑰驗證行為" #: src/config/SSSDConfig/sssdoptions.py:58 msgid "Enumeration cache timeout length (seconds)" -msgstr "" +msgstr "列舉快取逾時長度(秒)" #: src/config/SSSDConfig/sssdoptions.py:59 msgid "Entry cache background update timeout length (seconds)" -msgstr "" +msgstr "項目快取背景更新逾時長度(秒)" #: src/config/SSSDConfig/sssdoptions.py:60 #: src/config/SSSDConfig/sssdoptions.py:125 msgid "Negative cache timeout length (seconds)" -msgstr "" +msgstr "負面快取逾時長度(秒)" #: src/config/SSSDConfig/sssdoptions.py:61 msgid "Users that SSSD should explicitly ignore" @@ -172,73 +179,73 @@ msgstr "過濾的使用者是否應該顯現在群組內" #: src/config/SSSDConfig/sssdoptions.py:64 msgid "The value of the password field the NSS provider should return" -msgstr "" +msgstr "NSS 提供者應回傳的密碼欄位值" #: src/config/SSSDConfig/sssdoptions.py:65 msgid "Override homedir value from the identity provider with this value" -msgstr "" +msgstr "使用此值覆寫身分提供者的家目錄值" #: src/config/SSSDConfig/sssdoptions.py:66 msgid "" "Substitute empty homedir value from the identity provider with this value" -msgstr "" +msgstr "使用此值取代身分提供者傳回的空家目錄值" #: src/config/SSSDConfig/sssdoptions.py:67 msgid "Override shell value from the identity provider with this value" -msgstr "" +msgstr "使用此值覆寫身分提供者的 shell 值" #: src/config/SSSDConfig/sssdoptions.py:68 msgid "The list of shells users are allowed to log in with" -msgstr "" +msgstr "允許使用者登入的 shell 清單" #: src/config/SSSDConfig/sssdoptions.py:69 msgid "" "The list of shells that will be vetoed, and replaced with the fallback shell" -msgstr "" +msgstr "將被否決並以後備 shell 取代的 shell 清單" #: src/config/SSSDConfig/sssdoptions.py:70 msgid "" "If a shell stored in central directory is allowed but not available, use " "this fallback" -msgstr "" +msgstr "若中央目錄中儲存的 shell 雖被允許但不可用,則使用此後備" #: src/config/SSSDConfig/sssdoptions.py:71 msgid "Shell to use if the provider does not list one" -msgstr "" +msgstr "提供者未列出 shell 時要使用的 shell" #: src/config/SSSDConfig/sssdoptions.py:72 msgid "How long will be in-memory cache records valid" -msgstr "" +msgstr "記憶體中快取紀錄的有效時間" #: src/config/SSSDConfig/sssdoptions.py:74 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for passwd requests" -msgstr "" +msgstr "為 passwd 請求配置於快速記憶體快取中的資料表大小(百萬位元組)" #: src/config/SSSDConfig/sssdoptions.py:76 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for group requests" -msgstr "" +msgstr "為 group 請求配置於快速記憶體快取中的資料表大小(百萬位元組)" #: src/config/SSSDConfig/sssdoptions.py:78 msgid "" "Size (in megabytes) of the data table allocated inside fast in-memory cache " "for initgroups requests" -msgstr "" +msgstr "為 initgroups 請求配置於快速記憶體快取中的資料表大小(百萬位元組)" #: src/config/SSSDConfig/sssdoptions.py:79 msgid "" "The value of this option will be used in the expansion of the " "override_homedir option if the template contains the format string %H." -msgstr "" +msgstr "若範本包含格式字串 %H,此選項的值將用於展開 override_homedir 選項。" #: src/config/SSSDConfig/sssdoptions.py:81 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." -msgstr "" +msgstr "指定子網域清單被視為有效的時間(秒)。" #: src/config/SSSDConfig/sssdoptions.py:83 msgid "" @@ -246,174 +253,175 @@ msgid "" "if they are requested beyond a percentage of the entry_cache_timeout value " "for the domain." msgstr "" +"若項目在超過網域的 entry_cache_timeout 值一定百分比後仍被請求,可設定項目快取" +"在背景自動更新項目。" #: src/config/SSSDConfig/sssdoptions.py:88 msgid "How long to allow cached logins between online logins (days)" -msgstr "" +msgstr "允許線上登入之間使用快取登入的時間(天)" #: src/config/SSSDConfig/sssdoptions.py:89 msgid "How many failed logins attempts are allowed when offline" -msgstr "" +msgstr "離線時允許的失敗登入嘗試次數" #: src/config/SSSDConfig/sssdoptions.py:91 msgid "" "How long (minutes) to deny login after offline_failed_login_attempts has " "been reached" -msgstr "" +msgstr "達到 offline_failed_login_attempts 之後拒絕登入的時間(分鐘)" #: src/config/SSSDConfig/sssdoptions.py:92 msgid "What kind of messages are displayed to the user during authentication" -msgstr "" +msgstr "認證期間顯示給使用者的訊息類型" #: src/config/SSSDConfig/sssdoptions.py:93 msgid "Filter PAM responses sent to the pam_sss" -msgstr "" +msgstr "過濾傳送給 pam_sss 的 PAM 回應" #: src/config/SSSDConfig/sssdoptions.py:94 msgid "How many seconds to keep identity information cached for PAM requests" -msgstr "" +msgstr "為 PAM 請求快取身分資訊的秒數" #: src/config/SSSDConfig/sssdoptions.py:95 msgid "How many days before password expiration a warning should be displayed" -msgstr "" +msgstr "密碼到期前多少天應顯示警告" #: src/config/SSSDConfig/sssdoptions.py:96 msgid "List of trusted uids or user's name" -msgstr "" +msgstr "受信任的 uid 或使用者名稱的清單" #: src/config/SSSDConfig/sssdoptions.py:97 msgid "List of domains accessible even for untrusted users." -msgstr "" +msgstr "即使未受信任的使用者也能存取的網域清單。" #: src/config/SSSDConfig/sssdoptions.py:98 msgid "Message printed when user account is expired." -msgstr "" +msgstr "使用者帳號到期時顯示的訊息。" #: src/config/SSSDConfig/sssdoptions.py:99 msgid "Message printed when user account is locked." -msgstr "" +msgstr "使用者帳號鎖定時顯示的訊息。" #: src/config/SSSDConfig/sssdoptions.py:100 msgid "Allow certificate based/Smartcard authentication." -msgstr "" +msgstr "允許以憑證/智慧卡進行認證。" #: src/config/SSSDConfig/sssdoptions.py:101 msgid "Path to certificate database with PKCS#11 modules." -msgstr "" +msgstr "含 PKCS#11 模組的憑證資料庫路徑。" #: src/config/SSSDConfig/sssdoptions.py:102 -#, fuzzy msgid "Tune certificate verification for PAM authentication." -msgstr "需要 TLS 憑證驗證" +msgstr "調整 PAM 認證的憑證驗證。" #: src/config/SSSDConfig/sssdoptions.py:103 msgid "How many seconds will pam_sss wait for p11_child to finish" -msgstr "" +msgstr "pam_sss 等待 p11_child 完成的秒數" #: src/config/SSSDConfig/sssdoptions.py:104 msgid "Which PAM services are permitted to contact application domains" -msgstr "" +msgstr "允許哪些 PAM 服務聯絡應用程式網域" #: src/config/SSSDConfig/sssdoptions.py:105 msgid "Allowed services for using smartcards" -msgstr "" +msgstr "允許使用智慧卡的服務" #: src/config/SSSDConfig/sssdoptions.py:106 msgid "Additional timeout to wait for a card if requested" -msgstr "" +msgstr "若有要求,等待卡片就緒的額外逾時" #: src/config/SSSDConfig/sssdoptions.py:107 msgid "" "PKCS#11 URI to restrict the selection of devices for Smartcard authentication" -msgstr "" +msgstr "用於限制智慧卡認證裝置選取的 PKCS#11 URI" #: src/config/SSSDConfig/sssdoptions.py:108 msgid "When shall the PAM responder force an initgroups request" -msgstr "" +msgstr "PAM 回應器應於何時強制發出 initgroups 請求" #: src/config/SSSDConfig/sssdoptions.py:109 msgid "List of PAM services that are allowed to authenticate with GSSAPI." -msgstr "" +msgstr "允許使用 GSSAPI 認證的 PAM 服務清單。" #: src/config/SSSDConfig/sssdoptions.py:110 msgid "Whether to match authenticated UPN with target user" -msgstr "" +msgstr "是否將已認證的 UPN 與目標使用者比對" #: src/config/SSSDConfig/sssdoptions.py:111 msgid "" "List of pairs : that must be enforced " "for PAM access with GSSAPI authentication" -msgstr "" +msgstr "使用 GSSAPI 認證的 PAM 存取必須強制執行的 :<認證指示器> 配對清單" #: src/config/SSSDConfig/sssdoptions.py:113 msgid "Allow passkey device authentication." -msgstr "" +msgstr "允許金鑰裝置認證。" #: src/config/SSSDConfig/sssdoptions.py:114 msgid "How many seconds will pam_sss wait for passkey_child to finish" -msgstr "" +msgstr "pam_sss 等待 passkey_child 完成的秒數" #: src/config/SSSDConfig/sssdoptions.py:115 msgid "Enable debugging in the libfido2 library" -msgstr "" +msgstr "在 libfido2 函式庫中啟用除錯" #: src/config/SSSDConfig/sssdoptions.py:116 msgid "Enable JSON protocol for authentication methods selection." -msgstr "" +msgstr "啟用 JSON 協定以選取認證方法。" #: src/config/SSSDConfig/sssdoptions.py:119 msgid "Whether to evaluate the time-based attributes in sudo rules" -msgstr "" +msgstr "是否評估 sudo 規則中與時間相關的屬性" #: src/config/SSSDConfig/sssdoptions.py:120 msgid "If true, SSSD will switch back to lower-wins ordering logic" -msgstr "" +msgstr "若為 true,SSSD 將切回較低優先順序得勝的排序邏輯" #: src/config/SSSDConfig/sssdoptions.py:121 msgid "" "Maximum number of rules that can be refreshed at once. If this is exceeded, " "full refresh is performed." -msgstr "" +msgstr "一次可重新整理的規則數上限。若超過此數,將執行完整重新整理。" #: src/config/SSSDConfig/sssdoptions.py:128 msgid "Whether to hash host names and addresses in the known_hosts file" -msgstr "" +msgstr "是否對 known_hosts 檔案中的主機名稱與位址進行雜湊" #: src/config/SSSDConfig/sssdoptions.py:129 msgid "" "How many seconds to keep a host in the known_hosts file after its host keys " "were requested" -msgstr "" +msgstr "主機金鑰被請求之後,主機保留在 known_hosts 檔案中的秒數" #: src/config/SSSDConfig/sssdoptions.py:131 msgid "Path to storage of trusted CA certificates" -msgstr "" +msgstr "受信任 CA 憑證儲存的路徑" #: src/config/SSSDConfig/sssdoptions.py:132 msgid "Allow to generate ssh-keys from certificates" -msgstr "" +msgstr "允許從憑證產生 ssh 金鑰" #: src/config/SSSDConfig/sssdoptions.py:133 msgid "" "Use the following matching rules to filter the certificates for ssh-key " "generation" -msgstr "" +msgstr "使用下列比對規則篩選用於產生 ssh 金鑰的憑證" #: src/config/SSSDConfig/sssdoptions.py:137 msgid "List of UIDs or user names allowed to access the PAC responder" -msgstr "" +msgstr "允許存取 PAC 回應器的 UID 或使用者名稱清單" #: src/config/SSSDConfig/sssdoptions.py:138 msgid "How long the PAC data is considered valid" -msgstr "" +msgstr "PAC 資料被視為有效的時間" #: src/config/SSSDConfig/sssdoptions.py:139 msgid "Validate the PAC" -msgstr "" +msgstr "驗證 PAC" #: src/config/SSSDConfig/sssdoptions.py:142 msgid "List of user attributes the InfoPipe is allowed to publish" -msgstr "" +msgstr "允許 InfoPipe 發布的使用者屬性清單" #: src/config/SSSDConfig/sssdoptions.py:145 msgid "" @@ -421,6 +429,8 @@ msgid "" "- No users are recorded. some - Users/groups specified by users and groups " "options are recorded. all - All users are recorded." msgstr "" +"下列字串之一,指定工作階段錄製的範圍:none - 不錄製任何使用者。some - 錄製 " +"users 與 groups 選項指定的使用者/群組。all - 錄製所有使用者。" #: src/config/SSSDConfig/sssdoptions.py:148 msgid "" @@ -428,6 +438,8 @@ msgid "" "Matches user names as returned by NSS. I.e. after the possible space " "replacement, case changes, etc." msgstr "" +"應啟用工作階段錄製的使用者清單,以逗號分隔。比對 NSS 回傳的使用者名稱,亦即經" +"過可能的空格取代、大小寫變更等處理之後的名稱。" #: src/config/SSSDConfig/sssdoptions.py:150 msgid "" @@ -435,18 +447,20 @@ msgid "" "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" +"成員應啟用工作階段錄製的群組清單,以逗號分隔。比對 NSS 回傳的群組名稱,亦即經" +"過可能的空格取代、大小寫變更等處理之後的名稱。" #: src/config/SSSDConfig/sssdoptions.py:153 msgid "" "A comma-separated list of users to be excluded from recording, only when " "scope=all" -msgstr "" +msgstr "要排除於錄製之外的使用者清單,以逗號分隔,僅在 scope=all 時生效" #: src/config/SSSDConfig/sssdoptions.py:154 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording, only when scope=all. " -msgstr "" +msgstr "成員應排除於錄製之外的群組清單,以逗號分隔,僅在 scope=all 時生效。 " #: src/config/SSSDConfig/sssdoptions.py:158 msgid "Identity provider" @@ -466,36 +480,35 @@ msgstr "密碼變更提供者" #: src/config/SSSDConfig/sssdoptions.py:162 msgid "SUDO provider" -msgstr "" +msgstr "SUDO 提供者" #: src/config/SSSDConfig/sssdoptions.py:163 msgid "Autofs provider" -msgstr "" +msgstr "Autofs 提供者" #: src/config/SSSDConfig/sssdoptions.py:164 msgid "Host identity provider" -msgstr "" +msgstr "主機身分提供者" #: src/config/SSSDConfig/sssdoptions.py:165 msgid "SELinux provider" -msgstr "" +msgstr "SELinux 提供者" #: src/config/SSSDConfig/sssdoptions.py:166 msgid "Session management provider" -msgstr "" +msgstr "工作階段管理提供者" #: src/config/SSSDConfig/sssdoptions.py:167 msgid "Resolver provider" -msgstr "" +msgstr "解析器提供者" #: src/config/SSSDConfig/sssdoptions.py:170 msgid "Whether the domain is usable by the OS or by applications" -msgstr "" +msgstr "此網域是否可供作業系統或應用程式使用" #: src/config/SSSDConfig/sssdoptions.py:171 -#, fuzzy msgid "Enable or disable the domain" -msgstr "啟用憑證驗證" +msgstr "啟用或停用此網域" #: src/config/SSSDConfig/sssdoptions.py:172 msgid "Minimum user ID" @@ -515,11 +528,11 @@ msgstr "供離線登入使用的快取憑證" #: src/config/SSSDConfig/sssdoptions.py:176 msgid "Display users/groups in fully-qualified form" -msgstr "" +msgstr "以完整限定形式顯示使用者/群組" #: src/config/SSSDConfig/sssdoptions.py:177 msgid "Don't include group members in group lookups" -msgstr "" +msgstr "在群組查詢中不包含群組成員" #: src/config/SSSDConfig/sssdoptions.py:178 #: src/config/SSSDConfig/sssdoptions.py:190 @@ -530,34 +543,34 @@ msgstr "" #: src/config/SSSDConfig/sssdoptions.py:195 #: src/config/SSSDConfig/sssdoptions.py:196 msgid "Entry cache timeout length (seconds)" -msgstr "" +msgstr "項目快取逾時長度(秒)" #: src/config/SSSDConfig/sssdoptions.py:179 msgid "" "Restrict or prefer a specific address family when performing DNS lookups" -msgstr "" +msgstr "執行 DNS 查詢時限制或偏好特定的位址家族" #: src/config/SSSDConfig/sssdoptions.py:180 msgid "How long to keep cached entries after last successful login (days)" -msgstr "" +msgstr "最後一次成功登入後保留快取項目的時間(天)" #: src/config/SSSDConfig/sssdoptions.py:181 msgid "" "How long should SSSD talk to single DNS server before trying next server " "(miliseconds)" -msgstr "" +msgstr "SSSD 嘗試下一台伺服器前,與單一 DNS 伺服器通訊的時間(毫秒)" #: src/config/SSSDConfig/sssdoptions.py:183 msgid "How long should keep trying to resolve single DNS query (seconds)" -msgstr "" +msgstr "持續嘗試解析單一 DNS 查詢的時間(秒)" #: src/config/SSSDConfig/sssdoptions.py:184 msgid "How long to wait for replies from DNS when resolving servers (seconds)" -msgstr "" +msgstr "解析伺服器時等待 DNS 回覆的時間(秒)" #: src/config/SSSDConfig/sssdoptions.py:185 msgid "The domain part of service discovery DNS query" -msgstr "" +msgstr "服務探索 DNS 查詢的網域部分" #: src/config/SSSDConfig/sssdoptions.py:186 msgid "" @@ -565,126 +578,127 @@ msgid "" "reconnect to the primary server after a successful connection to the backup " "server" msgstr "" +"指定 SSSD 在成功連線到備份伺服器後,嘗試重新連線到主要伺服器前等待的間隔(秒" +")" #: src/config/SSSDConfig/sssdoptions.py:188 msgid "Override GID value from the identity provider with this value" -msgstr "" +msgstr "使用此值覆寫身分提供者的 GID 值" #: src/config/SSSDConfig/sssdoptions.py:189 msgid "Treat usernames as case sensitive" -msgstr "" +msgstr "將使用者名稱視為區分大小寫" #: src/config/SSSDConfig/sssdoptions.py:197 msgid "How often should expired entries be refreshed in background" -msgstr "" +msgstr "過期項目在背景重新整理的頻率" #: src/config/SSSDConfig/sssdoptions.py:198 msgid "Maximum period deviation when refreshing expired entries in background" -msgstr "" +msgstr "在背景重新整理過期項目時的最大時間偏差" #: src/config/SSSDConfig/sssdoptions.py:199 msgid "Whether to automatically update the client's DNS entry" -msgstr "" +msgstr "是否自動更新用戶端的 DNS 記錄" #: src/config/SSSDConfig/sssdoptions.py:200 msgid "" "Whether DNS update of A and AAAA record should be performed in one update or " "in two separate updates" -msgstr "" +msgstr "A 與 AAAA 記錄的 DNS 更新應在一次更新中執行,還是分兩次更新執行" #: src/config/SSSDConfig/sssdoptions.py:202 msgid "The TTL to apply to the client's DNS entry after updating it" -msgstr "" +msgstr "更新後套用於用戶端 DNS 記錄的 TTL" #: src/config/SSSDConfig/sssdoptions.py:203 msgid "The interface whose IP should be used for dynamic DNS updates" -msgstr "" +msgstr "動態 DNS 更新應使用其 IP 的網路介面" #: src/config/SSSDConfig/sssdoptions.py:204 msgid "The list of IP addresses that should be used for dynamic DNS updates" -msgstr "" +msgstr "動態 DNS 更新應使用的 IP 位址清單" #: src/config/SSSDConfig/sssdoptions.py:205 msgid "How often to periodically update the client's DNS entry" -msgstr "" +msgstr "定期更新用戶端 DNS 記錄的頻率" #: src/config/SSSDConfig/sssdoptions.py:206 msgid "Maximum period deviation when updating the client's DNS entry" -msgstr "" +msgstr "更新用戶端 DNS 記錄時的最大時間偏差" #: src/config/SSSDConfig/sssdoptions.py:207 msgid "Whether the provider should explicitly update the PTR record as well" -msgstr "" +msgstr "提供者是否也應明確更新 PTR 記錄" #: src/config/SSSDConfig/sssdoptions.py:208 msgid "Whether the nsupdate utility should default to using TCP" -msgstr "" +msgstr "nsupdate 工具是否應預設使用 TCP" #: src/config/SSSDConfig/sssdoptions.py:209 msgid "What kind of authentication should be used to perform the DNS update" -msgstr "" +msgstr "執行 DNS 更新應使用哪種認證" #: src/config/SSSDConfig/sssdoptions.py:210 msgid "Override the DNS server used to perform the DNS update" -msgstr "" +msgstr "覆寫用於執行 DNS 更新的 DNS 伺服器" #: src/config/SSSDConfig/sssdoptions.py:211 msgid "The file of the certificate authorities certificates for DoT" -msgstr "" +msgstr "DoT 的憑證授權機構憑證檔案" #: src/config/SSSDConfig/sssdoptions.py:212 -#, fuzzy msgid "The certificate(s) file for authentication for the DoT transport" -msgstr "需要 TLS 憑證驗證" +msgstr "用於 DoT 傳輸認證的憑證檔案" #: src/config/SSSDConfig/sssdoptions.py:213 msgid "The key file for authenticated encryption for the DoT transport" -msgstr "" +msgstr "用於 DoT 傳輸驗證加密的金鑰檔案" #: src/config/SSSDConfig/sssdoptions.py:214 msgid "How often should subdomains list be refreshed" -msgstr "" +msgstr "子網域清單重新整理的頻率" #: src/config/SSSDConfig/sssdoptions.py:215 msgid "Maximum period deviation when refreshing the subdomain list" -msgstr "" +msgstr "重新整理子網域清單時的最大時間偏差" #: src/config/SSSDConfig/sssdoptions.py:216 msgid "List of options that should be inherited into a subdomain" -msgstr "" +msgstr "應繼承到子網域的選項清單" #: src/config/SSSDConfig/sssdoptions.py:217 msgid "Default subdomain homedir value" -msgstr "" +msgstr "預設的子網域家目錄值" #: src/config/SSSDConfig/sssdoptions.py:218 msgid "How long can cached credentials be used for cached authentication" -msgstr "" +msgstr "快取認證可使用快取憑證的時間" #: src/config/SSSDConfig/sssdoptions.py:219 msgid "Whether to automatically create private groups for users" -msgstr "" +msgstr "是否自動為使用者建立私有群組" #: src/config/SSSDConfig/sssdoptions.py:220 msgid "Display a warning N days before the password expires." -msgstr "" +msgstr "在密碼到期前 N 天顯示警告。" #: src/config/SSSDConfig/sssdoptions.py:221 msgid "" "Various tags stored by the realmd configuration service for this domain." -msgstr "" +msgstr "realmd 設定服務為此網域儲存的各種標籤。" #: src/config/SSSDConfig/sssdoptions.py:222 msgid "" "The provider which should handle fetching of subdomains. This value should " "be always the same as id_provider." -msgstr "" +msgstr "應負責取得子網域的提供者。此值應永遠與 id_provider 相同。" #: src/config/SSSDConfig/sssdoptions.py:224 msgid "" "How many seconds to keep a host ssh key after refresh. IE how long to cache " "the host key for." -msgstr "" +msgstr "重新整理後保留主機 ssh 金鑰的秒數。亦即主機金鑰的快取時間。" #: src/config/SSSDConfig/sssdoptions.py:226 msgid "" @@ -692,10 +706,12 @@ msgid "" "this value determines the minimal length the first authentication factor " "(long term password) must have to be saved as SHA512 hash into the cache." msgstr "" +"若使用雙因素認證 (2FA) 且應儲存憑證,此值決定第一個認證因素(長期密碼)要存入" +"快取作為 SHA512 雜湊所需的最短長度。" #: src/config/SSSDConfig/sssdoptions.py:230 msgid "Local authentication methods policy " -msgstr "" +msgstr "本機認證方法原則 " #: src/config/SSSDConfig/sssdoptions.py:233 msgid "IPA domain" @@ -707,7 +723,7 @@ msgstr "IPA 伺服器位址" #: src/config/SSSDConfig/sssdoptions.py:235 msgid "Address of backup IPA server" -msgstr "" +msgstr "備份 IPA 伺服器的位址" #: src/config/SSSDConfig/sssdoptions.py:236 msgid "IPA client hostname" @@ -715,305 +731,309 @@ msgstr "IPA 客戶端主機名稱" #: src/config/SSSDConfig/sssdoptions.py:237 msgid "Search base for HBAC related objects" -msgstr "" +msgstr "HBAC 相關物件的搜尋基準" #: src/config/SSSDConfig/sssdoptions.py:238 msgid "" "The amount of time between lookups of the HBAC rules against the IPA server" -msgstr "" +msgstr "向 IPA 伺服器查詢 HBAC 規則之間的間隔時間" #: src/config/SSSDConfig/sssdoptions.py:239 msgid "" "The amount of time in seconds between lookups of the SELinux maps against " "the IPA server" -msgstr "" +msgstr "向 IPA 伺服器查詢 SELinux 對應之間的間隔時間(秒)" #: src/config/SSSDConfig/sssdoptions.py:241 msgid "If set to false, host argument given by PAM will be ignored" -msgstr "" +msgstr "若設為 false,將忽略 PAM 提供的主機引數" #: src/config/SSSDConfig/sssdoptions.py:242 msgid "The automounter location this IPA client is using" -msgstr "" +msgstr "此 IPA 用戶端正在使用的自動掛載位置" #: src/config/SSSDConfig/sssdoptions.py:243 msgid "Search base for object containing info about IPA domain" -msgstr "" +msgstr "包含 IPA 網域資訊之物件的搜尋基準" #: src/config/SSSDConfig/sssdoptions.py:244 msgid "Search base for objects containing info about ID ranges" -msgstr "" +msgstr "包含 ID 範圍資訊之物件的搜尋基準" #: src/config/SSSDConfig/sssdoptions.py:245 msgid "Search base for view containers" -msgstr "" +msgstr "檢視容器的搜尋基準" #: src/config/SSSDConfig/sssdoptions.py:246 msgid "Objectclass for view containers" -msgstr "" +msgstr "檢視容器的物件類別" #: src/config/SSSDConfig/sssdoptions.py:247 msgid "Attribute with the name of the view" -msgstr "" +msgstr "包含檢視名稱的屬性" #: src/config/SSSDConfig/sssdoptions.py:248 msgid "Objectclass for override objects" -msgstr "" +msgstr "覆寫物件的物件類別" #: src/config/SSSDConfig/sssdoptions.py:249 msgid "Attribute with the reference to the original object" -msgstr "" +msgstr "包含原始物件參照的屬性" #: src/config/SSSDConfig/sssdoptions.py:250 msgid "Objectclass for user override objects" -msgstr "" +msgstr "使用者覆寫物件的物件類別" #: src/config/SSSDConfig/sssdoptions.py:251 msgid "Objectclass for group override objects" -msgstr "" +msgstr "群組覆寫物件的物件類別" #: src/config/SSSDConfig/sssdoptions.py:252 msgid "Search base for Desktop Profile related objects" -msgstr "" +msgstr "桌面設定檔相關物件的搜尋基準" #: src/config/SSSDConfig/sssdoptions.py:253 msgid "" "The amount of time in seconds between lookups of the Desktop Profile rules " "against the IPA server" -msgstr "" +msgstr "向 IPA 伺服器查詢桌面設定檔規則之間的間隔時間(秒)" #: src/config/SSSDConfig/sssdoptions.py:255 msgid "" "The amount of time in minutes between lookups of Desktop Profiles rules " "against the IPA server when the last request did not find any rule" msgstr "" +"當最後一次請求未找到任何規則時,向 IPA 伺服器查詢桌面設定檔規則之間的間隔時間" +"(分鐘)" #: src/config/SSSDConfig/sssdoptions.py:258 #: src/config/SSSDConfig/sssdoptions.py:455 msgid "Search base for SUBID ranges" -msgstr "" +msgstr "SUBID 範圍的搜尋基準" #: src/config/SSSDConfig/sssdoptions.py:259 #: src/config/SSSDConfig/sssdoptions.py:506 msgid "Which rules should be used to evaluate access control" -msgstr "" +msgstr "應用哪些規則評估存取控制" #: src/config/SSSDConfig/sssdoptions.py:260 msgid "The LDAP attribute that contains FQDN of the host." -msgstr "" +msgstr "包含主機 FQDN 的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:261 #: src/config/SSSDConfig/sssdoptions.py:284 msgid "The object class of a host entry in LDAP." -msgstr "" +msgstr "LDAP 中主機項目的物件類別。" #: src/config/SSSDConfig/sssdoptions.py:262 msgid "Use the given string as search base for host objects." -msgstr "" +msgstr "使用給定的字串作為主機物件的搜尋基準。" #: src/config/SSSDConfig/sssdoptions.py:263 msgid "The LDAP attribute that contains the host's SSH public keys." -msgstr "" +msgstr "包含主機 SSH 公開金鑰的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:264 msgid "The LDAP attribute that contains NIS domain name of the netgroup." -msgstr "" +msgstr "包含網路群組之 NIS 網域名稱的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:265 msgid "The LDAP attribute that contains the names of the netgroup's members." -msgstr "" +msgstr "包含網路群組成員名稱的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:266 msgid "" "The LDAP attribute that lists FQDNs of hosts and host groups that are " "members of the netgroup." -msgstr "" +msgstr "列出為網路群組成員之主機與主機群組 FQDN 的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:268 msgid "" "The LDAP attribute that lists hosts and host groups that are direct members " "of the netgroup." -msgstr "" +msgstr "列出為網路群組直接成員之主機與主機群組的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:270 msgid "The LDAP attribute that lists netgroup's memberships." -msgstr "" +msgstr "列出網路群組成員身分的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:271 msgid "" "The LDAP attribute that lists system users and groups that are direct " "members of the netgroup." -msgstr "" +msgstr "列出為網路群組直接成員之系統使用者與群組的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:273 msgid "The LDAP attribute that corresponds to the netgroup name." -msgstr "" +msgstr "對應網路群組名稱的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:274 msgid "The object class of a netgroup entry in LDAP." -msgstr "" +msgstr "LDAP 中網路群組項目的物件類別。" #: src/config/SSSDConfig/sssdoptions.py:275 msgid "" "The LDAP attribute that contains the UUID/GUID of an LDAP netgroup object." -msgstr "" +msgstr "包含 LDAP 網路群組物件之 UUID/GUID 的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:276 msgid "" "The LDAP attribute that contains whether or not is user map enabled for " "usage." -msgstr "" +msgstr "包含使用者對應是否已啟用供使用的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:278 msgid "The LDAP attribute that contains host category such as 'all'." -msgstr "" +msgstr "包含主機類別(如 'all')的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:279 msgid "" "The LDAP attribute that contains all hosts / hostgroups this rule match " "against." -msgstr "" +msgstr "包含此規則比對之所有主機/主機群組的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:281 msgid "" "The LDAP attribute that contains all users / groups this rule match against." -msgstr "" +msgstr "包含此規則比對之所有使用者/群組的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:283 msgid "The LDAP attribute that contains the name of SELinux usermap." -msgstr "" +msgstr "包含 SELinux 使用者對應名稱的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:285 msgid "" "The LDAP attribute that contains DN of HBAC rule which can be used for " "matching instead of memberUser and memberHost." -msgstr "" +msgstr "包含 HBAC 規則 DN 的 LDAP 屬性,可代替 memberUser 與 memberHost 用於比對。" #: src/config/SSSDConfig/sssdoptions.py:287 msgid "The LDAP attribute that contains SELinux user string itself." -msgstr "" +msgstr "包含 SELinux 使用者字串本身的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:288 msgid "The LDAP attribute that contains user category such as 'all'." -msgstr "" +msgstr "包含使用者類別(如 'all')的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:289 msgid "The LDAP attribute that contains unique ID of the user map." -msgstr "" +msgstr "包含使用者對應唯一 ID 的 LDAP 屬性。" #: src/config/SSSDConfig/sssdoptions.py:290 msgid "" "The option denotes that the SSSD is running on IPA server and should perform " "lookups of users and groups from trusted domains differently." msgstr "" +"此選項表示 SSSD 正在 IPA 伺服器上執行,且應以不同方式查詢來自受信任網域的使用" +"者與群組。" #: src/config/SSSDConfig/sssdoptions.py:292 msgid "Use the given string as search base for trusted domains." -msgstr "" +msgstr "使用給定的字串作為受信任網域的搜尋基準。" #: src/config/SSSDConfig/sssdoptions.py:295 msgid "Active Directory domain" -msgstr "" +msgstr "Active Directory 網域" #: src/config/SSSDConfig/sssdoptions.py:296 msgid "Enabled Active Directory domains" -msgstr "" +msgstr "已啟用的 Active Directory 網域" #: src/config/SSSDConfig/sssdoptions.py:297 msgid "Active Directory server address" -msgstr "" +msgstr "Active Directory 伺服器位址" #: src/config/SSSDConfig/sssdoptions.py:298 msgid "Active Directory backup server address" -msgstr "" +msgstr "Active Directory 備份伺服器位址" #: src/config/SSSDConfig/sssdoptions.py:299 msgid "Active Directory client hostname" -msgstr "" +msgstr "Active Directory 用戶端主機名稱" #: src/config/SSSDConfig/sssdoptions.py:300 msgid "Enable DNS sites - location based service discovery" -msgstr "" +msgstr "啟用 DNS 站台 - 以位置為基礎的服務探索" #: src/config/SSSDConfig/sssdoptions.py:301 #: src/config/SSSDConfig/sssdoptions.py:504 msgid "LDAP filter to determine access privileges" -msgstr "" +msgstr "判斷存取權限的 LDAP 篩選器" #: src/config/SSSDConfig/sssdoptions.py:302 msgid "Whether to use the Global Catalog for lookups" -msgstr "" +msgstr "查詢時是否使用全域目錄" #: src/config/SSSDConfig/sssdoptions.py:303 msgid "Operation mode for GPO-based access control" -msgstr "" +msgstr "以 GPO 為基礎之存取控制的作業模式" #: src/config/SSSDConfig/sssdoptions.py:304 msgid "" "The amount of time between lookups of the GPO policy files against the AD " "server" -msgstr "" +msgstr "向 AD 伺服器查詢 GPO 原則檔案之間的間隔時間" #: src/config/SSSDConfig/sssdoptions.py:305 msgid "" "PAM service names that map to the GPO (Deny)InteractiveLogonRight policy " "settings" -msgstr "" +msgstr "對應到 GPO (Deny)InteractiveLogonRight 原則設定的 PAM 服務名稱" #: src/config/SSSDConfig/sssdoptions.py:307 msgid "" "PAM service names that map to the GPO (Deny)RemoteInteractiveLogonRight " "policy settings" -msgstr "" +msgstr "對應到 GPO (Deny)RemoteInteractiveLogonRight 原則設定的 PAM 服務名稱" #: src/config/SSSDConfig/sssdoptions.py:309 msgid "" "PAM service names that map to the GPO (Deny)NetworkLogonRight policy settings" -msgstr "" +msgstr "對應到 GPO (Deny)NetworkLogonRight 原則設定的 PAM 服務名稱" #: src/config/SSSDConfig/sssdoptions.py:310 msgid "" "PAM service names that map to the GPO (Deny)BatchLogonRight policy settings" -msgstr "" +msgstr "對應到 GPO (Deny)BatchLogonRight 原則設定的 PAM 服務名稱" #: src/config/SSSDConfig/sssdoptions.py:311 msgid "" "PAM service names that map to the GPO (Deny)ServiceLogonRight policy settings" -msgstr "" +msgstr "對應到 GPO (Deny)ServiceLogonRight 原則設定的 PAM 服務名稱" #: src/config/SSSDConfig/sssdoptions.py:312 msgid "PAM service names for which GPO-based access is always granted" -msgstr "" +msgstr "一律允許以 GPO 為基礎之存取的 PAM 服務名稱" #: src/config/SSSDConfig/sssdoptions.py:313 msgid "PAM service names for which GPO-based access is always denied" -msgstr "" +msgstr "一律拒絕以 GPO 為基礎之存取的 PAM 服務名稱" #: src/config/SSSDConfig/sssdoptions.py:314 msgid "" "Default logon right (or permit/deny) to use for unmapped PAM service names" -msgstr "" +msgstr "未對應 PAM 服務名稱使用的預設登入權限(或允許/拒絕)" #: src/config/SSSDConfig/sssdoptions.py:315 msgid "a particular site to be used by the client" -msgstr "" +msgstr "用戶端要使用的特定站台" #: src/config/SSSDConfig/sssdoptions.py:316 msgid "" "Maximum age in days before the machine account password should be renewed" -msgstr "" +msgstr "機器帳號密碼應更新前的最大天數" #: src/config/SSSDConfig/sssdoptions.py:318 msgid "Option for tuning the machine account renewal task" -msgstr "" +msgstr "調整機器帳號更新工作的選項" #: src/config/SSSDConfig/sssdoptions.py:319 msgid "Whether to update the machine account password in the Samba database" -msgstr "" +msgstr "是否在 Samba 資料庫中更新機器帳號密碼" #: src/config/SSSDConfig/sssdoptions.py:321 msgid "Use LDAPS port for LDAP and Global Catalog requests" -msgstr "" +msgstr "對 LDAP 與全域目錄請求使用 LDAPS 連接埠" #: src/config/SSSDConfig/sssdoptions.py:324 #: src/config/SSSDConfig/sssdoptions.py:325 @@ -1022,11 +1042,11 @@ msgstr "Kerberos 伺服器位址" #: src/config/SSSDConfig/sssdoptions.py:326 msgid "Kerberos backup server address" -msgstr "" +msgstr "Kerberos 備份伺服器位址" #: src/config/SSSDConfig/sssdoptions.py:327 msgid "Kerberos realm" -msgstr "" +msgstr "Kerberos 領域" #: src/config/SSSDConfig/sssdoptions.py:328 msgid "Authentication timeout" @@ -1034,11 +1054,11 @@ msgstr "認證逾時" #: src/config/SSSDConfig/sssdoptions.py:329 msgid "Whether to create kdcinfo files" -msgstr "" +msgstr "是否建立 kdcinfo 檔案" #: src/config/SSSDConfig/sssdoptions.py:330 msgid "Where to drop krb5 config snippets" -msgstr "" +msgstr "放置 krb5 設定片段的位置" #: src/config/SSSDConfig/sssdoptions.py:333 msgid "Directory to store credential caches" @@ -1058,124 +1078,124 @@ msgstr "啟用憑證驗證" #: src/config/SSSDConfig/sssdoptions.py:337 msgid "Store password if offline for later online authentication" -msgstr "" +msgstr "離線時儲存密碼以供日後線上認證" #: src/config/SSSDConfig/sssdoptions.py:338 msgid "Renewable lifetime of the TGT" -msgstr "" +msgstr "TGT 的可續期存續時間" #: src/config/SSSDConfig/sssdoptions.py:339 msgid "Lifetime of the TGT" -msgstr "" +msgstr "TGT 的存續時間" #: src/config/SSSDConfig/sssdoptions.py:340 msgid "Time between two checks for renewal" -msgstr "" +msgstr "兩次續期檢查之間的間隔時間" #: src/config/SSSDConfig/sssdoptions.py:341 msgid "Enables FAST" -msgstr "" +msgstr "啟用 FAST" #: src/config/SSSDConfig/sssdoptions.py:342 msgid "Selects the principal to use for FAST" -msgstr "" +msgstr "選取 FAST 使用的 principal" #: src/config/SSSDConfig/sssdoptions.py:343 msgid "Use anonymous PKINIT to request FAST credentials" -msgstr "" +msgstr "使用匿名 PKINIT 請求 FAST 憑證" #: src/config/SSSDConfig/sssdoptions.py:344 msgid "Enables principal canonicalization" -msgstr "" +msgstr "啟用 principal 正規化" #: src/config/SSSDConfig/sssdoptions.py:345 msgid "Enables enterprise principals" -msgstr "" +msgstr "啟用企業 principal" #: src/config/SSSDConfig/sssdoptions.py:346 msgid "Enables using of subdomains realms for authentication" -msgstr "" +msgstr "啟用使用子網域領域進行認證" #: src/config/SSSDConfig/sssdoptions.py:347 msgid "A mapping from user names to Kerberos principal names" -msgstr "" +msgstr "從使用者名稱到 Kerberos principal 名稱的對應" #: src/config/SSSDConfig/sssdoptions.py:350 #: src/config/SSSDConfig/sssdoptions.py:351 msgid "Server where the change password service is running if not on the KDC" -msgstr "" +msgstr "變更密碼服務執行所在的伺服器(若非位於 KDC 上)" #: src/config/SSSDConfig/sssdoptions.py:354 msgid "ldap_uri, The URI of the LDAP server" -msgstr "" +msgstr "ldap_uri:LDAP 伺服器的 URI" #: src/config/SSSDConfig/sssdoptions.py:355 msgid "ldap_backup_uri, The URI of the LDAP server" -msgstr "" +msgstr "ldap_backup_uri:LDAP 伺服器的 URI" #: src/config/SSSDConfig/sssdoptions.py:356 msgid "The default base DN" -msgstr "" +msgstr "預設的基準 DN" #: src/config/SSSDConfig/sssdoptions.py:357 msgid "How to read rootDSE from LDAP server" -msgstr "" +msgstr "如何從 LDAP 伺服器讀取 rootDSE" #: src/config/SSSDConfig/sssdoptions.py:358 msgid "The Schema Type in use on the LDAP server, rfc2307" -msgstr "" +msgstr "LDAP 伺服器使用的架構類型 rfc2307" #: src/config/SSSDConfig/sssdoptions.py:359 msgid "Mode used to change user password" -msgstr "" +msgstr "變更使用者密碼使用的模式" #: src/config/SSSDConfig/sssdoptions.py:360 msgid "The default bind DN" -msgstr "" +msgstr "預設的 bind DN" #: src/config/SSSDConfig/sssdoptions.py:361 msgid "The type of the authentication token of the default bind DN" -msgstr "" +msgstr "預設 bind DN 的認證權杖類型" #: src/config/SSSDConfig/sssdoptions.py:362 msgid "The authentication token of the default bind DN" -msgstr "" +msgstr "預設 bind DN 的認證權杖" #: src/config/SSSDConfig/sssdoptions.py:363 msgid "Length of time to attempt connection" -msgstr "" +msgstr "嘗試連線的時間長度" #: src/config/SSSDConfig/sssdoptions.py:364 msgid "Length of time to attempt synchronous LDAP operations" -msgstr "" +msgstr "嘗試同步 LDAP 作業的時間長度" #: src/config/SSSDConfig/sssdoptions.py:365 msgid "Length of time between attempts to reconnect while offline" -msgstr "" +msgstr "離線時嘗試重新連線的間隔時間" #: src/config/SSSDConfig/sssdoptions.py:366 msgid "Use only the upper case for realm names" -msgstr "" +msgstr "領域名稱僅使用大寫" #: src/config/SSSDConfig/sssdoptions.py:367 msgid "File that contains CA certificates" -msgstr "" +msgstr "包含 CA 憑證的檔案" #: src/config/SSSDConfig/sssdoptions.py:368 msgid "Path to CA certificate directory" -msgstr "" +msgstr "CA 憑證目錄的路徑" #: src/config/SSSDConfig/sssdoptions.py:369 msgid "File that contains the client certificate" -msgstr "" +msgstr "包含用戶端憑證的檔案" #: src/config/SSSDConfig/sssdoptions.py:370 msgid "File that contains the client key" -msgstr "" +msgstr "包含用戶端金鑰的檔案" #: src/config/SSSDConfig/sssdoptions.py:371 msgid "List of possible ciphers suites" -msgstr "" +msgstr "可能的加密套件清單" #: src/config/SSSDConfig/sssdoptions.py:372 msgid "Require TLS certificate verification" @@ -1191,93 +1211,93 @@ msgstr "指定要使用的 sasl 認證 id" #: src/config/SSSDConfig/sssdoptions.py:375 msgid "Specify the sasl authorization realm to use" -msgstr "" +msgstr "指定要使用的 sasl 授權領域" #: src/config/SSSDConfig/sssdoptions.py:376 msgid "Specify the minimal SSF for LDAP sasl authorization" -msgstr "" +msgstr "指定 LDAP sasl 授權的最低 SSF" #: src/config/SSSDConfig/sssdoptions.py:377 msgid "Specify the maximal SSF for LDAP sasl authorization" -msgstr "" +msgstr "指定 LDAP sasl 授權的最高 SSF" #: src/config/SSSDConfig/sssdoptions.py:378 msgid "Kerberos service keytab" -msgstr "" +msgstr "Kerberos 服務 keytab" #: src/config/SSSDConfig/sssdoptions.py:379 msgid "Use Kerberos auth for LDAP connection" -msgstr "" +msgstr "LDAP 連線使用 Kerberos 認證" #: src/config/SSSDConfig/sssdoptions.py:380 msgid "Follow LDAP referrals" -msgstr "" +msgstr "追蹤 LDAP 轉介" #: src/config/SSSDConfig/sssdoptions.py:381 msgid "Lifetime of TGT for LDAP connection" -msgstr "" +msgstr "LDAP 連線的 TGT 存續時間" #: src/config/SSSDConfig/sssdoptions.py:382 msgid "How to dereference aliases" -msgstr "" +msgstr "如何解除別名參照" #: src/config/SSSDConfig/sssdoptions.py:383 msgid "Service name for DNS service lookups" -msgstr "" +msgstr "DNS 服務查詢的服務名稱" #: src/config/SSSDConfig/sssdoptions.py:384 msgid "The number of records to retrieve in a single LDAP query" -msgstr "" +msgstr "單次 LDAP 查詢要取回的紀錄數" #: src/config/SSSDConfig/sssdoptions.py:385 msgid "The number of members that must be missing to trigger a full deref" -msgstr "" +msgstr "觸發完整解除參照所需缺失的成員數" #: src/config/SSSDConfig/sssdoptions.py:386 msgid "Ignore unreadable LDAP references" -msgstr "" +msgstr "忽略無法讀取的 LDAP 參照" #: src/config/SSSDConfig/sssdoptions.py:387 msgid "" "Whether the LDAP library should perform a reverse lookup to canonicalize the " "host name during a SASL bind" -msgstr "" +msgstr "LDAP 函式庫在 SASL bind 期間是否應執行反向查詢以正規化主機名稱" #: src/config/SSSDConfig/sssdoptions.py:389 msgid "" "Allows to retain local users as members of an LDAP group for servers that " "use the RFC2307 schema." -msgstr "" +msgstr "允許對使用 RFC2307 架構的伺服器保留本機使用者作為 LDAP 群組的成員。" #: src/config/SSSDConfig/sssdoptions.py:392 msgid "entryUSN attribute" -msgstr "" +msgstr "entryUSN 屬性" #: src/config/SSSDConfig/sssdoptions.py:393 msgid "lastUSN attribute" -msgstr "" +msgstr "lastUSN 屬性" #: src/config/SSSDConfig/sssdoptions.py:395 msgid "How long to retain a connection to the LDAP server before disconnecting" -msgstr "" +msgstr "中斷連線前保留 LDAP 伺服器連線的時間" #: src/config/SSSDConfig/sssdoptions.py:398 msgid "Disable the LDAP paging control" -msgstr "" +msgstr "停用 LDAP 分頁控制" #: src/config/SSSDConfig/sssdoptions.py:399 msgid "Disable Active Directory range retrieval" -msgstr "" +msgstr "停用 Active Directory 範圍取回" #: src/config/SSSDConfig/sssdoptions.py:400 msgid "Use the ppolicy extension" -msgstr "" +msgstr "使用 ppolicy 擴充功能" #: src/config/SSSDConfig/sssdoptions.py:401 msgid "" "Force a password change when remaining grace logins reach or go below this " "threshold" -msgstr "" +msgstr "當剩餘寬限登入次數達到或低於此門檻時強制變更密碼" #: src/config/SSSDConfig/sssdoptions.py:404 msgid "Length of time to wait for a search request" @@ -1285,88 +1305,88 @@ msgstr "搜尋請求的等候時間長度" #: src/config/SSSDConfig/sssdoptions.py:405 msgid "Length of time to wait for a enumeration request" -msgstr "" +msgstr "等待列舉請求的時間長度" #: src/config/SSSDConfig/sssdoptions.py:406 msgid "Length of time between enumeration updates" -msgstr "" +msgstr "列舉更新之間的間隔時間" #: src/config/SSSDConfig/sssdoptions.py:407 msgid "Maximum period deviation between enumeration updates" -msgstr "" +msgstr "列舉更新之間的最大時間偏差" #: src/config/SSSDConfig/sssdoptions.py:408 msgid "Length of time between cache cleanups" -msgstr "" +msgstr "快取清理之間的間隔時間" #: src/config/SSSDConfig/sssdoptions.py:409 msgid "Maximum time deviation between cache cleanups" -msgstr "" +msgstr "快取清理之間的最大時間偏差" #: src/config/SSSDConfig/sssdoptions.py:410 msgid "Require TLS for ID lookups" -msgstr "" +msgstr "ID 查詢需要 TLS" #: src/config/SSSDConfig/sssdoptions.py:411 msgid "Use ID-mapping of objectSID instead of pre-set IDs" -msgstr "" +msgstr "使用 objectSID 的 ID 對應而非預先設定的 ID" #: src/config/SSSDConfig/sssdoptions.py:412 msgid "Base DN for user lookups" -msgstr "" +msgstr "使用者查詢的基準 DN" #: src/config/SSSDConfig/sssdoptions.py:413 msgid "Scope of user lookups" -msgstr "" +msgstr "使用者查詢的範圍" #: src/config/SSSDConfig/sssdoptions.py:414 msgid "Filter for user lookups" -msgstr "" +msgstr "使用者查詢的篩選器" #: src/config/SSSDConfig/sssdoptions.py:415 msgid "Objectclass for users" -msgstr "" +msgstr "使用者的物件類別" #: src/config/SSSDConfig/sssdoptions.py:416 msgid "Username attribute" -msgstr "" +msgstr "使用者名稱屬性" #: src/config/SSSDConfig/sssdoptions.py:417 msgid "UID attribute" -msgstr "" +msgstr "UID 屬性" #: src/config/SSSDConfig/sssdoptions.py:418 msgid "Primary GID attribute" -msgstr "" +msgstr "主要 GID 屬性" #: src/config/SSSDConfig/sssdoptions.py:419 msgid "GECOS attribute" -msgstr "" +msgstr "GECOS 屬性" #: src/config/SSSDConfig/sssdoptions.py:420 msgid "Home directory attribute" -msgstr "" +msgstr "家目錄屬性" #: src/config/SSSDConfig/sssdoptions.py:421 msgid "Shell attribute" -msgstr "" +msgstr "Shell 屬性" #: src/config/SSSDConfig/sssdoptions.py:422 msgid "UUID attribute" -msgstr "" +msgstr "UUID 屬性" #: src/config/SSSDConfig/sssdoptions.py:423 #: src/config/SSSDConfig/sssdoptions.py:464 msgid "objectSID attribute" -msgstr "" +msgstr "objectSID 屬性" #: src/config/SSSDConfig/sssdoptions.py:424 msgid "Active Directory primary group attribute for ID-mapping" -msgstr "" +msgstr "用於 ID 對應的 Active Directory 主要群組屬性" #: src/config/SSSDConfig/sssdoptions.py:425 msgid "User principal attribute (for Kerberos)" -msgstr "" +msgstr "使用者 principal 屬性(用於 Kerberos)" #: src/config/SSSDConfig/sssdoptions.py:426 msgid "Full Name" @@ -1374,259 +1394,259 @@ msgstr "全名" #: src/config/SSSDConfig/sssdoptions.py:427 msgid "memberOf attribute" -msgstr "" +msgstr "memberOf 屬性" #: src/config/SSSDConfig/sssdoptions.py:428 msgid "Modification time attribute" -msgstr "" +msgstr "修改時間屬性" #: src/config/SSSDConfig/sssdoptions.py:429 msgid "shadowLastChange attribute" -msgstr "" +msgstr "shadowLastChange 屬性" #: src/config/SSSDConfig/sssdoptions.py:430 msgid "shadowMin attribute" -msgstr "" +msgstr "shadowMin 屬性" #: src/config/SSSDConfig/sssdoptions.py:431 msgid "shadowMax attribute" -msgstr "" +msgstr "shadowMax 屬性" #: src/config/SSSDConfig/sssdoptions.py:432 msgid "shadowWarning attribute" -msgstr "" +msgstr "shadowWarning 屬性" #: src/config/SSSDConfig/sssdoptions.py:433 msgid "shadowInactive attribute" -msgstr "" +msgstr "shadowInactive 屬性" #: src/config/SSSDConfig/sssdoptions.py:434 msgid "shadowExpire attribute" -msgstr "" +msgstr "shadowExpire 屬性" #: src/config/SSSDConfig/sssdoptions.py:435 msgid "shadowFlag attribute" -msgstr "" +msgstr "shadowFlag 屬性" #: src/config/SSSDConfig/sssdoptions.py:436 msgid "Attribute listing authorized PAM services" -msgstr "" +msgstr "列出已授權 PAM 服務的屬性" #: src/config/SSSDConfig/sssdoptions.py:437 msgid "Attribute listing authorized server hosts" -msgstr "" +msgstr "列出已授權伺服器主機的屬性" #: src/config/SSSDConfig/sssdoptions.py:438 msgid "Attribute listing authorized server rhosts" -msgstr "" +msgstr "列出已授權伺服器 rhosts 的屬性" #: src/config/SSSDConfig/sssdoptions.py:439 msgid "krbLastPwdChange attribute" -msgstr "" +msgstr "krbLastPwdChange 屬性" #: src/config/SSSDConfig/sssdoptions.py:440 msgid "krbPasswordExpiration attribute" -msgstr "" +msgstr "krbPasswordExpiration 屬性" #: src/config/SSSDConfig/sssdoptions.py:441 msgid "Attribute indicating that server side password policies are active" -msgstr "" +msgstr "表示伺服器端密碼原則已生效的屬性" #: src/config/SSSDConfig/sssdoptions.py:442 msgid "accountExpires attribute of AD" -msgstr "" +msgstr "AD 的 accountExpires 屬性" #: src/config/SSSDConfig/sssdoptions.py:443 msgid "userAccountControl attribute of AD" -msgstr "" +msgstr "AD 的 userAccountControl 屬性" #: src/config/SSSDConfig/sssdoptions.py:444 msgid "nsAccountLock attribute" -msgstr "" +msgstr "nsAccountLock 屬性" #: src/config/SSSDConfig/sssdoptions.py:445 msgid "loginDisabled attribute of NDS" -msgstr "" +msgstr "NDS 的 loginDisabled 屬性" #: src/config/SSSDConfig/sssdoptions.py:446 msgid "loginExpirationTime attribute of NDS" -msgstr "" +msgstr "NDS 的 loginExpirationTime 屬性" #: src/config/SSSDConfig/sssdoptions.py:447 msgid "loginAllowedTimeMap attribute of NDS" -msgstr "" +msgstr "NDS 的 loginAllowedTimeMap 屬性" #: src/config/SSSDConfig/sssdoptions.py:448 msgid "SSH public key attribute" -msgstr "" +msgstr "SSH 公開金鑰屬性" #: src/config/SSSDConfig/sssdoptions.py:449 msgid "attribute listing allowed authentication types for a user" -msgstr "" +msgstr "列出使用者允許之認證類型的屬性" #: src/config/SSSDConfig/sssdoptions.py:450 msgid "attribute containing the X509 certificate of the user" -msgstr "" +msgstr "包含使用者 X509 憑證的屬性" #: src/config/SSSDConfig/sssdoptions.py:451 msgid "attribute containing the email address of the user" -msgstr "" +msgstr "包含使用者電子郵件位址的屬性" #: src/config/SSSDConfig/sssdoptions.py:452 msgid "attribute containing the passkey mapping data of the user" -msgstr "" +msgstr "包含使用者金鑰對應資料的屬性" #: src/config/SSSDConfig/sssdoptions.py:453 msgid "A list of extra attributes to download along with the user entry" -msgstr "" +msgstr "與使用者項目一起下載的額外屬性清單" #: src/config/SSSDConfig/sssdoptions.py:457 msgid "Base DN for group lookups" -msgstr "" +msgstr "群組查詢的基準 DN" #: src/config/SSSDConfig/sssdoptions.py:458 msgid "Objectclass for groups" -msgstr "" +msgstr "群組的物件類別" #: src/config/SSSDConfig/sssdoptions.py:459 msgid "Group name" -msgstr "" +msgstr "群組名稱" #: src/config/SSSDConfig/sssdoptions.py:460 msgid "Group password" -msgstr "" +msgstr "群組密碼" #: src/config/SSSDConfig/sssdoptions.py:461 msgid "GID attribute" -msgstr "" +msgstr "GID 屬性" #: src/config/SSSDConfig/sssdoptions.py:462 msgid "Group member attribute" -msgstr "" +msgstr "群組成員屬性" #: src/config/SSSDConfig/sssdoptions.py:463 msgid "Group UUID attribute" -msgstr "" +msgstr "群組 UUID 屬性" #: src/config/SSSDConfig/sssdoptions.py:465 msgid "Modification time attribute for groups" -msgstr "" +msgstr "群組的修改時間屬性" #: src/config/SSSDConfig/sssdoptions.py:466 msgid "Type of the group and other flags" -msgstr "" +msgstr "群組類型及其他旗標" #: src/config/SSSDConfig/sssdoptions.py:467 msgid "The LDAP group external member attribute" -msgstr "" +msgstr "LDAP 群組外部成員屬性" #: src/config/SSSDConfig/sssdoptions.py:468 msgid "Maximum nesting level SSSD will follow" -msgstr "" +msgstr "SSSD 會追蹤的最大巢狀層級" #: src/config/SSSDConfig/sssdoptions.py:469 msgid "Filter for group lookups" -msgstr "" +msgstr "群組查詢的篩選器" #: src/config/SSSDConfig/sssdoptions.py:470 msgid "Scope of group lookups" -msgstr "" +msgstr "群組查詢的範圍" #: src/config/SSSDConfig/sssdoptions.py:472 msgid "Base DN for netgroup lookups" -msgstr "" +msgstr "網路群組查詢的基準 DN" #: src/config/SSSDConfig/sssdoptions.py:473 msgid "Objectclass for netgroups" -msgstr "" +msgstr "網路群組的物件類別" #: src/config/SSSDConfig/sssdoptions.py:474 msgid "Netgroup name" -msgstr "" +msgstr "網路群組名稱" #: src/config/SSSDConfig/sssdoptions.py:475 msgid "Netgroups members attribute" -msgstr "" +msgstr "網路群組成員屬性" #: src/config/SSSDConfig/sssdoptions.py:476 msgid "Netgroup triple attribute" -msgstr "" +msgstr "網路群組三元組屬性" #: src/config/SSSDConfig/sssdoptions.py:477 msgid "Modification time attribute for netgroups" -msgstr "" +msgstr "網路群組的修改時間屬性" #: src/config/SSSDConfig/sssdoptions.py:479 msgid "Base DN for service lookups" -msgstr "" +msgstr "服務查詢的基準 DN" #: src/config/SSSDConfig/sssdoptions.py:480 msgid "Objectclass for services" -msgstr "" +msgstr "服務的物件類別" #: src/config/SSSDConfig/sssdoptions.py:481 msgid "Service name attribute" -msgstr "" +msgstr "服務名稱屬性" #: src/config/SSSDConfig/sssdoptions.py:482 msgid "Service port attribute" -msgstr "" +msgstr "服務連接埠屬性" #: src/config/SSSDConfig/sssdoptions.py:483 msgid "Service protocol attribute" -msgstr "" +msgstr "服務協定屬性" #: src/config/SSSDConfig/sssdoptions.py:485 msgid "Lower bound for ID-mapping" -msgstr "" +msgstr "ID 對應的下限" #: src/config/SSSDConfig/sssdoptions.py:486 msgid "Upper bound for ID-mapping" -msgstr "" +msgstr "ID 對應的上限" #: src/config/SSSDConfig/sssdoptions.py:487 msgid "Number of IDs for each slice when ID-mapping" -msgstr "" +msgstr "ID 對應時每個區段的 ID 數量" #: src/config/SSSDConfig/sssdoptions.py:488 msgid "Use autorid-compatible algorithm for ID-mapping" -msgstr "" +msgstr "ID 對應使用與 autorid 相容的演算法" #: src/config/SSSDConfig/sssdoptions.py:489 msgid "Name of the default domain for ID-mapping" -msgstr "" +msgstr "ID 對應的預設網域名稱" #: src/config/SSSDConfig/sssdoptions.py:490 msgid "SID of the default domain for ID-mapping" -msgstr "" +msgstr "ID 對應的預設網域 SID" #: src/config/SSSDConfig/sssdoptions.py:491 msgid "Number of secondary slices" -msgstr "" +msgstr "次要區段數量" #: src/config/SSSDConfig/sssdoptions.py:493 msgid "Whether to use Token-Groups" -msgstr "" +msgstr "是否使用 Token-Groups" #: src/config/SSSDConfig/sssdoptions.py:494 msgid "Set lower boundary for allowed IDs from the LDAP server" -msgstr "" +msgstr "設定 LDAP 伺服器允許 ID 的下限" #: src/config/SSSDConfig/sssdoptions.py:495 msgid "Set upper boundary for allowed IDs from the LDAP server" -msgstr "" +msgstr "設定 LDAP 伺服器允許 ID 的上限" #: src/config/SSSDConfig/sssdoptions.py:496 msgid "DN for ppolicy queries" -msgstr "" +msgstr "ppolicy 查詢的 DN" #: src/config/SSSDConfig/sssdoptions.py:497 msgid "How many maximum entries to fetch during a wildcard request" -msgstr "" +msgstr "萬用字元請求期間最多取回的項目數" #: src/config/SSSDConfig/sssdoptions.py:498 msgid "Set libldap debug level" -msgstr "" +msgstr "設定 libldap 除錯層級" #: src/config/SSSDConfig/sssdoptions.py:501 msgid "Policy to evaluate the password expiration" @@ -1634,184 +1654,184 @@ msgstr "評估密碼過期時效的策略" #: src/config/SSSDConfig/sssdoptions.py:505 msgid "Which attributes shall be used to evaluate if an account is expired" -msgstr "" +msgstr "應用哪些屬性評估帳號是否已到期" #: src/config/SSSDConfig/sssdoptions.py:509 msgid "URI of an LDAP server where password changes are allowed" -msgstr "" +msgstr "允許變更密碼之 LDAP 伺服器的 URI" #: src/config/SSSDConfig/sssdoptions.py:510 msgid "URI of a backup LDAP server where password changes are allowed" -msgstr "" +msgstr "允許變更密碼之備份 LDAP 伺服器的 URI" #: src/config/SSSDConfig/sssdoptions.py:511 msgid "DNS service name for LDAP password change server" -msgstr "" +msgstr "LDAP 密碼變更伺服器的 DNS 服務名稱" #: src/config/SSSDConfig/sssdoptions.py:512 msgid "" "Whether to update the ldap_user_shadow_last_change attribute after a " "password change" -msgstr "" +msgstr "密碼變更後是否更新 ldap_user_shadow_last_change 屬性" #: src/config/SSSDConfig/sssdoptions.py:516 msgid "Base DN for sudo rules lookups" -msgstr "" +msgstr "sudo 規則查詢的基準 DN" #: src/config/SSSDConfig/sssdoptions.py:517 msgid "Automatic full refresh period" -msgstr "" +msgstr "自動完整重新整理週期" #: src/config/SSSDConfig/sssdoptions.py:518 msgid "Automatic smart refresh period" -msgstr "" +msgstr "自動智慧重新整理週期" #: src/config/SSSDConfig/sssdoptions.py:519 msgid "Smart and full refresh random offset" -msgstr "" +msgstr "智慧與完整重新整理的隨機偏移" #: src/config/SSSDConfig/sssdoptions.py:520 msgid "Whether to filter rules by hostname, IP addresses and network" -msgstr "" +msgstr "是否依主機名稱、IP 位址與網路篩選規則" #: src/config/SSSDConfig/sssdoptions.py:521 msgid "" "Hostnames and/or fully qualified domain names of this machine to filter sudo " "rules" -msgstr "" +msgstr "用於篩選 sudo 規則的此機器主機名稱與/或完整限定網域名稱" #: src/config/SSSDConfig/sssdoptions.py:522 msgid "IPv4 or IPv6 addresses or network of this machine to filter sudo rules" -msgstr "" +msgstr "用於篩選 sudo 規則的此機器 IPv4 或 IPv6 位址或網路" #: src/config/SSSDConfig/sssdoptions.py:523 msgid "Whether to include rules that contains netgroup in host attribute" -msgstr "" +msgstr "是否包含主機屬性中含有網路群組的規則" #: src/config/SSSDConfig/sssdoptions.py:524 msgid "" "Whether to include rules that contains regular expression in host attribute" -msgstr "" +msgstr "是否包含主機屬性中含有正規表示式的規則" #: src/config/SSSDConfig/sssdoptions.py:525 msgid "Object class for sudo rules" -msgstr "" +msgstr "sudo 規則的物件類別" #: src/config/SSSDConfig/sssdoptions.py:526 msgid "Name of attribute that is used as object class for sudo rules" -msgstr "" +msgstr "作為 sudo 規則物件類別的屬性名稱" #: src/config/SSSDConfig/sssdoptions.py:527 msgid "Sudo rule name" -msgstr "" +msgstr "sudo 規則名稱" #: src/config/SSSDConfig/sssdoptions.py:528 msgid "Sudo rule command attribute" -msgstr "" +msgstr "sudo 規則指令屬性" #: src/config/SSSDConfig/sssdoptions.py:529 msgid "Sudo rule host attribute" -msgstr "" +msgstr "sudo 規則主機屬性" #: src/config/SSSDConfig/sssdoptions.py:530 msgid "Sudo rule user attribute" -msgstr "" +msgstr "sudo 規則使用者屬性" #: src/config/SSSDConfig/sssdoptions.py:531 msgid "Sudo rule option attribute" -msgstr "" +msgstr "sudo 規則選項屬性" #: src/config/SSSDConfig/sssdoptions.py:532 msgid "Sudo rule runas attribute" -msgstr "" +msgstr "sudo 規則 runas 屬性" #: src/config/SSSDConfig/sssdoptions.py:533 msgid "Sudo rule runasuser attribute" -msgstr "" +msgstr "sudo 規則 runasuser 屬性" #: src/config/SSSDConfig/sssdoptions.py:534 msgid "Sudo rule runasgroup attribute" -msgstr "" +msgstr "sudo 規則 runasgroup 屬性" #: src/config/SSSDConfig/sssdoptions.py:535 msgid "Sudo rule notbefore attribute" -msgstr "" +msgstr "sudo 規則 notbefore 屬性" #: src/config/SSSDConfig/sssdoptions.py:536 msgid "Sudo rule notafter attribute" -msgstr "" +msgstr "sudo 規則 notafter 屬性" #: src/config/SSSDConfig/sssdoptions.py:537 msgid "Sudo rule order attribute" -msgstr "" +msgstr "sudo 規則順序屬性" #: src/config/SSSDConfig/sssdoptions.py:540 msgid "Object class for automounter maps" -msgstr "" +msgstr "自動掛載器對應表的物件類別" #: src/config/SSSDConfig/sssdoptions.py:541 msgid "Automounter map name attribute" -msgstr "" +msgstr "自動掛載器對應表名稱屬性" #: src/config/SSSDConfig/sssdoptions.py:542 msgid "Object class for automounter map entries" -msgstr "" +msgstr "自動掛載器對應表項目的物件類別" #: src/config/SSSDConfig/sssdoptions.py:543 msgid "Automounter map entry key attribute" -msgstr "" +msgstr "自動掛載器對應表項目鍵屬性" #: src/config/SSSDConfig/sssdoptions.py:544 msgid "Automounter map entry value attribute" -msgstr "" +msgstr "自動掛載器對應表項目值屬性" #: src/config/SSSDConfig/sssdoptions.py:545 msgid "Base DN for automounter map lookups" -msgstr "" +msgstr "自動掛載器對應表查詢的基準 DN" #: src/config/SSSDConfig/sssdoptions.py:546 msgid "The name of the automount master map in LDAP." -msgstr "" +msgstr "LDAP 中自動掛載主對應表的名稱。" #: src/config/SSSDConfig/sssdoptions.py:549 msgid "Base DN for IP hosts lookups" -msgstr "" +msgstr "IP 主機查詢的基準 DN" #: src/config/SSSDConfig/sssdoptions.py:550 msgid "Object class for IP hosts" -msgstr "" +msgstr "IP 主機的物件類別" #: src/config/SSSDConfig/sssdoptions.py:551 msgid "IP host name attribute" -msgstr "" +msgstr "IP 主機名稱屬性" #: src/config/SSSDConfig/sssdoptions.py:552 msgid "IP host number (address) attribute" -msgstr "" +msgstr "IP 主機號碼(位址)屬性" #: src/config/SSSDConfig/sssdoptions.py:553 msgid "IP host entryUSN attribute" -msgstr "" +msgstr "IP 主機 entryUSN 屬性" #: src/config/SSSDConfig/sssdoptions.py:554 msgid "Base DN for IP networks lookups" -msgstr "" +msgstr "IP 網路查詢的基準 DN" #: src/config/SSSDConfig/sssdoptions.py:555 msgid "Object class for IP networks" -msgstr "" +msgstr "IP 網路的物件類別" #: src/config/SSSDConfig/sssdoptions.py:556 msgid "IP network name attribute" -msgstr "" +msgstr "IP 網路名稱屬性" #: src/config/SSSDConfig/sssdoptions.py:557 msgid "IP network number (address) attribute" -msgstr "" +msgstr "IP 網路號碼(位址)屬性" #: src/config/SSSDConfig/sssdoptions.py:558 msgid "IP network entryUSN attribute" -msgstr "" +msgstr "IP 網路 entryUSN 屬性" #: src/config/SSSDConfig/sssdoptions.py:561 msgid "Comma separated list of allowed users" @@ -1826,6 +1846,8 @@ msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." msgstr "" +"允許登入的群組清單,以逗號分隔。此設定僅適用於此 SSSD 網域內的群組。本機群組" +"不予評估。" #: src/config/SSSDConfig/sssdoptions.py:565 msgid "" @@ -1833,10 +1855,12 @@ msgid "" "applies only to groups within this SSSD domain. Local groups are not " "evaluated." msgstr "" +"明確拒絕存取的群組清單,以逗號分隔。此設定僅適用於此 SSSD 網域內的群組。本機" +"群組不予評估。" #: src/config/SSSDConfig/sssdoptions.py:569 msgid "The number of preforked proxy children." -msgstr "" +msgstr "預先分派的代理子處理程式數量。" #: src/config/SSSDConfig/sssdoptions.py:572 msgid "The name of the NSS library to use" @@ -1844,11 +1868,11 @@ msgstr "要使用的 NSS 函式庫名稱" #: src/config/SSSDConfig/sssdoptions.py:573 msgid "The name of the NSS library to use for hosts and networks lookups" -msgstr "" +msgstr "用於主機與網路查詢的 NSS 函式庫名稱" #: src/config/SSSDConfig/sssdoptions.py:574 msgid "Whether to look up canonical group name from cache if possible" -msgstr "" +msgstr "是否在可能時從快取查詢正式群組名稱" #: src/config/SSSDConfig/sssdoptions.py:577 msgid "PAM stack to use" @@ -1856,11 +1880,11 @@ msgstr "要使用的 PAM 堆疊" #: src/config/SSSDConfig/sssdoptions.py:580 msgid "Path of passwd file sources." -msgstr "" +msgstr "passwd 檔案來源的路徑。" #: src/config/SSSDConfig/sssdoptions.py:581 msgid "Path of group file sources." -msgstr "" +msgstr "group 檔案來源的路徑。" #: src/monitor/monitor.c:1757 msgid "Become a daemon (default)" @@ -1872,7 +1896,7 @@ msgstr "以互動方式執行 (非幕後程式)" #: src/monitor/monitor.c:1761 msgid "Print version number and exit" -msgstr "" +msgstr "顯示版本號碼後結束" #: src/monitor/monitor.c:1772 #, c-format @@ -1881,28 +1905,31 @@ msgid "" "Invalid option %s: %s\n" "\n" msgstr "" +"\n" +"無效的選項 %s:%s\n" +"\n" #: src/monitor/monitor.c:1794 msgid "Option -i|--interactive is not allowed together with -D|--daemon\n" -msgstr "" +msgstr "選項 -i|--interactive 不能與 -D|--daemon 一起使用\n" #: src/monitor/monitor.c:1836 msgid "Failed to get initial capabilities\n" -msgstr "" +msgstr "無法取得初始能力\n" #: src/monitor/monitor.c:1847 msgid "Non-root service user support isn't built. Can't run under %" -msgstr "" +msgstr "未建置非 root 服務使用者支援。無法以 % 執行" #: src/monitor/monitor.c:1864 #, c-format msgid "Can't read config: '%s'\n" -msgstr "" +msgstr "無法讀取設定:「%s」\n" #: src/monitor/monitor.c:1876 #, c-format msgid "Failed to boostrap SSSD 'monitor' process: %s" -msgstr "" +msgstr "無法啟動 SSSD「monitor」處理程式:%s" #: src/monitor/monitor.c:1971 msgid "Out of memory\n" @@ -1910,90 +1937,90 @@ msgstr "記憶體耗盡\n" #: src/providers/krb5/krb5_child.c:4221 msgid "Use anonymous PKINIT to request FAST armor ticket" -msgstr "" +msgstr "使用匿名 PKINIT 請求 FAST armor 票券" #: src/providers/krb5/krb5_child.c:4223 msgid "Kerberos realm to use" -msgstr "" +msgstr "要使用的 Kerberos 領域" #: src/providers/krb5/krb5_child.c:4225 msgid "Requested lifetime of the ticket" -msgstr "" +msgstr "請求的票券存續時間" #: src/providers/krb5/krb5_child.c:4227 msgid "Requested renewable lifetime of the ticket" -msgstr "" +msgstr "請求的票券可續期存續時間" #: src/providers/krb5/krb5_child.c:4229 msgid "FAST options ('never', 'try', 'demand')" -msgstr "" +msgstr "FAST 選項('never'、'try'、'demand')" #: src/providers/krb5/krb5_child.c:4232 msgid "Specifies the server principal to use for FAST" -msgstr "" +msgstr "指定 FAST 使用的伺服器 principal" #: src/providers/krb5/krb5_child.c:4234 msgid "Requests canonicalization of the principal name" -msgstr "" +msgstr "請求 principal 名稱的正規化" #: src/providers/krb5/krb5_child.c:4236 msgid "Use custom version of krb5_get_init_creds_password" -msgstr "" +msgstr "使用自訂版本的 krb5_get_init_creds_password" #: src/providers/krb5/krb5_child.c:4238 msgid "Check PAC flags" -msgstr "" +msgstr "檢查 PAC 旗標" #: src/providers/data_provider_be.c:790 msgid "Domain of the information provider (mandatory)" -msgstr "" +msgstr "資訊提供者的網域(必填)" #: src/sss_client/common.c:1165 msgid "Socket has wrong ownership or permissions." -msgstr "" +msgstr "Socket 的擁有者或權限不正確。" #: src/sss_client/common.c:1168 msgid "Unexpected format of the server credential message." -msgstr "" +msgstr "伺服器憑證訊息格式不符合預期。" #: src/sss_client/common.c:1171 msgid "SSSD is not run by trusted user." -msgstr "" +msgstr "SSSD 並非由受信任的使用者執行。" #: src/sss_client/common.c:1174 msgid "SSSD socket does not exist." -msgstr "" +msgstr "SSSD socket 不存在。" #: src/sss_client/common.c:1177 msgid "Cannot get stat of SSSD socket." -msgstr "" +msgstr "無法取得 SSSD socket 的 stat。" #: src/sss_client/common.c:1182 msgid "An error occurred, but no description can be found." -msgstr "" +msgstr "發生錯誤,但找不到任何說明。" #: src/sss_client/common.c:1188 msgid "Unexpected error while looking for an error description" -msgstr "" +msgstr "尋找錯誤說明時發生非預期的錯誤" #: src/sss_client/pam_sss.c:74 msgid "Permission denied. " -msgstr "" +msgstr "權限被拒絕。 " #: src/sss_client/pam_sss.c:75 src/sss_client/pam_sss.c:843 #: src/sss_client/pam_sss.c:854 msgid "Server message: " -msgstr "伺服器訊息:" +msgstr "伺服器訊息: " #: src/sss_client/pam_sss.c:76 msgid "" "Kerberos TGT will not be granted upon login, user experience will be " "affected." -msgstr "" +msgstr "登入時不會授予 Kerberos TGT,使用者體驗將受影響。" #: src/sss_client/pam_sss.c:77 msgid "Enter PIN:" -msgstr "" +msgstr "輸入 PIN:" #: src/sss_client/pam_sss.c:320 msgid "Passwords do not match" @@ -2001,34 +2028,34 @@ msgstr "密碼不相符" #: src/sss_client/pam_sss.c:508 msgid "Password reset by root is not supported." -msgstr "" +msgstr "不支援由 root 重設密碼。" #: src/sss_client/pam_sss.c:549 msgid "Authenticated with cached credentials" -msgstr "" +msgstr "已使用快取憑證認證" #: src/sss_client/pam_sss.c:550 msgid ", your cached password will expire at: " -msgstr ",您快取的密碼將在此刻過期:" +msgstr ",您快取的密碼將在此刻過期: " #: src/sss_client/pam_sss.c:580 #, c-format msgid "Your password has expired. You have %1$d grace login(s) remaining." -msgstr "" +msgstr "您的密碼已過期。您剩下 %1$d 次寬限登入。" #: src/sss_client/pam_sss.c:630 #, c-format msgid "Your password will expire in %1$d %2$s." -msgstr "" +msgstr "您的密碼將在 %1$d %2$s 後到期。" #: src/sss_client/pam_sss.c:633 -#, fuzzy, c-format +#, c-format msgid "Your password has expired." -msgstr ",您快取的密碼將在此刻過期:" +msgstr "您的密碼已過期。" #: src/sss_client/pam_sss.c:684 msgid "Authentication is denied until: " -msgstr "" +msgstr "認證將被拒絕直到: " #: src/sss_client/pam_sss.c:705 msgid "System is offline, password change not possible" @@ -2038,71 +2065,73 @@ msgstr "系統已離線,不可能作密碼變更" msgid "" "After changing the OTP password, you need to log out and back in order to " "acquire a ticket" -msgstr "" +msgstr "變更 OTP 密碼後,您需要登出再登入才能取得票券" #: src/sss_client/pam_sss.c:735 msgid "PIN locked" -msgstr "" +msgstr "PIN 已鎖定" #: src/sss_client/pam_sss.c:750 msgid "" "No Kerberos TGT granted as the server does not support this method. Your " "single-sign on(SSO) experience will be affected." msgstr "" +"由於伺服器不支援此方法,未授予 Kerberos TGT。您的單一登入 (SSO) 體驗將受影響" +"。" #: src/sss_client/pam_sss.c:840 src/sss_client/pam_sss.c:853 msgid "Password change failed. " -msgstr "密碼變更失敗。" +msgstr "密碼變更失敗。 " #: src/sss_client/pam_sss.c:1859 #, c-format msgid "Authenticate at %1$s and press ENTER." -msgstr "" +msgstr "在 %1$s 進行認證,然後按 ENTER。" #: src/sss_client/pam_sss.c:1862 #, c-format msgid "Authenticate with PIN %1$s at %2$s and press ENTER." -msgstr "" +msgstr "在 %2$s 使用 PIN %1$s 進行認證,然後按 ENTER。" #: src/sss_client/pam_sss.c:2281 msgid "Please (re)insert (different) Smartcard" -msgstr "" +msgstr "請(重新)插入(不同的)智慧卡" #: src/sss_client/pam_sss.c:2482 msgid "New Password: " -msgstr "新密碼:" +msgstr "新密碼: " #: src/sss_client/pam_sss.c:2483 msgid "Reenter new Password: " -msgstr "再次輸入新密碼:" +msgstr "再次輸入新密碼: " #: src/sss_client/pam_sss.c:2676 src/sss_client/pam_sss.c:2679 msgid "First Factor: " -msgstr "" +msgstr "第一因素: " #: src/sss_client/pam_sss.c:2677 src/sss_client/pam_sss.c:2851 msgid "Second Factor (optional): " -msgstr "" +msgstr "第二因素(選填): " #: src/sss_client/pam_sss.c:2680 src/sss_client/pam_sss.c:2855 msgid "Second Factor: " -msgstr "" +msgstr "第二因素: " #: src/sss_client/pam_sss.c:2684 msgid "Insert your passkey device, then press ENTER." -msgstr "" +msgstr "插入您的金鑰裝置,然後按 ENTER。" #: src/sss_client/pam_sss.c:2688 src/sss_client/pam_sss.c:2696 msgid "Password: " -msgstr "密碼:" +msgstr "密碼: " #: src/sss_client/pam_sss.c:2850 src/sss_client/pam_sss.c:2854 msgid "First Factor (Current Password): " -msgstr "" +msgstr "第一因素(目前密碼): " #: src/sss_client/pam_sss.c:2874 msgid "Current Password: " -msgstr "目前的密碼:" +msgstr "目前的密碼: " #: src/sss_client/pam_sss.c:3248 msgid "Password expired. Change your password now." @@ -2110,11 +2139,11 @@ msgstr "密碼已過期。請立刻變更您的密碼。" #: src/sss_client/ssh/sss_ssh_authorizedkeys.c:41 src/tools/sss_cache.c:707 msgid "The debug level to run with" -msgstr "" +msgstr "執行的除錯層級" #: src/sss_client/ssh/sss_ssh_authorizedkeys.c:43 msgid "The SSSD domain to use" -msgstr "" +msgstr "要使用的 SSSD 網域" #: src/sss_client/ssh/sss_ssh_authorizedkeys.c:57 src/tools/sss_cache.c:753 msgid "Error setting the locale\n" @@ -2122,15 +2151,15 @@ msgstr "設定區域設置時發生錯誤\n" #: src/sss_client/ssh/sss_ssh_authorizedkeys.c:64 msgid "Not enough memory\n" -msgstr "" +msgstr "記憶體不足\n" #: src/sss_client/ssh/sss_ssh_authorizedkeys.c:83 msgid "User not specified\n" -msgstr "" +msgstr "未指定使用者\n" #: src/sss_client/ssh/sss_ssh_authorizedkeys.c:97 msgid "Error looking up public keys\n" -msgstr "" +msgstr "查詢公開金鑰時發生錯誤\n" #: src/sss_client/ssh/sss_ssh_knownhostsproxy.c:27 msgid "" @@ -2142,98 +2171,104 @@ msgid "" "******************************************************************************\n" "\n" msgstr "" +"\n" +"******************************************************************************\n" +"您的系統設定為使用已淘汰的工具 sss_ssh_knownhostsproxy。\n" +"請閱讀 sss_ssh_knownhosts(1) 的手冊頁以了解取代它的工具。\n" +"******************************************************************************\n" +"\n" #: src/tools/sss_cache.c:229 msgid "No cache object matched the specified search\n" -msgstr "" +msgstr "沒有快取物件符合指定的搜尋\n" #: src/tools/sss_cache.c:520 #, c-format msgid "Couldn't invalidate %1$s\n" -msgstr "" +msgstr "無法讓 %1$s 失效\n" #: src/tools/sss_cache.c:527 #, c-format msgid "Couldn't invalidate %1$s %2$s\n" -msgstr "" +msgstr "無法讓 %1$s %2$s 失效\n" #: src/tools/sss_cache.c:653 msgid "Can't find configuration db, was SSSD configured and run?\n" -msgstr "" +msgstr "找不到設定資料庫,SSSD 是否已設定並執行?\n" #: src/tools/sss_cache.c:709 msgid "Invalidate all cached entries" -msgstr "" +msgstr "讓所有快取項目失效" #: src/tools/sss_cache.c:711 msgid "Invalidate particular user" -msgstr "" +msgstr "讓特定使用者失效" #: src/tools/sss_cache.c:713 msgid "Invalidate all users" -msgstr "" +msgstr "讓所有使用者失效" #: src/tools/sss_cache.c:715 msgid "Invalidate particular group" -msgstr "" +msgstr "讓特定群組失效" #: src/tools/sss_cache.c:717 msgid "Invalidate all groups" -msgstr "" +msgstr "讓所有群組失效" #: src/tools/sss_cache.c:719 msgid "Invalidate particular netgroup" -msgstr "" +msgstr "讓特定網路群組失效" #: src/tools/sss_cache.c:721 msgid "Invalidate all netgroups" -msgstr "" +msgstr "讓所有網路群組失效" #: src/tools/sss_cache.c:723 msgid "Invalidate particular service" -msgstr "" +msgstr "讓特定服務失效" #: src/tools/sss_cache.c:725 msgid "Invalidate all services" -msgstr "" +msgstr "讓所有服務失效" #: src/tools/sss_cache.c:728 msgid "Invalidate particular autofs map" -msgstr "" +msgstr "讓特定 autofs 對應表失效" #: src/tools/sss_cache.c:730 msgid "Invalidate all autofs maps" -msgstr "" +msgstr "讓所有 autofs 對應表失效" #: src/tools/sss_cache.c:734 msgid "Invalidate particular SSH host" -msgstr "" +msgstr "讓特定 SSH 主機失效" #: src/tools/sss_cache.c:736 msgid "Invalidate all SSH hosts" -msgstr "" +msgstr "讓所有 SSH 主機失效" #: src/tools/sss_cache.c:740 msgid "Invalidate particular sudo rule" -msgstr "" +msgstr "讓特定 sudo 規則失效" #: src/tools/sss_cache.c:742 msgid "Invalidate all cached sudo rules" -msgstr "" +msgstr "讓所有快取的 sudo 規則失效" #: src/tools/sss_cache.c:745 msgid "Only invalidate entries from a particular domain" -msgstr "" +msgstr "僅讓特定網域的項目失效" #: src/tools/sss_cache.c:799 msgid "" "Unexpected argument(s) provided, options that invalidate a single object " "only accept a single provided argument.\n" -msgstr "" +msgstr "提供了非預期的引數,讓單一物件失效的選項只接受單一提供的引數。\n" #: src/tools/sss_cache.c:809 msgid "Please select at least one object to invalidate\n" -msgstr "" +msgstr "請至少選取一個要讓其失效的物件\n" #: src/tools/sss_cache.c:892 #, c-format @@ -2241,300 +2276,299 @@ msgid "" "Could not open domain %1$s. If the domain is a subdomain (trusted domain), " "use fully qualified name instead of --domain/-d parameter.\n" msgstr "" +"無法開啟網域 %1$s。若此網域是子網域(受信任網域),請改用完整限定名稱而非 --" +"domain/-d 參數。\n" #: src/tools/sss_cache.c:897 msgid "Could not open available domains\n" -msgstr "" +msgstr "無法開啟可用的網域\n" #: src/tools/tools_util.h:36 #, c-format msgid "%1$s must be run as root\n" -msgstr "" +msgstr "%1$s 必須以 root 身分執行\n" #: src/tools/sssctl/sssctl.c:35 msgid "yes" -msgstr "" +msgstr "是" #: src/tools/sssctl/sssctl.c:37 msgid "no" -msgstr "" +msgstr "否" #: src/tools/sssctl/sssctl.c:39 msgid "error" -msgstr "" +msgstr "錯誤" #: src/tools/sssctl/sssctl.c:42 msgid "Invalid result." -msgstr "" +msgstr "結果無效。" #: src/tools/sssctl/sssctl.c:78 msgid "Unable to read user input\n" -msgstr "" +msgstr "無法讀取使用者輸入\n" #: src/tools/sssctl/sssctl.c:91 #, c-format msgid "Invalid input, please provide either '%s' or '%s'.\n" -msgstr "" +msgstr "輸入無效,請提供「%s」或「%s」。\n" #: src/tools/sssctl/sssctl.c:151 src/tools/sssctl/sssctl.c:161 msgid "Error while executing external command\n" -msgstr "" +msgstr "執行外部指令時發生錯誤\n" #: src/tools/sssctl/sssctl.c:165 #, c-format msgid "Error while executing external command '%s'\n" -msgstr "" +msgstr "執行外部指令「%s」時發生錯誤\n" #: src/tools/sssctl/sssctl.c:168 #, c-format msgid "Command '%s' failed with [%d]\n" -msgstr "" +msgstr "指令「%s」以 [%d] 失敗\n" #: src/tools/sssctl/sssctl.c:215 msgid "SSSD needs to be running. Start SSSD now?" -msgstr "" +msgstr "SSSD 需要執行中。現在啟動 SSSD?" #: src/tools/sssctl/sssctl.c:254 msgid "SSSD must not be running. Stop SSSD now?" -msgstr "" +msgstr "SSSD 不得執行中。現在停止 SSSD?" #: src/tools/sssctl/sssctl.c:290 msgid "SSSD needs to be restarted. Restart SSSD now?" -msgstr "" +msgstr "SSSD 需要重新啟動。現在重新啟動 SSSD?" #: src/tools/sssctl/sssctl.c:322 msgid "SSSD Status:" -msgstr "" +msgstr "SSSD 狀態:" #: src/tools/sssctl/sssctl.c:323 msgid "List available domains" -msgstr "" +msgstr "列出可用的網域" #: src/tools/sssctl/sssctl.c:324 msgid "Print information about domain" -msgstr "" +msgstr "顯示網域的資訊" #: src/tools/sssctl/sssctl.c:325 msgid "Print information about a user and check authentication" -msgstr "" +msgstr "顯示使用者的資訊並檢查認證" #: src/tools/sssctl/sssctl.c:326 msgid "Generate access report for a domain" -msgstr "" +msgstr "為網域產生存取報告" #: src/tools/sssctl/sssctl.c:327 msgid "Information about cached content:" -msgstr "" +msgstr "快取內容的資訊:" #: src/tools/sssctl/sssctl.c:328 -#, fuzzy msgid "Information about cached user" -msgstr "無法取得關於這位使用者的資訊\n" +msgstr "快取使用者的資訊" #: src/tools/sssctl/sssctl.c:329 msgid "Information about cached group" -msgstr "" +msgstr "快取群組的資訊" #: src/tools/sssctl/sssctl.c:330 msgid "Information about cached netgroup" -msgstr "" +msgstr "快取網路群組的資訊" #: src/tools/sssctl/sssctl.c:331 msgid "Local data tools:" -msgstr "" +msgstr "本機資料工具:" #: src/tools/sssctl/sssctl.c:332 msgid "Backup local data" -msgstr "" +msgstr "備份本機資料" #: src/tools/sssctl/sssctl.c:333 msgid "Restore local data from backup" -msgstr "" +msgstr "從備份還原本機資料" #: src/tools/sssctl/sssctl.c:334 msgid "Backup local data and remove cached content" -msgstr "" +msgstr "備份本機資料並移除快取內容" #: src/tools/sssctl/sssctl.c:335 msgid "Invalidate cached objects" -msgstr "" +msgstr "讓快取物件失效" #: src/tools/sssctl/sssctl.c:336 msgid "Manage cache indexes" -msgstr "" +msgstr "管理快取索引" #: src/tools/sssctl/sssctl.c:337 msgid "Log files tools:" -msgstr "" +msgstr "日誌檔工具:" #: src/tools/sssctl/sssctl.c:338 msgid "Remove existing SSSD log files" -msgstr "" +msgstr "移除既有的 SSSD 日誌檔" #: src/tools/sssctl/sssctl.c:339 msgid "Archive SSSD log files in tarball" -msgstr "" +msgstr "將 SSSD 日誌檔封存為 tarball" #: src/tools/sssctl/sssctl.c:340 msgid "Change or print information about SSSD debug level" -msgstr "" +msgstr "變更或顯示 SSSD 除錯層級的資訊" #: src/tools/sssctl/sssctl.c:341 msgid "Analyze logged data" -msgstr "" +msgstr "分析已記錄的資料" #: src/tools/sssctl/sssctl.c:342 msgid "Configuration files tools:" -msgstr "" +msgstr "設定檔工具:" #: src/tools/sssctl/sssctl.c:343 msgid "Perform static analysis of SSSD configuration" -msgstr "" +msgstr "對 SSSD 設定執行靜態分析" #: src/tools/sssctl/sssctl.c:344 msgid "Certificate related tools:" -msgstr "" +msgstr "憑證相關工具:" #: src/tools/sssctl/sssctl.c:345 msgid "Print information about the certificate" -msgstr "" +msgstr "顯示憑證的資訊" #: src/tools/sssctl/sssctl.c:346 msgid "Show users mapped to the certificate" -msgstr "" +msgstr "顯示對應到此憑證的使用者" #: src/tools/sssctl/sssctl.c:347 msgid "Check mapping and matching rule with a certificate" -msgstr "" +msgstr "以憑證檢查對應與比對規則" #: src/tools/sssctl/sssctl.c:348 msgid "GPOs related tools:" -msgstr "" +msgstr "GPO 相關工具:" #: src/tools/sssctl/sssctl.c:349 -#, fuzzy msgid "Information about cached GPO" -msgstr "無法取得關於這位使用者的資訊\n" +msgstr "快取 GPO 的資訊" #: src/tools/sssctl/sssctl.c:350 msgid "Enumerate cached GPOs" -msgstr "" +msgstr "列舉快取的 GPO" #: src/tools/sssctl/sssctl.c:351 msgid "Remove cached GPO" -msgstr "" +msgstr "移除快取的 GPO" #: src/tools/sssctl/sssctl.c:352 msgid "Remove all cached GPOs" -msgstr "" +msgstr "移除所有快取的 GPO" #: src/tools/sssctl/sssctl.c:354 msgid "Passkey related tools:" -msgstr "" +msgstr "金鑰相關工具:" #: src/tools/sssctl/sssctl.c:355 msgid "Perform passkey registration" -msgstr "" +msgstr "執行金鑰註冊" #: src/tools/sssctl/sssctl_cache.c:31 #, c-format msgid " %s is not present in cache.\n" -msgstr "" +msgstr " %s 不在快取中。\n" #: src/tools/sssctl/sssctl_cache.c:33 msgid "Name" -msgstr "" +msgstr "名稱" #: src/tools/sssctl/sssctl_cache.c:34 msgid "Cache entry creation date" -msgstr "" +msgstr "快取項目建立日期" #: src/tools/sssctl/sssctl_cache.c:35 msgid "Cache entry last update time" -msgstr "" +msgstr "快取項目最後更新時間" #: src/tools/sssctl/sssctl_cache.c:36 msgid "Cache entry expiration time" -msgstr "" +msgstr "快取項目到期時間" #: src/tools/sssctl/sssctl_cache.c:37 msgid "Cached in InfoPipe" -msgstr "" +msgstr "已在 InfoPipe 中快取" #: src/tools/sssctl/sssctl_cache.c:38 -#, fuzzy msgid "Policy Name" -msgstr "全名" +msgstr "原則名稱" #: src/tools/sssctl/sssctl_cache.c:39 msgid "Policy GUID" -msgstr "" +msgstr "原則 GUID" #: src/tools/sssctl/sssctl_cache.c:40 msgid "Policy Path" -msgstr "" +msgstr "原則路徑" #: src/tools/sssctl/sssctl_cache.c:41 msgid "Policy file timeout" -msgstr "" +msgstr "原則檔逾時" #: src/tools/sssctl/sssctl_cache.c:42 msgid "Policy version" -msgstr "" +msgstr "原則版本" #: src/tools/sssctl/sssctl_cache.c:556 #, c-format msgid "Error: Unable to get object [%d]: %s\n" -msgstr "" +msgstr "錯誤:無法取得物件 [%d]:%s\n" #: src/tools/sssctl/sssctl_cache.c:572 src/tools/sssctl/sssctl_cache.c:927 #, c-format msgid "%s: Unable to read value [%d]: %s\n" -msgstr "" +msgstr "%s:無法讀取值 [%d]:%s\n" #: src/tools/sssctl/sssctl_cache.c:602 msgid "Specify name." -msgstr "" +msgstr "指定名稱。" #: src/tools/sssctl/sssctl_cache.c:612 #, c-format msgid "Unable to parse name %s.\n" -msgstr "" +msgstr "無法解析名稱 %s。\n" #: src/tools/sssctl/sssctl_cache.c:641 src/tools/sssctl/sssctl_cache.c:688 msgid "Search by SID" -msgstr "" +msgstr "依 SID 搜尋" #: src/tools/sssctl/sssctl_cache.c:642 msgid "Search by user ID" -msgstr "" +msgstr "依使用者 ID 搜尋" #: src/tools/sssctl/sssctl_cache.c:651 msgid "Initgroups expiration time" -msgstr "" +msgstr "initgroups 到期時間" #: src/tools/sssctl/sssctl_cache.c:689 msgid "Search by group ID" -msgstr "" +msgstr "依群組 ID 搜尋" #: src/tools/sssctl/sssctl_cache.c:778 src/tools/sssctl/sssctl_cache.c:1126 msgid "Search by GPO guid" -msgstr "" +msgstr "依 GPO guid 搜尋" #: src/tools/sssctl/sssctl_cache.c:785 src/tools/sssctl/sssctl_cache.c:1143 #, c-format msgid "Failed to parse command line: %s\n" -msgstr "" +msgstr "解析命令列失敗:%s\n" #: src/tools/sssctl/sssctl_cache.c:790 src/tools/sssctl/sssctl_cache.c:1148 #, c-format msgid "%s\n" -msgstr "" +msgstr "%s\n" #: src/tools/sssctl/sssctl_cache.c:803 #, c-format msgid "Failed to print object: %s\n" -msgstr "" +msgstr "顯示物件失敗:%s\n" #: src/tools/sssctl/sssctl_cache.c:835 src/tools/sssctl/sssctl_cache.c:918 #: src/tools/sssctl/sssctl_cache.c:950 src/tools/sssctl/sssctl_cache.c:956 @@ -2543,167 +2577,167 @@ msgstr "" #: src/tools/sssctl/sssctl_cache.c:1229 src/tools/sssctl/sssctl_cache.c:1235 #: src/tools/sssctl/sssctl_cache.c:1244 msgid "talloc failed\n" -msgstr "" +msgstr "talloc 失敗\n" #: src/tools/sssctl/sssctl_cache.c:841 msgid "Unable to get attribute list!\n" -msgstr "" +msgstr "無法取得屬性清單!\n" #: src/tools/sssctl/sssctl_cache.c:848 msgid "Unable to create filter\n" -msgstr "" +msgstr "無法建立篩選器\n" #: src/tools/sssctl/sssctl_cache.c:861 #, c-format msgid "%s [%s]:\n" -msgstr "" +msgstr "%s [%s]:\n" #: src/tools/sssctl/sssctl_cache.c:866 msgid "Unable to get GPOs base DN\n" -msgstr "" +msgstr "無法取得 GPO 基準 DN\n" #: src/tools/sssctl/sssctl_cache.c:876 #, c-format msgid "Unable to search sysdb: %s\n" -msgstr "" +msgstr "無法搜尋 sysdb:%s\n" #: src/tools/sssctl/sssctl_cache.c:882 #, c-format msgid "Unable to convert message to sysdb attrs: %s\n" -msgstr "" +msgstr "無法將訊息轉換為 sysdb 屬性:%s\n" #: src/tools/sssctl/sssctl_cache.c:931 #, c-format msgid "\t%s: %s\n" -msgstr "" +msgstr "\t%s:%s\n" #: src/tools/sssctl/sssctl_cache.c:933 src/tools/sssctl/sssctl_logs.c:50 msgid "\n" -msgstr "" +msgstr "\n" #: src/tools/sssctl/sssctl_cache.c:1016 msgid "Could not find GUID attribute from GPO entry\n" -msgstr "" +msgstr "無法從 GPO 項目找到 GUID 屬性\n" #: src/tools/sssctl/sssctl_cache.c:1023 msgid "Could not find description attribute from GPO entry\n" -msgstr "" +msgstr "無法從 GPO 項目找到描述屬性\n" #: src/tools/sssctl/sssctl_cache.c:1047 msgid "Could not delete GPO entry from cache\n" -msgstr "" +msgstr "無法從快取刪除 GPO 項目\n" #: src/tools/sssctl/sssctl_cache.c:1053 #, c-format msgid "" "The GPO path was not yet stored in cache. Please remove files manually from " "[%s]\n" -msgstr "" +msgstr "GPO 路徑尚未儲存在快取中。請手動從 [%s] 移除檔案\n" #: src/tools/sssctl/sssctl_cache.c:1062 src/tools/sssctl/sssctl_cache.c:1068 #, c-format msgid "Could not determine real path for [%s]: %s\n" -msgstr "" +msgstr "無法判斷 [%s] 的實際路徑:%s\n" #: src/tools/sssctl/sssctl_cache.c:1073 #, c-format msgid "The cached GPO path [%s] is not under [%s], ignoring.\n" -msgstr "" +msgstr "快取的 GPO 路徑 [%s] 不在 [%s] 之下,已忽略。\n" #: src/tools/sssctl/sssctl_cache.c:1098 #, c-format msgid "Unable to remove downloaded GPO files: %s\n" -msgstr "" +msgstr "無法移除已下載的 GPO 檔案:%s\n" #: src/tools/sssctl/sssctl_cache.c:1165 #, c-format msgid "Failed to fetch cache entry: %s\n" -msgstr "" +msgstr "取得快取項目失敗:%s\n" #: src/tools/sssctl/sssctl_cache.c:1170 msgid "Could not determine object domain\n" -msgstr "" +msgstr "無法判斷物件的網域\n" #: src/tools/sssctl/sssctl_cache.c:1200 msgid "Could not find GUID attribute in GPO entry\n" -msgstr "" +msgstr "無法在 GPO 項目中找到 GUID 屬性\n" #: src/tools/sssctl/sssctl_cache.c:1206 #, c-format msgid "Failed to delete GPO: %s\n" -msgstr "" +msgstr "刪除 GPO 失敗:%s\n" #: src/tools/sssctl/sssctl_cache.c:1210 #, c-format msgid "%s removed from cache\n" -msgstr "" +msgstr "%s 已從快取移除\n" #: src/tools/sssctl/sssctl_cert.c:50 src/tools/sssctl/sssctl_cert.c:108 #: src/tools/sssctl/sssctl_cert.c:214 msgid "Show debug information" -msgstr "" +msgstr "顯示除錯資訊" #: src/tools/sssctl/sssctl_cert.c:56 src/tools/sssctl/sssctl_cert.c:114 #: src/tools/sssctl/sssctl_cert.c:220 msgid "Specify base64 encoded certificate." -msgstr "" +msgstr "指定 base64 編碼的憑證。" #: src/tools/sssctl/sssctl_cert.c:138 src/tools/sssctl/sssctl_domains.c:104 #: src/tools/sssctl/sssctl_domains.c:366 #: src/tools/sssctl/sssctl_user_checks.c:99 msgid "Unable to connect to system bus!\n" -msgstr "" +msgstr "無法連線到系統匯流排!\n" #: src/tools/sssctl/sssctl_cert.c:164 msgid " - no mapped users found -" -msgstr "" +msgstr " - 未找到對應的使用者 -" #: src/tools/sssctl/sssctl_cert.c:212 msgid "Mapping rule" -msgstr "" +msgstr "對應規則" #: src/tools/sssctl/sssctl_cert.c:213 msgid "Matching rule" -msgstr "" +msgstr "比對規則" #: src/tools/sssctl/sssctl_cert.c:223 msgid "Unable to parse command arguments\n" -msgstr "" +msgstr "無法解析指令引數\n" #: src/tools/sssctl/sssctl_cert.c:229 src/tools/sssctl/sssctl_domains.c:354 msgid "Out of memory!\n" -msgstr "" +msgstr "記憶體耗盡!\n" #: src/tools/sssctl/sssctl_cert.c:238 msgid "Failed to setup certmap context.\n" -msgstr "" +msgstr "設定 certmap 環境失敗。\n" #: src/tools/sssctl/sssctl_cert.c:244 #, c-format msgid "Failed to add mapping and matching rules with error [%d][%s].\n" -msgstr "" +msgstr "新增對應與比對規則失敗,錯誤 [%d][%s]。\n" #: src/tools/sssctl/sssctl_cert.c:251 msgid "Failed to decode base64 string.\n" -msgstr "" +msgstr "解碼 base64 字串失敗。\n" #: src/tools/sssctl/sssctl_cert.c:259 msgid "Certificate matches rule.\n" -msgstr "" +msgstr "憑證符合規則。\n" #: src/tools/sssctl/sssctl_cert.c:262 msgid "Certificate does not match rule.\n" -msgstr "" +msgstr "憑證不符合規則。\n" #: src/tools/sssctl/sssctl_cert.c:265 #, c-format msgid "Error during certificate matching [%d][%s].\n" -msgstr "" +msgstr "憑證比對期間發生錯誤 [%d][%s]。\n" #: src/tools/sssctl/sssctl_cert.c:272 #, c-format msgid "Failed to generate mapping filter [%d][%s].\n" -msgstr "" +msgstr "產生對應篩選器失敗 [%d][%s]。\n" #: src/tools/sssctl/sssctl_cert.c:276 #, c-format @@ -2713,6 +2747,10 @@ msgid "" " %s\n" "\n" msgstr "" +"對應篩選器:\n" +"\n" +" %s\n" +"\n" #: src/tools/sssctl/sssctl_config.c:75 msgid "" @@ -2720,155 +2758,155 @@ msgid "" "where the main config file is located. For example if the config is set to " "\"/my/path/sssd.conf\", the snippet dir \"/my/path/conf.d\" is used)" msgstr "" +"指定非預設的片段目錄(預設會在主要設定檔所在的同一位置尋找。例如若設定為 \"/" +"my/path/sssd.conf\",則使用片段目錄 \"/my/path/conf.d\")" #: src/tools/sssctl/sssctl_config.c:114 #, c-format msgid "File %1$s does not exist.\n" -msgstr "" +msgstr "檔案 %1$s 不存在。\n" #: src/tools/sssctl/sssctl_config.c:115 msgid "There is no configuration.\n" -msgstr "" +msgstr "沒有任何設定。\n" #: src/tools/sssctl/sssctl_config.c:120 #, c-format msgid "Configuration validation failed: %s\n" -msgstr "" +msgstr "設定驗證失敗:%s\n" #: src/tools/sssctl/sssctl_config.c:121 msgid "Run with high debug level to see details.\n" -msgstr "" +msgstr "以高除錯層級執行以檢視詳細資訊。\n" #: src/tools/sssctl/sssctl_config.c:130 msgid "Failed to run validators" -msgstr "" +msgstr "執行驗證器失敗" #: src/tools/sssctl/sssctl_config.c:134 #, c-format msgid "Issues identified by validators: %zu\n" -msgstr "" +msgstr "驗證器識別出的問題:%zu\n" #: src/tools/sssctl/sssctl_config.c:145 #, c-format msgid "Messages generated during configuration merging: %zu\n" -msgstr "" +msgstr "設定合併期間產生的訊息:%zu\n" #: src/tools/sssctl/sssctl_config.c:158 #, c-format msgid "Used configuration snippet files: %zu\n" -msgstr "" +msgstr "使用的設定片段檔:%zu\n" #: src/tools/sssctl/sssctl_data.c:91 #, c-format msgid "Unable to create backup directory [%d]: %s" -msgstr "" +msgstr "無法建立備份目錄 [%d]:%s" #: src/tools/sssctl/sssctl_data.c:97 msgid "SSSD backup of local data already exists, override?" -msgstr "" +msgstr "SSSD 本機資料備份已存在,要覆寫嗎?" #: src/tools/sssctl/sssctl_data.c:113 msgid "Unable to export user overrides\n" -msgstr "" +msgstr "無法匯出使用者覆寫\n" #: src/tools/sssctl/sssctl_data.c:120 msgid "Unable to export group overrides\n" -msgstr "" +msgstr "無法匯出群組覆寫\n" #: src/tools/sssctl/sssctl_data.c:135 src/tools/sssctl/sssctl_data.c:216 msgid "Override existing backup" -msgstr "" +msgstr "覆寫既有的備份" #: src/tools/sssctl/sssctl_data.c:165 msgid "Unable to import user overrides\n" -msgstr "" +msgstr "無法匯入使用者覆寫\n" #: src/tools/sssctl/sssctl_data.c:174 msgid "Unable to import group overrides\n" -msgstr "" +msgstr "無法匯入群組覆寫\n" #: src/tools/sssctl/sssctl_data.c:194 src/tools/sssctl/sssctl_domains.c:81 #: src/tools/sssctl/sssctl_domains.c:326 msgid "Start SSSD if it is not running" -msgstr "" +msgstr "若 SSSD 未執行則啟動它" #: src/tools/sssctl/sssctl_data.c:195 msgid "Restart SSSD after data import" -msgstr "" +msgstr "資料匯入後重新啟動 SSSD" #: src/tools/sssctl/sssctl_data.c:217 msgid "Create clean cache files and import local data" -msgstr "" +msgstr "建立乾淨的快取檔並匯入本機資料" #: src/tools/sssctl/sssctl_data.c:218 msgid "Stop SSSD before removing the cache" -msgstr "" +msgstr "移除快取前停止 SSSD" #: src/tools/sssctl/sssctl_data.c:219 msgid "Start SSSD when the cache is removed" -msgstr "" +msgstr "移除快取後啟動 SSSD" #: src/tools/sssctl/sssctl_data.c:234 msgid "Creating backup of local data...\n" -msgstr "" +msgstr "正在建立本機資料備份...\n" #: src/tools/sssctl/sssctl_data.c:237 msgid "Unable to create backup of local data, can not remove the cache.\n" -msgstr "" +msgstr "無法建立本機資料備份,無法移除快取。\n" #: src/tools/sssctl/sssctl_data.c:242 msgid "Removing cache files...\n" -msgstr "" +msgstr "正在移除快取檔...\n" #: src/tools/sssctl/sssctl_data.c:245 msgid "Unable to remove cache files\n" -msgstr "" +msgstr "無法移除快取檔\n" #: src/tools/sssctl/sssctl_data.c:250 msgid "Restoring local data...\n" -msgstr "" +msgstr "正在還原本機資料...\n" #: src/tools/sssctl/sssctl_data.c:377 #, c-format msgid "Creating cache index for domain %1$s\n" -msgstr "" +msgstr "正在為網域 %1$s 建立快取索引\n" #: src/tools/sssctl/sssctl_data.c:379 #, c-format msgid "Deleting cache index for domain %1$s\n" -msgstr "" +msgstr "正在刪除網域 %1$s 的快取索引\n" #: src/tools/sssctl/sssctl_data.c:381 #, c-format msgid "Indexes for domain %1$s:\n" -msgstr "" +msgstr "網域 %1$s 的索引:\n" #: src/tools/sssctl/sssctl_data.c:401 #, c-format msgid " Attribute: %1$s\n" -msgstr "" +msgstr " 屬性:%1$s\n" #: src/tools/sssctl/sssctl_data.c:428 src/tools/sssctl/sssctl_logs.c:525 msgid "Target a specific domain" -msgstr "" +msgstr "指定目標網域" #: src/tools/sssctl/sssctl_data.c:428 src/tools/sssctl/sssctl_logs.c:525 -#, fuzzy msgid "domain" -msgstr "IPA 網域" +msgstr "網域" #: src/tools/sssctl/sssctl_data.c:430 msgid "Attribute to index" -msgstr "" +msgstr "要建立索引的屬性" #: src/tools/sssctl/sssctl_data.c:430 msgid "attribute" -msgstr "" +msgstr "屬性" #: src/tools/sssctl/sssctl_data.c:443 -#, fuzzy msgid "Action not provided\n" -msgstr "認證提供者" +msgstr "未提供動作\n" #: src/tools/sssctl/sssctl_data.c:456 #, c-format @@ -2876,235 +2914,237 @@ msgid "" "Unknown action: %1$s\n" "Valid actions are \"%2$s\", \"%3$s and \"%4$s\"\n" msgstr "" +"未知的動作:%1$s\n" +"有效的動作有「%2$s」、「%3$s」與「%4$s」\n" #: src/tools/sssctl/sssctl_data.c:464 msgid "Attribute (-a) not provided\n" -msgstr "" +msgstr "未提供屬性 (-a)\n" #: src/tools/sssctl/sssctl_data.c:472 #, c-format msgid "Attribute %1$s not indexed.\n" -msgstr "" +msgstr "屬性 %1$s 未建立索引。\n" #: src/tools/sssctl/sssctl_data.c:475 #, c-format msgid "Attribute %1$s already indexed.\n" -msgstr "" +msgstr "屬性 %1$s 已建立索引。\n" #: src/tools/sssctl/sssctl_data.c:478 #, c-format msgid "Index operation failed: %1$s\n" -msgstr "" +msgstr "索引作業失敗:%1$s\n" #: src/tools/sssctl/sssctl_data.c:483 msgid "Don't forget to also update the indexes on the remote providers.\n" -msgstr "" +msgstr "別忘了也要更新遠端提供者上的索引。\n" #: src/tools/sssctl/sssctl_domains.c:82 msgid "Show domain list including primary or trusted domain type" -msgstr "" +msgstr "顯示網域清單,包括主要或受信任的網域類型" #: src/tools/sssctl/sssctl_domains.c:166 msgid "Online" -msgstr "" +msgstr "線上" #: src/tools/sssctl/sssctl_domains.c:166 msgid "Offline" -msgstr "" +msgstr "離線" #: src/tools/sssctl/sssctl_domains.c:166 #, c-format msgid "Online status: %s\n" -msgstr "" +msgstr "線上狀態:%s\n" #: src/tools/sssctl/sssctl_domains.c:212 msgid "This domain has no active servers.\n" -msgstr "" +msgstr "此網域沒有作用中的伺服器。\n" #: src/tools/sssctl/sssctl_domains.c:217 msgid "Active servers:\n" -msgstr "" +msgstr "作用中的伺服器:\n" #: src/tools/sssctl/sssctl_domains.c:229 msgid "not connected" -msgstr "" +msgstr "未連線" #: src/tools/sssctl/sssctl_domains.c:266 msgid "No servers discovered.\n" -msgstr "" +msgstr "未探索到任何伺服器。\n" #: src/tools/sssctl/sssctl_domains.c:272 #, c-format msgid "Discovered %s servers:\n" -msgstr "" +msgstr "已探索到 %s 台伺服器:\n" #: src/tools/sssctl/sssctl_domains.c:284 msgid "None so far.\n" -msgstr "" +msgstr "目前沒有。\n" #: src/tools/sssctl/sssctl_domains.c:323 msgid "Show online status" -msgstr "" +msgstr "顯示線上狀態" #: src/tools/sssctl/sssctl_domains.c:324 msgid "Show information about active server" -msgstr "" +msgstr "顯示作用中伺服器的資訊" #: src/tools/sssctl/sssctl_domains.c:325 msgid "Show list of discovered servers" -msgstr "" +msgstr "顯示已探索到的伺服器清單" #: src/tools/sssctl/sssctl_domains.c:331 msgid "Specify domain name." -msgstr "" +msgstr "指定網域名稱。" #: src/tools/sssctl/sssctl_domains.c:374 src/tools/sssctl/sssctl_domains.c:384 msgid "Unable to get online status\n" -msgstr "" +msgstr "無法取得線上狀態\n" #: src/tools/sssctl/sssctl_domains.c:394 msgid "Unable to get server list\n" -msgstr "" +msgstr "無法取得伺服器清單\n" #: src/tools/sssctl/sssctl_logs.c:214 msgid "SSSD is not running.\n" -msgstr "" +msgstr "SSSD 未在執行。\n" #: src/tools/sssctl/sssctl_logs.c:231 #, c-format msgid "%1$-25s %2$#.4x\n" -msgstr "" +msgstr "%1$-25s %2$#.4x\n" #: src/tools/sssctl/sssctl_logs.c:235 #, c-format msgid "%1$-25s Unknown domain\n" -msgstr "" +msgstr "%1$-25s 未知的網域\n" #: src/tools/sssctl/sssctl_logs.c:237 #, c-format msgid "%1$-25s Unreachable service\n" -msgstr "" +msgstr "%1$-25s 無法連線的服務\n" #: src/tools/sssctl/sssctl_logs.c:429 msgid "Delete log files instead of truncating" -msgstr "" +msgstr "刪除日誌檔而非截斷" #: src/tools/sssctl/sssctl_logs.c:440 msgid "Deleting log files...\n" -msgstr "" +msgstr "正在刪除日誌檔...\n" #: src/tools/sssctl/sssctl_logs.c:443 msgid "Unable to remove log files\n" -msgstr "" +msgstr "無法移除日誌檔\n" #: src/tools/sssctl/sssctl_logs.c:460 msgid "Truncating log files...\n" -msgstr "" +msgstr "正在截斷日誌檔...\n" #: src/tools/sssctl/sssctl_logs.c:464 msgid "Unable to truncate log files\n" -msgstr "" +msgstr "無法截斷日誌檔\n" #: src/tools/sssctl/sssctl_logs.c:498 #, c-format msgid "Archiving log files into %s...\n" -msgstr "" +msgstr "正在將日誌檔封存到 %s...\n" #: src/tools/sssctl/sssctl_logs.c:502 msgid "Unable to archive log files\n" -msgstr "" +msgstr "無法封存日誌檔\n" #: src/tools/sssctl/sssctl_logs.c:526 msgid "Target the SSSD service" -msgstr "" +msgstr "指定目標為 SSSD 服務" #: src/tools/sssctl/sssctl_logs.c:527 msgid "Target the NSS service" -msgstr "" +msgstr "指定目標為 NSS 服務" #: src/tools/sssctl/sssctl_logs.c:528 msgid "Target the PAM service" -msgstr "" +msgstr "指定目標為 PAM 服務" #: src/tools/sssctl/sssctl_logs.c:529 msgid "Target the SUDO service" -msgstr "" +msgstr "指定目標為 SUDO 服務" #: src/tools/sssctl/sssctl_logs.c:530 msgid "Target the AUTOFS service" -msgstr "" +msgstr "指定目標為 AUTOFS 服務" #: src/tools/sssctl/sssctl_logs.c:531 msgid "Target the SSH service" -msgstr "" +msgstr "指定目標為 SSH 服務" #: src/tools/sssctl/sssctl_logs.c:532 msgid "Target the PAC service" -msgstr "" +msgstr "指定目標為 PAC 服務" #: src/tools/sssctl/sssctl_logs.c:533 msgid "Target the IFP service" -msgstr "" +msgstr "指定目標為 IFP 服務" #: src/tools/sssctl/sssctl_logs.c:548 msgid "Specify debug level you want to set" -msgstr "" +msgstr "指定要設定的除錯層級" #: src/tools/sssctl/sssctl_logs.c:593 msgid "ERROR: Tevent chain ID support missing, log analyzer is unsupported.\n" -msgstr "" +msgstr "錯誤:缺少 Tevent chain ID 支援,不支援日誌分析器。\n" #: src/tools/sssctl/sssctl_user_checks.c:121 msgid "SSSD InfoPipe user lookup result:\n" -msgstr "" +msgstr "SSSD InfoPipe 使用者查詢結果:\n" #: src/tools/sssctl/sssctl_user_checks.c:171 #, c-format msgid "dlopen failed with [%s].\n" -msgstr "" +msgstr "dlopen 以 [%s] 失敗。\n" #: src/tools/sssctl/sssctl_user_checks.c:178 #, c-format msgid "dlsym failed with [%s].\n" -msgstr "" +msgstr "dlsym 以 [%s] 失敗。\n" #: src/tools/sssctl/sssctl_user_checks.c:186 msgid "malloc failed.\n" -msgstr "" +msgstr "malloc 失敗。\n" #: src/tools/sssctl/sssctl_user_checks.c:193 #, c-format msgid "sss_getpwnam_r failed with [%d].\n" -msgstr "" +msgstr "sss_getpwnam_r 以 [%d] 失敗。\n" #: src/tools/sssctl/sssctl_user_checks.c:198 msgid "SSSD nss user lookup result:\n" -msgstr "" +msgstr "SSSD nss 使用者查詢結果:\n" #: src/tools/sssctl/sssctl_user_checks.c:199 #, c-format msgid " - user name: %s\n" -msgstr "" +msgstr " - 使用者名稱:%s\n" #: src/tools/sssctl/sssctl_user_checks.c:200 #, c-format msgid " - user id: %d\n" -msgstr "" +msgstr " - 使用者 id:%d\n" #: src/tools/sssctl/sssctl_user_checks.c:201 #, c-format msgid " - group id: %d\n" -msgstr "" +msgstr " - 群組 id:%d\n" #: src/tools/sssctl/sssctl_user_checks.c:202 #, c-format msgid " - gecos: %s\n" -msgstr "" +msgstr " - gecos:%s\n" #: src/tools/sssctl/sssctl_user_checks.c:203 #, c-format msgid " - home directory: %s\n" -msgstr "" +msgstr " - 家目錄:%s\n" #: src/tools/sssctl/sssctl_user_checks.c:204 #, c-format @@ -3112,18 +3152,20 @@ msgid "" " - shell: %s\n" "\n" msgstr "" +" - shell:%s\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:235 msgid "PAM action [auth|acct|setc|chau|open|clos], default: " -msgstr "" +msgstr "PAM 動作 [auth|acct|setc|chau|open|clos],預設: " #: src/tools/sssctl/sssctl_user_checks.c:238 msgid "PAM service, default: " -msgstr "" +msgstr "PAM 服務,預設: " #: src/tools/sssctl/sssctl_user_checks.c:243 msgid "Specify user name." -msgstr "" +msgstr "指定使用者名稱。" #: src/tools/sssctl/sssctl_user_checks.c:250 #, c-format @@ -3133,32 +3175,38 @@ msgid "" "service: %s\n" "\n" msgstr "" +"使用者:%s\n" +"動作:%s\n" +"服務:%s\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:255 #, c-format msgid "User name lookup with [%s] failed.\n" -msgstr "" +msgstr "使用 [%s] 查詢使用者名稱失敗。\n" #: src/tools/sssctl/sssctl_user_checks.c:260 #, c-format msgid "InfoPipe User lookup with [%s] failed.\n" -msgstr "" +msgstr "使用 [%s] 查詢 InfoPipe 使用者失敗。\n" #: src/tools/sssctl/sssctl_user_checks.c:266 #, c-format msgid "pam_start failed: %s\n" -msgstr "" +msgstr "pam_start 失敗:%s\n" #: src/tools/sssctl/sssctl_user_checks.c:272 msgid "" "testing pam_authenticate\n" "\n" msgstr "" +"正在測試 pam_authenticate\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:276 #, c-format msgid "pam_get_item failed: %s\n" -msgstr "" +msgstr "pam_get_item 失敗:%s\n" #: src/tools/sssctl/sssctl_user_checks.c:279 #, c-format @@ -3166,12 +3214,16 @@ msgid "" "pam_authenticate for user [%s]: %s\n" "\n" msgstr "" +"對使用者 [%s] 執行 pam_authenticate:%s\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:282 msgid "" "testing pam_chauthtok\n" "\n" msgstr "" +"正在測試 pam_chauthtok\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:284 #, c-format @@ -3179,12 +3231,16 @@ msgid "" "pam_chauthtok: %s\n" "\n" msgstr "" +"pam_chauthtok:%s\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:286 msgid "" "testing pam_acct_mgmt\n" "\n" msgstr "" +"正在測試 pam_acct_mgmt\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:288 #, c-format @@ -3192,12 +3248,16 @@ msgid "" "pam_acct_mgmt: %s\n" "\n" msgstr "" +"pam_acct_mgmt:%s\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:290 msgid "" "testing pam_setcred\n" "\n" msgstr "" +"正在測試 pam_setcred\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:292 #, c-format @@ -3205,12 +3265,16 @@ msgid "" "pam_setcred: [%s]\n" "\n" msgstr "" +"pam_setcred:[%s]\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:294 msgid "" "testing pam_open_session\n" "\n" msgstr "" +"正在測試 pam_open_session\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:296 #, c-format @@ -3218,12 +3282,16 @@ msgid "" "pam_open_session: %s\n" "\n" msgstr "" +"pam_open_session:%s\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:298 msgid "" "testing pam_close_session\n" "\n" msgstr "" +"正在測試 pam_close_session\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:300 #, c-format @@ -3231,18 +3299,20 @@ msgid "" "pam_close_session: %s\n" "\n" msgstr "" +"pam_close_session:%s\n" +"\n" #: src/tools/sssctl/sssctl_user_checks.c:302 msgid "unknown action\n" -msgstr "" +msgstr "未知的動作\n" #: src/tools/sssctl/sssctl_user_checks.c:305 msgid "PAM Environment:\n" -msgstr "" +msgstr "PAM 環境:\n" #: src/tools/sssctl/sssctl_user_checks.c:313 msgid " - no env -\n" -msgstr "" +msgstr " - 沒有環境 -\n" #: src/util/util.h:100 msgid "Specify a non-default config file" @@ -3250,7 +3320,7 @@ msgstr "指定非預設的配置檔" #: src/util/util.h:107 msgid "Informs that the responder has been socket-activated" -msgstr "" +msgstr "告知回應器已由 socket 啟動" #~ msgid "The UID of the user" #~ msgstr "使用者的 UID" diff --git a/src/man/po/es.po b/src/man/po/es.po index 441597ee982..91ec54b5f16 100644 --- a/src/man/po/es.po +++ b/src/man/po/es.po @@ -19,9 +19,8 @@ msgstr "" "Project-Id-Version: sssd-docs 2.3.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" "POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 16:38+0000\n" -"Last-Translator: Weblate Translation Memory \n" +"PO-Revision-Date: 2026-05-30 21:01+0000\n" +"Last-Translator: \"Fco. Javier F. Serrador\" \n" "Language-Team: Spanish \n" "Language: es\n" @@ -29,7 +28,7 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n != 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.5\n" #. type: Content of: #: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 @@ -65,17 +64,17 @@ msgstr "5" #: sss_rpcidmapd.5.xml:28 sssd-session-recording.5.xml:12 sssd-kcm.8.xml:12 #: sssd-systemtap.5.xml:12 sssd-ldap-attributes.5.xml:12 msgid "File Formats and Conventions" -msgstr "Formatos de archivo y convenciones" +msgstr "Formatos de Archivo y Convenciones" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd.conf.5.xml:20 msgid "the configuration file for SSSD" -msgstr "El archivo de configuración de SSSD" +msgstr "el archivo de configuración para SSSD" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:24 msgid "FILE FORMAT" -msgstr "Formato de archivo" +msgstr "FORMATO DE ARCHIVO" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd.conf.5.xml:32 @@ -100,7 +99,7 @@ msgid "" "until the next section begins. An example of section with single and multi-" "valued parameters: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" -"El archivo tiene una sintaxis de estilo-ini consistente de secciones y " +"El archivo tiene una sintaxis de estilo‐ini consistente de secciones y " "parámetros. Una sección comienza con el nombre de dicha sección colocado " "entre corchetes, y continua hasta que comienza la siguiente sección. Este es " "un ejemplo de una sección con parámetros de valores simples y múltiples: " @@ -3578,7 +3577,7 @@ msgid "" "<replaceable>groups</replaceable> options are recorded." msgstr "" "Usuarios/grupos especificados por las opciones <replaceable>users</" -"replaceable> y<replaceable>groups</replaceable> están registrados." +"replaceable> y <replaceable>groups</replaceable> están registrados." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2414 sssd-session-recording.5.xml:91 @@ -4696,7 +4695,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3246 msgid "<quote>none</quote> disables SUDO explicitly." -msgstr "<quote>none</quote>deshabilita SUDO explícitamente." +msgstr "<quote>none</quote> inhabilita SUDO explícitamente." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3249 @@ -6153,7 +6152,7 @@ msgid "" "options in the trusted domain section are:" msgstr "" "Algunas opciones usadas en la sección dominio puede ser usadas también en la " -"sección dominio de confianza, esto es, en una sección llamada<quote>[domain/" +"sección dominio de confianza, esto es, en una sección llamada <quote>[domain/" "<replaceable>DOMAIN_NAME</replaceable>/<replaceable>TRUSTED_DOMAIN_NAME</" "replaceable>]</quote>. Donde DOMAIN_NAME es el dominio base real. Por favor " "vea los ejemplos de abajo para una explicación. Actualmente las opciones " @@ -8639,7 +8638,7 @@ msgid "" "example SSH keys." msgstr "" "<emphasis>pwd_expire_policy_reject, pwd_expire_policy_warn, " -"pwd_expire_policy_renew: </emphasis>Estas opciones son útiles si los " +"pwd_expire_policy_renew: </emphasis> Estas opciones son útiles si los " "usuarios están interesados en que se les avise de que la contraseña está " "próxima a expirar y la autenticación está basada en la utilización de un " "método distinto a las contraseñas; por ejemplo claves SSH." @@ -13651,7 +13650,7 @@ msgstr "" "SSSD solo resuelve grupos de seguridad de Active Directory. Para obtener más " "información sobre los tipos de grupos de AD, consulte: <ulink url=\"https://" "docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/understand-" -"security-groups\">Grupos de seguridad de Active Directory</ulink>" +"security-groups\"> Grupos de seguridad de Active Directory</ulink>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:120 @@ -15914,7 +15913,7 @@ msgstr "sssd" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd.8.xml:16 msgid "System Security Services Daemon" -msgstr "Dæmon de Servicios de Seguridad del Sistema (SSSD)" +msgstr "Dæmon de Servicios de Seguridad del Sistema" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: sssd.8.xml:21 @@ -18072,7 +18071,7 @@ msgid "" "<manvolnum>3</manvolnum> </citerefentry> and includes: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" -"De forma predeterminada, el contestador de InfoPipe del interfaz `/User` " +"De forma predeterminada, el contestador de InfoPipe del interfaz `/Users` " "solo concede el conjunto predeterminado de atributos POSIX. Este conjunto es " "el mismo que devuelve <citerefentry> <refentrytitle>getpwnam</refentrytitle> " "<manvolnum>3</manvolnum> </citerefentry> e incluye: <placeholder " @@ -18102,7 +18101,7 @@ msgstr "" "Es posible añadir otro atributo a este conjunto usando <quote>+attr_name</" "quote> o eliminarlo explícitamente usando <quote>-attr_name</quote>. " "Atributos añadidos serán hechos disponibles en el segmento <quote>" -"extraAttributes>/quote>. Por ejemplo, para permitir <quote>telephoneNumber</" +"extraAttributes</quote>. Por ejemplo, para permitir <quote>telephoneNumber</" "quote> pero denegar <quote>loginShell</quote>, se usaría la siguiente " "configuración: <placeholder type=\"programlisting\" id=\"0\"/>" @@ -18554,8 +18553,8 @@ msgstr "" "<citerefentry><refentrytitle>ssh</refentrytitle> <manvolnum>1</manvolnum></" "citerefentry> puede ser configurado para usar <command>sss_ssh_knownhosts</" "command> para autenticación de la clave del host usando la opción <quote>" -"KnownHostsCommand</quote>: <placeholder type=\"programlisting\" id=\"0\"/>" -"Refuera a la página man <citerefentry><refentrytitle>ssh_config</" +"KnownHostsCommand</quote>: <placeholder type=\"programlisting\" id=\"0\"/> " +"Refiérase a la página man <citerefentry><refentrytitle>ssh_config</" "refentrytitle><manvolnum>5</manvolnum></citerefentry> para más detalles " "sobre esta opción." @@ -18611,8 +18610,8 @@ msgid "" msgstr "" "Las líneas de clave obtenidas desde el segundo plano son esperadas para " "respetar el formato de clave como se describió en la sección <quote>FORMATO " -"DE ARCHIVO SSH_KNOWN_HOSTS </quote> de <citerefentry><refentrytitle>sshd</" -"refentrytitle> <manvolnum>8</manvolnum></citerefentry>. sin embargo, " +"DE ARCHIVO SSH_KNOWN_HOSTS</quote> de <citerefentry><refentrytitle>sshd</" +"refentrytitle> <manvolnum>8</manvolnum></citerefentry>. Sin embargo, " "devolver solo el tipo de clave y la misma clave es tolerado, en cual caso, " "el nombre del host recibido como parámetro será añadido antes del tipo de " "clave a la salida una línea correctamente formada. El nombre de host será " diff --git a/src/man/po/fi.po b/src/man/po/fi.po index 75d91710b2e..5a519d10456 100644 --- a/src/man/po/fi.po +++ b/src/man/po/fi.po @@ -4,7 +4,7 @@ msgstr "" "Project-Id-Version: sssd-docs 2.3.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" "POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 16:42+0000\n" +"PO-Revision-Date: 2026-05-08 05:45+0000\n" "Last-Translator: Ricky Tigg <ricky.tigg@gmail.com>\n" "Language-Team: Finnish <https://translate.fedoraproject.org/projects/sssd/" "sssd-manpage-master/fi/>\n" @@ -13,7 +13,7 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n != 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 5.17.1\n" #. type: Content of: <reference><title> #: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 @@ -794,21 +794,6 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:606 -#, fuzzy -#| msgid "" -#| "Please, note that when this option is set the output format of all " -#| "commands is always fully-qualified even when using short names for input " -#| "<phrase condition=\"with_files_provider\"> , for all users but the ones " -#| "managed by the files provider </phrase>. In case the administrator wants " -#| "the output not fully-qualified, the full_name_format option can be used " -#| "as shown below: <quote>full_name_format=%1$s</quote> However, keep in " -#| "mind that during login, login applications often canonicalize the " -#| "username by calling <citerefentry> <refentrytitle>getpwnam</" -#| "refentrytitle> <manvolnum>3</manvolnum> </citerefentry> which, if a " -#| "shortname is returned for a qualified input (while trying to reach a user " -#| "which exists in multiple domains) might re-route the login attempt into " -#| "the domain which uses shortnames, making this workaround totally not " -#| "recommended in cases where usernames may overlap between domains." msgid "" "Please, note that when this option is set the output format of all commands " "is always fully-qualified even when using short names for input. In case " @@ -822,21 +807,19 @@ msgid "" "domain which uses shortnames, making this workaround totally not recommended " "in cases where usernames may overlap between domains." msgstr "" -"Huomaa, että kun tämä vaihtoehto on asetettu, kaikkien komentojen tulosteen " -"muoto on aina täysin määritelty, vaikka syötteelle käytettäisiin lyhyitä " -"nimiä <phrase condition=\"with_files_provider\"> kaikille käyttäjille paitsi " -"niille, joita tiedostotoimittaja hallitsee </phrase >. Jos " -"järjestelmänvalvoja haluaa, että tuloste ei ole täysin määritelty, " -"full_name_format -vaihtoehtoa voidaan käyttää alla olevan kuvan mukaisesti: " -"<quote>full_name_format=%1$s</quote> Muista kuitenkin, että " -"sisäänkirjautumisen aikana sisäänkirjautumissovellukset usein kanonisoivat " -"käyttäjänimen. kutsumalla <citerefentry> <refentrytitle>getpwnam</" -"refentrytitle> <manvolnum>3</manvolnum> </citerefentry> joka, jos lyhyt nimi " -"palautetaan pätevälle syötteelle (yritettäessä tavoittaa useissa " -"verkkotunnuksissa olevaa käyttäjää), saattaa ohjata kirjautumisyrityksen " -"uudelleen lyhyitä nimiä käyttävään verkkotunnukseen, joten tämä kiertotapa " -"ei ole suositeltavaa tapauksissa jossa käyttäjänimet voivat mennä " -"päällekkäin verkkotunnusten välillä." +"Huomaa, että kun tämä asetus on asetettu, kaikkien komentojen tulostusmuoto " +"on aina täysin määritelty, vaikka syötteenä käytettäisiin lyhyitä nimiä. Jos " +"ylläpitäjä ei halua tulosteen olevan täysin määritelty, full_name_format-" +"asetusta voidaan käyttää alla olevan mukaisesti: <quote>" +"full_name_format=%1$s</quote> Muista kuitenkin, että kirjautumisen aikana " +"kirjautumissovellukset usein kanonisoivat käyttäjätunnuksen kutsumalla " +"funktiota <citerefentry> <refentrytitle>getpwnam</refentrytitle> <manvolnum>" +"3</manvolnum> </citerefentry>. Jos pätevälle syötteelle palautetaan " +"lyhytnimi (yritettäessä tavoittaa käyttäjää, joka on useilla " +"verkkotunnuksilla), kirjautumisyritys saattaa reitittää uudelleen " +"verkkotunnukseen, joka käyttää lyhyitä nimiä. Tämä tekee tästä kiertotavasta " +"täysin epäsuositeltavaa tapauksissa, joissa käyttäjätunnukset voivat olla " +"päällekkäisiä eri verkkotunnusten välillä." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:630 sssd.conf.5.xml:1697 sssd.conf.5.xml:4224 @@ -12621,12 +12604,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-idp.5.xml:250 -#, fuzzy -#| msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" msgid "" "<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " "type=\"programlisting\" id=\"1\"/>" -msgstr "Esimerkki: <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" +"<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " +"type=\"programlisting\" id=\"1\"/>" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd.8.xml:10 sssd.8.xml:15 diff --git a/src/man/po/fr.po b/src/man/po/fr.po index 9f2b52f3d3e..56b5965f45e 100644 --- a/src/man/po/fr.po +++ b/src/man/po/fr.po @@ -18,8 +18,8 @@ msgstr "" "Project-Id-Version: sssd-docs 2.3.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" "POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 16:29+0000\n" -"Last-Translator: Anonymous <noreply@weblate.org>\n" +"PO-Revision-Date: 2026-07-28 11:22+0000\n" +"Last-Translator: red max <redmax761@gmail.com>\n" "Language-Team: French <https://translate.fedoraproject.org/projects/sssd/" "sssd-manpage-master/fr/>\n" "Language: fr\n" @@ -27,7 +27,7 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n > 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.7.1\n" #. type: Content of: <reference><title> #: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 @@ -119,6 +119,8 @@ msgid "" "A comment line starts with a hash sign (<quote>#</quote>) or a semicolon " "(<quote>;</quote>). Inline comments are not supported." msgstr "" +"Une ligne de commentaire commence par un dièse (#) ou un point-virgule (;). " +"Les commentaires en ligne ne sont pas pris en charge." #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:50 @@ -158,7 +160,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:66 msgid "CONFIGURATION SNIPPETS FROM INCLUDE DIRECTORY" -msgstr "" +msgstr "EXTRAITS DE CONFIGURATION DU RÉPERTOIRE INCLUDE" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:69 @@ -167,6 +169,9 @@ msgid "" "configuration snippets using the include directory <filename>conf.d</" "filename>." msgstr "" +"Le fichier de configuration <filename>sssd.conf</filename> inclura des " +"extraits de configuration utilisant le répertoire d'inclusion <filename>" +"conf.d</filename>." #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:75 @@ -176,6 +181,10 @@ msgid "" "(<quote>.</quote>) will be used together with <filename>sssd.conf</filename> " "to configure SSSD." msgstr "" +"Tout fichier placé dans <filename>conf.d</filename> qui se termine par " +"<quote><filename>.conf</filename></quote> et ne commence pas par un point " +"(<quote>.</quote>) sera utilisé avec <filename>sssd.conf</filename> pour " +"configurer SSSD." #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:83 @@ -189,6 +198,13 @@ msgid "" "<filename>02_snippet.conf</filename> etc.) can help visualize the priority " "(higher number means higher priority)." msgstr "" +"Les extraits de configuration du fichier `conf.d` sont prioritaires sur ceux " +"du fichier `sssd.conf` et prévalent sur ce dernier en cas de conflit. Si " +"plusieurs extraits sont présents dans `conf.d`, ils sont inclus par ordre " +"alphabétique (selon les paramètres régionaux). Les fichiers inclus en " +"dernier sont prioritaires. Les préfixes numériques (par exemple, " +"`01_snippet.conf`, `02_snippet.conf`, etc.) permettent de visualiser la " +"priorité (un nombre plus élevé indique une priorité plus importante)." #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:97 @@ -196,6 +212,8 @@ msgid "" "The snippet files require the same owner and permissions as " "<filename>sssd.conf</filename>." msgstr "" +"Les fichiers d'extrait nécessitent le même propriétaire et les mêmes " +"permissions que <filename>sssd.conf</filename>." #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:103 @@ -222,7 +240,7 @@ msgstr "debug_level (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:117 msgid "debug (integer)" -msgstr "" +msgstr "débogage (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:120 @@ -232,6 +250,10 @@ msgid "" "are specified, the value of <replaceable>debug_level</replaceable> will be " "used." msgstr "" +"SSSD 1.14 et versions ultérieures incluent également l'alias `<replaceable>" +"debug</replaceable>` pour `<replaceable>debug_level</replaceable>`, par " +"commodité. Si les deux sont spécifiés, la valeur de `<replaceable>" +"debug_level</replaceable>` sera utilisée." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:130 @@ -292,7 +314,7 @@ msgstr "debug_microseconds (booléen)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:159 msgid "Enable debug backtrace." -msgstr "" +msgstr "Activer le débogage par trace d'exécution." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:162 @@ -303,6 +325,11 @@ msgid "" "to 0 or 1 then only those error levels will trigger backtrace, otherwise up " "to 2)." msgstr "" +"Dans le cas où SSSD est exécuté avec debug_level inférieur à 9, tout est " +"enregistré dans un tampon circulaire en mémoire et vidé dans un fichier " +"journal sur toute erreur jusqu'à et y compris `min(0x0040, debug_level)` " +"(c'est-à-dire que si debug_level est explicitement défini sur 0 ou 1, seuls " +"ces niveaux d'erreur déclencheront une trace d'exécution, sinon jusqu'à 2)." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:171 @@ -310,6 +337,9 @@ msgid "" "Feature is only supported for `logger == files` (i.e. setting doesn't have " "effect for other logger types)." msgstr "" +"Cette fonctionnalité est uniquement prise en charge pour `logger == files` " +"(c'est-à-dire que ce paramètre n'a aucun effet pour les autres types de " +"journalisation)." #. type: Content of: outside any tag (error?) #: sssd.conf.5.xml:111 sssd.conf.5.xml:186 sssd-ldap.5.xml:1754 @@ -341,6 +371,10 @@ msgid "" "ensure that the process is alive and capable of answering requests. Note " "that after three missed heartbeats the process will terminate itself." msgstr "" +"Délai d'attente en secondes entre les pulsations de ce service. Ce délai " +"permet de s'assurer que le processus est actif et capable de répondre aux " +"requêtes. Veuillez noter qu'après trois pulsations manquées, le processus " +"s'arrêtera automatiquement." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:198 sssd.conf.5.xml:1199 sssd.conf.5.xml:1673 @@ -377,6 +411,10 @@ msgid "" "platforms where systemd is supported, as they will either be socket or D-Bus " "activated when needed. </phrase>" msgstr "" +"Liste, séparée par des virgules, des services qui démarrent au lancement de " +"sssd. <phrase condition=\"have_systemd\"> Cette liste de services est " +"facultative sur les plateformes prenant en charge systemd, car ils seront " +"activés par socket ou D-Bus selon les besoins. </phrase>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:234 @@ -406,6 +444,9 @@ msgid "" "and the administrator must enable the ones allowed to be used by executing: " "\"systemctl enable sssd-@service@.socket\". </phrase>" msgstr "" +"Par défaut, tous les services sont désactivés et l'administrateur doit " +"activer ceux qui sont autorisés en exécutant la commande : « systemctl " +"enable sssd-@service@.socket »." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:250 @@ -422,6 +463,13 @@ msgid "" "alphanumeric ASCII characters, dashes, dots and underscores. '/' character " "is forbidden." msgstr "" +"Un domaine est une base de données contenant des informations utilisateur. " +"SSSD peut utiliser plusieurs domaines simultanément, mais au moins un doit " +"être configuré pour que SSSD puisse démarrer. Ce paramètre décrit la liste " +"des domaines dans l'ordre de leur interrogation. Il est recommandé qu'un nom " +"de domaine contienne uniquement des caractères alphanumériques ASCII, des " +"tirets, des points et des traits de soulignement. Le caractère « / » est " +"interdit." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:266 sssd.conf.5.xml:3467 @@ -444,6 +492,10 @@ msgid "" "ID providers there are also default regular expressions. See DOMAIN SECTIONS " "for more info on these regular expressions." msgstr "" +"Chaque domaine peut avoir sa propre expression régulière configurée. " +"Certains fournisseurs d'identité proposent également des expressions " +"régulières par défaut. Consultez la section DOMAINE pour plus d'informations " +"sur ces expressions régulières." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:283 sssd.conf.5.xml:3524 @@ -512,11 +564,13 @@ msgid "" "Each domain can have an individual format string configured. See DOMAIN " "SECTIONS for more info on this option." msgstr "" +"Chaque domaine peut avoir une chaîne de format personnalisée. Consultez la " +"section SECTIONS DE DOMAINE pour plus d'informations sur cette option." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:329 msgid "monitor_resolv_conf (boolean)" -msgstr "" +msgstr "monitor_resolv_conf (booléen)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:332 @@ -524,6 +578,8 @@ msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" +"Contrôle si SSSD doit surveiller l'état de resolv.conf pour identifier quand " +"il doit mettre à jour son résolveur DNS interne." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:342 @@ -537,6 +593,9 @@ msgid "" "changes and will fall back to polling every five seconds if inotify cannot " "be used." msgstr "" +"Par défaut, SSSD tentera d'utiliser inotify pour surveiller les " +"modifications des fichiers de configuration et se rabattra sur un " +"interrogation toutes les cinq secondes si inotify ne peut pas être utilisé." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:351 @@ -611,6 +670,8 @@ msgid "" "Please note that this option is deprecated and domain_resolution_order " "should be used." msgstr "" +"Veuillez noter que cette option est obsolète et qu'il convient d'utiliser " +"domain_resolution_order." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:395 @@ -637,6 +698,12 @@ msgid "" "is not allowed to use this option together with use_fully_qualified_names " "set to False." msgstr "" +"Veuillez noter que si cette option est activée, tous les utilisateurs du " +"domaine principal devront utiliser leur nom complet (par exemple, " +"utilisateur@nom.domaine) pour se connecter. L'activation de cette option " +"modifie la valeur par défaut de `use_fully_qualified_names` et la définit " +"sur `True`. Il est impossible d'utiliser cette option simultanément avec " +"`use_fully_qualified_names` défini sur `False`." #. type: Content of: <variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:414 sssd-ldap.5.xml:937 sssd-ldap.5.xml:949 @@ -676,6 +743,11 @@ msgid "" "character SSSD tries to return the unmodified name but in general the result " "of a lookup is undefined." msgstr "" +"Veuillez noter que l'utilisation d'un caractère de remplacement susceptible " +"d'être utilisé dans les noms d'utilisateurs ou de groupes constitue une " +"erreur de configuration. Si un nom contient ce caractère, SSSD tente de " +"renvoyer le nom non modifié, mais le résultat de la recherche est " +"généralement indéfini." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:439 @@ -685,12 +757,12 @@ msgstr "Par défaut : non défini (les espaces ne seront pas remplacées)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:444 msgid "certificate_verification (string)" -msgstr "" +msgstr "vérification_certificat (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:452 msgid "no_ocsp" -msgstr "" +msgstr "no_ocsp" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:454 @@ -699,11 +771,14 @@ msgid "" "needed if the OCSP servers defined in the certificate are not reachable from " "the client." msgstr "" +"Désactive les vérifications OCSP (Online Certificate Status Protocol). Cela " +"peut s'avérer nécessaire si les serveurs OCSP définis dans le certificat ne " +"sont pas accessibles depuis le client." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:462 msgid "soft_ocsp" -msgstr "" +msgstr "soft_ocsp" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:464 @@ -712,11 +787,14 @@ msgid "" "skipped. This option should be used to allow authentication when the system " "is offline and the OCSP responder cannot be reached." msgstr "" +"Si aucune connexion ne peut être établie avec un serveur OCSP, la " +"vérification OCSP est ignorée. Cette option permet l'authentification " +"lorsque le système est hors ligne et que le serveur OCSP est inaccessible." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:474 msgid "ocsp_dgst" -msgstr "" +msgstr "ocsp_dgst" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:476 @@ -724,36 +802,40 @@ msgid "" "Digest (hash) function used to create the certificate ID for the OCSP " "request. Allowed values are:" msgstr "" +"Fonction de hachage utilisée pour créer l'identifiant du certificat pour la " +"requête OCSP. Les valeurs autorisées sont :" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:480 msgid "sha1" -msgstr "" +msgstr "sha1" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:481 msgid "sha256" -msgstr "" +msgstr "sha256" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:482 msgid "sha384" -msgstr "" +msgstr "Sha348" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:483 msgid "sha512" -msgstr "" +msgstr "Sha12" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:486 msgid "Default: sha1 (to allow compatibility with RFC5019-compliant responder)" msgstr "" +"Par défaut : sha1 (pour assurer la compatibilité avec les répondeurs " +"conformes à la norme RFC5019)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:492 msgid "no_verification" -msgstr "" +msgstr "aucune_vérification" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:494 @@ -761,11 +843,13 @@ msgid "" "Disables verification completely. This option should only be used for " "testing." msgstr "" +"Désactive complètement la vérification. Cette option ne doit être utilisée " +"qu'à des fins de test." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:500 msgid "partial_chain" -msgstr "" +msgstr "chaîne partielle" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:502 @@ -774,11 +858,16 @@ msgid "" "chain cannot be built to a self-signed trust-anchor, provided it is possible " "to construct a chain to a trusted certificate that might not be self-signed." msgstr "" +"Autoriser la vérification à réussir même si une chaîne <replaceable>" +"complète</replaceable> ne peut pas être construite jusqu'à une ancre de " +"confiance auto-signée, à condition qu'il soit possible de construire une " +"chaîne jusqu'à un certificat de confiance qui pourrait ne pas être auto-" +"signé." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:511 msgid "ocsp_default_responder=URL" -msgstr "" +msgstr "ocsp_default_responder=URL" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:513 @@ -787,11 +876,14 @@ msgid "" "mentioned in the certificate. URL must be replaced with the URL of the OCSP " "default responder e.g. http://example.com:80/ocsp." msgstr "" +"Définit le répondeur OCSP par défaut à utiliser à la place de celui " +"mentionné dans le certificat. L'URL doit être remplacée par celle du " +"répondeur OCSP par défaut, par exemple : http://example.com:80/ocsp." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:523 msgid "ocsp_default_responder_signing_cert=NAME" -msgstr "" +msgstr "ocsp_default_responder_signing_cert=NOM" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:525 @@ -799,11 +891,13 @@ msgid "" "This option is currently ignored. All needed certificates must be available " "in the PEM file given by pam_cert_db_path." msgstr "" +"Cette option est actuellement ignorée. Tous les certificats nécessaires " +"doivent être disponibles dans le fichier PEM indiqué par pam_cert_db_path." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:533 msgid "crl_file=/PATH/TO/CRL/FILE" -msgstr "" +msgstr "crl_file=/CHEMIN/VERS/CRL/FICHIER" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:535 @@ -825,7 +919,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:548 msgid "soft_crl" -msgstr "" +msgstr "soft_crl" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:551 @@ -835,6 +929,10 @@ msgid "" "This option should be used to allow authentication when the system is " "offline and the CRL cannot be renewed." msgstr "" +"Si une liste de révocation de certificats (CRL) a expiré, ignorez sa date " +"d'expiration et vérifiez les certificats associés à cette CRL expirée. Cette " +"option permet l'authentification lorsque le système est hors ligne et que la " +"CRL ne peut être renouvelée." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:447 @@ -843,21 +941,26 @@ msgid "" "separated list of options. Supported options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"Ce paramètre permet de personnaliser la vérification du certificat à l'aide " +"d'une liste d'options séparées par des virgules. Les options prises en " +"charge sont : <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:564 msgid "Unknown options are reported but ignored." -msgstr "" +msgstr "Les options inconnues sont signalées mais ignorées." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:567 msgid "Default: not set, i.e. do not restrict certificate verification" msgstr "" +"Par défaut : non défini, c’est-à-dire que la vérification des certificats " +"n’est pas restreinte." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:573 msgid "disable_netlink (boolean)" -msgstr "" +msgstr "désactiver_netlink (booléen)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:576 @@ -865,6 +968,9 @@ msgid "" "SSSD hooks into the netlink interface to monitor changes to routes, " "addresses, links and trigger certain actions." msgstr "" +"SSSD s'intègre à l'interface netlink pour surveiller les modifications " +"apportées aux routes, aux adresses et aux liens, et déclencher certaines " +"actions." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:581 @@ -872,16 +978,19 @@ msgid "" "The SSSD state changes caused by netlink events may be undesirable and can " "be disabled by setting this option to 'true'" msgstr "" +"Les modifications d'état SSSD provoquées par les événements netlink peuvent " +"être indésirables et peuvent être désactivées en définissant cette option " +"sur « true »." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:586 msgid "Default: false (netlink changes are detected)" -msgstr "" +msgstr "Par défaut : faux (les modifications du réseau sont détectées)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:591 msgid "domain_resolution_order" -msgstr "" +msgstr "ordre_de_résolution_de_domaine" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:594 @@ -893,6 +1002,12 @@ msgid "" "subdomains which are not listed as part of <quote>lookup_order</quote> will " "be looked up in a random order for each parent domain." msgstr "" +"Liste de domaines et sous-domaines séparés par des virgules, indiquant " +"l'ordre de recherche à suivre. Cette liste n'a pas besoin d'être exhaustive, " +"car les domaines manquants seront recherchés selon l'ordre défini dans " +"l'option de configuration `<quote>domains</quote>`. Les sous-domaines non " +"listés dans `<quote>lookup_order</quote>` seront recherchés de manière " +"aléatoire pour chaque domaine parent." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:606 @@ -909,6 +1024,19 @@ msgid "" "domain which uses shortnames, making this workaround totally not recommended " "in cases where usernames may overlap between domains." msgstr "" +"Veuillez noter que lorsque cette option est activée, le format de sortie de " +"toutes les commandes est toujours complet, même avec des noms courts en " +"entrée. Si l'administrateur souhaite une sortie non complète, l'option " +"`full_name_format` peut être utilisée comme suit : `<quote>" +"full_name_format=%1$s</quote>`. Cependant, lors de la connexion, les " +"applications normalisent souvent le nom d'utilisateur en appelant " +"`<citerefentry> <refentrytitle>getpwnam</refentrytitle> <manvolnum>3</" +"manvolnum> </citerefentry>`. Si un nom court est renvoyé pour une entrée " +"qualifiée (lors de la tentative de connexion à un utilisateur présent sur " +"plusieurs domaines), la tentative de connexion peut être redirigée vers le " +"domaine utilisant les noms courts. Cette solution est donc fortement " +"déconseillée lorsque des noms d'utilisateur peuvent se chevaucher entre " +"plusieurs domaines." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:630 sssd.conf.5.xml:1697 sssd.conf.5.xml:4224 @@ -931,6 +1059,9 @@ msgid "" "evaluate and check the PAC. If it has to be disabled set this option to " "'false'." msgstr "" +"Le répondeur PAC est activé automatiquement pour permettre au fournisseur " +"IPA et AD d'évaluer et de vérifier le PAC. Si vous devez le désactiver, " +"définissez cette option sur « false »." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:649 @@ -947,6 +1078,11 @@ msgid "" "passwords. See man page prctl:PR_SET_DUMPABLE on Linux or " "procctl:PROC_TRACE_CTL on FreeBSD for details." msgstr "" +"Cette option permet de renforcer la sécurité du système : la désactiver " +"empêche la création de fichiers core pour tous les processus SSSD afin " +"d'éviter la divulgation des mots de passe en clair. Consultez la page de " +"manuel de `prctl:PR_SET_DUMPABLE` sous Linux ou de `procctl:PROC_TRACE_CTL` " +"sous FreeBSD pour plus de détails." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:660 @@ -956,6 +1092,10 @@ msgid "" "data in a memory and their behavior in this regards is governed by /proc/sys/" "fs/suid_dumpable system setting." msgstr "" +"Veuillez noter que ce paramètre n'a aucun effet sur 'ldap_child', " +"'krb5_child' et 'sssd_pam', car ces binaires privilégiés peuvent avoir une " +"copie des données keytab de l'hôte en mémoire et leur comportement à cet " +"égard est régi par le paramètre système /proc/sys/fs/suid_dumpable." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:673 @@ -977,6 +1117,9 @@ msgid "" "Enable or disable the user verification (i.e. PIN, fingerprint) during " "authentication. If enabled, the PIN will always be requested." msgstr "" +"Activez ou désactivez la vérification de l'utilisateur (code PIN, empreinte " +"digitale, etc.) lors de l'authentification. Si elle est activée, le code PIN " +"sera systématiquement demandé." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:689 @@ -985,20 +1128,20 @@ msgid "" "kerberos pre-authentication case, this value will be overwritten by the " "server." msgstr "" +"Par défaut, ce sont les paramètres clés qui déterminent le comportement à " +"adopter. Dans le cas d'une pré-authentification IPA ou Kerberos, cette " +"valeur sera remplacée par celle du serveur." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:676 -#, fuzzy -#| msgid "" -#| "The following expansions are supported: <placeholder " -#| "type=\"variablelist\" id=\"0\"/>" msgid "" "With this parameter the passkey verification can be tuned with a comma " "separated list of options. Supported options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" -"Les expansions suivantes sont prises en charge : <placeholder " -"type=\"variablelist\" id=\"0\"/>" +"Ce paramètre permet de personnaliser la vérification du code d'accès à " +"l'aide d'une liste d'options séparées par des virgules. Les options prises " +"en charge sont : <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:213 @@ -1063,7 +1206,7 @@ msgstr "" "peuvent être ouverts en même temps par ce processus SSSD. Sur les systèmes " "où SSSD se voit accorder la capacité CAP_SYS_RESOURCE, ce sera une limite " "absolue. Sur les systèmes sans cette capacité, la valeur résultante sera la " -"valeur inférieure ou la limite « hard » de limits.conf." +"valeur inférieure ou la limite « hard » de limits.conf." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:735 @@ -1084,13 +1227,16 @@ msgid "" "can't be shorter than 10 seconds. If a lower value is configured, it will be " "adjusted to 10 seconds." msgstr "" +"Cette option spécifie la durée pendant laquelle un client d'un processus " +"SSSD peut conserver un descripteur de fichier sans communiquer avec celui-" +"ci. Cette valeur est limitée afin d'éviter la saturation des ressources " +"système. Le délai d'expiration ne peut être inférieur à 10 secondes. Si une " +"valeur inférieure est configurée, elle sera ramenée à 10 secondes." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:752 -#, fuzzy -#| msgid "Default: 300" msgid "Default: 60, KCM: 300" -msgstr "Par défaut : 300" +msgstr "Valeur par défaut : 60, KCM : 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:757 @@ -1107,6 +1253,12 @@ msgid "" "time for the previous ones. After each unsuccessful attempt to go online, " "the new interval is recalculated by the following:" msgstr "" +"Lorsque SSSD passe en mode hors ligne, le délai avant la prochaine tentative " +"de connexion augmente en fonction de la durée de la déconnexion. Par défaut, " +"SSSD utilise un calcul incrémentiel pour allonger ce délai. Ainsi, le temps " +"d'attente pour une nouvelle tentative est plus long que pour les " +"précédentes. Après chaque tentative infructueuse de connexion, le nouvel " +"intervalle est recalculé comme suit :" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:771 sssd.conf.5.xml:827 @@ -1114,6 +1266,8 @@ msgid "" "new_delay = Minimum(old_delay * 2, offline_timeout_max) + " "random[0...offline_timeout_random_offset]" msgstr "" +"nouveau_délai = Minimum(ancien_délai * 2, délai_d'inactivité_max) + " +"aléatoire[0...décalage_aléatoire_d'inactivité]" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:774 @@ -1122,6 +1276,10 @@ msgid "" "value is 3600. The offline_timeout_random_offset default value is 30. The " "end result is amount of seconds before next retry." msgstr "" +"La valeur par défaut de offline_timeout est de 60. La valeur par défaut de " +"offline_timeout_max est de 3600. La valeur par défaut de " +"offline_timeout_random_offset est de 30. Le résultat final correspond au " +"nombre de secondes avant la prochaine tentative." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:780 @@ -1129,6 +1287,8 @@ msgid "" "Note that the maximum length of each interval is defined by " "offline_timeout_max (apart of random part)." msgstr "" +"Notez que la longueur maximale de chaque intervalle est définie par " +"offline_timeout_max (à l'exception de la partie aléatoire)." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:784 sssd.conf.5.xml:1110 sssd.conf.5.xml:1490 @@ -1138,10 +1298,8 @@ msgstr "Par défaut : 60" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:789 -#, fuzzy -#| msgid "offline_timeout (integer)" msgid "offline_timeout_max (integer)" -msgstr "offline_timeout (entier)" +msgstr "délai_d'inactivité_max (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:792 @@ -1149,11 +1307,13 @@ msgid "" "Controls by how much the time between attempts to go online can be " "incremented following unsuccessful attempts to go online." msgstr "" +"Contrôle la façon dont le délai entre les tentatives de connexion peut être " +"incrémenté après des tentatives infructueuses." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:797 msgid "A value of 0 disables the incrementing behaviour." -msgstr "" +msgstr "La valeur 0 désactive l'incrémentation." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:800 @@ -1161,6 +1321,8 @@ msgid "" "The value of this parameter should be set in correlation to offline_timeout " "parameter value." msgstr "" +"La valeur de ce paramètre doit être définie en corrélation avec la valeur du " +"paramètre offline_timeout." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:804 @@ -1170,6 +1332,10 @@ msgid "" "rule here should be to set offline_timeout_max to at least 4 times " "offline_timeout." msgstr "" +"Avec offline_timeout fixé à 60 (valeur par défaut), il est inutile de " +"définir offline_timeout_max à moins de 120, car cette valeur sera " +"immédiatement saturée. En règle générale, il est conseillé de définir " +"offline_timeout_max à au moins quatre fois la valeur de offline_timeout." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:810 @@ -1177,20 +1343,19 @@ msgid "" "Although a value between 0 and offline_timeout may be specified, it has the " "effect of overriding the offline_timeout value so is of little use." msgstr "" +"Bien qu'une valeur comprise entre 0 et offline_timeout puisse être " +"spécifiée, elle a pour effet de remplacer la valeur offline_timeout et " +"s'avère donc peu utile." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:815 -#, fuzzy -#| msgid "Default: 300" msgid "Default: 3600" -msgstr "Par défaut : 300" +msgstr "Default: 3600" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:820 -#, fuzzy -#| msgid "offline_timeout + random_offset" msgid "offline_timeout_random_offset (integer)" -msgstr "offline_timeout + random_offset" +msgstr "délai_d'inactivité_aléatoire (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:823 @@ -1198,6 +1363,8 @@ msgid "" "When SSSD is in offline mode it keeps probing backend servers in specified " "time intervals:" msgstr "" +"Lorsque SSSD est en mode hors ligne, il continue d'interroger les serveurs " +"backend à intervalles de temps spécifiés :" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:830 @@ -1205,6 +1372,9 @@ msgid "" "This parameter controls the value of the random offset used for the above " "equation. Final random_offset value will be random number in range:" msgstr "" +"Ce paramètre contrôle la valeur du décalage aléatoire utilisé pour " +"l'équation ci-dessus. La valeur finale de random_offset sera un nombre " +"aléatoire compris dans la plage :" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:835 @@ -1216,19 +1386,19 @@ msgstr "offline_timeout + random_offset" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:838 msgid "A value of 0 disables the random offset addition." -msgstr "" +msgstr "La valeur 0 désactive l'ajout de décalage aléatoire." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:841 #, fuzzy #| msgid "Default: 300" msgid "Default: 30" -msgstr "Par défaut : 300" +msgstr "Par défaut : 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:846 msgid "responder_idle_timeout" -msgstr "" +msgstr "La valeur 0 désactive l'ajout de décalage aléatoire." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:849 @@ -1241,6 +1411,12 @@ msgid "" "built with systemd support and when services are either socket or D-Bus " "activated." msgstr "" +"Cette option spécifie la durée maximale d'inactivité (en secondes) d'un " +"processus répondeur SSSD. Cette limite est imposée afin d'éviter la " +"saturation des ressources système. La valeur minimale acceptable est de 60 " +"secondes. Définir cette option sur 0 (zéro) désactive le délai d'expiration " +"du répondeur. Cette option n'est effective que si SSSD est compilé avec le " +"support de systemd et si les services sont activés via socket ou D-Bus." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:863 sssd.conf.5.xml:1123 sssd.conf.5.xml:2248 @@ -1251,7 +1427,7 @@ msgstr "Par défaut : 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:868 msgid "cache_first" -msgstr "" +msgstr "cache_first" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:871 @@ -1259,6 +1435,8 @@ msgid "" "This option specifies whether the responder should query all caches before " "querying the Data Providers." msgstr "" +"Cette option indique si le répondeur doit interroger tous les caches avant " +"d'interroger les fournisseurs de données." #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:883 @@ -1377,6 +1555,11 @@ msgid "" "also be set per-domain or include fully-qualified names to filter only users " "from the particular domain or by a user principal name (UPN)." msgstr "" +"Excluez certains utilisateurs ou groupes de la base de données NSS. Cette " +"option est particulièrement utile pour les comptes système. Elle peut être " +"configurée par domaine ou inclure les noms de domaine complets pour filtrer " +"uniquement les utilisateurs d'un domaine spécifique ou par nom d'utilisateur " +"principal (UPN)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:959 @@ -1386,6 +1569,10 @@ msgid "" "NSS. E.g. a group having a member group filtered out will still have the " "member users of the latter listed." msgstr "" +"REMARQUE : L’option filter_groups n’affecte pas l’héritage des membres de " +"groupes imbriqués, car le filtrage intervient après leur propagation pour le " +"retour via NSS. Par exemple, un groupe dont un sous-groupe est exclu " +"affichera toujours les utilisateurs membres de ce dernier." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:967 @@ -1515,6 +1702,8 @@ msgstr "" #: sssd.conf.5.xml:1045 msgid "The wildcard (*) can be used to allow any shell." msgstr "" +"Le caractère générique (*) peut être utilisé pour autoriser n'importe quel " +"shell." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1048 @@ -1523,6 +1712,10 @@ msgid "" "shell is not in <quote>/etc/shells</quote> and maintaining list of all " "allowed shells in allowed_shells would be to much overhead." msgstr "" +"L'astérisque (*) est utile si vous souhaitez utiliser shell_fallback au cas " +"où le shell de cet utilisateur ne se trouverait pas dans <quote>/etc/shells</" +"quote> et que la maintenance d'une liste de tous les shells autorisés dans " +"allowed_shells représenterait une surcharge trop importante." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1055 @@ -1619,10 +1812,8 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1115 -#, fuzzy -#| msgid "enum_cache_timeout (integer)" msgid "memcache_timeout (integer)" -msgstr "enum_cache_timeout (entier)" +msgstr "memcache_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1118 @@ -1630,6 +1821,8 @@ msgid "" "Specifies time in seconds for which records in the in-memory cache will be " "valid. Setting this option to zero will disable the in-memory cache." msgstr "" +"Spécifie la durée, en secondes, de validité des enregistrements dans le " +"cache en mémoire. Définir cette option à zéro désactive le cache en mémoire." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1126 @@ -1637,6 +1830,9 @@ msgid "" "WARNING: Disabling the in-memory cache will have significant negative impact " "on SSSD's performance and should only be used for testing." msgstr "" +"AVERTISSEMENT : La désactivation du cache en mémoire aura un impact négatif " +"important sur les performances de SSSD et ne doit être utilisée qu’à des " +"fins de test." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1132 sssd.conf.5.xml:1157 sssd.conf.5.xml:1182 @@ -1645,6 +1841,9 @@ msgid "" "NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", " "client applications will not use the fast in-memory cache." msgstr "" +"REMARQUE : Si la variable d'environnement SSS_NSS_USE_MEMCACHE est définie " +"sur « NO », les applications clientes n'utiliseront pas le cache en mémoire " +"rapide." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1140 @@ -1660,6 +1859,9 @@ msgid "" "for passwd requests. Setting the size to 0 will disable the passwd in-" "memory cache." msgstr "" +"Taille (en mégaoctets) de la table de données allouée dans le cache mémoire " +"rapide pour les requêtes passwd. Définir cette taille à 0 désactive le cache " +"mémoire passwd." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1149 sssd.conf.5.xml:2888 sssd-ldap.5.xml:604 @@ -1673,6 +1875,8 @@ msgid "" "WARNING: Disabled or too small in-memory cache can have significant negative " "impact on SSSD's performance." msgstr "" +"AVERTISSEMENT : Un cache en mémoire désactivé ou trop petit peut avoir un " +"impact négatif important sur les performances de SSSD." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1165 @@ -1688,6 +1892,9 @@ msgid "" "for group requests. Setting the size to 0 will disable the group in-memory " "cache." msgstr "" +"Taille (en mégaoctets) de la table de données allouée dans le cache mémoire " +"rapide pour les requêtes groupées. Définir cette taille à 0 désactive le " +"cache mémoire groupé." #. type: Content of: <variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1174 sssd.conf.5.xml:1226 sssd.conf.5.xml:3656 @@ -1710,6 +1917,9 @@ msgid "" "for initgroups requests. Setting the size to 0 will disable the initgroups " "in-memory cache." msgstr "" +"Taille (en mégaoctets) de la table de données allouée dans le cache mémoire " +"rapide pour les requêtes initgroups. Définir cette taille à 0 désactive le " +"cache mémoire des initgroups." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1215 @@ -1726,6 +1936,10 @@ msgid "" "currently cached in fast in-memory cache. Setting the size to 0 will " "disable the SID in-memory cache." msgstr "" +"Taille (en mégaoctets) de la table de données allouée dans le cache mémoire " +"rapide pour les requêtes liées au SID. Seules les requêtes SID-by-ID et ID-" +"by-SID sont actuellement mises en cache. Définir la taille à 0 désactivera " +"le cache mémoire des SID." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:1242 sssd-ifp.5.xml:90 @@ -1742,6 +1956,11 @@ msgid "" "<citerefentry> <refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</" "manvolnum> </citerefentry> for details) but with no default values." msgstr "" +"Certaines requêtes supplémentaires du répondeur NSS peuvent renvoyer plus " +"d'attributs que ceux définis par l'interface NSS au format POSIX. La liste " +"des attributs est contrôlée par cette option. Elle est gérée de la même " +"manière que l'option `user_attributes` du répondeur InfoPipe (voir `sssd-" +"ifp` pour plus de détails), mais sans valeurs par défaut." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1258 @@ -1749,6 +1968,8 @@ msgid "" "To make configuration more easy the NSS responder will check the InfoPipe " "option if it is not set for the NSS responder." msgstr "" +"Pour simplifier la configuration, le répondeur NSS vérifiera l'option " +"InfoPipe si elle n'est pas définie pour le répondeur NSS." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1263 @@ -1758,7 +1979,7 @@ msgstr "Par défaut : non défini, repli sur l'option InfoPipe" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1268 msgid "pwfield (string)" -msgstr "" +msgstr "pwfield (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1271 @@ -1766,13 +1987,15 @@ msgid "" "The value that NSS operations that return users or groups will return for " "the <quote>password</quote> field." msgstr "" +"La valeur que les opérations NSS qui renvoient des utilisateurs ou des " +"groupes renverront pour le champ <quote>mot de passe</quote>." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1276 #, fuzzy #| msgid "Default: <quote>permit</quote>" msgid "Default: <quote>*</quote>" -msgstr "Par défaut : <quote>permit</quote>" +msgstr "Par défaut : <quote>permit</quote>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1279 @@ -1789,6 +2012,8 @@ msgid "" "Default: <quote>not set</quote> (remote domains), <quote>x</quote> (proxy " "domain with nss_files and sssd-shadowutils target)" msgstr "" +"Par défaut : <quote>non défini</quote> (domaines distants), <quote>x</quote> " +"(domaine proxy avec nss_files et cible sssd-shadowutils)" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:1292 @@ -1931,6 +2156,11 @@ msgid "" "responses sent to pam_sss e.g. messages displayed to the user or environment " "variables which should be set by pam_sss." msgstr "" +"Une liste de chaînes de caractères séparées par des virgules permettant de " +"supprimer (filtrer) les données envoyées par le répondeur PAM au module PAM " +"pam_sss. Différents types de réponses sont envoyés à pam_sss, par exemple " +"des messages affichés à l'utilisateur ou des variables d'environnement que " +"pam_sss doit définir." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1388 @@ -1938,36 +2168,39 @@ msgid "" "While messages already can be controlled with the help of the pam_verbosity " "option this option allows to filter out other kind of responses as well." msgstr "" +"Bien que les messages puissent déjà être contrôlés grâce à l'option " +"pam_verbosity, cette option permet également de filtrer d'autres types de " +"réponses." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1395 msgid "ENV" -msgstr "" +msgstr "ENV" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1396 msgid "Do not send any environment variables to any service." -msgstr "" +msgstr "N'envoyez aucune variable d'environnement à aucun service." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1399 msgid "ENV:var_name" -msgstr "" +msgstr "ENV:var_name" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1400 msgid "Do not send environment variable var_name to any service." -msgstr "" +msgstr "Ne transmettez la variable d'environnement var_name à aucun service." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1404 msgid "ENV:var_name:service" -msgstr "" +msgstr "ENV:var_name:service" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1405 msgid "Do not send environment variable var_name to service." -msgstr "" +msgstr "Ne transmettez pas la variable d'environnement var_name au service." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1393 @@ -1975,6 +2208,8 @@ msgid "" "Currently the following filters are supported: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"Les filtres suivants sont actuellement pris en charge : <placeholder " +"type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1412 @@ -1986,17 +2221,24 @@ msgid "" "that either all list elements must have a '+' or '-' prefix or none. It is " "considered as an error to mix both styles." msgstr "" +"La liste de chaînes de caractères peut soit constituer la liste des filtres, " +"qui définira cette liste et remplacera les valeurs par défaut, soit être " +"précédée d'un caractère « + » ou « - » pour ajouter ou supprimer le filtre " +"des valeurs par défaut existantes. Veuillez noter que tous les éléments de " +"la liste doivent être précédés d'un « + » ou d'un « - », ou aucun. Mélanger " +"les deux styles est considéré comme une erreur." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1423 msgid "Default: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" -msgstr "" +msgstr "Valeur par défaut : ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1426 msgid "" "Example: -ENV:KRB5CCNAME:sudo-i will remove the filter from the default list" msgstr "" +"Exemple : -ENV:KRB5CCNAME:sudo-i supprimera le filtre de la liste par défaut" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1433 @@ -2089,11 +2331,17 @@ msgid "" "<quote>pam_public_domains</quote>. User names are resolved to UIDs at " "startup." msgstr "" +"Spécifie la liste, séparée par des virgules, des UID ou des noms " +"d'utilisateur autorisés à effectuer des conversations PAM sur les domaines " +"de confiance. Les utilisateurs non inclus dans cette liste peuvent " +"uniquement accéder aux domaines marqués comme publics avec " +"`pam_public_domains`. Les noms d'utilisateur sont résolus en UID au " +"démarrage." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1508 msgid "Default: All users are considered trusted by default" -msgstr "" +msgstr "Par défaut : Tous les utilisateurs sont considérés comme fiables." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1512 @@ -2101,6 +2349,8 @@ msgid "" "Please note that UID 0 is always allowed to access the PAM responder even in " "case it is not in the pam_trusted_users list." msgstr "" +"Veuillez noter que l'UID 0 est toujours autorisé à accéder au répondeur PAM " +"même s'il ne figure pas dans la liste pam_trusted_users." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1519 @@ -2113,6 +2363,8 @@ msgid "" "Specifies the comma-separated list of domain names that are accessible even " "to untrusted users." msgstr "" +"Spécifie la liste, séparée par des virgules, des noms de domaine accessibles " +"même aux utilisateurs non fiables." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1526 @@ -2153,6 +2405,8 @@ msgid "" "Allows a custom expiration message to be set, replacing the default " "'Permission denied' message." msgstr "" +"Permet de définir un message d'expiration personnalisé, remplaçant le " +"message par défaut « Permission refusée »." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1551 @@ -2160,6 +2414,9 @@ msgid "" "Note: Please be aware that message is only printed for the SSH service " "unless pam_verbosity is set to 3 (show all messages and debug information)." msgstr "" +"Remarque : Veuillez noter que ce message n'est imprimé que pour le service " +"SSH, sauf si pam_verbosity est défini sur 3 (afficher tous les messages et " +"les informations de débogage)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1559 @@ -2168,11 +2425,14 @@ msgid "" "pam_account_expired_message = Account expired, please contact help desk.\n" " " msgstr "" +"pam_account_expired_message = Compte expiré, veuillez contacter le service " +"d'assistance.\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1568 msgid "pam_account_locked_message (string)" -msgstr "" +msgstr "pam_account_locked_message (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1571 @@ -2180,6 +2440,8 @@ msgid "" "Allows a custom lockout message to be set, replacing the default 'Permission " "denied' message." msgstr "" +"Permet de définir un message de verrouillage personnalisé, remplaçant le " +"message par défaut « Permission refusée »." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1578 @@ -2188,6 +2450,9 @@ msgid "" "pam_account_locked_message = Account locked, please contact help desk.\n" " " msgstr "" +"pam_account_locked_message = Compte verrouillé, veuillez contacter le " +"service d'assistance.\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1587 @@ -2199,7 +2464,7 @@ msgstr "ldap_chpass_update_last_change (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1590 msgid "Enable passkey device based authentication." -msgstr "" +msgstr "Activer l'authentification par clé d'accès." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1593 sssd.conf.5.xml:1910 sssd-ad.5.xml:1286 @@ -2210,12 +2475,12 @@ msgstr "Par défaut : True" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1598 msgid "passkey_debug_libfido2 (bool)" -msgstr "" +msgstr "débogage de la clé d'accès libfido2 (livre)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1601 msgid "Enable libfido2 library debug messages." -msgstr "" +msgstr "Activer les messages de débogage de la bibliothèque libfido2." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1604 sssd.conf.5.xml:1618 sssd-ldap.5.xml:727 @@ -2228,7 +2493,7 @@ msgstr "Par défaut : False" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1609 msgid "pam_cert_auth (bool)" -msgstr "" +msgstr "pam_cert_auth (booléen)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1612 @@ -2237,21 +2502,24 @@ msgid "" "additional communication with the Smartcard which will delay the " "authentication process this option is disabled by default." msgstr "" +"Activer l'authentification par carte à puce basée sur un certificat. Cette " +"option, qui nécessite une communication supplémentaire avec la carte à puce " +"et ralentit le processus d'authentification, est désactivée par défaut." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1623 msgid "pam_cert_db_path (string)" -msgstr "" +msgstr "pam_cert_db_path (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1626 msgid "The path to the certificate database." -msgstr "" +msgstr "Le chemin d'accès à la base de données des certificats." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1629 sssd.conf.5.xml:2163 sssd.conf.5.xml:4338 msgid "Default:" -msgstr "" +msgstr "Défaut:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1631 sssd.conf.5.xml:2165 @@ -2259,6 +2527,8 @@ msgid "" "/etc/sssd/pki/sssd_auth_ca_db.pem (path to a file with trusted CA " "certificates in PEM format)" msgstr "" +"/etc/sssd/pki/sssd_auth_ca_db.pem (chemin d'accès à un fichier contenant les " +"certificats d'autorité de certification de confiance au format PEM)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1641 @@ -2276,13 +2546,14 @@ msgid "" "section. Supported options are the same of <quote>certificate_verification</" "quote>." msgstr "" +"Ce paramètre permet de configurer la vérification du certificat PAM à l'aide " +"d'une liste d'options séparées par des virgules, qui remplacent la valeur de " +"`certificate_verification` dans la section `[sssd]`. Les options prises en " +"charge sont les mêmes que celles de `certificate_verification`." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1655 -#, fuzzy, no-wrap -#| msgid "" -#| "subdomain_inherit = ldap_purge_cache_timeout\n" -#| " " +#, no-wrap msgid "" "pam_cert_verification = partial_chain\n" " " @@ -2296,16 +2567,21 @@ msgid "" "Default: not set, i.e. use default <quote>certificate_verification</quote> " "option defined in <quote>[sssd]</quote> section." msgstr "" +"Ce paramètre permet de configurer la vérification du certificat PAM à l'aide " +"d'une liste d'options séparées par des virgules, qui remplacent la valeur de " +"`certificate_verification` dans la section `[sssd]`. Les options prises en " +"charge sont les mêmes que celles de `certificate_verification`." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1666 msgid "p11_child_timeout (integer)" -msgstr "" +msgstr "p11_child_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1669 msgid "How many seconds will pam_sss wait for p11_child to finish." msgstr "" +"Combien de secondes pam_sss attendra-t-elle pour que p11_child ait terminé ?" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1678 @@ -2319,25 +2595,24 @@ msgstr "pam_id_timeout (entier)" msgid "" "How many seconds will the PAM responder wait for passkey_child to finish." msgstr "" +"Combien de secondes pam_sss attendra-t-elle pour que p11_child ait terminé ?" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1690 msgid "pam_app_services (string)" -msgstr "" +msgstr "pam_app_services (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1693 msgid "" "Which PAM services are permitted to contact domains of type " "<quote>application</quote>" -msgstr "" +msgstr "pam_app_services (chaîne de caractères)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1702 -#, fuzzy -#| msgid "ad_gpo_map_service (string)" msgid "pam_p11_allowed_services (string)" -msgstr "ad_gpo_map_service (chaîne)" +msgstr "pam_p11_allowed_services (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1705 @@ -2345,6 +2620,8 @@ msgid "" "A comma-separated list of PAM service names for which it will be allowed to " "use Smartcards." msgstr "" +"Liste, séparée par des virgules, des noms de services PAM pour lesquels " +"l'utilisation de cartes à puce sera autorisée." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1720 @@ -2353,6 +2630,8 @@ msgid "" "pam_p11_allowed_services = +my_pam_service, -login\n" " " msgstr "" +"pam_p11_allowed_services = +my_pam_service, -login\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1709 @@ -2365,67 +2644,75 @@ msgid "" "<quote>my_pam_service</quote>), you would use the following configuration: " "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"Il est possible d'ajouter un autre nom de service PAM à l'ensemble par " +"défaut en utilisant `<quote>+nom_du_service</quote>` ou de supprimer " +"explicitement un nom de service PAM de l'ensemble par défaut en utilisant " +"`<quote>-nom_du_service</quote>`. Par exemple, pour remplacer le nom de " +"service PAM par défaut pour l'authentification par carte à puce (par " +"exemple, `<quote>login</quote>`) par un nom de service PAM personnalisé (par " +"exemple, `<quote>mon_service_PAM</quote>`), vous utiliserez la configuration " +"suivante : `<placeholder type=\"programlisting\" id=\"0\"/>`" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1724 sssd-ad.5.xml:645 sssd-ad.5.xml:754 sssd-ad.5.xml:812 #: sssd-ad.5.xml:870 sssd-ad.5.xml:948 msgid "Default: the default set of PAM service names includes:" -msgstr "" +msgstr "Default: the default set of PAM service names includes:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1729 sssd-ad.5.xml:649 msgid "login" -msgstr "" +msgstr "se connecter" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1734 sssd-ad.5.xml:654 msgid "su" -msgstr "" +msgstr "sur" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1739 sssd-ad.5.xml:659 msgid "su-l" -msgstr "" +msgstr "sur le" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1744 sssd-ad.5.xml:674 msgid "gdm-smartcard" -msgstr "" +msgstr "carte à puce gdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1749 sssd-ad.5.xml:669 msgid "gdm-password" -msgstr "" +msgstr "carte à puce gdm" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1754 msgid "gdm-switchable-auth" -msgstr "" +msgstr "Authentification commutable gdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1759 sssd-ad.5.xml:679 msgid "kdm" -msgstr "" +msgstr "kdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1764 sssd-ad.5.xml:957 msgid "sudo" -msgstr "" +msgstr "sudo" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1769 sssd-ad.5.xml:962 msgid "sudo-i" -msgstr "" +msgstr "sudo-i" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1774 msgid "gnome-screensaver" -msgstr "" +msgstr "économiseur d'écran gnome" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1782 msgid "p11_wait_for_card_timeout (integer)" -msgstr "" +msgstr "p11_wait_for_card_timeout (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1785 @@ -2434,11 +2721,14 @@ msgid "" "to p11_child_timeout should the PAM responder wait until a Smartcard is " "inserted." msgstr "" +"Si l'authentification par carte à puce est requise, combien de secondes " +"supplémentaires, en plus de p11_child_timeout, le répondeur PAM doit-il " +"attendre avant qu'une carte à puce soit insérée ?" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1796 msgid "p11_uri (string)" -msgstr "" +msgstr "p11_uri (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1799 @@ -2450,6 +2740,13 @@ msgid "" "first slot found. If multiple readers are connected p11_uri can be used to " "tell p11_child to use a specific reader." msgstr "" +"L'URI PKCS#11 (voir RFC-7512 pour plus de détails) permet de limiter la " +"sélection des périphériques utilisés pour l'authentification par carte à " +"puce. Par défaut, le composant p11_child de SSSD recherche un emplacement " +"PKCS#11 (lecteur) où l'indicateur « amovible » est activé et lit les " +"certificats du jeton inséré à partir du premier emplacement trouvé. Si " +"plusieurs lecteurs sont connectés, l'URI PKCS#11 peut être utilisée pour " +"indiquer à p11_child d'utiliser un lecteur spécifique." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1812 @@ -2458,6 +2755,8 @@ msgid "" "p11_uri = pkcs11:slot-description=My%20Smartcard%20Reader\n" " " msgstr "" +"p11_uri = pkcs11:slot-description=Mon%20lecteur%20de%20cartes%20à%puce\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1816 @@ -2466,6 +2765,9 @@ msgid "" "p11_uri = pkcs11:library-description=OpenSC%20smartcard%20framework;slot-id=2\n" " " msgstr "" +"p11_uri = pkcs11:library-description=OpenSC%20smartcard%20framework;slot-" +"id=2\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1810 @@ -2475,27 +2777,34 @@ msgid "" "debug output of p11_child. As an alternative the GnuTLS utility 'p11tool' " "with e.g. the '--list-all' will show PKCS#11 URIs as well." msgstr "" +"Exemple : `<placeholder type=\"programlisting\" id=\"0\"/>` ou `<placeholder " +"type=\"programlisting\" id=\"1\"/>`. Pour trouver l'URI appropriée, veuillez " +"consulter la sortie de débogage de `p11_child`. Vous pouvez également " +"utiliser l'utilitaire GnuTLS `p11tool` avec l'option `--list-all`, par " +"exemple, pour afficher les URI PKCS#11." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1829 msgid "pam_initgroups_scheme" -msgstr "" +msgstr "schéma pam_initgroups" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1837 msgid "always" -msgstr "" +msgstr "toujours" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1838 msgid "" "Always do an online lookup, please note that pam_id_timeout still applies" msgstr "" +"Veuillez toujours effectuer une recherche en ligne. Notez que le délai " +"d'expiration de l'identifiant PAM (pam_id_timeout) reste applicable." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1842 msgid "no_session" -msgstr "" +msgstr "aucune session" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1843 @@ -2503,11 +2812,13 @@ msgid "" "Only do an online lookup if there is no active session of the user, i.e. if " "the user is currently not logged in" msgstr "" +"N’effectuez une recherche en ligne que si l’utilisateur n’a pas de session " +"active, c’est-à-dire s’il n’est pas connecté." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1848 sssd-ldap.5.xml:189 msgid "never" -msgstr "" +msgstr "jamais" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1849 @@ -2515,6 +2826,8 @@ msgid "" "Never force an online lookup, use the data from the cache as long as they " "are not expired" msgstr "" +"Ne jamais forcer une recherche en ligne, utiliser les données du cache tant " +"qu'elles ne sont pas expirées." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1832 @@ -2524,11 +2837,16 @@ msgid "" "should be done and the following values are allowed: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"Le répondeur PAM peut forcer une recherche en ligne pour obtenir les " +"appartenances aux groupes actuelles de l'utilisateur qui tente de se " +"connecter. Cette option détermine quand cette recherche doit être effectuée " +"et les valeurs suivantes sont autorisées : <placeholder " +"type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1856 msgid "Default: no_session" -msgstr "" +msgstr "Par défaut : aucune session" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:1861 sssd.conf.5.xml:4277 @@ -2539,18 +2857,20 @@ msgstr "ad_gpo_map_service (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1864 -#, fuzzy -#| msgid "Comma separated list of users who are allowed to log in." msgid "" "Comma separated list of PAM services that are allowed to try GSSAPI " "authentication using pam_sss_gss.so module." -msgstr "Liste séparée par des virgules d'utilisateurs autorisés à se connecter." +msgstr "" +"Liste, séparée par des virgules, des services PAM autorisés à tenter " +"l'authentification GSSAPI à l'aide du module pam_sss_gss.so." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1869 msgid "" "To disable GSSAPI authentication, set this option to <quote>-</quote> (dash)." msgstr "" +"Pour désactiver l'authentification GSSAPI, définissez cette option sur " +"<quote>-</quote> (tiret)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1873 sssd.conf.5.xml:1904 sssd.conf.5.xml:1942 @@ -2559,6 +2879,9 @@ msgid "" "[pam] section. It can also be set for trusted domain which overwrites the " "value in the domain section." msgstr "" +"Remarque : Cette option peut également être définie par domaine, remplaçant " +"ainsi la valeur de la section [pam]. Elle peut aussi être définie pour un " +"domaine de confiance, remplaçant alors la valeur de la section « domaine »." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1881 @@ -2581,12 +2904,12 @@ msgstr "Exemple : <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1885 msgid "Default: - (GSSAPI authentication is disabled)" -msgstr "" +msgstr "Par défaut : - (l’authentification GSSAPI est désactivée)" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:1890 sssd.conf.5.xml:4278 msgid "pam_gssapi_check_upn" -msgstr "" +msgstr "Vérification de Pam_Gaspi" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1893 @@ -2595,6 +2918,10 @@ msgid "" "successfully authenticated through GSSAPI can be associated with the user " "who is being authenticated. Authentication will fail if the check fails." msgstr "" +"Si cette option est activée, SSSD exigera que le principal utilisateur " +"Kerberos ayant réussi l'authentification via GSSAPI soit associé à " +"l'utilisateur en cours d'authentification. L'authentification échouera en " +"cas d'échec de cette vérification." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1900 @@ -2602,11 +2929,13 @@ msgid "" "If False, every user that is able to obtained required service ticket will " "be authenticated." msgstr "" +"Si la valeur est fausse, chaque utilisateur capable d'obtenir le ticket de " +"service requis sera authentifié." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1915 msgid "pam_gssapi_indicators_map" -msgstr "" +msgstr "pam_gssapi_indicators_map" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1918 @@ -2615,6 +2944,9 @@ msgid "" "a Kerberos ticket to access a PAM service that is allowed to try GSSAPI " "authentication using pam_sss_gss.so module." msgstr "" +"Liste séparée par des virgules des indicateurs d'authentification requis " +"dans un ticket Kerberos pour accéder à un service PAM autorisé à tenter une " +"authentification GSSAPI à l'aide du module pam_sss_gss.so." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1924 @@ -2630,6 +2962,17 @@ msgid "" "be denied. If the resulting list of indicators for the PAM service is empty, " "the check will not prevent the access." msgstr "" +"Chaque élément de la liste peut être soit le nom d'un indicateur " +"d'authentification, soit une paire <quote>service:indicateur</quote>. Les " +"indicateurs non préfixés par le nom du service PAM sont requis pour accéder " +"à tout service PAM configuré pour être utilisé avec <option>" +"pam_gssapi_services</option>. La liste d'indicateurs résultante pour chaque " +"service PAM est ensuite comparée aux indicateurs du ticket Kerberos lors de " +"l'authentification par pam_sss_gss.so. Tout indicateur du ticket " +"correspondant à la liste d'indicateurs résultante pour le service PAM " +"autorise l'accès. Si aucun indicateur de la liste ne correspond, l'accès est " +"refusé. Si la liste d'indicateurs résultante pour le service PAM est vide, " +"la vérification n'empêche pas l'accès." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1937 @@ -2638,6 +2981,10 @@ msgid "" "</quote> (dash). To disable the check for a specific PAM service, add " "<quote>service:-</quote>." msgstr "" +"Pour désactiver la vérification de l'indicateur d'authentification GSSAPI, " +"définissez cette option sur <quote>-</quote> (tiret). Pour désactiver la " +"vérification pour un service PAM spécifique, ajoutez <quote>service:-</quote>" +"." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1948 @@ -2645,6 +2992,8 @@ msgid "" "Following authentication indicators are supported by IPA Kerberos " "deployments:" msgstr "" +"Les indicateurs d'authentification suivants sont pris en charge par les " +"déploiements IPA Kerberos :" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1951 @@ -2652,6 +3001,8 @@ msgid "" "pkinit -- pre-authentication using X.509 certificates -- whether stored in " "files or on smart cards." msgstr "" +"pkinit -- pré-authentification utilisant des certificats X.509 -- qu'ils " +"soient stockés dans des fichiers ou sur des cartes à puce." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1954 @@ -2659,11 +3010,15 @@ msgid "" "hardened -- SPAKE pre-authentication or any pre-authentication wrapped in a " "FAST channel." msgstr "" +"durci -- pré-authentification SPAKE ou toute pré-authentification enveloppée " +"dans un canal FAST." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1957 msgid "radius -- pre-authentication with the help of a RADIUS server." msgstr "" +"durci -- pré-authentification SPAKE ou toute pré-authentification enveloppée " +"dans un canal FAST." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1960 @@ -2671,11 +3026,13 @@ msgid "" "otp -- pre-authentication using integrated two-factor authentication (2FA or " "one-time password, OTP) in IPA." msgstr "" +"otp -- pré-authentification utilisant l'authentification à deux facteurs " +"intégrée (2FA ou mot de passe à usage unique, OTP) dans IPA." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1963 msgid "idp -- pre-authentication using external identity provider." -msgstr "" +msgstr "idp -- pré-authentification via un fournisseur d'identité externe." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1973 @@ -2684,6 +3041,8 @@ msgid "" "pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" " " msgstr "" +"pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1968 @@ -2692,6 +3051,10 @@ msgid "" "their Kerberos tickets with a X.509 certificate pre-authentication (PKINIT), " "set <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"Exemple : pour limiter l’accès aux services SUDO aux seuls utilisateurs " +"ayant obtenu leur ticket Kerberos avec une pré-authentification par " +"certificat X.509 (PKINIT), définissez <placeholder type=\"programlisting\" " +"id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1977 @@ -2699,7 +3062,7 @@ msgstr "" #| msgid "Default: not set (no substitution for unset home directories)" msgid "Default: not set (use of authentication indicators is not required)" msgstr "" -"Par défaut : non défini (aucune substitution pour les répertoires d'accueil " +"Par défaut : non défini (aucune substitution pour les répertoires d'accueil " "non définis)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> @@ -2711,17 +3074,19 @@ msgstr "ad_gpo_map_service (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1985 -#, fuzzy -#| msgid "Comma separated list of users who are allowed to log in." msgid "" "Comma separated list of PAM services which can handle the JSON protocol for " "selecting authentication mechanisms" -msgstr "Liste séparée par des virgules d'utilisateurs autorisés à se connecter." +msgstr "" +"Liste, séparée par des virgules, des services PAM capables de gérer le " +"protocole JSON pour la sélection des mécanismes d'authentification." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1990 msgid "To disable JSON protocol, set this option to <quote>-</quote> (dash)." msgstr "" +"Pour désactiver le protocole JSON, définissez cette option sur <quote>-</" +"quote> (tiret)." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1996 @@ -2749,6 +3114,8 @@ msgid "" "Note: 2-Factor Authentication (2FA) is not supported. If 2FA is required, do " "not activate the JSON protocol." msgstr "" +"Remarque : L’authentification à deux facteurs (2FA) n’est pas prise en " +"charge. Si la 2FA est requise, n’activez pas le protocole JSON." #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:2013 @@ -2783,13 +3150,13 @@ msgid "" "Whether or not to evaluate the sudoNotBefore and sudoNotAfter attributes " "that implement time-dependent sudoers entries." msgstr "" -"Évaluation ou non des attributs sudoNotBefore et sudoNotAfter qui utilisent " +"Évaluation ou non des attributs sudoNotBefore et sudoNotAfter qui utilisent " "les entrées sudoers sensibles au temps." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2047 msgid "sudo_threshold (integer)" -msgstr "" +msgstr "sudo_threshold (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2050 @@ -2800,6 +3167,12 @@ msgid "" "<quote>full refresh</quote> of sudo rules is triggered instead. This " "threshold number also applies to IPA sudo command and command group searches." msgstr "" +"Nombre maximal de règles expirées pouvant être actualisées simultanément. Si " +"ce nombre est inférieur au seuil, les règles sont actualisées via le " +"mécanisme d'actualisation des règles. Si le seuil est dépassé, une " +"actualisation complète des règles sudo est déclenchée. Ce seuil s'applique " +"également aux recherches de commandes et de groupes de commandes sudo dans " +"l'API IPA." #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:2069 @@ -2842,7 +3215,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2100 msgid "ssh_use_certificate_keys (bool)" -msgstr "" +msgstr "ssh_use_certificate_keys (booléen)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2103 @@ -2852,11 +3225,16 @@ msgid "" "entry as well. See <citerefentry> <refentrytitle>sss_ssh_authorizedkeys</" "refentrytitle> <manvolnum>1</manvolnum> </citerefentry> for details." msgstr "" +"Si la valeur est définie sur « true », la commande `sss_ssh_authorizedkeys` " +"renverra également les clés SSH dérivées de la clé publique des certificats " +"X.509 stockés dans l'entrée utilisateur. Voir `<citerefentry><refentrytitle>" +"sss_ssh_authorizedkeys</refentrytitle><manvolnum>1</manvolnum></citerefentry>" +"` pour plus de détails." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2118 msgid "ssh_use_certificate_matching_rules (string)" -msgstr "" +msgstr "ssh_use_certificate_matching_rules (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2121 @@ -2867,6 +3245,11 @@ msgid "" "comma separated list of mapping and matching rule names. All other rules " "will be ignored." msgstr "" +"Par défaut, le serveur SSH utilise toutes les règles de correspondance de " +"certificats disponibles pour filtrer les certificats et ne dériver que des " +"certificats correspondants. Cette option permet de limiter les règles " +"utilisées à l'aide d'une liste de noms de règles de correspondance séparés " +"par des virgules. Toutes les autres règles seront ignorées." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2130 @@ -2875,6 +3258,10 @@ msgid "" "all or no rules, respectively. The latter means that no certificates will be " "filtered out and ssh keys will be generated from all valid certificates." msgstr "" +"Deux mots clés spéciaux, « all_rules » et « no_rules », permettent " +"respectivement d'activer toutes les règles ou de les désactiver. L'option « " +"no_rules » signifie qu'aucun certificat ne sera filtré et que les clés SSH " +"seront générées à partir de tous les certificats valides." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2137 @@ -2884,6 +3271,10 @@ msgid "" "the same behavior as for the PAM responder if certificate authentication is " "enabled." msgstr "" +"Si aucune règle n'est configurée, l'option « all_rules » active une règle " +"par défaut autorisant tous les certificats compatibles avec " +"l'authentification du client. Ce comportement est identique à celui du " +"répondeur PAM lorsque l'authentification par certificat est activée." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2144 @@ -2891,6 +3282,9 @@ msgid "" "A non-existing rule name is considered an error. If as a result no rule is " "selected all certificates will be ignored." msgstr "" +"Un nom de règle inexistant est considéré comme une erreur. Si, par " +"conséquent, aucune règle n'est sélectionnée, tous les certificats seront " +"ignorés." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2149 @@ -2898,11 +3292,13 @@ msgid "" "Default: not set, equivalent to 'all_rules', all found rules or the default " "rule are used" msgstr "" +"Valeur par défaut : non définie, équivalent à « all_rules », toutes les " +"règles trouvées ou la règle par défaut sont utilisées" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2155 msgid "ca_db (string)" -msgstr "" +msgstr "ca_db (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2158 @@ -2910,6 +3306,9 @@ msgid "" "Path to a storage of trusted CA certificates. The option is used to validate " "user certificates before deriving public ssh keys from them." msgstr "" +"Chemin d'accès à un répertoire de certificats d'autorité de certification de " +"confiance. Cette option permet de valider les certificats utilisateur avant " +"d'en dériver les clés SSH publiques." #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:2178 @@ -2926,6 +3325,13 @@ msgid "" "joined to and of remote trusted domains from the local domain controller. If " "the PAC is decoded and evaluated some of the following operations are done:" msgstr "" +"Le répondeur PAC fonctionne conjointement avec le plugin de données " +"d'autorisation pour MIT Kerberos sssd_pac_plugin.so et un fournisseur de " +"sous-domaine. Le plugin envoie les données PAC au répondeur PAC lors d'une " +"authentification GSSAPI. Le fournisseur de sous-domaine collecte les plages " +"SID et ID du domaine auquel le client est rattaché, ainsi que celles des " +"domaines distants de confiance, auprès du contrôleur de domaine local. Si le " +"PAC est décodé et évalué, les opérations suivantes sont effectuées :" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:2189 @@ -2937,6 +3343,12 @@ msgid "" "the system defaults are used, but can be overwritten with the default_shell " "parameter." msgstr "" +"Si l'utilisateur distant n'est pas présent dans le cache, il est créé. L'UID " +"est déterminé à l'aide du SID ; les domaines de confiance possèdent un UPG " +"et le GID a la même valeur que l'UID. Le répertoire personnel est défini en " +"fonction du paramètre `subdomain_homedir`. Par défaut, l'interpréteur de " +"commandes est vide (les commandes système par défaut sont utilisées), mais " +"il est possible de le remplacer avec le paramètre `default_shell`." #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:2197 @@ -3024,7 +3436,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2240 msgid "pac_lifetime (integer)" -msgstr "" +msgstr "pac_lifetime (entier)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2243 @@ -3032,6 +3444,9 @@ msgid "" "Lifetime of the PAC entry in seconds. As long as the PAC is valid the PAC " "data can be used to determine the group memberships of a user." msgstr "" +"Durée de vie de l'entrée PAC en secondes. Tant que le PAC est valide, ses " +"données peuvent être utilisées pour déterminer les groupes auxquels " +"appartient un utilisateur." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2253 @@ -3050,6 +3465,13 @@ msgid "" "IPA and AD provider. If krb5_validate is set to 'False' the PAC checks will " "be skipped." msgstr "" +"Effectuez des vérifications supplémentaires sur le PAC du ticket Kerberos, " +"disponible dans les domaines Active Directory et FreeIPA, le cas échéant. " +"Veuillez noter que la validation du ticket Kerberos doit être activée pour " +"pouvoir vérifier le PAC ; autrement dit, l’option `krb5_validate` doit être " +"définie sur « True », valeur par défaut pour les fournisseurs IPA et AD. Si " +"`krb5_validate` est définie sur « False », les vérifications du PAC seront " +"ignorées." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2266 @@ -3058,11 +3480,16 @@ msgid "" "Directory or recent versions of FreeIPA. PACs issued e.g. by a plain MIT " "Kerberos KDC will not contain the needed PAC data buffers to run the checks." msgstr "" +"Veuillez noter que les vérifications ci-dessous ne s'appliquent qu'aux " +"fichiers PAC émis par Active Directory ou les versions récentes de FreeIPA. " +"Les fichiers PAC émis, par exemple, par un contrôleur de domaine Kerberos " +"MIT standard ne contiennent pas les tampons de données nécessaires à " +"l'exécution de ces vérifications." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2277 msgid "no_check" -msgstr "" +msgstr "pas de vérification" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2279 @@ -3070,11 +3497,13 @@ msgid "" "The PAC must not be present and even if it is present no additional checks " "will be done." msgstr "" +"Le PAC ne doit pas être présent et, même s'il est présent, aucun contrôle " +"supplémentaire ne sera effectué." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2285 msgid "pac_present" -msgstr "" +msgstr "pac_présent" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2287 @@ -3083,11 +3512,13 @@ msgid "" "the help of the user's TGT. If the PAC is not available the authentication " "will fail." msgstr "" +"Le PAC doit figurer dans le ticket de service que SSSD demandera à l'aide du " +"TGT de l'utilisateur. Si le PAC est absent, l'authentification échouera." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2295 msgid "check_upn" -msgstr "" +msgstr "check_upn" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2297 @@ -3095,11 +3526,13 @@ msgid "" "If the PAC is present check if the user principal name (UPN) information is " "consistent." msgstr "" +"Si le PAC est présent, vérifiez si les informations du nom principal de " +"l'utilisateur (UPN) sont cohérentes." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2303 msgid "check_upn_allow_missing" -msgstr "" +msgstr "check_upn_autoriser_manquant" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2305 @@ -3112,6 +3545,14 @@ msgid "" "time and FreeIPA can handle enterprise principals just fine and there is no " "need anymore to set 'ldap_user_principal'." msgstr "" +"Cette option doit être utilisée conjointement avec « check_upn » et gère le " +"cas où un UPN est défini côté serveur mais n'est pas lu par SSSD. L'exemple " +"typique est celui d'un domaine FreeIPA où « ldap_user_principal » est défini " +"sur un nom d'attribut inexistant. Cette pratique était courante pour " +"contourner les problèmes de gestion des principaux d'entreprise. Cependant, " +"ce problème est résolu depuis longtemps et FreeIPA gère parfaitement les " +"principaux d'entreprise ; il n'est donc plus nécessaire de définir « " +"ldap_user_principal »." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2317 @@ -3123,21 +3564,29 @@ msgid "" "can be removed. If this is not possible, removing 'check_upn' will skip the " "test and avoid the log message." msgstr "" +"Actuellement, cette option est activée par défaut afin d'éviter les " +"régressions dans ces environnements. Un message sera ajouté au journal " +"système et au journal de débogage de SSSD si un UPN est trouvé dans le PAC " +"mais pas dans le cache de SSSD. Pour éviter ce message, il serait préférable " +"d'évaluer si l'option « ldap_user_principal » peut être supprimée. Si cela " +"n'est pas possible, la suppression de « check_upn » permettra d'ignorer le " +"test et d'éviter l'affichage du message." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2331 msgid "upn_dns_info_present" -msgstr "" +msgstr "upn_dns_info_présent" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2333 msgid "The PAC must contain the UPN-DNS-INFO buffer, implies 'check_upn'." msgstr "" +"Le PAC doit contenir le tampon UPN-DNS-INFO, ce qui implique 'check_upn'." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2338 msgid "check_upn_dns_info_ex" -msgstr "" +msgstr "check_upn_dns_info_ex" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2340 @@ -3145,11 +3594,14 @@ msgid "" "If the PAC is present and the extension to the UPN-DNS-INFO buffer is " "available check if the information in the extension is consistent." msgstr "" +"Si le PAC est présent et que l'extension du tampon UPN-DNS-INFO est " +"disponible, vérifiez si les informations contenues dans l'extension sont " +"cohérentes." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2347 msgid "upn_dns_info_ex_present" -msgstr "" +msgstr "upn_dns_info_ex_présent" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2349 @@ -3157,6 +3609,8 @@ msgid "" "The PAC must contain the extension of the UPN-DNS-INFO buffer, implies " "'check_upn_dns_info_ex', 'upn_dns_info_present' and 'check_upn'." msgstr "" +"Le PAC doit contenir l'extension du tampon UPN-DNS-INFO, ce qui implique " +"'check_upn_dns_info_ex', 'upn_dns_info_present' et 'check_upn'." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2273 @@ -3177,11 +3631,13 @@ msgid "" "Default: no_check (AD and IPA provider 'check_upn, check_upn_allow_missing, " "check_upn_dns_info_ex')" msgstr "" +"Par défaut : no_check (fournisseur AD et IPA : « check_upn, " +"check_upn_allow_missing, check_upn_dns_info_ex »)" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:2368 msgid "Session recording configuration options" -msgstr "" +msgstr "options de configuration de l'enregistrement de session" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:2370 @@ -3192,31 +3648,35 @@ msgid "" "they log in on a text terminal. See also <citerefentry> <refentrytitle>sssd-" "session-recording</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." msgstr "" +"L'enregistrement de session fonctionne conjointement avec `tlog-rec-" +"session`, un composant du paquet `tlog`, pour enregistrer ce que les " +"utilisateurs voient et saisissent lorsqu'ils se connectent à un terminal " +"texte. Voir aussi `sssd-session-recording`." #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:2383 msgid "These options can be used to configure session recording." -msgstr "" +msgstr "Ces options permettent de configurer l'enregistrement de session." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2387 sssd-session-recording.5.xml:64 msgid "scope (string)" -msgstr "" +msgstr "portée (chaîne)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2394 sssd-session-recording.5.xml:71 msgid "\"none\"" -msgstr "" +msgstr "\"aucun\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2397 sssd-session-recording.5.xml:74 msgid "No users are recorded." -msgstr "" +msgstr "Aucun utilisateur n'est enregistré." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2402 sssd-session-recording.5.xml:79 msgid "\"some\"" -msgstr "" +msgstr "\"quelques\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2405 sssd-session-recording.5.xml:82 @@ -3224,16 +3684,18 @@ msgid "" "Users/groups specified by <replaceable>users</replaceable> and " "<replaceable>groups</replaceable> options are recorded." msgstr "" +"Les utilisateurs/groupes spécifiés par les options <replaceable>users</" +"replaceable> et <replaceable>groups</replaceable> sont enregistrés." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2414 sssd-session-recording.5.xml:91 msgid "\"all\"" -msgstr "" +msgstr "\"tout\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2417 sssd-session-recording.5.xml:94 msgid "All users are recorded." -msgstr "" +msgstr "Tous les utilisateurs sont enregistrés." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2390 sssd-session-recording.5.xml:67 @@ -3241,16 +3703,18 @@ msgid "" "One of the following strings specifying the scope of session recording: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +"L'une des chaînes suivantes spécifiant la portée de l'enregistrement de " +"session : <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2424 sssd-session-recording.5.xml:101 msgid "Default: \"none\"" -msgstr "" +msgstr "Valeur par défaut : « aucune »" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2429 sssd-session-recording.5.xml:106 msgid "users (string)" -msgstr "" +msgstr "utilisateurs (chaîne de caractères)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2432 sssd-session-recording.5.xml:109 @@ -3259,16 +3723,20 @@ msgid "" "Matches user names as returned by NSS. I.e. after the possible space " "replacement, case changes, etc." msgstr "" +"Liste d'utilisateurs, séparés par des virgules, pour lesquels " +"l'enregistrement de session doit être activé. Les noms d'utilisateur doivent " +"correspondre à ceux renvoyés par NSS, c'est-à-dire après les éventuelles " +"modifications d'espaces, de casse, etc." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2438 sssd-session-recording.5.xml:115 msgid "Default: Empty. Matches no users." -msgstr "" +msgstr "Valeur par défaut : vide. Ne correspond à aucun utilisateur." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:120 msgid "groups (string)" -msgstr "" +msgstr "groupes (chaîne)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2446 sssd-session-recording.5.xml:123 @@ -3277,6 +3745,10 @@ msgid "" "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" +"Liste de groupes, séparés par des virgules, dont les membres doivent avoir " +"l'enregistrement de session activé. Les noms de groupes doivent correspondre " +"à ceux renvoyés par NSS, c'est-à-dire après les éventuelles modifications " +"d'espaces, de casse, etc." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2452 sssd.conf.5.xml:2484 sssd-session-recording.5.xml:129 @@ -3286,11 +3758,15 @@ msgid "" "performance cost, because each uncached request for a user requires " "retrieving and matching the groups the user is member of." msgstr "" +"REMARQUE : l'utilisation de cette option (quelle que soit sa valeur) a un " +"coût considérable en termes de performances, car chaque requête non mise en " +"cache pour un utilisateur nécessite de récupérer et de faire correspondre " +"les groupes auxquels l'utilisateur appartient." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2459 sssd-session-recording.5.xml:136 msgid "Default: Empty. Matches no groups." -msgstr "" +msgstr "Valeur par défaut : vide. Ne correspond à aucun groupe." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2464 sssd-session-recording.5.xml:141 @@ -3305,13 +3781,15 @@ msgid "" "A comma-separated list of users to be excluded from recording, only " "applicable with 'scope=all'." msgstr "" +"Liste d'utilisateurs séparés par des virgules à exclure de l'enregistrement, " +"applicable uniquement avec 'scope=all'." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2471 sssd-session-recording.5.xml:148 #, fuzzy #| msgid "Default: empty, i.e. ldap_uri is used." msgid "Default: Empty. No users excluded." -msgstr "Par défaut : vide, ldap_uri est donc utilisé." +msgstr "Par défaut : vide, ldap_uri est donc utilisé." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2476 sssd-session-recording.5.xml:153 @@ -3326,13 +3804,15 @@ msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording. Only applicable with 'scope=all'." msgstr "" +"Liste de groupes, séparés par des virgules, dont les membres doivent être " +"exclus de l'enregistrement. Applicable uniquement avec « scope=all »." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2491 sssd-session-recording.5.xml:168 #, fuzzy #| msgid "Default: empty, i.e. ldap_uri is used." msgid "Default: Empty. No groups excluded." -msgstr "Par défaut : vide, ldap_uri est donc utilisé." +msgstr "Par défaut : vide, ldap_uri est donc utilisé." #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:2501 @@ -3343,7 +3823,7 @@ msgstr "SECTIONS DOMAINES" #: sssd.conf.5.xml:2508 sssd.conf.5.xml:3964 sssd.conf.5.xml:3965 #: sssd.conf.5.xml:3968 msgid "enabled" -msgstr "" +msgstr "activé" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2511 @@ -3354,11 +3834,15 @@ msgid "" "enabled only if it is listed in the domains option in the <quote>[sssd]</" "quote> section." msgstr "" +"Activez ou désactivez explicitement le domaine. Si la valeur est « true », " +"le domaine est toujours activé. Si la valeur est « false », le domaine est " +"toujours désactivé. Si cette option n'est pas définie, le domaine est activé " +"uniquement s'il figure dans l'option « domains » de la section « [sssd] »." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2523 msgid "domain_type (string)" -msgstr "" +msgstr "type_domaine (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2526 @@ -3368,6 +3852,10 @@ msgid "" "be present or generated. Only objects from POSIX domains are available to " "the operating system interfaces and utilities." msgstr "" +"Indique si le domaine est destiné à être utilisé par des clients compatibles " +"POSIX, tels que le commutateur de service de noms, ou par des applications " +"qui n'ont pas besoin de données POSIX. Seuls les objets des domaines POSIX " +"sont accessibles aux interfaces et utilitaires du système d'exploitation." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2534 @@ -3375,6 +3863,8 @@ msgid "" "Allowed values for this option are <quote>posix</quote> and " "<quote>application</quote>." msgstr "" +"Les valeurs autorisées pour cette option sont <quote>posix</quote> et <quote>" +"application</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2538 @@ -3384,6 +3874,10 @@ msgid "" "<refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</manvolnum> </" "citerefentry>) and the PAM responder." msgstr "" +"Les domaines POSIX sont accessibles par tous les services. Les domaines " +"d'application ne sont accessibles que depuis le répondeur InfoPipe (voir " +"<citerefentry> <refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>) et le répondeur PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2546 @@ -3391,6 +3885,8 @@ msgid "" "NOTE: The application domains are currently well tested with " "<quote>id_provider=ldap</quote> only." msgstr "" +"REMARQUE : Les domaines d'application sont actuellement bien testés avec " +"<quote>id_provider=ldap</quote> uniquement." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2550 @@ -3398,11 +3894,13 @@ msgid "" "For an easy way to configure a non-POSIX domains, please see the " "<quote>Application domains</quote> section." msgstr "" +"Pour configurer facilement un domaine non-POSIX, veuillez consulter la " +"section <quote>Domaines d'application</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2554 msgid "Default: posix" -msgstr "" +msgstr "Par défaut : posix" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2560 @@ -3458,6 +3956,10 @@ msgid "" "enable enumeration in order for secondary groups to be displayed. This " "parameter can have one of the following values:" msgstr "" +"Détermine si un domaine peut être énuméré, c'est-à-dire s'il peut lister " +"tous les utilisateurs et groupes qu'il contient. Notez que l'activation de " +"l'énumération n'est pas nécessaire pour que les groupes secondaires " +"s'affichent. Ce paramètre peut prendre l'une des valeurs suivantes :" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2596 @@ -3480,6 +3982,8 @@ msgid "" "Enumerating a domain requires SSSD to download and store ALL user and group " "entries from the remote server." msgstr "" +"L'énumération d'un domaine nécessite que SSSD télécharge et stocke TOUTES " +"les entrées d'utilisateurs et de groupes depuis le serveur distant." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2610 @@ -3487,6 +3991,8 @@ msgid "" "Feature is only supported for domains with id_provider = ldap or id_provider " "= proxy." msgstr "" +"Cette fonctionnalité est uniquement prise en charge pour les domaines avec " +"id_provider = ldap ou id_provider = proxy." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2614 @@ -3501,6 +4007,16 @@ msgid "" "quote> process becoming unresponsive or even restarted by the internal " "watchdog." msgstr "" +"Remarque : L’activation de l’énumération a un impact important sur les " +"performances de SSSD pendant son exécution. L’énumération complète peut " +"prendre jusqu’à plusieurs minutes après le démarrage de SSSD. Pendant ce " +"temps, les requêtes d’information individuelles seront directement envoyées " +"à LDAP, mais le traitement peut être lent en raison de l’important volume de " +"données nécessaires à l’énumération. L’enregistrement d’un grand nombre " +"d’entrées dans le cache après l’énumération peut également solliciter " +"fortement le processeur, car les appartenances doivent être recalculées. " +"Cela peut entraîner le blocage du processus `sssd_be` ou même son " +"redémarrage par le système de surveillance interne." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2629 @@ -3542,6 +4058,10 @@ msgid "" "'libnss_files' and 'libnss_ldap'. 3rd party modules must follow the " "documented behavior of nss modules to be used in this configuration." msgstr "" +"Remarque : le fournisseur de proxy est testé avec des modules open source " +"tels que « libnss_files » et « libnss_ldap ». Les modules tiers doivent " +"respecter le comportement documenté des modules nss pour être utilisés dans " +"cette configuration." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2656 @@ -3646,7 +4166,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2734 msgid "entry_cache_resolver_timeout (integer)" -msgstr "" +msgstr "délai_d'expiration_du_résolveur_cache_d'entrée (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2737 @@ -3654,6 +4174,8 @@ msgid "" "How many seconds should nss_sss consider hosts and networks entries valid " "before asking the backend again" msgstr "" +"Combien de secondes nss_sss doit-il considérer les entrées hôtes et réseaux " +"comme valides avant d'interroger à nouveau le serveur ?" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2748 @@ -3700,7 +4222,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2789 msgid "entry_cache_computer_timeout (integer)" -msgstr "" +msgstr "délai_d'expiration_ordinateur_cache_entrée (entier)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2792 @@ -3708,6 +4230,8 @@ msgid "" "How many seconds to keep the local computer entry before asking the backend " "again" msgstr "" +"Combien de secondes faut-il conserver l’entrée de l’ordinateur local avant " +"de redemander les informations au serveur backend" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2802 @@ -3732,11 +4256,17 @@ msgid "" "user, typically ran at login) operation in the past, both the user entry " "and the group membership are updated." msgstr "" +"L'actualisation en arrière-plan traitera les utilisateurs, les groupes et " +"les groupes réseau présents dans le cache. Pour les utilisateurs ayant déjà " +"effectué l'opération initgroups (obtention de l'appartenance à un groupe, " +"généralement exécutée lors de la connexion), leur fiche utilisateur et leur " +"appartenance à un groupe seront mises à jour." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2818 msgid "This option is automatically inherited for all trusted domains." msgstr "" +"Cette option est automatiquement héritée pour tous les domaines de confiance." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2822 @@ -3755,6 +4285,15 @@ msgid "" "offline mode operation and reuse of existing valid cache entries. To make " "this change instant the user may want to manually invalidate existing cache." msgstr "" +"L'entrée du cache sera actualisée par une tâche en arrière-plan lorsque les " +"deux tiers du délai d'expiration du cache seront écoulés. Si des entrées " +"sont déjà en cache, la tâche en arrière-plan utilisera leurs valeurs de " +"délai d'expiration d'origine plutôt que la valeur de configuration actuelle. " +"Il est possible que l'actualisation en arrière-plan semble alors ne pas " +"fonctionner. Ce comportement est intentionnel afin d'optimiser le " +"fonctionnement hors ligne et la réutilisation des entrées de cache valides. " +"Pour une mise à jour instantanée, l'utilisateur peut invalider manuellement " +"le cache existant." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2839 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 @@ -3777,6 +4316,14 @@ msgid "" "as a successful online authentication is recorded in the cache without " "additional configuration." msgstr "" +"Détermine si les informations d'identification de l'utilisateur sont " +"également mises en cache dans le cache LDB local. Les informations " +"d'identification mises en cache concernent les mots de passe, y compris le " +"premier facteur (à long terme) de l'authentification à deux facteurs, et non " +"les autres mécanismes d'authentification. L'authentification par mot de " +"passe et par carte à puce devrait fonctionner hors ligne dès lors qu'une " +"authentification en ligne réussie est enregistrée dans le cache sans " +"configuration supplémentaire." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2859 @@ -3786,11 +4333,16 @@ msgid "" "get access to a cache file (normally requires privileged access) and to " "break a password using brute force attack." msgstr "" +"Notez que même si les identifiants sont stockés sous forme de hachage SHA512 " +"salé, cela présente toujours un risque potentiel pour la sécurité si un " +"attaquant parvient à accéder à un fichier cache (ce qui nécessite " +"normalement un accès privilégié) et à casser un mot de passe à l'aide d'une " +"attaque par force brute." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2873 msgid "cache_credentials_minimal_first_factor_length (int)" -msgstr "" +msgstr "cache_credentials_minimal_first_factor_length (int)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2876 @@ -3799,6 +4351,11 @@ msgid "" "this value determines the minimal length the first authentication factor " "(long term password) must have to be saved as SHA512 hash into the cache." msgstr "" +"Si l'authentification à deux facteurs (2FA) est utilisée et que les " +"informations d'identification doivent être enregistrées, cette valeur " +"détermine la longueur minimale que le premier facteur d'authentification " +"(mot de passe à long terme) doit avoir pour être enregistré sous forme de " +"hachage SHA512 dans le cache." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2883 @@ -3806,6 +4363,9 @@ msgid "" "This should avoid that the short PINs of a PIN based 2FA scheme are saved in " "the cache which would make them easy targets for brute-force attacks." msgstr "" +"Cela devrait éviter que les codes PIN courts d'un système d'authentification " +"à deux facteurs basé sur un code PIN ne soient enregistrés dans le cache, ce " +"qui en ferait des cibles faciles pour les attaques par force brute." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2894 @@ -3869,7 +4429,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2940 msgid "<quote>proxy</quote>: Support a legacy NSS provider." -msgstr "" +msgstr "<quote>proxy</quote> : Prise en charge d’un fournisseur NSS hérité." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2943 @@ -3985,6 +4545,8 @@ msgid "" "Default: FALSE (TRUE for trusted domain/sub-domains or if " "default_domain_suffix is used)" msgstr "" +"Valeur par défaut : FAUX (VRAI pour les domaines/sous-domaines de confiance " +"ou si default_domain_suffix est utilisé)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3009 @@ -4007,6 +4569,13 @@ msgid "" "citerefentry>. As an effect, <quote>getent group $groupname</quote> would " "return the requested group as if it was empty." msgstr "" +"Si la valeur est TRUE, l'attribut d'appartenance au groupe n'est pas demandé " +"au serveur LDAP et les membres du groupe ne sont pas renvoyés lors du " +"traitement des appels de recherche de groupe, tels que `<citerefentry> " +"<refentrytitle>getgrnam</refentrytitle> <manvolnum>3</manvolnum> </" +"citerefentry>` ou `<citerefentry> <refentrytitle>getgrgid</refentrytitle> " +"<manvolnum>3</manvolnum> </citerefentry>`. Par conséquent, `<quote>getent " +"group $groupname</quote>` renverra le groupe demandé comme s'il était vide." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3033 @@ -4015,6 +4584,9 @@ msgid "" "membership significantly faster, especially for groups containing many " "members." msgstr "" +"L'activation de cette option peut également accélérer considérablement les " +"vérifications d'appartenance au groupe effectuées par les fournisseurs " +"d'accès, notamment pour les groupes comportant de nombreux membres." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3039 sssd.conf.5.xml:3767 sssd-ldap.5.xml:401 @@ -4025,6 +4597,8 @@ msgid "" "This option can be also set per subdomain or inherited via " "<emphasis>subdomain_inherit</emphasis>." msgstr "" +"Cette option peut également être définie par sous-domaine ou héritée via " +"<emphasis>subdomain_inherit</emphasis>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3049 @@ -4049,7 +4623,7 @@ msgid "" msgstr "" "<quote>ldap</quote> pour une authentification LDAP native. Cf. " "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" -"manvolnum> </citerefentry> pour plus d'informations sur la configuration de " +"manvolnum> </citerefentry> pour plus d'informations sur la configuration de " "LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -4150,11 +4724,16 @@ msgid "" "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum></" "citerefentry> for more information on configuring Kerberos." msgstr "" +"<quote>krb5</quote> : Contrôle d'accès basé sur .k5login. Voir " +"<citerefentry> <refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</" +"manvolnum></citerefentry> pour plus d'informations sur la configuration de " +"Kerberos." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3160 msgid "<quote>proxy</quote> for relaying access control to another PAM module." msgstr "" +"<quote>proxy</quote> pour relayer le contrôle d'accès à un autre module PAM." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3163 @@ -4182,6 +4761,8 @@ msgid "" "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" "manvolnum> </citerefentry> for more information on configuring LDAP." msgstr "" +"Utilisez LDAP pour modifier un mot de passe stocké sur un serveur LDAP. " +"Consultez sssd-ldap pour plus d'informations sur la configuration de LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3184 @@ -4275,7 +4856,7 @@ msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle sudo requests." msgstr "" -"Par défaut : <quote>id_provider</quote> est utilisé s'il est défini et peut " +"Par défaut : <quote>id_provider</quote> est utilisé s'il est défini et peut " "gérer le chargement selinux" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -4288,6 +4869,12 @@ msgid "" "\"ldap_sudo_*\" in <citerefentry> <refentrytitle>sssd-ldap</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry>." msgstr "" +"Les instructions détaillées pour la configuration de sudo_provider se " +"trouvent dans la page de manuel <citerefentry> <refentrytitle>sssd-sudo</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>. De nombreuses " +"options de configuration permettent d'ajuster son comportement. Veuillez " +"vous référer à « ldap_sudo_* » dans <citerefentry> <refentrytitle>sssd-ldap</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3268 @@ -4297,6 +4884,10 @@ msgid "" "<emphasis>sudo_provider = None</emphasis> to disable all sudo-related " "activity in SSSD if you do not want to use sudo with SSSD at all." msgstr "" +"Remarque : les règles sudo sont téléchargées périodiquement en arrière-plan, " +"sauf si le fournisseur sudo est explicitement désactivé. Définissez " +"`sudo_provider = None` pour désactiver toute activité liée à sudo dans SSSD " +"si vous ne souhaitez pas utiliser sudo avec SSSD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3278 @@ -4377,6 +4968,10 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " "the AD provider." msgstr "" +"Utilisez la commande `<quote>ad</quote>` pour charger une liste de sous-" +"domaines à partir d'un serveur Active Directory. Consultez `<citerefentry>" +"<refentrytitle>sssd-ad</refentrytitle><manvolnum>5</manvolnum></citerefentry>" +"` pour plus d'informations sur la configuration du fournisseur AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3331 @@ -4394,13 +4989,13 @@ msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle subdomain requests." msgstr "" -"Par défaut : <quote>id_provider</quote> est utilisé s'il est défini et peut " +"Par défaut : <quote>id_provider</quote> est utilisé s'il est défini et peut " "gérer le chargement selinux" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3341 msgid "session_provider (string)" -msgstr "" +msgstr "fournisseur_de_session (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3344 @@ -4409,24 +5004,31 @@ msgid "" "only user session task currently provided is the integration with Fleet " "Commander, which works only with IPA. Supported session providers are:" msgstr "" +"Le fournisseur qui configure et gère les tâches liées aux sessions " +"utilisateur. La seule tâche de session utilisateur actuellement disponible " +"est l'intégration avec Fleet Commander, qui fonctionne uniquement avec IPA. " +"Les fournisseurs de session pris en charge sont :" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3351 msgid "<quote>ipa</quote> to allow performing user session related tasks." msgstr "" +"<quote>ipa</quote> pour permettre l'exécution de tâches liées à la session " +"utilisateur." