[992] | 1 | # $Id$ |
---|
[991] | 2 | |
---|
| 3 | =head1 NAME |
---|
| 4 | |
---|
[1008] | 5 | Link::Accounts - A multiple accounts base management and synchronisation |
---|
| 6 | system |
---|
| 7 | |
---|
[1010] | 8 | =head1 GENERALITY |
---|
[1008] | 9 | |
---|
| 10 | =head2 HISTORY |
---|
| 11 | |
---|
| 12 | Link::Accounts is born with the need to have same set of groups and users in |
---|
| 13 | multiples accounts bases: |
---|
| 14 | |
---|
| 15 | =over 4 |
---|
| 16 | |
---|
| 17 | =item OpenLDAP |
---|
| 18 | |
---|
| 19 | Standard ldap base w/o any change on basis schema |
---|
| 20 | |
---|
| 21 | =item Active Directory |
---|
| 22 | |
---|
| 23 | The domain management system for windows. Active Directory is a solution |
---|
| 24 | including LDAP, Kerberos, Smb protocol and a graphic interface to configure it. |
---|
| 25 | |
---|
| 26 | =item Unix file |
---|
| 27 | |
---|
| 28 | Standard users base under Unix system, also used for C<NIS>/C<YP> system. |
---|
| 29 | |
---|
[1111] | 30 | =item Kerberos/Heimdal |
---|
| 31 | |
---|
| 32 | Remote access to Kerberos base. |
---|
| 33 | |
---|
[1008] | 34 | =back |
---|
| 35 | |
---|
[1010] | 36 | =head2 WORKFLOW |
---|
| 37 | |
---|
[1111] | 38 | C<Link::Accounts> is made of three components: |
---|
[1010] | 39 | |
---|
| 40 | =over 4 |
---|
| 41 | |
---|
[1020] | 42 | =item L</Bases> |
---|
[1010] | 43 | |
---|
[1020] | 44 | =item L</Objects> |
---|
[1010] | 45 | |
---|
[1020] | 46 | =item L</Attributes> |
---|
[1010] | 47 | |
---|
| 48 | =back |
---|
| 49 | |
---|
| 50 | =head3 Bases |
---|
| 51 | |
---|
[1111] | 52 | A base module provide the common way to access a set of data. Usually a base is |
---|
| 53 | accessed remotely trought a network connection but always. |
---|
| 54 | |
---|
| 55 | In an ideal world, all base can be synchronised over another one. |
---|
| 56 | |
---|
| 57 | Each data inside a base is represented as objects of differents type. The most |
---|
| 58 | common type are for sure C<user> and C<group>. |
---|
| 59 | |
---|
[1020] | 60 | =head3 Objects |
---|
| 61 | |
---|
[1111] | 62 | Inside a base the objects is the unbreakble subset of data. |
---|
| 63 | |
---|
| 64 | Each object are identified uniquely by both a type and an identifier on the |
---|
| 65 | C<LATMOS::Accounts> side. This mean two object of different type can have the |
---|
| 66 | same id. |
---|
| 67 | |
---|
| 68 | On the other hand the identifier must allow to identify uniquelly the object |
---|
| 69 | inside the base. |
---|
| 70 | |
---|
| 71 | For example in C</Unix file> base each line of F<passwd> is a C<user> object and |
---|
| 72 | the login is the uniq identifier. |
---|
| 73 | |
---|
| 74 | The couple object type/identifier must also allow to find common objects through |
---|
| 75 | differents bases. |
---|
| 76 | |
---|
[1020] | 77 | =head3 Attributes |
---|
| 78 | |
---|
[1111] | 79 | The attributes is the basic data storage for an object. |
---|
| 80 | |
---|
| 81 | Each attribute have a name and normally a specific usage, even through base. |
---|
| 82 | |
---|
