
ÂÂ­ÂÂ­ÂÂ­ÂÂ­ÂÂ­ÂÂ­ÂÂ­ÂÂ­ÂÂ­ÂÂ­ÂÂ­ÂÂ­ÂÂ­ÂÂ­ÂÂ­ÂÂ­ÂÂ­ÂÂ­
<!DOCTYPE html>
<html>
3
u
hjS£  ã               @   sX   d dl Z d dlZdZdZejeeddZe jd  dkr>ejZnejZG dd„ deƒZ	dS )	é    NZ
sss_daemonz/usr/share/localeT)Zfallbacké   c            º  @   sÌ  e Zd Zdd„ Zedƒedƒedƒedƒedƒedƒedƒed	ƒed
ƒedƒedƒedƒedƒedƒedƒedƒedƒedƒedƒedƒedƒedƒedƒedƒedƒedƒedƒedƒedƒedƒed ƒed!ƒed"ƒed#ƒed$ƒed%ƒed&ƒed'ƒed(ƒed)ƒed*ƒed+ƒed,ƒed-ƒed.ƒed/ƒed0ƒed1ƒed2ƒed3ƒed4ƒed5ƒed6ƒed7ƒed8ƒed9ƒed:ƒed;ƒed<ƒed=ƒed>ƒed?ƒed@ƒedAƒedBƒedCƒedDƒedEƒedFƒedGƒedHƒedIƒedJƒedKƒedLƒedMƒedNƒedOƒedPƒedQƒedRƒedSƒed#ƒedTƒedUƒedVƒedWƒedXƒedYƒedZƒed[ƒed\ƒed]ƒed^ƒed_ƒed`ƒedaƒedbƒedcƒeddƒedeƒedfƒedgƒedhƒediƒedjƒedkƒedlƒedmƒednƒedoƒedpƒedqƒedrƒedsƒedtƒeduƒedvƒedwƒedxƒedyƒedzƒed{ƒed|ƒed}ƒedtƒedtƒedtƒedtƒedtƒedtƒedtƒed~ƒedƒed€ƒedƒed‚ƒedƒƒed„ƒed…ƒed†ƒed‡ƒedˆƒed‰ƒedŠƒed‹ƒedŒƒedƒedŽƒedƒedƒed‘ƒed’ƒed“ƒed”ƒed•ƒed–ƒed—ƒed˜ƒed™ƒedšƒedƒed‚ƒed›ƒedœƒedƒedžƒedŸƒed ƒed¡ƒed¢ƒed£ƒed¤ƒed¥ƒed¦ƒed§ƒed¨ƒed©ƒedªƒed«ƒed¬ƒed­ƒed®ƒed¯ƒed°ƒed±ƒed²ƒed³ƒed´ƒedµƒed¶ƒed·ƒed¸ƒed¹ƒedºƒed»ƒed¼ƒed½ƒed¾ƒed¿ƒedÀƒed°ƒedÁƒedÂƒedÃƒedÄƒedÅƒedÆƒedÇƒedÈƒedÉƒedÊƒedËƒed¢ƒedÌƒedÍƒedÎƒedÏƒedÐƒedÑƒedÒƒedÓƒedÔƒedÕƒedÖƒed×ƒedØƒedÙƒedÚƒedÛƒedÜƒedÝƒedÞƒedÞƒedßƒedàƒedáƒedâƒedãƒedäƒedåƒedæƒedçƒedèƒedéƒedêƒedëƒedìƒedíƒedîƒedïƒedðƒedñƒedòƒedóƒedóƒedôƒedõƒedöƒed÷ƒedøƒedùƒedúƒedûƒedüƒedýƒedþƒedÿƒed ƒedƒedƒedƒedƒedƒedƒedƒedƒed	ƒed
ƒedƒedƒedƒedƒedƒedƒedƒedƒedƒedƒedƒedƒedƒedƒedƒedƒedƒedƒedƒedƒedƒed ƒed!ƒed"ƒed#ƒed$ƒed%ƒed&ƒed'ƒed(ƒed)ƒed*ƒed+ƒed,ƒed-ƒed.ƒed/ƒed0ƒed1ƒed2ƒed3ƒed4ƒed5ƒed6ƒed7ƒed8ƒed9ƒed:ƒed;ƒed<ƒed=ƒed>ƒed?ƒed@ƒedAƒedBƒedCƒedDƒedEƒedFƒedGƒedHƒedIƒedJƒedKƒedLƒedMƒedNƒedOƒedPƒedQƒedRƒedSƒed.ƒedTƒedUƒedVƒedWƒedXƒedYƒedZƒed[ƒed\ƒed]ƒed^ƒed_ƒed`ƒedaƒedbƒedcƒeddƒedeƒedfƒedgƒedhƒediƒedjƒedkƒedlƒedmƒednƒedoƒedpƒedqƒedrƒedÌƒedsƒed®ƒedtƒeduƒedvƒedwƒedxƒedyƒedzƒed{ƒed|ƒed}ƒed~ƒedƒed€ƒedƒed‚ƒedƒƒed„ƒed…ƒed†ƒed‡ƒedˆƒed‰ƒedŠƒed‹ƒedŒƒedƒedŽƒedƒedƒed‘ƒed’ƒed“ƒed”ƒed•ƒed–ƒed—ƒed˜ƒed™ƒedšƒed›ƒedœƒedƒedžƒedŸƒed ƒed¡ƒed¢ƒed£ƒed¤ƒed¥ƒed¦ƒed§ƒed¨ƒed©ƒdªœ¹Zd«S (¬  ÚSSSDOptionsc             C   s   d S )N© )Úselfr   r   ú!/usr/lib/python3.6/sssdoptions.pyÚ__init__   s    zSSSDOptions.__init__z&Set the verbosity of the debug loggingz Include timestamps in debug logsz0Include microseconds in timestamps in debug logszEnable/disable debug backtracez*Watchdog timeout before restarting servicezCommand to start servicez7Number of times to attempt connection to Data ProviderszCThe number of file descriptors that may be opened by this responderz4Idle time before automatic disconnection of a clientz4Idle time before automatic shutdown of the responderz>Always query all the caches before querying the Data ProviderszèWhen SSSD switches to offline mode the amount of time before it tries to go back online will increase based upon the time spent disconnected. This value is in seconds and calculated by the following: offline_timeout + random_offset.zTIndicates what is the syntax of the config file. SSSD 0.6.0 and later use version 2.zSSSD Services to startzSSSD Domains to startz"Regex to parse username and domainz=Printf-compatible format for displaying fully-qualified nameszPDirectory on the filesystem where SSSD should store Kerberos replay cache files.z2Domain to add to names without a domain component.zThe user to drop privileges tozTune certificate verificationzFAll spaces in group or user names will be replaced with this characterz2Tune sssd to honor or ignore netlink state changesz+Enable or disable the implicit files domainz/A specific order of the domains to be looked upzwControls if SSSD should monitor the state of resolv.conf to identify when it needs to update its internal DNS resolver.zòSSSD monitors the state of resolv.conf to identify when it needs to update its internal DNS resolver. By default, we will attempt to use inotify for this, and will fall back to polling resolv.conf every five seconds if inotify cannot be used.z7Run PAC responder automatically for AD and IPA providerz4Enable or disable core dumps for all SSSD processes.z"Tune passkey verification behaviorz*Enumeration cache timeout length (seconds)z6Entry cache background update timeout length (seconds)z'Negative cache timeout length (seconds)z-Files negative cache timeout length (seconds)z(Users that SSSD should explicitly ignorez)Groups that SSSD should explicitly ignorez&Should filtered users appear in groupsz>The value of the password field the NSS provider should returnzAOverride homedir value from the identity provider with this valuezISubstitute empty homedir value from the identity