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3355 msgid "" "<quote>none</quote> does not perform any kind of user session related tasks." msgstr "" +"<quote>none</quote> n'effectue aucune tâche liée à la session utilisateur." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3359 #, fuzzy #| msgid "Default: <quote>permit</quote>" msgid "Default: <quote>none</quote>." -msgstr "Par défaut : <quote>permit</quote>" +msgstr "Par défaut : <quote>permit</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3365 @@ -4472,6 +5074,10 @@ msgid "" "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </" "citerefentry> for more information on configuring the AD provider." msgstr "" +"Utilisez la commande `<quote>ad</quote>` pour charger les cartes stockées " +"sur un serveur AD. Consultez `<citerefentry><refentrytitle>sssd-ad</" +"refentrytitle><manvolnum>5</manvolnum></citerefentry>` pour plus " +"d'informations sur la configuration du fournisseur AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3396 @@ -4488,7 +5094,7 @@ msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle autofs requests." msgstr "" -"Par défaut : <quote>id_provider</quote> est utilisé s'il est défini et peut " +"Par défaut : <quote>id_provider</quote> est utilisé s'il est défini et peut " "gérer les requêtes d'authentification." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -4532,13 +5138,13 @@ msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle hostid requests." msgstr "" -"Par défaut : <quote>id_provider</quote> est utilisé s'il est défini et peut " +"Par défaut : <quote>id_provider</quote> est utilisé s'il est défini et peut " "gérer les requêtes d'authentification." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3431 msgid "resolver_provider (string)" -msgstr "" +msgstr "fournisseur_de_résolution (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3434 @@ -4546,6 +5152,8 @@ msgid "" "The provider which should handle hosts and networks lookups. Supported " "resolver providers are:" msgstr "" +"Le fournisseur qui doit gérer les recherches d'hôtes et de réseaux. Les " +"fournisseurs de résolution pris en charge sont :" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3438 @@ -4553,6 +5161,8 @@ msgid "" "<quote>proxy</quote> to forward lookups to another NSS library. See " "<quote>proxy_resolver_lib_name</quote>" msgstr "" +"Utilisez un proxy pour rediriger les recherches vers une autre bibliothèque " +"NSS. Voir <quote>proxy_resolver_lib_name</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3442 @@ -4561,6 +5171,8 @@ msgid "" "<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" "manvolnum> </citerefentry> for more information on configuring LDAP." msgstr "" +"Utilisez LDAP pour récupérer les hôtes et les réseaux stockés dans LDAP. " +"Consultez sssd-ldap pour plus d'informations sur la configuration de LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3449 @@ -4570,11 +5182,17 @@ msgid "" "manvolnum> </citerefentry> for more information on configuring the AD " "provider." msgstr "" +"Utilisez `<quote>ad</quote>` pour récupérer les hôtes et les réseaux stockés " +"dans Active Directory. Consultez `<citerefentry> <refentrytitle>sssd-ad</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>` pour plus " +"d'informations sur la configuration du fournisseur Active Directory." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3457 msgid "<quote>none</quote> disallows fetching hosts and networks explicitly." msgstr "" +"<quote>none</quote> interdit la récupération explicite des hôtes et des " +"réseaux." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3460 @@ -4586,7 +5204,7 @@ msgid "" "Default: The value of <quote>id_provider</quote> is used if it is set and " "can handle resolver requests." msgstr "" -"Par défaut : <quote>id_provider</quote> est utilisé s'il est défini et peut " +"Par défaut : <quote>id_provider</quote> est utilisé s'il est défini et peut " "gérer les requêtes d'authentification." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> @@ -4617,10 +5235,10 @@ msgid "" "Default: <quote>^((?P<name>.+)@(?P<domain>[^@]*)|(?P<name>" "[^@]+))$</quote> which allows two different styles for user names:" msgstr "" -"Valeur par défaut pour les fournisseurs AD et IPA : <quote>((" +"Valeur par défaut pour les fournisseurs AD et IPA : <quote>((" "(?P<domain>[^\\\\]+)\\\\(?P<name>.+$))|((?P<name>[^@]+)@" "(?P<domain>.+$))|(^(?P<name>[^@\\\\]+)$))</quote> qui utilisent " -"trois styles différents pour les noms d'utilisateurs :" +"trois styles différents pour les noms d'utilisateurs :" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:3484 sssd.conf.5.xml:3498 @@ -4646,10 +5264,10 @@ msgid "" "P<name>[^@\\\\]+)))$</quote> which allows three different styles for " "user names:" msgstr "" -"Valeur par défaut pour les fournisseurs AD et IPA : <quote>((" +"Valeur par défaut pour les fournisseurs AD et IPA : <quote>((" "(?P<domain>[^\\\\]+)\\\\(?P<name>.+$))|((?P<name>[^@]+)@" "(?P<domain>.+$))|(^(?P<name>[^@\\\\]+)$))</quote> qui utilisent " -"trois styles différents pour les noms d'utilisateurs :" +"trois styles différents pour les noms d'utilisateurs :" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:3504 @@ -4675,6 +5293,11 @@ msgid "" "allowed in Windows group names). If a user wishes to use short names with " "<quote>@</quote> they must create their own re_expression." msgstr "" +"The default re_expression uses the <quote>@</quote> character as a separator " +"between the name and the domain. As a result of this setting the default " +"does not accept the <quote>@</quote> character in short names (as it is " +"allowed in Windows group names). If a user wishes to use short names with " +"<quote>@</quote> they must create their own re_expression." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3564 @@ -4744,12 +5367,16 @@ msgid "" "Defines the amount of time (in milliseconds) SSSD would try to talk to DNS " "server before trying next DNS server." msgstr "" +"Définit la durée (en millisecondes) pendant laquelle SSSD tentera de " +"communiquer avec un serveur DNS avant d'essayer un autre serveur DNS." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3606 msgid "" "The AD provider will use this option for the CLDAP ping timeouts as well." msgstr "" +"Le fournisseur AD utilisera également cette option pour les délais d'attente " +"de ping CLDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3610 sssd.conf.5.xml:3630 sssd.conf.5.xml:3651 @@ -4757,6 +5384,8 @@ msgid "" "Please see the section <quote>FAILOVER</quote> for more information about " "the service resolution." msgstr "" +"Veuillez consulter la section <quote>BAILOVER</quote> pour plus " +"d'informations sur la résolution du service." #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3615 sssd-ldap.5.xml:700 include/failover.xml:84 @@ -4777,6 +5406,9 @@ msgid "" "(e.g. resolution of a hostname or an SRV record) before trying the next " "hostname or DNS discovery." msgstr "" +"Définit le temps (en secondes) à attendre pour résoudre une seule requête " +"DNS (par exemple, la résolution d'un nom d'hôte ou d'un enregistrement SRV) " +"avant de tenter la découverte du nom d'hôte ou du DNS suivant." #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3635 include/failover.xml:100 @@ -4796,6 +5428,9 @@ msgid "" "If this timeout is reached, the domain will continue to operate in offline " "mode." msgstr "" +"Définit le délai (en secondes) d'attente d'une réponse du service de " +"basculement interne avant de considérer le service comme injoignable. Si ce " +"délai est atteint, le domaine continuera de fonctionner en mode hors ligne." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3662 @@ -4811,6 +5446,9 @@ msgid "" "\"search\" directive from the resolv.conf file. This can lead to delays in " "environments with improperly configured DNS." msgstr "" +"Normalement, le résolveur DNS interroge la liste de domaines définie dans la " +"directive « search » du fichier resolv.conf. Cela peut entraîner des délais " +"dans les environnements où le DNS est mal configuré." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3671 @@ -4819,6 +5457,9 @@ msgid "" "configuration, setting this option to FALSE can prevent unnecessary DNS " "lookups in such environments." msgstr "" +"Si des noms de domaine pleinement qualifiés (ou _srv_) sont utilisés dans la " +"configuration SSSD, le fait de définir cette option sur FALSE peut éviter " +"des recherches DNS inutiles dans de tels environnements." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3677 @@ -4860,18 +5501,21 @@ msgid "" "This option defines the number of seconds SSSD waits before attempting to " "reconnect to the primary server." msgstr "" +"En l'absence de serveur principal, SSSD bascule vers un serveur de secours. " +"Cette option définit le nombre de secondes pendant lesquelles SSSD attend " +"avant de tenter de se reconnecter au serveur principal." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3706 msgid "Note: The minimum value is 31." -msgstr "" +msgstr "Remarque : La valeur minimale est 31." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3709 #, fuzzy #| msgid "Default: 3" msgid "Default: 31" -msgstr "Par défaut : 3" +msgstr "Par défaut : 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3715 @@ -4897,6 +5541,7 @@ msgstr "True" #: sssd.conf.5.xml:3734 msgid "Case sensitive. This value is invalid for AD provider." msgstr "" +"Respectez la casse. Cette valeur n'est pas valide pour le fournisseur AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3740 @@ -4931,19 +5576,16 @@ msgid "" "If you want to set this value for trusted domain with IPA provider, you need " "to set it on both the client and SSSD on the server." msgstr "" +"Respectez la casse. Cette valeur n'est pas valide pour le fournisseur AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3727 -#, fuzzy -#| msgid "" -#| "The following expansions are supported: <placeholder " -#| "type=\"variablelist\" id=\"0\"/>" msgid "" "Treat user and group names as case sensitive. Possible option values are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" -"Les expansions suivantes sont prises en charge : <placeholder " -"type=\"variablelist\" id=\"0\"/>" +"Les noms d'utilisateurs et de groupes sont sensibles à la casse. Les valeurs " +"possibles sont : <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3772 @@ -4962,6 +5604,10 @@ msgid "" "subdomain. Please note that only selected parameters can be inherited. " "Currently the following options can be inherited:" msgstr "" +"Spécifie une liste de paramètres de configuration qui doivent être hérités " +"par un sous-domaine. Veuillez noter que seuls les paramètres sélectionnés " +"peuvent être hérités. Actuellement, les options suivantes peuvent être " +"héritées :" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3787 @@ -5009,6 +5655,8 @@ msgid "" "ldap_krb5_keytab (the value of krb5_keytab will be used if ldap_krb5_keytab " "is not set explicitly)" msgstr "" +"ldap_krb5_keytab (la valeur de krb5_keytab sera utilisée si ldap_krb5_keytab " +"n'est pas défini explicitement)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3809 @@ -5057,6 +5705,8 @@ msgstr "ignore_group_members" #: sssd.conf.5.xml:3830 msgid "auto_private_groups" msgstr "" +"ldap_krb5_keytab (la valeur de krb5_keytab sera utilisée si ldap_krb5_keytab " +"n'est pas défini explicitement)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3833 @@ -5079,6 +5729,7 @@ msgstr "" #: sssd.conf.5.xml:3845 msgid "Note: This option only works with the IPA and AD provider." msgstr "" +"Remarque : cette option fonctionne uniquement avec le fournisseur IPA et AD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3852 @@ -5140,7 +5791,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3887 msgid "cached_auth_timeout (int)" -msgstr "" +msgstr "délai_d'expiration_authentification_en_caché (int)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3890 @@ -5150,6 +5801,11 @@ msgid "" "the online mode. If the credentials are incorrect, SSSD falls back to online " "authentication." msgstr "" +"Spécifie le délai en secondes écoulé depuis la dernière authentification en " +"ligne réussie pour lequel l'utilisateur sera authentifié à l'aide des " +"informations d'identification mises en cache lorsque SSSD est en mode en " +"ligne. Si les informations d'identification sont incorrectes, SSSD utilise " +"l'authentification en ligne." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3898 @@ -5157,19 +5813,26 @@ msgid "" "This option's value is inherited by all trusted domains. At the moment it is " "not possible to set a different value per trusted domain." msgstr "" +"La valeur de cette option est héritée par tous les domaines de confiance. Il " +"n'est actuellement pas possible de définir une valeur différente pour chaque " +"domaine de confiance." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3903 msgid "Special value 0 implies that this feature is disabled." -msgstr "" +msgstr "La valeur spéciale 0 indique que cette fonctionnalité est désactivée." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3907 +#, fuzzy msgid "" "Please note that if <quote>cached_auth_timeout</quote> is longer than " "<quote>pam_id_timeout</quote> then the back end could be called to handle " "<quote>initgroups.</quote>" msgstr "" +"Veuillez noter que si <quote>cached_auth_timeout</quote> est supérieur à " +"<quote>pam_id_timeout</quote>, le serveur pourrait être sollicité pour gérer " +"<quote>initgroups</quote>." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3918 @@ -5189,6 +5852,15 @@ msgid "" "supported by the backend. With this option additional methods can be enabled " "which are evaluated and checked locally." msgstr "" +"Politique relative aux méthodes d'authentification locales. Certains " +"systèmes d'authentification (par exemple, LDAP, fournisseur proxy) ne " +"prennent en charge que l'authentification par mot de passe, tandis que " +"d'autres peuvent gérer l'authentification par carte à puce basée sur PKINIT " +"(AD, IPA), l'authentification à deux facteurs (IPA) ou d'autres méthodes " +"auprès d'une instance centrale. Par défaut, dans ces cas, l'authentification " +"est effectuée uniquement avec les méthodes prises en charge par le système " +"d'authentification. Cette option permet d'activer des méthodes " +"supplémentaires qui sont évaluées et vérifiées localement." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3933 @@ -5201,6 +5873,14 @@ msgid "" "passkey for local authentication. Multiple enable values should be comma-" "separated, such as <quote>enable:passkey, enable:smartcard</quote>" msgstr "" +"Cette option peut prendre trois valeurs : `match`, `only` et `enable`. " +"`match` permet de faire correspondre les états hors ligne et en ligne pour " +"les méthodes Kerberos. `only` ignore les méthodes en ligne et ne propose que " +"les méthodes locales. `enable` permet de définir explicitement les méthodes " +"d'authentification locale. Par exemple, `enable:passkey` active uniquement " +"l'authentification par clé d'accès pour l'authentification locale. Plusieurs " +"valeurs pour `enable` doivent être séparées par des virgules, comme ceci : " +"`enable:passkey, enable:smartcard`." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3946 @@ -5209,6 +5889,10 @@ msgid "" "properly, are currently enabled or disabled for each backend, with the " "default local_auth_policy: <quote>match</quote>" msgstr "" +"Le tableau suivant indique quelles méthodes d'authentification, si elles " +"sont correctement configurées, sont actuellement activées ou désactivées " +"pour chaque serveur, avec la politique d'authentification locale par défaut " +": <quote>match</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd.conf.5.xml:3959 @@ -5220,12 +5904,12 @@ msgstr "ldap_pwd_policy (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd.conf.5.xml:3960 msgid "Passkey" -msgstr "" +msgstr "Clé d'accès" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd.conf.5.xml:3961 msgid "Smartcard" -msgstr "" +msgstr "carte à puce" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:3964 sssd-ldap.5.xml:228 @@ -5240,12 +5924,12 @@ msgstr "AD" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> #: sssd.conf.5.xml:3967 sssd.conf.5.xml:3970 sssd.conf.5.xml:3971 msgid "disabled" -msgstr "" +msgstr "désactivé" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> #: sssd.conf.5.xml:3970 msgid "LDAP" -msgstr "" +msgstr "LDAP" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3975 @@ -5255,6 +5939,10 @@ msgid "" "authentication methods supported by the backend. I.e. there will be a PIN " "prompt instead of e.g. a password prompt." msgstr "" +"Veuillez noter que si l'authentification par carte à puce locale est activée " +"et qu'une carte à puce est présente, elle sera privilégiée par rapport aux " +"méthodes d'authentification prises en charge par le système. Autrement dit, " +"un code PIN vous sera demandé à la place d'un mot de passe." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:3987 @@ -5266,6 +5954,11 @@ msgid "" "auth_provider = none\n" "local_auth_policy = only\n" msgstr "" +"[domain/shadowutils]\n" +"id_provider = proxy\n" +"proxy_lib_name = files\n" +"auth_provider = none\n" +"local_auth_policy = only\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3983 @@ -5274,23 +5967,27 @@ msgid "" "locally using any enabled method (i.e. smartcard, passkey). <placeholder " "type=\"programlisting\" id=\"0\"/>" msgstr "" +"L'exemple de configuration suivant permet aux utilisateurs locaux de " +"s'authentifier localement à l'aide de n'importe quelle méthode activée (par " +"exemple, carte à puce, clé d'accès). <placeholder type=\"programlisting\" " +"id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3995 #, fuzzy #| msgid "Default: cn" msgid "Default: match" -msgstr "Par défaut : cn" +msgstr "Par défaut : cn" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4000 msgid "auto_private_groups (string)" -msgstr "" +msgstr "auto_private_groups (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4006 msgid "true" -msgstr "" +msgstr "vraie" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4009 @@ -5298,6 +5995,8 @@ msgid "" "Create user's private group unconditionally from user's UID number. The GID " "number is ignored in this case." msgstr "" +"Créez systématiquement le groupe privé de l'utilisateur à partir de son UID. " +"Le GID est ignoré dans ce cas." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4013 @@ -5307,11 +6006,15 @@ msgid "" "UID or GID number with this option. In other words, enabling this option " "enforces uniqueness across the ID space." msgstr "" +"REMARQUE : Étant donné que le numéro GID et le groupe privé de l’utilisateur " +"sont déduits du numéro UID, il est impossible d’avoir plusieurs entrées avec " +"le même numéro UID ou GID avec cette option. En d’autres termes, " +"l’activation de cette option garantit l’unicité de chaque identifiant." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4022 msgid "false" -msgstr "" +msgstr "FAUX" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4025 @@ -5319,11 +6022,13 @@ msgid "" "Always use the user's primary GID number. The GID number must refer to a " "group object in the LDAP database." msgstr "" +"Utilisez toujours le numéro GID principal de l'utilisateur. Ce numéro GID " +"doit faire référence à un objet groupe dans la base de données LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4031 msgid "hybrid" -msgstr "" +msgstr "hybride" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4034 @@ -5334,6 +6039,12 @@ msgid "" "GID in the user entry is also used by a group object, the primary GID of the " "user resolves to that group object." msgstr "" +"Un groupe principal est généré automatiquement pour les entrées utilisateur " +"dont les numéros UID et GID sont identiques, mais dont le numéro GID ne " +"correspond à aucun objet de groupe existant dans LDAP. Si les valeurs sont " +"identiques, mais que le GID principal de l'entrée utilisateur est également " +"utilisé par un objet de groupe, le GID principal de l'utilisateur est alors " +"associé à ce groupe." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4047 @@ -5341,6 +6052,9 @@ msgid "" "If the UID and GID of a user are different, then the GID must correspond to " "a group entry, otherwise the GID is simply not resolvable." msgstr "" +"Si l'UID et le GID d'un utilisateur sont différents, alors le GID doit " +"correspondre à une entrée de groupe, sinon le GID est tout simplement " +"insoluble." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4054 @@ -5349,6 +6063,9 @@ msgid "" "separate group objects for the user private groups, but also wish to retain " "the existing user private groups." msgstr "" +"Si l'UID et le GID d'un utilisateur sont différents, alors le GID doit " +"correspondre à une entrée de groupe, sinon le GID est tout simplement " +"insoluble." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4003 @@ -5356,6 +6073,8 @@ msgid "" "This option takes any of three available values: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"Cette option accepte l'une des trois valeurs disponibles : <placeholder " +"type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4066 @@ -5366,6 +6085,12 @@ msgid "" "provider is using True because IdPs typically do not have primary groups.</" "phrase>" msgstr "" +"Pour les fournisseurs d'identité basés sur LDAP (LDAP, IPA et AD), la valeur " +"par défaut pour le domaine configuré est généralement False, car les sources " +"utilisent la notion de groupe principal. <phrase " +"condition=\"with_idp_provider\">Le fournisseur d'identité utilise True, car " +"les fournisseurs d'identité n'ont généralement pas de groupes principaux.</" +"phrase>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4075 @@ -5373,6 +6098,8 @@ msgid "" "For subdomains, the default value is False for subdomains that use assigned " "POSIX IDs and True for subdomains that use automatic ID-mapping." msgstr "" +"For subdomains, the default value is False for subdomains that use assigned " +"POSIX IDs and True for subdomains that use automatic ID-mapping." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:4083 @@ -5381,6 +6108,8 @@ msgid "" "[domain/forest.domain/sub.domain]\n" "auto_private_groups = false\n" msgstr "" +"[domaine/forêt.domaine/sous-domaine]\n" +"auto_private_groups = false\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:4089 @@ -5390,6 +6119,9 @@ msgid "" "subdomain_inherit = auto_private_groups\n" "auto_private_groups = false\n" msgstr "" +"[domaine/forêt.domaine]\n" +"sous-domaine_hériter = groupes_privés_auto\n" +"groupes_privés_auto = faux\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4080 @@ -5399,6 +6131,11 @@ msgid "" "globally for all subdomains in the main domain section using the " "subdomain_inherit option: <placeholder type=\"programlisting\" id=\"1\"/>" msgstr "" +"La valeur de auto_private_groups peut être définie soit par sous-domaine " +"dans une sous-section, par exemple : <placeholder type=\"programlisting\" " +"id=\"0\"/>, soit globalement pour tous les sous-domaines de la section du " +"domaine principal à l'aide de l'option subdomain_inherit : <placeholder " +"type=\"programlisting\" id=\"1\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:2503 @@ -5433,7 +6170,7 @@ msgid "" "or create a new one and add the service name here. As an alternative you can " "enable local authentication with the local_auth_policy option." msgstr "" -"Par défaut : non défini, il faut utiliser une configuration de pam existante " +"Par défaut : non défini, il faut utiliser une configuration de pam existante " "ou en créer une nouvelle et ajouter le nom de service ici." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> @@ -5455,7 +6192,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4133 msgid "proxy_resolver_lib_name (string)" -msgstr "" +msgstr "nom_bibliothèque_résolveur_proxy (chaîne)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4136 @@ -5464,6 +6201,10 @@ msgid "" "domains. The NSS functions searched for in the library are in the form of " "_nss_$(libName)_$(function), for example _nss_dns_gethostbyname2_r." msgstr "" +"Nom de la bibliothèque NSS à utiliser pour la recherche d'hôtes et de " +"réseaux dans les domaines proxy. Les fonctions NSS recherchées dans la " +"bibliothèque sont au format _nss_$(nom_bibliothèque)_$(fonction), par " +"exemple _nss_dns_gethostbyname2_r." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4147 @@ -5487,7 +6228,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4164 msgid "proxy_max_children (integer)" -msgstr "" +msgstr "proxy_max_children (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4167 @@ -5496,6 +6237,10 @@ msgid "" "for high-load SSSD environments where sssd may run out of available child " "slots, which would cause some issues due to the requests being queued." msgstr "" +"Cette option spécifie le nombre de processus enfants proxy pré-forkés. Elle " +"est utile dans les environnements SSSD à forte charge où SSSD peut manquer " +"d'emplacements enfants disponibles, ce qui entraînerait des problèmes dus à " +"la mise en file d'attente des requêtes." #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4100 @@ -5509,7 +6254,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:4183 msgid "Application domains" -msgstr "" +msgstr "Domaines d'application" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:4185 @@ -5527,6 +6272,19 @@ msgid "" "<quote>application</quote> optionally inherits settings from a tradition " "SSSD domain." msgstr "" +"SSSD, avec son interface D-Bus (voir <citerefentry> <refentrytitle>sssd-ifp</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>), est un outil " +"précieux pour les applications, servant de passerelle vers un annuaire LDAP " +"où sont stockés les utilisateurs et les groupes. Cependant, contrairement au " +"déploiement SSSD traditionnel où tous les utilisateurs et groupes possèdent " +"des attributs POSIX ou où ces attributs peuvent être déduits des SID " +"Windows, dans de nombreux cas, les utilisateurs et les groupes pris en " +"charge par les applications ne possèdent pas d'attributs POSIX. Au lieu de " +"définir une section <quote>[domain/<replaceable>NAME</replaceable>]</quote>, " +"l'administrateur peut configurer une section <quote>[application/" +"<replaceable>NAME</replaceable>]</quote> qui représente en interne un " +"domaine de type <quote>application</quote> et qui peut hériter des " +"paramètres d'un domaine SSSD traditionnel." #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:4205 @@ -5535,16 +6293,20 @@ msgid "" "the <quote>domains</quote> parameter so that the lookup order between the " "application domain and its POSIX sibling domain is set correctly." msgstr "" +"Veuillez noter que le domaine d'application doit toujours être explicitement " +"activé dans le paramètre <quote>domains</quote> afin que l'ordre de " +"recherche entre le domaine d'application et son domaine frère POSIX soit " +"correctement défini." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> #: sssd.conf.5.xml:4211 msgid "Application domain parameters" -msgstr "" +msgstr "Paramètres du domaine d'application" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:4213 msgid "inherit_from (string)" -msgstr "" +msgstr "hériter_de (chaîne)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4216 @@ -5554,6 +6316,10 @@ msgid "" "application settings that augment or override the <quote>sibling</quote> " "domain settings." msgstr "" +"The SSSD POSIX-type domain the application domain inherits all settings " +"from. The application domain can moreover add its own settings to the " +"application settings that augment or override the <quote>sibling</quote> " +"domain settings." #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:4230 @@ -5564,6 +6330,11 @@ msgid "" "the telephoneNumber attribute, stores it as the phone attribute in the cache " "and makes the phone attribute reachable through the D-Bus interface." msgstr "" +"L'exemple suivant illustre l'utilisation d'un domaine d'application. Dans " +"cette configuration, le domaine POSIX est connecté à un serveur LDAP et " +"utilisé par le système d'exploitation via le répondeur NSS. De plus, le " +"domaine d'application récupère l'attribut telephoneNumber, le stocke comme " +"attribut phone dans le cache et le rend accessible via l'interface D-Bus." #. type: Content of: <reference><refentry><refsect1><refsect2><programlisting> #: sssd.conf.5.xml:4238 @@ -5584,11 +6355,25 @@ msgid "" "inherit_from = posixdom\n" "ldap_user_extra_attrs = phone:telephoneNumber\n" msgstr "" +"[sssd]\n" +"domaines = appdom, posixdom\n" +"\n" +"[ifp]\n" +"attributs_utilisateur = +téléphone\n" +"\n" +"[domaine/posixdom]\n" +"fournisseur_id = ldap\n" +"uri_ldap = ldap://ldap.example.com\n" +"base_recherche_ldap = dc=example,dc=com\n" +"\n" +"[application/appdom]\n" +"hériter_de = posixdom\n" +"attributs_utilisateur_supplémentaires_ldap = téléphone:numéro_de_téléphone\n" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:4258 msgid "TRUSTED DOMAIN SECTION" -msgstr "" +msgstr "SECTION DOMAINE DE CONFIANCE" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4260 @@ -5600,56 +6385,63 @@ msgid "" "domain. Please refer to examples below for explanation. Currently supported " "options in the trusted domain section are:" msgstr "" +"Certaines options utilisées dans la section « Domaine » peuvent également " +"être utilisées dans la section « Domaine de confiance », c’est-à-dire dans " +"une section nommée <quote>[domaine/<replaceable>NOM_DOMAIN</replaceable>/" +"<replaceable>NOM_DOMAIN_DE_CONFIANCE</replaceable>]</quote>. Où NOM_DOMAIN " +"correspond au domaine de base auquel la jonction est effectuée. Veuillez " +"consulter les exemples ci-dessous pour plus d’explications. Les options " +"actuellement prises en charge dans la section « Domaine de confiance » sont :" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4267 msgid "ldap_search_base," -msgstr "" +msgstr "base de recherche LDAP," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4268 msgid "ldap_user_search_base," -msgstr "" +msgstr "ldap_user_search_base," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4269 msgid "ldap_group_search_base," -msgstr "" +msgstr "base de recherche de groupe LDAP," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4270 msgid "ldap_netgroup_search_base," -msgstr "" +msgstr "ldap_netgroup_search_base," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4271 msgid "ldap_service_search_base," -msgstr "" +msgstr "base de recherche du service LDAP," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4272 msgid "ldap_sasl_mech," -msgstr "" +msgstr "ldap_sasl_mech," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4273 msgid "ad_server," -msgstr "" +msgstr "serveur_publicitaire," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4274 msgid "ad_backup_server," -msgstr "" +msgstr "serveur_de_sauvegarde_publicitaire," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4275 msgid "ad_site," -msgstr "" +msgstr "site_publicitaire," #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:4276 sssd-ipa.5.xml:934 msgid "use_fully_qualified_names" -msgstr "" +msgstr "use_fully_qualified_names" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4280 @@ -5657,11 +6449,13 @@ msgid "" "For more details about these options see their individual description in the " "manual page." msgstr "" +"Pour plus de détails sur ces options, consultez leur description " +"individuelle dans la page du manuel." #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:4286 msgid "CERTIFICATE MAPPING SECTION" -msgstr "" +msgstr "SECTION DE CARTOGRAPHIE DES CERTIFICATS" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4288 @@ -5675,6 +6469,15 @@ msgid "" "might be cumbersome or not even possible to do this for the general case " "where local services use PAM for authentication." msgstr "" +"Pour permettre l'authentification par carte à puce et certificat, SSSD doit " +"pouvoir associer les certificats aux utilisateurs. Cela peut se faire en " +"ajoutant le certificat complet à l'objet LDAP de l'utilisateur ou en " +"utilisant une substitution locale. Bien que l'utilisation du certificat " +"complet soit requise pour l'authentification par carte à puce SSH (voir " +"<citerefentry> <refentrytitle>sss_ssh_authorizedkeys</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> pour plus de détails), cela peut " +"s'avérer complexe, voire impossible, dans le cas général où les services " +"locaux utilisent PAM pour l'authentification." #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4302 @@ -5683,6 +6486,10 @@ msgid "" "SSSD (see <citerefentry> <refentrytitle>sss-certmap</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> for details)." msgstr "" +"Pour rendre le mappage plus flexible, des règles de mappage et de " +"correspondance ont été ajoutées à SSSD (voir <citerefentry> <refentrytitle>" +"sss-certmap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> pour " +"plus de détails)." #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4311 @@ -5692,11 +6499,16 @@ msgid "" "<replaceable>DOMAIN_NAME</replaceable>/<replaceable>RULE_NAME</" "replaceable>]</quote>. In this section the following options are allowed:" msgstr "" +"Une règle de mappage et de correspondance peut être ajoutée à la " +"configuration SSSD dans une section dédiée, nommée par exemple : <quote>" +"[certmap/<replaceable>NOM_DOMAIN</replaceable>/<replaceable>NOM_RÈGLE</" +"replaceable>]</quote>. Dans cette section, les options suivantes sont " +"autorisées :" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:4318 msgid "matchrule (string)" -msgstr "" +msgstr "règle de correspondance (chaîne)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4321 @@ -5704,6 +6516,8 @@ msgid "" "Only certificates from the Smartcard which matches this rule will be " "processed, all others are ignored." msgstr "" +"Only certificates from the Smartcard which matches this rule will be " +"processed, all others are ignored." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4325 @@ -5711,16 +6525,19 @@ msgid "" "Default: KRB5:<EKU>clientAuth, i.e. only certificates which have the " "Extended Key Usage <quote>clientAuth</quote>" msgstr "" +"Par défaut : KRB5 : &EKU > clientAuth, c’est-à-dire uniquement les " +"certificats disposant de l’utilisation étendue de la clé <quote>clientAuth</" +"quote>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:4332 msgid "maprule (string)" -msgstr "" +msgstr "règle de carte (chaîne)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4335 msgid "Defines how the user is found for a given certificate." -msgstr "" +msgstr "Définit comment l'utilisateur est trouvé pour un certificat donné." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:4341 @@ -5728,6 +6545,8 @@ msgid "" "LDAP:(userCertificate;binary={cert!bin}) for LDAP based providers like " "<quote>ldap</quote>, <quote>AD</quote> or <quote>ipa</quote>." msgstr "" +"LDAP:(userCertificate;binary={cert!bin}) pour les fournisseurs basés sur " +"LDAP comme <quote>ldap</quote>, <quote>AD</quote> ou <quote>ipa</quote>." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:4347 @@ -5735,11 +6554,13 @@ msgid "" "If maprule is not set and provider is <quote>proxy</quote>, the RULE_NAME " "name is assumed to be the name of the matching user." msgstr "" +"Si maprule n'est pas défini et que provider est <quote>proxy</quote>, le nom " +"RULE_NAME est supposé être le nom de l'utilisateur correspondant." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:4357 msgid "domains (string)" -msgstr "" +msgstr "domaines (chaîne de caractères)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4360 @@ -5749,16 +6570,20 @@ msgid "" "supports subdomains this option can be used to add the rule to subdomains as " "well." msgstr "" +"Liste de noms de domaine, séparés par des virgules, auxquels la règle doit " +"s'appliquer. Par défaut, une règle n'est valable que pour le domaine " +"configuré dans sssd.conf. Si le fournisseur prend en charge les sous-" +"domaines, cette option permet d'ajouter la règle à ces derniers." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4367 msgid "Default: the configured domain in sssd.conf" -msgstr "" +msgstr "Par défaut : le domaine configuré dans sssd.conf" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:4372 msgid "priority (integer)" -msgstr "" +msgstr "priorité (entier)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4375 @@ -5767,16 +6592,19 @@ msgid "" "number the lower the priority. <quote>0</quote> stands for the highest " "priority while <quote>4294967295</quote> is the lowest." msgstr "" +"Valeur entière non signée définissant la priorité de la règle. Plus le " +"nombre est élevé, plus la priorité est faible. 0 représente la priorité la " +"plus élevée, tandis que 4294967295 représente la plus faible." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4381 msgid "Default: the lowest priority" -msgstr "" +msgstr "Par défaut : priorité la plus basse" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:4389 msgid "PROMPTING CONFIGURATION SECTION" -msgstr "" +msgstr "SECTION DE CONFIGURATION DES INVITATIONS" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4391 @@ -5787,6 +6615,12 @@ msgid "" "Based on the results pam_sss will prompt the user for appropriate " "credentials." msgstr "" +"Si un fichier spécifique (<filename>/var/lib/sss/pubconf/" +"pam_preauth_available</filename>) existe, le module PAM de SSSD, pam_sss, " +"interrogera SSSD pour déterminer les méthodes d'authentification disponibles " +"pour l'utilisateur qui tente de se connecter. En fonction des résultats, " +"pam_sss invitera l'utilisateur à saisir les informations d'identification " +"appropriées." #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4399 @@ -5796,21 +6630,25 @@ msgid "" "select the prompting might not be suitable for all use cases. The following " "options should provide a better flexibility here." msgstr "" +"Face à la multiplication des méthodes d'authentification et à la possibilité " +"qu'un même utilisateur en utilise plusieurs, l'heuristique employée par " +"pam_sss pour sélectionner le message d'invite peut ne pas convenir à tous " +"les cas de figure. Les options suivantes offrent une plus grande flexibilité." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4411 msgid "[prompting/password]" -msgstr "" +msgstr "[invite/mot de passe]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4414 msgid "password_prompt" -msgstr "" +msgstr "invite_mot_de_passe" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4415 msgid "to change the string of the password prompt" -msgstr "" +msgstr "modifier le texte de l'invite de mot de passe" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4413 @@ -5818,36 +6656,38 @@ msgid "" "to configure password prompting, allowed options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"Pour configurer l'invite de mot de passe, les options autorisées sont : " +"<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4423 msgid "[prompting/2fa]" -msgstr "" +msgstr "[invite/2fa]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4427 msgid "first_prompt" -msgstr "" +msgstr "première_invite" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4428 msgid "to change the string of the prompt for the first factor" -msgstr "" +msgstr "modifier la chaîne de l'invite pour le premier facteur" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4431 msgid "second_prompt" -msgstr "" +msgstr "modifier la chaîne de l'invite pour le premier facteur" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4432 msgid "to change the string of the prompt for the second factor" -msgstr "" +msgstr "modifier le texte de l'invite pour le deuxième facteur" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4435 msgid "single_prompt" -msgstr "" +msgstr "invite unique" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4436 @@ -5857,6 +6697,10 @@ msgid "" "string. Please note that both factors have to be entered here, even if the " "second factor is optional." msgstr "" +"Valeur booléenne : si la valeur est Vrai, une seule invite s’affichera, " +"utilisant la valeur de `first_prompt`, où les deux facteurs doivent être " +"saisis sous forme d’une seule chaîne de caractères. Veuillez noter que les " +"deux facteurs doivent être saisis, même si le second est facultatif." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4425 @@ -5866,6 +6710,11 @@ msgid "" "optional and it should be possible to log in either only with the password " "or with both factors two-step prompting has to be used." msgstr "" +"Pour configurer l'invite d'authentification à deux facteurs, les options " +"autorisées sont : <placeholder type=\"variablelist\" id=\"0\"/> Si le " +"deuxième facteur est facultatif et qu'il doit être possible de se connecter " +"soit uniquement avec le mot de passe, soit avec les deux facteurs, l'invite " +"en deux étapes doit être utilisée." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4449 @@ -5877,16 +6726,23 @@ msgid "" "the user at the SSH password prompt will always be the two factors in a " "single string, even if two-factor authentication is optional." msgstr "" +"Certains clients, comme SSH avec l'option « PasswordAuthentication yes », " +"génèrent leurs propres invites et n'utilisent pas celles fournies par SSSD " +"ou d'autres modules PAM. De plus, pour SSH avec PasswordAuthentication, si " +"l'authentification à deux facteurs est disponible, SSSD exige que les " +"identifiants saisis par l'utilisateur lors de l'invite de mot de passe SSH " +"correspondent toujours aux deux facteurs dans une seule chaîne de " +"caractères, même si l'authentification à deux facteurs est optionnelle." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4464 msgid "[prompting/passkey]" -msgstr "" +msgstr "[invite/clé d'accès]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:4470 sssd-ad.5.xml:1022 msgid "interactive" -msgstr "" +msgstr "interactif" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4472 @@ -5895,21 +6751,24 @@ msgid "" "of a passkey device. Recommended if your device doesn’t have a tactile " "trigger." msgstr "" +"Valeur booléenne : si la valeur est Vrai, afficher un message et attendre " +"avant de tester la présence d’un périphérique à code d’accès. Recommandé si " +"votre appareil ne possède pas de déclencheur tactile." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4480 msgid "interactive_prompt" -msgstr "" +msgstr "invite interactive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4482 msgid "to change the message of the interactive prompt." -msgstr "" +msgstr "modifier le message de l'invite interactive." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4487 msgid "touch" -msgstr "" +msgstr "touch" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4489 @@ -5917,16 +6776,18 @@ msgid "" "boolean value, if True prompt a message to remind the user to touch the " "device." msgstr "" +"Valeur booléenne ; si la valeur est True, afficher un message invitant " +"l’utilisateur à toucher l’appareil." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4495 msgid "touch_prompt" -msgstr "" +msgstr "invite tactile" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4497 msgid "to change the message of the touch prompt." -msgstr "" +msgstr "modifier le message de l'invite tactile." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4466 @@ -5949,6 +6810,11 @@ msgid "" "type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" id=\"1\"/" "> <placeholder type=\"variablelist\" id=\"2\"/>" msgstr "" +"Chaque méthode d'authentification prise en charge possède sa propre sous-" +"section de configuration sous <quote>[prompting/...]</quote>. Actuellement, " +"on y trouve : <placeholder type=\"variablelist\" id=\"0\"/> <placeholder " +"type=\"variablelist\" id=\"1\"/> <placeholder type=\"variablelist\" " +"id=\"2\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4508 @@ -5957,11 +6823,14 @@ msgid "" "<quote>[prompting/password/sshd]</quote> to individual change the prompting " "for this service." msgstr "" +"Il est possible d'ajouter une sous-section pour des services PAM " +"spécifiques, par exemple <quote>[prompting/password/sshd]</quote> pour " +"modifier individuellement l'invite pour ce service." #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:4515 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 msgid "EXAMPLES" -msgstr "" +msgstr "EXEMPLES" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd.conf.5.xml:4521 @@ -6049,6 +6918,10 @@ msgid "" "configuring domains for more details. <placeholder type=\"programlisting\" " "id=\"0\"/>" msgstr "" +"1. L'exemple suivant illustre une configuration SSSD typique. Il ne décrit " +"pas la configuration des domaines eux-mêmes ; reportez-vous à la " +"documentation relative à la configuration des domaines pour plus de détails. " +"<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd.conf.5.xml:4553 @@ -6057,6 +6930,8 @@ msgid "" "[domain/ipa.com/child.ad.com]\n" "use_fully_qualified_names = false\n" msgstr "" +"[domain/ipa.com/child.ad.com]\n" +"use_fully_qualified_names = false\n" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4547 @@ -6068,6 +6943,12 @@ msgid "" "configuration should be used. <placeholder type=\"programlisting\" id=\"0\"/" ">" msgstr "" +"2. L'exemple suivant illustre la configuration d'une approbation IPA AD " +"lorsque la forêt AD est composée de deux domaines dans une structure parent-" +"enfant. Supposons que le domaine IPA (ipa.com) ait une approbation avec le " +"domaine AD (ad.com). ad.com possède un domaine enfant (child.ad.com). Pour " +"activer les noms courts dans le domaine enfant, la configuration suivante " +"doit être utilisée. <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd.conf.5.xml:4564 @@ -6079,6 +6960,11 @@ msgid "" "domains = my.domain, your.domain\n" "priority = 10\n" msgstr "" +"[certmap/my.domain/rule_name]\n" +"matchrule = <ISSUER>^CN=My-CA,DC=MY,DC=DOMAIN$\n" +"maprule = (userCertificate;binary={cert!bin})\n" +"domains = my.domain, your.domain\n" +"priority = 10\n" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4558 @@ -6089,6 +6975,11 @@ msgid "" "certificate in the search filter. <placeholder type=\"programlisting\" " "id=\"0\"/>" msgstr "" +"3. L'exemple suivant illustre la configuration d'une règle de mappage de " +"certificat. Elle est valable pour le domaine configuré <quote>my.domain</" +"quote> et également pour les sous-domaines <quote>your.domain</quote>, et " +"utilise le certificat complet dans le filtre de recherche. <placeholder " +"type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-ldap.5.xml:10 sssd-ldap.5.xml:16 @@ -6353,18 +7244,22 @@ msgid "" "default, this is done anonymously. However, this may not be permitted by the " "LDAP server. In such cases we can use this option to influence SSSD behavior." msgstr "" +"SSSD consulte RootDSE pour obtenir des informations sur LDAP et ses " +"fonctionnalités. Par défaut, cette opération est anonyme. Toutefois, il est " +"possible que le serveur LDAP l'interdise. Dans ce cas, cette option permet " +"d'influencer le comportement de SSSD." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:175 #, fuzzy #| msgid "The following values are allowed:" msgid "Allowed values are:" -msgstr "Les valeurs suivantes sont autorisées :" +msgstr "Les valeurs suivantes sont autorisées :" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ldap.5.xml:179 msgid "anonymous" -msgstr "" +msgstr "anonyme" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ldap.5.xml:184 diff --git a/src/man/po/ka.po b/src/man/po/ka.po index e7bbd26bb43..a520084b0e1 100644 --- a/src/man/po/ka.po +++ b/src/man/po/ka.po @@ -8,7 +8,7 @@ msgstr "" "Project-Id-Version: sssd-docs 2.11.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" "POT-Creation-Date: 2025-06-04 14:28+0000\n" -"PO-Revision-Date: 2026-04-23 16:20+0000\n" +"PO-Revision-Date: 2026-08-02 07:18+0000\n" "Last-Translator: Temuri Doghonadze <temuri.doghonadze@gmail.com>\n" "Language-Team: Georgian <https://translate.fedoraproject.org/projects/sssd/" "sssd-manpage-master/ka/>\n" @@ -17,7 +17,7 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=n != 1;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.7.1\n" #. type: Content of: <reference><title> #: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 @@ -63,7 +63,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:24 msgid "FILE FORMAT" -msgstr "" +msgstr "ფაილის ფორმატი" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd.conf.5.xml:32 @@ -164,7 +164,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:103 msgid "GENERAL OPTIONS" -msgstr "" +msgstr "ზოგადი პარამეტრები" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:105 @@ -179,12 +179,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:113 msgid "debug_level (integer)" -msgstr "" +msgstr "debug_level (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:117 msgid "debug (integer)" -msgstr "" +msgstr "debug (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:120 @@ -198,7 +198,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:130 msgid "debug_timestamps (bool)" -msgstr "" +msgstr "debug_timestamps (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:133 @@ -216,12 +216,12 @@ msgstr "" #: sssd-ipa.5.xml:362 sssd-ad.5.xml:252 sssd-ad.5.xml:367 sssd-ad.5.xml:1232 #: sssd-ad.5.xml:1400 sssd-krb5.5.xml:358 msgid "Default: true" -msgstr "" +msgstr "ნაგულისხმევი: ჭეშმარიტი" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:143 msgid "debug_microseconds (bool)" -msgstr "" +msgstr "debug_microseconds (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:146 @@ -237,12 +237,12 @@ msgstr "" #: sssd-ipa.5.xml:255 sssd-ipa.5.xml:727 sssd-ad.5.xml:1135 sssd-krb5.5.xml:268 #: sssd-krb5.5.xml:330 sssd-krb5.5.xml:432 include/krb5_options.xml:163 msgid "Default: false" -msgstr "" +msgstr "ნაგულისხმევი: ცრუ" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:156 msgid "debug_backtrace_enabled (bool)" -msgstr "" +msgstr "debug_backtrace_enabled (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:159 @@ -277,7 +277,7 @@ msgstr "" #: sssd-ldap-attributes.5.xml:1250 include/autofs_attributes.xml:1 #: include/krb5_options.xml:1 msgid "<placeholder type=\"variablelist\" id=\"0\"/>" -msgstr "" +msgstr "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:184 @@ -287,7 +287,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:188 msgid "timeout (integer)" -msgstr "" +msgstr "timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:191 @@ -302,22 +302,22 @@ msgstr "" #: sssd.conf.5.xml:4170 sssd-ldap.5.xml:820 sssd-idp.5.xml:192 #: include/ldap_id_mapping.xml:270 msgid "Default: 10" -msgstr "" +msgstr "ნაგულისხმევი: 10" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:208 msgid "SPECIAL SECTIONS" -msgstr "" +msgstr "სპეციალური განყოფილებები" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:211 msgid "The [sssd] section" -msgstr "" +msgstr "სექცია [sssd]" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><title> #: sssd.conf.5.xml:220 msgid "Section parameters" -msgstr "" +msgstr "განყოფილების პარამეტრები" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:222 @@ -369,7 +369,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:266 sssd.conf.5.xml:3454 msgid "re_expression (string)" -msgstr "" +msgstr "re_expression (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:269 @@ -389,7 +389,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:283 sssd.conf.5.xml:3511 msgid "full_name_format (string)" -msgstr "" +msgstr "full_name_format (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:286 sssd.conf.5.xml:3514 @@ -408,7 +408,7 @@ msgstr "%1$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:298 sssd.conf.5.xml:3526 msgid "user name" -msgstr "" +msgstr "მომხმარებლის სახელი" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:301 sssd.conf.5.xml:3529 @@ -449,7 +449,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:329 msgid "monitor_resolv_conf (boolean)" -msgstr "" +msgstr "monitor_resolv_conf (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:332 @@ -461,7 +461,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:342 msgid "try_inotify (boolean)" -msgstr "" +msgstr "try_inotify (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:345 @@ -496,7 +496,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:368 msgid "krb5_rcache_dir (string)" -msgstr "" +msgstr "krb5_rcache_dir (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:371 @@ -522,7 +522,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:388 msgid "default_domain_suffix (string)" -msgstr "" +msgstr "default_domain_suffix (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:391 @@ -558,12 +558,12 @@ msgstr "" #: include/ldap_id_mapping.xml:211 include/ldap_id_mapping.xml:222 #: include/krb5_options.xml:148 msgid "Default: not set" -msgstr "" +msgstr "ნაგულისხმევი: დაყენებული არაა" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:419 msgid "override_space (string)" -msgstr "" +msgstr "override_space (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:422 @@ -592,7 +592,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:444 msgid "certificate_verification (string)" -msgstr "" +msgstr "certificate_verification (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:452 @@ -672,7 +672,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:500 msgid "partial_chain" -msgstr "" +msgstr "partial_chain" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:502 @@ -685,7 +685,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:511 msgid "ocsp_default_responder=URL" -msgstr "" +msgstr "ocsp_default_responder=URL" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:513 @@ -698,7 +698,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:523 msgid "ocsp_default_responder_signing_cert=NAME" -msgstr "" +msgstr "ocsp_default_responder_signing_cert=NAME" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:525 @@ -710,7 +710,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:533 msgid "crl_file=/PATH/TO/CRL/FILE" -msgstr "" +msgstr "crl_file=/PATH/TO/CRL/FILE" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:535 @@ -724,7 +724,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:548 msgid "soft_crl" -msgstr "" +msgstr "soft_crl" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:551 @@ -756,7 +756,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:573 msgid "disable_netlink (boolean)" -msgstr "" +msgstr "disable_netlink (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:576 @@ -780,7 +780,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:591 msgid "domain_resolution_order" -msgstr "" +msgstr "domain_resolution_order" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:594 @@ -815,12 +815,12 @@ msgstr "" #: sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 sssd-idp.5.xml:108 #: sssd-idp.5.xml:132 sssd-idp.5.xml:145 sssd-idp.5.xml:159 sssd-idp.5.xml:180 msgid "Default: Not set" -msgstr "" +msgstr "ნაგულისხმევი: დაყენებული არაა" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:635 msgid "implicit_pac_responder (boolean)" -msgstr "" +msgstr "implicit_pac_responder (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:638 @@ -833,7 +833,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:649 msgid "core_dumpable (boolean)" -msgstr "" +msgstr "core_dumpable (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:652 @@ -856,12 +856,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:673 msgid "passkey_verification (string)" -msgstr "" +msgstr "passkey_verification (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:681 msgid "user_verification (boolean)" -msgstr "" +msgstr "user_verification (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:683 @@ -924,7 +924,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:723 msgid "fd_limit" -msgstr "" +msgstr "fd_limit" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:726 @@ -944,7 +944,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:740 msgid "client_idle_timeout" -msgstr "" +msgstr "client_idle_timeout" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:743 @@ -959,12 +959,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:752 msgid "Default: 60, KCM: 300" -msgstr "" +msgstr "ნაგულისხმევი: 60, KCM: 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:757 msgid "offline_timeout (integer)" -msgstr "" +msgstr "offline_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:760 @@ -1003,12 +1003,12 @@ msgstr "" #: sssd.conf.5.xml:784 sssd.conf.5.xml:1110 sssd.conf.5.xml:1490 #: sssd.conf.5.xml:1786 sssd-ldap.5.xml:545 msgid "Default: 60" -msgstr "" +msgstr "ნაგულისხმევი: 60" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:789 msgid "offline_timeout_max (integer)" -msgstr "" +msgstr "offline_timeout_max (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:792 @@ -1048,12 +1048,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:815 msgid "Default: 3600" -msgstr "" +msgstr "ნაგულისხმევი: 3600" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:820 msgid "offline_timeout_random_offset (integer)" -msgstr "" +msgstr "offline_timeout_random_offset (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:823 @@ -1072,7 +1072,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:835 msgid "[0 - offline_timeout_random_offset]" -msgstr "" +msgstr "[0 - offline_timeout_random_offset]" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:838 @@ -1082,12 +1082,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:841 msgid "Default: 30" -msgstr "" +msgstr "ნაგულისხმევი: 30" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:846 msgid "responder_idle_timeout" -msgstr "" +msgstr "responder_idle_timeout" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:849 @@ -1105,12 +1105,12 @@ msgstr "" #: sssd.conf.5.xml:863 sssd.conf.5.xml:1123 sssd.conf.5.xml:2215 #: sssd-ldap.5.xml:382 msgid "Default: 300" -msgstr "" +msgstr "ნაგულისხმევი: 300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:868 msgid "cache_first" -msgstr "" +msgstr "cache_first" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:871 @@ -1134,7 +1134,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:890 msgid "enum_cache_timeout (integer)" -msgstr "" +msgstr "enum_cache_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:893 @@ -1146,12 +1146,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:897 msgid "Default: 120" -msgstr "" +msgstr "ნაგულისხმევი: 120" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:902 msgid "entry_cache_nowait_percentage (integer)" -msgstr "" +msgstr "entry_cache_nowait_percentage (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:905 @@ -1183,12 +1183,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:929 sssd.conf.5.xml:2028 msgid "Default: 50" -msgstr "" +msgstr "ნაგულისხმევი: 50" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:934 msgid "entry_negative_timeout (integer)" -msgstr "" +msgstr "entry_negative_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:937 @@ -1201,12 +1201,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:943 sssd.conf.5.xml:1685 sssd.conf.5.xml:2052 msgid "Default: 15" -msgstr "" +msgstr "ნაგულისხმევი: 15" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:948 msgid "filter_users, filter_groups (string)" -msgstr "" +msgstr "filter_users, filter_groups (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:951 @@ -1229,12 +1229,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:967 msgid "Default: root" -msgstr "" +msgstr "ნაგულისხმევი: root" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:972 msgid "filter_users_in_groups (bool)" -msgstr "" +msgstr "filter_users_in_groups (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:975 @@ -1244,7 +1244,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:986 msgid "fallback_homedir (string)" -msgstr "" +msgstr "fallback_homedir (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:989 @@ -1265,6 +1265,8 @@ msgid "" "fallback_homedir = /home/%u\n" " " msgstr "" +"fallback_homedir = /home/%u\n" +" " #. type: Content of: <varlistentry><listitem><para> #: sssd.conf.5.xml:998 sssd.conf.5.xml:1557 sssd.conf.5.xml:1576 @@ -1280,7 +1282,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1010 msgid "override_shell (string)" -msgstr "" +msgstr "override_shell (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1013 @@ -1298,7 +1300,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1025 msgid "allowed_shells (string)" -msgstr "" +msgstr "allowed_shells (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1028 @@ -1357,7 +1359,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1067 msgid "vetoed_shells (string)" -msgstr "" +msgstr "vetoed_shells (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1070 @@ -1367,7 +1369,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1075 msgid "shell_fallback (string)" -msgstr "" +msgstr "shell_fallback (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1078 @@ -1379,12 +1381,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1082 msgid "Default: /bin/sh" -msgstr "" +msgstr "ნაგულისხმევი: /bin/sh" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1087 msgid "default_shell" -msgstr "" +msgstr "default_shell" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1090 @@ -1404,7 +1406,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1103 sssd.conf.5.xml:1483 msgid "get_domains_timeout (int)" -msgstr "" +msgstr "get_domains_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1106 sssd.conf.5.xml:1486 @@ -1416,7 +1418,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1115 msgid "memcache_timeout (integer)" -msgstr "" +msgstr "memcache_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1118 @@ -1443,7 +1445,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1140 msgid "memcache_size_passwd (integer)" -msgstr "" +msgstr "memcache_size_passwd (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1143 @@ -1456,7 +1458,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1149 sssd.conf.5.xml:2874 sssd-ldap.5.xml:599 msgid "Default: 8" -msgstr "" +msgstr "ნაგულისხმევი: 8" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1152 sssd.conf.5.xml:1177 sssd.conf.5.xml:1202 @@ -1469,7 +1471,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1165 msgid "memcache_size_group (integer)" -msgstr "" +msgstr "memcache_size_group (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1168 @@ -1484,12 +1486,12 @@ msgstr "" #: sssd-ldap.5.xml:524 sssd-ldap.5.xml:576 include/failover.xml:116 #: include/krb5_options.xml:11 msgid "Default: 6" -msgstr "" +msgstr "ნაგულისხმევი: 6" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1190 msgid "memcache_size_initgroups (integer)" -msgstr "" +msgstr "memcache_size_initgroups (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1193 @@ -1502,7 +1504,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1215 msgid "memcache_size_sid (integer)" -msgstr "" +msgstr "memcache_size_sid (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1218 @@ -1516,7 +1518,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:1242 sssd-ifp.5.xml:90 msgid "user_attributes (string)" -msgstr "" +msgstr "user_attributes (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1245 @@ -1545,7 +1547,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1268 msgid "pwfield (string)" -msgstr "" +msgstr "pwfield (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1271 @@ -1557,7 +1559,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1276 msgid "Default: <quote>*</quote>" -msgstr "" +msgstr "ნაგულისხმევი: <quote>*</quote>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1279 @@ -1588,7 +1590,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1299 msgid "offline_credentials_expiration (integer)" -msgstr "" +msgstr "offline_credentials_expiration (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1302 @@ -1600,12 +1602,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1307 sssd.conf.5.xml:1320 msgid "Default: 0 (No limit)" -msgstr "" +msgstr "ნაგულისხმევი: 0 (შეზღუდვის გარეშე)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1313 msgid "offline_failed_login_attempts (integer)" -msgstr "" +msgstr "offline_failed_login_attempts (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1316 @@ -1617,7 +1619,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1326 msgid "offline_failed_login_delay (integer)" -msgstr "" +msgstr "offline_failed_login_delay (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1329 @@ -1637,12 +1639,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1340 sssd.conf.5.xml:1450 msgid "Default: 5" -msgstr "" +msgstr "ნაგულისხმევი: 5" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1346 msgid "pam_verbosity (integer)" -msgstr "" +msgstr "pam_verbosity (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1349 @@ -1679,12 +1681,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1371 sssd.8.xml:63 msgid "Default: 1" -msgstr "" +msgstr "ნაგულისხმევი: 1" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1377 msgid "pam_response_filter (string)" -msgstr "" +msgstr "pam_response_filter (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1380 @@ -1705,7 +1707,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1395 msgid "ENV" -msgstr "" +msgstr "ENV" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1396 @@ -1715,7 +1717,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1399 msgid "ENV:var_name" -msgstr "" +msgstr "ENV:var_name" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1400 @@ -1725,7 +1727,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1404 msgid "ENV:var_name:service" -msgstr "" +msgstr "ENV:var_name:service" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1405 @@ -1753,7 +1755,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1423 msgid "Default: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" -msgstr "" +msgstr "ნაგულისხმევი: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1426 @@ -1763,7 +1765,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1433 msgid "pam_id_timeout (integer)" -msgstr "" +msgstr "pam_id_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1436 @@ -1786,7 +1788,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1456 msgid "pam_pwd_expiration_warning (integer)" -msgstr "" +msgstr "pam_pwd_expiration_warning (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1459 sssd.conf.5.xml:2898 @@ -1820,12 +1822,12 @@ msgstr "" #: sssd.conf.5.xml:1478 sssd.conf.5.xml:3909 sssd-ldap.5.xml:657 #: sssd-ldap.5.xml:1727 sssd.8.xml:79 msgid "Default: 0" -msgstr "" +msgstr "ნაგულისხმევი: 0" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1495 msgid "pam_trusted_users (string)" -msgstr "" +msgstr "pam_trusted_users (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1498 @@ -1852,7 +1854,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1519 msgid "pam_public_domains (string)" -msgstr "" +msgstr "pam_public_domains (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1522 @@ -1883,12 +1885,12 @@ msgstr "" #: sssd.conf.5.xml:1819 sssd.conf.5.xml:2636 sssd.conf.5.xml:3838 #: sssd-ldap.5.xml:1264 msgid "Default: none" -msgstr "" +msgstr "ნაგულისხმევი: არცერთი" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1543 msgid "pam_account_expired_message (string)" -msgstr "" +msgstr "pam_account_expired_message (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1546 @@ -1915,7 +1917,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1568 msgid "pam_account_locked_message (string)" -msgstr "" +msgstr "pam_account_locked_message (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1571 @@ -1935,7 +1937,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1587 msgid "pam_passkey_auth (bool)" -msgstr "" +msgstr "pam_passkey_auth (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1590 @@ -1946,12 +1948,12 @@ msgstr "" #: sssd.conf.5.xml:1593 sssd.conf.5.xml:1905 sssd-ad.5.xml:1304 #: sss_rpcidmapd.5.xml:76 msgid "Default: True" -msgstr "" +msgstr "ნაგულისხმევი: ჭეშმარიტი" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1598 msgid "passkey_debug_libfido2 (bool)" -msgstr "" +msgstr "passkey_debug_libfido2 (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1601 @@ -1964,12 +1966,12 @@ msgstr "" #: sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1155 sssd-ad.5.xml:1207 #: include/ldap_id_mapping.xml:250 msgid "Default: False" -msgstr "" +msgstr "ნაგულისხმევი: ცრუ" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1609 msgid "pam_cert_auth (bool)" -msgstr "" +msgstr "pam_cert_auth (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1612 @@ -1982,7 +1984,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1623 msgid "pam_cert_db_path (string)" -msgstr "" +msgstr "pam_cert_db_path (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1626 @@ -1992,7 +1994,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1629 sssd.conf.5.xml:2130 sssd.conf.5.xml:4334 msgid "Default:" -msgstr "" +msgstr "ნაგულისხმევი:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1631 sssd.conf.5.xml:2132 @@ -2004,7 +2006,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1641 msgid "pam_cert_verification (string)" -msgstr "" +msgstr "pam_cert_verification (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1644 @@ -2034,7 +2036,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1666 msgid "p11_child_timeout (integer)" -msgstr "" +msgstr "p11_child_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1669 @@ -2044,7 +2046,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1678 msgid "passkey_child_timeout (integer)" -msgstr "" +msgstr "passkey_child_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1681 @@ -2054,7 +2056,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1690 msgid "pam_app_services (string)" -msgstr "" +msgstr "pam_app_services (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1693 @@ -2066,7 +2068,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1702 msgid "pam_p11_allowed_services (string)" -msgstr "" +msgstr "pam_p11_allowed_services (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1705 @@ -2104,52 +2106,52 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1729 sssd-ad.5.xml:649 msgid "login" -msgstr "" +msgstr "login" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1734 sssd-ad.5.xml:654 msgid "su" -msgstr "" +msgstr "su" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1739 sssd-ad.5.xml:659 msgid "su-l" -msgstr "" +msgstr "su-l" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1744 sssd-ad.5.xml:674 msgid "gdm-smartcard" -msgstr "" +msgstr "gdm-smartcard" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1749 sssd-ad.5.xml:669 msgid "gdm-password" -msgstr "" +msgstr "gdm-password" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1754 sssd-ad.5.xml:679 msgid "kdm" -msgstr "" +msgstr "kdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1759 sssd-ad.5.xml:957 msgid "sudo" -msgstr "" +msgstr "sudo" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1764 sssd-ad.5.xml:962 msgid "sudo-i" -msgstr "" +msgstr "sudo-i" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1769 msgid "gnome-screensaver" -msgstr "" +msgstr "gnome-screensaver" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1777 msgid "p11_wait_for_card_timeout (integer)" -msgstr "" +msgstr "p11_wait_for_card_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1780 @@ -2162,7 +2164,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1791 msgid "p11_uri (string)" -msgstr "" +msgstr "p11_uri (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1794 @@ -2204,12 +2206,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1824 msgid "pam_initgroups_scheme" -msgstr "" +msgstr "pam_initgroups_scheme" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1832 msgid "always" -msgstr "" +msgstr "ყოველთვის" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1833 @@ -2219,7 +2221,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1837 msgid "no_session" -msgstr "" +msgstr "no_session" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1838 @@ -2231,7 +2233,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1843 sssd-ldap.5.xml:189 msgid "never" -msgstr "" +msgstr "არასოდეს" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1844 @@ -2252,12 +2254,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1851 msgid "Default: no_session" -msgstr "" +msgstr "ნაგულისხმევი: no_session" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:1856 sssd.conf.5.xml:4273 msgid "pam_gssapi_services" -msgstr "" +msgstr "pam_gssapi_services" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1859 @@ -2288,11 +2290,13 @@ msgid "" "pam_gssapi_services = sudo, sudo-i\n" " " msgstr "" +"pam_gssapi_services = sudo, sudo-i\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1874 sssd.conf.5.xml:3832 msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" -msgstr "" +msgstr "მაგალითი: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1880 @@ -2302,7 +2306,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:1885 sssd.conf.5.xml:4274 msgid "pam_gssapi_check_upn" -msgstr "" +msgstr "pam_gssapi_check_upn" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1888 @@ -2322,7 +2326,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1910 msgid "pam_gssapi_indicators_map" -msgstr "" +msgstr "pam_gssapi_indicators_map" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1913 @@ -2400,6 +2404,8 @@ msgid "" "pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" " " msgstr "" +"pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1963 @@ -2417,7 +2423,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:1980 msgid "SUDO configuration options" -msgstr "" +msgstr "SUDO-ის კონფიგურაციის პარამეტრები" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:1982 @@ -2434,7 +2440,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1999 msgid "sudo_timed (bool)" -msgstr "" +msgstr "sudo_timed (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2002 @@ -2446,7 +2452,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2014 msgid "sudo_threshold (integer)" -msgstr "" +msgstr "sudo_threshold (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2017 @@ -2462,7 +2468,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:2036 msgid "AUTOFS configuration options" -msgstr "" +msgstr "AUTOFS-ის კონფიგურაციის პარამეტრები" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:2038 @@ -2472,7 +2478,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2042 msgid "autofs_negative_timeout (integer)" -msgstr "" +msgstr "autofs_negative_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2045 @@ -2485,7 +2491,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:2061 msgid "SSH configuration options" -msgstr "" +msgstr "SSH-ის კონფიგურაციის პარამეტრები" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:2063 @@ -2495,7 +2501,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2067 msgid "ssh_use_certificate_keys (bool)" -msgstr "" +msgstr "ssh_use_certificate_keys (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2070 @@ -2510,7 +2516,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2085 msgid "ssh_use_certificate_matching_rules (string)" -msgstr "" +msgstr "ssh_use_certificate_matching_rules (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2088 @@ -2556,7 +2562,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2122 msgid "ca_db (string)" -msgstr "" +msgstr "ca_db (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2125 @@ -2607,7 +2613,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2174 sssd-ifp.5.xml:66 msgid "allowed_uids (string)" -msgstr "" +msgstr "allowed_uids (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2177 @@ -2650,7 +2656,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2207 msgid "pac_lifetime (integer)" -msgstr "" +msgstr "pac_lifetime (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2210 @@ -2662,7 +2668,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2220 msgid "pac_check (string)" -msgstr "" +msgstr "pac_check (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2223 @@ -2678,7 +2684,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2237 msgid "no_check" -msgstr "" +msgstr "no_check" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2239 @@ -2690,7 +2696,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2245 msgid "pac_present" -msgstr "" +msgstr "pac_present" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2247 @@ -2703,7 +2709,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2255 msgid "check_upn" -msgstr "" +msgstr "check_upn" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2257 @@ -2715,7 +2721,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2263 msgid "check_upn_allow_missing" -msgstr "" +msgstr "check_upn_allow_missing" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2265 @@ -2743,7 +2749,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2291 msgid "upn_dns_info_present" -msgstr "" +msgstr "upn_dns_info_present" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2293 @@ -2753,7 +2759,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2298 msgid "check_upn_dns_info_ex" -msgstr "" +msgstr "check_upn_dns_info_ex" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2300 @@ -2765,7 +2771,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2307 msgid "upn_dns_info_ex_present" -msgstr "" +msgstr "upn_dns_info_ex_present" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2309 @@ -2812,12 +2818,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2347 sssd-session-recording.5.xml:64 msgid "scope (string)" -msgstr "" +msgstr "scope (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2354 sssd-session-recording.5.xml:71 msgid "\"none\"" -msgstr "" +msgstr "„none“" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2357 sssd-session-recording.5.xml:74 @@ -2827,7 +2833,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2362 sssd-session-recording.5.xml:79 msgid "\"some\"" -msgstr "" +msgstr "\"some\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2365 sssd-session-recording.5.xml:82 @@ -2839,7 +2845,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2374 sssd-session-recording.5.xml:91 msgid "\"all\"" -msgstr "" +msgstr "\"all\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2377 sssd-session-recording.5.xml:94 @@ -2856,12 +2862,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2384 sssd-session-recording.5.xml:101 msgid "Default: \"none\"" -msgstr "" +msgstr "ნაგულისხმევი: \"none\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2389 sssd-session-recording.5.xml:106 msgid "users (string)" -msgstr "" +msgstr "users (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2392 sssd-session-recording.5.xml:109 @@ -2879,7 +2885,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2403 sssd-session-recording.5.xml:120 msgid "groups (string)" -msgstr "" +msgstr "groups (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2406 sssd-session-recording.5.xml:123 @@ -2906,7 +2912,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2424 sssd-session-recording.5.xml:141 msgid "exclude_users (string)" -msgstr "" +msgstr "exclude_users (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2427 sssd-session-recording.5.xml:144 @@ -2923,7 +2929,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2436 sssd-session-recording.5.xml:153 msgid "exclude_groups (string)" -msgstr "" +msgstr "exclude_groups (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2439 sssd-session-recording.5.xml:156 @@ -2946,7 +2952,7 @@ msgstr "" #: sssd.conf.5.xml:2468 sssd.conf.5.xml:3960 sssd.conf.5.xml:3961 #: sssd.conf.5.xml:3964 msgid "enabled" -msgstr "" +msgstr "enabled" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2471 @@ -2961,7 +2967,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2483 msgid "domain_type (string)" -msgstr "" +msgstr "domain_type (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2486 @@ -3005,12 +3011,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2514 msgid "Default: posix" -msgstr "" +msgstr "ნაგულისხმევი: posix" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2520 msgid "min_id,max_id (integer)" -msgstr "" +msgstr "min_id,max_id (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2523 @@ -3043,7 +3049,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2545 msgid "enumerate (bool)" -msgstr "" +msgstr "enumerate (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2548 @@ -3067,7 +3073,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2562 sssd.conf.5.xml:2853 sssd.conf.5.xml:3030 msgid "Default: FALSE" -msgstr "" +msgstr "ნაგულისხმევი: ცრუ" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2565 @@ -3131,12 +3137,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2616 msgid "subdomain_enumerate (string)" -msgstr "" +msgstr "subdomain_enumerate (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2623 msgid "all" -msgstr "" +msgstr "ყველა" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2624 @@ -3146,7 +3152,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2627 msgid "none" -msgstr "" +msgstr "არცერთი" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2628 @@ -3165,7 +3171,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2642 msgid "entry_cache_timeout (integer)" -msgstr "" +msgstr "entry_cache_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2645 @@ -3188,12 +3194,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2662 msgid "Default: 5400" -msgstr "" +msgstr "ნაგულისხმევი: 5400" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2668 msgid "entry_cache_user_timeout (integer)" -msgstr "" +msgstr "entry_cache_user_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2671 @@ -3207,12 +3213,12 @@ msgstr "" #: sssd.conf.5.xml:2714 sssd.conf.5.xml:2728 sssd.conf.5.xml:2741 #: sssd.conf.5.xml:2755 sssd.conf.5.xml:2769 sssd.conf.5.xml:2782 msgid "Default: entry_cache_timeout" -msgstr "" +msgstr "ნაგულისხმევი: entry_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2681 msgid "entry_cache_group_timeout (integer)" -msgstr "" +msgstr "entry_cache_group_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2684 @@ -3224,7 +3230,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2694 msgid "entry_cache_netgroup_timeout (integer)" -msgstr "" +msgstr "entry_cache_netgroup_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2697 @@ -3236,7 +3242,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2707 msgid "entry_cache_service_timeout (integer)" -msgstr "" +msgstr "entry_cache_service_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2710 @@ -3248,7 +3254,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2720 msgid "entry_cache_resolver_timeout (integer)" -msgstr "" +msgstr "entry_cache_resolver_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2723 @@ -3260,7 +3266,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2734 msgid "entry_cache_sudo_timeout (integer)" -msgstr "" +msgstr "entry_cache_sudo_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2737 @@ -3272,7 +3278,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2747 msgid "entry_cache_autofs_timeout (integer)" -msgstr "" +msgstr "entry_cache_autofs_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2750 @@ -3284,7 +3290,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2761 msgid "entry_cache_ssh_host_timeout (integer)" -msgstr "" +msgstr "entry_cache_ssh_host_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2764 @@ -3296,7 +3302,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2775 msgid "entry_cache_computer_timeout (integer)" -msgstr "" +msgstr "entry_cache_computer_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2778 @@ -3308,7 +3314,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2788 msgid "refresh_expired_interval (integer)" -msgstr "" +msgstr "refresh_expired_interval (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2791 @@ -3352,12 +3358,12 @@ msgstr "" #: sssd.conf.5.xml:2825 sssd-ldap.5.xml:411 sssd-ldap.5.xml:1828 #: sssd-ipa.5.xml:271 msgid "Default: 0 (disabled)" -msgstr "" +msgstr "ნაგულისხმევი: 0 (გათიშულია)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2831 msgid "cache_credentials (bool)" -msgstr "" +msgstr "cache_credentials (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2834 @@ -3382,7 +3388,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2859 msgid "cache_credentials_minimal_first_factor_length (int)" -msgstr "" +msgstr "cache_credentials_minimal_first_factor_length (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2862 @@ -3402,7 +3408,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2880 msgid "account_cache_expiration (integer)" -msgstr "" +msgstr "account_cache_expiration (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2883 @@ -3416,12 +3422,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2890 msgid "Default: 0 (unlimited)" -msgstr "" +msgstr "ნაგულისხმევი: 0 (შეუზღუდავი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2895 msgid "pwd_expiration_warning (integer)" -msgstr "" +msgstr "pwd_expiration_warning (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2906 @@ -3435,12 +3441,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2913 msgid "Default: 7 (Kerberos), 0 (LDAP)" -msgstr "" +msgstr "ნაგულისხმევი: 7 (Kerberos), 0 (LDAP)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2919 msgid "id_provider (string)" -msgstr "" +msgstr "id_provider (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2922 @@ -3492,7 +3498,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2965 msgid "use_fully_qualified_names (bool)" -msgstr "" +msgstr "use_fully_qualified_names (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2968 @@ -3528,7 +3534,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2995 msgid "ignore_group_members (bool)" -msgstr "" +msgstr "ignore_group_members (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2998 @@ -3569,7 +3575,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3035 msgid "auth_provider (string)" -msgstr "" +msgstr "auth_provider (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3038 @@ -3622,7 +3628,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3093 msgid "access_provider (string)" -msgstr "" +msgstr "access_provider (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3096 @@ -3668,12 +3674,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3149 msgid "Default: <quote>permit</quote>" -msgstr "" +msgstr "ნაგულისხმევი: <quote>permit</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3154 msgid "chpass_provider (string)" -msgstr "" +msgstr "chpass_provider (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3157 @@ -3719,7 +3725,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3209 msgid "sudo_provider (string)" -msgstr "" +msgstr "sudo_provider (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3212 @@ -3783,7 +3789,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3264 msgid "selinux_provider (string)" -msgstr "" +msgstr "selinux_provider (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3267 @@ -3817,7 +3823,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3290 msgid "subdomains_provider (string)" -msgstr "" +msgstr "subdomains_provider (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3293 @@ -3859,7 +3865,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3327 msgid "session_provider (string)" -msgstr "" +msgstr "session_provider (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3330 @@ -3889,7 +3895,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3352 msgid "autofs_provider (string)" -msgstr "" +msgstr "autofs_provider (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3355 @@ -3935,7 +3941,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3393 msgid "hostid_provider (string)" -msgstr "" +msgstr "hostid_provider (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3396 @@ -3968,7 +3974,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3418 msgid "resolver_provider (string)" -msgstr "" +msgstr "resolver_provider (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3421 @@ -4035,12 +4041,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:3471 sssd.conf.5.xml:3485 msgid "username" -msgstr "" +msgstr "მომხმარებლის სახელი" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:3474 sssd.conf.5.xml:3488 msgid "username@domain.name" -msgstr "" +msgstr "username@domain.name" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3479 @@ -4053,7 +4059,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:3491 msgid "domain\\username" -msgstr "" +msgstr "domain\\username" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3494 @@ -4080,7 +4086,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3557 msgid "lookup_family_order (string)" -msgstr "" +msgstr "lookup_family_order (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3560 @@ -4092,7 +4098,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3564 msgid "Supported values:" -msgstr "" +msgstr "მხარდაჭერილი მნიშვნელობები:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3567 @@ -4117,12 +4123,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3579 msgid "Default: ipv4_first" -msgstr "" +msgstr "ნაგულისხმევი: ipv4_first" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3585 msgid "dns_resolver_server_timeout (integer)" -msgstr "" +msgstr "dns_resolver_server_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3588 @@ -4146,12 +4152,12 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3602 sssd-ldap.5.xml:695 include/failover.xml:84 msgid "Default: 1000" -msgstr "" +msgstr "ნაგულისხმევი: 1000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3608 msgid "dns_resolver_op_timeout (integer)" -msgstr "" +msgstr "dns_resolver_op_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3611 @@ -4164,12 +4170,12 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3622 include/failover.xml:100 msgid "Default: 3" -msgstr "" +msgstr "ნაგულისხმევი: 3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3628 msgid "dns_resolver_timeout (integer)" -msgstr "" +msgstr "dns_resolver_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3631 @@ -4183,7 +4189,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3649 msgid "dns_resolver_use_search_list (bool)" -msgstr "" +msgstr "dns_resolver_use_search_list (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3652 @@ -4204,12 +4210,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3664 msgid "Default: TRUE" -msgstr "" +msgstr "ნაგულისხმევი: ჭეშმარიტი" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3670 msgid "dns_discovery_domain (string)" -msgstr "" +msgstr "dns_discovery_domain (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3673 @@ -4226,7 +4232,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3683 msgid "failover_primary_timeout (integer)" -msgstr "" +msgstr "failover_primary_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3686 @@ -4244,12 +4250,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3696 msgid "Default: 31" -msgstr "" +msgstr "ნაგულისხმევი: 31" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3702 msgid "override_gid (integer)" -msgstr "" +msgstr "override_gid (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3705 @@ -4259,12 +4265,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3711 msgid "case_sensitive (string)" -msgstr "" +msgstr "case_sensitive (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3718 msgid "True" -msgstr "" +msgstr "ჭეშმარიტი" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3721 @@ -4274,7 +4280,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3727 msgid "False" -msgstr "" +msgstr "მცდარი" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3729 @@ -4284,7 +4290,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3733 msgid "Preserving" -msgstr "" +msgstr "შენარჩუნება" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3736 @@ -4316,7 +4322,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3765 msgid "subdomain_inherit (string)" -msgstr "" +msgstr "subdomain_inherit (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3768 @@ -4329,42 +4335,42 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3774 msgid "ldap_search_timeout" -msgstr "" +msgstr "ldap_search_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3777 msgid "ldap_network_timeout" -msgstr "" +msgstr "ldap_network_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3780 msgid "ldap_opt_timeout" -msgstr "" +msgstr "ldap_opt_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3783 msgid "ldap_offline_timeout" -msgstr "" +msgstr "ldap_offline_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3786 msgid "ldap_enumeration_refresh_timeout" -msgstr "" +msgstr "ldap_enumeration_refresh_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3789 msgid "ldap_enumeration_refresh_offset" -msgstr "" +msgstr "ldap_enumeration_refresh_offset" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3792 msgid "ldap_purge_cache_timeout" -msgstr "" +msgstr "ldap_purge_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3795 msgid "ldap_purge_cache_offset" -msgstr "" +msgstr "ldap_purge_cache_offset" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3798 @@ -4376,52 +4382,52 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3802 msgid "ldap_krb5_ticket_lifetime" -msgstr "" +msgstr "ldap_krb5_ticket_lifetime" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3805 msgid "ldap_enumeration_search_timeout" -msgstr "" +msgstr "ldap_enumeration_search_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3808 msgid "ldap_connection_expire_timeout" -msgstr "" +msgstr "ldap_connection_expire_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3811 msgid "ldap_connection_expire_offset" -msgstr "" +msgstr "ldap_connection_expire_offset" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3814 msgid "ldap_connection_idle_timeout" -msgstr "" +msgstr "ldap_connection_idle_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3817 sssd-ldap.5.xml:451 msgid "ldap_use_tokengroups" -msgstr "" +msgstr "ldap_use_tokengroups" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3820 msgid "ldap_user_principal" -msgstr "" +msgstr "ldap_user_principal" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3823 msgid "ignore_group_members" -msgstr "" +msgstr "ignore_group_members" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3826 msgid "auto_private_groups" -msgstr "" +msgstr "auto_private_groups" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3829 msgid "case_sensitive" -msgstr "" +msgstr "case_sensitive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:3834 @@ -4439,12 +4445,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3848 msgid "subdomain_homedir (string)" -msgstr "" +msgstr "subdomain_homedir (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3859 msgid "%F" -msgstr "" +msgstr "%F" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3860 @@ -4474,7 +4480,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3874 msgid "realmd_tags (string)" -msgstr "" +msgstr "realmd_tags (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3877 @@ -4484,7 +4490,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3883 msgid "cached_auth_timeout (int)" -msgstr "" +msgstr "cached_auth_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3886 @@ -4518,7 +4524,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3914 msgid "local_auth_policy (string)" -msgstr "" +msgstr "local_auth_policy (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3917 @@ -4560,32 +4566,32 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd.conf.5.xml:3956 msgid "Passkey" -msgstr "" +msgstr "საკვანძო გასაღები" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd.conf.5.xml:3957 msgid "Smartcard" -msgstr "" +msgstr "Smart ბარათი" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:3960 sssd-ldap.5.xml:228 msgid "IPA" -msgstr "" +msgstr "IPA" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:3963 sssd-ldap.5.xml:233 msgid "AD" -msgstr "" +msgstr "AD" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> #: sssd.conf.5.xml:3963 sssd.conf.5.xml:3966 sssd.conf.5.xml:3967 msgid "disabled" -msgstr "" +msgstr "გამორთულია" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> #: sssd.conf.5.xml:3966 msgid "LDAP" -msgstr "" +msgstr "LDAP" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3971 @@ -4618,17 +4624,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3991 msgid "Default: match" -msgstr "" +msgstr "ნაგულისხმევი: დამთხვევა" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3996 msgid "auto_private_groups (string)" -msgstr "" +msgstr "auto_private_groups (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4002 msgid "true" -msgstr "" +msgstr "ჭეშმარიტი" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4005 @@ -4649,7 +4655,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4018 msgid "false" -msgstr "" +msgstr "მცდარი" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4021 @@ -4661,7 +4667,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4027 msgid "hybrid" -msgstr "" +msgstr "ჰიბრიდი" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4030 @@ -4750,7 +4756,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4100 msgid "proxy_pam_target (string)" -msgstr "" +msgstr "proxy_pam_target (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4103 @@ -4768,7 +4774,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4116 msgid "proxy_lib_name (string)" -msgstr "" +msgstr "proxy_lib_name (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4119 @@ -4781,7 +4787,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4129 msgid "proxy_resolver_lib_name (string)" -msgstr "" +msgstr "proxy_resolver_lib_name (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4132 @@ -4794,7 +4800,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4143 msgid "proxy_fast_alias (boolean)" -msgstr "" +msgstr "proxy_fast_alias (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4146 @@ -4808,7 +4814,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4160 msgid "proxy_max_children (integer)" -msgstr "" +msgstr "proxy_max_children (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4163 @@ -4828,7 +4834,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:4179 msgid "Application domains" -msgstr "" +msgstr "აპლიკაციის დომენები" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:4181 @@ -4864,7 +4870,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:4209 msgid "inherit_from (string)" -msgstr "" +msgstr "inherit_from (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4212 @@ -4924,52 +4930,52 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4263 msgid "ldap_search_base," -msgstr "" +msgstr "ldap_search_base," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4264 msgid "ldap_user_search_base," -msgstr "" +msgstr "ldap_user_search_base," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4265 msgid "ldap_group_search_base," -msgstr "" +msgstr "ldap_group_search_base," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4266 msgid "ldap_netgroup_search_base," -msgstr "" +msgstr "ldap_netgroup_search_base," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4267 msgid "ldap_service_search_base," -msgstr "" +msgstr "ldap_service_search_base," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4268 msgid "ldap_sasl_mech," -msgstr "" +msgstr "ldap_sasl_mech," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4269 msgid "ad_server," -msgstr "" +msgstr "ad_server," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4270 msgid "ad_backup_server," -msgstr "" +msgstr "ad_backup_server," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4271 msgid "ad_site," -msgstr "" +msgstr "ad_site," #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:4272 sssd-ipa.5.xml:955 msgid "use_fully_qualified_names" -msgstr "" +msgstr "use_fully_qualified_names" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4276 @@ -5017,7 +5023,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:4314 msgid "matchrule (string)" -msgstr "" +msgstr "matchrule (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4317 @@ -5036,7 +5042,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:4328 msgid "maprule (string)" -msgstr "" +msgstr "maprule (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4331 @@ -5060,7 +5066,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:4353 msgid "domains (string)" -msgstr "" +msgstr "domains (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4356 @@ -5079,7 +5085,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:4368 msgid "priority (integer)" -msgstr "" +msgstr "priority (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4371 @@ -5121,12 +5127,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4407 msgid "[prompting/password]" -msgstr "" +msgstr "[prompting/password]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4410 msgid "password_prompt" -msgstr "" +msgstr "password_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4411 @@ -5143,12 +5149,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4419 msgid "[prompting/2fa]" -msgstr "" +msgstr "[prompting/2fa]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4423 msgid "first_prompt" -msgstr "" +msgstr "first_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4424 @@ -5158,7 +5164,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4427 msgid "second_prompt" -msgstr "" +msgstr "second_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4428 @@ -5168,7 +5174,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4431 msgid "single_prompt" -msgstr "" +msgstr "single_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4432 @@ -5202,12 +5208,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4460 msgid "[prompting/passkey]" -msgstr "" +msgstr "[prompting/passkey]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:4466 sssd-ad.5.xml:1022 msgid "interactive" -msgstr "" +msgstr "ინტერაქტიური" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4468 @@ -5220,7 +5226,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4476 msgid "interactive_prompt" -msgstr "" +msgstr "interactive_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4478 @@ -5230,7 +5236,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4483 msgid "touch" -msgstr "" +msgstr "touch" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4485 @@ -5242,7 +5248,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4491 msgid "touch_prompt" -msgstr "" +msgstr "touch_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4493 @@ -5276,7 +5282,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:4511 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 msgid "EXAMPLES" -msgstr "" +msgstr "მაგალითები" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd.conf.5.xml:4517 @@ -5359,7 +5365,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-ldap.5.xml:10 sssd-ldap.5.xml:16 msgid "sssd-ldap" -msgstr "" +msgstr "sssd-ldap" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-ldap.5.xml:17 @@ -5377,7 +5383,7 @@ msgstr "" #: sssd-session-recording.5.xml:21 sssd-kcm.8.xml:21 sssd-systemtap.5.xml:21 #: sssd-ldap-attributes.5.xml:21 sssd_krb5_localauth_plugin.8.xml:20 msgid "DESCRIPTION" -msgstr "" +msgstr "აღწერა" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:23 @@ -5417,7 +5423,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:67 msgid "ldap_uri, ldap_backup_uri (string)" -msgstr "" +msgstr "ldap_uri, ldap_backup_uri (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:70 @@ -5438,7 +5444,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:80 msgid "ldap[s]://<host>[:port]" -msgstr "" +msgstr "ldap[s]://<host>[:port]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:83 @@ -5448,12 +5454,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:86 msgid "example: ldap://[fc00::126:25]:389" -msgstr "" +msgstr "მაგალითი: ldap://[fc00::126:25]:389" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:92 msgid "ldap_chpass_uri, ldap_chpass_backup_uri (string)" -msgstr "" +msgstr "ldap_chpass_uri, ldap_chpass_backup_uri (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:95 @@ -5477,7 +5483,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:112 msgid "ldap_search_base (string)" -msgstr "" +msgstr "ldap_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:115 @@ -5494,7 +5500,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:123 msgid "search_base[?scope?[filter][?search_base?scope?[filter]]*]" -msgstr "" +msgstr "search_base[?scope?[filter][?search_base?scope?[filter]]*]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:126 @@ -5512,7 +5518,7 @@ msgstr "" #: sssd-ldap.5.xml:133 sssd-ad.5.xml:312 sss_override.8.xml:143 #: sss_override.8.xml:240 sssd-ldap-attributes.5.xml:453 msgid "Examples:" -msgstr "" +msgstr "მაგალითები:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:136 @@ -5551,7 +5557,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:165 msgid "ldap_read_rootdse (string)" -msgstr "" +msgstr "ldap_read_rootdse (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:168 @@ -5565,17 +5571,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:175 msgid "Allowed values are:" -msgstr "" +msgstr "დაშვებული მნიშვნელობებია:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ldap.5.xml:179 msgid "anonymous" -msgstr "" +msgstr "anonymous" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ldap.5.xml:184 msgid "authenticated" -msgstr "" +msgstr "authenticated" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:193 @@ -5587,12 +5593,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:198 msgid "Default: anonymous" -msgstr "" +msgstr "ნაგულისხმევი: anonymous" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:204 msgid "ldap_schema (string)" -msgstr "" +msgstr "ldap_schema (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:207 @@ -5610,12 +5616,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ldap.5.xml:218 msgid "rfc2307" -msgstr "" +msgstr "rfc2307" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ldap.5.xml:223 msgid "rfc2307bis" -msgstr "" +msgstr "rfc2307bis" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:239 @@ -5631,12 +5637,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:249 msgid "Default: rfc2307" -msgstr "" +msgstr "ნაგულისხმევი: rfc2307" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:255 msgid "ldap_pwmodify_mode (string)" -msgstr "" +msgstr "ldap_pwmodify_mode (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:258 @@ -5646,7 +5652,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:262 msgid "Two modes are currently supported:" -msgstr "" +msgstr "ამჟამად მხარდაჭერილია ორი რეჟიმი:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ldap.5.xml:266 @@ -5679,12 +5685,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:298 msgid "Default: exop" -msgstr "" +msgstr "ნაგულისხმევი: exop" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:304 msgid "ldap_default_bind_dn (string)" -msgstr "" +msgstr "ldap_default_bind_dn (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:307 @@ -5694,7 +5700,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:314 msgid "ldap_default_authtok_type (string)" -msgstr "" +msgstr "ldap_default_authtok_type (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:317 @@ -5709,17 +5715,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:324 msgid "password" -msgstr "" +msgstr "password" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:327 msgid "obfuscated_password" -msgstr "" +msgstr "obfuscated_password" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:330 msgid "Default: password" -msgstr "" +msgstr "ნაგულისხმევი: password" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:333 @@ -5731,7 +5737,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:344 msgid "ldap_default_authtok (string)" -msgstr "" +msgstr "ldap_default_authtok (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:347 @@ -5741,7 +5747,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:353 msgid "ldap_force_upper_case_realm (boolean)" -msgstr "" +msgstr "ldap_force_upper_case_realm (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:356 @@ -5755,7 +5761,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:369 msgid "ldap_enumeration_refresh_timeout (integer)" -msgstr "" +msgstr "ldap_enumeration_refresh_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:372 @@ -5767,7 +5773,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:388 msgid "ldap_purge_cache_timeout (integer)" -msgstr "" +msgstr "ldap_purge_cache_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:391 @@ -5789,7 +5795,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:417 msgid "ldap_group_nesting_level (integer)" -msgstr "" +msgstr "ldap_group_nesting_level (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:420 @@ -5822,7 +5828,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:445 msgid "Default: 2" -msgstr "" +msgstr "ნაგულისხმევი: 2" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:454 @@ -5839,7 +5845,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:470 msgid "ldap_host_search_base (string)" -msgstr "" +msgstr "ldap_host_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:473 @@ -5862,22 +5868,22 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:489 msgid "ldap_service_search_base (string)" -msgstr "" +msgstr "ldap_service_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:494 msgid "ldap_iphost_search_base (string)" -msgstr "" +msgstr "ldap_iphost_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:499 msgid "ldap_ipnetwork_search_base (string)" -msgstr "" +msgstr "ldap_ipnetwork_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:504 msgid "ldap_search_timeout (integer)" -msgstr "" +msgstr "ldap_search_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:507 @@ -5898,7 +5904,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:530 msgid "ldap_enumeration_search_timeout (integer)" -msgstr "" +msgstr "ldap_enumeration_search_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:533 @@ -5911,7 +5917,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:551 msgid "ldap_network_timeout (integer)" -msgstr "" +msgstr "ldap_network_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:554 @@ -5927,7 +5933,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:582 msgid "ldap_opt_timeout (integer)" -msgstr "" +msgstr "ldap_opt_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:585 @@ -5941,7 +5947,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:605 msgid "ldap_connection_expire_timeout (integer)" -msgstr "" +msgstr "ldap_connection_expire_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:608 @@ -5973,12 +5979,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:638 sssd-ldap.5.xml:681 sssd-ldap.5.xml:1803 msgid "Default: 900 (15 minutes)" -msgstr "" +msgstr "ნაგულისხმევი: 900 (15 წთ)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:644 msgid "ldap_connection_expire_offset (integer)" -msgstr "" +msgstr "ldap_connection_expire_offset (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:647 @@ -5990,7 +5996,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:663 msgid "ldap_connection_idle_timeout (integer)" -msgstr "" +msgstr "ldap_connection_idle_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:666 @@ -6008,7 +6014,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:687 msgid "ldap_page_size (integer)" -msgstr "" +msgstr "ldap_page_size (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:690 @@ -6020,7 +6026,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:701 msgid "ldap_disable_paging (boolean)" -msgstr "" +msgstr "ldap_disable_paging (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:704 @@ -6049,7 +6055,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:728 msgid "ldap_disable_range_retrieval (boolean)" -msgstr "" +msgstr "ldap_disable_range_retrieval (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:731 @@ -6072,7 +6078,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:753 msgid "ldap_sasl_minssf (integer)" -msgstr "" +msgstr "ldap_sasl_minssf (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:756 @@ -6090,7 +6096,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:769 msgid "ldap_sasl_maxssf (integer)" -msgstr "" +msgstr "ldap_sasl_maxssf (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:772 @@ -6103,7 +6109,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:785 msgid "ldap_deref_threshold (integer)" -msgstr "" +msgstr "ldap_deref_threshold (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:788 @@ -6144,7 +6150,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:826 msgid "ldap_ignore_unreadable_references (bool)" -msgstr "" +msgstr "ldap_ignore_unreadable_references (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:829 @@ -6165,7 +6171,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:849 msgid "ldap_tls_reqcert (string)" -msgstr "" +msgstr "ldap_tls_reqcert (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:852 @@ -6213,12 +6219,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:885 msgid "Default: hard" -msgstr "" +msgstr "ნაგულისხმევი: hard" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:891 msgid "ldap_tls_cacert (string)" -msgstr "" +msgstr "ldap_tls_cacert (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:894 @@ -6237,7 +6243,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:906 msgid "ldap_tls_cacertdir (string)" -msgstr "" +msgstr "ldap_tls_cacertdir (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:909 @@ -6252,7 +6258,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:925 msgid "ldap_tls_cert (string)" -msgstr "" +msgstr "ldap_tls_cert (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:928 @@ -6262,7 +6268,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:938 msgid "ldap_tls_key (string)" -msgstr "" +msgstr "ldap_tls_key (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:941 @@ -6272,7 +6278,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:950 msgid "ldap_tls_cipher_suite (string)" -msgstr "" +msgstr "ldap_tls_cipher_suite (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:953 @@ -6285,7 +6291,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:966 msgid "ldap_id_use_start_tls (boolean)" -msgstr "" +msgstr "ldap_id_use_start_tls (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:969 @@ -6298,7 +6304,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:980 msgid "ldap_id_mapping (boolean)" -msgstr "" +msgstr "ldap_id_mapping (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:983 @@ -6316,7 +6322,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:999 msgid "ldap_min_id, ldap_max_id (integer)" -msgstr "" +msgstr "ldap_min_id, ldap_max_id (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1002 @@ -6337,7 +6343,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1020 msgid "ldap_sasl_mech (string)" -msgstr "" +msgstr "ldap_sasl_mech (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1023 @@ -6360,7 +6366,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1043 msgid "ldap_sasl_authid (string)" -msgstr "" +msgstr "ldap_sasl_authid (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd-ldap.5.xml:1055 @@ -6395,7 +6401,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1072 msgid "ldap_sasl_realm (string)" -msgstr "" +msgstr "ldap_sasl_realm (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1075 @@ -6413,7 +6419,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1087 msgid "ldap_sasl_canonicalize (boolean)" -msgstr "" +msgstr "ldap_sasl_canonicalize (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1090 @@ -6425,12 +6431,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1095 msgid "Default: false;" -msgstr "" +msgstr "ნაგულისხმევი: ცრუ;" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1101 msgid "ldap_krb5_keytab (string)" -msgstr "" +msgstr "ldap_krb5_keytab (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1104 @@ -6445,7 +6451,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1119 msgid "ldap_krb5_init_creds (boolean)" -msgstr "" +msgstr "ldap_krb5_init_creds (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1122 @@ -6458,7 +6464,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1134 msgid "ldap_krb5_ticket_lifetime (integer)" -msgstr "" +msgstr "ldap_krb5_ticket_lifetime (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1137 @@ -6470,12 +6476,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1146 sssd-ad.5.xml:1285 msgid "Default: 86400 (24 hours)" -msgstr "" +msgstr "ნაგულისხმევი: 86400 (24 სთ)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1152 sssd-krb5.5.xml:74 msgid "krb5_server, krb5_backup_server (string)" -msgstr "" +msgstr "krb5_server, krb5_backup_server (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1155 @@ -6509,7 +6515,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1181 sssd-ipa.5.xml:596 sssd-krb5.5.xml:103 msgid "krb5_realm (string)" -msgstr "" +msgstr "krb5_realm (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1184 @@ -6524,7 +6530,7 @@ msgstr "" #. type: Content of: <variablelist><varlistentry><term> #: sssd-ldap.5.xml:1194 include/krb5_options.xml:154 msgid "krb5_canonicalize (boolean)" -msgstr "" +msgstr "krb5_canonicalize (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1197 @@ -6536,7 +6542,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1209 sssd-krb5.5.xml:336 msgid "krb5_use_kdcinfo (boolean)" -msgstr "" +msgstr "krb5_use_kdcinfo (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1212 sssd-krb5.5.xml:339 @@ -6560,7 +6566,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1237 msgid "ldap_pwd_policy (string)" -msgstr "" +msgstr "ldap_pwd_policy (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1240 @@ -6604,7 +6610,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1275 msgid "ldap_referrals (boolean)" -msgstr "" +msgstr "ldap_referrals (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1278 @@ -6634,7 +6640,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1306 msgid "ldap_dns_service_name (string)" -msgstr "" +msgstr "ldap_dns_service_name (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1309 @@ -6644,12 +6650,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1313 msgid "Default: ldap" -msgstr "" +msgstr "ნაგულისხმევი: ldap" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1319 msgid "ldap_chpass_dns_service_name (string)" -msgstr "" +msgstr "ldap_chpass_dns_service_name (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1322 @@ -6666,7 +6672,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1333 msgid "ldap_chpass_update_last_change (bool)" -msgstr "" +msgstr "ldap_chpass_update_last_change (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1336 @@ -6687,7 +6693,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1356 msgid "ldap_access_filter (string)" -msgstr "" +msgstr "ldap_access_filter (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1359 @@ -6709,7 +6715,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1379 msgid "Example:" -msgstr "" +msgstr "მაგალითი:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><programlisting> #: sssd-ldap.5.xml:1382 @@ -6739,12 +6745,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1399 sssd-ldap.5.xml:1455 msgid "Default: Empty" -msgstr "" +msgstr "ნაგულისხმევი: ცარიელი" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1405 msgid "ldap_account_expire_policy (string)" -msgstr "" +msgstr "ldap_account_expire_policy (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1408 @@ -6810,7 +6816,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1461 msgid "ldap_access_order (string)" -msgstr "" +msgstr "ldap_access_order (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1464 sssd-ipa.5.xml:421 @@ -6930,7 +6936,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1568 msgid "Default: filter" -msgstr "" +msgstr "ნაგულისხმევი: filter" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1571 @@ -6942,7 +6948,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1578 msgid "ldap_pwdlockout_dn (string)" -msgstr "" +msgstr "ldap_pwdlockout_dn (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1581 @@ -6961,12 +6967,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1592 msgid "Default: cn=ppolicy,ou=policies,$ldap_search_base" -msgstr "" +msgstr "ნაგულისხმევი: cn=ppolicy,ou=policies,$ldap_search_base" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1598 msgid "ldap_deref (string)" -msgstr "" +msgstr "ldap_deref (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1601 @@ -7011,7 +7017,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1633 msgid "ldap_rfc2307_fallback_to_local_users (boolean)" -msgstr "" +msgstr "ldap_rfc2307_fallback_to_local_users (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1636 @@ -7042,7 +7048,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1663 sssd-ifp.5.xml:152 msgid "wildcard_limit (integer)" -msgstr "" +msgstr "wildcard_limit (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1666 @@ -7064,7 +7070,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1680 msgid "ldap_library_debug_level (integer)" -msgstr "" +msgstr "ldap_library_debug_level (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1683 @@ -7088,7 +7094,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1699 msgid "ldap_use_ppolicy (boolean)" -msgstr "" +msgstr "ldap_use_ppolicy (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1702 @@ -7101,7 +7107,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1714 msgid "ldap_ppolicy_pwd_change_threshold (integer)" -msgstr "" +msgstr "ldap_ppolicy_pwd_change_threshold (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1717 @@ -7129,7 +7135,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:1737 msgid "SUDO OPTIONS" -msgstr "" +msgstr "SUDO-ის პარამეტრები" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:1739 @@ -7142,7 +7148,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1750 msgid "ldap_sudo_full_refresh_interval (integer)" -msgstr "" +msgstr "ldap_sudo_full_refresh_interval (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1753 @@ -7168,12 +7174,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1768 msgid "Default: 21600 (6 hours)" -msgstr "" +msgstr "ნაგულისხმევი: 21600 (6 სთ)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1774 msgid "ldap_sudo_smart_refresh_interval (integer)" -msgstr "" +msgstr "ldap_sudo_smart_refresh_interval (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1777 @@ -7210,7 +7216,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1809 msgid "ldap_sudo_random_offset (integer)" -msgstr "" +msgstr "ldap_sudo_random_offset (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1812 @@ -7236,7 +7242,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1834 msgid "ldap_sudo_use_host_filter (boolean)" -msgstr "" +msgstr "ldap_sudo_use_host_filter (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1837 @@ -7248,7 +7254,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1848 msgid "ldap_sudo_hostnames (string)" -msgstr "" +msgstr "ldap_sudo_hostnames (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1851 @@ -7275,12 +7281,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1866 sssd-ldap.5.xml:1889 msgid "Default: not specified" -msgstr "" +msgstr "ნაგულისხმევი: მითითებული არაა" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1872 msgid "ldap_sudo_ip (string)" -msgstr "" +msgstr "ldap_sudo_ip (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1875 @@ -7299,7 +7305,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1895 msgid "ldap_sudo_include_netgroups (boolean)" -msgstr "" +msgstr "ldap_sudo_include_netgroups (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1898 @@ -7311,7 +7317,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1913 msgid "ldap_sudo_include_regexp (boolean)" -msgstr "" +msgstr "ldap_sudo_include_regexp (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1916 @@ -7339,7 +7345,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:1948 msgid "AUTOFS OPTIONS" -msgstr "" +msgstr "AUTOFS-ის კონფიგურაცია" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:1950 @@ -7351,7 +7357,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1956 msgid "ldap_autofs_map_master_name (string)" -msgstr "" +msgstr "ldap_autofs_map_master_name (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1959 @@ -7361,32 +7367,32 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1962 msgid "Default: auto.master" -msgstr "" +msgstr "ნაგულისხმევი: auto.master" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:1973 msgid "ADVANCED OPTIONS" -msgstr "" +msgstr "დამატებითი პარამეტრები" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1980 msgid "ldap_netgroup_search_base (string)" -msgstr "" +msgstr "ldap_netgroup_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1985 msgid "ldap_user_search_base (string)" -msgstr "" +msgstr "ldap_user_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1990 msgid "ldap_group_search_base (string)" -msgstr "" +msgstr "ldap_group_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><note> #: sssd-ldap.5.xml:1995 msgid "<note>" -msgstr "" +msgstr "<note>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><note><para> #: sssd-ldap.5.xml:1997 @@ -7400,17 +7406,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist> #: sssd-ldap.5.xml:2004 msgid "</note>" -msgstr "" +msgstr "</note>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:2006 msgid "ldap_sudo_search_base (string)" -msgstr "" +msgstr "ldap_sudo_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:2011 msgid "ldap_autofs_search_base (string)" -msgstr "" +msgstr "ldap_autofs_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:1975 @@ -7426,7 +7432,7 @@ msgstr "" #: sssd-ad.5.xml:1488 sssd-idp.5.xml:248 sssd-krb5.5.xml:483 #: sss_rpcidmapd.5.xml:98 sssd-session-recording.5.xml:176 msgid "EXAMPLE" -msgstr "" +msgstr "მაგალითი" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:2028 @@ -7489,7 +7495,7 @@ msgstr "" #: sssd-ldap.5.xml:2067 sssd_krb5_locator_plugin.8.xml:83 sssd-simple.5.xml:189 #: sssd-ad.5.xml:1511 sssd.8.xml:270 sss_seed.8.xml:163 msgid "NOTES" -msgstr "" +msgstr "შენიშვნები" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:2069 @@ -7503,7 +7509,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: pam_sss.8.xml:11 pam_sss.8.xml:16 msgid "pam_sss" -msgstr "" +msgstr "pam_sss" #. type: Content of: <reference><refentry><refmeta><manvolnum> #: pam_sss.8.xml:12 pam_sss_gss.8.xml:12 sssd_krb5_locator_plugin.8.xml:11 @@ -7512,7 +7518,7 @@ msgstr "" #: idmap_sss.8.xml:11 sssctl.8.xml:11 sssd-kcm.8.xml:11 #: sssd_krb5_localauth_plugin.8.xml:11 msgid "8" -msgstr "" +msgstr "8" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: pam_sss.8.xml:17 @@ -7551,12 +7557,12 @@ msgstr "" #: sss_cache.8.xml:39 sss_seed.8.xml:42 sss_ssh_authorizedkeys.1.xml:123 #: sss_ssh_knownhosts.1.xml:59 msgid "OPTIONS" -msgstr "" +msgstr "პარამეტრები" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:77 msgid "<option>quiet</option>" -msgstr "" +msgstr "<option>quiet</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:80 @@ -7566,7 +7572,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:85 msgid "<option>forward_pass</option>" -msgstr "" +msgstr "<option>forward_pass</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:88 @@ -7578,7 +7584,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:95 msgid "<option>use_first_pass</option>" -msgstr "" +msgstr "<option>use_first_pass</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:98 @@ -7592,7 +7598,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:106 msgid "<option>use_authtok</option>" -msgstr "" +msgstr "<option>use_authtok</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:109 @@ -7604,7 +7610,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:116 msgid "<option>retry=N</option>" -msgstr "" +msgstr "<option>retry=N</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:119 @@ -7624,7 +7630,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:130 msgid "<option>ignore_unknown_user</option>" -msgstr "" +msgstr "<option>ignore_unknown_user</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:133 @@ -7636,7 +7642,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:140 msgid "<option>ignore_authinfo_unavail</option>" -msgstr "" +msgstr "<option>ignore_authinfo_unavail</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:144 @@ -7648,7 +7654,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:151 msgid "<option>domains</option>" -msgstr "" +msgstr "<option>domains</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:155 @@ -7673,7 +7679,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:176 msgid "<option>allow_missing_name</option>" -msgstr "" +msgstr "<option>allow_missing_name</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:180 @@ -7689,6 +7695,8 @@ msgid "" "auth sufficient pam_sss.so allow_missing_name\n" " " msgstr "" +"auth sufficient pam_sss.so allow_missing_name\n" +" " #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:185 @@ -7704,7 +7712,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:200 msgid "<option>prompt_always</option>" -msgstr "" +msgstr "<option>prompt_always</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:204 @@ -7719,7 +7727,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:215 msgid "<option>try_cert_auth</option>" -msgstr "" +msgstr "<option>try_cert_auth</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:219 @@ -7740,7 +7748,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:235 msgid "<option>require_cert_auth</option>" -msgstr "" +msgstr "<option>require_cert_auth</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:239 @@ -7764,7 +7772,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:257 msgid "<option>allow_chauthtok_by_root</option>" -msgstr "" +msgstr "<option>allow_chauthtok_by_root</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:261 @@ -7804,12 +7812,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: pam_sss.8.xml:286 pam_sss_gss.8.xml:108 msgid "RETURN VALUES" -msgstr "" +msgstr "RETURN VALUES" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:289 pam_sss_gss.8.xml:111 msgid "PAM_SUCCESS" -msgstr "" +msgstr "PAM_SUCCESS" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:292 pam_sss_gss.8.xml:114 @@ -7819,7 +7827,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:297 pam_sss_gss.8.xml:119 msgid "PAM_USER_UNKNOWN" -msgstr "" +msgstr "PAM_USER_UNKNOWN" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:300 @@ -7831,7 +7839,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:306 pam_sss_gss.8.xml:128 msgid "PAM_AUTH_ERR" -msgstr "" +msgstr "PAM_AUTH_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:309 @@ -7843,7 +7851,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:315 msgid "PAM_PERM_DENIED" -msgstr "" +msgstr "PAM_PERM_DENIED" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:318 @@ -7855,7 +7863,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:324 msgid "PAM_IGNORE" -msgstr "" +msgstr "PAM_IGNORE" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:327 @@ -7867,7 +7875,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:333 msgid "PAM_AUTHTOK_ERR" -msgstr "" +msgstr "PAM_AUTHTOK_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:336 @@ -7881,7 +7889,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:344 pam_sss_gss.8.xml:136 msgid "PAM_AUTHINFO_UNAVAIL" -msgstr "" +msgstr "PAM_AUTHINFO_UNAVAIL" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:347 pam_sss_gss.8.xml:139 @@ -7893,7 +7901,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:353 msgid "PAM_BUF_ERR" -msgstr "" +msgstr "PAM_BUF_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:356 @@ -7906,7 +7914,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:363 pam_sss_gss.8.xml:145 msgid "PAM_SYSTEM_ERR" -msgstr "" +msgstr "PAM_SYSTEM_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:366 pam_sss_gss.8.xml:148 @@ -7918,7 +7926,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:372 msgid "PAM_CRED_ERR" -msgstr "" +msgstr "PAM_CRED_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:375 @@ -7928,7 +7936,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:380 msgid "PAM_CRED_INSUFFICIENT" -msgstr "" +msgstr "PAM_CRED_INSUFFICIENT" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:383 @@ -7941,17 +7949,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:391 msgid "PAM_SERVICE_ERR" -msgstr "" +msgstr "PAM_SERVICE_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:394 msgid "Error in service module." -msgstr "" +msgstr "შეცდომა სერვისის მოდულში." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:399 msgid "PAM_NEW_AUTHTOK_REQD" -msgstr "" +msgstr "PAM_NEW_AUTHTOK_REQD" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:402 @@ -7961,17 +7969,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:407 msgid "PAM_ACCT_EXPIRED" -msgstr "" +msgstr "PAM_ACCT_EXPIRED" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:410 msgid "The user account has expired." -msgstr "" +msgstr "მომხმარებლის ანგარიშის ვადა ამოიწურა." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:415 msgid "PAM_SESSION_ERR" -msgstr "" +msgstr "PAM_SESSION_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:418 @@ -7981,7 +7989,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:423 msgid "PAM_CRED_UNAVAIL" -msgstr "" +msgstr "PAM_CRED_UNAVAIL" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:426 @@ -7991,7 +7999,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:431 msgid "PAM_NO_MODULE_DATA" -msgstr "" +msgstr "PAM_NO_MODULE_DATA" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:434 @@ -8004,7 +8012,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:441 msgid "PAM_CONV_ERR" -msgstr "" +msgstr "PAM_CONV_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:444 @@ -8014,7 +8022,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:449 msgid "PAM_AUTHTOK_LOCK_BUSY" -msgstr "" +msgstr "PAM_AUTHTOK_LOCK_BUSY" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:452 @@ -8024,7 +8032,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:457 msgid "PAM_ABORT" -msgstr "" +msgstr "PAM_ABORT" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:460 @@ -8034,7 +8042,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:465 msgid "PAM_MODULE_UNKNOWN" -msgstr "" +msgstr "PAM_MODULE_UNKNOWN" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:468 @@ -8044,7 +8052,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:473 msgid "PAM_BAD_ITEM" -msgstr "" +msgstr "PAM_BAD_ITEM" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:476 @@ -8054,7 +8062,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: pam_sss.8.xml:484 msgid "FILES" -msgstr "" +msgstr "ფაილები" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss.8.xml:485 @@ -8089,7 +8097,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: pam_sss_gss.8.xml:11 pam_sss_gss.8.xml:16 msgid "pam_sss_gss" -msgstr "" +msgstr "pam_sss_gss" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: pam_sss_gss.8.xml:17 @@ -8173,12 +8181,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss_gss.8.xml:93 msgid "<option>debug</option>" -msgstr "" +msgstr "<option>debug</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss_gss.8.xml:96 msgid "Print debugging information." -msgstr "" +msgstr "გამართვის ინფორმაციის გამოტანა." #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:104 @@ -8195,7 +8203,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss_gss.8.xml:131 msgid "Authentication failure." -msgstr "" +msgstr "ავთენტიკაციის ჩავარდნა." #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:159 @@ -8230,11 +8238,15 @@ msgid "" "...\n" " " msgstr "" +"...\n" +"auth sufficient pam_sss_gss.so\n" +"...\n" +" " #. type: Content of: <reference><refentry><refsect1><title> #: pam_sss_gss.8.xml:180 msgid "TROUBLESHOOTING" -msgstr "" +msgstr "პრობლემების გადაჭრა" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:182 @@ -8290,11 +8302,14 @@ msgid "" ".myhostname = MYREALM\n" " " msgstr "" +"[domain_realm]\n" +".myhostname = MYREALM\n" +" " #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd_krb5_locator_plugin.8.xml:10 sssd_krb5_locator_plugin.8.xml:15 msgid "sssd_krb5_locator_plugin" -msgstr "" +msgstr "sssd_krb5_locator_plugin" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd_krb5_locator_plugin.8.xml:16 @@ -8343,32 +8358,32 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd_krb5_locator_plugin.8.xml:58 msgid "kdc.example.com" -msgstr "" +msgstr "kdc.example.com" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd_krb5_locator_plugin.8.xml:59 msgid "kdc.example.com:321" -msgstr "" +msgstr "kdc.example.com:321" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd_krb5_locator_plugin.8.xml:60 msgid "1.2.3.4" -msgstr "" +msgstr "1.2.3.4" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd_krb5_locator_plugin.8.xml:61 msgid "5.6.7.8:99" -msgstr "" +msgstr "5.6.7.8:99" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd_krb5_locator_plugin.8.xml:62 msgid "2001:db8:85a3::8a2e:370:7334" -msgstr "" +msgstr "2001:db8:85a3::8a2e:370:7334" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd_krb5_locator_plugin.8.xml:63 msgid "[2001:db8:85a3::8a2e:370:7334]:321" -msgstr "" +msgstr "[2001:db8:85a3::8a2e:370:7334]:321" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:65 @@ -8426,7 +8441,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-simple.5.xml:10 sssd-simple.5.xml:16 msgid "sssd-simple" -msgstr "" +msgstr "sssd-simple" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-simple.5.xml:17 @@ -8496,7 +8511,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-simple.5.xml:91 msgid "simple_allow_users (string)" -msgstr "" +msgstr "simple_allow_users (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-simple.5.xml:94 @@ -8509,7 +8524,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-simple.5.xml:103 msgid "simple_deny_users (string)" -msgstr "" +msgstr "simple_deny_users (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-simple.5.xml:106 @@ -8530,7 +8545,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-simple.5.xml:120 msgid "simple_allow_groups (string)" -msgstr "" +msgstr "simple_allow_groups (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-simple.5.xml:123 @@ -8557,7 +8572,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-simple.5.xml:141 msgid "simple_deny_groups (string)" -msgstr "" +msgstr "simple_deny_groups (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-simple.5.xml:144 @@ -8627,7 +8642,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss-certmap.5.xml:10 sss-certmap.5.xml:16 msgid "sss-certmap" -msgstr "" +msgstr "sss-certmap" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss-certmap.5.xml:17 @@ -8682,7 +8697,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sss-certmap.5.xml:57 msgid "PRIORITY" -msgstr "" +msgstr "პრიორიტეტი" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:59 @@ -8740,7 +8755,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:99 msgid "<SUBJECT>regular-expression" -msgstr "" +msgstr "<SUBJECT>რეგულარული-გამოსახულება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:102 @@ -8784,7 +8799,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:135 msgid "<ISSUER>regular-expression" -msgstr "" +msgstr "<ISSUER>რეგულარული-გამოსახულება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:138 @@ -8801,7 +8816,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:148 msgid "<KU>key-usage" -msgstr "" +msgstr "<KU>გასაღების-გამოყენება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:151 @@ -8813,47 +8828,47 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:155 msgid "digitalSignature" -msgstr "" +msgstr "digitalSignature" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:156 msgid "nonRepudiation" -msgstr "" +msgstr "nonRepudiation" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:157 msgid "keyEncipherment" -msgstr "" +msgstr "keyEncipherment" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:158 msgid "dataEncipherment" -msgstr "" +msgstr "dataEncipherment" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:159 msgid "keyAgreement" -msgstr "" +msgstr "keyAgreement" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:160 msgid "keyCertSign" -msgstr "" +msgstr "keyCertSign" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:161 msgid "cRLSign" -msgstr "" +msgstr "cRLSign" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:162 msgid "encipherOnly" -msgstr "" +msgstr "encipherOnly" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:163 msgid "decipherOnly" -msgstr "" +msgstr "decipherOnly" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:167 @@ -8870,7 +8885,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:176 msgid "<EKU>extended-key-usage" -msgstr "" +msgstr "<EKU>გასაღების-გაფართოებული-გამოყენება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:179 @@ -8882,47 +8897,47 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:183 msgid "serverAuth" -msgstr "" +msgstr "serverAuth" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:184 msgid "clientAuth" -msgstr "" +msgstr "clientAuth" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:185 msgid "codeSigning" -msgstr "" +msgstr "codeSigning" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:186 msgid "emailProtection" -msgstr "" +msgstr "emailProtection" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:187 msgid "timeStamping" -msgstr "" +msgstr "timeStamping" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:188 msgid "OCSPSigning" -msgstr "" +msgstr "OCSPSigning" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:189 msgid "KPClientAuth" -msgstr "" +msgstr "KPClientAuth" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:190 msgid "pkinit" -msgstr "" +msgstr "pkinit" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:191 msgid "msScLogin" -msgstr "" +msgstr "msScLogin" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:195 @@ -8939,7 +8954,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:204 msgid "<SAN>regular-expression" -msgstr "" +msgstr "<SAN>რეგულარულ-გამოსახულება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:207 @@ -8957,7 +8972,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:217 msgid "<SAN:Principal>regular-expression" -msgstr "" +msgstr "<SAN:Principal>რეგულარული-გამოსახულება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:220 @@ -8967,12 +8982,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:224 msgid "Example: <SAN:Principal>.*@MY\\.REALM" -msgstr "" +msgstr "მაგალითი: <SAN:Principal>.*@MY\\.REALM" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:229 msgid "<SAN:ntPrincipalName>regular-expression" -msgstr "" +msgstr "<SAN:ntPrincipalName>რეგულარული-გამოსახულება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:232 @@ -8982,12 +8997,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:236 msgid "Example: <SAN:ntPrincipalName>.*@MY.AD.REALM" -msgstr "" +msgstr "მაგალითი: <SAN:ntPrincipalName>.*@MY.AD.REALM" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:241 msgid "<SAN:pkinit>regular-expression" -msgstr "" +msgstr "<SAN:pkinit>რეგულარული-გამოსახულება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:244 @@ -8997,12 +9012,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:247 msgid "Example: <SAN:ntPrincipalName>.*@MY\\.PKINIT\\.REALM" -msgstr "" +msgstr "მაგალითი: <SAN:ntPrincipalName>.*@MY\\.PKINIT\\.REALM" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:252 msgid "<SAN:dotted-decimal-oid>regular-expression" -msgstr "" +msgstr "<SAN:dotted-decimal-oid>რეგულარული-გამოსახულება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:255 @@ -9015,12 +9030,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:261 msgid "Example: <SAN:1.2.3.4>test" -msgstr "" +msgstr "მაგალითი: <SAN:1.2.3.4>test" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:266 msgid "<SAN:otherName>base64-string" -msgstr "" +msgstr "<SAN:otherName>base64-სტრიქონი" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:269 @@ -9034,12 +9049,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:276 msgid "Example: <SAN:otherName>MTIz" -msgstr "" +msgstr "მაგალითი: <SAN:otherName>MTIz" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:281 msgid "<SAN:rfc822Name>regular-expression" -msgstr "" +msgstr "<SAN:rfc822Name>რეგულარული-გამოსახულება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:284 @@ -9049,12 +9064,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:287 msgid "Example: <SAN:rfc822Name>.*@email\\.domain" -msgstr "" +msgstr "მაგალითი: <SAN:rfc822Name>.*@email\\.domain" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:292 msgid "<SAN:dNSName>regular-expression" -msgstr "" +msgstr "<SAN:dNSName>რეგულარული-გამოსახულება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:295 @@ -9064,12 +9079,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:298 msgid "Example: <SAN:dNSName>.*\\.my\\.dns\\.domain" -msgstr "" +msgstr "მაგალითი: <SAN:dNSName>.*\\.my\\.dns\\.domain" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:303 msgid "<SAN:x400Address>base64-string" -msgstr "" +msgstr "<SAN:x400Address>base64-სტრიქონი" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:306 @@ -9079,12 +9094,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:309 msgid "Example: <SAN:x400Address>MTIz" -msgstr "" +msgstr "მაგალითი: <SAN:x400Address>MTIz" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:314 msgid "<SAN:directoryName>regular-expression" -msgstr "" +msgstr "<SAN:directoryName>რეგულარული-გამოსახულება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:317 @@ -9096,12 +9111,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:322 msgid "Example: <SAN:directoryName>.*,DC=com" -msgstr "" +msgstr "მაგალითი: <SAN:directoryName>.*,DC=com" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:327 msgid "<SAN:ediPartyName>base64-string" -msgstr "" +msgstr "<SAN:ediPartyName>base64-სტრიქონი" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:330 @@ -9111,12 +9126,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:333 msgid "Example: <SAN:ediPartyName>MTIz" -msgstr "" +msgstr "მაგალითი: <SAN:ediPartyName>MTIz" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:338 msgid "<SAN:uniformResourceIdentifier>regular-expression" -msgstr "" +msgstr "<SAN:uniformResourceIdentifier>რეგულარული-გამოსახულება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:341 @@ -9126,12 +9141,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:344 msgid "Example: <SAN:uniformResourceIdentifier>URN:.*" -msgstr "" +msgstr "მაგალითი: <SAN:uniformResourceIdentifier>URN:.*" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:349 msgid "<SAN:iPAddress>regular-expression" -msgstr "" +msgstr "<SAN:iPAddress>რეგულარული-გამოსახულება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:352 @@ -9141,12 +9156,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:355 msgid "Example: <SAN:iPAddress>192\\.168\\..*" -msgstr "" +msgstr "მაგალითი: <SAN:iPAddress>192\\.168\\..*" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:360 msgid "<SAN:registeredID>regular-expression" -msgstr "" +msgstr "<SAN:registeredID>რეგულარული-გამოსახულება" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:363 @@ -9156,7 +9171,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:367 msgid "Example: <SAN:registeredID>1\\.2\\.3\\..*" -msgstr "" +msgstr "მაგალითი: <SAN:registeredID>1\\.2\\.3\\..*" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:96 @@ -9223,7 +9238,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:424 msgid "{issuer_dn[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" -msgstr "" +msgstr "{issuer_dn[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:427 @@ -9260,11 +9275,13 @@ msgid "" "Example: " "(ipacertmapdata=X509:<I>{issuer_dn!ad}<S>{subject_dn!ad})" msgstr "" +"მაგალითი: (ipacertmapdata=X509:<I>{issuer_dn!ad}<S>" +"{subject_dn!ad})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:450 msgid "{subject_dn[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" -msgstr "" +msgstr "{subject_dn[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:453 @@ -9280,11 +9297,13 @@ msgid "" "Example: " "(ipacertmapdata=X509:<I>{issuer_dn!nss_x500}<S>{subject_dn!nss_x500})" msgstr "" +"მაგალითი: (ipacertmapdata=X509:<I>{issuer_dn!nss_x500}<S>" +"{subject_dn!nss_x500})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:476 msgid "{cert[!(bin|base64)]}" -msgstr "" +msgstr "{cert[!(bin|base64)]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:479 @@ -9299,12 +9318,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:487 msgid "Example: (userCertificate;binary={cert!bin})" -msgstr "" +msgstr "მაგალითი: (userCertificate;binary={cert!bin})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:492 msgid "{subject_principal[.short_name]}" -msgstr "" +msgstr "{subject_principal[.short_name]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:495 @@ -9320,11 +9339,13 @@ msgid "" "Example: " "(|(userPrincipal={subject_principal})(samAccountName={subject_principal.short_name}))" msgstr "" +"მაგალითი: (|(userPrincipal={subject_principal})(samAccountName=" +"{subject_principal.short_name}))" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:506 msgid "{subject_pkinit_principal[.short_name]}" -msgstr "" +msgstr "{subject_pkinit_principal[.short_name]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:509 @@ -9340,11 +9361,13 @@ msgid "" "Example: " "(|(userPrincipal={subject_pkinit_principal})(uid={subject_pkinit_principal.short_name}))" msgstr "" +"მაგალითი: (|(userPrincipal={subject_pkinit_principal})(uid=" +"{subject_pkinit_principal.short_name}))" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:520 msgid "{subject_nt_principal[.short_name]}" -msgstr "" +msgstr "{subject_nt_principal[.short_name]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:523 @@ -9360,11 +9383,13 @@ msgid "" "Example: " "(|(userPrincipalName={subject_nt_principal})(samAccountName={subject_nt_principal.short_name}))" msgstr "" +"მაგალითი: (|(userPrincipalName={subject_nt_principal})(samAccountName=" +"{subject_nt_principal.short_name}))" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:534 msgid "{subject_rfc822_name[.short_name]}" -msgstr "" +msgstr "{subject_rfc822_name[.short_name]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:537 @@ -9380,11 +9405,13 @@ msgid "" "Example: " "(|(mail={subject_rfc822_name})(uid={subject_rfc822_name.short_name}))" msgstr "" +"მაგალითი: (|(mail={subject_rfc822_name})(uid=" +"{subject_rfc822_name.short_name}))" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:548 msgid "{subject_dns_name[.short_name]}" -msgstr "" +msgstr "{subject_dns_name[.short_name]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:551 @@ -9398,11 +9425,12 @@ msgstr "" #: sss-certmap.5.xml:557 msgid "Example: (|(fqdn={subject_dns_name})(host={subject_dns_name.short_name}))" msgstr "" +"მაგალითი: (|(fqdn={subject_dns_name})(host={subject_dns_name.short_name}))" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:562 msgid "{subject_uri}" -msgstr "" +msgstr "{subject_uri}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:565 @@ -9414,12 +9442,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:569 msgid "Example: (uri={subject_uri})" -msgstr "" +msgstr "მაგალითი: (uri={subject_uri})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:574 msgid "{subject_ip_address}" -msgstr "" +msgstr "{subject_ip_address}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:577 @@ -9431,12 +9459,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:581 msgid "Example: (ip={subject_ip_address})" -msgstr "" +msgstr "მაგალითი: (ip={subject_ip_address})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:586 msgid "{subject_x400_address}" -msgstr "" +msgstr "{subject_x400_address}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:589 @@ -9448,12 +9476,13 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:594 msgid "Example: (attr:binary={subject_x400_address})" -msgstr "" +msgstr "მაგალითი: (attr:binary={subject_x400_address})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:599 msgid "{subject_directory_name[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" msgstr "" +"{subject_directory_name[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:602 @@ -9465,12 +9494,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:606 msgid "Example: (orig_dn={subject_directory_name})" -msgstr "" +msgstr "მაგალითი: (orig_dn={subject_directory_name})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:611 msgid "{subject_ediparty_name}" -msgstr "" +msgstr "{subject_ediparty_name}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:614 @@ -9482,12 +9511,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:619 msgid "Example: (attr:binary={subject_ediparty_name})" -msgstr "" +msgstr "მაგალითი: (attr:binary={subject_ediparty_name})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:624 msgid "{subject_registered_id}" -msgstr "" +msgstr "{subject_registered_id}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:627 @@ -9499,7 +9528,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:632 msgid "Example: (oid={subject_registered_id})" -msgstr "" +msgstr "მაგალითი: (oid={subject_registered_id})" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:417 @@ -9514,7 +9543,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><title> #: sss-certmap.5.xml:639 msgid "LDAPU1 extension" -msgstr "" +msgstr "LDAPU1 გაფართოება" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para> #: sss-certmap.5.xml:641 @@ -9524,7 +9553,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:647 msgid "{serial_number[!(dec|hex[_ucr])]}" -msgstr "" +msgstr "{serial_number[!(dec|hex[_ucr])]}" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:650 @@ -9552,7 +9581,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:671 msgid "{subject_key_id[!hex[_ucr]]}" -msgstr "" +msgstr "{subject_key_id[!hex[_ucr]]}" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:674 @@ -9579,7 +9608,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:694 msgid "{cert[!DIGEST[_ucr]]}" -msgstr "" +msgstr "{cert[!DIGEST[_ucr]]}" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:697 @@ -9602,12 +9631,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:712 msgid "Example: LDAPU1:(dgst={cert!sha256})" -msgstr "" +msgstr "მაგალითი: LDAPU1:(dgst={cert!sha256})" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:718 msgid "{subject_dn_component[(.attr_name|[number]]}" -msgstr "" +msgstr "{subject_dn_component[(.attr_name|[number]]}" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:721 @@ -9636,7 +9665,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:743 msgid "{issuer_dn_component[(.attr_name|[number]]}" -msgstr "" +msgstr "{issuer_dn_component[(.attr_name|[number]]}" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:746 @@ -9662,7 +9691,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:760 msgid "{sid[.rid]}" -msgstr "" +msgstr "{sid[.rid]}" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:763 @@ -9675,7 +9704,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:770 msgid "Example: LDAPU1:(objectsid={sid})" -msgstr "" +msgstr "მაგალითი: LDAPU1:(objectsid={sid})" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sss-certmap.5.xml:779 @@ -9693,7 +9722,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-ipa.5.xml:10 sssd-ipa.5.xml:16 msgid "sssd-ipa" -msgstr "" +msgstr "sssd-ipa" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-ipa.5.xml:17 @@ -9768,7 +9797,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:90 msgid "ipa_domain (string)" -msgstr "" +msgstr "ipa_domain (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:93 @@ -9780,7 +9809,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:101 msgid "ipa_server, ipa_backup_server (string)" -msgstr "" +msgstr "ipa_server, ipa_backup_server (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:104 @@ -9795,7 +9824,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:117 msgid "ipa_hostname (string)" -msgstr "" +msgstr "ipa_hostname (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:120 @@ -9808,7 +9837,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:129 sssd-ad.5.xml:1213 msgid "dyndns_update (boolean)" -msgstr "" +msgstr "dyndns_update (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:132 @@ -9838,7 +9867,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:158 sssd-ad.5.xml:1238 msgid "dyndns_ttl (integer)" -msgstr "" +msgstr "dyndns_ttl (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:161 sssd-ad.5.xml:1241 @@ -9859,12 +9888,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:172 msgid "Default: 1200 (seconds)" -msgstr "" +msgstr "ნაგულისხმევი: 1200 (წმ)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:178 sssd-ad.5.xml:1252 msgid "dyndns_iface (string)" -msgstr "" +msgstr "dyndns_iface (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:181 sssd-ad.5.xml:1255 @@ -9898,7 +9927,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:205 sssd-ad.5.xml:1323 msgid "dyndns_auth (string)" -msgstr "" +msgstr "dyndns_auth (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:208 sssd-ad.5.xml:1326 @@ -9911,12 +9940,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:214 sssd-ad.5.xml:1332 msgid "Default: GSS-TSIG" -msgstr "" +msgstr "ნაგულისხმევი: GSS-TSIG" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:220 sssd-ad.5.xml:1338 msgid "dyndns_auth_ptr (string)" -msgstr "" +msgstr "dyndns_auth_ptr (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:223 sssd-ad.5.xml:1341 @@ -9934,7 +9963,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:235 msgid "ipa_enable_dns_sites (boolean)" -msgstr "" +msgstr "ipa_enable_dns_sites (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:238 sssd-ad.5.xml:238 @@ -9957,7 +9986,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:261 sssd-ad.5.xml:1273 msgid "dyndns_refresh_interval (integer)" -msgstr "" +msgstr "dyndns_refresh_interval (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:264 @@ -9970,7 +9999,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:277 sssd-ad.5.xml:1291 msgid "dyndns_update_ptr (bool)" -msgstr "" +msgstr "dyndns_update_ptr (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:280 sssd-ad.5.xml:1294 @@ -10001,7 +10030,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:302 sssd-ad.5.xml:1310 msgid "dyndns_force_tcp (bool)" -msgstr "" +msgstr "dyndns_force_tcp (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:305 sssd-ad.5.xml:1313 @@ -10018,7 +10047,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:315 sssd-ad.5.xml:1353 msgid "dyndns_server (string)" -msgstr "" +msgstr "dyndns_server (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:318 sssd-ad.5.xml:1356 @@ -10067,7 +10096,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:353 sssd-ad.5.xml:1391 msgid "dyndns_update_per_family (boolean)" -msgstr "" +msgstr "dyndns_update_per_family (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:356 sssd-ad.5.xml:1394 @@ -10080,7 +10109,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:368 sssd-ad.5.xml:1406 msgid "dyndns_dot_cacert (string)" -msgstr "" +msgstr "dyndns_dot_cacert (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:371 sssd-ad.5.xml:1409 @@ -10098,7 +10127,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:383 sssd-ad.5.xml:1421 msgid "dyndns_dot_cert (string)" -msgstr "" +msgstr "dyndns_dot_cert (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:386 sssd-ad.5.xml:1424 @@ -10124,7 +10153,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:403 sssd-ad.5.xml:1441 msgid "dyndns_dot_key (string)" -msgstr "" +msgstr "dyndns_dot_key (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:406 sssd-ad.5.xml:1444 @@ -10137,7 +10166,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:418 msgid "ipa_access_order (string)" -msgstr "" +msgstr "ipa_access_order (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:425 @@ -10154,7 +10183,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:471 msgid "ipa_deskprofile_search_base (string)" -msgstr "" +msgstr "ipa_deskprofile_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:474 @@ -10171,7 +10200,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:484 msgid "ipa_subid_ranges_search_base (string)" -msgstr "" +msgstr "ipa_subid_ranges_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:487 @@ -10188,7 +10217,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:498 msgid "ipa_hbac_search_base (string)" -msgstr "" +msgstr "ipa_hbac_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:501 @@ -10198,7 +10227,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:511 msgid "ipa_host_search_base (string)" -msgstr "" +msgstr "ipa_host_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:514 @@ -10208,7 +10237,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:520 msgid "ipa_selinux_search_base (string)" -msgstr "" +msgstr "ipa_selinux_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:523 @@ -10218,7 +10247,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:539 msgid "ipa_subdomains_search_base (string)" -msgstr "" +msgstr "ipa_subdomains_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:542 @@ -10233,7 +10262,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:558 msgid "ipa_master_domain_search_base (string)" -msgstr "" +msgstr "ipa_master_domain_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:561 @@ -10248,7 +10277,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:577 msgid "ipa_views_search_base (string)" -msgstr "" +msgstr "ipa_views_search_base (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:580 @@ -10277,7 +10306,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:611 sssd-ad.5.xml:1459 msgid "krb5_confd_path (string)" -msgstr "" +msgstr "krb5_confd_path (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:614 sssd-ad.5.xml:1462 @@ -10301,7 +10330,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:629 msgid "ipa_deskprofile_refresh (integer)" -msgstr "" +msgstr "ipa_deskprofile_refresh (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:632 @@ -10314,12 +10343,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:639 sssd-ipa.5.xml:669 sssd-ipa.5.xml:685 sssd-ad.5.xml:600 msgid "Default: 5 (seconds)" -msgstr "" +msgstr "ნაგულისხმევი: 5 (წმ)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:645 msgid "ipa_deskprofile_request_interval (integer)" -msgstr "" +msgstr "ipa_deskprofile_request_interval (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:648 @@ -10331,12 +10360,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:653 msgid "Default: 60 (minutes)" -msgstr "" +msgstr "ნაგულისხმევი: 60 (წთ)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:659 msgid "ipa_hbac_refresh (integer)" -msgstr "" +msgstr "ipa_hbac_refresh (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:662 @@ -10349,7 +10378,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:675 msgid "ipa_hbac_selinux (integer)" -msgstr "" +msgstr "ipa_hbac_selinux (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:678 @@ -10362,7 +10391,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:691 msgid "ipa_server_mode (boolean)" -msgstr "" +msgstr "ipa_server_mode (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:694 @@ -10403,7 +10432,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:733 msgid "ipa_automount_location (string)" -msgstr "" +msgstr "ipa_automount_location (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:736 @@ -10423,7 +10452,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:756 msgid "ipa_view_class (string)" -msgstr "" +msgstr "ipa_view_class (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:759 @@ -10433,12 +10462,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:762 msgid "Default: nsContainer" -msgstr "" +msgstr "ნაგულისხმევი: nsContainer" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:768 msgid "ipa_view_name (string)" -msgstr "" +msgstr "ipa_view_name (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:771 @@ -10451,12 +10480,12 @@ msgstr "" #: sssd-ldap-attributes.5.xml:1010 sssd-ldap-attributes.5.xml:1068 #: sssd-ldap-attributes.5.xml:1226 sssd-ldap-attributes.5.xml:1271 msgid "Default: cn" -msgstr "" +msgstr "ნაგულისხმევი: cn" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:781 msgid "ipa_override_object_class (string)" -msgstr "" +msgstr "ipa_override_object_class (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:784 @@ -10466,12 +10495,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:787 msgid "Default: ipaOverrideAnchor" -msgstr "" +msgstr "ნაგულისხმევი: ipaOverrideAnchor" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:793 msgid "ipa_anchor_uuid (string)" -msgstr "" +msgstr "ipa_anchor_uuid (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:796 @@ -10483,12 +10512,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:800 msgid "Default: ipaAnchorUUID" -msgstr "" +msgstr "ნაგულისხმევი: ipaAnchorUUID" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:806 msgid "ipa_user_override_object_class (string)" -msgstr "" +msgstr "ipa_user_override_object_class (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:809 @@ -10505,47 +10534,47 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:817 msgid "ldap_user_name" -msgstr "" +msgstr "ldap_user_name" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:820 msgid "ldap_user_uid_number" -msgstr "" +msgstr "ldap_user_uid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:823 msgid "ldap_user_gid_number" -msgstr "" +msgstr "ldap_user_gid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:826 msgid "ldap_user_gecos" -msgstr "" +msgstr "ldap_user_gecos" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:829 msgid "ldap_user_home_directory" -msgstr "" +msgstr "ldap_user_home_directory" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:832 msgid "ldap_user_shell" -msgstr "" +msgstr "ldap_user_shell" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:835 msgid "ldap_user_ssh_public_key" -msgstr "" +msgstr "ldap_user_ssh_public_key" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:840 msgid "Default: ipaUserOverride" -msgstr "" +msgstr "ნაგულისხმევი: ipaUserOverride" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:846 msgid "ipa_group_override_object_class (string)" -msgstr "" +msgstr "ipa_group_override_object_class (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:849 @@ -10562,17 +10591,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:857 msgid "ldap_group_name" -msgstr "" +msgstr "ldap_group_name" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:860 msgid "ldap_group_gid_number" -msgstr "" +msgstr "ldap_group_gid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:865 msgid "Default: ipaGroupOverride" -msgstr "" +msgstr "ნაგულისხმევი: ipaGroupOverride" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd-ipa.5.xml:749 @@ -10667,42 +10696,42 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:931 sssd-ipa.5.xml:971 msgid "ad_server" -msgstr "" +msgstr "ad_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:934 msgid "ad_backup_server" -msgstr "" +msgstr "ad_backup_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:937 sssd-ipa.5.xml:974 msgid "ad_site" -msgstr "" +msgstr "ad_site" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:940 msgid "ipa_server" -msgstr "" +msgstr "ipa_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:943 msgid "ipa_backup_server" -msgstr "" +msgstr "ipa_backup_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:946 msgid "ldap_search_base" -msgstr "" +msgstr "ldap_search_base" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:949 msgid "ldap_user_search_base" -msgstr "" +msgstr "ldap_user_search_base" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:952 msgid "ldap_group_search_base" -msgstr "" +msgstr "ldap_group_search_base" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd-ipa.5.xml:960 @@ -10766,7 +10795,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-ad.5.xml:10 sssd-ad.5.xml:16 msgid "sssd-ad" -msgstr "" +msgstr "sssd-ad" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-ad.5.xml:17 @@ -10854,6 +10883,8 @@ msgid "" "ldap_id_mapping = False\n" " " msgstr "" +"ldap_id_mapping = False\n" +" " #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:85 @@ -10906,7 +10937,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:138 msgid "ad_domain (string)" -msgstr "" +msgstr "ad_domain (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:141 @@ -10932,7 +10963,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:158 msgid "ad_enabled_domains (string)" -msgstr "" +msgstr "ad_enabled_domains (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:161 @@ -10977,7 +11008,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:193 msgid "ad_server, ad_backup_server (string)" -msgstr "" +msgstr "ad_server, ad_backup_server (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:196 @@ -11004,7 +11035,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:216 msgid "ad_hostname (string)" -msgstr "" +msgstr "ad_hostname (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:219 @@ -11026,7 +11057,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:235 msgid "ad_enable_dns_sites (boolean)" -msgstr "" +msgstr "ad_enable_dns_sites (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:242 @@ -11042,7 +11073,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:258 msgid "ad_access_filter (string)" -msgstr "" +msgstr "ad_access_filter (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:261 @@ -11123,7 +11154,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:334 msgid "ad_site (string)" -msgstr "" +msgstr "ad_site (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:337 @@ -11135,7 +11166,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:348 msgid "ad_enable_gc (boolean)" -msgstr "" +msgstr "ad_enable_gc (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:351 @@ -11158,7 +11189,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:373 msgid "ad_gpo_access_control (string)" -msgstr "" +msgstr "ad_gpo_access_control (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:376 @@ -11264,17 +11295,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:482 msgid "Default: permissive" -msgstr "" +msgstr "ნაგულისხმევი: permissive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:485 msgid "Default: enforcing" -msgstr "" +msgstr "ნაგულისხმევი: enforcing" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:491 msgid "ad_gpo_implicit_deny (boolean)" -msgstr "" +msgstr "ad_gpo_implicit_deny (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:494 @@ -11303,23 +11334,23 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd-ad.5.xml:523 sssd-ad.5.xml:549 msgid "allow-rules" -msgstr "" +msgstr "allow-rules" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd-ad.5.xml:523 sssd-ad.5.xml:549 msgid "deny-rules" -msgstr "" +msgstr "deny-rules" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd-ad.5.xml:524 sssd-ad.5.xml:550 msgid "results" -msgstr "" +msgstr "results" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> #: sssd-ad.5.xml:527 sssd-ad.5.xml:530 sssd-ad.5.xml:533 sssd-ad.5.xml:553 #: sssd-ad.5.xml:556 sssd-ad.5.xml:559 msgid "missing" -msgstr "" +msgstr "missing" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> #: sssd-ad.5.xml:528 @@ -11330,7 +11361,7 @@ msgstr "" #: sssd-ad.5.xml:530 sssd-ad.5.xml:533 sssd-ad.5.xml:536 sssd-ad.5.xml:556 #: sssd-ad.5.xml:559 sssd-ad.5.xml:562 msgid "present" -msgstr "" +msgstr "present" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> #: sssd-ad.5.xml:531 @@ -11350,7 +11381,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd-ad.5.xml:548 msgid "ad_gpo_implicit_deny = True" -msgstr "" +msgstr "ad_gpo_implicit_deny = True" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> #: sssd-ad.5.xml:554 sssd-ad.5.xml:557 @@ -11360,7 +11391,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:570 msgid "ad_gpo_ignore_unreadable (boolean)" -msgstr "" +msgstr "ad_gpo_ignore_unreadable (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:573 @@ -11375,7 +11406,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:590 msgid "ad_gpo_cache_timeout (integer)" -msgstr "" +msgstr "ad_gpo_cache_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:593 @@ -11388,7 +11419,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:606 msgid "ad_gpo_map_interactive (string)" -msgstr "" +msgstr "ad_gpo_map_interactive (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:609 @@ -11436,37 +11467,37 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:664 msgid "gdm-fingerprint" -msgstr "" +msgstr "gdm-fingerprint" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:684 msgid "lightdm" -msgstr "" +msgstr "lightdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:689 msgid "lxdm" -msgstr "" +msgstr "lxdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:694 msgid "sddm" -msgstr "" +msgstr "sddm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:699 msgid "unity" -msgstr "" +msgstr "unity" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:704 msgid "xdm" -msgstr "" +msgstr "xdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:713 msgid "ad_gpo_map_remote_interactive (string)" -msgstr "" +msgstr "ad_gpo_map_remote_interactive (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:716 @@ -11515,17 +11546,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:758 msgid "sshd" -msgstr "" +msgstr "sshd" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:763 msgid "cockpit" -msgstr "" +msgstr "cockpit" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:772 msgid "ad_gpo_map_network (string)" -msgstr "" +msgstr "ad_gpo_map_network (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:775 @@ -11574,17 +11605,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:816 msgid "ftp" -msgstr "" +msgstr "ftp" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:821 msgid "samba" -msgstr "" +msgstr "samba" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:830 msgid "ad_gpo_map_batch (string)" -msgstr "" +msgstr "ad_gpo_map_batch (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:833 @@ -11636,12 +11667,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:874 msgid "crond" -msgstr "" +msgstr "crond" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:883 msgid "ad_gpo_map_service (string)" -msgstr "" +msgstr "ad_gpo_map_service (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:886 @@ -11673,6 +11704,8 @@ msgid "" "ad_gpo_map_service = +my_pam_service\n" " " msgstr "" +"ad_gpo_map_service = +my_pam_service\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:909 sssd-ad.5.xml:984 @@ -11688,7 +11721,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:927 msgid "ad_gpo_map_permit (string)" -msgstr "" +msgstr "ad_gpo_map_permit (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:930 @@ -11704,6 +11737,8 @@ msgid "" "ad_gpo_map_permit = +my_pam_service, -sudo\n" " " msgstr "" +"ad_gpo_map_permit = +my_pam_service, -sudo\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:935 @@ -11720,17 +11755,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:952 msgid "polkit-1" -msgstr "" +msgstr "polkit-1" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:967 msgid "systemd-user" -msgstr "" +msgstr "systemd-user" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:976 msgid "ad_gpo_map_deny (string)" -msgstr "" +msgstr "ad_gpo_map_deny (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:979 @@ -11746,11 +11781,13 @@ msgid "" "ad_gpo_map_deny = +my_pam_service\n" " " msgstr "" +"ad_gpo_map_deny = +my_pam_service\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:1002 msgid "ad_gpo_default_right (string)" -msgstr "" +msgstr "ad_gpo_default_right (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1005 @@ -11773,42 +11810,42 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:1027 msgid "remote_interactive" -msgstr "" +msgstr "remote_interactive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:1032 msgid "network" -msgstr "" +msgstr "network" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:1037 msgid "batch" -msgstr "" +msgstr "batch" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:1042 msgid "service" -msgstr "" +msgstr "service" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:1047 msgid "permit" -msgstr "" +msgstr "permit" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:1052 msgid "deny" -msgstr "" +msgstr "deny" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1058 msgid "Default: deny" -msgstr "" +msgstr "ნაგულისხმევი: deny" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:1064 msgid "ad_maximum_machine_account_password_age (integer)" -msgstr "" +msgstr "ad_maximum_machine_account_password_age (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1067 @@ -11821,12 +11858,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1073 msgid "Default: 30 days" -msgstr "" +msgstr "ნაგულისხმევი: 30 დღე" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:1079 msgid "ad_machine_account_password_renewal_opts (string)" -msgstr "" +msgstr "ad_machine_account_password_renewal_opts (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1082 @@ -11872,7 +11909,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:1125 msgid "ad_update_samba_machine_account_password (boolean)" -msgstr "" +msgstr "ad_update_samba_machine_account_password (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1128 @@ -11886,7 +11923,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:1141 msgid "ad_use_ldaps (bool)" -msgstr "" +msgstr "ad_use_ldaps (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1144 @@ -11902,7 +11939,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:1161 msgid "ad_allow_remote_domain_local_groups (boolean)" -msgstr "" +msgstr "ad_allow_remote_domain_local_groups (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1164 @@ -11962,7 +11999,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1246 msgid "Default: 3600 (seconds)" -msgstr "" +msgstr "ნაგულისხმევი: 3600 (წმ)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1263 @@ -12047,7 +12084,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-sudo.5.xml:10 sssd-sudo.5.xml:16 msgid "sssd-sudo" -msgstr "" +msgstr "sssd-sudo" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-sudo.5.xml:17 @@ -12091,7 +12128,7 @@ msgstr "" #: sssd-sudo.5.xml:57 #, no-wrap msgid "sudoers: files sss\n" -msgstr "" +msgstr "sudoers: files sss\n" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:61 @@ -12230,12 +12267,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> #: sssd-sudo.5.xml:167 msgid "keyword ALL" -msgstr "" +msgstr "keyword ALL" #. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> #: sssd-sudo.5.xml:172 msgid "wildcard" -msgstr "" +msgstr "wildcard" #. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> #: sssd-sudo.5.xml:177 @@ -12320,7 +12357,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-idp.5.xml:10 sssd-idp.5.xml:16 msgid "sssd-idp" -msgstr "" +msgstr "sssd-idp" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-idp.5.xml:17 @@ -12362,7 +12399,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-idp.5.xml:62 msgid "idp_type (string)" -msgstr "" +msgstr "idp_type (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:65 @@ -12383,12 +12420,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:78 sssd-idp.5.xml:94 sssd-idp.5.xml:119 msgid "Default: Not set (Required)" -msgstr "" +msgstr "ნაგულისხმევი: დაყენებული არაა (აუცილებელია)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-idp.5.xml:83 msgid "idp_client_id (string)" -msgstr "" +msgstr "idp_client_id (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:86 @@ -12402,7 +12439,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-idp.5.xml:99 msgid "idp_client_secret (string)" -msgstr "" +msgstr "idp_client_secret (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:102 @@ -12415,7 +12452,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-idp.5.xml:113 msgid "idp_token_endpoint (string)" -msgstr "" +msgstr "idp_token_endpoint (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:116 @@ -12425,7 +12462,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-idp.5.xml:124 msgid "idp_device_auth_endpoint (string)" -msgstr "" +msgstr "idp_device_auth_endpoint (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:127 @@ -12437,7 +12474,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-idp.5.xml:137 msgid "idp_userinfo_endpoint (string)" -msgstr "" +msgstr "idp_userinfo_endpoint (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:140 @@ -12449,7 +12486,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-idp.5.xml:150 msgid "idp_id_scope (string)" -msgstr "" +msgstr "idp_id_scope (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:153 @@ -12462,7 +12499,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-idp.5.xml:164 msgid "idp_auth_scope (string)" -msgstr "" +msgstr "idp_auth_scope (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:167 @@ -12483,7 +12520,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-idp.5.xml:185 msgid "idp_request_timeout (integer)" -msgstr "" +msgstr "idp_request_timeout (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:188 @@ -12493,7 +12530,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-idp.5.xml:197 msgid "idmap_range_min (integer)" -msgstr "" +msgstr "idmap_range_min (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:200 @@ -12516,12 +12553,12 @@ msgstr "" #: sssd-idp.5.xml:213 sssd-idp.5.xml:239 include/ldap_id_mapping.xml:139 #: include/ldap_id_mapping.xml:197 msgid "Default: 200000" -msgstr "" +msgstr "ნაგულისხმევი: 200000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-idp.5.xml:218 msgid "idmap_range_max (integer)" -msgstr "" +msgstr "idmap_range_max (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:221 @@ -12534,12 +12571,12 @@ msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:227 include/ldap_id_mapping.xml:165 msgid "Default: 2000200000" -msgstr "" +msgstr "ნაგულისხმევი: 2000200000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-idp.5.xml:232 msgid "idmap_range_size (integer)" -msgstr "" +msgstr "idmap_range_size (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-idp.5.xml:235 @@ -12594,7 +12631,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd.8.xml:10 sssd.8.xml:15 msgid "sssd" -msgstr "" +msgstr "sssd" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd.8.xml:16 @@ -12630,7 +12667,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:53 msgid "<option>--debug-timestamps=</option><replaceable>mode</replaceable>" -msgstr "" +msgstr "<option>--debug-timestamps=</option><replaceable>რეჟიმი</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:57 @@ -12645,7 +12682,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:69 msgid "<option>--debug-microseconds=</option><replaceable>mode</replaceable>" -msgstr "" +msgstr "<option>--debug-microseconds=</option><replaceable>რეჟიმი</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:73 @@ -12660,7 +12697,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:85 msgid "<option>--logger=</option><replaceable>value</replaceable>" -msgstr "" +msgstr "<option>--logger=</option><replaceable>მნიშვნელობა</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:89 @@ -12695,7 +12732,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:113 msgid "<option>-D</option>,<option>--daemon</option>" -msgstr "" +msgstr "<option>-D</option>,<option>--daemon</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:117 @@ -12705,7 +12742,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:123 sss_seed.8.xml:136 msgid "<option>-i</option>,<option>--interactive</option>" -msgstr "" +msgstr "<option>-i</option>,<option>--interactive</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:127 @@ -12715,7 +12752,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:133 msgid "<option>-c</option>,<option>--config</option>" -msgstr "" +msgstr "<option>-c</option>,<option>--config</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:137 @@ -12730,22 +12767,22 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:151 msgid "<option>--version</option>" -msgstr "" +msgstr "<option>--version</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:155 msgid "Print version number and exit." -msgstr "" +msgstr "ვერსიის ინფორმაციის გამოტანა და გასვლა." #. type: Content of: <reference><refentry><refsect1><title> #: sssd.8.xml:163 msgid "Signals" -msgstr "" +msgstr "სიგნალები" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:166 msgid "SIGTERM/SIGINT" -msgstr "" +msgstr "SIGTERM/SIGINT" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:169 @@ -12757,7 +12794,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:175 msgid "SIGHUP" -msgstr "" +msgstr "SIGHUP" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:178 @@ -12770,7 +12807,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:186 msgid "SIGUSR1" -msgstr "" +msgstr "SIGUSR1" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:189 @@ -12784,7 +12821,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:198 msgid "SIGUSR2" -msgstr "" +msgstr "SIGUSR2" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:201 @@ -12797,7 +12834,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:208 msgid "SIGRTMIN+1" -msgstr "" +msgstr "SIGRTMIN+1" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:211 @@ -12810,12 +12847,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.8.xml:223 sss_ssh_authorizedkeys.1.xml:141 sss_ssh_knownhosts.1.xml:116 msgid "EXIT STATUS" -msgstr "" +msgstr "გასვლის სტატუსი" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:226 msgid "0" -msgstr "" +msgstr "0" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:229 @@ -12825,7 +12862,7 @@ msgstr "" #. type: Content of: <reference><refentry><refmeta><manvolnum> #: sssd.8.xml:234 sss_ssh_authorizedkeys.1.xml:11 sss_ssh_knownhosts.1.xml:11 msgid "1" -msgstr "" +msgstr "1" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:237 @@ -12835,17 +12872,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:242 msgid "2" -msgstr "" +msgstr "2" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:245 msgid "Memory allocation error." -msgstr "" +msgstr "მეხსიერების გამოყოფის შეცდომა." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:250 msgid "6" -msgstr "" +msgstr "6" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:253 @@ -12855,7 +12892,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:258 msgid "Other codes" -msgstr "" +msgstr "სხვა კოდები" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:261 @@ -12881,7 +12918,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_obfuscate.8.xml:10 sss_obfuscate.8.xml:15 msgid "sss_obfuscate" -msgstr "" +msgstr "sss_obfuscate" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_obfuscate.8.xml:16 @@ -12929,7 +12966,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_obfuscate.8.xml:63 msgid "<option>-s</option>,<option>--stdin</option>" -msgstr "" +msgstr "<option>-s</option>,<option>--stdin</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_obfuscate.8.xml:67 @@ -12943,6 +12980,8 @@ msgid "" "<option>-d</option>,<option>--domain</option> " "<replaceable>DOMAIN</replaceable>" msgstr "" +"<option>-d</option>,<option>--domain</option> <replaceable>დომენი</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_obfuscate.8.xml:79 @@ -12955,6 +12994,7 @@ msgstr "" #: sss_obfuscate.8.xml:86 msgid "<option>-f</option>,<option>--file</option> <replaceable>FILE</replaceable>" msgstr "" +"<option>-f</option>,<option>--file</option> <replaceable>ფაილი</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_obfuscate.8.xml:91 @@ -12964,12 +13004,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_obfuscate.8.xml:95 msgid "Default: <filename>/etc/sssd/sssd.conf</filename>" -msgstr "" +msgstr "ნაგულისხმევი: <filename>/etc/sssd/sssd.conf</filename>" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_override.8.xml:10 sss_override.8.xml:15 msgid "sss_override" -msgstr "" +msgstr "sss_override" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_override.8.xml:16 @@ -13050,7 +13090,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:86 msgid "<option>user-del</option> <emphasis>NAME</emphasis>" -msgstr "" +msgstr "<option>user-del</option> <emphasis>სახელი</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:91 @@ -13066,6 +13106,8 @@ msgid "" "<option>user-find</option> <optional><option>-d,--domain</option> " "DOMAIN</optional>" msgstr "" +"<option>user-find</option> <optional><option>-d,--domain</option> დომენი</" +"optional>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:105 @@ -13087,7 +13129,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:124 msgid "<option>user-import</option> <emphasis>FILE</emphasis>" -msgstr "" +msgstr "<option>user-import</option> <emphasis>ფაილი</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:129 @@ -13099,7 +13141,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:134 msgid "original_name:name:uid:gid:gecos:home:shell:base64_encoded_certificate" -msgstr "" +msgstr "original_name:name:uid:gid:gecos:home:shell:base64_encoded_certificate" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:137 @@ -13112,17 +13154,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:146 msgid "ckent:superman::::::" -msgstr "" +msgstr "ckent:superman::::::" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:149 msgid "ckent@krypton.com::501:501:Superman:/home/earth:/bin/bash:" -msgstr "" +msgstr "ckent@krypton.com::501:501:Superman:/home/earth:/bin/bash:" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:155 msgid "<option>user-export</option> <emphasis>FILE</emphasis>" -msgstr "" +msgstr "<option>user-export</option> <emphasis>ფაილი</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:160 @@ -13150,7 +13192,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:183 msgid "<option>group-del</option> <emphasis>NAME</emphasis>" -msgstr "" +msgstr "<option>group-del</option> <emphasis>სახელი</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:188 @@ -13166,6 +13208,8 @@ msgid "" "<option>group-find</option> <optional><option>-d,--domain</option> " "DOMAIN</optional>" msgstr "" +"<option>group-find</option> <optional><option>-d,--domain</option> დომენი</" +"optional>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:202 @@ -13177,7 +13221,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:210 msgid "<option>group-show</option> <emphasis>NAME</emphasis>" -msgstr "" +msgstr "<option>group-show</option> <emphasis>სახელი</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:215 @@ -13187,7 +13231,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:221 msgid "<option>group-import</option> <emphasis>FILE</emphasis>" -msgstr "" +msgstr "<option>group-import</option> <emphasis>ფაილი</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:226 @@ -13199,7 +13243,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:231 msgid "original_name:name:gid" -msgstr "" +msgstr "original_name:name:gid" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:234 @@ -13212,17 +13256,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:243 msgid "admins:administrators:" -msgstr "" +msgstr "admins:administrators:" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:246 msgid "Domain Users:Users:501" -msgstr "" +msgstr "Domain Users:Users:501" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:252 msgid "<option>group-export</option> <emphasis>FILE</emphasis>" -msgstr "" +msgstr "<option>group-export</option> <emphasis>ფაილი</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:257 @@ -13240,17 +13284,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para> #: sss_override.8.xml:269 sssctl.8.xml:52 msgid "Those options are available with all commands." -msgstr "" +msgstr "ეს პარამეტრები ხელმისაწვდომია ყველა ბრძანებისთვის." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:274 sssctl.8.xml:57 msgid "<option>--debug</option> <replaceable>LEVEL</replaceable>" -msgstr "" +msgstr "<option>--debug</option> <replaceable>დონე</replaceable>" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-krb5.5.xml:10 sssd-krb5.5.xml:16 msgid "sssd-krb5" -msgstr "" +msgstr "sssd-krb5" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-krb5.5.xml:17 @@ -13323,7 +13367,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:113 msgid "krb5_kpasswd, krb5_backup_kpasswd (string)" -msgstr "" +msgstr "krb5_kpasswd, krb5_backup_kpasswd (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:116 @@ -13350,7 +13394,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:135 msgid "krb5_ccachedir (string)" -msgstr "" +msgstr "krb5_ccachedir (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:138 @@ -13363,17 +13407,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:145 msgid "Default: /tmp" -msgstr "" +msgstr "ნაგულისხმევი: /tmp" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:151 msgid "krb5_ccname_template (string)" -msgstr "" +msgstr "krb5_ccname_template (სტრიქონი)" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:165 include/override_homedir.xml:11 msgid "%u" -msgstr "" +msgstr "%u" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:166 include/override_homedir.xml:12 @@ -13383,7 +13427,7 @@ msgstr "" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:169 include/override_homedir.xml:15 msgid "%U" -msgstr "" +msgstr "%U" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:170 @@ -13393,37 +13437,37 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:173 msgid "%p" -msgstr "" +msgstr "%p" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:174 msgid "principal name" -msgstr "" +msgstr "პრინციპალის სახელი" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:178 msgid "%r" -msgstr "" +msgstr "%r" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:179 msgid "realm name" -msgstr "" +msgstr "რეალმის სახელი" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:182 include/override_homedir.xml:53 msgid "%h" -msgstr "" +msgstr "%h" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:183 sssd-ifp.5.xml:124 msgid "home directory" -msgstr "" +msgstr "საწყისი საქაღალდე" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:187 include/override_homedir.xml:19 msgid "%d" -msgstr "" +msgstr "%d" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:188 @@ -13433,7 +13477,7 @@ msgstr "" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:193 include/override_homedir.xml:31 msgid "%P" -msgstr "" +msgstr "%P" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:194 @@ -13443,7 +13487,7 @@ msgstr "" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:199 include/override_homedir.xml:68 msgid "%%" -msgstr "" +msgstr "%%" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:200 include/override_homedir.xml:69 @@ -13494,12 +13538,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:234 msgid "Default: (from libkrb5)" -msgstr "" +msgstr "ნაგულისხმევი: (libkrb5-დან)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:240 msgid "krb5_keytab (string)" -msgstr "" +msgstr "krb5_keytab (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:243 @@ -13511,7 +13555,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:253 msgid "krb5_store_password_if_offline (boolean)" -msgstr "" +msgstr "krb5_store_password_if_offline (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:256 @@ -13531,7 +13575,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:274 msgid "krb5_use_fast (string)" -msgstr "" +msgstr "krb5_use_fast (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:277 @@ -13582,7 +13626,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:312 msgid "krb5_fast_principal (string)" -msgstr "" +msgstr "krb5_fast_principal (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:315 @@ -13592,7 +13636,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:321 msgid "krb5_fast_use_anonymous_pkinit (boolean)" -msgstr "" +msgstr "krb5_fast_use_anonymous_pkinit (ლოდიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:324 @@ -13605,7 +13649,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:364 msgid "krb5_kdcinfo_lookahead (string)" -msgstr "" +msgstr "krb5_kdcinfo_lookahead (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:367 @@ -13637,12 +13681,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:392 msgid "Default: 3:1" -msgstr "" +msgstr "ნაგულისხმევი: 3:1" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:398 msgid "krb5_use_enterprise_principal (boolean)" -msgstr "" +msgstr "krb5_use_enterprise_principal (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:401 @@ -13668,7 +13712,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:419 msgid "krb5_use_subdomain_realm (boolean)" -msgstr "" +msgstr "krb5_use_subdomain_realm (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:422 @@ -13683,7 +13727,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:438 msgid "krb5_map_user (string)" -msgstr "" +msgstr "krb5_map_user (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:441 @@ -13746,7 +13790,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_cache.8.xml:10 sss_cache.8.xml:15 msgid "sss_cache" -msgstr "" +msgstr "sss_cache" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_cache.8.xml:16 @@ -13759,6 +13803,8 @@ msgid "" "<command>sss_cache</command> <arg choice='opt'> " "<replaceable>options</replaceable> </arg>" msgstr "" +"<command>sss_cache</command> <arg choice='opt'> <replaceable>პარამეტრები</" +"replaceable> </arg>" #. type: Content of: <reference><refentry><refsect1><para> #: sss_cache.8.xml:31 @@ -13772,7 +13818,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:43 msgid "<option>-E</option>,<option>--everything</option>" -msgstr "" +msgstr "<option>-E</option>,<option>--everything</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:47 @@ -13783,6 +13829,8 @@ msgstr "" #: sss_cache.8.xml:53 msgid "<option>-u</option>,<option>--user</option> <replaceable>login</replaceable>" msgstr "" +"<option>-u</option>,<option>--user</option> <replaceable>მომხმარებლისსახელი</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:58 @@ -13792,7 +13840,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:64 msgid "<option>-U</option>,<option>--users</option>" -msgstr "" +msgstr "<option>-U</option>,<option>--users</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:68 @@ -13807,6 +13855,7 @@ msgid "" "<option>-g</option>,<option>--group</option> " "<replaceable>group</replaceable>" msgstr "" +"<option>-g</option>,<option>--group</option> <replaceable>ჯგუფი</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:80 @@ -13816,7 +13865,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:86 msgid "<option>-G</option>,<option>--groups</option>" -msgstr "" +msgstr "<option>-G</option>,<option>--groups</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:90 @@ -13831,6 +13880,8 @@ msgid "" "<option>-n</option>,<option>--netgroup</option> " "<replaceable>netgroup</replaceable>" msgstr "" +"<option>-n</option>,<option>--netgroup</option> <replaceable>ქსელურჯგუფი</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:102 @@ -13840,7 +13891,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:108 msgid "<option>-N</option>,<option>--netgroups</option>" -msgstr "" +msgstr "<option>-N</option>,<option>--netgroups</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:112 @@ -13855,6 +13906,8 @@ msgid "" "<option>-s</option>,<option>--service</option> " "<replaceable>service</replaceable>" msgstr "" +"<option>-s</option>,<option>--service</option> <replaceable>სერვისი</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:124 @@ -13864,7 +13917,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:130 msgid "<option>-S</option>,<option>--services</option>" -msgstr "" +msgstr "<option>-S</option>,<option>--services</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:134 @@ -13888,7 +13941,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:152 msgid "<option>-A</option>,<option>--autofs-maps</option>" -msgstr "" +msgstr "<option>-A</option>,<option>--autofs-maps</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:156 @@ -13903,6 +13956,8 @@ msgid "" "<option>-h</option>,<option>--ssh-host</option> " "<replaceable>hostname</replaceable>" msgstr "" +"<option>-h</option>,<option>--ssh-host</option> <replaceable>ჰოსტისსახელი</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:168 @@ -13912,7 +13967,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:174 msgid "<option>-H</option>,<option>--ssh-hosts</option>" -msgstr "" +msgstr "<option>-H</option>,<option>--ssh-hosts</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:178 @@ -13936,7 +13991,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:197 msgid "<option>-R</option>,<option>--sudo-rules</option>" -msgstr "" +msgstr "<option>-R</option>,<option>--sudo-rules</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:201 @@ -13951,6 +14006,8 @@ msgid "" "<option>-d</option>,<option>--domain</option> " "<replaceable>domain</replaceable>" msgstr "" +"<option>-d</option>,<option>--domain</option> <replaceable>დომენი</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:214 @@ -14007,7 +14064,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_debuglevel.8.xml:10 sss_debuglevel.8.xml:15 msgid "sss_debuglevel" -msgstr "" +msgstr "sss_debuglevel" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_debuglevel.8.xml:16 @@ -14033,7 +14090,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_seed.8.xml:10 sss_seed.8.xml:15 msgid "sss_seed" -msgstr "" +msgstr "sss_seed" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_seed.8.xml:16 @@ -14092,6 +14149,7 @@ msgstr "" #: sss_seed.8.xml:76 msgid "<option>-u</option>,<option>--uid</option> <replaceable>UID</replaceable>" msgstr "" +"<option>-u</option>,<option>--uid</option> <replaceable>UID</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_seed.8.xml:81 @@ -14102,6 +14160,7 @@ msgstr "" #: sss_seed.8.xml:88 msgid "<option>-g</option>,<option>--gid</option> <replaceable>GID</replaceable>" msgstr "" +"<option>-g</option>,<option>--gid</option> <replaceable>GID</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_seed.8.xml:93 @@ -14114,6 +14173,8 @@ msgid "" "<option>-c</option>,<option>--gecos</option> " "<replaceable>COMMENT</replaceable>" msgstr "" +"<option>-c</option>,<option>--gecos</option> <replaceable>კომენტარი</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_seed.8.xml:105 @@ -14178,7 +14239,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-ifp.5.xml:10 sssd-ifp.5.xml:16 msgid "sssd-ifp" -msgstr "" +msgstr "sssd-ifp" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-ifp.5.xml:17 @@ -14219,17 +14280,17 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ifp.5.xml:48 sss_ssh_authorizedkeys.1.xml:92 msgid "ca_db" -msgstr "" +msgstr "ca_db" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ifp.5.xml:49 sss_ssh_authorizedkeys.1.xml:93 msgid "p11_child_timeout" -msgstr "" +msgstr "p11_child_timeout" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ifp.5.xml:50 sss_ssh_authorizedkeys.1.xml:94 msgid "certificate_verification" -msgstr "" +msgstr "certificate_verification" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd-ifp.5.xml:52 @@ -14274,7 +14335,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-ifp.5.xml:107 msgid "name" -msgstr "" +msgstr "name" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:108 @@ -14284,7 +14345,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-ifp.5.xml:111 msgid "uidNumber" -msgstr "" +msgstr "uidNumber" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:112 @@ -14294,7 +14355,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-ifp.5.xml:115 msgid "gidNumber" -msgstr "" +msgstr "gidNumber" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:116 @@ -14304,7 +14365,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-ifp.5.xml:119 msgid "gecos" -msgstr "" +msgstr "gecos" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:120 @@ -14314,12 +14375,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-ifp.5.xml:123 msgid "homeDirectory" -msgstr "" +msgstr "homeDirectory" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-ifp.5.xml:127 msgid "loginShell" -msgstr "" +msgstr "loginShell" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:128 @@ -14386,7 +14447,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_rpcidmapd.5.xml:26 sss_rpcidmapd.5.xml:32 msgid "sss_rpcidmapd" -msgstr "" +msgstr "sss_rpcidmapd" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_rpcidmapd.5.xml:33 @@ -14396,7 +14457,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sss_rpcidmapd.5.xml:37 msgid "CONFIGURATION FILE" -msgstr "" +msgstr "კონფიგურაციის ფაილი" #. type: Content of: <reference><refentry><refsect1><para> #: sss_rpcidmapd.5.xml:39 @@ -14445,7 +14506,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sss_rpcidmapd.5.xml:69 msgid "memcache (bool)" -msgstr "" +msgstr "memcache (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sss_rpcidmapd.5.xml:72 @@ -14500,7 +14561,7 @@ msgstr "" #. type: Content of: <refsect1><title> #: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:316 include/seealso.xml:2 msgid "SEE ALSO" -msgstr "" +msgstr "ასევე იხილეთ" #. type: Content of: <reference><refentry><refsect1><para> #: sss_rpcidmapd.5.xml:122 @@ -14513,7 +14574,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_ssh_authorizedkeys.1.xml:10 sss_ssh_authorizedkeys.1.xml:15 msgid "sss_ssh_authorizedkeys" -msgstr "" +msgstr "sss_ssh_authorizedkeys" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_ssh_authorizedkeys.1.xml:16 @@ -14655,7 +14716,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_ssh_knownhosts.1.xml:10 sss_ssh_knownhosts.1.xml:15 msgid "sss_ssh_knownhosts" -msgstr "" +msgstr "sss_ssh_knownhosts" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_ssh_knownhosts.1.xml:16 @@ -14715,7 +14776,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_ssh_knownhosts.1.xml:75 msgid "<option>-o</option>,<option>--only-host-name</option>" -msgstr "" +msgstr "<option>-o</option>,<option>--only-host-name</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_ssh_knownhosts.1.xml:79 @@ -14773,7 +14834,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: idmap_sss.8.xml:10 idmap_sss.8.xml:15 msgid "idmap_sss" -msgstr "" +msgstr "idmap_sss" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: idmap_sss.8.xml:16 @@ -14845,7 +14906,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssctl.8.xml:10 sssctl.8.xml:15 msgid "sssctl" -msgstr "" +msgstr "sssctl" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssctl.8.xml:16 @@ -14881,7 +14942,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-session-recording.5.xml:10 sssd-session-recording.5.xml:16 msgid "sssd-session-recording" -msgstr "" +msgstr "sssd-session-recording" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-session-recording.5.xml:17 @@ -14946,7 +15007,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-kcm.8.xml:10 sssd-kcm.8.xml:16 msgid "sssd-kcm" -msgstr "" +msgstr "sssd-kcm" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-kcm.8.xml:17 @@ -15109,6 +15170,9 @@ msgid "" "debug_level = 10\n" " " msgstr "" +"[kcm]\n" +"debug_level = 10\n" +" " #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-kcm.8.xml:149 sssd-kcm.8.xml:211 @@ -15117,6 +15181,8 @@ msgid "" "systemctl restart sssd-kcm.service\n" " " msgstr "" +"systemctl restart sssd-kcm.service\n" +" " #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:135 @@ -15146,7 +15212,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-kcm.8.xml:166 msgid "RENEWALS" -msgstr "" +msgstr "განახლებები" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-kcm.8.xml:174 @@ -15234,7 +15300,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-kcm.8.xml:234 msgid "socket_path (string)" -msgstr "" +msgstr "socket_path (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:237 @@ -15245,6 +15311,7 @@ msgstr "" #: sssd-kcm.8.xml:240 msgid "Default: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" msgstr "" +"ნაგულისხმევი: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:243 @@ -15257,7 +15324,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-kcm.8.xml:252 msgid "max_ccaches (integer)" -msgstr "" +msgstr "max_ccaches (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:255 @@ -15272,7 +15339,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-kcm.8.xml:264 msgid "max_uid_ccaches (integer)" -msgstr "" +msgstr "max_uid_ccaches (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:267 @@ -15284,12 +15351,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:272 msgid "Default: 64" -msgstr "" +msgstr "ნაგულისხმევი: 64" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-kcm.8.xml:277 msgid "max_ccache_size (integer)" -msgstr "" +msgstr "max_ccache_size (მთელი რიცხვი)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:280 @@ -15301,12 +15368,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:284 msgid "Default: 65536" -msgstr "" +msgstr "ნაგულისხმევი: 65536" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-kcm.8.xml:289 msgid "tgt_renewal (bool)" -msgstr "" +msgstr "tgt_renewal (ლოგიკური)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:292 @@ -15321,7 +15388,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-kcm.8.xml:300 msgid "tgt_renewal_inherit (string)" -msgstr "" +msgstr "tgt_renewal_inherit (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:303 @@ -15331,7 +15398,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:307 msgid "Default: NULL" -msgstr "" +msgstr "ნაგულისხმევი: NULL" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:318 @@ -15345,12 +15412,12 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-systemtap.5.xml:10 sssd-systemtap.5.xml:16 msgid "sssd-systemtap" -msgstr "" +msgstr "sssd-systemtap" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-systemtap.5.xml:17 msgid "SSSD systemtap information" -msgstr "" +msgstr "SSSD systemtap-ის ინფორმაცია" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-systemtap.5.xml:23 @@ -15383,7 +15450,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-systemtap.5.xml:57 msgid "PROBE POINTS" -msgstr "" +msgstr "ზონდირების წერტილები" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd-systemtap.5.xml:59 sssd-systemtap.5.xml:367 @@ -15640,6 +15707,8 @@ msgid "" "filter:string\n" " " msgstr "" +"filter:სტრიქონი\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:288 @@ -15787,7 +15856,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:422 msgid "dp_request.stp" -msgstr "" +msgstr "dp_request.stp" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:425 @@ -15797,7 +15866,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:430 msgid "id_perf.stp" -msgstr "" +msgstr "id_perf.stp" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:433 @@ -15807,7 +15876,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:439 msgid "ldap_perf.stp" -msgstr "" +msgstr "ldap_perf.stp" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:442 @@ -15817,7 +15886,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:447 msgid "nested_group_perf.stp" -msgstr "" +msgstr "nested_group_perf.stp" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:450 @@ -15827,7 +15896,7 @@ msgstr "" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-ldap-attributes.5.xml:10 sssd-ldap-attributes.5.xml:16 msgid "sssd-ldap-attributes" -msgstr "" +msgstr "sssd-ldap-attributes" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-ldap-attributes.5.xml:17 @@ -15853,7 +15922,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:42 msgid "ldap_user_object_class (string)" -msgstr "" +msgstr "ldap_user_object_class (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:45 @@ -15863,12 +15932,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:48 msgid "Default: posixAccount" -msgstr "" +msgstr "ნაგულისხმევი: posixAccount" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:54 msgid "ldap_user_name (string)" -msgstr "" +msgstr "ldap_user_name (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:57 @@ -15883,7 +15952,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:68 msgid "ldap_user_uid_number (string)" -msgstr "" +msgstr "ldap_user_uid_number (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:71 @@ -15893,12 +15962,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:75 msgid "Default: uidNumber" -msgstr "" +msgstr "ნაგულისხმევი: uidNumber" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:81 msgid "ldap_user_gid_number (string)" -msgstr "" +msgstr "ldap_user_gid_number (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:84 @@ -15908,12 +15977,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:88 sssd-ldap-attributes.5.xml:700 msgid "Default: gidNumber" -msgstr "" +msgstr "ნაგულისხმევი: gidNumber" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:94 msgid "ldap_user_primary_group (string)" -msgstr "" +msgstr "ldap_user_primary_group (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:97 @@ -15931,7 +16000,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:109 msgid "ldap_user_gecos (string)" -msgstr "" +msgstr "ldap_user_gecos (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:112 @@ -15941,12 +16010,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:116 msgid "Default: gecos" -msgstr "" +msgstr "ნაგულისხმევი: gecos" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:122 msgid "ldap_user_home_directory (string)" -msgstr "" +msgstr "ldap_user_home_directory (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:125 @@ -15961,7 +16030,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:135 msgid "ldap_user_shell (string)" -msgstr "" +msgstr "ldap_user_shell (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:138 @@ -15971,12 +16040,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:142 msgid "Default: loginShell" -msgstr "" +msgstr "ნაგულისხმევი: loginShell" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:148 msgid "ldap_user_uuid (string)" -msgstr "" +msgstr "ldap_user_uuid (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:151 @@ -15993,7 +16062,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:162 msgid "ldap_user_objectsid (string)" -msgstr "" +msgstr "ldap_user_objectsid (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:165 @@ -16010,7 +16079,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:177 msgid "ldap_user_modify_timestamp (string)" -msgstr "" +msgstr "ldap_user_modify_timestamp (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:180 sssd-ldap-attributes.5.xml:751 @@ -16024,12 +16093,12 @@ msgstr "" #: sssd-ldap-attributes.5.xml:184 sssd-ldap-attributes.5.xml:755 #: sssd-ldap-attributes.5.xml:881 msgid "Default: modifyTimestamp" -msgstr "" +msgstr "ნაგულისხმევი: modifyTimestamp" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:190 msgid "ldap_user_shadow_last_change (string)" -msgstr "" +msgstr "ldap_user_shadow_last_change (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:193 @@ -16043,12 +16112,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:203 msgid "Default: shadowLastChange" -msgstr "" +msgstr "ნაგულისხმევი: shadowLastChange" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:209 msgid "ldap_user_shadow_min (string)" -msgstr "" +msgstr "ldap_user_shadow_min (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:212 @@ -16062,12 +16131,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:221 msgid "Default: shadowMin" -msgstr "" +msgstr "ნაგულისხმევი: shadowMin" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:227 msgid "ldap_user_shadow_max (string)" -msgstr "" +msgstr "ldap_user_shadow_max (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:230 @@ -16081,12 +16150,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:239 msgid "Default: shadowMax" -msgstr "" +msgstr "ნაგულისხმევი: shadowMax" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:245 msgid "ldap_user_shadow_warning (string)" -msgstr "" +msgstr "ldap_user_shadow_warning (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:248 @@ -16100,12 +16169,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:258 msgid "Default: shadowWarning" -msgstr "" +msgstr "ნაგულისხმევი: shadowWarning" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:264 msgid "ldap_user_shadow_inactive (string)" -msgstr "" +msgstr "ldap_user_shadow_inactive (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:267 @@ -16119,12 +16188,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:277 msgid "Default: shadowInactive" -msgstr "" +msgstr "ნაგულისხმევი: shadowInactive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:283 msgid "ldap_user_shadow_expire (string)" -msgstr "" +msgstr "ldap_user_shadow_expire (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:286 @@ -16139,12 +16208,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:296 msgid "Default: shadowExpire" -msgstr "" +msgstr "ნაგულისხმევი: shadowExpire" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:302 msgid "ldap_user_krb_last_pwd_change (string)" -msgstr "" +msgstr "ldap_user_krb_last_pwd_change (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:305 @@ -16157,12 +16226,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:311 msgid "Default: krbLastPwdChange" -msgstr "" +msgstr "ნაგულისხმევი: krbLastPwdChange" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:317 msgid "ldap_user_krb_password_expiration (string)" -msgstr "" +msgstr "ldap_user_krb_password_expiration (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:320 @@ -16174,12 +16243,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:326 msgid "Default: krbPasswordExpiration" -msgstr "" +msgstr "ნაგულისხმევი: krbPasswordExpiration" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:332 msgid "ldap_user_ad_account_expires (string)" -msgstr "" +msgstr "ldap_user_ad_account_expires (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:335 @@ -16191,12 +16260,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:340 msgid "Default: accountExpires" -msgstr "" +msgstr "ნაგულისხმევი: accountExpires" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:346 msgid "ldap_user_ad_user_account_control (string)" -msgstr "" +msgstr "ldap_user_ad_user_account_control (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:349 @@ -16208,12 +16277,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:354 msgid "Default: userAccountControl" -msgstr "" +msgstr "ნაგულისხმევი: userAccountControl" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:360 msgid "ldap_ns_account_lock (string)" -msgstr "" +msgstr "ldap_ns_account_lock (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:363 @@ -16225,12 +16294,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:368 msgid "Default: nsAccountLock" -msgstr "" +msgstr "ნაგულისხმევი: nsAccountLock" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:374 msgid "ldap_user_nds_login_disabled (string)" -msgstr "" +msgstr "ldap_user_nds_login_disabled (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:377 @@ -16242,12 +16311,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:381 sssd-ldap-attributes.5.xml:395 msgid "Default: loginDisabled" -msgstr "" +msgstr "ნაგულისხმევი: loginDisabled" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:387 msgid "ldap_user_nds_login_expiration_time (string)" -msgstr "" +msgstr "ldap_user_nds_login_expiration_time (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:390 @@ -16259,7 +16328,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:401 msgid "ldap_user_nds_login_allowed_time_map (string)" -msgstr "" +msgstr "ldap_user_nds_login_allowed_time_map (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:404 @@ -16271,12 +16340,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:409 msgid "Default: loginAllowedTimeMap" -msgstr "" +msgstr "ნაგულისხმევი: loginAllowedTimeMap" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:415 msgid "ldap_user_principal (string)" -msgstr "" +msgstr "ldap_user_principal (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:418 @@ -16288,12 +16357,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:422 msgid "Default: krbPrincipalName" -msgstr "" +msgstr "ნაგულისხმევი: krbPrincipalName" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:428 msgid "ldap_user_extra_attrs (string)" -msgstr "" +msgstr "ldap_user_extra_attrs (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:431 @@ -16324,7 +16393,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:456 msgid "ldap_user_extra_attrs = telephoneNumber" -msgstr "" +msgstr "ldap_user_extra_attrs = telephoneNumber" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:459 @@ -16336,7 +16405,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:463 msgid "ldap_user_extra_attrs = phone:telephoneNumber" -msgstr "" +msgstr "ldap_user_extra_attrs = phone:telephoneNumber" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:466 @@ -16348,7 +16417,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:476 msgid "ldap_user_ssh_public_key (string)" -msgstr "" +msgstr "ldap_user_ssh_public_key (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:479 @@ -16358,12 +16427,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:483 sssd-ldap-attributes.5.xml:965 msgid "Default: sshPublicKey" -msgstr "" +msgstr "ნაგულისხმევი: sshPublicKey" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:489 msgid "ldap_user_fullname (string)" -msgstr "" +msgstr "ldap_user_fullname (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:492 @@ -16373,7 +16442,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:502 msgid "ldap_user_member_of (string)" -msgstr "" +msgstr "ldap_user_member_of (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:505 @@ -16383,12 +16452,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:509 sssd-ldap-attributes.5.xml:952 msgid "Default: memberOf" -msgstr "" +msgstr "ნაგულისხმევი: memberOf" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:515 msgid "ldap_user_authorized_service (string)" -msgstr "" +msgstr "ldap_user_authorized_service (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:518 @@ -16426,12 +16495,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:545 msgid "Default: authorizedService" -msgstr "" +msgstr "ნაგულისხმევი: authorizedService" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:551 msgid "ldap_user_authorized_host (string)" -msgstr "" +msgstr "ldap_user_authorized_host (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:554 @@ -16459,12 +16528,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:572 msgid "Default: host" -msgstr "" +msgstr "ნაგულისხმევი: host" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:578 msgid "ldap_user_authorized_rhost (string)" -msgstr "" +msgstr "ldap_user_authorized_rhost (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:581 @@ -16492,12 +16561,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:600 msgid "Default: rhost" -msgstr "" +msgstr "ნაგულისხმევი: rhost" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:606 msgid "ldap_user_certificate (string)" -msgstr "" +msgstr "ldap_user_certificate (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:609 @@ -16507,12 +16576,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:613 msgid "Default: userCertificate;binary" -msgstr "" +msgstr "ნაგულისხმევი: userCertificate;binary" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:619 msgid "ldap_user_email (string)" -msgstr "" +msgstr "ldap_user_email (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:622 @@ -16533,12 +16602,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:637 msgid "Default: mail" -msgstr "" +msgstr "ნაგულისხმევი: mail" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:642 msgid "ldap_user_passkey (string)" -msgstr "" +msgstr "ldap_user_passkey (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:645 @@ -16558,7 +16627,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:663 msgid "ldap_group_object_class (string)" -msgstr "" +msgstr "ldap_group_object_class (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:666 @@ -16568,12 +16637,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:669 msgid "Default: posixGroup" -msgstr "" +msgstr "ნაგულისხმევი: posixGroup" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:675 msgid "ldap_group_name (string)" -msgstr "" +msgstr "ldap_group_name (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:678 @@ -16587,12 +16656,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:686 msgid "Default: cn (rfc2307, rfc2307bis and IPA), sAMAccountName (AD)" -msgstr "" +msgstr "ნაგულისხმევი: cn (rfc2307, rfc2307bis და IPA), sAMAccountName (AD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:693 msgid "ldap_group_gid_number (string)" -msgstr "" +msgstr "ldap_group_gid_number (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:696 @@ -16602,7 +16671,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:706 msgid "ldap_group_member (string)" -msgstr "" +msgstr "ldap_group_member (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:709 @@ -16612,12 +16681,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:713 msgid "Default: memberuid (rfc2307) / member (rfc2307bis)" -msgstr "" +msgstr "ნაგულისხმევი: memberuid (rfc2307) / member (rfc2307bis)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:719 msgid "ldap_group_uuid (string)" -msgstr "" +msgstr "ldap_group_uuid (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:722 @@ -16627,7 +16696,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:733 msgid "ldap_group_objectsid (string)" -msgstr "" +msgstr "ldap_group_objectsid (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:736 @@ -16639,12 +16708,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:748 msgid "ldap_group_modify_timestamp (string)" -msgstr "" +msgstr "ldap_group_modify_timestamp (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:761 msgid "ldap_group_type (string)" -msgstr "" +msgstr "ldap_group_type (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:764 @@ -16669,7 +16738,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:782 msgid "ldap_group_external_member (string)" -msgstr "" +msgstr "ldap_group_external_member (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:785 @@ -16691,7 +16760,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:805 msgid "ldap_netgroup_object_class (string)" -msgstr "" +msgstr "ldap_netgroup_object_class (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:808 @@ -16706,12 +16775,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:815 msgid "Default: nisNetgroup" -msgstr "" +msgstr "ნაგულისხმევი: nisNetgroup" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:821 msgid "ldap_netgroup_name (string)" -msgstr "" +msgstr "ldap_netgroup_name (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:824 @@ -16726,7 +16795,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:838 msgid "ldap_netgroup_member (string)" -msgstr "" +msgstr "ldap_netgroup_member (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:841 @@ -16741,12 +16810,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:849 msgid "Default: memberNisNetgroup" -msgstr "" +msgstr "ნაგულისხმევი: memberNisNetgroup" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:855 msgid "ldap_netgroup_triple (string)" -msgstr "" +msgstr "ldap_netgroup_triple (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:858 @@ -16761,12 +16830,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:865 msgid "Default: nisNetgroupTriple" -msgstr "" +msgstr "ნაგულისხმევი: nisNetgroupTriple" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:871 msgid "ldap_netgroup_modify_timestamp (string)" -msgstr "" +msgstr "ldap_netgroup_modify_timestamp (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap-attributes.5.xml:890 @@ -16776,7 +16845,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:894 msgid "ldap_host_object_class (string)" -msgstr "" +msgstr "ldap_host_object_class (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:897 @@ -16786,12 +16855,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:997 msgid "Default: ipService" -msgstr "" +msgstr "ნაგულისხმევი: ipService" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:906 msgid "ldap_host_name (string)" -msgstr "" +msgstr "ldap_host_name (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:909 sssd-ldap-attributes.5.xml:935 @@ -16801,7 +16870,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:919 msgid "ldap_host_fqdn (string)" -msgstr "" +msgstr "ldap_host_fqdn (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:922 @@ -16813,22 +16882,22 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:926 msgid "Default: fqdn" -msgstr "" +msgstr "ნაგულისხმევი: fqdn" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:932 msgid "ldap_host_serverhostname (string)" -msgstr "" +msgstr "ldap_host_serverhostname (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:939 msgid "Default: serverHostname" -msgstr "" +msgstr "ნაგულისხმევი: serverHostname" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:945 msgid "ldap_host_member_of (string)" -msgstr "" +msgstr "ldap_host_member_of (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:948 @@ -16838,7 +16907,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:958 msgid "ldap_host_ssh_public_key (string)" -msgstr "" +msgstr "ldap_host_ssh_public_key (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:961 @@ -16848,7 +16917,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:971 msgid "ldap_host_uuid (string)" -msgstr "" +msgstr "ldap_host_uuid (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:974 @@ -16863,7 +16932,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:991 msgid "ldap_service_object_class (string)" -msgstr "" +msgstr "ldap_service_object_class (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:994 @@ -16873,7 +16942,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1003 msgid "ldap_service_name (string)" -msgstr "" +msgstr "ldap_service_name (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1006 @@ -16885,7 +16954,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1016 msgid "ldap_service_port (string)" -msgstr "" +msgstr "ldap_service_port (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1019 @@ -16895,12 +16964,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1023 msgid "Default: ipServicePort" -msgstr "" +msgstr "ნაგულისხმევი: ipServicePort" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1029 msgid "ldap_service_proto (string)" -msgstr "" +msgstr "ldap_service_proto (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1032 @@ -16910,7 +16979,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1036 msgid "Default: ipServiceProtocol" -msgstr "" +msgstr "ნაგულისხმევი: ipServiceProtocol" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap-attributes.5.xml:1045 @@ -16920,7 +16989,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1049 msgid "ldap_sudorule_object_class (string)" -msgstr "" +msgstr "ldap_sudorule_object_class (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1052 @@ -16930,12 +16999,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1055 msgid "Default: sudoRole" -msgstr "" +msgstr "ნაგულისხმევი: sudoRole" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1061 msgid "ldap_sudorule_name (string)" -msgstr "" +msgstr "ldap_sudorule_name (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1064 @@ -16945,7 +17014,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1074 msgid "ldap_sudorule_command (string)" -msgstr "" +msgstr "ldap_sudorule_command (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1077 @@ -16955,12 +17024,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1081 msgid "Default: sudoCommand" -msgstr "" +msgstr "ნაგულისხმევი: sudoCommand" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1087 msgid "ldap_sudorule_host (string)" -msgstr "" +msgstr "ldap_sudorule_host (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1090 @@ -16972,12 +17041,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1095 msgid "Default: sudoHost" -msgstr "" +msgstr "ნაგულისხმევი: sudoHost" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1101 msgid "ldap_sudorule_user (string)" -msgstr "" +msgstr "ldap_sudorule_user (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1104 @@ -16989,12 +17058,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1108 msgid "Default: sudoUser" -msgstr "" +msgstr "ნაგულისხმევი: sudoUser" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1114 msgid "ldap_sudorule_option (string)" -msgstr "" +msgstr "ldap_sudorule_option (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1117 @@ -17004,12 +17073,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1121 msgid "Default: sudoOption" -msgstr "" +msgstr "ნაგულისხმევი: sudoOption" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1127 msgid "ldap_sudorule_runasuser (string)" -msgstr "" +msgstr "ldap_sudorule_runasuser (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1130 @@ -17021,12 +17090,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1134 msgid "Default: sudoRunAsUser" -msgstr "" +msgstr "ნაგულისხმევი: sudoRunAsUser" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1140 msgid "ldap_sudorule_runasgroup (string)" -msgstr "" +msgstr "ldap_sudorule_runasgroup (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1143 @@ -17038,12 +17107,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1147 msgid "Default: sudoRunAsGroup" -msgstr "" +msgstr "ნაგულისხმევი: sudoRunAsGroup" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1153 msgid "ldap_sudorule_notbefore (string)" -msgstr "" +msgstr "ldap_sudorule_notbefore (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1156 @@ -17055,12 +17124,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1160 msgid "Default: sudoNotBefore" -msgstr "" +msgstr "ნაგულისხმევი: sudoNotBefore" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1166 msgid "ldap_sudorule_notafter (string)" -msgstr "" +msgstr "ldap_sudorule_notafter (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1169 @@ -17072,12 +17141,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1174 msgid "Default: sudoNotAfter" -msgstr "" +msgstr "ნაგულისხმევი: sudoNotAfter" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1180 msgid "ldap_sudorule_order (string)" -msgstr "" +msgstr "ldap_sudorule_order (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1183 @@ -17087,7 +17156,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1187 msgid "Default: sudoOrder" -msgstr "" +msgstr "ნაგულისხმევი: sudoOrder" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap-attributes.5.xml:1196 @@ -17102,7 +17171,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1207 msgid "ldap_iphost_object_class (string)" -msgstr "" +msgstr "ldap_iphost_object_class (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1210 @@ -17112,12 +17181,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1213 msgid "Default: ipHost" -msgstr "" +msgstr "ნაგულისხმევი: ipHost" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1219 msgid "ldap_iphost_name (string)" -msgstr "" +msgstr "ldap_iphost_name (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1222 @@ -17129,7 +17198,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1232 msgid "ldap_iphost_number (string)" -msgstr "" +msgstr "ldap_iphost_number (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1235 @@ -17139,7 +17208,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1239 msgid "Default: ipHostNumber" -msgstr "" +msgstr "ნაგულისხმევი: ipHostNumber" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap-attributes.5.xml:1248 @@ -17149,7 +17218,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1252 msgid "ldap_ipnetwork_object_class (string)" -msgstr "" +msgstr "ldap_ipnetwork_object_class (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1255 @@ -17159,12 +17228,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1258 msgid "Default: ipNetwork" -msgstr "" +msgstr "ნაგულისხმევი: ipNetwork" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1264 msgid "ldap_ipnetwork_name (string)" -msgstr "" +msgstr "ldap_ipnetwork_name (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1267 @@ -17176,7 +17245,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1277 msgid "ldap_ipnetwork_number (string)" -msgstr "" +msgstr "ldap_ipnetwork_number (სტრიქონი)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1280 @@ -17186,12 +17255,12 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1284 msgid "Default: ipNetworkNumber" -msgstr "" +msgstr "ნაგულისხმევი: ipNetworkNumber" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd_krb5_localauth_plugin.8.xml:10 sssd_krb5_localauth_plugin.8.xml:15 msgid "sssd_krb5_localauth_plugin" -msgstr "" +msgstr "sssd_krb5_localauth_plugin" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd_krb5_localauth_plugin.8.xml:16 @@ -17230,7 +17299,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><title> #: sssd_krb5_localauth_plugin.8.xml:46 msgid "CONFIGURATION" -msgstr "" +msgstr "კონფიგურაცია" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd_krb5_localauth_plugin.8.xml:56 @@ -17258,7 +17327,7 @@ msgstr "" #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:3 msgid "ldap_autofs_map_object_class (string)" -msgstr "" +msgstr "ldap_autofs_map_object_class (სტრიქონი)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:6 @@ -17273,7 +17342,7 @@ msgstr "" #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:16 msgid "ldap_autofs_map_name (string)" -msgstr "" +msgstr "ldap_autofs_map_name (სტრიქონი)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:19 @@ -17290,7 +17359,7 @@ msgstr "" #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:29 msgid "ldap_autofs_entry_object_class (string)" -msgstr "" +msgstr "ldap_autofs_entry_object_class (სტრიქონი)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:32 @@ -17307,7 +17376,7 @@ msgstr "" #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:44 msgid "ldap_autofs_entry_key (string)" -msgstr "" +msgstr "ldap_autofs_entry_key (სტრიქონი)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:47 include/autofs_attributes.xml:61 @@ -17324,7 +17393,7 @@ msgstr "" #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:58 msgid "ldap_autofs_entry_value (string)" -msgstr "" +msgstr "ldap_autofs_entry_value (სტრიქონი)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:65 @@ -17336,7 +17405,7 @@ msgstr "" #. type: Content of: <refsect1><title> #: include/service_discovery.xml:2 msgid "SERVICE DISCOVERY" -msgstr "" +msgstr "სერვისის აღმოჩენა" #. type: Content of: <refsect1><para> #: include/service_discovery.xml:4 @@ -17349,7 +17418,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><title> #: include/service_discovery.xml:9 include/ldap_id_mapping.xml:99 msgid "Configuration" -msgstr "" +msgstr "კონფიგურაცია" #. type: Content of: <refsect1><refsect2><para> #: include/service_discovery.xml:11 @@ -17366,7 +17435,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><title> #: include/service_discovery.xml:23 msgid "The domain name" -msgstr "" +msgstr "დომენის სახელი" #. type: Content of: <refsect1><refsect2><para> #: include/service_discovery.xml:25 @@ -17379,7 +17448,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><title> #: include/service_discovery.xml:35 msgid "The protocol" -msgstr "" +msgstr "პროტოკოლი" #. type: Content of: <refsect1><refsect2><para> #: include/service_discovery.xml:37 @@ -17391,7 +17460,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><title> #: include/service_discovery.xml:42 msgid "See Also" -msgstr "" +msgstr "ასევე იხილეთ" #. type: Content of: <refsect1><refsect2><para> #: include/service_discovery.xml:44 @@ -17408,12 +17477,12 @@ msgstr "" #. type: Content of: outside any tag (error?) #: include/upstream.xml:1 msgid "<placeholder type=\"refentryinfo\" id=\"0\"/>" -msgstr "" +msgstr "<placeholder type=\"refentryinfo\" id=\"0\"/>" #. type: Content of: <refsect1><title> #: include/failover.xml:2 msgid "FAILOVER" -msgstr "" +msgstr "გადართვა გათიშვისას" #. type: Content of: <refsect1><para> #: include/failover.xml:4 @@ -17503,7 +17572,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><term> #: include/failover.xml:76 msgid "dns_resolver_server_timeout" -msgstr "" +msgstr "dns_resolver_server_timeout" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: include/failover.xml:80 @@ -17515,7 +17584,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><term> #: include/failover.xml:90 msgid "dns_resolver_op_timeout" -msgstr "" +msgstr "dns_resolver_op_timeout" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: include/failover.xml:94 @@ -17528,7 +17597,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><term> #: include/failover.xml:106 msgid "dns_resolver_timeout" -msgstr "" +msgstr "dns_resolver_timeout" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: include/failover.xml:110 @@ -17698,12 +17767,12 @@ msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><title> #: include/ldap_id_mapping.xml:117 msgid "Advanced Configuration" -msgstr "" +msgstr "დამატებითი პარამეტრები" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:120 msgid "ldap_idmap_range_min (integer)" -msgstr "" +msgstr "ldap_idmap_range_min (მთელი რიცხვი)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:123 @@ -17727,7 +17796,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:144 msgid "ldap_idmap_range_max (integer)" -msgstr "" +msgstr "ldap_idmap_range_max (მთელი რიცხვი)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:147 @@ -17752,7 +17821,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:170 msgid "ldap_idmap_range_size (integer)" -msgstr "" +msgstr "ldap_idmap_range_size (მთელი რიცხვი)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:173 @@ -17790,7 +17859,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:202 msgid "ldap_idmap_default_domain_sid (string)" -msgstr "" +msgstr "ldap_idmap_default_domain_sid (სტრიქონი)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:205 @@ -17803,7 +17872,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:216 msgid "ldap_idmap_default_domain (string)" -msgstr "" +msgstr "ldap_idmap_default_domain (სტრიქონი)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:219 @@ -17813,7 +17882,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:227 msgid "ldap_idmap_autorid_compat (boolean)" -msgstr "" +msgstr "ldap_idmap_autorid_compat (ლოგიკური)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:230 @@ -17842,7 +17911,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:255 msgid "ldap_idmap_helper_table_size (integer)" -msgstr "" +msgstr "ldap_idmap_helper_table_size (მთელი რიცხვი)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:258 @@ -17919,7 +17988,7 @@ msgstr "" #. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> #: include/ldap_id_mapping.xml:297 msgid "Built-in" -msgstr "" +msgstr "ჩაშენებული" #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:299 @@ -17945,7 +18014,7 @@ msgstr "" #. type: Content of: <varlistentry><term> #: include/param_help.xml:3 msgid "<option>-?</option>,<option>--help</option>" -msgstr "" +msgstr "<option>-?</option>,<option>--help</option>" #. type: Content of: <varlistentry><listitem><para> #: include/param_help.xml:7 include/param_help_py.xml:7 @@ -17955,7 +18024,7 @@ msgstr "" #. type: Content of: <varlistentry><term> #: include/param_help_py.xml:3 msgid "<option>-h</option>,<option>--help</option>" -msgstr "" +msgstr "<option>-h</option>,<option>--help</option>" #. type: Content of: <listitem><para> #: include/debug_levels.xml:3 include/debug_levels_tools.xml:3 @@ -18197,12 +18266,12 @@ msgstr "" #: include/ldap_search_bases.xml:9 #, no-wrap msgid "search_base[?scope?[filter][?search_base?scope?[filter]]*]\n" -msgstr "" +msgstr "search_base[?scope?[filter][?search_base?scope?[filter]]*]\n" #. type: Content of: <listitem><para> #: include/ldap_search_bases.xml:7 msgid "syntax: <placeholder type=\"programlisting\" id=\"0\"/>" -msgstr "" +msgstr "სინტაქსი: <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <listitem><para> #: include/ldap_search_bases.xml:13 @@ -18238,12 +18307,12 @@ msgstr "" #. type: Content of: <varlistentry><term> #: include/override_homedir.xml:2 msgid "override_homedir (string)" -msgstr "" +msgstr "override_homedir (სტრიქონი)" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:16 msgid "UID number" -msgstr "" +msgstr "UID-ის ნომერი" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:20 @@ -18253,7 +18322,7 @@ msgstr "" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: include/override_homedir.xml:23 msgid "%f" -msgstr "" +msgstr "%f" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:24 @@ -18263,7 +18332,7 @@ msgstr "" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: include/override_homedir.xml:27 msgid "%l" -msgstr "" +msgstr "%l" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:28 @@ -18278,7 +18347,7 @@ msgstr "" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: include/override_homedir.xml:35 msgid "%o" -msgstr "" +msgstr "%o" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:38 @@ -18306,7 +18375,7 @@ msgstr "" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: include/override_homedir.xml:61 msgid "%H" -msgstr "" +msgstr "%H" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:63 @@ -18324,7 +18393,7 @@ msgstr "" #. type: Content of: <varlistentry><listitem><para> #: include/override_homedir.xml:75 msgid "This option can also be set per-domain." -msgstr "" +msgstr "This option can also be set per-domain." #. type: Content of: <varlistentry><listitem><para><programlisting> #: include/override_homedir.xml:80 @@ -18353,7 +18422,7 @@ msgstr "" #. type: Content of: <varlistentry><term> #: include/homedir_substring.xml:2 msgid "homedir_substring (string)" -msgstr "" +msgstr "homedir_substring (სტრიქონი)" #. type: Content of: <varlistentry><listitem><para> #: include/homedir_substring.xml:5 @@ -18370,7 +18439,7 @@ msgstr "" #. type: Content of: <varlistentry><listitem><para> #: include/homedir_substring.xml:15 msgid "Default: /home" -msgstr "" +msgstr "ნაგულისხმევი: /home" #. type: Content of: <refsect1><title> #: include/ad_modified_defaults.xml:2 include/ipa_modified_defaults.xml:2 @@ -18393,12 +18462,12 @@ msgstr "" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:13 include/ipa_modified_defaults.xml:13 msgid "krb5_validate = true" -msgstr "" +msgstr "krb5_validate = true" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:18 msgid "krb5_use_enterprise_principal = true" -msgstr "" +msgstr "krb5_use_enterprise_principal = true" #. type: Content of: <refsect1><refsect2><title> #: include/ad_modified_defaults.xml:24 @@ -18408,37 +18477,37 @@ msgstr "" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:28 msgid "ldap_schema = ad" -msgstr "" +msgstr "ldap_schema = ad" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:33 include/ipa_modified_defaults.xml:38 msgid "ldap_force_upper_case_realm = true" -msgstr "" +msgstr "ldap_force_upper_case_realm = true" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:38 msgid "ldap_id_mapping = true" -msgstr "" +msgstr "ldap_id_mapping = true" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:43 msgid "ldap_sasl_mech = GSS-SPNEGO" -msgstr "" +msgstr "ldap_sasl_mech = GSS-SPNEGO" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:48 msgid "ldap_referrals = false" -msgstr "" +msgstr "ldap_referrals = false" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:53 msgid "ldap_account_expire_policy = ad" -msgstr "" +msgstr "ldap_account_expire_policy = ad" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:58 include/ipa_modified_defaults.xml:58 msgid "ldap_use_tokengroups = true" -msgstr "" +msgstr "ldap_use_tokengroups = true" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:63 @@ -18460,12 +18529,12 @@ msgstr "" #. type: Content of: <refsect1><refsect2><title> #: include/ad_modified_defaults.xml:80 msgid "NSS configuration" -msgstr "" +msgstr "NSS-ის მორგება" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:84 msgid "fallback_homedir = /home/%d/%u" -msgstr "" +msgstr "fallback_homedir = /home/%d/%u" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:87 @@ -18504,12 +18573,12 @@ msgstr "" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:18 msgid "krb5_use_fast = try" -msgstr "" +msgstr "krb5_use_fast = try" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:23 msgid "krb5_canonicalize = true" -msgstr "" +msgstr "krb5_canonicalize = true" #. type: Content of: <refsect1><refsect2><title> #: include/ipa_modified_defaults.xml:29 @@ -18519,47 +18588,47 @@ msgstr "" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:33 msgid "ldap_schema = ipa_v1" -msgstr "" +msgstr "ldap_schema = ipa_v1" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:43 msgid "ldap_sasl_mech = GSSAPI" -msgstr "" +msgstr "ldap_sasl_mech = GSSAPI" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:48 msgid "ldap_sasl_minssf = 56" -msgstr "" +msgstr "ldap_sasl_minssf = 56" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:53 msgid "ldap_account_expire_policy = ipa" -msgstr "" +msgstr "ldap_account_expire_policy = ipa" #. type: Content of: <refsect1><refsect2><title> #: include/ipa_modified_defaults.xml:64 msgid "LDAP Provider - User options" -msgstr "" +msgstr "LDAP Provider - User options" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:68 msgid "ldap_user_member_of = memberOf" -msgstr "" +msgstr "ldap_user_member_of = memberOf" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:73 msgid "ldap_user_uuid = ipaUniqueID" -msgstr "" +msgstr "ldap_user_uuid = ipaUniqueID" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:78 msgid "ldap_user_ssh_public_key = ipaSshPubKey" -msgstr "" +msgstr "ldap_user_ssh_public_key = ipaSshPubKey" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:83 msgid "ldap_user_auth_type = ipaUserAuthType" -msgstr "" +msgstr "ldap_user_auth_type = ipaUserAuthType" #. type: Content of: <refsect1><refsect2><title> #: include/ipa_modified_defaults.xml:89 @@ -18569,37 +18638,37 @@ msgstr "" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:93 msgid "ldap_group_object_class = ipaUserGroup" -msgstr "" +msgstr "ldap_group_object_class = ipaUserGroup" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:98 msgid "ldap_group_object_class_alt = posixGroup" -msgstr "" +msgstr "ldap_group_object_class_alt = posixGroup" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:103 msgid "ldap_group_member = member" -msgstr "" +msgstr "ldap_group_member = member" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:108 msgid "ldap_group_uuid = ipaUniqueID" -msgstr "" +msgstr "ldap_group_uuid = ipaUniqueID" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:113 msgid "ldap_group_objectsid = ipaNTSecurityIdentifier" -msgstr "" +msgstr "ldap_group_objectsid = ipaNTSecurityIdentifier" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:118 msgid "ldap_group_external_member = ipaExternalMember" -msgstr "" +msgstr "ldap_group_external_member = ipaExternalMember" #. type: Content of: <variablelist><varlistentry><term> #: include/krb5_options.xml:3 msgid "krb5_auth_timeout (integer)" -msgstr "" +msgstr "krb5_auth_timeout (მთელი რიცხვი)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:6 @@ -18643,7 +18712,7 @@ msgstr "" #. type: Content of: <variablelist><varlistentry><term> #: include/krb5_options.xml:44 msgid "krb5_renewable_lifetime (string)" -msgstr "" +msgstr "krb5_renewable_lifetime (სტრიქონი)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:47 @@ -18696,7 +18765,7 @@ msgstr "" #. type: Content of: <variablelist><varlistentry><term> #: include/krb5_options.xml:79 msgid "krb5_lifetime (string)" -msgstr "" +msgstr "krb5_lifetime (სტრიქონი)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:82 @@ -18725,7 +18794,7 @@ msgstr "" #. type: Content of: <variablelist><varlistentry><term> #: include/krb5_options.xml:114 msgid "krb5_renew_interval (string)" -msgstr "" +msgstr "krb5_renew_interval (სტრიქონი)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:117 diff --git a/src/man/po/ko.po b/src/man/po/ko.po index 0b0476671e1..a1d7e55c3b0 100644 --- a/src/man/po/ko.po +++ b/src/man/po/ko.po @@ -8,8 +8,8 @@ msgstr "" "Project-Id-Version: sssd-docs 2.5.2\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" "POT-Creation-Date: 2021-07-12 20:51+0200\n" -"PO-Revision-Date: 2026-04-23 16:36+0000\n" -"Last-Translator: seo hojin <jinswhat@naver.com>\n" +"PO-Revision-Date: 2026-06-22 07:32+0000\n" +"Last-Translator: Min Kyung Kwon <min.kyung.kwon.dev@gmail.com>\n" "Language-Team: Korean <https://translate.fedoraproject.org/projects/sssd/" "sssd-manpage-master/ko/>\n" "Language: ko\n" @@ -17,7 +17,7 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=1; plural=0;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.6.1\n" #. type: Content of: <reference><title> #: sss_groupmod.8.xml:5 sssd.conf.5.xml:5 sssd-ldap.5.xml:5 pam_sss.8.xml:5 @@ -755,6 +755,13 @@ msgid "" "permissions may result in a non-usable SSSD. The same may occur in case of " "changes of the user running the NSS responder. </phrase>" msgstr "" +"root 사용자로 실행하지 않도록 적절한 경우 권한을 낮출 사용자입니다. <phrase " +"condition=\"have_systemd\"> 이 옵션은 소켓 활성화 서비스를 실행할 때 " +"작동하지 않습니다. 프로세스를 실행하도록 설정된 사용자는 컴파일 시점에 " +"설정되기 때문입니다. systemd 단위 파일을 재정의하는 방법은 /etc/systemd/" +"system/에 적절한 파일을 만드는 것입니다. 소켓 사용자, 그룹 또는 권한을 " +"변경하면 SSSD를 사용할 수 없게 될 수 있습니다. NSS 응답자를 실행하는 " +"사용자를 변경하는 경우에도 동일한 문제가 발생할 수 있습니다. </phrase>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:427 @@ -775,11 +782,10 @@ msgid "" "trusted domain. The option allows those users to log in just with their " "user name without giving a domain name as well." msgstr "" -"이와 같은 문자열은 도메인 이름 구성이 없는 모든 이름을 위해 기본 도메인 " -"이름으로 사용됩니다. 주요 사용 경우는 기본 도메인이 호스트 정책을 관리하고 " -"모든 사용자가 신뢰 할 수 있는 도메인에 있는 환경입니다. 이와 같은 옵션을 " -"사용하면 해당 사용자는 도메인 이름도 제공하지 않고 이들 사용자 이름만으로 " -"로그인 할 수 있습니다." +"이 문자열은 도메인 이름 구성 요소가 없는 모든 이름의 기본 도메인 이름으로 " +"사용됩니다. 주요 사용 사례는 기본 도메인이 호스트 정책 관리를 목적으로 하고 " +"모든 사용자가 신뢰할 수 있는 도메인에 있는 환경입니다. 이 옵션을 사용하면 " +"해당 사용자가 도메인 이름 없이 사용자 이름만으로 로그인할 수 있습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:445 @@ -793,6 +799,13 @@ msgid "" "nss_files and therefore their output is not qualified even when the " "default_domain_suffix option is used." msgstr "" +"이 옵션이 설정되면 기본 도메인의 모든 사용자가 로그인 시 정규화된 이름(예: " +"user@domain.name)을 사용해야 합니다. 이 옵션을 설정하면 " +"use_fully_qualified_names의 기본값이 True로 변경됩니다. 이 옵션은 " +"use_fully_qualified_names가 False로 설정된 경우와 함께 사용할 수 없습니다. " +"이 규칙의 한 가지 예외는 <quote>id_provider=files</quote>인 도메인으로, 항상 " +"nss_files의 동작을 따르려 하기 때문에 default_domain_suffix 옵션을 " +"사용하더라도 출력이 정규화되지 않습니다." #. type: Content of: <variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:460 sssd-ldap.5.xml:772 sssd-ldap.5.xml:784 @@ -1001,6 +1014,9 @@ msgid "" "the related certificates. This option should be used to allow authentication " "when the system is offline and the CRL cannot be renewed." msgstr "" +"인증서 폐기 목록(CRL)이 만료된 경우 관련 인증서의 CRL 점검을 무시합니다. 이 " +"옵션은 시스템이 오프라인이고 CRL을 갱신할 수 없을 때 인증을 허용하기 위해 " +"사용해야 합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:493 @@ -1062,6 +1078,8 @@ msgid "" "When this option is enabled, SSSD prepends an implicit domain with " "<quote>id_provider=files</quote> before any explicitly configured domains." msgstr "" +"이 옵션이 활성화되면 SSSD는 명시적으로 구성된 도메인 앞에 <quote>" +"id_provider=files</quote>를 사용하는 암묵적 도메인을 추가합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:652 @@ -1078,11 +1096,11 @@ msgid "" "subdomains which are not listed as part of <quote>lookup_order</quote> will " "be looked up in a random order for each parent domain." msgstr "" -"따라야 할 조회 순서를 나타내는 쉼표로 구분된 도메인 및 하위 도메인의 목록. " -"목록은 누락된 도메인이 <quote>domains</quote> 구성에서 제공된 순서에 " -"기반하여 조회되는 모든 가능한 도메인을 포함하지 않아도 됩니다. <quote>" -"lookup_order</quote> 의 부분으로 나열되지 않은 하위 도메인은 각 상위 " -"도메인을 위해 무작위 순서로 조회됩니다." +"따라야 할 조회 순서를 나타내는 쉼표로 구분된 도메인 및 하위 도메인의 " +"목록입니다. 목록에 모든 가능한 도메인을 포함할 필요는 없습니다. 누락된 " +"도메인은 <quote>domains</quote> 구성 옵션에 표시된 순서에 따라 조회됩니다. " +"<quote>lookup_order</quote>의 일부로 나열되지 않은 하위 도메인은 각 상위 " +"도메인에 대해 임의의 순서로 조회됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:667 @@ -1100,6 +1118,16 @@ msgid "" "shortnames, making this workaround totally not recommended in cases where " "usernames may overlap between domains." msgstr "" +"이 옵션이 설정되면 파일 공급자가 관리하는 사용자를 제외한 모든 사용자에 대해 " +"입력에 짧은 이름을 사용하더라도 항상 모든 명령의 출력 형식이 정규화됩니다. " +"관리자가 출력을 정규화하지 않으려는 경우 다음과 같이 full_name_format 옵션을 " +"사용할 수 있습니다: <quote>full_name_format=%1$s</quote> 하지만 로그인 중에 " +"로그인 응용 프로그램이 <citerefentry> <refentrytitle>getpwnam</" +"refentrytitle> <manvolnum>3</manvolnum> </citerefentry>을 호출하여 사용자 " +"이름을 정규화하는 경우, 정규화된 입력에 대해 짧은 이름이 반환되면(여러 " +"도메인에 존재하는 사용자에 접근하려는 시도 중) 로그인 시도가 짧은 이름을 " +"사용하는 도메인으로 재라우팅될 수 있으므로, 사용자 이름이 도메인 간에 겹칠 " +"수 있는 경우에는 이 해결 방법을 사용하지 않는 것이 좋습니다." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:692 sssd.conf.5.xml:1659 sssd.conf.5.xml:3927 @@ -1117,6 +1145,11 @@ msgid "" "some other important options like the identity domains. <placeholder type=" "\"variablelist\" id=\"0\"/>" msgstr "" +"SSSD의 개별 기능은 SSSD와 함께 시작 및 종료되는 특수 SSSD 서비스에 의해 " +"제공됩니다. 이 서비스들은 흔히 <quote>모니터</quote>라고 불리는 특수 " +"서비스에 의해 관리됩니다. <quote>[sssd]</quote> 섹션은 모니터 설정뿐만 " +"아니라 ID 도메인과 같은 다른 중요한 옵션을 구성하는 데 사용됩니다. " +"<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:703 @@ -1131,6 +1164,9 @@ msgid "" "section, for example, for NSS service, the section would be <quote>[nss]</" "quote>" msgstr "" +"다양한 서비스를 구성하는 데 사용할 수 있는 설정이 이 섹션에 설명되어 " +"있습니다. [<replaceable>$NAME</replaceable>] 섹션에 위치해야 합니다. 예를 " +"들어 NSS 서비스의 경우 <quote>[nss]</quote> 섹션이 됩니다" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:712 @@ -1156,6 +1192,10 @@ msgid "" "systems without this capability, the resulting value will be the lower value " "of this or the limits.conf \"hard\" limit." msgstr "" +"이 옵션은 이 SSSD 프로세스가 한 번에 열 수 있는 최대 파일 설명자 수를 " +"지정합니다. SSSD에 CAP_SYS_RESOURCE 기능이 부여된 시스템에서는 절대적인 " +"설정입니다. 이 기능이 없는 시스템에서는 이 값과 limits.conf의 \"hard\" 제한 " +"중 낮은 값이 결과값으로 사용됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:743 @@ -1176,6 +1216,10 @@ msgid "" "can't be shorter than 10 seconds. If a lower value is configured, it will be " "adjusted to 10 seconds." msgstr "" +"이 옵션은 SSSD 프로세스의 클라이언트가 통신하지 않고 파일 설명자를 유지할 수 " +"있는 시간(초)을 지정합니다. 이 값은 시스템의 리소스 고갈을 방지하기 위해 " +"제한됩니다. 시간 초과는 10초보다 짧을 수 없습니다. 더 낮은 값을 구성하면 " +"10초로 조정됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:760 @@ -1197,6 +1241,11 @@ msgid "" "time for the previous ones. After each unsuccessful attempt to go online, " "the new interval is recalculated by the following:" msgstr "" +"SSSD가 오프라인 모드로 전환되면 다시 온라인으로 돌아가기 전의 시간이 연결이 " +"끊긴 시간에 따라 증가합니다. 기본적으로 SSSD는 증분 방식을 사용하여 재시도 " +"사이의 지연을 계산합니다. 따라서 주어진 재시도의 대기 시간은 이전 재시도의 " +"대기 시간보다 깁니다. 온라인 전환에 실패할 때마다 새 간격은 다음 공식으로 " +"다시 계산됩니다:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:779 sssd.conf.5.xml:835 @@ -1214,6 +1263,9 @@ msgid "" "value is 3600. The offline_timeout_random_offset default value is 30. The " "end result is amount of seconds before next retry." msgstr "" +"offline_timeout 기본값은 60입니다. offline_timeout_max 기본값은 " +"3600입니다. offline_timeout_random_offset 기본값은 30입니다. 최종 결과는 " +"다음 재시도 전까지의 시간(초)입니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:788 @@ -1221,6 +1273,8 @@ msgid "" "Note that the maximum length of each interval is defined by " "offline_timeout_max (apart of random part)." msgstr "" +"각 간격의 최대 길이는 offline_timeout_max에 의해 정의됩니다(무작위 부분 제외)" +"." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:792 sssd.conf.5.xml:1132 sssd.conf.5.xml:1486 @@ -1239,6 +1293,8 @@ msgid "" "Controls by how much the time between attempts to go online can be " "incremented following unsuccessful attempts to go online." msgstr "" +"온라인 전환에 실패한 후 온라인 전환 시도 사이의 시간을 얼마나 증가시킬 " +"것인지 제어합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:805 @@ -1250,7 +1306,7 @@ msgstr "0의 값은 동작을 비활성화 합니다." msgid "" "The value of this parameter should be set in correlation to offline_timeout " "parameter value." -msgstr "" +msgstr "이 매개변수의 값은 offline_timeout 매개변수 값과 연관하여 설정해야 합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:812 @@ -1260,6 +1316,9 @@ msgid "" "rule here should be to set offline_timeout_max to at least 4 times " "offline_timeout." msgstr "" +"offline_timeout이 60(기본값)으로 설정된 경우 offline_timeout_max를 120 " +"미만으로 설정하면 즉시 포화 상태가 되므로 의미가 없습니다. 일반적인 규칙은 " +"offline_timeout_max를 offline_timeout의 최소 4배로 설정하는 것입니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:818 @@ -1267,6 +1326,8 @@ msgid "" "Although a value between 0 and offline_timeout may be specified, it has the " "effect of overriding the offline_timeout value so is of little use." msgstr "" +"0과 offline_timeout 사이의 값을 지정할 수 있지만, offline_timeout 값을 " +"재정의하는 효과가 있으므로 실질적인 의미가 거의 없습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:823 @@ -1293,6 +1354,8 @@ msgid "" "This parameter controls the value of the random offset used for the above " "equation. Final random_offset value will be random number in range:" msgstr "" +"이 매개변수는 위 수식에 사용되는 무작위 오프셋의 값을 제어합니다. 최종 " +"random_offset 값은 다음 범위의 무작위 수가 됩니다:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:843 @@ -1325,6 +1388,11 @@ msgid "" "built with systemd support and when services are either socket or D-Bus " "activated." msgstr "" +"이 옵션은 SSSD 응답자 프로세스가 사용되지 않은 채로 유지될 수 있는 시간(초)" +"을 지정합니다. 이 값은 시스템의 리소스 고갈을 방지하기 위해 제한됩니다. 이 " +"옵션의 최소 허용 값은 60초입니다. 이 옵션을 0(영)으로 설정하면 응답자에 " +"시간 초과가 설정되지 않습니다. 이 옵션은 SSSD가 systemd 지원으로 빌드되고 " +"서비스가 소켓 또는 D-Bus로 활성화된 경우에만 효과가 있습니다." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:871 sssd.conf.5.xml:1145 sssd.conf.5.xml:2187 @@ -1343,6 +1411,8 @@ msgid "" "This option specifies whether the responder should query all caches before " "querying the Data Providers." msgstr "" +"이 옵션은 응답자가 자료 공급자를 질의하기 전에 모든 캐시를 질의해야 하는지 " +"여부를 지정합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:891 @@ -1365,7 +1435,7 @@ msgstr "enum_cache_timeout (정수)" msgid "" "How many seconds should nss_sss cache enumerations (requests for info about " "all users)" -msgstr "nss_sss 캐쉬가 열거된 시간(초) (모든 사용자에 대한 정보를 위한 요청)" +msgstr "nss_sss가 열거(모든 사용자에 대한 정보 요청)를 캐시해야 하는 시간(초)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:905 @@ -1397,6 +1467,10 @@ msgid "" "but the SSSD will go and update the cache on its own, so that future " "requests will not need to block waiting for a cache update." msgstr "" +"예를 들어, 도메인의 entry_cache_timeout이 30초로 설정되고 " +"entry_cache_nowait_percentage가 50(퍼센트)로 설정된 경우, 마지막 캐시 " +"업데이트 후 15초 이후에 들어오는 항목은 즉시 반환되지만, SSSD가 독자적으로 " +"캐시를 업데이트하므로 향후 요청이 캐시 업데이트를 기다리며 차단되지 않습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:929 @@ -1406,6 +1480,9 @@ msgid "" "percentage will never reduce the nowait timeout to less than 10 seconds. (0 " "disables this feature)" msgstr "" +"이 옵션의 유효한 값은 0-99이며 각 도메인의 entry_cache_timeout 백분율을 " +"나타냅니다. 성능상의 이유로 이 백분율은 nowait 시간 초과를 10초 미만으로 " +"줄이지 않습니다. (0은 이 기능을 비활성화합니다)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:937 sssd.conf.5.xml:1987 @@ -1424,6 +1501,9 @@ msgid "" "(that is, queries for invalid database entries, like nonexistent ones) " "before asking the back end again." msgstr "" +"nss_sss가 백엔드에 다시 요청하기 전에 네거티브 캐시 적중(존재하지 않는 것과 " +"같은 잘못된 데이터베이스 항목에 대한 조회)을 캐시해야 하는 시간(초)을 " +"지정합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:951 sssd.conf.5.xml:2011 @@ -1442,6 +1522,9 @@ msgid "" "negative cache before trying to look it up in the back end again. Setting " "the option to 0 disables this feature." msgstr "" +"nss_sss가 백엔드에서 다시 조회를 시도하기 전에 로컬 사용자 및 그룹을 " +"네거티브 캐시에 유지해야 하는 시간(초)을 지정합니다. 이 옵션을 0으로 " +"설정하면 이 기능이 비활성화됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:965 @@ -1461,6 +1544,10 @@ msgid "" "also be set per-domain or include fully-qualified names to filter only users " "from the particular domain or by a user principal name (UPN)." msgstr "" +"sss NSS 데이터베이스에서 특정 사용자 또는 그룹을 가져오지 않도록 제외합니다. " +"시스템 계정에 특히 유용합니다. 이 옵션은 도메인별로 설정하거나 정규화된 " +"이름을 포함하여 특정 도메인의 사용자만 또는 사용자 주체 이름(UPN)으로 " +"필터링할 수도 있습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:981 @@ -1470,6 +1557,10 @@ msgid "" "NSS. E.g. a group having a member group filtered out will still have the " "member users of the latter listed." msgstr "" +"참고: filter_groups 옵션은 중첩된 그룹 구성원의 상속에 영향을 주지 않습니다. " +"필터링은 NSS를 통해 반환하기 위해 전파된 후에 이루어지기 때문입니다. 예를 " +"들어 구성원 그룹이 필터링된 그룹에도 해당 그룹의 구성원 사용자가 여전히 " +"나열됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:989 @@ -1500,6 +1591,8 @@ msgid "" "Set a default template for a user's home directory if one is not specified " "explicitly by the domain's data provider." msgstr "" +"도메인의 자료 공급자가 명시적으로 지정하지 않은 경우 사용자의 홈 디렉토리에 " +"대한 기본 템플릿을 설정합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1016 @@ -1542,6 +1635,8 @@ msgid "" "shell options if it takes effect and can be set either in the [nss] section " "or per-domain." msgstr "" +"모든 사용자의 로그인 쉘을 재정의합니다. 이 옵션이 적용되면 다른 모든 쉘 " +"옵션보다 우선하며 [nss] 섹션 또는 도메인별로 설정할 수 있습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1041 @@ -1557,12 +1652,12 @@ msgstr "allowed_shells (문자열)" #: sssd.conf.5.xml:1050 msgid "" "Restrict user shell to one of the listed values. The order of evaluation is:" -msgstr "" +msgstr "사용자 쉘을 나열된 값 중 하나로 제한합니다. 평가 순서는 다음과 같습니다:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1053 msgid "1. If the shell is present in <quote>/etc/shells</quote>, it is used." -msgstr "" +msgstr "1. 쉘이 <quote>/etc/shells</quote>에 있으면 해당 쉘이 사용됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1057 @@ -1570,6 +1665,8 @@ msgid "" "2. If the shell is in the allowed_shells list but not in <quote>/etc/shells</" "quote>, use the value of the shell_fallback parameter." msgstr "" +"2. 쉘이 allowed_shells 목록에는 있지만 <quote>/etc/shells</quote>에는 " +"없으면, shell_fallback 매개변수의 값을 사용합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1062 @@ -1577,6 +1674,8 @@ msgid "" "3. If the shell is not in the allowed_shells list and not in <quote>/etc/" "shells</quote>, a nologin shell is used." msgstr "" +"3. 쉘이 allowed_shells 목록에도 없고 <quote>/etc/shells</quote>에도 없으면, " +"nologin 쉘이 사용됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1067 @@ -1590,6 +1689,9 @@ msgid "" "shell is not in <quote>/etc/shells</quote> and maintaining list of all " "allowed shells in allowed_shells would be to much overhead." msgstr "" +"(*)는 사용자의 쉘이 <quote>/etc/shells</quote>에 없을 때 shell_fallback을 " +"사용하려는 경우에 유용하며, allowed_shells에 모든 허용된 쉘 목록을 유지하는 " +"것이 부담스러울 때 사용합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1077 @@ -1602,6 +1704,8 @@ msgid "" "The <quote>/etc/shells</quote> is only read on SSSD start up, which means " "that a restart of the SSSD is required in case a new shell is installed." msgstr "" +"<quote>/etc/shells</quote>는 SSSD 시작 시에만 읽히므로, 새 쉘이 설치된 경우 " +"SSSD를 다시 시작해야 합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1084 @@ -1645,6 +1749,8 @@ msgid "" "The default shell to use if the provider does not return one during lookup. " "This option can be specified globally in the [nss] section or per-domain." msgstr "" +"공급자가 조회 중 쉘을 반환하지 않는 경우 사용할 기본 쉘입니다. 이 옵션은 " +"[nss] 섹션에서 전역적으로 또는 도메인별로 지정할 수 있습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1118 @@ -1652,6 +1758,8 @@ msgid "" "Default: not set (Return NULL if no shell is specified and rely on libc to " "substitute something sensible when necessary, usually /bin/sh)" msgstr "" +"기본값: 설정되지 않음(쉘을 지정하지 않으면 NULL을 반환하고 필요 시 libc가 " +"적절한 값으로 대체하도록 합니다. 보통 /bin/sh)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1125 sssd.conf.5.xml:1479 @@ -1676,6 +1784,8 @@ msgid "" "Specifies time in seconds for which records in the in-memory cache will be " "valid. Setting this option to zero will disable the in-memory cache." msgstr "" +"메모리 내 캐시의 레코드가 유효한 시간(초)을 지정합니다. 이 옵션을 0으로 " +"설정하면 메모리 내 캐시가 비활성화됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1148 @@ -1683,6 +1793,8 @@ msgid "" "WARNING: Disabling the in-memory cache will have significant negative impact " "on SSSD's performance and should only be used for testing." msgstr "" +"경고: 메모리 내 캐시를 비활성화하면 SSSD 성능에 심각한 부정적인 영향을 " +"미치며 테스트 목적으로만 사용해야 합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1154 sssd.conf.5.xml:1179 sssd.conf.5.xml:1204 @@ -1691,6 +1803,8 @@ msgid "" "NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", " "client applications will not use the fast in-memory cache." msgstr "" +"참고: 환경 변수 SSS_NSS_USE_MEMCACHE가 \"NO\"로 설정된 경우, 클라이언트 응용 " +"프로그램은 빠른 메모리 내 캐시를 사용하지 않습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1162 @@ -1704,6 +1818,8 @@ msgid "" "for passwd requests. Setting the size to 0 will disable the passwd in-" "memory cache." msgstr "" +"passwd 요청을 위해 빠른 캐쉬 메모리 내에 할당된 자료 테이블의 크기(megabytes)" +"입니다. 크기를 0으로 설정하면 메모리 내의 passwd 가 비활성화됩니다." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1171 sssd.conf.5.xml:2720 sssd-ldap.5.xml:513 @@ -1716,6 +1832,8 @@ msgid "" "WARNING: Disabled or too small in-memory cache can have significant negative " "impact on SSSD's performance." msgstr "" +"경고: 비활성화되었거나 너무 작은 메모리 내 캐시는 SSSD 성능에 심각한 " +"부정적인 영향을 미칠 수 있습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1187 @@ -1729,6 +1847,8 @@ msgid "" "for group requests. Setting the size to 0 will disable the group in-memory " "cache." msgstr "" +"그룹 요청을 위한 빠른 캐쉬 메모리에 할당된 자료 테이블의 크기(megabytes). " +"크기를 0으로 설정하면 메모리 캐쉬에서 그룹이 비활성화됩니다." #. type: Content of: <variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1196 sssd.conf.5.xml:3515 sssd-ldap.5.xml:453 @@ -1748,6 +1868,9 @@ msgid "" "for initgroups requests. Setting the size to 0 will disable the initgroups " "in-memory cache." msgstr "" +"initgroups 요청을 위한 빠른 메모리 캐쉬에 안에 할당된 자료 테이블의 크기" +"(megabytes). 크기를 0으로 설정하면 메모리 캐쉬에 initgroups가 " +"비활성화됩니다." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:1237 sssd-ifp.5.xml:74 @@ -1764,6 +1887,11 @@ msgid "" "<citerefentry> <refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</" "manvolnum> </citerefentry> for details) but with no default values." msgstr "" +"일부 추가 NSS 응답자 요청은 NSS 인터페이스에 정의된 POSIX 속성보다 더 많은 " +"속성을 반환할 수 있습니다. 속성 목록은 이 옵션에 의해 제어됩니다. InfoPipe " +"응답자의 <quote>user_attributes</quote> 옵션과 동일한 방식으로 처리됩니다" +"(자세한 내용은 <citerefentry> <refentrytitle>sssd-ifp</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> 참조). 다만 기본값은 없습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1253 @@ -1771,6 +1899,8 @@ msgid "" "To make configuration more easy the NSS responder will check the InfoPipe " "option if it is not set for the NSS responder." msgstr "" +"구성을 더 쉽게 하기 위해 NSS 응답자에 대해 설정되지 않은 경우 NSS 응답자가 " +"InfoPipe 옵션을 확인합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1258 @@ -1788,6 +1918,8 @@ msgid "" "The value that NSS operations that return users or groups will return for " "the <quote>password</quote> field." msgstr "" +"사용자 또는 그룹을 반환하는 NSS 연산이 <quote>password</quote> 필드에 대해 " +"반환하는 값입니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1271 @@ -1799,7 +1931,7 @@ msgstr "기본값: <quote>*</quote>" msgid "" "Note: This option can also be set per-domain which overwrites the value in " "[nss] section." -msgstr "" +msgstr "참고: 이 옵션은 도메인별로도 설정할 수 있으며 [nss] 섹션의 값을 덮어씁니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1278 @@ -1808,6 +1940,8 @@ msgid "" "files domain), <quote>x</quote> (proxy domain with nss_files and sssd-" "shadowutils target)" msgstr "" +"기본값: <quote>설정되지 않음</quote>(원격 도메인), <quote>x</quote>(파일 " +"도메인), <quote>x</quote>(nss_files 및 sssd-shadowutils 대상의 프록시 도메인)" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:1288 @@ -1832,6 +1966,8 @@ msgid "" "If the authentication provider is offline, how long should we allow cached " "logins (in days since the last successful online login)." msgstr "" +"인증 공급자가 오프라인인 경우 캐시된 로그인을 허용해야 하는 기간(마지막 " +"성공적인 온라인 로그인 이후 일 수)입니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1303 sssd.conf.5.xml:1316 @@ -1848,7 +1984,7 @@ msgstr "offline_failed_login_attempts (정수)" msgid "" "If the authentication provider is offline, how many failed login attempts " "are allowed." -msgstr "" +msgstr "인증 공급자가 오프라인인 경우 허용되는 로그인 시도 실패 횟수입니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1322 @@ -1861,6 +1997,8 @@ msgid "" "The time in minutes which has to pass after offline_failed_login_attempts " "has been reached before a new login attempt is possible." msgstr "" +"offline_failed_login_attempts에 도달한 후 새 로그인 시도가 가능해지기 전에 " +"경과해야 하는 시간(분)입니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1330 @@ -1869,6 +2007,9 @@ msgid "" "offline_failed_login_attempts has been reached. Only a successful online " "authentication can enable offline authentication again." msgstr "" +"0으로 설정하면 offline_failed_login_attempts에 도달한 경우 사용자가 " +"오프라인으로 인증할 수 없습니다. 성공적인 온라인 인증만이 오프라인 인증을 " +"다시 활성화할 수 있습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1336 sssd.conf.5.xml:1446 @@ -1886,6 +2027,8 @@ msgid "" "Controls what kind of messages are shown to the user during authentication. " "The higher the number to more messages are displayed." msgstr "" +"인증 중 사용자에게 표시되는 메시지의 종류를 제어합니다. 숫자가 높을수록 더 " +"많은 메시지가 표시됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1350 @@ -1930,6 +2073,10 @@ msgid "" "responses sent to pam_sss e.g. messages displayed to the user or environment " "variables which should be set by pam_sss." msgstr "" +"PAM 응답자가 pam_sss PAM 모듈로 보내는 데이터를 제거(필터링)할 수 있는 " +"쉼표로 구분된 문자열 목록입니다. pam_sss로 전송되는 다양한 종류의 응답이 " +"있습니다. 예를 들어 사용자에게 표시되는 메시지 또는 pam_sss에 의해 " +"설정되어야 하는 환경 변수 등입니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1384 @@ -1937,6 +2084,8 @@ msgid "" "While messages already can be controlled with the help of the pam_verbosity " "option this option allows to filter out other kind of responses as well." msgstr "" +"메시지는 pam_verbosity 옵션의 도움으로 이미 제어할 수 있지만, 이 옵션은 다른 " +"종류의 응답도 필터링할 수 있게 합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1391 @@ -1946,7 +2095,7 @@ msgstr "ENV" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1392 msgid "Do not send any environment variables to any service." -msgstr "모든 환경 변수를 다른 서비스에 보낼 수 없습니다." +msgstr "모든 환경 변수를 어떤 서비스에도 보내지 않습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1395 @@ -1956,7 +2105,7 @@ msgstr "ENV:var_name" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1396 msgid "Do not send environment variable var_name to any service." -msgstr "환경 변수 var_name을 다른 어떤 서비스에 보내지 않습니다." +msgstr "환경 변수 var_name을 어떤 서비스에도 보내지 않습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1400 @@ -1987,6 +2136,11 @@ msgid "" "that either all list elements must have a '+' or '-' prefix or none. It is " "considered as an error to mix both styles." msgstr "" +"문자열 목록은 이 필터 목록을 설정하고 기본값을 덮어쓰는 필터 목록이 될 수 " +"있습니다. 또는 목록의 각 요소에 '+' 또는 '-' 문자를 접두사로 붙여 기존 " +"기본값에 필터를 추가하거나 기본값에서 제거할 수 있습니다. 모든 목록 요소에 " +"'+' 또는 '-' 접두사가 있거나 모두 없어야 합니다. 두 가지 스타일을 혼용하는 " +"것은 오류로 간주됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1419 @@ -2011,6 +2165,8 @@ msgid "" "immediately update the cached identity information for the user in order to " "ensure that authentication takes place with the latest information." msgstr "" +"SSSD가 온라인 상태일 때 모든 PAM 요청에 대해, SSSD는 최신 정보로 인증이 " +"이루어지도록 사용자의 캐시된 ID 정보를 즉시 업데이트하려고 시도합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1438 @@ -2020,6 +2176,9 @@ msgid "" "client-application basis) how long (in seconds) we can cache the identity " "information to avoid excessive round-trips to the identity provider." msgstr "" +"완전한 PAM 대화는 계정 관리 및 세션 열기와 같은 여러 PAM 요청을 수행할 수 " +"있습니다. 이 옵션은 (클라이언트 응용 프로그램별로) ID 공급자에 대한 과도한 " +"왕복을 피하기 위해 ID 정보를 캐시할 수 있는 시간(초)을 제어합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1452 @@ -2038,6 +2197,8 @@ msgid "" "expiration time of the password. If this information is missing, sssd " "cannot display a warning." msgstr "" +"백엔드 서버가 비밀번호의 만료 시간에 대한 정보를 제공해야 합니다. 이 정보가 " +"없으면 sssd는 경고를 표시할 수 없습니다." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1464 sssd.conf.5.xml:2747 @@ -2045,6 +2206,8 @@ msgid "" "If zero is set, then this filter is not applied, i.e. if the expiration " "warning was received from backend server, it will automatically be displayed." msgstr "" +"0으로 설정하면 이 필터가 적용되지 않습니다. 즉, 백엔드 서버에서 만료 경고를 " +"수신하면 자동으로 표시됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1469 @@ -2052,6 +2215,8 @@ msgid "" "This setting can be overridden by setting <emphasis>pwd_expiration_warning</" "emphasis> for a particular domain." msgstr "" +"이 설정은 특정 도메인에 대해 <emphasis>pwd_expiration_warning</emphasis>을 " +"설정하여 재정의할 수 있습니다." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1474 sssd.conf.5.xml:3709 sssd-ldap.5.xml:549 sssd.8.xml:79 @@ -2072,6 +2237,10 @@ msgid "" "<quote>pam_public_domains</quote>. User names are resolved to UIDs at " "startup." msgstr "" +"신뢰할 수 있는 도메인에 대해 PAM 대화를 실행할 수 있는 UID 값 또는 사용자 " +"이름의 쉼표로 구분된 목록을 지정합니다. 이 목록에 포함되지 않은 사용자는 " +"<quote>pam_public_domains</quote>로 공개로 표시된 도메인에만 접근할 수 " +"있습니다. 사용자 이름은 시작 시 UID로 확인됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1504 @@ -2084,6 +2253,8 @@ msgid "" "Please note that UID 0 is always allowed to access the PAM responder even in " "case it is not in the pam_trusted_users list." msgstr "" +"UID 0은 pam_trusted_users 목록에 없더라도 항상 PAM 응답자에 대한 접근이 " +"허용됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1515 @@ -2096,11 +2267,13 @@ msgid "" "Specifies the comma-separated list of domain names that are accessible even " "to untrusted users." msgstr "" +"신뢰할 수 없는 사용자도 접근할 수 있는 도메인 이름의 쉼표로 구분된 목록을 " +"지정합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1522 msgid "Two special values for pam_public_domains option are defined:" -msgstr "" +msgstr "pam_public_domains 옵션에 대해 두 가지 특수 값이 정의되어 있습니다:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1526 @@ -2135,6 +2308,8 @@ msgid "" "Allows a custom expiration message to be set, replacing the default " "'Permission denied' message." msgstr "" +"기본 '권한이 거부되었습니다' 메시지를 대체하는 사용자 지정 만료 메시지를 " +"설정할 수 있습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1547 @@ -2142,6 +2317,8 @@ msgid "" "Note: Please be aware that message is only printed for the SSH service " "unless pam_verbosity is set to 3 (show all messages and debug information)." msgstr "" +"참고: pam_verbosity가 3(모든 메시지 및 디버그 정보 표시)으로 설정되지 않는 " +"한 메시지는 SSH 서비스에 대해서만 출력됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1555 @@ -2164,6 +2341,8 @@ msgid "" "Allows a custom lockout message to be set, replacing the default 'Permission " "denied' message." msgstr "" +"기본 '권한이 거부되었습니다' 메시지를 대체하는 사용자 지정 잠금 메시지를 " +"설정할 수 있습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1574 @@ -2188,6 +2367,9 @@ msgid "" "additional communication with the Smartcard which will delay the " "authentication process this option is disabled by default." msgstr "" +"인증서 기반 스마트카드 인증을 활성화합니다. 스마트카드와의 추가 통신이 " +"필요하여 인증 프로세스가 지연되므로 이 옵션은 기본적으로 비활성화되어 " +"있습니다." #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1592 sssd-ldap.5.xml:590 sssd-ldap.5.xml:611 @@ -2234,6 +2416,10 @@ msgid "" "section. Supported options are the same of <quote>certificate_verification</" "quote>." msgstr "" +"이 매개변수를 사용하면 <quote>[sssd]</quote> 섹션의 <quote>" +"certificate_verification</quote> 값을 재정의하는 쉼표로 구분된 옵션 목록으로 " +"PAM 인증서 확인을 조정할 수 있습니다. 지원되는 옵션은 <quote>" +"certificate_verification</quote>과 동일합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1629 @@ -2251,6 +2437,8 @@ msgid "" "Default: not set, i.e. use default <quote>certificate_verification</quote> " "option defined in <quote>[sssd]</quote> section." msgstr "" +"기본값: 설정되지 않음. 즉, <quote>[sssd]</quote> 섹션에 정의된 기본 <quote>" +"certificate_verification</quote> 옵션을 사용합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1640 @@ -2272,7 +2460,7 @@ msgstr "pam_app_services (문자열)" msgid "" "Which PAM services are permitted to contact domains of type " "<quote>application</quote>" -msgstr "" +msgstr "<quote>application</quote> 유형의 도메인에 접속할 수 있는 PAM 서비스" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1664 @@ -2307,6 +2495,12 @@ msgid "" "<quote>my_pam_service</quote>), you would use the following configuration: " "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"<quote>+service_name</quote>을 사용하여 기본 집합에 다른 PAM 서비스 이름을 " +"추가하거나 <quote>-service_name</quote>을 사용하여 기본 집합에서 PAM 서비스 " +"이름을 명시적으로 제거할 수 있습니다. 예를 들어 스마트카드 인증을 위한 기본 " +"PAM 서비스 이름(예: <quote>login</quote>)을 사용자 지정 PAM 서비스 이름(예: " +"<quote>my_pam_service</quote>)으로 대체하려면 다음과 같이 구성합니다: " +"<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1686 sssd-ad.5.xml:621 sssd-ad.5.xml:730 sssd-ad.5.xml:788 @@ -2371,6 +2565,8 @@ msgid "" "to p11_child_timeout should the PAM responder wait until a Smartcard is " "inserted." msgstr "" +"스마트카드 인증이 필요한 경우, PAM 응답기가 스마트카드 삽입을 기다려야 하는 " +"추가 시간(초)으로, p11_child_timeout에 더해집니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1753 @@ -2387,6 +2583,11 @@ msgid "" "first slot found. If multiple readers are connected p11_uri can be used to " "tell p11_child to use a specific reader." msgstr "" +"스마트카드 인증에 사용되는 장치 선택을 제한하는 데 사용할 수 있는 PKCS#11 " +"URI입니다(자세한 내용은 RFC-7512 참조). 기본적으로 SSSD의 p11_child는 " +"'removable' 플래그가 설정된 PKCS#11 슬롯(리더기)을 검색하고 처음 발견된 " +"슬롯에 삽입된 토큰에서 인증서를 읽습니다. 여러 리더기가 연결된 경우 " +"p11_uri를 사용하여 p11_child가 특정 리더기를 사용하도록 지정할 수 있습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1769 @@ -2417,6 +2618,10 @@ msgid "" "debug output of p11_child. As an alternative the GnuTLS utility 'p11tool' " "with e.g. the '--list-all' will show PKCS#11 URIs as well." msgstr "" +"예시: <placeholder type=\"programlisting\" id=\"0\"/> 또는 <placeholder " +"type=\"programlisting\" id=\"1\"/> 적합한 URI를 찾으려면 p11_child의 디버그 " +"출력을 확인하십시오. 대안으로 GnuTLS 유틸리티 'p11tool'을 '--list-all' 등의 " +"옵션과 함께 사용하면 PKCS#11 URI도 확인할 수 있습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1786 @@ -2447,6 +2652,8 @@ msgid "" "Only do an online lookup if there is no active session of the user, i.e. if " "the user is currently not logged in" msgstr "" +"사용자의 활성 세션이 없는 경우, 즉 사용자가 현재 로그인되어 있지 않은 " +"경우에만 온라인 조회를 수행합니다" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1805 @@ -2459,6 +2666,8 @@ msgid "" "Never force an online lookup, use the data from the cache as long as they " "are not expired" msgstr "" +"온라인 조회를 강제하지 않으며, 캐시 데이터가 만료되지 않은 한 캐시의 " +"데이터를 사용합니다" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1789 @@ -2468,6 +2677,9 @@ msgid "" "should be done and the following values are allowed: <placeholder type=" "\"variablelist\" id=\"0\"/>" msgstr "" +"PAM 응답기는 로그인을 시도하는 사용자의 현재 그룹 멤버십을 가져오기 위해 " +"온라인 조회를 강제할 수 있습니다. 이 옵션은 언제 이를 수행할지를 제어하며, " +"다음 값이 허용됩니다: <placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1813 @@ -2485,12 +2697,14 @@ msgid "" "Comma separated list of PAM services that are allowed to try GSSAPI " "authentication using pam_sss_gss.so module." msgstr "" +"pam_sss_gss.so 모듈을 사용하여 GSSAPI 인증을 시도할 수 있는 PAM 서비스의 " +"쉼표로 구분된 목록입니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1826 msgid "" "To disable GSSAPI authentication, set this option to <quote>-</quote> (dash)." -msgstr "" +msgstr "GSSAPI 인증을 비활성화하려면 이 옵션을 <quote>-</quote>(대시)로 설정하십시오." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1830 sssd.conf.5.xml:1861 sssd.conf.5.xml:1899 @@ -2499,6 +2713,9 @@ msgid "" "[pam] section. It can also be set for trusted domain which overwrites the " "value in the domain section." msgstr "" +"참고: 이 옵션은 도메인별로 설정할 수도 있으며, 이 경우 [pam] 섹션의 값을 " +"덮어씁니다. 또한 신뢰할 수 있는 도메인에 대해 설정할 수 있으며, 이 경우 " +"도메인 섹션의 값을 덮어씁니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1838 @@ -2532,6 +2749,9 @@ msgid "" "successfully authenticated through GSSAPI can be associated with the user " "who is being authenticated. Authentication will fail if the check fails." msgstr "" +"True로 설정된 경우, SSSD는 GSSAPI를 통해 성공적으로 인증된 Kerberos 사용자 " +"주체가 인증 중인 사용자와 연결될 수 있어야 합니다. 확인에 실패하면 인증이 " +"실패합니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1857 @@ -2539,6 +2759,8 @@ msgid "" "If False, every user that is able to obtained required service ticket will " "be authenticated." msgstr "" +"False로 설정된 경우, 필요한 서비스 티켓을 획득할 수 있는 모든 사용자가 " +"인증됩니다." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1867 sssd-ad.5.xml:1243 sss_rpcidmapd.5.xml:76 @@ -2558,6 +2780,9 @@ msgid "" "a Kerberos ticket to access a PAM service that is allowed to try GSSAPI " "authentication using pam_sss_gss.so module." msgstr "" +"pam_sss_gss.so 모듈을 사용하여 GSSAPI 인증을 시도할 수 있는 PAM 서비스에 " +"액세스하기 위해 Kerberos 티켓에 포함되어야 하는 인증 지표의 쉼표로 구분된 " +"목록입니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1881 @@ -2573,6 +2798,14 @@ msgid "" "be denied. If the resulting list of indicators for the PAM service is empty, " "the check will not prevent the access." msgstr "" +"목록의 각 요소는 인증 지표 이름이거나 <quote>service:indicator</quote> 쌍일 " +"수 있습니다. PAM 서비스 이름이 접두사로 붙지 않은 지표는 <option>" +"pam_gssapi_services</option>.와 함께 사용하도록 구성된 모든 PAM 서비스에 " +"액세스하는 데 필요합니다. PAM 서비스별 지표 목록은 pam_sss_gss.so에 의한 " +"인증 중에 Kerberos 티켓의 지표와 대조하여 확인됩니다. 티켓의 지표 중 PAM " +"서비스의 지표 목록과 일치하는 항목이 있으면 액세스가 허용됩니다. 목록의 지표 " +"중 일치하는 항목이 없으면 액세스가 거부됩니다. PAM 서비스의 지표 목록이 비어 " +"있으면 해당 확인으로 인해 액세스가 차단되지 않습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1894 @@ -2581,13 +2814,16 @@ msgid "" "</quote> (dash). To disable the check for a specific PAM service, add " "<quote>service:-</quote>." msgstr "" +"GSSAPI 인증 지표 확인을 비활성화하려면 이 옵션을 <quote>-</quote>(대시)로 " +"설정하십시오. 특정 PAM 서비스에 대한 확인을 비활성화하려면 <quote>service:-</" +"quote>.를 추가하십시오." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1905 msgid "" "Following authentication indicators are supported by IPA Kerberos " "deployments:" -msgstr "" +msgstr "다음 인증 지표는 IPA Kerberos 배포에서 지원됩니다:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1908 @@ -2595,6 +2831,8 @@ msgid "" "pkinit -- pre-authentication using X.509 certificates -- whether stored in " "files or on smart cards." msgstr "" +"pkinit -- X.509 인증서를 사용한 사전 인증 -- 파일 또는 스마트카드에 저장된 " +"경우 모두 해당됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1911 @@ -2843,6 +3081,11 @@ msgid "" "the system defaults are used, but can be overwritten with the default_shell " "parameter." msgstr "" +"원격 사용자가 캐시에 존재하지 않는 경우 새로 생성됩니다. UID는 SID를 통해 " +"결정되며, 신뢰할 수 있는 도메인은 UPG를 가지고 GID는 UID와 동일한 값을 " +"갖습니다. 홈 디렉토리는 subdomain_homedir 파라미터를 기반으로 설정됩니다. " +"셸은 기본적으로 비어 있으며, 즉 시스템 기본값이 사용되지만 default_shell " +"파라미터로 덮어쓸 수 있습니다." #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:2147 @@ -2850,6 +3093,8 @@ msgid "" "If there are SIDs of groups from domains sssd knows about, the user will be " "added to those groups." msgstr "" +"SSSD가 알고 있는 도메인의 그룹 SID가 있는 경우, 해당 그룹에 사용자가 " +"추가됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:2153 @@ -2868,11 +3113,13 @@ msgid "" "allowed to access the PAC responder. User names are resolved to UIDs at " "startup." msgstr "" +"PAC 응답기에 액세스할 수 있는 UID 값 또는 사용자 이름의 쉼표로 구분된 목록을 " +"지정합니다. 사용자 이름은 시작 시 UID로 확인됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2166 msgid "Default: 0 (only the root user is allowed to access the PAC responder)" -msgstr "" +msgstr "기본값: 0 (루트 사용자만 PAC 응답기에 액세스할 수 있습니다)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2170 @@ -8803,6 +9050,8 @@ msgid "" "This option can be used to specify which extended key usage the certificate " "should have. The following value can be used in a comma separated list:" msgstr "" +"이와 같은 옵션은 확장된 키 사용 값을 갖도록 지정하는 데 사용 될 수 있습니다. " +"다음 값은 쉼표로 분리된 목록에서 사용 될 수 있습니다:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:163 @@ -9397,6 +9646,8 @@ msgid "" "This template will add the DN string of the value which is stored in the " "directoryName component of the SAN." msgstr "" +"이와 같은 템플릿트는 SAN의 디렉토리명칭 구성 요소에서 저장된 것과 같은 DN " +"문자열이 추가됩니다." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:575 @@ -17093,6 +17344,8 @@ msgid "" "When using ldap_account_expire_policy=rhds or equivalent, this parameter " "determines if access is allowed or not." msgstr "" +"ldap_account_expire_policy=rhds 이거나 동일하게 사용 할 때에, 이와 같은 " +"매개변수는 접근 허용 여부를 결정합니다." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:368 @@ -17669,7 +17922,7 @@ msgstr "ldap_host_fqdn (문자열)" msgid "" "The LDAP attribute that corresponds to the host's fully-qualified domain " "name." -msgstr "" +msgstr "호스트의 정규화된 도메인 이름에 일치하는 LDAP 속성." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:907 diff --git a/src/man/po/pt.po b/src/man/po/pt.po index 93bac206ab4..3dee07a6cf2 100644 --- a/src/man/po/pt.po +++ b/src/man/po/pt.po @@ -9,7 +9,7 @@ msgstr "" "Project-Id-Version: sssd-docs 2.3.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" "POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 17:01+0000\n" +"PO-Revision-Date: 2026-05-12 17:59+0000\n" "Last-Translator: Américo Monteiro <a_monteiro@gmx.com>\n" "Language-Team: Portuguese <https://translate.fedoraproject.org/projects/sssd/" "sssd-manpage-master/pt/>\n" @@ -18,7 +18,7 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=(n != 1);\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 5.17.1\n" #. type: Content of: <reference><title> #: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 @@ -10486,8 +10486,8 @@ msgid "" "this file." msgstr "" "Provedor de autenticação krb5 do SSSD o qual é usado pelos provedores IPA e " -"AD assim como adiciona os endereços do KDC actual ou controlador de domínio " -"que o SSSD está usar para este ficheiro." +"AD também adiciona os endereços do KDC atual ou controlador de domínio que o " +"SSSD está usar para este ficheiro." #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:70 diff --git a/src/man/po/pt_BR.po b/src/man/po/pt_BR.po index ca104bd01fc..3ae0d3793c3 100644 --- a/src/man/po/pt_BR.po +++ b/src/man/po/pt_BR.po @@ -5,8 +5,8 @@ msgstr "" "Project-Id-Version: sssd-docs 2.3.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" "POT-Creation-Date: 2026-01-14 15:00+0000\n" -"PO-Revision-Date: 2026-04-23 16:56+0000\n" -"Last-Translator: Nari Ivy <nki.life@pm.me>\n" +"PO-Revision-Date: 2026-06-18 20:10+0000\n" +"Last-Translator: Rafael Fontenelle <rafaelff@gnome.org>\n" "Language-Team: Portuguese (Brazil) <https://translate.fedoraproject.org/" "projects/sssd/sssd-manpage-master/pt_BR/>\n" "Language: pt_BR\n" @@ -14,7 +14,7 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=2; plural=(n != 1);\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.6.1\n" #. type: Content of: <reference><title> #: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 @@ -453,6 +453,8 @@ msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" +"Controla se SSSD deve monitorar o estado de resolv.conf para identificar " +"quando ele precisa atualizar seu resolvedor interno de DNS." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:342 @@ -500,6 +502,8 @@ msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." msgstr "" +"Diretório no sistema de arquivos no qual SSSD deve armazenar arquivos cache " +"de reprodução de Kerberos." #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:375 @@ -1154,6 +1158,9 @@ msgid "" "if they are requested beyond a percentage of the entry_cache_timeout value " "for the domain." msgstr "" +"O cache de entrada pode ser definido para atualizar automaticamente entradas " +"em segundo plano se elas forem solicitadas além de uma porcentagem do valor " +"entry_cache_timeout para o domínio." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:911 @@ -1407,6 +1414,8 @@ msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." msgstr "" +"Especifica o tempo em segundos pelo qual a lista de subdomínios será " +"considerada válida." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1115 @@ -1785,7 +1794,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1459 sssd.conf.5.xml:2912 msgid "Display a warning N days before the password expires." -msgstr "" +msgstr "Exibe um aviso N dias antes da expiração da senha." #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1462 @@ -2909,6 +2918,10 @@ msgid "" "Matches user names as returned by NSS. I.e. after the possible space " "replacement, case changes, etc." msgstr "" +"Uma lista de usuários separados por vírgula que devem ter a gravação de " +"sessão ativada. Corresponde aos nomes de usuário retornados pelo NSS, ou " +"seja, após possíveis substituições de espaços, alterações de maiúsculas e " +"minúsculas, etc." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2438 sssd-session-recording.5.xml:115 @@ -2927,6 +2940,10 @@ msgid "" "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" +"Uma lista de grupos separados por vírgulas, cujos membros devem ter a " +"gravação de sessão ativada. Corresponde aos nomes dos grupos conforme " +"retornados pelo NSS, ou seja, após a possível substituição de espaços, " +"alterações de maiúsculas e minúsculas, etc." #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2452 sssd.conf.5.xml:2484 sssd-session-recording.5.xml:129 @@ -3297,6 +3314,8 @@ msgid "" "How many seconds to keep a host ssh key after refresh. IE how long to cache " "the host key for." msgstr "" +"Por quantos segundos manter uma chave SSH do host após a atualização. Ou " +"seja, por quanto tempo armazenar a chave do host em cache." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2789 @@ -3396,6 +3415,10 @@ msgid "" "this value determines the minimal length the first authentication factor " "(long term password) must have to be saved as SHA512 hash into the cache." msgstr "" +"Se a autenticação de dois fatores (2FA) for usada e as credenciais devem ser " +"salvas, este valor determina o comprimento mínimo que o primeiro fator de " +"autenticação (senha de longo prazo) deve ter para ser salvo como hash SHA512 " +"no cache." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2883 @@ -4466,6 +4489,8 @@ msgstr "" msgid "" "Various tags stored by the realmd configuration service for this domain." msgstr "" +"Várias tags armazenadas pelo serviço de configuração realmd para este " +"domínio." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3887 @@ -16588,7 +16613,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:808 msgid "The object class of a netgroup entry in LDAP." -msgstr "" +msgstr "A classe de objeto de uma entrada de grupo de rede no LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:811 @@ -16608,7 +16633,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:824 msgid "The LDAP attribute that corresponds to the netgroup name." -msgstr "" +msgstr "O atributo LDAP que corresponde ao nome do grupo de rede." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:828 @@ -16623,7 +16648,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:841 msgid "The LDAP attribute that contains the names of the netgroup's members." -msgstr "" +msgstr "O atributo LDAP que contém os nomes dos membros do grupo de rede." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:845 @@ -16674,7 +16699,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:897 msgid "The object class of a host entry in LDAP." -msgstr "" +msgstr "A classe de objeto de uma entrada de host no LDAP." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:997 @@ -16736,7 +16761,7 @@ msgstr "" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:961 msgid "The LDAP attribute that contains the host's SSH public keys." -msgstr "" +msgstr "O atributo LDAP que contém as chaves públicas SSH do host." #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:971 diff --git a/src/man/po/ro.po b/src/man/po/ro.po new file mode 100644 index 00000000000..e1d2408ae9a --- /dev/null +++ b/src/man/po/ro.po @@ -0,0 +1,18798 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Red Hat +# This file is distributed under the same license as the sssd-docs package. +# FIRST AUTHOR <EMAIL@ADDRESS>, YEAR. +# +msgid "" +msgstr "" +"Project-Id-Version: sssd-docs 2.12.0\n" +"Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" +"POT-Creation-Date: 2026-01-14 15:00+0000\n" +"PO-Revision-Date: 2026-05-14 05:59+0000\n" +"Last-Translator: Petru Rebeja <petru@rebeja.eu>\n" +"Language-Team: Romanian <https://translate.fedoraproject.org/projects/sssd/" +"sssd-manpage-master/ro/>\n" +"Language: ro\n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" +"Plural-Forms: nplurals=3; plural=n==1 ? 0 : (n==0 || (n%100 > 0 && n%100 < " +"20)) ? 1 : 2;\n" +"X-Generator: Weblate 5.17.1\n" + +#. type: Content of: <reference><title> +#: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 +#: sssd_krb5_locator_plugin.8.xml:5 sssd-simple.5.xml:5 sss-certmap.5.xml:5 +#: sssd-ipa.5.xml:5 sssd-ad.5.xml:5 sssd-sudo.5.xml:5 sssd-idp.5.xml:5 +#: sssd.8.xml:5 sss_obfuscate.8.xml:5 sss_override.8.xml:5 sssd-krb5.5.xml:5 +#: sss_cache.8.xml:5 sss_debuglevel.8.xml:5 sss_seed.8.xml:5 sssd-ifp.5.xml:5 +#: sss_rpcidmapd.5.xml:5 sss_ssh_authorizedkeys.1.xml:5 +#: sss_ssh_knownhosts.1.xml:5 idmap_sss.8.xml:5 sssctl.8.xml:5 +#: sssd-session-recording.5.xml:5 sssd-kcm.8.xml:5 sssd-systemtap.5.xml:5 +#: sssd-ldap-attributes.5.xml:5 sssd_krb5_localauth_plugin.8.xml:5 +msgid "SSSD Manual pages" +msgstr "Pagini ale manualului SSSD" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd.conf.5.xml:13 sssd.conf.5.xml:19 +msgid "sssd.conf" +msgstr "sssd.conf" + +#. type: Content of: <reference><refentry><refmeta><manvolnum> +#: sssd.conf.5.xml:14 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 +#: sss-certmap.5.xml:11 sssd-ipa.5.xml:11 sssd-ad.5.xml:11 sssd-sudo.5.xml:11 +#: sssd-idp.5.xml:11 sssd-krb5.5.xml:11 sssd-ifp.5.xml:11 +#: sss_rpcidmapd.5.xml:27 sssd-session-recording.5.xml:11 +#: sssd-systemtap.5.xml:11 sssd-ldap-attributes.5.xml:11 +msgid "5" +msgstr "5" + +#. type: Content of: <reference><refentry><refmeta><refmiscinfo> +#: sssd.conf.5.xml:15 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 +#: sss-certmap.5.xml:12 sssd-ipa.5.xml:12 sssd-ad.5.xml:12 sssd-sudo.5.xml:12 +#: sssd-idp.5.xml:12 sssd-krb5.5.xml:12 sssd-ifp.5.xml:12 +#: sss_rpcidmapd.5.xml:28 sssd-session-recording.5.xml:12 sssd-kcm.8.xml:12 +#: sssd-systemtap.5.xml:12 sssd-ldap-attributes.5.xml:12 +msgid "File Formats and Conventions" +msgstr "Formate ale fișierelor și convenții" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd.conf.5.xml:20 +msgid "the configuration file for SSSD" +msgstr "fișierul de configurare al SSSD" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:24 +msgid "FILE FORMAT" +msgstr "FORMAT FIȘIER" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd.conf.5.xml:32 +#, no-wrap +msgid "" +"<replaceable>[section]</replaceable>\n" +"<replaceable>key</replaceable> = <replaceable>value</replaceable>\n" +"<replaceable>key2</replaceable> = <replaceable>value2,value3</replaceable>\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:27 +msgid "" +"The file has an ini-style syntax and consists of sections and parameters. A " +"section begins with the name of the section in square brackets and continues " +"until the next section begins. An example of section with single and " +"multi-valued parameters: <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:39 +msgid "" +"The data types used are string (no quotes needed), integer and bool (with " +"values of <quote>TRUE/FALSE</quote>)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:44 +msgid "" +"A comment line starts with a hash sign (<quote>#</quote>) or a semicolon " +"(<quote>;</quote>). Inline comments are not supported." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:50 +msgid "" +"All sections can have an optional <replaceable>description</replaceable> " +"parameter. Its function is only as a label for the section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:56 +msgid "" +"<filename>sssd.conf</filename> must be a regular file that is owned, " +"readable, and writeable only by 'root'." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:60 +msgid "" +"<filename>sssd.conf</filename> must be a regular file that is accessible " +"only by the user used to run SSSD service or root." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:66 +msgid "CONFIGURATION SNIPPETS FROM INCLUDE DIRECTORY" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:69 +msgid "" +"The configuration file <filename>sssd.conf</filename> will include " +"configuration snippets using the include directory " +"<filename>conf.d</filename>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:75 +msgid "" +"Any file placed in <filename>conf.d</filename> that ends in " +"<quote><filename>.conf</filename></quote> and does not begin with a dot " +"(<quote>.</quote>) will be used together with <filename>sssd.conf</filename> " +"to configure SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:83 +msgid "" +"The configuration snippets from <filename>conf.d</filename> have higher " +"priority than <filename>sssd.conf</filename> and will override " +"<filename>sssd.conf</filename> when conflicts occur. If several snippets are " +"present in <filename>conf.d</filename>, then they are included in " +"alphabetical order (based on locale). Files included later have higher " +"priority. Numerical prefixes (<filename>01_snippet.conf</filename>, " +"<filename>02_snippet.conf</filename> etc.) can help visualize the priority " +"(higher number means higher priority)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:97 +msgid "" +"The snippet files require the same owner and permissions as " +"<filename>sssd.conf</filename>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:103 +msgid "GENERAL OPTIONS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:105 +msgid "Following options are usable in more than one configuration sections." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:109 +msgid "Options usable in all sections" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:113 +msgid "debug_level (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:117 +msgid "debug (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:120 +msgid "" +"SSSD 1.14 and later also includes the <replaceable>debug</replaceable> alias " +"for <replaceable>debug_level</replaceable> as a convenience feature. If both " +"are specified, the value of <replaceable>debug_level</replaceable> will be " +"used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:130 +msgid "debug_timestamps (bool)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:133 +msgid "" +"Add a timestamp to the debug messages. If journald is enabled for SSSD " +"debug logging this option is ignored." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:138 sssd.conf.5.xml:175 sssd.conf.5.xml:337 +#: sssd.conf.5.xml:644 sssd.conf.5.xml:668 sssd.conf.5.xml:875 +#: sssd.conf.5.xml:979 sssd.conf.5.xml:2113 sssd-ldap.5.xml:979 +#: sssd-ldap.5.xml:1134 sssd-ldap.5.xml:1237 sssd-ldap.5.xml:1306 +#: sssd-ldap.5.xml:1714 sssd-ldap.5.xml:1848 sssd-ldap.5.xml:1913 +#: sssd-ipa.5.xml:346 sssd-ad.5.xml:252 sssd-ad.5.xml:367 sssd-ad.5.xml:1180 +#: sssd-ad.5.xml:1382 sssd-krb5.5.xml:358 +msgid "Default: true" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:143 +msgid "debug_microseconds (bool)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:146 +msgid "" +"Add microseconds to the timestamp in debug messages. If journald is enabled " +"for SSSD debug logging this option is ignored." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:151 sssd.conf.5.xml:2040 sssd.conf.5.xml:4158 +#: sssd-ldap.5.xml:363 sssd-ldap.5.xml:998 sssd-ldap.5.xml:1209 +#: sssd-ldap.5.xml:1663 sssd-ldap.5.xml:1937 sssd-ipa.5.xml:146 +#: sssd-ipa.5.xml:706 sssd-ad.5.xml:1135 sssd-krb5.5.xml:268 +#: sssd-krb5.5.xml:330 sssd-krb5.5.xml:432 include/krb5_options.xml:163 +msgid "Default: false" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:156 +msgid "debug_backtrace_enabled (bool)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:159 +msgid "Enable debug backtrace." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:162 +msgid "" +"In case SSSD is run with debug_level less than 9, everything is logged to a " +"ring buffer in memory and flushed to a log file on any error up to and " +"including `min(0x0040, debug_level)` (i.e. if debug_level is explicitly set " +"to 0 or 1 then only those error levels will trigger backtrace, otherwise up " +"to 2)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:171 +msgid "" +"Feature is only supported for `logger == files` (i.e. setting doesn't have " +"effect for other logger types)." +msgstr "" + +#. type: Content of: outside any tag (error?) +#: sssd.conf.5.xml:111 sssd.conf.5.xml:186 sssd-ldap.5.xml:1754 +#: sssd-ldap.5.xml:1960 sss-certmap.5.xml:645 sssd-systemtap.5.xml:82 +#: sssd-systemtap.5.xml:143 sssd-systemtap.5.xml:236 sssd-systemtap.5.xml:274 +#: sssd-systemtap.5.xml:330 sssd-ldap-attributes.5.xml:40 +#: sssd-ldap-attributes.5.xml:661 sssd-ldap-attributes.5.xml:803 +#: sssd-ldap-attributes.5.xml:892 sssd-ldap-attributes.5.xml:989 +#: sssd-ldap-attributes.5.xml:1047 sssd-ldap-attributes.5.xml:1205 +#: sssd-ldap-attributes.5.xml:1250 sssd-ldap-attributes.5.xml:1295 +#: include/autofs_attributes.xml:1 include/krb5_options.xml:1 +msgid "<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:184 +msgid "Options usable in SERVICE and DOMAIN sections" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:188 +msgid "timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:191 +msgid "" +"Timeout in seconds between heartbeats for this service. This is used to " +"ensure that the process is alive and capable of answering requests. Note " +"that after three missed heartbeats the process will terminate itself." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:198 sssd.conf.5.xml:1199 sssd.conf.5.xml:1673 +#: sssd.conf.5.xml:4174 sssd-ldap.5.xml:825 sssd-idp.5.xml:192 +#: include/ldap_id_mapping.xml:270 +msgid "Default: 10" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:208 +msgid "SPECIAL SECTIONS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:211 +msgid "The [sssd] section" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><title> +#: sssd.conf.5.xml:220 +msgid "Section parameters" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:222 +msgid "services" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:225 +msgid "" +"Comma separated list of services that are started when sssd itself starts. " +"<phrase condition=\"have_systemd\"> The services' list is optional on " +"platforms where systemd is supported, as they will either be socket or D-Bus " +"activated when needed. </phrase>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:234 +msgid "" +"Supported services: nss, pam, ifp <phrase condition=\"with_sudo\">, " +"sudo</phrase> <phrase condition=\"with_autofs\">, autofs</phrase> <phrase " +"condition=\"with_ssh\">, ssh</phrase> <phrase " +"condition=\"with_pac_responder\">, pac</phrase>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:241 +msgid "" +"<phrase condition=\"have_systemd\"> By default, all services are disabled " +"and the administrator must enable the ones allowed to be used by executing: " +"\"systemctl enable sssd-@service@.socket\". </phrase>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:250 +msgid "domains" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:253 +msgid "" +"A domain is a database containing user information. SSSD can use more " +"domains at the same time, but at least one must be configured or SSSD won't " +"start. This parameter describes the list of domains in the order you want " +"them to be queried. A domain name is recommended to contain only " +"alphanumeric ASCII characters, dashes, dots and underscores. '/' character " +"is forbidden." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:266 sssd.conf.5.xml:3467 +msgid "re_expression (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:269 +msgid "" +"Default regular expression that describes how to parse the string containing " +"user name and domain into these components." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:274 +msgid "" +"Each domain can have an individual regular expression configured. For some " +"ID providers there are also default regular expressions. See DOMAIN SECTIONS " +"for more info on these regular expressions." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:283 sssd.conf.5.xml:3524 +msgid "full_name_format (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:286 sssd.conf.5.xml:3527 +msgid "" +"A <citerefentry> <refentrytitle>printf</refentrytitle> " +"<manvolnum>3</manvolnum> </citerefentry>-compatible format that describes " +"how to compose a fully qualified name from user name and domain name " +"components." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:297 sssd.conf.5.xml:3538 +msgid "%1$s" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:298 sssd.conf.5.xml:3539 +msgid "user name" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:301 sssd.conf.5.xml:3542 +msgid "%2$s" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:304 sssd.conf.5.xml:3545 +msgid "domain name as specified in the SSSD config file." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:310 sssd.conf.5.xml:3551 +msgid "%3$s" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:313 sssd.conf.5.xml:3554 +msgid "" +"domain flat name. Mostly usable for Active Directory domains, both directly " +"configured or discovered via IPA trusts." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:294 sssd.conf.5.xml:3535 +msgid "" +"The following expansions are supported: <placeholder type=\"variablelist\" " +"id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:323 +msgid "" +"Each domain can have an individual format string configured. See DOMAIN " +"SECTIONS for more info on this option." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:329 +msgid "monitor_resolv_conf (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:332 +msgid "" +"Controls if SSSD should monitor the state of resolv.conf to identify when it " +"needs to update its internal DNS resolver." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:342 +msgid "try_inotify (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:345 +msgid "" +"By default, SSSD will attempt to use inotify to monitor configuration files " +"changes and will fall back to polling every five seconds if inotify cannot " +"be used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:351 +msgid "" +"There are some limited situations where it is preferred that we should skip " +"even trying to use inotify. In these rare cases, this option should be set " +"to 'false'" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:357 +msgid "" +"Default: true on platforms where inotify is supported. False on other " +"platforms." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:361 +msgid "" +"Note: this option will have no effect on platforms where inotify is " +"unavailable. On these platforms, polling will always be used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:368 +msgid "krb5_rcache_dir (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:371 +msgid "" +"Directory on the filesystem where SSSD should store Kerberos replay cache " +"files." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:375 +msgid "" +"This option accepts a special value __LIBKRB5_DEFAULTS__ that will instruct " +"SSSD to let libkrb5 decide the appropriate location for the replay cache." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:381 +msgid "" +"Default: Distribution-specific and specified at " +"build-time. (__LIBKRB5_DEFAULTS__ if not configured)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:388 +msgid "default_domain_suffix (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:391 +msgid "" +"Please note that this option is deprecated and domain_resolution_order " +"should be used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:395 +msgid "" +"This string will be used as a default domain name for all names without a " +"domain name component. The main use case is environments where the primary " +"domain is intended for managing host policies and all users are located in a " +"trusted domain. The option allows those users to log in just with their " +"user name without giving a domain name as well." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:405 +msgid "" +"Please note that if this option is set all users from the primary domain " +"have to use their fully qualified name, e.g. user@domain.name, to log " +"in. Setting this option changes default of use_fully_qualified_names to " +"True. It is not allowed to use this option together with " +"use_fully_qualified_names set to False." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:414 sssd-ldap.5.xml:937 sssd-ldap.5.xml:949 +#: sssd-ldap.5.xml:1042 sssd-ad.5.xml:921 sssd-ad.5.xml:996 sssd-krb5.5.xml:468 +#: sssd-ldap-attributes.5.xml:470 sssd-ldap-attributes.5.xml:978 +#: include/ldap_id_mapping.xml:211 include/ldap_id_mapping.xml:222 +#: include/krb5_options.xml:148 +msgid "Default: not set" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:419 +msgid "override_space (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:422 +msgid "" +"This parameter will replace spaces (space bar) with the given character for " +"user and group names. e.g. (_). User name "john doe" will be " +""john_doe" This feature was added to help compatibility with shell " +"scripts that have difficulty handling spaces, due to the default field " +"separator in the shell." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:431 +msgid "" +"Please note it is a configuration error to use a replacement character that " +"might be used in user or group names. If a name contains the replacement " +"character SSSD tries to return the unmodified name but in general the result " +"of a lookup is undefined." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:439 +msgid "Default: not set (spaces will not be replaced)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:444 +msgid "certificate_verification (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:452 +msgid "no_ocsp" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:454 +msgid "" +"Disables Online Certificate Status Protocol (OCSP) checks. This might be " +"needed if the OCSP servers defined in the certificate are not reachable from " +"the client." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:462 +msgid "soft_ocsp" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:464 +msgid "" +"If a connection cannot be established to an OCSP responder the OCSP check is " +"skipped. This option should be used to allow authentication when the system " +"is offline and the OCSP responder cannot be reached." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:474 +msgid "ocsp_dgst" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:476 +msgid "" +"Digest (hash) function used to create the certificate ID for the OCSP " +"request. Allowed values are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:480 +msgid "sha1" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:481 +msgid "sha256" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:482 +msgid "sha384" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:483 +msgid "sha512" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:486 +msgid "Default: sha1 (to allow compatibility with RFC5019-compliant responder)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:492 +msgid "no_verification" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:494 +msgid "" +"Disables verification completely. This option should only be used for " +"testing." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:500 +msgid "partial_chain" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:502 +msgid "" +"Allow verification to succeed even if a <replaceable>complete</replaceable> " +"chain cannot be built to a self-signed trust-anchor, provided it is possible " +"to construct a chain to a trusted certificate that might not be self-signed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:511 +msgid "ocsp_default_responder=URL" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:513 +msgid "" +"Sets the OCSP default responder which should be used instead of the one " +"mentioned in the certificate. URL must be replaced with the URL of the OCSP " +"default responder e.g. http://example.com:80/ocsp." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:523 +msgid "ocsp_default_responder_signing_cert=NAME" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:525 +msgid "" +"This option is currently ignored. All needed certificates must be available " +"in the PEM file given by pam_cert_db_path." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:533 +msgid "crl_file=/PATH/TO/CRL/FILE" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:535 +msgid "" +"Use the Certificate Revocation List (CRL) from the given file during the " +"verification of the certificate. The CRL must be given in PEM format, see " +"<citerefentry> <refentrytitle>crl</refentrytitle> " +"<manvolnum>1ssl</manvolnum> </citerefentry> for details." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:548 +msgid "soft_crl" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:551 +msgid "" +"If a Certificate Revocation List (CRL) is expired ignore the expiration " +"time of the CRL and check the related certificates with the expired " +"CRL. This option should be used to allow authentication when the system is " +"offline and the CRL cannot be renewed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:447 +msgid "" +"With this parameter the certificate verification can be tuned with a comma " +"separated list of options. Supported options are: <placeholder " +"type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:564 +msgid "Unknown options are reported but ignored." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:567 +msgid "Default: not set, i.e. do not restrict certificate verification" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:573 +msgid "disable_netlink (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:576 +msgid "" +"SSSD hooks into the netlink interface to monitor changes to routes, " +"addresses, links and trigger certain actions." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:581 +msgid "" +"The SSSD state changes caused by netlink events may be undesirable and can " +"be disabled by setting this option to 'true'" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:586 +msgid "Default: false (netlink changes are detected)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:591 +msgid "domain_resolution_order" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:594 +msgid "" +"Comma separated list of domains and subdomains representing the lookup order " +"that will be followed. The list doesn't have to include all possible " +"domains as the missing domains will be looked up based on the order they're " +"presented in the <quote>domains</quote> configuration option. The " +"subdomains which are not listed as part of <quote>lookup_order</quote> will " +"be looked up in a random order for each parent domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:606 +msgid "" +"Please, note that when this option is set the output format of all commands " +"is always fully-qualified even when using short names for input. In case " +"the administrator wants the output not fully-qualified, the full_name_format " +"option can be used as shown below: <quote>full_name_format=%1$s</quote> " +"However, keep in mind that during login, login applications often " +"canonicalize the username by calling <citerefentry> " +"<refentrytitle>getpwnam</refentrytitle> <manvolnum>3</manvolnum> " +"</citerefentry> which, if a shortname is returned for a qualified input " +"(while trying to reach a user which exists in multiple domains) might " +"re-route the login attempt into the domain which uses shortnames, making " +"this workaround totally not recommended in cases where usernames may overlap " +"between domains." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:630 sssd.conf.5.xml:1697 sssd.conf.5.xml:4224 +#: sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 sssd-idp.5.xml:108 +#: sssd-idp.5.xml:132 sssd-idp.5.xml:145 sssd-idp.5.xml:159 sssd-idp.5.xml:180 +msgid "Default: Not set" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:635 +msgid "implicit_pac_responder (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:638 +msgid "" +"The PAC responder is enabled automatically for the IPA and AD provider to " +"evaluate and check the PAC. If it has to be disabled set this option to " +"'false'." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:649 +msgid "core_dumpable (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:652 +msgid "" +"This option can be used for general system hardening: setting it to 'false' " +"forbids core dumps for all SSSD processes to avoid leaking plain text " +"passwords. See man page prctl:PR_SET_DUMPABLE on Linux or " +"procctl:PROC_TRACE_CTL on FreeBSD for details." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:660 +msgid "" +"Take a note that this setting has no effect for 'ldap_child', 'krb5_child' " +"and 'sssd_pam' as those privileged binaries can have a copy of a host keytab " +"data in a memory and their behavior in this regards is governed by " +"/proc/sys/fs/suid_dumpable system setting." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:673 +msgid "passkey_verification (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:681 +msgid "user_verification (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:683 +msgid "" +"Enable or disable the user verification (i.e. PIN, fingerprint) during " +"authentication. If enabled, the PIN will always be requested." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:689 +msgid "" +"The default is that the key settings decide what to do. In the IPA or " +"kerberos pre-authentication case, this value will be overwritten by the " +"server." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:676 +msgid "" +"With this parameter the passkey verification can be tuned with a comma " +"separated list of options. Supported options are: <placeholder " +"type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:213 +msgid "" +"Individual pieces of SSSD functionality are provided by special SSSD " +"services that are started and stopped together with SSSD. The services are " +"managed by a special service frequently called <quote>monitor</quote>. The " +"<quote>[sssd]</quote> section is used to configure the monitor as well as " +"some other important options like the identity domains. <placeholder " +"type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:708 +msgid "SERVICES SECTIONS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:710 +msgid "" +"Settings that can be used to configure different services are described in " +"this section. They should reside in the [<replaceable>$NAME</replaceable>] " +"section, for example, for NSS service, the section would be " +"<quote>[nss]</quote>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:717 +msgid "General service configuration options" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:719 +msgid "These options can be used to configure any service." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:723 +msgid "fd_limit" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:726 +msgid "" +"This option specifies the maximum number of file descriptors that may be " +"opened at one time by this SSSD process. On systems where SSSD is granted " +"the CAP_SYS_RESOURCE capability, this will be an absolute setting. On " +"systems without this capability, the resulting value will be the lower value " +"of this or the limits.conf \"hard\" limit." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:735 +msgid "Default: 8192 (or limits.conf \"hard\" limit)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:740 +msgid "client_idle_timeout" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:743 +msgid "" +"This option specifies the number of seconds that a client of an SSSD process " +"can hold onto a file descriptor without communicating on it. This value is " +"limited in order to avoid resource exhaustion on the system. The timeout " +"can't be shorter than 10 seconds. If a lower value is configured, it will be " +"adjusted to 10 seconds." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:752 +msgid "Default: 60, KCM: 300" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:757 +msgid "offline_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:760 +msgid "" +"When SSSD switches to offline mode the amount of time before it tries to go " +"back online will increase based upon the time spent disconnected. By " +"default SSSD uses incremental behaviour to calculate delay in between " +"retries. So, the wait time for a given retry will be longer than the wait " +"time for the previous ones. After each unsuccessful attempt to go online, " +"the new interval is recalculated by the following:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:771 sssd.conf.5.xml:827 +msgid "" +"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " +"random[0...offline_timeout_random_offset]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:774 +msgid "" +"The offline_timeout default value is 60. The offline_timeout_max default " +"value is 3600. The offline_timeout_random_offset default value is 30. The " +"end result is amount of seconds before next retry." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:780 +msgid "" +"Note that the maximum length of each interval is defined by " +"offline_timeout_max (apart of random part)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:784 sssd.conf.5.xml:1110 sssd.conf.5.xml:1490 +#: sssd.conf.5.xml:1791 sssd-ldap.5.xml:550 +msgid "Default: 60" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:789 +msgid "offline_timeout_max (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:792 +msgid "" +"Controls by how much the time between attempts to go online can be " +"incremented following unsuccessful attempts to go online." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:797 +msgid "A value of 0 disables the incrementing behaviour." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:800 +msgid "" +"The value of this parameter should be set in correlation to offline_timeout " +"parameter value." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:804 +msgid "" +"With offline_timeout set to 60 (default value) there is no point in setting " +"offlinet_timeout_max to less than 120 as it will saturate instantly. General " +"rule here should be to set offline_timeout_max to at least 4 times " +"offline_timeout." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:810 +msgid "" +"Although a value between 0 and offline_timeout may be specified, it has the " +"effect of overriding the offline_timeout value so is of little use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:815 +msgid "Default: 3600" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:820 +msgid "offline_timeout_random_offset (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:823 +msgid "" +"When SSSD is in offline mode it keeps probing backend servers in specified " +"time intervals:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:830 +msgid "" +"This parameter controls the value of the random offset used for the above " +"equation. Final random_offset value will be random number in range:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:835 +msgid "[0 - offline_timeout_random_offset]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:838 +msgid "A value of 0 disables the random offset addition." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:841 +msgid "Default: 30" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:846 +msgid "responder_idle_timeout" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:849 +msgid "" +"This option specifies the number of seconds that an SSSD responder process " +"can be up without being used. This value is limited in order to avoid " +"resource exhaustion on the system. The minimum acceptable value for this " +"option is 60 seconds. Setting this option to 0 (zero) means that no timeout " +"will be set up to the responder. This option only has effect when SSSD is " +"built with systemd support and when services are either socket or D-Bus " +"activated." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:863 sssd.conf.5.xml:1123 sssd.conf.5.xml:2248 +#: sssd-ldap.5.xml:377 +msgid "Default: 300" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:868 +msgid "cache_first" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:871 +msgid "" +"This option specifies whether the responder should query all caches before " +"querying the Data Providers." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:883 +msgid "NSS configuration options" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:885 +msgid "" +"These options can be used to configure the Name Service Switch (NSS) " +"service." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:890 +msgid "enum_cache_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:893 +msgid "" +"How many seconds should nss_sss cache enumerations (requests for info about " +"all users)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:897 +msgid "Default: 120" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:902 +msgid "entry_cache_nowait_percentage (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:905 +msgid "" +"The entry cache can be set to automatically update entries in the background " +"if they are requested beyond a percentage of the entry_cache_timeout value " +"for the domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:911 +msgid "" +"For example, if the domain's entry_cache_timeout is set to 30s and " +"entry_cache_nowait_percentage is set to 50 (percent), entries that come in " +"after 15 seconds past the last cache update will be returned immediately, " +"but the SSSD will go and update the cache on its own, so that future " +"requests will not need to block waiting for a cache update." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:921 +msgid "" +"Valid values for this option are 0-99 and represent a percentage of the " +"entry_cache_timeout for each domain. For performance reasons, this " +"percentage will never reduce the nowait timeout to less than 10 seconds. (0 " +"disables this feature)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:929 sssd.conf.5.xml:2061 +msgid "Default: 50" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:934 +msgid "entry_negative_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:937 +msgid "" +"Specifies for how many seconds nss_sss should cache negative cache hits " +"(that is, queries for invalid database entries, like nonexistent ones) " +"before asking the back end again." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:943 sssd.conf.5.xml:1685 sssd.conf.5.xml:2085 +msgid "Default: 15" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:948 +msgid "filter_users, filter_groups (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:951 +msgid "" +"Exclude certain users or groups from being fetched from the sss NSS " +"database. This is particularly useful for system accounts. This option can " +"also be set per-domain or include fully-qualified names to filter only users " +"from the particular domain or by a user principal name (UPN)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:959 +msgid "" +"NOTE: The filter_groups option doesn't affect inheritance of nested group " +"members, since filtering happens after they are propagated for returning via " +"NSS. E.g. a group having a member group filtered out will still have the " +"member users of the latter listed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:967 +msgid "Default: root" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:972 +msgid "filter_users_in_groups (bool)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:975 +msgid "If you want filtered user still be group members set this option to false." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:986 +msgid "fallback_homedir (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:989 +msgid "" +"Set a default template for a user's home directory if one is not specified " +"explicitly by the domain's data provider." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:994 +msgid "The available values for this option are the same as for override_homedir." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1000 +#, no-wrap +msgid "" +"fallback_homedir = /home/%u\n" +" " +msgstr "" + +#. type: Content of: <varlistentry><listitem><para> +#: sssd.conf.5.xml:998 sssd.conf.5.xml:1557 sssd.conf.5.xml:1576 +#: sssd.conf.5.xml:1653 sssd-krb5.5.xml:451 include/override_homedir.xml:78 +msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1004 +msgid "Default: not set (no substitution for unset home directories)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1010 +msgid "override_shell (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1013 +msgid "" +"Override the login shell for all users. This option supersedes any other " +"shell options if it takes effect and can be set either in the [nss] section " +"or per-domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1019 +msgid "Default: not set (SSSD will use the value retrieved from LDAP)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1025 +msgid "allowed_shells (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1028 +msgid "Restrict user shell to one of the listed values. The order of evaluation is:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1031 +msgid "1. If the shell is present in <quote>/etc/shells</quote>, it is used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1035 +msgid "" +"2. If the shell is in the allowed_shells list but not in " +"<quote>/etc/shells</quote>, use the value of the shell_fallback parameter." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1040 +msgid "" +"3. If the shell is not in the allowed_shells list and not in " +"<quote>/etc/shells</quote>, a nologin shell is used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1045 +msgid "The wildcard (*) can be used to allow any shell." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1048 +msgid "" +"The (*) is useful if you want to use shell_fallback in case that user's " +"shell is not in <quote>/etc/shells</quote> and maintaining list of all " +"allowed shells in allowed_shells would be to much overhead." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1055 +msgid "An empty string for shell is passed as-is to libc." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1058 +msgid "" +"The <quote>/etc/shells</quote> is only read on SSSD start up, which means " +"that a restart of the SSSD is required in case a new shell is installed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1062 +msgid "Default: Not set. The user shell is automatically used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1067 +msgid "vetoed_shells (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1070 +msgid "Replace any instance of these shells with the shell_fallback" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1075 +msgid "shell_fallback (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1078 +msgid "" +"The default shell to use if an allowed shell is not installed on the " +"machine." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1082 +msgid "Default: /bin/sh" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1087 +msgid "default_shell" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1090 +msgid "" +"The default shell to use if the provider does not return one during " +"lookup. This option can be specified globally in the [nss] section or " +"per-domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1096 +msgid "" +"Default: not set (Return NULL if no shell is specified and rely on libc to " +"substitute something sensible when necessary, usually /bin/sh)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1103 sssd.conf.5.xml:1483 +msgid "get_domains_timeout (int)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1106 sssd.conf.5.xml:1486 +msgid "" +"Specifies time in seconds for which the list of subdomains will be " +"considered valid." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1115 +msgid "memcache_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1118 +msgid "" +"Specifies time in seconds for which records in the in-memory cache will be " +"valid. Setting this option to zero will disable the in-memory cache." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1126 +msgid "" +"WARNING: Disabling the in-memory cache will have significant negative impact " +"on SSSD's performance and should only be used for testing." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1132 sssd.conf.5.xml:1157 sssd.conf.5.xml:1182 +#: sssd.conf.5.xml:1207 sssd.conf.5.xml:1234 +msgid "" +"NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", " +"client applications will not use the fast in-memory cache." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1140 +msgid "memcache_size_passwd (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1143 +msgid "" +"Size (in megabytes) of the data table allocated inside fast in-memory cache " +"for passwd requests. Setting the size to 0 will disable the passwd " +"in-memory cache." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1149 sssd.conf.5.xml:2888 sssd-ldap.5.xml:604 +msgid "Default: 8" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1152 sssd.conf.5.xml:1177 sssd.conf.5.xml:1202 +#: sssd.conf.5.xml:1229 +msgid "" +"WARNING: Disabled or too small in-memory cache can have significant negative " +"impact on SSSD's performance." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1165 +msgid "memcache_size_group (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1168 +msgid "" +"Size (in megabytes) of the data table allocated inside fast in-memory cache " +"for group requests. Setting the size to 0 will disable the group in-memory " +"cache." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1174 sssd.conf.5.xml:1226 sssd.conf.5.xml:3656 +#: sssd-ldap.5.xml:534 sssd-ldap.5.xml:581 include/failover.xml:116 +#: include/krb5_options.xml:11 +msgid "Default: 6" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1190 +msgid "memcache_size_initgroups (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1193 +msgid "" +"Size (in megabytes) of the data table allocated inside fast in-memory cache " +"for initgroups requests. Setting the size to 0 will disable the initgroups " +"in-memory cache." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1215 +msgid "memcache_size_sid (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1218 +msgid "" +"Size (in megabytes) of the data table allocated inside fast in-memory cache " +"for SID related requests. Only SID-by-ID and ID-by-SID requests are " +"currently cached in fast in-memory cache. Setting the size to 0 will " +"disable the SID in-memory cache." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1242 sssd-ifp.5.xml:90 +msgid "user_attributes (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1245 +msgid "" +"Some of the additional NSS responder requests can return more attributes " +"than just the POSIX ones defined by the NSS interface. The list of " +"attributes is controlled by this option. It is handled the same way as the " +"<quote>user_attributes</quote> option of the InfoPipe responder (see " +"<citerefentry> <refentrytitle>sssd-ifp</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> for details) but with no default " +"values." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1258 +msgid "" +"To make configuration more easy the NSS responder will check the InfoPipe " +"option if it is not set for the NSS responder." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1263 +msgid "Default: not set, fallback to InfoPipe option" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1268 +msgid "pwfield (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1271 +msgid "" +"The value that NSS operations that return users or groups will return for " +"the <quote>password</quote> field." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1276 +msgid "Default: <quote>*</quote>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1279 +msgid "" +"Note: This option can also be set per-domain which overwrites the value in " +"[nss] section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1283 +msgid "" +"Default: <quote>not set</quote> (remote domains), <quote>x</quote> (proxy " +"domain with nss_files and sssd-shadowutils target)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:1292 +msgid "PAM configuration options" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:1294 +msgid "" +"These options can be used to configure the Pluggable Authentication Module " +"(PAM) service." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1299 +msgid "offline_credentials_expiration (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1302 +msgid "" +"If the authentication provider is offline, how long should we allow cached " +"logins (in days since the last successful online login)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1307 sssd.conf.5.xml:1320 +msgid "Default: 0 (No limit)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1313 +msgid "offline_failed_login_attempts (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1316 +msgid "" +"If the authentication provider is offline, how many failed login attempts " +"are allowed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1326 +msgid "offline_failed_login_delay (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1329 +msgid "" +"The time in minutes which has to pass after offline_failed_login_attempts " +"has been reached before a new login attempt is possible." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1334 +msgid "" +"If set to 0 the user cannot authenticate offline if " +"offline_failed_login_attempts has been reached. Only a successful online " +"authentication can enable offline authentication again." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1340 sssd.conf.5.xml:1450 +msgid "Default: 5" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1346 +msgid "pam_verbosity (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1349 +msgid "" +"Controls what kind of messages are shown to the user during " +"authentication. The higher the number to more messages are displayed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1354 +msgid "Currently sssd supports the following values:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1357 +msgid "<emphasis>0</emphasis>: do not show any message" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1360 +msgid "<emphasis>1</emphasis>: show only important messages" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1364 +msgid "<emphasis>2</emphasis>: show informational messages" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1367 +msgid "<emphasis>3</emphasis>: show all messages and debug information" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1371 sssd.8.xml:63 +msgid "Default: 1" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1377 +msgid "pam_response_filter (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1380 +msgid "" +"A comma separated list of strings which allows to remove (filter) data sent " +"by the PAM responder to pam_sss PAM module. There are different kind of " +"responses sent to pam_sss e.g. messages displayed to the user or environment " +"variables which should be set by pam_sss." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1388 +msgid "" +"While messages already can be controlled with the help of the pam_verbosity " +"option this option allows to filter out other kind of responses as well." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1395 +msgid "ENV" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1396 +msgid "Do not send any environment variables to any service." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1399 +msgid "ENV:var_name" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1400 +msgid "Do not send environment variable var_name to any service." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1404 +msgid "ENV:var_name:service" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1405 +msgid "Do not send environment variable var_name to service." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1393 +msgid "" +"Currently the following filters are supported: <placeholder " +"type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1412 +msgid "" +"The list of strings can either be the list of filters which would set this " +"list of filters and overwrite the defaults. Or each element of the list can " +"be prefixed by a '+' or '-' character which would add the filter to the " +"existing default or remove it from the defaults, respectively. Please note " +"that either all list elements must have a '+' or '-' prefix or none. It is " +"considered as an error to mix both styles." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1423 +msgid "Default: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1426 +msgid "Example: -ENV:KRB5CCNAME:sudo-i will remove the filter from the default list" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1433 +msgid "pam_id_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1436 +msgid "" +"For any PAM request while SSSD is online, the SSSD will attempt to " +"immediately update the cached identity information for the user in order to " +"ensure that authentication takes place with the latest information." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1442 +msgid "" +"A complete PAM conversation may perform multiple PAM requests, such as " +"account management and session opening. This option controls (on a " +"per-client-application basis) how long (in seconds) we can cache the " +"identity information to avoid excessive round-trips to the identity " +"provider." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1456 +msgid "pam_pwd_expiration_warning (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1459 sssd.conf.5.xml:2912 +msgid "Display a warning N days before the password expires." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1462 +msgid "" +"Please note that the backend server has to provide information about the " +"expiration time of the password. If this information is missing, sssd " +"cannot display a warning." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1468 sssd.conf.5.xml:2915 +msgid "" +"If zero is set, then this filter is not applied, i.e. if the expiration " +"warning was received from backend server, it will automatically be " +"displayed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1473 +msgid "" +"This setting can be overridden by setting " +"<emphasis>pwd_expiration_warning</emphasis> for a particular domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1478 sssd.conf.5.xml:3913 sssd-ldap.5.xml:662 +#: sssd-ldap.5.xml:1733 sssd.8.xml:79 +msgid "Default: 0" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1495 +msgid "pam_trusted_users (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1498 +msgid "" +"Specifies the comma-separated list of UID values or user names that are " +"allowed to run PAM conversations against trusted domains. Users not " +"included in this list can only access domains marked as public with " +"<quote>pam_public_domains</quote>. User names are resolved to UIDs at " +"startup." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1508 +msgid "Default: All users are considered trusted by default" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1512 +msgid "" +"Please note that UID 0 is always allowed to access the PAM responder even in " +"case it is not in the pam_trusted_users list." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1519 +msgid "pam_public_domains (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1522 +msgid "" +"Specifies the comma-separated list of domain names that are accessible even " +"to untrusted users." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1526 +msgid "Two special values for pam_public_domains option are defined:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1530 +msgid "all (Untrusted users are allowed to access all domains in PAM responder.)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1534 +msgid "" +"none (Untrusted users are not allowed to access any domains PAM in " +"responder.)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1538 sssd.conf.5.xml:1563 sssd.conf.5.xml:1582 +#: sssd.conf.5.xml:1824 sssd.conf.5.xml:3842 sssd-ldap.5.xml:1270 +msgid "Default: none" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1543 +msgid "pam_account_expired_message (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1546 +msgid "" +"Allows a custom expiration message to be set, replacing the default " +"'Permission denied' message." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1551 +msgid "" +"Note: Please be aware that message is only printed for the SSH service " +"unless pam_verbosity is set to 3 (show all messages and debug information)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1559 +#, no-wrap +msgid "" +"pam_account_expired_message = Account expired, please contact help desk.\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1568 +msgid "pam_account_locked_message (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1571 +msgid "" +"Allows a custom lockout message to be set, replacing the default 'Permission " +"denied' message." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1578 +#, no-wrap +msgid "" +"pam_account_locked_message = Account locked, please contact help desk.\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1587 +msgid "pam_passkey_auth (bool)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1590 +msgid "Enable passkey device based authentication." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1593 sssd.conf.5.xml:1910 sssd-ad.5.xml:1286 +#: sss_rpcidmapd.5.xml:76 +msgid "Default: True" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1598 +msgid "passkey_debug_libfido2 (bool)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1601 +msgid "Enable libfido2 library debug messages." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1604 sssd.conf.5.xml:1618 sssd-ldap.5.xml:727 +#: sssd-ldap.5.xml:752 sssd-ldap.5.xml:848 sssd-ldap.5.xml:1356 +#: sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1155 +#: include/ldap_id_mapping.xml:250 +msgid "Default: False" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1609 +msgid "pam_cert_auth (bool)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1612 +msgid "" +"Enable certificate based Smartcard authentication. Since this requires " +"additional communication with the Smartcard which will delay the " +"authentication process this option is disabled by default." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1623 +msgid "pam_cert_db_path (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1626 +msgid "The path to the certificate database." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1629 sssd.conf.5.xml:2163 sssd.conf.5.xml:4338 +msgid "Default:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1631 sssd.conf.5.xml:2165 +msgid "" +"/etc/sssd/pki/sssd_auth_ca_db.pem (path to a file with trusted CA " +"certificates in PEM format)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1641 +msgid "pam_cert_verification (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1644 +msgid "" +"With this parameter the PAM certificate verification can be tuned with a " +"comma separated list of options that override the " +"<quote>certificate_verification</quote> value in <quote>[sssd]</quote> " +"section. Supported options are the same of " +"<quote>certificate_verification</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1655 +#, no-wrap +msgid "" +"pam_cert_verification = partial_chain\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1659 +msgid "" +"Default: not set, i.e. use default <quote>certificate_verification</quote> " +"option defined in <quote>[sssd]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1666 +msgid "p11_child_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1669 +msgid "How many seconds will pam_sss wait for p11_child to finish." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1678 +msgid "passkey_child_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1681 +msgid "How many seconds will the PAM responder wait for passkey_child to finish." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1690 +msgid "pam_app_services (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1693 +msgid "" +"Which PAM services are permitted to contact domains of type " +"<quote>application</quote>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1702 +msgid "pam_p11_allowed_services (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1705 +msgid "" +"A comma-separated list of PAM service names for which it will be allowed to " +"use Smartcards." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1720 +#, no-wrap +msgid "" +"pam_p11_allowed_services = +my_pam_service, -login\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1709 +msgid "" +"It is possible to add another PAM service name to the default set by using " +"<quote>+service_name</quote> or to explicitly remove a PAM service name from " +"the default set by using <quote>-service_name</quote>. For example, in order " +"to replace a default PAM service name for authentication with Smartcards " +"(e.g. <quote>login</quote>) with a custom PAM service name " +"(e.g. <quote>my_pam_service</quote>), you would use the following " +"configuration: <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1724 sssd-ad.5.xml:645 sssd-ad.5.xml:754 sssd-ad.5.xml:812 +#: sssd-ad.5.xml:870 sssd-ad.5.xml:948 +msgid "Default: the default set of PAM service names includes:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1729 sssd-ad.5.xml:649 +msgid "login" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1734 sssd-ad.5.xml:654 +msgid "su" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1739 sssd-ad.5.xml:659 +msgid "su-l" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1744 sssd-ad.5.xml:674 +msgid "gdm-smartcard" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1749 sssd-ad.5.xml:669 +msgid "gdm-password" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1754 +msgid "gdm-switchable-auth" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1759 sssd-ad.5.xml:679 +msgid "kdm" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1764 sssd-ad.5.xml:957 +msgid "sudo" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1769 sssd-ad.5.xml:962 +msgid "sudo-i" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1774 +msgid "gnome-screensaver" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1782 +msgid "p11_wait_for_card_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1785 +msgid "" +"If Smartcard authentication is required how many extra seconds in addition " +"to p11_child_timeout should the PAM responder wait until a Smartcard is " +"inserted." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1796 +msgid "p11_uri (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1799 +msgid "" +"PKCS#11 URI (see RFC-7512 for details) which can be used to restrict the " +"selection of devices used for Smartcard authentication. By default SSSD's " +"p11_child will search for a PKCS#11 slot (reader) where the 'removable' " +"flags is set and read the certificates from the inserted token from the " +"first slot found. If multiple readers are connected p11_uri can be used to " +"tell p11_child to use a specific reader." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1812 +#, no-wrap +msgid "" +"p11_uri = pkcs11:slot-description=My%20Smartcard%20Reader\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1816 +#, no-wrap +msgid "" +"p11_uri = " +"pkcs11:library-description=OpenSC%20smartcard%20framework;slot-id=2\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1810 +msgid "" +"Example: <placeholder type=\"programlisting\" id=\"0\"/> or <placeholder " +"type=\"programlisting\" id=\"1\"/> To find suitable URI please check the " +"debug output of p11_child. As an alternative the GnuTLS utility 'p11tool' " +"with e.g. the '--list-all' will show PKCS#11 URIs as well." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1829 +msgid "pam_initgroups_scheme" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1837 +msgid "always" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1838 +msgid "Always do an online lookup, please note that pam_id_timeout still applies" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1842 +msgid "no_session" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1843 +msgid "" +"Only do an online lookup if there is no active session of the user, i.e. if " +"the user is currently not logged in" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1848 sssd-ldap.5.xml:189 +msgid "never" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1849 +msgid "" +"Never force an online lookup, use the data from the cache as long as they " +"are not expired" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1832 +msgid "" +"The PAM responder can force an online lookup to get the current group " +"memberships of the user trying to log in. This option controls when this " +"should be done and the following values are allowed: <placeholder " +"type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1856 +msgid "Default: no_session" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:1861 sssd.conf.5.xml:4277 +msgid "pam_gssapi_services" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1864 +msgid "" +"Comma separated list of PAM services that are allowed to try GSSAPI " +"authentication using pam_sss_gss.so module." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1869 +msgid "" +"To disable GSSAPI authentication, set this option to <quote>-</quote> " +"(dash)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1873 sssd.conf.5.xml:1904 sssd.conf.5.xml:1942 +msgid "" +"Note: This option can also be set per-domain which overwrites the value in " +"[pam] section. It can also be set for trusted domain which overwrites the " +"value in the domain section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1881 +#, no-wrap +msgid "" +"pam_gssapi_services = sudo, sudo-i\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1879 sssd.conf.5.xml:1994 sssd.conf.5.xml:3836 +msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1885 +msgid "Default: - (GSSAPI authentication is disabled)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:1890 sssd.conf.5.xml:4278 +msgid "pam_gssapi_check_upn" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1893 +msgid "" +"If True, SSSD will require that the Kerberos user principal that " +"successfully authenticated through GSSAPI can be associated with the user " +"who is being authenticated. Authentication will fail if the check fails." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1900 +msgid "" +"If False, every user that is able to obtained required service ticket will " +"be authenticated." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1915 +msgid "pam_gssapi_indicators_map" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1918 +msgid "" +"Comma separated list of authentication indicators required to be present in " +"a Kerberos ticket to access a PAM service that is allowed to try GSSAPI " +"authentication using pam_sss_gss.so module." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1924 +msgid "" +"Each element of the list can be either an authentication indicator name or a " +"pair <quote>service:indicator</quote>. Indicators not prefixed with the PAM " +"service name will be required to access any PAM service configured to be " +"used with <option>pam_gssapi_services</option>. A resulting list of " +"indicators per PAM service is then checked against indicators in the " +"Kerberos ticket during authentication by pam_sss_gss.so. Any indicator from " +"the ticket that matches the resulting list of indicators for the PAM service " +"would grant access. If none of the indicators in the list match, access will " +"be denied. If the resulting list of indicators for the PAM service is empty, " +"the check will not prevent the access." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1937 +msgid "" +"To disable GSSAPI authentication indicator check, set this option to " +"<quote>-</quote> (dash). To disable the check for a specific PAM service, " +"add <quote>service:-</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1948 +msgid "" +"Following authentication indicators are supported by IPA Kerberos " +"deployments:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1951 +msgid "" +"pkinit -- pre-authentication using X.509 certificates -- whether stored in " +"files or on smart cards." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1954 +msgid "" +"hardened -- SPAKE pre-authentication or any pre-authentication wrapped in a " +"FAST channel." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1957 +msgid "radius -- pre-authentication with the help of a RADIUS server." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1960 +msgid "" +"otp -- pre-authentication using integrated two-factor authentication (2FA or " +"one-time password, OTP) in IPA." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:1963 +msgid "idp -- pre-authentication using external identity provider." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1973 +#, no-wrap +msgid "" +"pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1968 +msgid "" +"Example: to require access to SUDO services only for users which obtained " +"their Kerberos tickets with a X.509 certificate pre-authentication (PKINIT), " +"set <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1977 +msgid "Default: not set (use of authentication indicators is not required)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:1982 +msgid "pam_json_services (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1985 +msgid "" +"Comma separated list of PAM services which can handle the JSON protocol for " +"selecting authentication mechanisms" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:1990 +msgid "To disable JSON protocol, set this option to <quote>-</quote> (dash)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:1996 +#, no-wrap +msgid "" +"pam_json_services = gdm-switchable-auth\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2000 +msgid "Default: - (JSON protocol is disabled)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2003 +msgid "" +"Note: 2-Factor Authentication (2FA) is not supported. If 2FA is required, do " +"not activate the JSON protocol." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:2013 +msgid "SUDO configuration options" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2015 +msgid "" +"These options can be used to configure the sudo service. The detailed " +"instructions for configuration of <citerefentry> " +"<refentrytitle>sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " +"to work with <citerefentry> <refentrytitle>sssd</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> are in the manual page " +"<citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2032 +msgid "sudo_timed (bool)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2035 +msgid "" +"Whether or not to evaluate the sudoNotBefore and sudoNotAfter attributes " +"that implement time-dependent sudoers entries." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2047 +msgid "sudo_threshold (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2050 +msgid "" +"Maximum number of expired rules that can be refreshed at once. If number of " +"expired rules is below threshold, those rules are refreshed with " +"<quote>rules refresh</quote> mechanism. If the threshold is exceeded a " +"<quote>full refresh</quote> of sudo rules is triggered instead. This " +"threshold number also applies to IPA sudo command and command group " +"searches." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:2069 +msgid "AUTOFS configuration options" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2071 +msgid "These options can be used to configure the autofs service." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2075 +msgid "autofs_negative_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2078 +msgid "" +"Specifies for how many seconds should the autofs responder negative cache " +"hits (that is, queries for invalid map entries, like nonexistent ones) " +"before asking the back end again." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:2094 +msgid "SSH configuration options" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2096 +msgid "These options can be used to configure the SSH service." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2100 +msgid "ssh_use_certificate_keys (bool)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2103 +msgid "" +"If set to true the <command>sss_ssh_authorizedkeys</command> will return ssh " +"keys derived from the public key of X.509 certificates stored in the user " +"entry as well. See <citerefentry> " +"<refentrytitle>sss_ssh_authorizedkeys</refentrytitle> " +"<manvolnum>1</manvolnum> </citerefentry> for details." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2118 +msgid "ssh_use_certificate_matching_rules (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2121 +msgid "" +"By default the ssh responder will use all available certificate matching " +"rules to filter the certificates so that ssh keys are only derived from the " +"matching ones. With this option the used rules can be restricted with a " +"comma separated list of mapping and matching rule names. All other rules " +"will be ignored." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2130 +msgid "" +"There are two special key words 'all_rules' and 'no_rules' which will enable " +"all or no rules, respectively. The latter means that no certificates will be " +"filtered out and ssh keys will be generated from all valid certificates." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2137 +msgid "" +"If no rules are configured using 'all_rules' will enable a default rule " +"which enables all certificates suitable for client authentication. This is " +"the same behavior as for the PAM responder if certificate authentication is " +"enabled." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2144 +msgid "" +"A non-existing rule name is considered an error. If as a result no rule is " +"selected all certificates will be ignored." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2149 +msgid "" +"Default: not set, equivalent to 'all_rules', all found rules or the default " +"rule are used" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2155 +msgid "ca_db (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2158 +msgid "" +"Path to a storage of trusted CA certificates. The option is used to validate " +"user certificates before deriving public ssh keys from them." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:2178 +msgid "PAC responder configuration options" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2180 +msgid "" +"The PAC responder works together with the authorization data plugin for MIT " +"Kerberos sssd_pac_plugin.so and a sub-domain provider. The plugin sends the " +"PAC data during a GSSAPI authentication to the PAC responder. The sub-domain " +"provider collects domain SID and ID ranges of the domain the client is " +"joined to and of remote trusted domains from the local domain controller. If " +"the PAC is decoded and evaluated some of the following operations are done:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:2189 +msgid "" +"If the remote user does not exist in the cache, it is created. The UID is " +"determined with the help of the SID, trusted domains will have UPGs and the " +"GID will have the same value as the UID. The home directory is set based on " +"the subdomain_homedir parameter. The shell will be empty by default, " +"i.e. the system defaults are used, but can be overwritten with the " +"default_shell parameter." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:2197 +msgid "" +"If there are SIDs of groups from domains sssd knows about, the user will be " +"added to those groups." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2203 +msgid "These options can be used to configure the PAC responder." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2207 sssd-ifp.5.xml:66 +msgid "allowed_uids (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2210 +msgid "" +"Specifies the comma-separated list of UID values or user names that are " +"allowed to access the PAC responder. User names are resolved to UIDs at " +"startup." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2216 +msgid "" +"Default: 0, &sssd_user_name; (only root and SSSD service users are allowed " +"to access the PAC responder)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2220 +msgid "Default: 0 (only the root user is allowed to access the PAC responder)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2224 +msgid "" +"Please note that defaults will be overwritten with this option. If you still " +"want to allow the root and/or '&sssd_user_name;' user to access the PAC " +"responder, which would be the typical case, you have to add those to the " +"list of allowed UIDs explicitly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2231 +msgid "" +"Please note that although the UID 0 is used as the default it will be " +"overwritten with this option. If you still want to allow the root user to " +"access the PAC responder, which would be the typical case, you have to add 0 " +"to the list of allowed UIDs as well." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2240 +msgid "pac_lifetime (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2243 +msgid "" +"Lifetime of the PAC entry in seconds. As long as the PAC is valid the PAC " +"data can be used to determine the group memberships of a user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2253 +msgid "pac_check (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2256 +msgid "" +"Apply additional checks on the PAC of the Kerberos ticket which is available " +"in Active Directory and FreeIPA domains, if configured. Please note that " +"Kerberos ticket validation must be enabled to be able to check the PAC, " +"i.e. the krb5_validate option must be set to 'True' which is the default for " +"the IPA and AD provider. If krb5_validate is set to 'False' the PAC checks " +"will be skipped." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2266 +msgid "" +"Please note that the checks listed below only apply to PACs issued by Active " +"Directory or recent versions of FreeIPA. PACs issued e.g. by a plain MIT " +"Kerberos KDC will not contain the needed PAC data buffers to run the checks." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2277 +msgid "no_check" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2279 +msgid "" +"The PAC must not be present and even if it is present no additional checks " +"will be done." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2285 +msgid "pac_present" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2287 +msgid "" +"The PAC must be present in the service ticket which SSSD will request with " +"the help of the user's TGT. If the PAC is not available the authentication " +"will fail." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2295 +msgid "check_upn" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2297 +msgid "" +"If the PAC is present check if the user principal name (UPN) information is " +"consistent." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2303 +msgid "check_upn_allow_missing" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2305 +msgid "" +"This option should be used together with 'check_upn' and handles the case " +"where a UPN is set on the server-side but is not read by SSSD. The typical " +"example is a FreeIPA domain where 'ldap_user_principal' is set to a not " +"existing attribute name. This was typically done to work-around issues in " +"the handling of enterprise principals. But this is fixed since quite some " +"time and FreeIPA can handle enterprise principals just fine and there is no " +"need anymore to set 'ldap_user_principal'." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2317 +msgid "" +"Currently this option is set by default to avoid regressions in such " +"environments. A log message will be added to the system log and SSSD's debug " +"log in case a UPN is found in the PAC but not in SSSD's cache. To avoid this " +"log message it would be best to evaluate if the 'ldap_user_principal' option " +"can be removed. If this is not possible, removing 'check_upn' will skip the " +"test and avoid the log message." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2331 +msgid "upn_dns_info_present" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2333 +msgid "The PAC must contain the UPN-DNS-INFO buffer, implies 'check_upn'." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2338 +msgid "check_upn_dns_info_ex" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2340 +msgid "" +"If the PAC is present and the extension to the UPN-DNS-INFO buffer is " +"available check if the information in the extension is consistent." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2347 +msgid "upn_dns_info_ex_present" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2349 +msgid "" +"The PAC must contain the extension of the UPN-DNS-INFO buffer, implies " +"'check_upn_dns_info_ex', 'upn_dns_info_present' and 'check_upn'." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2273 +msgid "" +"The following options can be used alone or in a comma-separated list: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2359 +msgid "" +"Default: no_check (AD and IPA provider 'check_upn, check_upn_allow_missing, " +"check_upn_dns_info_ex')" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:2368 +msgid "Session recording configuration options" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2370 +msgid "" +"Session recording works in conjunction with <citerefentry> " +"<refentrytitle>tlog-rec-session</refentrytitle> <manvolnum>8</manvolnum> " +"</citerefentry>, a part of tlog package, to log what users see and type when " +"they log in on a text terminal. See also <citerefentry> " +"<refentrytitle>sssd-session-recording</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:2383 +msgid "These options can be used to configure session recording." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2387 sssd-session-recording.5.xml:64 +msgid "scope (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2394 sssd-session-recording.5.xml:71 +msgid "\"none\"" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2397 sssd-session-recording.5.xml:74 +msgid "No users are recorded." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2402 sssd-session-recording.5.xml:79 +msgid "\"some\"" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2405 sssd-session-recording.5.xml:82 +msgid "" +"Users/groups specified by <replaceable>users</replaceable> and " +"<replaceable>groups</replaceable> options are recorded." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2414 sssd-session-recording.5.xml:91 +msgid "\"all\"" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2417 sssd-session-recording.5.xml:94 +msgid "All users are recorded." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2390 sssd-session-recording.5.xml:67 +msgid "" +"One of the following strings specifying the scope of session recording: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2424 sssd-session-recording.5.xml:101 +msgid "Default: \"none\"" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2429 sssd-session-recording.5.xml:106 +msgid "users (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2432 sssd-session-recording.5.xml:109 +msgid "" +"A comma-separated list of users which should have session recording " +"enabled. Matches user names as returned by NSS. I.e. after the possible " +"space replacement, case changes, etc." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2438 sssd-session-recording.5.xml:115 +msgid "Default: Empty. Matches no users." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:120 +msgid "groups (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2446 sssd-session-recording.5.xml:123 +msgid "" +"A comma-separated list of groups, members of which should have session " +"recording enabled. Matches group names as returned by NSS. I.e. after the " +"possible space replacement, case changes, etc." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2452 sssd.conf.5.xml:2484 sssd-session-recording.5.xml:129 +#: sssd-session-recording.5.xml:161 +msgid "" +"NOTE: using this option (having it set to anything) has a considerable " +"performance cost, because each uncached request for a user requires " +"retrieving and matching the groups the user is member of." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2459 sssd-session-recording.5.xml:136 +msgid "Default: Empty. Matches no groups." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2464 sssd-session-recording.5.xml:141 +msgid "exclude_users (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2467 sssd-session-recording.5.xml:144 +msgid "" +"A comma-separated list of users to be excluded from recording, only " +"applicable with 'scope=all'." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2471 sssd-session-recording.5.xml:148 +msgid "Default: Empty. No users excluded." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2476 sssd-session-recording.5.xml:153 +msgid "exclude_groups (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2479 sssd-session-recording.5.xml:156 +msgid "" +"A comma-separated list of groups, members of which should be excluded from " +"recording. Only applicable with 'scope=all'." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2491 sssd-session-recording.5.xml:168 +msgid "Default: Empty. No groups excluded." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:2501 +msgid "DOMAIN SECTIONS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd.conf.5.xml:2508 sssd.conf.5.xml:3964 sssd.conf.5.xml:3965 +#: sssd.conf.5.xml:3968 +msgid "enabled" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2511 +msgid "" +"Explicitly enable or disable the domain. If <quote>true</quote>, the domain " +"is always <quote>enabled</quote>. If <quote>false</quote>, the domain is " +"always <quote>disabled</quote>. If this option is not set, the domain is " +"enabled only if it is listed in the domains option in the " +"<quote>[sssd]</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2523 +msgid "domain_type (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2526 +msgid "" +"Specifies whether the domain is meant to be used by POSIX-aware clients such " +"as the Name Service Switch or by applications that do not need POSIX data to " +"be present or generated. Only objects from POSIX domains are available to " +"the operating system interfaces and utilities." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2534 +msgid "" +"Allowed values for this option are <quote>posix</quote> and " +"<quote>application</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2538 +msgid "" +"POSIX domains are reachable by all services. Application domains are only " +"reachable from the InfoPipe responder (see <citerefentry> " +"<refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry>) and the PAM responder." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2546 +msgid "" +"NOTE: The application domains are currently well tested with " +"<quote>id_provider=ldap</quote> only." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2550 +msgid "" +"For an easy way to configure a non-POSIX domains, please see the " +"<quote>Application domains</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2554 +msgid "Default: posix" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2560 +msgid "min_id,max_id (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2563 +msgid "" +"UID and GID limits for the domain. If a domain contains an entry that is " +"outside these limits, it is ignored." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2568 +msgid "" +"For users, this affects the primary GID limit. The user will not be returned " +"to NSS if either the UID or the primary GID is outside the range. For " +"non-primary group memberships, those that are in range will be reported as " +"expected." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2575 +msgid "" +"These ID limits affect even saving entries to cache, not only returning them " +"by name or ID." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2579 +msgid "Default: 1 for min_id, 0 (no limit) for max_id" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2585 +msgid "enumerate (bool)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2588 +msgid "" +"Determines if a domain can be enumerated, that is, whether the domain can " +"list all the users and group it contains. Note that it is not required to " +"enable enumeration in order for secondary groups to be displayed. This " +"parameter can have one of the following values:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2596 +msgid "TRUE = Users and groups are enumerated" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2599 +msgid "FALSE = No enumerations for this domain" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2602 sssd.conf.5.xml:2867 sssd.conf.5.xml:3044 +msgid "Default: FALSE" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2605 +msgid "" +"Enumerating a domain requires SSSD to download and store ALL user and group " +"entries from the remote server." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2610 +msgid "" +"Feature is only supported for domains with id_provider = ldap or id_provider " +"= proxy." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2614 +msgid "" +"Note: Enabling enumeration has a severe performance impact on SSSD while " +"enumeration is running. It may take up to several minutes after SSSD startup " +"to fully complete enumerations. During this time, individual requests for " +"information will go directly to LDAP, though it may be slow, due to the " +"heavy enumeration processing. Saving a large number of entries to cache " +"after the enumeration completes might also be CPU intensive as the " +"memberships have to be recomputed. This can lead to the " +"<quote>sssd_be</quote> process becoming unresponsive or even restarted by " +"the internal watchdog." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2629 +msgid "" +"While the first enumeration is running, requests for the complete user or " +"group lists may return no results until it completes." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2634 +msgid "" +"Further, enabling enumeration may increase the time necessary to detect " +"network disconnection, as longer timeouts are required to ensure that " +"enumeration lookups are completed successfully. For more information, refer " +"to the man pages for the specific id_provider in use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2642 +msgid "" +"For the reasons cited above, enabling enumeration is not recommended, " +"especially in large environments." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2647 +msgid "" +"Note: the proxy provider is tested with open source modules like " +"'libnss_files' and 'libnss_ldap'. 3rd party modules must follow the " +"documented behavior of nss modules to be used in this configuration." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2656 +msgid "entry_cache_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2659 +msgid "" +"How many seconds should nss_sss consider entries valid before asking the " +"backend again" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2663 +msgid "" +"The cache expiration timestamps are stored as attributes of individual " +"objects in the cache. Therefore, changing the cache timeout only has effect " +"for newly added or expired entries. You should run the <citerefentry> " +"<refentrytitle>sss_cache</refentrytitle> <manvolnum>8</manvolnum> " +"</citerefentry> tool in order to force refresh of entries that have already " +"been cached." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2676 +msgid "Default: 5400" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2682 +msgid "entry_cache_user_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2685 +msgid "" +"How many seconds should nss_sss consider user entries valid before asking " +"the backend again" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2689 sssd.conf.5.xml:2702 sssd.conf.5.xml:2715 +#: sssd.conf.5.xml:2728 sssd.conf.5.xml:2742 sssd.conf.5.xml:2755 +#: sssd.conf.5.xml:2769 sssd.conf.5.xml:2783 sssd.conf.5.xml:2796 +msgid "Default: entry_cache_timeout" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2695 +msgid "entry_cache_group_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2698 +msgid "" +"How many seconds should nss_sss consider group entries valid before asking " +"the backend again" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2708 +msgid "entry_cache_netgroup_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2711 +msgid "" +"How many seconds should nss_sss consider netgroup entries valid before " +"asking the backend again" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2721 +msgid "entry_cache_service_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2724 +msgid "" +"How many seconds should nss_sss consider service entries valid before asking " +"the backend again" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2734 +msgid "entry_cache_resolver_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2737 +msgid "" +"How many seconds should nss_sss consider hosts and networks entries valid " +"before asking the backend again" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2748 +msgid "entry_cache_sudo_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2751 +msgid "" +"How many seconds should sudo consider rules valid before asking the backend " +"again" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2761 +msgid "entry_cache_autofs_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2764 +msgid "" +"How many seconds should the autofs service consider automounter maps valid " +"before asking the backend again" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2775 +msgid "entry_cache_ssh_host_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2778 +msgid "" +"How many seconds to keep a host ssh key after refresh. IE how long to cache " +"the host key for." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2789 +msgid "entry_cache_computer_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2792 +msgid "" +"How many seconds to keep the local computer entry before asking the backend " +"again" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2802 +msgid "refresh_expired_interval (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2805 +msgid "" +"Specifies how many seconds SSSD has to wait before triggering a background " +"refresh task which will refresh all expired or nearly expired records." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2810 +msgid "" +"The background refresh will process users, groups and netgroups in the " +"cache. For users who have performed the initgroups (get group membership for " +"user, typically ran at login) operation in the past, both the user entry " +"and the group membership are updated." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2818 +msgid "This option is automatically inherited for all trusted domains." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2822 +msgid "You can consider setting this value to 3/4 * entry_cache_timeout." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2826 +msgid "" +"Cache entry will be refreshed by background task when 2/3 of cache timeout " +"has already passed. If there are existing cached entries, the background " +"task will refer to their original cache timeout values instead of current " +"configuration value. This may lead to a situation in which background " +"refresh task appears to not be working. This is done by design to improve " +"offline mode operation and reuse of existing valid cache entries. To make " +"this change instant the user may want to manually invalidate existing cache." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2839 sssd-ldap.5.xml:406 sssd-ldap.5.xml:1834 +#: sssd-ipa.5.xml:255 +msgid "Default: 0 (disabled)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2845 +msgid "cache_credentials (bool)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2848 +msgid "" +"Determines if user credentials are also cached in the local LDB cache. The " +"cached credentials refer to passwords, which includes the first (long term) " +"factor of two-factor authentication, not other authentication " +"mechanisms. Passkey and Smartcard authentications are expected to work " +"offline as long as a successful online authentication is recorded in the " +"cache without additional configuration." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2859 +msgid "" +"Take a note that while credentials are stored as a salted SHA512 hash, this " +"still potentially poses some security risk in case an attacker manages to " +"get access to a cache file (normally requires privileged access) and to " +"break a password using brute force attack." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2873 +msgid "cache_credentials_minimal_first_factor_length (int)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2876 +msgid "" +"If 2-Factor-Authentication (2FA) is used and credentials should be saved " +"this value determines the minimal length the first authentication factor " +"(long term password) must have to be saved as SHA512 hash into the cache." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2883 +msgid "" +"This should avoid that the short PINs of a PIN based 2FA scheme are saved in " +"the cache which would make them easy targets for brute-force attacks." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2894 +msgid "account_cache_expiration (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2897 +msgid "" +"Number of days entries are left in cache after last successful login before " +"being removed during a cleanup of the cache. 0 means keep forever. The " +"value of this parameter must be greater than or equal to " +"offline_credentials_expiration." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2904 +msgid "Default: 0 (unlimited)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2909 +msgid "pwd_expiration_warning (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2920 +msgid "" +"Please note that the backend server has to provide information about the " +"expiration time of the password. If this information is missing, sssd " +"cannot display a warning. Also an auth provider has to be configured for the " +"backend." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2927 +msgid "Default: 7 (Kerberos), 0 (LDAP)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2933 +msgid "id_provider (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2936 +msgid "" +"The identification provider used for the domain. Supported ID providers " +"are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2940 +msgid "<quote>proxy</quote>: Support a legacy NSS provider." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2943 +msgid "" +"<quote>ldap</quote>: LDAP provider. See <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> for more information on configuring LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2951 sssd.conf.5.xml:3070 sssd.conf.5.xml:3129 +#: sssd.conf.5.xml:3192 +msgid "" +"<quote>ipa</quote>: FreeIPA and Red Hat Identity Management provider. See " +"<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " +"FreeIPA." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2960 sssd.conf.5.xml:3079 sssd.conf.5.xml:3138 +#: sssd.conf.5.xml:3201 +msgid "" +"<quote>ad</quote>: Active Directory provider. See <citerefentry> " +"<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> for more information on configuring Active Directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2968 +msgid "" +"<quote>idp</quote>: Provider for OAuth 2.0/OIDC based Identity Providers " +"(IdP). See <citerefentry> <refentrytitle>sssd-idp</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> for more information." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:2979 +msgid "use_fully_qualified_names (bool)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2982 +msgid "" +"Use the full name and domain (as formatted by the domain's full_name_format) " +"as the user's login name reported to NSS." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2987 +msgid "" +"If set to TRUE, all requests to this domain must use fully qualified " +"names. For example, if used in EXAMPLE domain that contains a \"test\" user, " +"<command>getent passwd test</command> wouldn't find the user while " +"<command>getent passwd test@EXAMPLE</command> would." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:2995 +msgid "" +"NOTE: This option has no effect on netgroup lookups due to their tendency to " +"include nested netgroups without qualified names. For netgroups, all domains " +"will be searched when an unqualified name is requested." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3002 +msgid "" +"Default: FALSE (TRUE for trusted domain/sub-domains or if " +"default_domain_suffix is used)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3009 +msgid "ignore_group_members (bool)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3012 +msgid "Do not return group members for group lookups." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3015 +msgid "" +"If set to TRUE, the group membership attribute is not requested from the " +"ldap server, and group members are not returned when processing group lookup " +"calls, such as <citerefentry> <refentrytitle>getgrnam</refentrytitle> " +"<manvolnum>3</manvolnum> </citerefentry> or <citerefentry> " +"<refentrytitle>getgrgid</refentrytitle> <manvolnum>3</manvolnum> " +"</citerefentry>. As an effect, <quote>getent group $groupname</quote> would " +"return the requested group as if it was empty." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3033 +msgid "" +"Enabling this option can also make access provider checks for group " +"membership significantly faster, especially for groups containing many " +"members." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3039 sssd.conf.5.xml:3767 sssd-ldap.5.xml:401 +#: sssd-ldap.5.xml:454 sssd-ldap.5.xml:529 sssd-ldap.5.xml:576 +#: sssd-ldap.5.xml:599 sssd-ldap.5.xml:638 sssd-ldap.5.xml:657 +#: sssd-ldap.5.xml:681 sssd-ldap.5.xml:1114 sssd-ldap.5.xml:1147 +msgid "" +"This option can be also set per subdomain or inherited via " +"<emphasis>subdomain_inherit</emphasis>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3049 +msgid "auth_provider (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3052 +msgid "" +"The authentication provider used for the domain. Supported auth providers " +"are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3056 sssd.conf.5.xml:3122 +msgid "" +"<quote>ldap</quote> for native LDAP authentication. See <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> for more information on configuring LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3063 +msgid "" +"<quote>krb5</quote> for Kerberos authentication. See <citerefentry> " +"<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> for more information on configuring Kerberos." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3087 +msgid "" +"<quote>idp</quote>: Provider for OAuth 2.0/OIDC based authentication. See " +"<citerefentry> <refentrytitle>sssd-idp</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> for more information." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3095 +msgid "<quote>proxy</quote> for relaying authentication to some other PAM target." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3098 +msgid "<quote>none</quote> disables authentication explicitly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3101 +msgid "" +"Default: <quote>id_provider</quote> is used if it is set and can handle " +"authentication requests." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3107 +msgid "access_provider (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3110 +msgid "" +"The access control provider used for the domain. There are two built-in " +"access providers (in addition to any included in installed backends) " +"Internal special providers are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3116 +msgid "<quote>permit</quote> always allow access." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3119 +msgid "<quote>deny</quote> always deny access." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3146 +msgid "" +"<quote>simple</quote> access control based on access or deny lists. See " +"<citerefentry> <refentrytitle>sssd-simple</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry> for more information on configuring " +"the simple access module." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3153 +msgid "" +"<quote>krb5</quote>: .k5login based access control. See <citerefentry> " +"<refentrytitle>sssd-krb5</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry> for more information on configuring " +"Kerberos." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3160 +msgid "<quote>proxy</quote> for relaying access control to another PAM module." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3163 +msgid "Default: <quote>permit</quote>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3168 +msgid "chpass_provider (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3171 +msgid "" +"The provider which should handle change password operations for the domain. " +"Supported change password providers are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3176 +msgid "" +"<quote>ldap</quote> to change a password stored in a LDAP server. See " +"<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " +"LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3184 +msgid "" +"<quote>krb5</quote> to change the Kerberos password. See <citerefentry> " +"<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> for more information on configuring Kerberos." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3209 +msgid "<quote>proxy</quote> for relaying password changes to some other PAM target." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3213 +msgid "<quote>none</quote> disallows password changes explicitly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3216 +msgid "" +"Default: <quote>auth_provider</quote> is used if it is set and can handle " +"change password requests." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3223 +msgid "sudo_provider (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3226 +msgid "The SUDO provider used for the domain. Supported SUDO providers are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3230 +msgid "" +"<quote>ldap</quote> for rules stored in LDAP. See <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> for more information on configuring LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3238 +msgid "" +"<quote>ipa</quote> the same as <quote>ldap</quote> but with IPA default " +"settings." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3242 +msgid "" +"<quote>ad</quote> the same as <quote>ldap</quote> but with AD default " +"settings." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3246 +msgid "<quote>none</quote> disables SUDO explicitly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3249 +msgid "" +"Default: The value of <quote>id_provider</quote> is used if it is set and " +"can handle sudo requests." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3253 +msgid "" +"The detailed instructions for configuration of sudo_provider are in the " +"manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>. There are many configuration " +"options that can be used to adjust the behavior. Please refer to " +"\"ldap_sudo_*\" in <citerefentry> <refentrytitle>sssd-ldap</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3268 +msgid "" +"<emphasis>NOTE:</emphasis> Sudo rules are periodically downloaded in the " +"background unless the sudo provider is explicitly disabled. Set " +"<emphasis>sudo_provider = None</emphasis> to disable all sudo-related " +"activity in SSSD if you do not want to use sudo with SSSD at all." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3278 +msgid "selinux_provider (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3281 +msgid "" +"The provider which should handle loading of selinux settings. Note that this " +"provider will be called right after access provider ends. Supported selinux " +"providers are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3287 +msgid "" +"<quote>ipa</quote> to load selinux settings from an IPA server. See " +"<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " +"IPA." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3295 +msgid "<quote>none</quote> disallows fetching selinux settings explicitly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3298 +msgid "" +"Default: <quote>id_provider</quote> is used if it is set and can handle " +"selinux loading requests." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3304 +msgid "subdomains_provider (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3307 +msgid "" +"The provider which should handle fetching of subdomains. This value should " +"be always the same as id_provider. Supported subdomain providers are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3313 +msgid "" +"<quote>ipa</quote> to load a list of subdomains from an IPA server. See " +"<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " +"IPA." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3322 +msgid "" +"<quote>ad</quote> to load a list of subdomains from an Active Directory " +"server. See <citerefentry> <refentrytitle>sssd-ad</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " +"the AD provider." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3331 +msgid "<quote>none</quote> disallows fetching subdomains explicitly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3335 +msgid "" +"Default: The value of <quote>id_provider</quote> is used if it is set and " +"can handle subdomain requests." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3341 +msgid "session_provider (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3344 +msgid "" +"The provider which configures and manages user session related tasks. The " +"only user session task currently provided is the integration with Fleet " +"Commander, which works only with IPA. Supported session providers are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3351 +msgid "<quote>ipa</quote> to allow performing user session related tasks." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3355 +msgid "<quote>none</quote> does not perform any kind of user session related tasks." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3359 +msgid "Default: <quote>none</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3365 +msgid "autofs_provider (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3368 +msgid "The autofs provider used for the domain. Supported autofs providers are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3372 +msgid "" +"<quote>ldap</quote> to load maps stored in LDAP. See <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> for more information on configuring LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3379 +msgid "" +"<quote>ipa</quote> to load maps stored in an IPA server. See <citerefentry> " +"<refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> for more information on configuring IPA." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3387 +msgid "" +"<quote>ad</quote> to load maps stored in an AD server. See <citerefentry> " +"<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> for more information on configuring the AD provider." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3396 +msgid "<quote>none</quote> disables autofs explicitly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3399 +msgid "" +"Default: The value of <quote>id_provider</quote> is used if it is set and " +"can handle autofs requests." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3406 +msgid "hostid_provider (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3409 +msgid "" +"The provider used for retrieving host identity information. Supported " +"hostid providers are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3413 +msgid "" +"<quote>ipa</quote> to load host identity stored in an IPA server. See " +"<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " +"IPA." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3421 +msgid "<quote>none</quote> disables hostid explicitly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3424 +msgid "" +"Default: The value of <quote>id_provider</quote> is used if it is set and " +"can handle hostid requests." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3431 +msgid "resolver_provider (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3434 +msgid "" +"The provider which should handle hosts and networks lookups. Supported " +"resolver providers are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3438 +msgid "" +"<quote>proxy</quote> to forward lookups to another NSS library. See " +"<quote>proxy_resolver_lib_name</quote>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3442 +msgid "" +"<quote>ldap</quote> to fetch hosts and networks stored in LDAP. See " +"<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " +"LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3449 +msgid "" +"<quote>ad</quote> to fetch hosts and networks stored in AD. See " +"<citerefentry> <refentrytitle>sssd-ad</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " +"the AD provider." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3457 +msgid "<quote>none</quote> disallows fetching hosts and networks explicitly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3460 +msgid "" +"Default: The value of <quote>id_provider</quote> is used if it is set and " +"can handle resolver requests." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3470 +msgid "" +"Regular expression for this domain that describes how to parse the string " +"containing user name and domain into these components. The \"domain\" can " +"match either the SSSD configuration domain name, or, in the case of IPA " +"trust subdomains and Active Directory domains, the flat (NetBIOS) name of " +"the domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3479 +msgid "" +"Default: " +"<quote>^((?P<name>.+)@(?P<domain>[^@]*)|(?P<name>[^@]+))$</quote> " +"which allows two different styles for user names:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:3484 sssd.conf.5.xml:3498 +msgid "username" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:3487 sssd.conf.5.xml:3501 +msgid "username@domain.name" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3492 +msgid "" +"Default for the AD and IPA provider: " +"<quote>^(((?P<domain>[^\\\\]+)\\\\(?P<name>.+))|((?P<name>.+)@(?P<domain>[^@]+))|((?P<name>[^@\\\\]+)))$</quote> " +"which allows three different styles for user names:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:3504 +msgid "domain\\username" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3507 +msgid "" +"While the first two correspond to the general default the third one is " +"introduced to allow easy integration of users from Windows domains." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3512 +msgid "" +"The default re_expression uses the <quote>@</quote> character as a separator " +"between the name and the domain. As a result of this setting the default " +"does not accept the <quote>@</quote> character in short names (as it is " +"allowed in Windows group names). If a user wishes to use short names with " +"<quote>@</quote> they must create their own re_expression." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3564 +msgid "Default: <quote>%1$s@%2$s</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3570 +msgid "lookup_family_order (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3573 +msgid "" +"Provides the ability to select preferred address family to use when " +"performing DNS lookups." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3577 +msgid "Supported values:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3580 +msgid "ipv4_first: Try looking up IPv4 address, if that fails, try IPv6" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3583 +msgid "ipv4_only: Only attempt to resolve hostnames to IPv4 addresses." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3586 +msgid "ipv6_first: Try looking up IPv6 address, if that fails, try IPv4" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3589 +msgid "ipv6_only: Only attempt to resolve hostnames to IPv6 addresses." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3592 +msgid "Default: ipv4_first" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3598 +msgid "dns_resolver_server_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3601 +msgid "" +"Defines the amount of time (in milliseconds) SSSD would try to talk to DNS " +"server before trying next DNS server." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3606 +msgid "The AD provider will use this option for the CLDAP ping timeouts as well." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3610 sssd.conf.5.xml:3630 sssd.conf.5.xml:3651 +msgid "" +"Please see the section <quote>FAILOVER</quote> for more information about " +"the service resolution." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3615 sssd-ldap.5.xml:700 include/failover.xml:84 +msgid "Default: 1000" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3621 +msgid "dns_resolver_op_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3624 +msgid "" +"Defines the amount of time (in seconds) to wait to resolve single DNS query " +"(e.g. resolution of a hostname or an SRV record) before trying the next " +"hostname or DNS discovery." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3635 include/failover.xml:100 +msgid "Default: 3" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3641 +msgid "dns_resolver_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3644 +msgid "" +"Defines the amount of time (in seconds) to wait for a reply from the " +"internal fail over service before assuming that the service is " +"unreachable. If this timeout is reached, the domain will continue to operate " +"in offline mode." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3662 +msgid "dns_resolver_use_search_list (bool)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3665 +msgid "" +"Normally, the DNS resolver searches the domain list defined in the " +"\"search\" directive from the resolv.conf file. This can lead to delays in " +"environments with improperly configured DNS." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3671 +msgid "" +"If fully qualified domain names (or _srv_) are used in the SSSD " +"configuration, setting this option to FALSE can prevent unnecessary DNS " +"lookups in such environments." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3677 +msgid "Default: TRUE" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3683 +msgid "dns_discovery_domain (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3686 +msgid "" +"If service discovery is used in the back end, specifies the domain part of " +"the service discovery DNS query." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3690 +msgid "Default: Use the domain part of machine's hostname" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3696 +msgid "failover_primary_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3699 +msgid "" +"When no primary server is available, SSSD fails over to a backup " +"server. This option defines the number of seconds SSSD waits before " +"attempting to reconnect to the primary server." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3706 +msgid "Note: The minimum value is 31." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3709 +msgid "Default: 31" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3715 +msgid "override_gid (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3718 +msgid "Override the primary GID value with the one specified." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3724 +msgid "case_sensitive (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3731 +msgid "True" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3734 +msgid "Case sensitive. This value is invalid for AD provider." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3740 +msgid "False" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3742 +msgid "Case insensitive." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3746 +msgid "Preserving" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3749 +msgid "" +"Same as False (case insensitive), but does not lowercase names in the result " +"of NSS operations. Note that name aliases (and in case of services also " +"protocol names) are still lowercased in the output." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3757 +msgid "" +"If you want to set this value for trusted domain with IPA provider, you need " +"to set it on both the client and SSSD on the server." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3727 +msgid "" +"Treat user and group names as case sensitive. Possible option values are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3772 +msgid "Default: True (False for AD provider)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3778 +msgid "subdomain_inherit (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3781 +msgid "" +"Specifies a list of configuration parameters that should be inherited by a " +"subdomain. Please note that only selected parameters can be inherited. " +"Currently the following options can be inherited:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3787 +msgid "ldap_search_timeout" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3790 +msgid "ldap_network_timeout" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3793 +msgid "ldap_opt_timeout" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3796 +msgid "ldap_offline_timeout" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3799 +msgid "ldap_purge_cache_timeout" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3802 +msgid "ldap_purge_cache_offset" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3805 +msgid "" +"ldap_krb5_keytab (the value of krb5_keytab will be used if ldap_krb5_keytab " +"is not set explicitly)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3809 +msgid "ldap_krb5_ticket_lifetime" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3812 +msgid "ldap_connection_expire_timeout" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3815 +msgid "ldap_connection_expire_offset" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3818 +msgid "ldap_connection_idle_timeout" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3821 sssd-ldap.5.xml:446 +msgid "ldap_use_tokengroups" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3824 +msgid "ldap_user_principal" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3827 +msgid "ignore_group_members" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3830 +msgid "auto_private_groups" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3833 +msgid "case_sensitive" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:3838 +#, no-wrap +msgid "" +"subdomain_inherit = ldap_purge_cache_timeout\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3845 +msgid "Note: This option only works with the IPA and AD provider." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3852 +msgid "subdomain_homedir (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3863 +msgid "%F" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3864 +msgid "flat (NetBIOS) name of a subdomain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3855 +msgid "" +"Use this homedir as default value for all subdomains within this domain in " +"IPA AD trust. See <emphasis>override_homedir</emphasis> for info about " +"possible values. In addition to those, the expansion below can only be used " +"with <emphasis>subdomain_homedir</emphasis>. <placeholder " +"type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3869 +msgid "The value can be overridden by <emphasis>override_homedir</emphasis> option." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3873 +msgid "Default: <filename>/home/%d/%u</filename>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3878 +msgid "realmd_tags (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3881 +msgid "Various tags stored by the realmd configuration service for this domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3887 +msgid "cached_auth_timeout (int)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3890 +msgid "" +"Specifies time in seconds since last successful online authentication for " +"which user will be authenticated using cached credentials while SSSD is in " +"the online mode. If the credentials are incorrect, SSSD falls back to online " +"authentication." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3898 +msgid "" +"This option's value is inherited by all trusted domains. At the moment it is " +"not possible to set a different value per trusted domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3903 +msgid "Special value 0 implies that this feature is disabled." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3907 +msgid "" +"Please note that if <quote>cached_auth_timeout</quote> is longer than " +"<quote>pam_id_timeout</quote> then the back end could be called to handle " +"<quote>initgroups.</quote>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:3918 +msgid "local_auth_policy (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3921 +msgid "" +"Local authentication methods policy. Some backends (i.e. LDAP, proxy " +"provider) only support a password based authentication, while others can " +"handle PKINIT based Smartcard authentication (AD, IPA), two-factor " +"authentication (IPA), or other methods against a central instance. By " +"default in such cases authentication is only performed with the methods " +"supported by the backend. With this option additional methods can be enabled " +"which are evaluated and checked locally." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3933 +msgid "" +"There are three possible values for this option: match, only, " +"enable. <quote>match</quote> is used to match offline and online states for " +"Kerberos methods. <quote>only</quote> ignores the online methods and only " +"offer the local ones. enable allows explicitly defining the methods for " +"local authentication. As an example, <quote>enable:passkey</quote>, only " +"enables passkey for local authentication. Multiple enable values should be " +"comma-separated, such as <quote>enable:passkey, enable:smartcard</quote>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3946 +msgid "" +"The following table shows which authentication methods, if configured " +"properly, are currently enabled or disabled for each backend, with the " +"default local_auth_policy: <quote>match</quote>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> +#: sssd.conf.5.xml:3959 +msgid "local_auth_policy = match (default)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> +#: sssd.conf.5.xml:3960 +msgid "Passkey" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> +#: sssd.conf.5.xml:3961 +msgid "Smartcard" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:3964 sssd-ldap.5.xml:228 +msgid "IPA" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:3967 sssd-ldap.5.xml:233 +msgid "AD" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd.conf.5.xml:3967 sssd.conf.5.xml:3970 sssd.conf.5.xml:3971 +msgid "disabled" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> +#: sssd.conf.5.xml:3970 +msgid "LDAP" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3975 +msgid "" +"Please note that if local Smartcard authentication is enabled and a " +"Smartcard is present, Smartcard authentication will be preferred over the " +"authentication methods supported by the backend. I.e. there will be a PIN " +"prompt instead of e.g. a password prompt." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:3987 +#, no-wrap +msgid "" +"[domain/shadowutils]\n" +"id_provider = proxy\n" +"proxy_lib_name = files\n" +"auth_provider = none\n" +"local_auth_policy = only\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3983 +msgid "" +"The following configuration example allows local users to authenticate " +"locally using any enabled method (i.e. smartcard, passkey). <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:3995 +msgid "Default: match" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4000 +msgid "auto_private_groups (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4006 +msgid "true" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4009 +msgid "" +"Create user's private group unconditionally from user's UID number. The GID " +"number is ignored in this case." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4013 +msgid "" +"NOTE: Because the GID number and the user private group are inferred from " +"the UID number, it is not supported to have multiple entries with the same " +"UID or GID number with this option. In other words, enabling this option " +"enforces uniqueness across the ID space." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4022 +msgid "false" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4025 +msgid "" +"Always use the user's primary GID number. The GID number must refer to a " +"group object in the LDAP database." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4031 +msgid "hybrid" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4034 +msgid "" +"A primary group is autogenerated for user entries whose UID and GID numbers " +"have the same value and at the same time the GID number does not correspond " +"to a real group object in LDAP. If the values are the same, but the primary " +"GID in the user entry is also used by a group object, the primary GID of the " +"user resolves to that group object." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4047 +msgid "" +"If the UID and GID of a user are different, then the GID must correspond to " +"a group entry, otherwise the GID is simply not resolvable." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4054 +msgid "" +"This feature is useful for environments that wish to stop maintaining a " +"separate group objects for the user private groups, but also wish to retain " +"the existing user private groups." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4003 +msgid "" +"This option takes any of three available values: <placeholder " +"type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4066 +msgid "" +"For the LDAP based id providers (LDAP, IPA and AD) the default for the " +"configured domain is typically False because the sources have the concept of " +"a primary group. <phrase condition=\"with_idp_provider\">The IdP id " +"provider is using True because IdPs typically do not have primary " +"groups.</phrase>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4075 +msgid "" +"For subdomains, the default value is False for subdomains that use assigned " +"POSIX IDs and True for subdomains that use automatic ID-mapping." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:4083 +#, no-wrap +msgid "" +"[domain/forest.domain/sub.domain]\n" +"auto_private_groups = false\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> +#: sssd.conf.5.xml:4089 +#, no-wrap +msgid "" +"[domain/forest.domain]\n" +"subdomain_inherit = auto_private_groups\n" +"auto_private_groups = false\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4080 +msgid "" +"The value of auto_private_groups can either be set per subdomains in a " +"subsection, for example: <placeholder type=\"programlisting\" id=\"0\"/> or " +"globally for all subdomains in the main domain section using the " +"subdomain_inherit option: <placeholder type=\"programlisting\" id=\"1\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:2503 +msgid "" +"These configuration options can be present in a domain configuration " +"section, that is, in a section called " +"<quote>[domain/<replaceable>NAME</replaceable>]</quote> <placeholder " +"type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4104 +msgid "proxy_pam_target (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4107 +msgid "The proxy target PAM proxies to." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4110 +msgid "" +"Default: not set by default, you have to take an existing pam configuration " +"or create a new one and add the service name here. As an alternative you can " +"enable local authentication with the local_auth_policy option." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4120 +msgid "proxy_lib_name (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4123 +msgid "" +"The name of the NSS library to use in proxy domains. The NSS functions " +"searched for in the library are in the form of _nss_$(libName)_$(function), " +"for example _nss_files_getpwent." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4133 +msgid "proxy_resolver_lib_name (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4136 +msgid "" +"The name of the NSS library to use for hosts and networks lookups in proxy " +"domains. The NSS functions searched for in the library are in the form of " +"_nss_$(libName)_$(function), for example _nss_dns_gethostbyname2_r." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4147 +msgid "proxy_fast_alias (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4150 +msgid "" +"When a user or group is looked up by name in the proxy provider, a second " +"lookup by ID is performed to \"canonicalize\" the name in case the requested " +"name was an alias. Setting this option to true would cause the SSSD to " +"perform the ID lookup from cache for performance reasons." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4164 +msgid "proxy_max_children (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4167 +msgid "" +"This option specifies the number of pre-forked proxy children. It is useful " +"for high-load SSSD environments where sssd may run out of available child " +"slots, which would cause some issues due to the requests being queued." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4100 +msgid "" +"Options valid for proxy domains. <placeholder type=\"variablelist\" " +"id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd.conf.5.xml:4183 +msgid "Application domains" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:4185 +msgid "" +"SSSD, with its D-Bus interface (see <citerefentry> " +"<refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry>) is appealing to applications as a gateway to an LDAP " +"directory where users and groups are stored. However, contrary to the " +"traditional SSSD deployment where all users and groups either have POSIX " +"attributes or those attributes can be inferred from the Windows SIDs, in " +"many cases the users and groups in the application support scenario have no " +"POSIX attributes. Instead of setting a " +"<quote>[domain/<replaceable>NAME</replaceable>]</quote> section, the " +"administrator can set up an " +"<quote>[application/<replaceable>NAME</replaceable>]</quote> section that " +"internally represents a domain with type <quote>application</quote> " +"optionally inherits settings from a tradition SSSD domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:4205 +msgid "" +"Please note that the application domain must still be explicitly enabled in " +"the <quote>domains</quote> parameter so that the lookup order between the " +"application domain and its POSIX sibling domain is set correctly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> +#: sssd.conf.5.xml:4211 +msgid "Application domain parameters" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4213 +msgid "inherit_from (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4216 +msgid "" +"The SSSD POSIX-type domain the application domain inherits all settings " +"from. The application domain can moreover add its own settings to the " +"application settings that augment or override the <quote>sibling</quote> " +"domain settings." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd.conf.5.xml:4230 +msgid "" +"The following example illustrates the use of an application domain. In this " +"setup, the POSIX domain is connected to an LDAP server and is used by the OS " +"through the NSS responder. In addition, the application domain also requests " +"the telephoneNumber attribute, stores it as the phone attribute in the cache " +"and makes the phone attribute reachable through the D-Bus interface." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><programlisting> +#: sssd.conf.5.xml:4238 +#, no-wrap +msgid "" +"[sssd]\n" +"domains = appdom, posixdom\n" +"\n" +"[ifp]\n" +"user_attributes = +phone\n" +"\n" +"[domain/posixdom]\n" +"id_provider = ldap\n" +"ldap_uri = ldap://ldap.example.com\n" +"ldap_search_base = dc=example,dc=com\n" +"\n" +"[application/appdom]\n" +"inherit_from = posixdom\n" +"ldap_user_extra_attrs = phone:telephoneNumber\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:4258 +msgid "TRUSTED DOMAIN SECTION" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4260 +msgid "" +"Some options used in the domain section can also be used in the trusted " +"domain section, that is, in a section called " +"<quote>[domain/<replaceable>DOMAIN_NAME</replaceable>/<replaceable>TRUSTED_DOMAIN_NAME</replaceable>]</quote>. " +"Where DOMAIN_NAME is the actual joined-to base domain. Please refer to " +"examples below for explanation. Currently supported options in the trusted " +"domain section are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4267 +msgid "ldap_search_base," +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4268 +msgid "ldap_user_search_base," +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4269 +msgid "ldap_group_search_base," +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4270 +msgid "ldap_netgroup_search_base," +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4271 +msgid "ldap_service_search_base," +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4272 +msgid "ldap_sasl_mech," +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4273 +msgid "ad_server," +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4274 +msgid "ad_backup_server," +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4275 +msgid "ad_site," +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:4276 sssd-ipa.5.xml:934 +msgid "use_fully_qualified_names" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4280 +msgid "" +"For more details about these options see their individual description in the " +"manual page." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:4286 +msgid "CERTIFICATE MAPPING SECTION" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4288 +msgid "" +"To allow authentication with Smartcards and certificates SSSD must be able " +"to map certificates to users. This can be done by adding the full " +"certificate to the LDAP object of the user or to a local override. While " +"using the full certificate is required to use the Smartcard authentication " +"feature of SSH (see <citerefentry> " +"<refentrytitle>sss_ssh_authorizedkeys</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> for details) it might be cumbersome " +"or not even possible to do this for the general case where local services " +"use PAM for authentication." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4302 +msgid "" +"To make the mapping more flexible mapping and matching rules were added to " +"SSSD (see <citerefentry> <refentrytitle>sss-certmap</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> for details)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4311 +msgid "" +"A mapping and matching rule can be added to the SSSD configuration in a " +"section on its own with a name like " +"<quote>[certmap/<replaceable>DOMAIN_NAME</replaceable>/<replaceable>RULE_NAME</replaceable>]</quote>. " +"In this section the following options are allowed:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4318 +msgid "matchrule (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4321 +msgid "" +"Only certificates from the Smartcard which matches this rule will be " +"processed, all others are ignored." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4325 +msgid "" +"Default: KRB5:<EKU>clientAuth, i.e. only certificates which have the " +"Extended Key Usage <quote>clientAuth</quote>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4332 +msgid "maprule (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4335 +msgid "Defines how the user is found for a given certificate." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:4341 +msgid "" +"LDAP:(userCertificate;binary={cert!bin}) for LDAP based providers like " +"<quote>ldap</quote>, <quote>AD</quote> or <quote>ipa</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:4347 +msgid "" +"If maprule is not set and provider is <quote>proxy</quote>, the RULE_NAME " +"name is assumed to be the name of the matching user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4357 +msgid "domains (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4360 +msgid "" +"Comma separated list of domain names the rule should be applied. By default " +"a rule is only valid in the domain configured in sssd.conf. If the provider " +"supports subdomains this option can be used to add the rule to subdomains as " +"well." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4367 +msgid "Default: the configured domain in sssd.conf" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4372 +msgid "priority (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4375 +msgid "" +"Unsigned integer value defining the priority of the rule. The higher the " +"number the lower the priority. <quote>0</quote> stands for the highest " +"priority while <quote>4294967295</quote> is the lowest." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4381 +msgid "Default: the lowest priority" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:4389 +msgid "PROMPTING CONFIGURATION SECTION" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4391 +msgid "" +"If a special file " +"(<filename>/var/lib/sss/pubconf/pam_preauth_available</filename>) exists " +"SSSD's PAM module pam_sss will ask SSSD to figure out which authentication " +"methods are available for the user trying to log in. Based on the results " +"pam_sss will prompt the user for appropriate credentials." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4399 +msgid "" +"With the growing number of authentication methods and the possibility that " +"there are multiple ones for a single user the heuristic used by pam_sss to " +"select the prompting might not be suitable for all use cases. The following " +"options should provide a better flexibility here." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4411 +msgid "[prompting/password]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4414 +msgid "password_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4415 +msgid "to change the string of the password prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4413 +msgid "" +"to configure password prompting, allowed options are: <placeholder " +"type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4423 +msgid "[prompting/2fa]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4427 +msgid "first_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4428 +msgid "to change the string of the prompt for the first factor" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4431 +msgid "second_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4432 +msgid "to change the string of the prompt for the second factor" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4435 +msgid "single_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4436 +msgid "" +"boolean value, if True there will be only a single prompt using the value of " +"first_prompt where it is expected that both factors are entered as a single " +"string. Please note that both factors have to be entered here, even if the " +"second factor is optional." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4425 +msgid "" +"to configure two-factor authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/> If the second factor is " +"optional and it should be possible to log in either only with the password " +"or with both factors two-step prompting has to be used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4449 +msgid "" +"Some clients, such as SSH with 'PasswordAuthentication yes', generate their " +"own prompts and do not use prompts provided by SSSD or other PAM " +"modules. Additionally, for SSH with PasswordAuthentication, if two-factor " +"authentication is available, SSSD expects that the credentials entered by " +"the user at the SSH password prompt will always be the two factors in a " +"single string, even if two-factor authentication is optional." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4464 +msgid "[prompting/passkey]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd.conf.5.xml:4470 sssd-ad.5.xml:1022 +msgid "interactive" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4472 +msgid "" +"boolean value, if True prompt a message and wait before testing the presence " +"of a passkey device. Recommended if your device doesn’t have a tactile " +"trigger." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4480 +msgid "interactive_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4482 +msgid "to change the message of the interactive prompt." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4487 +msgid "touch" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4489 +msgid "" +"boolean value, if True prompt a message to remind the user to touch the " +"device." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd.conf.5.xml:4495 +msgid "touch_prompt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4497 +msgid "to change the message of the touch prompt." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd.conf.5.xml:4466 +msgid "" +"to configure passkey authentication prompting, allowed options are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4406 +msgid "" +"Each supported authentication method has its own configuration subsection " +"under <quote>[prompting/...]</quote>. Currently there are: <placeholder " +"type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" " +"id=\"1\"/> <placeholder type=\"variablelist\" id=\"2\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4508 +msgid "" +"It is possible to add a subsection for specific PAM services, " +"e.g. <quote>[prompting/password/sshd]</quote> to individual change the " +"prompting for this service." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.conf.5.xml:4515 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 +msgid "EXAMPLES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd.conf.5.xml:4521 +#, no-wrap +msgid "" +"[sssd]\n" +"domains = LDAP\n" +"services = nss, pam\n" +"\n" +"[nss]\n" +"filter_groups = root\n" +"filter_users = root\n" +"\n" +"[pam]\n" +"\n" +"[domain/LDAP]\n" +"id_provider = ldap\n" +"ldap_uri = ldap://ldap.example.com\n" +"ldap_search_base = dc=example,dc=com\n" +"\n" +"auth_provider = krb5\n" +"krb5_server = kerberos.example.com\n" +"krb5_realm = EXAMPLE.COM\n" +"cache_credentials = true\n" +"\n" +"min_id = 10000\n" +"max_id = 20000\n" +"enumerate = False\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4517 +msgid "" +"1. The following example shows a typical SSSD config. It does not describe " +"configuration of the domains themselves - refer to documentation on " +"configuring domains for more details. <placeholder type=\"programlisting\" " +"id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd.conf.5.xml:4553 +#, no-wrap +msgid "" +"[domain/ipa.com/child.ad.com]\n" +"use_fully_qualified_names = false\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4547 +msgid "" +"2. The following example shows configuration of IPA AD trust where the AD " +"forest consists of two domains in a parent-child structure. Suppose IPA " +"domain (ipa.com) has trust with AD domain(ad.com). ad.com has child domain " +"(child.ad.com). To enable shortnames in the child domain the following " +"configuration should be used. <placeholder type=\"programlisting\" " +"id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd.conf.5.xml:4564 +#, no-wrap +msgid "" +"[certmap/my.domain/rule_name]\n" +"matchrule = <ISSUER>^CN=My-CA,DC=MY,DC=DOMAIN$\n" +"maprule = (userCertificate;binary={cert!bin})\n" +"domains = my.domain, your.domain\n" +"priority = 10\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.conf.5.xml:4558 +msgid "" +"3. The following example shows the configuration of a certificate mapping " +"rule. It is valid for the configured domain <quote>my.domain</quote> and " +"additionally for the subdomains <quote>your.domain</quote> and uses the full " +"certificate in the search filter. <placeholder type=\"programlisting\" " +"id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd-ldap.5.xml:10 sssd-ldap.5.xml:16 +msgid "sssd-ldap" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd-ldap.5.xml:17 +msgid "SSSD LDAP provider" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap.5.xml:21 pam_sss.8.xml:66 pam_sss_gss.8.xml:30 +#: sssd_krb5_locator_plugin.8.xml:20 sssd-simple.5.xml:22 sss-certmap.5.xml:21 +#: sssd-ipa.5.xml:21 sssd-ad.5.xml:21 sssd-sudo.5.xml:21 sssd-idp.5.xml:21 +#: sssd.8.xml:29 sss_obfuscate.8.xml:30 sss_override.8.xml:30 +#: sssd-krb5.5.xml:21 sss_cache.8.xml:29 sss_debuglevel.8.xml:30 +#: sss_seed.8.xml:31 sssd-ifp.5.xml:21 sss_ssh_authorizedkeys.1.xml:30 +#: sss_ssh_knownhosts.1.xml:30 idmap_sss.8.xml:20 sssctl.8.xml:30 +#: sssd-session-recording.5.xml:21 sssd-kcm.8.xml:21 sssd-systemtap.5.xml:21 +#: sssd-ldap-attributes.5.xml:21 sssd_krb5_localauth_plugin.8.xml:20 +msgid "DESCRIPTION" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ldap.5.xml:23 +msgid "" +"This manual page describes the configuration of LDAP domains for " +"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " +"</citerefentry>. Refer to the <quote>FILE FORMAT</quote> section of the " +"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page for detailed syntax " +"information." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ldap.5.xml:35 +msgid "You can configure SSSD to use more than one LDAP domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ldap.5.xml:38 +msgid "" +"LDAP back end supports id, auth, access and chpass providers. If you want to " +"authenticate against an LDAP server either TLS/SSL or LDAPS is " +"required. <command>sssd</command> <emphasis>does not</emphasis> support " +"authentication over an unencrypted channel. Even if the LDAP server is used " +"only as an identity provider, an encrypted channel is strongly " +"recommended. Please refer to the <quote>ldap_access_filter</quote> config " +"option for more information about using LDAP as an access provider." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap.5.xml:50 sssd-simple.5.xml:82 sssd-ipa.5.xml:82 sssd-ad.5.xml:130 +#: sssd-idp.5.xml:54 sssd-krb5.5.xml:63 sssd-ifp.5.xml:60 +#: sssd-session-recording.5.xml:58 sssd-kcm.8.xml:202 +msgid "CONFIGURATION OPTIONS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:67 +msgid "ldap_uri, ldap_backup_uri (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:70 +msgid "" +"Specifies the comma-separated list of URIs of the LDAP servers to which SSSD " +"should connect in the order of preference. Refer to the " +"<quote>FAILOVER</quote> section for more information on failover and server " +"redundancy. If neither option is specified, service discovery is " +"enabled. For more information, refer to the <quote>SERVICE DISCOVERY</quote> " +"section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:77 +msgid "The format of the URI must match the format defined in RFC 2732:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:80 +msgid "ldap[s]://<host>[:port]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:83 +msgid "For explicit IPv6 addresses, <host> must be enclosed in brackets []" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:86 +msgid "example: ldap://[fc00::126:25]:389" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:92 +msgid "ldap_chpass_uri, ldap_chpass_backup_uri (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:95 +msgid "" +"Specifies the comma-separated list of URIs of the LDAP servers to which SSSD " +"should connect in the order of preference to change the password of a " +"user. Refer to the <quote>FAILOVER</quote> section for more information on " +"failover and server redundancy." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:102 +msgid "To enable service discovery ldap_chpass_dns_service_name must be set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:106 +msgid "Default: empty, i.e. ldap_uri is used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:112 +msgid "ldap_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:115 +msgid "The default base DN to use for performing LDAP user operations." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:119 +msgid "" +"Starting with SSSD 1.7.0, SSSD supports multiple search bases using the " +"syntax:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:123 +msgid "search_base[?scope?[filter][?search_base?scope?[filter]]*]" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:126 +msgid "The scope can be one of \"base\", \"onelevel\" or \"subtree\"." +msgstr "" + +#. type: Content of: <listitem><para> +#: sssd-ldap.5.xml:129 include/ldap_search_bases.xml:18 +msgid "" +"The filter must be a valid LDAP search filter as specified by " +"http://www.ietf.org/rfc/rfc2254.txt" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:133 sssd-ad.5.xml:312 sss_override.8.xml:143 +#: sss_override.8.xml:240 sssd-ldap-attributes.5.xml:453 +msgid "Examples:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:136 +msgid "" +"ldap_search_base = dc=example,dc=com (which is equivalent to) " +"ldap_search_base = dc=example,dc=com?subtree?" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:141 +msgid "" +"ldap_search_base = " +"cn=host_specific,dc=example,dc=com?subtree?(host=thishost)?dc=example.com?subtree?" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:144 +msgid "" +"Note: It is unsupported to have multiple search bases which reference " +"identically-named objects (for example, groups with the same name in two " +"different search bases). This will lead to unpredictable behavior on client " +"machines." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:151 +msgid "" +"Default: If not set, the value of the defaultNamingContext or namingContexts " +"attribute from the RootDSE of the LDAP server is used. If " +"defaultNamingContext does not exist or has an empty value namingContexts is " +"used. The namingContexts attribute must have a single value with the DN of " +"the search base of the LDAP server to make this work. Multiple values are " +"are not supported." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:165 +msgid "ldap_read_rootdse (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:168 +msgid "" +"SSSD reads RootDSE to get information about LDAP and its capabilities. By " +"default, this is done anonymously. However, this may not be permitted by the " +"LDAP server. In such cases we can use this option to influence SSSD " +"behavior." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:175 +msgid "Allowed values are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ldap.5.xml:179 +msgid "anonymous" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ldap.5.xml:184 +msgid "authenticated" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:193 +msgid "" +"By default, using the \"anonymous\" option, SSSD tries to read RootDSE " +"anonymously. If this fails SSSD retries the attempt with authentication." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:198 +msgid "Default: anonymous" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:204 +msgid "ldap_schema (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:207 +msgid "" +"Specifies the Schema Type in use on the target LDAP server. Depending on " +"the selected schema, the default attribute names retrieved from the servers " +"may vary. The way that some attributes are handled may also differ." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:214 +msgid "Four schema types are currently supported:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ldap.5.xml:218 +msgid "rfc2307" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ldap.5.xml:223 +msgid "rfc2307bis" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:239 +msgid "" +"The main difference between these schema types is how group memberships are " +"recorded in the server. With rfc2307, group members are listed by name in " +"the <emphasis>memberUid</emphasis> attribute. With rfc2307bis and IPA, " +"group members are listed by DN and stored in the <emphasis>member</emphasis> " +"attribute. The AD schema type sets the attributes to correspond with Active " +"Directory 2008r2 values." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:249 +msgid "Default: rfc2307" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:255 +msgid "ldap_pwmodify_mode (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:258 +msgid "Specify the operation that is used to modify user password." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:262 +msgid "Two modes are currently supported:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ldap.5.xml:266 +msgid "exop - Password Modify Extended Operation (RFC 3062)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ldap.5.xml:272 +msgid "ldap_modify - Direct modification of userPassword (not recommended)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ldap.5.xml:278 +msgid "" +"exop_force - Try Password Modify Extended Operation (RFC 3062) even if there " +"are no grace logins left. Depending on the type and configuration of the " +"LDAP server the password change might fail because an authenticated bind is " +"not possible." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:290 +msgid "" +"Note: First, a new connection is established to verify current password by " +"binding as the user that requested password change. If successful, this " +"connection is used to change the password therefore the user must have write " +"access to userPassword attribute." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:298 +msgid "Default: exop" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:304 +msgid "ldap_default_bind_dn (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:307 +msgid "The default bind DN to use for performing LDAP operations." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:314 +msgid "ldap_default_authtok_type (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:317 +msgid "The type of the authentication token of the default bind DN." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:321 +msgid "The two mechanisms currently supported are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:324 +msgid "password" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:327 +msgid "obfuscated_password" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:330 +msgid "Default: password" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:333 +msgid "" +"See the <citerefentry> <refentrytitle>sss_obfuscate</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> manual page for more information." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:344 +msgid "ldap_default_authtok (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:347 +msgid "The authentication token of the default bind DN." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:353 +msgid "ldap_force_upper_case_realm (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:356 +msgid "" +"Some directory servers, for example Active Directory, might deliver the " +"realm part of the UPN in lower case, which might cause the authentication to " +"fail. Set this option to a non-zero value if you want to use an upper-case " +"realm." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:369 +msgid "ldap_enumeration_refresh_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:372 +msgid "" +"Specifies how many seconds SSSD has to wait before refreshing its cache of " +"enumerated records." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:383 +msgid "ldap_purge_cache_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:386 +msgid "" +"Determine how often to check the cache for inactive entries (such as groups " +"with no members and users who have never logged in) and remove them to save " +"space." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:392 +msgid "" +"Setting this option to zero will disable the cache cleanup operation. Please " +"note that if enumeration is enabled, the cleanup task is required in order " +"to detect entries removed from the server and can't be disabled. By default, " +"the cleanup task will run every 3 hours with enumeration enabled." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:412 +msgid "ldap_group_nesting_level (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:415 +msgid "" +"If ldap_schema is set to a schema format that supports nested groups " +"(e.g. RFC2307bis), then this option controls how many levels of nesting SSSD " +"will follow. This option has no effect on the RFC2307 schema." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:422 +msgid "" +"Note: This option specifies the guaranteed level of nested groups to be " +"processed for any lookup. However, nested groups beyond this limit " +"<emphasis>may be</emphasis> returned if previous lookups already resolved " +"the deeper nesting levels. Also, subsequent lookups for other groups may " +"enlarge the result set for original lookup if re-queried." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:431 +msgid "" +"If ldap_group_nesting_level is set to 0 then no nested groups are processed " +"at all. However, when connected to Active-Directory Server 2008 and later " +"using <quote>id_provider=ad</quote> it is furthermore required to disable " +"usage of Token-Groups by setting ldap_use_tokengroups to false in order to " +"restrict group nesting." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:440 +msgid "Default: 2" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:449 +msgid "" +"This options enables or disables use of Token-Groups attribute when " +"performing initgroup for users from Active Directory Server 2008 and later." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:459 +msgid "Default: True for AD and IPA otherwise False." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:465 +msgid "ldap_host_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:468 +msgid "Optional. Use the given string as search base for host objects." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:472 sssd-ipa.5.xml:506 sssd-ipa.5.xml:525 sssd-ipa.5.xml:544 +#: sssd-ipa.5.xml:563 +msgid "" +"See <quote>ldap_search_base</quote> for information about configuring " +"multiple search bases." +msgstr "" + +#. type: Content of: <listitem><para> +#: sssd-ldap.5.xml:477 sssd-ipa.5.xml:511 include/ldap_search_bases.xml:27 +msgid "Default: the value of <emphasis>ldap_search_base</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:484 +msgid "ldap_subid_ranges_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:487 +msgid "" +"Optional. Use the given string as search base for subordinate ranges related " +"objects." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:491 +msgid "" +"Default: the value of <emphasis>cn=subids,%basedn</emphasis> for IPA " +"otherwise <emphasis>ldap_search_base</emphasis>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:499 +msgid "ldap_service_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:504 +msgid "ldap_iphost_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:509 +msgid "ldap_ipnetwork_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:514 +msgid "ldap_search_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:517 +msgid "" +"Specifies the timeout (in seconds) that ldap searches are allowed to run " +"before they are cancelled and cached results are returned (and offline mode " +"is entered)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:523 +msgid "" +"Note: this option is subject to change in future versions of the SSSD. It " +"will likely be replaced at some point by a series of timeouts for specific " +"lookup types." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:540 +msgid "ldap_enumeration_search_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:543 +msgid "" +"Specifies the timeout (in seconds) that ldap searches for user and group " +"enumerations are allowed to run before they are cancelled and cached results " +"are returned (and offline mode is entered)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:556 +msgid "ldap_network_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:559 +msgid "" +"Specifies the timeout (in seconds) after which the <citerefentry> " +"<refentrytitle>poll</refentrytitle> <manvolnum>2</manvolnum> " +"</citerefentry>/<citerefentry> <refentrytitle>select</refentrytitle> " +"<manvolnum>2</manvolnum> </citerefentry> following a <citerefentry> " +"<refentrytitle>connect</refentrytitle> <manvolnum>2</manvolnum> " +"</citerefentry> returns in case of no activity." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:587 +msgid "ldap_opt_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:590 +msgid "" +"Specifies a timeout (in seconds) after which calls to synchronous LDAP APIs " +"will abort if no response is received. Also controls the timeout when " +"communicating with the KDC in case of SASL bind, the timeout of an LDAP bind " +"operation, password change extended operation and the StartTLS operation." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:610 +msgid "ldap_connection_expire_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:613 +msgid "" +"Specifies a timeout (in seconds) that a connection to an LDAP server will be " +"maintained. After this time, the connection will be re-established. If used " +"in parallel with SASL/GSSAPI, the sooner of the two values (this value " +"vs. the TGT lifetime) will be used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:621 +msgid "" +"If the connection is idle (not actively running an operation) within " +"<emphasis>ldap_opt_timeout</emphasis> seconds of expiration, then it will be " +"closed early to ensure that a new query cannot require the connection to " +"remain open past its expiration. This implies that connections will always " +"be closed immediately and will never be reused if " +"<emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:633 +msgid "" +"This timeout can be extended of a random value specified by " +"<emphasis>ldap_connection_expire_offset</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:643 sssd-ldap.5.xml:686 sssd-ldap.5.xml:1809 +msgid "Default: 900 (15 minutes)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:649 +msgid "ldap_connection_expire_offset (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:652 +msgid "" +"Random offset between 0 and configured value is added to " +"<emphasis>ldap_connection_expire_timeout</emphasis>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:668 +msgid "ldap_connection_idle_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:671 +msgid "" +"Specifies a timeout (in seconds) that an idle connection to an LDAP server " +"will be maintained. If the connection is idle for more than this time then " +"the connection will be closed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:677 +msgid "You can disable this timeout by setting the value to 0." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:692 +msgid "ldap_page_size (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:695 +msgid "" +"Specify the number of records to retrieve from LDAP in a single " +"request. Some LDAP servers enforce a maximum limit per-request." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:706 +msgid "ldap_disable_paging (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:709 +msgid "" +"Disable the LDAP paging control. This option should be used if the LDAP " +"server reports that it supports the LDAP paging control in its RootDSE but " +"it is not enabled or does not behave properly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:715 +msgid "" +"Example: OpenLDAP servers with the paging control module installed on the " +"server but not enabled will report it in the RootDSE but be unable to use " +"it." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:721 +msgid "" +"Example: 389 DS has a bug where it can only support a one paging control at " +"a time on a single connection. On busy clients, this can result in some " +"requests being denied." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:733 +msgid "ldap_disable_range_retrieval (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:736 +msgid "Disable Active Directory range retrieval." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:739 +msgid "" +"Active Directory limits the number of members that can be retrieved in a " +"single lookup using the MaxValRange policy, which defaults to 1500 " +"members. If a group contains more than 1500 members, the reply includes an " +"AD-specific range extension. When enabled, this option prevents SSSD from " +"parsing the range extension. As a result large groups will appear as they " +"have no members. This option does not enable SSSD to read subsequent " +"ranges. To retrieve all members of a group, you must increase the " +"MaxValRange setting in Active Directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:758 +msgid "ldap_sasl_minssf (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:761 +msgid "" +"When communicating with an LDAP server using SASL, specify the minimum " +"security level necessary to establish the connection. The values of this " +"option are defined by OpenLDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:767 sssd-ldap.5.xml:783 +msgid "Default: Use the system default (usually specified by ldap.conf)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:774 +msgid "ldap_sasl_maxssf (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:777 +msgid "" +"When communicating with an LDAP server using SASL, specify the maximal " +"security level necessary to establish the connection. The values of this " +"option are defined by OpenLDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:790 +msgid "ldap_deref_threshold (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:793 +msgid "" +"Specify the number of group members that must be missing from the internal " +"cache in order to trigger a dereference lookup. If less members are missing, " +"they are looked up individually." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:799 +msgid "" +"You can turn off dereference lookups completely by setting the value to " +"0. Please note that there are some codepaths in SSSD, like the IPA HBAC " +"provider, that are only implemented using the dereference call, so even with " +"dereference explicitly disabled, those parts will still use dereference if " +"the server supports it and advertises the dereference control in the rootDSE " +"object." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:810 +msgid "" +"A dereference lookup is a means of fetching all group members in a single " +"LDAP call. Different LDAP servers may implement different dereference " +"methods. The currently supported servers are 389/RHDS, OpenLDAP and Active " +"Directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:818 +msgid "" +"<emphasis>Note:</emphasis> If any of the search bases specifies a search " +"filter, then the dereference lookup performance enhancement will be disabled " +"regardless of this setting." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:831 +msgid "ldap_ignore_unreadable_references (bool)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:834 +msgid "" +"Ignore unreadable LDAP entries referenced in group's member attribute. If " +"this parameter is set to false an error will be returned and the operation " +"will fail instead of just ignoring the unreadable entry." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:841 +msgid "" +"This parameter may be useful when using the AD provider and the computer " +"account that sssd uses to connect to AD does not have access to a particular " +"entry or LDAP sub-tree for security reasons." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:854 +msgid "ldap_tls_reqcert (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:857 +msgid "" +"Specifies what checks to perform on server certificates in a TLS session, if " +"any. It can be specified as one of the following values:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:863 +msgid "" +"<emphasis>never</emphasis> = The client will not request or check any server " +"certificate." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:867 +msgid "" +"<emphasis>allow</emphasis> = The server certificate is requested. If no " +"certificate is provided, the session proceeds normally. If a bad certificate " +"is provided, it will be ignored and the session proceeds normally." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:874 +msgid "" +"<emphasis>try</emphasis> = The server certificate is requested. If no " +"certificate is provided, the session proceeds normally. If a bad certificate " +"is provided, the session is immediately terminated." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:880 +msgid "" +"<emphasis>demand</emphasis> = The server certificate is requested. If no " +"certificate is provided, or a bad certificate is provided, the session is " +"immediately terminated." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:886 +msgid "<emphasis>hard</emphasis> = Same as <quote>demand</quote>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:890 +msgid "Default: hard" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:896 +msgid "ldap_tls_cacert (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:899 +msgid "" +"Specifies the file that contains certificates for all of the Certificate " +"Authorities that <command>sssd</command> will recognize." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:904 sssd-ldap.5.xml:923 sssd-ldap.5.xml:964 +msgid "" +"Default: use OpenLDAP defaults, typically in " +"<filename>/etc/openldap/ldap.conf</filename>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:911 +msgid "ldap_tls_cacertdir (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:914 +msgid "" +"Specifies the path of a directory that contains Certificate Authority " +"certificates in separate individual files. Typically the file names need to " +"be the hash of the certificate followed by '.0'. If available, " +"<command>openssl rehash</command> or <command>c_rehash</command> can be used " +"to create the correct names." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:930 +msgid "ldap_tls_cert (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:933 +msgid "Specifies the file that contains the certificate for the client's key." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:943 +msgid "ldap_tls_key (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:946 +msgid "Specifies the file that contains the client's key." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:955 +msgid "ldap_tls_cipher_suite (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:958 +msgid "" +"Specifies acceptable cipher suites. Typically this is a colon separated " +"list. See <citerefentry><refentrytitle>ldap.conf</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry> for format." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:971 +msgid "ldap_id_use_start_tls (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:974 +msgid "" +"Specifies that the id_provider connection must also use <systemitem " +"class=\"protocol\">tls</systemitem> to protect the channel. " +"<emphasis>true</emphasis> is strongly recommended for security reasons." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:985 +msgid "ldap_id_mapping (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:988 +msgid "" +"Specifies that SSSD should attempt to map user and group IDs from the " +"ldap_user_objectsid and ldap_group_objectsid attributes instead of relying " +"on ldap_user_uid_number and ldap_group_gid_number." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:994 +msgid "Currently this feature supports only ActiveDirectory objectSID mapping." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1004 +msgid "ldap_min_id, ldap_max_id (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1007 +msgid "" +"In contrast to the SID based ID mapping which is used if ldap_id_mapping is " +"set to true the allowed ID range for ldap_user_uid_number and " +"ldap_group_gid_number is unbound. In a setup with sub/trusted-domains this " +"might lead to ID collisions. To avoid collisions ldap_min_id and ldap_max_id " +"can be set to restrict the allowed range for the IDs which are read directly " +"from the server. Sub-domains can then pick other ranges to map IDs." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1019 +msgid "Default: not set (both options are set to 0)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1025 +msgid "ldap_sasl_mech (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1028 +msgid "" +"Specify the SASL mechanism to use. Currently only GSSAPI and GSS-SPNEGO are " +"tested and supported." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1032 +msgid "" +"If the backend supports sub-domains the value of ldap_sasl_mech is " +"automatically inherited to the sub-domains. If a different value is needed " +"for a sub-domain it can be overwritten by setting ldap_sasl_mech for this " +"sub-domain explicitly. Please see TRUSTED DOMAIN SECTION in " +"<citerefentry><refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry> for details." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1048 +msgid "ldap_sasl_authid (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> +#: sssd-ldap.5.xml:1060 +#, no-wrap +msgid "" +"hostname@REALM\n" +"netbiosname$@REALM\n" +"host/hostname@REALM\n" +"*$@REALM\n" +"host/*@REALM\n" +"netbiosname$@*\n" +"host/*\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1051 +msgid "" +"Specify the SASL authorization id to use. When GSSAPI/GSS-SPNEGO are used, " +"this represents the Kerberos principal used for authentication to the " +"directory. This option can either contain the full principal (for example " +"host/myhost@EXAMPLE.COM) or just the principal name (for example " +"host/myhost). By default, the value is not set and the following principals " +"are used: <placeholder type=\"programlisting\" id=\"0\"/> If none of them " +"are found, the first principal in keytab is returned." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1072 +msgid "Default: host/hostname@REALM" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1078 +msgid "ldap_sasl_realm (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1081 +msgid "" +"Specify the SASL realm to use. When not specified, this option defaults to " +"the value of krb5_realm. If the ldap_sasl_authid contains the realm as " +"well, this option is ignored." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1087 +msgid "Default: the value of krb5_realm." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1093 +msgid "ldap_sasl_canonicalize (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1096 +msgid "" +"If set to true, the LDAP library would perform a reverse lookup to " +"canonicalize the host name during a SASL bind." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1101 +msgid "Default: false;" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1107 +msgid "ldap_krb5_keytab (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1110 +msgid "Specify the keytab to use when using SASL/GSSAPI/GSS-SPNEGO." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1119 sssd-krb5.5.xml:247 +msgid "Default: System keytab, normally <filename>/etc/krb5.keytab</filename>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1125 +msgid "ldap_krb5_init_creds (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1128 +msgid "" +"Specifies that the id_provider should init Kerberos credentials (TGT). This " +"action is performed only if SASL is used and the mechanism selected is " +"GSSAPI or GSS-SPNEGO." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1140 +msgid "ldap_krb5_ticket_lifetime (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1143 +msgid "" +"Specifies the lifetime in seconds of the TGT if GSSAPI or GSS-SPNEGO is " +"used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1152 sssd-ad.5.xml:1267 +msgid "Default: 86400 (24 hours)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1158 sssd-krb5.5.xml:74 +msgid "krb5_server, krb5_backup_server (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1161 +msgid "" +"Specifies the comma-separated list of IP addresses or hostnames of the " +"Kerberos servers to which SSSD should connect in the order of " +"preference. For more information on failover and server redundancy, see the " +"<quote>FAILOVER</quote> section. An optional port number (preceded by a " +"colon) may be appended to the addresses or hostnames. If empty, service " +"discovery is enabled - for more information, refer to the <quote>SERVICE " +"DISCOVERY</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1173 sssd-krb5.5.xml:89 +msgid "" +"When using service discovery for KDC or kpasswd servers, SSSD first searches " +"for DNS entries that specify _udp as the protocol and falls back to _tcp if " +"none are found." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1178 sssd-krb5.5.xml:94 +msgid "" +"This option was named <quote>krb5_kdcip</quote> in earlier releases of " +"SSSD. While the legacy name is recognized for the time being, users are " +"advised to migrate their config files to use <quote>krb5_server</quote> " +"instead." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1187 sssd-ipa.5.xml:575 sssd-krb5.5.xml:103 +msgid "krb5_realm (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1190 +msgid "Specify the Kerberos REALM (for SASL/GSSAPI/GSS-SPNEGO auth)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1194 +msgid "Default: System defaults, see <filename>/etc/krb5.conf</filename>" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1200 include/krb5_options.xml:154 +msgid "krb5_canonicalize (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1203 +msgid "" +"Specifies if the host principal should be canonicalized when connecting to " +"LDAP server. This feature is available with MIT Kerberos >= 1.7" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1215 sssd-krb5.5.xml:336 +msgid "krb5_use_kdcinfo (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1218 sssd-krb5.5.xml:339 +msgid "" +"Specifies if the SSSD should instruct the Kerberos libraries what realm and " +"which KDCs to use. This option is on by default, if you disable it, you need " +"to configure the Kerberos library using the <citerefentry> " +"<refentrytitle>krb5.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> configuration file." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1229 sssd-krb5.5.xml:350 +msgid "" +"See the <citerefentry> " +"<refentrytitle>sssd_krb5_locator_plugin</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> manual page for more information on " +"the locator plugin." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1243 +msgid "ldap_pwd_policy (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1246 +msgid "" +"Select the policy to evaluate the password expiration on the client " +"side. The following values are allowed:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1251 +msgid "" +"<emphasis>none</emphasis> - No evaluation on the client side. This option " +"cannot disable server-side password policies." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1256 +msgid "" +"<emphasis>shadow</emphasis> - Use " +"<citerefentry><refentrytitle>shadow</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry> style attributes to evaluate if the " +"password has expired. Please see option \"ldap_chpass_update_last_change\" " +"as well." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1264 +msgid "" +"<emphasis>mit_kerberos</emphasis> - Use the attributes used by MIT Kerberos " +"to determine if the password has expired. Use chpass_provider=krb5 to update " +"these attributes when the password is changed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1273 +msgid "" +"<emphasis>Note</emphasis>: if a password policy is configured on server " +"side, it always takes precedence over policy set with this option." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1281 +msgid "ldap_referrals (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1284 +msgid "Specifies whether automatic referral chasing should be enabled." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1288 +msgid "" +"Please note that sssd only supports referral chasing when it is compiled " +"with OpenLDAP version 2.4.13 or higher." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1293 +msgid "" +"Chasing referrals may incur a performance penalty in environments that use " +"them heavily, a notable example is Microsoft Active Directory. If your setup " +"does not in fact require the use of referrals, setting this option to false " +"might bring a noticeable performance improvement. Setting this option to " +"false is therefore recommended in case the SSSD LDAP provider is used " +"together with Microsoft Active Directory as a backend. Even if SSSD would be " +"able to follow the referral to a different AD DC no additional data would be " +"available." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1312 +msgid "ldap_dns_service_name (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1315 +msgid "Specifies the service name to use when service discovery is enabled." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1319 +msgid "Default: ldap" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1325 +msgid "ldap_chpass_dns_service_name (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1328 +msgid "" +"Specifies the service name to use to find an LDAP server which allows " +"password changes when service discovery is enabled." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1333 +msgid "Default: not set, i.e. service discovery is disabled" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1339 +msgid "ldap_chpass_update_last_change (bool)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1342 +msgid "" +"Specifies whether to update the ldap_user_shadow_last_change attribute with " +"days since the Epoch after a password change operation." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1348 +msgid "" +"It is recommended to set this option explicitly if \"ldap_pwd_policy = " +"shadow\" is used to let SSSD know if the LDAP server will update " +"shadowLastChange LDAP attribute automatically after a password change or if " +"SSSD has to update it." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1362 +msgid "ldap_access_filter (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1365 +msgid "" +"If using access_provider = ldap and ldap_access_order = filter (default), " +"this option is mandatory. It specifies an LDAP search filter criteria that " +"must be met for the user to be granted access on this host. If " +"access_provider = ldap, ldap_access_order = filter and this option is not " +"set, it will result in all users being denied access. Use access_provider = " +"permit to change this default behavior. Please note that this filter is " +"applied on the LDAP user entry only and thus filtering based on nested " +"groups may not work (e.g. memberOf attribute on AD entries points only to " +"direct parents). If filtering based on nested groups is required, please see " +"<citerefentry> " +"<refentrytitle>sssd-simple</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1385 +msgid "Example:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><programlisting> +#: sssd-ldap.5.xml:1388 +#, no-wrap +msgid "" +"access_provider = ldap\n" +"ldap_access_filter = (employeeType=admin)\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1392 +msgid "" +"This example means that access to this host is restricted to users whose " +"employeeType attribute is set to \"admin\"." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1397 +msgid "" +"Offline caching for this feature is limited to determining whether the " +"user's last online login was granted access permission. If they were granted " +"access during their last login, they will continue to be granted access " +"while offline and vice versa." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1405 sssd-ldap.5.xml:1461 +msgid "Default: Empty" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1411 +msgid "ldap_account_expire_policy (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1414 +msgid "" +"With this option a client side evaluation of access control attributes can " +"be enabled." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1418 +msgid "" +"Please note that it is always recommended to use server side access control, " +"i.e. the LDAP server should deny the bind request with a suitable error code " +"even if the password is correct." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1425 +msgid "The following values are allowed:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1428 +msgid "" +"<emphasis>shadow</emphasis>: use the value of ldap_user_shadow_expire to " +"determine if the account is expired." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1433 +msgid "" +"<emphasis>ad</emphasis>: use the value of the 32bit field " +"ldap_user_ad_user_account_control and allow access if the second bit is not " +"set. If the attribute is missing access is granted. Also the expiration time " +"of the account is checked." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1440 +msgid "" +"<emphasis>rhds</emphasis>, <emphasis>ipa</emphasis>, " +"<emphasis>389ds</emphasis>: use the value of ldap_ns_account_lock to check " +"if access is allowed or not." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1446 +msgid "" +"<emphasis>nds</emphasis>: the values of " +"ldap_user_nds_login_allowed_time_map, ldap_user_nds_login_disabled and " +"ldap_user_nds_login_expiration_time are used to check if access is " +"allowed. If both attributes are missing access is granted." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1454 +msgid "" +"Please note that the ldap_access_order configuration option " +"<emphasis>must</emphasis> include <quote>expire</quote> in order for the " +"ldap_account_expire_policy option to work." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1467 +msgid "ldap_access_order (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:405 +msgid "Comma separated list of access control options. Allowed values are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1474 +msgid "<emphasis>filter</emphasis>: use ldap_access_filter" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1477 +msgid "" +"<emphasis>lockout</emphasis>: use account locking. If set, this option " +"denies access in case that ldap attribute 'pwdAccountLockedTime' is present " +"and has value of '000001010000Z'. Please see the option ldap_pwdlockout_dn. " +"Please note that 'access_provider = ldap' must be set for this feature to " +"work." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1487 +msgid "" +"<emphasis> Please note that this option is superseded by the " +"<quote>ppolicy</quote> option and might be removed in a future release. " +"</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1494 +msgid "" +"<emphasis>ppolicy</emphasis>: use account locking. If set, this option " +"denies access in case that ldap attribute 'pwdAccountLockedTime' is present " +"and has value of '000001010000Z' or represents any time in the past. The " +"value of the 'pwdAccountLockedTime' attribute must end with 'Z', which " +"denotes the UTC time zone. Other time zones are not currently supported and " +"will result in \"access-denied\" when users attempt to log in. Please see " +"the option ldap_pwdlockout_dn. Please note that 'access_provider = ldap' " +"must be set for this feature to work." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1511 +msgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1515 sssd-ipa.5.xml:413 +msgid "" +"<emphasis>pwd_expire_policy_reject, pwd_expire_policy_warn, " +"pwd_expire_policy_renew: </emphasis> These options are useful if users are " +"interested in being warned that password is about to expire and " +"authentication is based on using a different method than passwords - for " +"example SSH keys." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1525 sssd-ipa.5.xml:423 +msgid "" +"The difference between these options is the action taken if user password is " +"expired:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ldap.5.xml:1530 sssd-ipa.5.xml:428 +msgid "pwd_expire_policy_reject - user is denied to log in," +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ldap.5.xml:1536 sssd-ipa.5.xml:434 +msgid "pwd_expire_policy_warn - user is still able to log in," +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ldap.5.xml:1542 sssd-ipa.5.xml:440 +msgid "" +"pwd_expire_policy_renew - user is prompted to change their password " +"immediately." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1550 +msgid "" +"Please note that 'access_provider = ldap' must be set for this feature to " +"work. Also 'ldap_pwd_policy' must be set to shadow or mit_kerberos, these " +"options do not work with server-side password policies." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1556 +msgid "" +"<emphasis>authorized_service</emphasis>: use the authorizedService attribute " +"to determine access" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1561 +msgid "<emphasis>host</emphasis>: use the host attribute to determine access" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1565 +msgid "" +"<emphasis>rhost</emphasis>: use the rhost attribute to determine whether " +"remote host can access" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1569 +msgid "" +"Please note, rhost field in pam is set by application, it is better to check " +"what the application sends to pam, before enabling this access control " +"option" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1574 +msgid "Default: filter" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1577 +msgid "" +"Please note that it is a configuration error if a value is used more than " +"once." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1584 +msgid "ldap_pwdlockout_dn (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1587 +msgid "" +"This option specifies the DN of password policy entry on LDAP server. Please " +"note that absence of this option in sssd.conf in case of enabled account " +"lockout checking will yield access denied as ppolicy attributes on LDAP " +"server cannot be checked properly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1595 +msgid "Example: cn=ppolicy,ou=policies,dc=example,dc=com" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1598 +msgid "Default: cn=ppolicy,ou=policies,$ldap_search_base" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1604 +msgid "ldap_deref (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1607 +msgid "" +"Specifies how alias dereferencing is done when performing a search. The " +"following options are allowed:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1612 +msgid "<emphasis>never</emphasis>: Aliases are never dereferenced." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1616 +msgid "" +"<emphasis>searching</emphasis>: Aliases are dereferenced in subordinates of " +"the base object, but not in locating the base object of the search." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1621 +msgid "" +"<emphasis>finding</emphasis>: Aliases are only dereferenced when locating " +"the base object of the search." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1626 +msgid "" +"<emphasis>always</emphasis>: Aliases are dereferenced both in searching and " +"in locating the base object of the search." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1631 +msgid "" +"Default: Empty (this is handled as <emphasis>never</emphasis> by the LDAP " +"client libraries)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1639 +msgid "ldap_rfc2307_fallback_to_local_users (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1642 +msgid "" +"Allows to retain local users as members of an LDAP group for servers that " +"use the RFC2307 schema." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1646 +msgid "" +"In some environments where the RFC2307 schema is used, local users are made " +"members of LDAP groups by adding their names to the memberUid attribute. " +"The self-consistency of the domain is compromised when this is done, so SSSD " +"would normally remove the \"missing\" users from the cached group " +"memberships as soon as nsswitch tries to fetch information about the user " +"via getpw*() or initgroups() calls." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1657 +msgid "" +"This option falls back to checking if local users are referenced, and caches " +"them so that later initgroups() calls will augment the local users with the " +"additional LDAP groups." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1669 sssd-ifp.5.xml:158 +msgid "wildcard_limit (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1672 +msgid "" +"Specifies an upper limit on the number of entries that are downloaded during " +"a wildcard lookup." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1676 +msgid "At the moment, only the InfoPipe responder supports wildcard lookups." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1680 +msgid "Default: 1000 (often the size of one page)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1686 +msgid "ldap_library_debug_level (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1689 +msgid "" +"Switches on libldap debugging with the given level. The libldap debug " +"messages will be written independent of the general debug_level." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1694 +msgid "" +"OpenLDAP uses a bitmap to enable debugging for specific components, -1 will " +"enable full debug output." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1699 +msgid "Default: 0 (libldap debugging disabled)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1705 +msgid "ldap_use_ppolicy (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1708 +msgid "" +"Turns on requesting and relying on the server-side password policy " +"controls. Disabling this allows interacting with services which send back " +"invalid ppolicy extension." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1720 +msgid "ldap_ppolicy_pwd_change_threshold (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1723 +msgid "" +"Forces a password change when server side password policy controls are " +"enabled and remaining grace logins returned by the server after the " +"authentication reach or go below the threshold. Note that the minimum " +"useful value is 2, as changing the password consumes 2 additional grace " +"logins, one to verify the current password and a second one to perform the " +"password change." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ldap.5.xml:52 +msgid "" +"All of the common configuration options that apply to SSSD domains also " +"apply to LDAP domains. Refer to the <quote>DOMAIN SECTIONS</quote> section " +"of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page for full details. Note " +"that SSSD LDAP mapping attributes are described in the <citerefentry> " +"<refentrytitle>sssd-ldap-attributes</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> manual page. <placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap.5.xml:1743 +msgid "SUDO OPTIONS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ldap.5.xml:1745 +msgid "" +"The detailed instructions for configuration of sudo_provider are in the " +"manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1756 +msgid "ldap_sudo_full_refresh_interval (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1759 +msgid "" +"How many seconds SSSD will wait between executing a full refresh of sudo " +"rules (which downloads all rules that are stored on the server)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1764 +msgid "" +"The value must be greater than <emphasis>ldap_sudo_smart_refresh_interval " +"</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1769 +msgid "" +"You can disable full refresh by setting this option to 0. However, either " +"smart or full refresh must be enabled." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1774 +msgid "Default: 21600 (6 hours)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1780 +msgid "ldap_sudo_smart_refresh_interval (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1783 +msgid "" +"How many seconds SSSD has to wait before executing a smart refresh of sudo " +"rules (which downloads all rules that have USN higher than the highest " +"server USN value that is currently known by SSSD)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1789 +msgid "" +"If USN attributes are not supported by the server, the modifyTimestamp " +"attribute is used instead." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1793 +msgid "" +"<emphasis>Note:</emphasis> the highest USN value can be updated by three " +"tasks: 1) By sudo full and smart refresh (if updated rules are found), 2) by " +"enumeration of users and groups (if enabled and updated users or groups are " +"found) and 3) by reconnecting to the server (by default every 15 minutes, " +"see <emphasis>ldap_connection_expire_timeout</emphasis>)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1804 +msgid "" +"You can disable smart refresh by setting this option to 0. However, either " +"smart or full refresh must be enabled." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1815 +msgid "ldap_sudo_random_offset (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1818 +msgid "" +"Random offset between 0 and configured value is added to smart and full " +"refresh periods each time the periodic task is scheduled. The value is in " +"seconds." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1824 +msgid "" +"Note that this random offset is also applied on the first SSSD start which " +"delays the first sudo rules refresh. This prolongs the time when the sudo " +"rules are not available for use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1830 +msgid "You can disable this offset by setting the value to 0." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1840 +msgid "ldap_sudo_use_host_filter (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1843 +msgid "" +"If true, SSSD will download only rules that are applicable to this machine " +"(using the IPv4 or IPv6 host/network addresses and hostnames)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1854 +msgid "ldap_sudo_hostnames (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1857 +msgid "" +"Space separated list of hostnames or fully qualified domain names that " +"should be used to filter the rules." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1862 +msgid "" +"If this option is empty, SSSD will try to discover the hostname and the " +"fully qualified domain name automatically." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1867 sssd-ldap.5.xml:1890 sssd-ldap.5.xml:1908 +#: sssd-ldap.5.xml:1926 +msgid "" +"If <emphasis>ldap_sudo_use_host_filter</emphasis> is " +"<emphasis>false</emphasis> then this option has no effect." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1872 sssd-ldap.5.xml:1895 +msgid "Default: not specified" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1878 +msgid "ldap_sudo_ip (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1881 +msgid "" +"Space separated list of IPv4 or IPv6 host/network addresses that should be " +"used to filter the rules." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1886 +msgid "" +"If this option is empty, SSSD will try to discover the addresses " +"automatically." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1901 +msgid "ldap_sudo_include_netgroups (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1904 +msgid "" +"If true then SSSD will download every rule that contains a netgroup in " +"sudoHost attribute." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1919 +msgid "ldap_sudo_include_regexp (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1922 +msgid "" +"If true then SSSD will download every rule that contains a wildcard in " +"sudoHost attribute." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><note><para> +#: sssd-ldap.5.xml:1932 +msgid "" +"Using wildcard is an operation that is very costly to evaluate on the LDAP " +"server side!" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ldap.5.xml:1944 +msgid "" +"This manual page only describes attribute name mapping. For detailed " +"explanation of sudo related attribute semantics, see <citerefentry> " +"<refentrytitle>sudoers.ldap</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap.5.xml:1954 +msgid "AUTOFS OPTIONS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ldap.5.xml:1956 +msgid "" +"Some of the defaults for the parameters below are dependent on the LDAP " +"schema." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1962 +msgid "ldap_autofs_map_master_name (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1965 +msgid "The name of the automount master map in LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap.5.xml:1968 +msgid "Default: auto.master" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap.5.xml:1979 +msgid "ADVANCED OPTIONS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1986 +msgid "ldap_netgroup_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1991 +msgid "ldap_user_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:1996 +msgid "ldap_group_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><note> +#: sssd-ldap.5.xml:2001 +msgid "<note>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><note><para> +#: sssd-ldap.5.xml:2003 +msgid "" +"If the option <quote>ldap_use_tokengroups</quote> is enabled, the searches " +"against Active Directory will not be restricted and return all groups " +"memberships, even with no GID mapping. It is recommended to disable this " +"feature, if group names are not being displayed correctly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist> +#: sssd-ldap.5.xml:2010 +msgid "</note>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:2012 +msgid "ldap_sudo_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap.5.xml:2017 +msgid "ldap_autofs_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ldap.5.xml:1981 +msgid "" +"These options are supported by LDAP domains, but they should be used with " +"caution. Please include them in your configuration only if you know what you " +"are doing. <placeholder type=\"variablelist\" id=\"0\"/> <placeholder " +"type=\"variablelist\" id=\"1\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap.5.xml:2032 sssd-simple.5.xml:169 sssd-ipa.5.xml:984 +#: sssd-ad.5.xml:1470 sssd-idp.5.xml:248 sssd-krb5.5.xml:483 +#: sss_rpcidmapd.5.xml:98 sssd-session-recording.5.xml:176 +msgid "EXAMPLE" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ldap.5.xml:2034 +msgid "" +"The following example assumes that SSSD is correctly configured and LDAP is " +"set to one of the domains in the <replaceable>[domains]</replaceable> " +"section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-ldap.5.xml:2040 +#, no-wrap +msgid "" +"[domain/LDAP]\n" +"id_provider = ldap\n" +"auth_provider = ldap\n" +"ldap_uri = ldap://ldap.mydomain.org\n" +"ldap_search_base = dc=mydomain,dc=org\n" +"ldap_tls_reqcert = demand\n" +"cache_credentials = true\n" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: sssd-ldap.5.xml:2039 sssd-ldap.5.xml:2057 sssd-simple.5.xml:177 +#: sssd-ipa.5.xml:992 sssd-ad.5.xml:1478 sssd-sudo.5.xml:56 sssd-krb5.5.xml:492 +#: sssd-session-recording.5.xml:182 include/ldap_id_mapping.xml:105 +msgid "<placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap.5.xml:2051 +msgid "LDAP ACCESS FILTER EXAMPLE" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ldap.5.xml:2053 +msgid "" +"The following example assumes that SSSD is correctly configured and to use " +"the ldap_access_order=lockout." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-ldap.5.xml:2058 +#, no-wrap +msgid "" +"[domain/LDAP]\n" +"id_provider = ldap\n" +"auth_provider = ldap\n" +"access_provider = ldap\n" +"ldap_access_order = lockout\n" +"ldap_pwdlockout_dn = cn=ppolicy,ou=policies,dc=mydomain,dc=org\n" +"ldap_uri = ldap://ldap.mydomain.org\n" +"ldap_search_base = dc=mydomain,dc=org\n" +"ldap_tls_reqcert = demand\n" +"cache_credentials = true\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap.5.xml:2073 sssd_krb5_locator_plugin.8.xml:83 sssd-simple.5.xml:189 +#: sssd-ad.5.xml:1493 sssd.8.xml:270 sss_seed.8.xml:163 +msgid "NOTES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ldap.5.xml:2075 +msgid "" +"The descriptions of some of the configuration options in this manual page " +"are based on the <citerefentry> <refentrytitle>ldap.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page from the OpenLDAP 2.4 " +"distribution." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: pam_sss.8.xml:11 pam_sss.8.xml:16 +msgid "pam_sss" +msgstr "" + +#. type: Content of: <reference><refentry><refmeta><manvolnum> +#: pam_sss.8.xml:12 pam_sss_gss.8.xml:12 sssd_krb5_locator_plugin.8.xml:11 +#: sssd.8.xml:11 sss_obfuscate.8.xml:11 sss_override.8.xml:11 +#: sss_cache.8.xml:11 sss_debuglevel.8.xml:11 sss_seed.8.xml:11 +#: idmap_sss.8.xml:11 sssctl.8.xml:11 sssd-kcm.8.xml:11 +#: sssd_krb5_localauth_plugin.8.xml:11 +msgid "8" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: pam_sss.8.xml:17 +msgid "PAM module for SSSD" +msgstr "" + +#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> +#: pam_sss.8.xml:22 +msgid "" +"<command>pam_sss.so</command> <arg choice='opt'> " +"<replaceable>quiet</replaceable> </arg> <arg choice='opt'> " +"<replaceable>forward_pass</replaceable> </arg> <arg choice='opt'> " +"<replaceable>use_first_pass</replaceable> </arg> <arg choice='opt'> " +"<replaceable>use_authtok</replaceable> </arg> <arg choice='opt'> " +"<replaceable>retry=N</replaceable> </arg> <arg choice='opt'> " +"<replaceable>ignore_unknown_user</replaceable> </arg> <arg choice='opt'> " +"<replaceable>ignore_authinfo_unavail</replaceable> </arg> <arg choice='opt'> " +"<replaceable>domains=X</replaceable> </arg> <arg choice='opt'> " +"<replaceable>allow_missing_name</replaceable> </arg> <arg choice='opt'> " +"<replaceable>prompt_always</replaceable> </arg> <arg choice='opt'> " +"<replaceable>try_cert_auth</replaceable> </arg> <arg choice='opt'> " +"<replaceable>require_cert_auth</replaceable> </arg> <arg choice='opt'> " +"<replaceable>allow_chauthtok_by_root</replaceable> </arg>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss.8.xml:67 +msgid "" +"<command>pam_sss.so</command> is the PAM interface to the System Security " +"Services daemon (SSSD). Errors and results are logged through " +"<command>syslog(3)</command> with the LOG_AUTHPRIV facility." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: pam_sss.8.xml:73 pam_sss_gss.8.xml:89 sssd.8.xml:42 sss_obfuscate.8.xml:58 +#: sss_cache.8.xml:39 sss_seed.8.xml:42 sss_ssh_authorizedkeys.1.xml:123 +#: sss_ssh_knownhosts.1.xml:59 +msgid "OPTIONS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:77 +msgid "<option>quiet</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:80 +msgid "Suppress log messages for unknown users." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:85 +msgid "<option>forward_pass</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:88 +msgid "" +"If <option>forward_pass</option> is set the entered password is put on the " +"stack for other PAM modules to use." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:95 +msgid "<option>use_first_pass</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:98 +msgid "" +"The argument use_first_pass forces the module to use a previous stacked " +"modules password and will never prompt the user - if no password is " +"available or the password is not appropriate, the user will be denied " +"access." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:106 +msgid "<option>use_authtok</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:109 +msgid "" +"When password changing enforce the module to set the new password to the one " +"provided by a previously stacked password module." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:116 +msgid "<option>retry=N</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:119 +msgid "" +"If specified the user is asked another N times for a password if " +"authentication fails. Default is 0." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:121 +msgid "" +"Please note that this option might not work as expected if the application " +"calling PAM handles the user dialog on its own. A typical example is " +"<command>sshd</command> with <option>PasswordAuthentication</option>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:130 +msgid "<option>ignore_unknown_user</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:133 +msgid "" +"If this option is specified and the user does not exist, the PAM module will " +"return PAM_IGNORE. This causes the PAM framework to ignore this module." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:140 +msgid "<option>ignore_authinfo_unavail</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:144 +msgid "" +"Specifies that the PAM module should return PAM_IGNORE if it cannot contact " +"the SSSD daemon. This causes the PAM framework to ignore this module." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:151 +msgid "<option>domains</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:155 +msgid "" +"Allows the administrator to restrict the domains a particular PAM service is " +"allowed to authenticate against. The format is a comma-separated list of " +"SSSD domain names, as specified in the sssd.conf file." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:161 +msgid "" +"NOTE: If this is used for a service not running as root user, e.g. a " +"web-server, it must be used in conjunction with the " +"<quote>pam_trusted_users</quote> and <quote>pam_public_domains</quote> " +"options. Please see the <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> manual page for more information on these two PAM responder " +"options." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:176 +msgid "<option>allow_missing_name</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:180 +msgid "" +"The main purpose of this option is to let SSSD determine the user name based " +"on additional information, e.g. the certificate from a Smartcard." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting> +#: pam_sss.8.xml:190 +#, no-wrap +msgid "" +"auth sufficient pam_sss.so allow_missing_name\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:185 +msgid "" +"The current use case are login managers which can monitor a Smartcard reader " +"for card events. In case a Smartcard is inserted the login manager will call " +"a PAM stack which includes a line like <placeholder type=\"programlisting\" " +"id=\"0\"/> In this case SSSD will try to determine the user name based on " +"the content of the Smartcard, returns it to pam_sss which will finally put " +"it on the PAM stack." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:200 +msgid "<option>prompt_always</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:204 +msgid "" +"Always prompt the user for credentials. With this option credentials " +"requested by other PAM modules, typically a password, will be ignored and " +"pam_sss will prompt for credentials again. Based on the pre-auth reply by " +"SSSD pam_sss might prompt for a password, a Smartcard PIN or other " +"credentials." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:215 +msgid "<option>try_cert_auth</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:219 +msgid "" +"Try to use certificate based authentication, i.e. authentication with a " +"Smartcard or similar devices. If a Smartcard is available and the service is " +"allowed for Smartcard authentication the user will be prompted for a PIN and " +"the certificate based authentication will continue" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:227 +msgid "" +"If no Smartcard is available or certificate based authentication is not " +"allowed for the current service PAM_AUTHINFO_UNAVAIL is returned." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:235 +msgid "<option>require_cert_auth</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:239 +msgid "" +"Do certificate based authentication, i.e. authentication with a Smartcard " +"or similar devices. If a Smartcard is not available the user will be " +"prompted to insert one. SSSD will wait for a Smartcard until the timeout " +"defined by p11_wait_for_card_timeout passed, please see " +"<citerefentry><refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry> for details." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:249 +msgid "" +"If no Smartcard is available after the timeout or certificate based " +"authentication is not allowed for the current service PAM_AUTHINFO_UNAVAIL " +"is returned." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:257 +msgid "<option>allow_chauthtok_by_root</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:261 +msgid "" +"By default the chauthtok PAM action will short-circuit to returning " +"PAM_SUCCESS when pam_sss.so is invoked by root user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:266 +msgid "" +"This option disables this behavior allowing to change auth tokens when " +"running as root." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: pam_sss.8.xml:275 pam_sss_gss.8.xml:103 +msgid "MODULE TYPES PROVIDED" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss.8.xml:276 +msgid "" +"All module types (<option>account</option>, <option>auth</option>, " +"<option>password</option> and <option>session</option>) are provided." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss.8.xml:279 +msgid "" +"If SSSD's PAM responder is not running, e.g. if the PAM responder socket is " +"not available, pam_sss will return PAM_USER_UNKNOWN when called as " +"<option>account</option> module to avoid issues with users from other " +"sources during access control." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: pam_sss.8.xml:286 pam_sss_gss.8.xml:108 +msgid "RETURN VALUES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:289 pam_sss_gss.8.xml:111 +msgid "PAM_SUCCESS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:292 pam_sss_gss.8.xml:114 +msgid "The PAM operation finished successfully." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:297 pam_sss_gss.8.xml:119 +msgid "PAM_USER_UNKNOWN" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:300 +msgid "" +"The user is not known to the authentication service or the SSSD's PAM " +"responder is not running." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:306 pam_sss_gss.8.xml:128 +msgid "PAM_AUTH_ERR" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:309 +msgid "" +"Authentication failure. Also, could be returned when there is a problem with " +"getting the certificate." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:315 +msgid "PAM_PERM_DENIED" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:318 +msgid "" +"Permission denied. The SSSD log files may contain additional information " +"about the error." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:324 +msgid "PAM_IGNORE" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:327 +msgid "" +"See options <option>ignore_unknown_user</option> and " +"<option>ignore_authinfo_unavail</option>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:333 +msgid "PAM_AUTHTOK_ERR" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:336 +msgid "" +"Unable to obtain the new authentication token. Also, could be returned when " +"the user authenticates with certificates and multiple certificates are " +"available, but the installed version of GDM does not support selection from " +"multiple certificates." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:344 pam_sss_gss.8.xml:136 +msgid "PAM_AUTHINFO_UNAVAIL" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:347 pam_sss_gss.8.xml:139 +msgid "" +"Unable to access the authentication information. This might be due to a " +"network or hardware failure." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:353 +msgid "PAM_BUF_ERR" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:356 +msgid "" +"A memory error occurred. Also, could be returned when options use_first_pass " +"or use_authtok were set, but no password was found from the previously " +"stacked PAM module." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:363 pam_sss_gss.8.xml:145 +msgid "PAM_SYSTEM_ERR" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:366 pam_sss_gss.8.xml:148 +msgid "" +"A system error occurred. The SSSD log files may contain additional " +"information about the error." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:372 +msgid "PAM_CRED_ERR" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:375 +msgid "Unable to set the credentials of the user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:380 +msgid "PAM_CRED_INSUFFICIENT" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:383 +msgid "" +"The application does not have sufficient credentials to authenticate the " +"user. For example, missing PIN during smartcard authentication or missing " +"factor during two-factor authentication." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:391 +msgid "PAM_SERVICE_ERR" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:394 +msgid "Error in service module." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:399 +msgid "PAM_NEW_AUTHTOK_REQD" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:402 +msgid "The user's authentication token has expired." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:407 +msgid "PAM_ACCT_EXPIRED" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:410 +msgid "The user account has expired." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:415 +msgid "PAM_SESSION_ERR" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:418 +msgid "Unable to fetch IPA Desktop Profile rules or user info." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:423 +msgid "PAM_CRED_UNAVAIL" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:426 +msgid "Unable to retrieve Kerberos user credentials." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:431 +msgid "PAM_NO_MODULE_DATA" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:434 +msgid "" +"No authentication method was found by Kerberos. This might happen if the " +"user has a Smartcard assigned but the pkint plugin is not available on the " +"client." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:441 +msgid "PAM_CONV_ERR" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:444 +msgid "Conversation failure." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:449 +msgid "PAM_AUTHTOK_LOCK_BUSY" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:452 +msgid "No KDC suitable for password change is available." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:457 +msgid "PAM_ABORT" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:460 +msgid "Unknown PAM call." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:465 +msgid "PAM_MODULE_UNKNOWN" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:468 +msgid "Unsupported PAM task or command." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss.8.xml:473 +msgid "PAM_BAD_ITEM" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss.8.xml:476 +msgid "The authentication module cannot handle Smartcard credentials." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: pam_sss.8.xml:484 +msgid "FILES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss.8.xml:485 +msgid "" +"If a password reset by root fails, because the corresponding SSSD provider " +"does not support password resets, an individual message can be " +"displayed. This message can e.g. contain instructions about how to reset a " +"password." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss.8.xml:490 +msgid "" +"The message is read from the file " +"<filename>pam_sss_pw_reset_message.LOC</filename> where LOC stands for a " +"locale string returned by <citerefentry> " +"<refentrytitle>setlocale</refentrytitle><manvolnum>3</manvolnum> " +"</citerefentry>. If there is no matching file the content of " +"<filename>pam_sss_pw_reset_message.txt</filename> is displayed. Root must be " +"the owner of the files and only root may have read and write permissions " +"while all other users must have only read permissions." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss.8.xml:500 +msgid "" +"These files are searched in the directory " +"<filename>/etc/sssd/customize/DOMAIN_NAME/</filename>. If no matching file " +"is present a generic message is displayed." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: pam_sss_gss.8.xml:11 pam_sss_gss.8.xml:16 +msgid "pam_sss_gss" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: pam_sss_gss.8.xml:17 +msgid "PAM module for SSSD GSSAPI authentication" +msgstr "" + +#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> +#: pam_sss_gss.8.xml:22 +msgid "" +"<command>pam_sss_gss.so</command> <arg choice='opt'> " +"<replaceable>debug</replaceable> </arg>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:32 +msgid "" +"<command>pam_sss_gss.so</command> authenticates user over GSSAPI in " +"cooperation with SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:36 +msgid "" +"This module will try to authenticate the user using the GSSAPI hostbased " +"service name host@hostname which translates to host/hostname@REALM Kerberos " +"principal. The <emphasis>REALM</emphasis> part of the Kerberos principal " +"name is derived by Kerberos internal mechanisms and it can be set explicitly " +"in configuration of [domain_realm] section in /etc/krb5.conf." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:44 +msgid "" +"SSSD is used to provide desired service name and to validate the user's " +"credentials using GSSAPI calls. If the service ticket is already present in " +"the Kerberos credentials cache or if user's ticket granting ticket can be " +"used to get the correct service ticket then the user will be authenticated." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:51 +msgid "" +"If <option>pam_gssapi_check_upn</option> is True (default) then SSSD " +"requires that the credentials used to obtain the service tickets can be " +"associated with the user. This means that the principal that owns the " +"Kerberos credentials must match with the user principal name as defined in " +"LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:58 +msgid "" +"To enable GSSAPI authentication in SSSD, set " +"<option>pam_gssapi_services</option> option in [pam] or domain section of " +"sssd.conf. The service credentials need to be stored in SSSD's keytab (it is " +"already present if you use ipa or ad provider). The keytab location can be " +"set with <option>krb5_keytab</option> option. See <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> and <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> for more details on these options." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:74 +msgid "" +"Some Kerberos deployments allow to associate authentication indicators with " +"a particular pre-authentication method used to obtain the ticket granting " +"ticket by the user. <command>pam_sss_gss.so</command> allows to enforce " +"presence of authentication indicators in the service tickets before a " +"particular PAM service can be accessed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:82 +msgid "" +"If <option>pam_gssapi_indicators_map</option> is set in the [pam] or domain " +"section of sssd.conf, then SSSD will perform a check of the presence of any " +"configured indicators in the service ticket." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: pam_sss_gss.8.xml:93 +msgid "<option>debug</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss_gss.8.xml:96 +msgid "Print debugging information." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:104 +msgid "Only the <option>auth</option> module type is provided." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss_gss.8.xml:122 +msgid "" +"The user is not known to the authentication service or the GSSAPI " +"authentication is not supported." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: pam_sss_gss.8.xml:131 +msgid "Authentication failure." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:159 +msgid "" +"The main use case is to provide password-less authentication in sudo but " +"without the need to disable authentication completely. To achieve this, " +"first enable GSSAPI authentication for sudo in sssd.conf:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><programlisting> +#: pam_sss_gss.8.xml:165 +#, no-wrap +msgid "" +"[domain/MYDOMAIN]\n" +"pam_gssapi_services = sudo, sudo-i\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:169 +msgid "" +"And then enable the module in desired PAM stack (e.g. /etc/pam.d/sudo and " +"/etc/pam.d/sudo-i)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><programlisting> +#: pam_sss_gss.8.xml:173 +#, no-wrap +msgid "" +"...\n" +"auth sufficient pam_sss_gss.so\n" +"...\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: pam_sss_gss.8.xml:180 +msgid "TROUBLESHOOTING" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:182 +msgid "" +"SSSD logs, pam_sss_gss debug output and syslog may contain helpful " +"information about the error. Here are some common issues:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:186 +msgid "" +"1. I have KRB5CCNAME environment variable set and the authentication does " +"not work: Depending on your sudo version, it is possible that sudo does not " +"pass this variable to the PAM environment. Try adding KRB5CCNAME to " +"<option>env_keep</option> in /etc/sudoers or in your LDAP sudo rules default " +"options." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:193 +msgid "" +"2. Authentication does not work and syslog contains \"Server not found in " +"Kerberos database\": Kerberos is probably not able to resolve correct realm " +"for the service ticket based on the hostname. Try adding the hostname " +"directly to <option>[domain_realm]</option> in /etc/krb5.conf like so:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:200 +msgid "" +"3. Authentication does not work and syslog contains \"No Kerberos " +"credentials available\": You don't have any credentials that can be used to " +"obtain the required service ticket. Use kinit or authenticate over SSSD to " +"acquire those credentials." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: pam_sss_gss.8.xml:206 +msgid "" +"4. Authentication does not work and SSSD sssd-pam log contains \"User with " +"UPN [$UPN] was not found.\" or \"UPN [$UPN] does not match target user " +"[$username].\": You are using credentials that can not be mapped to the user " +"that is being authenticated. Try to use kswitch to select different " +"principal, make sure you authenticated with SSSD or consider disabling " +"<option>pam_gssapi_check_upn</option>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><programlisting> +#: pam_sss_gss.8.xml:214 +#, no-wrap +msgid "" +"[domain_realm]\n" +".myhostname = MYREALM\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd_krb5_locator_plugin.8.xml:10 sssd_krb5_locator_plugin.8.xml:15 +msgid "sssd_krb5_locator_plugin" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd_krb5_locator_plugin.8.xml:16 +msgid "Kerberos locator plugin" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:22 +msgid "" +"The Kerberos locator plugin <command>sssd_krb5_locator_plugin</command> is " +"used by libkrb5 to find KDCs for a given Kerberos realm. SSSD provides such " +"a plugin to guide all Kerberos clients on a system to a single KDC. In " +"general it should not matter to which KDC a client process is talking to. " +"But there are cases, e.g. after a password change, where not all KDCs are in " +"the same state because the new data has to be replicated first. To avoid " +"unexpected authentication failures and maybe even account lockings it would " +"be good to talk to a single KDC as long as possible." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:34 +msgid "" +"libkrb5 will search the locator plugin in the libkrb5 sub-directory of the " +"Kerberos plugin directory, see plugin_base_dir in <citerefentry> " +"<refentrytitle>krb5.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> for details. The plugin can only be disabled by removing the " +"plugin file. There is no option in the Kerberos configuration to disable " +"it. But the SSSD_KRB5_LOCATOR_DISABLE environment variable can be used to " +"disable the plugin for individual commands. Alternatively the SSSD option " +"krb5_use_kdcinfo=False can be used to not generate the data needed by the " +"plugin. With this the plugin is still called but will provide no data to the " +"caller so that libkrb5 can fall back to other methods defined in krb5.conf." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:50 +msgid "" +"The plugin reads the information about the KDCs of a given realm from a file " +"called <filename>kdcinfo.REALM</filename>. The file should contain one or " +"more DNS names or IP addresses either in dotted-decimal IPv4 notation or the " +"hexadecimal IPv6 notation. An optional port number can be added to the end " +"separated with a colon, the IPv6 address has to be enclosed in squared " +"brackets in this case as usual. Valid entries are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd_krb5_locator_plugin.8.xml:58 +msgid "kdc.example.com" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd_krb5_locator_plugin.8.xml:59 +msgid "kdc.example.com:321" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd_krb5_locator_plugin.8.xml:60 +msgid "1.2.3.4" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd_krb5_locator_plugin.8.xml:61 +msgid "5.6.7.8:99" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd_krb5_locator_plugin.8.xml:62 +msgid "2001:db8:85a3::8a2e:370:7334" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd_krb5_locator_plugin.8.xml:63 +msgid "[2001:db8:85a3::8a2e:370:7334]:321" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:65 +msgid "" +"SSSD's krb5 auth-provider which is used by the IPA and AD providers as well " +"adds the address of the current KDC or domain controller SSSD is using to " +"this file." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:70 +msgid "" +"In environments with read-only and read-write KDCs where clients are " +"expected to use the read-only instances for the general operations and only " +"the read-write KDC for config changes like password changes a " +"<filename>kpasswdinfo.REALM</filename> is used as well to identify " +"read-write KDCs. If this file exists for the given realm the content will be " +"used by the plugin to reply to requests for a kpasswd or kadmin server or " +"for the MIT Kerberos specific master KDC. If the address contains a port " +"number the default KDC port 88 will be used for the latter." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:85 +msgid "" +"Not all Kerberos implementations support the use of plugins. If " +"<command>sssd_krb5_locator_plugin</command> is not available on your system " +"you have to edit /etc/krb5.conf to reflect your Kerberos setup." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:91 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_DEBUG is set to any value " +"debug messages will be sent to stderr." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:95 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_DISABLE is set to any value " +"the plugin is disabled and will just return KRB5_PLUGIN_NO_HANDLE to the " +"caller." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_locator_plugin.8.xml:100 +msgid "" +"If the environment variable SSSD_KRB5_LOCATOR_IGNORE_DNS_FAILURES is set to " +"any value plugin will try to resolve all DNS names in kdcinfo file. By " +"default plugin returns KRB5_PLUGIN_NO_HANDLE to the caller immediately on " +"first DNS resolving failure." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd-simple.5.xml:10 sssd-simple.5.xml:16 +msgid "sssd-simple" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd-simple.5.xml:17 +msgid "the configuration file for SSSD's 'simple' access-control provider" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-simple.5.xml:24 +msgid "" +"This manual page describes the configuration of the simple access-control " +"provider for <citerefentry> <refentrytitle>sssd</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry>. For a detailed syntax reference, " +"refer to the <quote>FILE FORMAT</quote> section of the <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> manual page." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-simple.5.xml:38 +msgid "" +"The simple access provider grants or denies access based on an access or " +"deny list of user or group names." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-simple.5.xml:42 +msgid "" +"Groups from other domains configured in sssd.conf, even if the simple access " +"provider is used there as well, and groups managed outside of SSSD are not " +"evaluated." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-simple.5.xml:47 +msgid "The following rules apply:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd-simple.5.xml:51 +msgid "" +"It is not recommended to leave an option empty, it might cause errors. If " +"you want to allow all users, do not specify any `simple_allow_users` or " +"`simple_allow_groups`." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd-simple.5.xml:58 +msgid "" +"If any list is provided, the order of evaluation is: allow → deny. This " +"means that any matching deny rule will supersede any matched allow rule." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd-simple.5.xml:65 +msgid "" +"If either or both \"allow\" lists are provided, all users are denied unless " +"they appear in at least one of these lists (OR condition)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd-simple.5.xml:72 +msgid "" +"If either or both \"deny\" lists are provided, all users are granted access " +"unless they appear in at least one of these lists (OR condition)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-simple.5.xml:91 +msgid "simple_allow_users (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-simple.5.xml:94 +msgid "" +"Comma-separated list of users who are allowed to log in. If this option is " +"specified, all other users are denied unless they are members of groups " +"listed in`simple_allow_groups`." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-simple.5.xml:103 +msgid "simple_deny_users (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-simple.5.xml:106 +msgid "" +"Comma-separated list of users who are explicitly denied access. If this " +"option is specified, these users will be denied regardless of whether they " +"appear in `simple_allow_users` or `simple_allow_groups`." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-simple.5.xml:112 +msgid "" +"OR Logic Applies: A user will be denied access if they are listed in " +"`simple_deny_users` or if they are a member of a group in " +"`simple_deny_groups`." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-simple.5.xml:120 +msgid "simple_allow_groups (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-simple.5.xml:123 +msgid "" +"Comma-separated list of groups that are allowed to log in. If this option is " +"specified, all other users are denied unless they are explicitly listed in " +"`simple_allow_users`." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-simple.5.xml:129 +msgid "" +"OR Logic Applies: A user can log in if they are listed in " +"`simple_allow_users` or if they belong to a group in `simple_allow_groups`." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-simple.5.xml:134 sssd-simple.5.xml:154 +msgid "" +"This applies only to groups within this SSSD domain. Local groups are not " +"evaluated." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-simple.5.xml:141 +msgid "simple_deny_groups (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-simple.5.xml:144 +msgid "" +"Comma-separated list of groups that are explicitly denied access. This " +"applies only to groups within this SSSD domain. Local groups are not " +"evaluated." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-simple.5.xml:149 +msgid "" +"OR Logic Applies: A user will be denied access if they are listed in " +"`simple_deny_users` or if they are a member of any group in " +"`simple_deny_groups`." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-simple.5.xml:83 sssd-ipa.5.xml:83 sssd-ad.5.xml:131 sssd-idp.5.xml:55 +msgid "" +"Refer to the section <quote>DOMAIN SECTIONS</quote> of the <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> manual page for details on the configuration of an SSSD " +"domain. <placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-simple.5.xml:162 +msgid "" +"Specifying no values for any of the lists is equivalent to skipping it " +"entirely. Beware of this while generating parameters for the simple provider " +"using automated scripts." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-simple.5.xml:171 +msgid "" +"The following example assumes that SSSD is correctly configured and " +"example.com is one of the domains in the <replaceable>[sssd]</replaceable> " +"section. This example shows only the simple access provider-specific " +"options." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-simple.5.xml:178 +#, no-wrap +msgid "" +"[domain/example.com]\n" +"access_provider = simple\n" +"simple_allow_users = user1, user2\n" +"simple_deny_users = user3, user4\n" +"simple_allow_groups = allowed_group1\n" +"simple_deny_groups = denied_group1\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-simple.5.xml:191 +msgid "" +"The complete group membership hierarchy is resolved before the access check, " +"thus even nested groups can be included in the access lists. Please be " +"aware that the <quote>ldap_group_nesting_level</quote> option may impact the " +"results and should be set to a sufficient value. (<citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry>) option." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sss-certmap.5.xml:10 sss-certmap.5.xml:16 +msgid "sss-certmap" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sss-certmap.5.xml:17 +msgid "SSSD Certificate Matching and Mapping Rules" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss-certmap.5.xml:23 +msgid "" +"The manual page describes the rules which can be used by SSSD and other " +"components to match X.509 certificates and map them to accounts." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss-certmap.5.xml:28 +msgid "" +"Each rule has four components, a <quote>priority</quote>, a <quote>matching " +"rule</quote>, a <quote>mapping rule</quote> and a <quote>domain " +"list</quote>. All components are optional. A missing <quote>priority</quote> " +"will add the rule with the lowest priority. The default <quote>matching " +"rule</quote> will match certificates with the digitalSignature key usage and " +"clientAuth extended key usage. If the <quote>mapping rule</quote> is empty " +"the certificates will be searched in the userCertificate attribute as DER " +"encoded binary. If no domains are given only the local domain will be " +"searched." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss-certmap.5.xml:39 +msgid "" +"To allow extensions or completely different style of rule the " +"<quote>mapping</quote> and <quote>matching rules</quote> can contain a " +"prefix separated with a ':' from the main part of the rule. The prefix may " +"only contain upper-case ASCII letters and numbers. If the prefix is omitted " +"the default type will be used which is 'KRB5' for the matching rules and " +"'LDAP' for the mapping rules." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss-certmap.5.xml:48 +msgid "" +"The 'sssctl' utility provides the 'cert-eval-rule' command to check if a " +"given certificate matches a matching rules and how the output of a mapping " +"rule would look like." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sss-certmap.5.xml:55 +msgid "RULE COMPONENTS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sss-certmap.5.xml:57 +msgid "PRIORITY" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss-certmap.5.xml:59 +msgid "" +"The rules are processed by priority while the number '0' (zero) indicates " +"the highest priority. The higher the number the lower is the priority. A " +"missing value indicates the lowest priority. The rules processing is stopped " +"when a matched rule is found and no further rules are checked." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss-certmap.5.xml:66 +msgid "" +"Internally the priority is treated as unsigned 32bit integer, using a " +"priority value larger than 4294967295 will cause an error." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss-certmap.5.xml:70 +msgid "" +"If multiple rules have the same priority and only one of the related " +"matching rules applies, this rule will be chosen. If there are multiple " +"rules with the same priority which matches, one is chosen but which one is " +"undefined. To avoid this undefined behavior either use different priorities " +"or make the matching rules more specific e.g. by using distinct " +"<ISSUER> patterns." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sss-certmap.5.xml:79 +msgid "MATCHING RULE" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss-certmap.5.xml:81 +msgid "" +"The matching rule is used to select a certificate to which the mapping rule " +"should be applied. It uses a system similar to the one used by " +"<quote>pkinit_cert_match</quote> option of MIT Kerberos. It consists of a " +"keyword enclosed by '<' and '>' which identified a certain part of the " +"certificate and a pattern which should be found for the rule to " +"match. Multiple keyword pattern pairs can be either joined with '&&' " +"(and) or '||' (or)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss-certmap.5.xml:90 +msgid "" +"Given the similarity to MIT Kerberos the type prefix for this rule is " +"'KRB5'. But 'KRB5' will also be the default for <quote>matching " +"rules</quote> so that \"<SUBJECT>.*,DC=MY,DC=DOMAIN\" and " +"\"KRB5:<SUBJECT>.*,DC=MY,DC=DOMAIN\" are equivalent." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:99 +msgid "<SUBJECT>regular-expression" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:102 +msgid "" +"With this a part or the whole subject name of the certificate can be " +"matched. For the matching POSIX Extended Regular Expression syntax is used, " +"see regex(7) for details." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:108 +msgid "" +"For the matching the subject name stored in the certificate in DER encoded " +"ASN.1 is converted into a string according to RFC 4514. This means the most " +"specific name component comes first. Please note that not all possible " +"attribute names are covered by RFC 4514. The names included are 'CN', 'L', " +"'ST', 'O', 'OU', 'C', 'STREET', 'DC' and 'UID'. Other attribute names might " +"be shown differently on different platform and by different tools. To avoid " +"confusion those attribute names are best not used or covered by a suitable " +"regular-expression." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:121 +msgid "Example: <SUBJECT>.*,DC=MY,DC=DOMAIN" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:124 +msgid "" +"Please note that the characters \"^.[$()|*+?{\\\" have a special meaning in " +"regular expressions and must be escaped with the help of the '\\' character " +"so that they are matched as ordinary characters." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:130 +msgid "Example: <SUBJECT>^CN=.* \\(Admin\\),DC=MY,DC=DOMAIN$" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:135 +msgid "<ISSUER>regular-expression" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:138 +msgid "" +"With this a part or the whole issuer name of the certificate can be " +"matched. All comments for <SUBJECT> apply her as well." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:143 +msgid "Example: <ISSUER>^CN=My-CA,DC=MY,DC=DOMAIN$" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:148 +msgid "<KU>key-usage" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:151 +msgid "" +"This option can be used to specify which key usage values the certificate " +"should have. The following values can be used in a comma separated list:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:155 +msgid "digitalSignature" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:156 +msgid "nonRepudiation" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:157 +msgid "keyEncipherment" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:158 +msgid "dataEncipherment" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:159 +msgid "keyAgreement" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:160 +msgid "keyCertSign" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:161 +msgid "cRLSign" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:162 +msgid "encipherOnly" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:163 +msgid "decipherOnly" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:167 +msgid "" +"A numerical value in the range of a 32bit unsigned integer can be used as " +"well to cover special use cases." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:171 +msgid "Example: <KU>digitalSignature,keyEncipherment" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:176 +msgid "<EKU>extended-key-usage" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:179 +msgid "" +"This option can be used to specify which extended key usage the certificate " +"should have. The following value can be used in a comma separated list:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:183 +msgid "serverAuth" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:184 +msgid "clientAuth" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:185 +msgid "codeSigning" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:186 +msgid "emailProtection" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:187 +msgid "timeStamping" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:188 +msgid "OCSPSigning" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:189 +msgid "KPClientAuth" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:190 +msgid "pkinit" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sss-certmap.5.xml:191 +msgid "msScLogin" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:195 +msgid "" +"Extended key usages which are not listed above can be specified with their " +"OID in dotted-decimal notation." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:199 +msgid "Example: <EKU>clientAuth,1.3.6.1.5.2.3.4" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:204 +msgid "<SAN>regular-expression" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:207 +msgid "" +"To be compatible with the usage of MIT Kerberos this option will match the " +"Kerberos principals in the PKINIT or AD NT Principal SAN as " +"<SAN:Principal> does." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:212 +msgid "Example: <SAN>.*@MY\\.REALM" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:217 +msgid "<SAN:Principal>regular-expression" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:220 +msgid "Match the Kerberos principals in the PKINIT or AD NT Principal SAN." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:224 +msgid "Example: <SAN:Principal>.*@MY\\.REALM" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:229 +msgid "<SAN:ntPrincipalName>regular-expression" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:232 +msgid "Match the Kerberos principals from the AD NT Principal SAN." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:236 +msgid "Example: <SAN:ntPrincipalName>.*@MY.AD.REALM" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:241 +msgid "<SAN:pkinit>regular-expression" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:244 +msgid "Match the Kerberos principals from the PKINIT SAN." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:247 +msgid "Example: <SAN:ntPrincipalName>.*@MY\\.PKINIT\\.REALM" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:252 +msgid "<SAN:dotted-decimal-oid>regular-expression" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:255 +msgid "" +"Take the value of the otherName SAN component given by the OID in " +"dotted-decimal notation, interpret it as string and try to match it against " +"the regular expression." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:261 +msgid "Example: <SAN:1.2.3.4>test" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:266 +msgid "<SAN:otherName>base64-string" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:269 +msgid "" +"Do a binary match with the base64 encoded blob against all otherName SAN " +"components. With this option it is possible to match against custom " +"otherName components with special encodings which could not be treated as " +"strings." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:276 +msgid "Example: <SAN:otherName>MTIz" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:281 +msgid "<SAN:rfc822Name>regular-expression" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:284 +msgid "Match the value of the rfc822Name SAN." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:287 +msgid "Example: <SAN:rfc822Name>.*@email\\.domain" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:292 +msgid "<SAN:dNSName>regular-expression" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:295 +msgid "Match the value of the dNSName SAN." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:298 +msgid "Example: <SAN:dNSName>.*\\.my\\.dns\\.domain" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:303 +msgid "<SAN:x400Address>base64-string" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:306 +msgid "Binary match the value of the x400Address SAN." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:309 +msgid "Example: <SAN:x400Address>MTIz" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:314 +msgid "<SAN:directoryName>regular-expression" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:317 +msgid "" +"Match the value of the directoryName SAN. The same comments as given for " +"<ISSUER> and <SUBJECT> apply here as well." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:322 +msgid "Example: <SAN:directoryName>.*,DC=com" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:327 +msgid "<SAN:ediPartyName>base64-string" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:330 +msgid "Binary match the value of the ediPartyName SAN." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:333 +msgid "Example: <SAN:ediPartyName>MTIz" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:338 +msgid "<SAN:uniformResourceIdentifier>regular-expression" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:341 +msgid "Match the value of the uniformResourceIdentifier SAN." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:344 +msgid "Example: <SAN:uniformResourceIdentifier>URN:.*" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:349 +msgid "<SAN:iPAddress>regular-expression" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:352 +msgid "Match the value of the iPAddress SAN." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:355 +msgid "Example: <SAN:iPAddress>192\\.168\\..*" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:360 +msgid "<SAN:registeredID>regular-expression" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:363 +msgid "Match the value of the registeredID SAN as dotted-decimal string." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:367 +msgid "Example: <SAN:registeredID>1\\.2\\.3\\..*" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss-certmap.5.xml:96 +msgid "The available options are: <placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sss-certmap.5.xml:375 +msgid "MAPPING RULE" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss-certmap.5.xml:377 +msgid "" +"The mapping rule is used to associate a certificate with one or more " +"accounts. A Smartcard with the certificate and the matching private key can " +"then be used to authenticate as one of those accounts." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss-certmap.5.xml:382 +msgid "" +"Currently SSSD basically only supports LDAP to lookup user information (the " +"exception is the proxy provider which is not of relevance here). Because of " +"this the mapping rule is based on LDAP search filter syntax with templates " +"to add certificate content to the filter. It is expected that the filter " +"will only contain the specific data needed for the mapping and that the " +"caller will embed it in another filter to do the actual search. Because of " +"this the filter string should start and stop with '(' and ')' respectively." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss-certmap.5.xml:392 +msgid "" +"In general it is recommended to use attributes from the certificate and add " +"them to special attributes to the LDAP user object. E.g. the " +"'altSecurityIdentities' attribute in AD or the 'ipaCertMapData' attribute " +"for IPA can be used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss-certmap.5.xml:398 +msgid "" +"This should be preferred to read user specific data from the certificate " +"like e.g. an email address and search for it in the LDAP server. The reason " +"is that the user specific data in LDAP might change for various reasons " +"would break the mapping. On the other hand it would be hard to break the " +"mapping on purpose for a specific user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss-certmap.5.xml:406 +msgid "" +"The default <quote>mapping rule</quote> type is 'LDAP' which can be added as " +"a prefix to a rule like e.g. " +"'LDAP:(userCertificate;binary={cert!bin})'. There is an extension called " +"'LDAPU1' which offer more templates for more flexibility. To allow older " +"versions of this library to ignore the extension the prefix 'LDAPU1' must be " +"used when using the new templates in a <quote>mapping rule</quote> otherwise " +"the old version of this library will fail with a parsing error. The new " +"templates are described in section <xref linkend=\"map_ldapu1\"/>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:424 +msgid "{issuer_dn[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:427 +msgid "" +"This template will add the full issuer DN converted to a string according to " +"RFC 4514. If X.500 ordering (most specific RDN comes last) an option with " +"the '_x500' prefix should be used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:433 sss-certmap.5.xml:459 +msgid "" +"The conversion options starting with 'ad_' will use attribute names as used " +"by AD, e.g. 'S' instead of 'ST'." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:437 sss-certmap.5.xml:463 +msgid "" +"The conversion options starting with 'nss_' will use attribute names as used " +"by NSS." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:441 sss-certmap.5.xml:467 +msgid "" +"The default conversion option is 'nss', i.e. attribute names according to " +"NSS and LDAP/RFC 4514 ordering." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:445 +msgid "" +"Example: " +"(ipacertmapdata=X509:<I>{issuer_dn!ad}<S>{subject_dn!ad})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:450 +msgid "{subject_dn[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:453 +msgid "" +"This template will add the full subject DN converted to string according to " +"RFC 4514. If X.500 ordering (most specific RDN comes last) an option with " +"the '_x500' prefix should be used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:471 +msgid "" +"Example: " +"(ipacertmapdata=X509:<I>{issuer_dn!nss_x500}<S>{subject_dn!nss_x500})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:476 +msgid "{cert[!(bin|base64)]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:479 +msgid "" +"This template will add the whole DER encoded certificate as a string to the " +"search filter. Depending on the conversion option the binary certificate is " +"either converted to an escaped hex sequence '\\xx' or base64. The escaped " +"hex sequence is the default and can e.g. be used with the LDAP attribute " +"'userCertificate;binary'." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:487 +msgid "Example: (userCertificate;binary={cert!bin})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:492 +msgid "{subject_principal[.short_name]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:495 +msgid "" +"This template will add the Kerberos principal which is taken either from the " +"SAN used by pkinit or the one used by AD. The 'short_name' component " +"represents the first part of the principal before the '@' sign." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:501 +msgid "" +"Example: " +"(|(userPrincipal={subject_principal})(samAccountName={subject_principal.short_name}))" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:506 +msgid "{subject_pkinit_principal[.short_name]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:509 +msgid "" +"This template will add the Kerberos principal which is given by the SAN used " +"by pkinit. The 'short_name' component represents the first part of the " +"principal before the '@' sign." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:515 +msgid "" +"Example: " +"(|(userPrincipal={subject_pkinit_principal})(uid={subject_pkinit_principal.short_name}))" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:520 +msgid "{subject_nt_principal[.short_name]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:523 +msgid "" +"This template will add the Kerberos principal which is given by the SAN used " +"by AD. The 'short_name' component represent the first part of the principal " +"before the '@' sign." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:529 +msgid "" +"Example: " +"(|(userPrincipalName={subject_nt_principal})(samAccountName={subject_nt_principal.short_name}))" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:534 +msgid "{subject_rfc822_name[.short_name]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:537 +msgid "" +"This template will add the string which is stored in the rfc822Name " +"component of the SAN, typically an email address. The 'short_name' component " +"represents the first part of the address before the '@' sign." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:543 +msgid "" +"Example: " +"(|(mail={subject_rfc822_name})(uid={subject_rfc822_name.short_name}))" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:548 +msgid "{subject_dns_name[.short_name]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:551 +msgid "" +"This template will add the string which is stored in the dNSName component " +"of the SAN, typically a fully-qualified host name. The 'short_name' " +"component represents the first part of the name before the first '.' sign." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:557 +msgid "Example: (|(fqdn={subject_dns_name})(host={subject_dns_name.short_name}))" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:562 +msgid "{subject_uri}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:565 +msgid "" +"This template will add the string which is stored in the " +"uniformResourceIdentifier component of the SAN." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:569 +msgid "Example: (uri={subject_uri})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:574 +msgid "{subject_ip_address}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:577 +msgid "" +"This template will add the string which is stored in the iPAddress component " +"of the SAN." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:581 +msgid "Example: (ip={subject_ip_address})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:586 +msgid "{subject_x400_address}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:589 +msgid "" +"This template will add the value which is stored in the x400Address " +"component of the SAN as escaped hex sequence." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:594 +msgid "Example: (attr:binary={subject_x400_address})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:599 +msgid "{subject_directory_name[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:602 +msgid "" +"This template will add the DN string of the value which is stored in the " +"directoryName component of the SAN." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:606 +msgid "Example: (orig_dn={subject_directory_name})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:611 +msgid "{subject_ediparty_name}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:614 +msgid "" +"This template will add the value which is stored in the ediPartyName " +"component of the SAN as escaped hex sequence." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:619 +msgid "Example: (attr:binary={subject_ediparty_name})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:624 +msgid "{subject_registered_id}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:627 +msgid "" +"This template will add the OID which is stored in the registeredID component " +"of the SAN as a dotted-decimal string." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:632 +msgid "Example: (oid={subject_registered_id})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss-certmap.5.xml:417 +msgid "" +"The templates to add certificate data to the search filter are based on " +"Python-style formatting strings. They consist of a keyword in curly braces " +"with an optional sub-component specifier separated by a '.' or an optional " +"conversion/formatting option separated by a '!'. Allowed values are: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><title> +#: sss-certmap.5.xml:639 +msgid "LDAPU1 extension" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para> +#: sss-certmap.5.xml:641 +msgid "The following templates are available when using the 'LDAPU1' extension:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:647 +msgid "{serial_number[!(dec|hex[_ucr])]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:650 +msgid "" +"This template will add the serial number of the certificate. By default it " +"will be printed as a hexadecimal number with lower-case letters." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:655 +msgid "" +"With the formatting option '!dec' the number will be printed as decimal " +"string. The hexadecimal output can be printed with upper-case letters " +"('!hex_u'), with a colon separating the hexadecimal bytes ('!hex_c') or with " +"the hexadecimal bytes in reverse order ('!hex_r'). The postfix letters can " +"be combined so that e.g. '!hex_uc' will produce a colon-separated " +"hexadecimal string with upper-case letters." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:665 +msgid "Example: LDAPU1:(serial={serial_number})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:671 +msgid "{subject_key_id[!hex[_ucr]]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:674 +msgid "" +"This template will add the subject key id of the certificate. By default it " +"will be printed as a hexadecimal number with lower-case letters." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:679 +msgid "" +"The hexadecimal output can be printed with upper-case letters ('!hex_u'), " +"with a colon separating the hexadecimal bytes ('!hex_c') or with the " +"hexadecimal bytes in reverse order ('!hex_r'). The postfix letters can be " +"combined so that e.g. '!hex_uc' will produce a colon-separated hexadecimal " +"string with upper-case letters." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:688 +msgid "Example: LDAPU1:(ski={subject_key_id})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:694 +msgid "{cert[!DIGEST[_ucr]]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:697 +msgid "" +"This template will add the hexadecimal digest/hash of the certificate where " +"DIGEST must be replaced with the name of a digest/hash function supported by " +"OpenSSL, e.g. 'sha512'." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:703 +msgid "" +"The hexadecimal output can be printed with upper-case letters ('!sha512_u'), " +"with a colon separating the hexadecimal bytes ('!sha512_c') or with the " +"hexadecimal bytes in reverse order ('!sha512_r'). The postfix letters can be " +"combined so that e.g. '!sha512_uc' will produce a colon-separated " +"hexadecimal string with upper-case letters." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:712 +msgid "Example: LDAPU1:(dgst={cert!sha256})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:718 +msgid "{subject_dn_component[(.attr_name|[number]]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:721 +msgid "" +"This template will add an attribute value of a component of the subject DN, " +"by default the value of the most specific component." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:726 +msgid "" +"A different component can be selected by either attribute name, " +"e.g. {subject_dn_component.uid} or by position, " +"e.g. {subject_dn_component.[2]} where positive numbers start counting from " +"the most specific component and negative numbers start counting from the " +"least specific component. Attribute name and the position can be combined as " +"e.g. {subject_dn_component.uid[2]} which means that the name of the second " +"component must be 'uid'." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:737 +msgid "Example: LDAPU1:(uid={subject_dn_component.uid})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:743 +msgid "{issuer_dn_component[(.attr_name|[number]]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:746 +msgid "" +"This template will add an attribute value of a component of the issuer DN, " +"by default the value of the most specific component." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:751 +msgid "" +"See 'subject_dn_component' for details about the attribute name and position " +"specifiers." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:755 +msgid "" +"Example: " +"LDAPU1:(domain={issuer_dn_component.[-2]}.{issuer_dn_component.dc[-1]})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> +#: sss-certmap.5.xml:760 +msgid "{sid[.rid]}" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:763 +msgid "" +"This template will add the SID if the corresponding extension introduced by " +"Microsoft with the OID 1.3.6.1.4.1.311.25.2 is available. With the '.rid' " +"selector only the last component, i.e. the RID, will be added." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> +#: sss-certmap.5.xml:770 +msgid "Example: LDAPU1:(objectsid={sid})" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sss-certmap.5.xml:779 +msgid "DOMAIN LIST" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss-certmap.5.xml:781 +msgid "" +"If the domain list is not empty users mapped to a given certificate are not " +"only searched in the local domain but in the listed domains as well as long " +"as they are know by SSSD. Domains not know to SSSD will be ignored." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd-ipa.5.xml:10 sssd-ipa.5.xml:16 +msgid "sssd-ipa" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd-ipa.5.xml:17 +msgid "SSSD IPA provider" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ipa.5.xml:23 +msgid "" +"This manual page describes the configuration of the IPA provider for " +"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " +"</citerefentry>. For a detailed syntax reference, refer to the <quote>FILE " +"FORMAT</quote> section of the <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> manual page." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ipa.5.xml:36 +msgid "" +"The IPA provider is a back end used to connect to an IPA server. (Refer to " +"the freeipa.org web site for information about IPA servers.) This provider " +"requires that the machine be joined to the IPA domain; configuration is " +"almost entirely self-discovered and obtained directly from the server." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ipa.5.xml:43 +msgid "" +"The IPA provider enables SSSD to use the <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> identity provider and the <citerefentry> " +"<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> authentication provider with optimizations for IPA " +"environments. The IPA provider accepts the same options used by the " +"sssd-ldap and sssd-krb5 providers with some exceptions. However, it is " +"neither necessary nor recommended to set these options." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ipa.5.xml:57 +msgid "" +"The IPA provider primarily copies the traditional ldap and krb5 provider " +"default options with some exceptions, the differences are listed in the " +"<quote>MODIFIED DEFAULT OPTIONS</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ipa.5.xml:62 +msgid "" +"As an access provider, the IPA provider has a minimal configuration (see " +"<quote>ipa_access_order</quote>) as it mainly uses HBAC (host-based access " +"control) rules. Please refer to freeipa.org for more information about HBAC." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ipa.5.xml:68 +msgid "" +"If <quote>auth_provider=ipa</quote> or <quote>access_provider=ipa</quote> is " +"configured in sssd.conf then the id_provider must also be set to " +"<quote>ipa</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ipa.5.xml:74 +msgid "" +"The IPA provider will use the PAC responder if the Kerberos tickets of users " +"from trusted realms contain a PAC. To make configuration easier the PAC " +"responder is started automatically if the IPA ID provider is configured." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:90 +msgid "ipa_domain (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:93 +msgid "" +"Specifies the name of the IPA domain. This is optional. If not provided, " +"the configuration domain name is used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:101 +msgid "ipa_server, ipa_backup_server (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:104 +msgid "" +"The comma-separated list of IP addresses or hostnames of the IPA servers to " +"which SSSD should connect in the order of preference. For more information " +"on failover and server redundancy, see the <quote>FAILOVER</quote> section. " +"This is optional if autodiscovery is enabled. For more information on " +"service discovery, refer to the <quote>SERVICE DISCOVERY</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:117 +msgid "ipa_hostname (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:120 +msgid "" +"Optional. May be set on machines where the hostname(5) does not reflect the " +"fully qualified name used in the IPA domain to identify this host. The " +"hostname must be fully qualified." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:129 sssd-ad.5.xml:1161 +msgid "dyndns_update (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:132 +msgid "" +"Optional. This option tells SSSD to automatically update the DNS server " +"built into FreeIPA with the IP address of this client. The update is secured " +"using GSS-TSIG. The IP address of the IPA LDAP connection is used for the " +"updates, if it is not otherwise specified by using the " +"<quote>dyndns_iface</quote> option." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:141 sssd-ad.5.xml:1175 +msgid "" +"NOTE: On older systems (such as RHEL 5), for this behavior to work reliably, " +"the default Kerberos realm must be set properly in /etc/krb5.conf" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:152 sssd-ad.5.xml:1186 +msgid "dyndns_ttl (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:155 sssd-ad.5.xml:1189 +msgid "" +"The TTL to apply to the client DNS record when updating it. If " +"dyndns_update is false this has no effect. This will override the TTL " +"serverside if set by an administrator." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:160 +msgid "Default: 1200 (seconds)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:166 sssd-ad.5.xml:1200 +msgid "dyndns_iface (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:169 sssd-ad.5.xml:1203 +msgid "" +"Optional. Applicable only when dyndns_update is true. Choose the interface " +"or a list of interfaces whose IP addresses should be used for dynamic DNS " +"updates. The name of interface can be a wildcard pattern prefixed with " +"<emphasis>!</emphasis> for interface excluding. First match stops the " +"evaluation. For example list <emphasis>!eth1, *</emphasis> instruct SSSD to " +"use all interfaces except <emphasis>eth1</emphasis>. See <emphasis>man 7 " +"glob</emphasis> for details about patterns." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:182 +msgid "" +"Default: Use the IP addresses of the interface which is used for IPA LDAP " +"connection" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:186 sssd-ad.5.xml:1226 +msgid "Example: dyndns_iface = em[12], !vnet1, vnet*" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:192 sssd-ad.5.xml:1232 +msgid "dyndns_address (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:195 sssd-ad.5.xml:1235 +msgid "" +"Optional. Applicable only when <emphasis>dyndns_update</emphasis> is true. " +"A list of IP addresses or IP networks to be used for dynamic DNS " +"updates. Network addresses must be in CIDR format. An entry can be prefixed " +"with <emphasis>!</emphasis> to indicate exclusion. The <emphasis>best " +"match</emphasis> is used to determine whether an address is included or " +"excluded (i.e., a longer prefix takes precedence)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:206 sssd-ad.5.xml:1246 +msgid "Default: No filtering of IP addresses." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:209 sssd-ad.5.xml:1249 +msgid "Example: dyndns_address = 10.0.0.0/16, !10.0.1.0/24" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:215 sssd-ad.5.xml:1305 +msgid "dyndns_auth (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:218 sssd-ad.5.xml:1308 +msgid "" +"Whether the nsupdate utility should use GSS-TSIG authentication for secure " +"updates with the DNS server, insecure updates can be sent by setting this " +"option to 'none'." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:224 sssd-ad.5.xml:1314 +msgid "Default: GSS-TSIG" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:230 sssd-ad.5.xml:1320 +msgid "dyndns_auth_ptr (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:233 sssd-ad.5.xml:1323 +msgid "" +"Whether the nsupdate utility should use GSS-TSIG authentication for secure " +"PTR updates with the DNS server, insecure updates can be sent by setting " +"this option to 'none'." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:239 sssd-ad.5.xml:1329 +msgid "Default: Same as dyndns_auth" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:245 sssd-ad.5.xml:1255 +msgid "dyndns_refresh_interval (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:248 +msgid "" +"How often should the back end perform periodic DNS update in addition to the " +"automatic update performed when the back end goes online. This option is " +"optional and applicable only when dyndns_update is true." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:261 sssd-ad.5.xml:1273 +msgid "dyndns_update_ptr (bool)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:264 sssd-ad.5.xml:1276 +msgid "" +"Whether the PTR record should also be explicitly updated when updating the " +"client's DNS records. Applicable only when dyndns_update is true." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:269 +msgid "" +"This option should be False in most IPA deployments as the IPA server " +"generates the PTR records automatically when forward records are changed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:275 sssd-ad.5.xml:1281 +msgid "" +"Note that <emphasis>dyndns_update_per_family</emphasis> parameter does not " +"apply for PTR record updates. Those updates are always sent separately." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:280 +msgid "Default: False (disabled)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:286 sssd-ad.5.xml:1292 +msgid "dyndns_force_tcp (bool)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:289 sssd-ad.5.xml:1295 +msgid "" +"Whether the nsupdate utility should default to using TCP for communicating " +"with the DNS server." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:293 sssd-ad.5.xml:1299 +msgid "Default: False (let nsupdate choose the protocol)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:299 sssd-ad.5.xml:1335 +msgid "dyndns_server (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:302 sssd-ad.5.xml:1338 +msgid "" +"The DNS server to use when performing a DNS update. In most setups, it's " +"recommended to leave this option unset." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:307 sssd-ad.5.xml:1343 +msgid "" +"Setting this option makes sense for environments where the DNS server is " +"different from the identity server or when we use encrypted DNS." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:312 sssd-ad.5.xml:1348 +msgid "" +"The parameter can be a simple string containing DNS name or IP address. It " +"can also be an URI. The URI can look like " +"<emphasis>dns://servername/</emphasis> or " +"<emphasis>dns+tls://1.2.3.4:853#servername/</emphasis>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:319 sssd-ad.5.xml:1355 +msgid "" +"The second example enables DNS-over-TLS protocol for DNS updates. The " +"nsupdate utility must support DoT - check the <emphasis>man " +"nsupdate</emphasis> before enabling it in SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:325 sssd-ad.5.xml:1361 +msgid "" +"Please note that this option will be only used in fallback attempt when " +"previous attempt using autodetected settings failed or when DNS-over-TLS is " +"enabled." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:331 sssd-ad.5.xml:1367 +msgid "Default: None (let nsupdate choose the server)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:337 sssd-ad.5.xml:1373 +msgid "dyndns_update_per_family (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:340 sssd-ad.5.xml:1376 +msgid "" +"DNS update is by default performed in two steps - IPv4 update and then IPv6 " +"update. In some cases it might be desirable to perform IPv4 and IPv6 update " +"in single step." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:352 sssd-ad.5.xml:1388 +msgid "dyndns_dot_cacert (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:355 sssd-ad.5.xml:1391 +msgid "" +"This option specifies the file of the certificate authorities certificates " +"(in PEM format) in order to verify the remote server TLS certificate when " +"using DoT." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:361 sssd-ad.5.xml:1397 +msgid "Default: None (use global certificate store)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:367 sssd-ad.5.xml:1403 +msgid "dyndns_dot_cert (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:370 sssd-ad.5.xml:1406 +msgid "" +"This option sets the certificate(s) file for authentication for the DoT " +"transport to the remote server. The certificate chain file is expected to be " +"in PEM format." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:376 sssd-ad.5.xml:1412 +msgid "" +"The <emphasis>dyndns_dot_cert</emphasis> and " +"<emphasis>dyndns_dot_key</emphasis> options must be both set to achieve " +"mutual TLS authentication." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:381 sssd-ipa.5.xml:396 sssd-ad.5.xml:1417 sssd-ad.5.xml:1432 +msgid "Default: None (Do not use TLS authentication)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:387 sssd-ad.5.xml:1423 +msgid "dyndns_dot_key (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:390 sssd-ad.5.xml:1426 +msgid "" +"This option sets the key file for authenticated encryption for the DoT " +"transport to the remote server. The private key file is expected to be in " +"PEM format." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:402 +msgid "ipa_access_order (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:409 +msgid "<emphasis>expire</emphasis>: use IPA's account expiration policy." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:448 +msgid "" +"Please note that 'access_provider = ipa' must be set for this feature to " +"work." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:455 +msgid "ipa_deskprofile_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:458 +msgid "" +"Optional. Use the given string as search base for Desktop Profile related " +"objects." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:462 sssd-ipa.5.xml:484 +msgid "Default: Use base DN" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:468 +msgid "ipa_subid_ranges_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:471 +msgid "Deprecated. Use ldap_subid_ranges_search_base instead." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:477 +msgid "ipa_hbac_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:480 +msgid "Optional. Use the given string as search base for HBAC related objects." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:490 +msgid "ipa_host_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:493 +msgid "Deprecated. Use ldap_host_search_base instead." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:499 +msgid "ipa_selinux_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:502 +msgid "Optional. Use the given string as search base for SELinux user maps." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:518 +msgid "ipa_subdomains_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:521 +msgid "Optional. Use the given string as search base for trusted domains." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:530 +msgid "Default: the value of <emphasis>cn=trusts,%basedn</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:537 +msgid "ipa_master_domain_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:540 +msgid "Optional. Use the given string as search base for master domain object." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:549 +msgid "Default: the value of <emphasis>cn=ad,cn=etc,%basedn</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:556 +msgid "ipa_views_search_base (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:559 +msgid "Optional. Use the given string as search base for views containers." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:568 +msgid "Default: the value of <emphasis>cn=views,cn=accounts,%basedn</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:578 +msgid "" +"The name of the Kerberos realm. This is optional and defaults to the value " +"of <quote>ipa_domain</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:582 +msgid "" +"The name of the Kerberos realm has a special meaning in IPA - it is " +"converted into the base DN to use for performing LDAP operations." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:590 sssd-ad.5.xml:1441 +msgid "krb5_confd_path (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:593 sssd-ad.5.xml:1444 +msgid "" +"Absolute path of a directory where SSSD should place Kerberos configuration " +"snippets." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:597 sssd-ad.5.xml:1448 +msgid "" +"To disable the creation of the configuration snippets set the parameter to " +"'none'." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:601 sssd-ad.5.xml:1452 +msgid "Default: not set (krb5.include.d subdirectory of SSSD's pubconf directory)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:608 +msgid "ipa_deskprofile_refresh (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:611 +msgid "" +"The amount of time between lookups of the Desktop Profile rules against the " +"IPA server. This will reduce the latency and load on the IPA server if there " +"are many desktop profiles requests made in a short period." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:618 sssd-ipa.5.xml:648 sssd-ipa.5.xml:664 sssd-ad.5.xml:600 +msgid "Default: 5 (seconds)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:624 +msgid "ipa_deskprofile_request_interval (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:627 +msgid "" +"The amount of time between lookups of the Desktop Profile rules against the " +"IPA server in case the last request did not return any rule." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:632 +msgid "Default: 60 (minutes)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:638 +msgid "ipa_hbac_refresh (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:641 +msgid "" +"The amount of time between lookups of the HBAC rules against the IPA " +"server. This will reduce the latency and load on the IPA server if there are " +"many access-control requests made in a short period." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:654 +msgid "ipa_hbac_selinux (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:657 +msgid "" +"The amount of time between lookups of the SELinux maps against the IPA " +"server. This will reduce the latency and load on the IPA server if there are " +"many user login requests made in a short period." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:670 +msgid "ipa_server_mode (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:673 +msgid "" +"This option will be set by the IPA installer (ipa-server-install) " +"automatically and denotes if SSSD is running on an IPA server or not." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:678 +msgid "" +"On an IPA server SSSD will lookup users and groups from trusted domains " +"directly while on a client it will ask an IPA server." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:683 +msgid "" +"NOTE: There are currently some assumptions that must be met when SSSD is " +"running on an IPA server." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:688 +msgid "" +"The <quote>ipa_server</quote> option must be configured to point to the IPA " +"server itself. This is already the default set by the IPA installer, so no " +"manual change is required." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:697 +msgid "" +"The <quote>full_name_format</quote> option must not be tweaked to only print " +"short names for users from trusted domains." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:712 +msgid "ipa_automount_location (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:715 +msgid "The automounter location this IPA client will be using" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:718 +msgid "Default: The location named \"default\"" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd-ipa.5.xml:726 +msgid "VIEWS AND OVERRIDES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:735 +msgid "ipa_view_class (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:738 +msgid "Objectclass of the view container." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:741 +msgid "Default: nsContainer" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:747 +msgid "ipa_view_name (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:750 +msgid "Name of the attribute holding the name of the view." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:754 sssd-ldap-attributes.5.xml:496 +#: sssd-ldap-attributes.5.xml:832 sssd-ldap-attributes.5.xml:913 +#: sssd-ldap-attributes.5.xml:1010 sssd-ldap-attributes.5.xml:1068 +#: sssd-ldap-attributes.5.xml:1226 sssd-ldap-attributes.5.xml:1271 +msgid "Default: cn" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:760 +msgid "ipa_override_object_class (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:763 +msgid "Objectclass of the override objects." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:766 +msgid "Default: ipaOverrideAnchor" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:772 +msgid "ipa_anchor_uuid (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:775 +msgid "" +"Name of the attribute containing the reference to the original object in a " +"remote domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:779 +msgid "Default: ipaAnchorUUID" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:785 +msgid "ipa_user_override_object_class (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:788 +msgid "" +"Name of the objectclass for user overrides. It is used to determine if the " +"found override object is related to a user or a group." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:793 +msgid "User overrides can contain attributes given by" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:796 +msgid "ldap_user_name" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:799 +msgid "ldap_user_uid_number" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:802 +msgid "ldap_user_gid_number" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:805 +msgid "ldap_user_gecos" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:808 +msgid "ldap_user_home_directory" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:811 +msgid "ldap_user_shell" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:814 +msgid "ldap_user_ssh_public_key" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:819 +msgid "Default: ipaUserOverride" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-ipa.5.xml:825 +msgid "ipa_group_override_object_class (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:828 +msgid "" +"Name of the objectclass for group overrides. It is used to determine if the " +"found override object is related to a user or a group." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:833 +msgid "Group overrides can contain attributes given by" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:836 +msgid "ldap_group_name" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:839 +msgid "ldap_group_gid_number" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-ipa.5.xml:844 +msgid "Default: ipaGroupOverride" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd-ipa.5.xml:728 +msgid "" +"SSSD can handle views and overrides which are offered by FreeIPA 4.1 and " +"later version. Since all paths and objectclasses are fixed on the server " +"side there is basically no need to configure anything. For completeness the " +"related options are listed here with their default values. <placeholder " +"type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ipa.5.xml:856 +msgid "SUBDOMAINS PROVIDER" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ipa.5.xml:858 +msgid "" +"The IPA subdomains provider behaves slightly differently if it is configured " +"explicitly or implicitly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ipa.5.xml:862 +msgid "" +"If the option 'subdomains_provider = ipa' is found in the domain section of " +"sssd.conf, the IPA subdomains provider is configured explicitly, and all " +"subdomain requests are sent to the IPA server if necessary." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ipa.5.xml:868 +msgid "" +"If the option 'subdomains_provider' is not set in the domain section of " +"sssd.conf but there is the option 'id_provider = ipa', the IPA subdomains " +"provider is configured implicitly. In this case, if a subdomain request " +"fails and indicates that the server does not support subdomains, i.e. is not " +"configured for trusts, the IPA subdomains provider is disabled. After an " +"hour or after the IPA provider goes online, the subdomains provider is " +"enabled again." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ipa.5.xml:879 +msgid "TRUSTED DOMAINS CONFIGURATION" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-ipa.5.xml:887 +#, no-wrap +msgid "" +"[domain/ipa.domain.com/ad.domain.com]\n" +"ad_server = dc.ad.domain.com\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ipa.5.xml:881 +msgid "" +"Some configuration options can also be set for a trusted domain. A trusted " +"domain configuration can be set using the trusted domain subsection as shown " +"in the example below. Alternatively, the <quote>subdomain_inherit</quote> " +"option can be used in the parent domain. <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ipa.5.xml:892 +msgid "" +"For more details, see the <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> manual page." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ipa.5.xml:899 +msgid "" +"Different configuration options are tunable for a trusted domain depending " +"on whether you are configuring SSSD on an IPA server or an IPA client." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd-ipa.5.xml:904 +msgid "OPTIONS TUNABLE ON IPA MASTERS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd-ipa.5.xml:906 +msgid "The following options can be set in a subdomain section on an IPA master:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:910 sssd-ipa.5.xml:950 +msgid "ad_server" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:913 +msgid "ad_backup_server" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:916 sssd-ipa.5.xml:953 +msgid "ad_site" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:919 +msgid "ipa_server" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:922 +msgid "ipa_backup_server" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:925 +msgid "ldap_search_base" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:928 +msgid "ldap_user_search_base" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd-ipa.5.xml:931 +msgid "ldap_group_search_base" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd-ipa.5.xml:939 +msgid "" +"Options prefixed with 'ad_' or 'ipa_' only apply to their respective " +"subdomain type." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd-ipa.5.xml:944 +msgid "OPTIONS TUNABLE ON IPA CLIENTS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd-ipa.5.xml:946 +msgid "" +"The following options can be set in an AD subdomain section on an IPA " +"client:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd-ipa.5.xml:958 +msgid "" +"Note that if both options are set, only <quote>ad_server</quote> is " +"evaluated." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd-ipa.5.xml:962 +msgid "" +"Since any request for a user or a group identity from a trusted domain " +"triggered from an IPA client is resolved by the IPA server, the " +"<quote>ad_server</quote> and <quote>ad_site</quote> options only affect " +"which AD DC will the authentication be performed against. In particular, the " +"addresses resolved from these lists will be written to " +"<quote>kdcinfo</quote> files read by the Kerberos locator plugin. Please " +"refer to the <citerefentry> " +"<refentrytitle>sssd_krb5_locator_plugin</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> manual page for more details on the " +"Kerberos locator plugin." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ipa.5.xml:986 +msgid "" +"The following example assumes that SSSD is correctly configured and " +"example.com is one of the domains in the <replaceable>[sssd]</replaceable> " +"section. This examples shows only the ipa provider-specific options." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-ipa.5.xml:993 +#, no-wrap +msgid "" +"[domain/example.com]\n" +"id_provider = ipa\n" +"ipa_server = ipaserver.example.com\n" +"ipa_hostname = myhost.example.com\n" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd-ad.5.xml:10 sssd-ad.5.xml:16 +msgid "sssd-ad" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd-ad.5.xml:17 +msgid "SSSD Active Directory provider" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:23 +msgid "" +"This manual page describes the configuration of the AD provider for " +"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " +"</citerefentry>. For a detailed syntax reference, refer to the <quote>FILE " +"FORMAT</quote> section of the <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> manual page." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:36 +msgid "" +"The AD provider is a back end used to connect to an Active Directory " +"server. This provider requires that the machine be joined to the AD domain " +"and a keytab is available. Back end communication occurs over a " +"GSSAPI-encrypted channel, SSL/TLS options should not be used with the AD " +"provider and will be superseded by Kerberos usage." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:44 +msgid "" +"The AD provider supports connecting to Active Directory 2008 R2 or " +"later. Earlier versions may work, but are unsupported." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:48 +msgid "" +"The AD provider can be used to get user information and authenticate users " +"from trusted domains. Currently only trusted domains in the same forest are " +"recognized. In addition servers from trusted domains are always " +"auto-discovered." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:54 +msgid "" +"The AD provider enables SSSD to use the <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> identity provider and the <citerefentry> " +"<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> authentication provider with optimizations for Active " +"Directory environments. The AD provider accepts the same options used by the " +"sssd-ldap and sssd-krb5 providers with some exceptions. However, it is " +"neither necessary nor recommended to set these options." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:69 +msgid "" +"The AD provider primarily copies the traditional ldap and krb5 provider " +"default options with some exceptions, the differences are listed in the " +"<quote>MODIFIED DEFAULT OPTIONS</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:74 +msgid "" +"The AD provider can also be used as an access, chpass, sudo and autofs " +"provider. No configuration of the access provider is required on the client " +"side." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:79 +msgid "" +"If <quote>auth_provider=ad</quote> or <quote>access_provider=ad</quote> is " +"configured in sssd.conf then the id_provider must also be set to " +"<quote>ad</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-ad.5.xml:91 +#, no-wrap +msgid "" +"ldap_id_mapping = False\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:85 +msgid "" +"By default, the AD provider will map UID and GID values from the objectSID " +"parameter in Active Directory. For details on this, see the <quote>ID " +"MAPPING</quote> section below. If you want to disable ID mapping and instead " +"rely on POSIX attributes defined in Active Directory, you should set " +"<placeholder type=\"programlisting\" id=\"0\"/> If POSIX attributes should " +"be used, it is recommended for performance reasons that the attributes are " +"also replicated to the Global Catalog. If POSIX attributes are replicated, " +"SSSD will attempt to locate the domain of a requested numerical ID with the " +"help of the Global Catalog and only search that domain. In contrast, if " +"POSIX attributes are not replicated to the Global Catalog, SSSD must search " +"all the domains in the forest sequentially. Please note that the " +"<quote>cache_first</quote> option might be also helpful in speeding up " +"domainless searches. Note that if only a subset of POSIX attributes is " +"present in the Global Catalog, the non-replicated attributes are currently " +"not read from the LDAP port." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:108 +msgid "" +"Users, groups and other entities served by SSSD are always treated as " +"case-insensitive in the AD provider for compatibility with Active " +"Directory's LDAP implementation." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:113 +msgid "" +"SSSD only resolves Active Directory Security Groups. For more information " +"about AD group types see: <ulink " +"url=\"https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/understand-security-groups\"> " +"Active Directory security groups</ulink>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:120 +msgid "" +"SSSD filters out Domain Local groups from remote domains in the AD " +"forest. By default they are filtered out e.g. when following a nested group " +"hierarchy in remote domains because they are not valid in the local " +"domain. This is done to be in agreement with Active Directory's " +"group-membership assignment which can be seen in the PAC of the Kerberos " +"ticket of a user issued by Active Directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:138 +msgid "ad_domain (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:141 +msgid "" +"Specifies the name of the Active Directory domain. This is optional. If not " +"provided, the configuration domain name is used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:146 +msgid "" +"For proper operation, this option should be specified as the lower-case " +"version of the long version of the Active Directory domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:151 +msgid "" +"The short domain name (also known as the NetBIOS or the flat name) is " +"autodetected by the SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:158 +msgid "ad_enabled_domains (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:161 +msgid "" +"A comma-separated list of enabled Active Directory domains. If provided, " +"SSSD will ignore any domains not listed in this option. If left unset, all " +"discovered domains from the AD forest will be available." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:168 +msgid "" +"During the discovery of the domains SSSD will filter out some domains where " +"flags or attributes indicate that they do not belong to the local forest or " +"are not trusted. If ad_enabled_domains is set, SSSD will try to enable all " +"listed domains." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> +#: sssd-ad.5.xml:179 +#, no-wrap +msgid "" +"ad_enabled_domains = sales.example.com, eng.example.com\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:175 +msgid "" +"For proper operation, this option must be specified in all lower-case and as " +"the fully qualified domain name of the Active Directory domain. For example: " +"<placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:183 +msgid "" +"The short domain name (also known as the NetBIOS or the flat name) will be " +"autodetected by SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:193 +msgid "ad_server, ad_backup_server (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:196 +msgid "" +"The comma-separated list of hostnames of the AD servers to which SSSD should " +"connect in order of preference. For more information on failover and server " +"redundancy, see the <quote>FAILOVER</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:203 +msgid "" +"This is optional if autodiscovery is enabled. For more information on " +"service discovery, refer to the <quote>SERVICE DISCOVERY</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:208 +msgid "" +"Note: Trusted domains will always auto-discover servers even if the primary " +"server is explicitly defined in the ad_server option." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:216 +msgid "ad_hostname (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:219 +msgid "" +"Optional. On machines where the hostname(5) does not reflect the fully " +"qualified name, sssd will try to expand the short name. If it is not " +"possible or the short name should be really used instead, set this parameter " +"explicitly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:226 +msgid "" +"This field is used to determine the host principal in use in the keytab and " +"to perform dynamic DNS updates. It must match the hostname for which the " +"keytab was issued." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:235 +msgid "ad_enable_dns_sites (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:238 +msgid "Enables DNS sites - location based service discovery." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:242 +msgid "" +"If true and service discovery (see Service Discovery paragraph at the bottom " +"of the man page) is enabled, the SSSD will first attempt to discover the " +"Active Directory server to connect to using the Active Directory Site " +"Discovery and fall back to the DNS SRV records if no AD site is found. The " +"DNS SRV configuration, including the discovery domain, is used during site " +"discovery as well." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:258 +msgid "ad_access_filter (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:261 +msgid "" +"Specifies an LDAP access control filter that a user must match to gain " +"access. The <quote>access_provider</quote> option must be explicitly set to " +"<quote>ad</quote> for this option to take effect. If you want to use the " +"<quote>ad_access_filter</quote> as the only access control scheme, you must " +"disable GPO based access control (see option " +"<quote>ad_gpo_access_control</quote> for details)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:270 +msgid "" +"The option also supports specifying different filters per domain or " +"forest. This extended filter would consist of: " +"<quote>KEYWORD:NAME:FILTER</quote>. The keyword can be either " +"<quote>DOM</quote>, <quote>FOREST</quote> or missing." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:278 +msgid "" +"If the keyword equals to <quote>DOM</quote> or is missing, then " +"<quote>NAME</quote> specifies the domain or subdomain the filter applies " +"to. If the keyword equals to <quote>FOREST</quote>, then the filter equals " +"to all domains from the forest specified by <quote>NAME</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:286 +msgid "" +"Multiple filters can be separated with the <quote>?</quote> character, " +"similarly to how search bases work." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:291 +msgid "" +"Nested group membership must be searched for using a special OID " +"<quote>:1.2.840.113556.1.4.1941:</quote> in addition to the full " +"DOM:domain.example.org: syntax to ensure the parser does not attempt to " +"interpret the colon characters associated with the OID. If you do not use " +"this OID then nested group membership will not be resolved. See usage " +"example below and refer here for further information about the OID: <ulink " +"url=\"https://msdn.microsoft.com/en-us/library/cc223367.aspx\"> [MS-ADTS] " +"section LDAP extensions</ulink>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:304 +msgid "" +"The most specific match is always used. For example, if the option specified " +"filter for a domain the user is a member of and a global filter, the " +"per-domain filter would be applied. If there are more matches with the same " +"specification, the first one is used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><programlisting> +#: sssd-ad.5.xml:315 +#, no-wrap +msgid "" +"# apply filter on domain called dom1 only:\n" +"dom1:(memberOf=cn=admins,ou=groups,dc=dom1,dc=com)\n" +"\n" +"# apply filter on domain called dom2 only:\n" +"DOM:dom2:(memberOf=cn=admins,ou=groups,dc=dom2,dc=com)\n" +"\n" +"# apply filter on forest called EXAMPLE.COM only:\n" +"FOREST:EXAMPLE.COM:(memberOf=cn=admins,ou=groups,dc=example,dc=com)\n" +"\n" +"# apply filter for a member of a nested group in dom1:\n" +"DOM:dom1:(memberOf:1.2.840.113556.1.4.1941:=cn=nestedgroup,ou=groups,dc=example,dc=com)\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:334 +msgid "ad_site (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:337 +msgid "" +"Specify AD site to which client should try to connect. If this option is " +"not provided, the AD site will be auto-discovered." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:348 +msgid "ad_enable_gc (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:351 +msgid "" +"By default, the SSSD connects to the Global Catalog first to retrieve users " +"from trusted domains and uses the LDAP port to retrieve group memberships or " +"as a fallback. Disabling this option makes the SSSD only connect to the LDAP " +"port of the current AD server." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:359 +msgid "" +"Please note that disabling Global Catalog support does not disable " +"retrieving users from trusted domains. The SSSD would connect to the LDAP " +"port of trusted domains instead. However, Global Catalog must be used in " +"order to resolve cross-domain group memberships." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:373 +msgid "ad_gpo_access_control (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:376 +msgid "" +"This option specifies the operation mode for GPO-based access control " +"functionality: whether it operates in disabled mode, enforcing mode, or " +"permissive mode. Please note that the <quote>access_provider</quote> option " +"must be explicitly set to <quote>ad</quote> in order for this option to have " +"an effect." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:385 +msgid "" +"GPO-based access control functionality uses GPO policy settings to determine " +"whether or not a particular user is allowed to logon to the host. For more " +"information on the supported policy settings please refer to the " +"<quote>ad_gpo_map</quote> options." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:393 +msgid "" +"Please note that current version of SSSD does not support Active Directory's " +"built-in groups. Built-in groups (such as Administrators with SID " +"S-1-5-32-544) in GPO access control rules will be ignored by SSSD. See " +"upstream issue tracker https://github.com/SSSD/sssd/issues/5063 ." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:402 +msgid "" +"Before performing access control SSSD applies group policy security " +"filtering on the GPOs. For every single user login, the applicability of the " +"GPOs that are linked to the host is checked. In order for a GPO to apply to " +"a user, the user or at least one of the groups to which it belongs must have " +"following permissions on the GPO:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:412 +msgid "" +"Read: The user or one of its groups must have read access to the properties " +"of the GPO (RIGHT_DS_READ_PROPERTY)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:419 +msgid "" +"Apply Group Policy: The user or at least one of its groups must be allowed " +"to apply the GPO (RIGHT_DS_CONTROL_ACCESS)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:427 +msgid "" +"By default, the Authenticated Users group is present on a GPO and this group " +"has both Read and Apply Group Policy access rights. Since authentication of " +"a user must have been completed successfully before GPO security filtering " +"and access control are started, the Authenticated Users group permissions on " +"the GPO always apply also to the user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:436 +msgid "" +"NOTE: If the operation mode is set to enforcing, it is possible that users " +"that were previously allowed logon access will now be denied logon access " +"(as dictated by the GPO policy settings). In order to facilitate a smooth " +"transition for administrators, a permissive mode is available that will not " +"enforce the access control rules, but will evaluate them and will output a " +"syslog message if access would have been denied. By examining the logs, " +"administrators can then make the necessary changes before setting the mode " +"to enforcing. For logging GPO-based access control debug level 'trace " +"functions' is required (see <citerefentry> " +"<refentrytitle>sssctl</refentrytitle> <manvolnum>8</manvolnum> " +"</citerefentry> manual page)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:455 +msgid "There are three supported values for this option:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:459 +msgid "disabled: GPO-based access control rules are neither evaluated nor enforced." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:465 +msgid "enforcing: GPO-based access control rules are evaluated and enforced." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:471 +msgid "" +"permissive: GPO-based access control rules are evaluated, but not enforced. " +"Instead, a syslog message will be emitted indicating that the user would " +"have been denied access if this option's value were set to enforcing." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:482 +msgid "Default: permissive" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:485 +msgid "Default: enforcing" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:491 +msgid "ad_gpo_implicit_deny (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:494 +msgid "" +"Normally when no applicable GPOs are found the users are allowed " +"access. When this option is set to True users will be allowed access only " +"when explicitly allowed by a GPO rule. Otherwise users will be denied " +"access. This can be used to harden security but be careful when using this " +"option because it can deny access even to users in the built-in " +"Administrators group if no GPO rules apply to them." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:510 +msgid "" +"The following 2 tables should illustrate when a user is allowed or rejected " +"based on the allow and deny login rights defined on the server-side and the " +"setting of ad_gpo_implicit_deny." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> +#: sssd-ad.5.xml:522 +msgid "ad_gpo_implicit_deny = False (default)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> +#: sssd-ad.5.xml:523 sssd-ad.5.xml:549 +msgid "allow-rules" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> +#: sssd-ad.5.xml:523 sssd-ad.5.xml:549 +msgid "deny-rules" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> +#: sssd-ad.5.xml:524 sssd-ad.5.xml:550 +msgid "results" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> +#: sssd-ad.5.xml:527 sssd-ad.5.xml:530 sssd-ad.5.xml:533 sssd-ad.5.xml:553 +#: sssd-ad.5.xml:556 sssd-ad.5.xml:559 +msgid "missing" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd-ad.5.xml:528 +msgid "all users are allowed" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> +#: sssd-ad.5.xml:530 sssd-ad.5.xml:533 sssd-ad.5.xml:536 sssd-ad.5.xml:556 +#: sssd-ad.5.xml:559 sssd-ad.5.xml:562 +msgid "present" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd-ad.5.xml:531 +msgid "only users not in deny-rules are allowed" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd-ad.5.xml:534 sssd-ad.5.xml:560 +msgid "only users in allow-rules are allowed" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd-ad.5.xml:537 sssd-ad.5.xml:563 +msgid "only users in allow-rules and not in deny-rules are allowed" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> +#: sssd-ad.5.xml:548 +msgid "ad_gpo_implicit_deny = True" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> +#: sssd-ad.5.xml:554 sssd-ad.5.xml:557 +msgid "no users are allowed" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:570 +msgid "ad_gpo_ignore_unreadable (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:573 +msgid "" +"Normally when some group policy containers (AD object) of applicable group " +"policy objects are not readable by SSSD then users are denied access. This " +"option allows to ignore group policy containers and with them associated " +"policies if their attributes in group policy containers are not readable for " +"SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:590 +msgid "ad_gpo_cache_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:593 +msgid "" +"The amount of time between lookups of GPO policy files against the AD " +"server. This will reduce the latency and load on the AD server if there are " +"many access-control requests made in a short period." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:606 +msgid "ad_gpo_map_interactive (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:609 +msgid "" +"A comma-separated list of PAM service names for which GPO-based access " +"control is evaluated based on the InteractiveLogonRight and " +"DenyInteractiveLogonRight policy settings. Only those GPOs are evaluated " +"for which the user has Read and Apply Group Policy permission (see option " +"<quote>ad_gpo_access_control</quote>). If an evaluated GPO contains the " +"deny interactive logon setting for the user or one of its groups, the user " +"is denied local access. If none of the evaluated GPOs has an interactive " +"logon right defined, the user is granted local access. If at least one " +"evaluated GPO contains interactive logon right settings, the user is granted " +"local access only, if it or at least one of its groups is part of the policy " +"settings." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:627 +msgid "" +"Note: Using the Group Policy Management Editor this value is called \"Allow " +"log on locally\" and \"Deny log on locally\"." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> +#: sssd-ad.5.xml:641 +#, no-wrap +msgid "" +"ad_gpo_map_interactive = +my_pam_service, -login\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:632 +msgid "" +"It is possible to add another PAM service name to the default set by using " +"<quote>+service_name</quote> or to explicitly remove a PAM service name from " +"the default set by using <quote>-service_name</quote>. For example, in " +"order to replace a default PAM service name for this logon right " +"(e.g. <quote>login</quote>) with a custom pam service name " +"(e.g. <quote>my_pam_service</quote>), you would use the following " +"configuration: <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:664 +msgid "gdm-fingerprint" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:684 +msgid "lightdm" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:689 +msgid "lxdm" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:694 +msgid "sddm" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:699 +msgid "unity" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:704 +msgid "xdm" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:713 +msgid "ad_gpo_map_remote_interactive (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:716 +msgid "" +"A comma-separated list of PAM service names for which GPO-based access " +"control is evaluated based on the RemoteInteractiveLogonRight and " +"DenyRemoteInteractiveLogonRight policy settings. Only those GPOs are " +"evaluated for which the user has Read and Apply Group Policy permission (see " +"option <quote>ad_gpo_access_control</quote>). If an evaluated GPO contains " +"the deny remote logon setting for the user or one of its groups, the user is " +"denied remote interactive access. If none of the evaluated GPOs has a " +"remote interactive logon right defined, the user is granted remote " +"access. If at least one evaluated GPO contains remote interactive logon " +"right settings, the user is granted remote access only, if it or at least " +"one of its groups is part of the policy settings." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:735 +msgid "" +"Note: Using the Group Policy Management Editor this value is called \"Allow " +"log on through Remote Desktop Services\" and \"Deny log on through Remote " +"Desktop Services\"." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> +#: sssd-ad.5.xml:750 +#, no-wrap +msgid "" +"ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:741 +msgid "" +"It is possible to add another PAM service name to the default set by using " +"<quote>+service_name</quote> or to explicitly remove a PAM service name from " +"the default set by using <quote>-service_name</quote>. For example, in " +"order to replace a default PAM service name for this logon right " +"(e.g. <quote>sshd</quote>) with a custom pam service name " +"(e.g. <quote>my_pam_service</quote>), you would use the following " +"configuration: <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:758 +msgid "sshd" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:763 +msgid "cockpit" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:772 +msgid "ad_gpo_map_network (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:775 +msgid "" +"A comma-separated list of PAM service names for which GPO-based access " +"control is evaluated based on the NetworkLogonRight and " +"DenyNetworkLogonRight policy settings. Only those GPOs are evaluated for " +"which the user has Read and Apply Group Policy permission (see option " +"<quote>ad_gpo_access_control</quote>). If an evaluated GPO contains the " +"deny network logon setting for the user or one of its groups, the user is " +"denied network logon access. If none of the evaluated GPOs has a network " +"logon right defined, the user is granted logon access. If at least one " +"evaluated GPO contains network logon right settings, the user is granted " +"logon access only, if it or at least one of its groups is part of the policy " +"settings." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:793 +msgid "" +"Note: Using the Group Policy Management Editor this value is called \"Access " +"this computer from the network\" and \"Deny access to this computer from the " +"network\"." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> +#: sssd-ad.5.xml:808 +#, no-wrap +msgid "" +"ad_gpo_map_network = +my_pam_service, -ftp\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:799 +msgid "" +"It is possible to add another PAM service name to the default set by using " +"<quote>+service_name</quote> or to explicitly remove a PAM service name from " +"the default set by using <quote>-service_name</quote>. For example, in " +"order to replace a default PAM service name for this logon right " +"(e.g. <quote>ftp</quote>) with a custom pam service name " +"(e.g. <quote>my_pam_service</quote>), you would use the following " +"configuration: <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:816 +msgid "ftp" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:821 +msgid "samba" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:830 +msgid "ad_gpo_map_batch (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:833 +msgid "" +"A comma-separated list of PAM service names for which GPO-based access " +"control is evaluated based on the BatchLogonRight and DenyBatchLogonRight " +"policy settings. Only those GPOs are evaluated for which the user has Read " +"and Apply Group Policy permission (see option " +"<quote>ad_gpo_access_control</quote>). If an evaluated GPO contains the " +"deny batch logon setting for the user or one of its groups, the user is " +"denied batch logon access. If none of the evaluated GPOs has a batch logon " +"right defined, the user is granted logon access. If at least one evaluated " +"GPO contains batch logon right settings, the user is granted logon access " +"only, if it or at least one of its groups is part of the policy settings." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:851 +msgid "" +"Note: Using the Group Policy Management Editor this value is called \"Allow " +"log on as a batch job\" and \"Deny log on as a batch job\"." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> +#: sssd-ad.5.xml:865 +#, no-wrap +msgid "" +"ad_gpo_map_batch = +my_pam_service, -crond\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:856 +msgid "" +"It is possible to add another PAM service name to the default set by using " +"<quote>+service_name</quote> or to explicitly remove a PAM service name from " +"the default set by using <quote>-service_name</quote>. For example, in " +"order to replace a default PAM service name for this logon right " +"(e.g. <quote>crond</quote>) with a custom pam service name " +"(e.g. <quote>my_pam_service</quote>), you would use the following " +"configuration: <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:868 +msgid "Note: Cron service name may differ depending on Linux distribution used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:874 +msgid "crond" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:883 +msgid "ad_gpo_map_service (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:886 +msgid "" +"A comma-separated list of PAM service names for which GPO-based access " +"control is evaluated based on the ServiceLogonRight and " +"DenyServiceLogonRight policy settings. Only those GPOs are evaluated for " +"which the user has Read and Apply Group Policy permission (see option " +"<quote>ad_gpo_access_control</quote>). If an evaluated GPO contains the " +"deny service logon setting for the user or one of its groups, the user is " +"denied service logon access. If none of the evaluated GPOs has a service " +"logon right defined, the user is granted logon access. If at least one " +"evaluated GPO contains service logon right settings, the user is granted " +"logon access only, if it or at least one of its groups is part of the policy " +"settings." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:904 +msgid "" +"Note: Using the Group Policy Management Editor this value is called \"Allow " +"log on as a service\" and \"Deny log on as a service\"." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> +#: sssd-ad.5.xml:917 +#, no-wrap +msgid "" +"ad_gpo_map_service = +my_pam_service\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:909 sssd-ad.5.xml:984 +msgid "" +"It is possible to add a PAM service name to the default set by using " +"<quote>+service_name</quote>. Since the default set is empty, it is not " +"possible to remove a PAM service name from the default set. For example, in " +"order to add a custom pam service name (e.g. <quote>my_pam_service</quote>), " +"you would use the following configuration: <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:927 +msgid "ad_gpo_map_permit (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:930 +msgid "" +"A comma-separated list of PAM service names for which GPO-based access is " +"always granted, regardless of any GPO Logon Rights." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> +#: sssd-ad.5.xml:944 +#, no-wrap +msgid "" +"ad_gpo_map_permit = +my_pam_service, -sudo\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:935 +msgid "" +"It is possible to add another PAM service name to the default set by using " +"<quote>+service_name</quote> or to explicitly remove a PAM service name from " +"the default set by using <quote>-service_name</quote>. For example, in " +"order to replace a default PAM service name for unconditionally permitted " +"access (e.g. <quote>sudo</quote>) with a custom pam service name " +"(e.g. <quote>my_pam_service</quote>), you would use the following " +"configuration: <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:952 +msgid "polkit-1" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:967 +msgid "systemd-user" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:976 +msgid "ad_gpo_map_deny (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:979 +msgid "" +"A comma-separated list of PAM service names for which GPO-based access is " +"always denied, regardless of any GPO Logon Rights." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> +#: sssd-ad.5.xml:992 +#, no-wrap +msgid "" +"ad_gpo_map_deny = +my_pam_service\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:1002 +msgid "ad_gpo_default_right (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1005 +msgid "" +"This option defines how access control is evaluated for PAM service names " +"that are not explicitly listed in one of the ad_gpo_map_* options. This " +"option can be set in two different manners. First, this option can be set to " +"use a default logon right. For example, if this option is set to " +"'interactive', it means that unmapped PAM service names will be processed " +"based on the InteractiveLogonRight and DenyInteractiveLogonRight policy " +"settings. Alternatively, this option can be set to either always permit or " +"always deny access for unmapped PAM service names." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1018 +msgid "Supported values for this option include:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:1027 +msgid "remote_interactive" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:1032 +msgid "network" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:1037 +msgid "batch" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:1042 +msgid "service" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:1047 +msgid "permit" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> +#: sssd-ad.5.xml:1052 +msgid "deny" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1058 +msgid "Default: deny" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:1064 +msgid "ad_maximum_machine_account_password_age (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1067 +msgid "" +"SSSD will check once a day if the machine account password is older than the " +"given age in days and try to renew it. A value of 0 will disable the renewal " +"attempt." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1073 +msgid "Default: 30 days" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:1079 +msgid "ad_machine_account_password_renewal_opts (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1082 +msgid "" +"This option should only be used to test the machine account renewal " +"task. The option expects 3 integers and a string separated by a colon " +"(':'). The first integer defines the interval in seconds how often the task " +"is run. The second specifies the initial timeout in seconds before the task " +"is run for the first time after startup. The optional third value specifies " +"a maximal random offset to the previous two values to avoid updates of many " +"hosts at the same time (\"thundering herd problem\"). If this value is " +"missing or empty in the value string '0' will be used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1096 +msgid "" +"The optional fourth string value identifies the helper binary which should " +"be used for the renewal. Currently <command>adcli</command> and " +"<command>realm</command> are supported. If this value is missing or empty in " +"the value string <command>realm</command> will be used. Since the helper is " +"started as the user SSSD is running as there might be the chance that the " +"renewal will fail if this user does not has permissions to modify the keytab " +"file where the machine account credentials are stored. This will typically " +"be the case for <command>adcli</command>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1110 +msgid "" +"<command>realm</command> is not updating the keytab directly but is calling " +"the <command>realmd</command> process, which runs as root user, for this " +"task. <command>realmd</command> can allow access to non-privileged users " +"with the help of PolicyKit and by default SSSD provides suitable rules for " +"the user SSSD is running as." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1119 +msgid "Default: 86400:750:300:realm (24h, 12m30s and 5m)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:1125 +msgid "ad_update_samba_machine_account_password (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1128 +msgid "" +"If enabled, when SSSD renews the machine account password, it will also be " +"updated in Samba's database. This prevents Samba's copy of the machine " +"account password from getting out of date when it is set up to use AD for " +"authentication." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ad.5.xml:1141 +msgid "ad_use_ldaps (bool)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1144 +msgid "" +"By default SSSD uses the plain LDAP port 389 and the Global Catalog port " +"3628. If this option is set to True SSSD will use the LDAPS port 636 and " +"Global Catalog port 3629 with LDAPS protection. Since AD does not allow to " +"have multiple encryption layers on a single connection and we still want to " +"use SASL/GSSAPI or SASL/GSS-SPNEGO for authentication the SASL security " +"property maxssf is set to 0 (zero) for those connections." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1164 +msgid "" +"Optional. This option tells SSSD to automatically update the Active " +"Directory DNS server with the IP address of this client. The update is " +"secured using GSS-TSIG. As a consequence, the Active Directory administrator " +"only needs to allow secure updates for the DNS zone. The IP address of the " +"AD LDAP connection is used for the updates, if it is not otherwise specified " +"by using the <quote>dyndns_iface</quote> option." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1194 +msgid "Default: 3600 (seconds)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1216 +msgid "" +"NOTE: While it is still possible to use the old " +"<emphasis>ipa_dyndns_iface</emphasis> option, users should migrate to using " +"<emphasis>dyndns_iface</emphasis> in their config file." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1222 +msgid "" +"Default: Use the IP addresses of the interface which is used for AD LDAP " +"connection" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ad.5.xml:1258 +msgid "" +"How often should the back end perform periodic DNS update in addition to the " +"automatic update performed when the back end goes online. This option is " +"optional and applicable only when dyndns_update is true. Note that the " +"lowest possible value is 60 seconds in-case if value is provided less than " +"60, parameter will assume lowest value only." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:1472 +msgid "" +"The following example assumes that SSSD is correctly configured and " +"example.com is one of the domains in the <replaceable>[sssd]</replaceable> " +"section. This example shows only the AD provider-specific options." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-ad.5.xml:1479 +#, no-wrap +msgid "" +"[domain/EXAMPLE]\n" +"id_provider = ad\n" +"auth_provider = ad\n" +"access_provider = ad\n" +"chpass_provider = ad\n" +"\n" +"ad_server = dc1.example.com\n" +"ad_hostname = client.example.com\n" +"ad_domain = example.com\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-ad.5.xml:1499 +#, no-wrap +msgid "" +"access_provider = ldap\n" +"ldap_access_order = expire\n" +"ldap_account_expire_policy = ad\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:1495 +msgid "" +"The AD access control provider checks if the account is expired. It has the " +"same effect as the following configuration of the LDAP provider: " +"<placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:1505 +msgid "" +"However, unless the <quote>ad</quote> access control provider is explicitly " +"configured, the default access provider is <quote>permit</quote>. Please " +"note that if you configure an access provider other than <quote>ad</quote>, " +"you need to set all the connection parameters (such as LDAP URIs and " +"encryption details) manually." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ad.5.xml:1513 +msgid "" +"When the autofs provider is set to <quote>ad</quote>, the RFC2307 schema " +"attribute mapping (nisMap, nisObject, ...) is used, because these attributes " +"are included in the default Active Directory schema." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd-sudo.5.xml:10 sssd-sudo.5.xml:16 +msgid "sssd-sudo" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd-sudo.5.xml:17 +msgid "Configuring sudo with the SSSD back end" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:23 +msgid "" +"This manual page describes how to configure <citerefentry> " +"<refentrytitle>sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " +"to work with <citerefentry> <refentrytitle>sssd</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> and how SSSD caches sudo rules." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-sudo.5.xml:36 +msgid "Configuring sudo to cooperate with SSSD" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:38 +msgid "" +"To enable SSSD as a source for sudo rules, add <emphasis>sss</emphasis> to " +"the <emphasis>sudoers</emphasis> entry in <citerefentry> " +"<refentrytitle>nsswitch.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:47 +msgid "" +"For example, to configure sudo to first lookup rules in the standard " +"<citerefentry> <refentrytitle>sudoers</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> file (which should contain rules " +"that apply to local users) and then in SSSD, the nsswitch.conf file should " +"contain the following line:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-sudo.5.xml:57 +#, no-wrap +msgid "sudoers: files sss\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:61 +msgid "" +"More information about configuring the sudoers search order from the " +"nsswitch.conf file as well as information about the LDAP schema that is used " +"to store sudo rules in the directory can be found in <citerefentry> " +"<refentrytitle>sudoers.ldap</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:70 +msgid "" +"<emphasis>Note</emphasis>: in order to use netgroups or IPA hostgroups in " +"sudo rules, you also need to correctly set <citerefentry> " +"<refentrytitle>nisdomainname</refentrytitle> <manvolnum>1</manvolnum> " +"</citerefentry> to your NIS domain name (which equals to IPA domain name " +"when using hostgroups)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-sudo.5.xml:82 +msgid "Configuring SSSD to fetch sudo rules" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:84 +msgid "" +"All configuration that is needed on SSSD side is to extend the list of " +"<emphasis>services</emphasis> with \"sudo\" in [sssd] section of " +"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>. To speed up the LDAP lookups, you " +"can also set search base for sudo rules using " +"<emphasis>ldap_sudo_search_base</emphasis> option." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:94 +msgid "" +"The following example shows how to configure SSSD to download sudo rules " +"from an LDAP server." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-sudo.5.xml:99 +#, no-wrap +msgid "" +"[sssd]\n" +"services = nss, pam, sudo\n" +"domains = EXAMPLE\n" +"\n" +"[domain/EXAMPLE]\n" +"id_provider = ldap\n" +"sudo_provider = ldap\n" +"ldap_uri = ldap://example.com\n" +"ldap_sudo_search_base = ou=sudoers,dc=example,dc=com\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:98 +msgid "" +"<placeholder type=\"programlisting\" id=\"0\"/> <phrase " +"condition=\"have_systemd\"> It's important to note that on platforms where " +"systemd is supported there's no need to add the \"sudo\" provider to the " +"list of services, as it became optional. However, sssd-sudo.socket must be " +"enabled instead. </phrase>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:117 +msgid "" +"When SSSD is configured to use IPA as the ID provider, the sudo provider is " +"automatically enabled. The sudo search base is configured to use the IPA " +"native LDAP tree (cn=sudo,$SUFFIX). If any other search base is defined in " +"sssd.conf, this value will be used instead. The compat tree " +"(ou=sudoers,$SUFFIX) is no longer required for IPA sudo functionality." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-sudo.5.xml:127 +msgid "The SUDO rule caching mechanism" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:129 +msgid "" +"The biggest challenge, when developing sudo support in SSSD, was to ensure " +"that running sudo with SSSD as the data source provides the same user " +"experience and is as fast as sudo but keeps providing the most current set " +"of rules as possible. To satisfy these requirements, SSSD uses three kinds " +"of updates. They are referred to as full refresh, smart refresh and rules " +"refresh." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:137 +msgid "" +"The <emphasis>smart refresh</emphasis> periodically downloads rules that are " +"new or were modified after the last update. Its primary goal is to keep the " +"database growing by fetching only small increments that do not generate " +"large amounts of network traffic." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:143 +msgid "" +"The <emphasis>full refresh</emphasis> simply deletes all sudo rules stored " +"in the cache and replaces them with all rules that are stored on the " +"server. This is used to keep the cache consistent by removing every rule " +"which was deleted from the server. However, full refresh may produce a lot " +"of traffic and thus it should be run only occasionally depending on the size " +"and stability of the sudo rules." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:151 +msgid "" +"The <emphasis>rules refresh</emphasis> ensures that we do not grant the user " +"more permission than defined. It is triggered each time the user runs " +"sudo. Rules refresh will find all rules that apply to this user, check their " +"expiration time and redownload them if expired. In the case that any of " +"these rules are missing on the server, the SSSD will do an out of band full " +"refresh because more rules (that apply to other users) may have been " +"deleted." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:160 +msgid "" +"If enabled, SSSD will store only rules that can be applied to this " +"machine. This means rules that contain one of the following values in " +"<emphasis>sudoHost</emphasis> attribute:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> +#: sssd-sudo.5.xml:167 +msgid "keyword ALL" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> +#: sssd-sudo.5.xml:172 +msgid "wildcard" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> +#: sssd-sudo.5.xml:177 +msgid "netgroup (in the form \"+netgroup\")" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> +#: sssd-sudo.5.xml:182 +msgid "hostname or fully qualified domain name of this machine" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> +#: sssd-sudo.5.xml:187 +msgid "one of the IP addresses of this machine" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> +#: sssd-sudo.5.xml:192 +msgid "one of the IP addresses of the network (in the form \"address/mask\")" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:198 +msgid "" +"There are many configuration options that can be used to adjust the " +"behavior. Please refer to \"ldap_sudo_*\" in <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> and \"sudo_*\" in <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-sudo.5.xml:212 +msgid "Tuning the performance" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:214 +msgid "" +"SSSD uses different kinds of mechanisms with more or less complex LDAP " +"filters to keep the cached sudo rules up to date. The default configuration " +"is set to values that should satisfy most of our users, but the following " +"paragraphs contain few tips on how to fine- tune the configuration to your " +"requirements." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:221 +msgid "" +"1. <emphasis>Index LDAP attributes</emphasis>. Make sure that following LDAP " +"attributes are indexed: objectClass, cn, entryUSN or modifyTimestamp." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:226 +msgid "" +"2. <emphasis>Set ldap_sudo_search_base</emphasis>. Set the search base to " +"the container that holds the sudo rules to limit the scope of the lookup." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:231 +msgid "" +"3. <emphasis>Set full and smart refresh interval</emphasis>. If your sudo " +"rules do not change often and you do not require quick update of cached " +"rules on your clients, you may consider increasing the " +"<emphasis>ldap_sudo_full_refresh_interval</emphasis> and " +"<emphasis>ldap_sudo_smart_refresh_interval</emphasis>. You may also consider " +"disabling the smart refresh by setting " +"<emphasis>ldap_sudo_smart_refresh_interval = 0</emphasis>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-sudo.5.xml:240 +msgid "" +"4. If you have large number of clients, you may consider increasing the " +"value of <emphasis>ldap_sudo_random_offset</emphasis> to distribute the load " +"on the server better." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd-idp.5.xml:10 sssd-idp.5.xml:16 +msgid "sssd-idp" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd-idp.5.xml:17 +msgid "SSSD IdP provider" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-idp.5.xml:23 +msgid "" +"This manual page describes the configuration of the IdP provider for " +"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " +"</citerefentry>. For a detailed syntax reference, refer to the <quote>FILE " +"FORMAT</quote> section of the <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> manual page." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-idp.5.xml:36 +msgid "" +"The IdP provider is a back end used to connect to an OAuth 2.0 and REST " +"based identity provider (IdP). Since products might have individual " +"implementation of the REST API for looking up user and group attributes " +"dedicated code might be required, see the <quote>idp_type</quote> option for " +"details." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-idp.5.xml:43 +msgid "" +"IdPs typically do not provide POSIX attributes like e.g. user Id (UID) or " +"home directory. SSSD's IdP provider will autogenerate the needed " +"attributes. The default algorithm to generate user IDs (UIDs) and group IDs " +"(GIDs) aims to create reproducible IDs on different systems. As a drawback " +"it might happen that the algorithm assigns the same ID to different objects " +"and only the first one requested via SSSD will be available." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:62 +msgid "idp_type (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:65 +msgid "" +"Required option that specifies the IdP product. Currently Entra ID " +"(entra_id) and Keycloak (keycloak) are supported." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:70 +msgid "" +"Depending on the IdP product additional platform specific options might " +"follow the name separated by a colon (:). E.g. for Keycloak the base URI for " +"the user and group REST API must be given. For Entra ID this is not needed " +"because there is a generic endpoint for all tenants." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:78 sssd-idp.5.xml:94 sssd-idp.5.xml:119 +msgid "Default: Not set (Required)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:83 +msgid "idp_client_id (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:86 +msgid "" +"ID of the IdP client used by SSSD to authenticate users and as a client to " +"lookup user and group attributes. This client must offer device " +"authorization according to RFC-8628 and must have permissions to search and " +"read user and group attributes." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:99 +msgid "idp_client_secret (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:102 +msgid "" +"Password of the IdP client. The password is required for the id_provider. If " +"only used as auth_provider it depends on the server side configuration if it " +"is required or not." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:113 +msgid "idp_token_endpoint (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:116 +msgid "IdP endpoint for requesting access tokens." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:124 +msgid "idp_device_auth_endpoint (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:127 +msgid "" +"IdP endpoint for device authorization according to RFC-8628. This is " +"required for user authentication." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:137 +msgid "idp_userinfo_endpoint (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:140 +msgid "" +"IdP userinfo endpoint to request user attributes after a successful " +"authentication of the user. Required for authentication." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:150 +msgid "idp_id_scope (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:153 +msgid "" +"Scope required for looking up user and group attributes with the REST " +"API. The scopes are used by the server to determine which attributes/claims " +"are returned to the caller." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:164 +msgid "idp_auth_scope (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:167 +msgid "" +"Scope required during authentication. The scopes are used by the server to " +"determine which attributes/claims are returned to the caller." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:172 +msgid "" +"Currently the tokens returned during user authentication are not used for " +"other purposes hence the only important claim is the subject identifier " +"'sub' which is used to check if the authenticated user is the one trying to " +"log in. This might change in future." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:185 +msgid "idp_request_timeout (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:188 +msgid "Timeout in seconds for an individual request to the IdP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:197 +msgid "idmap_range_min (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:200 +msgid "" +"Specifies the lower (inclusive) bound of the range of POSIX IDs to use for " +"mapping IdP users and group to POSIX IDs. It is the first POSIX ID which can " +"be used for the mapping." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:206 +msgid "" +"The interval between <quote>idmap_range_min</quote> and " +"<quote>idmap_range_max</quote> will be split into smaller ranges of size " +"<quote>idmap_range_size</quote> which will be used by an individual IdP " +"domain." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:213 sssd-idp.5.xml:239 include/ldap_id_mapping.xml:139 +#: include/ldap_id_mapping.xml:197 +msgid "Default: 200000" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:218 +msgid "idmap_range_max (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:221 +msgid "" +"Specifies the upper (exclusive) bound of the range of POSIX IDs to use for " +"mapping IdP users and groups to POSIX IDs. It is the first POSIX ID which " +"will not be used for POSIX ID-mapping anymore." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:227 include/ldap_id_mapping.xml:165 +msgid "Default: 2000200000" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-idp.5.xml:232 +msgid "idmap_range_size (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-idp.5.xml:235 +msgid "Specifies the number of POSIX IDs available for a single IdP domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-idp.5.xml:251 +#, no-wrap +msgid "" +"[domain/entra_id]\n" +"id_provider = idp\n" +"idp_type = entra_id\n" +"idp_client_id = 12345678-abcd-0101-efef-ba9876543210\n" +"idp_client_secret = YOUR-CLIENT-SCERET\n" +"idp_token_endpoint = " +"https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/token\n" +"idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me\n" +"idp_device_auth_endpoint = " +"https://login.microsoftonline.com/TENNANT-ID/oauth2/v2.0/devicecode\n" +"idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default\n" +"idp_auth_scope = openid profile email\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-idp.5.xml:263 +#, no-wrap +msgid "" +"[domain/keycloak]\n" +"idp_type = " +"keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/\n" +"id_provider = idp\n" +"idp_client_id = myclient\n" +"idp_client_secret = YOUR-CLIENT-SCERET\n" +"idp_token_endpoint = " +"https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token\n" +"idp_userinfo_endpoint = " +"https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo\n" +"idp_device_auth_endpoint = " +"https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device\n" +"idp_id_scope = profile\n" +"idp_auth_scope = openid profile email\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-idp.5.xml:250 +msgid "" +"<placeholder type=\"programlisting\" id=\"0\"/> <placeholder " +"type=\"programlisting\" id=\"1\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd.8.xml:10 sssd.8.xml:15 +msgid "sssd" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd.8.xml:16 +msgid "System Security Services Daemon" +msgstr "" + +#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> +#: sssd.8.xml:21 +msgid "" +"<command>sssd</command> <arg choice='opt'> " +"<replaceable>options</replaceable> </arg>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.8.xml:31 +msgid "" +"<command>SSSD</command> provides a set of daemons to manage access to remote " +"directories and authentication mechanisms. It provides an NSS and PAM " +"interface toward the system and a pluggable backend system to connect to " +"multiple different account sources as well as D-Bus interface. It is also " +"the basis to provide client auditing and policy services for projects like " +"FreeIPA. It provides a more robust database to store local users as well as " +"extended user data." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:46 +msgid "" +"<option>-d</option>,<option>--debug-level</option> " +"<replaceable>LEVEL</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:53 +msgid "<option>--debug-timestamps=</option><replaceable>mode</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:57 +msgid "<emphasis>1</emphasis>: Add a timestamp to the debug messages" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:60 +msgid "<emphasis>0</emphasis>: Disable timestamp in the debug messages" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:69 +msgid "<option>--debug-microseconds=</option><replaceable>mode</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:73 +msgid "<emphasis>1</emphasis>: Add microseconds to the timestamp in debug messages" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:76 +msgid "<emphasis>0</emphasis>: Disable microseconds in timestamp" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:85 +msgid "<option>--logger=</option><replaceable>value</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:89 +msgid "Location where SSSD will send log messages." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:92 +msgid "" +"<emphasis>stderr</emphasis>: Redirect debug messages to standard error " +"output." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:96 +msgid "" +"<emphasis>files</emphasis>: Redirect debug messages to the log files. By " +"default, the log files are stored in <filename>/var/log/sssd</filename> and " +"there are separate log files for every SSSD service and domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:102 +msgid "<emphasis>journald</emphasis>: Redirect debug messages to systemd-journald" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:106 +msgid "Default: not set (fall back to journald if available, otherwise to stderr)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:113 +msgid "<option>-D</option>,<option>--daemon</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:117 +msgid "Become a daemon after starting up." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:123 sss_seed.8.xml:136 +msgid "<option>-i</option>,<option>--interactive</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:127 +msgid "Run in the foreground, don't become a daemon." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:133 +msgid "<option>-c</option>,<option>--config</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:137 +msgid "" +"Specify a non-default config file. The default is " +"<filename>/etc/sssd/sssd.conf</filename>. For reference on the config file " +"syntax and options, consult the <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> manual page." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:151 +msgid "<option>--version</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:155 +msgid "Print version number and exit." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.8.xml:163 +msgid "Signals" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:166 +msgid "SIGTERM/SIGINT" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:169 +msgid "" +"Informs the SSSD to gracefully terminate all of its child processes and then " +"shut down the monitor." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:175 +msgid "SIGHUP" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:178 +msgid "" +"Tells the SSSD to stop writing to its current debug file descriptors and to " +"close and reopen them. This is meant to facilitate log rolling with programs " +"like logrotate." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:186 +msgid "SIGUSR1" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:189 +msgid "" +"Tells the SSSD to simulate offline operation for the duration of the " +"<quote>offline_timeout</quote> parameter. This is useful for testing. The " +"signal can be sent to either the sssd process or any sssd_be process " +"directly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:198 +msgid "SIGUSR2" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:201 +msgid "" +"Tells the SSSD to go online immediately. This is useful for testing. The " +"signal can be sent to either the sssd process or any sssd_be process " +"directly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:208 +msgid "SIGRTMIN+1" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:211 +msgid "" +"Tells the SSSD to reschedule the periodic tasks. The internal watchdog sends " +"this signal to the providers when a clock shift is detected although it can " +"be sent to any sssd_be process directly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd.8.xml:223 sss_ssh_authorizedkeys.1.xml:141 sss_ssh_knownhosts.1.xml:116 +msgid "EXIT STATUS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:226 +msgid "0" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:229 +msgid "SSSD was shutdown gracefully." +msgstr "" + +#. type: Content of: <reference><refentry><refmeta><manvolnum> +#: sssd.8.xml:234 sss_ssh_authorizedkeys.1.xml:11 sss_ssh_knownhosts.1.xml:11 +msgid "1" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:237 +msgid "Bad configuration or command line option." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:242 +msgid "2" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:245 +msgid "Memory allocation error." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:250 +msgid "6" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:253 +msgid "SSSD is already running." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd.8.xml:258 +msgid "Other codes" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd.8.xml:261 +msgid "" +"Other codes denote different errors, most probably about missing required " +"access rights. See SSSD and system logs for details." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.8.xml:272 +msgid "" +"If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", client " +"applications will not use the fast in-memory cache." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd.8.xml:276 +msgid "" +"If the environment variable SSS_LOCKFREE is set to \"NO\", requests from " +"multiple threads of a single application will be serialized." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sss_obfuscate.8.xml:10 sss_obfuscate.8.xml:15 +msgid "sss_obfuscate" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sss_obfuscate.8.xml:16 +msgid "obfuscate a clear text password" +msgstr "" + +#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> +#: sss_obfuscate.8.xml:21 +msgid "" +"<command>sss_obfuscate</command> <arg choice='opt'> " +"<replaceable>options</replaceable> </arg> <arg " +"choice='plain'><replaceable>[PASSWORD]</replaceable></arg>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_obfuscate.8.xml:32 +msgid "" +"<command>sss_obfuscate</command> converts a given password into " +"human-unreadable format and places it into appropriate domain section of the " +"SSSD config file." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_obfuscate.8.xml:37 +msgid "" +"The cleartext password is read from standard input or entered " +"interactively. The obfuscated password is put into " +"<quote>ldap_default_authtok</quote> parameter of a given SSSD domain and the " +"<quote>ldap_default_authtok_type</quote> parameter is set to " +"<quote>obfuscated_password</quote>. Refer to <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> for more details on these parameters." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_obfuscate.8.xml:49 +msgid "" +"Please note that obfuscating the password provides <emphasis>no real " +"security benefit</emphasis> as it is still possible for an attacker to " +"reverse-engineer the password back. Using better authentication mechanisms " +"such as client side certificates or GSSAPI is <emphasis>strongly</emphasis> " +"advised." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_obfuscate.8.xml:63 +msgid "<option>-s</option>,<option>--stdin</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_obfuscate.8.xml:67 +msgid "The password to obfuscate will be read from standard input." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_obfuscate.8.xml:74 sss_ssh_authorizedkeys.1.xml:127 +#: sss_ssh_knownhosts.1.xml:63 +msgid "" +"<option>-d</option>,<option>--domain</option> " +"<replaceable>DOMAIN</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_obfuscate.8.xml:79 +msgid "" +"The SSSD domain to use the password in. The default name is " +"<quote>default</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_obfuscate.8.xml:86 +msgid "<option>-f</option>,<option>--file</option> <replaceable>FILE</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_obfuscate.8.xml:91 +msgid "Read the config file specified by the positional parameter." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_obfuscate.8.xml:95 +msgid "Default: <filename>/etc/sssd/sssd.conf</filename>" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sss_override.8.xml:10 sss_override.8.xml:15 +msgid "sss_override" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sss_override.8.xml:16 +msgid "create local overrides of user and group attributes" +msgstr "" + +#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> +#: sss_override.8.xml:21 +msgid "" +"<command>sss_override</command> <arg " +"choice='plain'><replaceable>COMMAND</replaceable></arg> <arg choice='opt'> " +"<replaceable>options</replaceable> </arg>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_override.8.xml:32 +msgid "" +"<command>sss_override</command> enables to create a client-side view and " +"allows to change selected values of specific user and groups. This change " +"takes effect only on local machine." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_override.8.xml:37 +msgid "" +"Overrides data are stored in the SSSD cache. If the cache is deleted, all " +"local overrides are lost. Please note that after the first override is " +"created using any of the following <emphasis>user-add</emphasis>, " +"<emphasis>group-add</emphasis>, <emphasis>user-import</emphasis> or " +"<emphasis>group-import</emphasis> command. SSSD needs to be restarted to " +"take effect. <emphasis>sss_override</emphasis> prints message when a " +"restart is required." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_override.8.xml:48 +msgid "" +"<emphasis>NOTE:</emphasis> The options provided in this man page only work " +"with <quote>ldap</quote> and <quote>AD</quote> <quote> " +"id_provider</quote>. IPA overrides can be managed centrally on the IPA " +"server." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sss_override.8.xml:56 sssctl.8.xml:41 +msgid "AVAILABLE COMMANDS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_override.8.xml:58 +msgid "" +"Argument <emphasis>NAME</emphasis> is the name of original object in all " +"commands. It is not possible to override <emphasis>uid</emphasis> or " +"<emphasis>gid</emphasis> to 0." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_override.8.xml:65 +msgid "" +"<option>user-add</option> <emphasis>NAME</emphasis> " +"<optional><option>-n,--name</option> NAME</optional> " +"<optional><option>-u,--uid</option> UID</optional> " +"<optional><option>-g,--gid</option> GID</optional> " +"<optional><option>-h,--home</option> HOME</optional> " +"<optional><option>-s,--shell</option> SHELL</optional> " +"<optional><option>-c,--gecos</option> GECOS</optional> " +"<optional><option>-x,--certificate</option> BASE64 ENCODED " +"CERTIFICATE</optional>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:78 +msgid "" +"Override attributes of an user. Please be aware that calling this command " +"will replace any previous override for the (NAMEd) user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_override.8.xml:86 +msgid "<option>user-del</option> <emphasis>NAME</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:91 +msgid "" +"Remove user overrides. However be aware that overridden attributes might be " +"returned from memory cache. Please see SSSD option " +"<emphasis>memcache_timeout</emphasis> for more details." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_override.8.xml:100 +msgid "" +"<option>user-find</option> <optional><option>-d,--domain</option> " +"DOMAIN</optional>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:105 +msgid "" +"List all users with set overrides. If <emphasis>DOMAIN</emphasis> parameter " +"is set, only users from the domain are listed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_override.8.xml:113 +msgid "<option>user-show</option> <emphasis>NAME</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:118 +msgid "Show user overrides." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_override.8.xml:124 +msgid "<option>user-import</option> <emphasis>FILE</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:129 +msgid "" +"Import user overrides from <emphasis>FILE</emphasis>. Data format is " +"similar to standard passwd file. The format is:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:134 +msgid "original_name:name:uid:gid:gecos:home:shell:base64_encoded_certificate" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:137 +msgid "" +"where original_name is original name of the user whose attributes should be " +"overridden. The rest of fields correspond to new values. You can omit a " +"value simply by leaving corresponding field empty." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:146 +msgid "ckent:superman::::::" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:149 +msgid "ckent@krypton.com::501:501:Superman:/home/earth:/bin/bash:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_override.8.xml:155 +msgid "<option>user-export</option> <emphasis>FILE</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:160 +msgid "" +"Export all overridden attributes and store them in " +"<emphasis>FILE</emphasis>. See <emphasis>user-import</emphasis> for data " +"format." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_override.8.xml:168 +msgid "" +"<option>group-add</option> <emphasis>NAME</emphasis> " +"<optional><option>-n,--name</option> NAME</optional> " +"<optional><option>-g,--gid</option> GID</optional>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:175 +msgid "" +"Override attributes of a group. Please be aware that calling this command " +"will replace any previous override for the (NAMEd) group." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_override.8.xml:183 +msgid "<option>group-del</option> <emphasis>NAME</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:188 +msgid "" +"Remove group overrides. However be aware that overridden attributes might be " +"returned from memory cache. Please see SSSD option " +"<emphasis>memcache_timeout</emphasis> for more details." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_override.8.xml:197 +msgid "" +"<option>group-find</option> <optional><option>-d,--domain</option> " +"DOMAIN</optional>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:202 +msgid "" +"List all groups with set overrides. If <emphasis>DOMAIN</emphasis> " +"parameter is set, only groups from the domain are listed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_override.8.xml:210 +msgid "<option>group-show</option> <emphasis>NAME</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:215 +msgid "Show group overrides." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_override.8.xml:221 +msgid "<option>group-import</option> <emphasis>FILE</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:226 +msgid "" +"Import group overrides from <emphasis>FILE</emphasis>. Data format is " +"similar to standard group file. The format is:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:231 +msgid "original_name:name:gid" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:234 +msgid "" +"where original_name is original name of the group whose attributes should be " +"overridden. The rest of fields correspond to new values. You can omit a " +"value simply by leaving corresponding field empty." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:243 +msgid "admins:administrators:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:246 +msgid "Domain Users:Users:501" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_override.8.xml:252 +msgid "<option>group-export</option> <emphasis>FILE</emphasis>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_override.8.xml:257 +msgid "" +"Export all overridden attributes and store them in " +"<emphasis>FILE</emphasis>. See <emphasis>group-import</emphasis> for data " +"format." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sss_override.8.xml:267 sssctl.8.xml:50 +msgid "COMMON OPTIONS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_override.8.xml:269 sssctl.8.xml:52 +msgid "Those options are available with all commands." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_override.8.xml:274 sssctl.8.xml:57 +msgid "<option>--debug</option> <replaceable>LEVEL</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd-krb5.5.xml:10 sssd-krb5.5.xml:16 +msgid "sssd-krb5" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd-krb5.5.xml:17 +msgid "SSSD Kerberos provider" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-krb5.5.xml:23 +msgid "" +"This manual page describes the configuration of the Kerberos 5 " +"authentication backend for <citerefentry> " +"<refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " +"</citerefentry>. For a detailed syntax reference, please refer to the " +"<quote>FILE FORMAT</quote> section of the <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> manual page." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-krb5.5.xml:36 +msgid "" +"The Kerberos 5 authentication backend contains auth and chpass providers. It " +"must be paired with an identity provider in order to function properly (for " +"example, id_provider = ldap). Some information required by the Kerberos 5 " +"authentication backend must be provided by the identity provider, such as " +"the user's Kerberos Principal Name (UPN). The configuration of the identity " +"provider should have an entry to specify the UPN. Please refer to the man " +"page for the applicable identity provider for details on how to configure " +"this." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-krb5.5.xml:47 +msgid "" +"This backend also provides access control based on the .k5login file in the " +"home directory of the user. See <citerefentry> " +"<refentrytitle>k5login</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry> for more details. Please note that an empty .k5login file " +"will deny all access to this user. To activate this feature, use " +"'access_provider = krb5' in your SSSD configuration." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-krb5.5.xml:55 +msgid "" +"In the case where the UPN is not available in the identity backend, " +"<command>sssd</command> will construct a UPN using the format " +"<replaceable>username</replaceable>@<replaceable>krb5_realm</replaceable>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:77 +msgid "" +"Specifies the comma-separated list of IP addresses or hostnames of the " +"Kerberos servers to which SSSD should connect, in the order of " +"preference. For more information on failover and server redundancy, see the " +"<quote>FAILOVER</quote> section. An optional port number (preceded by a " +"colon) may be appended to the addresses or hostnames. If empty, service " +"discovery is enabled; for more information, refer to the <quote>SERVICE " +"DISCOVERY</quote> section." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:106 +msgid "" +"The name of the Kerberos realm. This option is required and must be " +"specified." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:113 +msgid "krb5_kpasswd, krb5_backup_kpasswd (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:116 +msgid "" +"If the change password service is not running on the KDC, alternative " +"servers can be defined here. An optional port number (preceded by a colon) " +"may be appended to the addresses or hostnames." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:122 +msgid "" +"For more information on failover and server redundancy, see the " +"<quote>FAILOVER</quote> section. NOTE: Even if there are no more kpasswd " +"servers to try, the backend is not switched to operate offline if " +"authentication against the KDC is still possible." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:129 +msgid "Default: Use the KDC" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:135 +msgid "krb5_ccachedir (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:138 +msgid "" +"Directory to store credential caches. All the substitution sequences of " +"krb5_ccname_template can be used here, too, except %d and %P. The directory " +"is created as private and owned by the user, with permissions set to 0700." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:145 +msgid "Default: /tmp" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:151 +msgid "krb5_ccname_template (string)" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:165 include/override_homedir.xml:11 +msgid "%u" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:166 include/override_homedir.xml:12 +msgid "login name" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:169 include/override_homedir.xml:15 +msgid "%U" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:170 +msgid "login UID" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:173 +msgid "%p" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:174 +msgid "principal name" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:178 +msgid "%r" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:179 +msgid "realm name" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:182 include/override_homedir.xml:53 +msgid "%h" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:183 sssd-ifp.5.xml:128 +msgid "home directory" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:187 include/override_homedir.xml:19 +msgid "%d" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:188 +msgid "value of krb5_ccachedir" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:193 include/override_homedir.xml:31 +msgid "%P" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:194 +msgid "the process ID of the SSSD client" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:199 include/override_homedir.xml:68 +msgid "%%" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:200 include/override_homedir.xml:69 +msgid "a literal '%'" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:154 +msgid "" +"Location of the user's credential cache. Three credential cache types are " +"currently supported: <quote>FILE</quote>, <quote>DIR</quote> and " +"<quote>KEYRING:persistent</quote>. The cache can be specified either as " +"<replaceable>TYPE:RESIDUAL</replaceable>, or as an absolute path, which " +"implies the <quote>FILE</quote> type. In the template, the following " +"sequences are substituted: <placeholder type=\"variablelist\" id=\"0\"/> If " +"the template ends with 'XXXXXX' mkstemp(3) is used to create a unique " +"filename in a safe way." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:208 +msgid "" +"When using KEYRING types, the only supported mechanism is " +"<quote>KEYRING:persistent:%U</quote>, which uses the Linux kernel keyring to " +"store credentials on a per-UID basis. This is also the recommended choice, " +"as it is the most secure and predictable method." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:216 +msgid "" +"The default value for the credential cache name is sourced from the profile " +"stored in the system wide krb5.conf configuration file in the [libdefaults] " +"section. The option name is default_ccache_name. See krb5.conf(5)'s " +"PARAMETER EXPANSION paragraph for additional information on the expansion " +"format defined by krb5.conf." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:225 +msgid "" +"NOTE: Please be aware that libkrb5 ccache expansion template from " +"<citerefentry> <refentrytitle>krb5.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> uses different expansion sequences " +"than SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:234 +msgid "Default: (from libkrb5)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:240 +msgid "krb5_keytab (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:243 +msgid "" +"The location of the keytab to use when validating credentials obtained from " +"KDCs." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:253 +msgid "krb5_store_password_if_offline (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:256 +msgid "" +"Store the password of the user if the provider is offline and use it to " +"request a TGT when the provider comes online again." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:261 +msgid "" +"NOTE: this feature is only available on Linux. Passwords stored in this way " +"are kept in plaintext in the kernel keyring and are potentially accessible " +"by the root user (with difficulty)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:274 +msgid "krb5_use_fast (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:277 +msgid "" +"Enables flexible authentication secure tunneling (FAST) for Kerberos " +"pre-authentication. The following options are supported:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:282 +msgid "" +"<emphasis>never</emphasis> use FAST. This is equivalent to not setting this " +"option at all." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:286 +msgid "" +"<emphasis>try</emphasis> to use FAST. If the server does not support FAST, " +"continue the authentication without it." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:291 +msgid "" +"<emphasis>demand</emphasis> to use FAST. The authentication fails if the " +"server does not require fast." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:296 +msgid "Default: not set, i.e. FAST is not used." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:299 +msgid "NOTE: a keytab or support for anonymous PKINIT is required to use FAST." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:303 +msgid "" +"NOTE: SSSD supports FAST only with MIT Kerberos version 1.8 and later. If " +"SSSD is used with an older version of MIT Kerberos, using this option is a " +"configuration error." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:312 +msgid "krb5_fast_principal (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:315 +msgid "Specifies the server principal to use for FAST." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:321 +msgid "krb5_fast_use_anonymous_pkinit (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:324 +msgid "" +"If set to true try to use anonymous PKINIT instead of a keytab to get the " +"required credential for FAST. The krb5_fast_principal options is ignored in " +"this case." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:364 +msgid "krb5_kdcinfo_lookahead (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:367 +msgid "" +"When krb5_use_kdcinfo is set to true, you can limit the amount of servers " +"handed to <citerefentry> " +"<refentrytitle>sssd_krb5_locator_plugin</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry>. This might be helpful when there " +"are too many servers discovered using SRV record." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:377 +msgid "" +"The krb5_kdcinfo_lookahead option contains two numbers separated by a " +"colon. The first number represents number of primary servers used and the " +"second number specifies the number of backup servers." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:383 +msgid "" +"For example <emphasis>10:0</emphasis> means that up to 10 primary servers " +"will be handed to <citerefentry> " +"<refentrytitle>sssd_krb5_locator_plugin</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> but no backup servers." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:392 +msgid "Default: 3:1" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:398 +msgid "krb5_use_enterprise_principal (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:401 +msgid "" +"Specifies if the user principal should be treated as enterprise " +"principal. See section 5 of RFC 6806 for more details about enterprise " +"principals." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:407 +msgid "Default: false (AD provider: true)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:410 +msgid "" +"The IPA provider will set to option to 'true' if it detects that the server " +"is capable of handling enterprise principals and the option is not set " +"explicitly in the config file." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:419 +msgid "krb5_use_subdomain_realm (boolean)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:422 +msgid "" +"Specifies to use subdomains realms for the authentication of users from " +"trusted domains. This option can be set to 'true' if enterprise principals " +"are used with upnSuffixes which are not known on the parent domain KDCs. If " +"the option is set to 'true' SSSD will try to send the request directly to a " +"KDC of the trusted domain the user is coming from." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-krb5.5.xml:438 +msgid "krb5_map_user (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:441 +msgid "" +"The list of mappings is given as a comma-separated list of pairs " +"<quote>username:primary</quote> where <quote>username</quote> is a UNIX user " +"name and <quote>primary</quote> is a user part of a kerberos principal. This " +"mapping is used when user is authenticating using <quote>auth_provider = " +"krb5</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> +#: sssd-krb5.5.xml:453 +#, no-wrap +msgid "" +"krb5_realm = REALM\n" +"krb5_map_user = joe:juser,dick:richard\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-krb5.5.xml:458 +msgid "" +"<quote>joe</quote> and <quote>dick</quote> are UNIX user names and " +"<quote>juser</quote> and <quote>richard</quote> are primaries of kerberos " +"principals. For user <quote>joe</quote> resp. <quote>dick</quote> SSSD will " +"try to kinit as <quote>juser@REALM</quote> resp. " +"<quote>richard@REALM</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-krb5.5.xml:65 +msgid "" +"If the auth-module krb5 is used in an SSSD domain, the following options " +"must be used. See the <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> manual page, section <quote>DOMAIN SECTIONS</quote>, for " +"details on the configuration of an SSSD domain. <placeholder " +"type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-krb5.5.xml:485 +msgid "" +"The following example assumes that SSSD is correctly configured and FOO is " +"one of the domains in the <replaceable>[sssd]</replaceable> section. This " +"example shows only configuration of Kerberos authentication; it does not " +"include any identity provider." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-krb5.5.xml:493 +#, no-wrap +msgid "" +"[domain/FOO]\n" +"auth_provider = krb5\n" +"krb5_server = 192.168.1.1\n" +"krb5_realm = EXAMPLE.COM\n" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sss_cache.8.xml:10 sss_cache.8.xml:15 +msgid "sss_cache" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sss_cache.8.xml:16 +msgid "perform cache cleanup" +msgstr "" + +#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> +#: sss_cache.8.xml:21 +msgid "" +"<command>sss_cache</command> <arg choice='opt'> " +"<replaceable>options</replaceable> </arg>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_cache.8.xml:31 +msgid "" +"<command>sss_cache</command> invalidates records in SSSD cache. Invalidated " +"records are forced to be reloaded from server as soon as related SSSD " +"backend is online. Options that invalidate a single object only accept a " +"single provided argument." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:43 +msgid "<option>-E</option>,<option>--everything</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:47 +msgid "Invalidate all cached entries." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:53 +msgid "<option>-u</option>,<option>--user</option> <replaceable>login</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:58 +msgid "Invalidate specific user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:64 +msgid "<option>-U</option>,<option>--users</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:68 +msgid "" +"Invalidate all user records. This option overrides invalidation of specific " +"user if it was also set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:75 +msgid "" +"<option>-g</option>,<option>--group</option> " +"<replaceable>group</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:80 +msgid "Invalidate specific group." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:86 +msgid "<option>-G</option>,<option>--groups</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:90 +msgid "" +"Invalidate all group records. This option overrides invalidation of specific " +"group if it was also set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:97 +msgid "" +"<option>-n</option>,<option>--netgroup</option> " +"<replaceable>netgroup</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:102 +msgid "Invalidate specific netgroup." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:108 +msgid "<option>-N</option>,<option>--netgroups</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:112 +msgid "" +"Invalidate all netgroup records. This option overrides invalidation of " +"specific netgroup if it was also set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:119 +msgid "" +"<option>-s</option>,<option>--service</option> " +"<replaceable>service</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:124 +msgid "Invalidate specific service." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:130 +msgid "<option>-S</option>,<option>--services</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:134 +msgid "" +"Invalidate all service records. This option overrides invalidation of " +"specific service if it was also set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:141 +msgid "" +"<option>-a</option>,<option>--autofs-map</option> " +"<replaceable>autofs-map</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:146 +msgid "Invalidate specific autofs maps." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:152 +msgid "<option>-A</option>,<option>--autofs-maps</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:156 +msgid "" +"Invalidate all autofs maps. This option overrides invalidation of specific " +"map if it was also set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:163 +msgid "" +"<option>-h</option>,<option>--ssh-host</option> " +"<replaceable>hostname</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:168 +msgid "Invalidate SSH public keys of a specific host." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:174 +msgid "<option>-H</option>,<option>--ssh-hosts</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:178 +msgid "" +"Invalidate SSH public keys of all hosts. This option overrides invalidation " +"of SSH public keys of specific host if it was also set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:186 +msgid "" +"<option>-r</option>,<option>--sudo-rule</option> " +"<replaceable>rule</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:191 +msgid "Invalidate particular sudo rule." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:197 +msgid "<option>-R</option>,<option>--sudo-rules</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:201 +msgid "" +"Invalidate all cached sudo rules. This option overrides invalidation of " +"specific sudo rule if it was also set." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_cache.8.xml:209 +msgid "" +"<option>-d</option>,<option>--domain</option> " +"<replaceable>domain</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_cache.8.xml:214 +msgid "Restrict invalidation process only to a particular domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sss_cache.8.xml:224 +msgid "EFFECTS ON THE FAST MEMORY CACHE" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_cache.8.xml:226 +msgid "" +"<command>sss_cache</command> also invalidates the memory cache. Since the " +"memory cache is a file which is mapped into the memory of each process which " +"called SSSD to resolve users or groups the file cannot be truncated. A " +"special flag is set in the header of the file to indicate that the content " +"is invalid and then the file is unlinked by SSSD's NSS responder and a new " +"cache file is created. Whenever a process is now doing a new lookup for a " +"user or a group it will see the flag, close the old memory cache file and " +"map the new one into its memory. When all processes which had opened the old " +"memory cache file have closed it while looking up a user or a group the " +"kernel can release the occupied disk space and the old memory cache file is " +"finally removed completely." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_cache.8.xml:240 +msgid "" +"A special case is long running processes which are doing user or group " +"lookups only at startup, e.g. to determine the name of the user the process " +"is running as. For those lookups the memory cache file is mapped into the " +"memory of the process. But since there will be no further lookups this " +"process would never detect if the memory cache file was invalidated and " +"hence it will be kept in memory and will occupy disk space until the process " +"stops. As a result calling <command>sss_cache</command> might increase the " +"disk usage because old memory cache files cannot be removed from the disk " +"because they are still mapped by long running processes." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_cache.8.xml:252 +msgid "" +"A possible work-around for long running processes which are looking up users " +"and groups only at startup or very rarely is to run them with the " +"environment variable SSS_NSS_USE_MEMCACHE set to \"NO\" so that they won't " +"use the memory cache at all and not map the memory cache file into the " +"memory. In general a better solution is to tune the cache timeout parameters " +"so that they meet the local expectations and calling " +"<command>sss_cache</command> is not needed." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sss_debuglevel.8.xml:10 sss_debuglevel.8.xml:15 +msgid "sss_debuglevel" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sss_debuglevel.8.xml:16 +msgid "[DEPRECATED] change debug level while SSSD is running" +msgstr "" + +#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> +#: sss_debuglevel.8.xml:21 +msgid "" +"<command>sss_debuglevel</command> <arg choice='opt'> " +"<replaceable>options</replaceable> </arg> <arg " +"choice='plain'><replaceable>NEW_DEBUG_LEVEL</replaceable></arg>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_debuglevel.8.xml:32 +msgid "" +"<command>sss_debuglevel</command> is deprecated and replaced by the sssctl " +"debug-level command. Please refer to the <command>sssctl</command> man page " +"for more information on sssctl usage." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sss_seed.8.xml:10 sss_seed.8.xml:15 +msgid "sss_seed" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sss_seed.8.xml:16 +msgid "seed the SSSD cache with a user" +msgstr "" + +#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> +#: sss_seed.8.xml:21 +msgid "" +"<command>sss_seed</command> <arg choice='opt'> " +"<replaceable>options</replaceable> </arg> <arg choice='plain'>-D " +"<replaceable>DOMAIN</replaceable></arg> <arg choice='plain'>-n " +"<replaceable>USER</replaceable></arg>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_seed.8.xml:33 +msgid "" +"<command>sss_seed</command> seeds the SSSD cache with a user entry and " +"temporary password. If a user entry is already present in the SSSD cache " +"then the entry is updated with the temporary password." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_seed.8.xml:46 +msgid "" +"<option>-D</option>,<option>--domain</option> " +"<replaceable>DOMAIN</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_seed.8.xml:51 +msgid "" +"Provide the name of the domain in which the user is a member of. The domain " +"is also used to retrieve user information. The domain must be configured in " +"sssd.conf. The <replaceable>DOMAIN</replaceable> option must be provided. " +"Information retrieved from the domain overrides what is provided in the " +"options." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_seed.8.xml:63 +msgid "" +"<option>-n</option>,<option>--username</option> " +"<replaceable>USER</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_seed.8.xml:68 +msgid "" +"The username of the entry to be created or modified in the cache. The " +"<replaceable>USER</replaceable> option must be provided." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_seed.8.xml:76 +msgid "<option>-u</option>,<option>--uid</option> <replaceable>UID</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_seed.8.xml:81 +msgid "Set the UID of the user to <replaceable>UID</replaceable>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_seed.8.xml:88 +msgid "<option>-g</option>,<option>--gid</option> <replaceable>GID</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_seed.8.xml:93 +msgid "Set the GID of the user to <replaceable>GID</replaceable>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_seed.8.xml:100 +msgid "" +"<option>-c</option>,<option>--gecos</option> " +"<replaceable>COMMENT</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_seed.8.xml:105 +msgid "" +"Any text string describing the user. Often used as the field for the user's " +"full name." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_seed.8.xml:112 +msgid "" +"<option>-h</option>,<option>--home</option> " +"<replaceable>HOME_DIR</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_seed.8.xml:117 +msgid "Set the home directory of the user to <replaceable>HOME_DIR</replaceable>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_seed.8.xml:124 +msgid "" +"<option>-s</option>,<option>--shell</option> " +"<replaceable>SHELL</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_seed.8.xml:129 +msgid "Set the login shell of the user to <replaceable>SHELL</replaceable>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_seed.8.xml:140 +msgid "" +"Interactive mode for entering user information. This option will only prompt " +"for information not provided in the options or retrieved from the domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_seed.8.xml:148 +msgid "" +"<option>-p</option>,<option>--password-file</option> " +"<replaceable>PASS_FILE</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_seed.8.xml:153 +msgid "" +"Specify file to read user's password from. (if not specified password is " +"prompted for)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_seed.8.xml:165 +msgid "" +"The length of the password (or the size of file specified with -p or " +"--password-file option) must be less than or equal to PASS_MAX bytes (64 " +"bytes on systems with no globally-defined PASS_MAX value)." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd-ifp.5.xml:10 sssd-ifp.5.xml:16 +msgid "sssd-ifp" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd-ifp.5.xml:17 +msgid "SSSD InfoPipe responder" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ifp.5.xml:23 +msgid "" +"This manual page describes the configuration of the InfoPipe responder for " +"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " +"</citerefentry>. For a detailed syntax reference, refer to the <quote>FILE " +"FORMAT</quote> section of the <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> manual page." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ifp.5.xml:36 +msgid "" +"The InfoPipe responder provides a public D-Bus interface accessible over the " +"system bus. The interface allows the user to query information about remote " +"users and groups over the system bus." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd-ifp.5.xml:43 +msgid "FIND BY VALID CERTIFICATE" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd-ifp.5.xml:45 +msgid "" +"The following options can be used to control how the certificates are " +"validated when using the FindByValidCertificate() API:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd-ifp.5.xml:48 sss_ssh_authorizedkeys.1.xml:92 +msgid "ca_db" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd-ifp.5.xml:49 sss_ssh_authorizedkeys.1.xml:93 +msgid "p11_child_timeout" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> +#: sssd-ifp.5.xml:50 sss_ssh_authorizedkeys.1.xml:94 +msgid "certificate_verification" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd-ifp.5.xml:52 +msgid "" +"For more details about the options see " +"<citerefentry><refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ifp.5.xml:62 +msgid "These options can be used to configure the InfoPipe responder." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-ifp.5.xml:69 +msgid "" +"Specifies the comma-separated list of UID values or user names that are " +"allowed to access the InfoPipe responder. User names are resolved to UIDs at " +"startup." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-ifp.5.xml:75 +msgid "Default: 0 (only the root user is allowed to access the InfoPipe responder)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-ifp.5.xml:79 +msgid "" +"Please note that although the UID 0 is used as the default it will be " +"overwritten with this option. If you still want to allow the root user to " +"access the InfoPipe responder, which would be the typical case, you have to " +"add 0 to the list of allowed UIDs as well." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-ifp.5.xml:93 +msgid "" +"Specifies the comma-separated list of white or blacklisted attributes. This " +"option only applies to the <quote>Users</quote> interface. The deprecated " +"<quote>GetUserAttr</quote> interface does not utilize this option, it allows " +"any attribute requested." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd-ifp.5.xml:111 +msgid "name" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd-ifp.5.xml:112 +msgid "user's login name" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd-ifp.5.xml:115 +msgid "uidNumber" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd-ifp.5.xml:116 +msgid "user ID" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd-ifp.5.xml:119 +msgid "gidNumber" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd-ifp.5.xml:120 +msgid "primary group ID" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd-ifp.5.xml:123 +msgid "gecos" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd-ifp.5.xml:124 +msgid "user information, typically full name" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd-ifp.5.xml:127 +msgid "homeDirectory" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> +#: sssd-ifp.5.xml:131 +msgid "loginShell" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: sssd-ifp.5.xml:132 +msgid "user shell" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-ifp.5.xml:101 +msgid "" +"By default, the InfoPipe responder `/Users` interface only allows the " +"default set of POSIX attributes to be requested. This set is the same as " +"returned by <citerefentry> <refentrytitle>getpwnam</refentrytitle> " +"<manvolnum>3</manvolnum> </citerefentry> and includes: <placeholder " +"type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting> +#: sssd-ifp.5.xml:147 +#, no-wrap +msgid "" +"user_attributes = +telephoneNumber, -loginShell\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-ifp.5.xml:137 +msgid "" +"It is possible to add another attribute to this set by using " +"<quote>+attr_name</quote> or explicitly remove an attribute using " +"<quote>-attr_name</quote>. Added attributes will be made available in the " +"<quote>extraAttributes</quote> array. For example, to allow " +"<quote>telephoneNumber</quote> but deny <quote>loginShell</quote>, you would " +"use the following configuration: <placeholder type=\"programlisting\" " +"id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-ifp.5.xml:151 +msgid "Default: not set. Only the default set of POSIX attributes is allowed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-ifp.5.xml:161 +msgid "" +"Specifies an upper limit on the number of entries that are downloaded during " +"a wildcard lookup that overrides caller-supplied limit." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-ifp.5.xml:166 +msgid "Default: 0 (let the caller set an upper limit)" +msgstr "" + +#. type: Content of: <reference><refentry><refentryinfo> +#: sss_rpcidmapd.5.xml:8 +msgid "" +"<productname>sss rpc.idmapd plugin</productname> <author> " +"<firstname>Noam</firstname> <surname>Meltzer</surname> <affiliation> " +"<orgname>Primary Data Inc.</orgname> </affiliation> <contrib>Developer " +"(2013-2014)</contrib> </author> <author> <firstname>Noam</firstname> " +"<surname>Meltzer</surname> <contrib>Developer (2014-)</contrib> " +"<email>tsnoam@gmail.com</email> </author>" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sss_rpcidmapd.5.xml:26 sss_rpcidmapd.5.xml:32 +msgid "sss_rpcidmapd" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sss_rpcidmapd.5.xml:33 +msgid "sss plugin configuration directives for rpc.idmapd" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sss_rpcidmapd.5.xml:37 +msgid "CONFIGURATION FILE" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_rpcidmapd.5.xml:39 +msgid "" +"rpc.idmapd configuration file is usually found at " +"<emphasis>/etc/idmapd.conf</emphasis>. See <citerefentry> " +"<refentrytitle>idmapd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> for more information." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sss_rpcidmapd.5.xml:49 +msgid "SSS CONFIGURATION EXTENSION" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sss_rpcidmapd.5.xml:51 +msgid "Enable SSS plugin" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss_rpcidmapd.5.xml:53 +msgid "" +"In section <quote>[Translation]</quote>, modify/set <quote>Method</quote> " +"attribute to contain <emphasis>sss</emphasis>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sss_rpcidmapd.5.xml:59 +msgid "[sss] config section" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss_rpcidmapd.5.xml:61 +msgid "" +"In order to change the default of one of the configuration attributes of the " +"<emphasis>sss</emphasis> plugin listed below you will need to create a " +"config section for it, named <quote>[sss]</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> +#: sss_rpcidmapd.5.xml:67 +msgid "Configuration attributes" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sss_rpcidmapd.5.xml:69 +msgid "memcache (bool)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sss_rpcidmapd.5.xml:72 +msgid "Indicates whether or not to use memcache optimisation technique." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sss_rpcidmapd.5.xml:85 +msgid "SSSD INTEGRATION" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_rpcidmapd.5.xml:87 +msgid "" +"The sss plugin requires the <emphasis>NSS Responder</emphasis> to be enabled " +"in sssd." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_rpcidmapd.5.xml:91 +msgid "" +"The attribute <quote>use_fully_qualified_names</quote> must be enabled on " +"all domains (NFSv4 clients expect a fully qualified name to be sent on the " +"wire)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sss_rpcidmapd.5.xml:103 +#, no-wrap +msgid "" +"[General]\n" +"Verbosity = 2\n" +"# domain must be synced between NFSv4 server and clients\n" +"# Solaris/Illumos/AIX use \"localdomain\" as default!\n" +"Domain = default\n" +"\n" +"[Mapping]\n" +"Nobody-User = nfsnobody\n" +"Nobody-Group = nfsnobody\n" +"\n" +"[Translation]\n" +"Method = sss\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_rpcidmapd.5.xml:100 +msgid "" +"The following example shows a minimal idmapd.conf which makes use of the sss " +"plugin. <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <refsect1><title> +#: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:316 include/seealso.xml:2 +msgid "SEE ALSO" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_rpcidmapd.5.xml:122 +msgid "" +"<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> " +"</citerefentry>, <citerefentry> <refentrytitle>idmapd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sss_ssh_authorizedkeys.1.xml:10 sss_ssh_authorizedkeys.1.xml:15 +msgid "sss_ssh_authorizedkeys" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sss_ssh_authorizedkeys.1.xml:16 +msgid "get OpenSSH authorized keys" +msgstr "" + +#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> +#: sss_ssh_authorizedkeys.1.xml:21 +msgid "" +"<command>sss_ssh_authorizedkeys</command> <arg choice='opt'> " +"<replaceable>options</replaceable> </arg> <arg " +"choice='plain'><replaceable>USER</replaceable></arg>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_ssh_authorizedkeys.1.xml:32 +msgid "" +"<command>sss_ssh_authorizedkeys</command> acquires SSH public keys for user " +"<replaceable>USER</replaceable> and outputs them in OpenSSH authorized_keys " +"format (see the <quote>AUTHORIZED_KEYS FILE FORMAT</quote> section of " +"<citerefentry><refentrytitle>sshd</refentrytitle> " +"<manvolnum>8</manvolnum></citerefentry> for more information)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_ssh_authorizedkeys.1.xml:41 +msgid "" +"<citerefentry><refentrytitle>sshd</refentrytitle> " +"<manvolnum>8</manvolnum></citerefentry> can be configured to use " +"<command>sss_ssh_authorizedkeys</command> for public key user authentication " +"if it is compiled with support for <quote>AuthorizedKeysCommand</quote> " +"option. Please refer to the <citerefentry> " +"<refentrytitle>sshd_config</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry> man page for more details about this " +"option." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sss_ssh_authorizedkeys.1.xml:59 +#, no-wrap +msgid "" +" AuthorizedKeysCommand /usr/bin/sss_ssh_authorizedkeys\n" +" AuthorizedKeysCommandUser nobody\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_ssh_authorizedkeys.1.xml:52 +msgid "" +"If <quote>AuthorizedKeysCommand</quote> is supported, " +"<citerefentry><refentrytitle>sshd</refentrytitle> " +"<manvolnum>8</manvolnum></citerefentry> can be configured to use it by " +"putting the following directives in <citerefentry> " +"<refentrytitle>sshd_config</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry>: <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sss_ssh_authorizedkeys.1.xml:65 +msgid "KEYS FROM CERTIFICATES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss_ssh_authorizedkeys.1.xml:67 +msgid "" +"In addition to the public SSH keys for user <replaceable>USER</replaceable> " +"<command>sss_ssh_authorizedkeys</command> can return public SSH keys derived " +"from the public key of a X.509 certificate as well." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss_ssh_authorizedkeys.1.xml:73 +msgid "" +"To enable this the <quote>ssh_use_certificate_keys</quote> option must be " +"set to true (default) in the [ssh] section of " +"<filename>sssd.conf</filename>. If the user entry contains certificates (see " +"<quote>ldap_user_certificate</quote> in " +"<citerefentry><refentrytitle>sssd-ldap</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry> for details) or there is a " +"certificate in an override entry for the user (see " +"<citerefentry><refentrytitle>sss_override</refentrytitle> " +"<manvolnum>8</manvolnum></citerefentry> or " +"<citerefentry><refentrytitle>sssd-ipa</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry> for details) and the certificate is " +"valid SSSD will extract the public key from the certificate and convert it " +"into the format expected by sshd." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss_ssh_authorizedkeys.1.xml:90 +msgid "Besides <quote>ssh_use_certificate_keys</quote> the options" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss_ssh_authorizedkeys.1.xml:96 +msgid "" +"can be used to control how the certificates are validated (see " +"<citerefentry><refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry> for details)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss_ssh_authorizedkeys.1.xml:101 +msgid "" +"The validation is the benefit of using X.509 certificates instead of SSH " +"keys directly because e.g. it gives a better control of the lifetime of the " +"keys. When the ssh client is configured to use the private keys from a " +"Smartcard with the help of a PKCS#11 shared library (see " +"<citerefentry><refentrytitle>ssh</refentrytitle> " +"<manvolnum>1</manvolnum></citerefentry> for details) it might be irritating " +"that authentication is still working even if the related X.509 certificate " +"on the Smartcard is already expired because neither <command>ssh</command> " +"nor <command>sshd</command> will look at the certificate at all." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sss_ssh_authorizedkeys.1.xml:114 +msgid "" +"It has to be noted that the derived public SSH key can still be added to the " +"<filename>authorized_keys</filename> file of the user to bypass the " +"certificate validation if the <command>sshd</command> configuration permits " +"this." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_ssh_authorizedkeys.1.xml:132 +msgid "" +"Search for user public keys in SSSD domain " +"<replaceable>DOMAIN</replaceable>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_ssh_authorizedkeys.1.xml:143 +msgid "" +"In case of success, an exit value of 0 is returned. Otherwise, 1 is " +"returned." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sss_ssh_knownhosts.1.xml:10 sss_ssh_knownhosts.1.xml:15 +msgid "sss_ssh_knownhosts" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sss_ssh_knownhosts.1.xml:16 +msgid "get OpenSSH known hosts public keys" +msgstr "" + +#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> +#: sss_ssh_knownhosts.1.xml:21 +msgid "" +"<command>sss_ssh_knownhosts</command> <arg choice='opt'> " +"<replaceable>options</replaceable> </arg> <arg " +"choice='plain'><replaceable>HOST</replaceable></arg>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_ssh_knownhosts.1.xml:32 +msgid "" +"<command>sss_ssh_knownhosts</command> acquires SSH public keys for host " +"<replaceable>HOST</replaceable> and outputs them in OpenSSH known_hosts key " +"format (see the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> section of " +"<citerefentry><refentrytitle>sshd</refentrytitle> " +"<manvolnum>8</manvolnum></citerefentry> for more information)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sss_ssh_knownhosts.1.xml:47 +#, no-wrap +msgid "" +" KnownHostsCommand /usr/bin/sss_ssh_knownhosts %H\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_ssh_knownhosts.1.xml:41 +msgid "" +"<citerefentry><refentrytitle>ssh</refentrytitle> " +"<manvolnum>1</manvolnum></citerefentry> can be configured to use " +"<command>sss_ssh_knownhosts</command> for public key host authentication " +"using the <quote>KnownHostsCommand</quote> option: <placeholder " +"type=\"programlisting\" id=\"0\"/> Please refer to the <citerefentry> " +"<refentrytitle>ssh_config</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry> man page for more details about this option." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_ssh_knownhosts.1.xml:54 +msgid "This tool requires that SSSD's ssh service is enabled to work properly." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_ssh_knownhosts.1.xml:68 +msgid "" +"Search for host public keys in SSSD domain " +"<replaceable>DOMAIN</replaceable>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sss_ssh_knownhosts.1.xml:75 +msgid "<option>-o</option>,<option>--only-host-name</option>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sss_ssh_knownhosts.1.xml:79 +msgid "" +"When the keys retrieved from the backend do not include the hostname, this " +"tool will add the unmodified hostname as provided by the caller. If this " +"flag is set, only the hostname (no port number) will be added to the keys." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sss_ssh_knownhosts.1.xml:91 +msgid "KEY RETRIEVAL" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_ssh_knownhosts.1.xml:93 +msgid "" +"The key lines retrieved from the backend are expected to respect the key " +"format as decribed in the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> section " +"of <citerefentry><refentrytitle>sshd</refentrytitle> " +"<manvolnum>8</manvolnum></citerefentry>. However, returning only the keytype " +"and the key itself is tolerated, in which case, the hostname received as " +"parameter will be added before the keytype to output a correctly formatted " +"line. The hostname will be added unmodified or just the hostname (no port " +"number), depending on whether the " +"<option>-o</option>,<option>--only-host-name</option> option was provided." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sss_ssh_knownhosts.1.xml:110 +#, no-wrap +msgid "" +" [canonical.host.name]:2222 <keytype> " +"<base64-encoded key>\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_ssh_knownhosts.1.xml:105 +msgid "" +"When the SSH server is listening on a non-default port, the backend MUST " +"provide the hostname including the port number in the correct format and " +"position as part of the key line. For example, the minimal key line would " +"be: <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sss_ssh_knownhosts.1.xml:118 +msgid "" +"In case of successful execution, even if no key was found for that host or " +"if the ssh responder could not be contacted, 0 is returned. 1 is returned " +"in case of any other error." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: idmap_sss.8.xml:10 idmap_sss.8.xml:15 +msgid "idmap_sss" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: idmap_sss.8.xml:16 +msgid "SSSD's idmap_sss Backend for Winbind" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: idmap_sss.8.xml:22 +msgid "" +"The idmap_sss module provides a way to call SSSD to map UIDs/GIDs and " +"SIDs. No database is required in this case as the mapping is done by SSSD." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: idmap_sss.8.xml:29 +msgid "IDMAP OPTIONS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: idmap_sss.8.xml:33 +msgid "range = low - high" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: idmap_sss.8.xml:35 +msgid "" +"Defines the available matching UID and GID range for which the backend is " +"authoritative." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: idmap_sss.8.xml:45 +msgid "This example shows how to configure idmap_sss as the default mapping module." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><programlisting> +#: idmap_sss.8.xml:50 +#, no-wrap +msgid "" +"[global]\n" +"security = ads\n" +"workgroup = <AD-DOMAIN-SHORTNAME>\n" +"\n" +"idmap config <AD-DOMAIN-SHORTNAME> : backend = sss\n" +"idmap config <AD-DOMAIN-SHORTNAME> : range = " +"200000-2147483647\n" +"\n" +"idmap config * : backend = tdb\n" +"idmap config * : range = 100000-199999\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: idmap_sss.8.xml:62 +msgid "" +"Please replace <AD-DOMAIN-SHORTNAME> with the NetBIOS domain name of " +"the AD domain. If multiple AD domains should be used each domain needs an " +"<literal>idmap config</literal> line with <literal>backend = sss</literal> " +"and a line with a suitable <literal>range</literal>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: idmap_sss.8.xml:69 +msgid "" +"Since Winbind requires a writeable default backend and idmap_sss is " +"read-only the example includes <literal>backend = tdb</literal> as default." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssctl.8.xml:10 sssctl.8.xml:15 +msgid "sssctl" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssctl.8.xml:16 +msgid "SSSD control and status utility" +msgstr "" + +#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> +#: sssctl.8.xml:21 +msgid "" +"<command>sssctl</command> <arg " +"choice='plain'><replaceable>COMMAND</replaceable></arg> <arg choice='opt'> " +"<replaceable>options</replaceable> </arg>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssctl.8.xml:32 +msgid "" +"<command>sssctl</command> provides a simple and unified way to obtain " +"information about SSSD status, such as active server, auto-discovered " +"servers, domains and cached objects. In addition, it can manage SSSD data " +"files for troubleshooting in such a way that is safe to manipulate while " +"SSSD is running." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssctl.8.xml:43 +msgid "" +"To list all available commands run <command>sssctl</command> without any " +"parameters. To print help for selected command run <command>sssctl COMMAND " +"--help</command>." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd-session-recording.5.xml:10 sssd-session-recording.5.xml:16 +msgid "sssd-session-recording" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd-session-recording.5.xml:17 +msgid "Configuring session recording with SSSD" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-session-recording.5.xml:23 +msgid "" +"This manual page describes how to configure <citerefentry> " +"<refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " +"to work with <citerefentry> <refentrytitle>tlog-rec-session</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry>, a part of tlog package, to " +"implement user session recording on text terminals. For a detailed " +"configuration syntax reference, refer to the <quote>FILE FORMAT</quote> " +"section of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-session-recording.5.xml:41 +msgid "" +"SSSD can be set up to enable recording of everything specific users see or " +"type during their sessions on text terminals. E.g. when users log in on the " +"console, or via SSH. SSSD itself doesn't record anything, but makes sure " +"tlog-rec-session is started upon user login, so it can record according to " +"its configuration." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-session-recording.5.xml:48 +msgid "" +"For users with session recording enabled, SSSD replaces the user shell with " +"tlog-rec-session in NSS responses, and adds a variable specifying the " +"original shell to the user environment, upon PAM session setup. This way " +"tlog-rec-session can be started in place of the user shell, and know which " +"actual shell to start, once it set up the recording." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-session-recording.5.xml:60 +msgid "These options can be used to configure the session recording." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-session-recording.5.xml:178 +msgid "" +"The following snippet of sssd.conf enables session recording for users " +"\"contractor1\" and \"contractor2\", and group \"students\"." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-session-recording.5.xml:183 +#, no-wrap +msgid "" +"[session_recording]\n" +"scope = some\n" +"users = contractor1, contractor2\n" +"groups = students\n" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd-kcm.8.xml:10 sssd-kcm.8.xml:16 +msgid "sssd-kcm" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd-kcm.8.xml:17 +msgid "SSSD Kerberos Cache Manager" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:23 +msgid "" +"This manual page describes the configuration of the SSSD Kerberos Cache " +"Manager (KCM). KCM is a process that stores, tracks and manages Kerberos " +"credential caches. It originates in the Heimdal Kerberos project, although " +"the MIT Kerberos library also provides client side (more details on that " +"below) support for the KCM credential cache." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:31 +msgid "" +"In a setup where Kerberos caches are managed by KCM, the Kerberos library " +"(typically used through an application, like e.g., <citerefentry> " +"<refentrytitle>kinit</refentrytitle><manvolnum>1</manvolnum> " +"</citerefentry>, is a <quote>\"KCM client\"</quote> and the KCM daemon is " +"being referred to as a <quote>\"KCM server\"</quote>. The client and server " +"communicate over a UNIX socket." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:42 +msgid "" +"The KCM server keeps track of each credential caches's owner and performs " +"access check control based on the UID and GID of the KCM client." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:47 +msgid "The KCM credential cache has several interesting properties:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd-kcm.8.xml:51 +msgid "" +"since the process runs in userspace, it is subject to UID namespacing, " +"unlike the kernel keyring" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd-kcm.8.xml:56 +msgid "" +"unlike the kernel keyring-based cache, which is shared between all " +"containers, the KCM server is a separate process whose entry point is a UNIX " +"socket" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd-kcm.8.xml:61 +msgid "" +"the SSSD implementation stores the ccaches in a database, typically located " +"at <replaceable>/var/lib/sss/secrets</replaceable> allowing the ccaches to " +"survive KCM server restarts or machine reboots." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:67 +msgid "" +"This allows the system to use a collection-aware credential cache, yet share " +"the credential cache between some or no containers by bind-mounting the " +"socket." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:72 +msgid "" +"The KCM default client idle timeout is 5 minutes, this allows more time for " +"user interaction with command line tools such as kinit." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-kcm.8.xml:78 +msgid "USING THE KCM CREDENTIAL CACHE" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-kcm.8.xml:88 +#, no-wrap +msgid "" +"[libdefaults]\n" +" default_ccache_name = KCM:\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:80 +msgid "" +"In order to use KCM credential cache, it must be selected as the default " +"credential type in <citerefentry> " +"<refentrytitle>krb5.conf</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry>, The credentials cache name must be only <quote>KCM:</quote> " +"without any template expansions. For example: <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:93 +msgid "" +"Next, make sure the Kerberos client libraries and the KCM server must agree " +"on the UNIX socket path. By default, both use the same path " +"<replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>. To configure " +"the Kerberos library, change its <quote>kcm_socket</quote> option which is " +"described in the <citerefentry> " +"<refentrytitle>krb5.conf</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry> manual page." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-kcm.8.xml:115 +#, no-wrap +msgid "" +"systemctl start sssd-kcm.socket\n" +"systemctl enable sssd-kcm.socket\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:104 +msgid "" +"Finally, make sure the SSSD KCM server can be contacted. The KCM service is " +"typically socket-activated by <citerefentry> " +"<refentrytitle>systemd</refentrytitle> <manvolnum>1</manvolnum> " +"</citerefentry>. Unlike other SSSD services, it cannot be started by adding " +"the <quote>kcm</quote> string to the <quote>service</quote> directive. " +"<placeholder type=\"programlisting\" id=\"0\"/> Please note your " +"distribution may already configure the units for you." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-kcm.8.xml:124 +msgid "THE CREDENTIAL CACHE STORAGE" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:126 +msgid "" +"The credential caches are stored in a database, much like SSSD caches user " +"or group entries. The database is typically located at " +"<quote>/var/lib/sss/secrets</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-kcm.8.xml:133 +msgid "OBTAINING DEBUG LOGS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-kcm.8.xml:144 +#, no-wrap +msgid "" +"[kcm]\n" +"debug_level = 10\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-kcm.8.xml:149 sssd-kcm.8.xml:211 +#, no-wrap +msgid "" +"systemctl restart sssd-kcm.service\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:135 +msgid "" +"The sssd-kcm service is typically socket-activated <citerefentry> " +"<refentrytitle>systemd</refentrytitle> <manvolnum>1</manvolnum> " +"</citerefentry>. To generate debug logs, add the following either to the " +"<filename>/etc/sssd/sssd.conf</filename> file directly or as a configuration " +"snippet to <filename>/etc/sssd/conf.d/</filename> directory: <placeholder " +"type=\"programlisting\" id=\"0\"/> Then, restart the sssd-kcm service: " +"<placeholder type=\"programlisting\" id=\"1\"/> Finally, run whatever " +"use-case doesn't work for you. The KCM logs will be generated at " +"<filename>/var/log/sssd/sssd_kcm.log</filename>. It is recommended to " +"disable the debug logs when you no longer need the debugging to be enabled " +"as the sssd-kcm service can generate quite a large amount of debugging " +"information." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:159 +msgid "" +"Please note that configuration snippets are, at the moment, only processed " +"if the main configuration file at <filename>/etc/sssd/sssd.conf</filename> " +"exists at all." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-kcm.8.xml:166 +msgid "RENEWALS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-kcm.8.xml:174 +#, no-wrap +msgid "" +"tgt_renewal = true\n" +"krb5_renew_interval = 60m\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:168 +msgid "" +"The sssd-kcm service can be configured to attempt TGT renewal for renewable " +"TGTs stored in the KCM ccache. Renewals are only attempted when half of the " +"ticket lifetime has been reached. KCM Renewals are configured when the " +"following options are set in the [kcm] section: <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:179 +msgid "SSSD can also inherit krb5 options for renewals from an existing domain." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><programlisting> +#: sssd-kcm.8.xml:183 +#, no-wrap +msgid "" +"tgt_renewal = true\n" +"tgt_renewal_inherit = domain-name\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd-kcm.8.xml:191 +#, no-wrap +msgid "" +"krb5_renew_interval\n" +"krb5_renewable_lifetime\n" +"krb5_lifetime\n" +"krb5_validate\n" +"krb5_canonicalize\n" +"krb5_auth_timeout\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:187 +msgid "" +"The following krb5 options can be configured in the [kcm] section to control " +"renewal behavior, these options are described in detail below <placeholder " +"type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:204 +msgid "" +"The KCM service is configured in the <quote>kcm</quote> section of the " +"sssd.conf file. Please note that because the KCM service is typically " +"socket-activated, it is enough to just restart the <quote>sssd-kcm</quote> " +"service after changing options in the <quote>kcm</quote> section of " +"sssd.conf: <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:215 +msgid "" +"The KCM service is configured in the <quote>kcm</quote> For a detailed " +"syntax reference, refer to the <quote>FILE FORMAT</quote> section of the " +"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:223 +msgid "" +"The generic SSSD service options such as <quote>debug_level</quote> or " +"<quote>fd_limit</quote> are accepted by the kcm service. Please refer to " +"the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page for a complete list. In " +"addition, there are some KCM-specific options as well." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd-kcm.8.xml:234 +msgid "socket_path (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-kcm.8.xml:237 +msgid "The socket the KCM service will listen on." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-kcm.8.xml:240 +msgid "Default: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-kcm.8.xml:243 +msgid "" +"<phrase condition=\"have_systemd\"> Note: on platforms where systemd is " +"supported, the socket path is overwritten by the one defined in the " +"sssd-kcm.socket unit file. </phrase>" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd-kcm.8.xml:252 +msgid "max_ccaches (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-kcm.8.xml:255 +msgid "How many credential caches does the KCM database allow for all users." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-kcm.8.xml:259 +msgid "Default: 0 (unlimited, only the per-UID quota is enforced)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd-kcm.8.xml:264 +msgid "max_uid_ccaches (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-kcm.8.xml:267 +msgid "" +"How many credential caches does the KCM database allow per UID. This is " +"equivalent to <quote>with how many principals you can kinit</quote>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-kcm.8.xml:272 +msgid "Default: 64" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd-kcm.8.xml:277 +msgid "max_ccache_size (integer)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-kcm.8.xml:280 +msgid "" +"How big can a credential cache be per ccache. Each service ticket accounts " +"into this quota." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-kcm.8.xml:284 +msgid "Default: 65536" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd-kcm.8.xml:289 +msgid "tgt_renewal (bool)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-kcm.8.xml:292 +msgid "Enables TGT renewals functionality." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-kcm.8.xml:295 +msgid "Default: False (Automatic renewals disabled)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd-kcm.8.xml:300 +msgid "tgt_renewal_inherit (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-kcm.8.xml:303 +msgid "Domain to inherit krb5_* options from, for use with TGT renewals." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-kcm.8.xml:307 +msgid "Default: NULL" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-kcm.8.xml:318 +msgid "" +"<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> " +"</citerefentry>, <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry>," +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd-systemtap.5.xml:10 sssd-systemtap.5.xml:16 +msgid "sssd-systemtap" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd-systemtap.5.xml:17 +msgid "SSSD systemtap information" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-systemtap.5.xml:23 +msgid "" +"This manual page provides information about the systemtap functionality in " +"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " +"</citerefentry>." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-systemtap.5.xml:32 +msgid "" +"SystemTap Probe points have been added into various locations in SSSD code " +"to assist in troubleshooting and analyzing performance related issues." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd-systemtap.5.xml:40 +msgid "Sample SystemTap scripts are provided in /usr/share/sssd/systemtap/" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> +#: sssd-systemtap.5.xml:46 +msgid "" +"Probes and miscellaneous functions are defined in " +"/usr/share/systemtap/tapset/sssd.stp and " +"/usr/share/systemtap/tapset/sssd_functions.stp respectively." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-systemtap.5.xml:57 +msgid "PROBE POINTS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para> +#: sssd-systemtap.5.xml:59 sssd-systemtap.5.xml:367 +msgid "" +"The information below lists the probe points and arguments available in the " +"following format:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:64 +msgid "probe $name" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:67 +msgid "Description of probe point" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><programlisting> +#: sssd-systemtap.5.xml:70 +#, no-wrap +msgid "" +"variable1:datatype\n" +"variable2:datatype\n" +"variable3:datatype\n" +"...\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd-systemtap.5.xml:80 +msgid "Database Transaction Probes" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:84 +msgid "probe sssd_transaction_start" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:87 +msgid "Start of a sysdb transaction, probes the sysdb_transaction_start() function." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> +#: sssd-systemtap.5.xml:91 sssd-systemtap.5.xml:105 sssd-systemtap.5.xml:118 +#: sssd-systemtap.5.xml:131 +#, no-wrap +msgid "" +"nesting:integer\n" +"probestr:string\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:97 +msgid "probe sssd_transaction_cancel" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:100 +msgid "" +"Cancellation of a sysdb transaction, probes the sysdb_transaction_cancel() " +"function." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:111 +msgid "probe sssd_transaction_commit_before" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:114 +msgid "Probes the sysdb_transaction_commit_before() function." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:124 +msgid "probe sssd_transaction_commit_after" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:127 +msgid "Probes the sysdb_transaction_commit_after() function." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd-systemtap.5.xml:141 +msgid "LDAP Search Probes" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:145 +msgid "probe sdap_search_send" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:148 +msgid "Probes the sdap_get_generic_ext_send() function." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> +#: sssd-systemtap.5.xml:152 +#, no-wrap +msgid "" +"base:string\n" +"scope:integer\n" +"filter:string\n" +"attrs:string\n" +"probestr:string\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:161 +msgid "probe sdap_search_recv" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:164 +msgid "Probes the sdap_get_generic_ext_recv() function." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> +#: sssd-systemtap.5.xml:168 sssd-systemtap.5.xml:222 +#, no-wrap +msgid "" +"base:string\n" +"scope:integer\n" +"filter:string\n" +"probestr:string\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:176 +msgid "probe sdap_parse_entry" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:179 +msgid "" +"Probes the sdap_parse_entry() function. It is called repeatedly with every " +"received attribute." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> +#: sssd-systemtap.5.xml:184 +#, no-wrap +msgid "" +"attr:string\n" +"value:string\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:190 +msgid "probe sdap_parse_entry_done" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:193 +msgid "" +"Probes the sdap_parse_entry() function. It is called when parsing of " +"received object is finished." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:201 +msgid "probe sdap_deref_send" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:204 +msgid "Probes the sdap_deref_search_send() function." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> +#: sssd-systemtap.5.xml:208 +#, no-wrap +msgid "" +"base_dn:string\n" +"deref_attr:string\n" +"probestr:string\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:215 +msgid "probe sdap_deref_recv" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:218 +msgid "Probes the sdap_deref_search_recv() function." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd-systemtap.5.xml:234 +msgid "LDAP Account Request Probes" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:238 +msgid "probe sdap_acct_req_send" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:241 +msgid "Probes the sdap_acct_req_send() function." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> +#: sssd-systemtap.5.xml:245 sssd-systemtap.5.xml:260 +#, no-wrap +msgid "" +"entry_type:int\n" +"filter_type:int\n" +"filter_value:string\n" +"extra_value:string\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:253 +msgid "probe sdap_acct_req_recv" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:256 +msgid "Probes the sdap_acct_req_recv() function." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd-systemtap.5.xml:272 +msgid "LDAP User Search Probes" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:276 +msgid "probe sdap_search_user_send" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:279 +msgid "Probes the sdap_search_user_send() function." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> +#: sssd-systemtap.5.xml:283 sssd-systemtap.5.xml:295 sssd-systemtap.5.xml:307 +#: sssd-systemtap.5.xml:319 +#, no-wrap +msgid "" +"filter:string\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:288 +msgid "probe sdap_search_user_recv" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:291 +msgid "Probes the sdap_search_user_recv() function." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:300 +msgid "probe sdap_search_user_save_begin" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:303 +msgid "Probes the sdap_search_user_save_begin() function." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:312 +msgid "probe sdap_search_user_save_end" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:315 +msgid "Probes the sdap_search_user_save_end() function." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd-systemtap.5.xml:328 +msgid "Data Provider Request Probes" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:332 +msgid "probe dp_req_send" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:335 +msgid "A Data Provider request is submitted." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> +#: sssd-systemtap.5.xml:338 +#, no-wrap +msgid "" +"dp_req_domain:string\n" +"dp_req_name:string\n" +"dp_req_target:int\n" +"dp_req_method:int\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:346 +msgid "probe dp_req_done" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:349 +msgid "A Data Provider request is completed." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> +#: sssd-systemtap.5.xml:352 +#, no-wrap +msgid "" +"dp_req_name:string\n" +"dp_req_target:int\n" +"dp_req_method:int\n" +"dp_ret:int\n" +"dp_errorstr:string\n" +" " +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><title> +#: sssd-systemtap.5.xml:365 +msgid "MISCELLANEOUS FUNCTIONS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:372 +msgid "function acct_req_desc(entry_type)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:375 +msgid "Convert entry_type to string and return string" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:380 +msgid "" +"function sssd_acct_req_probestr(fc_name, entry_type, filter_type, " +"filter_value, extra_value)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:384 +msgid "Create probe string based on filter type" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:389 +msgid "function dp_target_str(target)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:392 +msgid "Convert target to string and return string" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:397 +msgid "function dp_method_str(target)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:400 +msgid "Convert method to string and return string" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-systemtap.5.xml:410 +msgid "SAMPLE SYSTEMTAP SCRIPTS" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-systemtap.5.xml:412 +msgid "" +"Start the SystemTap script (<command>stap " +"/usr/share/sssd/systemtap/<script_name>.stp</command>), then perform " +"an identity operation and the script will collect information from probes." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-systemtap.5.xml:418 +msgid "Provided SystemTap scripts are:" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:422 +msgid "dp_request.stp" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:425 +msgid "Monitoring of data provider request performance." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:430 +msgid "id_perf.stp" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:433 +msgid "Monitoring of <command>id</command> command performance." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:439 +msgid "ldap_perf.stp" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:442 +msgid "Monitoring of LDAP queries." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> +#: sssd-systemtap.5.xml:447 +msgid "nested_group_perf.stp" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> +#: sssd-systemtap.5.xml:450 +msgid "Performance of nested groups resolving." +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd-ldap-attributes.5.xml:10 sssd-ldap-attributes.5.xml:16 +msgid "sssd-ldap-attributes" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd-ldap-attributes.5.xml:17 +msgid "SSSD LDAP Provider: Mapping Attributes" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd-ldap-attributes.5.xml:23 +msgid "" +"This manual page describes the mapping attributes of SSSD LDAP provider " +"<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>. Refer to the <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> manual page for full details about SSSD LDAP provider " +"configuration options." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap-attributes.5.xml:38 +msgid "USER ATTRIBUTES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:42 +msgid "ldap_user_object_class (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:45 +msgid "The object class of a user entry in LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:48 +msgid "Default: posixAccount" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:54 +msgid "ldap_user_name (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:57 +msgid "The LDAP attribute that corresponds to the user's login name." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:61 +msgid "Default: uid (rfc2307, rfc2307bis and IPA), sAMAccountName (AD)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:68 +msgid "ldap_user_uid_number (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:71 +msgid "The LDAP attribute that corresponds to the user's id." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:75 +msgid "Default: uidNumber" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:81 +msgid "ldap_user_gid_number (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:84 +msgid "The LDAP attribute that corresponds to the user's primary group id." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:88 sssd-ldap-attributes.5.xml:700 +msgid "Default: gidNumber" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:94 +msgid "ldap_user_primary_group (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:97 +msgid "" +"Active Directory primary group attribute for ID-mapping. Note that this " +"attribute should only be set manually if you are running the " +"<quote>ldap</quote> provider with ID mapping." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:103 +msgid "Default: unset (LDAP), primaryGroupID (AD)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:109 +msgid "ldap_user_gecos (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:112 +msgid "The LDAP attribute that corresponds to the user's gecos field." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:116 +msgid "Default: gecos" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:122 +msgid "ldap_user_home_directory (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:125 +msgid "The LDAP attribute that contains the name of the user's home directory." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:129 +msgid "Default: homeDirectory (LDAP and IPA), unixHomeDirectory (AD)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:135 +msgid "ldap_user_shell (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:138 +msgid "The LDAP attribute that contains the path to the user's default shell." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:142 +msgid "Default: loginShell" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:148 +msgid "ldap_user_uuid (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:151 +msgid "The LDAP attribute that contains the UUID/GUID of an LDAP user object." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:155 sssd-ldap-attributes.5.xml:726 +msgid "" +"Default: not set in the general case, objectGUID for AD and ipaUniqueID for " +"IPA" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:162 +msgid "ldap_user_objectsid (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:165 +msgid "" +"The LDAP attribute that contains the objectSID of an LDAP user object. This " +"is usually only necessary for ActiveDirectory servers." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:170 sssd-ldap-attributes.5.xml:741 +msgid "Default: objectSid for ActiveDirectory, not set for other servers." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:177 +msgid "ldap_user_modify_timestamp (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:180 sssd-ldap-attributes.5.xml:751 +#: sssd-ldap-attributes.5.xml:874 +msgid "" +"The LDAP attribute that contains timestamp of the last modification of the " +"parent object." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:184 sssd-ldap-attributes.5.xml:755 +#: sssd-ldap-attributes.5.xml:881 +msgid "Default: modifyTimestamp" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:190 +msgid "ldap_user_shadow_last_change (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:193 +msgid "" +"When using ldap_pwd_policy=shadow, this parameter contains the name of an " +"LDAP attribute corresponding to its <citerefentry> " +"<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> counterpart (date of the last password change)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:203 +msgid "Default: shadowLastChange" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:209 +msgid "ldap_user_shadow_min (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:212 +msgid "" +"When using ldap_pwd_policy=shadow, this parameter contains the name of an " +"LDAP attribute corresponding to its <citerefentry> " +"<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> counterpart (minimum password age)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:221 +msgid "Default: shadowMin" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:227 +msgid "ldap_user_shadow_max (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:230 +msgid "" +"When using ldap_pwd_policy=shadow, this parameter contains the name of an " +"LDAP attribute corresponding to its <citerefentry> " +"<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> counterpart (maximum password age)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:239 +msgid "Default: shadowMax" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:245 +msgid "ldap_user_shadow_warning (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:248 +msgid "" +"When using ldap_pwd_policy=shadow, this parameter contains the name of an " +"LDAP attribute corresponding to its <citerefentry> " +"<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> counterpart (password warning period)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:258 +msgid "Default: shadowWarning" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:264 +msgid "ldap_user_shadow_inactive (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:267 +msgid "" +"When using ldap_pwd_policy=shadow, this parameter contains the name of an " +"LDAP attribute corresponding to its <citerefentry> " +"<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> counterpart (password inactivity period)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:277 +msgid "Default: shadowInactive" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:283 +msgid "ldap_user_shadow_expire (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:286 +msgid "" +"When using ldap_pwd_policy=shadow or ldap_account_expire_policy=shadow, this " +"parameter contains the name of an LDAP attribute corresponding to its " +"<citerefentry> <refentrytitle>shadow</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> counterpart (account expiration " +"date)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:296 +msgid "Default: shadowExpire" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:302 +msgid "ldap_user_krb_last_pwd_change (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:305 +msgid "" +"When using ldap_pwd_policy=mit_kerberos, this parameter contains the name of " +"an LDAP attribute storing the date and time of last password change in " +"kerberos." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:311 +msgid "Default: krbLastPwdChange" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:317 +msgid "ldap_user_krb_password_expiration (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:320 +msgid "" +"When using ldap_pwd_policy=mit_kerberos, this parameter contains the name of " +"an LDAP attribute storing the date and time when current password expires." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:326 +msgid "Default: krbPasswordExpiration" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:332 +msgid "ldap_user_ad_account_expires (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:335 +msgid "" +"When using ldap_account_expire_policy=ad, this parameter contains the name " +"of an LDAP attribute storing the expiration time of the account." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:340 +msgid "Default: accountExpires" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:346 +msgid "ldap_user_ad_user_account_control (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:349 +msgid "" +"When using ldap_account_expire_policy=ad, this parameter contains the name " +"of an LDAP attribute storing the user account control bit field." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:354 +msgid "Default: userAccountControl" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:360 +msgid "ldap_ns_account_lock (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:363 +msgid "" +"When using ldap_account_expire_policy=rhds or equivalent, this parameter " +"determines if access is allowed or not." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:368 +msgid "Default: nsAccountLock" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:374 +msgid "ldap_user_nds_login_disabled (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:377 +msgid "" +"When using ldap_account_expire_policy=nds, this attribute determines if " +"access is allowed or not." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:381 sssd-ldap-attributes.5.xml:395 +msgid "Default: loginDisabled" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:387 +msgid "ldap_user_nds_login_expiration_time (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:390 +msgid "" +"When using ldap_account_expire_policy=nds, this attribute determines until " +"which date access is granted." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:401 +msgid "ldap_user_nds_login_allowed_time_map (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:404 +msgid "" +"When using ldap_account_expire_policy=nds, this attribute determines the " +"hours of a day in a week when access is granted." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:409 +msgid "Default: loginAllowedTimeMap" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:415 +msgid "ldap_user_principal (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:418 +msgid "" +"The LDAP attribute that contains the user's Kerberos User Principal Name " +"(UPN)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:422 +msgid "Default: krbPrincipalName" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:428 +msgid "ldap_user_extra_attrs (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:431 +msgid "" +"Comma-separated list of LDAP attributes that SSSD would fetch along with the " +"usual set of user attributes." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:436 +msgid "" +"The list can either contain LDAP attribute names only, or colon-separated " +"tuples of SSSD cache attribute name and LDAP attribute name. In case only " +"LDAP attribute name is specified, the attribute is saved to the cache " +"verbatim. Using a custom SSSD attribute name might be required by " +"environments that configure several SSSD domains with different LDAP " +"schemas." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:446 +msgid "" +"Please note that several attribute names are reserved by SSSD, notably the " +"<quote>name</quote> attribute. SSSD would report an error if any of the " +"reserved attribute names is used as an extra attribute name." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:456 +msgid "ldap_user_extra_attrs = telephoneNumber" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:459 +msgid "" +"Save the <quote>telephoneNumber</quote> attribute from LDAP as " +"<quote>telephoneNumber</quote> to the cache." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:463 +msgid "ldap_user_extra_attrs = phone:telephoneNumber" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:466 +msgid "" +"Save the <quote>telephoneNumber</quote> attribute from LDAP as " +"<quote>phone</quote> to the cache." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:476 +msgid "ldap_user_ssh_public_key (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:479 +msgid "The LDAP attribute that contains the user's SSH public keys." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:483 sssd-ldap-attributes.5.xml:965 +msgid "Default: sshPublicKey" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:489 +msgid "ldap_user_fullname (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:492 +msgid "The LDAP attribute that corresponds to the user's full name." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:502 +msgid "ldap_user_member_of (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:505 +msgid "The LDAP attribute that lists the user's group memberships." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:509 sssd-ldap-attributes.5.xml:952 +msgid "Default: memberOf" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:515 +msgid "ldap_user_authorized_service (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:518 +msgid "" +"If access_provider=ldap and ldap_access_order=authorized_service, SSSD will " +"use the presence of the authorizedService attribute in the user's LDAP entry " +"to determine access privilege." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:525 +msgid "" +"An explicit deny (!svc) is resolved first. Second, SSSD searches for " +"explicit allow (svc) and finally for allow_all (*)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:530 +msgid "" +"Please note that the ldap_access_order configuration option " +"<emphasis>must</emphasis> include <quote>authorized_service</quote> in order " +"for the ldap_user_authorized_service option to work." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:537 +msgid "" +"Some distributions (such as Fedora-29+ or RHEL-8) always include the " +"<quote>systemd-user</quote> PAM service as part of the login " +"process. Therefore when using service-based access control, the " +"<quote>systemd-user</quote> service might need to be added to the list of " +"allowed services." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:545 +msgid "Default: authorizedService" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:551 +msgid "ldap_user_authorized_host (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:554 +msgid "" +"If access_provider=ldap and ldap_access_order=host, SSSD will use the " +"presence of the host attribute in the user's LDAP entry to determine access " +"privilege." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:560 +msgid "" +"An explicit deny (!host) is resolved first. Second, SSSD searches for " +"explicit allow (host) and finally for allow_all (*)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:565 +msgid "" +"Please note that the ldap_access_order configuration option " +"<emphasis>must</emphasis> include <quote>host</quote> in order for the " +"ldap_user_authorized_host option to work." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:572 +msgid "Default: host" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:578 +msgid "ldap_user_authorized_rhost (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:581 +msgid "" +"If access_provider=ldap and ldap_access_order=rhost, SSSD will use the " +"presence of the rhost attribute in the user's LDAP entry to determine access " +"privilege. Similarly to host verification process." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:588 +msgid "" +"An explicit deny (!rhost) is resolved first. Second, SSSD searches for " +"explicit allow (rhost) and finally for allow_all (*)." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:593 +msgid "" +"Please note that the ldap_access_order configuration option " +"<emphasis>must</emphasis> include <quote>rhost</quote> in order for the " +"ldap_user_authorized_rhost option to work." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:600 +msgid "Default: rhost" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:606 +msgid "ldap_user_certificate (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:609 +msgid "Name of the LDAP attribute containing the X509 certificate of the user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:613 +msgid "Default: userCertificate;binary" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:619 +msgid "ldap_user_email (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:622 +msgid "Name of the LDAP attribute containing the email address of the user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:626 +msgid "" +"Note: If an email address of a user conflicts with an email address or fully " +"qualified name of another user, then SSSD will not be able to serve those " +"users properly. This option allows users to login by (1) username, and (2) " +"e-mail address. If for some reason several users need to share the same " +"email address then set this option to a nonexistent attribute name in order " +"to disable user lookup/login by email." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:637 +msgid "Default: mail" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:642 +msgid "ldap_user_passkey (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:645 +msgid "Name of the LDAP attribute containing the passkey mapping data of the user." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:649 +msgid "Default: passkey (LDAP), ipaPassKey (IPA), altSecurityIdentities (AD)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap-attributes.5.xml:659 +msgid "GROUP ATTRIBUTES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:663 +msgid "ldap_group_object_class (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:666 +msgid "The object class of a group entry in LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:669 +msgid "Default: posixGroup" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:675 +msgid "ldap_group_name (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:678 +msgid "" +"The LDAP attribute that corresponds to the group name. In an environment " +"with nested groups, this value must be an LDAP attribute which has a unique " +"name for every group. This requirement includes non-POSIX groups in the tree " +"of nested groups." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:686 +msgid "Default: cn (rfc2307, rfc2307bis and IPA), sAMAccountName (AD)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:693 +msgid "ldap_group_gid_number (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:696 +msgid "The LDAP attribute that corresponds to the group's id." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:706 +msgid "ldap_group_member (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:709 +msgid "The LDAP attribute that contains the names of the group's members." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:713 +msgid "Default: memberuid (rfc2307) / member (rfc2307bis)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:719 +msgid "ldap_group_uuid (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:722 +msgid "The LDAP attribute that contains the UUID/GUID of an LDAP group object." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:733 +msgid "ldap_group_objectsid (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:736 +msgid "" +"The LDAP attribute that contains the objectSID of an LDAP group object. This " +"is usually only necessary for ActiveDirectory servers." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:748 +msgid "ldap_group_modify_timestamp (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:761 +msgid "ldap_group_type (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:764 +msgid "" +"The LDAP attribute that contains an integer value indicating the type of the " +"group and maybe other flags." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:769 +msgid "" +"This attribute is currently only used by the AD provider to determine if a " +"group is a domain local groups and has to be filtered out for trusted " +"domains." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:775 +msgid "Default: groupType in the AD provider, otherwise not set" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:782 +msgid "ldap_group_external_member (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:785 +msgid "" +"The LDAP attribute that references group members that are defined in an " +"external domain. At the moment, only IPA's external members are supported." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:791 +msgid "Default: ipaExternalMember in the IPA provider, otherwise unset." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap-attributes.5.xml:801 +msgid "NETGROUP ATTRIBUTES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:805 +msgid "ldap_netgroup_object_class (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:808 +msgid "The object class of a netgroup entry in LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:811 +msgid "In IPA provider, ipa_netgroup_object_class should be used instead." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:815 +msgid "Default: nisNetgroup" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:821 +msgid "ldap_netgroup_name (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:824 +msgid "The LDAP attribute that corresponds to the netgroup name." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:828 +msgid "In IPA provider, ipa_netgroup_name should be used instead." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:838 +msgid "ldap_netgroup_member (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:841 +msgid "The LDAP attribute that contains the names of the netgroup's members." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:845 +msgid "In IPA provider, ipa_netgroup_member should be used instead." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:849 +msgid "Default: memberNisNetgroup" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:855 +msgid "ldap_netgroup_triple (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:858 +msgid "The LDAP attribute that contains the (host, user, domain) netgroup triples." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:862 sssd-ldap-attributes.5.xml:878 +msgid "This option is not available in IPA provider." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:865 +msgid "Default: nisNetgroupTriple" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:871 +msgid "ldap_netgroup_modify_timestamp (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap-attributes.5.xml:890 +msgid "HOST ATTRIBUTES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:894 +msgid "ldap_host_object_class (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:897 +msgid "The object class of a host entry in LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:997 +msgid "Default: ipService" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:906 +msgid "ldap_host_name (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:909 sssd-ldap-attributes.5.xml:935 +msgid "The LDAP attribute that corresponds to the host's name." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:919 +msgid "ldap_host_fqdn (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:922 +msgid "" +"The LDAP attribute that corresponds to the host's fully-qualified domain " +"name." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:926 +msgid "Default: fqdn" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:932 +msgid "ldap_host_serverhostname (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:939 +msgid "Default: serverHostname" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:945 +msgid "ldap_host_member_of (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:948 +msgid "The LDAP attribute that lists the host's group memberships." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:958 +msgid "ldap_host_ssh_public_key (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:961 +msgid "The LDAP attribute that contains the host's SSH public keys." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:971 +msgid "ldap_host_uuid (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:974 +msgid "The LDAP attribute that contains the UUID/GUID of an LDAP host object." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap-attributes.5.xml:987 +msgid "SERVICE ATTRIBUTES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:991 +msgid "ldap_service_object_class (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:994 +msgid "The object class of a service entry in LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1003 +msgid "ldap_service_name (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1006 +msgid "" +"The LDAP attribute that contains the name of service attributes and their " +"aliases." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1016 +msgid "ldap_service_port (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1019 +msgid "The LDAP attribute that contains the port managed by this service." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1023 +msgid "Default: ipServicePort" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1029 +msgid "ldap_service_proto (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1032 +msgid "The LDAP attribute that contains the protocols understood by this service." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1036 +msgid "Default: ipServiceProtocol" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap-attributes.5.xml:1045 +msgid "SUDO ATTRIBUTES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1049 +msgid "ldap_sudorule_object_class (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1052 +msgid "The object class of a sudo rule entry in LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1055 +msgid "Default: sudoRole" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1061 +msgid "ldap_sudorule_name (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1064 +msgid "The LDAP attribute that corresponds to the sudo rule name." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1074 +msgid "ldap_sudorule_command (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1077 +msgid "The LDAP attribute that corresponds to the command name." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1081 +msgid "Default: sudoCommand" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1087 +msgid "ldap_sudorule_host (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1090 +msgid "" +"The LDAP attribute that corresponds to the host name (or host IP address, " +"host IP network, or host netgroup)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1095 +msgid "Default: sudoHost" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1101 +msgid "ldap_sudorule_user (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1104 +msgid "" +"The LDAP attribute that corresponds to the user name (or UID, group name or " +"user's netgroup)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1108 +msgid "Default: sudoUser" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1114 +msgid "ldap_sudorule_option (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1117 +msgid "The LDAP attribute that corresponds to the sudo options." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1121 +msgid "Default: sudoOption" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1127 +msgid "ldap_sudorule_runasuser (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1130 +msgid "" +"The LDAP attribute that corresponds to the user name that commands may be " +"run as." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1134 +msgid "Default: sudoRunAsUser" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1140 +msgid "ldap_sudorule_runasgroup (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1143 +msgid "" +"The LDAP attribute that corresponds to the group name or group GID that " +"commands may be run as." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1147 +msgid "Default: sudoRunAsGroup" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1153 +msgid "ldap_sudorule_notbefore (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1156 +msgid "" +"The LDAP attribute that corresponds to the start date/time for when the sudo " +"rule is valid." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1160 +msgid "Default: sudoNotBefore" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1166 +msgid "ldap_sudorule_notafter (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1169 +msgid "" +"The LDAP attribute that corresponds to the expiration date/time, after which " +"the sudo rule will no longer be valid." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1174 +msgid "Default: sudoNotAfter" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1180 +msgid "ldap_sudorule_order (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1183 +msgid "The LDAP attribute that corresponds to the ordering index of the rule." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1187 +msgid "Default: sudoOrder" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap-attributes.5.xml:1196 +msgid "AUTOFS ATTRIBUTES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap-attributes.5.xml:1203 +msgid "IP HOST ATTRIBUTES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1207 +msgid "ldap_iphost_object_class (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1210 +msgid "The object class of an iphost entry in LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1213 +msgid "Default: ipHost" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1219 +msgid "ldap_iphost_name (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1222 +msgid "" +"The LDAP attribute that contains the name of the IP host attributes and " +"their aliases." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1232 +msgid "ldap_iphost_number (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1235 +msgid "The LDAP attribute that contains the IP host address." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1239 +msgid "Default: ipHostNumber" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap-attributes.5.xml:1248 +msgid "IP NETWORK ATTRIBUTES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1252 +msgid "ldap_ipnetwork_object_class (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1255 +msgid "The object class of an ipnetwork entry in LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1258 +msgid "Default: ipNetwork" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1264 +msgid "ldap_ipnetwork_name (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1267 +msgid "" +"The LDAP attribute that contains the name of the IP network attributes and " +"their aliases." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1277 +msgid "ldap_ipnetwork_number (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1280 +msgid "The LDAP attribute that contains the IP network address." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1284 +msgid "Default: ipNetworkNumber" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd-ldap-attributes.5.xml:1293 +msgid "SUBID ATTRIBUTES" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1297 +msgid "ldap_subuid_object_class (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1300 +msgid "The object class of an subid entry in LDAP." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1303 +msgid "Default: subordinateIdEntry" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1309 +msgid "ldap_subuid_count (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1312 +msgid "Subordinate user ID count (range size)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1315 +msgid "Default: subUidCount" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1321 +msgid "ldap_subgid_count (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1324 +msgid "Subordinate group ID count (range size)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1327 +msgid "Default: subGidCount" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1333 +msgid "ldap_subuid_number (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1336 +msgid "Numerical subordinate user ID (range start value)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1339 +msgid "Default: subUidNumber" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1345 +msgid "ldap_subgid_number (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1348 +msgid "Numerical subordinate group ID (range start value)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1351 +msgid "Default: subGidNumber" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> +#: sssd-ldap-attributes.5.xml:1357 +msgid "ldap_subid_range_owner (string)" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1360 +msgid "Owner of an entry" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> +#: sssd-ldap-attributes.5.xml:1363 +msgid "Default: subidRangeOwner" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refname> +#: sssd_krb5_localauth_plugin.8.xml:10 sssd_krb5_localauth_plugin.8.xml:15 +msgid "sssd_krb5_localauth_plugin" +msgstr "" + +#. type: Content of: <reference><refentry><refnamediv><refpurpose> +#: sssd_krb5_localauth_plugin.8.xml:16 +msgid "Kerberos local authorization plugin" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:22 +msgid "" +"The Kerberos local authorization plugin " +"<command>sssd_krb5_localauth_plugin</command> is used by libkrb5 to either " +"find the local name for a given Kerberos principal or to check if a given " +"local name and a given Kerberos principal relate to each other." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:29 +msgid "" +"SSSD handles the local names for users from a remote source and can read the " +"Kerberos user principal name from the remote source as well. With this " +"information SSSD can easily handle the mappings mentioned above even if the " +"local name and the Kerberos principal differ considerably." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:36 +msgid "" +"Additionally with the information read from the remote source SSSD can help " +"to prevent unexpected or unwanted mappings in case the user part of the " +"Kerberos principal accidentally corresponds to a local name of a different " +"user. By default libkrb5 might just strip the realm part of the Kerberos " +"principal to get the local name which would lead to wrong mappings in this " +"case." +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><title> +#: sssd_krb5_localauth_plugin.8.xml:46 +msgid "CONFIGURATION" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para><programlisting> +#: sssd_krb5_localauth_plugin.8.xml:56 +#, no-wrap +msgid "" +"[plugins]\n" +" localauth = {\n" +" module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" +" }\n" +msgstr "" + +#. type: Content of: <reference><refentry><refsect1><para> +#: sssd_krb5_localauth_plugin.8.xml:48 +msgid "" +"The Kerberos local authorization plugin must be enabled explicitly in the " +"Kerberos configuration, see <citerefentry> " +"<refentrytitle>krb5.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry>. SSSD will create a config snippet with the content like " +"e.g. <placeholder type=\"programlisting\" id=\"0\"/> automatically in the " +"SSSD's public Kerberos configuration snippet directory. If this directory is " +"included in the local Kerberos configuration the plugin will be enabled " +"automatically." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><term> +#: include/autofs_attributes.xml:3 +msgid "ldap_autofs_map_object_class (string)" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/autofs_attributes.xml:6 +msgid "The object class of an automount map entry in LDAP." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/autofs_attributes.xml:9 +msgid "Default: nisMap (rfc2307, autofs_provider=ad), otherwise automountMap" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><term> +#: include/autofs_attributes.xml:16 +msgid "ldap_autofs_map_name (string)" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/autofs_attributes.xml:19 +msgid "The name of an automount map entry in LDAP." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/autofs_attributes.xml:22 +msgid "" +"Default: nisMapName (rfc2307, autofs_provider=ad), otherwise " +"automountMapName" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><term> +#: include/autofs_attributes.xml:29 +msgid "ldap_autofs_entry_object_class (string)" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/autofs_attributes.xml:32 +msgid "" +"The object class of an automount entry in LDAP. The entry usually " +"corresponds to a mount point." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/autofs_attributes.xml:37 +msgid "Default: nisObject (rfc2307, autofs_provider=ad), otherwise automount" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><term> +#: include/autofs_attributes.xml:44 +msgid "ldap_autofs_entry_key (string)" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/autofs_attributes.xml:47 include/autofs_attributes.xml:61 +msgid "" +"The key of an automount entry in LDAP. The entry usually corresponds to a " +"mount point." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/autofs_attributes.xml:51 +msgid "Default: cn (rfc2307, autofs_provider=ad), otherwise automountKey" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><term> +#: include/autofs_attributes.xml:58 +msgid "ldap_autofs_entry_value (string)" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/autofs_attributes.xml:65 +msgid "" +"Default: nisMapEntry (rfc2307, autofs_provider=ad), otherwise " +"automountInformation" +msgstr "" + +#. type: Content of: <refsect1><title> +#: include/service_discovery.xml:2 +msgid "SERVICE DISCOVERY" +msgstr "" + +#. type: Content of: <refsect1><para> +#: include/service_discovery.xml:4 +msgid "" +"The service discovery feature allows back ends to automatically find the " +"appropriate servers to connect to using a special DNS query. This feature is " +"not supported for backup servers." +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/service_discovery.xml:9 include/ldap_id_mapping.xml:99 +msgid "Configuration" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/service_discovery.xml:11 +msgid "" +"If no servers are specified, the back end automatically uses service " +"discovery to try to find a server. Optionally, the user may choose to use " +"both fixed server addresses and service discovery by inserting a special " +"keyword, <quote>_srv_</quote>, in the list of servers. The order of " +"preference is maintained. This feature is useful if, for example, the user " +"prefers to use service discovery whenever possible, and fall back to a " +"specific server when no servers can be discovered using DNS." +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/service_discovery.xml:23 +msgid "The domain name" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/service_discovery.xml:25 +msgid "" +"Please refer to the <quote>dns_discovery_domain</quote> parameter in the " +"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> manual page for more details." +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/service_discovery.xml:35 +msgid "The protocol" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/service_discovery.xml:37 +msgid "" +"The queries usually specify _tcp as the protocol. Exceptions are documented " +"in respective option description." +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/service_discovery.xml:42 +msgid "See Also" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/service_discovery.xml:44 +msgid "For more information on the service discovery mechanism, refer to RFC 2782." +msgstr "" + +#. type: Content of: <refentryinfo> +#: include/upstream.xml:2 +msgid "" +"<productname>SSSD</productname> <orgname>The SSSD upstream - " +"https://github.com/SSSD/sssd/</orgname>" +msgstr "" + +#. type: Content of: outside any tag (error?) +#: include/upstream.xml:1 +msgid "<placeholder type=\"refentryinfo\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <refsect1><title> +#: include/failover.xml:2 +msgid "FAILOVER" +msgstr "" + +#. type: Content of: <refsect1><para> +#: include/failover.xml:4 +msgid "" +"The failover feature allows back ends to automatically switch to a different " +"server if the current server fails." +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/failover.xml:8 +msgid "Failover Syntax" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/failover.xml:10 +msgid "" +"The list of servers is given as a comma-separated list; any number of spaces " +"is allowed around the comma. The servers are listed in order of " +"preference. The list can contain any number of servers." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/failover.xml:16 +msgid "" +"For each failover-enabled config option, two variants exist: " +"<emphasis>primary</emphasis> and <emphasis>backup</emphasis>. The idea is " +"that servers in the primary list are preferred and backup servers are only " +"searched if no primary servers can be reached. If a backup server is " +"selected, a timeout of 31 seconds is set. After this timeout SSSD will " +"periodically try to reconnect to one of the primary servers. If it succeeds, " +"it will replace the current active (backup) server." +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/failover.xml:27 +msgid "The Failover Mechanism" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/failover.xml:29 +msgid "" +"The failover mechanism distinguishes between a machine and a service. The " +"back end first tries to resolve the hostname of a given machine; if this " +"resolution attempt fails, the machine is considered offline. No further " +"attempts are made to connect to this machine for any other service. If the " +"resolution attempt succeeds, the back end tries to connect to a service on " +"this machine. If the service connection attempt fails, then only this " +"particular service is considered offline and the back end automatically " +"switches over to the next service. The machine is still considered online " +"and might still be tried for another service." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/failover.xml:42 +msgid "" +"Further connection attempts are made to machines or services marked as " +"offline after a specified period of time; this is currently hard coded to 30 " +"seconds." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/failover.xml:47 +msgid "" +"If there are no more machines to try, the back end as a whole switches to " +"offline mode, and then attempts to reconnect every 30 seconds." +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/failover.xml:53 +msgid "Failover time outs and tuning" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/failover.xml:55 +msgid "" +"Resolving a server to connect to can be as simple as running a single DNS " +"query or can involve several steps, such as finding the correct site or " +"trying out multiple host names in case some of the configured servers are " +"not reachable. The more complex scenarios can take some time and SSSD needs " +"to balance between providing enough time to finish the resolution process " +"but on the other hand, not trying for too long before falling back to " +"offline mode. If the SSSD debug logs show that the server resolution is " +"timing out before a live server is contacted, you can consider changing the " +"time outs." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><term> +#: include/failover.xml:76 +msgid "dns_resolver_server_timeout" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: include/failover.xml:80 +msgid "" +"Time in milliseconds that sets how long would SSSD talk to a single DNS " +"server before trying next one." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><term> +#: include/failover.xml:90 +msgid "dns_resolver_op_timeout" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: include/failover.xml:94 +msgid "" +"Time in seconds to tell how long would SSSD try to resolve single DNS query " +"(e.g. resolution of a hostname or an SRV record) before trying the next " +"hostname or discovery domain." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><term> +#: include/failover.xml:106 +msgid "dns_resolver_timeout" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> +#: include/failover.xml:110 +msgid "" +"How long would SSSD try to resolve a failover service. This service " +"resolution internally might include several steps, such as resolving DNS SRV " +"queries or locating the site." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/failover.xml:67 +msgid "" +"This section lists the available tunables. Please refer to their description " +"in the <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry>, manual page. <placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/failover.xml:123 +msgid "" +"For LDAP-based providers, the resolve operation is performed as part of an " +"LDAP connection operation. Therefore, also the " +"<quote>ldap_opt_timeout</quote> timeout should be set to a larger value than " +"<quote>dns_resolver_timeout</quote> which in turn should be set to a larger " +"value than <quote>dns_resolver_op_timeout</quote> which should be larger " +"than <quote>dns_resolver_server_timeout</quote>." +msgstr "" + +#. type: Content of: <refsect1><title> +#: include/ldap_id_mapping.xml:2 +msgid "ID MAPPING" +msgstr "" + +#. type: Content of: <refsect1><para> +#: include/ldap_id_mapping.xml:4 +msgid "" +"The ID-mapping feature allows SSSD to act as a client of Active Directory " +"without requiring administrators to extend user attributes to support POSIX " +"attributes for user and group identifiers." +msgstr "" + +#. type: Content of: <refsect1><para> +#: include/ldap_id_mapping.xml:9 +msgid "" +"NOTE: When ID-mapping is enabled, the uidNumber and gidNumber attributes are " +"ignored. This is to avoid the possibility of conflicts between " +"automatically-assigned and manually-assigned values. If you need to use " +"manually-assigned values, ALL values must be manually-assigned." +msgstr "" + +#. type: Content of: <refsect1><para> +#: include/ldap_id_mapping.xml:16 +msgid "" +"Please note that changing the ID mapping related configuration options will " +"cause user and group IDs to change. At the moment, SSSD does not support " +"changing IDs, so the SSSD database must be removed. Because cached passwords " +"are also stored in the database, removing the database should only be " +"performed while the authentication servers are reachable, otherwise users " +"might get locked out. In order to cache the password, an authentication must " +"be performed. It is not sufficient to use <citerefentry> " +"<refentrytitle>sss_cache</refentrytitle> <manvolnum>8</manvolnum> " +"</citerefentry> to remove the database, rather the process consists of:" +msgstr "" + +#. type: Content of: <refsect1><para><itemizedlist><listitem><para> +#: include/ldap_id_mapping.xml:33 +msgid "Making sure the remote servers are reachable" +msgstr "" + +#. type: Content of: <refsect1><para><itemizedlist><listitem><para> +#: include/ldap_id_mapping.xml:38 +msgid "Stopping the SSSD service" +msgstr "" + +#. type: Content of: <refsect1><para><itemizedlist><listitem><para> +#: include/ldap_id_mapping.xml:43 +msgid "Removing the database" +msgstr "" + +#. type: Content of: <refsect1><para><itemizedlist><listitem><para> +#: include/ldap_id_mapping.xml:48 +msgid "Starting the SSSD service" +msgstr "" + +#. type: Content of: <refsect1><para> +#: include/ldap_id_mapping.xml:52 +msgid "" +"Moreover, as the change of IDs might necessitate the adjustment of other " +"system properties such as file and directory ownership, it's advisable to " +"plan ahead and test the ID mapping configuration thoroughly." +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/ldap_id_mapping.xml:59 +msgid "Mapping Algorithm" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/ldap_id_mapping.xml:61 +msgid "" +"Active Directory provides an objectSID for every user and group object in " +"the directory. This objectSID can be broken up into components that " +"represent the Active Directory domain identity and the relative identifier " +"(RID) of the user or group object." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/ldap_id_mapping.xml:67 +msgid "" +"The SSSD ID-mapping algorithm takes a range of available UIDs and divides it " +"into equally-sized component sections - called \"slices\". Each slice " +"represents the space available to an Active Directory domain." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/ldap_id_mapping.xml:73 +msgid "" +"When a user or group entry for a particular domain is encountered for the " +"first time, the SSSD allocates one of the available slices for that " +"domain. In order to make this slice-assignment repeatable on different " +"client machines, we select the slice based on the following algorithm:" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/ldap_id_mapping.xml:80 +msgid "" +"The SID string is passed through the murmurhash3 algorithm to convert it to " +"a 32-bit hashed value. We then take the modulus of this value with the total " +"number of available slices to pick the slice." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/ldap_id_mapping.xml:86 +msgid "" +"NOTE: It is possible to encounter collisions in the hash and subsequent " +"modulus. In these situations, we will select the next available slice, but " +"it may not be possible to reproduce the same exact set of slices on other " +"machines (since the order that they are encountered will determine their " +"slice). In this situation, it is recommended to either switch to using " +"explicit POSIX attributes in Active Directory (disabling ID-mapping) or " +"configure a default domain to guarantee that at least one is always " +"consistent. See <quote>Configuration</quote> for details." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/ldap_id_mapping.xml:101 +msgid "Minimum configuration (in the <quote>[domain/DOMAINNAME]</quote> section):" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><programlisting> +#: include/ldap_id_mapping.xml:106 +#, no-wrap +msgid "" +"ldap_id_mapping = True\n" +"ldap_schema = ad\n" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/ldap_id_mapping.xml:111 +msgid "" +"The default configuration results in configuring 10,000 slices, each capable " +"of holding up to 200,000 IDs, starting from 200,000 and going up to " +"2,000,200,000. This should be sufficient for most deployments." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><title> +#: include/ldap_id_mapping.xml:117 +msgid "Advanced Configuration" +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> +#: include/ldap_id_mapping.xml:120 +msgid "ldap_idmap_range_min (integer)" +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:123 +msgid "" +"Specifies the lower (inclusive) bound of the range of POSIX IDs to use for " +"mapping Active Directory user and group SIDs. It is the first POSIX ID which " +"can be used for the mapping." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:129 +msgid "" +"NOTE: This option is different from <quote>min_id</quote> in that " +"<quote>min_id</quote> acts to filter the output of requests to this domain, " +"whereas this option controls the range of ID assignment. This is a subtle " +"distinction, but the good general advice would be to have " +"<quote>min_id</quote> be less-than or equal to " +"<quote>ldap_idmap_range_min</quote>" +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> +#: include/ldap_id_mapping.xml:144 +msgid "ldap_idmap_range_max (integer)" +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:147 +msgid "" +"Specifies the upper (exclusive) bound of the range of POSIX IDs to use for " +"mapping Active Directory user and group SIDs. It is the first POSIX ID which " +"cannot be used for the mapping anymore, i.e. one larger than the last one " +"which can be used for the mapping." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:155 +msgid "" +"NOTE: This option is different from <quote>max_id</quote> in that " +"<quote>max_id</quote> acts to filter the output of requests to this domain, " +"whereas this option controls the range of ID assignment. This is a subtle " +"distinction, but the good general advice would be to have " +"<quote>max_id</quote> be greater-than or equal to " +"<quote>ldap_idmap_range_max</quote>" +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> +#: include/ldap_id_mapping.xml:170 +msgid "ldap_idmap_range_size (integer)" +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:173 +msgid "" +"Specifies the number of IDs available for each slice. If the range size " +"does not divide evenly into the min and max values, it will create as many " +"complete slices as it can." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:179 +msgid "" +"NOTE: The value of this option must be at least as large as the highest user " +"RID planned for use on the Active Directory server. User lookups and login " +"will fail for any user whose RID is greater than this value." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:185 +msgid "" +"For example, if your most recently-added Active Directory user has " +"objectSid=S-1-5-21-2153326666-2176343378-3404031434-1107, " +"<quote>ldap_idmap_range_size</quote> must be at least 1108 as range size is " +"equal to maximal RID minus minimal RID plus one (e.g. 1108 = 1107 - 0 + 1)." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:192 +msgid "" +"It is important to plan ahead for future expansion, as changing this value " +"will result in changing all of the ID mappings on the system, leading to " +"users with different local IDs than they previously had." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> +#: include/ldap_id_mapping.xml:202 +msgid "ldap_idmap_default_domain_sid (string)" +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:205 +msgid "" +"Specify the domain SID of the default domain. This will guarantee that this " +"domain will always be assigned to slice zero in the ID map, bypassing the " +"murmurhash algorithm described above." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> +#: include/ldap_id_mapping.xml:216 +msgid "ldap_idmap_default_domain (string)" +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:219 +msgid "Specify the name of the default domain." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> +#: include/ldap_id_mapping.xml:227 +msgid "ldap_idmap_autorid_compat (boolean)" +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:230 +msgid "" +"Changes the behavior of the ID-mapping algorithm to behave more similarly to " +"winbind's <quote>idmap_autorid</quote> algorithm." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:235 +msgid "" +"When this option is configured, domains will be allocated starting with " +"slice zero and increasing monotonically with each additional domain." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:240 +msgid "" +"NOTE: This algorithm is non-deterministic (it depends on the order that " +"users and groups are requested). If this mode is required for compatibility " +"with machines running winbind, it is recommended to also use the " +"<quote>ldap_idmap_default_domain_sid</quote> option to guarantee that at " +"least one domain is consistently allocated to slice zero." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> +#: include/ldap_id_mapping.xml:255 +msgid "ldap_idmap_helper_table_size (integer)" +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:258 +msgid "" +"Maximal number of secondary slices that is tried when performing mapping " +"from UNIX id to SID." +msgstr "" + +#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> +#: include/ldap_id_mapping.xml:262 +msgid "" +"Note: Additional secondary slices might be generated when SID is being " +"mapped to UNIX id and RID part of SID is out of range for secondary slices " +"generated so far. If value of ldap_idmap_helper_table_size is equal to 0 " +"then no additional secondary slices are generated." +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/ldap_id_mapping.xml:279 +msgid "Well-Known SIDs" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/ldap_id_mapping.xml:281 +msgid "" +"SSSD supports to look up the names of Well-Known SIDs, i.e. SIDs with a " +"special hardcoded meaning. Since the generic users and groups related to " +"those Well-Known SIDs have no equivalent in a Linux/UNIX environment no " +"POSIX IDs are available for those objects." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/ldap_id_mapping.xml:287 +msgid "" +"The SID name space is organized in authorities which can be seen as " +"different domains. The authorities for the Well-Known SIDs are" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> +#: include/ldap_id_mapping.xml:290 +msgid "Null Authority" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> +#: include/ldap_id_mapping.xml:291 +msgid "World Authority" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> +#: include/ldap_id_mapping.xml:292 +msgid "Local Authority" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> +#: include/ldap_id_mapping.xml:293 +msgid "Creator Authority" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> +#: include/ldap_id_mapping.xml:294 +msgid "Mandatory Label Authority" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> +#: include/ldap_id_mapping.xml:295 +msgid "Authentication Authority" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> +#: include/ldap_id_mapping.xml:296 +msgid "NT Authority" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> +#: include/ldap_id_mapping.xml:297 +msgid "Built-in" +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/ldap_id_mapping.xml:299 +msgid "" +"The capitalized version of these names are used as domain names when " +"returning the fully qualified name of a Well-Known SID." +msgstr "" + +#. type: Content of: <refsect1><refsect2><para> +#: include/ldap_id_mapping.xml:303 +msgid "" +"Since some utilities allow to modify SID based access control information " +"with the help of a name instead of using the SID directly SSSD supports to " +"look up the SID by the name as well. To avoid collisions only the fully " +"qualified names can be used to look up Well-Known SIDs. As a result the " +"domain names <quote>NULL AUTHORITY</quote>, <quote>WORLD AUTHORITY</quote>, " +"<quote>LOCAL AUTHORITY</quote>, <quote>CREATOR AUTHORITY</quote>, " +"<quote>MANDATORY LABEL AUTHORITY</quote>, <quote>AUTHENTICATION " +"AUTHORITY</quote>, <quote>NT AUTHORITY</quote> and <quote>BUILTIN</quote> " +"should not be used as domain names in <filename>sssd.conf</filename>." +msgstr "" + +#. type: Content of: <varlistentry><term> +#: include/param_help.xml:3 +msgid "<option>-?</option>,<option>--help</option>" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para> +#: include/param_help.xml:7 include/param_help_py.xml:7 +msgid "Display help message and exit." +msgstr "" + +#. type: Content of: <varlistentry><term> +#: include/param_help_py.xml:3 +msgid "<option>-h</option>,<option>--help</option>" +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:3 include/debug_levels_tools.xml:3 +msgid "" +"SSSD supports two representations for specifying the debug level. The " +"simplest is to specify a decimal value from 0-9, which represents enabling " +"that level and all lower-level debug messages. The more comprehensive option " +"is to specify a hexadecimal bitmask to enable or disable specific levels " +"(such as if you wish to suppress a level)." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:10 +msgid "" +"Please note that each SSSD service logs into its own log file. Also please " +"note that enabling <quote>debug_level</quote> in the <quote>[sssd]</quote> " +"section only enables debugging just for the sssd process itself, not for the " +"responder or provider processes. The <quote>debug_level</quote> parameter " +"should be added to all sections that you wish to produce debug logs from." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:18 +msgid "" +"In addition to changing the log level in the config file using the " +"<quote>debug_level</quote> parameter, which is persistent, but requires SSSD " +"restart, it is also possible to change the debug level on the fly using the " +"<citerefentry> <refentrytitle>sss_debuglevel</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> tool." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:29 include/debug_levels_tools.xml:10 +msgid "Currently supported debug levels:" +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:32 include/debug_levels_tools.xml:13 +msgid "" +"<emphasis>0</emphasis>, <emphasis>0x0010</emphasis>: Fatal " +"failures. Anything that would prevent SSSD from starting up or causes it to " +"cease running." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:38 include/debug_levels_tools.xml:19 +msgid "" +"<emphasis>1</emphasis>, <emphasis>0x0020</emphasis>: Critical failures. An " +"error that doesn't kill SSSD, but one that indicates that at least one major " +"feature is not going to work properly." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:45 include/debug_levels_tools.xml:26 +msgid "" +"<emphasis>2</emphasis>, <emphasis>0x0040</emphasis>: Serious failures. An " +"error announcing that a particular request or operation has failed." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:50 include/debug_levels_tools.xml:31 +msgid "" +"<emphasis>3</emphasis>, <emphasis>0x0080</emphasis>: Minor failures. These " +"are the errors that would percolate down to cause the operation failure of " +"2." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:55 include/debug_levels_tools.xml:36 +msgid "<emphasis>4</emphasis>, <emphasis>0x0100</emphasis>: Configuration settings." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:59 include/debug_levels_tools.xml:40 +msgid "<emphasis>5</emphasis>, <emphasis>0x0200</emphasis>: Function data." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:63 include/debug_levels_tools.xml:44 +msgid "" +"<emphasis>6</emphasis>, <emphasis>0x0400</emphasis>: Trace messages for " +"operation functions." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:67 include/debug_levels_tools.xml:48 +msgid "" +"<emphasis>7</emphasis>, <emphasis>0x1000</emphasis>: Trace messages for " +"internal control functions." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:72 include/debug_levels_tools.xml:53 +msgid "" +"<emphasis>8</emphasis>, <emphasis>0x2000</emphasis>: Contents of " +"function-internal variables that may be interesting." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:77 include/debug_levels_tools.xml:58 +msgid "" +"<emphasis>9</emphasis>, <emphasis>0x4000</emphasis>: Extremely low-level " +"tracing information." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:81 +msgid "" +"<emphasis>9</emphasis>, <emphasis>0x20000</emphasis>: Performance and " +"statistical data, please note that due to the way requests are processed " +"internally the logged execution time of a request might be longer than it " +"actually was." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:88 include/debug_levels_tools.xml:62 +msgid "" +"<emphasis>10</emphasis>, <emphasis>0x10000</emphasis>: Even more low-level " +"libldb tracing information. Almost never really required." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:93 include/debug_levels_tools.xml:67 +msgid "" +"To log required bitmask debug levels, simply add their numbers together as " +"shown in following examples:" +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:97 include/debug_levels_tools.xml:71 +msgid "" +"<emphasis>Example</emphasis>: To log fatal failures, critical failures, " +"serious failures and function data use 0x0270." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:101 include/debug_levels_tools.xml:75 +msgid "" +"<emphasis>Example</emphasis>: To log fatal failures, configuration settings, " +"function data, trace messages for internal control functions use 0x1310." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:106 include/debug_levels_tools.xml:80 +msgid "" +"<emphasis>Note</emphasis>: The bitmask format of debug levels was introduced " +"in 1.7.0." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/debug_levels.xml:110 include/debug_levels_tools.xml:84 +msgid "" +"<emphasis>Default</emphasis>: 0x0070 (i.e. fatal, critical and serious " +"failures; corresponds to setting 2 in decimal notation)" +msgstr "" + +#. type: Content of: <refsect1><title> +#: include/local.xml:2 +msgid "THE LOCAL DOMAIN" +msgstr "" + +#. type: Content of: <refsect1><para> +#: include/local.xml:4 +msgid "" +"In order to function correctly, a domain with " +"<quote>id_provider=local</quote> must be created and the SSSD must be " +"running." +msgstr "" + +#. type: Content of: <refsect1><para> +#: include/local.xml:9 +msgid "" +"The administrator might want to use the SSSD local users instead of " +"traditional UNIX users in cases where the group nesting (see <citerefentry> " +"<refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</manvolnum> " +"</citerefentry>) is needed. The local users are also useful for testing and " +"development of the SSSD without having to deploy a full remote server. The " +"<command>sss_user*</command> and <command>sss_group*</command> tools use a " +"local LDB storage to store users and groups." +msgstr "" + +#. type: Content of: <refsect1><para> +#: include/seealso.xml:4 +msgid "" +"<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> " +"</citerefentry>, <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry>, <citerefentry> " +"<refentrytitle>sssd-ldap</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry>, <citerefentry> " +"<refentrytitle>sssd-ldap-attributes</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry>, <citerefentry> " +"<refentrytitle>sssd-krb5</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry>, <citerefentry> " +"<refentrytitle>sssd-simple</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry>, <citerefentry> " +"<refentrytitle>sssd-ipa</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry>, <citerefentry> " +"<refentrytitle>sssd-ad</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry>, <phrase condition=\"with_idp_provider\"> <citerefentry> " +"<refentrytitle>sssd-idp</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry>, </phrase> <phrase condition=\"with_sudo\"> <citerefentry> " +"<refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry>, </phrase> <citerefentry> " +"<refentrytitle>sssd-session-recording</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>, <citerefentry> " +"<refentrytitle>sss_cache</refentrytitle><manvolnum>8</manvolnum> " +"</citerefentry>, <citerefentry> " +"<refentrytitle>sss_debuglevel</refentrytitle><manvolnum>8</manvolnum> " +"</citerefentry>, <citerefentry> " +"<refentrytitle>sss_obfuscate</refentrytitle><manvolnum>8</manvolnum> " +"</citerefentry>, <citerefentry> " +"<refentrytitle>sss_seed</refentrytitle><manvolnum>8</manvolnum> " +"</citerefentry>, <citerefentry> " +"<refentrytitle>sssd_krb5_locator_plugin</refentrytitle><manvolnum>8</manvolnum> " +"</citerefentry>, <phrase condition=\"with_ssh\"> <citerefentry> " +"<refentrytitle>sss_ssh_authorizedkeys</refentrytitle> " +"<manvolnum>1</manvolnum> </citerefentry>, <citerefentry> " +"<refentrytitle>sss_ssh_knownhosts</refentrytitle> <manvolnum>1</manvolnum> " +"</citerefentry>, </phrase> <citerefentry> " +"<refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry>, <citerefentry> " +"<refentrytitle>pam_sss</refentrytitle><manvolnum>8</manvolnum> " +"</citerefentry>. <citerefentry> " +"<refentrytitle>sss_rpcidmapd</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> <phrase condition=\"with_stap\"> <citerefentry> " +"<refentrytitle>sssd-systemtap</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> </phrase>" +msgstr "" + +#. type: Content of: <listitem><para> +#: include/ldap_search_bases.xml:3 +msgid "" +"An optional base DN, search scope and LDAP filter to restrict LDAP searches " +"for this attribute type." +msgstr "" + +#. type: Content of: <listitem><para><programlisting> +#: include/ldap_search_bases.xml:9 +#, no-wrap +msgid "search_base[?scope?[filter][?search_base?scope?[filter]]*]\n" +msgstr "" + +#. type: Content of: <listitem><para> +#: include/ldap_search_bases.xml:7 +msgid "syntax: <placeholder type=\"programlisting\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <listitem><para> +#: include/ldap_search_bases.xml:13 +msgid "" +"The scope can be one of \"base\", \"onelevel\" or \"subtree\". The scope " +"functions as specified in section 4.5.1.2 of " +"http://tools.ietf.org/html/rfc4511" +msgstr "" + +#. type: Content of: <listitem><para> +#: include/ldap_search_bases.xml:23 +msgid "" +"For examples of this syntax, please refer to the " +"<quote>ldap_search_base</quote> examples section." +msgstr "" + +#. type: Content of: <listitem><para> +#: include/ldap_search_bases.xml:31 +msgid "" +"Please note that specifying scope or filter is not supported for searches " +"against an Active Directory Server that might yield a large number of " +"results and trigger the Range Retrieval extension in the response." +msgstr "" + +#. type: Content of: <para> +#: include/autofs_restart.xml:2 +msgid "" +"Please note that the automounter only reads the master map on startup, so if " +"any autofs-related changes are made to the sssd.conf, you typically also " +"need to restart the automounter daemon after restarting the SSSD." +msgstr "" + +#. type: Content of: <varlistentry><term> +#: include/override_homedir.xml:2 +msgid "override_homedir (string)" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: include/override_homedir.xml:16 +msgid "UID number" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: include/override_homedir.xml:20 +msgid "domain name" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> +#: include/override_homedir.xml:23 +msgid "%f" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: include/override_homedir.xml:24 +msgid "fully qualified user name (user@domain)" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> +#: include/override_homedir.xml:27 +msgid "%l" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: include/override_homedir.xml:28 +msgid "The first letter of the login name." +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: include/override_homedir.xml:32 +msgid "UPN - User Principal Name (name@REALM)" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> +#: include/override_homedir.xml:35 +msgid "%o" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: include/override_homedir.xml:38 +msgid "The homedir value that is defined in the directory of the identity provider." +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: include/override_homedir.xml:42 +msgid "" +"This substitution is designed to be used in an IPA-AD trust scenario. If " +"this substitution is used for the <emphasis>subdomain_homedir</emphasis> " +"option, it propagates the home directory value from the AD domain to the IPA " +"clients. In this scenario, the option must be set in the SSSD configuration " +"on the IPA server where SSSD is running in server mode." +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: include/override_homedir.xml:55 +msgid "" +"The path defined for the homedir directory attribute of the identity " +"provider, but in lower case. For details of use, see " +"<emphasis>%o</emphasis>." +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> +#: include/override_homedir.xml:61 +msgid "%H" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> +#: include/override_homedir.xml:63 +msgid "The value of configure option <emphasis>homedir_substring</emphasis>." +msgstr "" + +#. type: Content of: <varlistentry><listitem><para> +#: include/override_homedir.xml:5 +msgid "" +"Override the user's home directory. You can either provide an absolute value " +"or a template. In the template, the following sequences are substituted: " +"<placeholder type=\"variablelist\" id=\"0\"/>" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para> +#: include/override_homedir.xml:75 +msgid "This option can also be set per-domain." +msgstr "" + +#. type: Content of: <varlistentry><listitem><para><programlisting> +#: include/override_homedir.xml:80 +#, no-wrap +msgid "" +"override_homedir = /home/%u\n" +" " +msgstr "" + +#. type: Content of: <varlistentry><listitem><para> +#: include/override_homedir.xml:84 +msgid "Default: Not set (SSSD will use the value retrieved from LDAP)" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para> +#: include/override_homedir.xml:88 +msgid "" +"Please note, the home directory from a specific override for the user, " +"either locally (see " +"<citerefentry><refentrytitle>sss_override</refentrytitle> " +"<manvolnum>8</manvolnum></citerefentry>) or centrally managed IPA " +"id-overrides, has a higher precedence and will be used instead of the value " +"given by override_homedir." +msgstr "" + +#. type: Content of: <varlistentry><term> +#: include/homedir_substring.xml:2 +msgid "homedir_substring (string)" +msgstr "" + +#. type: Content of: <varlistentry><listitem><para> +#: include/homedir_substring.xml:5 +msgid "" +"The value of this option will be used in the expansion of the " +"<emphasis>override_homedir</emphasis> option if the template contains the " +"format string <emphasis>%H</emphasis>. An LDAP directory entry can directly " +"contain this template so that this option can be used to expand the home " +"directory path for each client machine (or operating system). It can be set " +"per-domain or globally in the [nss] section. A value specified in a domain " +"section will override one set in the [nss] section." +msgstr "" + +#. type: Content of: <varlistentry><listitem><para> +#: include/homedir_substring.xml:15 +msgid "Default: /home" +msgstr "" + +#. type: Content of: <refsect1><title> +#: include/ad_modified_defaults.xml:2 include/ipa_modified_defaults.xml:2 +msgid "MODIFIED DEFAULT OPTIONS" +msgstr "" + +#. type: Content of: <refsect1><para> +#: include/ad_modified_defaults.xml:4 +msgid "" +"Certain option defaults do not match their respective backend provider " +"defaults, these option names and AD provider-specific defaults are listed " +"below:" +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/ad_modified_defaults.xml:9 include/ipa_modified_defaults.xml:9 +msgid "KRB5 Provider" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:13 include/ipa_modified_defaults.xml:13 +msgid "krb5_validate = true" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:18 +msgid "krb5_use_enterprise_principal = true" +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/ad_modified_defaults.xml:24 +msgid "LDAP Provider" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:28 +msgid "ldap_schema = ad" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:33 include/ipa_modified_defaults.xml:38 +msgid "ldap_force_upper_case_realm = true" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:38 +msgid "ldap_id_mapping = true" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:43 +msgid "ldap_sasl_mech = GSS-SPNEGO" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:48 +msgid "ldap_referrals = false" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:53 +msgid "ldap_account_expire_policy = ad" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:58 include/ipa_modified_defaults.xml:58 +msgid "ldap_use_tokengroups = true" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:63 +msgid "ldap_sasl_authid = sAMAccountName@REALM (typically SHORTNAME$@REALM)" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:66 +msgid "" +"The AD provider looks for a different principal than the LDAP provider by " +"default, because in an Active Directory environment the principals are " +"divided into two groups - User Principals and Service Principals. Only User " +"Principal can be used to obtain a TGT and by default, computer object's " +"principal is constructed from its sAMAccountName and the AD realm. The " +"well-known host/hostname@REALM principal is a Service Principal and thus " +"cannot be used to get a TGT with." +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/ad_modified_defaults.xml:80 +msgid "NSS configuration" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:84 +msgid "fallback_homedir = /home/%d/%u" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:87 +msgid "" +"The AD provider automatically sets \"fallback_homedir = /home/%d/%u\" to " +"provide personal home directories for users without the homeDirectory " +"attribute. If your AD Domain is properly populated with Posix attributes, " +"and you want to avoid this fallback behavior, you can explicitly set " +"\"fallback_homedir = %o\"." +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:96 +msgid "" +"Note that the system typically expects a home directory in /home/%u " +"folder. If you decide to use a different directory structure, some other " +"parts of your system may need adjustments." +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ad_modified_defaults.xml:102 +msgid "" +"For example automated creation of home directories in combination with " +"selinux requires selinux adjustment, otherwise the home directory will be " +"created with wrong selinux context." +msgstr "" + +#. type: Content of: <refsect1><para> +#: include/ipa_modified_defaults.xml:4 +msgid "" +"Certain option defaults do not match their respective backend provider " +"defaults, these option names and IPA provider-specific defaults are listed " +"below:" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:18 +msgid "krb5_use_fast = try" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:23 +msgid "krb5_canonicalize = true" +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/ipa_modified_defaults.xml:29 +msgid "LDAP Provider - General" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:33 +msgid "ldap_schema = ipa_v1" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:43 +msgid "ldap_sasl_mech = GSSAPI" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:48 +msgid "ldap_sasl_minssf = 56" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:53 +msgid "ldap_account_expire_policy = ipa" +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/ipa_modified_defaults.xml:64 +msgid "LDAP Provider - User options" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:68 +msgid "ldap_user_member_of = memberOf" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:73 +msgid "ldap_user_uuid = ipaUniqueID" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:78 +msgid "ldap_user_ssh_public_key = ipaSshPubKey" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:83 +msgid "ldap_user_auth_type = ipaUserAuthType" +msgstr "" + +#. type: Content of: <refsect1><refsect2><title> +#: include/ipa_modified_defaults.xml:89 +msgid "LDAP Provider - Group options" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:93 +msgid "ldap_group_object_class = ipaUserGroup" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:98 +msgid "ldap_group_object_class_alt = posixGroup" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:103 +msgid "ldap_group_member = member" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:108 +msgid "ldap_group_uuid = ipaUniqueID" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:113 +msgid "ldap_group_objectsid = ipaNTSecurityIdentifier" +msgstr "" + +#. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> +#: include/ipa_modified_defaults.xml:118 +msgid "ldap_group_external_member = ipaExternalMember" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><term> +#: include/krb5_options.xml:3 +msgid "krb5_auth_timeout (integer)" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:6 +msgid "" +"Timeout in seconds after an online authentication request or change password " +"request is aborted. If possible, the authentication request is continued " +"offline." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><term> +#: include/krb5_options.xml:17 +msgid "krb5_validate (boolean)" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:20 +msgid "" +"Verify with the help of krb5_keytab that the TGT obtained has not been " +"spoofed. The keytab is checked for entries sequentially, and the first entry " +"with a matching realm is used for validation. If no entry matches the realm, " +"the last entry in the keytab is used. This process can be used to validate " +"environments using cross-realm trust by placing the appropriate keytab entry " +"as the last entry or the only entry in the keytab file." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:29 +msgid "Default: false (IPA and AD provider: true)" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:32 +msgid "" +"Please note that the ticket validation is the first step when checking the " +"PAC (see 'pac_check' in the <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " +"</citerefentry> manual page for details). If ticket validation is disabled " +"the PAC checks will be skipped as well." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><term> +#: include/krb5_options.xml:44 +msgid "krb5_renewable_lifetime (string)" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:47 +msgid "" +"Request a renewable ticket with a total lifetime, given as an integer " +"immediately followed by a time unit:" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:52 include/krb5_options.xml:86 +#: include/krb5_options.xml:123 +msgid "<emphasis>s</emphasis> for seconds" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:55 include/krb5_options.xml:89 +#: include/krb5_options.xml:126 +msgid "<emphasis>m</emphasis> for minutes" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:58 include/krb5_options.xml:92 +#: include/krb5_options.xml:129 +msgid "<emphasis>h</emphasis> for hours" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:61 include/krb5_options.xml:95 +#: include/krb5_options.xml:132 +msgid "<emphasis>d</emphasis> for days." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:64 include/krb5_options.xml:135 +msgid "If there is no unit given, <emphasis>s</emphasis> is assumed." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:68 include/krb5_options.xml:139 +msgid "" +"NOTE: It is not possible to mix units. To set the renewable lifetime to one " +"and a half hours, use '90m' instead of '1h30m'." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:73 +msgid "Default: not set, i.e. the TGT is not renewable" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><term> +#: include/krb5_options.xml:79 +msgid "krb5_lifetime (string)" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:82 +msgid "" +"Request ticket with a lifetime, given as an integer immediately followed by " +"a time unit:" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:98 +msgid "If there is no unit given <emphasis>s</emphasis> is assumed." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:102 +msgid "" +"NOTE: It is not possible to mix units. To set the lifetime to one and a " +"half hours please use '90m' instead of '1h30m'." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:107 +msgid "Default: not set, i.e. the default ticket lifetime configured on the KDC." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><term> +#: include/krb5_options.xml:114 +msgid "krb5_renew_interval (string)" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:117 +msgid "" +"The time in seconds between two checks if the TGT should be renewed. TGTs " +"are renewed if about half of their lifetime is exceeded, given as an integer " +"immediately followed by a time unit:" +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:144 +msgid "If this option is not set or is 0 the automatic renewal is disabled." +msgstr "" + +#. type: Content of: <variablelist><varlistentry><listitem><para> +#: include/krb5_options.xml:157 +msgid "" +"Specifies if the host and user principal should be canonicalized. This " +"feature is available with MIT Kerberos 1.7 and later versions." +msgstr "" diff --git a/src/man/po/zh_TW.po b/src/man/po/zh_TW.po index 7945abf7e50..cf88834d4a6 100644 --- a/src/man/po/zh_TW.po +++ b/src/man/po/zh_TW.po @@ -8,8 +8,8 @@ msgstr "" "Project-Id-Version: sssd-docs 2.10.0\n" "Report-Msgid-Bugs-To: sssd-devel@redhat.com\n" "POT-Creation-Date: 2024-10-15 11:44+0200\n" -"PO-Revision-Date: 2026-04-23 16:49+0000\n" -"Last-Translator: hsu zangmen <chzang55@gmail.com>\n" +"PO-Revision-Date: 2026-08-01 06:29+0000\n" +"Last-Translator: Alang Hsu <alang.hsu@gmail.com>\n" "Language-Team: Chinese (Traditional) <https://translate.fedoraproject.org/" "projects/sssd/sssd-manpage-master/zh_TW/>\n" "Language: zh_TW\n" @@ -17,7 +17,7 @@ msgstr "" "Content-Type: text/plain; charset=UTF-8\n" "Content-Transfer-Encoding: 8bit\n" "Plural-Forms: nplurals=1; plural=0;\n" -"X-Generator: Weblate 5.17\n" +"X-Generator: Weblate 2026.7.1\n" #. type: Content of: <reference><title> #: sssd.conf.5.xml:8 sssd-ldap.5.xml:5 pam_sss.8.xml:5 pam_sss_gss.8.xml:5 @@ -31,11 +31,10 @@ msgstr "" #: sssd-kcm.8.xml:5 sssd-systemtap.5.xml:5 sssd-ldap-attributes.5.xml:5 #: sssd_krb5_localauth_plugin.8.xml:5 msgid "SSSD Manual pages" -msgstr "SSSD 手冊主頁" +msgstr "SSSD 手冊頁" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd.conf.5.xml:13 sssd.conf.5.xml:19 -#, fuzzy msgid "sssd.conf" msgstr "sssd.conf" @@ -45,7 +44,6 @@ msgstr "sssd.conf" #: sssd-krb5.5.xml:11 sssd-ifp.5.xml:11 sss_rpcidmapd.5.xml:27 #: sssd-files.5.xml:11 sssd-session-recording.5.xml:11 sssd-systemtap.5.xml:11 #: sssd-ldap-attributes.5.xml:11 -#, fuzzy msgid "5" msgstr "5" @@ -70,7 +68,7 @@ msgstr "檔案格式" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd.conf.5.xml:32 -#, fuzzy, no-wrap +#, no-wrap msgid "" "<replaceable>[section]</replaceable>\n" "<replaceable>key</replaceable> = <replaceable>value</replaceable>\n" @@ -90,8 +88,8 @@ msgid "" "until the next section begins. An example of section with single and " "multi-valued parameters: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" -"檔案採用 ini-style 語法,由區段和參數組成。