| 83 | Attributes may have different behavior, depending their definition and base |
---|
| 84 | constraint: |
---|
| 85 | |
---|
| 86 | =over 4 |
---|
| 87 | |
---|
| 88 | =item single or multiple value |
---|
| 89 | |
---|
| 90 | =item limited possible values |
---|
| 91 | |
---|
| 92 | =item reference to others objects |
---|
| 93 | |
---|
| 94 | =back |
---|
| 95 | |
---|
[993] | 96 | =head1 CONFIGURATION |
---|
[991] | 97 | |
---|
[1029] | 98 | All configuration files listed bellow must be stored in the same directory. |
---|
| 99 | |
---|
| 100 | By default this directory is F</etc/latmos-accounts>. |
---|
| 101 | |
---|
| 102 | It can be overload by setting envirronment variable C<LA_CONFIG>. |
---|
| 103 | |
---|
[991] | 104 | =head2 Configuration files list |
---|
| 105 | |
---|
[993] | 106 | =over 4 |
---|
| 107 | |
---|
| 108 | =item latmos-accounts.ini |
---|
| 109 | |
---|
| 110 | Bases and synchronisations definitions. |
---|
| 111 | |
---|
[1010] | 112 | See L<latmos-accounts.ini> |
---|
[993] | 113 | |
---|
| 114 | =item la-allowed-values.ini |
---|
| 115 | |
---|
| 116 | Attributes values allowed. |
---|
| 117 | |
---|
[1010] | 118 | See L<la-allowed-values.ini> |
---|
[993] | 119 | |
---|
| 120 | =item la-sync-manager.ini |
---|
| 121 | |
---|
| 122 | The setup of L<la-sync-manager>, the daemon in charge of pushing values from |
---|
| 123 | primary base to others. |
---|
| 124 | |
---|
[1010] | 125 | See L<la-sync-manager.ini> |
---|
[993] | 126 | |
---|
| 127 | =item la-acls.ini |
---|
| 128 | |
---|
| 129 | Access list configuration, used by Web application |
---|
| 130 | |
---|
[1010] | 131 | See L<la-acls.ini> |
---|
[993] | 132 | |
---|
| 133 | =item la-sync-list.ini |
---|
| 134 | |
---|
| 135 | Configuration of mailing synchronisation module |
---|
| 136 | |
---|
[1010] | 137 | See L<la-sync-list.ini> |
---|
[993] | 138 | |
---|
| 139 | =back |
---|
| 140 | |
---|
[1992] | 141 | =head1 INPUT FILE |
---|
| 142 | |
---|
| 143 | The input file is a list of attribute and value separate by a semi-colon. |
---|
| 144 | Multi-values attributes must be repeated for each value. |
---|
| 145 | Attributes not listed are left untouched. |
---|
| 146 | |
---|
| 147 | Example: |
---|
| 148 | |
---|
| 149 | sn: Myname |
---|
| 150 | givenName: Myfirstname |
---|
| 151 | |
---|
| 152 | Some object have related objects, for example C<user> have multiple C<address> |
---|
| 153 | and C<employment>. It can be usefull to create those object in same time the |
---|
| 154 | main object. |
---|
| 155 | |
---|
| 156 | At creation the related object attributes can given using attribute in form |
---|
| 157 | C<OTYPE.ATTRIBUTE>. |
---|
| 158 | |
---|
| 159 | Example: |
---|
| 160 | |
---|
| 161 | sn: Myname |
---|
| 162 | givenName: Myfirstname |
---|
| 163 | address.streetAddress: 5th Avenue, 123 |
---|
| 164 | |
---|
| 165 | Multiple objects of same type can be given a key between C<[]>, this key may |
---|
| 166 | use any letter C<a-z>, C<A-Z> or number C<0-9>. |
---|
| 167 | |
---|
| 168 | sn: Myname |
---|
| 169 | givenName: Myfirstname |