provider with this valuez?Override shell value from the identity provider with this valuez3The list of shells users are allowed to log in withzLThe list of shells that will be vetoed, and replaced with the fallback shellzVIf a shell stored in central directory is allowed but not available, use this fallbackz.Shell to use if the provider does not list onez.How long will be in-memory cache records validz_Size (in megabytes) of the data table allocated inside fast in-memory cache for passwd requestsz^Size (in megabytes) of the data table allocated inside fast in-memory cache for group requestszcSize (in megabytes) of the data table allocated inside fast in-memory cache for initgroups requestsz„The value of this option will be used in the expansion of the override_homedir option if the template contains the format string %H.zTSpecifies time in seconds for which the list of subdomains will be considered valid.z§The entry cache can be set to automatically update entries in the background if they are requested beyond a percentage of the entry_cache_timeout value for the domain.z<How long to allow cached logins between online logins (days)z8How many failed logins attempts are allowed when offlinezUHow long (minutes) to deny login after offline_failed_login_attempts has been reachedzEWhat kind of messages are displayed to the user during authenticationz(Filter PAM responses sent to the pam_ssszEHow many seconds to keep identity information cached for PAM requestszFHow many days before password expiration a warning should be displayedz#List of trusted uids or user's namez4List of domains accessible even for untrusted users.z-Message printed when user account is expired.z,Message printed when user account is locked.z1Allow certificate based/Smartcard authentication.z2Path to certificate database with PKCS#11 modules.z5Tune certificate verification for PAM authentication.z:How many seconds will pam_sss wait for p11_child to finishz?Which PAM services are permitted to contact application domainsz%Allowed services for using smartcardsz2Additional timeout to wait for a card if requestedzMPKCS#11 URI to restrict the selection of devices for Smartcard authenticationz8When shall the PAM responder force an initgroups requestzBList of PAM services that are allowed to authenticate with GSSAPI.z3Whether to match authenticated UPN with target userzvList of pairs <PAM service>:<authentication indicator> that must be enforced for PAM access with GSSAPI authenticationz$Allow passkey device authentication.z>How many seconds will pam_sss wait for passkey_child to finishz(Enable debugging in the libfido2 libraryz;Whether to evaluate the time-based attributes in sudo rulesz;If true, SSSD will switch back to lower-wins ordering logiczfMaximum number of rules that can be refreshed at once. If this is exceeded, full refresh is performed.z@Whether to hash host names and addresses in the known_hosts filezZHow many seconds to keep a host in the known_hosts file after its host keys were requestedz*Path to storage of trusted CA certificatesz,Allow to generate ssh-keys from certificateszRUse the following matching rules to filter the certificates for ssh-key generationz>List of UIDs or user names allowed to access the PAC responderz)How long the PAC data is considered validzValidate the PACz:List of user attributes the InfoPipe is allowed to publishzËOne of the following strings specifying the scope of session recording: none - No users are recorded. some - Users/groups specified by users and groups options are recorded. all - All users are recorded.z±A comma-separated list of users which should have session recording enabled. Matches user names as returned by NSS. I.e. after the possible space replacement, case changes, etc.z¿A comma-separated list of groups, members of which should have session recording enabled. Matches group names as returned by NSS. I.e. after the possible space replacement, case changes, etc.zRA comma-separated list of users to be excluded from recording, only when scope=allzlA comma-separated list of groups, members of which should be excluded from recording,  only when scope=all. zIdentity providerzAuthentication providerzAccess control providerzPassword change providerzSUDO providerzAutofs providerzHost identity providerzSELinux providerzSession management providerzResolver providerz9Whether the domain is usable by the OS or by applicationszEnable or disable the domainzMinimum user IDzMaximum user IDz#Enable enumerating all