一節以方括號中的節名開始,一直到下" -"一節開始為止。包含單值和多值參數的節範例: <placeholder " +"檔案採用 ini-style 語法,由區段和參數組成。一個區段以方括號中的區段名稱開始," +"一直持續到下一區段開始。包含單值和多值參數的節範例: <placeholder " "type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> @@ -100,7 +98,7 @@ msgid "" "The data types used are string (no quotes needed), integer and bool (with " "values of <quote>TRUE/FALSE</quote>)." msgstr "" -"使用的資料類型為字串 (不需要引號)、整數和布林值 (值為 <quote>TRUE/FALSE</" +"使用的資料類型為字串 (不需要引號)、整數與布林值 (值為 <quote>TRUE/FALSE</" "quote>)。" #. type: Content of: <reference><refentry><refsect1><para> @@ -109,6 +107,8 @@ msgid "" "A comment line starts with a hash sign (<quote>#</quote>) or a semicolon " "(<quote>;</quote>). Inline comments are not supported." msgstr "" +"註解行以井字號 (<quote>#</quote>) 或分號 (<quote>;</quote>) 開頭。不支援行內" +"註解。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:50 @@ -116,6 +116,8 @@ msgid "" "All sections can have an optional <replaceable>description</replaceable> " "parameter. Its function is only as a label for the section." msgstr "" +"所有區段都可以有選擇性的 <replaceable>description</replaceable> 參數,其作用" +"僅為該區段的標籤。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:56 @@ -123,6 +125,8 @@ msgid "" "<filename>sssd.conf</filename> must be a regular file that is owned, " "readable, and writeable only by 'root'." msgstr "" +"<filename>sssd.conf</filename> 必須是一般檔案,且僅由 'root' 擁有、可讀且可寫" +"。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:60 @@ -130,11 +134,13 @@ msgid "" "<filename>sssd.conf</filename> must be a regular file that is owned, " "readable, and writeable by the same user as configured to run SSSD service." msgstr "" +"<filename>sssd.conf</filename> 必須是一般檔案,且由設定為執行 SSSD 服務的同一" +"使用者擁有、可讀且可寫。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:67 msgid "CONFIGURATION SNIPPETS FROM INCLUDE DIRECTORY" -msgstr "" +msgstr "來自 INCLUDE 目錄的設定片段" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:70 @@ -143,6 +149,8 @@ msgid "" "configuration snippets using the include directory " "<filename>conf.d</filename>." msgstr "" +"設定檔 <filename>sssd.conf</filename> 會透過 include 目錄 <filename>conf.d</" +"filename> 納入設定片段。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:76 @@ -152,6 +160,9 @@ msgid "" "(<quote>.</quote>) will be used together with <filename>sssd.conf</filename> " "to configure SSSD." msgstr "" +"置於 <filename>conf.d</filename> 中、以 <quote><filename>.conf</filename></" +"quote> 結尾且不以點號 (<quote>.</quote>) 開頭的任何檔案,都會與 <filename>" +"sssd.conf</filename> 一起用來設定 SSSD。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:84 @@ -165,38 +176,43 @@ msgid "" "<filename>02_snippet.conf</filename> etc.) can help visualize the priority " "(higher number means higher priority)." msgstr "" +"來自 <filename>conf.d</filename> 的設定片段優先順序高於 <filename>sssd.conf</" +"filename>,發生衝突時會覆寫 <filename>sssd.conf</filename>。若 <filename>" +"conf.d</filename> 中有多個片段,則會依字母順序(依語言環境)納入。越晚納入的" +"檔案優先順序越高。數字前綴(<filename>01_snippet.conf</filename>、<filename>" +"02_snippet.conf</filename> 等)有助於看出優先順序(數字越大優先順序越高)。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:98 msgid "" "The snippet files require the same owner and permissions as " "<filename>sssd.conf</filename>." -msgstr "" +msgstr "片段檔需要與 <filename>sssd.conf</filename> 相同的擁有者與權限。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:104 msgid "GENERAL OPTIONS" -msgstr "" +msgstr "一般選項" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:106 msgid "Following options are usable in more than one configuration sections." -msgstr "" +msgstr "下列選項可用於多個設定區段。" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:110 msgid "Options usable in all sections" -msgstr "" +msgstr "可用於所有區段的選項" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:114 msgid "debug_level (integer)" -msgstr "" +msgstr "debug_level (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:118 msgid "debug (integer)" -msgstr "" +msgstr "debug (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:121 @@ -206,18 +222,21 @@ msgid "" "are specified, the value of <replaceable>debug_level</replaceable> will be " "used." msgstr "" +"SSSD 1.14 起也提供 <replaceable>debug</replaceable> 作為 <replaceable>" +"debug_level</replaceable> 的別名,以方便使用。若同時指定兩者,將採用 " +"<replaceable>debug_level</replaceable> 的值。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:131 msgid "debug_timestamps (bool)" -msgstr "" +msgstr "debug_timestamps (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:134 msgid "" "Add a timestamp to the debug messages. If journald is enabled for SSSD " "debug logging this option is ignored." -msgstr "" +msgstr "在除錯訊息中加入時間戳記。若 SSSD 除錯記錄已啟用 journald,此選項會被忽略。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:139 sssd.conf.5.xml:176 sssd.conf.5.xml:338 @@ -228,12 +247,12 @@ msgstr "" #: sssd-ipa.5.xml:347 sssd-ad.5.xml:252 sssd-ad.5.xml:367 sssd-ad.5.xml:1201 #: sssd-ad.5.xml:1354 sssd-krb5.5.xml:358 msgid "Default: true" -msgstr "" +msgstr "預設:true" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:144 msgid "debug_microseconds (bool)" -msgstr "" +msgstr "debug_microseconds (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:147 @@ -241,6 +260,8 @@ msgid "" "Add microseconds to the timestamp in debug messages. If journald is enabled " "for SSSD debug logging this option is ignored." msgstr "" +"在除錯訊息的時間戳記中加入微秒。若 SSSD 除錯記錄已啟用 journald,此選項會被忽" +"略。" #. type: Content of: <variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:152 sssd.conf.5.xml:636 sssd.conf.5.xml:920 @@ -250,17 +271,17 @@ msgstr "" #: sssd-ipa.5.xml:254 sssd-ipa.5.xml:662 sssd-ad.5.xml:1107 sssd-krb5.5.xml:268 #: sssd-krb5.5.xml:330 sssd-krb5.5.xml:432 include/krb5_options.xml:163 msgid "Default: false" -msgstr "" +msgstr "預設:false" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:157 msgid "debug_backtrace_enabled (bool)" -msgstr "" +msgstr "debug_backtrace_enabled (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:160 msgid "Enable debug backtrace." -msgstr "" +msgstr "啟用除錯回溯。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:163 @@ -271,13 +292,17 @@ msgid "" "to 0 or 1 then only those error levels will trigger backtrace, otherwise up " "to 2)." msgstr "" +"若 SSSD 以低於 9 的 debug_level 執行,所有內容都會記錄到記憶體中的環形緩衝區" +",並在任何錯誤發生時(直到且包含 `min(0x0040, debug_level)`)寫入記錄檔(亦即" +",若 debug_level 明確設為 0 或 1,只有那些錯誤層級會觸發回溯,否則最多到 2)" +"。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:172 msgid "" "Feature is only supported for `logger == files` (i.e. setting doesn't have " "effect for other logger types)." -msgstr "" +msgstr "此功能僅支援 `logger == files`(亦即此設定對其他記錄器類型無效)。" #. type: Content of: outside any tag (error?) #: sssd.conf.5.xml:112 sssd.conf.5.xml:187 sssd-ldap.5.xml:1694 @@ -290,17 +315,17 @@ msgstr "" #: sssd-ldap-attributes.5.xml:1250 include/autofs_attributes.xml:1 #: include/krb5_options.xml:1 msgid "<placeholder type=\"variablelist\" id=\"0\"/>" -msgstr "" +msgstr "<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:185 msgid "Options usable in SERVICE and DOMAIN sections" -msgstr "" +msgstr "可用於 SERVICE 與 DOMAIN 區段的選項" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:189 msgid "timeout (integer)" -msgstr "" +msgstr "timeout (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:192 @@ -309,32 +334,34 @@ msgid "" "ensure that the process is alive and capable of answering requests. Note " "that after three missed heartbeats the process will terminate itself." msgstr "" +"此服務心跳之間的時間(秒)。此值用來確保程序仍在執行且能回應要求。請注意,連" +"續三次錯過心跳後,程序會自行終止。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:199 sssd.conf.5.xml:1261 sssd.conf.5.xml:1738 #: sssd.conf.5.xml:4247 sssd-ldap.5.xml:766 include/ldap_id_mapping.xml:270 msgid "Default: 10" -msgstr "" +msgstr "預設:10" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:209 msgid "SPECIAL SECTIONS" -msgstr "" +msgstr "特殊區段" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:212 msgid "The [sssd] section" -msgstr "" +msgstr "[sssd] 區段" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><title> #: sssd.conf.5.xml:221 msgid "Section parameters" -msgstr "" +msgstr "區段參數" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:223 msgid "services" -msgstr "" +msgstr "services" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:226 @@ -344,6 +371,9 @@ msgid "" "platforms where systemd is supported, as they will either be socket or D-Bus " "activated when needed. </phrase>" msgstr "" +"以逗號分隔的服務清單,列出 sssd 本身啟動時會啟動的服務。<phrase " +"condition=\"have_systemd\"> 在支援 systemd 的平台上,服務清單為選擇性,因為需" +"要時它們會以 socket 或 D-Bus 方式啟動。</phrase>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:235 @@ -353,6 +383,10 @@ msgid "" "condition=\"with_ssh\">, ssh</phrase> <phrase " "condition=\"with_pac_responder\">, pac</phrase>" msgstr "" +"支援的服務:nss、pam、ifp<phrase condition=\"with_sudo\">、sudo</phrase> " +"<phrase condition=\"with_autofs\">、autofs</phrase> <phrase " +"condition=\"with_ssh\">、ssh</phrase> <phrase " +"condition=\"with_pac_responder\">、pac</phrase>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:242 @@ -361,11 +395,14 @@ msgid "" "and the administrator must enable the ones allowed to be used by executing: " "\"systemctl enable sssd-@service@.socket\". </phrase>" msgstr "" +"<phrase condition=\"have_systemd\"> 依預設所有服務都是停用的,管理員必須執行" +"下列指令來啟用允許使用的服務:\"systemctl enable sssd-@service@.socket\"。</" +"phrase>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:251 msgid "domains" -msgstr "" +msgstr "domains" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:254 @@ -377,18 +414,21 @@ msgid "" "alphanumeric ASCII characters, dashes, dots and underscores. '/' character " "is forbidden." msgstr "" +"網域是包含使用者資訊的資料庫。SSSD 可以同時使用多個網域,但至少必須設定一個," +"否則 SSSD 不會啟動。此參數以您希望查詢的順序描述網域清單。建議網域名稱只包含 " +"ASCII 字母數字、連字號、句點與底線。禁止使用 '/' 字元。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:267 sssd.conf.5.xml:3535 msgid "re_expression (string)" -msgstr "" +msgstr "re_expression (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:270 msgid "" "Default regular expression that describes how to parse the string containing " "user name and domain into these components." -msgstr "" +msgstr "預設的正規表示式,描述如何將包含使用者名稱與網域的字串剖析為這些組成部分。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:275 @@ -397,11 +437,13 @@ msgid "" "ID providers there are also default regular expressions. See DOMAIN SECTIONS " "for more info on these regular expressions." msgstr "" +"每個網域都可以設定各自的正規表示式。某些 ID 提供者也有預設的正規表示式。有關" +"這些正規表示式的更多資訊,請參閱 DOMAIN SECTIONS。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:284 sssd.conf.5.xml:3592 msgid "full_name_format (string)" -msgstr "" +msgstr "full_name_format (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:287 sssd.conf.5.xml:3595 @@ -411,31 +453,34 @@ msgid "" "how to compose a fully qualified name from user name and domain name " "components." msgstr "" +"一種與 <citerefentry> <refentrytitle>printf</refentrytitle> <manvolnum>3</" +"manvolnum> </citerefentry> 相容的格式,描述如何從使用者名稱與網域名稱組成部分" +"構成完整名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:298 sssd.conf.5.xml:3606 msgid "%1$s" -msgstr "" +msgstr "%1$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:299 sssd.conf.5.xml:3607 msgid "user name" -msgstr "" +msgstr "使用者名稱" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:302 sssd.conf.5.xml:3610 msgid "%2$s" -msgstr "" +msgstr "%2$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:305 sssd.conf.5.xml:3613 msgid "domain name as specified in the SSSD config file." -msgstr "" +msgstr "SSSD 設定檔中指定的網域名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:311 sssd.conf.5.xml:3619 msgid "%3$s" -msgstr "" +msgstr "%3$s" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:314 sssd.conf.5.xml:3622 @@ -443,13 +488,15 @@ msgid "" "domain flat name. Mostly usable for Active Directory domains, both directly " "configured or discovered via IPA trusts." msgstr "" +"網域簡短名稱。主要用於 Active Directory 網域,無論是直接設定或透過 IPA 信任探" +"索到的。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:295 sssd.conf.5.xml:3603 msgid "" "The following expansions are supported: <placeholder type=\"variablelist\" " "id=\"0\"/>" -msgstr "" +msgstr "支援下列展開:<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:324 @@ -457,11 +504,13 @@ msgid "" "Each domain can have an individual format string configured. See DOMAIN " "SECTIONS for more info on this option." msgstr "" +"每個網域都可以設定各自的格式字串。有關此選項的更多資訊,請參閱 DOMAIN " +"SECTIONS。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:330 msgid "monitor_resolv_conf (boolean)" -msgstr "" +msgstr "monitor_resolv_conf (boolean)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:333 @@ -469,11 +518,13 @@ msgid "" "Controls if SSSD should monitor the state of resolv.conf to identify when it " "needs to update its internal DNS resolver." msgstr "" +"控制 SSSD 是否應監控 resolv.conf 的狀態,以判斷何時需要更新其內部的 DNS 解析" +"器。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:343 msgid "try_inotify (boolean)" -msgstr "" +msgstr "try_inotify (boolean)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:346 @@ -482,6 +533,8 @@ msgid "" "changes and will fall back to polling every five seconds if inotify cannot " "be used." msgstr "" +"依預設,SSSD 會嘗試使用 inotify 監控設定檔的變更;若無法使用 inotify,則會退" +"回每五秒輪詢一次。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:352 @@ -490,32 +543,34 @@ msgid "" "even trying to use inotify. In these rare cases, this option should be set " "to 'false'" msgstr "" +"有些少數情況最好連嘗試使用 inotify 都省略。在這些罕見情況下,應將此選項設為 " +"'false'" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:358 msgid "" "Default: true on platforms where inotify is supported. False on other " "platforms." -msgstr "" +msgstr "預設:在支援 inotify 的平台上為 true,其他平台為 false。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:362 msgid "" "Note: this option will have no effect on platforms where inotify is " "unavailable. On these platforms, polling will always be used." -msgstr "" +msgstr "注意:在無法使用 inotify 的平台上,此選項沒有效果。這些平台一律會使用輪詢。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:369 msgid "krb5_rcache_dir (string)" -msgstr "" +msgstr "krb5_rcache_dir (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:372 msgid "" "Directory on the filesystem where SSSD should store Kerberos replay cache " "files." -msgstr "" +msgstr "SSSD 應在檔案系統上儲存 Kerberos 重播快取檔案的目錄。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:376 @@ -523,18 +578,20 @@ msgid "" "This option accepts a special value __LIBKRB5_DEFAULTS__ that will instruct " "SSSD to let libkrb5 decide the appropriate location for the replay cache." msgstr "" +"此選項接受特殊值 __LIBKRB5_DEFAULTS__,指示 SSSD 讓 libkrb5 決定重播快取的適" +"當位置。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:382 msgid "" "Default: Distribution-specific and specified at " "build-time. (__LIBKRB5_DEFAULTS__ if not configured)" -msgstr "" +msgstr "預設:依發行版而異,於建置時指定。(若未設定則為 __LIBKRB5_DEFAULTS__)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:389 msgid "user (string)" -msgstr "" +msgstr "user (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:392 @@ -543,13 +600,15 @@ msgid "" "where appropriate to avoid running as the root user. The only supported " "value is '&sssd_user_name;'." msgstr "" +"設定在適當時機放棄權限的使用者之傳統(已棄用)方法,以避免以 root 使用者執行" +"。唯一支援的值是 '&sssd_user_name;'。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:399 msgid "" "This option is ignored if main SSSD process is started under non-root user " "initially (preferred method)." -msgstr "" +msgstr "若主要 SSSD 程序最初以非 root 使用者啟動(建議方式),此選項會被忽略。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:404 @@ -560,16 +619,19 @@ msgid "" "general isn't supported: everything should be configured to run either under " "'&sssd_user_name;' or 'root'." msgstr "" +"此選項不適用於 socket 啟動的服務,因為在這種情況下,執行程序的使用者是在 " +"systemd 服務檔中設定的。請注意,一般來說不支援對不同 SSSD 元件使用不同的服務" +"使用者:所有元件都應設定為在 '&sssd_user_name;' 或 'root' 下執行。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:415 msgid "Default: not set, process will run as root" -msgstr "" +msgstr "預設:未設定,程序會以 root 執行" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:420 msgid "default_domain_suffix (string)" -msgstr "" +msgstr "default_domain_suffix (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:423 @@ -580,6 +642,9 @@ msgid "" "trusted domain. The option allows those users to log in just with their " "user name without giving a domain name as well." msgstr "" +"此字串會用作所有沒有網域名稱組成部分之名稱的預設網域名稱。主要使用案例是主要" +"網域用於管理主機原則、而所有使用者都位於受信任網域的環境。此選項也允許這些使" +"用者只輸入使用者名稱登入,而不需要提供網域名稱。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:433 @@ -594,6 +659,12 @@ msgid "" "of nss_files and therefore their output is not qualified even when the " "default_domain_suffix option is used. </phrase>" msgstr "" +"請注意,若設定此選項,主要網域的所有使用者都必須使用完整名稱(例如 " +"user@domain.name)登入。設定此選項會將 use_fully_qualified_names 的預設值改" +"為 True。不允許將此選項與設為 False 的 use_fully_qualified_names 一起使用" +"。<phrase condition=\"with_files_provider\"> 此規則的唯一例外是使用 <quote>" +"id_provider=files</quote> 的網域,這些網域一律嘗試比照 nss_files 的行為,因此" +"即使使用 default_domain_suffix 選項,其輸出也不會限定。</phrase>" #. type: Content of: <variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:450 sssd-ldap.5.xml:878 sssd-ldap.5.xml:890 @@ -602,12 +673,12 @@ msgstr "" #: include/ldap_id_mapping.xml:211 include/ldap_id_mapping.xml:222 #: include/krb5_options.xml:148 msgid "Default: not set" -msgstr "" +msgstr "預設:未設定" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:455 msgid "override_space (string)" -msgstr "" +msgstr "override_space (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:458 @@ -618,6 +689,9 @@ msgid "" "scripts that have difficulty handling spaces, due to the default field " "separator in the shell." msgstr "" +"此參數會以給定的字元取代使用者與群組名稱中的空格。例如 (_)。使用者名稱 " +""john doe" 會變成 "john_doe"。新增此功能是為了與難以處理" +"空格的 shell 指令碼相容,因為 shell 的預設欄位分隔符為空格。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:467 @@ -627,21 +701,23 @@ msgid "" "character SSSD tries to return the unmodified name but in general the result " "of a lookup is undefined." msgstr "" +"請注意,使用可能出現在使用者或群組名稱中的取代字元屬於設定錯誤。若名稱包含取" +"代字元,SSSD 會嘗試傳回未修改的名稱,但一般來說查詢結果是未定義的。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:475 msgid "Default: not set (spaces will not be replaced)" -msgstr "" +msgstr "預設:未設定(不會取代空格)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:480 msgid "certificate_verification (string)" -msgstr "" +msgstr "certificate_verification (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:488 msgid "no_ocsp" -msgstr "" +msgstr "no_ocsp" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:490 @@ -650,11 +726,13 @@ msgid "" "needed if the OCSP servers defined in the certificate are not reachable from " "the client." msgstr "" +"停用線上憑證狀態協定 (OCSP) 檢查。若憑證中定義的 OCSP 伺服器無法從用戶端連線" +",可能需要此選項。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:498 msgid "soft_ocsp" -msgstr "" +msgstr "soft_ocsp" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:500 @@ -663,60 +741,62 @@ msgid "" "skipped. This option should be used to allow authentication when the system " "is offline and the OCSP responder cannot be reached." msgstr "" +"若無法與 OCSP 回應器建立連線,則會略過 OCSP 檢查。當系統離線且無法連線 OCSP " +"回應器時,應使用此選項允許驗證。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:510 msgid "ocsp_dgst" -msgstr "" +msgstr "ocsp_dgst" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:512 msgid "" "Digest (hash) function used to create the certificate ID for the OCSP " "request. Allowed values are:" -msgstr "" +msgstr "用來建立 OCSP 要求憑證 ID 的摘要(雜湊)函式。允許的值有:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:516 msgid "sha1" -msgstr "" +msgstr "sha1" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:517 msgid "sha256" -msgstr "" +msgstr "sha256" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:518 msgid "sha384" -msgstr "" +msgstr "sha384" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:519 msgid "sha512" -msgstr "" +msgstr "sha512" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:522 msgid "Default: sha1 (to allow compatibility with RFC5019-compliant responder)" -msgstr "" +msgstr "預設:sha1(以相容於符合 RFC5019 的回應器)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:528 msgid "no_verification" -msgstr "" +msgstr "no_verification" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:530 msgid "" "Disables verification completely. This option should only be used for " "testing." -msgstr "" +msgstr "完全停用驗證。此選項只應用於測試。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:536 msgid "partial_chain" -msgstr "" +msgstr "partial_chain" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:538 @@ -725,11 +805,13 @@ msgid "" "chain cannot be built to a self-signed trust-anchor, provided it is possible " "to construct a chain to a trusted certificate that might not be self-signed." msgstr "" +"即使無法建立到自簽信任錨點的<replaceable>完整</replaceable>鏈結,只要可以建立" +"到受信任憑證(可能不是自簽)的鏈結,就允許驗證成功。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:547 msgid "ocsp_default_responder=URL" -msgstr "" +msgstr "ocsp_default_responder=URL" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:549 @@ -738,11 +820,13 @@ msgid "" "mentioned in the certificate. URL must be replaced with the URL of the OCSP " "default responder e.g. http://example.com:80/ocsp." msgstr "" +"設定應取代憑證中所提及回應器的 OCSP 預設回應器。URL 必須替換為 OCSP 預設回應" +"器的 URL,例如 http://example.com:80/ocsp。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:559 msgid "ocsp_default_responder_signing_cert=NAME" -msgstr "" +msgstr "ocsp_default_responder_signing_cert=NAME" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:561 @@ -750,11 +834,13 @@ msgid "" "This option is currently ignored. All needed certificates must be available " "in the PEM file given by pam_cert_db_path." msgstr "" +"此選項目前會被忽略。所有需要的憑證都必須存在於 pam_cert_db_path 指定的 PEM 檔" +"案中。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:569 msgid "crl_file=/PATH/TO/CRL/FILE" -msgstr "" +msgstr "crl_file=/PATH/TO/CRL/FILE" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:571 @@ -764,11 +850,14 @@ msgid "" "<citerefentry> <refentrytitle>crl</refentrytitle> " "<manvolnum>1ssl</manvolnum> </citerefentry> for details." msgstr "" +"驗證憑證時,使用指定檔案中的憑證撤銷清單 (CRL)。CRL 必須以 PEM 格式提供,詳情" +"請參閱 <citerefentry> <refentrytitle>crl</refentrytitle> <manvolnum>1ssl</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:584 msgid "soft_crl" -msgstr "" +msgstr "soft_crl" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:587 @@ -778,6 +867,8 @@ msgid "" "CRL. This option should be used to allow authentication when the system is " "offline and the CRL cannot be renewed." msgstr "" +"若憑證撤銷清單 (CRL) 已過期,則忽略 CRL 的到期時間,並使用已過期的 CRL 檢查相" +"關憑證。當系統離線且無法更新 CRL 時,應使用此選項允許驗證。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:483 @@ -786,45 +877,47 @@ msgid "" "separated list of options. Supported options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"使用此參數可以透過逗號分隔的選項清單調整憑證驗證。支援的選項有:<placeholder " +"type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:600 msgid "Unknown options are reported but ignored." -msgstr "" +msgstr "未知選項會被回報但予以忽略。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:603 msgid "Default: not set, i.e. do not restrict certificate verification" -msgstr "" +msgstr "預設:未設定,亦即不限制憑證驗證" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:609 msgid "disable_netlink (boolean)" -msgstr "" +msgstr "disable_netlink (boolean)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:612 msgid "" "SSSD hooks into the netlink interface to monitor changes to routes, " "addresses, links and trigger certain actions." -msgstr "" +msgstr "SSSD 掛接至 netlink 介面,以監控路由、位址、連結的變更並觸發特定動作。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:617 msgid "" "The SSSD state changes caused by netlink events may be undesirable and can " "be disabled by setting this option to 'true'" -msgstr "" +msgstr "由 netlink 事件造成的 SSSD 狀態變更可能不受歡迎,可將此選項設為 'true' 來停用" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:622 msgid "Default: false (netlink changes are detected)" -msgstr "" +msgstr "預設:false(會偵測 netlink 變更)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:627 msgid "enable_files_domain (boolean)" -msgstr "" +msgstr "enable_files_domain (boolean)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:630 @@ -832,11 +925,13 @@ msgid "" "When this option is enabled, SSSD prepends an implicit domain with " "<quote>id_provider=files</quote> before any explicitly configured domains." msgstr "" +"啟用此選項時,SSSD 會在任何明確設定的網域之前加上具有 <quote>" +"id_provider=files</quote> 的隱含網域。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:641 msgid "domain_resolution_order" -msgstr "" +msgstr "domain_resolution_order" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:644 @@ -848,6 +943,10 @@ msgid "" "subdomains which are not listed as part of <quote>lookup_order</quote> will " "be looked up in a random order for each parent domain." msgstr "" +"以逗號分隔的網域與子網域清單,代表將遵循的查詢順序。此清單不必包含所有可能的" +"網域,因為遺漏的網域會依 <quote>domains</quote> 設定選項中呈現的順序查詢。未" +"列為 <quote>lookup_order</quote> 一部分的子網域,會以隨機順序對每個父網域查詢" +"。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:656 @@ -866,17 +965,26 @@ msgid "" "shortnames, making this workaround totally not recommended in cases where " "usernames may overlap between domains." msgstr "" +"請注意,設定此選項時,所有指令的輸出格式一律為完整名稱,即使輸入使用簡短名稱" +"亦然<phrase condition=\"with_files_provider\">,但由 files 提供者管理的使用者" +"除外</phrase>。若管理員不希望輸出為完整名稱,可以使用 full_name_format 選項," +"如下所示:<quote>full_name_format=%1$s</quote> 不過請記住,登入時登入應用程式" +"常會呼叫 <citerefentry> <refentrytitle>getpwnam</refentrytitle> <manvolnum>" +"3</manvolnum> </citerefentry> 來正規化使用者名稱;若完整名稱的輸入傳回了簡短" +"名稱(在嘗試存取存在於多個網域的使用者時),可能會將登入嘗試重新導向到使用簡" +"短名稱的網域,因此在網域之間使用者名稱可能重疊的情況下,完全不建議使用此變通" +"方式。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:684 sssd.conf.5.xml:1762 sssd.conf.5.xml:4297 #: sssd-ad.5.xml:187 sssd-ad.5.xml:328 sssd-ad.5.xml:342 msgid "Default: Not set" -msgstr "" +msgstr "預設:未設定" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:689 msgid "implicit_pac_responder (boolean)" -msgstr "" +msgstr "implicit_pac_responder (boolean)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:692 @@ -885,11 +993,13 @@ msgid "" "evaluate and check the PAC. If it has to be disabled set this option to " "'false'." msgstr "" +"PAC 回應器會為 IPA 與 AD 提供者自動啟用,以評估與檢查 PAC。若必須停用,請將此" +"選項設為 'false'。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:703 msgid "core_dumpable (boolean)" -msgstr "" +msgstr "core_dumpable (boolean)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:706 @@ -898,16 +1008,18 @@ msgid "" "forbids core dumps for all SSSD processes to avoid leaking plain text " "passwords. See man page prctl:PR_SET_DUMPABLE for details." msgstr "" +"此選項可用於一般系統強化:設為 'false' 會禁止所有 SSSD 程序傾印 core,以避免" +"洩漏明文密碼。詳情請參閱 prctl:PR_SET_DUMPABLE 手冊頁。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:718 msgid "passkey_verification (string)" -msgstr "" +msgstr "passkey_verification (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:726 msgid "user_verification (boolean)" -msgstr "" +msgstr "user_verification (boolean)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:728 @@ -915,6 +1027,8 @@ msgid "" "Enable or disable the user verification (i.e. PIN, fingerprint) during " "authentication. If enabled, the PIN will always be requested." msgstr "" +"啟用或停用驗證期間的使用者驗證(例如 PIN、指紋)。若啟用,一律會要求輸入 PIN" +"。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:734 @@ -923,6 +1037,8 @@ msgid "" "kerberos pre-authentication case, this value will be overwritten by the " "server." msgstr "" +"預設行為是由金鑰設定決定如何處理。在 IPA 或 kerberos 預先驗證的情況下,此值會" +"被伺服器覆寫。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:721 @@ -931,6 +1047,8 @@ msgid "" "separated list of options. Supported options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"使用此參數可以透過逗號分隔的選項清單調整 passkey 驗證。支援的選項有" +":<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:214 @@ -942,11 +1060,15 @@ msgid "" "some other important options like the identity domains. <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"SSSD 的各項功能由特殊的 SSSD 服務提供,這些服務會與 SSSD 一同啟動與停止。服務" +"由一個通常稱為 <quote>monitor</quote> 的特殊服務管理。<quote>[sssd]</quote> " +"區段用來設定 monitor,以及身分網域等其他重要選項。<placeholder " +"type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:753 msgid "SERVICES SECTIONS" -msgstr "" +msgstr "服務區段" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:755 @@ -956,21 +1078,23 @@ msgid "" "section, for example, for NSS service, the section would be " "<quote>[nss]</quote>" msgstr "" +"本節說明可用來設定不同服務的設定。這些設定應位於 [<replaceable>$NAME</" +"replaceable>] 區段,例如 NSS 服務的區段為 <quote>[nss]</quote>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:762 msgid "General service configuration options" -msgstr "" +msgstr "一般服務設定選項" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:764 msgid "These options can be used to configure any service." -msgstr "" +msgstr "這些選項可用來設定任何服務。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:768 msgid "fd_limit" -msgstr "" +msgstr "fd_limit" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:771 @@ -981,16 +1105,19 @@ msgid "" "systems without this capability, the resulting value will be the lower value " "of this or the limits.conf \"hard\" limit." msgstr "" +"此選項指定此 SSSD 程序一次可以開啟的檔案描述符數目上限。在授予 SSSD " +"CAP_SYS_RESOURCE 能力的系統上,此為絕對設定。在沒有此能力的系統上,最終值會取" +"此值與 limits.conf \"hard\" 限制中的較低者。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:780 msgid "Default: 8192 (or limits.conf \"hard\" limit)" -msgstr "" +msgstr "預設:8192(或 limits.conf \"hard\" 限制)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:785 msgid "client_idle_timeout" -msgstr "" +msgstr "client_idle_timeout" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:788 @@ -1001,16 +1128,19 @@ msgid "" "can't be shorter than 10 seconds. If a lower value is configured, it will be " "adjusted to 10 seconds." msgstr "" +"此選項指定 SSSD 程序的用戶端可以在不進行通訊的情況下持有檔案描述符的秒數。限" +"制此值是為了避免系統資源耗盡。此逾時不能短於 10 秒。若設定了更低的值,會調整" +"為 10 秒。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:797 msgid "Default: 60, KCM: 300" -msgstr "" +msgstr "預設:60,KCM:300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:802 msgid "offline_timeout (integer)" -msgstr "" +msgstr "offline_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:805 @@ -1022,6 +1152,9 @@ msgid "" "time for the previous ones. After each unsuccessful attempt to go online, " "the new interval is recalculated by the following:" msgstr "" +"當 SSSD 切換到離線模式時,嘗試恢復上線之前的時間會依離線時間的長短而增加。依" +"預設,SSSD 使用遞增行為計算重試之間的延遲。因此,某次重試的等待時間會比先前幾" +"次更長。每次嘗試上線失敗後,會依下列方式重新計算新的間隔:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:816 sssd.conf.5.xml:872 @@ -1029,6 +1162,8 @@ msgid "" "new_delay = Minimum(old_delay * 2, offline_timeout_max) + " "random[0...offline_timeout_random_offset]" msgstr "" +"new_delay = Minimum(old_delay * 2, offline_timeout_max) + " +"random[0...offline_timeout_random_offset]" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:819 @@ -1037,43 +1172,45 @@ msgid "" "value is 3600. The offline_timeout_random_offset default value is 30. The " "end result is amount of seconds before next retry." msgstr "" +"offline_timeout 的預設值為 60。offline_timeout_max 的預設值為 3600。" +"offline_timeout_random_offset 的預設值為 30。最終結果是下一次重試前的秒數。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:825 msgid "" "Note that the maximum length of each interval is defined by " "offline_timeout_max (apart of random part)." -msgstr "" +msgstr "請注意,每個間隔的最大長度由 offline_timeout_max 定義(隨機部分除外)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:829 sssd.conf.5.xml:1172 sssd.conf.5.xml:1555 #: sssd.conf.5.xml:1851 sssd-ldap.5.xml:495 msgid "Default: 60" -msgstr "" +msgstr "預設:60" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:834 msgid "offline_timeout_max (integer)" -msgstr "" +msgstr "offline_timeout_max (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:837 msgid "" "Controls by how much the time between attempts to go online can be " "incremented following unsuccessful attempts to go online." -msgstr "" +msgstr "控制嘗試上線失敗後,每次嘗試上線之間的時間可以增加多少。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:842 msgid "A value of 0 disables the incrementing behaviour." -msgstr "" +msgstr "值為 0 會停用遞增行為。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:845 msgid "" "The value of this parameter should be set in correlation to offline_timeout " "parameter value." -msgstr "" +msgstr "此參數的值應與 offline_timeout 參數的值相關聯地設定。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:849 @@ -1083,6 +1220,9 @@ msgid "" "rule here should be to set offline_timeout_max to at least 4 times " "offline_timeout." msgstr "" +"當 offline_timeout 設為 60(預設值)時,將 offlinet_timeout_max 設為低於 120 " +"沒有意義,因為它會立即飽和。這裡的一般規則應該是將 offline_timeout_max 設為至" +"少 offline_timeout 的 4 倍。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:855 @@ -1090,23 +1230,25 @@ msgid "" "Although a value between 0 and offline_timeout may be specified, it has the " "effect of overriding the offline_timeout value so is of little use." msgstr "" +"雖然可以指定介於 0 與 offline_timeout 之間的值,但此值的效果是覆寫 " +"offline_timeout 的值,因此用處不大。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:860 msgid "Default: 3600" -msgstr "" +msgstr "預設:3600" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:865 msgid "offline_timeout_random_offset (integer)" -msgstr "" +msgstr "offline_timeout_random_offset (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:868 msgid "" "When SSSD is in offline mode it keeps probing backend servers in specified " "time intervals:" -msgstr "" +msgstr "當 SSSD 處於離線模式時,它會以指定的時間間隔持續探測後端伺服器:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:875 @@ -1114,26 +1256,28 @@ msgid "" "This parameter controls the value of the random offset used for the above " "equation. Final random_offset value will be random number in range:" msgstr "" +"此參數控制上述公式所使用的隨機偏移值。最終的 random_offset 值會是下列範圍內的" +"隨機數:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:880 msgid "[0 - offline_timeout_random_offset]" -msgstr "" +msgstr "[0 - offline_timeout_random_offset]" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:883 msgid "A value of 0 disables the random offset addition." -msgstr "" +msgstr "值為 0 會停用隨機偏移的加成。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:886 msgid "Default: 30" -msgstr "" +msgstr "預設:30" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:891 msgid "responder_idle_timeout" -msgstr "" +msgstr "responder_idle_timeout" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:894 @@ -1146,58 +1290,62 @@ msgid "" "built with systemd support and when services are either socket or D-Bus " "activated." msgstr "" +"此選項指定 SSSD 回應器程序在未使用的情況下可以運作的秒數。限制此值是為了避免" +"系統資源耗盡。此選項可接受的最小值為 60 秒。將此選項設為 0(零)表示不會對回" +"應器設定逾時。此選項只有在 SSSD 以 systemd 支援建置,且服務以 socket 或 D-" +"Bus 方式啟動時才有效。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:908 sssd.conf.5.xml:1185 sssd.conf.5.xml:2304 #: sssd-ldap.5.xml:332 msgid "Default: 300" -msgstr "" +msgstr "預設:300" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:913 msgid "cache_first" -msgstr "" +msgstr "cache_first" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:916 msgid "" "This option specifies whether the responder should query all caches before " "querying the Data Providers." -msgstr "" +msgstr "此選項指定回應器在查詢資料提供者之前,是否應先查詢所有快取。" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:931 msgid "NSS configuration options" -msgstr "" +msgstr "NSS 設定選項" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:933 msgid "" "These options can be used to configure the Name Service Switch (NSS) " "service." -msgstr "" +msgstr "這些選項可用來設定名稱服務切換 (NSS) 服務。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:938 msgid "enum_cache_timeout (integer)" -msgstr "" +msgstr "enum_cache_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:941 msgid "" "How many seconds should nss_sss cache enumerations (requests for info about " "all users)" -msgstr "" +msgstr "nss_sss 應該快取列舉(關於所有使用者的資訊要求)多少秒" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:945 msgid "Default: 120" -msgstr "" +msgstr "預設:120" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:950 msgid "entry_cache_nowait_percentage (integer)" -msgstr "" +msgstr "entry_cache_nowait_percentage (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:953 @@ -1206,6 +1354,8 @@ msgid "" "if they are requested beyond a percentage of the entry_cache_timeout value " "for the domain." msgstr "" +"若項目在超過網域的 entry_cache_timeout 值一定百分比後仍被請求,可設定項目快取" +"在背景自動更新項目。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:959 @@ -1216,6 +1366,10 @@ msgid "" "but the SSSD will go and update the cache on its own, so that future " "requests will not need to block waiting for a cache update." msgstr "" +"例如,若網域的 entry_cache_timeout 設為 30 秒,且 " +"entry_cache_nowait_percentage 設為 50(百分比),則在最後一次快取更新 15 秒後" +"進入的項目會立即傳回,但 SSSD 會自行更新快取,因此未來的要求不需要為了等待快" +"取更新而阻塞。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:969 @@ -1225,16 +1379,18 @@ msgid "" "percentage will never reduce the nowait timeout to less than 10 seconds. (0 " "disables this feature)" msgstr "" +"此選項的有效值為 0-99,代表每個網域 entry_cache_timeout 的百分比。基於效能考" +"量,此百分比絕不會將 nowait 逾時降到低於 10 秒。(0 會停用此功能)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:977 sssd.conf.5.xml:2093 msgid "Default: 50" -msgstr "" +msgstr "預設:50" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:982 msgid "entry_negative_timeout (integer)" -msgstr "" +msgstr "entry_negative_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:985 @@ -1243,16 +1399,18 @@ msgid "" "(that is, queries for invalid database entries, like nonexistent ones) " "before asking the back end again." msgstr "" +"指定 nss_sss 在再次詢問後端之前,應該快取負面快取命中(亦即對無效資料庫項目的" +"查詢,例如不存在的項目)多少秒。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:991 sssd.conf.5.xml:1750 sssd.conf.5.xml:2117 msgid "Default: 15" -msgstr "" +msgstr "預設:15" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:996 msgid "local_negative_timeout (integer)" -msgstr "" +msgstr "local_negative_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:999 @@ -1261,16 +1419,18 @@ msgid "" "negative cache before trying to look it up in the back end again. Setting " "the option to 0 disables this feature." msgstr "" +"指定 nss_sss 在再次嘗試於後端查詢本機使用者與群組之前,應該將它們保留在負面快" +"取中多少秒。將此選項設為 0 會停用此功能。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1005 msgid "Default: 14400 (4 hours)" -msgstr "" +msgstr "預設:14400(4 小時)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1010 msgid "filter_users, filter_groups (string)" -msgstr "" +msgstr "filter_users, filter_groups (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1013 @@ -1280,6 +1440,9 @@ msgid "" "also be set per-domain or include fully-qualified names to filter only users " "from the particular domain or by a user principal name (UPN)." msgstr "" +"排除從 sss NSS 資料庫取回的特定使用者或群組。這對系統帳戶特別有用。此選項也可" +"以逐網域設定,或包含完整名稱,以只過濾特定網域的使用者,或依使用者主體名稱 " +"(UPN) 過濾。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1021 @@ -1289,38 +1452,40 @@ msgid "" "NSS. E.g. a group having a member group filtered out will still have the " "member users of the latter listed." msgstr "" +"注意:filter_groups 選項不影響巢狀群組成員的繼承,因為過濾發生在成員透過 NSS " +"傳播傳回之後。例如,某個群組的成員群組被過濾掉時,後者的成員使用者仍會列出。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1029 msgid "Default: root" -msgstr "" +msgstr "預設:root" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1034 msgid "filter_users_in_groups (bool)" -msgstr "" +msgstr "filter_users_in_groups (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1037 msgid "If you want filtered user still be group members set this option to false." -msgstr "" +msgstr "若您希望被過濾的使用者仍然是群組成員,請將此選項設為 false。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1048 msgid "fallback_homedir (string)" -msgstr "" +msgstr "fallback_homedir (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1051 msgid "" "Set a default template for a user's home directory if one is not specified " "explicitly by the domain's data provider." -msgstr "" +msgstr "若網域的資料提供者沒有明確指定使用者的家目錄,請設定預設範本。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1056 msgid "The available values for this option are the same as for override_homedir." -msgstr "" +msgstr "此選項可用的值與 override_homedir 相同。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1062 @@ -1329,22 +1494,24 @@ msgid "" "fallback_homedir = /home/%u\n" " " msgstr "" +"fallback_homedir = /home/%u\n" +" " #. type: Content of: <varlistentry><listitem><para> #: sssd.conf.5.xml:1060 sssd.conf.5.xml:1622 sssd.conf.5.xml:1641 #: sssd.conf.5.xml:1718 sssd-krb5.5.xml:451 include/override_homedir.xml:66 msgid "example: <placeholder type=\"programlisting\" id=\"0\"/>" -msgstr "" +msgstr "範例:<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1066 msgid "Default: not set (no substitution for unset home directories)" -msgstr "" +msgstr "預設:未設定(未設定的家目錄不會替換)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1072 msgid "override_shell (string)" -msgstr "" +msgstr "override_shell (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1075 @@ -1353,26 +1520,28 @@ msgid "" "shell options if it takes effect and can be set either in the [nss] section " "or per-domain." msgstr "" +"覆寫所有使用者的登入 shell。若此選項生效,會取代任何其他 shell 選項,且可以" +"在 [nss] 區段或逐網域設定。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1081 msgid "Default: not set (SSSD will use the value retrieved from LDAP)" -msgstr "" +msgstr "預設:未設定(SSSD 會使用從 LDAP 取回的值)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1087 msgid "allowed_shells (string)" -msgstr "" +msgstr "allowed_shells (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1090 msgid "Restrict user shell to one of the listed values. The order of evaluation is:" -msgstr "" +msgstr "將使用者 shell 限制為列出的值之一。評估順序為:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1093 msgid "1. If the shell is present in <quote>/etc/shells</quote>, it is used." -msgstr "" +msgstr "1. 若 shell 存在於 <quote>/etc/shells</quote>,則使用它。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1097 @@ -1380,6 +1549,8 @@ msgid "" "2. If the shell is in the allowed_shells list but not in " "<quote>/etc/shells</quote>, use the value of the shell_fallback parameter." msgstr "" +"2. 若 shell 在 allowed_shells 清單中但不在 <quote>/etc/shells</quote>,使用 " +"shell_fallback 參數的值。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1102 @@ -1387,11 +1558,13 @@ msgid "" "3. If the shell is not in the allowed_shells list and not in " "<quote>/etc/shells</quote>, a nologin shell is used." msgstr "" +"3. 若 shell 不在 allowed_shells 清單中且不在 <quote>/etc/shells</quote>,使" +"用 nologin shell。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1107 msgid "The wildcard (*) can be used to allow any shell." -msgstr "" +msgstr "可以使用萬用字元 (*) 允許任何 shell。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1110 @@ -1400,11 +1573,13 @@ msgid "" "shell is not in <quote>/etc/shells</quote> and maintaining list of all " "allowed shells in allowed_shells would be to much overhead." msgstr "" +"若您希望在使用者 shell 不在 <quote>/etc/shells</quote> 時使用 shell_fallback" +",且維護 allowed_shells 中所有允許 shell 的清單負擔過重,(*) 就很有用。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1117 msgid "An empty string for shell is passed as-is to libc." -msgstr "" +msgstr "shell 的空字串會原樣傳給 libc。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1120 @@ -1412,43 +1587,45 @@ msgid "" "The <quote>/etc/shells</quote> is only read on SSSD start up, which means " "that a restart of the SSSD is required in case a new shell is installed." msgstr "" +"<quote>/etc/shells</quote> 只在 SSSD 啟動時讀取,這表示安裝新 shell 後需要重" +"新啟動 SSSD。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1124 msgid "Default: Not set. The user shell is automatically used." -msgstr "" +msgstr "預設:未設定。會自動使用使用者 shell。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1129 msgid "vetoed_shells (string)" -msgstr "" +msgstr "vetoed_shells (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1132 msgid "Replace any instance of these shells with the shell_fallback" -msgstr "" +msgstr "以 shell_fallback 取代這些 shell 的任何實例" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1137 msgid "shell_fallback (string)" -msgstr "" +msgstr "shell_fallback (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1140 msgid "" "The default shell to use if an allowed shell is not installed on the " "machine." -msgstr "" +msgstr "若允許的 shell 未安裝在機器上時要使用的預設 shell。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1144 msgid "Default: /bin/sh" -msgstr "" +msgstr "預設:/bin/sh" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1149 msgid "default_shell" -msgstr "" +msgstr "default_shell" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1152 @@ -1457,6 +1634,8 @@ msgid "" "lookup. This option can be specified globally in the [nss] section or " "per-domain." msgstr "" +"若提供者在查詢時沒有傳回 shell,則使用的預設 shell。此選項可以在 [nss] 區段全" +"域指定,或逐網域指定。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1158 @@ -1464,37 +1643,39 @@ msgid "" "Default: not set (Return NULL if no shell is specified and rely on libc to " "substitute something sensible when necessary, usually /bin/sh)" msgstr "" +"預設:未設定(若未指定 shell 則傳回 NULL,必要時依賴 libc 替換為合理的值,通" +"常是 /bin/sh)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1165 sssd.conf.5.xml:1548 msgid "get_domains_timeout (int)" -msgstr "" +msgstr "get_domains_timeout (int)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1168 sssd.conf.5.xml:1551 msgid "" "Specifies time in seconds for which the list of subdomains will be " "considered valid." -msgstr "" +msgstr "指定子網域清單被視為有效的時間(秒)。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1177 msgid "memcache_timeout (integer)" -msgstr "" +msgstr "memcache_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1180 msgid "" "Specifies time in seconds for which records in the in-memory cache will be " "valid. Setting this option to zero will disable the in-memory cache." -msgstr "" +msgstr "指定記憶體快取中的記錄有效的秒數。將此選項設為零會停用記憶體快取。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1188 msgid "" "WARNING: Disabling the in-memory cache will have significant negative impact " "on SSSD's performance and should only be used for testing." -msgstr "" +msgstr "警告:停用記憶體快取會對 SSSD 的效能造成重大負面影響,只應用於測試。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1194 sssd.conf.5.xml:1219 sssd.conf.5.xml:1244 @@ -1503,11 +1684,13 @@ msgid "" "NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", " "client applications will not use the fast in-memory cache." msgstr "" +"注意:若環境變數 SSS_NSS_USE_MEMCACHE 設為 \"NO\",用戶端應用程式不會使用快速" +"的記憶體快取。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1202 msgid "memcache_size_passwd (integer)" -msgstr "" +msgstr "memcache_size_passwd (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1205 @@ -1516,11 +1699,13 @@ msgid "" "for passwd requests. Setting the size to 0 will disable the passwd " "in-memory cache." msgstr "" +"快速記憶體快取內為 passwd 要求配置的資料表大小(以 MB 為單位)。將大小設為 0 " +"會停用 passwd 記憶體快取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1211 sssd.conf.5.xml:2963 sssd-ldap.5.xml:549 msgid "Default: 8" -msgstr "" +msgstr "預設:8" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1214 sssd.conf.5.xml:1239 sssd.conf.5.xml:1264 @@ -1528,12 +1713,12 @@ msgstr "" msgid "" "WARNING: Disabled or too small in-memory cache can have significant negative " "impact on SSSD's performance." -msgstr "" +msgstr "警告:停用或太小的記憶體快取會對 SSSD 的效能造成重大負面影響。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1227 msgid "memcache_size_group (integer)" -msgstr "" +msgstr "memcache_size_group (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1230 @@ -1542,18 +1727,20 @@ msgid "" "for group requests. Setting the size to 0 will disable the group in-memory " "cache." msgstr "" +"快速記憶體快取內為群組要求配置的資料表大小(以 MB 為單位)。將大小設為 0 會停" +"用群組記憶體快取。" #. type: Content of: <variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1236 sssd.conf.5.xml:1288 sssd.conf.5.xml:3724 #: sssd-ldap.5.xml:474 sssd-ldap.5.xml:526 include/failover.xml:116 #: include/krb5_options.xml:11 msgid "Default: 6" -msgstr "" +msgstr "預設:6" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1252 msgid "memcache_size_initgroups (integer)" -msgstr "" +msgstr "memcache_size_initgroups (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1255 @@ -1562,11 +1749,13 @@ msgid "" "for initgroups requests. Setting the size to 0 will disable the initgroups " "in-memory cache." msgstr "" +"快速記憶體快取內為 initgroups 要求配置的資料表大小(以 MB 為單位)。將大小設" +"為 0 會停用 initgroups 記憶體快取。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1277 msgid "memcache_size_sid (integer)" -msgstr "" +msgstr "memcache_size_sid (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1280 @@ -1576,11 +1765,14 @@ msgid "" "currently cached in fast in-memory cache. Setting the size to 0 will " "disable the SID in-memory cache." msgstr "" +"快速記憶體快取內為 SID 相關要求配置的資料表大小(以 MB 為單位)。目前只有 " +"SID-by-ID 與 ID-by-SID 要求會快取在快速記憶體快取中。將大小設為 0 會停用 SID " +"記憶體快取。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:1304 sssd-ifp.5.xml:90 msgid "user_attributes (string)" -msgstr "" +msgstr "user_attributes (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1307 @@ -1593,6 +1785,10 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> for details) but with no default " "values." msgstr "" +"部分額外的 NSS 回應器要求可以傳回比 NSS 介面定義的 POSIX 屬性更多的屬性。屬性" +"清單由此選項控制。其處理方式與 InfoPipe 回應器的 <quote>user_attributes</" +"quote> 選項相同(詳情請參閱 <citerefentry> <refentrytitle>sssd-ifp</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>),但沒有預設值。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1320 @@ -1600,35 +1796,37 @@ msgid "" "To make configuration more easy the NSS responder will check the InfoPipe " "option if it is not set for the NSS responder." msgstr "" +"為了讓設定更容易,若 NSS 回應器沒有設定 InfoPipe 選項,NSS 回應器會檢查該選項" +"。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1325 msgid "Default: not set, fallback to InfoPipe option" -msgstr "" +msgstr "預設:未設定,退回 InfoPipe 選項" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1330 msgid "pwfield (string)" -msgstr "" +msgstr "pwfield (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1333 msgid "" "The value that NSS operations that return users or groups will return for " "the <quote>password</quote> field." -msgstr "" +msgstr "傳回使用者或群組的 NSS 作業會為 <quote>password</quote> 欄位傳回的值。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1338 msgid "Default: <quote>*</quote>" -msgstr "" +msgstr "預設:<quote>*</quote>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1341 msgid "" "Note: This option can also be set per-domain which overwrites the value in " "[nss] section." -msgstr "" +msgstr "注意:此選項也可以逐網域設定,會覆寫 [nss] 區段中的值。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1345 @@ -1638,52 +1836,55 @@ msgid "" "</phrase> <quote>x</quote> (proxy domain with nss_files and sssd-shadowutils " "target)" msgstr "" +"預設:<quote>未設定</quote>(遠端網域),<phrase " +"condition=\"with_files_provider\"> <quote>x</quote>(files 網域),</phrase> " +"<quote>x</quote>(以 nss_files 與 sssd-shadowutils 為目標的 proxy 網域)" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:1357 msgid "PAM configuration options" -msgstr "" +msgstr "PAM 設定選項" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:1359 msgid "" "These options can be used to configure the Pluggable Authentication Module " "(PAM) service." -msgstr "" +msgstr "這些選項可用來設定可插拔驗證模組 (PAM) 服務。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1364 msgid "offline_credentials_expiration (integer)" -msgstr "" +msgstr "offline_credentials_expiration (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1367 msgid "" "If the authentication provider is offline, how long should we allow cached " "logins (in days since the last successful online login)." -msgstr "" +msgstr "若驗證提供者離線,允許快取登入多久(以自上次成功線上登入起的天數計)。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1372 sssd.conf.5.xml:1385 msgid "Default: 0 (No limit)" -msgstr "" +msgstr "預設:0(無限制)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1378 msgid "offline_failed_login_attempts (integer)" -msgstr "" +msgstr "offline_failed_login_attempts (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1381 msgid "" "If the authentication provider is offline, how many failed login attempts " "are allowed." -msgstr "" +msgstr "若驗證提供者離線,允許多少次失敗的登入嘗試。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1391 msgid "offline_failed_login_delay (integer)" -msgstr "" +msgstr "offline_failed_login_delay (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1394 @@ -1691,6 +1892,8 @@ msgid "" "The time in minutes which has to pass after offline_failed_login_attempts " "has been reached before a new login attempt is possible." msgstr "" +"在達到 offline_failed_login_attempts 之後、可以再次嘗試登入之前,必須經過的時" +"間(分鐘)。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1399 @@ -1699,58 +1902,60 @@ msgid "" "offline_failed_login_attempts has been reached. Only a successful online " "authentication can enable offline authentication again." msgstr "" +"若設為 0,當 offline_failed_login_attempts 已達上限時,使用者無法離線驗證。只" +"有成功的線上驗證才能再次啟用離線驗證。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1405 sssd.conf.5.xml:1515 msgid "Default: 5" -msgstr "" +msgstr "預設:5" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1411 msgid "pam_verbosity (integer)" -msgstr "" +msgstr "pam_verbosity (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1414 msgid "" "Controls what kind of messages are shown to the user during " "authentication. The higher the number to more messages are displayed." -msgstr "" +msgstr "控制驗證期間會向使用者顯示哪種訊息。數字越高,顯示的訊息越多。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1419 msgid "Currently sssd supports the following values:" -msgstr "" +msgstr "目前 sssd 支援下列值:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1422 msgid "<emphasis>0</emphasis>: do not show any message" -msgstr "" +msgstr "<emphasis>0</emphasis>:不顯示任何訊息" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1425 msgid "<emphasis>1</emphasis>: show only important messages" -msgstr "" +msgstr "<emphasis>1</emphasis>:只顯示重要訊息" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1429 msgid "<emphasis>2</emphasis>: show informational messages" -msgstr "" +msgstr "<emphasis>2</emphasis>:顯示資訊訊息" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1432 msgid "<emphasis>3</emphasis>: show all messages and debug information" -msgstr "" +msgstr "<emphasis>3</emphasis>:顯示所有訊息與除錯資訊" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1436 sssd.8.xml:63 msgid "Default: 1" -msgstr "" +msgstr "預設:1" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1442 msgid "pam_response_filter (string)" -msgstr "" +msgstr "pam_response_filter (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1445 @@ -1760,6 +1965,9 @@ msgid "" "responses sent to pam_sss e.g. messages displayed to the user or environment " "variables which should be set by pam_sss." msgstr "" +"以逗號分隔的字串清單,允許移除(過濾)PAM 回應器傳送給 pam_sss PAM 模組的資料" +"。傳送給 pam_sss 的回應有不同種類,例如顯示給使用者的訊息或應由 pam_sss 設定" +"的環境變數。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1453 @@ -1767,43 +1975,45 @@ msgid "" "While messages already can be controlled with the help of the pam_verbosity " "option this option allows to filter out other kind of responses as well." msgstr "" +"雖然訊息已經可以透過 pam_verbosity 選項控制,此選項也允許過濾掉其他種類的回應" +"。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1460 msgid "ENV" -msgstr "" +msgstr "ENV" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1461 msgid "Do not send any environment variables to any service." -msgstr "" +msgstr "不將任何環境變數傳送給任何服務。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1464 msgid "ENV:var_name" -msgstr "" +msgstr "ENV:var_name" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1465 msgid "Do not send environment variable var_name to any service." -msgstr "" +msgstr "不將環境變數 var_name 傳送給任何服務。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1469 msgid "ENV:var_name:service" -msgstr "" +msgstr "ENV:var_name:service" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1470 msgid "Do not send environment variable var_name to service." -msgstr "" +msgstr "不將環境變數 var_name 傳送給 service。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1458 msgid "" "Currently the following filters are supported: <placeholder " "type=\"variablelist\" id=\"0\"/>" -msgstr "" +msgstr "目前支援下列過濾器:<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1477 @@ -1815,21 +2025,25 @@ msgid "" "that either all list elements must have a '+' or '-' prefix or none. It is " "considered as an error to mix both styles." msgstr "" +"字串清單可以是過濾器清單,設定此過濾器清單並覆寫預設值;或者清單的每個元素可" +"以加上 '+' 或 '-' 字元前綴,分別將過濾器加入現有預設值或從預設值移除。請注意" +",清單元素必須全部加上 '+' 或 '-' 前綴,或全部不加。混用兩種樣式會被視為錯誤" +"。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1488 msgid "Default: ENV:KRB5CCNAME:sudo, ENV:KRB5CCNAME:sudo-i" -msgstr "" +msgstr "預設:ENV:KRB5CCNAME:sudo、ENV:KRB5CCNAME:sudo-i" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1491 msgid "Example: -ENV:KRB5CCNAME:sudo-i will remove the filter from the default list" -msgstr "" +msgstr "範例:-ENV:KRB5CCNAME:sudo-i 會從預設清單移除該過濾器" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1498 msgid "pam_id_timeout (integer)" -msgstr "" +msgstr "pam_id_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1501 @@ -1838,6 +2052,8 @@ msgid "" "immediately update the cached identity information for the user in order to " "ensure that authentication takes place with the latest information." msgstr "" +"SSSD 在線上時,對於任何 PAM 要求,SSSD 都會嘗試立即更新使用者的快取身分資訊," +"以確保驗證使用最新的資訊進行。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1507 @@ -1848,16 +2064,19 @@ msgid "" "identity information to avoid excessive round-trips to the identity " "provider." msgstr "" +"完整的 PAM 對話可能執行多個 PAM 要求,例如帳戶管理與開啟工作階段。此選項控制" +"(以每個用戶端應用程式為單位)可以快取身分資訊多久(秒),以避免過度往返身分" +"提供者。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1521 msgid "pam_pwd_expiration_warning (integer)" -msgstr "" +msgstr "pam_pwd_expiration_warning (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1524 sssd.conf.5.xml:2987 msgid "Display a warning N days before the password expires." -msgstr "" +msgstr "在密碼到期前 N 天顯示警告。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1527 @@ -1866,6 +2085,8 @@ msgid "" "expiration time of the password. If this information is missing, sssd " "cannot display a warning." msgstr "" +"請注意,後端伺服器必須提供密碼到期時間的資訊。若缺少此資訊,sssd 無法顯示警告" +"。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1533 sssd.conf.5.xml:2990 @@ -1873,25 +2094,25 @@ msgid "" "If zero is set, then this filter is not applied, i.e. if the expiration " "warning was received from backend server, it will automatically be " "displayed." -msgstr "" +msgstr "若設為零,則不套用此過濾器,亦即若收到來自後端伺服器的到期警告,會自動顯示。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1538 msgid "" "This setting can be overridden by setting " "<emphasis>pwd_expiration_warning</emphasis> for a particular domain." -msgstr "" +msgstr "可以為特定網域設定 <emphasis>pwd_expiration_warning</emphasis> 來覆寫此設定。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1543 sssd.conf.5.xml:3990 sssd-ldap.5.xml:607 #: sssd-ldap.5.xml:1673 sssd.8.xml:79 msgid "Default: 0" -msgstr "" +msgstr "預設:0" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1560 msgid "pam_trusted_users (string)" -msgstr "" +msgstr "pam_trusted_users (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1563 @@ -1902,11 +2123,14 @@ msgid "" "<quote>pam_public_domains</quote>. User names are resolved to UIDs at " "startup." msgstr "" +"指定允許對受信任網域執行 PAM 對話的 UID 值或使用者名稱清單(以逗號分隔)。未" +"包含在此清單中的使用者只能存取以 <quote>pam_public_domains</quote> 標記為公開" +"的網域。使用者名稱會在啟動時解析為 UID。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1573 msgid "Default: All users are considered trusted by default" -msgstr "" +msgstr "預設:依預設所有使用者都被視為受信任" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1577 @@ -1914,54 +2138,56 @@ msgid "" "Please note that UID 0 is always allowed to access the PAM responder even in " "case it is not in the pam_trusted_users list." msgstr "" +"請注意,UID 0 一律允許存取 PAM 回應器,即使它不在 pam_trusted_users 清單中亦" +"然。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1584 msgid "pam_public_domains (string)" -msgstr "" +msgstr "pam_public_domains (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1587 msgid "" "Specifies the comma-separated list of domain names that are accessible even " "to untrusted users." -msgstr "" +msgstr "指定即使是不受信任的使用者也可以存取的網域名稱清單(以逗號分隔)。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1591 msgid "Two special values for pam_public_domains option are defined:" -msgstr "" +msgstr "定義了 pam_public_domains 選項的兩個特殊值:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1595 msgid "all (Untrusted users are allowed to access all domains in PAM responder.)" -msgstr "" +msgstr "all(允許不受信任的使用者存取 PAM 回應器中的所有網域。)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1599 msgid "" "none (Untrusted users are not allowed to access any domains PAM in " "responder.)" -msgstr "" +msgstr "none(不允許不受信任的使用者存取回應器中的任何 PAM 網域。)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1603 sssd.conf.5.xml:1628 sssd.conf.5.xml:1647 #: sssd.conf.5.xml:1884 sssd.conf.5.xml:2725 sssd.conf.5.xml:3919 #: sssd-ldap.5.xml:1210 msgid "Default: none" -msgstr "" +msgstr "預設:none" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1608 msgid "pam_account_expired_message (string)" -msgstr "" +msgstr "pam_account_expired_message (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1611 msgid "" "Allows a custom expiration message to be set, replacing the default " "'Permission denied' message." -msgstr "" +msgstr "允許設定自訂的到期訊息,取代預設的 'Permission denied' 訊息。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1616 @@ -1969,6 +2195,8 @@ msgid "" "Note: Please be aware that message is only printed for the SSH service " "unless pam_verbosity is set to 3 (show all messages and debug information)." msgstr "" +"注意:除非 pam_verbosity 設為 3(顯示所有訊息與除錯資訊),否則此訊息只會為 " +"SSH 服務顯示。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1624 @@ -1977,18 +2205,20 @@ msgid "" "pam_account_expired_message = Account expired, please contact help desk.\n" " " msgstr "" +"pam_account_expired_message = Account expired, please contact help desk.\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1633 msgid "pam_account_locked_message (string)" -msgstr "" +msgstr "pam_account_locked_message (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1636 msgid "" "Allows a custom lockout message to be set, replacing the default 'Permission " "denied' message." -msgstr "" +msgstr "允許設定自訂的鎖定訊息,取代預設的 'Permission denied' 訊息。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1643 @@ -1997,32 +2227,34 @@ msgid "" "pam_account_locked_message = Account locked, please contact help desk.\n" " " msgstr "" +"pam_account_locked_message = Account locked, please contact help desk.\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1652 msgid "pam_passkey_auth (bool)" -msgstr "" +msgstr "pam_passkey_auth (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1655 msgid "Enable passkey device based authentication." -msgstr "" +msgstr "啟用以 passkey 裝置為基礎的驗證。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1658 sssd.conf.5.xml:1970 sssd-ad.5.xml:1272 #: sss_rpcidmapd.5.xml:76 sssd-files.5.xml:145 msgid "Default: True" -msgstr "" +msgstr "預設:True" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1663 msgid "passkey_debug_libfido2 (bool)" -msgstr "" +msgstr "passkey_debug_libfido2 (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1666 msgid "Enable libfido2 library debug messages." -msgstr "" +msgstr "啟用 libfido2 程式庫的除錯訊息。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1669 sssd.conf.5.xml:1683 sssd-ldap.5.xml:672 @@ -2030,12 +2262,12 @@ msgstr "" #: sssd-ad.5.xml:506 sssd-ad.5.xml:582 sssd-ad.5.xml:1127 sssd-ad.5.xml:1176 #: include/ldap_id_mapping.xml:250 msgid "Default: False" -msgstr "" +msgstr "預設:False" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1674 msgid "pam_cert_auth (bool)" -msgstr "" +msgstr "pam_cert_auth (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1677 @@ -2044,33 +2276,35 @@ msgid "" "additional communication with the Smartcard which will delay the " "authentication process this option is disabled by default." msgstr "" +"啟用以憑證為基礎的智慧卡驗證。由於這需要與智慧卡進行額外通訊,會延遲驗證流程" +",因此此選項依預設停用。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1688 msgid "pam_cert_db_path (string)" -msgstr "" +msgstr "pam_cert_db_path (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1691 msgid "The path to the certificate database." -msgstr "" +msgstr "憑證資料庫的路徑。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1694 sssd.conf.5.xml:2219 sssd.conf.5.xml:4411 msgid "Default:" -msgstr "" +msgstr "預設:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1696 sssd.conf.5.xml:2221 msgid "" "/etc/sssd/pki/sssd_auth_ca_db.pem (path to a file with trusted CA " "certificates in PEM format)" -msgstr "" +msgstr "/etc/sssd/pki/sssd_auth_ca_db.pem(包含 PEM 格式受信任 CA 憑證之檔案的路徑)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1706 msgid "pam_cert_verification (string)" -msgstr "" +msgstr "pam_cert_verification (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1709 @@ -2081,6 +2315,9 @@ msgid "" "section. Supported options are the same of " "<quote>certificate_verification</quote>." msgstr "" +"使用此參數可以透過逗號分隔的選項清單調整 PAM 憑證驗證,這些選項會覆寫 <quote>" +"[sssd]</quote> 區段中的 <quote>certificate_verification</quote> 值。支援的選" +"項與 <quote>certificate_verification</quote> 相同。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1720 @@ -2089,6 +2326,8 @@ msgid "" "pam_cert_verification = partial_chain\n" " " msgstr "" +"pam_cert_verification = partial_chain\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1724 @@ -2096,50 +2335,52 @@ msgid "" "Default: not set, i.e. use default <quote>certificate_verification</quote> " "option defined in <quote>[sssd]</quote> section." msgstr "" +"預設:未設定,亦即使用 <quote>[sssd]</quote> 區段中定義的預設 <quote>" +"certificate_verification</quote> 選項。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1731 msgid "p11_child_timeout (integer)" -msgstr "" +msgstr "p11_child_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1734 msgid "How many seconds will pam_sss wait for p11_child to finish." -msgstr "" +msgstr "pam_sss 會等待 p11_child 完成多少秒。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1743 msgid "passkey_child_timeout (integer)" -msgstr "" +msgstr "passkey_child_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1746 msgid "How many seconds will the PAM responder wait for passkey_child to finish." -msgstr "" +msgstr "PAM 回應器會等待 passkey_child 完成多少秒。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1755 msgid "pam_app_services (string)" -msgstr "" +msgstr "pam_app_services (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1758 msgid "" "Which PAM services are permitted to contact domains of type " "<quote>application</quote>" -msgstr "" +msgstr "允許哪些 PAM 服務聯絡 <quote>application</quote> 類型的網域" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1767 msgid "pam_p11_allowed_services (string)" -msgstr "" +msgstr "pam_p11_allowed_services (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1770 msgid "" "A comma-separated list of PAM service names for which it will be allowed to " "use Smartcards." -msgstr "" +msgstr "允許使用智慧卡的 PAM 服務名稱清單(以逗號分隔)。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1785 @@ -2148,6 +2389,8 @@ msgid "" "pam_p11_allowed_services = +my_pam_service, -login\n" " " msgstr "" +"pam_p11_allowed_services = +my_pam_service, -login\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1774 @@ -2160,62 +2403,67 @@ msgid "" "(e.g. <quote>my_pam_service</quote>), you would use the following " "configuration: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"可以使用 <quote>+service_name</quote> 將另一個 PAM 服務名稱加入預設集合,或使" +"用 <quote>-service_name</quote> 明確地從預設集合移除某個 PAM 服務名稱。例如," +"若要將智慧卡驗證的預設 PAM 服務名稱(例如 <quote>login</quote>)替換為自訂的 " +"PAM 服務名稱(例如 <quote>my_pam_service</quote>),請使用下列設定" +":<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1789 sssd-ad.5.xml:645 sssd-ad.5.xml:754 sssd-ad.5.xml:812 #: sssd-ad.5.xml:870 sssd-ad.5.xml:948 msgid "Default: the default set of PAM service names includes:" -msgstr "" +msgstr "預設:預設的 PAM 服務名稱集合包含:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1794 sssd-ad.5.xml:649 msgid "login" -msgstr "" +msgstr "login" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1799 sssd-ad.5.xml:654 msgid "su" -msgstr "" +msgstr "su" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1804 sssd-ad.5.xml:659 msgid "su-l" -msgstr "" +msgstr "su-l" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1809 sssd-ad.5.xml:674 msgid "gdm-smartcard" -msgstr "" +msgstr "gdm-smartcard" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1814 sssd-ad.5.xml:669 msgid "gdm-password" -msgstr "" +msgstr "gdm-password" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1819 sssd-ad.5.xml:679 msgid "kdm" -msgstr "" +msgstr "kdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1824 sssd-ad.5.xml:957 msgid "sudo" -msgstr "" +msgstr "sudo" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1829 sssd-ad.5.xml:962 msgid "sudo-i" -msgstr "" +msgstr "sudo-i" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:1834 msgid "gnome-screensaver" -msgstr "" +msgstr "gnome-screensaver" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1842 msgid "p11_wait_for_card_timeout (integer)" -msgstr "" +msgstr "p11_wait_for_card_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1845 @@ -2224,11 +2472,13 @@ msgid "" "to p11_child_timeout should the PAM responder wait until a Smartcard is " "inserted." msgstr "" +"若需要智慧卡驗證,PAM 回應器在 p11_child_timeout 之外,還應該多等待多少秒直到" +"插入智慧卡。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1856 msgid "p11_uri (string)" -msgstr "" +msgstr "p11_uri (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1859 @@ -2240,6 +2490,10 @@ msgid "" "first slot found. If multiple readers are connected p11_uri can be used to " "tell p11_child to use a specific reader." msgstr "" +"PKCS#11 URI(詳情請參閱 RFC-7512),可用來限制智慧卡驗證所使用的裝置選擇。依" +"預設,SSSD 的 p11_child 會搜尋設定 'removable' 旗標的 PKCS#11 插槽(讀卡機)" +",並從找到的第一個插槽讀取已插入權杖中的憑證。若連接了多台讀卡機,可以使用 " +"p11_uri 告訴 p11_child 使用特定的讀卡機。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1872 @@ -2248,6 +2502,8 @@ msgid "" "p11_uri = pkcs11:slot-description=My%20Smartcard%20Reader\n" " " msgstr "" +"p11_uri = pkcs11:slot-description=My%20Smartcard%20Reader\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1876 @@ -2257,6 +2513,9 @@ msgid "" "pkcs11:library-description=OpenSC%20smartcard%20framework;slot-id=2\n" " " msgstr "" +"p11_uri = pkcs11:library-description=OpenSC%20smartcard%20framework;slot-" +"id=2\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1870 @@ -2266,45 +2525,49 @@ msgid "" "debug output of p11_child. As an alternative the GnuTLS utility 'p11tool' " "with e.g. the '--list-all' will show PKCS#11 URIs as well." msgstr "" +"範例:<placeholder type=\"programlisting\" id=\"0\"/> 或 <placeholder " +"type=\"programlisting\" id=\"1\"/> 若要尋找合適的 URI,請檢查 p11_child 的除" +"錯輸出。或者,GnuTLS 工具程式 'p11tool'(例如搭配 '--list-all')也會顯示 " +"PKCS#11 URI。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1889 msgid "pam_initgroups_scheme" -msgstr "" +msgstr "pam_initgroups_scheme" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1897 msgid "always" -msgstr "" +msgstr "always" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1898 msgid "Always do an online lookup, please note that pam_id_timeout still applies" -msgstr "" +msgstr "一律執行線上查詢,請注意 pam_id_timeout 仍然適用" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1902 msgid "no_session" -msgstr "" +msgstr "no_session" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1903 msgid "" "Only do an online lookup if there is no active session of the user, i.e. if " "the user is currently not logged in" -msgstr "" +msgstr "只有在使用者沒有作用中的工作階段(亦即使用者目前未登入)時才執行線上查詢" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:1908 msgid "never" -msgstr "" +msgstr "never" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1909 msgid "" "Never force an online lookup, use the data from the cache as long as they " "are not expired" -msgstr "" +msgstr "絕不強制執行線上查詢,只要快取中的資料尚未到期就使用它們" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1892 @@ -2314,30 +2577,33 @@ msgid "" "should be done and the following values are allowed: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"PAM 回應器可以強制執行線上查詢,以取得嘗試登入之使用者目前的群組成員資格。此" +"選項控制何時應執行此動作,允許下列值:<placeholder type=\"variablelist\" " +"id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1916 msgid "Default: no_session" -msgstr "" +msgstr "預設:no_session" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:1921 sssd.conf.5.xml:4350 msgid "pam_gssapi_services" -msgstr "" +msgstr "pam_gssapi_services" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1924 msgid "" "Comma separated list of PAM services that are allowed to try GSSAPI " "authentication using pam_sss_gss.so module." -msgstr "" +msgstr "允許使用 pam_sss_gss.so 模組嘗試 GSSAPI 驗證的 PAM 服務清單(以逗號分隔)。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1929 msgid "" "To disable GSSAPI authentication, set this option to <quote>-</quote> " "(dash)." -msgstr "" +msgstr "若要停用 GSSAPI 驗證,請將此選項設為 <quote>-</quote>(破折號)。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1933 sssd.conf.5.xml:1964 sssd.conf.5.xml:2002 @@ -2346,6 +2612,8 @@ msgid "" "[pam] section. It can also be set for trusted domain which overwrites the " "value in the domain section." msgstr "" +"注意:此選項也可以逐網域設定,會覆寫 [pam] 區段中的值。也可以為受信任網域設定" +",會覆寫網域區段中的值。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:1941 @@ -2354,21 +2622,23 @@ msgid "" "pam_gssapi_services = sudo, sudo-i\n" " " msgstr "" +"pam_gssapi_services = sudo, sudo-i\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1939 sssd.conf.5.xml:3913 msgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>" -msgstr "" +msgstr "範例:<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1945 msgid "Default: - (GSSAPI authentication is disabled)" -msgstr "" +msgstr "預設:-(GSSAPI 驗證已停用)" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:1950 sssd.conf.5.xml:4351 msgid "pam_gssapi_check_upn" -msgstr "" +msgstr "pam_gssapi_check_upn" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1953 @@ -2377,18 +2647,20 @@ msgid "" "successfully authenticated through GSSAPI can be associated with the user " "who is being authenticated. Authentication will fail if the check fails." msgstr "" +"若為 True,SSSD 會要求透過 GSSAPI 成功驗證的 Kerberos 使用者主體可以與正在驗" +"證的使用者關聯。若檢查失敗,驗證會失敗。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1960 msgid "" "If False, every user that is able to obtained required service ticket will " "be authenticated." -msgstr "" +msgstr "若為 False,任何能夠取得所需服務票證的使用者都會被驗證。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:1975 msgid "pam_gssapi_indicators_map" -msgstr "" +msgstr "pam_gssapi_indicators_map" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1978 @@ -2397,6 +2669,8 @@ msgid "" "a Kerberos ticket to access a PAM service that is allowed to try GSSAPI " "authentication using pam_sss_gss.so module." msgstr "" +"要存取允許使用 pam_sss_gss.so 模組嘗試 GSSAPI 驗證的 PAM 服務,Kerberos 票證" +"中必須包含的驗證指示器清單(以逗號分隔)。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1984 @@ -2412,6 +2686,13 @@ msgid "" "be denied. If the resulting list of indicators for the PAM service is empty, " "the check will not prevent the access." msgstr "" +"清單的每個元素可以是驗證指示器名稱,或 <quote>service:indicator</quote> 配對" +"。未加上 PAM 服務名稱前綴的指示器,會是存取任何設定搭配 <option>" +"pam_gssapi_services</option> 使用的 PAM 服務所必需的。接著,pam_sss_gss.so 會" +"在驗證期間,將每個 PAM 服務產生的指示器清單與 Kerberos 票證中的指示器比對。票" +"證中任何與該 PAM 服務產生之指示器清單相符的指示器都會授予存取權。若清單中的指" +"示器都沒有相符,則會拒絕存取。若該 PAM 服務產生的指示器清單為空,此檢查不會阻" +"止存取。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:1997 @@ -2420,44 +2701,46 @@ msgid "" "<quote>-</quote> (dash). To disable the check for a specific PAM service, " "add <quote>service:-</quote>." msgstr "" +"若要停用 GSSAPI 驗證指示器檢查,請將此選項設為 <quote>-</quote>(破折號)。若" +"要為特定 PAM 服務停用檢查,請加入 <quote>service:-</quote>。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2008 msgid "" "Following authentication indicators are supported by IPA Kerberos " "deployments:" -msgstr "" +msgstr "IPA Kerberos 部署支援下列驗證指示器:" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:2011 msgid "" "pkinit -- pre-authentication using X.509 certificates -- whether stored in " "files or on smart cards." -msgstr "" +msgstr "pkinit -- 使用 X.509 憑證進行預先驗證(無論是儲存在檔案中或智慧卡上)。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:2014 msgid "" "hardened -- SPAKE pre-authentication or any pre-authentication wrapped in a " "FAST channel." -msgstr "" +msgstr "hardened -- SPAKE 預先驗證,或任何包裝在 FAST 通道中的預先驗證。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:2017 msgid "radius -- pre-authentication with the help of a RADIUS server." -msgstr "" +msgstr "radius -- 借助 RADIUS 伺服器的預先驗證。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:2020 msgid "" "otp -- pre-authentication using integrated two-factor authentication (2FA or " "one-time password, OTP) in IPA." -msgstr "" +msgstr "otp -- 在 IPA 中使用整合式雙重因素驗證(2FA 或一次性密碼,OTP)進行預先驗證。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:2023 msgid "idp -- pre-authentication using external identity provider." -msgstr "" +msgstr "idp -- 使用外部身分提供者的預先驗證。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:2033 @@ -2466,6 +2749,8 @@ msgid "" "pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" " " msgstr "" +"pam_gssapi_indicators_map = sudo:pkinit, sudo-i:pkinit\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2028 @@ -2474,16 +2759,18 @@ msgid "" "their Kerberos tickets with a X.509 certificate pre-authentication (PKINIT), " "set <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"範例:若只要讓以 X.509 憑證預先驗證(PKINIT)取得 Kerberos 票證的使用者存取 " +"SUDO 服務,請設定 <placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2037 msgid "Default: not set (use of authentication indicators is not required)" -msgstr "" +msgstr "預設:未設定(不要求使用驗證指示器)" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:2045 msgid "SUDO configuration options" -msgstr "" +msgstr "SUDO 設定選項" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:2047 @@ -2496,23 +2783,28 @@ msgid "" "<citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry>." msgstr "" +"這些選項可用來設定 sudo 服務。<citerefentry> <refentrytitle>sudo</" +"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> 與 <citerefentry> " +"<refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> " +"搭配使用的詳細設定說明,請參閱手冊頁 <citerefentry> <refentrytitle>sssd-" +"sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2064 msgid "sudo_timed (bool)" -msgstr "" +msgstr "sudo_timed (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2067 msgid "" "Whether or not to evaluate the sudoNotBefore and sudoNotAfter attributes " "that implement time-dependent sudoers entries." -msgstr "" +msgstr "是否評估實作時間相依 sudoers 項目的 sudoNotBefore 與 sudoNotAfter 屬性。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2079 msgid "sudo_threshold (integer)" -msgstr "" +msgstr "sudo_threshold (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2082 @@ -2524,21 +2816,25 @@ msgid "" "threshold number also applies to IPA sudo command and command group " "searches." msgstr "" +"一次可以重新整理的過期規則數目上限。若過期規則數目低於門檻值,這些規則會透過 " +"<quote>rules refresh</quote> 機制重新整理。若超過門檻值,則會改為觸發 sudo 規" +"則的 <quote>full refresh</quote>。此門檻值也適用於 IPA sudo 指令與指令群組搜" +"尋。" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:2101 msgid "AUTOFS configuration options" -msgstr "" +msgstr "AUTOFS 設定選項" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:2103 msgid "These options can be used to configure the autofs service." -msgstr "" +msgstr "這些選項可用來設定 autofs 服務。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2107 msgid "autofs_negative_timeout (integer)" -msgstr "" +msgstr "autofs_negative_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2110 @@ -2547,50 +2843,52 @@ msgid "" "hits (that is, queries for invalid map entries, like nonexistent ones) " "before asking the back end again." msgstr "" +"指定 autofs 回應器在再次詢問後端之前,應該將負面快取命中(亦即對無效對應表項" +"目的查詢,例如不存在的項目)保留多少秒。" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:2126 msgid "SSH configuration options" -msgstr "" +msgstr "SSH 設定選項" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:2128 msgid "These options can be used to configure the SSH service." -msgstr "" +msgstr "這些選項可用來設定 SSH 服務。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2132 msgid "ssh_hash_known_hosts (bool)" -msgstr "" +msgstr "ssh_hash_known_hosts (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2135 msgid "" "Whether or not to hash host names and addresses in the managed known_hosts " "file." -msgstr "" +msgstr "是否對受管理的 known_hosts 檔案中的主機名稱與位址進行雜湊。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2144 msgid "ssh_known_hosts_timeout (integer)" -msgstr "" +msgstr "ssh_known_hosts_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2147 msgid "" "How many seconds to keep a host in the managed known_hosts file after its " "host keys were requested." -msgstr "" +msgstr "主機金鑰被要求之後,將主機保留在受管理的 known_hosts 檔案中的秒數。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2151 msgid "Default: 180" -msgstr "" +msgstr "預設:180" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2156 msgid "ssh_use_certificate_keys (bool)" -msgstr "" +msgstr "ssh_use_certificate_keys (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2159 @@ -2601,11 +2899,15 @@ msgid "" "<refentrytitle>sss_ssh_authorizedkeys</refentrytitle> " "<manvolnum>1</manvolnum> </citerefentry> for details." msgstr "" +"若設為 true,<command>sss_ssh_authorizedkeys</command> 也會傳回從儲存在使用者" +"項目中之 X.509 憑證公開金鑰衍生的 ssh 金鑰。詳情請參閱 <citerefentry> " +"<refentrytitle>sss_ssh_authorizedkeys</refentrytitle> <manvolnum>1</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2174 msgid "ssh_use_certificate_matching_rules (string)" -msgstr "" +msgstr "ssh_use_certificate_matching_rules (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2177 @@ -2616,6 +2918,9 @@ msgid "" "comma separated list of mapping and matching rule names. All other rules " "will be ignored." msgstr "" +"依預設,ssh 回應器會使用所有可用的憑證比對規則來過濾憑證,因此 ssh 金鑰只會從" +"相符的憑證衍生。使用此選項可以透過以逗號分隔的對應與比對規則名稱清單限制使用" +"的規則。其他所有規則都會被忽略。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2186 @@ -2624,6 +2929,8 @@ msgid "" "all or no rules, respectively. The latter means that no certificates will be " "filtered out and ssh keys will be generated from all valid certificates." msgstr "" +"有兩個特殊關鍵字 'all_rules' 與 'no_rules',分別啟用所有規則或停用所有規則。" +"後者表示不會過濾掉任何憑證,且會從所有有效憑證產生 ssh 金鑰。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2193 @@ -2633,25 +2940,27 @@ msgid "" "the same behavior as for the PAM responder if certificate authentication is " "enabled." msgstr "" +"若未設定任何規則,使用 'all_rules' 會啟用預設規則,啟用所有適合用戶端驗證的憑" +"證。這與啟用憑證驗證時 PAM 回應器的行為相同。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2200 msgid "" "A non-existing rule name is considered an error. If as a result no rule is " "selected all certificates will be ignored." -msgstr "" +msgstr "不存在的規則名稱會被視為錯誤。若因此沒有選取任何規則,所有憑證都會被忽略。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2205 msgid "" "Default: not set, equivalent to 'all_rules', all found rules or the default " "rule are used" -msgstr "" +msgstr "預設:未設定,等同於 'all_rules',會使用所有找到的規則或預設規則" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2211 msgid "ca_db (string)" -msgstr "" +msgstr "ca_db (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2214 @@ -2659,11 +2968,13 @@ msgid "" "Path to a storage of trusted CA certificates. The option is used to validate " "user certificates before deriving public ssh keys from them." msgstr "" +"受信任 CA 憑證儲存區的路徑。此選項用來在從使用者憑證衍生公開 ssh 金鑰之前驗證" +"這些憑證。" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:2234 msgid "PAC responder configuration options" -msgstr "" +msgstr "PAC 回應器設定選項" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:2236 @@ -2675,6 +2986,10 @@ msgid "" "joined to and of remote trusted domains from the local domain controller. If " "the PAC is decoded and evaluated some of the following operations are done:" msgstr "" +"PAC 回應器與 MIT Kerberos sssd_pac_plugin.so 的授權資料外掛程式及子網域提供者" +"搭配運作。外掛程式會在 GSSAPI 驗證期間將 PAC 資料傳送給 PAC 回應器。子網域提" +"供者會從本機網域控制站收集用戶端所加入網域及遠端受信任網域的網域 SID 與 ID 範" +"圍。若 PAC 被解碼並評估,會執行下列部分作業:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:2245 @@ -2686,23 +3001,26 @@ msgid "" "i.e. the system defaults are used, but can be overwritten with the " "default_shell parameter." msgstr "" +"若遠端使用者不存在於快取中,則會建立。UID 借助 SID 決定,受信任網域會有 UPG," +"且 GID 會與 UID 有相同的值。家目錄依 subdomain_homedir 參數設定。shell 依預設" +"為空,亦即使用系統預設值,但可以使用 default_shell 參數覆寫。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:2253 msgid "" "If there are SIDs of groups from domains sssd knows about, the user will be " "added to those groups." -msgstr "" +msgstr "若存在 sssd 所知網域的群組 SID,使用者會加入那些群組。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:2259 msgid "These options can be used to configure the PAC responder." -msgstr "" +msgstr "這些選項可用來設定 PAC 回應器。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2263 sssd-ifp.5.xml:66 msgid "allowed_uids (string)" -msgstr "" +msgstr "allowed_uids (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2266 @@ -2711,18 +3029,20 @@ msgid "" "allowed to access the PAC responder. User names are resolved to UIDs at " "startup." msgstr "" +"指定允許存取 PAC 回應器的 UID 值或使用者名稱清單(以逗號分隔)。使用者名稱會" +"在啟動時解析為 UID。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2272 msgid "" "Default: 0, &sssd_user_name; (only root and SSSD service users are allowed " "to access the PAC responder)" -msgstr "" +msgstr "預設:0、&sssd_user_name;(只允許 root 與 SSSD 服務使用者存取 PAC 回應器)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2276 msgid "Default: 0 (only the root user is allowed to access the PAC responder)" -msgstr "" +msgstr "預設:0(只允許 root 使用者存取 PAC 回應器)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2280 @@ -2732,6 +3052,9 @@ msgid "" "responder, which would be the typical case, you have to add those to the " "list of allowed UIDs explicitly." msgstr "" +"請注意,設定此選項會覆寫預設值。若您仍然希望允許 root 與/或 " +"'&sssd_user_name;' 使用者存取 PAC 回應器(這是一般情況),您必須明確地將它們" +"加入允許的 UID 清單。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2287 @@ -2741,11 +3064,13 @@ msgid "" "access the PAC responder, which would be the typical case, you have to add 0 " "to the list of allowed UIDs as well." msgstr "" +"請注意,雖然預設使用 UID 0,設定此選項會覆寫它。若您仍然希望允許 root 使用者" +"存取 PAC 回應器(這是一般情況),您也必須將 0 加入允許的 UID 清單。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2296 msgid "pac_lifetime (integer)" -msgstr "" +msgstr "pac_lifetime (integer)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2299 @@ -2753,11 +3078,13 @@ msgid "" "Lifetime of the PAC entry in seconds. As long as the PAC is valid the PAC " "data can be used to determine the group memberships of a user." msgstr "" +"PAC 項目的存留時間(秒)。只要 PAC 有效,就可以使用 PAC 資料判斷使用者的群組" +"成員資格。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:2309 msgid "pac_check (string)" -msgstr "" +msgstr "pac_check (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2312 @@ -2769,23 +3096,27 @@ msgid "" "the IPA and AD provider. If krb5_validate is set to 'False' the PAC checks " "will be skipped." msgstr "" +"若已設定,對 Active Directory 與 FreeIPA 網域中可用的 Kerberos 票證 PAC 套用" +"額外檢查。請注意,必須啟用 Kerberos 票證驗證才能檢查 PAC,亦即必須將 " +"krb5_validate 選項設為 'True',這是 IPA 與 AD 提供者的預設值。若 " +"krb5_validate 設為 'False',則會略過 PAC 檢查。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2326 msgid "no_check" -msgstr "" +msgstr "no_check" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2328 msgid "" "The PAC must not be present and even if it is present no additional checks " "will be done." -msgstr "" +msgstr "PAC 不得存在,即使存在也不會執行任何額外檢查。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2334 msgid "pac_present" -msgstr "" +msgstr "pac_present" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2336 @@ -2794,23 +3125,25 @@ msgid "" "the help of the user's TGT. If the PAC is not available the authentication " "will fail." msgstr "" +"SSSD 借助使用者的 TGT 要求的服務票證中必須存在 PAC。若 PAC 不可用,驗證會失敗" +"。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2344 msgid "check_upn" -msgstr "" +msgstr "check_upn" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2346 msgid "" "If the PAC is present check if the user principal name (UPN) information is " "consistent." -msgstr "" +msgstr "若 PAC 存在,檢查使用者主體名稱 (UPN) 資訊是否一致。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2352 msgid "check_upn_allow_missing" -msgstr "" +msgstr "check_upn_allow_missing" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2354 @@ -2823,6 +3156,10 @@ msgid "" "time and FreeIPA can handle enterprise principals just fine and there is no " "need anymore to set 'ldap_user_principal'." msgstr "" +"此選項應與 'check_upn' 一起使用,處理伺服器端設定了 UPN 但 SSSD 沒有讀取的情" +"況。典型的例子是 'ldap_user_principal' 設為不存在之屬性名稱的 FreeIPA 網域。" +"這通常是為了繞過企業主體處理上的問題。但這個問題早已修正,FreeIPA 可以正常處" +"理企業主體,不再需要設定 'ldap_user_principal'。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2366 @@ -2834,21 +3171,25 @@ msgid "" "can be removed. If this is not possible, removing 'check_upn' will skip the " "test and avoid the log message." msgstr "" +"目前此選項依預設啟用,以避免在這種環境中發生回歸。若在 PAC 中找到 UPN 但不在 " +"SSSD 的快取中,會將記錄訊息加入系統記錄檔與 SSSD 的除錯記錄檔。若要避免這則記" +"錄訊息,最好評估是否可以移除 'ldap_user_principal' 選項。若無法移除,移除 " +"'check_upn' 會略過測試並避免記錄訊息。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2380 msgid "upn_dns_info_present" -msgstr "" +msgstr "upn_dns_info_present" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2382 msgid "The PAC must contain the UPN-DNS-INFO buffer, implies 'check_upn'." -msgstr "" +msgstr "PAC 必須包含 UPN-DNS-INFO 緩衝區,隱含 'check_upn'。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2387 msgid "check_upn_dns_info_ex" -msgstr "" +msgstr "check_upn_dns_info_ex" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2389 @@ -2856,11 +3197,13 @@ msgid "" "If the PAC is present and the extension to the UPN-DNS-INFO buffer is " "available check if the information in the extension is consistent." msgstr "" +"若 PAC 存在且 UPN-DNS-INFO 緩衝區的延伸部分可用,檢查延伸部分中的資訊是否一致" +"。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2396 msgid "upn_dns_info_ex_present" -msgstr "" +msgstr "upn_dns_info_ex_present" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2398 @@ -2868,6 +3211,8 @@ msgid "" "The PAC must contain the extension of the UPN-DNS-INFO buffer, implies " "'check_upn_dns_info_ex', 'upn_dns_info_present' and 'check_upn'." msgstr "" +"PAC 必須包含 UPN-DNS-INFO 緩衝區的延伸部分,隱含 " +"'check_upn_dns_info_ex'、'upn_dns_info_present' 與 'check_upn'。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2322 @@ -2875,6 +3220,8 @@ msgid "" "The following options can be used alone or in a comma-separated list: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +"下列選項可以單獨使用,或用在逗號分隔的清單中:<placeholder " +"type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2408 @@ -2882,11 +3229,13 @@ msgid "" "Default: no_check (AD and IPA provider 'check_upn, check_upn_allow_missing, " "check_upn_dns_info_ex')" msgstr "" +"預設:no_check(AD 與 IPA 提供者為 'check_upn、check_upn_allow_missing、" +"check_upn_dns_info_ex')" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:2417 msgid "Session recording configuration options" -msgstr "" +msgstr "工作階段錄製設定選項" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:2419 @@ -2898,31 +3247,36 @@ msgid "" "<refentrytitle>sssd-session-recording</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry>." msgstr "" +"工作階段錄製與 tlog 套件的一部分 <citerefentry> <refentrytitle>tlog-rec-" +"session</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> 搭配運作,記" +"錄使用者在文字終端機登入時看到與輸入的內容。另請參閱 <citerefentry> " +"<refentrytitle>sssd-session-recording</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:2432 msgid "These options can be used to configure session recording." -msgstr "" +msgstr "這些選項可用來設定工作階段錄製。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2436 sssd-session-recording.5.xml:64 msgid "scope (string)" -msgstr "" +msgstr "scope (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2443 sssd-session-recording.5.xml:71 msgid "\"none\"" -msgstr "" +msgstr "\"none\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2446 sssd-session-recording.5.xml:74 msgid "No users are recorded." -msgstr "" +msgstr "不錄製任何使用者。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2451 sssd-session-recording.5.xml:79 msgid "\"some\"" -msgstr "" +msgstr "\"some\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2454 sssd-session-recording.5.xml:82 @@ -2930,16 +3284,18 @@ msgid "" "Users/groups specified by <replaceable>users</replaceable> and " "<replaceable>groups</replaceable> options are recorded." msgstr "" +"會錄製 <replaceable>users</replaceable> 與 <replaceable>groups</replaceable> " +"選項指定的使用者/群組。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2463 sssd-session-recording.5.xml:91 msgid "\"all\"" -msgstr "" +msgstr "\"all\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2466 sssd-session-recording.5.xml:94 msgid "All users are recorded." -msgstr "" +msgstr "錄製所有使用者。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2439 sssd-session-recording.5.xml:67 @@ -2947,16 +3303,18 @@ msgid "" "One of the following strings specifying the scope of session recording: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +"下列其中一個字串,指定工作階段錄製的範圍:<placeholder type=\"variablelist\" " +"id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2473 sssd-session-recording.5.xml:101 msgid "Default: \"none\"" -msgstr "" +msgstr "預設:\"none\"" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2478 sssd-session-recording.5.xml:106 msgid "users (string)" -msgstr "" +msgstr "users (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2481 sssd-session-recording.5.xml:109 @@ -2965,16 +3323,18 @@ msgid "" "enabled. Matches user names as returned by NSS. I.e. after the possible " "space replacement, case changes, etc." msgstr "" +"應啟用工作階段錄製的使用者清單,以逗號分隔。比對 NSS 回傳的使用者名稱,亦即經" +"過可能的空格取代、大小寫變更等處理之後的名稱。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2487 sssd-session-recording.5.xml:115 msgid "Default: Empty. Matches no users." -msgstr "" +msgstr "預設:空。不匹配任何使用者。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2492 sssd-session-recording.5.xml:120 msgid "groups (string)" -msgstr "" +msgstr "groups (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2495 sssd-session-recording.5.xml:123 @@ -2983,6 +3343,8 @@ msgid "" "recording enabled. Matches group names as returned by NSS. I.e. after the " "possible space replacement, case changes, etc." msgstr "" +"成員應啟用工作階段錄製的群組清單,以逗號分隔。比對 NSS 回傳的群組名稱,亦即經" +"過可能的空格取代、大小寫變更等處理之後的名稱。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2501 sssd.conf.5.xml:2533 sssd-session-recording.5.xml:129 @@ -2992,56 +3354,58 @@ msgid "" "performance cost, because each uncached request for a user requires " "retrieving and matching the groups the user is member of." msgstr "" +"注意:使用此選項(將其設為任何值)會有可觀的效能成本,因為每個未快取的使用者" +"要求都需要取回並比對使用者所屬的群組。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2508 sssd-session-recording.5.xml:136 msgid "Default: Empty. Matches no groups." -msgstr "" +msgstr "預設:空。不匹配任何群組。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2513 sssd-session-recording.5.xml:141 msgid "exclude_users (string)" -msgstr "" +msgstr "exclude_users (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2516 sssd-session-recording.5.xml:144 msgid "" "A comma-separated list of users to be excluded from recording, only " "applicable with 'scope=all'." -msgstr "" +msgstr "要從錄製中排除的使用者清單(以逗號分隔),只適用於 'scope=all'。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2520 sssd-session-recording.5.xml:148 msgid "Default: Empty. No users excluded." -msgstr "" +msgstr "預設:空。不排除任何使用者。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:2525 sssd-session-recording.5.xml:153 msgid "exclude_groups (string)" -msgstr "" +msgstr "exclude_groups (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2528 sssd-session-recording.5.xml:156 msgid "" "A comma-separated list of groups, members of which should be excluded from " "recording. Only applicable with 'scope=all'." -msgstr "" +msgstr "成員應從錄製中排除的群組清單(以逗號分隔)。只適用於 'scope=all'。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2540 sssd-session-recording.5.xml:168 msgid "Default: Empty. No groups excluded." -msgstr "" +msgstr "預設:空。不排除任何群組。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:2550 msgid "DOMAIN SECTIONS" -msgstr "" +msgstr "DOMAIN 區段" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> #: sssd.conf.5.xml:2557 sssd.conf.5.xml:4041 sssd.conf.5.xml:4042 #: sssd.conf.5.xml:4045 msgid "enabled" -msgstr "" +msgstr "enabled" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2560 @@ -3052,11 +3416,14 @@ msgid "" "enabled only if it is listed in the domains option in the " "<quote>[sssd]</quote> section." msgstr "" +"明確地啟用或停用網域。若為 <quote>true</quote>,網域一律<quote>啟用</quote>。" +"若為 <quote>false</quote>,網域一律<quote>停用</quote>。若未設定此選項,只有" +"當網域列在 <quote>[sssd]</quote> 區段的 domains 選項中時才會啟用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2572 msgid "domain_type (string)" -msgstr "" +msgstr "domain_type (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2575 @@ -3066,13 +3433,16 @@ msgid "" "be present or generated. Only objects from POSIX domains are available to " "the operating system interfaces and utilities." msgstr "" +"指定網域是要供了解 POSIX 的用戶端(例如名稱服務切換)使用,還是供不需要存在或" +"產生 POSIX 資料的應用程式使用。只有 POSIX 網域的物件可供作業系統介面與工具程" +"式使用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2583 msgid "" "Allowed values for this option are <quote>posix</quote> and " "<quote>application</quote>." -msgstr "" +msgstr "此選項允許的值為 <quote>posix</quote> 與 <quote>application</quote>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2587 @@ -3082,37 +3452,40 @@ msgid "" "<refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry>) and the PAM responder." msgstr "" +"所有服務都可以連線 POSIX 網域。Application 網域只能從 InfoPipe 回應器(詳情請" +"參閱 <citerefentry> <refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>)與 PAM 回應器連線。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2595 msgid "" "NOTE: The application domains are currently well tested with " "<quote>id_provider=ldap</quote> only." -msgstr "" +msgstr "注意:application 網域目前只與 <quote>id_provider=ldap</quote> 做了完整測試。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2599 msgid "" "For an easy way to configure a non-POSIX domains, please see the " "<quote>Application domains</quote> section." -msgstr "" +msgstr "若要簡單地設定非 POSIX 網域,請參閱 <quote>Application domains</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2603 msgid "Default: posix" -msgstr "" +msgstr "預設:posix" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2609 msgid "min_id,max_id (integer)" -msgstr "" +msgstr "min_id,max_id (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2612 msgid "" "UID and GID limits for the domain. If a domain contains an entry that is " "outside these limits, it is ignored." -msgstr "" +msgstr "網域的 UID 與 GID 限制。若網域包含超出這些限制的項目,該項目會被忽略。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2617 @@ -3122,23 +3495,25 @@ msgid "" "non-primary group memberships, those that are in range will be reported as " "expected." msgstr "" +"對使用者而言,這會影響主要 GID 的限制。若 UID 或主要 GID 任一超出範圍,該使用" +"者就不會傳回給 NSS。對於非主要的群組成員資格,範圍內的成員資格會如預期回報。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2624 msgid "" "These ID limits affect even saving entries to cache, not only returning them " "by name or ID." -msgstr "" +msgstr "這些 ID 限制甚至會影響項目儲存到快取,而不只是依名稱或 ID 傳回項目。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2628 msgid "Default: 1 for min_id, 0 (no limit) for max_id" -msgstr "" +msgstr "預設:min_id 為 1,max_id 為 0(無限制)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2634 msgid "enumerate (bool)" -msgstr "" +msgstr "enumerate (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2637 @@ -3148,35 +3523,37 @@ msgid "" "enable enumeration in order for secondary groups to be displayed. This " "parameter can have one of the following values:" msgstr "" +"決定網域是否可以被列舉,亦即網域是否可以列出其包含的所有使用者與群組。請注意" +",要顯示次要群組不需要啟用列舉。此參數可以有下列其中一個值:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2645 msgid "TRUE = Users and groups are enumerated" -msgstr "" +msgstr "TRUE = 列舉使用者與群組" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2648 msgid "FALSE = No enumerations for this domain" -msgstr "" +msgstr "FALSE = 不列舉此網域" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2651 sssd.conf.5.xml:2942 sssd.conf.5.xml:3119 msgid "Default: FALSE" -msgstr "" +msgstr "預設:FALSE" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2654 msgid "" "Enumerating a domain requires SSSD to download and store ALL user and group " "entries from the remote server." -msgstr "" +msgstr "列舉網域需要 SSSD 從遠端伺服器下載並儲存所有使用者與群組項目。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2659 msgid "" "Feature is only supported for domains with id_provider = ldap or id_provider " "= proxy." -msgstr "" +msgstr "此功能只支援 id_provider = ldap 或 id_provider = proxy 的網域。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2663 @@ -3191,6 +3568,11 @@ msgid "" "<quote>sssd_be</quote> process becoming unresponsive or even restarted by " "the internal watchdog." msgstr "" +"注意:啟用列舉會在列舉執行期間對 SSSD 造成嚴重的效能影響。SSSD 啟動後可能需要" +"數分鐘才能完整完成列舉。在此期間,個別的資訊要求會直接送到 LDAP,但由於列舉處" +"理負擔沉重,可能會很慢。列舉完成後將大量項目儲存到快取也可能耗費大量 CPU,因" +"為必須重新計算成員資格。這可能導致 <quote>sssd_be</quote> 程序無回應,甚至被" +"內部看門狗重新啟動。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2678 @@ -3198,6 +3580,8 @@ msgid "" "While the first enumeration is running, requests for the complete user or " "group lists may return no results until it completes." msgstr "" +"第一次列舉執行期間,要求完整使用者或群組清單可能不會傳回任何結果,直到列舉完" +"成。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2683 @@ -3207,13 +3591,15 @@ msgid "" "enumeration lookups are completed successfully. For more information, refer " "to the man pages for the specific id_provider in use." msgstr "" +"此外,啟用列舉可能會增加偵測網路斷線所需的時間,因為需要較長的逾時來確保列舉" +"查詢成功完成。更多資訊請參閱所使用 id_provider 的手冊頁。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2691 msgid "" "For the reasons cited above, enabling enumeration is not recommended, " "especially in large environments." -msgstr "" +msgstr "基於上述原因,不建議啟用列舉,尤其是在大型環境中。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2696 @@ -3222,31 +3608,33 @@ msgid "" "'libnss_files' and 'libnss_ldap'. 3rd party modules must follow the " "documented behavior of nss modules to be used in this configuration." msgstr "" +"注意:proxy 提供者已與 'libnss_files' 與 'libnss_ldap' 等開放原始碼模組測試。" +"協力廠商模組必須遵循 nss 模組記載的行為,才能用於此設定。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2705 msgid "subdomain_enumerate (string)" -msgstr "" +msgstr "subdomain_enumerate (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2712 msgid "all" -msgstr "" +msgstr "all" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2713 msgid "All discovered trusted domains will be enumerated" -msgstr "" +msgstr "所有探索到的受信任網域都會被列舉" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2716 msgid "none" -msgstr "" +msgstr "none" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2717 msgid "No discovered trusted domains will be enumerated" -msgstr "" +msgstr "不會列舉任何探索到的受信任網域" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2708 @@ -3256,18 +3644,21 @@ msgid "" "Optionally, a list of one or more domain names can enable enumeration just " "for these trusted domains." msgstr "" +"是否應列舉任何自動偵測到的受信任網域。支援的值有:<placeholder " +"type=\"variablelist\" id=\"0\"/> 也可以選擇性地提供一個或多個網域名稱的清單," +"只為這些受信任網域啟用列舉。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2731 msgid "entry_cache_timeout (integer)" -msgstr "" +msgstr "entry_cache_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2734 msgid "" "How many seconds should nss_sss consider entries valid before asking the " "backend again" -msgstr "" +msgstr "nss_sss 在再次詢問後端之前,應該將項目視為有效的秒數" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2738 @@ -3279,131 +3670,135 @@ msgid "" "</citerefentry> tool in order to force refresh of entries that have already " "been cached." msgstr "" +"快取到期時間戳記會儲存為快取中各個物件的屬性。因此,變更快取逾時只對新加入或" +"已到期的項目有效。您應該執行 <citerefentry> <refentrytitle>sss_cache</" +"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> 工具,以強制重新整理" +"已快取的項目。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2751 msgid "Default: 5400" -msgstr "" +msgstr "預設:5400" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2757 msgid "entry_cache_user_timeout (integer)" -msgstr "" +msgstr "entry_cache_user_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2760 msgid "" "How many seconds should nss_sss consider user entries valid before asking " "the backend again" -msgstr "" +msgstr "nss_sss 在再次詢問後端之前,應該將使用者項目視為有效的秒數" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2764 sssd.conf.5.xml:2777 sssd.conf.5.xml:2790 #: sssd.conf.5.xml:2803 sssd.conf.5.xml:2817 sssd.conf.5.xml:2830 #: sssd.conf.5.xml:2844 sssd.conf.5.xml:2858 sssd.conf.5.xml:2871 msgid "Default: entry_cache_timeout" -msgstr "" +msgstr "預設:entry_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2770 msgid "entry_cache_group_timeout (integer)" -msgstr "" +msgstr "entry_cache_group_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2773 msgid "" "How many seconds should nss_sss consider group entries valid before asking " "the backend again" -msgstr "" +msgstr "nss_sss 在再次詢問後端之前,應該將群組項目視為有效的秒數" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2783 msgid "entry_cache_netgroup_timeout (integer)" -msgstr "" +msgstr "entry_cache_netgroup_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2786 msgid "" "How many seconds should nss_sss consider netgroup entries valid before " "asking the backend again" -msgstr "" +msgstr "nss_sss 在再次詢問後端之前,應該將網路群組項目視為有效的秒數" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2796 msgid "entry_cache_service_timeout (integer)" -msgstr "" +msgstr "entry_cache_service_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2799 msgid "" "How many seconds should nss_sss consider service entries valid before asking " "the backend again" -msgstr "" +msgstr "nss_sss 在再次詢問後端之前,應該將服務項目視為有效的秒數" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2809 msgid "entry_cache_resolver_timeout (integer)" -msgstr "" +msgstr "entry_cache_resolver_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2812 msgid "" "How many seconds should nss_sss consider hosts and networks entries valid " "before asking the backend again" -msgstr "" +msgstr "nss_sss 在再次詢問後端之前,應該將主機與網路項目視為有效的秒數" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2823 msgid "entry_cache_sudo_timeout (integer)" -msgstr "" +msgstr "entry_cache_sudo_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2826 msgid "" "How many seconds should sudo consider rules valid before asking the backend " "again" -msgstr "" +msgstr "sudo 在再次詢問後端之前,應該將規則視為有效的秒數" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2836 msgid "entry_cache_autofs_timeout (integer)" -msgstr "" +msgstr "entry_cache_autofs_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2839 msgid "" "How many seconds should the autofs service consider automounter maps valid " "before asking the backend again" -msgstr "" +msgstr "autofs 服務在再次詢問後端之前,應該將自動掛載對應表視為有效的秒數" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2850 msgid "entry_cache_ssh_host_timeout (integer)" -msgstr "" +msgstr "entry_cache_ssh_host_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2853 msgid "" "How many seconds to keep a host ssh key after refresh. IE how long to cache " "the host key for." -msgstr "" +msgstr "重新整理後保留主機 ssh 金鑰的秒數。亦即主機金鑰的快取時間。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2864 msgid "entry_cache_computer_timeout (integer)" -msgstr "" +msgstr "entry_cache_computer_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2867 msgid "" "How many seconds to keep the local computer entry before asking the backend " "again" -msgstr "" +msgstr "在再次詢問後端之前,保留本機電腦項目的秒數" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2877 msgid "refresh_expired_interval (integer)" -msgstr "" +msgstr "refresh_expired_interval (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2880 @@ -3411,6 +3806,8 @@ msgid "" "Specifies how many seconds SSSD has to wait before triggering a background " "refresh task which will refresh all expired or nearly expired records." msgstr "" +"指定 SSSD 在觸發背景重新整理工作之前必須等待的秒數,該工作會重新整理所有已到" +"期或即將到期的記錄。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2885 @@ -3420,16 +3817,19 @@ msgid "" "user, typically ran at login) operation in the past, both the user entry " "and the group membership are updated." msgstr "" +"背景重新整理會處理快取中的使用者、群組與網路群組。對於過去執行過 initgroups(" +"取得使用者的群組成員資格,通常在登入時執行)作業的使用者,使用者項目與群組成" +"員資格都會更新。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2893 msgid "This option is automatically inherited for all trusted domains." -msgstr "" +msgstr "此選項會自動繼承到所有受信任網域。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2897 msgid "You can consider setting this value to 3/4 * entry_cache_timeout." -msgstr "" +msgstr "您可以考慮將此值設為 entry_cache_timeout 的 3/4。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2901 @@ -3442,17 +3842,21 @@ msgid "" "offline mode operation and reuse of existing valid cache entries. To make " "this change instant the user may want to manually invalidate existing cache." msgstr "" +"快取逾時已過 2/3 時,背景工作會重新整理快取項目。若已有快取項目,背景工作會參" +"照它們原本的快取逾時值,而不是目前的設定值。這可能導致背景重新整理工作看起來" +"沒有作用的情況。這是刻意設計,目的是改善離線模式運作並重複使用現有的有效快取" +"項目。若要讓此變更立即生效,使用者可能想要手動使現有快取失效。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2914 sssd-ldap.5.xml:361 sssd-ldap.5.xml:1774 #: sssd-ipa.5.xml:270 msgid "Default: 0 (disabled)" -msgstr "" +msgstr "預設:0(停用)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2920 msgid "cache_credentials (bool)" -msgstr "" +msgstr "cache_credentials (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2923 @@ -3464,6 +3868,9 @@ msgid "" "offline as long as a successful online authentication is recorded in the " "cache without additional configuration." msgstr "" +"決定使用者憑證是否也快取在本機 LDB 快取中。快取的憑證指密碼,包含雙重因素驗證" +"的第一(長期)因素,不包含其他驗證機制。只要快取中記錄了成功的線上驗證," +"Passkey 與智慧卡驗證預期可以在沒有額外設定的情況下離線運作。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2934 @@ -3473,11 +3880,13 @@ msgid "" "get access to a cache file (normally requires privileged access) and to " "break a password using brute force attack." msgstr "" +"請注意,雖然憑證以加鹽的 SHA512 雜湊儲存,若攻擊者設法取得快取檔案的存取權(" +"通常需要特權存取)並以暴力破解攻擊破解密碼,這仍然可能構成一些安全風險。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2948 msgid "cache_credentials_minimal_first_factor_length (int)" -msgstr "" +msgstr "cache_credentials_minimal_first_factor_length (int)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2951 @@ -3486,6 +3895,8 @@ msgid "" "this value determines the minimal length the first authentication factor " "(long term password) must have to be saved as SHA512 hash into the cache." msgstr "" +"若使用雙因素認證 (2FA) 且應儲存憑證,此值決定第一個認證因素(長期密碼)要存入" +"快取作為 SHA512 雜湊所需的最短長度。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2958 @@ -3493,11 +3904,13 @@ msgid "" "This should avoid that the short PINs of a PIN based 2FA scheme are saved in " "the cache which would make them easy targets for brute-force attacks." msgstr "" +"這可以避免以 PIN 為基礎之 2FA 方案的短 PIN 被儲存到快取中,因為那會讓它們成為" +"暴力破解攻擊的容易目標。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2969 msgid "account_cache_expiration (integer)" -msgstr "" +msgstr "account_cache_expiration (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2972 @@ -3507,16 +3920,18 @@ msgid "" "value of this parameter must be greater than or equal to " "offline_credentials_expiration." msgstr "" +"在最後一次成功登入後,項目留在快取中、直到快取清理時被移除的天數。0 表示永久" +"保留。此參數的值必須大於或等於 offline_credentials_expiration。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2979 msgid "Default: 0 (unlimited)" -msgstr "" +msgstr "預設:0(無限制)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:2984 msgid "pwd_expiration_warning (integer)" -msgstr "" +msgstr "pwd_expiration_warning (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:2995 @@ -3526,28 +3941,30 @@ msgid "" "cannot display a warning. Also an auth provider has to be configured for the " "backend." msgstr "" +"請注意,後端伺服器必須提供密碼到期時間的資訊。若缺少此資訊,sssd 無法顯示警告" +"。後端也必須設定 auth 提供者。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3002 msgid "Default: 7 (Kerberos), 0 (LDAP)" -msgstr "" +msgstr "預設:7(Kerberos),0(LDAP)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3008 msgid "id_provider (string)" -msgstr "" +msgstr "id_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3011 msgid "" "The identification provider used for the domain. Supported ID providers " "are:" -msgstr "" +msgstr "網域使用的身分提供者。支援的 ID 提供者有:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3015 msgid "<quote>proxy</quote>: Support a legacy NSS provider." -msgstr "" +msgstr "<quote>proxy</quote>:支援傳統的 NSS 提供者。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3018 @@ -3557,6 +3974,9 @@ msgid "" "</citerefentry> for more information on how to mirror local users and groups " "into SSSD." msgstr "" +"<quote>files</quote>:FILES 提供者。如何將本機使用者與群組鏡像到 SSSD 的更多" +"資訊,請參閱 <citerefentry> <refentrytitle>sssd-files</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3026 @@ -3565,6 +3985,9 @@ msgid "" "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> for more information on configuring LDAP." msgstr "" +"<quote>ldap</quote>:LDAP 提供者。設定 LDAP 的更多資訊,請參閱 " +"<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3034 sssd.conf.5.xml:3145 sssd.conf.5.xml:3196 @@ -3575,6 +3998,9 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " "FreeIPA." msgstr "" +"<quote>ipa</quote>:FreeIPA 與 Red Hat Identity Management 提供者。設定 " +"FreeIPA 的更多資訊,請參閱 <citerefentry> <refentrytitle>sssd-ipa</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3043 sssd.conf.5.xml:3154 sssd.conf.5.xml:3205 @@ -3584,11 +4010,14 @@ msgid "" "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> for more information on configuring Active Directory." msgstr "" +"<quote>ad</quote>:Active Directory 提供者。設定 Active Directory 的更多資訊" +",請參閱 <citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3054 msgid "use_fully_qualified_names (bool)" -msgstr "" +msgstr "use_fully_qualified_names (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3057 @@ -3596,6 +4025,8 @@ msgid "" "Use the full name and domain (as formatted by the domain's full_name_format) " "as the user's login name reported to NSS." msgstr "" +"使用完整名稱與網域(依網域的 full_name_format 格式化)作為回報給 NSS 的使用者" +"登入名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3062 @@ -3605,6 +4036,9 @@ msgid "" "<command>getent passwd test</command> wouldn't find the user while " "<command>getent passwd test@LOCAL</command> would." msgstr "" +"若設為 TRUE,對此網域的所有要求都必須使用完整名稱。例如,若用於包含 \"test\" " +"使用者的 LOCAL 網域,<command>getent passwd test</command> 找不到該使用者," +"而 <command>getent passwd test@LOCAL</command> 可以。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3070 @@ -3613,23 +4047,25 @@ msgid "" "include nested netgroups without qualified names. For netgroups, all domains " "will be searched when an unqualified name is requested." msgstr "" +"注意:此選項對網路群組查詢沒有效果,因為網路群組往往包含沒有完整名稱的巢狀網" +"路群組。對網路群組而言,要求未限定名稱時會搜尋所有網域。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3077 msgid "" "Default: FALSE (TRUE for trusted domain/sub-domains or if " "default_domain_suffix is used)" -msgstr "" +msgstr "預設:FALSE(受信任網域/子網域或使用 default_domain_suffix 時為 TRUE)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3084 msgid "ignore_group_members (bool)" -msgstr "" +msgstr "ignore_group_members (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3087 msgid "Do not return group members for group lookups." -msgstr "" +msgstr "群組查詢不傳回群組成員。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3090 @@ -3642,6 +4078,12 @@ msgid "" "</citerefentry>. As an effect, <quote>getent group $groupname</quote> would " "return the requested group as if it was empty." msgstr "" +"若設為 TRUE,不會向 ldap 伺服器要求群組成員資格屬性,處理群組查詢呼叫(例如 " +"<citerefentry> <refentrytitle>getgrnam</refentrytitle> <manvolnum>3</" +"manvolnum> </citerefentry> 或 <citerefentry> <refentrytitle>getgrgid</" +"refentrytitle> <manvolnum>3</manvolnum> </citerefentry>)時也不會傳回群組成員" +"。結果是 <quote>getent group $groupname</quote> 會傳回所要求的群組,彷彿它是" +"空的。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3108 @@ -3650,6 +4092,8 @@ msgid "" "membership significantly faster, especially for groups containing many " "members." msgstr "" +"啟用此選項也可以讓 access 提供者的群組成員資格檢查明顯更快,尤其是成員眾多的" +"群組。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3114 sssd.conf.5.xml:3835 sssd-ldap.5.xml:327 @@ -3661,18 +4105,20 @@ msgid "" "This option can be also set per subdomain or inherited via " "<emphasis>subdomain_inherit</emphasis>." msgstr "" +"此選項也可以逐子網域設定,或透過 <emphasis>subdomain_inherit</emphasis> 繼承" +"。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3124 msgid "auth_provider (string)" -msgstr "" +msgstr "auth_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3127 msgid "" "The authentication provider used for the domain. Supported auth providers " "are:" -msgstr "" +msgstr "網域使用的驗證提供者。支援的 auth 提供者有:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3131 sssd.conf.5.xml:3189 @@ -3681,6 +4127,9 @@ msgid "" "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> for more information on configuring LDAP." msgstr "" +"<quote>ldap</quote>:用於原生 LDAP 驗證。設定 LDAP 的更多資訊,請參閱 " +"<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3138 @@ -3689,28 +4138,31 @@ msgid "" "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> for more information on configuring Kerberos." msgstr "" +"<quote>krb5</quote>:用於 Kerberos 驗證。設定 Kerberos 的更多資訊,請參閱 " +"<citerefentry> <refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3162 msgid "<quote>proxy</quote> for relaying authentication to some other PAM target." -msgstr "" +msgstr "<quote>proxy</quote>:將驗證轉送給其他 PAM 目標。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3165 msgid "<quote>none</quote> disables authentication explicitly." -msgstr "" +msgstr "<quote>none</quote>:明確地停用驗證。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3168 msgid "" "Default: <quote>id_provider</quote> is used if it is set and can handle " "authentication requests." -msgstr "" +msgstr "預設:若已設定 <quote>id_provider</quote> 且可以處理驗證要求,則使用它。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3174 msgid "access_provider (string)" -msgstr "" +msgstr "access_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3177 @@ -3719,18 +4171,20 @@ msgid "" "access providers (in addition to any included in installed backends) " "Internal special providers are:" msgstr "" +"網域使用的存取控制提供者。有兩個內建的 access 提供者(除了已安裝後端中包含的" +"以外)。內部的特殊提供者有:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3183 msgid "" "<quote>permit</quote> always allow access. It's the only permitted access " "provider for a local domain." -msgstr "" +msgstr "<quote>permit</quote>:一律允許存取。這是本機網域唯一允許的 access 提供者。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3186 msgid "<quote>deny</quote> always deny access." -msgstr "" +msgstr "<quote>deny</quote>:一律拒絕存取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3213 @@ -3740,6 +4194,9 @@ msgid "" "<manvolnum>5</manvolnum></citerefentry> for more information on configuring " "the simple access module." msgstr "" +"<quote>simple</quote>:以允許或拒絕清單為基礎的存取控制。設定 simple access " +"模組的更多資訊,請參閱 <citerefentry> <refentrytitle>sssd-simple</" +"refentrytitle> <manvolnum>5</manvolnum></citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3220 @@ -3749,28 +4206,31 @@ msgid "" "<manvolnum>5</manvolnum></citerefentry> for more information on configuring " "Kerberos." msgstr "" +"<quote>krb5</quote>:以 .k5login 為基礎的存取控制。設定 Kerberos 的更多資訊," +"請參閱 <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</" +"manvolnum></citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3227 msgid "<quote>proxy</quote> for relaying access control to another PAM module." -msgstr "" +msgstr "<quote>proxy</quote>:將存取控制轉送給另一個 PAM 模組。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3230 msgid "Default: <quote>permit</quote>" -msgstr "" +msgstr "預設:<quote>permit</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3235 msgid "chpass_provider (string)" -msgstr "" +msgstr "chpass_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3238 msgid "" "The provider which should handle change password operations for the domain. " "Supported change password providers are:" -msgstr "" +msgstr "應處理網域變更密碼作業的提供者。支援的變更密碼提供者有:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3243 @@ -3780,6 +4240,9 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " "LDAP." msgstr "" +"<quote>ldap</quote>:變更儲存在 LDAP 伺服器中的密碼。設定 LDAP 的更多資訊,請" +"參閱 <citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3251 @@ -3788,16 +4251,19 @@ msgid "" "<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> for more information on configuring Kerberos." msgstr "" +"<quote>krb5</quote>:變更 Kerberos 密碼。設定 Kerberos 的更多資訊,請參閱 " +"<citerefentry> <refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3276 msgid "<quote>proxy</quote> for relaying password changes to some other PAM target." -msgstr "" +msgstr "<quote>proxy</quote>:將密碼變更轉送給其他 PAM 目標。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3280 msgid "<quote>none</quote> disallows password changes explicitly." -msgstr "" +msgstr "<quote>none</quote>:明確地禁止變更密碼。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3283 @@ -3805,16 +4271,18 @@ msgid "" "Default: <quote>auth_provider</quote> is used if it is set and can handle " "change password requests." msgstr "" +"預設:若已設定 <quote>auth_provider</quote> 且可以處理變更密碼要求,則使用它" +"。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3290 msgid "sudo_provider (string)" -msgstr "" +msgstr "sudo_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3293 msgid "The SUDO provider used for the domain. Supported SUDO providers are:" -msgstr "" +msgstr "網域使用的 SUDO 提供者。支援的 SUDO 提供者有:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3297 @@ -3823,31 +4291,34 @@ msgid "" "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> for more information on configuring LDAP." msgstr "" +"<quote>ldap</quote>:規則儲存在 LDAP 中。設定 LDAP 的更多資訊,請參閱 " +"<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3305 msgid "" "<quote>ipa</quote> the same as <quote>ldap</quote> but with IPA default " "settings." -msgstr "" +msgstr "<quote>ipa</quote>:與 <quote>ldap</quote> 相同,但使用 IPA 預設設定。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3309 msgid "" "<quote>ad</quote> the same as <quote>ldap</quote> but with AD default " "settings." -msgstr "" +msgstr "<quote>ad</quote>:與 <quote>ldap</quote> 相同,但使用 AD 預設設定。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3313 msgid "<quote>none</quote> disables SUDO explicitly." -msgstr "" +msgstr "<quote>none</quote>:明確地停用 SUDO。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3316 sssd.conf.5.xml:3402 sssd.conf.5.xml:3467 #: sssd.conf.5.xml:3492 sssd.conf.5.xml:3528 msgid "Default: The value of <quote>id_provider</quote> is used if it is set." -msgstr "" +msgstr "預設:若已設定 <quote>id_provider</quote>,則使用它的值。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3320 @@ -3859,6 +4330,11 @@ msgid "" "\"ldap_sudo_*\" in <citerefentry> <refentrytitle>sssd-ldap</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry>." msgstr "" +"sudo_provider 設定的詳細說明請參閱手冊頁 <citerefentry> <refentrytitle>sssd-" +"sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>。有許多設定選項" +"可以用來調整行為。請參閱 <citerefentry> <refentrytitle>sssd-ldap</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 中的 " +"\"ldap_sudo_*\"。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3335 @@ -3868,11 +4344,14 @@ msgid "" "<emphasis>sudo_provider = None</emphasis> to disable all sudo-related " "activity in SSSD if you do not want to use sudo with SSSD at all." msgstr "" +"<emphasis>注意:</emphasis>除非明確停用 sudo 提供者,否則 Sudo 規則會定期在背" +"景中下載。若您完全不打算將 sudo 與 SSSD 一起使用,請設定 <emphasis>" +"sudo_provider = None</emphasis>,以停用 SSSD 中所有與 sudo 相關的活動。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3345 msgid "selinux_provider (string)" -msgstr "" +msgstr "selinux_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3348 @@ -3881,6 +4360,8 @@ msgid "" "provider will be called right after access provider ends. Supported selinux " "providers are:" msgstr "" +"應處理載入 selinux 設定的提供者。請注意,此提供者會在 access 提供者結束後立即" +"被呼叫。支援的 selinux 提供者有:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3354 @@ -3890,11 +4371,14 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " "IPA." msgstr "" +"<quote>ipa</quote>:從 IPA 伺服器載入 selinux 設定。IPA 的更多設定資訊,請參" +"閱 <citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3362 msgid "<quote>none</quote> disallows fetching selinux settings explicitly." -msgstr "" +msgstr "<quote>none</quote>:明確地禁止取回 selinux 設定。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3365 @@ -3902,11 +4386,13 @@ msgid "" "Default: <quote>id_provider</quote> is used if it is set and can handle " "selinux loading requests." msgstr "" +"預設:若已設定 <quote>id_provider</quote> 且可以處理 selinux 載入要求,則使用" +"它。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3371 msgid "subdomains_provider (string)" -msgstr "" +msgstr "subdomains_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3374 @@ -3914,6 +4400,8 @@ msgid "" "The provider which should handle fetching of subdomains. This value should " "be always the same as id_provider. Supported subdomain providers are:" msgstr "" +"應處理取回子網域的提供者。此值應一律與 id_provider 相同。支援的子網域提供者有" +":" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3380 @@ -3923,6 +4411,9 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " "IPA." msgstr "" +"<quote>ipa</quote>:從 IPA 伺服器載入子網域清單。設定 IPA 的更多資訊,請參閱 " +"<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3389 @@ -3932,16 +4423,19 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " "the AD provider." msgstr "" +"<quote>ad</quote>:從 Active Directory 伺服器載入子網域清單。設定 AD 提供者的" +"更多資訊,請參閱 <citerefentry> <refentrytitle>sssd-ad</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3398 msgid "<quote>none</quote> disallows fetching subdomains explicitly." -msgstr "" +msgstr "<quote>none</quote>:明確地禁止取回子網域。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3408 msgid "session_provider (string)" -msgstr "" +msgstr "session_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3411 @@ -3950,16 +4444,18 @@ msgid "" "only user session task currently provided is the integration with Fleet " "Commander, which works only with IPA. Supported session providers are:" msgstr "" +"設定與管理使用者工作階段相關工作的提供者。目前提供的唯一使用者工作階段工作是" +"與 Fleet Commander 的整合,這只適用於 IPA。支援的 session 提供者有:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3418 msgid "<quote>ipa</quote> to allow performing user session related tasks." -msgstr "" +msgstr "<quote>ipa</quote>:允許執行與使用者工作階段相關的工作。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3422 msgid "<quote>none</quote> does not perform any kind of user session related tasks." -msgstr "" +msgstr "<quote>none</quote>:不執行任何與使用者工作階段相關的工作。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3426 @@ -3967,16 +4463,18 @@ msgid "" "Default: <quote>id_provider</quote> is used if it is set and can perform " "session related tasks." msgstr "" +"預設:若已設定 <quote>id_provider</quote> 且可以執行與工作階段相關的工作,則" +"使用它。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3433 msgid "autofs_provider (string)" -msgstr "" +msgstr "autofs_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3436 msgid "The autofs provider used for the domain. Supported autofs providers are:" -msgstr "" +msgstr "網域使用的 autofs 提供者。支援的 autofs 提供者有:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3440 @@ -3985,6 +4483,9 @@ msgid "" "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> for more information on configuring LDAP." msgstr "" +"<quote>ldap</quote>:載入儲存在 LDAP 中的對應表。設定 LDAP 的更多資訊,請參" +"閱 <citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3447 @@ -3993,6 +4494,9 @@ msgid "" "<refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> for more information on configuring IPA." msgstr "" +"<quote>ipa</quote>:載入儲存在 IPA 伺服器中的對應表。設定 IPA 的更多資訊,請" +"參閱 <citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3455 @@ -4001,23 +4505,26 @@ msgid "" "<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> for more information on configuring the AD provider." msgstr "" +"<quote>ad</quote>:載入儲存在 AD 伺服器中的對應表。設定 AD 提供者的更多資訊," +"請參閱 <citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3464 msgid "<quote>none</quote> disables autofs explicitly." -msgstr "" +msgstr "<quote>none</quote>:明確地停用 autofs。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3474 msgid "hostid_provider (string)" -msgstr "" +msgstr "hostid_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3477 msgid "" "The provider used for retrieving host identity information. Supported " "hostid providers are:" -msgstr "" +msgstr "用來取回主機身分資訊的提供者。支援的 hostid 提供者有:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3481 @@ -4027,23 +4534,26 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " "IPA." msgstr "" +"<quote>ipa</quote>:載入儲存在 IPA 伺服器中的主機身分。設定 IPA 的更多資訊," +"請參閱 <citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3489 msgid "<quote>none</quote> disables hostid explicitly." -msgstr "" +msgstr "<quote>none</quote>:明確地停用 hostid。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3499 msgid "resolver_provider (string)" -msgstr "" +msgstr "resolver_provider (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3502 msgid "" "The provider which should handle hosts and networks lookups. Supported " "resolver providers are:" -msgstr "" +msgstr "應處理主機與網路查詢的提供者。支援的 resolver 提供者有:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3506 @@ -4051,6 +4561,8 @@ msgid "" "<quote>proxy</quote> to forward lookups to another NSS library. See " "<quote>proxy_resolver_lib_name</quote>" msgstr "" +"<quote>proxy</quote>:將查詢轉送給另一個 NSS 程式庫。請參閱 <quote>" +"proxy_resolver_lib_name</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3510 @@ -4060,6 +4572,9 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " "LDAP." msgstr "" +"<quote>ldap</quote>:取回儲存在 LDAP 中的主機與網路。設定 LDAP 的更多資訊,請" +"參閱 <citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3517 @@ -4069,11 +4584,14 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> for more information on configuring " "the AD provider." msgstr "" +"<quote>ad</quote>:取回儲存在 AD 中的主機與網路。設定 AD 提供者的更多資訊,請" +"參閱 <citerefentry> <refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3525 msgid "<quote>none</quote> disallows fetching hosts and networks explicitly." -msgstr "" +msgstr "<quote>none</quote>:明確地禁止取回主機與網路。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3538 @@ -4084,6 +4602,9 @@ msgid "" "trust subdomains and Active Directory domains, the flat (NetBIOS) name of " "the domain." msgstr "" +"此網域的正規表示式,描述如何將包含使用者名稱與網域的字串剖析為這些組成部分" +"。\"domain\" 可以匹配 SSSD 設定網域名稱,或是在 IPA 信任子網域與 Active " +"Directory 網域的情況下,匹配網域的簡短 (NetBIOS) 名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3547 @@ -4092,16 +4613,18 @@ msgid "" "<quote>^((?P<name>.+)@(?P<domain>[^@]*)|(?P<name>[^@]+))$</quote> " "which allows two different styles for user names:" msgstr "" +"預設:<quote>^((?P<name>.+)@(?P<domain>[^@]*)|" +"(?P<name>[^@]+))$</quote>,允許兩種不同的使用者名稱樣式:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:3552 sssd.conf.5.xml:3566 msgid "username" -msgstr "" +msgstr "username" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:3555 sssd.conf.5.xml:3569 msgid "username@domain.name" -msgstr "" +msgstr "username@domain.name" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3560 @@ -4110,11 +4633,14 @@ msgid "" "<quote>^(((?P<domain>[^\\\\]+)\\\\(?P<name>.+))|((?P<name>.+)@(?P<domain>[^@]+))|((?P<name>[^@\\\\]+)))$</quote> " "which allows three different styles for user names:" msgstr "" +"AD 與 IPA 提供者的預設值:<quote>^(((?P<domain>[^\\\\]+)\\\\" +"(?P<name>.+))|((?P<name>.+)@(?P<domain>[^@]+))|(" +"(?P<name>[^@\\\\]+)))$</quote>,允許三種不同的使用者名稱樣式:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:3572 msgid "domain\\username" -msgstr "" +msgstr "domain\\username" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3575 @@ -4122,6 +4648,8 @@ msgid "" "While the first two correspond to the general default the third one is " "introduced to allow easy integration of users from Windows domains." msgstr "" +"前兩種對應到一般預設值,第三種是為了讓來自 Windows 網域的使用者容易整合而引入" +"。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3580 @@ -4132,87 +4660,90 @@ msgid "" "allowed in Windows group names). If a user wishes to use short names with " "<quote>@</quote> they must create their own re_expression." msgstr "" +"預設的 re_expression 使用 <quote>@</quote> 字元作為名稱與網域之間的分隔符。因" +"此,預設不接受簡短名稱中的 <quote>@</quote> 字元(Windows 群組名稱允許)。若" +"使用者希望使用帶有 <quote>@</quote> 的簡短名稱,必須自行建立 re_expression。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3632 msgid "Default: <quote>%1$s@%2$s</quote>." -msgstr "" +msgstr "預設:<quote>%1$s@%2$s</quote>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3638 msgid "lookup_family_order (string)" -msgstr "" +msgstr "lookup_family_order (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3641 msgid "" "Provides the ability to select preferred address family to use when " "performing DNS lookups." -msgstr "" +msgstr "提供選擇執行 DNS 查詢時使用之慣用位址系列的能力。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3645 msgid "Supported values:" -msgstr "" +msgstr "支援的值:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3648 msgid "ipv4_first: Try looking up IPv4 address, if that fails, try IPv6" -msgstr "" +msgstr "ipv4_first:嘗試查詢 IPv4 位址,若失敗再嘗試 IPv6" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3651 msgid "ipv4_only: Only attempt to resolve hostnames to IPv4 addresses." -msgstr "" +msgstr "ipv4_only:只嘗試將主機名稱解析為 IPv4 位址。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3654 msgid "ipv6_first: Try looking up IPv6 address, if that fails, try IPv4" -msgstr "" +msgstr "ipv6_first:嘗試查詢 IPv6 位址,若失敗再嘗試 IPv4" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3657 msgid "ipv6_only: Only attempt to resolve hostnames to IPv6 addresses." -msgstr "" +msgstr "ipv6_only:只嘗試將主機名稱解析為 IPv6 位址。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3660 msgid "Default: ipv4_first" -msgstr "" +msgstr "預設:ipv4_first" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3666 msgid "dns_resolver_server_timeout (integer)" -msgstr "" +msgstr "dns_resolver_server_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3669 msgid "" "Defines the amount of time (in milliseconds) SSSD would try to talk to DNS " "server before trying next DNS server." -msgstr "" +msgstr "定義 SSSD 在嘗試下一個 DNS 伺服器之前,嘗試與 DNS 伺服器通訊的時間(毫秒)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3674 msgid "The AD provider will use this option for the CLDAP ping timeouts as well." -msgstr "" +msgstr "AD 提供者也會將此選項用於 CLDAP ping 逾時。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3678 sssd.conf.5.xml:3698 sssd.conf.5.xml:3719 msgid "" "Please see the section <quote>FAILOVER</quote> for more information about " "the service resolution." -msgstr "" +msgstr "有關服務解析的更多資訊,請參閱 <quote>FAILOVER</quote> 一節。" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3683 sssd-ldap.5.xml:645 include/failover.xml:84 msgid "Default: 1000" -msgstr "" +msgstr "預設:1000" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3689 msgid "dns_resolver_op_timeout (integer)" -msgstr "" +msgstr "dns_resolver_op_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3692 @@ -4221,16 +4752,18 @@ msgid "" "(e.g. resolution of a hostname or an SRV record) before trying the next " "hostname or DNS discovery." msgstr "" +"定義在嘗試下一個主機名稱或 DNS 探索之前,等待解析單一 DNS 查詢(例如解析主機" +"名稱或 SRV 記錄)的時間(秒)。" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3703 include/failover.xml:100 msgid "Default: 3" -msgstr "" +msgstr "預設:3" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3709 msgid "dns_resolver_timeout (integer)" -msgstr "" +msgstr "dns_resolver_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3712 @@ -4240,11 +4773,13 @@ msgid "" "unreachable. If this timeout is reached, the domain will continue to operate " "in offline mode." msgstr "" +"定義在假設服務無法連線之前,等待內部故障轉移服務回覆的時間(秒)。若達到此逾" +"時,網域會繼續以離線模式運作。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3730 msgid "dns_resolver_use_search_list (bool)" -msgstr "" +msgstr "dns_resolver_use_search_list (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3733 @@ -4253,6 +4788,8 @@ msgid "" "\"search\" directive from the resolv.conf file. This can lead to delays in " "environments with improperly configured DNS." msgstr "" +"一般來說,DNS 解析器會搜尋 resolv.conf 檔案中 \"search\" 指令定義的網域清單。" +"在 DNS 設定不當的環境中,這可能導致延遲。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3739 @@ -4261,33 +4798,35 @@ msgid "" "configuration, setting this option to FALSE can prevent unnecessary DNS " "lookups in such environments." msgstr "" +"若 SSSD 設定中使用完整網域名稱(或 _srv_),將此選項設為 FALSE 可以防止在這種" +"環境中進行不必要的 DNS 查詢。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3745 msgid "Default: TRUE" -msgstr "" +msgstr "預設:TRUE" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3751 msgid "dns_discovery_domain (string)" -msgstr "" +msgstr "dns_discovery_domain (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3754 msgid "" "If service discovery is used in the back end, specifies the domain part of " "the service discovery DNS query." -msgstr "" +msgstr "若後端使用服務探索,指定服務探索 DNS 查詢的網域部分。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3758 msgid "Default: Use the domain part of machine's hostname" -msgstr "" +msgstr "預設:使用機器主機名稱的網域部分" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3764 msgid "failover_primary_timeout (integer)" -msgstr "" +msgstr "failover_primary_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3767 @@ -4296,56 +4835,58 @@ msgid "" "server. This option defines the number of seconds SSSD waits before " "attempting to reconnect to the primary server." msgstr "" +"當沒有可用的主要伺服器時,SSSD 會故障轉移到備份伺服器。此選項定義 SSSD 在嘗試" +"重新連線主要伺服器之前等待的秒數。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3774 msgid "Note: The minimum value is 31." -msgstr "" +msgstr "注意:最小值為 31。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3777 msgid "Default: 31" -msgstr "" +msgstr "預設:31" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3783 msgid "override_gid (integer)" -msgstr "" +msgstr "override_gid (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3786 msgid "Override the primary GID value with the one specified." -msgstr "" +msgstr "以指定的值覆寫主要 GID 值。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3792 msgid "case_sensitive (string)" -msgstr "" +msgstr "case_sensitive (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3799 msgid "True" -msgstr "" +msgstr "True" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3802 msgid "Case sensitive. This value is invalid for AD provider." -msgstr "" +msgstr "區分大小寫。此值對 AD 提供者無效。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3808 msgid "False" -msgstr "" +msgstr "False" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3810 msgid "Case insensitive." -msgstr "" +msgstr "不區分大小寫。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3814 msgid "Preserving" -msgstr "" +msgstr "Preserving" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3817 @@ -4354,6 +4895,8 @@ msgid "" "of NSS operations. Note that name aliases (and in case of services also " "protocol names) are still lowercased in the output." msgstr "" +"與 False(不區分大小寫)相同,但不會將 NSS 作業結果中的名稱轉為小寫。請注意," +"輸出中的名稱別名(服務的話還包含協定名稱)仍會轉為小寫。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3825 @@ -4361,6 +4904,8 @@ msgid "" "If you want to set this value for trusted domain with IPA provider, you need " "to set it on both the client and SSSD on the server." msgstr "" +"若您想為使用 IPA 提供者的受信任網域設定此值,需要在用戶端與伺服器上的 SSSD 兩" +"邊都設定。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3795 @@ -4368,16 +4913,18 @@ msgid "" "Treat user and group names as case sensitive. Possible option values are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +"將使用者與群組名稱視為區分大小寫。可能的選項值有:<placeholder " +"type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3840 msgid "Default: True (False for AD provider)" -msgstr "" +msgstr "預設:True(AD 提供者為 False)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3846 msgid "subdomain_inherit (string)" -msgstr "" +msgstr "subdomain_inherit (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3849 @@ -4386,103 +4933,105 @@ msgid "" "subdomain. Please note that only selected parameters can be inherited. " "Currently the following options can be inherited:" msgstr "" +"指定應由子網域繼承的設定參數清單。請注意,只有選定的參數可以繼承。目前可以繼" +"承下列選項:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3855 msgid "ldap_search_timeout" -msgstr "" +msgstr "ldap_search_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3858 msgid "ldap_network_timeout" -msgstr "" +msgstr "ldap_network_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3861 msgid "ldap_opt_timeout" -msgstr "" +msgstr "ldap_opt_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3864 msgid "ldap_offline_timeout" -msgstr "" +msgstr "ldap_offline_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3867 msgid "ldap_enumeration_refresh_timeout" -msgstr "" +msgstr "ldap_enumeration_refresh_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3870 msgid "ldap_enumeration_refresh_offset" -msgstr "" +msgstr "ldap_enumeration_refresh_offset" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3873 msgid "ldap_purge_cache_timeout" -msgstr "" +msgstr "ldap_purge_cache_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3876 msgid "ldap_purge_cache_offset" -msgstr "" +msgstr "ldap_purge_cache_offset" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3879 msgid "" "ldap_krb5_keytab (the value of krb5_keytab will be used if ldap_krb5_keytab " "is not set explicitly)" -msgstr "" +msgstr "ldap_krb5_keytab(若未明確設定 ldap_krb5_keytab,則使用 krb5_keytab 的值)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3883 msgid "ldap_krb5_ticket_lifetime" -msgstr "" +msgstr "ldap_krb5_ticket_lifetime" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3886 msgid "ldap_enumeration_search_timeout" -msgstr "" +msgstr "ldap_enumeration_search_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3889 msgid "ldap_connection_expire_timeout" -msgstr "" +msgstr "ldap_connection_expire_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3892 msgid "ldap_connection_expire_offset" -msgstr "" +msgstr "ldap_connection_expire_offset" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3895 msgid "ldap_connection_idle_timeout" -msgstr "" +msgstr "ldap_connection_idle_timeout" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3898 sssd-ldap.5.xml:401 msgid "ldap_use_tokengroups" -msgstr "" +msgstr "ldap_use_tokengroups" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3901 msgid "ldap_user_principal" -msgstr "" +msgstr "ldap_user_principal" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3904 msgid "ignore_group_members" -msgstr "" +msgstr "ignore_group_members" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3907 msgid "auto_private_groups" -msgstr "" +msgstr "auto_private_groups" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3910 msgid "case_sensitive" -msgstr "" +msgstr "case_sensitive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:3915 @@ -4491,26 +5040,28 @@ msgid "" "subdomain_inherit = ldap_purge_cache_timeout\n" " " msgstr "" +"subdomain_inherit = ldap_purge_cache_timeout\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3922 msgid "Note: This option only works with the IPA and AD provider." -msgstr "" +msgstr "注意:此選項只適用於 IPA 與 AD 提供者。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3929 msgid "subdomain_homedir (string)" -msgstr "" +msgstr "subdomain_homedir (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3940 msgid "%F" -msgstr "" +msgstr "%F" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3941 msgid "flat (NetBIOS) name of a subdomain." -msgstr "" +msgstr "子網域的簡短 (NetBIOS) 名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3932 @@ -4521,31 +5072,35 @@ msgid "" "with <emphasis>subdomain_homedir</emphasis>. <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"在 IPA AD 信任中,將此家目錄用作此網域內所有子網域的預設值。可能值的相關資訊" +"請參閱 <emphasis>override_homedir</emphasis>。除此之外,下列展開只能與 " +"<emphasis>subdomain_homedir</emphasis> 一起使用。<placeholder " +"type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3946 msgid "The value can be overridden by <emphasis>override_homedir</emphasis> option." -msgstr "" +msgstr "此值可以被 <emphasis>override_homedir</emphasis> 選項覆寫。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3950 msgid "Default: <filename>/home/%d/%u</filename>" -msgstr "" +msgstr "預設:<filename>/home/%d/%u</filename>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3955 msgid "realmd_tags (string)" -msgstr "" +msgstr "realmd_tags (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3958 msgid "Various tags stored by the realmd configuration service for this domain." -msgstr "" +msgstr "realmd 設定服務為此網域儲存的各種標籤。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3964 msgid "cached_auth_timeout (int)" -msgstr "" +msgstr "cached_auth_timeout (int)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3967 @@ -4555,18 +5110,20 @@ msgid "" "the online mode. If the credentials are incorrect, SSSD falls back to online " "authentication." msgstr "" +"指定自最後一次成功線上驗證以來,SSSD 處於線上模式時使用者將使用快取憑證進行驗" +"證的時間(秒)。若憑證不正確,SSSD 會退回線上驗證。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3975 msgid "" "This option's value is inherited by all trusted domains. At the moment it is " "not possible to set a different value per trusted domain." -msgstr "" +msgstr "此選項的值會由所有受信任網域繼承。目前無法為每個受信任網域設定不同的值。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3980 msgid "Special value 0 implies that this feature is disabled." -msgstr "" +msgstr "特殊值 0 表示停用此功能。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3984 @@ -4575,11 +5132,13 @@ msgid "" "<quote>pam_id_timeout</quote> then the back end could be called to handle " "<quote>initgroups.</quote>" msgstr "" +"請注意,若 <quote>cached_auth_timeout</quote> 比 <quote>pam_id_timeout</" +"quote> 長,則可能呼叫後端處理 <quote>initgroups。</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:3995 msgid "local_auth_policy (string)" -msgstr "" +msgstr "local_auth_policy (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:3998 @@ -4592,6 +5151,10 @@ msgid "" "supported by the backend. With this option additional methods can be enabled " "which are evaluated and checked locally." msgstr "" +"本機驗證方法原則。某些後端(例如 LDAP、proxy 提供者)只支援以密碼為基礎的驗證" +",而其他後端可以處理以 PKINIT 為基礎的 Smartcard 驗證(AD、IPA)、雙因素驗證" +"(IPA)或針對中央實例的其他方法。預設情況下,這種情況只會使用後端支援的方法進" +"行驗證。透過此選項,可以啟用在本機評估與檢查的其他方法。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4010 @@ -4604,6 +5167,11 @@ msgid "" "enables passkey for local authentication. Multiple enable values should be " "comma-separated, such as <quote>enable:passkey, enable:smartcard</quote>" msgstr "" +"此選項有三個可能的值:match、only、enable。<quote>match</quote> 用於匹配 " +"Kerberos 方法的離線與線上狀態。<quote>only</quote> 忽略線上方法,只提供本機方" +"法。enable 允許明確定義用於本機驗證的方法。例如,<quote>enable:passkey</" +"quote> 只為本機驗證啟用 passkey。多個 enable 值應以逗號分隔,例如 <quote>" +"enable:passkey, enable:smartcard</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4023 @@ -4612,41 +5180,43 @@ msgid "" "properly, are currently enabled or disabled for each backend, with the " "default local_auth_policy: <quote>match</quote>" msgstr "" +"下表顯示在設定正確的情況下,每個後端目前啟用或停用的驗證方法,預設的 " +"local_auth_policy 為:<quote>match</quote>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd.conf.5.xml:4036 msgid "local_auth_policy = match (default)" -msgstr "" +msgstr "local_auth_policy = match (default)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd.conf.5.xml:4037 msgid "Passkey" -msgstr "" +msgstr "Passkey" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd.conf.5.xml:4038 msgid "Smartcard" -msgstr "" +msgstr "Smartcard" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:4041 sssd-ldap.5.xml:189 msgid "IPA" -msgstr "" +msgstr "IPA" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:4044 sssd-ldap.5.xml:194 msgid "AD" -msgstr "" +msgstr "AD" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> #: sssd.conf.5.xml:4044 sssd.conf.5.xml:4047 sssd.conf.5.xml:4048 msgid "disabled" -msgstr "" +msgstr "停用" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> #: sssd.conf.5.xml:4047 msgid "LDAP" -msgstr "" +msgstr "LDAP" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4052 @@ -4656,6 +5226,8 @@ msgid "" "authentication methods supported by the backend. I.e. there will be a PIN " "prompt instead of e.g. a password prompt." msgstr "" +"請注意,若已啟用本機 Smartcard 驗證且存在 Smartcard,則 Smartcard 驗證會優先" +"於後端支援的驗證方法。也就是說,會出現 PIN 提示,而不是例如密碼提示。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:4064 @@ -4667,6 +5239,11 @@ msgid "" "auth_provider = none\n" "local_auth_policy = only\n" msgstr "" +"[domain/shadowutils]\n" +"id_provider = proxy\n" +"proxy_lib_name = files\n" +"auth_provider = none\n" +"local_auth_policy = only\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4060 @@ -4675,6 +5252,8 @@ msgid "" "locally using any enabled method (i.e. smartcard, passkey). <placeholder " "type=\"programlisting\" id=\"0\"/>" msgstr "" +"下列設定範例允許本機使用者使用任何已啟用的方法(例如 smartcard、passkey)在本" +"機驗證。<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4072 @@ -4682,28 +5261,30 @@ msgid "" "It is expected that the <quote>files</quote> provider ignores the " "local_auth_policy option and supports Smartcard authentication by default." msgstr "" +"預期 <quote>files</quote> 提供者會忽略 local_auth_policy 選項,並預設支援 " +"Smartcard 驗證。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4077 msgid "Default: match" -msgstr "" +msgstr "預設:match" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4082 msgid "auto_private_groups (string)" -msgstr "" +msgstr "auto_private_groups (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4088 msgid "true" -msgstr "" +msgstr "true" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4091 msgid "" "Create user's private group unconditionally from user's UID number. The GID " "number is ignored in this case." -msgstr "" +msgstr "一律依使用者的 UID 編號建立使用者的私人群組。在此情況下會忽略 GID 編號。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4095 @@ -4713,23 +5294,26 @@ msgid "" "UID or GID number with this option. In other words, enabling this option " "enforces uniqueness across the ID space." msgstr "" +"注意:由於 GID 編號與使用者私人群組是從 UID 編號推斷出來的,因此此選項不支援" +"多個具有相同 UID 或 GID 編號的項目。換句話說,啟用此選項會強制整個 ID 空間的" +"唯一性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4104 msgid "false" -msgstr "" +msgstr "false" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4107 msgid "" "Always use the user's primary GID number. The GID number must refer to a " "group object in the LDAP database." -msgstr "" +msgstr "一律使用使用者的主要 GID 編號。GID 編號必須指向 LDAP 資料庫中的群組物件。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4113 msgid "hybrid" -msgstr "" +msgstr "hybrid" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4116 @@ -4740,13 +5324,16 @@ msgid "" "GID in the user entry is also used by a group object, the primary GID of the " "user resolves to that group object." msgstr "" +"對於 UID 與 GID 編號值相同、且 GID 編號不對應 LDAP 中任何真實群組物件的使用者" +"項目,會自動產生主要群組。若兩者值相同,但使用者項目中的主要 GID 也被群組物件" +"使用,則使用者的主要 GID 會解析為該群組物件。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4129 msgid "" "If the UID and GID of a user are different, then the GID must correspond to " "a group entry, otherwise the GID is simply not resolvable." -msgstr "" +msgstr "若使用者的 UID 與 GID 不同,則 GID 必須對應群組項目,否則 GID 根本無法解析。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4136 @@ -4755,6 +5342,8 @@ msgid "" "separate group objects for the user private groups, but also wish to retain " "the existing user private groups." msgstr "" +"此功能對希望停止為使用者私人群組維護個別群組物件、但也希望保留現有使用者私人" +"群組的環境很有用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4085 @@ -4762,6 +5351,8 @@ msgid "" "This option takes any of three available values: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"此選項接受三個可用值中的任何一個:<placeholder type=\"variablelist\" " +"id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4148 @@ -4769,6 +5360,8 @@ msgid "" "For subdomains, the default value is False for subdomains that use assigned " "POSIX IDs and True for subdomains that use automatic ID-mapping." msgstr "" +"對於子網域,使用指派 POSIX ID 的子網域預設值為 False,使用自動 ID 對應的子網" +"域預設值為 True。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:4156 @@ -4777,6 +5370,8 @@ msgid "" "[domain/forest.domain/sub.domain]\n" "auto_private_groups = false\n" msgstr "" +"[domain/forest.domain/sub.domain]\n" +"auto_private_groups = false\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd.conf.5.xml:4162 @@ -4786,6 +5381,9 @@ msgid "" "subdomain_inherit = auto_private_groups\n" "auto_private_groups = false\n" msgstr "" +"[domain/forest.domain]\n" +"subdomain_inherit = auto_private_groups\n" +"auto_private_groups = false\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4153 @@ -4795,6 +5393,9 @@ msgid "" "globally for all subdomains in the main domain section using the " "subdomain_inherit option: <placeholder type=\"programlisting\" id=\"1\"/>" msgstr "" +"auto_private_groups 的值可以在子區段中逐子網域設定,例如:<placeholder " +"type=\"programlisting\" id=\"0\"/>,或使用 subdomain_inherit 選項在主網域區段" +"中為所有子網域全域設定:<placeholder type=\"programlisting\" id=\"1\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:2552 @@ -4804,16 +5405,19 @@ msgid "" "<quote>[domain/<replaceable>NAME</replaceable>]</quote> <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"這些設定選項可以出現在網域設定區段中,也就是名為 <quote>[domain/<replaceable>" +"NAME</replaceable>]</quote> 的區段中 <placeholder type=\"variablelist\" " +"id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4177 msgid "proxy_pam_target (string)" -msgstr "" +msgstr "proxy_pam_target (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4180 msgid "The proxy target PAM proxies to." -msgstr "" +msgstr "proxy 轉送到的 PAM 目標。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4183 @@ -4822,11 +5426,13 @@ msgid "" "or create a new one and add the service name here. As an alternative you can " "enable local authentication with the local_auth_policy option." msgstr "" +"預設:預設未設定,您必須採用現有的 pam 設定或建立新的設定,並在此加入服務名稱" +"。另一種做法是使用 local_auth_policy 選項啟用本機驗證。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4193 msgid "proxy_lib_name (string)" -msgstr "" +msgstr "proxy_lib_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4196 @@ -4835,11 +5441,13 @@ msgid "" "searched for in the library are in the form of _nss_$(libName)_$(function), " "for example _nss_files_getpwent." msgstr "" +"在 proxy 網域中使用的 NSS 程式庫名稱。在程式庫中搜尋的 NSS 函式形式為 _nss_$" +"(libName)_$(function),例如 _nss_files_getpwent。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4206 msgid "proxy_resolver_lib_name (string)" -msgstr "" +msgstr "proxy_resolver_lib_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4209 @@ -4848,11 +5456,13 @@ msgid "" "domains. The NSS functions searched for in the library are in the form of " "_nss_$(libName)_$(function), for example _nss_dns_gethostbyname2_r." msgstr "" +"在 proxy 網域中用於主機與網路查詢的 NSS 程式庫名稱。在程式庫中搜尋的 NSS 函式" +"形式為 _nss_$(libName)_$(function),例如 _nss_dns_gethostbyname2_r。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4220 msgid "proxy_fast_alias (boolean)" -msgstr "" +msgstr "proxy_fast_alias (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4223 @@ -4862,11 +5472,14 @@ msgid "" "name was an alias. Setting this option to true would cause the SSSD to " "perform the ID lookup from cache for performance reasons." msgstr "" +"在 proxy 提供者中依名稱查詢使用者或群組時,會再依 ID 進行第二次查詢,以「正規" +"化」名稱,以防要求的名稱是別名。將此選項設為 true 會讓 SSSD 基於效能考量從快" +"取執行 ID 查詢。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4237 msgid "proxy_max_children (integer)" -msgstr "" +msgstr "proxy_max_children (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4240 @@ -4875,18 +5488,20 @@ msgid "" "for high-load SSSD environments where sssd may run out of available child " "slots, which would cause some issues due to the requests being queued." msgstr "" +"此選項指定預先分叉的 proxy 子程序數目。這對高負載的 SSSD 環境很有用,在這種環" +"境中 sssd 可能會用完可用的子程序位置,導致要求排隊而產生一些問題。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4173 msgid "" "Options valid for proxy domains. <placeholder type=\"variablelist\" " "id=\"0\"/>" -msgstr "" +msgstr "適用於 proxy 網域的選項。<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd.conf.5.xml:4256 msgid "Application domains" -msgstr "" +msgstr "應用程式網域" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:4258 @@ -4905,6 +5520,15 @@ msgid "" "internally represents a domain with type <quote>application</quote> " "optionally inherits settings from a tradition SSSD domain." msgstr "" +"SSSD 憑藉其 D-Bus 介面(請參閱 <citerefentry> <refentrytitle>sssd-ifp</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>),作為通往儲存使用者" +"與群組之 LDAP 目錄的閘道,對應用程式很有吸引力。然而,與傳統 SSSD 部署(所有" +"使用者與群組都擁有 POSIX 屬性,或可以從 Windows SID 推斷這些屬性)相反,在許" +"多情況下,應用程式支援情境中的使用者與群組沒有 POSIX 屬性。管理員可以不必設" +"定 <quote>[domain/<replaceable>NAME</replaceable>]</quote> 區段,而改為設定 " +"<quote>[application/<replaceable>NAME</replaceable>]</quote> 區段,該區段在內" +"部代表類型為 <quote>application</quote> 的網域,並可選擇性地從傳統 SSSD 網域" +"繼承設定。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:4278 @@ -4913,16 +5537,18 @@ msgid "" "the <quote>domains</quote> parameter so that the lookup order between the " "application domain and its POSIX sibling domain is set correctly." msgstr "" +"請注意,應用程式網域仍必須在 <quote>domains</quote> 參數中明確啟用,才能正確" +"設定應用程式網域與其 POSIX 對應網域之間的查詢順序。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> #: sssd.conf.5.xml:4284 msgid "Application domain parameters" -msgstr "" +msgstr "應用程式網域參數" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd.conf.5.xml:4286 msgid "inherit_from (string)" -msgstr "" +msgstr "inherit_from (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4289 @@ -4932,6 +5558,8 @@ msgid "" "application settings that augment or override the <quote>sibling</quote> " "domain settings." msgstr "" +"應用程式網域從中繼承所有設定的 SSSD POSIX 類型網域。此外,應用程式網域可以在" +"應用程式設定中加入自己的設定,以擴充或覆寫<quote>對應</quote>網域的設定。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd.conf.5.xml:4303 @@ -4942,6 +5570,10 @@ msgid "" "the telephoneNumber attribute, stores it as the phone attribute in the cache " "and makes the phone attribute reachable through the D-Bus interface." msgstr "" +"下列範例說明應用程式網域的用法。在此設定中,POSIX 網域連線到 LDAP 伺服器,並" +"由作業系統透過 NSS responder 使用。此外,應用程式網域也會要求 " +"telephoneNumber 屬性,將其儲存為快取中的 phone 屬性,並讓 phone 屬性可透過 D-" +"Bus 介面存取。" #. type: Content of: <reference><refentry><refsect1><refsect2><programlisting> #: sssd.conf.5.xml:4311 @@ -4962,11 +5594,25 @@ msgid "" "inherit_from = posixdom\n" "ldap_user_extra_attrs = phone:telephoneNumber\n" msgstr "" +"[sssd]\n" +"domains = appdom, posixdom\n" +"\n" +"[ifp]\n" +"user_attributes = +phone\n" +"\n" +"[domain/posixdom]\n" +"id_provider = ldap\n" +"ldap_uri = ldap://ldap.example.com\n" +"ldap_search_base = dc=example,dc=com\n" +"\n" +"[application/appdom]\n" +"inherit_from = posixdom\n" +"ldap_user_extra_attrs = phone:telephoneNumber\n" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:4331 msgid "TRUSTED DOMAIN SECTION" -msgstr "" +msgstr "受信任網域區段" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4333 @@ -4978,68 +5624,72 @@ msgid "" "examples below for explanation. Currently supported options in the trusted " "domain section are:" msgstr "" +"網域區段中使用的一些選項也可以在受信任網域區段中使用,也就是名為 <quote>" +"[domain/<replaceable>DOMAIN_NAME</replaceable>/<replaceable>" +"TRUSTED_DOMAIN_NAME</replaceable>]</quote> 的區段。其中 DOMAIN_NAME 是實際加" +"入的基礎網域。請參閱下列範例以了解說明。目前受信任網域區段支援的選項有:" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4340 msgid "ldap_search_base," -msgstr "" +msgstr "ldap_search_base," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4341 msgid "ldap_user_search_base," -msgstr "" +msgstr "ldap_user_search_base," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4342 msgid "ldap_group_search_base," -msgstr "" +msgstr "ldap_group_search_base," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4343 msgid "ldap_netgroup_search_base," -msgstr "" +msgstr "ldap_netgroup_search_base," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4344 msgid "ldap_service_search_base," -msgstr "" +msgstr "ldap_service_search_base," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4345 msgid "ldap_sasl_mech," -msgstr "" +msgstr "ldap_sasl_mech," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4346 msgid "ad_server," -msgstr "" +msgstr "ad_server," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4347 msgid "ad_backup_server," -msgstr "" +msgstr "ad_backup_server," #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4348 msgid "ad_site," -msgstr "" +msgstr "ad_site," #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:4349 sssd-ipa.5.xml:884 msgid "use_fully_qualified_names" -msgstr "" +msgstr "use_fully_qualified_names" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4353 msgid "" "For more details about these options see their individual description in the " "manual page." -msgstr "" +msgstr "關於這些選項的更多詳細資料,請參閱手冊頁中各選項的個別說明。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:4359 msgid "CERTIFICATE MAPPING SECTION" -msgstr "" +msgstr "憑證對應區段" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4361 @@ -5054,6 +5704,12 @@ msgid "" "or not even possible to do this for the general case where local services " "use PAM for authentication." msgstr "" +"若要允許使用 Smartcard 與憑證進行驗證,SSSD 必須能夠將憑證對應到使用者。這可" +"以透過將完整憑證加入使用者的 LDAP 物件或本機覆寫來完成。雖然使用完整憑證是使" +"用 SSH 之 Smartcard 驗證功能所必需的(詳情請參閱 <citerefentry> " +"<refentrytitle>sss_ssh_authorizedkeys</refentrytitle> <manvolnum>8</" +"manvolnum> </citerefentry>),但對於本機服務使用 PAM 進行驗證的一般情況來說," +"這樣做可能很麻煩,甚至不可能。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4375 @@ -5062,6 +5718,9 @@ msgid "" "SSSD (see <citerefentry> <refentrytitle>sss-certmap</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> for details)." msgstr "" +"為了讓對應更有彈性,SSSD 加入了對應與匹配規則(詳情請參閱 <citerefentry> " +"<refentrytitle>sss-certmap</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry>)。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4384 @@ -5071,18 +5730,21 @@ msgid "" "<quote>[certmap/<replaceable>DOMAIN_NAME</replaceable>/<replaceable>RULE_NAME</replaceable>]</quote>. " "In this section the following options are allowed:" msgstr "" +"可以在 SSSD 設定中新增對應與匹配規則,使用名稱類似 <quote>[certmap/" +"<replaceable>DOMAIN_NAME</replaceable>/<replaceable>RULE_NAME</replaceable>" +"]</quote> 的獨立區段。此區段允許下列選項:" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:4391 msgid "matchrule (string)" -msgstr "" +msgstr "matchrule (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4394 msgid "" "Only certificates from the Smartcard which matches this rule will be " "processed, all others are ignored." -msgstr "" +msgstr "只會處理 Smartcard 中符合此規則的憑證,其他憑證都會被忽略。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4398 @@ -5090,16 +5752,18 @@ msgid "" "Default: KRB5:<EKU>clientAuth, i.e. only certificates which have the " "Extended Key Usage <quote>clientAuth</quote>" msgstr "" +"預設:KRB5:<EKU>clientAuth,也就是只有具有擴充金鑰用法 <quote>" +"clientAuth</quote> 的憑證" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:4405 msgid "maprule (string)" -msgstr "" +msgstr "maprule (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4408 msgid "Defines how the user is found for a given certificate." -msgstr "" +msgstr "定義如何為給定的憑證找到使用者。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:4414 @@ -5107,18 +5771,20 @@ msgid "" "LDAP:(userCertificate;binary={cert!bin}) for LDAP based providers like " "<quote>ldap</quote>, <quote>AD</quote> or <quote>ipa</quote>." msgstr "" +"LDAP:(userCertificate;binary={cert!bin}):用於以 LDAP 為基礎的提供者,例如 " +"<quote>ldap</quote>、<quote>AD</quote> 或 <quote>ipa</quote>。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:4420 msgid "" "The RULE_NAME for the <quote>files</quote> provider which tries to find a " "user with the same name." -msgstr "" +msgstr "RULE_NAME 用於 <quote>files</quote> 提供者,會嘗試找到具有相同名稱的使用者。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:4429 msgid "domains (string)" -msgstr "" +msgstr "domains (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4432 @@ -5128,16 +5794,18 @@ msgid "" "supports subdomains this option can be used to add the rule to subdomains as " "well." msgstr "" +"套用規則的網域名稱逗號分隔清單。預設情況下,規則只在 sssd.conf 中設定的網域有" +"效。若提供者支援子網域,此選項也可以用來將規則加入子網域。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4439 msgid "Default: the configured domain in sssd.conf" -msgstr "" +msgstr "預設:sssd.conf 中設定的網域" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.conf.5.xml:4444 msgid "priority (integer)" -msgstr "" +msgstr "priority (integer)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4447 @@ -5146,11 +5814,13 @@ msgid "" "number the lower the priority. <quote>0</quote> stands for the highest " "priority while <quote>4294967295</quote> is the lowest." msgstr "" +"定義規則優先順序的無符號整數值。數字越大優先順序越低。<quote>0</quote> 代表最" +"高優先順序,<quote>4294967295</quote> 代表最低。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4453 msgid "Default: the lowest priority" -msgstr "" +msgstr "預設:最低優先順序" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4459 @@ -5158,13 +5828,15 @@ msgid "" "To make the configuration simple and reduce the amount of configuration " "options the <quote>files</quote> provider has some special properties:" msgstr "" +"為了讓設定更簡單並減少設定選項的數量,<quote>files</quote> 提供者有一些特殊屬" +"性:" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:4465 msgid "" "if maprule is not set the RULE_NAME name is assumed to be the name of the " "matching user" -msgstr "" +msgstr "若未設定 maprule,RULE_NAME 名稱會被視為匹配使用者的名稱" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:4471 @@ -5174,16 +5846,19 @@ msgid "" "e.g. <quote>(username)</quote> or " "<quote>({subject_rfc822_name.short_name})</quote>" msgstr "" +"若使用 maprule,單一使用者名稱或像是 <quote>{subject_rfc822_name.short_name}" +"</quote> 的範本都必須放在大括號中,例如 <quote>(username)</quote> 或 <quote>(" +"{subject_rfc822_name.short_name})</quote>" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:4480 msgid "the <quote>domains</quote> option is ignored" -msgstr "" +msgstr "<quote>domains</quote> 選項會被忽略" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:4488 msgid "PROMPTING CONFIGURATION SECTION" -msgstr "" +msgstr "提示設定區段" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4490 @@ -5194,6 +5869,9 @@ msgid "" "methods are available for the user trying to log in. Based on the results " "pam_sss will prompt the user for appropriate credentials." msgstr "" +"若存在特殊檔案(<filename>/var/lib/sss/pubconf/pam_preauth_available</" +"filename>),SSSD 的 PAM 模組 pam_sss 會要求 SSSD 找出嘗試登入的使用者可以使" +"用哪些驗證方法。根據結果,pam_sss 會提示使用者輸入適當的憑證。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4498 @@ -5203,58 +5881,61 @@ msgid "" "select the prompting might not be suitable for all use cases. The following " "options should provide a better flexibility here." msgstr "" +"隨著驗證方法的數量增加,以及單一使用者可能有多種驗證方法,pam_sss 用來選擇提" +"示方式的啟發式演算法可能不適合所有使用案例。下列選項應該能在這裡提供更好的彈" +"性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4510 msgid "[prompting/password]" -msgstr "" +msgstr "[prompting/password]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4513 msgid "password_prompt" -msgstr "" +msgstr "password_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4514 msgid "to change the string of the password prompt" -msgstr "" +msgstr "變更密碼提示的字串" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4512 msgid "" "to configure password prompting, allowed options are: <placeholder " "type=\"variablelist\" id=\"0\"/>" -msgstr "" +msgstr "設定密碼提示,允許的選項有:<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4522 msgid "[prompting/2fa]" -msgstr "" +msgstr "[prompting/2fa]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4526 msgid "first_prompt" -msgstr "" +msgstr "first_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4527 msgid "to change the string of the prompt for the first factor" -msgstr "" +msgstr "變更第一個因素的提示字串" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4530 msgid "second_prompt" -msgstr "" +msgstr "second_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4531 msgid "to change the string of the prompt for the second factor" -msgstr "" +msgstr "變更第二個因素的提示字串" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4534 msgid "single_prompt" -msgstr "" +msgstr "single_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4535 @@ -5264,6 +5945,8 @@ msgid "" "string. Please note that both factors have to be entered here, even if the " "second factor is optional." msgstr "" +"布林值,若為 True,則只會出現單一提示,使用 first_prompt 的值,預期兩個因素會" +"以單一字串輸入。請注意,即使第二個因素是選用的,兩個因素都必須在此輸入。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4524 @@ -5273,6 +5956,9 @@ msgid "" "optional and it should be possible to log in either only with the password " "or with both factors two-step prompting has to be used." msgstr "" +"設定雙因素驗證提示,允許的選項有:<placeholder type=\"variablelist\" " +"id=\"0\"/> 若第二個因素是選用的,且應該可以只使用密碼或使用兩個因素登入,則必" +"須使用兩步驟提示。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4548 @@ -5284,16 +5970,20 @@ msgid "" "the user at the SSH password prompt will always be the two factors in a " "single string, even if two-factor authentication is optional." msgstr "" +"某些用戶端(例如啟用 'PasswordAuthentication yes' 的 SSH)會產生自己的提示," +"不使用 SSSD 或其他 PAM 模組提供的提示。此外,對於使用 PasswordAuthentication " +"的 SSH,若可以使用雙因素驗證,SSSD 預期使用者在 SSH 密碼提示輸入的憑證一律是" +"以單一字串呈現的兩個因素,即使雙因素驗證是選用的。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4563 msgid "[prompting/passkey]" -msgstr "" +msgstr "[prompting/passkey]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd.conf.5.xml:4569 sssd-ad.5.xml:1022 msgid "interactive" -msgstr "" +msgstr "interactive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4571 @@ -5302,38 +5992,40 @@ msgid "" "of a passkey device. Recommended if your device doesn’t have a tactile " "trigger." msgstr "" +"布林值,若為 True,則在測試 passkey 裝置是否存在之前,先顯示訊息並等待。若您" +"的裝置沒有觸覺觸發器,建議使用此選項。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4579 msgid "interactive_prompt" -msgstr "" +msgstr "interactive_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4581 msgid "to change the message of the interactive prompt." -msgstr "" +msgstr "變更互動提示的訊息。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4586 msgid "touch" -msgstr "" +msgstr "touch" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4588 msgid "" "boolean value, if True prompt a message to remind the user to touch the " "device." -msgstr "" +msgstr "布林值,若為 True,則顯示訊息提醒使用者觸碰裝置。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd.conf.5.xml:4594 msgid "touch_prompt" -msgstr "" +msgstr "touch_prompt" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4596 msgid "to change the message of the touch prompt." -msgstr "" +msgstr "變更觸碰提示的訊息。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd.conf.5.xml:4565 @@ -5341,6 +6033,8 @@ msgid "" "to configure passkey authentication prompting, allowed options are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +"設定 passkey 驗證提示,允許的選項有:<placeholder type=\"variablelist\" " +"id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4505 @@ -5350,6 +6044,10 @@ msgid "" "type=\"variablelist\" id=\"0\"/> <placeholder type=\"variablelist\" " "id=\"1\"/> <placeholder type=\"variablelist\" id=\"2\"/>" msgstr "" +"每個支援的驗證方法在 <quote>[prompting/...]</quote> 下都有自己的設定子區段。" +"目前有:<placeholder type=\"variablelist\" id=\"0\"/> <placeholder " +"type=\"variablelist\" id=\"1\"/> <placeholder type=\"variablelist\" " +"id=\"2\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4607 @@ -5358,11 +6056,13 @@ msgid "" "e.g. <quote>[prompting/password/sshd]</quote> to individual change the " "prompting for this service." msgstr "" +"可以為特定的 PAM 服務加入子區段,例如 <quote>[prompting/password/sshd]</" +"quote>,以個別變更此服務的提示。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.conf.5.xml:4614 pam_sss_gss.8.xml:157 idmap_sss.8.xml:43 msgid "EXAMPLES" -msgstr "" +msgstr "範例" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd.conf.5.xml:4620 @@ -5392,6 +6092,29 @@ msgid "" "max_id = 20000\n" "enumerate = False\n" msgstr "" +"[sssd]\n" +"domains = LDAP\n" +"services = nss, pam\n" +"\n" +"[nss]\n" +"filter_groups = root\n" +"filter_users = root\n" +"\n" +"[pam]\n" +"\n" +"[domain/LDAP]\n" +"id_provider = ldap\n" +"ldap_uri = ldap://ldap.example.com\n" +"ldap_search_base = dc=example,dc=com\n" +"\n" +"auth_provider = krb5\n" +"krb5_server = kerberos.example.com\n" +"krb5_realm = EXAMPLE.COM\n" +"cache_credentials = true\n" +"\n" +"min_id = 10000\n" +"max_id = 20000\n" +"enumerate = False\n" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4616 @@ -5401,6 +6124,8 @@ msgid "" "configuring domains for more details. <placeholder type=\"programlisting\" " "id=\"0\"/>" msgstr "" +"1. 下列範例顯示典型的 SSSD 設定。它沒有描述網域本身的設定——關於設定網域的更多" +"詳細資料,請參閱相關文件。<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd.conf.5.xml:4652 @@ -5409,6 +6134,8 @@ msgid "" "[domain/ipa.com/child.ad.com]\n" "use_fully_qualified_names = false\n" msgstr "" +"[domain/ipa.com/child.ad.com]\n" +"use_fully_qualified_names = false\n" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4646 @@ -5420,6 +6147,10 @@ msgid "" "configuration should be used. <placeholder type=\"programlisting\" " "id=\"0\"/>" msgstr "" +"2. 下列範例顯示 IPA AD 信任的設定,其中 AD 樹系由兩個以父子結構組成的網域構成" +"。假設 IPA 網域 (ipa.com) 與 AD 網域 (ad.com) 有信任關係。ad.com 有子網域 " +"(child.ad.com)。若要在子網域啟用簡短名稱,應使用下列設定。<placeholder " +"type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd.conf.5.xml:4663 @@ -5431,6 +6162,11 @@ msgid "" "domains = my.domain, your.domain\n" "priority = 10\n" msgstr "" +"[certmap/my.domain/rule_name]\n" +"matchrule = <ISSUER>^CN=My-CA,DC=MY,DC=DOMAIN$\n" +"maprule = (userCertificate;binary={cert!bin})\n" +"domains = my.domain, your.domain\n" +"priority = 10\n" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.conf.5.xml:4657 @@ -5441,16 +6177,19 @@ msgid "" "certificate in the search filter. <placeholder type=\"programlisting\" " "id=\"0\"/>" msgstr "" +"3. 下列範例顯示憑證對應規則的設定。它適用於設定的網域 <quote>my.domain</" +"quote>,也適用於子網域 <quote>your.domain</quote>,並在搜尋篩選器中使用完整憑" +"證。<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-ldap.5.xml:10 sssd-ldap.5.xml:16 msgid "sssd-ldap" -msgstr "" +msgstr "sssd-ldap" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-ldap.5.xml:17 msgid "SSSD LDAP provider" -msgstr "" +msgstr "SSSD LDAP 提供者" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:21 pam_sss.8.xml:63 pam_sss_gss.8.xml:30 @@ -5464,7 +6203,7 @@ msgstr "" #: sssd-session-recording.5.xml:21 sssd-kcm.8.xml:21 sssd-systemtap.5.xml:21 #: sssd-ldap-attributes.5.xml:21 sssd_krb5_localauth_plugin.8.xml:20 msgid "DESCRIPTION" -msgstr "" +msgstr "說明" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:23 @@ -5476,11 +6215,15 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> manual page for detailed syntax " "information." msgstr "" +"本手冊頁說明 <citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>" +"8</manvolnum> </citerefentry> 之 LDAP 網域的設定。詳細的語法資訊請參閱 " +"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> 手冊頁的 <quote>FILE FORMAT</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:35 msgid "You can configure SSSD to use more than one LDAP domain." -msgstr "" +msgstr "您可以設定 SSSD 使用多個 LDAP 網域。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:38 @@ -5493,18 +6236,23 @@ msgid "" "recommended. Please refer to the <quote>ldap_access_filter</quote> config " "option for more information about using LDAP as an access provider." msgstr "" +"LDAP 後端支援 id、auth、access 與 chpass 提供者。若您想針對 LDAP 伺服器進行驗" +"證,需要 TLS/SSL 或 LDAPS。<command>sssd</command> <emphasis>不</emphasis>支" +"援透過未加密通道進行驗證。即使 LDAP 伺服器只用來當作身分提供者,也強烈建議使" +"用加密通道。有關將 LDAP 用作 access 提供者的更多資訊,請參閱 <quote>" +"ldap_access_filter</quote> 設定選項。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:50 sssd-simple.5.xml:69 sssd-ipa.5.xml:82 sssd-ad.5.xml:130 #: sssd-krb5.5.xml:63 sssd-ifp.5.xml:60 sssd-files.5.xml:77 #: sssd-session-recording.5.xml:58 sssd-kcm.8.xml:202 msgid "CONFIGURATION OPTIONS" -msgstr "" +msgstr "設定選項" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:67 msgid "ldap_uri, ldap_backup_uri (string)" -msgstr "" +msgstr "ldap_uri, ldap_backup_uri (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:70 @@ -5516,31 +6264,34 @@ msgid "" "enabled. For more information, refer to the <quote>SERVICE DISCOVERY</quote> " "section." msgstr "" +"指定 SSSD 應依偏好順序連線之 LDAP 伺服器的 URI 逗號分隔清單。有關故障轉移與伺" +"服器備援的更多資訊,請參閱 <quote>FAILOVER</quote> 一節。若兩個選項都未指定," +"則啟用服務探索。更多資訊請參閱 <quote>SERVICE DISCOVERY</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:77 msgid "The format of the URI must match the format defined in RFC 2732:" -msgstr "" +msgstr "URI 的格式必須符合 RFC 2732 定義的格式:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:80 msgid "ldap[s]://<host>[:port]" -msgstr "" +msgstr "ldap[s]://<host>[:port]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:83 msgid "For explicit IPv6 addresses, <host> must be enclosed in brackets []" -msgstr "" +msgstr "對於明確的 IPv6 位址,<host> 必須以方括號 [] 括起來" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:86 msgid "example: ldap://[fc00::126:25]:389" -msgstr "" +msgstr "example: ldap://[fc00::126:25]:389" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:92 msgid "ldap_chpass_uri, ldap_chpass_backup_uri (string)" -msgstr "" +msgstr "ldap_chpass_uri, ldap_chpass_backup_uri (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:95 @@ -5550,56 +6301,58 @@ msgid "" "user. Refer to the <quote>FAILOVER</quote> section for more information on " "failover and server redundancy." msgstr "" +"指定 SSSD 應依偏好順序連線以變更使用者密碼之 LDAP 伺服器的 URI 逗號分隔清單。" +"有關故障轉移與伺服器備援的更多資訊,請參閱 <quote>FAILOVER</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:102 msgid "To enable service discovery ldap_chpass_dns_service_name must be set." -msgstr "" +msgstr "若要啟用服務探索,必須設定 ldap_chpass_dns_service_name。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:106 msgid "Default: empty, i.e. ldap_uri is used." -msgstr "" +msgstr "預設:空白,也就是使用 ldap_uri。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:112 msgid "ldap_search_base (string)" -msgstr "" +msgstr "ldap_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:115 msgid "The default base DN to use for performing LDAP user operations." -msgstr "" +msgstr "執行 LDAP 使用者作業時使用的預設基礎 DN。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:119 msgid "" "Starting with SSSD 1.7.0, SSSD supports multiple search bases using the " "syntax:" -msgstr "" +msgstr "從 SSSD 1.7.0 開始,SSSD 支援使用下列語法的多個搜尋基礎:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:123 msgid "search_base[?scope?[filter][?search_base?scope?[filter]]*]" -msgstr "" +msgstr "search_base[?scope?[filter][?search_base?scope?[filter]]*]" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:126 msgid "The scope can be one of \"base\", \"onelevel\" or \"subtree\"." -msgstr "" +msgstr "scope 可以是 \"base\"、\"onelevel\" 或 \"subtree\" 之一。" #. type: Content of: <listitem><para> #: sssd-ldap.5.xml:129 include/ldap_search_bases.xml:18 msgid "" "The filter must be a valid LDAP search filter as specified by " "http://www.ietf.org/rfc/rfc2254.txt" -msgstr "" +msgstr "filter 必須是 http://www.ietf.org/rfc/rfc2254.txt 指定的有效 LDAP 搜尋篩選器" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:133 sssd-ad.5.xml:312 sss_override.8.xml:143 #: sss_override.8.xml:240 sssd-ldap-attributes.5.xml:453 msgid "Examples:" -msgstr "" +msgstr "範例:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:136 @@ -5607,6 +6360,8 @@ msgid "" "ldap_search_base = dc=example,dc=com (which is equivalent to) " "ldap_search_base = dc=example,dc=com?subtree?" msgstr "" +"ldap_search_base = dc=example,dc=com(等同於) ldap_search_base = " +"dc=example,dc=com?subtree?" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:141 @@ -5614,6 +6369,8 @@ msgid "" "ldap_search_base = " "cn=host_specific,dc=example,dc=com?subtree?(host=thishost)?dc=example.com?subtree?" msgstr "" +"ldap_search_base = cn=host_specific,dc=example,dc=com?subtree?(host=thishost)" +"?dc=example.com?subtree?" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:144 @@ -5623,6 +6380,8 @@ msgid "" "different search bases). This will lead to unpredictable behavior on client " "machines." msgstr "" +"注意:不支援多個搜尋基礎參照同名物件(例如,兩個不同搜尋基礎中名稱相同的群組" +")。這會導致用戶端機器上出現不可預期的行為。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:151 @@ -5634,11 +6393,15 @@ msgid "" "the search base of the LDAP server to make this work. Multiple values are " "are not supported." msgstr "" +"預設:若未設定,則使用 LDAP 伺服器 RootDSE 中 defaultNamingContext 或 " +"namingContexts 屬性的值。若 defaultNamingContext 不存在或值為空白,則使用 " +"namingContexts。要讓此功能運作,namingContexts 屬性必須有單一值,即 LDAP 伺服" +"器搜尋基礎的 DN。不支援多個值。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:165 msgid "ldap_schema (string)" -msgstr "" +msgstr "ldap_schema (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:168 @@ -5647,21 +6410,23 @@ msgid "" "the selected schema, the default attribute names retrieved from the servers " "may vary. The way that some attributes are handled may also differ." msgstr "" +"指定目標 LDAP 伺服器使用的綱要類型。視選取的綱要而定,從伺服器取回的預設屬性" +"名稱可能會有所不同。某些屬性的處理方式也可能不同。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:175 msgid "Four schema types are currently supported:" -msgstr "" +msgstr "目前支援四種綱要類型:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ldap.5.xml:179 msgid "rfc2307" -msgstr "" +msgstr "rfc2307" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ldap.5.xml:184 msgid "rfc2307bis" -msgstr "" +msgstr "rfc2307bis" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:200 @@ -5673,36 +6438,40 @@ msgid "" "attribute. The AD schema type sets the attributes to correspond with Active " "Directory 2008r2 values." msgstr "" +"這些綱要類型之間的主要差異在於群組成員在伺服器中的記錄方式。使用 rfc2307 時," +"群組成員依名稱列在 <emphasis>memberUid</emphasis> 屬性中。使用 rfc2307bis 與 " +"IPA 時,群組成員依 DN 列出並儲存在 <emphasis>member</emphasis> 屬性中。AD 綱" +"要類型會將屬性設為對應 Active Directory 2008r2 的值。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:210 msgid "Default: rfc2307" -msgstr "" +msgstr "預設:rfc2307" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:216 msgid "ldap_pwmodify_mode (string)" -msgstr "" +msgstr "ldap_pwmodify_mode (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:219 msgid "Specify the operation that is used to modify user password." -msgstr "" +msgstr "指定用來修改使用者密碼的作業。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:223 msgid "Two modes are currently supported:" -msgstr "" +msgstr "目前支援兩種模式:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ldap.5.xml:227 msgid "exop - Password Modify Extended Operation (RFC 3062)" -msgstr "" +msgstr "exop - 密碼修改延伸作業 (RFC 3062)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ldap.5.xml:233 msgid "ldap_modify - Direct modification of userPassword (not recommended)." -msgstr "" +msgstr "ldap_modify - 直接修改 userPassword(不建議)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:240 @@ -5712,51 +6481,54 @@ msgid "" "connection is used to change the password therefore the user must have write " "access to userPassword attribute." msgstr "" +"注意:首先,會建立新連線,以要求變更密碼的使用者身分繫結來驗證目前的密碼。若" +"成功,此連線會用來變更密碼,因此使用者必須具有 userPassword 屬性的寫入存取權" +"。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:248 msgid "Default: exop" -msgstr "" +msgstr "預設:exop" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:254 msgid "ldap_default_bind_dn (string)" -msgstr "" +msgstr "ldap_default_bind_dn (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:257 msgid "The default bind DN to use for performing LDAP operations." -msgstr "" +msgstr "執行 LDAP 作業時使用的預設繫結 DN。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:264 msgid "ldap_default_authtok_type (string)" -msgstr "" +msgstr "ldap_default_authtok_type (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:267 msgid "The type of the authentication token of the default bind DN." -msgstr "" +msgstr "預設繫結 DN 的驗證權杖類型。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:271 msgid "The two mechanisms currently supported are:" -msgstr "" +msgstr "目前支援的兩種機制是:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:274 msgid "password" -msgstr "" +msgstr "password" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:277 msgid "obfuscated_password" -msgstr "" +msgstr "obfuscated_password" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:280 msgid "Default: password" -msgstr "" +msgstr "預設:password" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:283 @@ -5764,21 +6536,23 @@ msgid "" "See the <citerefentry> <refentrytitle>sss_obfuscate</refentrytitle> " "<manvolnum>8</manvolnum> </citerefentry> manual page for more information." msgstr "" +"更多資訊請參閱 <citerefentry> <refentrytitle>sss_obfuscate</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> 手冊頁。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:294 msgid "ldap_default_authtok (string)" -msgstr "" +msgstr "ldap_default_authtok (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:297 msgid "The authentication token of the default bind DN." -msgstr "" +msgstr "預設繫結 DN 的驗證權杖。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:303 msgid "ldap_force_upper_case_realm (boolean)" -msgstr "" +msgstr "ldap_force_upper_case_realm (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:306 @@ -5788,23 +6562,25 @@ msgid "" "fail. Set this option to a non-zero value if you want to use an upper-case " "realm." msgstr "" +"某些目錄伺服器(例如 Active Directory)可能以小寫傳送 UPN 的 realm 部分,這可" +"能導致驗證失敗。若您想使用大寫的 realm,請將此選項設為非零值。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:319 msgid "ldap_enumeration_refresh_timeout (integer)" -msgstr "" +msgstr "ldap_enumeration_refresh_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:322 msgid "" "Specifies how many seconds SSSD has to wait before refreshing its cache of " "enumerated records." -msgstr "" +msgstr "指定 SSSD 在重新整理列舉記錄快取之前必須等待的秒數。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:338 msgid "ldap_purge_cache_timeout (integer)" -msgstr "" +msgstr "ldap_purge_cache_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:341 @@ -5813,6 +6589,8 @@ msgid "" "with no members and users who have never logged in) and remove them to save " "space." msgstr "" +"決定多久檢查一次快取中的非使用中項目(例如沒有成員的群組與從未登入的使用者)" +",並移除它們以節省空間。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:347 @@ -5822,11 +6600,14 @@ msgid "" "to detect entries removed from the server and can't be disabled. By default, " "the cleanup task will run every 3 hours with enumeration enabled." msgstr "" +"將此選項設為零會停用快取清理作業。請注意,若啟用列舉,則需要清理工作才能偵測" +"已從伺服器移除的項目,且無法停用。預設情況下,啟用列舉時,清理工作每 3 小時執" +"行一次。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:367 msgid "ldap_group_nesting_level (integer)" -msgstr "" +msgstr "ldap_group_nesting_level (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:370 @@ -5835,6 +6616,8 @@ msgid "" "(e.g. RFC2307bis), then this option controls how many levels of nesting SSSD " "will follow. This option has no effect on the RFC2307 schema." msgstr "" +"若 ldap_schema 設為支援巢狀群組的綱要格式(例如 RFC2307bis),則此選項控制 " +"SSSD 會追蹤多少層巢狀。此選項對 RFC2307 綱要沒有影響。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:377 @@ -5845,6 +6628,9 @@ msgid "" "the deeper nesting levels. Also, subsequent lookups for other groups may " "enlarge the result set for original lookup if re-queried." msgstr "" +"注意:此選項指定任何查詢都會處理的保證巢狀群組層級。不過,若先前的查詢已經解" +"析較深的巢狀層級,超過此限制的巢狀群組<emphasis>可能</emphasis>會被傳回。此外" +",若重新查詢,對其他群組的後續查詢可能擴大原始查詢的結果集。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:386 @@ -5855,11 +6641,15 @@ msgid "" "usage of Token-Groups by setting ldap_use_tokengroups to false in order to " "restrict group nesting." msgstr "" +"若 ldap_group_nesting_level 設為 0,則完全不會處理巢狀群組。不過,使用 " +"<quote>id_provider=ad</quote> 連線到 Active Directory Server 2008 及更新版本" +"時,還需要將 ldap_use_tokengroups 設為 false 來停用 Token-Groups 的使用,以限" +"制群組巢狀。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:395 msgid "Default: 2" -msgstr "" +msgstr "預設:2" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:404 @@ -5867,21 +6657,23 @@ msgid "" "This options enables or disables use of Token-Groups attribute when " "performing initgroup for users from Active Directory Server 2008 and later." msgstr "" +"此選項啟用或停用在對 Active Directory Server 2008 及更新版本的使用者執行 " +"initgroup 時對 Token-Groups 屬性的使用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:414 msgid "Default: True for AD and IPA otherwise False." -msgstr "" +msgstr "預設:AD 與 IPA 為 True,其他情況為 False。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:420 msgid "ldap_host_search_base (string)" -msgstr "" +msgstr "ldap_host_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:423 msgid "Optional. Use the given string as search base for host objects." -msgstr "" +msgstr "選用。使用指定的字串作為主機物件的搜尋基礎。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:427 sssd-ipa.5.xml:462 sssd-ipa.5.xml:481 sssd-ipa.5.xml:500 @@ -5889,32 +6681,32 @@ msgstr "" msgid "" "See <quote>ldap_search_base</quote> for information about configuring " "multiple search bases." -msgstr "" +msgstr "有關設定多個搜尋基礎的資訊,請參閱 <quote>ldap_search_base</quote>。" #. type: Content of: <listitem><para> #: sssd-ldap.5.xml:432 sssd-ipa.5.xml:467 include/ldap_search_bases.xml:27 msgid "Default: the value of <emphasis>ldap_search_base</emphasis>" -msgstr "" +msgstr "預設:<emphasis>ldap_search_base</emphasis> 的值" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:439 msgid "ldap_service_search_base (string)" -msgstr "" +msgstr "ldap_service_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:444 msgid "ldap_iphost_search_base (string)" -msgstr "" +msgstr "ldap_iphost_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:449 msgid "ldap_ipnetwork_search_base (string)" -msgstr "" +msgstr "ldap_ipnetwork_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:454 msgid "ldap_search_timeout (integer)" -msgstr "" +msgstr "ldap_search_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:457 @@ -5922,7 +6714,7 @@ msgid "" "Specifies the timeout (in seconds) that ldap searches are allowed to run " "before they are cancelled and cached results are returned (and offline mode " "is entered)" -msgstr "" +msgstr "指定 LDAP 搜尋在取消並傳回快取結果(並進入離線模式)之前允許執行的逾時(秒)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:463 @@ -5931,11 +6723,13 @@ msgid "" "will likely be replaced at some point by a series of timeouts for specific " "lookup types." msgstr "" +"注意:此選項在 SSSD 未來的版本中可能會變更。未來某個時間點它可能會被一系列針" +"對特定查詢類型的逾時取代。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:480 msgid "ldap_enumeration_search_timeout (integer)" -msgstr "" +msgstr "ldap_enumeration_search_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:483 @@ -5944,11 +6738,13 @@ msgid "" "enumerations are allowed to run before they are cancelled and cached results " "are returned (and offline mode is entered)" msgstr "" +"指定使用者與群組列舉的 LDAP 搜尋在取消並傳回快取結果(並進入離線模式)之前允" +"許執行的逾時(秒)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:501 msgid "ldap_network_timeout (integer)" -msgstr "" +msgstr "ldap_network_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:504 @@ -5960,11 +6756,16 @@ msgid "" "<refentrytitle>connect</refentrytitle> <manvolnum>2</manvolnum> " "</citerefentry> returns in case of no activity." msgstr "" +"指定逾時(秒),超過此時間後,若沒有活動,<citerefentry> <refentrytitle>" +"connect</refentrytitle> <manvolnum>2</manvolnum> </citerefentry> 之後的 " +"<citerefentry> <refentrytitle>poll</refentrytitle> <manvolnum>2</manvolnum> " +"</citerefentry>/<citerefentry> <refentrytitle>select</refentrytitle> " +"<manvolnum>2</manvolnum> </citerefentry> 會傳回。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:532 msgid "ldap_opt_timeout (integer)" -msgstr "" +msgstr "ldap_opt_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:535 @@ -5974,11 +6775,14 @@ msgid "" "communicating with the KDC in case of SASL bind, the timeout of an LDAP bind " "operation, password change extended operation and the StartTLS operation." msgstr "" +"指定逾時(秒),超過此時間後,若沒有收到回應,對同步 LDAP API 的呼叫會中止。" +"也控制 SASL 繫結時與 KDC 通訊的逾時、LDAP 繫結作業的逾時、密碼變更延伸作業與 " +"StartTLS 作業的逾時。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:555 msgid "ldap_connection_expire_timeout (integer)" -msgstr "" +msgstr "ldap_connection_expire_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:558 @@ -5988,6 +6792,8 @@ msgid "" "in parallel with SASL/GSSAPI, the sooner of the two values (this value " "vs. the TGT lifetime) will be used." msgstr "" +"指定 LDAP 伺服器連線將維持的逾時(秒)。超過此時間後,會重新建立連線。若與 " +"SASL/GSSAPI 並行使用,會採用兩個值(此值與 TGT 存留時間)中較早的一個。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:566 @@ -5999,6 +6805,10 @@ msgid "" "be closed immediately and will never be reused if " "<emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" msgstr "" +"若連線在到期前的 <emphasis>ldap_opt_timeout</emphasis> 秒內處於閒置狀態(未在" +"執行作業),則會提早關閉,以確保新查詢無法要求連線在到期後仍保持開啟。這表示" +"若 <emphasis>ldap_connection_expire_timeout <= ldap_opt_timout</emphasis>" +",連線一律會立即關閉,且絕不會重複使用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:578 @@ -6006,16 +6816,18 @@ msgid "" "This timeout can be extended of a random value specified by " "<emphasis>ldap_connection_expire_offset</emphasis>" msgstr "" +"此逾時可以延長 <emphasis>ldap_connection_expire_offset</emphasis> 指定的隨機" +"值" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:588 sssd-ldap.5.xml:631 sssd-ldap.5.xml:1749 msgid "Default: 900 (15 minutes)" -msgstr "" +msgstr "預設:900(15 分鐘)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:594 msgid "ldap_connection_expire_offset (integer)" -msgstr "" +msgstr "ldap_connection_expire_offset (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:597 @@ -6023,11 +6835,13 @@ msgid "" "Random offset between 0 and configured value is added to " "<emphasis>ldap_connection_expire_timeout</emphasis>." msgstr "" +"會將介於 0 與設定值之間的隨機偏移加到 <emphasis>" +"ldap_connection_expire_timeout</emphasis>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:613 msgid "ldap_connection_idle_timeout (integer)" -msgstr "" +msgstr "ldap_connection_idle_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:616 @@ -6036,28 +6850,30 @@ msgid "" "will be maintained. If the connection is idle for more than this time then " "the connection will be closed." msgstr "" +"指定 LDAP 伺服器閒置連線將維持的逾時(秒)。若連線閒置超過此時間,則連線會關" +"閉。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:622 msgid "You can disable this timeout by setting the value to 0." -msgstr "" +msgstr "您可以將值設為 0 來停用此逾時。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:637 msgid "ldap_page_size (integer)" -msgstr "" +msgstr "ldap_page_size (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:640 msgid "" "Specify the number of records to retrieve from LDAP in a single " "request. Some LDAP servers enforce a maximum limit per-request." -msgstr "" +msgstr "指定單一要求中從 LDAP 取回的記錄數目。某些 LDAP 伺服器會強制每個要求的上限。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:651 msgid "ldap_disable_paging (boolean)" -msgstr "" +msgstr "ldap_disable_paging (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:654 @@ -6066,6 +6882,8 @@ msgid "" "server reports that it supports the LDAP paging control in its RootDSE but " "it is not enabled or does not behave properly." msgstr "" +"停用 LDAP 分頁控制。若 LDAP 伺服器在其 RootDSE 中回報支援 LDAP 分頁控制,但未" +"啟用或行為不正常,應使用此選項。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:660 @@ -6074,6 +6892,8 @@ msgid "" "server but not enabled will report it in the RootDSE but be unable to use " "it." msgstr "" +"範例:伺服器上安裝了分頁控制模組但未啟用的 OpenLDAP 伺服器,會在 RootDSE 中回" +"報該模組,但無法使用它。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:666 @@ -6082,16 +6902,18 @@ msgid "" "a time on a single connection. On busy clients, this can result in some " "requests being denied." msgstr "" +"範例:389 DS 有一個錯誤,在單一連線上一次只能支援一個分頁控制。在忙碌的用戶端" +"上,這可能導致部分要求被拒絕。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:678 msgid "ldap_disable_range_retrieval (boolean)" -msgstr "" +msgstr "ldap_disable_range_retrieval (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:681 msgid "Disable Active Directory range retrieval." -msgstr "" +msgstr "停用 Active Directory 範圍取回。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:684 @@ -6102,11 +6924,14 @@ msgid "" "extension. This option disables parsing of the range extension, therefore " "large groups will appear as having no members." msgstr "" +"Active Directory 使用 MaxValRange 原則(預設為 1500 個成員)限制單一查詢中取" +"回的成員數目。若群組包含更多成員,回覆會包含 AD 特定的範圍延伸。此選項停用範" +"圍延伸的剖析,因此大型群組看起來會像是沒有成員。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:699 msgid "ldap_sasl_minssf (integer)" -msgstr "" +msgstr "ldap_sasl_minssf (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:702 @@ -6115,16 +6940,18 @@ msgid "" "security level necessary to establish the connection. The values of this " "option are defined by OpenLDAP." msgstr "" +"使用 SASL 與 LDAP 伺服器通訊時,指定建立連線所需的最低安全性層級。此選項的值" +"由 OpenLDAP 定義。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:708 sssd-ldap.5.xml:724 msgid "Default: Use the system default (usually specified by ldap.conf)" -msgstr "" +msgstr "預設:使用系統預設值(通常由 ldap.conf 指定)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:715 msgid "ldap_sasl_maxssf (integer)" -msgstr "" +msgstr "ldap_sasl_maxssf (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:718 @@ -6133,11 +6960,13 @@ msgid "" "security level necessary to establish the connection. The values of this " "option are defined by OpenLDAP." msgstr "" +"使用 SASL 與 LDAP 伺服器通訊時,指定建立連線所需的最大安全性層級。此選項的值" +"由 OpenLDAP 定義。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:731 msgid "ldap_deref_threshold (integer)" -msgstr "" +msgstr "ldap_deref_threshold (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:734 @@ -6146,6 +6975,8 @@ msgid "" "cache in order to trigger a dereference lookup. If less members are missing, " "they are looked up individually." msgstr "" +"指定要觸發解除參照查詢時,內部快取中必須缺少的群組成員數目。若缺少的成員較少" +",則會個別查詢它們。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:740 @@ -6157,6 +6988,9 @@ msgid "" "the server supports it and advertises the dereference control in the rootDSE " "object." msgstr "" +"您可以將值設為 0 來完全關閉解除參照查詢。請注意,SSSD 中有些程式碼路徑(例如 " +"IPA HBAC 提供者)只使用解除參照呼叫來實作,因此即使明確停用解除參照,若伺服器" +"支援且在 rootDSE 物件中公告解除參照控制,這些部分仍會使用解除參照。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:751 @@ -6166,6 +7000,9 @@ msgid "" "methods. The currently supported servers are 389/RHDS, OpenLDAP and Active " "Directory." msgstr "" +"解除參照查詢是在單一 LDAP 呼叫中取回所有群組成員的方法。不同的 LDAP 伺服器可" +"能實作不同的解除參照方法。目前支援的伺服器是 389/RHDS、OpenLDAP 與 Active " +"Directory。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:759 @@ -6174,11 +7011,13 @@ msgid "" "filter, then the dereference lookup performance enhancement will be disabled " "regardless of this setting." msgstr "" +"<emphasis>注意:</emphasis>若任何搜尋基礎指定了搜尋篩選器,則無論此設定為何," +"解除參照查詢效能增強都會被停用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:772 msgid "ldap_ignore_unreadable_references (bool)" -msgstr "" +msgstr "ldap_ignore_unreadable_references (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:775 @@ -6187,6 +7026,8 @@ msgid "" "this parameter is set to false an error will be returned and the operation " "will fail instead of just ignoring the unreadable entry." msgstr "" +"忽略群組 member 屬性中參照的無法讀取 LDAP 項目。若此參數設為 false,會傳回錯" +"誤且作業會失敗,而不是只忽略無法讀取的項目。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:782 @@ -6195,25 +7036,27 @@ msgid "" "account that sssd uses to connect to AD does not have access to a particular " "entry or LDAP sub-tree for security reasons." msgstr "" +"當使用 AD 提供者,且 sssd 用來連線到 AD 的電腦帳戶基於安全性考量沒有特定項目" +"或 LDAP 子樹的存取權時,此參數可能很有用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:795 msgid "ldap_tls_reqcert (string)" -msgstr "" +msgstr "ldap_tls_reqcert (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:798 msgid "" "Specifies what checks to perform on server certificates in a TLS session, if " "any. It can be specified as one of the following values:" -msgstr "" +msgstr "指定在 TLS 工作階段中對伺服器憑證執行哪些檢查(若有)。可以指定為下列值之一:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:804 msgid "" "<emphasis>never</emphasis> = The client will not request or check any server " "certificate." -msgstr "" +msgstr "<emphasis>never</emphasis> = 用戶端不會要求或檢查任何伺服器憑證。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:808 @@ -6222,6 +7065,8 @@ msgid "" "certificate is provided, the session proceeds normally. If a bad certificate " "is provided, it will be ignored and the session proceeds normally." msgstr "" +"<emphasis>allow</emphasis> = 會要求伺服器憑證。若未提供憑證,工作階段會正常繼" +"續。若提供的憑證不良,它會被忽略,工作階段會正常繼續。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:815 @@ -6230,6 +7075,8 @@ msgid "" "certificate is provided, the session proceeds normally. If a bad certificate " "is provided, the session is immediately terminated." msgstr "" +"<emphasis>try</emphasis> = 會要求伺服器憑證。若未提供憑證,工作階段會正常繼續" +"。若提供的憑證不良,工作階段會立即終止。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:821 @@ -6238,28 +7085,30 @@ msgid "" "certificate is provided, or a bad certificate is provided, the session is " "immediately terminated." msgstr "" +"<emphasis>demand</emphasis> = 會要求伺服器憑證。若未提供憑證,或提供的憑證不" +"良,工作階段會立即終止。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:827 msgid "<emphasis>hard</emphasis> = Same as <quote>demand</quote>" -msgstr "" +msgstr "<emphasis>hard</emphasis> = 與 <quote>demand</quote> 相同" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:831 msgid "Default: hard" -msgstr "" +msgstr "預設:hard" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:837 msgid "ldap_tls_cacert (string)" -msgstr "" +msgstr "ldap_tls_cacert (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:840 msgid "" "Specifies the file that contains certificates for all of the Certificate " "Authorities that <command>sssd</command> will recognize." -msgstr "" +msgstr "指定包含 <command>sssd</command> 會識別之所有憑證授權單位憑證的檔案。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:845 sssd-ldap.5.xml:864 sssd-ldap.5.xml:905 @@ -6267,11 +7116,13 @@ msgid "" "Default: use OpenLDAP defaults, typically in " "<filename>/etc/openldap/ldap.conf</filename>" msgstr "" +"預設:使用 OpenLDAP 預設值,通常在 <filename>/etc/openldap/ldap.conf</" +"filename>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:852 msgid "ldap_tls_cacertdir (string)" -msgstr "" +msgstr "ldap_tls_cacertdir (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:855 @@ -6282,31 +7133,34 @@ msgid "" "<command>openssl rehash</command> or <command>c_rehash</command> can be used " "to create the correct names." msgstr "" +"指定包含個別憑證授權單位憑證檔案的目錄路徑。通常檔案名稱必須是憑證的雜湊值後" +"接 '.0'。若可用,可以使用 <command>openssl rehash</command> 或 <command>" +"c_rehash</command> 建立正確的名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:871 msgid "ldap_tls_cert (string)" -msgstr "" +msgstr "ldap_tls_cert (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:874 msgid "Specifies the file that contains the certificate for the client's key." -msgstr "" +msgstr "指定包含用戶端金鑰憑證的檔案。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:884 msgid "ldap_tls_key (string)" -msgstr "" +msgstr "ldap_tls_key (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:887 msgid "Specifies the file that contains the client's key." -msgstr "" +msgstr "指定包含用戶端金鑰的檔案。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:896 msgid "ldap_tls_cipher_suite (string)" -msgstr "" +msgstr "ldap_tls_cipher_suite (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:899 @@ -6315,11 +7169,14 @@ msgid "" "list. See <citerefentry><refentrytitle>ldap.conf</refentrytitle> " "<manvolnum>5</manvolnum></citerefentry> for format." msgstr "" +"指定可接受的加密套件。通常是以冒號分隔的清單。格式請參閱 <citerefentry>" +"<refentrytitle>ldap.conf</refentrytitle> <manvolnum>5</manvolnum></" +"citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:912 msgid "ldap_id_use_start_tls (boolean)" -msgstr "" +msgstr "ldap_id_use_start_tls (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:915 @@ -6328,11 +7185,14 @@ msgid "" "class=\"protocol\">tls</systemitem> to protect the channel. " "<emphasis>true</emphasis> is strongly recommended for security reasons." msgstr "" +"指定 id_provider 連線也必須使用 <systemitem class=\"protocol\">tls</" +"systemitem> 來保護通道。基於安全性考量,強烈建議使用 <emphasis>true</" +"emphasis>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:926 msgid "ldap_id_mapping (boolean)" -msgstr "" +msgstr "ldap_id_mapping (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:929 @@ -6341,16 +7201,18 @@ msgid "" "ldap_user_objectsid and ldap_group_objectsid attributes instead of relying " "on ldap_user_uid_number and ldap_group_gid_number." msgstr "" +"指定 SSSD 應嘗試從 ldap_user_objectsid 與 ldap_group_objectsid 屬性對應使用者" +"與群組 ID,而不是依賴 ldap_user_uid_number 與 ldap_group_gid_number。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:935 msgid "Currently this feature supports only ActiveDirectory objectSID mapping." -msgstr "" +msgstr "目前此功能只支援 ActiveDirectory objectSID 對應。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:945 msgid "ldap_min_id, ldap_max_id (integer)" -msgstr "" +msgstr "ldap_min_id, ldap_max_id (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:948 @@ -6362,23 +7224,28 @@ msgid "" "can be set to restrict the allowed range for the IDs which are read directly " "from the server. Sub-domains can then pick other ranges to map IDs." msgstr "" +"與 ldap_id_mapping 設為 true 時使用的 SID 型 ID 對應相反," +"ldap_user_uid_number 與 ldap_group_gid_number 允許的 ID 範圍是無限制的。在具" +"有子網域/受信任網域的設定中,這可能導致 ID 衝突。為避免衝突,可以設定 " +"ldap_min_id 與 ldap_max_id 來限制直接從伺服器讀取之 ID 的允許範圍。子網域隨後" +"可以選擇其他範圍來對應 ID。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:960 msgid "Default: not set (both options are set to 0)" -msgstr "" +msgstr "預設:未設定(兩個選項都設為 0)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:966 msgid "ldap_sasl_mech (string)" -msgstr "" +msgstr "ldap_sasl_mech (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:969 msgid "" "Specify the SASL mechanism to use. Currently only GSSAPI and GSS-SPNEGO are " "tested and supported." -msgstr "" +msgstr "指定要使用的 SASL 機制。目前只測試並支援 GSSAPI 與 GSS-SPNEGO。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:973 @@ -6390,11 +7257,15 @@ msgid "" "<citerefentry><refentrytitle>sssd.conf</refentrytitle> " "<manvolnum>5</manvolnum></citerefentry> for details." msgstr "" +"若後端支援子網域,ldap_sasl_mech 的值會自動繼承到子網域。若子網域需要不同的值" +",可以明確為此子網域設定 ldap_sasl_mech 來覆寫。詳情請參閱 <citerefentry>" +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum></" +"citerefentry> 中的受信任網域區段。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:989 msgid "ldap_sasl_authid (string)" -msgstr "" +msgstr "ldap_sasl_authid (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd-ldap.5.xml:1001 @@ -6408,6 +7279,13 @@ msgid "" "host/*\n" " " msgstr "" +"hostname@REALM\n" +"netbiosname$@REALM\n" +"host/hostname@REALM\n" +"*$@REALM\n" +"host/*@REALM\n" +"host/*\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:992 @@ -6420,16 +7298,21 @@ msgid "" "are used: <placeholder type=\"programlisting\" id=\"0\"/> If none of them " "are found, the first principal in keytab is returned." msgstr "" +"指定要使用的 SASL 授權 ID。使用 GSSAPI/GSS-SPNEGO 時,這代表用於向目錄驗證的 " +"Kerberos principal。此選項可以包含完整的 principal(例如 host/" +"myhost@EXAMPLE.COM)或只包含 principal 名稱(例如 host/myhost)。預設情況下," +"值未設定,會使用下列 principal:<placeholder type=\"programlisting\" " +"id=\"0\"/> 若找不到任何一個,則會傳回 keytab 中的第一個 principal。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1012 msgid "Default: host/hostname@REALM" -msgstr "" +msgstr "預設:host/hostname@REALM" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1018 msgid "ldap_sasl_realm (string)" -msgstr "" +msgstr "ldap_sasl_realm (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1021 @@ -6438,48 +7321,50 @@ msgid "" "the value of krb5_realm. If the ldap_sasl_authid contains the realm as " "well, this option is ignored." msgstr "" +"指定要使用的 SASL realm。若未指定,此選項預設為 krb5_realm 的值。若 " +"ldap_sasl_authid 也包含 realm,則會忽略此選項。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1027 msgid "Default: the value of krb5_realm." -msgstr "" +msgstr "預設:krb5_realm 的值。