---|
| 170 | address[0].streetAddress: 5th Avenue, 123 |
---|
| 171 | address[aa].streetAddress: 5th Avenue, 123 |
---|
| 172 | |
---|
[991] | 173 | =head1 TOOLS LIST |
---|
| 174 | |
---|
[993] | 175 | The tools listed bellow are availlable to administrate the C<Link::Accounts> |
---|
| 176 | system. |
---|
[991] | 177 | |
---|
[993] | 178 | They are low level tools and are designed to be used system administrator, not |
---|
| 179 | end user (unlike the web interface). |
---|
| 180 | |
---|
| 181 | =head2 Configuration Tools |
---|
| 182 | |
---|
| 183 | =over 4 |
---|
| 184 | |
---|
| 185 | =item la-config |
---|
| 186 | |
---|
| 187 | Display configuration information. |
---|
| 188 | |
---|
[1010] | 189 | L<la-config> |
---|
[993] | 190 | |
---|
| 191 | =item la-attributes |
---|
| 192 | |
---|
| 193 | Display supported object and attributes. |
---|
| 194 | |
---|
[1010] | 195 | L<la-attributes> |
---|
[993] | 196 | |
---|
| 197 | =item la-log-test |
---|
| 198 | |
---|
| 199 | Send message using log functions (for testing purpose) |
---|
| 200 | |
---|
[1010] | 201 | L<la-log-test> |
---|
[993] | 202 | |
---|
| 203 | =item la-acls |
---|
| 204 | |
---|
| 205 | Check validity of ACL file (eg L<la-acls.ini>). |
---|
| 206 | |
---|
[1010] | 207 | See: L<la-acls> |
---|
[993] | 208 | |
---|
| 209 | =item la-qacls |
---|
| 210 | |
---|
| 211 | Test ACLs permission for given user over given object. |
---|
| 212 | |
---|
[1010] | 213 | See: L<la-qacls> |
---|
[993] | 214 | |
---|
| 215 | =back |
---|
| 216 | |
---|
| 217 | =head2 Base Content Tools |
---|
| 218 | |
---|
| 219 | =over 4 |
---|
| 220 | |
---|
[1008] | 221 | =item la-cli |
---|
[993] | 222 | |
---|
[1008] | 223 | Interactive command line interface, include online help, completion, etc... |
---|
[993] | 224 | |
---|
[1010] | 225 | See L<la-cli> |
---|
[993] | 226 | |
---|
[1008] | 227 | =item la-create |
---|
[993] | 228 | |
---|
[1008] | 229 | Create an object into main base. |
---|
[993] | 230 | |
---|
[1010] | 231 | See L<la-create> |
---|
[993] | 232 | |
---|
[1008] | 233 | =item la-delete |
---|
| 234 | |
---|
| 235 | Delete an object from main base |
---|
| 236 | |
---|
[1010] | 237 | See L<la-delete> |
---|
[1008] | 238 | |
---|
| 239 | =item la-edit |
---|
| 240 | |
---|
| 241 | Modify object into main base. |
---|
| 242 | |
---|
[1010] | 243 | See L<la-edit> |
---|
[1008] | 244 | |
---|
[993] | 245 | =item L<la-expired-reminder> |
---|
| 246 | |
---|
| 247 | |
---|
| 248 | =item L<la-graph.pl> |
---|
| 249 | |
---|
| 250 | =item L<la-group> |
---|
| 251 | |
---|
| 252 | =item L<la-guser> |
---|
| 253 | |
---|
[1323] | 254 | =item L<la-passwd> |
---|
[993] | 255 | |
---|
[1008] | 256 | Change the password of users. |
---|
[993] | 257 | |
---|
| 258 | =item L<la-query> |
---|
| 259 | |
---|
[1323] | 260 | The basic tools to query any database |
---|
| 261 | |
---|
[993] | 262 | =item L<la-rename> |
---|
| 263 | |
---|
[1323] | 264 | Allow to rename an object in all configured base simultaneously, then avoiding |
---|
| 265 | a deletion and a creation potentially destructive in some base. |
