diff options
| author | Cy Schubert <cy@FreeBSD.org> | 2023-08-04 17:53:10 +0000 |
|---|---|---|
| committer | Cy Schubert <cy@FreeBSD.org> | 2023-08-04 17:53:10 +0000 |
| commit | 0320e0d5bb9fbb5da53478b3fd80ad79b110191d (patch) | |
| tree | e1185f75bd2d3f87b0c17f787debc3ee8648214b /doc/html/user/user_config/k5identity.html | |
| parent | b0e4d68d5124581ae353493d69bea352de4cff8a (diff) | |
Diffstat (limited to 'doc/html/user/user_config/k5identity.html')
| -rw-r--r-- | doc/html/user/user_config/k5identity.html | 51 |
1 files changed, 25 insertions, 26 deletions
diff --git a/doc/html/user/user_config/k5identity.html b/doc/html/user/user_config/k5identity.html index d1155590d7bc..fc38fdb6ec2c 100644 --- a/doc/html/user/user_config/k5identity.html +++ b/doc/html/user/user_config/k5identity.html @@ -1,33 +1,31 @@ + <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> - <html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> - - <title>.k5identity — MIT Kerberos Documentation</title> - + <title>.k5identity — MIT Kerberos Documentation</title> <link rel="stylesheet" href="../../_static/agogo.css" type="text/css" /> <link rel="stylesheet" href="../../_static/pygments.css" type="text/css" /> <link rel="stylesheet" href="../../_static/kerb.css" type="text/css" /> - <script type="text/javascript"> var DOCUMENTATION_OPTIONS = { URL_ROOT: '../../', - VERSION: '1.16', + VERSION: '1.21.1', COLLAPSE_INDEX: false, FILE_SUFFIX: '.html', - HAS_SOURCE: true + HAS_SOURCE: true, + SOURCELINK_SUFFIX: '.txt' }; </script> <script type="text/javascript" src="../../_static/jquery.js"></script> <script type="text/javascript" src="../../_static/underscore.js"></script> <script type="text/javascript" src="../../_static/doctools.js"></script> <link rel="author" title="About these documents" href="../../about.html" /> + <link rel="index" title="Index" href="../../genindex.html" /> + <link rel="search" title="Search" href="../../search.html" /> <link rel="copyright" title="Copyright" href="../../copyright.html" /> - <link rel="top" title="MIT Kerberos Documentation" href="../../index.html" /> - <link rel="up" title="User config files" href="index.html" /> <link rel="next" title="User commands" href="../user_commands/index.html" /> <link rel="prev" title=".k5login" href="k5login.html" /> </head> @@ -61,20 +59,20 @@ <div class="documentwrapper"> <div class="bodywrapper"> - <div class="body"> + <div class="body" role="main"> <div class="section" id="k5identity"> <span id="k5identity-5"></span><h1>.k5identity<a class="headerlink" href="#k5identity" title="Permalink to this headline">¶</a></h1> <div class="section" id="description"> <h2>DESCRIPTION<a class="headerlink" href="#description" title="Permalink to this headline">¶</a></h2> -<p>The .k5identity file, which resides in a user’s home directory, +<p>The .k5identity file, which resides in a user’s home directory, contains a list of rules for selecting a client principals based on the server being accessed. These rules are used to choose a credential cache within the cache collection when possible.</p> -<p>Blank lines and lines beginning with <tt class="docutils literal"><span class="pre">#</span></tt> are ignored. Each line has +<p>Blank lines and lines beginning with <code class="docutils literal"><span class="pre">#</span></code> are ignored. Each line has the form:</p> <blockquote> -<div><em>principal</em> <em>field</em>=<em>value</em> ...</div></blockquote> +<div><em>principal</em> <em>field</em>=<em>value</em> …</div></blockquote> <p>If the server principal meets all of the field constraints, then principal is chosen as the client principal. The following fields are recognized:</p> @@ -83,8 +81,8 @@ recognized:</p> <dd>If the realm of the server principal is known, it is matched against <em>value</em>, which may be a pattern using shell wildcards. For host-based server principals, the realm will generally only be -known if there is a <a class="reference internal" href="../../admin/conf_files/krb5_conf.html#domain-realm"><em>[domain_realm]</em></a> section in -<a class="reference internal" href="../../admin/conf_files/krb5_conf.html#krb5-conf-5"><em>krb5.conf</em></a> with a mapping for the hostname.</dd> +known if there is a <a class="reference internal" href="../../admin/conf_files/krb5_conf.html#domain-realm"><span class="std std-ref">[domain_realm]</span></a> section in +<a class="reference internal" href="../../admin/conf_files/krb5_conf.html#krb5-conf-5"><span class="std std-ref">krb5.conf</span></a> with a mapping for the hostname.