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1033 msgid "ldap_sasl_canonicalize (boolean)" -msgstr "" +msgstr "ldap_sasl_canonicalize (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1036 msgid "" "If set to true, the LDAP library would perform a reverse lookup to " "canonicalize the host name during a SASL bind." -msgstr "" +msgstr "若設為 true,LDAP 程式庫會在 SASL 繫結期間執行反向查詢來正規化主機名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1041 msgid "Default: false;" -msgstr "" +msgstr "預設:false;" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1047 msgid "ldap_krb5_keytab (string)" -msgstr "" +msgstr "ldap_krb5_keytab (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1050 msgid "Specify the keytab to use when using SASL/GSSAPI/GSS-SPNEGO." -msgstr "" +msgstr "指定使用 SASL/GSSAPI/GSS-SPNEGO 時要使用的 keytab。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1059 sssd-krb5.5.xml:247 msgid "Default: System keytab, normally <filename>/etc/krb5.keytab</filename>" -msgstr "" +msgstr "預設:系統 keytab,通常是 <filename>/etc/krb5.keytab</filename>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1065 msgid "ldap_krb5_init_creds (boolean)" -msgstr "" +msgstr "ldap_krb5_init_creds (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1068 @@ -6488,28 +7373,30 @@ msgid "" "action is performed only if SASL is used and the mechanism selected is " "GSSAPI or GSS-SPNEGO." msgstr "" +"指定 id_provider 應初始化 Kerberos 憑證 (TGT)。只有在使用 SASL 且選取的機制" +"是 GSSAPI 或 GSS-SPNEGO 時,才會執行此動作。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1080 msgid "ldap_krb5_ticket_lifetime (integer)" -msgstr "" +msgstr "ldap_krb5_ticket_lifetime (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1083 msgid "" "Specifies the lifetime in seconds of the TGT if GSSAPI or GSS-SPNEGO is " "used." -msgstr "" +msgstr "若使用 GSSAPI 或 GSS-SPNEGO,指定 TGT 的存留時間(秒)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1092 sssd-ad.5.xml:1253 msgid "Default: 86400 (24 hours)" -msgstr "" +msgstr "預設:86400(24 小時)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1098 sssd-krb5.5.xml:74 msgid "krb5_server, krb5_backup_server (string)" -msgstr "" +msgstr "krb5_server, krb5_backup_server (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1101 @@ -6522,6 +7409,10 @@ msgid "" "discovery is enabled - for more information, refer to the <quote>SERVICE " "DISCOVERY</quote> section." msgstr "" +"指定 SSSD 應依偏好順序連線之 Kerberos 伺服器的 IP 位址或主機名稱逗號分隔清單" +"。有關故障轉移與伺服器備援的更多資訊,請參閱 <quote>FAILOVER</quote> 一節。可" +"以在位址或主機名稱後面附加選用的連接埠號碼(前面加上冒號)。若為空白,則啟用" +"服務探索——更多資訊請參閱 <quote>SERVICE DISCOVERY</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1113 sssd-krb5.5.xml:89 @@ -6530,6 +7421,8 @@ msgid "" "for DNS entries that specify _udp as the protocol and falls back to _tcp if " "none are found." msgstr "" +"對 KDC 或 kpasswd 伺服器使用服務探索時,SSSD 會先搜尋指定 _udp 為協定的 DNS " +"項目,若找不到,則退回 _tcp。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1118 sssd-krb5.5.xml:94 @@ -6539,26 +7432,28 @@ msgid "" "advised to migrate their config files to use <quote>krb5_server</quote> " "instead." msgstr "" +"此選項在 SSSD 的早期版本中名為 <quote>krb5_kdcip</quote>。雖然暫時仍會識別舊" +"名稱,但建議使用者將設定檔遷移為改用 <quote>krb5_server</quote>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1127 sssd-ipa.5.xml:531 sssd-krb5.5.xml:103 msgid "krb5_realm (string)" -msgstr "" +msgstr "krb5_realm (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1130 msgid "Specify the Kerberos REALM (for SASL/GSSAPI/GSS-SPNEGO auth)." -msgstr "" +msgstr "指定 Kerberos REALM(用於 SASL/GSSAPI/GSS-SPNEGO 驗證)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1134 msgid "Default: System defaults, see <filename>/etc/krb5.conf</filename>" -msgstr "" +msgstr "預設:系統預設值,請參閱 <filename>/etc/krb5.conf</filename>" #. type: Content of: <variablelist><varlistentry><term> #: sssd-ldap.5.xml:1140 include/krb5_options.xml:154 msgid "krb5_canonicalize (boolean)" -msgstr "" +msgstr "krb5_canonicalize (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1143 @@ -6566,11 +7461,13 @@ msgid "" "Specifies if the host principal should be canonicalized when connecting to " "LDAP server. This feature is available with MIT Kerberos >= 1.7" msgstr "" +"指定連線到 LDAP 伺服器時是否應正規化主機 principal。MIT Kerberos >= 1.7 提供" +"此功能" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1155 sssd-krb5.5.xml:336 msgid "krb5_use_kdcinfo (boolean)" -msgstr "" +msgstr "krb5_use_kdcinfo (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1158 sssd-krb5.5.xml:339 @@ -6581,6 +7478,10 @@ msgid "" "<refentrytitle>krb5.conf</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> configuration file." msgstr "" +"指定 SSSD 是否應告知 Kerberos 程式庫要使用哪個 realm 與哪些 KDC。此選項預設為" +"開啟,若您停用它,需要使用 <citerefentry> <refentrytitle>krb5.conf</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 設定檔來設定 " +"Kerberos 程式庫。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1169 sssd-krb5.5.xml:350 @@ -6590,25 +7491,28 @@ msgid "" "<manvolnum>8</manvolnum> </citerefentry> manual page for more information on " "the locator plugin." msgstr "" +"有關 locator 外掛程式的更多資訊,請參閱 <citerefentry> <refentrytitle>" +"sssd_krb5_locator_plugin</refentrytitle> <manvolnum>8</manvolnum> </" +"citerefentry> 手冊頁。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1183 msgid "ldap_pwd_policy (string)" -msgstr "" +msgstr "ldap_pwd_policy (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1186 msgid "" "Select the policy to evaluate the password expiration on the client " "side. The following values are allowed:" -msgstr "" +msgstr "選取要在用戶端評估密碼到期日的原則。允許下列值:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1191 msgid "" "<emphasis>none</emphasis> - No evaluation on the client side. This option " "cannot disable server-side password policies." -msgstr "" +msgstr "<emphasis>none</emphasis> - 不在用戶端評估。此選項無法停用伺服器端密碼原則。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1196 @@ -6619,6 +7523,9 @@ msgid "" "password has expired. Please see option \"ldap_chpass_update_last_change\" " "as well." msgstr "" +"<emphasis>shadow</emphasis> - 使用 <citerefentry><refentrytitle>shadow</" +"refentrytitle> <manvolnum>5</manvolnum></citerefentry> 樣式屬性評估密碼是否已" +"到期。也請參閱 \"ldap_chpass_update_last_change\" 選項。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1204 @@ -6627,6 +7534,8 @@ msgid "" "to determine if the password has expired. Use chpass_provider=krb5 to update " "these attributes when the password is changed." msgstr "" +"<emphasis>mit_kerberos</emphasis> - 使用 MIT Kerberos 使用的屬性判斷密碼是否" +"已到期。密碼變更時,使用 chpass_provider=krb5 更新這些屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1213 @@ -6634,23 +7543,25 @@ msgid "" "<emphasis>Note</emphasis>: if a password policy is configured on server " "side, it always takes precedence over policy set with this option." msgstr "" +"<emphasis>注意</emphasis>:若在伺服器端設定了密碼原則,它一律優先於使用此選項" +"設定的原則。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1221 msgid "ldap_referrals (boolean)" -msgstr "" +msgstr "ldap_referrals (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1224 msgid "Specifies whether automatic referral chasing should be enabled." -msgstr "" +msgstr "指定是否應啟用自動追蹤轉介。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1228 msgid "" "Please note that sssd only supports referral chasing when it is compiled " "with OpenLDAP version 2.4.13 or higher." -msgstr "" +msgstr "請注意,只有使用 OpenLDAP 2.4.13 或更高版本編譯時,sssd 才支援追蹤轉介。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1233 @@ -6664,43 +7575,48 @@ msgid "" "able to follow the referral to a different AD DC no additional data would be " "available." msgstr "" +"在大量使用轉介的環境中,追蹤轉介可能造成效能損失,一個明顯的例子是 Microsoft " +"Active Directory。若您的設定實際上不需要使用轉介,將此選項設為 false 可能帶來" +"明顯的效能改善。因此,若 SSSD LDAP 提供者與 Microsoft Active Directory 一起作" +"為後端使用,建議將此選項設為 false。即使 SSSD 可以沿著轉介追蹤到不同的 AD DC" +",也不會有額外的資料可用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1252 msgid "ldap_dns_service_name (string)" -msgstr "" +msgstr "ldap_dns_service_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1255 msgid "Specifies the service name to use when service discovery is enabled." -msgstr "" +msgstr "指定啟用服務探索時要使用的服務名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1259 msgid "Default: ldap" -msgstr "" +msgstr "預設:ldap" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1265 msgid "ldap_chpass_dns_service_name (string)" -msgstr "" +msgstr "ldap_chpass_dns_service_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1268 msgid "" "Specifies the service name to use to find an LDAP server which allows " "password changes when service discovery is enabled." -msgstr "" +msgstr "指定啟用服務探索時,用來尋找允許變更密碼之 LDAP 伺服器的服務名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1273 msgid "Default: not set, i.e. service discovery is disabled" -msgstr "" +msgstr "預設:未設定,也就是停用服務探索" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1279 msgid "ldap_chpass_update_last_change (bool)" -msgstr "" +msgstr "ldap_chpass_update_last_change (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1282 @@ -6708,6 +7624,8 @@ msgid "" "Specifies whether to update the ldap_user_shadow_last_change attribute with " "days since the Epoch after a password change operation." msgstr "" +"指定在密碼變更作業之後,是否以自 Epoch 以來的天數更新 " +"ldap_user_shadow_last_change 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1288 @@ -6717,11 +7635,13 @@ msgid "" "shadowLastChange LDAP attribute automatically after a password change or if " "SSSD has to update it." msgstr "" +"若使用 \"ldap_pwd_policy = shadow\",建議明確設定此選項,讓 SSSD 知道 LDAP 伺" +"服器會在密碼變更後自動更新 shadowLastChange LDAP 屬性,還是必須由 SSSD 更新。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1302 msgid "ldap_access_filter (string)" -msgstr "" +msgstr "ldap_access_filter (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1305 @@ -6739,11 +7659,19 @@ msgid "" "<refentrytitle>sssd-simple</refentrytitle><manvolnum>5</manvolnum> " "</citerefentry>." msgstr "" +"若使用 access_provider = ldap 與 ldap_access_order = filter(預設),此選項是" +"必要的。它指定使用者必須符合才會被授予此主機存取權的 LDAP 搜尋篩選器準則。若 " +"access_provider = ldap、ldap_access_order = filter 且未設定此選項,會導致所有" +"使用者都被拒絕存取。使用 access_provider = permit 可以變更此預設行為。請注意" +",此篩選器只套用於 LDAP 使用者項目,因此以巢狀群組為基礎的篩選可能無法運作(" +"例如 AD 項目上的 memberOf 屬性只指向直接父群組)。若需要以巢狀群組為基礎的篩" +"選,請參閱 <citerefentry> <refentrytitle>sssd-simple</refentrytitle>" +"<manvolnum>5</manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1325 msgid "Example:" -msgstr "" +msgstr "範例:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><programlisting> #: sssd-ldap.5.xml:1328 @@ -6753,13 +7681,16 @@ msgid "" "ldap_access_filter = (employeeType=admin)\n" " " msgstr "" +"access_provider = ldap\n" +"ldap_access_filter = (employeeType=admin)\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1332 msgid "" "This example means that access to this host is restricted to users whose " "employeeType attribute is set to \"admin\"." -msgstr "" +msgstr "此範例表示此主機的存取權限限於 employeeType 屬性設為 \"admin\" 的使用者。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1337 @@ -6769,23 +7700,25 @@ msgid "" "access during their last login, they will continue to be granted access " "while offline and vice versa." msgstr "" +"此功能的離線快取只限於判斷使用者最後一次線上登入是否被授予存取權限。若他們在" +"最後一次登入時被授予存取權,則在離線時會繼續被授予存取權,反之亦然。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1345 sssd-ldap.5.xml:1401 msgid "Default: Empty" -msgstr "" +msgstr "預設:空白" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1351 msgid "ldap_account_expire_policy (string)" -msgstr "" +msgstr "ldap_account_expire_policy (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1354 msgid "" "With this option a client side evaluation of access control attributes can " "be enabled." -msgstr "" +msgstr "使用此選項可以啟用存取控制屬性的用戶端評估。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1358 @@ -6794,11 +7727,13 @@ msgid "" "i.e. the LDAP server should deny the bind request with a suitable error code " "even if the password is correct." msgstr "" +"請注意,一律建議使用伺服器端存取控制,也就是即使密碼正確,LDAP 伺服器也應以適" +"當的錯誤碼拒絕繫結要求。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1365 msgid "The following values are allowed:" -msgstr "" +msgstr "允許下列值:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1368 @@ -6806,6 +7741,8 @@ msgid "" "<emphasis>shadow</emphasis>: use the value of ldap_user_shadow_expire to " "determine if the account is expired." msgstr "" +"<emphasis>shadow</emphasis>:使用 ldap_user_shadow_expire 的值判斷帳戶是否已" +"到期。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1373 @@ -6815,6 +7752,9 @@ msgid "" "set. If the attribute is missing access is granted. Also the expiration time " "of the account is checked." msgstr "" +"<emphasis>ad</emphasis>:使用 32 位元欄位 ldap_user_ad_user_account_control " +"的值,若第二個位元未設定,則允許存取。若屬性不存在,則授予存取權。也會檢查帳" +"戶的到期時間。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1380 @@ -6823,6 +7763,8 @@ msgid "" "<emphasis>389ds</emphasis>: use the value of ldap_ns_account_lock to check " "if access is allowed or not." msgstr "" +"<emphasis>rhds</emphasis>、<emphasis>ipa</emphasis>、<emphasis>389ds</" +"emphasis>:使用 ldap_ns_account_lock 的值檢查是否允許存取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1386 @@ -6832,6 +7774,9 @@ msgid "" "ldap_user_nds_login_expiration_time are used to check if access is " "allowed. If both attributes are missing access is granted." msgstr "" +"<emphasis>nds</emphasis>:使用 ldap_user_nds_login_allowed_time_map、" +"ldap_user_nds_login_disabled 與 ldap_user_nds_login_expiration_time 的值檢查" +"是否允許存取。若兩個屬性都不存在,則授予存取權。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1394 @@ -6840,21 +7785,23 @@ msgid "" "<emphasis>must</emphasis> include <quote>expire</quote> in order for the " "ldap_account_expire_policy option to work." msgstr "" +"請注意,ldap_access_order 設定選項<emphasis>必須</emphasis>包含 <quote>" +"expire</quote>,ldap_account_expire_policy 選項才能運作。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1407 msgid "ldap_access_order (string)" -msgstr "" +msgstr "ldap_access_order (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1410 sssd-ipa.5.xml:356 msgid "Comma separated list of access control options. Allowed values are:" -msgstr "" +msgstr "存取控制選項的逗號分隔清單。允許的值有:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1414 msgid "<emphasis>filter</emphasis>: use ldap_access_filter" -msgstr "" +msgstr "<emphasis>filter</emphasis>:使用 ldap_access_filter" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1417 @@ -6865,6 +7812,10 @@ msgid "" "Please note that 'access_provider = ldap' must be set for this feature to " "work." msgstr "" +"<emphasis>lockout</emphasis>:使用帳戶鎖定。若設定,此選項會在 LDAP 屬性 " +"'pwdAccountLockedTime' 存在且值為 '000001010000Z' 時拒絕存取。請參閱 " +"ldap_pwdlockout_dn 選項。請注意,此功能要運作必須設定 'access_provider = " +"ldap'。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1427 @@ -6873,6 +7824,8 @@ msgid "" "<quote>ppolicy</quote> option and might be removed in a future release. " "</emphasis>" msgstr "" +"<emphasis> 請注意,此選項已被 <quote>ppolicy</quote> 選項取代,未來版本可能會" +"移除。 </emphasis>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1434 @@ -6886,11 +7839,17 @@ msgid "" "the option ldap_pwdlockout_dn. Please note that 'access_provider = ldap' " "must be set for this feature to work." msgstr "" +"<emphasis>ppolicy</emphasis>:使用帳戶鎖定。若設定,此選項會在 LDAP 屬性 " +"'pwdAccountLockedTime' 存在且值為 '000001010000Z' 或代表過去任何時間時拒絕存" +"取。'pwdAccountLockedTime' 屬性的值必須以 'Z' 結尾,這表示 UTC 時區。目前不支" +"援其他時區,使用者嘗試登入時會導致 \"access-denied\"。請參閱 " +"ldap_pwdlockout_dn 選項。請注意,此功能要運作必須設定 'access_provider = " +"ldap'。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1451 msgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy" -msgstr "" +msgstr "<emphasis>expire</emphasis>:使用 ldap_account_expire_policy" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1455 sssd-ipa.5.xml:364 @@ -6901,30 +7860,33 @@ msgid "" "authentication is based on using a different method than passwords - for " "example SSH keys." msgstr "" +"<emphasis>pwd_expire_policy_reject、pwd_expire_policy_warn、" +"pwd_expire_policy_renew:</emphasis>若使用者希望收到密碼即將到期的警告,且驗" +"證是基於密碼以外的方法(例如 SSH 金鑰),這些選項很有用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1465 sssd-ipa.5.xml:374 msgid "" "The difference between these options is the action taken if user password is " "expired:" -msgstr "" +msgstr "這些選項之間的差異在於使用者密碼到期時採取的動作:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ldap.5.xml:1470 sssd-ipa.5.xml:379 msgid "pwd_expire_policy_reject - user is denied to log in," -msgstr "" +msgstr "pwd_expire_policy_reject - 拒絕使用者登入," #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ldap.5.xml:1476 sssd-ipa.5.xml:385 msgid "pwd_expire_policy_warn - user is still able to log in," -msgstr "" +msgstr "pwd_expire_policy_warn - 使用者仍可以登入," #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ldap.5.xml:1482 sssd-ipa.5.xml:391 msgid "" "pwd_expire_policy_renew - user is prompted to change their password " "immediately." -msgstr "" +msgstr "pwd_expire_policy_renew - 提示使用者立即變更密碼。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1490 @@ -6933,6 +7895,8 @@ msgid "" "work. Also 'ldap_pwd_policy' must be set to shadow or mit_kerberos, these " "options do not work with server-side password policies." msgstr "" +"請注意,此功能要運作必須設定 'access_provider = ldap'。'ldap_pwd_policy' 也必" +"須設為 shadow 或 mit_kerberos,這些選項不適用於伺服器端密碼原則。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1496 @@ -6940,18 +7904,20 @@ msgid "" "<emphasis>authorized_service</emphasis>: use the authorizedService attribute " "to determine access" msgstr "" +"<emphasis>authorized_service</emphasis>:使用 authorizedService 屬性判斷存取" +"權" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1501 msgid "<emphasis>host</emphasis>: use the host attribute to determine access" -msgstr "" +msgstr "<emphasis>host</emphasis>:使用 host 屬性判斷存取權" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1505 msgid "" "<emphasis>rhost</emphasis>: use the rhost attribute to determine whether " "remote host can access" -msgstr "" +msgstr "<emphasis>rhost</emphasis>:使用 rhost 屬性判斷遠端主機是否可以存取" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1509 @@ -6960,23 +7926,25 @@ msgid "" "what the application sends to pam, before enabling this access control " "option" msgstr "" +"請注意,pam 中的 rhost 欄位由應用程式設定,在啟用此存取控制選項之前,最好先檢" +"查應用程式傳送給 pam 的內容" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1514 msgid "Default: filter" -msgstr "" +msgstr "預設:filter" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1517 msgid "" "Please note that it is a configuration error if a value is used more than " "once." -msgstr "" +msgstr "請注意,若一個值使用超過一次,就是設定錯誤。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1524 msgid "ldap_pwdlockout_dn (string)" -msgstr "" +msgstr "ldap_pwdlockout_dn (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1527 @@ -6986,33 +7954,36 @@ msgid "" "lockout checking will yield access denied as ppolicy attributes on LDAP " "server cannot be checked properly." msgstr "" +"此選項指定 LDAP 伺服器上密碼原則項目的 DN。請注意,若啟用帳戶鎖定檢查,而 " +"sssd.conf 中沒有此選項,會導致拒絕存取,因為無法正確檢查 LDAP 伺服器上的 " +"ppolicy 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1535 msgid "Example: cn=ppolicy,ou=policies,dc=example,dc=com" -msgstr "" +msgstr "範例:cn=ppolicy,ou=policies,dc=example,dc=com" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1538 msgid "Default: cn=ppolicy,ou=policies,$ldap_search_base" -msgstr "" +msgstr "預設:cn=ppolicy,ou=policies,$ldap_search_base" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1544 msgid "ldap_deref (string)" -msgstr "" +msgstr "ldap_deref (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1547 msgid "" "Specifies how alias dereferencing is done when performing a search. The " "following options are allowed:" -msgstr "" +msgstr "指定執行搜尋時如何解除別名參照。允許下列選項:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1552 msgid "<emphasis>never</emphasis>: Aliases are never dereferenced." -msgstr "" +msgstr "<emphasis>never</emphasis>:永遠不解除別名參照。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1556 @@ -7020,39 +7991,41 @@ msgid "" "<emphasis>searching</emphasis>: Aliases are dereferenced in subordinates of " "the base object, but not in locating the base object of the search." msgstr "" +"<emphasis>searching</emphasis>:會解除基礎物件下屬中的別名參照,但在定位搜尋" +"的基礎物件時不會。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1561 msgid "" "<emphasis>finding</emphasis>: Aliases are only dereferenced when locating " "the base object of the search." -msgstr "" +msgstr "<emphasis>finding</emphasis>:只在定位搜尋的基礎物件時解除別名參照。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1566 msgid "" "<emphasis>always</emphasis>: Aliases are dereferenced both in searching and " "in locating the base object of the search." -msgstr "" +msgstr "<emphasis>always</emphasis>:在搜尋與定位搜尋的基礎物件時都會解除別名參照。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1571 msgid "" "Default: Empty (this is handled as <emphasis>never</emphasis> by the LDAP " "client libraries)" -msgstr "" +msgstr "預設:空白(LDAP 用戶端程式庫會將此視為 <emphasis>never</emphasis> 處理)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1579 msgid "ldap_rfc2307_fallback_to_local_users (boolean)" -msgstr "" +msgstr "ldap_rfc2307_fallback_to_local_users (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1582 msgid "" "Allows to retain local users as members of an LDAP group for servers that " "use the RFC2307 schema." -msgstr "" +msgstr "允許對使用 RFC2307 架構的伺服器保留本機使用者作為 LDAP 群組的成員。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1586 @@ -7064,6 +8037,10 @@ msgid "" "memberships as soon as nsswitch tries to fetch information about the user " "via getpw*() or initgroups() calls." msgstr "" +"在某些使用 RFC2307 綱要的環境中,會透過將本機使用者的名稱加入 memberUid 屬性" +",讓本機使用者成為 LDAP 群組的成員。這樣做會破壞網域的自洽性,因此只要 " +"nsswitch 嘗試透過 getpw*() 或 initgroups() 呼叫取回使用者資訊,SSSD 通常就會" +"從快取的群組成員中移除「遺失」的使用者。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1597 @@ -7072,33 +8049,35 @@ msgid "" "them so that later initgroups() calls will augment the local users with the " "additional LDAP groups." msgstr "" +"此選項會退回檢查本機使用者是否被參照,並快取他們,讓之後的 initgroups() 呼叫" +"會以額外的 LDAP 群組擴充本機使用者。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1609 sssd-ifp.5.xml:152 msgid "wildcard_limit (integer)" -msgstr "" +msgstr "wildcard_limit (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1612 msgid "" "Specifies an upper limit on the number of entries that are downloaded during " "a wildcard lookup." -msgstr "" +msgstr "指定萬用字元查詢期間下載項目數目的上限。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1616 msgid "At the moment, only the InfoPipe responder supports wildcard lookups." -msgstr "" +msgstr "目前只有 InfoPipe responder 支援萬用字元查詢。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1620 msgid "Default: 1000 (often the size of one page)" -msgstr "" +msgstr "預設:1000(通常是一頁的大小)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1626 msgid "ldap_library_debug_level (integer)" -msgstr "" +msgstr "ldap_library_debug_level (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1629 @@ -7106,23 +8085,25 @@ msgid "" "Switches on libldap debugging with the given level. The libldap debug " "messages will be written independent of the general debug_level." msgstr "" +"以指定的層級開啟 libldap 除錯。libldap 除錯訊息會獨立於一般 debug_level 寫入" +"。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1634 msgid "" "OpenLDAP uses a bitmap to enable debugging for specific components, -1 will " "enable full debug output." -msgstr "" +msgstr "OpenLDAP 使用點陣圖來啟用特定元件的除錯,-1 會啟用完整的除錯輸出。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1639 msgid "Default: 0 (libldap debugging disabled)" -msgstr "" +msgstr "預設:0(停用 libldap 除錯)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1645 msgid "ldap_use_ppolicy (boolean)" -msgstr "" +msgstr "ldap_use_ppolicy (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1648 @@ -7131,11 +8112,13 @@ msgid "" "controls. Disabling this allows interacting with services which send back " "invalid ppolicy extension." msgstr "" +"開啟要求並依賴伺服器端密碼原則控制。停用此選項可以與回傳無效 ppolicy 延伸的服" +"務互動。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1660 msgid "ldap_ppolicy_pwd_change_threshold (integer)" -msgstr "" +msgstr "ldap_ppolicy_pwd_change_threshold (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1663 @@ -7147,6 +8130,9 @@ msgid "" "logins, one to verify the current password and a second one to perform the " "password change." msgstr "" +"當啟用伺服器端密碼原則控制,且伺服器在驗證後傳回的剩餘寬限登入次數達到或低於" +"門檻時,強制變更密碼。請注意,有用的最小值是 2,因為變更密碼會消耗 2 次額外的" +"寬限登入,一次用於驗證目前的密碼,第二次用於執行密碼變更。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:52 @@ -7159,11 +8145,17 @@ msgid "" "<refentrytitle>sssd-ldap-attributes</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> manual page. <placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +"適用於 SSSD 網域的所有一般設定選項也適用於 LDAP 網域。完整詳細資料請參閱 " +"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> 手冊頁的 <quote>DOMAIN SECTIONS</quote> 一節。請注" +"意,SSSD LDAP 對應屬性說明於 <citerefentry> <refentrytitle>sssd-ldap-" +"attributes</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 手冊頁" +"。<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:1683 msgid "SUDO OPTIONS" -msgstr "" +msgstr "SUDO 選項" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:1685 @@ -7172,11 +8164,13 @@ msgid "" "manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry>." msgstr "" +"sudo_provider 設定的詳細說明請參閱手冊頁 <citerefentry> <refentrytitle>sssd-" +"sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1696 msgid "ldap_sudo_full_refresh_interval (integer)" -msgstr "" +msgstr "ldap_sudo_full_refresh_interval (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1699 @@ -7184,13 +8178,15 @@ msgid "" "How many seconds SSSD will wait between executing a full refresh of sudo " "rules (which downloads all rules that are stored on the server)." msgstr "" +"SSSD 在執行 sudo 規則完整重新整理(會下載伺服器上儲存的所有規則)之間會等待多" +"少秒。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1704 msgid "" "The value must be greater than <emphasis>ldap_sudo_smart_refresh_interval " "</emphasis>" -msgstr "" +msgstr "此值必須大於 <emphasis>ldap_sudo_smart_refresh_interval </emphasis>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1709 @@ -7198,16 +8194,18 @@ msgid "" "You can disable full refresh by setting this option to 0. However, either " "smart or full refresh must be enabled." msgstr "" +"您可以將此選項設為 0 來停用完整重新整理。不過,智慧型或完整重新整理必須啟用其" +"中一個。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1714 msgid "Default: 21600 (6 hours)" -msgstr "" +msgstr "預設:21600(6 小時)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1720 msgid "ldap_sudo_smart_refresh_interval (integer)" -msgstr "" +msgstr "ldap_sudo_smart_refresh_interval (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1723 @@ -7216,13 +8214,15 @@ msgid "" "rules (which downloads all rules that have USN higher than the highest " "server USN value that is currently known by SSSD)." msgstr "" +"指定 SSSD 在執行 sudo 規則智慧型重新整理(會下載所有 USN 高於 SSSD 目前已知之" +"伺服器最高 USN 值的規則)之前必須等待的秒數。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1729 msgid "" "If USN attributes are not supported by the server, the modifyTimestamp " "attribute is used instead." -msgstr "" +msgstr "若伺服器不支援 USN 屬性,則改用 modifyTimestamp 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1733 @@ -7233,6 +8233,10 @@ msgid "" "found) and 3) by reconnecting to the server (by default every 15 minutes, " "see <emphasis>ldap_connection_expire_timeout</emphasis>)." msgstr "" +"<emphasis>注意:</emphasis>最高 USN 值可以由三個工作更新:1) sudo 完整與智慧" +"型重新整理(若找到更新的規則),2) 使用者與群組列舉(若啟用且找到更新的使用者" +"或群組),3) 重新連線到伺服器(預設每 15 分鐘,請參閱 <emphasis>" +"ldap_connection_expire_timeout</emphasis>)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1744 @@ -7240,11 +8244,13 @@ msgid "" "You can disable smart refresh by setting this option to 0. However, either " "smart or full refresh must be enabled." msgstr "" +"您可以將此選項設為 0 來停用智慧型重新整理。不過,智慧型或完整重新整理必須啟用" +"其中一個。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1755 msgid "ldap_sudo_random_offset (integer)" -msgstr "" +msgstr "ldap_sudo_random_offset (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1758 @@ -7253,6 +8259,8 @@ msgid "" "refresh periods each time the periodic task is scheduled. The value is in " "seconds." msgstr "" +"每次排定週期性工作時,會將介於 0 與設定值之間的隨機偏移加到智慧型與完整重新整" +"理週期。值以秒為單位。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1764 @@ -7261,16 +8269,18 @@ msgid "" "delays the first sudo rules refresh. This prolongs the time when the sudo " "rules are not available for use." msgstr "" +"請注意,此隨機偏移也會套用於 SSSD 第一次啟動,這會延遲第一次的 sudo 規則重新" +"整理。這會延長 sudo 規則無法使用的時間。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1770 msgid "You can disable this offset by setting the value to 0." -msgstr "" +msgstr "您可以將值設為 0 來停用此偏移。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1780 msgid "ldap_sudo_use_host_filter (boolean)" -msgstr "" +msgstr "ldap_sudo_use_host_filter (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1783 @@ -7278,25 +8288,27 @@ msgid "" "If true, SSSD will download only rules that are applicable to this machine " "(using the IPv4 or IPv6 host/network addresses and hostnames)." msgstr "" +"若為 true,SSSD 只會下載適用於此機器的規則(使用 IPv4 或 IPv6 主機/網路位址與" +"主機名稱)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1794 msgid "ldap_sudo_hostnames (string)" -msgstr "" +msgstr "ldap_sudo_hostnames (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1797 msgid "" "Space separated list of hostnames or fully qualified domain names that " "should be used to filter the rules." -msgstr "" +msgstr "應該用來篩選規則的主機名稱或完整網域名稱空格分隔清單。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1802 msgid "" "If this option is empty, SSSD will try to discover the hostname and the " "fully qualified domain name automatically." -msgstr "" +msgstr "若此選項為空白,SSSD 會嘗試自動探索主機名稱與完整網域名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1807 sssd-ldap.5.xml:1830 sssd-ldap.5.xml:1848 @@ -7305,61 +8317,63 @@ msgid "" "If <emphasis>ldap_sudo_use_host_filter</emphasis> is " "<emphasis>false</emphasis> then this option has no effect." msgstr "" +"若 <emphasis>ldap_sudo_use_host_filter</emphasis> 為 <emphasis>false</" +"emphasis>,則此選項沒有作用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1812 sssd-ldap.5.xml:1835 msgid "Default: not specified" -msgstr "" +msgstr "預設:未指定" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1818 msgid "ldap_sudo_ip (string)" -msgstr "" +msgstr "ldap_sudo_ip (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1821 msgid "" "Space separated list of IPv4 or IPv6 host/network addresses that should be " "used to filter the rules." -msgstr "" +msgstr "應該用來篩選規則的 IPv4 或 IPv6 主機/網路位址空格分隔清單。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1826 msgid "" "If this option is empty, SSSD will try to discover the addresses " "automatically." -msgstr "" +msgstr "若此選項為空白,SSSD 會嘗試自動探索位址。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1841 msgid "ldap_sudo_include_netgroups (boolean)" -msgstr "" +msgstr "ldap_sudo_include_netgroups (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1844 msgid "" "If true then SSSD will download every rule that contains a netgroup in " "sudoHost attribute." -msgstr "" +msgstr "若為 true,SSSD 會下載 sudoHost 屬性中包含 netgroup 的每個規則。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1859 msgid "ldap_sudo_include_regexp (boolean)" -msgstr "" +msgstr "ldap_sudo_include_regexp (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1862 msgid "" "If true then SSSD will download every rule that contains a wildcard in " "sudoHost attribute." -msgstr "" +msgstr "若為 true,SSSD 會下載 sudoHost 屬性中包含萬用字元的每個規則。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><note><para> #: sssd-ldap.5.xml:1872 msgid "" "Using wildcard is an operation that is very costly to evaluate on the LDAP " "server side!" -msgstr "" +msgstr "使用萬用字元是在 LDAP 伺服器端評估成本非常高的作業!" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:1884 @@ -7369,58 +8383,61 @@ msgid "" "<refentrytitle>sudoers.ldap</refentrytitle><manvolnum>5</manvolnum> " "</citerefentry>" msgstr "" +"本手冊頁只描述屬性名稱對應。sudo 相關屬性語意的詳細說明,請參閱 " +"<citerefentry> <refentrytitle>sudoers.ldap</refentrytitle><manvolnum>5</" +"manvolnum> </citerefentry>" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:1894 msgid "AUTOFS OPTIONS" -msgstr "" +msgstr "AUTOFS 選項" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:1896 msgid "" "Some of the defaults for the parameters below are dependent on the LDAP " "schema." -msgstr "" +msgstr "下列參數的部分預設值取決於 LDAP 綱要。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1902 msgid "ldap_autofs_map_master_name (string)" -msgstr "" +msgstr "ldap_autofs_map_master_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1905 msgid "The name of the automount master map in LDAP." -msgstr "" +msgstr "LDAP 中自動掛載主對應表的名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap.5.xml:1908 msgid "Default: auto.master" -msgstr "" +msgstr "預設:auto.master" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:1919 msgid "ADVANCED OPTIONS" -msgstr "" +msgstr "進階選項" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1926 msgid "ldap_netgroup_search_base (string)" -msgstr "" +msgstr "ldap_netgroup_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1931 msgid "ldap_user_search_base (string)" -msgstr "" +msgstr "ldap_user_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1936 msgid "ldap_group_search_base (string)" -msgstr "" +msgstr "ldap_group_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><note> #: sssd-ldap.5.xml:1941 msgid "<note>" -msgstr "" +msgstr "<note>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><note><para> #: sssd-ldap.5.xml:1943 @@ -7430,21 +8447,24 @@ msgid "" "memberships, even with no GID mapping. It is recommended to disable this " "feature, if group names are not being displayed correctly." msgstr "" +"若啟用 <quote>ldap_use_tokengroups</quote> 選項,對 Active Directory 的搜尋不" +"會受到限制,會傳回所有群組成員資格,即使沒有 GID 對應。若群組名稱顯示不正確," +"建議停用此功能。" #. type: Content of: <reference><refentry><refsect1><para><variablelist> #: sssd-ldap.5.xml:1950 msgid "</note>" -msgstr "" +msgstr "</note>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1952 msgid "ldap_sudo_search_base (string)" -msgstr "" +msgstr "ldap_sudo_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap.5.xml:1957 msgid "ldap_autofs_search_base (string)" -msgstr "" +msgstr "ldap_autofs_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:1921 @@ -7454,13 +8474,16 @@ msgid "" "are doing. <placeholder type=\"variablelist\" id=\"0\"/> <placeholder " "type=\"variablelist\" id=\"1\"/>" msgstr "" +"LDAP 網域支援這些選項,但應謹慎使用。請只在您知道自己在做什麼的情況下,才將它" +"們納入設定。<placeholder type=\"variablelist\" id=\"0\"/> <placeholder " +"type=\"variablelist\" id=\"1\"/>" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:1972 sssd-simple.5.xml:131 sssd-ipa.5.xml:930 #: sssd-ad.5.xml:1392 sssd-krb5.5.xml:483 sss_rpcidmapd.5.xml:98 #: sssd-files.5.xml:155 sssd-session-recording.5.xml:176 msgid "EXAMPLE" -msgstr "" +msgstr "範例" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:1974 @@ -7469,6 +8492,8 @@ msgid "" "set to one of the domains in the <replaceable>[domains]</replaceable> " "section." msgstr "" +"下列範例假設 SSSD 已正確設定,且 LDAP 設為 <replaceable>[domains]</" +"replaceable> 區段中的其中一個網域。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-ldap.5.xml:1980 @@ -7482,6 +8507,13 @@ msgid "" "ldap_tls_reqcert = demand\n" "cache_credentials = true\n" msgstr "" +"[domain/LDAP]\n" +"id_provider = ldap\n" +"auth_provider = ldap\n" +"ldap_uri = ldap://ldap.mydomain.org\n" +"ldap_search_base = dc=mydomain,dc=org\n" +"ldap_tls_reqcert = demand\n" +"cache_credentials = true\n" #. type: Content of: <refsect1><refsect2><para> #: sssd-ldap.5.xml:1979 sssd-ldap.5.xml:1997 sssd-simple.5.xml:139 @@ -7489,19 +8521,19 @@ msgstr "" #: sssd-files.5.xml:162 sssd-files.5.xml:173 sssd-session-recording.5.xml:182 #: include/ldap_id_mapping.xml:105 msgid "<placeholder type=\"programlisting\" id=\"0\"/>" -msgstr "" +msgstr "<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:1991 msgid "LDAP ACCESS FILTER EXAMPLE" -msgstr "" +msgstr "LDAP 存取篩選器範例" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:1993 msgid "" "The following example assumes that SSSD is correctly configured and to use " "the ldap_access_order=lockout." -msgstr "" +msgstr "下列範例假設 SSSD 已正確設定,且使用 ldap_access_order=lockout。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-ldap.5.xml:1998 @@ -7518,12 +8550,22 @@ msgid "" "ldap_tls_reqcert = demand\n" "cache_credentials = true\n" msgstr "" +"[domain/LDAP]\n" +"id_provider = ldap\n" +"auth_provider = ldap\n" +"access_provider = ldap\n" +"ldap_access_order = lockout\n" +"ldap_pwdlockout_dn = cn=ppolicy,ou=policies,dc=mydomain,dc=org\n" +"ldap_uri = ldap://ldap.mydomain.org\n" +"ldap_search_base = dc=mydomain,dc=org\n" +"ldap_tls_reqcert = demand\n" +"cache_credentials = true\n" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap.5.xml:2013 sssd_krb5_locator_plugin.8.xml:83 sssd-simple.5.xml:148 #: sssd-ad.5.xml:1415 sssd.8.xml:270 sss_seed.8.xml:163 msgid "NOTES" -msgstr "" +msgstr "注意事項" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap.5.xml:2015 @@ -7533,11 +8575,14 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> manual page from the OpenLDAP 2.4 " "distribution." msgstr "" +"本手冊頁中部分設定選項的說明是以 OpenLDAP 2.4 發行版中的 <citerefentry> " +"<refentrytitle>ldap.conf</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry> 手冊頁為基礎。" #. type: Content of: <reference><refentry><refnamediv><refname> #: pam_sss.8.xml:11 pam_sss.8.xml:16 msgid "pam_sss" -msgstr "" +msgstr "pam_sss" #. type: Content of: <reference><refentry><refmeta><manvolnum> #: pam_sss.8.xml:12 pam_sss_gss.8.xml:12 sssd_krb5_locator_plugin.8.xml:11 @@ -7546,12 +8591,12 @@ msgstr "" #: idmap_sss.8.xml:11 sssctl.8.xml:11 sssd-kcm.8.xml:11 #: sssd_krb5_localauth_plugin.8.xml:11 msgid "8" -msgstr "" +msgstr "8" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: pam_sss.8.xml:17 msgid "PAM module for SSSD" -msgstr "" +msgstr "SSSD 的 PAM 模組" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: pam_sss.8.xml:22 @@ -7570,6 +8615,18 @@ msgid "" "<replaceable>try_cert_auth</replaceable> </arg> <arg choice='opt'> " "<replaceable>require_cert_auth</replaceable> </arg>" msgstr "" +"<command>pam_sss.so</command> <arg choice='opt'> <replaceable>quiet</" +"replaceable> </arg> <arg choice='opt'> <replaceable>forward_pass</" +"replaceable> </arg> <arg choice='opt'> <replaceable>use_first_pass</" +"replaceable> </arg> <arg choice='opt'> <replaceable>use_authtok</" +"replaceable> </arg> <arg choice='opt'> <replaceable>retry=N</replaceable> </" +"arg> <arg choice='opt'> <replaceable>ignore_unknown_user</replaceable> </" +"arg> <arg choice='opt'> <replaceable>ignore_authinfo_unavail</replaceable> </" +"arg> <arg choice='opt'> <replaceable>domains=X</replaceable> </arg> <arg " +"choice='opt'> <replaceable>allow_missing_name</replaceable> </arg> <arg " +"choice='opt'> <replaceable>prompt_always</replaceable> </arg> <arg " +"choice='opt'> <replaceable>try_cert_auth</replaceable> </arg> <arg " +"choice='opt'> <replaceable>require_cert_auth</replaceable> </arg>" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss.8.xml:64 @@ -7578,28 +8635,30 @@ msgid "" "Services daemon (SSSD). Errors and results are logged through " "<command>syslog(3)</command> with the LOG_AUTHPRIV facility." msgstr "" +"<command>pam_sss.so</command> 是系統安全服務精靈 (SSSD) 的 PAM 介面。錯誤與結" +"果會透過 <command>syslog(3)</command> 以 LOG_AUTHPRIV 設施記錄。" #. type: Content of: <reference><refentry><refsect1><title> #: pam_sss.8.xml:70 pam_sss_gss.8.xml:89 sssd.8.xml:42 sss_obfuscate.8.xml:58 #: sss_cache.8.xml:39 sss_seed.8.xml:42 sss_ssh_authorizedkeys.1.xml:123 #: sss_ssh_knownhosts.1.xml:56 sss_ssh_knownhostsproxy.1.xml:72 msgid "OPTIONS" -msgstr "" +msgstr "選項" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:74 msgid "<option>quiet</option>" -msgstr "" +msgstr "<option>quiet</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:77 msgid "Suppress log messages for unknown users." -msgstr "" +msgstr "抑制未知使用者的記錄訊息。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:82 msgid "<option>forward_pass</option>" -msgstr "" +msgstr "<option>forward_pass</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:85 @@ -7607,11 +8666,13 @@ msgid "" "If <option>forward_pass</option> is set the entered password is put on the " "stack for other PAM modules to use." msgstr "" +"若設定 <option>forward_pass</option>,輸入的密碼會放到堆疊上供其他 PAM 模組使" +"用。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:92 msgid "<option>use_first_pass</option>" -msgstr "" +msgstr "<option>use_first_pass</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:95 @@ -7621,30 +8682,32 @@ msgid "" "available or the password is not appropriate, the user will be denied " "access." msgstr "" +"use_first_pass 參數會強制模組使用先前堆疊模組的密碼,而且絕不會提示使用者——若" +"沒有可用的密碼或密碼不適當,使用者會被拒絕存取。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:103 msgid "<option>use_authtok</option>" -msgstr "" +msgstr "<option>use_authtok</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:106 msgid "" "When password changing enforce the module to set the new password to the one " "provided by a previously stacked password module." -msgstr "" +msgstr "變更密碼時,強制模組將新密碼設為先前堆疊的密碼模組提供的密碼。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:113 msgid "<option>retry=N</option>" -msgstr "" +msgstr "<option>retry=N</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:116 msgid "" "If specified the user is asked another N times for a password if " "authentication fails. Default is 0." -msgstr "" +msgstr "若指定,驗證失敗時會再詢問使用者 N 次密碼。預設為 0。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:118 @@ -7653,11 +8716,14 @@ msgid "" "calling PAM handles the user dialog on its own. A typical example is " "<command>sshd</command> with <option>PasswordAuthentication</option>." msgstr "" +"請注意,若呼叫 PAM 的應用程式自行處理使用者對話,此選項可能無法如預期運作。典" +"型的例子是使用 <option>PasswordAuthentication</option> 的 <command>sshd</" +"command>。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:127 msgid "<option>ignore_unknown_user</option>" -msgstr "" +msgstr "<option>ignore_unknown_user</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:130 @@ -7665,11 +8731,13 @@ msgid "" "If this option is specified and the user does not exist, the PAM module will " "return PAM_IGNORE. This causes the PAM framework to ignore this module." msgstr "" +"若指定此選項且使用者不存在,PAM 模組會傳回 PAM_IGNORE。這會讓 PAM 架構忽略此" +"模組。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:137 msgid "<option>ignore_authinfo_unavail</option>" -msgstr "" +msgstr "<option>ignore_authinfo_unavail</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:141 @@ -7677,11 +8745,13 @@ msgid "" "Specifies that the PAM module should return PAM_IGNORE if it cannot contact " "the SSSD daemon. This causes the PAM framework to ignore this module." msgstr "" +"指定 PAM 模組在無法連絡 SSSD 精靈時應傳回 PAM_IGNORE。這會讓 PAM 架構忽略此模" +"組。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:148 msgid "<option>domains</option>" -msgstr "" +msgstr "<option>domains</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:152 @@ -7690,6 +8760,8 @@ msgid "" "allowed to authenticate against. The format is a comma-separated list of " "SSSD domain names, as specified in the sssd.conf file." msgstr "" +"允許管理員限制特定 PAM 服務可以驗證的網域。格式是 SSSD 網域名稱的逗號分隔清單" +",如 sssd.conf 檔案中所指定。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:158 @@ -7702,11 +8774,16 @@ msgid "" "</citerefentry> manual page for more information on these two PAM responder " "options." msgstr "" +"注意:若這是用於不是以 root 使用者執行的服務(例如網頁伺服器),必須與 " +"<quote>pam_trusted_users</quote> 與 <quote>pam_public_domains</quote> 選項一" +"起使用。有關這兩個 PAM responder 選項的更多資訊,請參閱 <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry> 手冊頁。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:173 msgid "<option>allow_missing_name</option>" -msgstr "" +msgstr "<option>allow_missing_name</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:177 @@ -7714,6 +8791,8 @@ msgid "" "The main purpose of this option is to let SSSD determine the user name based " "on additional information, e.g. the certificate from a Smartcard." msgstr "" +"此選項的主要目的是讓 SSSD 根據其他資訊(例如 Smartcard 的憑證)判斷使用者名稱" +"。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting> #: pam_sss.8.xml:187 @@ -7722,6 +8801,8 @@ msgid "" "auth sufficient pam_sss.so allow_missing_name\n" " " msgstr "" +"auth sufficient pam_sss.so allow_missing_name\n" +" " #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:182 @@ -7733,11 +8814,15 @@ msgid "" "the content of the Smartcard, returns it to pam_sss which will finally put " "it on the PAM stack." msgstr "" +"目前的使用案例是能夠監控 Smartcard 讀卡機卡片事件的登入管理員。若插入 " +"Smartcard,登入管理員會呼叫包含類似 <placeholder type=\"programlisting\" " +"id=\"0\"/> 這一行內容的 PAM 堆疊。在此情況下,SSSD 會嘗試根據 Smartcard 的內" +"容判斷使用者名稱,將它傳回 pam_sss,最後由 pam_sss 放到 PAM 堆疊上。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:197 msgid "<option>prompt_always</option>" -msgstr "" +msgstr "<option>prompt_always</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:201 @@ -7748,11 +8833,14 @@ msgid "" "SSSD pam_sss might prompt for a password, a Smartcard PIN or other " "credentials." msgstr "" +"一律提示使用者輸入憑證。使用此選項時,其他 PAM 模組要求的憑證(通常是密碼)會" +"被忽略,pam_sss 會再次提示輸入憑證。根據 SSSD 的預先驗證回覆,pam_sss 可能會" +"提示輸入密碼、Smartcard PIN 或其他憑證。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:212 msgid "<option>try_cert_auth</option>" -msgstr "" +msgstr "<option>try_cert_auth</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:216 @@ -7762,6 +8850,9 @@ msgid "" "allowed for Smartcard authentication the user will be prompted for a PIN and " "the certificate based authentication will continue" msgstr "" +"嘗試使用以憑證為基礎的驗證,也就是使用 Smartcard 或類似裝置驗證。若 " +"Smartcard 可用且服務允許 Smartcard 驗證,會提示使用者輸入 PIN,並繼續以憑證為" +"基礎的驗證" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:224 @@ -7769,11 +8860,13 @@ msgid "" "If no Smartcard is available or certificate based authentication is not " "allowed for the current service PAM_AUTHINFO_UNAVAIL is returned." msgstr "" +"若沒有可用的 Smartcard,或目前的服務不允許以憑證為基礎的驗證,會傳回 " +"PAM_AUTHINFO_UNAVAIL。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:232 msgid "<option>require_cert_auth</option>" -msgstr "" +msgstr "<option>require_cert_auth</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:236 @@ -7785,6 +8878,11 @@ msgid "" "<citerefentry><refentrytitle>sssd.conf</refentrytitle> " "<manvolnum>5</manvolnum></citerefentry> for details." msgstr "" +"執行以憑證為基礎的驗證,也就是使用 Smartcard 或類似裝置驗證。若沒有可用的 " +"Smartcard,會提示使用者插入一張。SSSD 會等待 Smartcard,直到 " +"p11_wait_for_card_timeout 定義的逾時過去,詳情請參閱 <citerefentry>" +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum></" +"citerefentry>。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:246 @@ -7793,11 +8891,13 @@ msgid "" "authentication is not allowed for the current service PAM_AUTHINFO_UNAVAIL " "is returned." msgstr "" +"若逾時後仍沒有可用的 Smartcard,或目前的服務不允許以憑證為基礎的驗證,會傳回 " +"PAM_AUTHINFO_UNAVAIL。" #. type: Content of: <reference><refentry><refsect1><title> #: pam_sss.8.xml:256 pam_sss_gss.8.xml:103 msgid "MODULE TYPES PROVIDED" -msgstr "" +msgstr "提供的模組類型" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss.8.xml:257 @@ -7805,6 +8905,8 @@ msgid "" "All module types (<option>account</option>, <option>auth</option>, " "<option>password</option> and <option>session</option>) are provided." msgstr "" +"提供所有模組類型(<option>account</option>、<option>auth</option>、<option>" +"password</option> 與 <option>session</option>)。" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss.8.xml:260 @@ -7814,62 +8916,65 @@ msgid "" "<option>account</option> module to avoid issues with users from other " "sources during access control." msgstr "" +"若 SSSD 的 PAM responder 未執行(例如 PAM responder 通訊端無法使用)," +"pam_sss 以 <option>account</option> 模組呼叫時會傳回 PAM_USER_UNKNOWN,以避免" +"存取控制期間其他來源的使用者發生問題。" #. type: Content of: <reference><refentry><refsect1><title> #: pam_sss.8.xml:267 pam_sss_gss.8.xml:108 msgid "RETURN VALUES" -msgstr "" +msgstr "傳回值" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:270 pam_sss_gss.8.xml:111 msgid "PAM_SUCCESS" -msgstr "" +msgstr "PAM_SUCCESS" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:273 pam_sss_gss.8.xml:114 msgid "The PAM operation finished successfully." -msgstr "" +msgstr "PAM 作業成功完成。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:278 pam_sss_gss.8.xml:119 msgid "PAM_USER_UNKNOWN" -msgstr "" +msgstr "PAM_USER_UNKNOWN" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:281 msgid "" "The user is not known to the authentication service or the SSSD's PAM " "responder is not running." -msgstr "" +msgstr "驗證服務不認識此使用者,或 SSSD 的 PAM responder 未執行。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:287 pam_sss_gss.8.xml:128 msgid "PAM_AUTH_ERR" -msgstr "" +msgstr "PAM_AUTH_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:290 msgid "" "Authentication failure. Also, could be returned when there is a problem with " "getting the certificate." -msgstr "" +msgstr "驗證失敗。取得憑證時發生問題,也可能傳回此值。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:296 msgid "PAM_PERM_DENIED" -msgstr "" +msgstr "PAM_PERM_DENIED" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:299 msgid "" "Permission denied. The SSSD log files may contain additional information " "about the error." -msgstr "" +msgstr "拒絕存取。SSSD 記錄檔可能包含此錯誤的其他資訊。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:305 msgid "PAM_IGNORE" -msgstr "" +msgstr "PAM_IGNORE" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:308 @@ -7877,11 +8982,13 @@ msgid "" "See options <option>ignore_unknown_user</option> and " "<option>ignore_authinfo_unavail</option>." msgstr "" +"請參閱 <option>ignore_unknown_user</option> 與 <option>" +"ignore_authinfo_unavail</option> 選項。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:314 msgid "PAM_AUTHTOK_ERR" -msgstr "" +msgstr "PAM_AUTHTOK_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:317 @@ -7891,23 +8998,25 @@ msgid "" "available, but the installed version of GDM does not support selection from " "multiple certificates." msgstr "" +"無法取得新的驗證權杖。使用者以憑證驗證且有多個憑證可用,但安裝的 GDM 版本不支" +"援從多個憑證中選擇時,也可能傳回此值。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:325 pam_sss_gss.8.xml:136 msgid "PAM_AUTHINFO_UNAVAIL" -msgstr "" +msgstr "PAM_AUTHINFO_UNAVAIL" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:328 pam_sss_gss.8.xml:139 msgid "" "Unable to access the authentication information. This might be due to a " "network or hardware failure." -msgstr "" +msgstr "無法存取驗證資訊。這可能是由於網路或硬體故障。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:334 msgid "PAM_BUF_ERR" -msgstr "" +msgstr "PAM_BUF_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:337 @@ -7916,33 +9025,35 @@ msgid "" "or use_authtok were set, but no password was found from the previously " "stacked PAM module." msgstr "" +"發生記憶體錯誤。設定了 use_first_pass 或 use_authtok 選項,但從先前堆疊的 " +"PAM 模組找不到密碼時,也可能傳回此值。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:344 pam_sss_gss.8.xml:145 msgid "PAM_SYSTEM_ERR" -msgstr "" +msgstr "PAM_SYSTEM_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:347 pam_sss_gss.8.xml:148 msgid "" "A system error occurred. The SSSD log files may contain additional " "information about the error." -msgstr "" +msgstr "發生系統錯誤。SSSD 記錄檔可能包含此錯誤的其他資訊。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:353 msgid "PAM_CRED_ERR" -msgstr "" +msgstr "PAM_CRED_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:356 msgid "Unable to set the credentials of the user." -msgstr "" +msgstr "無法設定使用者的憑證。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:361 msgid "PAM_CRED_INSUFFICIENT" -msgstr "" +msgstr "PAM_CRED_INSUFFICIENT" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:364 @@ -7951,61 +9062,63 @@ msgid "" "user. For example, missing PIN during smartcard authentication or missing " "factor during two-factor authentication." msgstr "" +"應用程式沒有足夠的憑證可以驗證使用者。例如,smartcard 驗證期間缺少 PIN,或雙" +"因素驗證期間缺少因素。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:372 msgid "PAM_SERVICE_ERR" -msgstr "" +msgstr "PAM_SERVICE_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:375 msgid "Error in service module." -msgstr "" +msgstr "服務模組發生錯誤。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:380 msgid "PAM_NEW_AUTHTOK_REQD" -msgstr "" +msgstr "PAM_NEW_AUTHTOK_REQD" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:383 msgid "The user's authentication token has expired." -msgstr "" +msgstr "使用者的驗證權杖已到期。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:388 msgid "PAM_ACCT_EXPIRED" -msgstr "" +msgstr "PAM_ACCT_EXPIRED" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:391 msgid "The user account has expired." -msgstr "" +msgstr "使用者帳戶已到期。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:396 msgid "PAM_SESSION_ERR" -msgstr "" +msgstr "PAM_SESSION_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:399 msgid "Unable to fetch IPA Desktop Profile rules or user info." -msgstr "" +msgstr "無法取回 IPA 桌面設定檔規則或使用者資訊。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:404 msgid "PAM_CRED_UNAVAIL" -msgstr "" +msgstr "PAM_CRED_UNAVAIL" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:407 msgid "Unable to retrieve Kerberos user credentials." -msgstr "" +msgstr "無法取回 Kerberos 使用者憑證。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:412 msgid "PAM_NO_MODULE_DATA" -msgstr "" +msgstr "PAM_NO_MODULE_DATA" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:415 @@ -8014,61 +9127,63 @@ msgid "" "user has a Smartcard assigned but the pkint plugin is not available on the " "client." msgstr "" +"Kerberos 找不到任何驗證方法。若使用者已指派 Smartcard,但用戶端沒有可用的 " +"pkint 外掛程式,就可能發生這種情況。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:422 msgid "PAM_CONV_ERR" -msgstr "" +msgstr "PAM_CONV_ERR" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:425 msgid "Conversation failure." -msgstr "" +msgstr "交談失敗。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:430 msgid "PAM_AUTHTOK_LOCK_BUSY" -msgstr "" +msgstr "PAM_AUTHTOK_LOCK_BUSY" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:433 msgid "No KDC suitable for password change is available." -msgstr "" +msgstr "沒有可用於變更密碼的合適 KDC。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:438 msgid "PAM_ABORT" -msgstr "" +msgstr "PAM_ABORT" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:441 msgid "Unknown PAM call." -msgstr "" +msgstr "未知的 PAM 呼叫。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:446 msgid "PAM_MODULE_UNKNOWN" -msgstr "" +msgstr "PAM_MODULE_UNKNOWN" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:449 msgid "Unsupported PAM task or command." -msgstr "" +msgstr "不支援的 PAM 工作或指令。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss.8.xml:454 msgid "PAM_BAD_ITEM" -msgstr "" +msgstr "PAM_BAD_ITEM" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss.8.xml:457 msgid "The authentication module cannot handle Smartcard credentials." -msgstr "" +msgstr "驗證模組無法處理 Smartcard 憑證。" #. type: Content of: <reference><refentry><refsect1><title> #: pam_sss.8.xml:465 msgid "FILES" -msgstr "" +msgstr "檔案" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss.8.xml:466 @@ -8078,6 +9193,8 @@ msgid "" "displayed. This message can e.g. contain instructions about how to reset a " "password." msgstr "" +"若 root 重設密碼失敗(因為對應的 SSSD 提供者不支援密碼重設),可以顯示個別訊" +"息。此訊息可以例如包含如何重設密碼的說明。" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss.8.xml:471 @@ -8091,6 +9208,11 @@ msgid "" "the owner of the files and only root may have read and write permissions " "while all other users must have only read permissions." msgstr "" +"訊息從檔案 <filename>pam_sss_pw_reset_message.LOC</filename> 讀取,其中 LOC " +"代表 <citerefentry> <refentrytitle>setlocale</refentrytitle><manvolnum>3</" +"manvolnum> </citerefentry> 傳回的地區設定字串。若沒有相符的檔案,則顯示 " +"<filename>pam_sss_pw_reset_message.txt</filename> 的內容。root 必須是這些檔案" +"的所有者,而且只有 root 可以有讀寫權限,其他所有使用者只能有讀取權限。" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss.8.xml:481 @@ -8099,16 +9221,18 @@ msgid "" "<filename>/etc/sssd/customize/DOMAIN_NAME/</filename>. If no matching file " "is present a generic message is displayed." msgstr "" +"這些檔案會在目錄 <filename>/etc/sssd/customize/DOMAIN_NAME/</filename> 中搜尋" +"。若沒有相符的檔案,會顯示一般訊息。" #. type: Content of: <reference><refentry><refnamediv><refname> #: pam_sss_gss.8.xml:11 pam_sss_gss.8.xml:16 msgid "pam_sss_gss" -msgstr "" +msgstr "pam_sss_gss" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: pam_sss_gss.8.xml:17 msgid "PAM module for SSSD GSSAPI authentication" -msgstr "" +msgstr "SSSD GSSAPI 驗證的 PAM 模組" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: pam_sss_gss.8.xml:22 @@ -8116,13 +9240,15 @@ msgid "" "<command>pam_sss_gss.so</command> <arg choice='opt'> " "<replaceable>debug</replaceable> </arg>" msgstr "" +"<command>pam_sss_gss.so</command> <arg choice='opt'> <replaceable>debug</" +"replaceable> </arg>" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:32 msgid "" "<command>pam_sss_gss.so</command> authenticates user over GSSAPI in " "cooperation with SSSD." -msgstr "" +msgstr "<command>pam_sss_gss.so</command> 與 SSSD 合作,透過 GSSAPI 驗證使用者。" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:36 @@ -8133,6 +9259,10 @@ msgid "" "name is derived by Kerberos internal mechanisms and it can be set explicitly " "in configuration of [domain_realm] section in /etc/krb5.conf." msgstr "" +"此模組會嘗試使用 GSSAPI 主機型服務名稱 host@hostname(會轉譯為 host/" +"hostname@REALM Kerberos principal)驗證使用者。Kerberos principal 名稱的 " +"<emphasis>REALM</emphasis> 部分由 Kerberos 內部機制推導,也可以在 /etc/" +"krb5.conf 的 [domain_realm] 區段設定中明確設定。" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:44 @@ -8142,6 +9272,9 @@ msgid "" "the Kerberos credentials cache or if user's ticket granting ticket can be " "used to get the correct service ticket then the user will be authenticated." msgstr "" +"SSSD 用於提供所需的服務名稱,並使用 GSSAPI 呼叫驗證使用者的憑證。若服務票證已" +"存在於 Kerberos 憑證快取中,或可以使用使用者的票證授予票證取得正確的服務票證" +",則使用者會被驗證。" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:51 @@ -8152,6 +9285,9 @@ msgid "" "Kerberos credentials must match with the user principal name as defined in " "LDAP." msgstr "" +"若 <option>pam_gssapi_check_upn</option> 為 True(預設),SSSD 會要求取得服務" +"票證所用的憑證可以與使用者關聯。這表示擁有 Kerberos 憑證的 principal 必須與 " +"LDAP 中定義的使用者 principal 名稱相符。" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:58 @@ -8165,6 +9301,13 @@ msgid "" "</citerefentry> and <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> for more details on these options." msgstr "" +"若要在 SSSD 中啟用 GSSAPI 驗證,請在 sssd.conf 的 [pam] 或網域區段設定 " +"<option>pam_gssapi_services</option> 選項。服務憑證需要儲存在 SSSD 的 keytab " +"中(若您使用 ipa 或 ad 提供者,keytab 已存在)。keytab 位置可以使用 <option>" +"krb5_keytab</option> 選項設定。這些選項的更多詳細資料請參閱 <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry> 與 <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:74 @@ -8175,6 +9318,9 @@ msgid "" "presence of authentication indicators in the service tickets before a " "particular PAM service can be accessed." msgstr "" +"某些 Kerberos 部署允許將驗證指標與使用者取得票證授予票證所使用的特定預先驗證" +"方法關聯。<command>pam_sss_gss.so</command> 允許在存取特定 PAM 服務之前,強制" +"服務票證中存在驗證指標。" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:82 @@ -8183,33 +9329,35 @@ msgid "" "section of sssd.conf, then SSSD will perform a check of the presence of any " "configured indicators in the service ticket." msgstr "" +"若在 sssd.conf 的 [pam] 或網域區段設定 <option>pam_gssapi_indicators_map</" +"option>,SSSD 會檢查服務票證中是否存在任何已設定的指標。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: pam_sss_gss.8.xml:93 msgid "<option>debug</option>" -msgstr "" +msgstr "<option>debug</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss_gss.8.xml:96 msgid "Print debugging information." -msgstr "" +msgstr "列印除錯資訊。" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:104 msgid "Only the <option>auth</option> module type is provided." -msgstr "" +msgstr "只提供 <option>auth</option> 模組類型。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss_gss.8.xml:122 msgid "" "The user is not known to the authentication service or the GSSAPI " "authentication is not supported." -msgstr "" +msgstr "驗證服務不認識此使用者,或不支援 GSSAPI 驗證。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: pam_sss_gss.8.xml:131 msgid "Authentication failure." -msgstr "" +msgstr "驗證失敗。" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:159 @@ -8218,6 +9366,8 @@ msgid "" "without the need to disable authentication completely. To achieve this, " "first enable GSSAPI authentication for sudo in sssd.conf:" msgstr "" +"主要使用案例是在 sudo 中提供免密碼驗證,但不需要完全停用驗證。要做到這點,請" +"先在 sssd.conf 中為 sudo 啟用 GSSAPI 驗證:" #. type: Content of: <reference><refentry><refsect1><programlisting> #: pam_sss_gss.8.xml:165 @@ -8227,6 +9377,9 @@ msgid "" "pam_gssapi_services = sudo, sudo-i\n" " " msgstr "" +"[domain/MYDOMAIN]\n" +"pam_gssapi_services = sudo, sudo-i\n" +" " #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:169 @@ -8234,6 +9387,8 @@ msgid "" "And then enable the module in desired PAM stack (e.g. /etc/pam.d/sudo and " "/etc/pam.d/sudo-i)." msgstr "" +"然後在所需的 PAM 堆疊中啟用此模組(例如 /etc/pam.d/sudo 與 /etc/pam.d/sudo-i" +")。" #. type: Content of: <reference><refentry><refsect1><programlisting> #: pam_sss_gss.8.xml:173 @@ -8244,11 +9399,15 @@ msgid "" "...\n" " " msgstr "" +"...\n" +"auth sufficient pam_sss_gss.so\n" +"...\n" +" " #. type: Content of: <reference><refentry><refsect1><title> #: pam_sss_gss.8.xml:180 msgid "TROUBLESHOOTING" -msgstr "" +msgstr "疑難排解" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:182 @@ -8256,6 +9415,8 @@ msgid "" "SSSD logs, pam_sss_gss debug output and syslog may contain helpful " "information about the error. Here are some common issues:" msgstr "" +"SSSD 記錄、pam_sss_gss 除錯輸出與 syslog 可能包含此錯誤的實用資訊。以下是一些" +"常見問題:" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:186 @@ -8266,6 +9427,9 @@ msgid "" "<option>env_keep</option> in /etc/sudoers or in your LDAP sudo rules default " "options." msgstr "" +"1. 我已設定 KRB5CCNAME 環境變數,但驗證無法運作:視您的 sudo 版本而定,sudo " +"可能不會將此變數傳遞給 PAM 環境。請嘗試在 /etc/sudoers 或 LDAP sudo 規則的預" +"設選項中,將 KRB5CCNAME 加入 <option>env_keep</option>。" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:193 @@ -8275,6 +9439,9 @@ msgid "" "for the service ticket based on the hostname. Try adding the hostname " "directly to <option>[domain_realm]</option> in /etc/krb5.conf like so:" msgstr "" +"2. 驗證無法運作,且 syslog 包含 \"Server not found in Kerberos database\":" +"Kerberos 可能無法根據主機名稱解析服務票證的正確 realm。請嘗試像這樣直接將主機" +"名稱加入 /etc/krb5.conf 中的 <option>[domain_realm]</option>:" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:200 @@ -8284,6 +9451,9 @@ msgid "" "obtain the required service ticket. Use kinit or authenticate over SSSD to " "acquire those credentials." msgstr "" +"3. 驗證無法運作,且 syslog 包含 \"No Kerberos credentials available\":您沒有" +"任何可以用來取得所需服務票證的憑證。請使用 kinit 或透過 SSSD 驗證來取得這些憑" +"證。" #. type: Content of: <reference><refentry><refsect1><para> #: pam_sss_gss.8.xml:206 @@ -8295,6 +9465,10 @@ msgid "" "principal, make sure you authenticated with SSSD or consider disabling " "<option>pam_gssapi_check_upn</option>." msgstr "" +"4. 驗證無法運作,且 SSSD sssd-pam 記錄包含 \"User with UPN [$UPN] was not " +"found.\" 或 \"UPN [$UPN] does not match target user [$username].\":您使用的" +"憑證無法對應到正在驗證的使用者。請嘗試使用 kswitch 選取不同的 principal,確認" +"您是透過 SSSD 驗證,或考慮停用 <option>pam_gssapi_check_upn</option>。" #. type: Content of: <reference><refentry><refsect1><programlisting> #: pam_sss_gss.8.xml:214 @@ -8304,16 +9478,19 @@ msgid "" ".myhostname = MYREALM\n" " " msgstr "" +"[domain_realm]\n" +".myhostname = MYREALM\n" +" " #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd_krb5_locator_plugin.8.xml:10 sssd_krb5_locator_plugin.8.xml:15 msgid "sssd_krb5_locator_plugin" -msgstr "" +msgstr "sssd_krb5_locator_plugin" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd_krb5_locator_plugin.8.xml:16 msgid "Kerberos locator plugin" -msgstr "" +msgstr "Kerberos locator 外掛程式" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:22 @@ -8327,6 +9504,11 @@ msgid "" "unexpected authentication failures and maybe even account lockings it would " "be good to talk to a single KDC as long as possible." msgstr "" +"Kerberos locator 外掛程式 <command>sssd_krb5_locator_plugin</command> 由 " +"libkrb5 用來尋找給定 Kerberos realm 的 KDC。SSSD 提供這種外掛程式,將系統上的" +"所有 Kerberos 用戶端引導到單一 KDC。一般來說,用戶端程序與哪個 KDC 通訊並不重" +"要。但在某些情況下(例如密碼變更之後),由於新資料必須先複寫,並非所有 KDC 都" +"處於相同狀態。為避免意外的驗證失敗,甚至帳戶鎖定,最好盡可能與單一 KDC 通訊。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:34 @@ -8342,6 +9524,14 @@ msgid "" "plugin. With this the plugin is still called but will provide no data to the " "caller so that libkrb5 can fall back to other methods defined in krb5.conf." msgstr "" +"libkrb5 會在 Kerberos 外掛程式目錄的 libkrb5 子目錄中搜尋 locator 外掛程式," +"詳情請參閱 <citerefentry> <refentrytitle>krb5.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> 中的 plugin_base_dir。外掛程式只能透" +"過移除外掛程式檔案來停用。Kerberos 設定中沒有可以停用它的選項。但可以使用 " +"SSSD_KRB5_LOCATOR_DISABLE 環境變數為個別指令停用外掛程式。另一種做法是使用 " +"SSSD 選項 krb5_use_kdcinfo=False,不要產生外掛程式需要的資料。這樣外掛程式仍" +"然會被呼叫,但不會提供任何資料給呼叫端,libkrb5 因此可以退回 krb5.conf 中定義" +"的其他方法。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:50 @@ -8353,36 +9543,40 @@ msgid "" "separated with a colon, the IPv6 address has to be enclosed in squared " "brackets in this case as usual. Valid entries are:" msgstr "" +"外掛程式會從名為 <filename>kdcinfo.REALM</filename> 的檔案讀取給定 realm 的 " +"KDC 資訊。檔案應包含一個或多個 DNS 名稱或 IP 位址,使用點十進位 IPv4 表示法或" +"十六進位 IPv6 表示法。可以將選用的連接埠號碼以冒號分隔加在結尾,這種情況下 " +"IPv6 位址必須照慣例以方括號括起來。有效的項目有:" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd_krb5_locator_plugin.8.xml:58 msgid "kdc.example.com" -msgstr "" +msgstr "kdc.example.com" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd_krb5_locator_plugin.8.xml:59 msgid "kdc.example.com:321" -msgstr "" +msgstr "kdc.example.com:321" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd_krb5_locator_plugin.8.xml:60 msgid "1.2.3.4" -msgstr "" +msgstr "1.2.3.4" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd_krb5_locator_plugin.8.xml:61 msgid "5.6.7.8:99" -msgstr "" +msgstr "5.6.7.8:99" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd_krb5_locator_plugin.8.xml:62 msgid "2001:db8:85a3::8a2e:370:7334" -msgstr "" +msgstr "2001:db8:85a3::8a2e:370:7334" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd_krb5_locator_plugin.8.xml:63 msgid "[2001:db8:85a3::8a2e:370:7334]:321" -msgstr "" +msgstr "[2001:db8:85a3::8a2e:370:7334]:321" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:65 @@ -8391,6 +9585,8 @@ msgid "" "adds the address of the current KDC or domain controller SSSD is using to " "this file." msgstr "" +"SSSD 的 krb5 auth-provider(IPA 與 AD 提供者也使用)會將 SSSD 目前使用的 KDC " +"或網域控制站位址加入此檔案。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:70 @@ -8404,6 +9600,11 @@ msgid "" "for the MIT Kerberos specific master KDC. If the address contains a port " "number the default KDC port 88 will be used for the latter." msgstr "" +"在同時具有唯讀與讀寫 KDC 的環境中(預期用戶端對一般作業使用唯讀執行個體,只對" +"密碼變更之類的設定變更使用讀寫 KDC),也會使用 <filename>kpasswdinfo.REALM</" +"filename> 來識別讀寫 KDC。若給定 realm 存在此檔案,外掛程式會使用其內容回覆 " +"kpasswd 或 kadmin 伺服器,或 MIT Kerberos 特定 master KDC 的要求。若位址包含" +"連接埠號碼,後者會使用預設的 KDC 連接埠 88。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:85 @@ -8412,13 +9613,16 @@ msgid "" "<command>sssd_krb5_locator_plugin</command> is not available on your system " "you have to edit /etc/krb5.conf to reflect your Kerberos setup." msgstr "" +"並非所有 Kerberos 實作都支援使用外掛程式。若您的系統沒有 <command>" +"sssd_krb5_locator_plugin</command>,您必須編輯 /etc/krb5.conf 以反映您的 " +"Kerberos 設定。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:91 msgid "" "If the environment variable SSSD_KRB5_LOCATOR_DEBUG is set to any value " "debug messages will be sent to stderr." -msgstr "" +msgstr "若 SSSD_KRB5_LOCATOR_DEBUG 環境變數設為任何值,除錯訊息會傳送到 stderr。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:95 @@ -8427,6 +9631,8 @@ msgid "" "the plugin is disabled and will just return KRB5_PLUGIN_NO_HANDLE to the " "caller." msgstr "" +"若 SSSD_KRB5_LOCATOR_DISABLE 環境變數設為任何值,外掛程式會被停用,只會向呼叫" +"端傳回 KRB5_PLUGIN_NO_HANDLE。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_locator_plugin.8.xml:100 @@ -8436,16 +9642,19 @@ msgid "" "default plugin returns KRB5_PLUGIN_NO_HANDLE to the caller immediately on " "first DNS resolving failure." msgstr "" +"若 SSSD_KRB5_LOCATOR_IGNORE_DNS_FAILURES 環境變數設為任何值,外掛程式會嘗試解" +"析 kdcinfo 檔案中的所有 DNS 名稱。預設情況下,外掛程式在第一次 DNS 解析失敗時" +"會立即向呼叫端傳回 KRB5_PLUGIN_NO_HANDLE。" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-simple.5.xml:10 sssd-simple.5.xml:16 msgid "sssd-simple" -msgstr "" +msgstr "sssd-simple" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-simple.5.xml:17 msgid "the configuration file for SSSD's 'simple' access-control provider" -msgstr "" +msgstr "SSSD 'simple' 存取控制提供者的設定檔" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-simple.5.xml:24 @@ -8457,6 +9666,10 @@ msgid "" "<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> manual page." msgstr "" +"本手冊頁說明 <citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>" +"8</manvolnum> </citerefentry> 之 simple 存取控制提供者的設定。詳細的語法參考" +"請參閱 <citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> 手冊頁的 <quote>FILE FORMAT</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-simple.5.xml:38 @@ -8464,11 +9677,13 @@ msgid "" "The simple access provider grants or denies access based on an access or " "deny list of user or group names. The following rules apply:" msgstr "" +"simple access 提供者根據使用者或群組名稱的允許或拒絕清單授予或拒絕存取。適用" +"下列規則:" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd-simple.5.xml:43 msgid "If all lists are empty, access is granted" -msgstr "" +msgstr "若所有清單都是空的,則授予存取權" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd-simple.5.xml:47 @@ -8476,6 +9691,8 @@ msgid "" "If any list is provided, the order of evaluation is allow,deny. This means " "that any matching deny rule will supersede any matched allow rule." msgstr "" +"若提供了任何清單,評估順序為 allow、deny。這表示任何相符的 deny 規則都會取代" +"任何相符的 allow 規則。" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd-simple.5.xml:54 @@ -8483,38 +9700,40 @@ msgid "" "If either or both \"allow\" lists are provided, all users are denied unless " "they appear in the list." msgstr "" +"若提供了其中一個或兩個 \"allow\" 清單,則所有使用者都會被拒絕,除非他們出現在" +"清單中。" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd-simple.5.xml:60 msgid "" "If only \"deny\" lists are provided, all users are granted access unless " "they appear in the list." -msgstr "" +msgstr "若只提供 \"deny\" 清單,則所有使用者都會被授予存取權,除非他們出現在清單中。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-simple.5.xml:78 msgid "simple_allow_users (string)" -msgstr "" +msgstr "simple_allow_users (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-simple.5.xml:81 msgid "Comma separated list of users who are allowed to log in." -msgstr "" +msgstr "允許登入之使用者的逗號分隔清單。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-simple.5.xml:88 msgid "simple_deny_users (string)" -msgstr "" +msgstr "simple_deny_users (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-simple.5.xml:91 msgid "Comma separated list of users who are explicitly denied access." -msgstr "" +msgstr "被明確拒絕存取之使用者的逗號分隔清單。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-simple.5.xml:97 msgid "simple_allow_groups (string)" -msgstr "" +msgstr "simple_allow_groups (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-simple.5.xml:100 @@ -8522,11 +9741,13 @@ msgid "" "Comma separated list of groups that are allowed to log in. This applies only " "to groups within this SSSD domain. Local groups are not evaluated." msgstr "" +"允許登入的群組清單,以逗號分隔。此設定僅適用於此 SSSD 網域內的群組。本機群組" +"不予評估。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-simple.5.xml:108 msgid "simple_deny_groups (string)" -msgstr "" +msgstr "simple_deny_groups (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-simple.5.xml:111 @@ -8535,6 +9756,8 @@ msgid "" "applies only to groups within this SSSD domain. Local groups are not " "evaluated." msgstr "" +"明確拒絕存取的群組清單,以逗號分隔。此設定僅適用於此 SSSD 網域內的群組。本機" +"群組不予評估。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-simple.5.xml:70 sssd-ipa.5.xml:83 sssd-ad.5.xml:131 @@ -8544,6 +9767,9 @@ msgid "" "</citerefentry> manual page for details on the configuration of an SSSD " "domain. <placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +"SSSD 網域設定的詳細資料請參閱 <citerefentry> <refentrytitle>sssd.conf</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 手冊頁的 <quote>" +"DOMAIN SECTIONS</quote> 一節。<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-simple.5.xml:120 @@ -8552,13 +9778,15 @@ msgid "" "entirely. Beware of this while generating parameters for the simple provider " "using automated scripts." msgstr "" +"不為任何清單指定值等同於完全跳過它。使用自動化指令碼為 simple 提供者產生參數" +"時,請注意這一點。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-simple.5.xml:125 msgid "" "Please note that it is an configuration error if both, simple_allow_users " "and simple_deny_users, are defined." -msgstr "" +msgstr "請注意,若同時定義 simple_allow_users 與 simple_deny_users,就是設定錯誤。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-simple.5.xml:133 @@ -8568,6 +9796,9 @@ msgid "" "section. This examples shows only the simple access provider-specific " "options." msgstr "" +"下列範例假設 SSSD 已正確設定,且 example.com 是 <replaceable>[sssd]</" +"replaceable> 區段中的其中一個網域。此範例只顯示 simple access 提供者專屬的選" +"項。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-simple.5.xml:140 @@ -8577,6 +9808,9 @@ msgid "" "access_provider = simple\n" "simple_allow_users = user1, user2\n" msgstr "" +"[domain/example.com]\n" +"access_provider = simple\n" +"simple_allow_users = user1, user2\n" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-simple.5.xml:150 @@ -8588,23 +9822,27 @@ msgid "" "<refentrytitle>sssd-ldap</refentrytitle><manvolnum>5</manvolnum> " "</citerefentry>) option." msgstr "" +"完整的群組成員階層會在存取檢查之前解析,因此即使是巢狀群組也可以包含在存取清" +"單中。請注意,<quote>ldap_group_nesting_level</quote> 選項可能影響結果,應設" +"為足夠的值。(<citerefentry> <refentrytitle>sssd-ldap</refentrytitle>" +"<manvolnum>5</manvolnum> </citerefentry>) 選項。" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss-certmap.5.xml:10 sss-certmap.5.xml:16 msgid "sss-certmap" -msgstr "" +msgstr "sss-certmap" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss-certmap.5.xml:17 msgid "SSSD Certificate Matching and Mapping Rules" -msgstr "" +msgstr "SSSD 憑證匹配與對應規則" #. type: Content of: <reference><refentry><refsect1><para> #: sss-certmap.5.xml:23 msgid "" "The manual page describes the rules which can be used by SSSD and other " "components to match X.509 certificates and map them to accounts." -msgstr "" +msgstr "本手冊頁說明 SSSD 與其他元件可以用來匹配 X.509 憑證並將它們對應到帳戶的規則。" #. type: Content of: <reference><refentry><refsect1><para> #: sss-certmap.5.xml:28 @@ -8619,6 +9857,13 @@ msgid "" "encoded binary. If no domains are given only the local domain will be " "searched." msgstr "" +"每個規則有四個組成部分:<quote>priority</quote>(優先順序)、<quote>matching " +"rule</quote>(匹配規則)、<quote>mapping rule</quote>(對應規則)與 <quote>" +"domain list</quote>(網域清單)。所有組成部分都是選用的。缺少 <quote>" +"priority</quote> 會以最低優先順序加入規則。預設的 <quote>matching rule</" +"quote> 會匹配具有 digitalSignature 金鑰用法與 clientAuth 擴充金鑰用法的憑證。" +"若 <quote>mapping rule</quote> 為空,會在 userCertificate 屬性中以 DER 編碼二" +"進位搜尋憑證。若未指定網域,只會搜尋本機網域。" #. type: Content of: <reference><refentry><refsect1><para> #: sss-certmap.5.xml:39 @@ -8630,6 +9875,10 @@ msgid "" "the default type will be used which is 'KRB5' for the matching rules and " "'LDAP' for the mapping rules." msgstr "" +"為了允許延伸或完全不同的規則樣式,<quote>mapping</quote> 與 <quote>matching " +"rules</quote> 可以包含一個前綴,以 ':' 與規則的主要部分分隔。前綴只能包含大" +"寫 ASCII 字母與數字。若省略前綴,會使用預設類型,即 matching rules 使用 " +"'KRB5'、mapping rules 使用 'LDAP'。" #. type: Content of: <reference><refentry><refsect1><para> #: sss-certmap.5.xml:48 @@ -8638,16 +9887,18 @@ msgid "" "given certificate matches a matching rules and how the output of a mapping " "rule would look like." msgstr "" +"'sssctl' 工具提供 'cert-eval-rule' 指令,可以檢查給定的憑證是否符合匹配規則," +"以及對應規則的輸出看起來如何。" #. type: Content of: <reference><refentry><refsect1><title> #: sss-certmap.5.xml:55 msgid "RULE COMPONENTS" -msgstr "" +msgstr "規則組成部分" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sss-certmap.5.xml:57 msgid "PRIORITY" -msgstr "" +msgstr "優先順序" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:59 @@ -8657,6 +9908,8 @@ msgid "" "missing value indicates the lowest priority. The rules processing is stopped " "when a matched rule is found and no further rules are checked." msgstr "" +"規則依優先順序處理,數字 '0'(零)表示最高優先順序。數字越大優先順序越低。缺" +"少值表示最低優先順序。找到相符的規則時,規則處理會停止,不再檢查其他規則。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:66 @@ -8664,6 +9917,8 @@ msgid "" "Internally the priority is treated as unsigned 32bit integer, using a " "priority value larger than 4294967295 will cause an error." msgstr "" +"內部會將優先順序視為無符號 32 位元整數,使用大於 4294967295 的優先順序值會導" +"致錯誤。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:70 @@ -8675,11 +9930,15 @@ msgid "" "or make the matching rules more specific e.g. by using distinct " "<ISSUER> patterns." msgstr "" +"若多個規則具有相同的優先順序,且只有其中一個相關匹配規則適用,則會選擇此規則" +"。若有多個相同優先順序的規則都匹配,會選擇其中一個,但選中哪一個未定義。為避" +"免這種未定義行為,請使用不同的優先順序,或讓匹配規則更具體,例如使用不同的 " +"<ISSUER> 模式。" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sss-certmap.5.xml:79 msgid "MATCHING RULE" -msgstr "" +msgstr "匹配規則" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:81 @@ -8692,6 +9951,10 @@ msgid "" "match. Multiple keyword pattern pairs can be either joined with '&&' " "(and) or '||' (or)." msgstr "" +"匹配規則用於選取應套用對應規則的憑證。它使用的系統類似 MIT Kerberos 的 " +"<quote>pkinit_cert_match</quote> 選項使用的系統。它由以 '<' 與 '>' 括起" +"來的關鍵字(識別憑證的特定部分)與模式(規則要匹配必須找到的內容)組成。多個" +"關鍵字模式配對可以以 '&&'(且)或 '||'(或)連接。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:90 @@ -8701,11 +9964,15 @@ msgid "" "rules</quote> so that \"<SUBJECT>.*,DC=MY,DC=DOMAIN\" and " "\"KRB5:<SUBJECT>.*,DC=MY,DC=DOMAIN\" are equivalent." msgstr "" +"鑑於與 MIT Kerberos 的相似性,此規則的類型前綴是 'KRB5'。但 'KRB5' 也會是 " +"<quote>matching rules</quote> 的預設值,因此 " +"\"<SUBJECT>.*,DC=MY,DC=DOMAIN\" 與 " +"\"KRB5:<SUBJECT>.*,DC=MY,DC=DOMAIN\" 是等價的。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:99 msgid "<SUBJECT>regular-expression" -msgstr "" +msgstr "<SUBJECT>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:102 @@ -8714,6 +9981,8 @@ msgid "" "matched. For the matching POSIX Extended Regular Expression syntax is used, " "see regex(7) for details." msgstr "" +"使用這個可以匹配憑證主旨名稱的一部分或全部。匹配使用 POSIX 延伸正規表示式語法" +",詳情請參閱 regex(7)。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:108 @@ -8727,11 +9996,16 @@ msgid "" "confusion those attribute names are best not used or covered by a suitable " "regular-expression." msgstr "" +"進行匹配時,儲存在憑證中 DER 編碼 ASN.1 的主旨名稱會依照 RFC 4514 轉換為字串" +"。這表示最具體的名稱組成部分會排在前面。請注意,RFC 4514 並未涵蓋所有可能的屬" +"性名稱。包含的名稱有 'CN'、'L'、'ST'、'O'、'OU'、'C'、'STREET'、'DC' 與 " +"'UID'。其他屬性名稱在不同平台與不同工具上可能顯示不同。為避免混淆,最好不要使" +"用這些屬性名稱,或使用合適的正規表示式涵蓋它們。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:121 msgid "Example: <SUBJECT>.*,DC=MY,DC=DOMAIN" -msgstr "" +msgstr "範例:<SUBJECT>.*,DC=MY,DC=DOMAIN" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:124 @@ -8740,16 +10014,18 @@ msgid "" "regular expressions and must be escaped with the help of the '\\' character " "so that they are matched as ordinary characters." msgstr "" +"請注意,\"^.[$()|*+?{\\\" 這些字元在正規表示式中有特殊意義,必須借助 '\\' 字" +"元逸出,才能當作一般字元匹配。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:130 msgid "Example: <SUBJECT>^CN=.* \\(Admin\\),DC=MY,DC=DOMAIN$" -msgstr "" +msgstr "範例:<SUBJECT>^CN=.* \\(Admin\\),DC=MY,DC=DOMAIN$" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:135 msgid "<ISSUER>regular-expression" -msgstr "" +msgstr "<ISSUER>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:138 @@ -8757,85 +10033,87 @@ msgid "" "With this a part or the whole issuer name of the certificate can be " "matched. All comments for <SUBJECT> apply her as well." msgstr "" +"使用這個可以匹配憑證簽發者名稱的一部分或全部。所有針對 <SUBJECT> 的註解" +"也適用於此。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:143 msgid "Example: <ISSUER>^CN=My-CA,DC=MY,DC=DOMAIN$" -msgstr "" +msgstr "範例:<ISSUER>^CN=My-CA,DC=MY,DC=DOMAIN$" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:148 msgid "<KU>key-usage" -msgstr "" +msgstr "<KU>key-usage" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:151 msgid "" "This option can be used to specify which key usage values the certificate " "should have. The following values can be used in a comma separated list:" -msgstr "" +msgstr "此選項可以用來指定憑證應具有哪些金鑰用法值。可以在逗號分隔清單中使用下列值:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:155 msgid "digitalSignature" -msgstr "" +msgstr "digitalSignature" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:156 msgid "nonRepudiation" -msgstr "" +msgstr "nonRepudiation" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:157 msgid "keyEncipherment" -msgstr "" +msgstr "keyEncipherment" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:158 msgid "dataEncipherment" -msgstr "" +msgstr "dataEncipherment" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:159 msgid "keyAgreement" -msgstr "" +msgstr "keyAgreement" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:160 msgid "keyCertSign" -msgstr "" +msgstr "keyCertSign" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:161 msgid "cRLSign" -msgstr "" +msgstr "cRLSign" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:162 msgid "encipherOnly" -msgstr "" +msgstr "encipherOnly" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:163 msgid "decipherOnly" -msgstr "" +msgstr "decipherOnly" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:167 msgid "" "A numerical value in the range of a 32bit unsigned integer can be used as " "well to cover special use cases." -msgstr "" +msgstr "也可以使用 32 位元無符號整數範圍內的數值,以涵蓋特殊使用案例。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:171 msgid "Example: <KU>digitalSignature,keyEncipherment" -msgstr "" +msgstr "範例:<KU>digitalSignature,keyEncipherment" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:176 msgid "<EKU>extended-key-usage" -msgstr "" +msgstr "<EKU>extended-key-usage" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:179 @@ -8843,68 +10121,70 @@ msgid "" "This option can be used to specify which extended key usage the certificate " "should have. The following value can be used in a comma separated list:" msgstr "" +"此選項可以用來指定憑證應具有哪些擴充金鑰用法。可以在逗號分隔清單中使用下列值" +":" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:183 msgid "serverAuth" -msgstr "" +msgstr "serverAuth" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:184 msgid "clientAuth" -msgstr "" +msgstr "clientAuth" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:185 msgid "codeSigning" -msgstr "" +msgstr "codeSigning" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:186 msgid "emailProtection" -msgstr "" +msgstr "emailProtection" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:187 msgid "timeStamping" -msgstr "" +msgstr "timeStamping" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:188 msgid "OCSPSigning" -msgstr "" +msgstr "OCSPSigning" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:189 msgid "KPClientAuth" -msgstr "" +msgstr "KPClientAuth" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:190 msgid "pkinit" -msgstr "" +msgstr "pkinit" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sss-certmap.5.xml:191 msgid "msScLogin" -msgstr "" +msgstr "msScLogin" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:195 msgid "" "Extended key usages which are not listed above can be specified with their " "OID in dotted-decimal notation." -msgstr "" +msgstr "未列於上方的擴充金鑰用法可以使用其 OID 以點十進位表示法指定。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:199 msgid "Example: <EKU>clientAuth,1.3.6.1.5.2.3.4" -msgstr "" +msgstr "範例:<EKU>clientAuth,1.3.6.1.5.2.3.4" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:204 msgid "<SAN>regular-expression" -msgstr "" +msgstr "<SAN>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:207 @@ -8913,61 +10193,63 @@ msgid "" "Kerberos principals in the PKINIT or AD NT Principal SAN as " "<SAN:Principal> does." msgstr "" +"為了與 MIT Kerberos 的用法相容,此選項會像 <SAN:Principal> 一樣匹配 " +"PKINIT 或 AD NT Principal SAN 中的 Kerberos principal。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:212 msgid "Example: <SAN>.*@MY\\.REALM" -msgstr "" +msgstr "範例:<SAN>.*@MY\\.REALM" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:217 msgid "<SAN:Principal>regular-expression" -msgstr "" +msgstr "<SAN:Principal>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:220 msgid "Match the Kerberos principals in the PKINIT or AD NT Principal SAN." -msgstr "" +msgstr "匹配 PKINIT 或 AD NT Principal SAN 中的 Kerberos principal。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:224 msgid "Example: <SAN:Principal>.*@MY\\.REALM" -msgstr "" +msgstr "範例:<SAN:Principal>.*@MY\\.REALM" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:229 msgid "<SAN:ntPrincipalName>regular-expression" -msgstr "" +msgstr "<SAN:ntPrincipalName>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:232 msgid "Match the Kerberos principals from the AD NT Principal SAN." -msgstr "" +msgstr "匹配 AD NT Principal SAN 中的 Kerberos principal。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:236 msgid "Example: <SAN:ntPrincipalName>.*@MY.AD.REALM" -msgstr "" +msgstr "範例:<SAN:ntPrincipalName>.*@MY.AD.REALM" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:241 msgid "<SAN:pkinit>regular-expression" -msgstr "" +msgstr "<SAN:pkinit>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:244 msgid "Match the Kerberos principals from the PKINIT SAN." -msgstr "" +msgstr "匹配 PKINIT SAN 中的 Kerberos principal。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:247 msgid "Example: <SAN:ntPrincipalName>.*@MY\\.PKINIT\\.REALM" -msgstr "" +msgstr "範例:<SAN:ntPrincipalName>.*@MY\\.PKINIT\\.REALM" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:252 msgid "<SAN:dotted-decimal-oid>regular-expression" -msgstr "" +msgstr "<SAN:dotted-decimal-oid>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:255 @@ -8976,16 +10258,18 @@ msgid "" "dotted-decimal notation, interpret it as string and try to match it against " "the regular expression." msgstr "" +"取以點十進位表示法之 OID 指定的 otherName SAN 組成部分值,將其解讀為字串,並" +"嘗試以正規表示式匹配它。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:261 msgid "Example: <SAN:1.2.3.4>test" -msgstr "" +msgstr "範例:<SAN:1.2.3.4>test" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:266 msgid "<SAN:otherName>base64-string" -msgstr "" +msgstr "<SAN:otherName>base64-string" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:269 @@ -8995,61 +10279,63 @@ msgid "" "otherName components with special encodings which could not be treated as " "strings." msgstr "" +"以 base64 編碼的 blob 對所有 otherName SAN 組成部分執行二進位匹配。使用此選項" +"可以匹配無法當作字串處理、具有特殊編碼的自訂 otherName 組成部分。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:276 msgid "Example: <SAN:otherName>MTIz" -msgstr "" +msgstr "範例:<SAN:otherName>MTIz" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:281 msgid "<SAN:rfc822Name>regular-expression" -msgstr "" +msgstr "<SAN:rfc822Name>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:284 msgid "Match the value of the rfc822Name SAN." -msgstr "" +msgstr "匹配 rfc822Name SAN 的值。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:287 msgid "Example: <SAN:rfc822Name>.*@email\\.domain" -msgstr "" +msgstr "範例:<SAN:rfc822Name>.*@email\\.domain" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:292 msgid "<SAN:dNSName>regular-expression" -msgstr "" +msgstr "<SAN:dNSName>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:295 msgid "Match the value of the dNSName SAN." -msgstr "" +msgstr "匹配 dNSName SAN 的值。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:298 msgid "Example: <SAN:dNSName>.*\\.my\\.dns\\.domain" -msgstr "" +msgstr "範例:<SAN:dNSName>.*\\.my\\.dns\\.domain" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:303 msgid "<SAN:x400Address>base64-string" -msgstr "" +msgstr "<SAN:x400Address>base64-string" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:306 msgid "Binary match the value of the x400Address SAN." -msgstr "" +msgstr "對 x400Address SAN 的值執行二進位匹配。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:309 msgid "Example: <SAN:x400Address>MTIz" -msgstr "" +msgstr "範例:<SAN:x400Address>MTIz" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:314 msgid "<SAN:directoryName>regular-expression" -msgstr "" +msgstr "<SAN:directoryName>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:317 @@ -9057,81 +10343,83 @@ msgid "" "Match the value of the directoryName SAN. The same comments as given for " "<ISSUER> and <SUBJECT> apply here as well." msgstr "" +"匹配 directoryName SAN 的值。針對 <ISSUER> 與 <SUBJECT> 提供的註" +"解也適用於此。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:322 msgid "Example: <SAN:directoryName>.*,DC=com" -msgstr "" +msgstr "範例:<SAN:directoryName>.*,DC=com" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:327 msgid "<SAN:ediPartyName>base64-string" -msgstr "" +msgstr "<SAN:ediPartyName>base64-string" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:330 msgid "Binary match the value of the ediPartyName SAN." -msgstr "" +msgstr "對 ediPartyName SAN 的值執行二進位匹配。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:333 msgid "Example: <SAN:ediPartyName>MTIz" -msgstr "" +msgstr "範例:<SAN:ediPartyName>MTIz" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:338 msgid "<SAN:uniformResourceIdentifier>regular-expression" -msgstr "" +msgstr "<SAN:uniformResourceIdentifier>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:341 msgid "Match the value of the uniformResourceIdentifier SAN." -msgstr "" +msgstr "匹配 uniformResourceIdentifier SAN 的值。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:344 msgid "Example: <SAN:uniformResourceIdentifier>URN:.*" -msgstr "" +msgstr "範例:<SAN:uniformResourceIdentifier>URN:.*" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:349 msgid "<SAN:iPAddress>regular-expression" -msgstr "" +msgstr "<SAN:iPAddress>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:352 msgid "Match the value of the iPAddress SAN." -msgstr "" +msgstr "匹配 iPAddress SAN 的值。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:355 msgid "Example: <SAN:iPAddress>192\\.168\\..*" -msgstr "" +msgstr "範例:<SAN:iPAddress>192\\.168\\..*" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:360 msgid "<SAN:registeredID>regular-expression" -msgstr "" +msgstr "<SAN:registeredID>regular-expression" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:363 msgid "Match the value of the registeredID SAN as dotted-decimal string." -msgstr "" +msgstr "以點十進位字串匹配 registeredID SAN 的值。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:367 msgid "Example: <SAN:registeredID>1\\.2\\.3\\..*" -msgstr "" +msgstr "範例:<SAN:registeredID>1\\.2\\.3\\..*" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:96 msgid "The available options are: <placeholder type=\"variablelist\" id=\"0\"/>" -msgstr "" +msgstr "可用的選項有:<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sss-certmap.5.xml:375 msgid "MAPPING RULE" -msgstr "" +msgstr "對應規則" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:377 @@ -9140,6 +10428,8 @@ msgid "" "accounts. A Smartcard with the certificate and the matching private key can " "then be used to authenticate as one of those accounts." msgstr "" +"對應規則用於將憑證與一個或多個帳戶關聯。之後可以使用包含憑證與相符私密金鑰的 " +"Smartcard,以其中一個帳戶身分驗證。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:382 @@ -9152,6 +10442,10 @@ msgid "" "caller will embed it in another filter to do the actual search. Because of " "this the filter string should start and stop with '(' and ')' respectively." msgstr "" +"目前 SSSD 基本上只支援使用 LDAP 查詢使用者資訊(例外是 proxy 提供者,但與此無" +"關)。因此,對應規則以 LDAP 搜尋篩選器語法為基礎,使用範本將憑證內容加入篩選" +"器。預期篩選器只會包含對應所需的特定資料,呼叫端會將它嵌入另一個篩選器來執行" +"實際搜尋。因此,篩選器字串應分別以 '(' 開始、以 ')' 結束。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:392 @@ -9161,6 +10455,8 @@ msgid "" "'altSecurityIdentities' attribute in AD or the 'ipaCertMapData' attribute " "for IPA can be used." msgstr "" +"一般建議使用憑證中的屬性,並將它們加入 LDAP 使用者物件的特殊屬性。例如可以使" +"用 AD 中的 'altSecurityIdentities' 屬性,或 IPA 的 'ipaCertMapData' 屬性。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:398 @@ -9171,6 +10467,9 @@ msgid "" "would break the mapping. On the other hand it would be hard to break the " "mapping on purpose for a specific user." msgstr "" +"這應該優先於從憑證讀取使用者特定資料(例如電子郵件地址)並在 LDAP 伺服器中搜" +"尋它。原因是 LDAP 中的使用者特定資料可能因為各種原因而變更,這會破壞對應。另" +"一方面,很難刻意為特定使用者破壞對應。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:406 @@ -9184,11 +10483,16 @@ msgid "" "the old version of this library will fail with a parsing error. The new " "templates are described in section <xref linkend=\"map_ldapu1\"/>." msgstr "" +"預設的 <quote>mapping rule</quote> 類型是 'LDAP',可以作為前綴加入規則,例如 " +"'LDAP:(userCertificate;binary={cert!bin})'。有一個名為 'LDAPU1' 的延伸提供更" +"多範本,以增加彈性。為了讓此程式庫的舊版本可以忽略此延伸,在 <quote>mapping " +"rule</quote> 中使用新範本時必須使用 'LDAPU1' 前綴,否則此程式庫的舊版本會以剖" +"析錯誤失敗。新範本說明於 <xref linkend=\"map_ldapu1\"/> 一節。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:424 msgid "{issuer_dn[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" -msgstr "" +msgstr "{issuer_dn[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:427 @@ -9197,27 +10501,29 @@ msgid "" "RFC 4514. If X.500 ordering (most specific RDN comes last) an option with " "the '_x500' prefix should be used." msgstr "" +"此範本會加入依照 RFC 4514 轉換為字串的完整簽發者 DN。若使用 X.500 排序(最具" +"體的 RDN 在最後),應使用帶有 '_x500' 前綴的選項。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:433 sss-certmap.5.xml:459 msgid "" "The conversion options starting with 'ad_' will use attribute names as used " "by AD, e.g. 'S' instead of 'ST'." -msgstr "" +msgstr "以 'ad_' 開頭的轉換選項會使用 AD 使用的屬性名稱,例如用 'S' 取代 'ST'。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:437 sss-certmap.5.xml:463 msgid "" "The conversion options starting with 'nss_' will use attribute names as used " "by NSS." -msgstr "" +msgstr "以 'nss_' 開頭的轉換選項會使用 NSS 使用的屬性名稱。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:441 sss-certmap.5.xml:467 msgid "" "The default conversion option is 'nss', i.e. attribute names according to " "NSS and LDAP/RFC 4514 ordering." -msgstr "" +msgstr "預設的轉換選項是 'nss',也就是依照 NSS 的屬性名稱與 LDAP/RFC 4514 排序。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:445 @@ -9225,11 +10531,12 @@ msgid "" "Example: " "(ipacertmapdata=X509:<I>{issuer_dn!ad}<S>{subject_dn!ad})" msgstr "" +"範例:(ipacertmapdata=X509:<I>{issuer_dn!ad}<S>{subject_dn!ad})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:450 msgid "{subject_dn[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" -msgstr "" +msgstr "{subject_dn[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:453 @@ -9238,6 +10545,8 @@ msgid "" "RFC 4514. If X.500 ordering (most specific RDN comes last) an option with " "the '_x500' prefix should be used." msgstr "" +"此範本會加入依照 RFC 4514 轉換為字串的完整主旨 DN。若使用 X.500 排序(最具體" +"的 RDN 在最後),應使用帶有 '_x500' 前綴的選項。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:471 @@ -9245,11 +10554,13 @@ msgid "" "Example: " "(ipacertmapdata=X509:<I>{issuer_dn!nss_x500}<S>{subject_dn!nss_x500})" msgstr "" +"範例:(ipacertmapdata=X509:<I>{issuer_dn!nss_x500}<S>" +"{subject_dn!nss_x500})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:476 msgid "{cert[!(bin|base64)]}" -msgstr "" +msgstr "{cert[!(bin|base64)]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:479 @@ -9260,16 +10571,19 @@ msgid "" "hex sequence is the default and can e.g. be used with the LDAP attribute " "'userCertificate;binary'." msgstr "" +"此範本會將整個 DER 編碼憑證以字串形式加入搜尋篩選器。視轉換選項而定,二進位憑" +"證會轉換為逸出十六進位序列 '\\xx' 或 base64。逸出十六進位序列是預設值,例如可" +"以與 LDAP 屬性 'userCertificate;binary' 一起使用。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:487 msgid "Example: (userCertificate;binary={cert!bin})" -msgstr "" +msgstr "範例:(userCertificate;binary={cert!bin})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:492 msgid "{subject_principal[.short_name]}" -msgstr "" +msgstr "{subject_principal[.short_name]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:495 @@ -9278,6 +10592,8 @@ msgid "" "SAN used by pkinit or the one used by AD. The 'short_name' component " "represents the first part of the principal before the '@' sign." msgstr "" +"此範本會加入從 pkinit 使用的 SAN 或 AD 使用的 SAN 取得的 Kerberos principal" +"。'short_name' 組成部分代表 principal 在 '@' 符號之前的第一部分。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:501 @@ -9285,11 +10601,13 @@ msgid "" "Example: " "(|(userPrincipal={subject_principal})(samAccountName={subject_principal.short_name}))" msgstr "" +"範例:(|(userPrincipal={subject_principal})(samAccountName=" +"{subject_principal.short_name}))" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:506 msgid "{subject_pkinit_principal[.short_name]}" -msgstr "" +msgstr "{subject_pkinit_principal[.short_name]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:509 @@ -9298,6 +10616,8 @@ msgid "" "by pkinit. The 'short_name' component represents the first part of the " "principal before the '@' sign." msgstr "" +"此範本會加入由 pkinit 使用的 SAN 提供的 Kerberos principal。'short_name' 組成" +"部分代表 principal 在 '@' 符號之前的第一部分。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:515 @@ -9305,11 +10625,13 @@ msgid "" "Example: " "(|(userPrincipal={subject_pkinit_principal})(uid={subject_pkinit_principal.short_name}))" msgstr "" +"範例:(|(userPrincipal={subject_pkinit_principal})(uid=" +"{subject_pkinit_principal.short_name}))" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:520 msgid "{subject_nt_principal[.short_name]}" -msgstr "" +msgstr "{subject_nt_principal[.short_name]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:523 @@ -9318,6 +10640,8 @@ msgid "" "by AD. The 'short_name' component represent the first part of the principal " "before the '@' sign." msgstr "" +"此範本會加入由 AD 使用的 SAN 提供的 Kerberos principal。'short_name' 組成部分" +"代表 principal 在 '@' 符號之前的第一部分。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:529 @@ -9325,11 +10649,13 @@ msgid "" "Example: " "(|(userPrincipalName={subject_nt_principal})(samAccountName={subject_nt_principal.short_name}))" msgstr "" +"範例:(|(userPrincipalName={subject_nt_principal})(samAccountName=" +"{subject_nt_principal.short_name}))" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:534 msgid "{subject_rfc822_name[.short_name]}" -msgstr "" +msgstr "{subject_rfc822_name[.short_name]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:537 @@ -9338,6 +10664,8 @@ msgid "" "component of the SAN, typically an email address. The 'short_name' component " "represents the first part of the address before the '@' sign." msgstr "" +"此範本會加入儲存在 SAN 之 rfc822Name 組成部分中的字串,通常是電子郵件地址" +"。'short_name' 組成部分代表地址在 '@' 符號之前的第一部分。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:543 @@ -9345,11 +10673,12 @@ msgid "" "Example: " "(|(mail={subject_rfc822_name})(uid={subject_rfc822_name.short_name}))" msgstr "" +"範例:(|(mail={subject_rfc822_name})(uid={subject_rfc822_name.short_name}))" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:548 msgid "{subject_dns_name[.short_name]}" -msgstr "" +msgstr "{subject_dns_name[.short_name]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:551 @@ -9358,113 +10687,116 @@ msgid "" "of the SAN, typically a fully-qualified host name. The 'short_name' " "component represents the first part of the name before the first '.' sign." msgstr "" +"此範本會加入儲存在 SAN 之 dNSName 組成部分中的字串,通常是完整主機名稱" +"。'short_name' 組成部分代表名稱在第一個 '.' 符號之前的第一部分。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:557 msgid "Example: (|(fqdn={subject_dns_name})(host={subject_dns_name.short_name}))" -msgstr "" +msgstr "範例:(|(fqdn={subject_dns_name})(host={subject_dns_name.short_name}))" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:562 msgid "{subject_uri}" -msgstr "" +msgstr "{subject_uri}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:565 msgid "" "This template will add the string which is stored in the " "uniformResourceIdentifier component of the SAN." -msgstr "" +msgstr "此範本會加入儲存在 SAN 之 uniformResourceIdentifier 組成部分中的字串。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:569 msgid "Example: (uri={subject_uri})" -msgstr "" +msgstr "範例:(uri={subject_uri})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:574 msgid "{subject_ip_address}" -msgstr "" +msgstr "{subject_ip_address}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:577 msgid "" "This template will add the string which is stored in the iPAddress component " "of the SAN." -msgstr "" +msgstr "此範本會加入儲存在 SAN 之 iPAddress 組成部分中的字串。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:581 msgid "Example: (ip={subject_ip_address})" -msgstr "" +msgstr "範例:(ip={subject_ip_address})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:586 msgid "{subject_x400_address}" -msgstr "" +msgstr "{subject_x400_address}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:589 msgid "" "This template will add the value which is stored in the x400Address " "component of the SAN as escaped hex sequence." -msgstr "" +msgstr "此範本會將儲存在 SAN 之 x400Address 組成部分中的值以逸出十六進位序列加入。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:594 msgid "Example: (attr:binary={subject_x400_address})" -msgstr "" +msgstr "範例:(attr:binary={subject_x400_address})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:599 msgid "{subject_directory_name[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" msgstr "" +"{subject_directory_name[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:602 msgid "" "This template will add the DN string of the value which is stored in the " "directoryName component of the SAN." -msgstr "" +msgstr "此範本會加入儲存在 SAN 之 directoryName 組成部分中值的 DN 字串。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:606 msgid "Example: (orig_dn={subject_directory_name})" -msgstr "" +msgstr "範例:(orig_dn={subject_directory_name})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:611 msgid "{subject_ediparty_name}" -msgstr "" +msgstr "{subject_ediparty_name}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:614 msgid "" "This template will add the value which is stored in the ediPartyName " "component of the SAN as escaped hex sequence." -msgstr "" +msgstr "此範本會將儲存在 SAN 之 ediPartyName 組成部分中的值以逸出十六進位序列加入。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:619 msgid "Example: (attr:binary={subject_ediparty_name})" -msgstr "" +msgstr "範例:(attr:binary={subject_ediparty_name})" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:624 msgid "{subject_registered_id}" -msgstr "" +msgstr "{subject_registered_id}" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:627 msgid "" "This template will add the OID which is stored in the registeredID component " "of the SAN as a dotted-decimal string." -msgstr "" +msgstr "此範本會將儲存在 SAN 之 registeredID 組成部分中的 OID 以點十進位字串加入。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:632 msgid "Example: (oid={subject_registered_id})" -msgstr "" +msgstr "範例:(oid={subject_registered_id})" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:417 @@ -9475,28 +10807,31 @@ msgid "" "conversion/formatting option separated by a '!'. Allowed values are: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +"用來將憑證資料加入搜尋篩選器的範本以 Python 樣式格式化字串為基礎。它們由大括" +"號中的關鍵字組成,並帶有以 '.' 分隔的選用子組成部分指定符,或以 '!' 分隔的選" +"用轉換/格式化選項。允許的值有:<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><title> #: sss-certmap.5.xml:639 msgid "LDAPU1 extension" -msgstr "" +msgstr "LDAPU1 延伸" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para> #: sss-certmap.5.xml:641 msgid "The following template are available when using the 'LDAPU1' extension:" -msgstr "" +msgstr "使用 'LDAPU1' 延伸時,可以使用下列範本:" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:647 msgid "{serial_number[!(dec|hex[_ucr])]}" -msgstr "" +msgstr "{serial_number[!(dec|hex[_ucr])]}" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:650 msgid "" "This template will add the serial number of the certificate. By default it " "will be printed as a hexadecimal number with lower-case letters." -msgstr "" +msgstr "此範本會加入憑證的序號。預設會以小寫字母的十六進位數字列印。" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:655 @@ -9508,23 +10843,27 @@ msgid "" "be combined so that e.g. '!hex_uc' will produce a colon-separated " "hexadecimal string with upper-case letters." msgstr "" +"使用 '!dec' 格式化選項時,數字會以十進位字串列印。十六進位輸出可以以大寫字母 " +"('!hex_u')、以冒號分隔十六進位位元組 ('!hex_c') 或十六進位位元組反序 " +"('!hex_r') 列印。後綴字母可以組合,例如 '!hex_uc' 會產生以大寫字母呈現、冒號" +"分隔的十六進位字串。" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:665 msgid "Example: LDAPU1:(serial={serial_number})" -msgstr "" +msgstr "範例:LDAPU1:(serial={serial_number})" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:671 msgid "{subject_key_id[!hex[_ucr]]}" -msgstr "" +msgstr "{subject_key_id[!hex[_ucr]]}" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:674 msgid "" "This template will add the subject key id of the certificate. By default it " "will be printed as a hexadecimal number with lower-case letters." -msgstr "" +msgstr "此範本會加入憑證的主旨金鑰 ID。預設會以小寫字母的十六進位數字印出。" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:679 @@ -9535,16 +10874,19 @@ msgid "" "combined so that e.g. '!hex_uc' will produce a colon-separated hexadecimal " "string with upper-case letters." msgstr "" +"十六進位輸出可以以大寫字母 ('!hex_u')、以冒號分隔十六進位位元組 ('!hex_c') 或" +"十六進位位元組反序 ('!hex_r') 列印。後綴字母可以組合,例如 '!hex_uc' 會產生以" +"大寫字母呈現、冒號分隔的十六進位字串。" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:688 msgid "Example: LDAPU1:(ski={subject_key_id})" -msgstr "" +msgstr "範例:LDAPU1:(ski={subject_key_id})" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:694 msgid "{cert[!DIGEST[_ucr]]}" -msgstr "" +msgstr "{cert[!DIGEST[_ucr]]}" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:697 @@ -9553,6 +10895,8 @@ msgid "" "DIGEST must be replaced with the name of a digest/hash function supported by " "OpenSSL, e.g. 'sha512'." msgstr "" +"此範本會加入憑證的十六進位摘要/雜湊,其中 DIGEST 必須替換為 OpenSSL 支援之摘" +"要/雜湊函式的名稱,例如 'sha512'。" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:703 @@ -9563,23 +10907,26 @@ msgid "" "combined so that e.g. '!sha512_uc' will produce a colon-separated " "hexadecimal string with upper-case letters." msgstr "" +"十六進位輸出可以以大寫字母 ('!sha512_u')、以冒號分隔十六進位位元組 " +"('!sha512_c') 或十六進位位元組反序 ('!sha512_r') 列印。後綴字母可以組合,例" +"如 '!sha512_uc' 會產生以大寫字母呈現、冒號分隔的十六進位字串。" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:712 msgid "Example: LDAPU1:(dgst={cert!sha256})" -msgstr "" +msgstr "範例:LDAPU1:(dgst={cert!sha256})" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:718 msgid "{subject_dn_component[(.attr_name|[number]]}" -msgstr "" +msgstr "{subject_dn_component[(.attr_name|[number]]}" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:721 msgid "" "This template will add an attribute value of a component of the subject DN, " "by default the value of the most specific component." -msgstr "" +msgstr "此範本會加入主旨 DN 某個組成部分的屬性值,預設為最具體組成部分的值。" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:726 @@ -9592,30 +10939,34 @@ msgid "" "e.g. {subject_dn_component.uid[2]} which means that the name of the second " "component must be 'uid'." msgstr "" +"可以依屬性名稱選取不同的組成部分,例如 {subject_dn_component.uid},或依位置選" +"取,例如 {subject_dn_component.[2]},其中正數從最具體的組成部分開始計算,負數" +"從最不具體的組成部分開始計算。屬性名稱與位置可以組合,例如 " +"{subject_dn_component.uid[2]},表示第二個組成部分的名稱必須是 'uid'。" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:737 msgid "Example: LDAPU1:(uid={subject_dn_component.uid})" -msgstr "" +msgstr "範例:LDAPU1:(uid={subject_dn_component.uid})" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:743 msgid "{issuer_dn_component[(.attr_name|[number]]}" -msgstr "" +msgstr "{issuer_dn_component[(.attr_name|[number]]}" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:746 msgid "" "This template will add an attribute value of a component of the issuer DN, " "by default the value of the most specific component." -msgstr "" +msgstr "此範本會加入簽發者 DN 某個組成部分的屬性值,預設為最具體組成部分的值。" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:751 msgid "" "See 'subject_dn_component' for details about the attribute name and position " "specifiers." -msgstr "" +msgstr "屬性名稱與位置指定符的詳細資料請參閱 'subject_dn_component'。" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:755 @@ -9623,11 +10974,12 @@ msgid "" "Example: " "LDAPU1:(domain={issuer_dn_component.[-2]}.{issuer_dn_component.dc[-1]})" msgstr "" +"範例:LDAPU1:(domain={issuer_dn_component.[-2]}.{issuer_dn_component.dc[-1]})" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><term> #: sss-certmap.5.xml:760 msgid "{sid[.rid]}" -msgstr "" +msgstr "{sid[.rid]}" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:763 @@ -9636,16 +10988,18 @@ msgid "" "Microsoft with the OID 1.3.6.1.4.1.311.25.2 is available. With the '.rid' " "selector only the last component, i.e. the RID, will be added." msgstr "" +"若 Microsoft 以 OID 1.3.6.1.4.1.311.25.2 引入的對應延伸可用,此範本會加入 SID" +"。使用 '.rid' 選取器時,只會加入最後一個組成部分,也就是 RID。" #. type: Content of: <reference><refentry><refsect1><refsect2><refsect3><para><variablelist><varlistentry><listitem><para> #: sss-certmap.5.xml:770 msgid "Example: LDAPU1:(objectsid={sid})" -msgstr "" +msgstr "範例:LDAPU1:(objectsid={sid})" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sss-certmap.5.xml:779 msgid "DOMAIN LIST" -msgstr "" +msgstr "網域清單" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss-certmap.5.xml:781 @@ -9654,16 +11008,18 @@ msgid "" "only searched in the local domain but in the listed domains as well as long " "as they are know by SSSD. Domains not know to SSSD will be ignored." msgstr "" +"若網域清單不是空的,對應到給定憑證的使用者不只會在網域本機中搜尋,只要 SSSD " +"知道列出的網域,也會在這些網域中搜尋。SSSD 不知道的網域會被忽略。" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-ipa.5.xml:10 sssd-ipa.5.xml:16 msgid "sssd-ipa" -msgstr "" +msgstr "sssd-ipa" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-ipa.5.xml:17 msgid "SSSD IPA provider" -msgstr "" +msgstr "SSSD IPA 提供者" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:23 @@ -9675,6 +11031,10 @@ msgid "" "<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> manual page." msgstr "" +"本手冊頁說明 <citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>" +"8</manvolnum> </citerefentry> 之 IPA 提供者的設定。詳細的語法參考請參閱 " +"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> 手冊頁的 <quote>FILE FORMAT</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:36 @@ -9684,6 +11044,9 @@ msgid "" "requires that the machine be joined to the IPA domain; configuration is " "almost entirely self-discovered and obtained directly from the server." msgstr "" +"IPA 提供者是用來連線到 IPA 伺服器的後端。(IPA 伺服器的相關資訊請參閱 " +"freeipa.org 網站。)此提供者要求機器加入 IPA 網域;設定幾乎完全自動探索,並直" +"接從伺服器取得。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:43 @@ -9697,6 +11060,12 @@ msgid "" "sssd-ldap and sssd-krb5 providers with some exceptions. However, it is " "neither necessary nor recommended to set these options." msgstr "" +"IPA 提供者讓 SSSD 可以使用 <citerefentry> <refentrytitle>sssd-ldap</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 身分提供者與 " +"<citerefentry> <refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> 驗證提供者,並針對 IPA 環境最佳化。IPA 提供者接受 " +"sssd-ldap 與 sssd-krb5 提供者使用的相同選項,但有一些例外。不過,設定這些選項" +"既非必要也不建議。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:57 @@ -9705,6 +11074,8 @@ msgid "" "default options with some exceptions, the differences are listed in the " "<quote>MODIFIED DEFAULT OPTIONS</quote> section." msgstr "" +"IPA 提供者主要複製傳統 ldap 與 krb5 提供者的預設選項,但有一些例外,差異列於 " +"<quote>MODIFIED DEFAULT OPTIONS</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:62 @@ -9713,6 +11084,9 @@ msgid "" "<quote>ipa_access_order</quote>) as it mainly uses HBAC (host-based access " "control) rules. Please refer to freeipa.org for more information about HBAC." msgstr "" +"作為 access 提供者,IPA 提供者的設定最少(請參閱 <quote>ipa_access_order</" +"quote>),因為它主要使用 HBAC(主機型存取控制)規則。HBAC 的更多資訊請參閱 " +"freeipa.org。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:68 @@ -9721,6 +11095,8 @@ msgid "" "configured in sssd.conf then the id_provider must also be set to " "<quote>ipa</quote>." msgstr "" +"若在 sssd.conf 中設定 <quote>auth_provider=ipa</quote> 或 <quote>" +"access_provider=ipa</quote>,則 id_provider 也必須設為 <quote>ipa</quote>。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:74 @@ -9729,23 +11105,25 @@ msgid "" "from trusted realms contain a PAC. To make configuration easier the PAC " "responder is started automatically if the IPA ID provider is configured." msgstr "" +"若來自受信任 realm 之使用者的 Kerberos 票證包含 PAC,IPA 提供者會使用 PAC " +"responder。為簡化設定,若設定了 IPA ID 提供者,PAC responder 會自動啟動。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:90 msgid "ipa_domain (string)" -msgstr "" +msgstr "ipa_domain (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:93 msgid "" "Specifies the name of the IPA domain. This is optional. If not provided, " "the configuration domain name is used." -msgstr "" +msgstr "指定 IPA 網域名稱。這是選用的。若未提供,則使用設定網域名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:101 msgid "ipa_server, ipa_backup_server (string)" -msgstr "" +msgstr "ipa_server, ipa_backup_server (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:104 @@ -9756,11 +11134,15 @@ msgid "" "This is optional if autodiscovery is enabled. For more information on " "service discovery, refer to the <quote>SERVICE DISCOVERY</quote> section." msgstr "" +"SSSD 應依偏好順序連線之 IPA 伺服器的 IP 位址或主機名稱逗號分隔清單。有關故障" +"轉移與伺服器備援的更多資訊,請參閱 <quote>FAILOVER</quote> 一節。若啟用自動探" +"索,此選項是選用的。服務探索的更多資訊請參閱 <quote>SERVICE DISCOVERY</" +"quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:117 msgid "ipa_hostname (string)" -msgstr "" +msgstr "ipa_hostname (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:120 @@ -9769,11 +11151,13 @@ msgid "" "fully qualified name used in the IPA domain to identify this host. The " "hostname must be fully qualified." msgstr "" +"選用。可以設定在主機名稱 (hostname(5)) 未反映 IPA 網域中用來識別此主機之完整" +"名稱的機器上。主機名稱必須是完整的。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:129 sssd-ad.5.xml:1182 msgid "dyndns_update (boolean)" -msgstr "" +msgstr "dyndns_update (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:132 @@ -9784,6 +11168,9 @@ msgid "" "updates, if it is not otherwise specified by using the " "<quote>dyndns_iface</quote> option." msgstr "" +"選用。此選項告訴 SSSD 自動以本用戶端的 IP 位址更新 FreeIPA 內建的 DNS 伺服器" +"。更新使用 GSS-TSIG 保護。若未使用 <quote>dyndns_iface</quote> 選項另行指定," +"則使用 IPA LDAP 連線的 IP 位址進行更新。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:141 sssd-ad.5.xml:1196 @@ -9791,6 +11178,8 @@ msgid "" "NOTE: On older systems (such as RHEL 5), for this behavior to work reliably, " "the default Kerberos realm must be set properly in /etc/krb5.conf" msgstr "" +"注意:在較舊的系統(例如 RHEL 5)上,此行為要可靠運作,必須在 /etc/krb5.conf " +"中正確設定預設的 Kerberos realm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:146 @@ -9799,11 +11188,13 @@ msgid "" "<emphasis>ipa_dyndns_update</emphasis> option, users should migrate to using " "<emphasis>dyndns_update</emphasis> in their config file." msgstr "" +"注意:雖然仍然可以使用舊的 <emphasis>ipa_dyndns_update</emphasis> 選項,但使" +"用者應在設定檔中遷移為使用 <emphasis>dyndns_update</emphasis>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:158 sssd-ad.5.xml:1207 msgid "dyndns_ttl (integer)" -msgstr "" +msgstr "dyndns_ttl (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:161 sssd-ad.5.xml:1210 @@ -9812,6 +11203,8 @@ msgid "" "dyndns_update is false this has no effect. This will override the TTL " "serverside if set by an administrator." msgstr "" +"更新用戶端 DNS 記錄時套用的 TTL。若 dyndns_update 為 false,這沒有作用。若管" +"理員設定了伺服器端 TTL,此值會覆寫它。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:166 @@ -9820,16 +11213,18 @@ msgid "" "<emphasis>ipa_dyndns_ttl</emphasis> option, users should migrate to using " "<emphasis>dyndns_ttl</emphasis> in their config file." msgstr "" +"注意:雖然仍然可以使用舊的 <emphasis>ipa_dyndns_ttl</emphasis> 選項,但使用者" +"應在設定檔中遷移為使用 <emphasis>dyndns_ttl</emphasis>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:172 msgid "Default: 1200 (seconds)" -msgstr "" +msgstr "預設:1200(秒)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:178 sssd-ad.5.xml:1221 msgid "dyndns_iface (string)" -msgstr "" +msgstr "dyndns_iface (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:181 sssd-ad.5.xml:1224 @@ -9839,6 +11234,8 @@ msgid "" "updates. Special value <quote>*</quote> implies that IPs from all interfaces " "should be used." msgstr "" +"選用。只在 dyndns_update 為 true 時適用。選擇其 IP 位址應用於動態 DNS 更新的" +"介面或介面清單。特殊值 <quote>*</quote> 表示應使用所有介面的 IP。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:188 @@ -9847,23 +11244,25 @@ msgid "" "<emphasis>ipa_dyndns_iface</emphasis> option, users should migrate to using " "<emphasis>dyndns_iface</emphasis> in their config file." msgstr "" +"注意:雖然仍然可以使用舊的 <emphasis>ipa_dyndns_iface</emphasis> 選項,但使用" +"者應在設定檔中遷移為使用 <emphasis>dyndns_iface</emphasis>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:194 msgid "" "Default: Use the IP addresses of the interface which is used for IPA LDAP " "connection" -msgstr "" +msgstr "預設:使用用於 IPA LDAP 連線之介面的 IP 位址" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:198 sssd-ad.5.xml:1235 msgid "Example: dyndns_iface = em1, vnet1, vnet2" -msgstr "" +msgstr "範例:dyndns_iface = em1, vnet1, vnet2" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:204 sssd-ad.5.xml:1291 msgid "dyndns_auth (string)" -msgstr "" +msgstr "dyndns_auth (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:207 sssd-ad.5.xml:1294 @@ -9872,16 +11271,18 @@ msgid "" "updates with the DNS server, insecure updates can be sent by setting this " "option to 'none'." msgstr "" +"nsupdate 工具是否應使用 GSS-TSIG 驗證與 DNS 伺服器進行安全更新,可以將此選項" +"設為 'none' 來傳送不安全的更新。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:213 sssd-ad.5.xml:1300 msgid "Default: GSS-TSIG" -msgstr "" +msgstr "預設:GSS-TSIG" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:219 sssd-ad.5.xml:1306 msgid "dyndns_auth_ptr (string)" -msgstr "" +msgstr "dyndns_auth_ptr (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:222 sssd-ad.5.xml:1309 @@ -9890,21 +11291,23 @@ msgid "" "PTR updates with the DNS server, insecure updates can be sent by setting " "this option to 'none'." msgstr "" +"nsupdate 工具是否應使用 GSS-TSIG 驗證與 DNS 伺服器進行安全 PTR 更新,可以將此" +"選項設為 'none' 來傳送不安全的更新。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:228 sssd-ad.5.xml:1315 msgid "Default: Same as dyndns_auth" -msgstr "" +msgstr "預設:與 dyndns_auth 相同" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:234 msgid "ipa_enable_dns_sites (boolean)" -msgstr "" +msgstr "ipa_enable_dns_sites (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:237 sssd-ad.5.xml:238 msgid "Enables DNS sites - location based service discovery." -msgstr "" +msgstr "啟用 DNS sites - 以位置為基礎的服務探索。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:241 @@ -9918,11 +11321,16 @@ msgid "" "servers located using the traditional SRV discovery are used as back up " "servers" msgstr "" +"若為 true 且啟用服務探索(請參閱手冊頁底部的 Service Discovery 段落),SSSD " +"會先嘗試使用包含 \"_location.hostname.example.com\" 的查詢進行以位置為基礎的" +"探索,然後退回傳統的 SRV 探索。若以位置為基礎的探索成功,以位置為基礎的探索找" +"到的 IPA 伺服器會被視為主要伺服器,使用傳統 SRV 探索找到的 IPA 伺服器會被用作" +"備份伺服器" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:260 sssd-ad.5.xml:1241 msgid "dyndns_refresh_interval (integer)" -msgstr "" +msgstr "dyndns_refresh_interval (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:263 @@ -9931,11 +11339,13 @@ msgid "" "automatic update performed when the back end goes online. This option is " "optional and applicable only when dyndns_update is true." msgstr "" +"除了後端上線時執行的自動更新之外,後端應多久執行一次週期性 DNS 更新。此選項是" +"選用的,只在 dyndns_update 為 true 時適用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:276 sssd-ad.5.xml:1259 msgid "dyndns_update_ptr (bool)" -msgstr "" +msgstr "dyndns_update_ptr (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:279 sssd-ad.5.xml:1262 @@ -9943,6 +11353,8 @@ msgid "" "Whether the PTR record should also be explicitly updated when updating the " "client's DNS records. Applicable only when dyndns_update is true." msgstr "" +"更新用戶端的 DNS 記錄時,是否也應明確更新 PTR 記錄。只在 dyndns_update 為 " +"true 時適用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:284 @@ -9950,6 +11362,8 @@ msgid "" "This option should be False in most IPA deployments as the IPA server " "generates the PTR records automatically when forward records are changed." msgstr "" +"在大多數 IPA 部署中,此選項應為 False,因為 IPA 伺服器會在正向記錄變更時自動" +"產生 PTR 記錄。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:290 sssd-ad.5.xml:1267 @@ -9957,64 +11371,66 @@ msgid "" "Note that <emphasis>dyndns_update_per_family</emphasis> parameter does not " "apply for PTR record updates. Those updates are always sent separately." msgstr "" +"請注意,<emphasis>dyndns_update_per_family</emphasis> 參數不適用於 PTR 記錄更" +"新。這些更新一律分別傳送。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:295 msgid "Default: False (disabled)" -msgstr "" +msgstr "預設:False(停用)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:301 sssd-ad.5.xml:1278 msgid "dyndns_force_tcp (bool)" -msgstr "" +msgstr "dyndns_force_tcp (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:304 sssd-ad.5.xml:1281 msgid "" "Whether the nsupdate utility should default to using TCP for communicating " "with the DNS server." -msgstr "" +msgstr "nsupdate 工具是否應預設使用 TCP 與 DNS 伺服器通訊。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:308 sssd-ad.5.xml:1285 msgid "Default: False (let nsupdate choose the protocol)" -msgstr "" +msgstr "預設:False(讓 nsupdate 選擇協定)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:314 sssd-ad.5.xml:1321 msgid "dyndns_server (string)" -msgstr "" +msgstr "dyndns_server (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:317 sssd-ad.5.xml:1324 msgid "" "The DNS server to use when performing a DNS update. In most setups, it's " "recommended to leave this option unset." -msgstr "" +msgstr "執行 DNS 更新時使用的 DNS 伺服器。在大多數設定中,建議讓此選項保持未設定。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:322 sssd-ad.5.xml:1329 msgid "" "Setting this option makes sense for environments where the DNS server is " "different from the identity server." -msgstr "" +msgstr "在 DNS 伺服器與身分伺服器不同的環境中,設定此選項才有意義。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:327 sssd-ad.5.xml:1334 msgid "" "Please note that this option will be only used in fallback attempt when " "previous attempt using autodetected settings failed." -msgstr "" +msgstr "請注意,此選項只會在先前使用自動偵測設定的嘗試失敗時,用於退回嘗試。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:332 sssd-ad.5.xml:1339 msgid "Default: None (let nsupdate choose the server)" -msgstr "" +msgstr "預設:None(讓 nsupdate 選擇伺服器)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:338 sssd-ad.5.xml:1345 msgid "dyndns_update_per_family (boolean)" -msgstr "" +msgstr "dyndns_update_per_family (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:341 sssd-ad.5.xml:1348 @@ -10023,139 +11439,141 @@ msgid "" "update. In some cases it might be desirable to perform IPv4 and IPv6 update " "in single step." msgstr "" +"DNS 更新預設分兩個步驟執行 - 先 IPv4 更新,再 IPv6 更新。在某些情況下,可能希" +"望單一步驟執行 IPv4 與 IPv6 更新。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:353 msgid "ipa_access_order (string)" -msgstr "" +msgstr "ipa_access_order (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:360 msgid "<emphasis>expire</emphasis>: use IPA's account expiration policy." -msgstr "" +msgstr "<emphasis>expire</emphasis>:使用 IPA 的帳戶到期原則。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:399 msgid "" "Please note that 'access_provider = ipa' must be set for this feature to " "work." -msgstr "" +msgstr "請注意,此功能要運作必須設定 'access_provider = ipa'。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:406 msgid "ipa_deskprofile_search_base (string)" -msgstr "" +msgstr "ipa_deskprofile_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:409 msgid "" "Optional. Use the given string as search base for Desktop Profile related " "objects." -msgstr "" +msgstr "選用。使用指定的字串作為桌面設定檔相關物件的搜尋基礎。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:413 sssd-ipa.5.xml:440 msgid "Default: Use base DN" -msgstr "" +msgstr "預設:使用基礎 DN" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:419 msgid "ipa_subid_ranges_search_base (string)" -msgstr "" +msgstr "ipa_subid_ranges_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:422 msgid "" "Optional. Use the given string as search base for subordinate ranges related " "objects." -msgstr "" +msgstr "選用。使用指定的字串作為下屬範圍相關物件的搜尋基礎。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:426 msgid "Default: the value of <emphasis>cn=subids,%basedn</emphasis>" -msgstr "" +msgstr "預設:<emphasis>cn=subids,%basedn</emphasis> 的值" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:433 msgid "ipa_hbac_search_base (string)" -msgstr "" +msgstr "ipa_hbac_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:436 msgid "Optional. Use the given string as search base for HBAC related objects." -msgstr "" +msgstr "選用。使用指定的字串作為 HBAC 相關物件的搜尋基礎。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:446 msgid "ipa_host_search_base (string)" -msgstr "" +msgstr "ipa_host_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:449 msgid "Deprecated. Use ldap_host_search_base instead." -msgstr "" +msgstr "已棄用。請改用 ldap_host_search_base。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:455 msgid "ipa_selinux_search_base (string)" -msgstr "" +msgstr "ipa_selinux_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:458 msgid "Optional. Use the given string as search base for SELinux user maps." -msgstr "" +msgstr "選用。使用指定的字串作為 SELinux 使用者對應表的搜尋基礎。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:474 msgid "ipa_subdomains_search_base (string)" -msgstr "" +msgstr "ipa_subdomains_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:477 msgid "Optional. Use the given string as search base for trusted domains." -msgstr "" +msgstr "選用。使用指定的字串作為受信任網域的搜尋基礎。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:486 msgid "Default: the value of <emphasis>cn=trusts,%basedn</emphasis>" -msgstr "" +msgstr "預設:<emphasis>cn=trusts,%basedn</emphasis> 的值" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:493 msgid "ipa_master_domain_search_base (string)" -msgstr "" +msgstr "ipa_master_domain_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:496 msgid "Optional. Use the given string as search base for master domain object." -msgstr "" +msgstr "選用。使用指定的字串作為主網域物件的搜尋基礎。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:505 msgid "Default: the value of <emphasis>cn=ad,cn=etc,%basedn</emphasis>" -msgstr "" +msgstr "預設:<emphasis>cn=ad,cn=etc,%basedn</emphasis> 的值" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:512 msgid "ipa_views_search_base (string)" -msgstr "" +msgstr "ipa_views_search_base (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:515 msgid "Optional. Use the given string as search base for views containers." -msgstr "" +msgstr "選用。使用指定的字串作為檢視容器的搜尋基礎。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:524 msgid "Default: the value of <emphasis>cn=views,cn=accounts,%basedn</emphasis>" -msgstr "" +msgstr "預設:<emphasis>cn=views,cn=accounts,%basedn</emphasis> 的值" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:534 msgid "" "The name of the Kerberos realm. This is optional and defaults to the value " "of <quote>ipa_domain</quote>." -msgstr "" +msgstr "Kerberos realm 的名稱。這是選用的,預設為 <quote>ipa_domain</quote> 的值。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:538 @@ -10163,35 +11581,37 @@ msgid "" "The name of the Kerberos realm has a special meaning in IPA - it is " "converted into the base DN to use for performing LDAP operations." msgstr "" +"Kerberos realm 的名稱在 IPA 中有特殊意義 - 它會轉換為執行 LDAP 作業時使用的基" +"礎 DN。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:546 sssd-ad.5.xml:1363 msgid "krb5_confd_path (string)" -msgstr "" +msgstr "krb5_confd_path (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:549 sssd-ad.5.xml:1366 msgid "" "Absolute path of a directory where SSSD should place Kerberos configuration " "snippets." -msgstr "" +msgstr "SSSD 應放置 Kerberos 設定片段之目錄的絕對路徑。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:553 sssd-ad.5.xml:1370 msgid "" "To disable the creation of the configuration snippets set the parameter to " "'none'." -msgstr "" +msgstr "若要停用設定片段的建立,請將參數設為 'none'。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:557 sssd-ad.5.xml:1374 msgid "Default: not set (krb5.include.d subdirectory of SSSD's pubconf directory)" -msgstr "" +msgstr "預設:未設定(SSSD pubconf 目錄的 krb5.include.d 子目錄)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:564 msgid "ipa_deskprofile_refresh (integer)" -msgstr "" +msgstr "ipa_deskprofile_refresh (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:567 @@ -10200,33 +11620,35 @@ msgid "" "IPA server. This will reduce the latency and load on the IPA server if there " "are many desktop profiles requests made in a short period." msgstr "" +"對 IPA 伺服器查詢桌面設定檔規則之間的時間量。若在短期內發出許多桌面設定檔要求" +",這會降低 IPA 伺服器的延遲與負載。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:574 sssd-ipa.5.xml:604 sssd-ipa.5.xml:620 sssd-ad.5.xml:600 msgid "Default: 5 (seconds)" -msgstr "" +msgstr "預設:5(秒)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:580 msgid "ipa_deskprofile_request_interval (integer)" -msgstr "" +msgstr "ipa_deskprofile_request_interval (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:583 msgid "" "The amount of time between lookups of the Desktop Profile rules against the " "IPA server in case the last request did not return any rule." -msgstr "" +msgstr "若上次要求沒有傳回任何規則,對 IPA 伺服器查詢桌面設定檔規則之間的時間量。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:588 msgid "Default: 60 (minutes)" -msgstr "" +msgstr "預設:60(分鐘)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:594 msgid "ipa_hbac_refresh (integer)" -msgstr "" +msgstr "ipa_hbac_refresh (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:597 @@ -10235,11 +11657,13 @@ msgid "" "server. This will reduce the latency and load on the IPA server if there are " "many access-control requests made in a short period." msgstr "" +"對 IPA 伺服器查詢 HBAC 規則之間的時間量。若在短期內發出許多存取控制要求,這會" +"降低 IPA 伺服器的延遲與負載。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:610 msgid "ipa_hbac_selinux (integer)" -msgstr "" +msgstr "ipa_hbac_selinux (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:613 @@ -10248,11 +11672,13 @@ msgid "" "server. This will reduce the latency and load on the IPA server if there are " "many user login requests made in a short period." msgstr "" +"對 IPA 伺服器查詢 SELinux 對應表之間的時間量。若在短期內發出許多使用者登入要" +"求,這會降低 IPA 伺服器的延遲與負載。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:626 msgid "ipa_server_mode (boolean)" -msgstr "" +msgstr "ipa_server_mode (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:629 @@ -10260,6 +11686,8 @@ msgid "" "This option will be set by the IPA installer (ipa-server-install) " "automatically and denotes if SSSD is running on an IPA server or not." msgstr "" +"此選項會由 IPA 安裝程式 (ipa-server-install) 自動設定,表示 SSSD 是否在 IPA " +"伺服器上執行。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:634 @@ -10267,13 +11695,15 @@ msgid "" "On an IPA server SSSD will lookup users and groups from trusted domains " "directly while on a client it will ask an IPA server." msgstr "" +"在 IPA 伺服器上,SSSD 會直接查詢受信任網域的使用者與群組,而在用戶端上,它會" +"詢問 IPA 伺服器。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:639 msgid "" "NOTE: There are currently some assumptions that must be met when SSSD is " "running on an IPA server." -msgstr "" +msgstr "注意:SSSD 在 IPA 伺服器上執行時,目前必須滿足一些假設。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:644 @@ -10282,6 +11712,8 @@ msgid "" "server itself. This is already the default set by the IPA installer, so no " "manual change is required." msgstr "" +"<quote>ipa_server</quote> 選項必須設定為指向 IPA 伺服器本身。這已經是 IPA 安" +"裝程式設定的預設值,因此不需要手動變更。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:653 @@ -10289,51 +11721,53 @@ msgid "" "The <quote>full_name_format</quote> option must not be tweaked to only print " "short names for users from trusted domains." msgstr "" +"<quote>full_name_format</quote> 選項不得調整為只對受信任網域的使用者列印簡短" +"名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:668 msgid "ipa_automount_location (string)" -msgstr "" +msgstr "ipa_automount_location (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:671 msgid "The automounter location this IPA client will be using" -msgstr "" +msgstr "此 IPA 用戶端將使用的自動掛載程式位置" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:674 msgid "Default: The location named \"default\"" -msgstr "" +msgstr "預設:名為 \"default\" 的位置" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd-ipa.5.xml:682 msgid "VIEWS AND OVERRIDES" -msgstr "" +msgstr "檢視與覆寫" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:691 msgid "ipa_view_class (string)" -msgstr "" +msgstr "ipa_view_class (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:694 msgid "Objectclass of the view container." -msgstr "" +msgstr "檢視容器的物件類別。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:697 msgid "Default: nsContainer" -msgstr "" +msgstr "預設:nsContainer" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:703 msgid "ipa_view_name (string)" -msgstr "" +msgstr "ipa_view_name (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:706 msgid "Name of the attribute holding the name of the view." -msgstr "" +msgstr "保存檢視名稱的屬性名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:710 sssd-ldap-attributes.5.xml:496 @@ -10341,128 +11775,128 @@ msgstr "" #: sssd-ldap-attributes.5.xml:1010 sssd-ldap-attributes.5.xml:1068 #: sssd-ldap-attributes.5.xml:1226 sssd-ldap-attributes.5.xml:1271 msgid "Default: cn" -msgstr "" +msgstr "預設:cn" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:716 msgid "ipa_override_object_class (string)" -msgstr "" +msgstr "ipa_override_object_class (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:719 msgid "Objectclass of the override objects." -msgstr "" +msgstr "覆寫物件的物件類別。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:722 msgid "Default: ipaOverrideAnchor" -msgstr "" +msgstr "預設:ipaOverrideAnchor" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:728 msgid "ipa_anchor_uuid (string)" -msgstr "" +msgstr "ipa_anchor_uuid (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:731 msgid "" "Name of the attribute containing the reference to the original object in a " "remote domain." -msgstr "" +msgstr "包含遠端網域中原始物件參照的屬性名稱。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:735 msgid "Default: ipaAnchorUUID" -msgstr "" +msgstr "預設:ipaAnchorUUID" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:741 msgid "ipa_user_override_object_class (string)" -msgstr "" +msgstr "ipa_user_override_object_class (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:744 msgid "" "Name of the objectclass for user overrides. It is used to determine if the " "found override object is related to a user or a group." -msgstr "" +msgstr "使用者覆寫的物件類別名稱。它用來判斷找到的覆寫物件是與使用者還是群組相關。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:749 msgid "User overrides can contain attributes given by" -msgstr "" +msgstr "使用者覆寫可以包含下列屬性:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:752 msgid "ldap_user_name" -msgstr "" +msgstr "ldap_user_name" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:755 msgid "ldap_user_uid_number" -msgstr "" +msgstr "ldap_user_uid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:758 msgid "ldap_user_gid_number" -msgstr "" +msgstr "ldap_user_gid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:761 msgid "ldap_user_gecos" -msgstr "" +msgstr "ldap_user_gecos" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:764 msgid "ldap_user_home_directory" -msgstr "" +msgstr "ldap_user_home_directory" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:767 msgid "ldap_user_shell" -msgstr "" +msgstr "ldap_user_shell" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:770 msgid "ldap_user_ssh_public_key" -msgstr "" +msgstr "ldap_user_ssh_public_key" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:775 msgid "Default: ipaUserOverride" -msgstr "" +msgstr "預設:ipaUserOverride" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-ipa.5.xml:781 msgid "ipa_group_override_object_class (string)" -msgstr "" +msgstr "ipa_group_override_object_class (string)" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:784 msgid "" "Name of the objectclass for group overrides. It is used to determine if the " "found override object is related to a user or a group." -msgstr "" +msgstr "群組覆寫的物件類別名稱。它用來判斷找到的覆寫物件是與使用者還是群組相關。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:789 msgid "Group overrides can contain attributes given by" -msgstr "" +msgstr "群組覆寫可以包含下列屬性:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:792 msgid "ldap_group_name" -msgstr "" +msgstr "ldap_group_name" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:795 msgid "ldap_group_gid_number" -msgstr "" +msgstr "ldap_group_gid_number" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-ipa.5.xml:800 msgid "Default: ipaGroupOverride" -msgstr "" +msgstr "預設:ipaGroupOverride" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd-ipa.5.xml:684 @@ -10473,18 +11907,21 @@ msgid "" "related options are listed here with their default values. <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"SSSD 可以處理 FreeIPA 4.1 及更新版本提供的檢視與覆寫。由於所有路徑與物件類別" +"在伺服器端都是固定的,基本上不需要設定任何內容。為求完整,相關選項在此列出並" +"附上預設值。<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ipa.5.xml:812 msgid "SUBDOMAINS PROVIDER" -msgstr "" +msgstr "子網域提供者" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:814 msgid "" "The IPA subdomains provider behaves slightly differently if it is configured " "explicitly or implicitly." -msgstr "" +msgstr "IPA 子網域提供者在明確或隱含設定時,行為略有不同。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:818 @@ -10493,6 +11930,8 @@ msgid "" "sssd.conf, the IPA subdomains provider is configured explicitly, and all " "subdomain requests are sent to the IPA server if necessary." msgstr "" +"若在 sssd.conf 的網域區段中找到 'subdomains_provider = ipa' 選項,IPA 子網域" +"提供者會被明確設定,必要時所有子網域要求都會傳送到 IPA 伺服器。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:824 @@ -10505,11 +11944,15 @@ msgid "" "hour or after the IPA provider goes online, the subdomains provider is " "enabled again." msgstr "" +"若 sssd.conf 的網域區段中未設定 'subdomains_provider' 選項,但有 " +"'id_provider = ipa' 選項,IPA 子網域提供者會被隱含設定。這種情況下,若子網域" +"要求失敗並表示伺服器不支援子網域(也就是未設定信任),IPA 子網域提供者會被停" +"用。一小時後或 IPA 提供者上線後,子網域提供者會再次啟用。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ipa.5.xml:835 msgid "TRUSTED DOMAINS CONFIGURATION" -msgstr "" +msgstr "受信任網域設定" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-ipa.5.xml:843 @@ -10518,6 +11961,8 @@ msgid "" "[domain/ipa.domain.com/ad.domain.com]\n" "ad_server = dc.ad.domain.com\n" msgstr "" +"[domain/ipa.domain.com/ad.domain.com]\n" +"ad_server = dc.ad.domain.com\n" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:837 @@ -10528,6 +11973,10 @@ msgid "" "option can be used in the parent domain. <placeholder " "type=\"programlisting\" id=\"0\"/>" msgstr "" +"某些設定選項也可以為受信任網域設定。可以使用如下列範例所示的受信任網域子區段" +"來設定受信任網域設定。另一種做法是,可以在父網域中使用 <quote>" +"subdomain_inherit</quote> 選項。<placeholder type=\"programlisting\" " +"id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:848 @@ -10536,6 +11985,8 @@ msgid "" "<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> manual page." msgstr "" +"更多詳細資料請參閱 <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> 手冊頁。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:855 @@ -10543,63 +11994,65 @@ msgid "" "Different configuration options are tunable for a trusted domain depending " "on whether you are configuring SSSD on an IPA server or an IPA client." msgstr "" +"可以在 IPA 伺服器還是 IPA 用戶端上設定 SSSD,決定了受信任網域可以調整哪些設定" +"選項。" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd-ipa.5.xml:860 msgid "OPTIONS TUNABLE ON IPA MASTERS" -msgstr "" +msgstr "可在 IPA 主伺服器上調整的選項" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd-ipa.5.xml:862 msgid "The following options can be set in a subdomain section on an IPA master:" -msgstr "" +msgstr "可以在 IPA 主伺服器的子網域區段中設定下列選項:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:866 sssd-ipa.5.xml:896 msgid "ad_server" -msgstr "" +msgstr "ad_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:869 msgid "ad_backup_server" -msgstr "" +msgstr "ad_backup_server" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:872 sssd-ipa.5.xml:899 msgid "ad_site" -msgstr "" +msgstr "ad_site" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:875 msgid "ldap_search_base" -msgstr "" +msgstr "ldap_search_base" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:878 msgid "ldap_user_search_base" -msgstr "" +msgstr "ldap_user_search_base" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ipa.5.xml:881 msgid "ldap_group_search_base" -msgstr "" +msgstr "ldap_group_search_base" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd-ipa.5.xml:890 msgid "OPTIONS TUNABLE ON IPA CLIENTS" -msgstr "" +msgstr "可在 IPA 用戶端上調整的選項" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd-ipa.5.xml:892 msgid "The following options can be set in a subdomain section on an IPA client:" -msgstr "" +msgstr "可以在 IPA 用戶端的子網域區段中設定下列選項:" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd-ipa.5.xml:904 msgid "" "Note that if both options are set, only <quote>ad_server</quote> is " "evaluated." -msgstr "" +msgstr "請注意,若同時設定兩個選項,只會評估 <quote>ad_server</quote>。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd-ipa.5.xml:908 @@ -10615,6 +12068,12 @@ msgid "" "<manvolnum>8</manvolnum> </citerefentry> manual page for more details on the " "Kerberos locator plugin." msgstr "" +"由於從 IPA 用戶端觸發、針對受信任網域之使用者或群組身分的任何要求都由 IPA 伺" +"服器解析,<quote>ad_server</quote> 與 <quote>ad_site</quote> 選項只會影響將針" +"對哪個 AD DC 執行驗證。特別的是,從這些清單解析出的位址會寫入 Kerberos " +"locator 外掛程式讀取的 <quote>kdcinfo</quote> 檔案。Kerberos locator 外掛程式" +"的更多詳細資料請參閱 <citerefentry> <refentrytitle>sssd_krb5_locator_plugin</" +"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> 手冊頁。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ipa.5.xml:932 @@ -10623,6 +12082,8 @@ msgid "" "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " "section. This examples shows only the ipa provider-specific options." msgstr "" +"下列範例假設 SSSD 已正確設定,且 example.com 是 <replaceable>[sssd]</" +"replaceable> 區段中的其中一個網域。此範例只顯示 ipa 提供者專屬的選項。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-ipa.5.xml:939 @@ -10633,16 +12094,20 @@ msgid "" "ipa_server = ipaserver.example.com\n" "ipa_hostname = myhost.example.com\n" msgstr "" +"[domain/example.com]\n" +"id_provider = ipa\n" +"ipa_server = ipaserver.example.com\n" +"ipa_hostname = myhost.example.com\n" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-ad.5.xml:10 sssd-ad.5.xml:16 msgid "sssd-ad" -msgstr "" +msgstr "sssd-ad" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-ad.5.xml:17 msgid "SSSD Active Directory provider" -msgstr "" +msgstr "SSSD Active Directory 提供者" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:23 @@ -10654,6 +12119,10 @@ msgid "" "<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> manual page." msgstr "" +"本手冊頁說明 <citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>" +"8</manvolnum> </citerefentry> 之 AD 提供者的設定。詳細的語法參考請參閱 " +"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> 手冊頁的 <quote>FILE FORMAT</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:36 @@ -10664,6 +12133,9 @@ msgid "" "GSSAPI-encrypted channel, SSL/TLS options should not be used with the AD " "provider and will be superseded by Kerberos usage." msgstr "" +"AD 提供者是用來連線到 Active Directory 伺服器的後端。此提供者要求機器加入 AD " +"網域,且必須有可用的 keytab。後端通訊透過 GSSAPI 加密通道進行,不應將 SSL/" +"TLS 選項與 AD 提供者一起使用,這些選項會被 Kerberos 的使用取代。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:44 @@ -10671,6 +12143,8 @@ msgid "" "The AD provider supports connecting to Active Directory 2008 R2 or " "later. Earlier versions may work, but are unsupported." msgstr "" +"AD 提供者支援連線到 Active Directory 2008 R2 或更新版本。較舊的版本可能可以運" +"作,但不受支援。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:48 @@ -10680,6 +12154,8 @@ msgid "" "recognized. In addition servers from trusted domains are always " "auto-discovered." msgstr "" +"AD 提供者可以用來取得受信任網域的使用者資訊並驗證使用者。目前只識別相同樹系中" +"的受信任網域。此外,來自受信任網域的伺服器一律會自動探索。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:54 @@ -10693,6 +12169,12 @@ msgid "" "sssd-ldap and sssd-krb5 providers with some exceptions. However, it is " "neither necessary nor recommended to set these options." msgstr "" +"AD 提供者讓 SSSD 可以使用 <citerefentry> <refentrytitle>sssd-ldap</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 身分提供者與 " +"<citerefentry> <refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> 驗證提供者,並針對 Active Directory 環境最佳化。" +"AD 提供者接受 sssd-ldap 與 sssd-krb5 提供者使用的相同選項,但有一些例外。不過" +",設定這些選項既非必要也不建議。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:69 @@ -10701,6 +12183,8 @@ msgid "" "default options with some exceptions, the differences are listed in the " "<quote>MODIFIED DEFAULT OPTIONS</quote> section." msgstr "" +"AD 提供者主要複製傳統 ldap 與 krb5 提供者的預設選項,但有一些例外,差異列於 " +"<quote>MODIFIED DEFAULT OPTIONS</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:74 @@ -10709,6 +12193,8 @@ msgid "" "provider. No configuration of the access provider is required on the client " "side." msgstr "" +"AD 提供者也可以用作 access、chpass、sudo 與 autofs 提供者。用戶端不需要設定 " +"access 提供者。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:79 @@ -10717,6 +12203,8 @@ msgid "" "configured in sssd.conf then the id_provider must also be set to " "<quote>ad</quote>." msgstr "" +"若在 sssd.conf 中設定 <quote>auth_provider=ad</quote> 或 <quote>" +"access_provider=ad</quote>,則 id_provider 也必須設為 <quote>ad</quote>。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-ad.5.xml:91 @@ -10725,6 +12213,8 @@ msgid "" "ldap_id_mapping = False\n" " " msgstr "" +"ldap_id_mapping = False\n" +" " #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:85 @@ -10745,6 +12235,15 @@ msgid "" "present in the Global Catalog, the non-replicated attributes are currently " "not read from the LDAP port." msgstr "" +"預設情況下,AD 提供者會從 Active Directory 中的 objectSID 參數對應 UID 與 " +"GID 值。詳細資料請參閱下方 <quote>ID MAPPING</quote> 一節。若您想停用 ID 對應" +",改為依賴 Active Directory 中定義的 POSIX 屬性,應設定 <placeholder " +"type=\"programlisting\" id=\"0\"/> 若應使用 POSIX 屬性,基於效能考量,建議也" +"將屬性複寫到全域目錄。若複寫了 POSIX 屬性,SSSD 會嘗試借助全域目錄定位要求之" +"數值 ID 的網域,並只搜尋該網域。相反地,若 POSIX 屬性未複寫到全域目錄,SSSD " +"必須依序搜尋樹系中的所有網域。請注意,<quote>cache_first</quote> 選項可能也有" +"助於加速無網域搜尋。請注意,若全域目錄中只有部分 POSIX 屬性,目前不會從 LDAP " +"連接埠讀取未複寫的屬性。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:108 @@ -10753,6 +12252,8 @@ msgid "" "case-insensitive in the AD provider for compatibility with Active " "Directory's LDAP implementation." msgstr "" +"為了與 Active Directory 的 LDAP 實作相容,SSSD 服務的使用者、群組與其他實體" +"在 AD 提供者中一律視為不區分大小寫。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:113 @@ -10762,6 +12263,9 @@ msgid "" "url=\"https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/understand-security-groups\"> " "Active Directory security groups</ulink>" msgstr "" +"SSSD 只解析 Active Directory 安全性群組。AD 群組類型的更多資訊請參閱:<ulink " +"url=\"https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/" +"understand-security-groups\"> Active Directory security groups</ulink>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:120 @@ -10773,37 +12277,41 @@ msgid "" "group-membership assignment which can be seen in the PAC of the Kerberos " "ticket of a user issued by Active Directory." msgstr "" +"SSSD 會過濾掉 AD 樹系中遠端網域的網域本機群組。預設會將它們過濾掉,例如追蹤遠" +"端網域中的巢狀群組階層時,因為它們在網域本機中無效。這樣做是為了與 Active " +"Directory 的群組成員資格指派一致,可以在 Active Directory 發行之使用者 " +"Kerberos 票證的 PAC 中看到。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:138 msgid "ad_domain (string)" -msgstr "" +msgstr "ad_domain (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:141 msgid "" "Specifies the name of the Active Directory domain. This is optional. If not " "provided, the configuration domain name is used." -msgstr "" +msgstr "指定 Active Directory 網域名稱。這是選用的。若未提供,則使用設定網域名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:146 msgid "" "For proper operation, this option should be specified as the lower-case " "version of the long version of the Active Directory domain." -msgstr "" +msgstr "為求正常運作,此選項應指定為 Active Directory 網域長名稱的小寫版本。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:151 msgid "" "The short domain name (also known as the NetBIOS or the flat name) is " "autodetected by the SSSD." -msgstr "" +msgstr "簡短網域名稱(也稱為 NetBIOS 或 flat 名稱)會由 SSSD 自動偵測。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:158 msgid "ad_enabled_domains (string)" -msgstr "" +msgstr "ad_enabled_domains (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:161 @@ -10812,6 +12320,8 @@ msgid "" "SSSD will ignore any domains not listed in this option. If left unset, all " "discovered domains from the AD forest will be available." msgstr "" +"已啟用 Active Directory 網域的逗號分隔清單。若提供,SSSD 會忽略未列在此選項中" +"的任何網域。若保持未設定,AD 樹系中探索到的所有網域都會可用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:168 @@ -10821,6 +12331,8 @@ msgid "" "are not trusted. If ad_enabled_domains is set, SSSD will try to enable all " "listed domains." msgstr "" +"在網域探索期間,SSSD 會過濾掉一些旗標或屬性表示它們不屬於本機樹系或不受信任的" +"網域。若設定了 ad_enabled_domains,SSSD 會嘗試啟用所有列出的網域。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd-ad.5.xml:179 @@ -10829,6 +12341,8 @@ msgid "" "ad_enabled_domains = sales.example.com, eng.example.com\n" " " msgstr "" +"ad_enabled_domains = sales.example.com, eng.example.com\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:175 @@ -10837,18 +12351,20 @@ msgid "" "the fully qualified domain name of the Active Directory domain. For example: " "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"為求正常運作,此選項必須以全小寫指定,並使用 Active Directory 網域的完整網域" +"名稱。例如:<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:183 msgid "" "The short domain name (also known as the NetBIOS or the flat name) will be " "autodetected by SSSD." -msgstr "" +msgstr "簡短網域名稱(也稱為 NetBIOS 或 flat 名稱)會由 SSSD 自動偵測。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:193 msgid "ad_server, ad_backup_server (string)" -msgstr "" +msgstr "ad_server, ad_backup_server (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:196 @@ -10857,6 +12373,8 @@ msgid "" "connect in order of preference. For more information on failover and server " "redundancy, see the <quote>FAILOVER</quote> section." msgstr "" +"SSSD 應依偏好順序連線之 AD 伺服器的主機名稱逗號分隔清單。有關故障轉移與伺服器" +"備援的更多資訊,請參閱 <quote>FAILOVER</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:203 @@ -10864,6 +12382,8 @@ msgid "" "This is optional if autodiscovery is enabled. For more information on " "service discovery, refer to the <quote>SERVICE DISCOVERY</quote> section." msgstr "" +"若啟用自動探索,此選項是選用的。服務探索的更多資訊請參閱 <quote>SERVICE " +"DISCOVERY</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:208 @@ -10871,11 +12391,13 @@ msgid "" "Note: Trusted domains will always auto-discover servers even if the primary " "server is explicitly defined in the ad_server option." msgstr "" +"注意:即使主要伺服器已在 ad_server 選項中明確定義,受信任網域一律會自動探索伺" +"服器。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:216 msgid "ad_hostname (string)" -msgstr "" +msgstr "ad_hostname (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:219 @@ -10885,6 +12407,8 @@ msgid "" "possible or the short name should be really used instead, set this parameter " "explicitly." msgstr "" +"選用。在 hostname(5) 未反映完整名稱的機器上,sssd 會嘗試展開簡短名稱。若無法" +"展開或確實應改用簡短名稱,請明確設定此參數。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:226 @@ -10893,11 +12417,13 @@ msgid "" "to perform dynamic DNS updates. It must match the hostname for which the " "keytab was issued." msgstr "" +"此欄位用來判斷 keytab 中使用的主機 principal,並執行動態 DNS 更新。它必須符合" +"簽發 keytab 時的主機名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:235 msgid "ad_enable_dns_sites (boolean)" -msgstr "" +msgstr "ad_enable_dns_sites (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:242 @@ -10909,11 +12435,15 @@ msgid "" "DNS SRV configuration, including the discovery domain, is used during site " "discovery as well." msgstr "" +"若為 true 且啟用服務探索(請參閱手冊頁底部的 Service Discovery 段落),SSSD " +"會先嘗試使用 Active Directory Site Discovery 探索要連線的 Active Directory 伺" +"服器,若找不到 AD site,則退回 DNS SRV 記錄。DNS SRV 設定(包括探索網域)也會" +"在 site 探索期間使用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:258 msgid "ad_access_filter (string)" -msgstr "" +msgstr "ad_access_filter (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:261 @@ -10925,6 +12455,10 @@ msgid "" "disable GPO based access control (see option " "<quote>ad_gpo_access_control</quote> for details)." msgstr "" +"指定使用者必須符合才能獲得存取權的 LDAP 存取控制篩選器。此選項要生效,<quote>" +"access_provider</quote> 選項必須明確設為 <quote>ad</quote>。若您想使用 " +"<quote>ad_access_filter</quote> 作為唯一的存取控制機制,必須停用以 GPO 為基礎" +"的存取控制(詳情請參閱 <quote>ad_gpo_access_control</quote> 選項)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:270 @@ -10934,6 +12468,9 @@ msgid "" "<quote>KEYWORD:NAME:FILTER</quote>. The keyword can be either " "<quote>DOM</quote>, <quote>FOREST</quote> or missing." msgstr "" +"此選項也支援依網域或樹系指定不同的篩選器。這種延伸篩選器由 <quote>" +"KEYWORD:NAME:FILTER</quote> 組成。關鍵字可以是 <quote>DOM</quote>、<quote>" +"FOREST</quote> 或省略。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:278 @@ -10943,13 +12480,16 @@ msgid "" "to. If the keyword equals to <quote>FOREST</quote>, then the filter equals " "to all domains from the forest specified by <quote>NAME</quote>." msgstr "" +"若關鍵字等於 <quote>DOM</quote> 或省略,則 <quote>NAME</quote> 指定篩選器適用" +"的網域或子網域。若關鍵字等於 <quote>FOREST</quote>,則篩選器等於 <quote>" +"NAME</quote> 指定之樹系中的所有網域。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:286 msgid "" "Multiple filters can be separated with the <quote>?</quote> character, " "similarly to how search bases work." -msgstr "" +msgstr "多個篩選器可以像搜尋基礎一樣,以 <quote>?</quote> 字元分隔。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:291 @@ -10963,6 +12503,12 @@ msgid "" "url=\"https://msdn.microsoft.com/en-us/library/cc223367.aspx\"> [MS-ADTS] " "section LDAP extensions</ulink>" msgstr "" +"巢狀群組成員資格必須使用特殊 OID <quote>:1.2.840.113556.1.4.1941:</quote> 搜" +"尋,另外還要使用完整的 DOM:domain.example.org: 語法,以確保剖析器不會嘗試解讀" +"與 OID 關聯的冒號字元。若您不使用此 OID,巢狀群組成員資格將無法解析。請參閱下" +"方的使用範例,並在此參考有關此 OID 的進一步資訊:<ulink url=\"https://" +"msdn.microsoft.com/en-us/library/cc223367.aspx\"> [MS-ADTS] section LDAP " +"extensions</ulink>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:304 @@ -10972,6 +12518,8 @@ msgid "" "per-domain filter would be applied. If there are more matches with the same " "specification, the first one is used." msgstr "" +"一律使用最具體的匹配。例如,若選項同時指定了使用者所屬網域的篩選器與全域篩選" +"器,則會套用逐網域篩選器。若有多個規格相同的匹配,則使用第一個。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><programlisting> #: sssd-ad.5.xml:315 @@ -10990,23 +12538,37 @@ msgid "" "DOM:dom1:(memberOf:1.2.840.113556.1.4.1941:=cn=nestedgroup,ou=groups,dc=example,dc=com)\n" " " msgstr "" +"# apply filter on domain called dom1 only:\n" +"dom1:(memberOf=cn=admins,ou=groups,dc=dom1,dc=com)\n" +"\n" +"# apply filter on domain called dom2 only:\n" +"DOM:dom2:(memberOf=cn=admins,ou=groups,dc=dom2,dc=com)\n" +"\n" +"# apply filter on forest called EXAMPLE.COM only:\n" +"FOREST:EXAMPLE.COM:(memberOf=cn=admins,ou=groups,dc=example,dc=com)\n" +"\n" +"# apply filter for a member of a nested group in dom1:\n" +"DOM:dom1:" +"(memberOf:1.2.840.113556.1.4.1941:=cn=nestedgroup,ou=groups,dc=example,dc=com)" +"\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:334 msgid "ad_site (string)" -msgstr "" +msgstr "ad_site (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:337 msgid "" "Specify AD site to which client should try to connect. If this option is " "not provided, the AD site will be auto-discovered." -msgstr "" +msgstr "指定用戶端應嘗試連線的 AD site。若未提供此選項,AD site 會自動探索。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:348 msgid "ad_enable_gc (boolean)" -msgstr "" +msgstr "ad_enable_gc (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:351 @@ -11016,6 +12578,9 @@ msgid "" "as a fallback. Disabling this option makes the SSSD only connect to the LDAP " "port of the current AD server." msgstr "" +"預設情況下,SSSD 會先連線到全域目錄,從受信任網域取回使用者,並使用 LDAP 連接" +"埠取回群組成員資格或作為退回。停用此選項會讓 SSSD 只連線到目前 AD 伺服器的 " +"LDAP 連接埠。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:359 @@ -11025,11 +12590,13 @@ msgid "" "port of trusted domains instead. However, Global Catalog must be used in " "order to resolve cross-domain group memberships." msgstr "" +"請注意,停用全域目錄支援不會停用從受信任網域取回使用者。SSSD 會改為連線到受信" +"任網域的 LDAP 連接埠。不過,要解析跨網域群組成員資格,必須使用全域目錄。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:373 msgid "ad_gpo_access_control (string)" -msgstr "" +msgstr "ad_gpo_access_control (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:376 @@ -11040,6 +12607,9 @@ msgid "" "must be explicitly set to <quote>ad</quote> in order for this option to have " "an effect." msgstr "" +"此選項指定 GPO 型存取控制功能的作業模式:以停用模式、強制模式或寬鬆模式運作。" +"請注意,此選項要生效,<quote>access_provider</quote> 選項必須明確設為 <quote>" +"ad</quote>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:385 @@ -11049,6 +12619,8 @@ msgid "" "information on the supported policy settings please refer to the " "<quote>ad_gpo_map</quote> options." msgstr "" +"GPO 型存取控制功能使用 GPO 原則設定,判斷特定使用者是否允許登入主機。支援之原" +"則設定的更多資訊請參閱 <quote>ad_gpo_map</quote> 選項。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:393 @@ -11058,6 +12630,9 @@ msgid "" "S-1-5-32-544) in GPO access control rules will be ignored by SSSD. See " "upstream issue tracker https://github.com/SSSD/sssd/issues/5063 ." msgstr "" +"請注意,目前版本的 SSSD 不支援 Active Directory 的內建群組。GPO 存取控制規則" +"中的內建群組(例如 SID 為 S-1-5-32-544 的 Administrators)會被 SSSD 忽略。請" +"參閱上游問題追蹤器 https://github.com/SSSD/sssd/issues/5063。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:402 @@ -11068,6 +12643,9 @@ msgid "" "a user, the user or at least one of the groups to which it belongs must have " "following permissions on the GPO:" msgstr "" +"執行存取控制之前,SSSD 會對 GPO 套用群組原則安全性篩選。每次使用者登入時,都" +"會檢查連結到主機之 GPO 的適用性。GPO 要套用於使用者,使用者或其所屬的至少一個" +"群組必須對 GPO 具有下列權限:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:412 @@ -11075,6 +12653,8 @@ msgid "" "Read: The user or one of its groups must have read access to the properties " "of the GPO (RIGHT_DS_READ_PROPERTY)" msgstr "" +"讀取:使用者或其其中一個群組必須對 GPO 的屬性具有讀取存取權 " +"(RIGHT_DS_READ_PROPERTY)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:419 @@ -11082,6 +12662,8 @@ msgid "" "Apply Group Policy: The user or at least one of its groups must be allowed " "to apply the GPO (RIGHT_DS_CONTROL_ACCESS)." msgstr "" +"套用群組原則:使用者或其至少一個群組必須被允許套用 GPO " +"(RIGHT_DS_CONTROL_ACCESS)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:427 @@ -11092,6 +12674,9 @@ msgid "" "and access control are started, the Authenticated Users group permissions on " "the GPO always apply also to the user." msgstr "" +"預設情況下,GPO 上會有 Authenticated Users 群組,此群組同時具有讀取與套用群組" +"原則存取權。由於必須先成功完成使用者驗證,才會開始 GPO 安全性篩選與存取控制," +"因此 GPO 上的 Authenticated Users 群組權限一律也適用於使用者。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:436 @@ -11108,21 +12693,27 @@ msgid "" "<refentrytitle>sssctl</refentrytitle> <manvolnum>8</manvolnum> " "</citerefentry> manual page)." msgstr "" +"注意:若作業模式設為強制,先前允許登入存取權的使用者現在可能會被拒絕登入存取" +"權(由 GPO 原則設定決定)。為方便管理員順利轉換,提供寬鬆模式,不會強制執行存" +"取控制規則,但會評估規則,若存取會被拒絕,則輸出 syslog 訊息。管理員檢查記錄" +"後,可以在將模式設為強制之前進行必要的變更。要記錄 GPO 型存取控制,需要 " +"'trace functions' 除錯層級(請參閱 <citerefentry> <refentrytitle>sssctl</" +"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> 手冊頁)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:455 msgid "There are three supported values for this option:" -msgstr "" +msgstr "此選項支援三個值:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:459 msgid "disabled: GPO-based access control rules are neither evaluated nor enforced." -msgstr "" +msgstr "disabled:GPO 型存取控制規則既不會評估也不會強制執行。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:465 msgid "enforcing: GPO-based access control rules are evaluated and enforced." -msgstr "" +msgstr "enforcing:GPO 型存取控制規則會評估並強制執行。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:471 @@ -11131,21 +12722,23 @@ msgid "" "Instead, a syslog message will be emitted indicating that the user would " "have been denied access if this option's value were set to enforcing." msgstr "" +"permissive:GPO 型存取控制規則會評估,但不會強制執行。取而代之的是,會發出 " +"syslog 訊息,表示若此選項的值設為 enforcing,使用者就會被拒絕存取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:482 msgid "Default: permissive" -msgstr "" +msgstr "預設:permissive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:485 msgid "Default: enforcing" -msgstr "" +msgstr "預設:enforcing" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:491 msgid "ad_gpo_implicit_deny (boolean)" -msgstr "" +msgstr "ad_gpo_implicit_deny (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:494 @@ -11157,6 +12750,10 @@ msgid "" "option because it can deny access even to users in the built-in " "Administrators group if no GPO rules apply to them." msgstr "" +"一般來說,找不到適用的 GPO 時,使用者會被允許存取。當此選項設為 True 時,只" +"有 GPO 規則明確允許時,使用者才會被允許存取。否則使用者會被拒絕存取。這可以用" +"來強化安全性,但使用此選項時要小心,因為若沒有 GPO 規則適用於內建 " +"Administrators 群組中的使用者,它甚至可能拒絕他們存取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:510 @@ -11165,73 +12762,75 @@ msgid "" "based on the allow and deny login rights defined on the server-side and the " "setting of ad_gpo_implicit_deny." msgstr "" +"下列 2 個表格說明根據伺服器端定義的允許與拒絕登入權限,以及 " +"ad_gpo_implicit_deny 的設定,使用者何時會被允許或拒絕。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd-ad.5.xml:522 msgid "ad_gpo_implicit_deny = False (default)" -msgstr "" +msgstr "ad_gpo_implicit_deny = False(預設)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd-ad.5.xml:523 sssd-ad.5.xml:549 msgid "allow-rules" -msgstr "" +msgstr "allow-rules" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd-ad.5.xml:523 sssd-ad.5.xml:549 msgid "deny-rules" -msgstr "" +msgstr "deny-rules" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd-ad.5.xml:524 sssd-ad.5.xml:550 msgid "results" -msgstr "" +msgstr "結果" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> #: sssd-ad.5.xml:527 sssd-ad.5.xml:530 sssd-ad.5.xml:533 sssd-ad.5.xml:553 #: sssd-ad.5.xml:556 sssd-ad.5.xml:559 msgid "missing" -msgstr "" +msgstr "不存在" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> #: sssd-ad.5.xml:528 msgid "all users are allowed" -msgstr "" +msgstr "允許所有使用者" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry> #: sssd-ad.5.xml:530 sssd-ad.5.xml:533 sssd-ad.5.xml:536 sssd-ad.5.xml:556 #: sssd-ad.5.xml:559 sssd-ad.5.xml:562 msgid "present" -msgstr "" +msgstr "存在" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> #: sssd-ad.5.xml:531 msgid "only users not in deny-rules are allowed" -msgstr "" +msgstr "只允許不在 deny-rules 中的使用者" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> #: sssd-ad.5.xml:534 sssd-ad.5.xml:560 msgid "only users in allow-rules are allowed" -msgstr "" +msgstr "只允許在 allow-rules 中的使用者" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> #: sssd-ad.5.xml:537 sssd-ad.5.xml:563 msgid "only users in allow-rules and not in deny-rules are allowed" -msgstr "" +msgstr "只允許在 allow-rules 中且不在 deny-rules 中的使用者" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><thead><row><entry> #: sssd-ad.5.xml:548 msgid "ad_gpo_implicit_deny = True" -msgstr "" +msgstr "ad_gpo_implicit_deny = True" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><informaltable><tgroup><tbody><row><entry><para> #: sssd-ad.5.xml:554 sssd-ad.5.xml:557 msgid "no users are allowed" -msgstr "" +msgstr "不允許任何使用者" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:570 msgid "ad_gpo_ignore_unreadable (boolean)" -msgstr "" +msgstr "ad_gpo_ignore_unreadable (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:573 @@ -11242,11 +12841,14 @@ msgid "" "policies if their attributes in group policy containers are not readable for " "SSSD." msgstr "" +"一般來說,當適用之群組原則物件的某些群組原則容器(AD 物件)無法被 SSSD 讀取時" +",使用者會被拒絕存取。此選項允許忽略群組原則容器及其關聯的原則(若其在群組原" +"則容器中的屬性無法被 SSSD 讀取)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:590 msgid "ad_gpo_cache_timeout (integer)" -msgstr "" +msgstr "ad_gpo_cache_timeout (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:593 @@ -11255,11 +12857,13 @@ msgid "" "server. This will reduce the latency and load on the AD server if there are " "many access-control requests made in a short period." msgstr "" +"對 AD 伺服器查詢 GPO 原則檔案之間的時間量。若在短期內發出許多存取控制要求,這" +"會降低 AD 伺服器的延遲與負載。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:606 msgid "ad_gpo_map_interactive (string)" -msgstr "" +msgstr "ad_gpo_map_interactive (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:609 @@ -11276,6 +12880,13 @@ msgid "" "local access only, if it or at least one of its groups is part of the policy " "settings." msgstr "" +"以 InteractiveLogonRight 與 DenyInteractiveLogonRight 原則設定評估 GPO 型存取" +"控制的 PAM 服務名稱逗號分隔清單。只會評估使用者具有讀取與套用群組原則權限的 " +"GPO(請參閱 <quote>ad_gpo_access_control</quote> 選項)。若評估的 GPO 包含針" +"對使用者或其其中一個群組的拒絕互動式登入設定,使用者會被拒絕本機存取。若評估" +"的 GPO 中沒有定義互動式登入權限,使用者會被授予本機存取。若至少一個評估的 " +"GPO 包含互動式登入權限設定,則只有使用者或其至少一個群組屬於原則設定的一部分" +"時,使用者才會被授予本機存取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:627 @@ -11283,6 +12894,8 @@ msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on locally\" and \"Deny log on locally\"." msgstr "" +"注意:使用群組原則管理編輯器時,此值稱為 \"Allow log on locally\" 與 \"Deny " +"log on locally\"。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd-ad.5.xml:641 @@ -11291,6 +12904,8 @@ msgid "" "ad_gpo_map_interactive = +my_pam_service, -login\n" " " msgstr "" +"ad_gpo_map_interactive = +my_pam_service, -login\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:632 @@ -11303,41 +12918,46 @@ msgid "" "(e.g. <quote>my_pam_service</quote>), you would use the following " "configuration: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"可以使用 <quote>+service_name</quote> 將另一個 PAM 服務名稱加入預設集合,或使" +"用 <quote>-service_name</quote> 明確地從預設集合移除 PAM 服務名稱。例如,若要" +"將此登入權限的預設 PAM 服務名稱(例如 <quote>login</quote>)取代為自訂 pam 服" +"務名稱(例如 <quote>my_pam_service</quote>),您可以使用下列設定" +":<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:664 msgid "gdm-fingerprint" -msgstr "" +msgstr "gdm-fingerprint" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:684 msgid "lightdm" -msgstr "" +msgstr "lightdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:689 msgid "lxdm" -msgstr "" +msgstr "lxdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:694 msgid "sddm" -msgstr "" +msgstr "sddm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:699 msgid "unity" -msgstr "" +msgstr "unity" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:704 msgid "xdm" -msgstr "" +msgstr "xdm" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:713 msgid "ad_gpo_map_remote_interactive (string)" -msgstr "" +msgstr "ad_gpo_map_remote_interactive (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:716 @@ -11354,6 +12974,13 @@ msgid "" "right settings, the user is granted remote access only, if it or at least " "one of its groups is part of the policy settings." msgstr "" +"以 RemoteInteractiveLogonRight 與 DenyRemoteInteractiveLogonRight 原則設定評" +"估 GPO 型存取控制的 PAM 服務名稱逗號分隔清單。只會評估使用者具有讀取與套用群" +"組原則權限的 GPO(請參閱 <quote>ad_gpo_access_control</quote> 選項)。若評估" +"的 GPO 包含針對使用者或其其中一個群組的拒絕遠端登入設定,使用者會被拒絕遠端互" +"動式存取。若評估的 GPO 中沒有定義遠端互動式登入權限,使用者會被授予遠端存取。" +"若至少一個評估的 GPO 包含遠端互動式登入權限設定,則只有使用者或其至少一個群組" +"屬於原則設定的一部分時,使用者才會被授予遠端存取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:735 @@ -11362,6 +12989,8 @@ msgid "" "log on through Remote Desktop Services\" and \"Deny log on through Remote " "Desktop Services\"." msgstr "" +"注意:使用群組原則管理編輯器時,此值稱為 \"Allow log on through Remote " +"Desktop Services\" 與 \"Deny log on through Remote Desktop Services\"。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd-ad.5.xml:750 @@ -11370,6 +12999,8 @@ msgid "" "ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n" " " msgstr "" +"ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:741 @@ -11382,21 +13013,26 @@ msgid "" "(e.g. <quote>my_pam_service</quote>), you would use the following " "configuration: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"可以使用 <quote>+service_name</quote> 將另一個 PAM 服務名稱加入預設集合,或使" +"用 <quote>-service_name</quote> 明確地從預設集合移除 PAM 服務名稱。例如,若要" +"將此登入權限的預設 PAM 服務名稱(例如 <quote>sshd</quote>)取代為自訂 pam 服" +"務名稱(例如 <quote>my_pam_service</quote>),您可以使用下列設定" +":<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:758 msgid "sshd" -msgstr "" +msgstr "sshd" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:763 msgid "cockpit" -msgstr "" +msgstr "cockpit" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:772 msgid "ad_gpo_map_network (string)" -msgstr "" +msgstr "ad_gpo_map_network (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:775 @@ -11413,6 +13049,13 @@ msgid "" "logon access only, if it or at least one of its groups is part of the policy " "settings." msgstr "" +"以 NetworkLogonRight 與 DenyNetworkLogonRight 原則設定評估 GPO 型存取控制的 " +"PAM 服務名稱逗號分隔清單。只會評估使用者具有讀取與套用群組原則權限的 GPO(請" +"參閱 <quote>ad_gpo_access_control</quote> 選項)。若評估的 GPO 包含針對使用者" +"或其其中一個群組的拒絕網路登入設定,使用者會被拒絕網路登入存取。若評估的 GPO " +"中沒有定義網路登入權限,使用者會被授予登入存取。若至少一個評估的 GPO 包含網路" +"登入權限設定,則只有使用者或其至少一個群組屬於原則設定的一部分時,使用者才會" +"被授予登入存取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:793 @@ -11421,6 +13064,8 @@ msgid "" "this computer from the network\" and \"Deny access to this computer from the " "network\"." msgstr "" +"注意:使用群組原則管理編輯器時,此值稱為 \"Access this computer from the " +"network\" 與 \"Deny access to this computer from the network\"。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd-ad.5.xml:808 @@ -11429,6 +13074,8 @@ msgid "" "ad_gpo_map_network = +my_pam_service, -ftp\n" " " msgstr "" +"ad_gpo_map_network = +my_pam_service, -ftp\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:799 @@ -11441,21 +13088,26 @@ msgid "" "(e.g. <quote>my_pam_service</quote>), you would use the following " "configuration: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"可以使用 <quote>+service_name</quote> 將另一個 PAM 服務名稱加入預設集合,或使" +"用 <quote>-service_name</quote> 明確地從預設集合移除 PAM 服務名稱。例如,若要" +"將此登入權限的預設 PAM 服務名稱(例如 <quote>ftp</quote>)取代為自訂 pam 服務" +"名稱(例如 <quote>my_pam_service</quote>),您可以使用下列設定:<placeholder " +"type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:816 msgid "ftp" -msgstr "" +msgstr "ftp" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:821 msgid "samba" -msgstr "" +msgstr "samba" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:830 msgid "ad_gpo_map_batch (string)" -msgstr "" +msgstr "ad_gpo_map_batch (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:833 @@ -11471,6 +13123,13 @@ msgid "" "GPO contains batch logon right settings, the user is granted logon access " "only, if it or at least one of its groups is part of the policy settings." msgstr "" +"以 BatchLogonRight 與 DenyBatchLogonRight 原則設定評估 GPO 型存取控制的 PAM " +"服務名稱逗號分隔清單。只會評估使用者具有讀取與套用群組原則權限的 GPO(請參閱 " +"<quote>ad_gpo_access_control</quote> 選項)。若評估的 GPO 包含針對使用者或其" +"其中一個群組的拒絕批次登入設定,使用者會被拒絕批次登入存取。若評估的 GPO 中沒" +"有定義批次登入權限,使用者會被授予登入存取。若至少一個評估的 GPO 包含批次登入" +"權限設定,則只有使用者或其至少一個群組屬於原則設定的一部分時,使用者才會被授" +"予登入存取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:851 @@ -11478,6 +13137,8 @@ msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a batch job\" and \"Deny log on as a batch job\"." msgstr "" +"注意:使用群組原則管理編輯器時,此值稱為 \"Allow log on as a batch job\" 與 " +"\"Deny log on as a batch job\"。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd-ad.5.xml:865 @@ -11486,6 +13147,8 @@ msgid "" "ad_gpo_map_batch = +my_pam_service, -crond\n" " " msgstr "" +"ad_gpo_map_batch = +my_pam_service, -crond\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:856 @@ -11498,21 +13161,26 @@ msgid "" "(e.g. <quote>my_pam_service</quote>), you would use the following " "configuration: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"可以使用 <quote>+service_name</quote> 將另一個 PAM 服務名稱加入預設集合,或使" +"用 <quote>-service_name</quote> 明確地從預設集合移除 PAM 服務名稱。例如,若要" +"將此登入權限的預設 PAM 服務名稱(例如 <quote>crond</quote>)取代為自訂 pam 服" +"務名稱(例如 <quote>my_pam_service</quote>),您可以使用下列設定" +":<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:868 msgid "Note: Cron service name may differ depending on Linux distribution used." -msgstr "" +msgstr "注意:Cron 服務名稱可能因使用的 Linux 發行版而異。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:874 msgid "crond" -msgstr "" +msgstr "crond" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:883 msgid "ad_gpo_map_service (string)" -msgstr "" +msgstr "ad_gpo_map_service (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:886 @@ -11529,6 +13197,13 @@ msgid "" "logon access only, if it or at least one of its groups is part of the policy " "settings." msgstr "" +"以 ServiceLogonRight 與 DenyServiceLogonRight 原則設定評估 GPO 型存取控制的 " +"PAM 服務名稱逗號分隔清單。只會評估使用者具有讀取與套用群組原則權限的 GPO(請" +"參閱 <quote>ad_gpo_access_control</quote> 選項)。若評估的 GPO 包含針對使用者" +"或其其中一個群組的拒絕服務登入設定,使用者會被拒絕服務登入存取。若評估的 GPO " +"中沒有定義服務登入權限,使用者會被授予登入存取。若至少一個評估的 GPO 包含服務" +"登入權限設定,則只有使用者或其至少一個群組屬於原則設定的一部分時,使用者才會" +"被授予登入存取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:904 @@ -11536,6 +13211,8 @@ msgid "" "Note: Using the Group Policy Management Editor this value is called \"Allow " "log on as a service\" and \"Deny log on as a service\"." msgstr "" +"注意:使用群組原則管理編輯器時,此值稱為 \"Allow log on as a service\" 與 " +"\"Deny log on as a service\"。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd-ad.5.xml:917 @@ -11544,6 +13221,8 @@ msgid "" "ad_gpo_map_service = +my_pam_service\n" " " msgstr "" +"ad_gpo_map_service = +my_pam_service\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:909 sssd-ad.5.xml:984 @@ -11555,18 +13234,22 @@ msgid "" "you would use the following configuration: <placeholder " "type=\"programlisting\" id=\"0\"/>" msgstr "" +"可以使用 <quote>+service_name</quote> 將 PAM 服務名稱加入預設集合。由於預設集" +"合是空的,無法從預設集合移除 PAM 服務名稱。例如,若要加入自訂 pam 服務名稱(" +"例如 <quote>my_pam_service</quote>),您可以使用下列設定:<placeholder " +"type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:927 msgid "ad_gpo_map_permit (string)" -msgstr "" +msgstr "ad_gpo_map_permit (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:930 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always granted, regardless of any GPO Logon Rights." -msgstr "" +msgstr "無論任何 GPO 登入權限為何,一律授予 GPO 型存取的 PAM 服務名稱逗號分隔清單。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd-ad.5.xml:944 @@ -11575,6 +13258,8 @@ msgid "" "ad_gpo_map_permit = +my_pam_service, -sudo\n" " " msgstr "" +"ad_gpo_map_permit = +my_pam_service, -sudo\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:935 @@ -11587,28 +13272,33 @@ msgid "" "(e.g. <quote>my_pam_service</quote>), you would use the following " "configuration: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"可以使用 <quote>+service_name</quote> 將另一個 PAM 服務名稱加入預設集合,或使" +"用 <quote>-service_name</quote> 明確地從預設集合移除 PAM 服務名稱。例如,若要" +"將無條件允許存取的預設 PAM 服務名稱(例如 <quote>sudo</quote>)取代為自訂 " +"pam 服務名稱(例如 <quote>my_pam_service</quote>),您可以使用下列設定" +":<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:952 msgid "polkit-1" -msgstr "" +msgstr "polkit-1" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:967 msgid "systemd-user" -msgstr "" +msgstr "systemd-user" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:976 msgid "ad_gpo_map_deny (string)" -msgstr "" +msgstr "ad_gpo_map_deny (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:979 msgid "" "A comma-separated list of PAM service names for which GPO-based access is " "always denied, regardless of any GPO Logon Rights." -msgstr "" +msgstr "無論任何 GPO 登入權限為何,一律拒絕 GPO 型存取的 PAM 服務名稱逗號分隔清單。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd-ad.5.xml:992 @@ -11617,11 +13307,13 @@ msgid "" "ad_gpo_map_deny = +my_pam_service\n" " " msgstr "" +"ad_gpo_map_deny = +my_pam_service\n" +" " #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:1002 msgid "ad_gpo_default_right (string)" -msgstr "" +msgstr "ad_gpo_default_right (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1005 @@ -11635,51 +13327,56 @@ msgid "" "settings. Alternatively, this option can be set to either always permit or " "always deny access for unmapped PAM service names." msgstr "" +"此選項定義如何為未明確列在任何 ad_gpo_map_* 選項中的 PAM 服務名稱評估存取控制" +"。此選項可以以兩種不同的方式設定。首先,此選項可以設為使用預設登入權限。例如" +",若此選項設為 'interactive',表示未對應的 PAM 服務名稱會根據 " +"InteractiveLogonRight 與 DenyInteractiveLogonRight 原則設定處理。另一種做法是" +",此選項可以設為一律允許或一律拒絕未對應 PAM 服務名稱的存取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1018 msgid "Supported values for this option include:" -msgstr "" +msgstr "此選項支援的值包括:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:1027 msgid "remote_interactive" -msgstr "" +msgstr "remote_interactive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:1032 msgid "network" -msgstr "" +msgstr "network" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:1037 msgid "batch" -msgstr "" +msgstr "batch" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:1042 msgid "service" -msgstr "" +msgstr "service" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:1047 msgid "permit" -msgstr "" +msgstr "permit" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para> #: sssd-ad.5.xml:1052 msgid "deny" -msgstr "" +msgstr "deny" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1058 msgid "Default: deny" -msgstr "" +msgstr "預設:deny" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:1064 msgid "ad_maximum_machine_account_password_age (integer)" -msgstr "" +msgstr "ad_maximum_machine_account_password_age (integer)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1067 @@ -11688,16 +13385,18 @@ msgid "" "given age in days and try to renew it. A value of 0 will disable the renewal " "attempt." msgstr "" +"SSSD 每天會檢查一次電腦帳戶密碼是否超過指定的天數,並嘗試更新它。值 0 會停用" +"更新嘗試。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1073 msgid "Default: 30 days" -msgstr "" +msgstr "預設:30 天" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:1079 msgid "ad_machine_account_password_renewal_opts (string)" -msgstr "" +msgstr "ad_machine_account_password_renewal_opts (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1082 @@ -11708,16 +13407,19 @@ msgid "" "second specifies the initial timeout in seconds before the task is run for " "the first time after startup." msgstr "" +"此選項只應用於測試電腦帳戶更新工作。此選項預期 2 個以冒號 (':') 分隔的整數。" +"第一個整數定義工作執行的間隔(秒)。第二個指定啟動後第一次執行工作之前的初始" +"逾時(秒)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1091 msgid "Default: 86400:750 (24h and 15m)" -msgstr "" +msgstr "預設:86400:750(24 小時與 15 分鐘)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:1097 msgid "ad_update_samba_machine_account_password (boolean)" -msgstr "" +msgstr "ad_update_samba_machine_account_password (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1100 @@ -11727,11 +13429,13 @@ msgid "" "account password from getting out of date when it is set up to use AD for " "authentication." msgstr "" +"若啟用,SSSD 更新電腦帳戶密碼時,也會更新 Samba 資料庫中的密碼。這可以防止設" +"定為使用 AD 驗證時,Samba 的電腦帳戶密碼副本過期。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:1113 msgid "ad_use_ldaps (bool)" -msgstr "" +msgstr "ad_use_ldaps (bool)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1116 @@ -11743,11 +13447,15 @@ msgid "" "use SASL/GSSAPI or SASL/GSS-SPNEGO for authentication the SASL security " "property maxssf is set to 0 (zero) for those connections." msgstr "" +"預設情況下,SSSD 使用純文字 LDAP 連接埠 389 與全域目錄連接埠 3628。若此選項設" +"為 True,SSSD 會使用具有 LDAPS 保護的 LDAPS 連接埠 636 與全域目錄連接埠 3629" +"。由於 AD 不允許在單一連線上有多層加密,而我們仍希望使用 SASL/GSSAPI 或 SASL/" +"GSS-SPNEGO 進行驗證,因此這些連線的 SASL 安全性屬性 maxssf 會設為 0(零)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ad.5.xml:1133 msgid "ad_allow_remote_domain_local_groups (boolean)" -msgstr "" +msgstr "ad_allow_remote_domain_local_groups (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1136 @@ -11759,6 +13467,10 @@ msgid "" "solutions which make AD users and groups available on Linux client this " "option was added." msgstr "" +"若此選項設為 <quote>true</quote>,SSSD 不會過濾掉 AD 樹系中遠端網域的網域本機" +"群組。預設會將它們過濾掉,例如追蹤遠端網域中的巢狀群組階層時,因為它們在網域" +"本機中無效。為了與其他讓 AD 使用者與群組在 Linux 用戶端上可用的解決方案相容," +"加入了此選項。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1146 @@ -11774,6 +13486,12 @@ msgid "" "the Kerberos ticket for a local service or in tokenGroups requests where " "remote Domain Local groups are missing as well." msgstr "" +"請注意,將此選項設為 <quote>true</quote> 會違背 Active Directory 中網域本機群" +"組的用意,<emphasis>只應用於促成從其他解決方案遷移</emphasis>。雖然群組存在且" +"使用者可以是群組的成員,但用意是群組只應在其定義的網域中使用,而不應在其他網" +"域中使用。由於只有一種 POSIX 群組類型,要在 Linux 端達成這一點,唯一的方法是" +"忽略這些群組。Active Directory 也是這樣做的,這可以從本機服務 Kerberos 票證" +"的 PAC 中看到,或從 tokenGroups 要求中看到,其中也缺少遠端網域本機群組。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1162 @@ -11787,6 +13505,12 @@ msgid "" "<quote>ldap_group_nesting_level</quote> if the remote Domain Local groups " "can only be found with a deeper nesting level." msgstr "" +"鑑於上述註解,若此選項設為 <quote>true</quote>,必須將 <quote>" +"ldap_use_tokengroups</quote> 設為 <quote>false</quote> 來停用 tokenGroups 要" +"求,才能取得一致的使用者群組成員資格。此外,也應將 <quote>ad_enable_gc</" +"quote> 設為 <quote>false</quote> 跳過全域目錄查詢。最後,若遠端網域本機群組只" +"能用更深的巢狀層級找到,可能有必要修改 <quote>ldap_group_nesting_level</" +"quote>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1185 @@ -11798,18 +13522,22 @@ msgid "" "AD LDAP connection is used for the updates, if it is not otherwise specified " "by using the <quote>dyndns_iface</quote> option." msgstr "" +"選用。此選項告訴 SSSD 自動以本用戶端的 IP 位址更新 Active Directory DNS 伺服" +"器。更新使用 GSS-TSIG 保護。因此,Active Directory 管理員只需要允許 DNS 區域" +"的安全更新。若未使用 <quote>dyndns_iface</quote> 選項另行指定,則使用 AD " +"LDAP 連線的 IP 位址進行更新。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1215 msgid "Default: 3600 (seconds)" -msgstr "" +msgstr "預設:3600(秒)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1231 msgid "" "Default: Use the IP addresses of the interface which is used for AD LDAP " "connection" -msgstr "" +msgstr "預設:使用用於 AD LDAP 連線之介面的 IP 位址" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ad.5.xml:1244 @@ -11820,6 +13548,9 @@ msgid "" "lowest possible value is 60 seconds in-case if value is provided less than " "60, parameter will assume lowest value only." msgstr "" +"除了後端上線時執行的自動更新之外,後端應多久執行一次週期性 DNS 更新。此選項是" +"選用的,只在 dyndns_update 為 true 時適用。請注意,可能的最低值是 60 秒,若提" +"供的值低於 60,參數只會採用最低值。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:1394 @@ -11828,6 +13559,8 @@ msgid "" "example.com is one of the domains in the <replaceable>[sssd]</replaceable> " "section. This example shows only the AD provider-specific options." msgstr "" +"下列範例假設 SSSD 已正確設定,且 example.com 是 <replaceable>[sssd]</" +"replaceable> 區段中的其中一個網域。此範例只顯示 AD 提供者專屬的選項。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-ad.5.xml:1401 @@ -11843,6 +13576,15 @@ msgid "" "ad_hostname = client.example.com\n" "ad_domain = example.com\n" msgstr "" +"[domain/EXAMPLE]\n" +"id_provider = ad\n" +"auth_provider = ad\n" +"access_provider = ad\n" +"chpass_provider = ad\n" +"\n" +"ad_server = dc1.example.com\n" +"ad_hostname = client.example.com\n" +"ad_domain = example.com\n" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-ad.5.xml:1421 @@ -11852,6 +13594,9 @@ msgid "" "ldap_access_order = expire\n" "ldap_account_expire_policy = ad\n" msgstr "" +"access_provider = ldap\n" +"ldap_access_order = expire\n" +"ldap_account_expire_policy = ad\n" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:1417 @@ -11860,6 +13605,8 @@ msgid "" "same effect as the following configuration of the LDAP provider: " "<placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"AD 存取控制提供者檢查帳戶是否已到期。它與 LDAP 提供者的下列設定有相同的效果" +":<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:1427 @@ -11870,6 +13617,9 @@ msgid "" "you need to set all the connection parameters (such as LDAP URIs and " "encryption details) manually." msgstr "" +"不過,除非明確設定 <quote>ad</quote> 存取控制提供者,否則預設的 access 提供者" +"是 <quote>permit</quote>。請注意,若您設定 <quote>ad</quote> 以外的 access 提" +"供者,需要手動設定所有連線參數(例如 LDAP URI 與加密詳細資料)。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ad.5.xml:1435 @@ -11878,16 +13628,18 @@ msgid "" "attribute mapping (nisMap, nisObject, ...) is used, because these attributes " "are included in the default Active Directory schema." msgstr "" +"當 autofs 提供者設為 <quote>ad</quote> 時,會使用 RFC2307 綱要屬性對應(" +"nisMap、nisObject、...),因為這些屬性包含在預設的 Active Directory 綱要中。" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-sudo.5.xml:10 sssd-sudo.5.xml:16 msgid "sssd-sudo" -msgstr "" +msgstr "sssd-sudo" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-sudo.5.xml:17 msgid "Configuring sudo with the SSSD back end" -msgstr "" +msgstr "使用 SSSD 後端設定 sudo" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:23 @@ -11897,11 +13649,15 @@ msgid "" "to work with <citerefentry> <refentrytitle>sssd</refentrytitle> " "<manvolnum>8</manvolnum> </citerefentry> and how SSSD caches sudo rules." msgstr "" +"本手冊頁說明如何設定 <citerefentry> <refentrytitle>sudo</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> 與 <citerefentry> <refentrytitle>" +"sssd</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> 一起運作,以及 " +"SSSD 如何快取 sudo 規則。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-sudo.5.xml:36 msgid "Configuring sudo to cooperate with SSSD" -msgstr "" +msgstr "設定 sudo 與 SSSD 合作" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:38 @@ -11911,6 +13667,9 @@ msgid "" "<refentrytitle>nsswitch.conf</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry>." msgstr "" +"若要啟用 SSSD 作為 sudo 規則的來源,請在 <citerefentry> <refentrytitle>" +"nsswitch.conf</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 中將 " +"<emphasis>sss</emphasis> 加入 <emphasis>sudoers</emphasis> 項目。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:47 @@ -11921,12 +13680,16 @@ msgid "" "that apply to local users) and then in SSSD, the nsswitch.conf file should " "contain the following line:" msgstr "" +"例如,若要設定 sudo 先在標準 <citerefentry> <refentrytitle>sudoers</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 檔案(應包含適用於本" +"機使用者的規則)中查詢規則,然後再在 SSSD 中查詢,nsswitch.conf 檔案應包含下" +"列這一行:" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-sudo.5.xml:57 #, no-wrap msgid "sudoers: files sss\n" -msgstr "" +msgstr "sudoers: files sss\n" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:61 @@ -11937,6 +13700,10 @@ msgid "" "<refentrytitle>sudoers.ldap</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry>." msgstr "" +"有關從 nsswitch.conf 檔案設定 sudoers 搜尋順序的更多資訊,以及用於在目錄中儲" +"存 sudo 規則之 LDAP 綱要的資訊,可以在 <citerefentry> <refentrytitle>" +"sudoers.ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 中找到" +"。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:70 @@ -11947,11 +13714,15 @@ msgid "" "</citerefentry> to your NIS domain name (which equals to IPA domain name " "when using hostgroups)." msgstr "" +"<emphasis>注意</emphasis>:若要在 sudo 規則中使用 netgroup 或 IPA hostgroup," +"您還需要將 <citerefentry> <refentrytitle>nisdomainname</refentrytitle> " +"<manvolnum>1</manvolnum> </citerefentry> 正確設為您的 NIS 網域名稱(使用 " +"hostgroup 時等於 IPA 網域名稱)。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-sudo.5.xml:82 msgid "Configuring SSSD to fetch sudo rules" -msgstr "" +msgstr "設定 SSSD 取回 sudo 規則" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:84 @@ -11963,13 +13734,18 @@ msgid "" "can also set search base for sudo rules using " "<emphasis>ldap_sudo_search_base</emphasis> option." msgstr "" +"SSSD 端需要的所有設定,就是在 <citerefentry> <refentrytitle>sssd.conf</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 的 [sssd] 區段中,以 " +"\"sudo\" 擴充 <emphasis>services</emphasis> 清單。若要加速 LDAP 查詢,您也可" +"以使用 <emphasis>ldap_sudo_search_base</emphasis> 選項設定 sudo 規則的搜尋基" +"礎。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:94 msgid "" "The following example shows how to configure SSSD to download sudo rules " "from an LDAP server." -msgstr "" +msgstr "下列範例顯示如何設定 SSSD 從 LDAP 伺服器下載 sudo 規則。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-sudo.5.xml:99 @@ -11985,6 +13761,15 @@ msgid "" "ldap_uri = ldap://example.com\n" "ldap_sudo_search_base = ou=sudoers,dc=example,dc=com\n" msgstr "" +"[sssd]\n" +"services = nss, pam, sudo\n" +"domains = EXAMPLE\n" +"\n" +"[domain/EXAMPLE]\n" +"id_provider = ldap\n" +"sudo_provider = ldap\n" +"ldap_uri = ldap://example.com\n" +"ldap_sudo_search_base = ou=sudoers,dc=example,dc=com\n" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:98 @@ -11995,6 +13780,10 @@ msgid "" "list of services, as it became optional. However, sssd-sudo.socket must be " "enabled instead. </phrase>" msgstr "" +"<placeholder type=\"programlisting\" id=\"0\"/> <phrase " +"condition=\"have_systemd\"> 請務必注意,在支援 systemd 的平台上,不需要將 " +"\"sudo\" 提供者加入服務清單,因為它已變成選用的。不過,必須改為啟用 sssd-" +"sudo.socket。 </phrase>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:117 @@ -12005,11 +13794,15 @@ msgid "" "sssd.conf, this value will be used instead. The compat tree " "(ou=sudoers,$SUFFIX) is no longer required for IPA sudo functionality." msgstr "" +"當 SSSD 設定為使用 IPA 作為 ID 提供者時,sudo 提供者會自動啟用。sudo 搜尋基礎" +"設定為使用 IPA 原生 LDAP 樹 (cn=sudo,$SUFFIX)。若在 sssd.conf 中定義了任何其" +"他搜尋基礎,則改用該值。IPA sudo 功能不再需要 compat 樹 (ou=sudoers,$SUFFIX)" +"。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-sudo.5.xml:127 msgid "The SUDO rule caching mechanism" -msgstr "" +msgstr "SUDO 規則快取機制" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:129 @@ -12021,6 +13814,10 @@ msgid "" "of updates. They are referred to as full refresh, smart refresh and rules " "refresh." msgstr "" +"在 SSSD 中開發 sudo 支援時最大的挑戰,是確保以 SSSD 作為資料來源執行 sudo 時" +",提供與 sudo 相同的使用者體驗與速度,同時盡可能持續提供最新的規則集。為滿足" +"這些要求,SSSD 使用三種更新。它們被稱為完整重新整理、智慧型重新整理與規則重新" +"整理。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:137 @@ -12030,6 +13827,8 @@ msgid "" "database growing by fetching only small increments that do not generate " "large amounts of network traffic." msgstr "" +"<emphasis>智慧型重新整理</emphasis>會定期下載新的或上次更新後修改過的規則。它" +"的主要目標是只取回不會產生大量網路流量的少量增量,讓資料庫持續成長。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:143 @@ -12041,6 +13840,10 @@ msgid "" "of traffic and thus it should be run only occasionally depending on the size " "and stability of the sudo rules." msgstr "" +"<emphasis>完整重新整理</emphasis>只會刪除快取中儲存的所有 sudo 規則,並以伺服" +"器上儲存的所有規則取代。這用來移除每個已從伺服器刪除的規則,以保持快取一致。" +"不過,完整重新整理可能產生大量流量,因此視 sudo 規則的大小與穩定性,應該只偶" +"爾執行。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:151 @@ -12053,6 +13856,10 @@ msgid "" "refresh because more rules (that apply to other users) may have been " "deleted." msgstr "" +"<emphasis>規則重新整理</emphasis>確保我們不會授予使用者超出定義的權限。它會在" +"使用者每次執行 sudo 時觸發。規則重新整理會找出適用於此使用者的所有規則,檢查" +"它們的到期時間,若已到期則重新下載。若其中任何規則在伺服器上遺失,SSSD 會執行" +"帶外完整重新整理,因為可能有更多規則(適用於其他使用者的規則)已被刪除。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:160 @@ -12061,36 +13868,38 @@ msgid "" "machine. This means rules that contain one of the following values in " "<emphasis>sudoHost</emphasis> attribute:" msgstr "" +"若啟用,SSSD 只會儲存可以套用於此機器的規則。這表示 <emphasis>sudoHost</" +"emphasis> 屬性中包含下列值之一的規則:" #. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> #: sssd-sudo.5.xml:167 msgid "keyword ALL" -msgstr "" +msgstr "關鍵字 ALL" #. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> #: sssd-sudo.5.xml:172 msgid "wildcard" -msgstr "" +msgstr "萬用字元" #. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> #: sssd-sudo.5.xml:177 msgid "netgroup (in the form \"+netgroup\")" -msgstr "" +msgstr "netgroup(形式為 \"+netgroup\")" #. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> #: sssd-sudo.5.xml:182 msgid "hostname or fully qualified domain name of this machine" -msgstr "" +msgstr "此機器的主機名稱或完整網域名稱" #. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> #: sssd-sudo.5.xml:187 msgid "one of the IP addresses of this machine" -msgstr "" +msgstr "此機器的其中一個 IP 位址" #. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para> #: sssd-sudo.5.xml:192 msgid "one of the IP addresses of the network (in the form \"address/mask\")" -msgstr "" +msgstr "網路的其中一個 IP 位址(形式為 \"address/mask\")" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:198 @@ -12102,11 +13911,15 @@ msgid "" "<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry>." msgstr "" +"有許多設定選項可以用來調整行為。請參閱 <citerefentry> <refentrytitle>sssd-" +"ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 中的 " +"\"ldap_sudo_*\" 與 <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> 中的 \"sudo_*\"。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-sudo.5.xml:212 msgid "Tuning the performance" -msgstr "" +msgstr "調整效能" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:214 @@ -12117,6 +13930,9 @@ msgid "" "paragraphs contain few tips on how to fine- tune the configuration to your " "requirements." msgstr "" +"SSSD 使用不同種類、複雜度不一的 LDAP 篩選器機制來保持快取的 sudo 規則為最新。" +"預設設定為應能滿足大多數使用者的值,但下列段落包含一些如何將設定微調為符合您" +"需求的秘訣。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:221 @@ -12124,6 +13940,8 @@ msgid "" "1. <emphasis>Index LDAP attributes</emphasis>. Make sure that following LDAP " "attributes are indexed: objectClass, cn, entryUSN or modifyTimestamp." msgstr "" +"1. <emphasis>為 LDAP 屬性建立索引</emphasis>。請確定下列 LDAP 屬性已建立索引" +":objectClass、cn、entryUSN 或 modifyTimestamp。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:226 @@ -12131,6 +13949,8 @@ msgid "" "2. <emphasis>Set ldap_sudo_search_base</emphasis>. Set the search base to " "the container that holds the sudo rules to limit the scope of the lookup." msgstr "" +"2. <emphasis>設定 ldap_sudo_search_base</emphasis>。將搜尋基礎設為保存 sudo " +"規則的容器,以限制查詢的範圍。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:231 @@ -12143,6 +13963,11 @@ msgid "" "disabling the smart refresh by setting " "<emphasis>ldap_sudo_smart_refresh_interval = 0</emphasis>." msgstr "" +"3. <emphasis>設定完整與智慧型重新整理間隔</emphasis>。若您的 sudo 規則不常變" +"更,且不需要用戶端上的快取規則快速更新,可以考慮增加 <emphasis>" +"ldap_sudo_full_refresh_interval</emphasis> 與 <emphasis>" +"ldap_sudo_smart_refresh_interval</emphasis>。也可以考慮將 <emphasis>" +"ldap_sudo_smart_refresh_interval = 0</emphasis> 來停用智慧型重新整理。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-sudo.5.xml:240 @@ -12151,16 +13976,18 @@ msgid "" "value of <emphasis>ldap_sudo_random_offset</emphasis> to distribute the load " "on the server better." msgstr "" +"4. 若您有大量的用戶端,可以考慮增加 <emphasis>ldap_sudo_random_offset</" +"emphasis> 的值,以更均勻地分散伺服器上的負載。" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd.8.xml:10 sssd.8.xml:15 msgid "sssd" -msgstr "" +msgstr "sssd" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd.8.xml:16 msgid "System Security Services Daemon" -msgstr "" +msgstr "系統安全服務精靈" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: sssd.8.xml:21 @@ -12168,6 +13995,8 @@ msgid "" "<command>sssd</command> <arg choice='opt'> " "<replaceable>options</replaceable> </arg>" msgstr "" +"<command>sssd</command> <arg choice='opt'> <replaceable>options</" +"replaceable> </arg>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.8.xml:31 @@ -12180,6 +14009,10 @@ msgid "" "FreeIPA. It provides a more robust database to store local users as well as " "extended user data." msgstr "" +"<command>SSSD</command> 提供一組精靈來管理對遠端目錄與驗證機制的存取。它向系" +"統提供 NSS 與 PAM 介面,以及連線到多個不同帳戶來源的可插拔後端系統,還有 D-" +"Bus 介面。它也是為 FreeIPA 之類的專案提供用戶端稽核與原則服務的基礎。它提供更" +"穩固的資料庫來儲存本機使用者與延伸使用者資料。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:46 @@ -12187,53 +14020,55 @@ msgid "" "<option>-d</option>,<option>--debug-level</option> " "<replaceable>LEVEL</replaceable>" msgstr "" +"<option>-d</option>,<option>--debug-level</option> <replaceable>LEVEL</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:53 msgid "<option>--debug-timestamps=</option><replaceable>mode</replaceable>" -msgstr "" +msgstr "<option>--debug-timestamps=</option><replaceable>mode</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:57 msgid "<emphasis>1</emphasis>: Add a timestamp to the debug messages" -msgstr "" +msgstr "<emphasis>1</emphasis>:在除錯訊息中加入時間戳記" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:60 msgid "<emphasis>0</emphasis>: Disable timestamp in the debug messages" -msgstr "" +msgstr "<emphasis>0</emphasis>:停用除錯訊息中的時間戳記" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:69 msgid "<option>--debug-microseconds=</option><replaceable>mode</replaceable>" -msgstr "" +msgstr "<option>--debug-microseconds=</option><replaceable>mode</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:73 msgid "<emphasis>1</emphasis>: Add microseconds to the timestamp in debug messages" -msgstr "" +msgstr "<emphasis>1</emphasis>:在除錯訊息中的時間戳記加入微秒" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:76 msgid "<emphasis>0</emphasis>: Disable microseconds in timestamp" -msgstr "" +msgstr "<emphasis>0</emphasis>:停用時間戳記中的微秒" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:85 msgid "<option>--logger=</option><replaceable>value</replaceable>" -msgstr "" +msgstr "<option>--logger=</option><replaceable>value</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:89 msgid "Location where SSSD will send log messages." -msgstr "" +msgstr "SSSD 傳送記錄訊息的位置。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:92 msgid "" "<emphasis>stderr</emphasis>: Redirect debug messages to standard error " "output." -msgstr "" +msgstr "<emphasis>stderr</emphasis>:將除錯訊息重新導向到標準錯誤輸出。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:96 @@ -12242,41 +14077,44 @@ msgid "" "default, the log files are stored in <filename>/var/log/sssd</filename> and " "there are separate log files for every SSSD service and domain." msgstr "" +"<emphasis>files</emphasis>:將除錯訊息重新導向到記錄檔。預設情況下,記錄檔儲" +"存在 <filename>/var/log/sssd</filename>,每個 SSSD 服務與網域都有各自的記錄檔" +"。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:102 msgid "<emphasis>journald</emphasis>: Redirect debug messages to systemd-journald" -msgstr "" +msgstr "<emphasis>journald</emphasis>:將除錯訊息重新導向到 systemd-journald" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:106 msgid "Default: not set (fall back to journald if available, otherwise to stderr)" -msgstr "" +msgstr "預設:未設定(若可用則退回 journald,否則退回 stderr)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:113 msgid "<option>-D</option>,<option>--daemon</option>" -msgstr "" +msgstr "<option>-D</option>,<option>--daemon</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:117 msgid "Become a daemon after starting up." -msgstr "" +msgstr "啟動後變成精靈。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:123 sss_seed.8.xml:136 msgid "<option>-i</option>,<option>--interactive</option>" -msgstr "" +msgstr "<option>-i</option>,<option>--interactive</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:127 msgid "Run in the foreground, don't become a daemon." -msgstr "" +msgstr "在前景執行,不要變成精靈。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:133 msgid "<option>-c</option>,<option>--config</option>" -msgstr "" +msgstr "<option>-c</option>,<option>--config</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:137 @@ -12287,38 +14125,41 @@ msgid "" "<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> manual page." msgstr "" +"指定非預設的設定檔。預設為 <filename>/etc/sssd/sssd.conf</filename>。設定檔語" +"法與選項的參考請參閱 <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> 手冊頁。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:151 msgid "<option>--version</option>" -msgstr "" +msgstr "<option>--version</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:155 msgid "Print version number and exit." -msgstr "" +msgstr "列印版本號碼並結束。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.8.xml:163 msgid "Signals" -msgstr "" +msgstr "訊號" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:166 msgid "SIGTERM/SIGINT" -msgstr "" +msgstr "SIGTERM/SIGINT" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:169 msgid "" "Informs the SSSD to gracefully terminate all of its child processes and then " "shut down the monitor." -msgstr "" +msgstr "告知 SSSD 正常終止其所有子程序,然後關閉監控器。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:175 msgid "SIGHUP" -msgstr "" +msgstr "SIGHUP" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:178 @@ -12327,11 +14168,13 @@ msgid "" "close and reopen them. This is meant to facilitate log rolling with programs " "like logrotate." msgstr "" +"告訴 SSSD 停止寫入目前的除錯檔案描述符,並關閉與重新開啟它們。這是為了方便使" +"用 logrotate 之類的程式進行記錄輪替。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:186 msgid "SIGUSR1" -msgstr "" +msgstr "SIGUSR1" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:189 @@ -12341,11 +14184,13 @@ msgid "" "signal can be sent to either the sssd process or any sssd_be process " "directly." msgstr "" +"告訴 SSSD 在 <quote>offline_timeout</quote> 參數的期間模擬離線作業。這對測試" +"很有用。此訊號可以直接傳送到 sssd 程序或任何 sssd_be 程序。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:198 msgid "SIGUSR2" -msgstr "" +msgstr "SIGUSR2" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:201 @@ -12354,11 +14199,13 @@ msgid "" "signal can be sent to either the sssd process or any sssd_be process " "directly." msgstr "" +"告訴 SSSD 立即上線。這對測試很有用。此訊號可以直接傳送到 sssd 程序或任何 " +"sssd_be 程序。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:208 msgid "SIGRTMIN+1" -msgstr "" +msgstr "SIGRTMIN+1" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:211 @@ -12367,58 +14214,60 @@ msgid "" "this signal to the providers when a clock shift is detected although it can " "be sent to any sssd_be process directly." msgstr "" +"告訴 SSSD 重新排定週期性工作。內部監看程式在偵測到時鐘偏移時會將此訊號傳送給" +"提供者,雖然它可以直接傳送到任何 sssd_be 程序。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd.8.xml:223 sss_ssh_authorizedkeys.1.xml:141 sss_ssh_knownhosts.1.xml:113 #: sss_ssh_knownhostsproxy.1.xml:112 msgid "EXIT STATUS" -msgstr "" +msgstr "結束狀態" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:226 msgid "0" -msgstr "" +msgstr "0" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:229 msgid "SSSD was shutdown gracefully." -msgstr "" +msgstr "SSSD 已正常關閉。" #. type: Content of: <reference><refentry><refmeta><manvolnum> #: sssd.8.xml:234 sss_ssh_authorizedkeys.1.xml:11 sss_ssh_knownhosts.1.xml:11 #: sss_ssh_knownhostsproxy.1.xml:11 msgid "1" -msgstr "" +msgstr "1" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:237 msgid "Bad configuration or command line option." -msgstr "" +msgstr "設定或命令列選項不正確。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:242 msgid "2" -msgstr "" +msgstr "2" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:245 msgid "Memory allocation error." -msgstr "" +msgstr "記憶體配置錯誤。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:250 msgid "6" -msgstr "" +msgstr "6" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:253 msgid "SSSD is already running." -msgstr "" +msgstr "SSSD 已在執行。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd.8.xml:258 msgid "Other codes" -msgstr "" +msgstr "其他代碼" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd.8.xml:261 @@ -12426,6 +14275,8 @@ msgid "" "Other codes denote different errors, most probably about missing required " "access rights. See SSSD and system logs for details." msgstr "" +"其他代碼表示不同的錯誤,最可能與缺少所需的存取權限有關。詳情請參閱 SSSD 與系" +"統記錄。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.8.xml:272 @@ -12433,23 +14284,25 @@ msgid "" "If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", client " "applications will not use the fast in-memory cache." msgstr "" +"若 SSS_NSS_USE_MEMCACHE 環境變數設為 \"NO\",用戶端應用程式將不會使用快速的記" +"憶體內快取。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd.8.xml:276 msgid "" "If the environment variable SSS_LOCKFREE is set to \"NO\", requests from " "multiple threads of a single application will be serialized." -msgstr "" +msgstr "若 SSS_LOCKFREE 環境變數設為 \"NO\",單一應用程式多個執行緒的要求會被序列化。" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_obfuscate.8.xml:10 sss_obfuscate.8.xml:15 msgid "sss_obfuscate" -msgstr "" +msgstr "sss_obfuscate" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_obfuscate.8.xml:16 msgid "obfuscate a clear text password" -msgstr "" +msgstr "混淆明文密碼" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: sss_obfuscate.8.xml:21 @@ -12458,6 +14311,9 @@ msgid "" "<replaceable>options</replaceable> </arg> <arg " "choice='plain'><replaceable>[PASSWORD]</replaceable></arg>" msgstr "" +"<command>sss_obfuscate</command> <arg choice='opt'> <replaceable>options</" +"replaceable> </arg> <arg choice='plain'><replaceable>[PASSWORD]</replaceable>" +"</arg>" #. type: Content of: <reference><refentry><refsect1><para> #: sss_obfuscate.8.xml:32 @@ -12466,6 +14322,8 @@ msgid "" "human-unreadable format and places it into appropriate domain section of the " "SSSD config file." msgstr "" +"<command>sss_obfuscate</command> 將給定的密碼轉換為人類無法閱讀的格式,並將它" +"放入 SSSD 設定檔的適當網域區段。" #. type: Content of: <reference><refentry><refsect1><para> #: sss_obfuscate.8.xml:37 @@ -12478,6 +14336,11 @@ msgid "" "<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> for more details on these parameters." msgstr "" +"明文密碼從標準輸入讀取或以互動方式輸入。混淆的密碼會放入給定 SSSD 網域的 " +"<quote>ldap_default_authtok</quote> 參數,且 <quote>" +"ldap_default_authtok_type</quote> 參數會設為 <quote>obfuscated_password</" +"quote>。這些參數的更多詳細資料請參閱 <citerefentry> <refentrytitle>sssd-" +"ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para> #: sss_obfuscate.8.xml:49 @@ -12488,16 +14351,19 @@ msgid "" "such as client side certificates or GSSAPI is <emphasis>strongly</emphasis> " "advised." msgstr "" +"請注意,混淆密碼<emphasis>沒有真正的安全性效益</emphasis>,因為攻擊者仍然可以" +"逆向工程還原密碼。<emphasis>強烈</emphasis>建議使用更好的驗證機制,例如用戶端" +"憑證或 GSSAPI。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_obfuscate.8.xml:63 msgid "<option>-s</option>,<option>--stdin</option>" -msgstr "" +msgstr "<option>-s</option>,<option>--stdin</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_obfuscate.8.xml:67 msgid "The password to obfuscate will be read from standard input." -msgstr "" +msgstr "要混淆的密碼會從標準輸入讀取。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_obfuscate.8.xml:74 sss_ssh_authorizedkeys.1.xml:127 @@ -12506,38 +14372,41 @@ msgid "" "<option>-d</option>,<option>--domain</option> " "<replaceable>DOMAIN</replaceable>" msgstr "" +"<option>-d</option>,<option>--domain</option> <replaceable>DOMAIN</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_obfuscate.8.xml:79 msgid "" "The SSSD domain to use the password in. The default name is " "<quote>default</quote>." -msgstr "" +msgstr "要使用密碼的 SSSD 網域。預設名稱為 <quote>default</quote>。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_obfuscate.8.xml:86 msgid "<option>-f</option>,<option>--file</option> <replaceable>FILE</replaceable>" msgstr "" +"<option>-f</option>,<option>--file</option> <replaceable>FILE</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_obfuscate.8.xml:91 msgid "Read the config file specified by the positional parameter." -msgstr "" +msgstr "讀取位置參數指定的設定檔。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_obfuscate.8.xml:95 msgid "Default: <filename>/etc/sssd/sssd.conf</filename>" -msgstr "" +msgstr "預設:<filename>/etc/sssd/sssd.conf</filename>" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_override.8.xml:10 sss_override.8.xml:15 msgid "sss_override" -msgstr "" +msgstr "sss_override" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_override.8.xml:16 msgid "create local overrides of user and group attributes" -msgstr "" +msgstr "建立使用者與群組屬性的本機覆寫" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: sss_override.8.xml:21 @@ -12546,6 +14415,9 @@ msgid "" "choice='plain'><replaceable>COMMAND</replaceable></arg> <arg choice='opt'> " "<replaceable>options</replaceable> </arg>" msgstr "" +"<command>sss_override</command> <arg choice='plain'><replaceable>COMMAND</" +"replaceable></arg> <arg choice='opt'> <replaceable>options</replaceable> </" +"arg>" #. type: Content of: <reference><refentry><refsect1><para> #: sss_override.8.xml:32 @@ -12554,6 +14426,8 @@ msgid "" "allows to change selected values of specific user and groups. This change " "takes effect only on local machine." msgstr "" +"<command>sss_override</command> 可以建立用戶端檢視,並允許變更特定使用者與群" +"組的選定值。此變更只在本機機器上生效。" #. type: Content of: <reference><refentry><refsect1><para> #: sss_override.8.xml:37 @@ -12566,6 +14440,11 @@ msgid "" "take effect. <emphasis>sss_override</emphasis> prints message when a " "restart is required." msgstr "" +"覆寫資料儲存在 SSSD 快取中。若刪除快取,所有本機覆寫都會遺失。請注意,使用下" +"列任何指令 <emphasis>user-add</emphasis>、<emphasis>group-add</emphasis>" +"、<emphasis>user-import</emphasis> 或 <emphasis>group-import</emphasis> 建立" +"第一個覆寫之後,SSSD 需要重新啟動才會生效。