1
0
mirror of https://github.com/samba-team/samba.git synced 2024-12-25 23:21:54 +03:00
samba-mirror/docs-xml/smbdotconf/security/checkpasswordscript.xml
Stefan Metzmacher 2e8daeb2bb docs-xml/smbdotconf: document export of SAMBA_CPS_{ACCOUNT,USER_PRINCIPAL,FULL}_NAME for check password script
Signed-off-by: Stefan Metzmacher <metze@samba.org>
Reviewed-by: Andrew Bartlett <abartlet@samba.org>

Autobuild-User(master): Andrew Bartlett <abartlet@samba.org>
Autobuild-Date(master): Mon Feb 11 11:03:58 CET 2019 on sn-devel-144
2019-02-11 11:03:58 +01:00

43 lines
1.7 KiB
XML

<samba:parameter name="check password script"
context="G"
type="string"
xmlns:samba="http://www.samba.org/samba/DTD/samba-doc">
<description>
<para>The name of a program that can be used to check password
complexity. The password is sent to the program's standard input.</para>
<para>The program must return 0 on a good password, or any other value
if the password is bad.
In case the password is considered weak (the program does not return 0) the
user will be notified and the password change will fail.</para>
<para>In Samba AD, this script will be run <emphasis>AS ROOT</emphasis> by
<citerefentry><refentrytitle>samba</refentrytitle> <manvolnum>8</manvolnum>
</citerefentry> without any substitutions.</para>
<para>Note that starting with Samba 4.11 the following environment variables are exported to the script:</para>
<itemizedlist>
<listitem><para>
SAMBA_CPS_ACCOUNT_NAME is always present and contains the sAMAccountName of user,
the is the same as the %u substitutions in the none AD DC case.
</para></listitem>
<listitem><para>
SAMBA_CPS_USER_PRINCIPAL_NAME is optional in the AD DC case if the userPrincipalName is present.
</para></listitem>
<listitem><para>
SAMBA_CPS_FULL_NAME is optional if the displayName is present.
</para></listitem>
</itemizedlist>
<para>Note: In the example directory is a sample program called <command moreinfo="none">crackcheck</command>
that uses cracklib to check the password quality.</para>
</description>
<value type="default"><comment>Disabled</comment></value>
<value type="example">/usr/local/sbin/crackcheck</value>
</samba:parameter>