File: lcmaps_ban_dn.mod.8

package info (click to toggle)
lcmaps-plugins-basic 1.7.1-3
  • links: PTS, VCS
  • area: main
  • in suites: forky, sid
  • size: 2,004 kB
  • sloc: sh: 11,020; ansic: 4,124; makefile: 128
file content (48 lines) | stat: -rw-r--r-- 1,616 bytes parent folder | download | duplicates (3)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
.TH LCMAPS_BAN_DN.MOD 8 "February 9, 2015" "Stichting FOM/Nikhef" "Site Access Control"
.SH NAME
lcmaps_ban_dn.mod \- LCMAPS plugin to ban a user based on the Subject DN
.SH SYNOPSIS
.B lcmaps_ban_dn.mod
.RB [ \-banmapfile
.IR banning\ file ]
.RB [ \-no_wildcard | \-disablewildcard ]
.SH DESCRIPTION
This plugin is a banning plugin and will provide the LCMAPS system with a
credential banning feature based on the Distinguished Name (DN).
It will read a grid-mapfile and check whether the DN
appears on it. If that is the case, the plug-in will fail with a
.BR LCMAPS_MOD_FAIL.
If the plugin succeeds and DN does not appear in the banning file the plugin will
finish with a
.BR LCMAPS_MOD_SUCCESS

.SH OPTIONS
.TP
.BI "\-banmapfile " ban-mapfile
This option sets the path to the banning file which contains the list of DNs
which must be banned by the plugin.
It is strongly advised to set an absolute path to the ban-mapfile to avoid usage
of the wrong file(path). In a (setuid-)root application, relative paths are
taken with respect to \fI/etc/grid-security/\fR.

.TP
.BI "\-no_wildcard\fR,\fB \-disablewildcard"
When this option is set the plug-in will only match exact DNs,
i.e. /DC=org/DC=terena/DC=tcs/C=NL/* will not match.

.SH RETURN VALUES
.TP
.B LCMAPS_MOD_SUCCESS
Success.
.TP
.B LCMAPS_MOD_FAIL
Failure or banned.
.SH BUGS
Please report any errors to the Nikhef Grid Middleware Security Team
<grid-mw-security-support@nikhef.nl>.
.SH SEE ALSO
.BR lcmaps.db (5), 
.BR lcmaps (3).
.SH AUTHORS
LCMAPS and the LCMAPS plug-ins were written by the Grid Middleware Security Team
<grid-mw-security@nikhef.nl>.