<emphasis>sss_override</emphasis> " +"在需要重新啟動時會列印訊息。" #. type: Content of: <reference><refentry><refsect1><para> #: sss_override.8.xml:48 @@ -12575,11 +14454,14 @@ msgid "" "id_provider</quote>. IPA overrides can be managed centrally on the IPA " "server." msgstr "" +"<emphasis>注意:</emphasis>本手冊頁提供的選項只適用於 <quote>ldap</quote> 與 " +"<quote>AD</quote> <quote> id_provider</quote>。IPA 覆寫可以在 IPA 伺服器上集" +"中管理。" #. type: Content of: <reference><refentry><refsect1><title> #: sss_override.8.xml:56 sssctl.8.xml:41 msgid "AVAILABLE COMMANDS" -msgstr "" +msgstr "可用的指令" #. type: Content of: <reference><refentry><refsect1><para> #: sss_override.8.xml:58 @@ -12588,6 +14470,8 @@ msgid "" "commands. It is not possible to override <emphasis>uid</emphasis> or " "<emphasis>gid</emphasis> to 0." msgstr "" +"在所有指令中,<emphasis>NAME</emphasis> 參數是原始物件的名稱。無法將 " +"<emphasis>uid</emphasis> 或 <emphasis>gid</emphasis> 覆寫為 0。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:65 @@ -12602,18 +14486,25 @@ msgid "" "<optional><option>-x,--certificate</option> BASE64 ENCODED " "CERTIFICATE</optional>" msgstr "" +"<option>user-add</option> <emphasis>NAME</emphasis> <optional><option>-n,--" +"name</option> NAME</optional> <optional><option>-u,--uid</option> UID</" +"optional> <optional><option>-g,--gid</option> GID</optional> <optional>" +"<option>-h,--home</option> HOME</optional> <optional><option>-s,--shell</" +"option> SHELL</optional> <optional><option>-c,--gecos</option> GECOS</" +"optional> <optional><option>-x,--certificate</option> BASE64 ENCODED " +"CERTIFICATE</optional>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:78 msgid "" "Override attributes of an user. Please be aware that calling this command " "will replace any previous override for the (NAMEd) user." -msgstr "" +msgstr "覆寫使用者的屬性。請注意,呼叫此指令會取代 (NAMEd) 使用者先前任何的覆寫。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:86 msgid "<option>user-del</option> <emphasis>NAME</emphasis>" -msgstr "" +msgstr "<option>user-del</option> <emphasis>NAME</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:91 @@ -12622,6 +14513,8 @@ msgid "" "returned from memory cache. Please see SSSD option " "<emphasis>memcache_timeout</emphasis> for more details." msgstr "" +"移除使用者覆寫。不過請注意,記憶體快取可能仍會傳回已覆寫的屬性。更多詳細資料" +"請參閱 SSSD 選項 <emphasis>memcache_timeout</emphasis>。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:100 @@ -12629,6 +14522,8 @@ msgid "" "<option>user-find</option> <optional><option>-d,--domain</option> " "DOMAIN</optional>" msgstr "" +"<option>user-find</option> <optional><option>-d,--domain</option> DOMAIN</" +"optional>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:105 @@ -12636,21 +14531,23 @@ msgid "" "List all users with set overrides. If <emphasis>DOMAIN</emphasis> parameter " "is set, only users from the domain are listed." msgstr "" +"列出所有已設定覆寫的使用者。若設定 <emphasis>DOMAIN</emphasis> 參數,只會列出" +"該網域的使用者。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:113 msgid "<option>user-show</option> <emphasis>NAME</emphasis>" -msgstr "" +msgstr "<option>user-show</option> <emphasis>NAME</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:118 msgid "Show user overrides." -msgstr "" +msgstr "顯示使用者覆寫。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:124 msgid "<option>user-import</option> <emphasis>FILE</emphasis>" -msgstr "" +msgstr "<option>user-import</option> <emphasis>FILE</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:129 @@ -12658,11 +14555,13 @@ msgid "" "Import user overrides from <emphasis>FILE</emphasis>. Data format is " "similar to standard passwd file. The format is:" msgstr "" +"從 <emphasis>FILE</emphasis> 匯入使用者覆寫。資料格式類似標準 passwd 檔案。格" +"式為:" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:134 msgid "original_name:name:uid:gid:gecos:home:shell:base64_encoded_certificate" -msgstr "" +msgstr "original_name:name:uid:gid:gecos:home:shell:base64_encoded_certificate" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:137 @@ -12671,21 +14570,23 @@ msgid "" "overridden. The rest of fields correspond to new values. You can omit a " "value simply by leaving corresponding field empty." msgstr "" +"其中 original_name 是要覆寫屬性之使用者的原始名稱。其餘欄位對應新值。您可以直" +"接留空對應欄位來省略值。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:146 msgid "ckent:superman::::::" -msgstr "" +msgstr "ckent:superman::::::" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:149 msgid "ckent@krypton.com::501:501:Superman:/home/earth:/bin/bash:" -msgstr "" +msgstr "ckent@krypton.com::501:501:Superman:/home/earth:/bin/bash:" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:155 msgid "<option>user-export</option> <emphasis>FILE</emphasis>" -msgstr "" +msgstr "<option>user-export</option> <emphasis>FILE</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:160 @@ -12694,6 +14595,8 @@ msgid "" "<emphasis>FILE</emphasis>. See <emphasis>user-import</emphasis> for data " "format." msgstr "" +"匯出所有已覆寫的屬性,並將它們儲存在 <emphasis>FILE</emphasis>。資料格式請參" +"閱 <emphasis>user-import</emphasis>。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:168 @@ -12702,18 +14605,21 @@ msgid "" "<optional><option>-n,--name</option> NAME</optional> " "<optional><option>-g,--gid</option> GID</optional>" msgstr "" +"<option>group-add</option> <emphasis>NAME</emphasis> <optional><option>-n,--" +"name</option> NAME</optional> <optional><option>-g,--gid</option> GID</" +"optional>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:175 msgid "" "Override attributes of a group. Please be aware that calling this command " "will replace any previous override for the (NAMEd) group." -msgstr "" +msgstr "覆寫群組的屬性。請注意,呼叫此指令會取代 (NAMEd) 群組先前任何的覆寫。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:183 msgid "<option>group-del</option> <emphasis>NAME</emphasis>" -msgstr "" +msgstr "<option>group-del</option> <emphasis>NAME</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:188 @@ -12722,6 +14628,8 @@ msgid "" "returned from memory cache. Please see SSSD option " "<emphasis>memcache_timeout</emphasis> for more details." msgstr "" +"移除群組覆寫。不過請注意,記憶體快取可能仍會傳回已覆寫的屬性。更多詳細資料請" +"參閱 SSSD 選項 <emphasis>memcache_timeout</emphasis>。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:197 @@ -12729,6 +14637,8 @@ msgid "" "<option>group-find</option> <optional><option>-d,--domain</option> " "DOMAIN</optional>" msgstr "" +"<option>group-find</option> <optional><option>-d,--domain</option> DOMAIN</" +"optional>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:202 @@ -12736,21 +14646,23 @@ msgid "" "List all groups with set overrides. If <emphasis>DOMAIN</emphasis> " "parameter is set, only groups from the domain are listed." msgstr "" +"列出所有已設定覆寫的群組。若設定 <emphasis>DOMAIN</emphasis> 參數,只會列出該" +"網域的群組。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:210 msgid "<option>group-show</option> <emphasis>NAME</emphasis>" -msgstr "" +msgstr "<option>group-show</option> <emphasis>NAME</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:215 msgid "Show group overrides." -msgstr "" +msgstr "顯示群組覆寫。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:221 msgid "<option>group-import</option> <emphasis>FILE</emphasis>" -msgstr "" +msgstr "<option>group-import</option> <emphasis>FILE</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:226 @@ -12758,11 +14670,13 @@ msgid "" "Import group overrides from <emphasis>FILE</emphasis>. Data format is " "similar to standard group file. The format is:" msgstr "" +"從 <emphasis>FILE</emphasis> 匯入群組覆寫。資料格式類似標準 group 檔案。格式" +"為:" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:231 msgid "original_name:name:gid" -msgstr "" +msgstr "original_name:name:gid" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:234 @@ -12771,21 +14685,23 @@ msgid "" "overridden. The rest of fields correspond to new values. You can omit a " "value simply by leaving corresponding field empty." msgstr "" +"其中 original_name 是要覆寫屬性之群組的原始名稱。其餘欄位對應新值。您可以直接" +"留空對應欄位來省略值。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:243 msgid "admins:administrators:" -msgstr "" +msgstr "admins:administrators:" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:246 msgid "Domain Users:Users:501" -msgstr "" +msgstr "Domain Users:Users:501" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:252 msgid "<option>group-export</option> <emphasis>FILE</emphasis>" -msgstr "" +msgstr "<option>group-export</option> <emphasis>FILE</emphasis>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_override.8.xml:257 @@ -12794,31 +14710,33 @@ msgid "" "<emphasis>FILE</emphasis>. See <emphasis>group-import</emphasis> for data " "format." msgstr "" +"匯出所有已覆寫的屬性,並將它們儲存在 <emphasis>FILE</emphasis>。資料格式請參" +"閱 <emphasis>group-import</emphasis>。" #. type: Content of: <reference><refentry><refsect1><title> #: sss_override.8.xml:267 sssctl.8.xml:50 msgid "COMMON OPTIONS" -msgstr "" +msgstr "一般選項" #. type: Content of: <reference><refentry><refsect1><para> #: sss_override.8.xml:269 sssctl.8.xml:52 msgid "Those options are available with all commands." -msgstr "" +msgstr "這些選項適用於所有指令。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_override.8.xml:274 sssctl.8.xml:57 msgid "<option>--debug</option> <replaceable>LEVEL</replaceable>" -msgstr "" +msgstr "<option>--debug</option> <replaceable>LEVEL</replaceable>" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-krb5.5.xml:10 sssd-krb5.5.xml:16 msgid "sssd-krb5" -msgstr "" +msgstr "sssd-krb5" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-krb5.5.xml:17 msgid "SSSD Kerberos provider" -msgstr "" +msgstr "SSSD Kerberos 提供者" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-krb5.5.xml:23 @@ -12831,6 +14749,10 @@ msgid "" "<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> manual page." msgstr "" +"本手冊頁說明 <citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>" +"8</manvolnum> </citerefentry> 之 Kerberos 5 驗證後端的設定。詳細的語法參考請" +"參閱 <citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> 手冊頁的 <quote>FILE FORMAT</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-krb5.5.xml:36 @@ -12844,6 +14766,10 @@ msgid "" "page for the applicable identity provider for details on how to configure " "this." msgstr "" +"Kerberos 5 驗證後端包含 auth 與 chpass 提供者。它必須與身分提供者配對才能正常" +"運作(例如 id_provider = ldap)。Kerberos 5 驗證後端所需的某些資訊必須由身分" +"提供者提供,例如使用者的 Kerberos Principal Name (UPN)。身分提供者的設定應有" +"指定 UPN 的項目。如何設定的詳細資料請參閱適用身分提供者的手冊頁。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-krb5.5.xml:47 @@ -12855,6 +14781,10 @@ msgid "" "will deny all access to this user. To activate this feature, use " "'access_provider = krb5' in your SSSD configuration." msgstr "" +"此後端也提供以使用者家目錄中 .k5login 檔案為基礎的存取控制。更多詳細資料請參" +"閱 <citerefentry> <refentrytitle>k5login</refentrytitle><manvolnum>5</" +"manvolnum> </citerefentry>。請注意,空的 .k5login 檔案會拒絕此使用者的所有存" +"取。若要啟動此功能,請在 SSSD 設定中使用 'access_provider = krb5'。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-krb5.5.xml:55 @@ -12863,6 +14793,8 @@ msgid "" "<command>sssd</command> will construct a UPN using the format " "<replaceable>username</replaceable>@<replaceable>krb5_realm</replaceable>." msgstr "" +"若身分後端中沒有可用的 UPN,<command>sssd</command> 會使用 <replaceable>" +"username</replaceable>@<replaceable>krb5_realm</replaceable> 格式建構 UPN。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:77 @@ -12875,18 +14807,22 @@ msgid "" "discovery is enabled; for more information, refer to the <quote>SERVICE " "DISCOVERY</quote> section." msgstr "" +"指定 SSSD 應依偏好順序連線之 Kerberos 伺服器的 IP 位址或主機名稱逗號分隔清單" +"。有關故障轉移與伺服器備援的更多資訊,請參閱 <quote>FAILOVER</quote> 一節。可" +"以在位址或主機名稱後面附加選用的連接埠號碼(前面加上冒號)。若為空白,則啟用" +"服務探索;更多資訊請參閱 <quote>SERVICE DISCOVERY</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:106 msgid "" "The name of the Kerberos realm. This option is required and must be " "specified." -msgstr "" +msgstr "Kerberos realm 的名稱。此選項是必要的,必須指定。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:113 msgid "krb5_kpasswd, krb5_backup_kpasswd (string)" -msgstr "" +msgstr "krb5_kpasswd, krb5_backup_kpasswd (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:116 @@ -12895,6 +14831,8 @@ msgid "" "servers can be defined here. An optional port number (preceded by a colon) " "may be appended to the addresses or hostnames." msgstr "" +"若變更密碼服務未在 KDC 上執行,可以在這裡定義替代伺服器。可以在位址或主機名稱" +"後面附加選用的連接埠號碼(前面加上冒號)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:122 @@ -12904,16 +14842,19 @@ msgid "" "servers to try, the backend is not switched to operate offline if " "authentication against the KDC is still possible." msgstr "" +"有關故障轉移與伺服器備援的更多資訊,請參閱 <quote>FAILOVER</quote> 一節。注意" +":即使沒有更多可以嘗試的 kpasswd 伺服器,只要仍可以針對 KDC 驗證,後端就不會" +"切換為離線運作。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:129 msgid "Default: Use the KDC" -msgstr "" +msgstr "預設:使用 KDC" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:135 msgid "krb5_ccachedir (string)" -msgstr "" +msgstr "krb5_ccachedir (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:138 @@ -12922,96 +14863,98 @@ msgid "" "krb5_ccname_template can be used here, too, except %d and %P. The directory " "is created as private and owned by the user, with permissions set to 0700." msgstr "" +"儲存憑證快取的目錄。除了 %d 與 %P 之外,krb5_ccname_template 的所有替換序列也" +"可以在這裡使用。此目錄會以私人權限建立並由使用者擁有,權限設為 0700。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:145 msgid "Default: /tmp" -msgstr "" +msgstr "預設:/tmp" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:151 msgid "krb5_ccname_template (string)" -msgstr "" +msgstr "krb5_ccname_template (string)" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:165 include/override_homedir.xml:11 msgid "%u" -msgstr "" +msgstr "%u" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:166 include/override_homedir.xml:12 msgid "login name" -msgstr "" +msgstr "登入名稱" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:169 include/override_homedir.xml:15 msgid "%U" -msgstr "" +msgstr "%U" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:170 msgid "login UID" -msgstr "" +msgstr "登入 UID" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:173 msgid "%p" -msgstr "" +msgstr "%p" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:174 msgid "principal name" -msgstr "" +msgstr "principal 名稱" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:178 msgid "%r" -msgstr "" +msgstr "%r" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:179 msgid "realm name" -msgstr "" +msgstr "realm 名稱" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:182 include/override_homedir.xml:42 msgid "%h" -msgstr "" +msgstr "%h" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:183 sssd-ifp.5.xml:124 msgid "home directory" -msgstr "" +msgstr "家目錄" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:187 include/override_homedir.xml:19 msgid "%d" -msgstr "" +msgstr "%d" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:188 msgid "value of krb5_ccachedir" -msgstr "" +msgstr "krb5_ccachedir 的值" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:193 include/override_homedir.xml:31 msgid "%P" -msgstr "" +msgstr "%P" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:194 msgid "the process ID of the SSSD client" -msgstr "" +msgstr "SSSD 用戶端的程序 ID" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:199 include/override_homedir.xml:56 msgid "%%" -msgstr "" +msgstr "%%" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:200 include/override_homedir.xml:57 msgid "a literal '%'" -msgstr "" +msgstr "字面上的 '%'" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:154 @@ -13025,6 +14968,12 @@ msgid "" "the template ends with 'XXXXXX' mkstemp(3) is used to create a unique " "filename in a safe way." msgstr "" +"使用者憑證快取的位置。目前支援三種憑證快取類型:<quote>FILE</quote>、<quote>" +"DIR</quote> 與 <quote>KEYRING:persistent</quote>。快取可以指定為 " +"<replaceable>TYPE:RESIDUAL</replaceable>,或指定為絕對路徑(表示 <quote>" +"FILE</quote> 類型)。在範本中,會替換下列序列:<placeholder " +"type=\"variablelist\" id=\"0\"/> 若範本以 'XXXXXX' 結尾,會使用 mkstemp(3) 以" +"安全的方式建立唯一的檔案名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:208 @@ -13034,6 +14983,9 @@ msgid "" "store credentials on a per-UID basis. This is also the recommended choice, " "as it is the most secure and predictable method." msgstr "" +"使用 KEYRING 類型時,唯一支援的機制是 <quote>KEYRING:persistent:%U</quote>," +"它使用 Linux 核心 keyring 以每個 UID 為基礎儲存憑證。這也是最推薦的選擇,因為" +"它是最安全且可預期的方法。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:216 @@ -13044,6 +14996,9 @@ msgid "" "PARAMETER EXPANSION paragraph for additional information on the expansion " "format defined by krb5.conf." msgstr "" +"憑證快取名稱的預設值來自儲存在全系統 krb5.conf 設定檔 [libdefaults] 區段中的" +"設定檔。選項名稱是 default_ccache_name。krb5.conf 定義之展開格式的其他資訊請" +"參閱 krb5.conf(5) 的 PARAMETER EXPANSION 段落。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:225 @@ -13053,35 +15008,38 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> uses different expansion sequences " "than SSSD." msgstr "" +"注意:請注意,<citerefentry> <refentrytitle>krb5.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> 的 libkrb5 ccache 展開範本使用與 " +"SSSD 不同的展開序列。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:234 msgid "Default: (from libkrb5)" -msgstr "" +msgstr "預設:(來自 libkrb5)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:240 msgid "krb5_keytab (string)" -msgstr "" +msgstr "krb5_keytab (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:243 msgid "" "The location of the keytab to use when validating credentials obtained from " "KDCs." -msgstr "" +msgstr "驗證從 KDC 取得的憑證時使用的 keytab 位置。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:253 msgid "krb5_store_password_if_offline (boolean)" -msgstr "" +msgstr "krb5_store_password_if_offline (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:256 msgid "" "Store the password of the user if the provider is offline and use it to " "request a TGT when the provider comes online again." -msgstr "" +msgstr "若提供者離線,儲存使用者的密碼,並在提供者再次上線時使用它要求 TGT。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:261 @@ -13090,25 +15048,27 @@ msgid "" "are kept in plaintext in the kernel keyring and are potentially accessible " "by the root user (with difficulty)." msgstr "" +"注意:此功能只適用於 Linux。以這種方式儲存的密碼會以明文保存在核心 keyring 中" +",root 使用者有可能(困難地)存取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:274 msgid "krb5_use_fast (string)" -msgstr "" +msgstr "krb5_use_fast (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:277 msgid "" "Enables flexible authentication secure tunneling (FAST) for Kerberos " "pre-authentication. The following options are supported:" -msgstr "" +msgstr "啟用 Kerberos 預先驗證的彈性驗證安全通道 (FAST)。支援下列選項:" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:282 msgid "" "<emphasis>never</emphasis> use FAST. This is equivalent to not setting this " "option at all." -msgstr "" +msgstr "<emphasis>never</emphasis>:不使用 FAST。這等同於完全不設定此選項。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:286 @@ -13116,23 +15076,25 @@ msgid "" "<emphasis>try</emphasis> to use FAST. If the server does not support FAST, " "continue the authentication without it." msgstr "" +"<emphasis>try</emphasis>:嘗試使用 FAST。若伺服器不支援 FAST,則在沒有 FAST " +"的情況下繼續驗證。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:291 msgid "" "<emphasis>demand</emphasis> to use FAST. The authentication fails if the " "server does not require fast." -msgstr "" +msgstr "<emphasis>demand</emphasis>:必須使用 FAST。若伺服器不需要 FAST,驗證會失敗。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:296 msgid "Default: not set, i.e. FAST is not used." -msgstr "" +msgstr "預設:未設定,也就是不使用 FAST。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:299 msgid "NOTE: a keytab or support for anonymous PKINIT is required to use FAST." -msgstr "" +msgstr "注意:使用 FAST 需要 keytab 或對匿名 PKINIT 的支援。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:303 @@ -13141,21 +15103,23 @@ msgid "" "SSSD is used with an older version of MIT Kerberos, using this option is a " "configuration error." msgstr "" +"注意:SSSD 只支援 MIT Kerberos 1.8 及更新版本的 FAST。若 SSSD 與較舊版本的 " +"MIT Kerberos 一起使用,使用此選項是設定錯誤。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:312 msgid "krb5_fast_principal (string)" -msgstr "" +msgstr "krb5_fast_principal (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:315 msgid "Specifies the server principal to use for FAST." -msgstr "" +msgstr "指定用於 FAST 的伺服器 principal。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:321 msgid "krb5_fast_use_anonymous_pkinit (boolean)" -msgstr "" +msgstr "krb5_fast_use_anonymous_pkinit (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:324 @@ -13164,11 +15128,13 @@ msgid "" "required credential for FAST. The krb5_fast_principal options is ignored in " "this case." msgstr "" +"若設為 true,嘗試使用匿名 PKINIT 而不是 keytab 取得 FAST 所需的憑證。這種情況" +"下會忽略 krb5_fast_principal 選項。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:364 msgid "krb5_kdcinfo_lookahead (string)" -msgstr "" +msgstr "krb5_kdcinfo_lookahead (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:367 @@ -13179,6 +15145,10 @@ msgid "" "<manvolnum>8</manvolnum> </citerefentry>. This might be helpful when there " "are too many servers discovered using SRV record." msgstr "" +"當 krb5_use_kdcinfo 設為 true 時,您可以限制交給 <citerefentry> " +"<refentrytitle>sssd_krb5_locator_plugin</refentrytitle> <manvolnum>8</" +"manvolnum> </citerefentry> 的伺服器數量。當使用 SRV 記錄探索到太多伺服器時," +"這可能很有幫助。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:377 @@ -13187,6 +15157,8 @@ msgid "" "colon. The first number represents number of primary servers used and the " "second number specifies the number of backup servers." msgstr "" +"krb5_kdcinfo_lookahead 選項包含兩個以冒號分隔的數字。第一個數字代表使用的主要" +"伺服器數目,第二個數字指定備份伺服器的數目。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:383 @@ -13196,16 +15168,19 @@ msgid "" "<refentrytitle>sssd_krb5_locator_plugin</refentrytitle> " "<manvolnum>8</manvolnum> </citerefentry> but no backup servers." msgstr "" +"例如 <emphasis>10:0</emphasis> 表示最多 10 個主要伺服器會交給 <citerefentry> " +"<refentrytitle>sssd_krb5_locator_plugin</refentrytitle> <manvolnum>8</" +"manvolnum> </citerefentry>,但沒有備份伺服器。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:392 msgid "Default: 3:1" -msgstr "" +msgstr "預設:3:1" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:398 msgid "krb5_use_enterprise_principal (boolean)" -msgstr "" +msgstr "krb5_use_enterprise_principal (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:401 @@ -13214,11 +15189,13 @@ msgid "" "principal. See section 5 of RFC 6806 for more details about enterprise " "principals." msgstr "" +"指定是否應將使用者 principal 視為 enterprise principal。enterprise principal " +"的更多詳細資料請參閱 RFC 6806 第 5 節。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:407 msgid "Default: false (AD provider: true)" -msgstr "" +msgstr "預設:false(AD 提供者:true)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:410 @@ -13227,11 +15204,13 @@ msgid "" "is capable of handling enterprise principals and the option is not set " "explicitly in the config file." msgstr "" +"若 IPA 提供者偵測到伺服器能夠處理 enterprise principal,且設定檔中未明確設定" +"此選項,則會將此選項設為 'true'。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:419 msgid "krb5_use_subdomain_realm (boolean)" -msgstr "" +msgstr "krb5_use_subdomain_realm (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:422 @@ -13242,11 +15221,14 @@ msgid "" "the option is set to 'true' SSSD will try to send the request directly to a " "KDC of the trusted domain the user is coming from." msgstr "" +"指定對受信任網域的使用者驗證時使用子網域 realm。若 enterprise principal 使用" +"父網域 KDC 不知道的 upnSuffix,可以將此選項設為 'true'。若此選項設為 'true'," +"SSSD 會嘗試直接將要求傳送到使用者來源之受信任網域的 KDC。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-krb5.5.xml:438 msgid "krb5_map_user (string)" -msgstr "" +msgstr "krb5_map_user (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:441 @@ -13257,6 +15239,10 @@ msgid "" "mapping is used when user is authenticating using <quote>auth_provider = " "krb5</quote>." msgstr "" +"對應清單以配對 <quote>username:primary</quote> 的逗號分隔清單給出,其中 " +"<quote>username</quote> 是 UNIX 使用者名稱,<quote>primary</quote> 是 " +"kerberos principal 的使用者部分。此對應在使用者使用 <quote>auth_provider = " +"krb5</quote> 驗證時使用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting> #: sssd-krb5.5.xml:453 @@ -13265,6 +15251,8 @@ msgid "" "krb5_realm = REALM\n" "krb5_map_user = joe:juser,dick:richard\n" msgstr "" +"krb5_realm = REALM\n" +"krb5_map_user = joe:juser,dick:richard\n" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-krb5.5.xml:458 @@ -13275,6 +15263,10 @@ msgid "" "try to kinit as <quote>juser@REALM</quote> resp. " "<quote>richard@REALM</quote>." msgstr "" +"<quote>joe</quote> 與 <quote>dick</quote> 是 UNIX 使用者名稱,<quote>juser</" +"quote> 與 <quote>richard</quote> 是 kerberos principal 的主要部分。對使用者 " +"<quote>joe</quote>(或 <quote>dick</quote>),SSSD 會嘗試以 <quote>" +"juser@REALM</quote>(或 <quote>richard@REALM</quote>)執行 kinit。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-krb5.5.xml:65 @@ -13286,6 +15278,10 @@ msgid "" "details on the configuration of an SSSD domain. <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"若在 SSSD 網域中使用 auth 模組 krb5,必須使用下列選項。SSSD 網域設定的詳細資" +"料請參閱 <citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>" +"5</manvolnum> </citerefentry> 手冊頁的 <quote>DOMAIN SECTIONS</quote> 一節" +"。<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-krb5.5.xml:485 @@ -13295,6 +15291,9 @@ msgid "" "example shows only configuration of Kerberos authentication; it does not " "include any identity provider." msgstr "" +"下列範例假設 SSSD 已正確設定,且 FOO 是 <replaceable>[sssd]</replaceable> 區" +"段中的其中一個網域。此範例只顯示 Kerberos 驗證的設定;它不包含任何身分提供者" +"。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-krb5.5.xml:493 @@ -13305,16 +15304,20 @@ msgid "" "krb5_server = 192.168.1.1\n" "krb5_realm = EXAMPLE.COM\n" msgstr "" +"[domain/FOO]\n" +"auth_provider = krb5\n" +"krb5_server = 192.168.1.1\n" +"krb5_realm = EXAMPLE.COM\n" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_cache.8.xml:10 sss_cache.8.xml:15 msgid "sss_cache" -msgstr "" +msgstr "sss_cache" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_cache.8.xml:16 msgid "perform cache cleanup" -msgstr "" +msgstr "執行快取清理" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: sss_cache.8.xml:21 @@ -13322,6 +15325,8 @@ msgid "" "<command>sss_cache</command> <arg choice='opt'> " "<replaceable>options</replaceable> </arg>" msgstr "" +"<command>sss_cache</command> <arg choice='opt'> <replaceable>options</" +"replaceable> </arg>" #. type: Content of: <reference><refentry><refsect1><para> #: sss_cache.8.xml:31 @@ -13331,38 +15336,42 @@ msgid "" "backend is online. Options that invalidate a single object only accept a " "single provided argument." msgstr "" +"<command>sss_cache</command> 使 SSSD 快取中的記錄失效。失效的記錄會在相關 " +"SSSD 後端上線時,被迫從伺服器重新載入。使單一物件失效的選項只接受單一提供的參" +"數。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:43 msgid "<option>-E</option>,<option>--everything</option>" -msgstr "" +msgstr "<option>-E</option>,<option>--everything</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:47 msgid "Invalidate all cached entries." -msgstr "" +msgstr "使所有快取的項目失效。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:53 msgid "<option>-u</option>,<option>--user</option> <replaceable>login</replaceable>" msgstr "" +"<option>-u</option>,<option>--user</option> <replaceable>login</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:58 msgid "Invalidate specific user." -msgstr "" +msgstr "使特定使用者失效。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:64 msgid "<option>-U</option>,<option>--users</option>" -msgstr "" +msgstr "<option>-U</option>,<option>--users</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:68 msgid "" "Invalidate all user records. This option overrides invalidation of specific " "user if it was also set." -msgstr "" +msgstr "使所有使用者記錄失效。若也設定了特定使用者的失效,此選項會覆寫它。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:75 @@ -13370,23 +15379,24 @@ msgid "" "<option>-g</option>,<option>--group</option> " "<replaceable>group</replaceable>" msgstr "" +"<option>-g</option>,<option>--group</option> <replaceable>group</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:80 msgid "Invalidate specific group." -msgstr "" +msgstr "使特定群組失效。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:86 msgid "<option>-G</option>,<option>--groups</option>" -msgstr "" +msgstr "<option>-G</option>,<option>--groups</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:90 msgid "" "Invalidate all group records. This option overrides invalidation of specific " "group if it was also set." -msgstr "" +msgstr "使所有群組記錄失效。若也設定了特定群組的失效,此選項會覆寫它。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:97 @@ -13394,23 +15404,25 @@ msgid "" "<option>-n</option>,<option>--netgroup</option> " "<replaceable>netgroup</replaceable>" msgstr "" +"<option>-n</option>,<option>--netgroup</option> <replaceable>netgroup</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:102 msgid "Invalidate specific netgroup." -msgstr "" +msgstr "使特定 netgroup 失效。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:108 msgid "<option>-N</option>,<option>--netgroups</option>" -msgstr "" +msgstr "<option>-N</option>,<option>--netgroups</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:112 msgid "" "Invalidate all netgroup records. This option overrides invalidation of " "specific netgroup if it was also set." -msgstr "" +msgstr "使所有 netgroup 記錄失效。若也設定了特定 netgroup 的失效,此選項會覆寫它。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:119 @@ -13418,23 +15430,25 @@ msgid "" "<option>-s</option>,<option>--service</option> " "<replaceable>service</replaceable>" msgstr "" +"<option>-s</option>,<option>--service</option> <replaceable>service</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:124 msgid "Invalidate specific service." -msgstr "" +msgstr "使特定服務失效。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:130 msgid "<option>-S</option>,<option>--services</option>" -msgstr "" +msgstr "<option>-S</option>,<option>--services</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:134 msgid "" "Invalidate all service records. This option overrides invalidation of " "specific service if it was also set." -msgstr "" +msgstr "使所有服務記錄失效。若也設定了特定服務的失效,此選項會覆寫它。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:141 @@ -13442,23 +15456,25 @@ msgid "" "<option>-a</option>,<option>--autofs-map</option> " "<replaceable>autofs-map</replaceable>" msgstr "" +"<option>-a</option>,<option>--autofs-map</option> <replaceable>autofs-map</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:146 msgid "Invalidate specific autofs maps." -msgstr "" +msgstr "使特定 autofs 對應失效。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:152 msgid "<option>-A</option>,<option>--autofs-maps</option>" -msgstr "" +msgstr "<option>-A</option>,<option>--autofs-maps</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:156 msgid "" "Invalidate all autofs maps. This option overrides invalidation of specific " "map if it was also set." -msgstr "" +msgstr "使所有 autofs 對應失效。若也設定了特定對應的失效,此選項會覆寫它。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:163 @@ -13466,16 +15482,18 @@ msgid "" "<option>-h</option>,<option>--ssh-host</option> " "<replaceable>hostname</replaceable>" msgstr "" +"<option>-h</option>,<option>--ssh-host</option> <replaceable>hostname</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:168 msgid "Invalidate SSH public keys of a specific host." -msgstr "" +msgstr "使特定主機的 SSH 公開金鑰失效。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:174 msgid "<option>-H</option>,<option>--ssh-hosts</option>" -msgstr "" +msgstr "<option>-H</option>,<option>--ssh-hosts</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:178 @@ -13483,6 +15501,8 @@ msgid "" "Invalidate SSH public keys of all hosts. This option overrides invalidation " "of SSH public keys of specific host if it was also set." msgstr "" +"使所有主機的 SSH 公開金鑰失效。若也設定了特定主機之 SSH 公開金鑰的失效,此選" +"項會覆寫它。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:186 @@ -13490,23 +15510,25 @@ msgid "" "<option>-r</option>,<option>--sudo-rule</option> " "<replaceable>rule</replaceable>" msgstr "" +"<option>-r</option>,<option>--sudo-rule</option> <replaceable>rule</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:191 msgid "Invalidate particular sudo rule." -msgstr "" +msgstr "使特定 sudo 規則失效。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:197 msgid "<option>-R</option>,<option>--sudo-rules</option>" -msgstr "" +msgstr "<option>-R</option>,<option>--sudo-rules</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:201 msgid "" "Invalidate all cached sudo rules. This option overrides invalidation of " "specific sudo rule if it was also set." -msgstr "" +msgstr "使所有快取的 sudo 規則失效。若也設定了特定 sudo 規則的失效,此選項會覆寫它。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_cache.8.xml:209 @@ -13514,16 +15536,18 @@ msgid "" "<option>-d</option>,<option>--domain</option> " "<replaceable>domain</replaceable>" msgstr "" +"<option>-d</option>,<option>--domain</option> <replaceable>domain</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_cache.8.xml:214 msgid "Restrict invalidation process only to a particular domain." -msgstr "" +msgstr "只將失效程序限制在特定網域。" #. type: Content of: <reference><refentry><refsect1><title> #: sss_cache.8.xml:224 msgid "EFFECTS ON THE FAST MEMORY CACHE" -msgstr "" +msgstr "對快速記憶體快取的影響" #. type: Content of: <reference><refentry><refsect1><para> #: sss_cache.8.xml:226 @@ -13540,6 +15564,13 @@ msgid "" "kernel can release the occupied disk space and the old memory cache file is " "finally removed completely." msgstr "" +"<command>sss_cache</command> 也會使記憶體快取失效。由於記憶體快取是對應到每個" +"呼叫 SSSD 解析使用者或群組之程序的記憶體中的檔案,因此該檔案無法截斷。檔案標" +"頭中會設定特殊旗標以表示內容無效,然後 SSSD 的 NSS responder 會取消連結該檔案" +"並建立新的快取檔案。每當程序對使用者或群組進行新的查詢時,它會看到旗標、關閉" +"舊的記憶體快取檔案並將新的對應到記憶體中。當所有開啟舊記憶體快取檔案的程序在" +"查詢使用者或群組時關閉它之後,核心就能釋放佔用的磁碟空間,舊的記憶體快取檔案" +"最後會完全移除。" #. type: Content of: <reference><refentry><refsect1><para> #: sss_cache.8.xml:240 @@ -13554,6 +15585,12 @@ msgid "" "disk usage because old memory cache files cannot be removed from the disk " "because they are still mapped by long running processes." msgstr "" +"一個特殊情況是只在啟動時執行使用者或群組查詢的長時間執行程序,例如確定程序執" +"行之使用者的名稱。對這些查詢,記憶體快取檔案會對應到程序的記憶體中。但由於不" +"會再有進一步的查詢,此程序永遠不會偵測到記憶體快取檔案是否已失效,因此它會保" +"留在記憶體中並佔用磁碟空間,直到程序停止。因此呼叫 <command>sss_cache</" +"command> 可能會增加磁碟使用量,因為舊的記憶體快取檔案仍被長時間執行的程序對應" +",無法從磁碟移除。" #. type: Content of: <reference><refentry><refsect1><para> #: sss_cache.8.xml:252 @@ -13566,16 +15603,20 @@ msgid "" "so that they meet the local expectations and calling " "<command>sss_cache</command> is not needed." msgstr "" +"對只在啟動時或極少查詢使用者與群組的長時間執行程序,一個可行的解決方法是將環" +"境變數 SSS_NSS_USE_MEMCACHE 設為 \"NO\" 執行它們,這樣它們完全不會使用記憶體" +"快取,也不會將記憶體快取檔案對應到記憶體中。一般來說,更好的解決方案是調整快" +"取逾時參數以符合本機預期,就不需要呼叫 <command>sss_cache</command>。" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_debuglevel.8.xml:10 sss_debuglevel.8.xml:15 msgid "sss_debuglevel" -msgstr "" +msgstr "sss_debuglevel" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_debuglevel.8.xml:16 msgid "[DEPRECATED] change debug level while SSSD is running" -msgstr "" +msgstr "[已棄用] 在 SSSD 執行期間變更除錯層級" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: sss_debuglevel.8.xml:21 @@ -13584,6 +15625,9 @@ msgid "" "<replaceable>options</replaceable> </arg> <arg " "choice='plain'><replaceable>NEW_DEBUG_LEVEL</replaceable></arg>" msgstr "" +"<command>sss_debuglevel</command> <arg choice='opt'> <replaceable>options</" +"replaceable> </arg> <arg choice='plain'><replaceable>NEW_DEBUG_LEVEL</" +"replaceable></arg>" #. type: Content of: <reference><refentry><refsect1><para> #: sss_debuglevel.8.xml:32 @@ -13592,16 +15636,18 @@ msgid "" "debug-level command. Please refer to the <command>sssctl</command> man page " "for more information on sssctl usage." msgstr "" +"<command>sss_debuglevel</command> 已棄用,改由 sssctl debug-level 指令取代。" +"sssctl 用法的更多資訊請參閱 <command>sssctl</command> 手冊頁。" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_seed.8.xml:10 sss_seed.8.xml:15 msgid "sss_seed" -msgstr "" +msgstr "sss_seed" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_seed.8.xml:16 msgid "seed the SSSD cache with a user" -msgstr "" +msgstr "以使用者為 SSSD 快取播種" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: sss_seed.8.xml:21 @@ -13611,6 +15657,9 @@ msgid "" "<replaceable>DOMAIN</replaceable></arg> <arg choice='plain'>-n " "<replaceable>USER</replaceable></arg>" msgstr "" +"<command>sss_seed</command> <arg choice='opt'> <replaceable>options</" +"replaceable> </arg> <arg choice='plain'>-D <replaceable>DOMAIN</replaceable>" +"</arg> <arg choice='plain'>-n <replaceable>USER</replaceable></arg>" #. type: Content of: <reference><refentry><refsect1><para> #: sss_seed.8.xml:33 @@ -13619,6 +15668,8 @@ msgid "" "temporary password. If a user entry is already present in the SSSD cache " "then the entry is updated with the temporary password." msgstr "" +"<command>sss_seed</command> 以使用者項目與暫時密碼為 SSSD 快取播種。若 SSSD " +"快取中已有使用者項目,則會以暫時密碼更新該項目。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_seed.8.xml:46 @@ -13626,6 +15677,8 @@ msgid "" "<option>-D</option>,<option>--domain</option> " "<replaceable>DOMAIN</replaceable>" msgstr "" +"<option>-D</option>,<option>--domain</option> <replaceable>DOMAIN</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_seed.8.xml:51 @@ -13636,6 +15689,9 @@ msgid "" "Information retrieved from the domain overrides what is provided in the " "options." msgstr "" +"提供使用者所屬網域的名稱。該網域也用於擷取使用者資訊。網域必須在 sssd.conf 中" +"設定。<replaceable>DOMAIN</replaceable> 選項必須提供。從網域擷取的資訊會覆寫" +"選項中提供的內容。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_seed.8.xml:63 @@ -13643,6 +15699,8 @@ msgid "" "<option>-n</option>,<option>--username</option> " "<replaceable>USER</replaceable>" msgstr "" +"<option>-n</option>,<option>--username</option> <replaceable>USER</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_seed.8.xml:68 @@ -13650,26 +15708,30 @@ msgid "" "The username of the entry to be created or modified in the cache. The " "<replaceable>USER</replaceable> option must be provided." msgstr "" +"要在快取中建立或修改之項目的使用者名稱。<replaceable>USER</replaceable> 選項" +"必須提供。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_seed.8.xml:76 msgid "<option>-u</option>,<option>--uid</option> <replaceable>UID</replaceable>" msgstr "" +"<option>-u</option>,<option>--uid</option> <replaceable>UID</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_seed.8.xml:81 msgid "Set the UID of the user to <replaceable>UID</replaceable>." -msgstr "" +msgstr "將使用者的 UID 設為 <replaceable>UID</replaceable>。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_seed.8.xml:88 msgid "<option>-g</option>,<option>--gid</option> <replaceable>GID</replaceable>" msgstr "" +"<option>-g</option>,<option>--gid</option> <replaceable>GID</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_seed.8.xml:93 msgid "Set the GID of the user to <replaceable>GID</replaceable>." -msgstr "" +msgstr "將使用者的 GID 設為 <replaceable>GID</replaceable>。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_seed.8.xml:100 @@ -13677,13 +15739,15 @@ msgid "" "<option>-c</option>,<option>--gecos</option> " "<replaceable>COMMENT</replaceable>" msgstr "" +"<option>-c</option>,<option>--gecos</option> <replaceable>COMMENT</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_seed.8.xml:105 msgid "" "Any text string describing the user. Often used as the field for the user's " "full name." -msgstr "" +msgstr "任何描述使用者的文字字串。常用於使用者全名的欄位。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_seed.8.xml:112 @@ -13691,11 +15755,13 @@ msgid "" "<option>-h</option>,<option>--home</option> " "<replaceable>HOME_DIR</replaceable>" msgstr "" +"<option>-h</option>,<option>--home</option> <replaceable>HOME_DIR</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_seed.8.xml:117 msgid "Set the home directory of the user to <replaceable>HOME_DIR</replaceable>." -msgstr "" +msgstr "將使用者的家目錄設為 <replaceable>HOME_DIR</replaceable>。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_seed.8.xml:124 @@ -13703,18 +15769,19 @@ msgid "" "<option>-s</option>,<option>--shell</option> " "<replaceable>SHELL</replaceable>" msgstr "" +"<option>-s</option>,<option>--shell</option> <replaceable>SHELL</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_seed.8.xml:129 msgid "Set the login shell of the user to <replaceable>SHELL</replaceable>." -msgstr "" +msgstr "將使用者的登入 shell 設為 <replaceable>SHELL</replaceable>。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_seed.8.xml:140 msgid "" "Interactive mode for entering user information. This option will only prompt " "for information not provided in the options or retrieved from the domain." -msgstr "" +msgstr "輸入使用者資訊的互動模式。此選項只會提示未在選項中提供或未從網域擷取的資訊。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_seed.8.xml:148 @@ -13722,13 +15789,15 @@ msgid "" "<option>-p</option>,<option>--password-file</option> " "<replaceable>PASS_FILE</replaceable>" msgstr "" +"<option>-p</option>,<option>--password-file</option> <replaceable>PASS_FILE</" +"replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_seed.8.xml:153 msgid "" "Specify file to read user's password from. (if not specified password is " "prompted for)" -msgstr "" +msgstr "指定從中讀取使用者密碼的檔案。(若未指定,會提示輸入密碼)" #. type: Content of: <reference><refentry><refsect1><para> #: sss_seed.8.xml:165 @@ -13737,16 +15806,18 @@ msgid "" "--password-file option) must be less than or equal to PASS_MAX bytes (64 " "bytes on systems with no globally-defined PASS_MAX value)." msgstr "" +"密碼長度(或以 -p 或 --password-file 選項指定之檔案的大小)必須小於或等於 " +"PASS_MAX 位元組(在沒有全域定義 PASS_MAX 值的系統上為 64 位元組)。" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-ifp.5.xml:10 sssd-ifp.5.xml:16 msgid "sssd-ifp" -msgstr "" +msgstr "sssd-ifp" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-ifp.5.xml:17 msgid "SSSD InfoPipe responder" -msgstr "" +msgstr "SSSD InfoPipe responder" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ifp.5.xml:23 @@ -13758,6 +15829,10 @@ msgid "" "<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> manual page." msgstr "" +"本手冊頁說明 <citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>" +"8</manvolnum> </citerefentry> 之 InfoPipe responder 的設定。詳細的語法參考請" +"參閱 <citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> 手冊頁的 <quote>FILE FORMAT</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ifp.5.xml:36 @@ -13766,33 +15841,35 @@ msgid "" "system bus. The interface allows the user to query information about remote " "users and groups over the system bus." msgstr "" +"InfoPipe responder 提供可透過系統匯流排存取的公開 D-Bus 介面。此介面允許使用" +"者透過系統匯流排查詢遠端使用者與群組的資訊。" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd-ifp.5.xml:43 msgid "FIND BY VALID CERTIFICATE" -msgstr "" +msgstr "依有效憑證尋找" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd-ifp.5.xml:45 msgid "" "The following options can be used to control how the certificates are " "validated when using the FindByValidCertificate() API:" -msgstr "" +msgstr "使用 FindByValidCertificate() API 時,可以使用下列選項控制憑證的驗證方式:" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ifp.5.xml:48 sss_ssh_authorizedkeys.1.xml:92 msgid "ca_db" -msgstr "" +msgstr "ca_db" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ifp.5.xml:49 sss_ssh_authorizedkeys.1.xml:93 msgid "p11_child_timeout" -msgstr "" +msgstr "p11_child_timeout" #. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para> #: sssd-ifp.5.xml:50 sss_ssh_authorizedkeys.1.xml:94 msgid "certificate_verification" -msgstr "" +msgstr "certificate_verification" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd-ifp.5.xml:52 @@ -13801,11 +15878,13 @@ msgid "" "<citerefentry><refentrytitle>sssd.conf</refentrytitle> " "<manvolnum>5</manvolnum></citerefentry>." msgstr "" +"這些選項的更多詳細資料請參閱 <citerefentry><refentrytitle>sssd.conf</" +"refentrytitle> <manvolnum>5</manvolnum></citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ifp.5.xml:62 msgid "These options can be used to configure the InfoPipe responder." -msgstr "" +msgstr "這些選項可用於設定 InfoPipe responder。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:69 @@ -13814,11 +15893,13 @@ msgid "" "allowed to access the InfoPipe responder. User names are resolved to UIDs at " "startup." msgstr "" +"指定允許存取 InfoPipe responder 的 UID 值或使用者名稱逗號分隔清單。使用者名稱" +"會在啟動時解析為 UID。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:75 msgid "Default: 0 (only the root user is allowed to access the InfoPipe responder)" -msgstr "" +msgstr "預設:0(只允許 root 使用者存取 InfoPipe responder)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:79 @@ -13828,66 +15909,68 @@ msgid "" "access the InfoPipe responder, which would be the typical case, you have to " "add 0 to the list of allowed UIDs as well." msgstr "" +"請注意,雖然 UID 0 用作預設值,它會被此選項覆寫。若您仍然想要允許 root 使用者" +"存取 InfoPipe responder(這是典型情況),您也必須將 0 加入允許的 UID 清單。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:93 msgid "Specifies the comma-separated list of white or blacklisted attributes." -msgstr "" +msgstr "指定白名單或黑名單屬性的逗號分隔清單。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-ifp.5.xml:107 msgid "name" -msgstr "" +msgstr "name" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:108 msgid "user's login name" -msgstr "" +msgstr "使用者的登入名稱" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-ifp.5.xml:111 msgid "uidNumber" -msgstr "" +msgstr "uidNumber" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:112 msgid "user ID" -msgstr "" +msgstr "使用者 ID" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-ifp.5.xml:115 msgid "gidNumber" -msgstr "" +msgstr "gidNumber" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:116 msgid "primary group ID" -msgstr "" +msgstr "主要群組 ID" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-ifp.5.xml:119 msgid "gecos" -msgstr "" +msgstr "gecos" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:120 msgid "user information, typically full name" -msgstr "" +msgstr "使用者資訊,通常是全名" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-ifp.5.xml:123 msgid "homeDirectory" -msgstr "" +msgstr "homeDirectory" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term> #: sssd-ifp.5.xml:127 msgid "loginShell" -msgstr "" +msgstr "loginShell" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:128 msgid "user shell" -msgstr "" +msgstr "使用者 shell" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:97 @@ -13898,6 +15981,10 @@ msgid "" "<manvolnum>3</manvolnum> </citerefentry> and includes: <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"依預設,InfoPipe responder 只允許要求預設的 POSIX 屬性集。此集合與 " +"<citerefentry> <refentrytitle>getpwnam</refentrytitle> <manvolnum>3</" +"manvolnum> </citerefentry> 傳回的相同,包括:<placeholder " +"type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting> #: sssd-ifp.5.xml:141 @@ -13906,6 +15993,8 @@ msgid "" "user_attributes = +telephoneNumber, -loginShell\n" " " msgstr "" +"user_attributes = +telephoneNumber, -loginShell\n" +" " #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:133 @@ -13917,23 +16006,27 @@ msgid "" "use the following configuration: <placeholder type=\"programlisting\" " "id=\"0\"/>" msgstr "" +"可以使用 <quote>+attr_name</quote> 將另一個屬性加入此集合,或使用 <quote>-" +"attr_name</quote> 明確移除屬性。例如,要允許 <quote>telephoneNumber</quote> " +"但拒絕 <quote>loginShell</quote>,您可以使用下列設定:<placeholder " +"type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:145 msgid "Default: not set. Only the default set of POSIX attributes is allowed." -msgstr "" +msgstr "預設:未設定。只允許預設的 POSIX 屬性集。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:155 msgid "" "Specifies an upper limit on the number of entries that are downloaded during " "a wildcard lookup that overrides caller-supplied limit." -msgstr "" +msgstr "指定萬用字元查詢期間下載的項目數目上限,此上限會覆寫呼叫者提供的限制。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-ifp.5.xml:160 msgid "Default: 0 (let the caller set an upper limit)" -msgstr "" +msgstr "預設:0(讓呼叫者設定上限)" #. type: Content of: <reference><refentry><refentryinfo> #: sss_rpcidmapd.5.xml:8 @@ -13945,21 +16038,27 @@ msgid "" "<surname>Meltzer</surname> <contrib>Developer (2014-)</contrib> " "<email>tsnoam@gmail.com</email> </author>" msgstr "" +"<productname>sss rpc.idmapd plugin</productname> <author> <firstname>Noam</" +"firstname> <surname>Meltzer</surname> <affiliation> <orgname>Primary Data " +"Inc.</orgname> </affiliation> <contrib>Developer (2013-2014)</contrib> </" +"author> <author> <firstname>Noam</firstname> <surname>Meltzer</surname> " +"<contrib>Developer (2014-)</contrib> <email>tsnoam@gmail.com</email> </" +"author>" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_rpcidmapd.5.xml:26 sss_rpcidmapd.5.xml:32 msgid "sss_rpcidmapd" -msgstr "" +msgstr "sss_rpcidmapd" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_rpcidmapd.5.xml:33 msgid "sss plugin configuration directives for rpc.idmapd" -msgstr "" +msgstr "rpc.idmapd 的 sss 外掛程式設定指示" #. type: Content of: <reference><refentry><refsect1><title> #: sss_rpcidmapd.5.xml:37 msgid "CONFIGURATION FILE" -msgstr "" +msgstr "設定檔" #. type: Content of: <reference><refentry><refsect1><para> #: sss_rpcidmapd.5.xml:39 @@ -13969,16 +16068,19 @@ msgid "" "<refentrytitle>idmapd.conf</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> for more information." msgstr "" +"rpc.idmapd 設定檔通常位於 <emphasis>/etc/idmapd.conf</emphasis>。更多資訊請參" +"閱 <citerefentry> <refentrytitle>idmapd.conf</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><title> #: sss_rpcidmapd.5.xml:49 msgid "SSS CONFIGURATION EXTENSION" -msgstr "" +msgstr "SSS 設定延伸" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sss_rpcidmapd.5.xml:51 msgid "Enable SSS plugin" -msgstr "" +msgstr "啟用 SSS 外掛程式" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss_rpcidmapd.5.xml:53 @@ -13986,11 +16088,13 @@ msgid "" "In section <quote>[Translation]</quote>, modify/set <quote>Method</quote> " "attribute to contain <emphasis>sss</emphasis>." msgstr "" +"在 <quote>[Translation]</quote> 區段中,將 <quote>Method</quote> 屬性修改/設" +"定為包含 <emphasis>sss</emphasis>。" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sss_rpcidmapd.5.xml:59 msgid "[sss] config section" -msgstr "" +msgstr "[sss] 設定區段" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss_rpcidmapd.5.xml:61 @@ -13999,33 +16103,35 @@ msgid "" "<emphasis>sss</emphasis> plugin listed below you will need to create a " "config section for it, named <quote>[sss]</quote>." msgstr "" +"若要變更下列列出之 <emphasis>sss</emphasis> 外掛程式其中一個設定屬性的預設值" +",您需要為它建立名為 <quote>[sss]</quote> 的設定區段。" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title> #: sss_rpcidmapd.5.xml:67 msgid "Configuration attributes" -msgstr "" +msgstr "設定屬性" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sss_rpcidmapd.5.xml:69 msgid "memcache (bool)" -msgstr "" +msgstr "memcache (bool)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sss_rpcidmapd.5.xml:72 msgid "Indicates whether or not to use memcache optimisation technique." -msgstr "" +msgstr "指出是否使用 memcache 最佳化技術。" #. type: Content of: <reference><refentry><refsect1><title> #: sss_rpcidmapd.5.xml:85 msgid "SSSD INTEGRATION" -msgstr "" +msgstr "SSSD 整合" #. type: Content of: <reference><refentry><refsect1><para> #: sss_rpcidmapd.5.xml:87 msgid "" "The sss plugin requires the <emphasis>NSS Responder</emphasis> to be enabled " "in sssd." -msgstr "" +msgstr "sss 外掛程式要求 sssd 中啟用 <emphasis>NSS Responder</emphasis>。" #. type: Content of: <reference><refentry><refsect1><para> #: sss_rpcidmapd.5.xml:91 @@ -14034,6 +16140,8 @@ msgid "" "all domains (NFSv4 clients expect a fully qualified name to be sent on the " "wire)." msgstr "" +"所有網域都必須啟用 <quote>use_fully_qualified_names</quote> 屬性(NFSv4 用戶" +"端預期在線路上傳送完整限定名稱)。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sss_rpcidmapd.5.xml:103 @@ -14052,6 +16160,18 @@ msgid "" "[Translation]\n" "Method = sss\n" msgstr "" +"[General]\n" +"Verbosity = 2\n" +"# domain must be synced between NFSv4 server and clients\n" +"# Solaris/Illumos/AIX use \"localdomain\" as default!\n" +"Domain = default\n" +"\n" +"[Mapping]\n" +"Nobody-User = nfsnobody\n" +"Nobody-Group = nfsnobody\n" +"\n" +"[Translation]\n" +"Method = sss\n" #. type: Content of: <reference><refentry><refsect1><para> #: sss_rpcidmapd.5.xml:100 @@ -14059,11 +16179,13 @@ msgid "" "The following example shows a minimal idmapd.conf which makes use of the sss " "plugin. <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"下列範例顯示使用 sss 外掛程式的最小 idmapd.conf。<placeholder " +"type=\"programlisting\" id=\"0\"/>" #. type: Content of: <refsect1><title> #: sss_rpcidmapd.5.xml:120 sssd-kcm.8.xml:316 include/seealso.xml:2 msgid "SEE ALSO" -msgstr "" +msgstr "另請參閱" #. type: Content of: <reference><refentry><refsect1><para> #: sss_rpcidmapd.5.xml:122 @@ -14072,16 +16194,19 @@ msgid "" "</citerefentry>, <citerefentry> <refentrytitle>idmapd.conf</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry>" msgstr "" +"<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>idmapd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_ssh_authorizedkeys.1.xml:10 sss_ssh_authorizedkeys.1.xml:15 msgid "sss_ssh_authorizedkeys" -msgstr "" +msgstr "sss_ssh_authorizedkeys" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_ssh_authorizedkeys.1.xml:16 msgid "get OpenSSH authorized keys" -msgstr "" +msgstr "取得 OpenSSH 授權金鑰" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: sss_ssh_authorizedkeys.1.xml:21 @@ -14090,6 +16215,9 @@ msgid "" "<replaceable>options</replaceable> </arg> <arg " "choice='plain'><replaceable>USER</replaceable></arg>" msgstr "" +"<command>sss_ssh_authorizedkeys</command> <arg choice='opt'> <replaceable>" +"options</replaceable> </arg> <arg choice='plain'><replaceable>USER</" +"replaceable></arg>" #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_authorizedkeys.1.xml:32 @@ -14100,6 +16228,11 @@ msgid "" "<citerefentry><refentrytitle>sshd</refentrytitle> " "<manvolnum>8</manvolnum></citerefentry> for more information)." msgstr "" +"<command>sss_ssh_authorizedkeys</command> 取得使用者 <replaceable>USER</" +"replaceable> 的 SSH 公開金鑰,並以 OpenSSH authorized_keys 格式輸出(更多資訊" +"請參閱 <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" +"manvolnum></citerefentry> 的 <quote>AUTHORIZED_KEYS FILE FORMAT</quote> 一節" +")。" #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_authorizedkeys.1.xml:41 @@ -14113,6 +16246,11 @@ msgid "" "<manvolnum>5</manvolnum></citerefentry> man page for more details about this " "option." msgstr "" +"若 <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</manvolnum>" +"</citerefentry> 編譯時支援 <quote>AuthorizedKeysCommand</quote> 選項,它可以" +"設定為使用 <command>sss_ssh_authorizedkeys</command> 進行公開金鑰使用者驗證。" +"此選項的更多詳細資料請參閱 <citerefentry> <refentrytitle>sshd_config</" +"refentrytitle> <manvolnum>5</manvolnum></citerefentry> 手冊頁。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sss_ssh_authorizedkeys.1.xml:59 @@ -14121,6 +16259,8 @@ msgid "" " AuthorizedKeysCommand /usr/bin/sss_ssh_authorizedkeys\n" " AuthorizedKeysCommandUser nobody\n" msgstr "" +" AuthorizedKeysCommand /usr/bin/sss_ssh_authorizedkeys\n" +" AuthorizedKeysCommandUser nobody\n" #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_authorizedkeys.1.xml:52 @@ -14133,11 +16273,16 @@ msgid "" "<manvolnum>5</manvolnum></citerefentry>: <placeholder " "type=\"programlisting\" id=\"0\"/>" msgstr "" +"若支援 <quote>AuthorizedKeysCommand</quote>,可以將下列指示放在 " +"<citerefentry> <refentrytitle>sshd_config</refentrytitle> <manvolnum>5</" +"manvolnum></citerefentry> 中,設定 <citerefentry><refentrytitle>sshd</" +"refentrytitle> <manvolnum>8</manvolnum></citerefentry> 使用它:<placeholder " +"type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sss_ssh_authorizedkeys.1.xml:65 msgid "KEYS FROM CERTIFICATES" -msgstr "" +msgstr "來自憑證的金鑰" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss_ssh_authorizedkeys.1.xml:67 @@ -14146,6 +16291,9 @@ msgid "" "<command>sss_ssh_authorizedkeys</command> can return public SSH keys derived " "from the public key of a X.509 certificate as well." msgstr "" +"除了使用者 <replaceable>USER</replaceable> 的公開 SSH 金鑰之外,<command>" +"sss_ssh_authorizedkeys</command> 也可以傳回從 X.509 憑證公開金鑰衍生的公開 " +"SSH 金鑰。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss_ssh_authorizedkeys.1.xml:73 @@ -14164,11 +16312,20 @@ msgid "" "valid SSSD will extract the public key from the certificate and convert it " "into the format expected by sshd." msgstr "" +"要啟用此功能,<filename>sssd.conf</filename> 的 [ssh] 區段中必須將 <quote>" +"ssh_use_certificate_keys</quote> 選項設為 true(預設)。若使用者項目包含憑證" +"(詳細資料請參閱 <citerefentry><refentrytitle>sssd-ldap</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry> 中的 <quote>ldap_user_certificate</" +"quote>)或使用者的覆寫項目中有憑證(詳細資料請參閱 <citerefentry>" +"<refentrytitle>sss_override</refentrytitle> <manvolnum>8</manvolnum></" +"citerefentry> 或 <citerefentry><refentrytitle>sssd-ipa</refentrytitle> " +"<manvolnum>5</manvolnum></citerefentry>),且憑證有效,SSSD 會從憑證擷取公開" +"金鑰並轉換成 sshd 預期的格式。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss_ssh_authorizedkeys.1.xml:90 msgid "Besides <quote>ssh_use_certificate_keys</quote> the options" -msgstr "" +msgstr "除了 <quote>ssh_use_certificate_keys</quote> 之外,選項" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss_ssh_authorizedkeys.1.xml:96 @@ -14177,6 +16334,8 @@ msgid "" "<citerefentry><refentrytitle>sssd.conf</refentrytitle> " "<manvolnum>5</manvolnum></citerefentry> for details)." msgstr "" +"可以用來控制憑證的驗證方式(詳細資料請參閱 <citerefentry><refentrytitle>" +"sssd.conf</refentrytitle> <manvolnum>5</manvolnum></citerefentry>)。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss_ssh_authorizedkeys.1.xml:101 @@ -14191,6 +16350,12 @@ msgid "" "on the Smartcard is already expired because neither <command>ssh</command> " "nor <command>sshd</command> will look at the certificate at all." msgstr "" +"驗證是使用 X.509 憑證而非直接使用 SSH 金鑰的好處,例如它提供對金鑰生命週期更" +"好的控制。當 ssh 用戶端在 PKCS#11 共用程式庫的協助下設定為使用 Smartcard 的私" +"密金鑰(詳細資料請參閱 <citerefentry><refentrytitle>ssh</refentrytitle> " +"<manvolnum>1</manvolnum></citerefentry>)時,即使 Smartcard 上的相關 X.509 憑" +"證已過期,驗證仍然有效,這可能令人困擾,因為 <command>ssh</command> 與 " +"<command>sshd</command> 都不會檢視憑證。" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sss_ssh_authorizedkeys.1.xml:114 @@ -14200,30 +16365,32 @@ msgid "" "certificate validation if the <command>sshd</command> configuration permits " "this." msgstr "" +"必須注意,若 <command>sshd</command> 設定允許,衍生的公開 SSH 金鑰仍然可以加" +"入使用者的 <filename>authorized_keys</filename> 檔案以略過憑證驗證。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_ssh_authorizedkeys.1.xml:132 msgid "" "Search for user public keys in SSSD domain " "<replaceable>DOMAIN</replaceable>." -msgstr "" +msgstr "在 SSSD 網域 <replaceable>DOMAIN</replaceable> 中搜尋使用者公開金鑰。" #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_authorizedkeys.1.xml:143 sss_ssh_knownhostsproxy.1.xml:114 msgid "" "In case of success, an exit value of 0 is returned. Otherwise, 1 is " "returned." -msgstr "" +msgstr "成功時傳回退出值 0。否則傳回 1。" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_ssh_knownhosts.1.xml:10 sss_ssh_knownhosts.1.xml:15 msgid "sss_ssh_knownhosts" -msgstr "" +msgstr "sss_ssh_knownhosts" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_ssh_knownhosts.1.xml:16 msgid "get OpenSSH known hosts public keys" -msgstr "" +msgstr "取得 OpenSSH 已知主機的公開金鑰" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: sss_ssh_knownhosts.1.xml:21 @@ -14232,6 +16399,9 @@ msgid "" "<replaceable>options</replaceable> </arg> <arg " "choice='plain'><replaceable>HOST</replaceable></arg>" msgstr "" +"<command>sss_ssh_knownhosts</command> <arg choice='opt'> <replaceable>" +"options</replaceable> </arg> <arg choice='plain'><replaceable>HOST</" +"replaceable></arg>" #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_knownhosts.1.xml:32 @@ -14242,6 +16412,11 @@ msgid "" "<citerefentry><refentrytitle>sshd</refentrytitle> " "<manvolnum>8</manvolnum></citerefentry> for more information)." msgstr "" +"<command>sss_ssh_knownhosts</command> 取得主機 <replaceable>HOST</" +"replaceable> 的 SSH 公開金鑰,並以 OpenSSH known_hosts 金鑰格式輸出(更多資訊" +"請參閱 <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</" +"manvolnum></citerefentry> 的 <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> 一節" +")。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sss_ssh_knownhosts.1.xml:47 @@ -14250,6 +16425,8 @@ msgid "" " KnownHostsCommand /usr/bin/sss_ssh_knownhosts %H\n" " " msgstr "" +" KnownHostsCommand /usr/bin/sss_ssh_knownhosts %H\n" +" " #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_knownhosts.1.xml:41 @@ -14262,18 +16439,24 @@ msgid "" "<refentrytitle>ssh_config</refentrytitle><manvolnum>5</manvolnum> " "</citerefentry> man page for more details about this option." msgstr "" +"使用 <quote>KnownHostsCommand</quote> 選項,可以設定 <citerefentry>" +"<refentrytitle>ssh</refentrytitle> <manvolnum>1</manvolnum></citerefentry> 使" +"用 <command>sss_ssh_knownhosts</command> 進行公開金鑰主機驗證:<placeholder " +"type=\"programlisting\" id=\"0\"/> 此選項的更多詳細資料請參閱 <citerefentry> " +"<refentrytitle>ssh_config</refentrytitle><manvolnum>5</manvolnum> </" +"citerefentry> 手冊頁。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_ssh_knownhosts.1.xml:65 sss_ssh_knownhostsproxy.1.xml:93 msgid "" "Search for host public keys in SSSD domain " "<replaceable>DOMAIN</replaceable>." -msgstr "" +msgstr "在 SSSD 網域 <replaceable>DOMAIN</replaceable> 中搜尋主機公開金鑰。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_ssh_knownhosts.1.xml:72 msgid "<option>-o</option>,<option>--only-host-name</option>" -msgstr "" +msgstr "<option>-o</option>,<option>--only-host-name</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_ssh_knownhosts.1.xml:76 @@ -14282,11 +16465,13 @@ msgid "" "tool will add the unmodified hostname as provided by the caller. If this " "flag is set, only the hostname (no port number) will be added to the keys." msgstr "" +"當從後端擷取的金鑰不包含主機名稱時,此工具會加入呼叫者提供的未修改主機名稱。" +"若設定此旗標,只會將主機名稱(沒有連接埠號碼)加入金鑰。" #. type: Content of: <reference><refentry><refsect1><title> #: sss_ssh_knownhosts.1.xml:88 msgid "KEY RETRIEVAL" -msgstr "" +msgstr "金鑰擷取" #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_knownhosts.1.xml:90 @@ -14301,6 +16486,12 @@ msgid "" "number), depending on whether the " "<option>-o</option>,<option>--only-host-name</option> option was provided." msgstr "" +"從後端擷取的金鑰行預期遵循 <citerefentry><refentrytitle>sshd</refentrytitle> " +"<manvolnum>8</manvolnum></citerefentry> 之 <quote>SSH_KNOWN_HOSTS FILE " +"FORMAT</quote> 一節所述的金鑰格式。不過,只傳回金鑰類型與金鑰本身也可接受,這" +"種情況下,作為參數收到的主機名稱會加在金鑰類型前面,以輸出格式正確的行。主機" +"名稱會以未修改的形式加入,或只加入主機名稱(沒有連接埠號碼),視是否提供 " +"<option>-o</option>,<option>--only-host-name</option> 選項而定。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sss_ssh_knownhosts.1.xml:107 @@ -14310,6 +16501,9 @@ msgid "" "<base64-encoded key>\n" " " msgstr "" +" [canonical.host.name]:2222 <keytype> <base64-" +"encoded key>\n" +" " #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_knownhosts.1.xml:102 @@ -14319,23 +16513,26 @@ msgid "" "position as part of the key line. For example, the minimal key line would " "be: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"當 SSH 伺服器監聽非預設連接埠時,後端必須以正確的格式與位置提供包含連接埠號碼" +"的主機名稱,作為金鑰行的一部分。例如,最小的金鑰行會是:<placeholder " +"type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_knownhosts.1.xml:115 msgid "" "In case of successful execution, even if no key was found, 0 is returned. 1 " "is returned in case of error." -msgstr "" +msgstr "執行成功時,即使沒有找到金鑰,也會傳回 0。發生錯誤時傳回 1。" #. type: Content of: <reference><refentry><refnamediv><refname> #: sss_ssh_knownhostsproxy.1.xml:10 sss_ssh_knownhostsproxy.1.xml:15 msgid "sss_ssh_knownhostsproxy" -msgstr "" +msgstr "sss_ssh_knownhostsproxy" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sss_ssh_knownhostsproxy.1.xml:16 msgid "get OpenSSH host keys" -msgstr "" +msgstr "取得 OpenSSH 主機金鑰" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: sss_ssh_knownhostsproxy.1.xml:21 @@ -14345,11 +16542,15 @@ msgid "" "choice='plain'><replaceable>HOST</replaceable></arg> <arg " "choice='opt'><replaceable>PROXY_COMMAND</replaceable></arg>" msgstr "" +"<command>sss_ssh_knownhostsproxy</command> <arg choice='opt'> <replaceable>" +"options</replaceable> </arg> <arg choice='plain'><replaceable>HOST</" +"replaceable></arg> <arg choice='opt'><replaceable>PROXY_COMMAND</replaceable>" +"</arg>" #. type: Content of: <reference><refentry><refsect1><title> #: sss_ssh_knownhostsproxy.1.xml:31 msgid "LIFE-CYCLE" -msgstr "" +msgstr "生命週期" #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_knownhostsproxy.1.xml:33 @@ -14357,6 +16558,8 @@ msgid "" "This tool is deprecated and will be removed in the future. Consider using " "the more reliable <command>sss_ssh_knownhosts</command> instead." msgstr "" +"此工具已棄用,未來將移除。請考慮改用更可靠的 <command>sss_ssh_knownhosts</" +"command>。" #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_knownhostsproxy.1.xml:43 @@ -14369,6 +16572,12 @@ msgid "" "<filename>/var/lib/sss/pubconf/known_hosts</filename> and establishes the " "connection to the host." msgstr "" +"<command>sss_ssh_knownhostsproxy</command> 取得主機 <replaceable>HOST</" +"replaceable> 的 SSH 主機公開金鑰,將它們儲存在自訂的 OpenSSH known_hosts 檔" +"案 <filename>/var/lib/sss/pubconf/known_hosts</filename>(更多資訊請參閱 " +"<citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</manvolnum></" +"citerefentry> 的 <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> 一節),並與主機" +"建立連線。" #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_knownhostsproxy.1.xml:53 @@ -14376,6 +16585,8 @@ msgid "" "If <replaceable>PROXY_COMMAND</replaceable> is specified, it is used to " "create the connection to the host instead of opening a socket." msgstr "" +"若指定 <replaceable>PROXY_COMMAND</replaceable>,會使用它建立與主機的連線,而" +"不是開啟 socket。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sss_ssh_knownhostsproxy.1.xml:65 @@ -14384,6 +16595,8 @@ msgid "" "ProxyCommand /usr/bin/sss_ssh_knownhostsproxy -p %p %h\n" "GlobalKnownHostsFile /var/lib/sss/pubconf/known_hosts\n" msgstr "" +"ProxyCommand /usr/bin/sss_ssh_knownhostsproxy -p %p %h\n" +"GlobalKnownHostsFile /var/lib/sss/pubconf/known_hosts\n" #. type: Content of: <reference><refentry><refsect1><para> #: sss_ssh_knownhostsproxy.1.xml:58 @@ -14396,38 +16609,44 @@ msgid "" "<manvolnum>1</manvolnum></citerefentry> configuration: <placeholder " "type=\"programlisting\" id=\"0\"/>" msgstr "" +"使用下列 <citerefentry><refentrytitle>ssh</refentrytitle> <manvolnum>1</" +"manvolnum></citerefentry> 設定指示,可以設定 <citerefentry><refentrytitle>" +"ssh</refentrytitle> <manvolnum>1</manvolnum></citerefentry> 使用 <command>" +"sss_ssh_knownhostsproxy</command> 進行主機金鑰驗證:<placeholder " +"type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_ssh_knownhostsproxy.1.xml:76 msgid "<option>-p</option>,<option>--port</option> <replaceable>PORT</replaceable>" msgstr "" +"<option>-p</option>,<option>--port</option> <replaceable>PORT</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_ssh_knownhostsproxy.1.xml:81 msgid "" "Use port <replaceable>PORT</replaceable> to connect to the host. By " "default, port 22 is used." -msgstr "" +msgstr "使用連接埠 <replaceable>PORT</replaceable> 連線到主機。依預設使用連接埠 22。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sss_ssh_knownhostsproxy.1.xml:99 msgid "<option>-k</option>,<option>--pubkey</option>" -msgstr "" +msgstr "<option>-k</option>,<option>--pubkey</option>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sss_ssh_knownhostsproxy.1.xml:103 msgid "Print the host ssh public keys for host <replaceable>HOST</replaceable>." -msgstr "" +msgstr "列印主機 <replaceable>HOST</replaceable> 的主機 SSH 公開金鑰。" #. type: Content of: <reference><refentry><refnamediv><refname> #: idmap_sss.8.xml:10 idmap_sss.8.xml:15 msgid "idmap_sss" -msgstr "" +msgstr "idmap_sss" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: idmap_sss.8.xml:16 msgid "SSSD's idmap_sss Backend for Winbind" -msgstr "" +msgstr "用於 Winbind 的 SSSD idmap_sss 後端" #. type: Content of: <reference><refentry><refsect1><para> #: idmap_sss.8.xml:22 @@ -14435,28 +16654,30 @@ msgid "" "The idmap_sss module provides a way to call SSSD to map UIDs/GIDs and " "SIDs. No database is required in this case as the mapping is done by SSSD." msgstr "" +"idmap_sss 模組提供呼叫 SSSD 對應 UID/GID 與 SID 的方式。這種情況下不需要資料" +"庫,因為對應由 SSSD 執行。" #. type: Content of: <reference><refentry><refsect1><title> #: idmap_sss.8.xml:29 msgid "IDMAP OPTIONS" -msgstr "" +msgstr "IDMAP 選項" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: idmap_sss.8.xml:33 msgid "range = low - high" -msgstr "" +msgstr "range = low - high" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: idmap_sss.8.xml:35 msgid "" "Defines the available matching UID and GID range for which the backend is " "authoritative." -msgstr "" +msgstr "定義後端具有權威性的可用符合 UID 與 GID 範圍。" #. type: Content of: <reference><refentry><refsect1><para> #: idmap_sss.8.xml:45 msgid "This example shows how to configure idmap_sss as the default mapping module." -msgstr "" +msgstr "此範例顯示如何將 idmap_sss 設定為預設對應模組。" #. type: Content of: <reference><refentry><refsect1><programlisting> #: idmap_sss.8.xml:50 @@ -14474,6 +16695,17 @@ msgid "" "idmap config * : range = 100000-199999\n" " " msgstr "" +"[global]\n" +"security = ads\n" +"workgroup = <AD-DOMAIN-SHORTNAME>\n" +"\n" +"idmap config <AD-DOMAIN-SHORTNAME> : backend = sss\n" +"idmap config <AD-DOMAIN-SHORTNAME> : range = 200000-" +"2147483647\n" +"\n" +"idmap config * : backend = tdb\n" +"idmap config * : range = 100000-199999\n" +" " #. type: Content of: <reference><refentry><refsect1><para> #: idmap_sss.8.xml:62 @@ -14483,6 +16715,9 @@ msgid "" "<literal>idmap config</literal> line with <literal>backend = sss</literal> " "and a line with a suitable <literal>range</literal>." msgstr "" +"請將 <AD-DOMAIN-SHORTNAME> 取代為 AD 網域的 NetBIOS 網域名稱。若應該使" +"用多個 AD 網域,每個網域都需要一行 <literal>idmap config</literal>,其中包含 " +"<literal>backend = sss</literal>,以及一行合適的 <literal>range</literal>。" #. type: Content of: <reference><refentry><refsect1><para> #: idmap_sss.8.xml:69 @@ -14490,16 +16725,18 @@ msgid "" "Since Winbind requires a writeable default backend and idmap_sss is " "read-only the example includes <literal>backend = tdb</literal> as default." msgstr "" +"由於 Winbind 需要可寫入的預設後端,而 idmap_sss 是唯讀的,範例包含 <literal>" +"backend = tdb</literal> 作為預設。" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssctl.8.xml:10 sssctl.8.xml:15 msgid "sssctl" -msgstr "" +msgstr "sssctl" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssctl.8.xml:16 msgid "SSSD control and status utility" -msgstr "" +msgstr "SSSD 控制與狀態公用程式" #. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis> #: sssctl.8.xml:21 @@ -14508,6 +16745,9 @@ msgid "" "choice='plain'><replaceable>COMMAND</replaceable></arg> <arg choice='opt'> " "<replaceable>options</replaceable> </arg>" msgstr "" +"<command>sssctl</command> <arg choice='plain'><replaceable>COMMAND</" +"replaceable></arg> <arg choice='opt'> <replaceable>options</replaceable> </" +"arg>" #. type: Content of: <reference><refentry><refsect1><para> #: sssctl.8.xml:32 @@ -14518,6 +16758,9 @@ msgid "" "files for troubleshooting in such a way that is safe to manipulate while " "SSSD is running." msgstr "" +"<command>sssctl</command> 提供取得 SSSD 狀態資訊(例如作用中伺服器、自動探索" +"的伺服器、網域與快取物件)的簡單統一方式。此外,它可以管理 SSSD 資料檔案以進" +"行疑難排解,而且這種方式在 SSSD 執行期間操作是安全的。" #. type: Content of: <reference><refentry><refsect1><para> #: sssctl.8.xml:43 @@ -14526,16 +16769,18 @@ msgid "" "parameters. To print help for selected command run <command>sssctl COMMAND " "--help</command>." msgstr "" +"要列出所有可用的指令,請在沒有任何參數的情況下執行 <command>sssctl</command>" +"。要列印所選指令的說明,請執行 <command>sssctl COMMAND --help</command>。" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-files.5.xml:10 sssd-files.5.xml:16 msgid "sssd-files" -msgstr "" +msgstr "sssd-files" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-files.5.xml:17 msgid "SSSD files provider" -msgstr "" +msgstr "SSSD files 提供者" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-files.5.xml:23 @@ -14547,6 +16792,10 @@ msgid "" "<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> manual page." msgstr "" +"本手冊頁說明 <citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>" +"8</manvolnum> </citerefentry> 的 files 提供者。詳細的語法參考請參閱 " +"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> 手冊頁的 <quote>FILE FORMAT</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-files.5.xml:36 @@ -14560,11 +16809,17 @@ msgid "" "<citerefentry> <refentrytitle>sssd-ifp</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry>." msgstr "" +"files 提供者鏡像 <citerefentry> <refentrytitle>passwd</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> 與 <citerefentry> <refentrytitle>" +"group</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 檔案的內容。" +"files 提供者的目的是讓傳統上只能透過 NSS 介面存取的使用者與群組,也能透過 " +"SSSD 介面(例如 <citerefentry> <refentrytitle>sssd-ifp</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>)存取。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-files.5.xml:55 msgid "Another reason is to provide efficient caching of local users and groups." -msgstr "" +msgstr "另一個原因是提供本機使用者與群組的有效率快取。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-files.5.xml:58 @@ -14574,6 +16829,9 @@ msgid "" "<citerefentry> <refentrytitle>sssd.conf</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> for details." msgstr "" +"請注意,除了明確的網域定義之外,files 提供者也可以使用 'enable_files_domain' " +"選項隱式設定。詳細資料請參閱 <citerefentry> <refentrytitle>sssd.conf</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-files.5.xml:66 @@ -14582,6 +16840,8 @@ msgid "" "UID/GID 0 is not handled by SSSD. Such requests are passed to next NSS " "module (usually files)." msgstr "" +"SSSD 永遠不處理使用者/群組 \"root\" 的解析。SSSD 也不處理 UID/GID 0 的解析。" +"這類要求會傳給下一個 NSS 模組(通常是 files)。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-files.5.xml:71 @@ -14589,11 +16849,13 @@ msgid "" "When SSSD is not running or responding, nss_sss returns the UNAVAIL code " "which causes the request to be passed to the next module." msgstr "" +"當 SSSD 未執行或未回應時,nss_sss 會傳回 UNAVAIL 代碼,導致要求傳給下一個模組" +"。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-files.5.xml:95 msgid "passwd_files (string)" -msgstr "" +msgstr "passwd_files (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-files.5.xml:98 @@ -14602,16 +16864,18 @@ msgid "" "enumerated by the files provider, inotify monitor watches will be set on " "each file to detect changes dynamically." msgstr "" +"要由 files 提供者讀取與列舉之一個或多個密碼檔名稱的逗號分隔清單,每個檔案上都" +"會設定 inotify 監視器以動態偵測變更。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-files.5.xml:104 msgid "Default: /etc/passwd" -msgstr "" +msgstr "預設:/etc/passwd" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-files.5.xml:110 msgid "group_files (string)" -msgstr "" +msgstr "group_files (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-files.5.xml:113 @@ -14620,16 +16884,18 @@ msgid "" "enumerated by the files provider, inotify monitor watches will be set on " "each file to detect changes dynamically." msgstr "" +"要由 files 提供者讀取與列舉之一個或多個群組檔名稱的逗號分隔清單,每個檔案上都" +"會設定 inotify 監視器以動態偵測變更。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-files.5.xml:119 msgid "Default: /etc/group" -msgstr "" +msgstr "預設:/etc/group" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-files.5.xml:125 msgid "fallback_to_nss (boolean)" -msgstr "" +msgstr "fallback_to_nss (boolean)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-files.5.xml:128 @@ -14640,6 +16906,10 @@ msgid "" "<filename>/etc/group</filename> and the NSS configuration has 'sss' before " "'files' for the 'passwd' and 'group' maps." msgstr "" +"在更新內部資料時,SSSD 會傳回錯誤並讓用戶端繼續使用下一個 NSS 模組。當使用預" +"設系統檔案 <filename>/etc/passwd</filename> 與 <filename>/etc/group</" +"filename>,且 NSS 設定在 'passwd' 與 'group' 對應中將 'sss' 放在 'files' 前面" +"時,這有助於避免延遲。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-files.5.xml:138 @@ -14648,6 +16918,8 @@ msgid "" "set this option to 'False' to avoid inconsistent behavior because in general " "there would be no other NSS module which can be used as a fallback." msgstr "" +"若 files 提供者設定為監視其他檔案,將此選項設為 'False' 以避免不一致的行為是" +"合理的,因為一般來說沒有其他 NSS 模組可以作為退回使用。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-files.5.xml:79 @@ -14664,6 +16936,13 @@ msgid "" "domain unless explicitly specified per-domain. <placeholder " "type=\"variablelist\" id=\"0\"/>" msgstr "" +"除了下列列出的選項之外,可以在適用的地方設定一般 SSSD 網域選項。SSSD 網域設定" +"的詳細資料請參閱 <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> 手冊頁的 <quote>DOMAIN SECTIONS</" +"quote> 一節。但 files 提供者的目的是透過 SSSD 介面公開與 UNIX 檔案相同的資料" +"。因此並非所有一般網域選項都支援。同樣地,某些全域選項(例如在 <quote>nss</" +"quote> 區段中為所有網域覆寫 shell)對 files 網域沒有影響,除非明確按網域指定" +"。<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-files.5.xml:157 @@ -14671,6 +16950,8 @@ msgid "" "The following example assumes that SSSD is correctly configured and files is " "one of the domains in the <replaceable>[sssd]</replaceable> section." msgstr "" +"下列範例假設 SSSD 已正確設定,且 files 是 <replaceable>[sssd]</replaceable> " +"區段中的其中一個網域。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-files.5.xml:163 @@ -14679,6 +16960,8 @@ msgid "" "[domain/files]\n" "id_provider = files\n" msgstr "" +"[domain/files]\n" +"id_provider = files\n" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-files.5.xml:168 @@ -14686,6 +16969,8 @@ msgid "" "To leverage caching of local users and groups by SSSD nss_sss module must be " "listed before nss_files module in /etc/nsswitch.conf." msgstr "" +"要充分運用 SSSD 對本機使用者與群組的快取,/etc/nsswitch.conf 中 nss_sss 模組" +"必須列在 nss_files 模組前面。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-files.5.xml:174 @@ -14694,16 +16979,18 @@ msgid "" "passwd: sss files\n" "group: sss files\n" msgstr "" +"passwd: sss files\n" +"group: sss files\n" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-session-recording.5.xml:10 sssd-session-recording.5.xml:16 msgid "sssd-session-recording" -msgstr "" +msgstr "sssd-session-recording" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-session-recording.5.xml:17 msgid "Configuring session recording with SSSD" -msgstr "" +msgstr "使用 SSSD 設定工作階段錄製" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-session-recording.5.xml:23 @@ -14717,6 +17004,13 @@ msgid "" "section of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" +"本手冊頁說明如何設定 <citerefentry> <refentrytitle>sssd</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> 與 tlog 套件的 <citerefentry> " +"<refentrytitle>tlog-rec-session</refentrytitle> <manvolnum>8</manvolnum> </" +"citerefentry> 搭配運作,以在文字終端機上實作使用者工作階段錄製。詳細的設定語" +"法參考請參閱 <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> 手冊頁的 <quote>FILE FORMAT</quote> " +"一節。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-session-recording.5.xml:41 @@ -14727,6 +17021,9 @@ msgid "" "tlog-rec-session is started upon user login, so it can record according to " "its configuration." msgstr "" +"SSSD 可以設定為啟用特定使用者在文字終端機工作階段期間看到或輸入的一切內容的錄" +"製。例如使用者透過主控台或 SSH 登入時。SSSD 本身不錄製任何內容,但確保使用者" +"在登入時啟動 tlog-rec-session,以便它根據其設定進行錄製。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-session-recording.5.xml:48 @@ -14737,11 +17034,15 @@ msgid "" "tlog-rec-session can be started in place of the user shell, and know which " "actual shell to start, once it set up the recording." msgstr "" +"對啟用工作階段錄製的使用者,SSSD 在 NSS 回應中將使用者 shell 取代為 tlog-rec-" +"session,並在 PAM 工作階段設定時,將指定原始 shell 的變數加入使用者環境。這" +"樣 tlog-rec-session 可以取代使用者 shell 啟動,並在設定好錄製後知道要啟動哪個" +"實際的 shell。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-session-recording.5.xml:60 msgid "These options can be used to configure the session recording." -msgstr "" +msgstr "這些選項可用於設定工作階段錄製。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-session-recording.5.xml:178 @@ -14749,6 +17050,8 @@ msgid "" "The following snippet of sssd.conf enables session recording for users " "\"contractor1\" and \"contractor2\", and group \"students\"." msgstr "" +"下列 sssd.conf 片段為使用者 \"contractor1\" 與 \"contractor2\",以及群組 " +"\"students\" 啟用工作階段錄製。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-session-recording.5.xml:183 @@ -14759,16 +17062,20 @@ msgid "" "users = contractor1, contractor2\n" "groups = students\n" msgstr "" +"[session_recording]\n" +"scope = some\n" +"users = contractor1, contractor2\n" +"groups = students\n" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-kcm.8.xml:10 sssd-kcm.8.xml:16 msgid "sssd-kcm" -msgstr "" +msgstr "sssd-kcm" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-kcm.8.xml:17 msgid "SSSD Kerberos Cache Manager" -msgstr "" +msgstr "SSSD Kerberos 快取管理員" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:23 @@ -14779,6 +17086,9 @@ msgid "" "the MIT Kerberos library also provides client side (more details on that " "below) support for the KCM credential cache." msgstr "" +"本手冊頁說明 SSSD Kerberos 快取管理員 (KCM) 的設定。KCM 是儲存、追蹤與管理 " +"Kerberos 憑證快取的程序。它起源於 Heimdal Kerberos 專案,不過 MIT Kerberos 程" +"式庫也提供 KCM 憑證快取的用戶端(下面有更多詳細資料)支援。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:31 @@ -14790,6 +17100,10 @@ msgid "" "being referred to as a <quote>\"KCM server\"</quote>. The client and server " "communicate over a UNIX socket." msgstr "" +"在由 KCM 管理 Kerberos 快取的設定中,Kerberos 程式庫(通常透過應用程式使用," +"例如 <citerefentry> <refentrytitle>kinit</refentrytitle><manvolnum>1</" +"manvolnum> </citerefentry>)是 <quote>\"KCM client\"</quote>,KCM 常駐程式被" +"稱為 <quote>\"KCM server\"</quote>。用戶端與伺服器透過 UNIX socket 通訊。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:42 @@ -14798,18 +17112,20 @@ msgid "" "access check control based on the UID and GID of the KCM client. The root " "user has access to all credential caches." msgstr "" +"KCM 伺服器追蹤每個憑證快取的所有者,並根據 KCM 用戶端的 UID 與 GID 執行存取檢" +"查控制。root 使用者可以存取所有憑證快取。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:47 msgid "The KCM credential cache has several interesting properties:" -msgstr "" +msgstr "KCM 憑證快取有幾個有趣的屬性:" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd-kcm.8.xml:51 msgid "" "since the process runs in userspace, it is subject to UID namespacing, " "unlike the kernel keyring" -msgstr "" +msgstr "由於程序在使用者空間執行,它受 UID 命名空間影響,不像核心 keyring" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd-kcm.8.xml:56 @@ -14818,6 +17134,8 @@ msgid "" "containers, the KCM server is a separate process whose entry point is a UNIX " "socket" msgstr "" +"不像在所有容器之間共用的核心 keyring 型快取,KCM 伺服器是獨立的程序,其進入點" +"是 UNIX socket" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd-kcm.8.xml:61 @@ -14826,6 +17144,9 @@ msgid "" "at <replaceable>/var/lib/sss/secrets</replaceable> allowing the ccaches to " "survive KCM server restarts or machine reboots." msgstr "" +"SSSD 實作將 ccache 儲存在資料庫中,通常位於 <replaceable>/var/lib/sss/" +"secrets</replaceable>,讓 ccache 在 KCM 伺服器重新啟動或機器重新開機後仍能保" +"存。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:67 @@ -14834,6 +17155,8 @@ msgid "" "the credential cache between some or no containers by bind-mounting the " "socket." msgstr "" +"這允許系統使用可感知集合的憑證快取,並透過 bind-mount socket 在部分或沒有容器" +"之間共用憑證快取。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:72 @@ -14841,11 +17164,13 @@ msgid "" "The KCM default client idle timeout is 5 minutes, this allows more time for " "user interaction with command line tools such as kinit." msgstr "" +"KCM 預設用戶端閒置逾時為 5 分鐘,這允許更多時間讓使用者與 kinit 等命令列工具" +"互動。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-kcm.8.xml:78 msgid "USING THE KCM CREDENTIAL CACHE" -msgstr "" +msgstr "使用 KCM 憑證快取" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-kcm.8.xml:88 @@ -14855,6 +17180,9 @@ msgid "" " default_ccache_name = KCM:\n" " " msgstr "" +"[libdefaults]\n" +" default_ccache_name = KCM:\n" +" " #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:80 @@ -14866,6 +17194,10 @@ msgid "" "without any template expansions. For example: <placeholder " "type=\"programlisting\" id=\"0\"/>" msgstr "" +"要使用 KCM 憑證快取,必須在 <citerefentry> <refentrytitle>krb5.conf</" +"refentrytitle><manvolnum>5</manvolnum> </citerefentry> 中將它選為預設憑證類型" +"。憑證快取名稱必須只有 <quote>KCM:</quote>,沒有任何範本展開。例如" +":<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:93 @@ -14878,6 +17210,11 @@ msgid "" "<refentrytitle>krb5.conf</refentrytitle><manvolnum>5</manvolnum> " "</citerefentry> manual page." msgstr "" +"接下來,確保 Kerberos 用戶端程式庫與 KCM 伺服器在 UNIX socket 路徑上必須一致" +"。依預設,兩者都使用相同的路徑 <replaceable>/var/run/.heim_org.h5l.kcm-" +"socket</replaceable>。若要設定 Kerberos 程式庫,請變更其 <quote>kcm_socket</" +"quote> 選項,該選項在 <citerefentry> <refentrytitle>krb5.conf</refentrytitle>" +"<manvolnum>5</manvolnum> </citerefentry> 手冊頁中有說明。" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-kcm.8.xml:115 @@ -14887,6 +17224,9 @@ msgid "" "systemctl enable sssd-kcm.socket\n" " " msgstr "" +"systemctl start sssd-kcm.socket\n" +"systemctl enable sssd-kcm.socket\n" +" " #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:104 @@ -14899,11 +17239,17 @@ msgid "" "<placeholder type=\"programlisting\" id=\"0\"/> Please note your " "distribution may already configure the units for you." msgstr "" +"最後,確保可以連絡 SSSD KCM 伺服器。KCM 服務通常由 <citerefentry> " +"<refentrytitle>systemd</refentrytitle> <manvolnum>1</manvolnum> </" +"citerefentry> 以 socket 啟動。與其他 SSSD 服務不同,它不能透過將 <quote>kcm</" +"quote> 字串加入 <quote>service</quote> 指示來啟動。<placeholder " +"type=\"programlisting\" id=\"0\"/> 請注意,您的發行版可能已為您設定好這些 " +"unit。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-kcm.8.xml:124 msgid "THE CREDENTIAL CACHE STORAGE" -msgstr "" +msgstr "憑證快取儲存" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:126 @@ -14912,11 +17258,13 @@ msgid "" "or group entries. The database is typically located at " "<quote>/var/lib/sss/secrets</quote>." msgstr "" +"憑證快取儲存在資料庫中,很像 SSSD 快取使用者或群組項目。資料庫通常位於 " +"<quote>/var/lib/sss/secrets</quote>。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-kcm.8.xml:133 msgid "OBTAINING DEBUG LOGS" -msgstr "" +msgstr "取得除錯記錄" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-kcm.8.xml:144 @@ -14926,6 +17274,9 @@ msgid "" "debug_level = 10\n" " " msgstr "" +"[kcm]\n" +"debug_level = 10\n" +" " #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-kcm.8.xml:149 sssd-kcm.8.xml:211 @@ -14934,6 +17285,8 @@ msgid "" "systemctl restart sssd-kcm.service\n" " " msgstr "" +"systemctl restart sssd-kcm.service\n" +" " #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:135 @@ -14951,6 +17304,14 @@ msgid "" "as the sssd-kcm service can generate quite a large amount of debugging " "information." msgstr "" +"sssd-kcm 服務通常由 <citerefentry> <refentrytitle>systemd</refentrytitle> " +"<manvolnum>1</manvolnum> </citerefentry> 以 socket 啟動。要產生除錯記錄,請將" +"下列內容直接加入 <filename>/etc/sssd/sssd.conf</filename> 檔案,或作為設定片" +"段加入 <filename>/etc/sssd/conf.d/</filename> 目錄:<placeholder " +"type=\"programlisting\" id=\"0\"/> 然後重新啟動 sssd-kcm 服務:<placeholder " +"type=\"programlisting\" id=\"1\"/> 最後,執行對您來說無法運作的任何使用案例。" +"KCM 記錄會在 <filename>/var/log/sssd/sssd_kcm.log</filename> 產生。建議在不再" +"需要除錯時停用除錯記錄,因為 sssd-kcm 服務可能產生相當大量的除錯資訊。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:159 @@ -14959,11 +17320,13 @@ msgid "" "if the main configuration file at <filename>/etc/sssd/sssd.conf</filename> " "exists at all." msgstr "" +"請注意,目前只有在主要設定檔 <filename>/etc/sssd/sssd.conf</filename> 存在時" +",才會處理設定片段。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-kcm.8.xml:166 msgid "RENEWALS" -msgstr "" +msgstr "續約" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-kcm.8.xml:174 @@ -14973,6 +17336,9 @@ msgid "" "krb5_renew_interval = 60m\n" " " msgstr "" +"tgt_renewal = true\n" +"krb5_renew_interval = 60m\n" +" " #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:168 @@ -14983,11 +17349,14 @@ msgid "" "following options are set in the [kcm] section: <placeholder " "type=\"programlisting\" id=\"0\"/>" msgstr "" +"sssd-kcm 服務可以設定為對儲存在 KCM ccache 中可續約的 TGT 嘗試 TGT 續約。只有" +"在票證生命週期過半時才會嘗試續約。在 [kcm] 區段中設定下列選項時,即設定 KCM " +"續約:<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:179 msgid "SSSD can also inherit krb5 options for renewals from an existing domain." -msgstr "" +msgstr "SSSD 也可以從現有的網域繼承用於續約的 krb5 選項。" #. type: Content of: <reference><refentry><refsect1><programlisting> #: sssd-kcm.8.xml:183 @@ -14997,6 +17366,9 @@ msgid "" "tgt_renewal_inherit = domain-name\n" " " msgstr "" +"tgt_renewal = true\n" +"tgt_renewal_inherit = domain-name\n" +" " #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd-kcm.8.xml:191 @@ -15010,6 +17382,13 @@ msgid "" "krb5_auth_timeout\n" " " msgstr "" +"krb5_renew_interval\n" +"krb5_renewable_lifetime\n" +"krb5_lifetime\n" +"krb5_validate\n" +"krb5_canonicalize\n" +"krb5_auth_timeout\n" +" " #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:187 @@ -15018,6 +17397,8 @@ msgid "" "renewal behavior, these options are described in detail below <placeholder " "type=\"programlisting\" id=\"0\"/>" msgstr "" +"可以在 [kcm] 區段中設定下列 krb5 選項以控制續約行為,這些選項在下面詳細說明 " +"<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:204 @@ -15028,6 +17409,10 @@ msgid "" "service after changing options in the <quote>kcm</quote> section of " "sssd.conf: <placeholder type=\"programlisting\" id=\"0\"/>" msgstr "" +"KCM 服務在 sssd.conf 檔案的 <quote>kcm</quote> 區段中設定。請注意,由於 KCM " +"服務通常以 socket 啟動,變更 sssd.conf 之 <quote>kcm</quote> 區段中的選項後," +"只要重新啟動 <quote>sssd-kcm</quote> 服務即可:<placeholder " +"type=\"programlisting\" id=\"0\"/>" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:215 @@ -15037,6 +17422,9 @@ msgid "" "<citerefentry> <refentrytitle>sssd.conf</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> manual page." msgstr "" +"KCM 服務在 <quote>kcm</quote> 中設定。詳細的語法參考請參閱 <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry> 手冊頁的 <quote>FILE FORMAT</quote> 一節。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:223 @@ -15047,21 +17435,25 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> manual page for a complete list. In " "addition, there are some KCM-specific options as well." msgstr "" +"kcm 服務接受 <quote>debug_level</quote> 或 <quote>fd_limit</quote> 等一般 " +"SSSD 服務選項。完整清單請參閱 <citerefentry> <refentrytitle>sssd.conf</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 手冊頁。此外,也有一" +"些 KCM 專用選項。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-kcm.8.xml:234 msgid "socket_path (string)" -msgstr "" +msgstr "socket_path (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:237 msgid "The socket the KCM service will listen on." -msgstr "" +msgstr "KCM 服務將在上面監聽的 socket。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:240 msgid "Default: <replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" -msgstr "" +msgstr "預設:<replaceable>/var/run/.heim_org.h5l.kcm-socket</replaceable>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:243 @@ -15070,26 +17462,28 @@ msgid "" "supported, the socket path is overwritten by the one defined in the " "sssd-kcm.socket unit file. </phrase>" msgstr "" +"<phrase condition=\"have_systemd\"> 注意:在支援 systemd 的平台上,socket 路" +"徑會被 sssd-kcm.socket unit 檔案中定義的路徑覆寫。 </phrase>" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-kcm.8.xml:252 msgid "max_ccaches (integer)" -msgstr "" +msgstr "max_ccaches (integer)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:255 msgid "How many credential caches does the KCM database allow for all users." -msgstr "" +msgstr "KCM 資料庫允許所有使用者擁有多少個憑證快取。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:259 msgid "Default: 0 (unlimited, only the per-UID quota is enforced)" -msgstr "" +msgstr "預設:0(無限制,只執行每個 UID 的配額)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-kcm.8.xml:264 msgid "max_uid_ccaches (integer)" -msgstr "" +msgstr "max_uid_ccaches (integer)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:267 @@ -15097,58 +17491,60 @@ msgid "" "How many credential caches does the KCM database allow per UID. This is " "equivalent to <quote>with how many principals you can kinit</quote>." msgstr "" +"KCM 資料庫允許每個 UID 擁有多少個憑證快取。這等同於 <quote>您可以對多少個 " +"principal 執行 kinit</quote>。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:272 msgid "Default: 64" -msgstr "" +msgstr "預設:64" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-kcm.8.xml:277 msgid "max_ccache_size (integer)" -msgstr "" +msgstr "max_ccache_size (integer)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:280 msgid "" "How big can a credential cache be per ccache. Each service ticket accounts " "into this quota." -msgstr "" +msgstr "每個 ccache 的憑證快取可以多大。每個服務票證都會計入此配額。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:284 msgid "Default: 65536" -msgstr "" +msgstr "預設:65536" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-kcm.8.xml:289 msgid "tgt_renewal (bool)" -msgstr "" +msgstr "tgt_renewal (bool)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:292 msgid "Enables TGT renewals functionality." -msgstr "" +msgstr "啟用 TGT 續約功能。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:295 msgid "Default: False (Automatic renewals disabled)" -msgstr "" +msgstr "預設:False(停用自動續約)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-kcm.8.xml:300 msgid "tgt_renewal_inherit (string)" -msgstr "" +msgstr "tgt_renewal_inherit (string)" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:303 msgid "Domain to inherit krb5_* options from, for use with TGT renewals." -msgstr "" +msgstr "從中繼承 krb5_* 選項以用於 TGT 續約的網域。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-kcm.8.xml:307 msgid "Default: NULL" -msgstr "" +msgstr "預設:NULL" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-kcm.8.xml:318 @@ -15158,16 +17554,19 @@ msgid "" "<refentrytitle>sssd.conf</refentrytitle><manvolnum>5</manvolnum> " "</citerefentry>," msgstr "" +"<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>sssd.conf</refentrytitle>" +"<manvolnum>5</manvolnum> </citerefentry>," #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-systemtap.5.xml:10 sssd-systemtap.5.xml:16 msgid "sssd-systemtap" -msgstr "" +msgstr "sssd-systemtap" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-systemtap.5.xml:17 msgid "SSSD systemtap information" -msgstr "" +msgstr "SSSD systemtap 資訊" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-systemtap.5.xml:23 @@ -15176,6 +17575,8 @@ msgid "" "<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> " "</citerefentry>." msgstr "" +"本手冊頁提供 <citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>" +"8</manvolnum> </citerefentry> 中 systemtap 功能的資訊。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-systemtap.5.xml:32 @@ -15183,11 +17584,13 @@ msgid "" "SystemTap Probe points have been added into various locations in SSSD code " "to assist in troubleshooting and analyzing performance related issues." msgstr "" +"SSSD 程式碼的各種位置已加入 SystemTap 探測點,以協助疑難排解與分析與效能相關" +"的問題。" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd-systemtap.5.xml:40 msgid "Sample SystemTap scripts are provided in /usr/share/sssd/systemtap/" -msgstr "" +msgstr "範例 SystemTap 腳本位於 /usr/share/sssd/systemtap/" #. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para> #: sssd-systemtap.5.xml:46 @@ -15196,28 +17599,30 @@ msgid "" "/usr/share/systemtap/tapset/sssd.stp and " "/usr/share/systemtap/tapset/sssd_functions.stp respectively." msgstr "" +"探測與各種函式分別在 /usr/share/systemtap/tapset/sssd.stp 與 /usr/share/" +"systemtap/tapset/sssd_functions.stp 中定義。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-systemtap.5.xml:57 msgid "PROBE POINTS" -msgstr "" +msgstr "探測點" #. type: Content of: <reference><refentry><refsect1><refsect2><para> #: sssd-systemtap.5.xml:59 sssd-systemtap.5.xml:367 msgid "" "The information below lists the probe points and arguments available in the " "following format:" -msgstr "" +msgstr "下列資訊以以下格式列出可用的探測點與引數:" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:64 msgid "probe $name" -msgstr "" +msgstr "probe $name" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:67 msgid "Description of probe point" -msgstr "" +msgstr "探測點的說明" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><programlisting> #: sssd-systemtap.5.xml:70 @@ -15229,21 +17634,26 @@ msgid "" "...\n" " " msgstr "" +"variable1:datatype\n" +"variable2:datatype\n" +"variable3:datatype\n" +"...\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd-systemtap.5.xml:80 msgid "Database Transaction Probes" -msgstr "" +msgstr "資料庫交易探測" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:84 msgid "probe sssd_transaction_start" -msgstr "" +msgstr "probe sssd_transaction_start" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:87 msgid "Start of a sysdb transaction, probes the sysdb_transaction_start() function." -msgstr "" +msgstr "sysdb 交易的開始,探測 sysdb_transaction_start() 函式。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> #: sssd-systemtap.5.xml:91 sssd-systemtap.5.xml:105 sssd-systemtap.5.xml:118 @@ -15254,53 +17664,56 @@ msgid "" "probestr:string\n" " " msgstr "" +"nesting:integer\n" +"probestr:string\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:97 msgid "probe sssd_transaction_cancel" -msgstr "" +msgstr "probe sssd_transaction_cancel" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:100 msgid "" "Cancellation of a sysdb transaction, probes the sysdb_transaction_cancel() " "function." -msgstr "" +msgstr "sysdb 交易的取消,探測 sysdb_transaction_cancel() 函式。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:111 msgid "probe sssd_transaction_commit_before" -msgstr "" +msgstr "probe sssd_transaction_commit_before" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:114 msgid "Probes the sysdb_transaction_commit_before() function." -msgstr "" +msgstr "探測 sysdb_transaction_commit_before() 函式。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:124 msgid "probe sssd_transaction_commit_after" -msgstr "" +msgstr "probe sssd_transaction_commit_after" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:127 msgid "Probes the sysdb_transaction_commit_after() function." -msgstr "" +msgstr "探測 sysdb_transaction_commit_after() 函式。" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd-systemtap.5.xml:141 msgid "LDAP Search Probes" -msgstr "" +msgstr "LDAP 搜尋探測" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:145 msgid "probe sdap_search_send" -msgstr "" +msgstr "probe sdap_search_send" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:148 msgid "Probes the sdap_get_generic_ext_send() function." -msgstr "" +msgstr "探測 sdap_get_generic_ext_send() 函式。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> #: sssd-systemtap.5.xml:152 @@ -15313,16 +17726,22 @@ msgid "" "probestr:string\n" " " msgstr "" +"base:string\n" +"scope:integer\n" +"filter:string\n" +"attrs:string\n" +"probestr:string\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:161 msgid "probe sdap_search_recv" -msgstr "" +msgstr "probe sdap_search_recv" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:164 msgid "Probes the sdap_get_generic_ext_recv() function." -msgstr "" +msgstr "探測 sdap_get_generic_ext_recv() 函式。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> #: sssd-systemtap.5.xml:168 sssd-systemtap.5.xml:222 @@ -15334,18 +17753,23 @@ msgid "" "probestr:string\n" " " msgstr "" +"base:string\n" +"scope:integer\n" +"filter:string\n" +"probestr:string\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:176 msgid "probe sdap_parse_entry" -msgstr "" +msgstr "probe sdap_parse_entry" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:179 msgid "" "Probes the sdap_parse_entry() function. It is called repeatedly with every " "received attribute." -msgstr "" +msgstr "探測 sdap_parse_entry() 函式。每收到一個屬性就會重複呼叫它。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> #: sssd-systemtap.5.xml:184 @@ -15355,28 +17779,31 @@ msgid "" "value:string\n" " " msgstr "" +"attr:string\n" +"value:string\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:190 msgid "probe sdap_parse_entry_done" -msgstr "" +msgstr "probe sdap_parse_entry_done" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:193 msgid "" "Probes the sdap_parse_entry() function. It is called when parsing of " "received object is finished." -msgstr "" +msgstr "探測 sdap_parse_entry() 函式。收到物件的剖析完成時呼叫它。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:201 msgid "probe sdap_deref_send" -msgstr "" +msgstr "probe sdap_deref_send" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:204 msgid "Probes the sdap_deref_search_send() function." -msgstr "" +msgstr "探測 sdap_deref_search_send() 函式。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> #: sssd-systemtap.5.xml:208 @@ -15387,31 +17814,35 @@ msgid "" "probestr:string\n" " " msgstr "" +"base_dn:string\n" +"deref_attr:string\n" +"probestr:string\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:215 msgid "probe sdap_deref_recv" -msgstr "" +msgstr "probe sdap_deref_recv" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:218 msgid "Probes the sdap_deref_search_recv() function." -msgstr "" +msgstr "探測 sdap_deref_search_recv() 函式。" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd-systemtap.5.xml:234 msgid "LDAP Account Request Probes" -msgstr "" +msgstr "LDAP 帳戶要求探測" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:238 msgid "probe sdap_acct_req_send" -msgstr "" +msgstr "probe sdap_acct_req_send" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:241 msgid "Probes the sdap_acct_req_send() function." -msgstr "" +msgstr "探測 sdap_acct_req_send() 函式。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> #: sssd-systemtap.5.xml:245 sssd-systemtap.5.xml:260 @@ -15423,31 +17854,36 @@ msgid "" "extra_value:string\n" " " msgstr "" +"entry_type:int\n" +"filter_type:int\n" +"filter_value:string\n" +"extra_value:string\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:253 msgid "probe sdap_acct_req_recv" -msgstr "" +msgstr "probe sdap_acct_req_recv" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:256 msgid "Probes the sdap_acct_req_recv() function." -msgstr "" +msgstr "探測 sdap_acct_req_recv() 函式。" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd-systemtap.5.xml:272 msgid "LDAP User Search Probes" -msgstr "" +msgstr "LDAP 使用者搜尋探測" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:276 msgid "probe sdap_search_user_send" -msgstr "" +msgstr "probe sdap_search_user_send" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:279 msgid "Probes the sdap_search_user_send() function." -msgstr "" +msgstr "探測 sdap_search_user_send() 函式。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> #: sssd-systemtap.5.xml:283 sssd-systemtap.5.xml:295 sssd-systemtap.5.xml:307 @@ -15457,51 +17893,53 @@ msgid "" "filter:string\n" " " msgstr "" +"filter:string\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:288 msgid "probe sdap_search_user_recv" -msgstr "" +msgstr "probe sdap_search_user_recv" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:291 msgid "Probes the sdap_search_user_recv() function." -msgstr "" +msgstr "探測 sdap_search_user_recv() 函式。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:300 msgid "probe sdap_search_user_save_begin" -msgstr "" +msgstr "probe sdap_search_user_save_begin" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:303 msgid "Probes the sdap_search_user_save_begin() function." -msgstr "" +msgstr "探測 sdap_search_user_save_begin() 函式。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:312 msgid "probe sdap_search_user_save_end" -msgstr "" +msgstr "probe sdap_search_user_save_end" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:315 msgid "Probes the sdap_search_user_save_end() function." -msgstr "" +msgstr "探測 sdap_search_user_save_end() 函式。" #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd-systemtap.5.xml:328 msgid "Data Provider Request Probes" -msgstr "" +msgstr "資料提供者要求探測" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:332 msgid "probe dp_req_send" -msgstr "" +msgstr "probe dp_req_send" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:335 msgid "A Data Provider request is submitted." -msgstr "" +msgstr "提交資料提供者要求。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> #: sssd-systemtap.5.xml:338 @@ -15513,16 +17951,21 @@ msgid "" "dp_req_method:int\n" " " msgstr "" +"dp_req_domain:string\n" +"dp_req_name:string\n" +"dp_req_target:int\n" +"dp_req_method:int\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:346 msgid "probe dp_req_done" -msgstr "" +msgstr "probe dp_req_done" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:349 msgid "A Data Provider request is completed." -msgstr "" +msgstr "資料提供者要求完成。" #. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting> #: sssd-systemtap.5.xml:352 @@ -15535,21 +17978,27 @@ msgid "" "dp_errorstr:string\n" " " msgstr "" +"dp_req_name:string\n" +"dp_req_target:int\n" +"dp_req_method:int\n" +"dp_ret:int\n" +"dp_errorstr:string\n" +" " #. type: Content of: <reference><refentry><refsect1><refsect2><title> #: sssd-systemtap.5.xml:365 msgid "MISCELLANEOUS FUNCTIONS" -msgstr "" +msgstr "其他函式" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:372 msgid "function acct_req_desc(entry_type)" -msgstr "" +msgstr "function acct_req_desc(entry_type)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:375 msgid "Convert entry_type to string and return string" -msgstr "" +msgstr "將 entry_type 轉換為字串並傳回字串" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:380 @@ -15557,36 +18006,38 @@ msgid "" "function sssd_acct_req_probestr(fc_name, entry_type, filter_type, " "filter_value, extra_value)" msgstr "" +"function sssd_acct_req_probestr(fc_name, entry_type, filter_type, " +"filter_value, extra_value)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:384 msgid "Create probe string based on filter type" -msgstr "" +msgstr "根據篩選器類型建立探測字串" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:389 msgid "function dp_target_str(target)" -msgstr "" +msgstr "function dp_target_str(target)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:392 msgid "Convert target to string and return string" -msgstr "" +msgstr "將 target 轉換為字串並傳回字串" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:397 msgid "function dp_method_str(target)" -msgstr "" +msgstr "function dp_method_str(target)" #. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:400 msgid "Convert method to string and return string" -msgstr "" +msgstr "將 method 轉換為字串並傳回字串" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-systemtap.5.xml:410 msgid "SAMPLE SYSTEMTAP SCRIPTS" -msgstr "" +msgstr "SYSTEMTAP 範例腳本" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-systemtap.5.xml:412 @@ -15595,61 +18046,63 @@ msgid "" "/usr/share/sssd/systemtap/<script_name>.stp</command>), then perform " "an identity operation and the script will collect information from probes." msgstr "" +"啟動 SystemTap 腳本(<command>stap /usr/share/sssd/systemtap/" +"<script_name>.stp</command>),然後執行身分操作,腳本會從探測收集資訊。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-systemtap.5.xml:418 msgid "Provided SystemTap scripts are:" -msgstr "" +msgstr "提供的 SystemTap 腳本有:" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:422 msgid "dp_request.stp" -msgstr "" +msgstr "dp_request.stp" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:425 msgid "Monitoring of data provider request performance." -msgstr "" +msgstr "監視資料提供者要求的效能。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:430 msgid "id_perf.stp" -msgstr "" +msgstr "id_perf.stp" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:433 msgid "Monitoring of <command>id</command> command performance." -msgstr "" +msgstr "監視 <command>id</command> 指令的效能。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:439 msgid "ldap_perf.stp" -msgstr "" +msgstr "ldap_perf.stp" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:442 msgid "Monitoring of LDAP queries." -msgstr "" +msgstr "監視 LDAP 查詢。" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term> #: sssd-systemtap.5.xml:447 msgid "nested_group_perf.stp" -msgstr "" +msgstr "nested_group_perf.stp" #. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para> #: sssd-systemtap.5.xml:450 msgid "Performance of nested groups resolving." -msgstr "" +msgstr "巢狀群組解析的效能。" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd-ldap-attributes.5.xml:10 sssd-ldap-attributes.5.xml:16 msgid "sssd-ldap-attributes" -msgstr "" +msgstr "sssd-ldap-attributes" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd-ldap-attributes.5.xml:17 msgid "SSSD LDAP Provider: Mapping Attributes" -msgstr "" +msgstr "SSSD LDAP 提供者:對應屬性" #. type: Content of: <reference><refentry><refsect1><para> #: sssd-ldap-attributes.5.xml:23 @@ -15661,76 +18114,80 @@ msgid "" "</citerefentry> manual page for full details about SSSD LDAP provider " "configuration options." msgstr "" +"本手冊頁說明 SSSD LDAP 提供者 <citerefentry> <refentrytitle>sssd-ldap</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 的對應屬性。SSSD " +"LDAP 提供者設定選項的完整詳細資料請參閱 <citerefentry> <refentrytitle>sssd-" +"ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> 手冊頁。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap-attributes.5.xml:38 msgid "USER ATTRIBUTES" -msgstr "" +msgstr "使用者屬性" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:42 msgid "ldap_user_object_class (string)" -msgstr "" +msgstr "ldap_user_object_class (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:45 msgid "The object class of a user entry in LDAP." -msgstr "" +msgstr "LDAP 中使用者項目的物件類別。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:48 msgid "Default: posixAccount" -msgstr "" +msgstr "預設:posixAccount" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:54 msgid "ldap_user_name (string)" -msgstr "" +msgstr "ldap_user_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:57 msgid "The LDAP attribute that corresponds to the user's login name." -msgstr "" +msgstr "對應使用者登入名稱的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:61 msgid "Default: uid (rfc2307, rfc2307bis and IPA), sAMAccountName (AD)" -msgstr "" +msgstr "預設:uid(rfc2307、rfc2307bis 與 IPA)、sAMAccountName(AD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:68 msgid "ldap_user_uid_number (string)" -msgstr "" +msgstr "ldap_user_uid_number (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:71 msgid "The LDAP attribute that corresponds to the user's id." -msgstr "" +msgstr "對應使用者 id 的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:75 msgid "Default: uidNumber" -msgstr "" +msgstr "預設:uidNumber" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:81 msgid "ldap_user_gid_number (string)" -msgstr "" +msgstr "ldap_user_gid_number (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:84 msgid "The LDAP attribute that corresponds to the user's primary group id." -msgstr "" +msgstr "對應使用者主要群組 id 的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:88 sssd-ldap-attributes.5.xml:700 msgid "Default: gidNumber" -msgstr "" +msgstr "預設:gidNumber" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:94 msgid "ldap_user_primary_group (string)" -msgstr "" +msgstr "ldap_user_primary_group (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:97 @@ -15739,78 +18196,80 @@ msgid "" "attribute should only be set manually if you are running the " "<quote>ldap</quote> provider with ID mapping." msgstr "" +"用於 ID 對應的 Active Directory 主要群組屬性。請注意,只有在搭配 ID 對應執行 " +"<quote>ldap</quote> 提供者時,才應手動設定此屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:103 msgid "Default: unset (LDAP), primaryGroupID (AD)" -msgstr "" +msgstr "預設:未設定(LDAP)、primaryGroupID(AD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:109 msgid "ldap_user_gecos (string)" -msgstr "" +msgstr "ldap_user_gecos (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:112 msgid "The LDAP attribute that corresponds to the user's gecos field." -msgstr "" +msgstr "對應使用者 gecos 欄位的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:116 msgid "Default: gecos" -msgstr "" +msgstr "預設:gecos" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:122 msgid "ldap_user_home_directory (string)" -msgstr "" +msgstr "ldap_user_home_directory (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:125 msgid "The LDAP attribute that contains the name of the user's home directory." -msgstr "" +msgstr "包含使用者家目錄名稱的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:129 msgid "Default: homeDirectory (LDAP and IPA), unixHomeDirectory (AD)" -msgstr "" +msgstr "預設:homeDirectory(LDAP 與 IPA)、unixHomeDirectory(AD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:135 msgid "ldap_user_shell (string)" -msgstr "" +msgstr "ldap_user_shell (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:138 msgid "The LDAP attribute that contains the path to the user's default shell." -msgstr "" +msgstr "包含使用者預設 shell 路徑的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:142 msgid "Default: loginShell" -msgstr "" +msgstr "預設:loginShell" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:148 msgid "ldap_user_uuid (string)" -msgstr "" +msgstr "ldap_user_uuid (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:151 msgid "The LDAP attribute that contains the UUID/GUID of an LDAP user object." -msgstr "" +msgstr "包含 LDAP 使用者物件之 UUID/GUID 的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:155 sssd-ldap-attributes.5.xml:726 msgid "" "Default: not set in the general case, objectGUID for AD and ipaUniqueID for " "IPA" -msgstr "" +msgstr "預設:一般情況下未設定,AD 為 objectGUID,IPA 為 ipaUniqueID" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:162 msgid "ldap_user_objectsid (string)" -msgstr "" +msgstr "ldap_user_objectsid (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:165 @@ -15818,16 +18277,18 @@ msgid "" "The LDAP attribute that contains the objectSID of an LDAP user object. This " "is usually only necessary for ActiveDirectory servers." msgstr "" +"包含 LDAP 使用者物件之 objectSID 的 LDAP 屬性。這通常只在 ActiveDirectory 伺" +"服器上需要。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:170 sssd-ldap-attributes.5.xml:741 msgid "Default: objectSid for ActiveDirectory, not set for other servers." -msgstr "" +msgstr "預設:ActiveDirectory 為 objectSid,其他伺服器未設定。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:177 msgid "ldap_user_modify_timestamp (string)" -msgstr "" +msgstr "ldap_user_modify_timestamp (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:180 sssd-ldap-attributes.5.xml:751 @@ -15835,18 +18296,18 @@ msgstr "" msgid "" "The LDAP attribute that contains timestamp of the last modification of the " "parent object." -msgstr "" +msgstr "包含父物件上次修改時間戳記的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:184 sssd-ldap-attributes.5.xml:755 #: sssd-ldap-attributes.5.xml:881 msgid "Default: modifyTimestamp" -msgstr "" +msgstr "預設:modifyTimestamp" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:190 msgid "ldap_user_shadow_last_change (string)" -msgstr "" +msgstr "ldap_user_shadow_last_change (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:193 @@ -15856,16 +18317,19 @@ msgid "" "<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> counterpart (date of the last password change)." msgstr "" +"使用 ldap_pwd_policy=shadow 時,此參數包含對應其 <citerefentry> " +"<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry> 相對項(上次密碼變更日期)的 LDAP 屬性名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:203 msgid "Default: shadowLastChange" -msgstr "" +msgstr "預設:shadowLastChange" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:209 msgid "ldap_user_shadow_min (string)" -msgstr "" +msgstr "ldap_user_shadow_min (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:212 @@ -15875,16 +18339,19 @@ msgid "" "<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> counterpart (minimum password age)." msgstr "" +"使用 ldap_pwd_policy=shadow 時,此參數包含對應其 <citerefentry> " +"<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry> 相對項(最小密碼年齡)的 LDAP 屬性名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:221 msgid "Default: shadowMin" -msgstr "" +msgstr "預設:shadowMin" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:227 msgid "ldap_user_shadow_max (string)" -msgstr "" +msgstr "ldap_user_shadow_max (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:230 @@ -15894,16 +18361,19 @@ msgid "" "<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> counterpart (maximum password age)." msgstr "" +"使用 ldap_pwd_policy=shadow 時,此參數包含對應其 <citerefentry> " +"<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry> 相對項(最大密碼年齡)的 LDAP 屬性名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:239 msgid "Default: shadowMax" -msgstr "" +msgstr "預設:shadowMax" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:245 msgid "ldap_user_shadow_warning (string)" -msgstr "" +msgstr "ldap_user_shadow_warning (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:248 @@ -15913,16 +18383,19 @@ msgid "" "<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> counterpart (password warning period)." msgstr "" +"使用 ldap_pwd_policy=shadow 時,此參數包含對應其 <citerefentry> " +"<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry> 相對項(密碼警告期限)的 LDAP 屬性名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:258 msgid "Default: shadowWarning" -msgstr "" +msgstr "預設:shadowWarning" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:264 msgid "ldap_user_shadow_inactive (string)" -msgstr "" +msgstr "ldap_user_shadow_inactive (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:267 @@ -15932,16 +18405,19 @@ msgid "" "<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> counterpart (password inactivity period)." msgstr "" +"使用 ldap_pwd_policy=shadow 時,此參數包含對應其 <citerefentry> " +"<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry> 相對項(密碼閒置期限)的 LDAP 屬性名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:277 msgid "Default: shadowInactive" -msgstr "" +msgstr "預設:shadowInactive" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:283 msgid "ldap_user_shadow_expire (string)" -msgstr "" +msgstr "ldap_user_shadow_expire (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:286 @@ -15952,16 +18428,19 @@ msgid "" "<manvolnum>5</manvolnum> </citerefentry> counterpart (account expiration " "date)." msgstr "" +"使用 ldap_pwd_policy=shadow 或 ldap_account_expire_policy=shadow 時,此參數包" +"含對應其 <citerefentry> <refentrytitle>shadow</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry> 相對項(帳戶到期日)的 LDAP 屬性名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:296 msgid "Default: shadowExpire" -msgstr "" +msgstr "預設:shadowExpire" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:302 msgid "ldap_user_krb_last_pwd_change (string)" -msgstr "" +msgstr "ldap_user_krb_last_pwd_change (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:305 @@ -15970,16 +18449,18 @@ msgid "" "an LDAP attribute storing the date and time of last password change in " "kerberos." msgstr "" +"使用 ldap_pwd_policy=mit_kerberos 時,此參數包含在 kerberos 中儲存上次密碼變" +"更日期與時間的 LDAP 屬性名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:311 msgid "Default: krbLastPwdChange" -msgstr "" +msgstr "預設:krbLastPwdChange" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:317 msgid "ldap_user_krb_password_expiration (string)" -msgstr "" +msgstr "ldap_user_krb_password_expiration (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:320 @@ -15987,16 +18468,18 @@ msgid "" "When using ldap_pwd_policy=mit_kerberos, this parameter contains the name of " "an LDAP attribute storing the date and time when current password expires." msgstr "" +"使用 ldap_pwd_policy=mit_kerberos 時,此參數包含儲存目前密碼到期日期與時間的 " +"LDAP 屬性名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:326 msgid "Default: krbPasswordExpiration" -msgstr "" +msgstr "預設:krbPasswordExpiration" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:332 msgid "ldap_user_ad_account_expires (string)" -msgstr "" +msgstr "ldap_user_ad_account_expires (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:335 @@ -16004,16 +18487,18 @@ msgid "" "When using ldap_account_expire_policy=ad, this parameter contains the name " "of an LDAP attribute storing the expiration time of the account." msgstr "" +"使用 ldap_account_expire_policy=ad 時,此參數包含儲存帳戶到期時間的 LDAP 屬性" +"名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:340 msgid "Default: accountExpires" -msgstr "" +msgstr "預設:accountExpires" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:346 msgid "ldap_user_ad_user_account_control (string)" -msgstr "" +msgstr "ldap_user_ad_user_account_control (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:349 @@ -16021,103 +18506,105 @@ msgid "" "When using ldap_account_expire_policy=ad, this parameter contains the name " "of an LDAP attribute storing the user account control bit field." msgstr "" +"使用 ldap_account_expire_policy=ad 時,此參數包含儲存使用者帳戶控制位元欄位" +"的 LDAP 屬性名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:354 msgid "Default: userAccountControl" -msgstr "" +msgstr "預設:userAccountControl" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:360 msgid "ldap_ns_account_lock (string)" -msgstr "" +msgstr "ldap_ns_account_lock (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:363 msgid "" "When using ldap_account_expire_policy=rhds or equivalent, this parameter " "determines if access is allowed or not." -msgstr "" +msgstr "使用 ldap_account_expire_policy=rhds 或等效策略時,此參數決定是否允許存取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:368 msgid "Default: nsAccountLock" -msgstr "" +msgstr "預設:nsAccountLock" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:374 msgid "ldap_user_nds_login_disabled (string)" -msgstr "" +msgstr "ldap_user_nds_login_disabled (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:377 msgid "" "When using ldap_account_expire_policy=nds, this attribute determines if " "access is allowed or not." -msgstr "" +msgstr "使用 ldap_account_expire_policy=nds 時,此屬性決定是否允許存取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:381 sssd-ldap-attributes.5.xml:395 msgid "Default: loginDisabled" -msgstr "" +msgstr "預設:loginDisabled" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:387 msgid "ldap_user_nds_login_expiration_time (string)" -msgstr "" +msgstr "ldap_user_nds_login_expiration_time (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:390 msgid "" "When using ldap_account_expire_policy=nds, this attribute determines until " "which date access is granted." -msgstr "" +msgstr "使用 ldap_account_expire_policy=nds 時,此屬性決定授權存取的截止日期。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:401 msgid "ldap_user_nds_login_allowed_time_map (string)" -msgstr "" +msgstr "ldap_user_nds_login_allowed_time_map (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:404 msgid "" "When using ldap_account_expire_policy=nds, this attribute determines the " "hours of a day in a week when access is granted." -msgstr "" +msgstr "使用 ldap_account_expire_policy=nds 時,此屬性決定一週中每天允許存取的時段。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:409 msgid "Default: loginAllowedTimeMap" -msgstr "" +msgstr "預設:loginAllowedTimeMap" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:415 msgid "ldap_user_principal (string)" -msgstr "" +msgstr "ldap_user_principal (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:418 msgid "" "The LDAP attribute that contains the user's Kerberos User Principal Name " "(UPN)." -msgstr "" +msgstr "包含使用者 Kerberos User Principal Name (UPN) 的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:422 msgid "Default: krbPrincipalName" -msgstr "" +msgstr "預設:krbPrincipalName" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:428 msgid "ldap_user_extra_attrs (string)" -msgstr "" +msgstr "ldap_user_extra_attrs (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:431 msgid "" "Comma-separated list of LDAP attributes that SSSD would fetch along with the " "usual set of user attributes." -msgstr "" +msgstr "SSSD 會與一般使用者屬性集一起擷取的 LDAP 屬性逗號分隔清單。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:436 @@ -16129,6 +18616,9 @@ msgid "" "environments that configure several SSSD domains with different LDAP " "schemas." msgstr "" +"清單可以只包含 LDAP 屬性名稱,或包含 SSSD 快取屬性名稱與 LDAP 屬性名稱的冒號" +"分隔 tuple。若只指定 LDAP 屬性名稱,屬性會原樣儲存到快取。設定具有不同 LDAP " +"schema 之多個 SSSD 網域的環境可能需要使用自訂的 SSSD 屬性名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:446 @@ -16137,11 +18627,13 @@ msgid "" "<quote>name</quote> attribute. SSSD would report an error if any of the " "reserved attribute names is used as an extra attribute name." msgstr "" +"請注意,SSSD 保留幾個屬性名稱,特別是 <quote>name</quote> 屬性。若任何保留屬" +"性名稱被用作額外屬性名稱,SSSD 會回報錯誤。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:456 msgid "ldap_user_extra_attrs = telephoneNumber" -msgstr "" +msgstr "ldap_user_extra_attrs = telephoneNumber" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:459 @@ -16149,11 +18641,13 @@ msgid "" "Save the <quote>telephoneNumber</quote> attribute from LDAP as " "<quote>telephoneNumber</quote> to the cache." msgstr "" +"將 LDAP 的 <quote>telephoneNumber</quote> 屬性以 <quote>telephoneNumber</" +"quote> 名稱儲存到快取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:463 msgid "ldap_user_extra_attrs = phone:telephoneNumber" -msgstr "" +msgstr "ldap_user_extra_attrs = phone:telephoneNumber" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:466 @@ -16161,51 +18655,53 @@ msgid "" "Save the <quote>telephoneNumber</quote> attribute from LDAP as " "<quote>phone</quote> to the cache." msgstr "" +"將 LDAP 的 <quote>telephoneNumber</quote> 屬性以 <quote>phone</quote> 名稱儲" +"存到快取。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:476 msgid "ldap_user_ssh_public_key (string)" -msgstr "" +msgstr "ldap_user_ssh_public_key (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:479 msgid "The LDAP attribute that contains the user's SSH public keys." -msgstr "" +msgstr "包含使用者 SSH 公開金鑰的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:483 sssd-ldap-attributes.5.xml:965 msgid "Default: sshPublicKey" -msgstr "" +msgstr "預設:sshPublicKey" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:489 msgid "ldap_user_fullname (string)" -msgstr "" +msgstr "ldap_user_fullname (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:492 msgid "The LDAP attribute that corresponds to the user's full name." -msgstr "" +msgstr "對應使用者全名的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:502 msgid "ldap_user_member_of (string)" -msgstr "" +msgstr "ldap_user_member_of (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:505 msgid "The LDAP attribute that lists the user's group memberships." -msgstr "" +msgstr "列出使用者群組成員資格的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:509 sssd-ldap-attributes.5.xml:952 msgid "Default: memberOf" -msgstr "" +msgstr "預設:memberOf" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:515 msgid "ldap_user_authorized_service (string)" -msgstr "" +msgstr "ldap_user_authorized_service (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:518 @@ -16214,13 +18710,15 @@ msgid "" "use the presence of the authorizedService attribute in the user's LDAP entry " "to determine access privilege." msgstr "" +"若 access_provider=ldap 且 ldap_access_order=authorized_service,SSSD 會使用" +"使用者 LDAP 項目中 authorizedService 屬性的存在與否決定存取權限。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:525 msgid "" "An explicit deny (!svc) is resolved first. Second, SSSD searches for " "explicit allow (svc) and finally for allow_all (*)." -msgstr "" +msgstr "先解析明確拒絕 (!svc)。接著 SSSD 搜尋明確允許 (svc),最後搜尋 allow_all (*)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:530 @@ -16229,6 +18727,8 @@ msgid "" "<emphasis>must</emphasis> include <quote>authorized_service</quote> in order " "for the ldap_user_authorized_service option to work." msgstr "" +"請注意,ldap_user_authorized_service 選項要能運作,ldap_access_order 設定選" +"項<emphasis>必須</emphasis>包含 <quote>authorized_service</quote>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:537 @@ -16239,16 +18739,19 @@ msgid "" "<quote>systemd-user</quote> service might need to be added to the list of " "allowed services." msgstr "" +"某些發行版(例如 Fedora-29+ 或 RHEL-8)一律將 <quote>systemd-user</quote> " +"PAM 服務包含為登入程序的一部分。因此使用以服務為基礎的存取控制時,可能需要將 " +"<quote>systemd-user</quote> 服務加入允許的服務清單。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:545 msgid "Default: authorizedService" -msgstr "" +msgstr "預設:authorizedService" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:551 msgid "ldap_user_authorized_host (string)" -msgstr "" +msgstr "ldap_user_authorized_host (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:554 @@ -16257,6 +18760,8 @@ msgid "" "presence of the host attribute in the user's LDAP entry to determine access " "privilege." msgstr "" +"若 access_provider=ldap 且 ldap_access_order=host,SSSD 會使用使用者 LDAP 項" +"目中 host 屬性的存在與否決定存取權限。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:560 @@ -16264,6 +18769,8 @@ msgid "" "An explicit deny (!host) is resolved first. Second, SSSD searches for " "explicit allow (host) and finally for allow_all (*)." msgstr "" +"先解析明確拒絕 (!host)。接著 SSSD 搜尋明確允許 (host),最後搜尋 allow_all (*)" +"。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:565 @@ -16272,16 +18779,18 @@ msgid "" "<emphasis>must</emphasis> include <quote>host</quote> in order for the " "ldap_user_authorized_host option to work." msgstr "" +"請注意,ldap_user_authorized_host 選項要能運作,ldap_access_order 設定選" +"項<emphasis>必須</emphasis>包含 <quote>host</quote>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:572 msgid "Default: host" -msgstr "" +msgstr "預設:host" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:578 msgid "ldap_user_authorized_rhost (string)" -msgstr "" +msgstr "ldap_user_authorized_rhost (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:581 @@ -16290,6 +18799,8 @@ msgid "" "presence of the rhost attribute in the user's LDAP entry to determine access " "privilege. Similarly to host verification process." msgstr "" +"若 access_provider=ldap 且 ldap_access_order=rhost,SSSD 會使用使用者 LDAP 項" +"目中 rhost 屬性的存在與否決定存取權限。與 host 驗證程序類似。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:588 @@ -16297,6 +18808,8 @@ msgid "" "An explicit deny (!rhost) is resolved first. Second, SSSD searches for " "explicit allow (rhost) and finally for allow_all (*)." msgstr "" +"先解析明確拒絕 (!rhost)。接著 SSSD 搜尋明確允許 (rhost),最後搜尋 allow_all " +"(*)。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:593 @@ -16305,36 +18818,38 @@ msgid "" "<emphasis>must</emphasis> include <quote>rhost</quote> in order for the " "ldap_user_authorized_rhost option to work." msgstr "" +"請注意,ldap_user_authorized_rhost 選項要能運作,ldap_access_order 設定選" +"項<emphasis>必須</emphasis>包含 <quote>rhost</quote>。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:600 msgid "Default: rhost" -msgstr "" +msgstr "預設:rhost" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:606 msgid "ldap_user_certificate (string)" -msgstr "" +msgstr "ldap_user_certificate (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:609 msgid "Name of the LDAP attribute containing the X509 certificate of the user." -msgstr "" +msgstr "包含使用者 X509 憑證的 LDAP 屬性名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:613 msgid "Default: userCertificate;binary" -msgstr "" +msgstr "預設:userCertificate;binary" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:619 msgid "ldap_user_email (string)" -msgstr "" +msgstr "ldap_user_email (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:622 msgid "Name of the LDAP attribute containing the email address of the user." -msgstr "" +msgstr "包含使用者電子郵件地址的 LDAP 屬性名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:626 @@ -16346,51 +18861,55 @@ msgid "" "email address then set this option to a nonexistent attribute name in order " "to disable user lookup/login by email." msgstr "" +"注意:若使用者的電子郵件地址與另一位使用者的電子郵件地址或完整限定名稱衝突," +"SSSD 將無法正常提供這些使用者服務。此選項允許使用者以 (1) 使用者名稱與 (2) 電" +"子郵件地址登入。若由於某些原因幾個使用者需要共用相同的電子郵件地址,請將此選" +"項設為不存在的屬性名稱,以停用依電子郵件進行的使用者查詢/登入。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:637 msgid "Default: mail" -msgstr "" +msgstr "預設:mail" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:642 msgid "ldap_user_passkey (string)" -msgstr "" +msgstr "ldap_user_passkey (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:645 msgid "Name of the LDAP attribute containing the passkey mapping data of the user." -msgstr "" +msgstr "包含使用者 passkey 對應資料的 LDAP 屬性名稱。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:649 msgid "Default: passkey (LDAP), ipaPassKey (IPA), altSecurityIdentities (AD)" -msgstr "" +msgstr "預設:passkey(LDAP)、ipaPassKey(IPA)、altSecurityIdentities(AD)" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap-attributes.5.xml:659 msgid "GROUP ATTRIBUTES" -msgstr "" +msgstr "群組屬性" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:663 msgid "ldap_group_object_class (string)" -msgstr "" +msgstr "ldap_group_object_class (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:666 msgid "The object class of a group entry in LDAP." -msgstr "" +msgstr "LDAP 中群組項目的物件類別。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:669 msgid "Default: posixGroup" -msgstr "" +msgstr "預設:posixGroup" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:675 msgid "ldap_group_name (string)" -msgstr "" +msgstr "ldap_group_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:678 @@ -16400,51 +18919,53 @@ msgid "" "name for every group. This requirement includes non-POSIX groups in the tree " "of nested groups." msgstr "" +"對應群組名稱的 LDAP 屬性。在具有巢狀群組的環境中,此值必須是對每個群組都有唯" +"一名稱的 LDAP 屬性。此要求包括巢狀群組樹中的非 POSIX 群組。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:686 msgid "Default: cn (rfc2307, rfc2307bis and IPA), sAMAccountName (AD)" -msgstr "" +msgstr "預設:cn(rfc2307、rfc2307bis 與 IPA)、sAMAccountName(AD)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:693 msgid "ldap_group_gid_number (string)" -msgstr "" +msgstr "ldap_group_gid_number (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:696 msgid "The LDAP attribute that corresponds to the group's id." -msgstr "" +msgstr "對應群組 id 的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:706 msgid "ldap_group_member (string)" -msgstr "" +msgstr "ldap_group_member (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:709 msgid "The LDAP attribute that contains the names of the group's members." -msgstr "" +msgstr "包含群組成員名稱的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:713 msgid "Default: memberuid (rfc2307) / member (rfc2307bis)" -msgstr "" +msgstr "預設:memberuid(rfc2307)/ member(rfc2307bis)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:719 msgid "ldap_group_uuid (string)" -msgstr "" +msgstr "ldap_group_uuid (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:722 msgid "The LDAP attribute that contains the UUID/GUID of an LDAP group object." -msgstr "" +msgstr "包含 LDAP 群組物件之 UUID/GUID 的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:733 msgid "ldap_group_objectsid (string)" -msgstr "" +msgstr "ldap_group_objectsid (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:736 @@ -16452,23 +18973,25 @@ msgid "" "The LDAP attribute that contains the objectSID of an LDAP group object. This " "is usually only necessary for ActiveDirectory servers." msgstr "" +"包含 LDAP 群組物件之 objectSID 的 LDAP 屬性。這通常只在 ActiveDirectory 伺服" +"器上需要。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:748 msgid "ldap_group_modify_timestamp (string)" -msgstr "" +msgstr "ldap_group_modify_timestamp (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:761 msgid "ldap_group_type (string)" -msgstr "" +msgstr "ldap_group_type (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:764 msgid "" "The LDAP attribute that contains an integer value indicating the type of the " "group and maybe other flags." -msgstr "" +msgstr "包含指出群組類型及可能其他旗標之整數值的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:769 @@ -16477,543 +19000,545 @@ msgid "" "group is a domain local groups and has to be filtered out for trusted " "domains." msgstr "" +"此屬性目前只由 AD 提供者用來判斷群組是否為網域本機群組,以及是否必須為受信任" +"網域篩除。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:775 msgid "Default: groupType in the AD provider, otherwise not set" -msgstr "" +msgstr "預設:AD 提供者中為 groupType,否則未設定" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:782 msgid "ldap_group_external_member (string)" -msgstr "" +msgstr "ldap_group_external_member (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:785 msgid "" "The LDAP attribute that references group members that are defined in an " "external domain. At the moment, only IPA's external members are supported." -msgstr "" +msgstr "參照在外部網域中定義之群組成員的 LDAP 屬性。目前只支援 IPA 的外部成員。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:791 msgid "Default: ipaExternalMember in the IPA provider, otherwise unset." -msgstr "" +msgstr "預設:IPA 提供者中為 ipaExternalMember,否則未設定。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap-attributes.5.xml:801 msgid "NETGROUP ATTRIBUTES" -msgstr "" +msgstr "NETGROUP 屬性" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:805 msgid "ldap_netgroup_object_class (string)" -msgstr "" +msgstr "ldap_netgroup_object_class (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:808 msgid "The object class of a netgroup entry in LDAP." -msgstr "" +msgstr "LDAP 中網路群組項目的物件類別。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:811 msgid "In IPA provider, ipa_netgroup_object_class should be used instead." -msgstr "" +msgstr "在 IPA 提供者中,應改用 ipa_netgroup_object_class。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:815 msgid "Default: nisNetgroup" -msgstr "" +msgstr "預設:nisNetgroup" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:821 msgid "ldap_netgroup_name (string)" -msgstr "" +msgstr "ldap_netgroup_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:824 msgid "The LDAP attribute that corresponds to the netgroup name." -msgstr "" +msgstr "對應網路群組名稱的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:828 msgid "In IPA provider, ipa_netgroup_name should be used instead." -msgstr "" +msgstr "在 IPA 提供者中,應改用 ipa_netgroup_name。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:838 msgid "ldap_netgroup_member (string)" -msgstr "" +msgstr "ldap_netgroup_member (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:841 msgid "The LDAP attribute that contains the names of the netgroup's members." -msgstr "" +msgstr "包含網路群組成員名稱的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:845 msgid "In IPA provider, ipa_netgroup_member should be used instead." -msgstr "" +msgstr "在 IPA 提供者中,應改用 ipa_netgroup_member。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:849 msgid "Default: memberNisNetgroup" -msgstr "" +msgstr "預設:memberNisNetgroup" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:855 msgid "ldap_netgroup_triple (string)" -msgstr "" +msgstr "ldap_netgroup_triple (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:858 msgid "The LDAP attribute that contains the (host, user, domain) netgroup triples." -msgstr "" +msgstr "包含 (host, user, domain) netgroup 三元組的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:862 sssd-ldap-attributes.5.xml:878 msgid "This option is not available in IPA provider." -msgstr "" +msgstr "此選項在 IPA 提供者中不可用。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:865 msgid "Default: nisNetgroupTriple" -msgstr "" +msgstr "預設:nisNetgroupTriple" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:871 msgid "ldap_netgroup_modify_timestamp (string)" -msgstr "" +msgstr "ldap_netgroup_modify_timestamp (string)" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap-attributes.5.xml:890 msgid "HOST ATTRIBUTES" -msgstr "" +msgstr "主機屬性" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:894 msgid "ldap_host_object_class (string)" -msgstr "" +msgstr "ldap_host_object_class (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:897 msgid "The object class of a host entry in LDAP." -msgstr "" +msgstr "LDAP 中主機項目的物件類別。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:900 sssd-ldap-attributes.5.xml:997 msgid "Default: ipService" -msgstr "" +msgstr "預設:ipService" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:906 msgid "ldap_host_name (string)" -msgstr "" +msgstr "ldap_host_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:909 sssd-ldap-attributes.5.xml:935 msgid "The LDAP attribute that corresponds to the host's name." -msgstr "" +msgstr "對應主機名稱的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:919 msgid "ldap_host_fqdn (string)" -msgstr "" +msgstr "ldap_host_fqdn (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:922 msgid "" "The LDAP attribute that corresponds to the host's fully-qualified domain " "name." -msgstr "" +msgstr "對應主機完整限定網域名稱的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:926 msgid "Default: fqdn" -msgstr "" +msgstr "預設:fqdn" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:932 msgid "ldap_host_serverhostname (string)" -msgstr "" +msgstr "ldap_host_serverhostname (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:939 msgid "Default: serverHostname" -msgstr "" +msgstr "預設:serverHostname" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:945 msgid "ldap_host_member_of (string)" -msgstr "" +msgstr "ldap_host_member_of (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:948 msgid "The LDAP attribute that lists the host's group memberships." -msgstr "" +msgstr "列出主機群組成員資格的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:958 msgid "ldap_host_ssh_public_key (string)" -msgstr "" +msgstr "ldap_host_ssh_public_key (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:961 msgid "The LDAP attribute that contains the host's SSH public keys." -msgstr "" +msgstr "包含主機 SSH 公開金鑰的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:971 msgid "ldap_host_uuid (string)" -msgstr "" +msgstr "ldap_host_uuid (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:974 msgid "The LDAP attribute that contains the UUID/GUID of an LDAP host object." -msgstr "" +msgstr "包含 LDAP 主機物件之 UUID/GUID 的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap-attributes.5.xml:987 msgid "SERVICE ATTRIBUTES" -msgstr "" +msgstr "服務屬性" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:991 msgid "ldap_service_object_class (string)" -msgstr "" +msgstr "ldap_service_object_class (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:994 msgid "The object class of a service entry in LDAP." -msgstr "" +msgstr "LDAP 中服務項目的物件類別。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1003 msgid "ldap_service_name (string)" -msgstr "" +msgstr "ldap_service_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1006 msgid "" "The LDAP attribute that contains the name of service attributes and their " "aliases." -msgstr "" +msgstr "包含服務屬性名稱及其別名的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1016 msgid "ldap_service_port (string)" -msgstr "" +msgstr "ldap_service_port (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1019 msgid "The LDAP attribute that contains the port managed by this service." -msgstr "" +msgstr "包含此服務管理之連接埠的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1023 msgid "Default: ipServicePort" -msgstr "" +msgstr "預設:ipServicePort" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1029 msgid "ldap_service_proto (string)" -msgstr "" +msgstr "ldap_service_proto (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1032 msgid "The LDAP attribute that contains the protocols understood by this service." -msgstr "" +msgstr "包含此服務可理解的協定的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1036 msgid "Default: ipServiceProtocol" -msgstr "" +msgstr "預設:ipServiceProtocol" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap-attributes.5.xml:1045 msgid "SUDO ATTRIBUTES" -msgstr "" +msgstr "SUDO 屬性" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1049 msgid "ldap_sudorule_object_class (string)" -msgstr "" +msgstr "ldap_sudorule_object_class (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1052 msgid "The object class of a sudo rule entry in LDAP." -msgstr "" +msgstr "LDAP 中 sudo 規則項目的物件類別。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1055 msgid "Default: sudoRole" -msgstr "" +msgstr "預設:sudoRole" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1061 msgid "ldap_sudorule_name (string)" -msgstr "" +msgstr "ldap_sudorule_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1064 msgid "The LDAP attribute that corresponds to the sudo rule name." -msgstr "" +msgstr "對應 sudo 規則名稱的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1074 msgid "ldap_sudorule_command (string)" -msgstr "" +msgstr "ldap_sudorule_command (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1077 msgid "The LDAP attribute that corresponds to the command name." -msgstr "" +msgstr "對應指令名稱的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1081 msgid "Default: sudoCommand" -msgstr "" +msgstr "預設:sudoCommand" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1087 msgid "ldap_sudorule_host (string)" -msgstr "" +msgstr "ldap_sudorule_host (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1090 msgid "" "The LDAP attribute that corresponds to the host name (or host IP address, " "host IP network, or host netgroup)" -msgstr "" +msgstr "對應主機名稱(或主機 IP 位址、主機 IP 網路或主機 netgroup)的 LDAP 屬性" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1095 msgid "Default: sudoHost" -msgstr "" +msgstr "預設:sudoHost" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1101 msgid "ldap_sudorule_user (string)" -msgstr "" +msgstr "ldap_sudorule_user (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1104 msgid "" "The LDAP attribute that corresponds to the user name (or UID, group name or " "user's netgroup)" -msgstr "" +msgstr "對應使用者名稱(或 UID、群組名稱或使用者的 netgroup)的 LDAP 屬性" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1108 msgid "Default: sudoUser" -msgstr "" +msgstr "預設:sudoUser" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1114 msgid "ldap_sudorule_option (string)" -msgstr "" +msgstr "ldap_sudorule_option (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1117 msgid "The LDAP attribute that corresponds to the sudo options." -msgstr "" +msgstr "對應 sudo 選項的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1121 msgid "Default: sudoOption" -msgstr "" +msgstr "預設:sudoOption" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1127 msgid "ldap_sudorule_runasuser (string)" -msgstr "" +msgstr "ldap_sudorule_runasuser (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1130 msgid "" "The LDAP attribute that corresponds to the user name that commands may be " "run as." -msgstr "" +msgstr "對應指令可以以其執行之使用者名稱的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1134 msgid "Default: sudoRunAsUser" -msgstr "" +msgstr "預設:sudoRunAsUser" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1140 msgid "ldap_sudorule_runasgroup (string)" -msgstr "" +msgstr "ldap_sudorule_runasgroup (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1143 msgid "" "The LDAP attribute that corresponds to the group name or group GID that " "commands may be run as." -msgstr "" +msgstr "對應指令可以以其執行之群組名稱或群組 GID 的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1147 msgid "Default: sudoRunAsGroup" -msgstr "" +msgstr "預設:sudoRunAsGroup" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1153 msgid "ldap_sudorule_notbefore (string)" -msgstr "" +msgstr "ldap_sudorule_notbefore (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1156 msgid "" "The LDAP attribute that corresponds to the start date/time for when the sudo " "rule is valid." -msgstr "" +msgstr "對應 sudo 規則開始有效之日期/時間的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1160 msgid "Default: sudoNotBefore" -msgstr "" +msgstr "預設:sudoNotBefore" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1166 msgid "ldap_sudorule_notafter (string)" -msgstr "" +msgstr "ldap_sudorule_notafter (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1169 msgid "" "The LDAP attribute that corresponds to the expiration date/time, after which " "the sudo rule will no longer be valid." -msgstr "" +msgstr "對應到期日期/時間(之後 sudo 規則不再有效)的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1174 msgid "Default: sudoNotAfter" -msgstr "" +msgstr "預設:sudoNotAfter" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1180 msgid "ldap_sudorule_order (string)" -msgstr "" +msgstr "ldap_sudorule_order (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1183 msgid "The LDAP attribute that corresponds to the ordering index of the rule." -msgstr "" +msgstr "對應規則排序索引的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1187 msgid "Default: sudoOrder" -msgstr "" +msgstr "預設:sudoOrder" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap-attributes.5.xml:1196 msgid "AUTOFS ATTRIBUTES" -msgstr "" +msgstr "AUTOFS 屬性" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap-attributes.5.xml:1203 msgid "IP HOST ATTRIBUTES" -msgstr "" +msgstr "IP HOST 屬性" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1207 msgid "ldap_iphost_object_class (string)" -msgstr "" +msgstr "ldap_iphost_object_class (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1210 msgid "The object class of an iphost entry in LDAP." -msgstr "" +msgstr "LDAP 中 iphost 項目的物件類別。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1213 msgid "Default: ipHost" -msgstr "" +msgstr "預設:ipHost" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1219 msgid "ldap_iphost_name (string)" -msgstr "" +msgstr "ldap_iphost_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1222 msgid "" "The LDAP attribute that contains the name of the IP host attributes and " "their aliases." -msgstr "" +msgstr "包含 IP 主機屬性名稱及其別名的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1232 msgid "ldap_iphost_number (string)" -msgstr "" +msgstr "ldap_iphost_number (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1235 msgid "The LDAP attribute that contains the IP host address." -msgstr "" +msgstr "包含 IP 主機位址的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1239 msgid "Default: ipHostNumber" -msgstr "" +msgstr "預設:ipHostNumber" #. type: Content of: <reference><refentry><refsect1><title> #: sssd-ldap-attributes.5.xml:1248 msgid "IP NETWORK ATTRIBUTES" -msgstr "" +msgstr "IP 網路屬性" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1252 msgid "ldap_ipnetwork_object_class (string)" -msgstr "" +msgstr "ldap_ipnetwork_object_class (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1255 msgid "The object class of an ipnetwork entry in LDAP." -msgstr "" +msgstr "LDAP 中 ipnetwork 項目的物件類別。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1258 msgid "Default: ipNetwork" -msgstr "" +msgstr "預設:ipNetwork" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1264 msgid "ldap_ipnetwork_name (string)" -msgstr "" +msgstr "ldap_ipnetwork_name (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1267 msgid "" "The LDAP attribute that contains the name of the IP network attributes and " "their aliases." -msgstr "" +msgstr "包含 IP 網路屬性名稱及其別名的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term> #: sssd-ldap-attributes.5.xml:1277 msgid "ldap_ipnetwork_number (string)" -msgstr "" +msgstr "ldap_ipnetwork_number (string)" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1280 msgid "The LDAP attribute that contains the IP network address." -msgstr "" +msgstr "包含 IP 網路位址的 LDAP 屬性。" #. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para> #: sssd-ldap-attributes.5.xml:1284 msgid "Default: ipNetworkNumber" -msgstr "" +msgstr "預設:ipNetworkNumber" #. type: Content of: <reference><refentry><refnamediv><refname> #: sssd_krb5_localauth_plugin.8.xml:10 sssd_krb5_localauth_plugin.8.xml:15 msgid "sssd_krb5_localauth_plugin" -msgstr "" +msgstr "sssd_krb5_localauth_plugin" #. type: Content of: <reference><refentry><refnamediv><refpurpose> #: sssd_krb5_localauth_plugin.8.xml:16 msgid "Kerberos local authorization plugin" -msgstr "" +msgstr "Kerberos 本機授權外掛程式" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_localauth_plugin.8.xml:22 @@ -17023,6 +19548,9 @@ msgid "" "find the local name for a given Kerberos principal or to check if a given " "local name and a given Kerberos principal relate to each other." msgstr "" +"libkrb5 使用 Kerberos 本機授權外掛程式 <command>sssd_krb5_localauth_plugin</" +"command> 來尋找指定 Kerberos principal 的本機名稱,或檢查指定的本機名稱與指定" +"的 Kerberos principal 是否彼此相關。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_localauth_plugin.8.xml:29 @@ -17032,6 +19560,9 @@ msgid "" "information SSSD can easily handle the mappings mentioned above even if the " "local name and the Kerberos principal differ considerably." msgstr "" +"SSSD 處理來自遠端來源之使用者的本機名稱,也可以從遠端來源讀取 Kerberos 使用" +"者 principal 名稱。有了這些資訊,即使本機名稱與 Kerberos principal 差異很大," +"SSSD 也能輕鬆處理上述對應。" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_localauth_plugin.8.xml:36 @@ -17043,11 +19574,15 @@ msgid "" "principal to get the local name which would lead to wrong mappings in this " "case." msgstr "" +"此外,借助從遠端來源讀取的資訊,SSSD 可以協助防止在 Kerberos principal 的使用" +"者部分意外對應到不同使用者本機名稱時,產生非預期或不想要的對應。依預設," +"libkrb5 可能只是剝除 Kerberos principal 的 realm 部分來取得本機名稱,這種情況" +"下會導致錯誤的對應。" #. type: Content of: <reference><refentry><refsect1><title> #: sssd_krb5_localauth_plugin.8.xml:46 msgid "CONFIGURATION" -msgstr "" +msgstr "設定" #. type: Content of: <reference><refentry><refsect1><para><programlisting> #: sssd_krb5_localauth_plugin.8.xml:56 @@ -17058,6 +19593,10 @@ msgid "" " module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" " }\n" msgstr "" +"[plugins]\n" +" localauth = {\n" +" module = sssd:/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so\n" +" }\n" #. type: Content of: <reference><refentry><refsect1><para> #: sssd_krb5_localauth_plugin.8.xml:48 @@ -17071,89 +19610,94 @@ msgid "" "included in the local Kerberos configuration the plugin will be enabled " "automatically." msgstr "" +"必須在 Kerberos 設定中明確啟用 Kerberos 本機授權外掛程式,請參閱 " +"<citerefentry> <refentrytitle>krb5.conf</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>。SSSD 會自動在 SSSD 的公開 Kerberos 設定片段目錄中" +"建立內容例如 <placeholder type=\"programlisting\" id=\"0\"/> 的設定片段。若本" +"機 Kerberos 設定包含此目錄,外掛程式會自動啟用。" #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:3 msgid "ldap_autofs_map_object_class (string)" -msgstr "" +msgstr "ldap_autofs_map_object_class (string)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:6 msgid "The object class of an automount map entry in LDAP." -msgstr "" +msgstr "LDAP 中 automount 對應項目的物件類別。" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:9 msgid "Default: nisMap (rfc2307, autofs_provider=ad), otherwise automountMap" -msgstr "" +msgstr "預設:nisMap(rfc2307、autofs_provider=ad),否則為 automountMap" #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:16 msgid "ldap_autofs_map_name (string)" -msgstr "" +msgstr "ldap_autofs_map_name (string)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:19 msgid "The name of an automount map entry in LDAP." -msgstr "" +msgstr "LDAP 中 automount 對應項目的名稱。" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:22 msgid "" "Default: nisMapName (rfc2307, autofs_provider=ad), otherwise " "automountMapName" -msgstr "" +msgstr "預設:nisMapName(rfc2307、autofs_provider=ad),否則為 automountMapName" #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:29 msgid "ldap_autofs_entry_object_class (string)" -msgstr "" +msgstr "ldap_autofs_entry_object_class (string)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:32 msgid "" "The object class of an automount entry in LDAP. The entry usually " "corresponds to a mount point." -msgstr "" +msgstr "LDAP 中 automount 項目的物件類別。該項目通常對應掛載點。" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:37 msgid "Default: nisObject (rfc2307, autofs_provider=ad), otherwise automount" -msgstr "" +msgstr "預設:nisObject(rfc2307、autofs_provider=ad),否則為 automount" #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:44 msgid "ldap_autofs_entry_key (string)" -msgstr "" +msgstr "ldap_autofs_entry_key (string)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:47 include/autofs_attributes.xml:61 msgid "" "The key of an automount entry in LDAP. The entry usually corresponds to a " "mount point." -msgstr "" +msgstr "LDAP 中 automount 項目的索引鍵。該項目通常對應掛載點。" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:51 msgid "Default: cn (rfc2307, autofs_provider=ad), otherwise automountKey" -msgstr "" +msgstr "預設:cn(rfc2307、autofs_provider=ad),否則為 automountKey" #. type: Content of: <variablelist><varlistentry><term> #: include/autofs_attributes.xml:58 msgid "ldap_autofs_entry_value (string)" -msgstr "" +msgstr "ldap_autofs_entry_value (string)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/autofs_attributes.xml:65 msgid "" "Default: nisMapEntry (rfc2307, autofs_provider=ad), otherwise " "automountInformation" -msgstr "" +msgstr "預設:nisMapEntry(rfc2307、autofs_provider=ad),否則為 automountInformation" #. type: Content of: <refsect1><title> #: include/service_discovery.xml:2 msgid "SERVICE DISCOVERY" -msgstr "" +msgstr "服務探索" #. type: Content of: <refsect1><para> #: include/service_discovery.xml:4 @@ -17162,11 +19706,13 @@ msgid "" "appropriate servers to connect to using a special DNS query. This feature is " "not supported for backup servers." msgstr "" +"服務探索功能允許後端使用特殊的 DNS 查詢自動尋找要連線的適當伺服器。此功能不支" +"援備份伺服器。" #. type: Content of: <refsect1><refsect2><title> #: include/service_discovery.xml:9 include/ldap_id_mapping.xml:99 msgid "Configuration" -msgstr "" +msgstr "設定" #. type: Content of: <refsect1><refsect2><para> #: include/service_discovery.xml:11 @@ -17179,11 +19725,15 @@ msgid "" "prefers to use service discovery whenever possible, and fall back to a " "specific server when no servers can be discovered using DNS." msgstr "" +"若未指定伺服器,後端會自動使用服務探索嘗試尋找伺服器。使用者也可以選擇在伺服" +"器清單中插入特殊關鍵字 <quote>_srv_</quote>,同時使用固定的伺服器位址與服務探" +"索。偏好順序會維持。例如,若使用者偏好盡可能使用服務探索,並在無法使用 DNS 探" +"索到任何伺服器時回到特定伺服器,此功能就很有用。" #. type: Content of: <refsect1><refsect2><title> #: include/service_discovery.xml:23 msgid "The domain name" -msgstr "" +msgstr "網域名稱" #. type: Content of: <refsect1><refsect2><para> #: include/service_discovery.xml:25 @@ -17192,28 +19742,31 @@ msgid "" "<citerefentry> <refentrytitle>sssd.conf</refentrytitle> " "<manvolnum>5</manvolnum> </citerefentry> manual page for more details." msgstr "" +"更多詳細資料請參閱 <citerefentry> <refentrytitle>sssd.conf</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry> 手冊頁中的 <quote>" +"dns_discovery_domain</quote> 參數。" #. type: Content of: <refsect1><refsect2><title> #: include/service_discovery.xml:35 msgid "The protocol" -msgstr "" +msgstr "協定" #. type: Content of: <refsect1><refsect2><para> #: include/service_discovery.xml:37 msgid "" "The queries usually specify _tcp as the protocol. Exceptions are documented " "in respective option description." -msgstr "" +msgstr "查詢通常指定 _tcp 作為協定。例外情況在各自的選項說明中有記載。" #. type: Content of: <refsect1><refsect2><title> #: include/service_discovery.xml:42 msgid "See Also" -msgstr "" +msgstr "另請參閱" #. type: Content of: <refsect1><refsect2><para> #: include/service_discovery.xml:44 msgid "For more information on the service discovery mechanism, refer to RFC 2782." -msgstr "" +msgstr "服務探索機制的更多資訊請參閱 RFC 2782。" #. type: Content of: <refentryinfo> #: include/upstream.xml:2 @@ -17221,28 +19774,30 @@ msgid "" "<productname>SSSD</productname> <orgname>The SSSD upstream - " "https://github.com/SSSD/sssd/</orgname>" msgstr "" +"<productname>SSSD</productname> <orgname>The SSSD upstream - https://" +"github.com/SSSD/sssd/</orgname>" #. type: Content of: outside any tag (error?) #: include/upstream.xml:1 msgid "<placeholder type=\"refentryinfo\" id=\"0\"/>" -msgstr "" +msgstr "<placeholder type=\"refentryinfo\" id=\"0\"/>" #. type: Content of: <refsect1><title> #: include/failover.xml:2 msgid "FAILOVER" -msgstr "" +msgstr "故障轉移" #. type: Content of: <refsect1><para> #: include/failover.xml:4 msgid "" "The failover feature allows back ends to automatically switch to a different " "server if the current server fails." -msgstr "" +msgstr "故障轉移功能允許後端在目前伺服器失敗時自動切換到不同的伺服器。" #. type: Content of: <refsect1><refsect2><title> #: include/failover.xml:8 msgid "Failover Syntax" -msgstr "" +msgstr "故障轉移語法" #. type: Content of: <refsect1><refsect2><para> #: include/failover.xml:10 @@ -17251,6 +19806,8 @@ msgid "" "is allowed around the comma. The servers are listed in order of " "preference. The list can contain any number of servers." msgstr "" +"伺服器清單以逗號分隔清單給出;逗號周圍允許任意數量的空格。伺服器依偏好順序列" +"出。清單可以包含任意數量的伺服器。" #. type: Content of: <refsect1><refsect2><para> #: include/failover.xml:16 @@ -17263,11 +19820,16 @@ msgid "" "periodically try to reconnect to one of the primary servers. If it succeeds, " "it will replace the current active (backup) server." msgstr "" +"每個啟用故障轉移的設定選項都有兩個變體:<emphasis>primary</emphasis> 與 " +"<emphasis>backup</emphasis>。概念是主要清單中的伺服器優先,只有無法連到任何主" +"要伺服器時才會搜尋備份伺服器。若選取備份伺服器,會設定 31 秒的逾時。此逾時之" +"後,SSSD 會定期嘗試重新連線到其中一個主要伺服器。若成功,它會取代目前作用中(" +"備份)的伺服器。" #. type: Content of: <refsect1><refsect2><title> #: include/failover.xml:27 msgid "The Failover Mechanism" -msgstr "" +msgstr "故障轉移機制" #. type: Content of: <refsect1><refsect2><para> #: include/failover.xml:29 @@ -17282,6 +19844,11 @@ msgid "" "switches over to the next service. The machine is still considered online " "and might still be tried for another service." msgstr "" +"故障轉移機制區分機器與服務。後端先嘗試解析指定機器的主機名稱;若此解析嘗試失" +"敗,該機器會被視為離線。不會再嘗試為任何其他服務連線到這台機器。若解析嘗試成" +"功,後端會嘗試連線到這台機器上的服務。若服務連線嘗試失敗,只會將這個特定服務" +"視為離線,後端會自動切換到下一個服務。該機器仍被視為線上,可能仍會為另一個服" +"務嘗試。" #. type: Content of: <refsect1><refsect2><para> #: include/failover.xml:42 @@ -17290,6 +19857,8 @@ msgid "" "offline after a specified period of time; this is currently hard coded to 30 " "seconds." msgstr "" +"經過指定的一段時間後,會再次嘗試連線標記為離線的機器或服務;目前這是硬編碼的 " +"30 秒。" #. type: Content of: <refsect1><refsect2><para> #: include/failover.xml:47 @@ -17297,11 +19866,13 @@ msgid "" "If there are no more machines to try, the back end as a whole switches to " "offline mode, and then attempts to reconnect every 30 seconds." msgstr "" +"若沒有更多可以嘗試的機器,整個後端會切換到離線模式,然後每 30 秒嘗試重新連線" +"。" #. type: Content of: <refsect1><refsect2><title> #: include/failover.xml:53 msgid "Failover time outs and tuning" -msgstr "" +msgstr "故障轉移逾時與調整" #. type: Content of: <refsect1><refsect2><para> #: include/failover.xml:55 @@ -17316,11 +19887,16 @@ msgid "" "timing out before a live server is contacted, you can consider changing the " "time outs." msgstr "" +"解析要連線的伺服器可以簡單到只執行單一 DNS 查詢,也可能涉及多個步驟,例如尋找" +"正確的站台,或在某些設定的伺服器無法連到時嘗試多個主機名稱。較複雜的情境可能" +"需要一些時間,SSSD 需要在提供足夠時間完成解析程序,與在進入離線模式前不要嘗試" +"太久之間取得平衡。若 SSSD 除錯記錄顯示伺服器解析在連到實際伺服器之前就逾時," +"您可以考慮變更逾時。" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><term> #: include/failover.xml:76 msgid "dns_resolver_server_timeout" -msgstr "" +msgstr "dns_resolver_server_timeout" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: include/failover.xml:80 @@ -17328,11 +19904,13 @@ msgid "" "Time in milliseconds that sets how long would SSSD talk to a single DNS " "server before trying next one." msgstr "" +"設定 SSSD 在嘗試下一個 DNS 伺服器之前與單一 DNS 伺服器通話多久的時間(毫秒)" +"。" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><term> #: include/failover.xml:90 msgid "dns_resolver_op_timeout" -msgstr "" +msgstr "dns_resolver_op_timeout" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: include/failover.xml:94 @@ -17341,11 +19919,13 @@ msgid "" "(e.g. resolution of a hostname or an SRV record) before trying the next " "hostname or discovery domain." msgstr "" +"告訴 SSSD 在嘗試下一個主機名稱或探索網域之前,會嘗試解析單一 DNS 查詢(例如主" +"機名稱或 SRV 記錄的解析)多久的時間(秒)。" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><term> #: include/failover.xml:106 msgid "dns_resolver_timeout" -msgstr "" +msgstr "dns_resolver_timeout" #. type: Content of: <refsect1><refsect2><para><variablelist><varlistentry><listitem><para> #: include/failover.xml:110 @@ -17354,6 +19934,8 @@ msgid "" "resolution internally might include several steps, such as resolving DNS SRV " "queries or locating the site." msgstr "" +"SSSD 會嘗試解析故障轉移服務多久。此服務解析內部可能包括幾個步驟,例如解析 " +"DNS SRV 查詢或找出站台位置。" #. type: Content of: <refsect1><refsect2><para> #: include/failover.xml:67 @@ -17363,6 +19945,9 @@ msgid "" "<refentrytitle>sssd.conf</refentrytitle><manvolnum>5</manvolnum> " "</citerefentry>, manual page. <placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +"本節列出可用的可調整參數。請參閱 <citerefentry> <refentrytitle>sssd.conf</" +"refentrytitle><manvolnum>5</manvolnum> </citerefentry> 手冊頁中它們的說明" +"。<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <refsect1><refsect2><para> #: include/failover.xml:123 @@ -17374,11 +19959,16 @@ msgid "" "value than <quote>dns_resolver_op_timeout</quote> which should be larger " "than <quote>dns_resolver_server_timeout</quote>." msgstr "" +"對以 LDAP 為基礎的提供者,解析操作是 LDAP 連線操作的一部分。因此,<quote>" +"ldap_opt_timeout</quote> 逾時也應設定為比 <quote>dns_resolver_timeout</" +"quote> 更大的值,而 <quote>dns_resolver_timeout</quote> 又應設定為比 <quote>" +"dns_resolver_op_timeout</quote> 更大的值,<quote>dns_resolver_op_timeout</" +"quote> 應大於 <quote>dns_resolver_server_timeout</quote>。" #. type: Content of: <refsect1><title> #: include/ldap_id_mapping.xml:2 msgid "ID MAPPING" -msgstr "" +msgstr "ID 對應" #. type: Content of: <refsect1><para> #: include/ldap_id_mapping.xml:4 @@ -17387,6 +19977,8 @@ msgid "" "without requiring administrators to extend user attributes to support POSIX " "attributes for user and group identifiers." msgstr "" +"ID 對應功能允許 SSSD 作為 Active Directory 的用戶端,不需要管理員擴充使用者屬" +"性以支援使用者與群組識別碼的 POSIX 屬性。" #. type: Content of: <refsect1><para> #: include/ldap_id_mapping.xml:9 @@ -17396,6 +19988,9 @@ msgid "" "automatically-assigned and manually-assigned values. If you need to use " "manually-assigned values, ALL values must be manually-assigned." msgstr "" +"注意:啟用 ID 對應時,會忽略 uidNumber 與 gidNumber 屬性。這是為了避免自動指" +"派與手動指派的值之間發生衝突的可能性。若您需要使用手動指派的值,所有值都必須" +"手動指派。" #. type: Content of: <refsect1><para> #: include/ldap_id_mapping.xml:16 @@ -17410,26 +20005,31 @@ msgid "" "<refentrytitle>sss_cache</refentrytitle> <manvolnum>8</manvolnum> " "</citerefentry> to remove the database, rather the process consists of:" msgstr "" +"請注意,變更與 ID 對應相關的設定選項會導致使用者與群組 ID 變更。目前 SSSD 不" +"支援變更 ID,因此必須移除 SSSD 資料庫。由於快取的密碼也儲存在資料庫中,只應在" +"驗證伺服器可連到時執行移除資料庫,否則使用者可能會被鎖定。要快取密碼,必須執" +"行驗證。使用 <citerefentry> <refentrytitle>sss_cache</refentrytitle> " +"<manvolnum>8</manvolnum> </citerefentry> 移除資料庫是不夠的,程序包括:" #. type: Content of: <refsect1><para><itemizedlist><listitem><para> #: include/ldap_id_mapping.xml:33 msgid "Making sure the remote servers are reachable" -msgstr "" +msgstr "確保遠端伺服器可連到" #. type: Content of: <refsect1><para><itemizedlist><listitem><para> #: include/ldap_id_mapping.xml:38 msgid "Stopping the SSSD service" -msgstr "" +msgstr "停止 SSSD 服務" #. type: Content of: <refsect1><para><itemizedlist><listitem><para> #: include/ldap_id_mapping.xml:43 msgid "Removing the database" -msgstr "" +msgstr "移除資料庫" #. type: Content of: <refsect1><para><itemizedlist><listitem><para> #: include/ldap_id_mapping.xml:48 msgid "Starting the SSSD service" -msgstr "" +msgstr "啟動 SSSD 服務" #. type: Content of: <refsect1><para> #: include/ldap_id_mapping.xml:52 @@ -17438,11 +20038,13 @@ msgid "" "system properties such as file and directory ownership, it's advisable to " "plan ahead and test the ID mapping configuration thoroughly." msgstr "" +"此外,由於 ID 的變更可能需要調整其他系統屬性(例如檔案與目錄的擁有權),建議" +"事先規劃並徹底測試 ID 對應設定。" #. type: Content of: <refsect1><refsect2><title> #: include/ldap_id_mapping.xml:59 msgid "Mapping Algorithm" -msgstr "" +msgstr "對應演算法" #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:61 @@ -17452,6 +20054,9 @@ msgid "" "represent the Active Directory domain identity and the relative identifier " "(RID) of the user or group object." msgstr "" +"Active Directory 為目錄中的每個使用者與群組物件提供 objectSID。此 objectSID " +"可以分解為代表 Active Directory 網域身分與使用者或群組物件相對識別碼 (RID) 的" +"元件。" #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:67 @@ -17460,6 +20065,8 @@ msgid "" "into equally-sized component sections - called \"slices\"-. Each slice " "represents the space available to an Active Directory domain." msgstr "" +"SSSD ID 對應演算法取一個可用的 UID 範圍,並將它分成大小相等的組成區段,稱為「" +"slices」。每個 slice 代表可供 Active Directory 網域使用的空間。" #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:73 @@ -17469,6 +20076,8 @@ msgid "" "domain. In order to make this slice-assignment repeatable on different " "client machines, we select the slice based on the following algorithm:" msgstr "" +"當第一次遇到特定網域的使用者或群組項目時,SSSD 會為該網域配置一個可用的 slice" +"。為了讓此 slice 指派在不同用戶端機器上可重現,我們根據下列演算法選取 slice:" #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:80 @@ -17477,6 +20086,8 @@ msgid "" "a 32-bit hashed value. We then take the modulus of this value with the total " "number of available slices to pick the slice." msgstr "" +"SID 字串會通過 murmurhash3 演算法轉換為 32 位元的雜湊值。然後我們對這個值取可" +"用 slice 總數的模數來選取 slice。" #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:86 @@ -17490,11 +20101,16 @@ msgid "" "configure a default domain to guarantee that at least one is always " "consistent. See <quote>Configuration</quote> for details." msgstr "" +"注意:在雜湊與後續模數中可能會遇到衝突。在這些情況下,我們會選取下一個可用的 " +"slice,但可能無法在其他機器上重現完全相同的 slice 集合(因為它們被遇到的順序" +"會決定它們的 slice)。這種情況下,建議改用 Active Directory 中的明確 POSIX 屬" +"性(停用 ID 對應),或設定預設網域以保證至少一個永遠一致。詳細資料請參閱 " +"<quote>Configuration</quote>。" #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:101 msgid "Minimum configuration (in the <quote>[domain/DOMAINNAME]</quote> section):" -msgstr "" +msgstr "最低設定(在 <quote>[domain/DOMAINNAME]</quote> 區段中):" #. type: Content of: <refsect1><refsect2><para><programlisting> #: include/ldap_id_mapping.xml:106 @@ -17503,6 +20119,8 @@ msgid "" "ldap_id_mapping = True\n" "ldap_schema = ad\n" msgstr "" +"ldap_id_mapping = True\n" +"ldap_schema = ad\n" #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:111 @@ -17511,16 +20129,18 @@ msgid "" "of holding up to 200,000 IDs, starting from 200,000 and going up to " "2,000,200,000. This should be sufficient for most deployments." msgstr "" +"預設設定會設定 10,000 個 slice,每個最多容納 200,000 個 ID,從 200,000 開始一" +"直到 2,000,200,000。這對大多數部署應該足夠。" #. type: Content of: <refsect1><refsect2><refsect3><title> #: include/ldap_id_mapping.xml:117 msgid "Advanced Configuration" -msgstr "" +msgstr "進階設定" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:120 msgid "ldap_idmap_range_min (integer)" -msgstr "" +msgstr "ldap_idmap_range_min (integer)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:123 @@ -17529,6 +20149,8 @@ msgid "" "mapping Active Directory user and group SIDs. It is the first POSIX ID which " "can be used for the mapping." msgstr "" +"指定用於對應 Active Directory 使用者與群組 SID 之 POSIX ID 範圍的下限(含)。" +"它是第一個可用於對應的 POSIX ID。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:129 @@ -17540,16 +20162,19 @@ msgid "" "<quote>min_id</quote> be less-than or equal to " "<quote>ldap_idmap_range_min</quote>" msgstr "" +"注意:此選項與 <quote>min_id</quote> 不同,<quote>min_id</quote> 用於篩選對此" +"網域要求的輸出,而此選項控制 ID 指派的範圍。這是很細微的區別,但一般好的建議" +"是讓 <quote>min_id</quote> 小於或等於 <quote>ldap_idmap_range_min</quote>" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:139 include/ldap_id_mapping.xml:197 msgid "Default: 200000" -msgstr "" +msgstr "預設:200000" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:144 msgid "ldap_idmap_range_max (integer)" -msgstr "" +msgstr "ldap_idmap_range_max (integer)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:147 @@ -17559,6 +20184,9 @@ msgid "" "cannot be used for the mapping anymore, i.e. one larger than the last one " "which can be used for the mapping." msgstr "" +"指定用於對應 Active Directory 使用者與群組 SID 之 POSIX ID 範圍的上限(不含)" +"。它是第一個不能再用作對應的 POSIX ID,也就是比最後一個可用於對應的 ID 大一個" +"。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:155 @@ -17570,16 +20198,19 @@ msgid "" "<quote>max_id</quote> be greater-than or equal to " "<quote>ldap_idmap_range_max</quote>" msgstr "" +"注意:此選項與 <quote>max_id</quote> 不同,<quote>max_id</quote> 用於篩選對此" +"網域要求的輸出,而此選項控制 ID 指派的範圍。這是很細微的區別,但一般好的建議" +"是讓 <quote>max_id</quote> 大於或等於 <quote>ldap_idmap_range_max</quote>" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:165 msgid "Default: 2000200000" -msgstr "" +msgstr "預設:2000200000" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:170 msgid "ldap_idmap_range_size (integer)" -msgstr "" +msgstr "ldap_idmap_range_size (integer)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:173 @@ -17588,6 +20219,8 @@ msgid "" "does not divide evenly into the min and max values, it will create as many " "complete slices as it can." msgstr "" +"指定每個 slice 可用的 ID 數目。若範圍大小無法平均除入最小與最大值,它會建立盡" +"可能多的完整 slice。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:179 @@ -17596,6 +20229,8 @@ msgid "" "RID planned for use on the Active Directory server. User lookups and login " "will fail for any user whose RID is greater than this value." msgstr "" +"注意:此選項的值至少必須與 Active Directory 伺服器上計畫使用的最高使用者 RID " +"一樣大。RID 大於此值的任何使用者的查詢與登入都會失敗。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:185 @@ -17605,6 +20240,10 @@ msgid "" "<quote>ldap_idmap_range_size</quote> must be at least 1108 as range size is " "equal to maximal SID minus minimal SID plus one (e.g. 1108 = 1107 - 0 + 1)." msgstr "" +"例如,若您最近新增的 Active Directory 使用者具有 objectSid=S-1-5-21-" +"2153326666-2176343378-3404031434-1107,<quote>ldap_idmap_range_size</quote> " +"至少必須為 1108,因為範圍大小等於最大 SID 減最小 SID 再加一(例如 1108 = " +"1107 - 0 + 1)。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:192 @@ -17613,11 +20252,13 @@ msgid "" "will result in changing all of the ID mappings on the system, leading to " "users with different local IDs than they previously had." msgstr "" +"事先規劃未來的擴充很重要,因為變更此值會導致系統上所有的 ID 對應變更,使使用" +"者擁有與之前不同的本機 ID。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:202 msgid "ldap_idmap_default_domain_sid (string)" -msgstr "" +msgstr "ldap_idmap_default_domain_sid (string)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:205 @@ -17626,21 +20267,23 @@ msgid "" "domain will always be assigned to slice zero in the ID map, bypassing the " "murmurhash algorithm described above." msgstr "" +"指定預設網域的網域 SID。這會保證此網域永遠被指派到 ID 對應中的第零個 slice," +"略過上述 murmurhash 演算法。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:216 msgid "ldap_idmap_default_domain (string)" -msgstr "" +msgstr "ldap_idmap_default_domain (string)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:219 msgid "Specify the name of the default domain." -msgstr "" +msgstr "指定預設網域的名稱。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:227 msgid "ldap_idmap_autorid_compat (boolean)" -msgstr "" +msgstr "ldap_idmap_autorid_compat (boolean)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:230 @@ -17648,13 +20291,15 @@ msgid "" "Changes the behavior of the ID-mapping algorithm to behave more similarly to " "winbind's <quote>idmap_autorid</quote> algorithm." msgstr "" +"變更 ID 對應演算法的行為,使其更像 winbind 的 <quote>idmap_autorid</quote> 演" +"算法。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:235 msgid "" "When this option is configured, domains will be allocated starting with " "slice zero and increasing monotonically with each additional domain." -msgstr "" +msgstr "設定此選項時,網域會從第零個 slice 開始配置,並隨每個額外的網域單調遞增。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:240 @@ -17665,18 +20310,22 @@ msgid "" "<quote>ldap_idmap_default_domain_sid</quote> option to guarantee that at " "least one domain is consistently allocated to slice zero." msgstr "" +"注意:此演算法是非確定性的(它取決於使用者與群組被要求的順序)。若為了與執行 " +"winbind 的機器相容而需要此模式,建議同時使用 <quote>" +"ldap_idmap_default_domain_sid</quote> 選項,保證至少有一個網域一致地配置到第" +"零個 slice。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term> #: include/ldap_id_mapping.xml:255 msgid "ldap_idmap_helper_table_size (integer)" -msgstr "" +msgstr "ldap_idmap_helper_table_size (integer)" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:258 msgid "" "Maximal number of secondary slices that is tried when performing mapping " "from UNIX id to SID." -msgstr "" +msgstr "執行從 UNIX id 到 SID 的對應時嘗試的次要 slice 最大數目。" #. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para> #: include/ldap_id_mapping.xml:262 @@ -17686,11 +20335,14 @@ msgid "" "generated so far. If value of ldap_idmap_helper_table_size is equal to 0 " "then no additional secondary slices are generated." msgstr "" +"注意:當 SID 對應到 UNIX id,且 SID 的 RID 部分超出目前已產生之次要 slice 的" +"範圍時,可能會產生額外的次要 slice。若 ldap_idmap_helper_table_size 的值等於 " +"0,則不會產生額外的次要 slice。" #. type: Content of: <refsect1><refsect2><title> #: include/ldap_id_mapping.xml:279 msgid "Well-Known SIDs" -msgstr "" +msgstr "眾所周知的 SID" #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:281 @@ -17700,60 +20352,63 @@ msgid "" "those Well-Known SIDs have no equivalent in a Linux/UNIX environment no " "POSIX IDs are available for those objects." msgstr "" +"SSSD 支援查詢 Well-Known SID(即具有特殊硬編碼意義的 SID)的名稱。由於與這些 " +"Well-Known SID 相關的一般使用者與群組在 Linux/UNIX 環境中沒有對應物,這些物件" +"沒有可用的 POSIX ID。" #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:287 msgid "" "The SID name space is organized in authorities which can be seen as " "different domains. The authorities for the Well-Known SIDs are" -msgstr "" +msgstr "SID 名稱空間以可視為不同網域的權威機構組織。Well-Known SID 的權威機構是" #. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> #: include/ldap_id_mapping.xml:290 msgid "Null Authority" -msgstr "" +msgstr "Null Authority" #. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> #: include/ldap_id_mapping.xml:291 msgid "World Authority" -msgstr "" +msgstr "World Authority" #. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> #: include/ldap_id_mapping.xml:292 msgid "Local Authority" -msgstr "" +msgstr "Local Authority" #. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> #: include/ldap_id_mapping.xml:293 msgid "Creator Authority" -msgstr "" +msgstr "Creator Authority" #. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> #: include/ldap_id_mapping.xml:294 msgid "Mandatory Label Authority" -msgstr "" +msgstr "Mandatory Label Authority" #. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> #: include/ldap_id_mapping.xml:295 msgid "Authentication Authority" -msgstr "" +msgstr "Authentication Authority" #. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> #: include/ldap_id_mapping.xml:296 msgid "NT Authority" -msgstr "" +msgstr "NT Authority" #. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para> #: include/ldap_id_mapping.xml:297 msgid "Built-in" -msgstr "" +msgstr "Built-in" #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:299 msgid "" "The capitalized version of these names are used as domain names when " "returning the fully qualified name of a Well-Known SID." -msgstr "" +msgstr "傳回 Well-Known SID 的完整限定名稱時,這些名稱的大寫版本用作網域名稱。" #. type: Content of: <refsect1><refsect2><para> #: include/ldap_id_mapping.xml:303 @@ -17768,21 +20423,28 @@ msgid "" "AUTHORITY</quote>, <quote>NT AUTHORITY</quote> and <quote>BUILTIN</quote> " "should not be used as domain names in <filename>sssd.conf</filename>." msgstr "" +"由於某些公用程式允許借助名稱修改以 SID 為基礎的存取控制資訊,而不是直接使用 " +"SID,SSSD 也支援依名稱查詢 SID。為避免衝突,只能使用完整限定名稱查詢 Well-" +"Known SID。因此,<quote>NULL AUTHORITY</quote>、<quote>WORLD AUTHORITY</" +"quote>、<quote>LOCAL AUTHORITY</quote>、<quote>CREATOR AUTHORITY</quote>" +"、<quote>MANDATORY LABEL AUTHORITY</quote>、<quote>AUTHENTICATION AUTHORITY</" +"quote>、<quote>NT AUTHORITY</quote> 與 <quote>BUILTIN</quote> 網域名稱不應用" +"作 <filename>sssd.conf</filename> 中的網域名稱。" #. type: Content of: <varlistentry><term> #: include/param_help.xml:3 msgid "<option>-?</option>,<option>--help</option>" -msgstr "" +msgstr "<option>-?</option>,<option>--help</option>" #. type: Content of: <varlistentry><listitem><para> #: include/param_help.xml:7 include/param_help_py.xml:7 msgid "Display help message and exit." -msgstr "" +msgstr "顯示說明訊息並結束。" #. type: Content of: <varlistentry><term> #: include/param_help_py.xml:3 msgid "<option>-h</option>,<option>--help</option>" -msgstr "" +msgstr "<option>-h</option>,<option>--help</option>" #. type: Content of: <listitem><para> #: include/debug_levels.xml:3 include/debug_levels_tools.xml:3 @@ -17793,6 +20455,9 @@ msgid "" "is to specify a hexadecimal bitmask to enable or disable specific levels " "(such as if you wish to suppress a level)." msgstr "" +"SSSD 支援兩種指定除錯層級的方式。最簡單的是指定 0-9 的十進位值,代表啟用該層" +"級與所有較低層級的除錯訊息。更全面的選項是指定十六進位位元遮罩以啟用或停用特" +"定層級(例如若您想要抑制某個層級)。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:10 @@ -17803,6 +20468,10 @@ msgid "" "responder or provider processes. The <quote>debug_level</quote> parameter " "should be added to all sections that you wish to produce debug logs from." msgstr "" +"請注意,每個 SSSD 服務都記錄到自己的記錄檔。也請注意,在 <quote>[sssd]</" +"quote> 區段中啟用 <quote>debug_level</quote> 只會為 sssd 程序本身啟用除錯,不" +"會為 responder 或提供者程序啟用。<quote>debug_level</quote> 參數應加入所有您" +"希望產生除錯記錄的區段。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:18 @@ -17813,11 +20482,15 @@ msgid "" "<citerefentry> <refentrytitle>sss_debuglevel</refentrytitle> " "<manvolnum>8</manvolnum> </citerefentry> tool." msgstr "" +"除了使用 <quote>debug_level</quote> 參數在設定檔中變更記錄層級(這是持久的," +"但需要重新啟動 SSSD)之外,也可以使用 <citerefentry> <refentrytitle>" +"sss_debuglevel</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> 工具" +"即時變更除錯層級。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:29 include/debug_levels_tools.xml:10 msgid "Currently supported debug levels:" -msgstr "" +msgstr "目前支援的除錯層級:" #. type: Content of: <listitem><para> #: include/debug_levels.xml:32 include/debug_levels_tools.xml:13 @@ -17826,6 +20499,8 @@ msgid "" "failures. Anything that would prevent SSSD from starting up or causes it to " "cease running." msgstr "" +"<emphasis>0</emphasis>, <emphasis>0x0010</emphasis>:致命失敗。任何會阻止 " +"SSSD 啟動或導致它停止執行的情況。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:38 include/debug_levels_tools.xml:19 @@ -17834,6 +20509,8 @@ msgid "" "error that doesn't kill SSSD, but one that indicates that at least one major " "feature is not going to work properly." msgstr "" +"<emphasis>1</emphasis>, <emphasis>0x0020</emphasis>:嚴重失敗。不會終止 SSSD" +",但表示至少有一個主要功能無法正常運作的錯誤。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:45 include/debug_levels_tools.xml:26 @@ -17841,6 +20518,8 @@ msgid "" "<emphasis>2</emphasis>, <emphasis>0x0040</emphasis>: Serious failures. An " "error announcing that a particular request or operation has failed." msgstr "" +"<emphasis>2</emphasis>, <emphasis>0x0040</emphasis>:重大失敗。宣佈特定要求或" +"操作已失敗的錯誤。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:50 include/debug_levels_tools.xml:31 @@ -17849,30 +20528,32 @@ msgid "" "are the errors that would percolate down to cause the operation failure of " "2." msgstr "" +"<emphasis>3</emphasis>, <emphasis>0x0080</emphasis>:輕微失敗。這些是會滲透下" +"去導致第 2 層級操作失敗的錯誤。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:55 include/debug_levels_tools.xml:36 msgid "<emphasis>4</emphasis>, <emphasis>0x0100</emphasis>: Configuration settings." -msgstr "" +msgstr "<emphasis>4</emphasis>, <emphasis>0x0100</emphasis>:設定設定。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:59 include/debug_levels_tools.xml:40 msgid "<emphasis>5</emphasis>, <emphasis>0x0200</emphasis>: Function data." -msgstr "" +msgstr "<emphasis>5</emphasis>, <emphasis>0x0200</emphasis>:函式資料。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:63 include/debug_levels_tools.xml:44 msgid "" "<emphasis>6</emphasis>, <emphasis>0x0400</emphasis>: Trace messages for " "operation functions." -msgstr "" +msgstr "<emphasis>6</emphasis>, <emphasis>0x0400</emphasis>:操作函式的追蹤訊息。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:67 include/debug_levels_tools.xml:48 msgid "" "<emphasis>7</emphasis>, <emphasis>0x1000</emphasis>: Trace messages for " "internal control functions." -msgstr "" +msgstr "<emphasis>7</emphasis>, <emphasis>0x1000</emphasis>:內部控制函式的追蹤訊息。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:72 include/debug_levels_tools.xml:53 @@ -17880,13 +20561,15 @@ msgid "" "<emphasis>8</emphasis>, <emphasis>0x2000</emphasis>: Contents of " "function-internal variables that may be interesting." msgstr "" +"<emphasis>8</emphasis>, <emphasis>0x2000</emphasis>:可能有趣的函式內部變數內" +"容。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:77 include/debug_levels_tools.xml:58 msgid "" "<emphasis>9</emphasis>, <emphasis>0x4000</emphasis>: Extremely low-level " "tracing information." -msgstr "" +msgstr "<emphasis>9</emphasis>, <emphasis>0x4000</emphasis>:極低階的追蹤資訊。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:81 @@ -17896,6 +20579,8 @@ msgid "" "internally the logged execution time of a request might be longer than it " "actually was." msgstr "" +"<emphasis>9</emphasis>, <emphasis>0x20000</emphasis>:效能與統計資料,請注意" +"由於要求內部處理的方式,記錄的要求執行時間可能比實際時間長。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:88 include/debug_levels_tools.xml:62 @@ -17903,13 +20588,15 @@ msgid "" "<emphasis>10</emphasis>, <emphasis>0x10000</emphasis>: Even more low-level " "libldb tracing information. Almost never really required." msgstr "" +"<emphasis>10</emphasis>, <emphasis>0x10000</emphasis>:更底層的 libldb 追蹤資" +"訊。幾乎從不真正需要。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:93 include/debug_levels_tools.xml:67 msgid "" "To log required bitmask debug levels, simply add their numbers together as " "shown in following examples:" -msgstr "" +msgstr "要記錄所需的位元遮罩除錯層級,只需將它們的數字相加,如下列範例所示:" #. type: Content of: <listitem><para> #: include/debug_levels.xml:97 include/debug_levels_tools.xml:71 @@ -17917,6 +20604,8 @@ msgid "" "<emphasis>Example</emphasis>: To log fatal failures, critical failures, " "serious failures and function data use 0x0270." msgstr "" +"<emphasis>範例</emphasis>:要記錄致命失敗、嚴重失敗、重大失敗與函式資料,請使" +"用 0x0270。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:101 include/debug_levels_tools.xml:75 @@ -17924,13 +20613,15 @@ msgid "" "<emphasis>Example</emphasis>: To log fatal failures, configuration settings, " "function data, trace messages for internal control functions use 0x1310." msgstr "" +"<emphasis>範例</emphasis>:要記錄致命失敗、設定設定、函式資料、內部控制函式的" +"追蹤訊息,請使用 0x1310。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:106 include/debug_levels_tools.xml:80 msgid "" "<emphasis>Note</emphasis>: The bitmask format of debug levels was introduced " "in 1.7.0." -msgstr "" +msgstr "<emphasis>注意</emphasis>:位元遮罩格式的除錯層級是在 1.7.0 中引入。" #. type: Content of: <listitem><para> #: include/debug_levels.xml:110 include/debug_levels_tools.xml:84 @@ -17938,11 +20629,13 @@ msgid "" "<emphasis>Default</emphasis>: 0x0070 (i.e. fatal, critical and serious " "failures; corresponds to setting 2 in decimal notation)" msgstr "" +"<emphasis>預設</emphasis>:0x0070(也就是致命、嚴重與重大失敗;對應十進位記法" +"的設定 2)" #. type: Content of: <refsect1><title> #: include/local.xml:2 msgid "THE LOCAL DOMAIN" -msgstr "" +msgstr "本機網域" #. type: Content of: <refsect1><para> #: include/local.xml:4 @@ -17951,6 +20644,8 @@ msgid "" "<quote>id_provider=local</quote> must be created and the SSSD must be " "running." msgstr "" +"要正常運作,必須建立具有 <quote>id_provider=local</quote> 的網域,且 SSSD 必" +"須執行中。" #. type: Content of: <refsect1><para> #: include/local.xml:9 @@ -17963,6 +20658,11 @@ msgid "" "<command>sss_user*</command> and <command>sss_group*</command> tools use a " "local LDB storage to store users and groups." msgstr "" +"在需要群組巢狀(請參閱 <citerefentry> <refentrytitle>sss_groupadd</" +"refentrytitle> <manvolnum>8</manvolnum> </citerefentry>)的情況下,管理員可能" +"想要使用 SSSD 本機使用者而不是傳統 UNIX 使用者。本機使用者對於不需部署完整遠" +"端伺服器的 SSSD 測試與開發也很有用。<command>sss_user*</command> 與 <command>" +"sss_group*</command> 工具使用本機 LDB 儲存來儲存使用者與群組。" #. type: Content of: <refsect1><para> #: include/seealso.xml:4 @@ -18012,24 +20712,59 @@ msgid "" "<refentrytitle>sssd-systemtap</refentrytitle> <manvolnum>5</manvolnum> " "</citerefentry> </phrase>" msgstr "" +"<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>sssd.conf</refentrytitle>" +"<manvolnum>5</manvolnum> </citerefentry>, <citerefentry> <refentrytitle>sssd-" +"ldap</refentrytitle><manvolnum>5</manvolnum> </citerefentry>, <citerefentry> " +"<refentrytitle>sssd-ldap-attributes</refentrytitle><manvolnum>5</manvolnum> " +"</citerefentry>, <citerefentry> <refentrytitle>sssd-krb5</refentrytitle>" +"<manvolnum>5</manvolnum> </citerefentry>, <citerefentry> <refentrytitle>sssd-" +"simple</refentrytitle><manvolnum>5</manvolnum> </citerefentry>, " +"<citerefentry> <refentrytitle>sssd-ipa</refentrytitle><manvolnum>5</" +"manvolnum> </citerefentry>, <citerefentry> <refentrytitle>sssd-ad</" +"refentrytitle><manvolnum>5</manvolnum> </citerefentry>, <phrase " +"condition=\"with_files_provider\"> <citerefentry> <refentrytitle>sssd-files</" +"refentrytitle><manvolnum>5</manvolnum> </citerefentry>, </phrase> <phrase " +"condition=\"with_sudo\"> <citerefentry> <refentrytitle>sssd-sudo</" +"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>, </phrase> " +"<citerefentry> <refentrytitle>sssd-session-recording</refentrytitle> " +"<manvolnum>5</manvolnum> </citerefentry>, <citerefentry> <refentrytitle>" +"sss_cache</refentrytitle><manvolnum>8</manvolnum> </citerefentry>, " +"<citerefentry> <refentrytitle>sss_debuglevel</refentrytitle><manvolnum>8</" +"manvolnum> </citerefentry>, <citerefentry> <refentrytitle>sss_obfuscate</" +"refentrytitle><manvolnum>8</manvolnum> </citerefentry>, <citerefentry> " +"<refentrytitle>sss_seed</refentrytitle><manvolnum>8</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>sssd_krb5_locator_plugin</" +"refentrytitle><manvolnum>8</manvolnum> </citerefentry>, <phrase " +"condition=\"with_ssh\"> <citerefentry> <refentrytitle>" +"sss_ssh_authorizedkeys</refentrytitle> <manvolnum>1</manvolnum> </" +"citerefentry>, <citerefentry> <refentrytitle>sss_ssh_knownhosts</" +"refentrytitle> <manvolnum>1</manvolnum> </citerefentry>, </phrase> " +"<citerefentry> <refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</" +"manvolnum> </citerefentry>, <citerefentry> <refentrytitle>pam_sss</" +"refentrytitle><manvolnum>8</manvolnum> </citerefentry>. <citerefentry> " +"<refentrytitle>sss_rpcidmapd</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry> <phrase condition=\"with_stap\"> <citerefentry> <refentrytitle>" +"sssd-systemtap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> </" +"phrase>" #. type: Content of: <listitem><para> #: include/ldap_search_bases.xml:3 msgid "" "An optional base DN, search scope and LDAP filter to restrict LDAP searches " "for this attribute type." -msgstr "" +msgstr "限制此屬性類型之 LDAP 搜尋的選用基礎 DN、搜尋範圍與 LDAP 篩選器。" #. type: Content of: <listitem><para><programlisting> #: include/ldap_search_bases.xml:9 #, no-wrap msgid "search_base[?scope?[filter][?search_base?scope?[filter]]*]\n" -msgstr "" +msgstr "search_base[?scope?[filter][?search_base?scope?[filter]]*]\n" #. type: Content of: <listitem><para> #: include/ldap_search_bases.xml:7 msgid "syntax: <placeholder type=\"programlisting\" id=\"0\"/>" -msgstr "" +msgstr "語法:<placeholder type=\"programlisting\" id=\"0\"/>" #. type: Content of: <listitem><para> #: include/ldap_search_bases.xml:13 @@ -18038,13 +20773,15 @@ msgid "" "functions as specified in section 4.5.1.2 of " "http://tools.ietf.org/html/rfc4511" msgstr "" +"範圍可以是 \"base\"、\"onelevel\" 或 \"subtree\" 之一。範圍的功能如 http://" +"tools.ietf.org/html/rfc4511 第 4.5.1.2 節所指定" #. type: Content of: <listitem><para> #: include/ldap_search_bases.xml:23 msgid "" "For examples of this syntax, please refer to the " "<quote>ldap_search_base</quote> examples section." -msgstr "" +msgstr "此語法的範例請參閱 <quote>ldap_search_base</quote> 範例一節。" #. type: Content of: <listitem><para> #: include/ldap_search_bases.xml:31 @@ -18053,6 +20790,8 @@ msgid "" "against an Active Directory Server that might yield a large number of " "results and trigger the Range Retrieval extension in the response." msgstr "" +"請注意,對可能產生大量結果並在回應中觸發 Range Retrieval 延伸的 Active " +"Directory Server 搜尋,不支援指定範圍或篩選器。" #. type: Content of: <para> #: include/autofs_restart.xml:2 @@ -18061,73 +20800,76 @@ msgid "" "any autofs-related changes are made to the sssd.conf, you typically also " "need to restart the automounter daemon after restarting the SSSD." msgstr "" +"請注意,automounter 只在啟動時讀取主對應,因此若對 sssd.conf 做了任何與 " +"autofs 相關的變更,您通常也需要在重新啟動 SSSD 後重新啟動 automounter 常駐程" +"式。" #. type: Content of: <varlistentry><term> #: include/override_homedir.xml:2 msgid "override_homedir (string)" -msgstr "" +msgstr "override_homedir (string)" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:16 msgid "UID number" -msgstr "" +msgstr "UID 號碼" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:20 msgid "domain name" -msgstr "" +msgstr "網域名稱" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: include/override_homedir.xml:23 msgid "%f" -msgstr "" +msgstr "%f" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:24 msgid "fully qualified user name (user@domain)" -msgstr "" +msgstr "完整限定使用者名稱(user@domain)" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: include/override_homedir.xml:27 msgid "%l" -msgstr "" +msgstr "%l" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:28 msgid "The first letter of the login name." -msgstr "" +msgstr "登入名稱的第一個字母。" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:32 msgid "UPN - User Principal Name (name@REALM)" -msgstr "" +msgstr "UPN - User Principal Name(name@REALM)" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: include/override_homedir.xml:35 msgid "%o" -msgstr "" +msgstr "%o" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:37 msgid "The original home directory retrieved from the identity provider." -msgstr "" +msgstr "從身分提供者擷取的原始家目錄。" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:44 msgid "" "The original home directory retrieved from the identity provider, but in " "lower case." -msgstr "" +msgstr "從身分提供者擷取的原始家目錄,但改為小寫。" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term> #: include/override_homedir.xml:49 msgid "%H" -msgstr "" +msgstr "%H" #. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para> #: include/override_homedir.xml:51 msgid "The value of configure option <emphasis>homedir_substring</emphasis>." -msgstr "" +msgstr "設定選項 <emphasis>homedir_substring</emphasis> 的值。" #. type: Content of: <varlistentry><listitem><para> #: include/override_homedir.xml:5 @@ -18136,11 +20878,13 @@ msgid "" "or a template. In the template, the following sequences are substituted: " "<placeholder type=\"variablelist\" id=\"0\"/>" msgstr "" +"覆寫使用者的家目錄。您可以提供絕對值或範本。在範本中,會替換下列序列" +":<placeholder type=\"variablelist\" id=\"0\"/>" #. type: Content of: <varlistentry><listitem><para> #: include/override_homedir.xml:63 msgid "This option can also be set per-domain." -msgstr "" +msgstr "此選項也可以按網域設定。" #. type: Content of: <varlistentry><listitem><para><programlisting> #: include/override_homedir.xml:68 @@ -18149,11 +20893,13 @@ msgid "" "override_homedir = /home/%u\n" " " msgstr "" +"override_homedir = /home/%u\n" +" " #. type: Content of: <varlistentry><listitem><para> #: include/override_homedir.xml:72 msgid "Default: Not set (SSSD will use the value retrieved from LDAP)" -msgstr "" +msgstr "預設:未設定(SSSD 將使用從 LDAP 擷取的值)" #. type: Content of: <varlistentry><listitem><para> #: include/override_homedir.xml:76 @@ -18165,11 +20911,15 @@ msgid "" "id-overrides, has a higher precedence and will be used instead of the value " "given by override_homedir." msgstr "" +"請注意,使用者特定覆寫的家目錄(無論是本機(請參閱 <citerefentry>" +"<refentrytitle>sss_override</refentrytitle> <manvolnum>8</manvolnum></" +"citerefentry>)或集中管理的 IPA id-overrides)具有較高的優先順序,將被使用而" +"不是 override_homedir 給定的值。" #. type: Content of: <varlistentry><term> #: include/homedir_substring.xml:2 msgid "homedir_substring (string)" -msgstr "" +msgstr "homedir_substring (string)" #. type: Content of: <varlistentry><listitem><para> #: include/homedir_substring.xml:5 @@ -18182,16 +20932,21 @@ msgid "" "per-domain or globally in the [nss] section. A value specified in a domain " "section will override one set in the [nss] section." msgstr "" +"若範本包含格式字串 <emphasis>%H</emphasis>,此選項的值將用於 <emphasis>" +"override_homedir</emphasis> 選項的展開。LDAP 目錄項目可以直接包含此範本,因此" +"此選項可以用來為每個用戶端機器(或作業系統)展開家目錄路徑。它可以按網域設定" +",或在 [nss] 區段中全域設定。在網域區段中指定的值會覆寫 [nss] 區段中設定的值" +"。" #. type: Content of: <varlistentry><listitem><para> #: include/homedir_substring.xml:15 msgid "Default: /home" -msgstr "" +msgstr "預設:/home" #. type: Content of: <refsect1><title> #: include/ad_modified_defaults.xml:2 include/ipa_modified_defaults.xml:2 msgid "MODIFIED DEFAULT OPTIONS" -msgstr "" +msgstr "已修改的預設選項" #. type: Content of: <refsect1><para> #: include/ad_modified_defaults.xml:4 @@ -18200,66 +20955,68 @@ msgid "" "defaults, these option names and AD provider-specific defaults are listed " "below:" msgstr "" +"某些選項的預設值與其各自後端提供者的預設值不符,下列列出這些選項名稱與 AD 提" +"供者特定的預設值:" #. type: Content of: <refsect1><refsect2><title> #: include/ad_modified_defaults.xml:9 include/ipa_modified_defaults.xml:9 msgid "KRB5 Provider" -msgstr "" +msgstr "KRB5 提供者" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:13 include/ipa_modified_defaults.xml:13 msgid "krb5_validate = true" -msgstr "" +msgstr "krb5_validate = true" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:18 msgid "krb5_use_enterprise_principal = true" -msgstr "" +msgstr "krb5_use_enterprise_principal = true" #. type: Content of: <refsect1><refsect2><title> #: include/ad_modified_defaults.xml:24 msgid "LDAP Provider" -msgstr "" +msgstr "LDAP 提供者" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:28 msgid "ldap_schema = ad" -msgstr "" +msgstr "ldap_schema = ad" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:33 include/ipa_modified_defaults.xml:38 msgid "ldap_force_upper_case_realm = true" -msgstr "" +msgstr "ldap_force_upper_case_realm = true" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:38 msgid "ldap_id_mapping = true" -msgstr "" +msgstr "ldap_id_mapping = true" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:43 msgid "ldap_sasl_mech = GSS-SPNEGO" -msgstr "" +msgstr "ldap_sasl_mech = GSS-SPNEGO" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:48 msgid "ldap_referrals = false" -msgstr "" +msgstr "ldap_referrals = false" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:53 msgid "ldap_account_expire_policy = ad" -msgstr "" +msgstr "ldap_account_expire_policy = ad" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:58 include/ipa_modified_defaults.xml:58 msgid "ldap_use_tokengroups = true" -msgstr "" +msgstr "ldap_use_tokengroups = true" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:63 msgid "ldap_sasl_authid = sAMAccountName@REALM (typically SHORTNAME$@REALM)" -msgstr "" +msgstr "ldap_sasl_authid = sAMAccountName@REALM(通常是 SHORTNAME$@REALM)" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:66 @@ -18272,16 +21029,21 @@ msgid "" "well-known host/hostname@REALM principal is a Service Principal and thus " "cannot be used to get a TGT with." msgstr "" +"依預設,AD 提供者尋找的 principal 與 LDAP 提供者不同,因為在 Active " +"Directory 環境中,principal 分為兩組:User Principal 與 Service Principal。只" +"有 User Principal 可以用來取得 TGT,依預設,電腦物件的 principal 是由其 " +"sAMAccountName 與 AD realm 建構。眾所周知的 host/hostname@REALM principal 是 " +"Service Principal,因此不能用它取得 TGT。" #. type: Content of: <refsect1><refsect2><title> #: include/ad_modified_defaults.xml:80 msgid "NSS configuration" -msgstr "" +msgstr "NSS 設定" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:84 msgid "fallback_homedir = /home/%d/%u" -msgstr "" +msgstr "fallback_homedir = /home/%d/%u" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:87 @@ -18292,6 +21054,9 @@ msgid "" "and you want to avoid this fallback behavior, you can explicitly set " "\"fallback_homedir = %o\"." msgstr "" +"AD 提供者自動設定 \"fallback_homedir = /home/%d/%u\",為沒有 homeDirectory 屬" +"性的使用者提供個人家目錄。若您的 AD 網域已正確填入 Posix 屬性,且您想要避免此" +"退回行為,您可以明確設定 \"fallback_homedir = %o\"。" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:96 @@ -18300,6 +21065,8 @@ msgid "" "folder. If you decide to use a different directory structure, some other " "parts of your system may need adjustments." msgstr "" +"請注意,系統通常預期家目錄在 /home/%u 資料夾中。若您決定使用不同的目錄結構," +"系統的其他部分可能需要調整。" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ad_modified_defaults.xml:102 @@ -18308,6 +21075,8 @@ msgid "" "selinux requires selinux adjustment, otherwise the home directory will be " "created with wrong selinux context." msgstr "" +"例如,與 selinux 搭配的自動建立家目錄需要調整 selinux,否則家目錄會以錯誤的 " +"selinux context 建立。" #. type: Content of: <refsect1><para> #: include/ipa_modified_defaults.xml:4 @@ -18316,106 +21085,108 @@ msgid "" "defaults, these option names and IPA provider-specific defaults are listed " "below:" msgstr "" +"某些選項的預設值與其各自後端提供者的預設值不符,下列列出這些選項名稱與 IPA 提" +"供者特定的預設值:" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:18 msgid "krb5_use_fast = try" -msgstr "" +msgstr "krb5_use_fast = try" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:23 msgid "krb5_canonicalize = true" -msgstr "" +msgstr "krb5_canonicalize = true" #. type: Content of: <refsect1><refsect2><title> #: include/ipa_modified_defaults.xml:29 msgid "LDAP Provider - General" -msgstr "" +msgstr "LDAP 提供者 - 一般" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:33 msgid "ldap_schema = ipa_v1" -msgstr "" +msgstr "ldap_schema = ipa_v1" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:43 msgid "ldap_sasl_mech = GSSAPI" -msgstr "" +msgstr "ldap_sasl_mech = GSSAPI" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:48 msgid "ldap_sasl_minssf = 56" -msgstr "" +msgstr "ldap_sasl_minssf = 56" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:53 msgid "ldap_account_expire_policy = ipa" -msgstr "" +msgstr "ldap_account_expire_policy = ipa" #. type: Content of: <refsect1><refsect2><title> #: include/ipa_modified_defaults.xml:64 msgid "LDAP Provider - User options" -msgstr "" +msgstr "LDAP 提供者 - 使用者選項" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:68 msgid "ldap_user_member_of = memberOf" -msgstr "" +msgstr "ldap_user_member_of = memberOf" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:73 msgid "ldap_user_uuid = ipaUniqueID" -msgstr "" +msgstr "ldap_user_uuid = ipaUniqueID" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:78 msgid "ldap_user_ssh_public_key = ipaSshPubKey" -msgstr "" +msgstr "ldap_user_ssh_public_key = ipaSshPubKey" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:83 msgid "ldap_user_auth_type = ipaUserAuthType" -msgstr "" +msgstr "ldap_user_auth_type = ipaUserAuthType" #. type: Content of: <refsect1><refsect2><title> #: include/ipa_modified_defaults.xml:89 msgid "LDAP Provider - Group options" -msgstr "" +msgstr "LDAP 提供者 - 群組選項" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:93 msgid "ldap_group_object_class = ipaUserGroup" -msgstr "" +msgstr "ldap_group_object_class = ipaUserGroup" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:98 msgid "ldap_group_object_class_alt = posixGroup" -msgstr "" +msgstr "ldap_group_object_class_alt = posixGroup" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:103 msgid "ldap_group_member = member" -msgstr "" +msgstr "ldap_group_member = member" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:108 msgid "ldap_group_uuid = ipaUniqueID" -msgstr "" +msgstr "ldap_group_uuid = ipaUniqueID" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:113 msgid "ldap_group_objectsid = ipaNTSecurityIdentifier" -msgstr "" +msgstr "ldap_group_objectsid = ipaNTSecurityIdentifier" #. type: Content of: <refsect1><refsect2><itemizedlist><listitem><para> #: include/ipa_modified_defaults.xml:118 msgid "ldap_group_external_member = ipaExternalMember" -msgstr "" +msgstr "ldap_group_external_member = ipaExternalMember" #. type: Content of: <variablelist><varlistentry><term> #: include/krb5_options.xml:3 msgid "krb5_auth_timeout (integer)" -msgstr "" +msgstr "krb5_auth_timeout (integer)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:6 @@ -18423,12 +21194,12 @@ msgid "" "Timeout in seconds after an online authentication request or change password " "request is aborted. If possible, the authentication request is continued " "offline." -msgstr "" +msgstr "線上驗證要求或變更密碼要求中止之前的逾時(秒)。若可能,驗證要求會離線繼續。" #. type: Content of: <variablelist><varlistentry><term> #: include/krb5_options.xml:17 msgid "krb5_validate (boolean)" -msgstr "" +msgstr "krb5_validate (boolean)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:20 @@ -18440,11 +21211,15 @@ msgid "" "environments using cross-realm trust by placing the appropriate keytab entry " "as the last entry or the only entry in the keytab file." msgstr "" +"在 krb5_keytab 的協助下驗證取得的 TGT 沒有被偽造。keytab 會依序檢查項目,第一" +"個具有相符 realm 的項目用於驗證。若沒有項目符合 realm,會使用 keytab 中的最後" +"一個項目。此程序可以透過將適當的 keytab 項目放在 keytab 檔案的最後一個項目或" +"唯一項目,用於驗證使用跨 realm 信任的環境。" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:29 msgid "Default: false (IPA and AD provider: true)" -msgstr "" +msgstr "預設:false(IPA 與 AD 提供者:true)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:32 @@ -18455,47 +21230,50 @@ msgid "" "</citerefentry> manual page for details). If ticket validation is disabled " "the PAC checks will be skipped as well." msgstr "" +"請注意,票證驗證是檢查 PAC 時的第一步(詳細資料請參閱 <citerefentry> " +"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </" +"citerefentry> 手冊頁中的 'pac_check')。若停用票證驗證,PAC 檢查也會被略過。" #. type: Content of: <variablelist><varlistentry><term> #: include/krb5_options.xml:44 msgid "krb5_renewable_lifetime (string)" -msgstr "" +msgstr "krb5_renewable_lifetime (string)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:47 msgid "" "Request a renewable ticket with a total lifetime, given as an integer " "immediately followed by a time unit:" -msgstr "" +msgstr "要求總生命週期的可續約票證,以整數緊接著時間單位給出:" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:52 include/krb5_options.xml:86 #: include/krb5_options.xml:123 msgid "<emphasis>s</emphasis> for seconds" -msgstr "" +msgstr "<emphasis>s</emphasis>:秒" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:55 include/krb5_options.xml:89 #: include/krb5_options.xml:126 msgid "<emphasis>m</emphasis> for minutes" -msgstr "" +msgstr "<emphasis>m</emphasis>:分鐘" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:58 include/krb5_options.xml:92 #: include/krb5_options.xml:129 msgid "<emphasis>h</emphasis> for hours" -msgstr "" +msgstr "<emphasis>h</emphasis>:小時" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:61 include/krb5_options.xml:95 #: include/krb5_options.xml:132 msgid "<emphasis>d</emphasis> for days." -msgstr "" +msgstr "<emphasis>d</emphasis>:天。" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:64 include/krb5_options.xml:135 msgid "If there is no unit given, <emphasis>s</emphasis> is assumed." -msgstr "" +msgstr "若沒有給定單位,假設為 <emphasis>s</emphasis>。" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:68 include/krb5_options.xml:139 @@ -18503,45 +21281,47 @@ msgid "" "NOTE: It is not possible to mix units. To set the renewable lifetime to one " "and a half hours, use '90m' instead of '1h30m'." msgstr "" +"注意:無法混合單位。要將可續約生命週期設為一個半小時,請使用 '90m' 而不是 " +"'1h30m'。" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:73 msgid "Default: not set, i.e. the TGT is not renewable" -msgstr "" +msgstr "預設:未設定,也就是 TGT 不可續約" #. type: Content of: <variablelist><varlistentry><term> #: include/krb5_options.xml:79 msgid "krb5_lifetime (string)" -msgstr "" +msgstr "krb5_lifetime (string)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:82 msgid "" "Request ticket with a lifetime, given as an integer immediately followed by " "a time unit:" -msgstr "" +msgstr "要求具有生命週期的票證,以整數緊接著時間單位給出:" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:98 msgid "If there is no unit given <emphasis>s</emphasis> is assumed." -msgstr "" +msgstr "若沒有給定單位,假設為 <emphasis>s</emphasis>。" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:102 msgid "" "NOTE: It is not possible to mix units. To set the lifetime to one and a " "half hours please use '90m' instead of '1h30m'." -msgstr "" +msgstr "注意:無法混合單位。要將生命週期設為一個半小時,請使用 '90m' 而不是 '1h30m'。" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:107 msgid "Default: not set, i.e. the default ticket lifetime configured on the KDC." -msgstr "" +msgstr "預設:未設定,也就是 KDC 上設定的預設票證生命週期。" #. type: Content of: <variablelist><varlistentry><term> #: include/krb5_options.xml:114 msgid "krb5_renew_interval (string)" -msgstr "" +msgstr "krb5_renew_interval (string)" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:117 @@ -18550,11 +21330,13 @@ msgid "" "are renewed if about half of their lifetime is exceeded, given as an integer " "immediately followed by a time unit:" msgstr "" +"兩次檢查 TGT 是否應續約之間的時間(秒)。當 TGT 生命週期約過半時會續約,以整" +"數緊接著時間單位給出:" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:144 msgid "If this option is not set or is 0 the automatic renewal is disabled." -msgstr "" +msgstr "若未設定此選項或為 0,自動續約會停用。" #. type: Content of: <variablelist><varlistentry><listitem><para> #: include/krb5_options.xml:157 @@ -18562,3 +21344,5 @@ msgid "" "Specifies if the host and user principal should be canonicalized. This " "feature is available with MIT Kerberos 1.7 and later versions." msgstr "" +"指定是否應正規化主機與使用者 principal。此功能在 MIT Kerberos 1.7 及更新版本" +"中可用。"