---|
[993] | 266 | |
---|
[1323] | 267 | To use carrefully |
---|
[993] | 268 | |
---|
| 269 | =item L<la-search> |
---|
| 270 | |
---|
[1323] | 271 | Search object into base. |
---|
| 272 | |
---|
[993] | 273 | =item L<la-sync> |
---|
| 274 | |
---|
| 275 | =item L<la-sync-manager> |
---|
| 276 | |
---|
| 277 | =item L<la-sync-process> |
---|
| 278 | |
---|
| 279 | =item L<la-warn-expire> |
---|
| 280 | |
---|
| 281 | =item L<la-test-mail> |
---|
| 282 | |
---|
| 283 | =back |
---|
| 284 | |
---|
[1008] | 285 | =head2 SQL Base Tools |
---|
[991] | 286 | |
---|
[1323] | 287 | =head3 Common tools |
---|
| 288 | |
---|
[993] | 289 | =over 4 |
---|
| 290 | |
---|
[1323] | 291 | =item L<la-sql-freeip> |
---|
[993] | 292 | |
---|
[1323] | 293 | Return an unallocated IP address from the given DHCP zone. |
---|
[993] | 294 | |
---|
[1323] | 295 | =back |
---|
[993] | 296 | |
---|
[1323] | 297 | =head3 Maintenance tools |
---|
[993] | 298 | |
---|
[1323] | 299 | =over 4 |
---|
[993] | 300 | |
---|
[1323] | 301 | =item L<la-sql-rev> |
---|
| 302 | |
---|
[1324] | 303 | Give the latest internal revision of the base. The revision is a counter |
---|
| 304 | increase when database is changed. |
---|
| 305 | |
---|
[1323] | 306 | =item L<la-sql-upgrade> |
---|
| 307 | |
---|
[1324] | 308 | Upgrade the schema of the SQL database |
---|
[1323] | 309 | |
---|
[1008] | 310 | =item L<la-sql-crypt-passwd> |
---|
| 311 | |
---|
[1324] | 312 | Tools to managed the reversible encryptage of passaword. |
---|
[1008] | 313 | |
---|
[1323] | 314 | =item L<la-rename-host> |
---|
| 315 | |
---|
[1324] | 316 | Rename an network host |
---|
| 317 | |
---|
[1323] | 318 | =item L<la-sql-exchange-hostname> |
---|
| 319 | |
---|
[1324] | 320 | Exchange the name between two hosts. |
---|
| 321 | |
---|
| 322 | =item L<la-sql-exchange-ip> |
---|
| 323 | |
---|
| 324 | Exchange two ip address between different hosts. |
---|
| 325 | |
---|
| 326 | =item L<la-sql-find-expired> |
---|
| 327 | |
---|
[1323] | 328 | =item L<la-sql-edit-form> |
---|
| 329 | |
---|
| 330 | =item L<la-sql-list-request> |
---|
| 331 | |
---|
[1324] | 332 | =item L<la-sql-valid-request> |
---|
| 333 | |
---|
[993] | 334 | =back |
---|
| 335 | |
---|
[2320] | 336 | =head1 ENVIRONMENT VARIABLES |
---|
| 337 | |
---|
| 338 | =head2 LA_DEBUG |
---|
| 339 | |
---|
| 340 | When set print a lot of debug message |
---|
| 341 | |
---|
| 342 | =head2 LA_ACL_DEBUG |
---|
| 343 | |
---|
| 344 | Print debug message about ACL processing. LA_DEBUG must be set to see |
---|
| 345 | ACL messages |
---|
| 346 | |
---|
| 347 | =head2 LA_USERNAME |
---|
| 348 | |
---|
| 349 | The user UID set into this variable will be used as logged user. |
---|
| 350 | If set ACL will always be used. |
---|
| 351 | |
---|
| 352 | =head2 LA_NO_COMMIT |
---|
| 353 | |
---|
| 354 | If set no commit will be done in the database. |
---|
| 355 | |
---|
[1008] | 356 | =head1 BUGS |
---|
| 357 | |
---|
[991] | 358 | =head1 AUTHOR |
---|
| 359 | |
---|
| 360 | Olivier Thauvin <olivier.thauvin@latmos.ipsl.fr> |
---|