</dd> <dt><strong>service</strong></dt> <dd>If the server principal is a host-based principal, its service component is matched against <em>value</em>, which may be a pattern using @@ -104,19 +102,19 @@ cache.</p> <div class="section" id="example"> <h2>EXAMPLE<a class="headerlink" href="#example" title="Permalink to this headline">¶</a></h2> <p>The following example .k5identity file selects the client principal -<tt class="docutils literal"><span class="pre">alice@KRBTEST.COM</span></tt> if the server principal is within that realm, -the principal <tt class="docutils literal"><span class="pre">alice/root@EXAMPLE.COM</span></tt> if the server host is within -a servers subdomain, and the principal <tt class="docutils literal"><span class="pre">alice/mail@EXAMPLE.COM</span></tt> when -accessing the IMAP service on <tt class="docutils literal"><span class="pre">mail.example.com</span></tt>:</p> -<div class="highlight-python"><div class="highlight"><pre>alice@KRBTEST.COM realm=KRBTEST.COM -alice/root@EXAMPLE.COM host=*.servers.example.com -alice/mail@EXAMPLE.COM host=mail.example.com service=imap +<code class="docutils literal"><span class="pre">alice@KRBTEST.COM</span></code> if the server principal is within that realm, +the principal <code class="docutils literal"><span class="pre">alice/root@EXAMPLE.COM</span></code> if the server host is within +a servers subdomain, and the principal <code class="docutils literal"><span class="pre">alice/mail@EXAMPLE.COM</span></code> when +accessing the IMAP service on <code class="docutils literal"><span class="pre">mail.example.com</span></code>:</p> +<div class="highlight-default"><div class="highlight"><pre><span></span><span class="n">alice</span><span class="nd">@KRBTEST</span><span class="o">.</span><span class="n">COM</span> <span class="n">realm</span><span class="o">=</span><span class="n">KRBTEST</span><span class="o">.</span><span class="n">COM</span> +<span class="n">alice</span><span class="o">/</span><span class="n">root</span><span class="nd">@EXAMPLE</span><span class="o">.</span><span class="n">COM</span> <span class="n">host</span><span class="o">=*.</span><span class="n">servers</span><span class="o">.</span><span class="n">example</span><span class="o">.</span><span class="n">com</span> +<span class="n">alice</span><span class="o">/</span><span class="n">mail</span><span class="nd">@EXAMPLE</span><span class="o">.</span><span class="n">COM</span> <span class="n">host</span><span class="o">=</span><span class="n">mail</span><span class="o">.</span><span class="n">example</span><span class="o">.</span><span class="n">com</span> <span class="n">service</span><span class="o">=</span><span class="n">imap</span> </pre></div> </div> </div> <div class="section" id="see-also"> <h2>SEE ALSO<a class="headerlink" href="#see-also" title="Permalink to this headline">¶</a></h2> -<p>kerberos(1), <a class="reference internal" href="../../admin/conf_files/krb5_conf.html#krb5-conf-5"><em>krb5.conf</em></a></p> +<p>kerberos(1), <a class="reference internal" href="../../admin/conf_files/krb5_conf.html#krb5-conf-5"><span class="std std-ref">krb5.conf</span></a></p> </div> </div> @@ -143,8 +141,9 @@ alice/mail@EXAMPLE.COM host=mail.example.com service=imap <li class="toctree-l2"><a class="reference internal" href="../pwd_mgmt.html">Password management</a></li> <li class="toctree-l2"><a class="reference internal" href="../tkt_mgmt.html">Ticket management</a></li> <li class="toctree-l2 current"><a class="reference internal" href="index.html">User config files</a><ul class="current"> +<li class="toctree-l3"><a class="reference internal" href="kerberos.html">kerberos</a></li> <li class="toctree-l3"><a class="reference internal" href="k5login.html">.k5login</a></li> -<li class="toctree-l3 current"><a class="current reference internal" href="">.k5identity</a></li> +<li class="toctree-l3 current"><a class="current reference internal" href="#">.k5identity</a></li> </ul> </li> <li class="toctree-l2"><a class="reference internal" href="../user_commands/index.html">User commands</a></li> @@ -178,8 +177,8 @@ alice/mail@EXAMPLE.COM host=mail.example.com service=imap <div class="footer-wrapper"> <div class="footer" > - <div class="right" ><i>Release: 1.16</i><br /> - © <a href="../../copyright.html">Copyright</a> 1985-2017, MIT. + <div class="right" ><i>Release: 1.21.1</i><br /> + © <a href="../../copyright.html">Copyright</a> 1985-2023, MIT. </div> <div class="left"> |