users/groupsz#Cache credentials for offline loginz,Display users/groups in fully-qualified formz,Don't include group members in group lookupsz$Entry cache timeout length (seconds)zHRestrict or prefer a specific address family when performing DNS lookupszBHow long to keep cached entries after last successful login (days)zVHow long should SSSD talk to single DNS server before trying next server (miliseconds)zAHow long should keep trying to resolve single DNS query (seconds)zFHow long to wait for replies from DNS when resolving servers (seconds)z.The domain part of service discovery DNS queryzkHow often SSSD tries to reconnect to the primary server after a successful connection to the backup server.z=Override GID value from the identity provider with this valuez!Treat usernames as case sensitivez;How often should expired entries be refreshed in backgroundzFMaximum period deviation when refreshing expired entries in backgroundz6Whether to automatically update the client's DNS entryz<The TTL to apply to the client's DNS entry after updating itz=The interface whose IP should be used for dynamic DNS updatesz7How often to periodically update the client's DNS entryz=Maximum period deviation when updating the client's DNS entryzDWhether the provider should explicitly update the PTR record as wellz8Whether the nsupdate utility should default to using TCPzDWhat kind of authentication should be used to perform the DNS updatez6Override the DNS server used to perform the DNS updatez&Control enumeration of trusted domainsz-How often should subdomains list be refreshedz;Maximum period deviation when refreshing the subdomain listz9List of options that should be inherited into a subdomainzDefault subdomain homedir valuezAHow long can cached credentials be used for cached authenticationz8Whether to automatically create private groups for usersz5Display a warning N days before the password expires.zHVarious tags stored by the realmd configuration service for this domain.zmThe provider which should handle fetching of subdomains. This value should be always the same as id_provider.z]How many seconds to keep a host ssh key after refresh. IE how long to cache the host key for.zÛIf 2-Factor-Authentication (2FA) is used and credentials should be saved this value determines the minimal length the first authentication factor (long term password) must have to be saved as SHA512 hash into the cache.z$Local authentication methods policy z
IPA domainzIPA server addresszAddress of backup IPA serverzIPA client hostnamezAWhether to automatically update the client's DNS entry in FreeIPAz$Search base for HBAC related objectszKThe amount of time between lookups of the HBAC rules against the IPA serverzXThe amount of time in seconds between lookups of the SELinux maps against the IPA serverz;If set to false, host argument given by PAM will be ignoredz1The automounter location this IPA client is usingz7Search base for object containing info about IPA domainz7Search base for objects containing info about ID rangesz3Enable DNS sites - location based service discoveryzSearch base for view containerszObjectclass for view containersz#Attribute with the name of the viewz Objectclass for override objectsz3Attribute with the reference to the original objectz%Objectclass for user override objectsz&Objectclass for group override objectsz/Search base for Desktop Profile related objectszaThe amount of time in seconds between lookups of the Desktop Profile rules against the IPA serverzŠThe amount of time in minutes between lookups of Desktop Profiles rules against the IPA server when the last request did not find any rulezSearch base for SUBID rangesz5Which rules should be used to evaluate access controlz2The LDAP attribute that contains FQDN of the host.z)The object class of a host entry in LDAP.z5Use the given string as search base for host objects.z<The LDAP attribute that contains the host's SSH public keys.zAThe LDAP attribute that contains NIS domain name of the netgroup.zEThe LDAP attribute that contains the names of the netgroup's members.z^The LDAP attribute that lists FQDNs of hosts and host groups that are members of the netgroup.z\The LDAP attribute that lists hosts and host groups that are direct members of the netgroup.z5The LDAP attribute that lists netgroup's memberships.z^The LDAP attribute that lists system users and groups that are direct members of the netgroup.z9The LDAP attribute that corresponds to the netgroup name.z-The object class of a netgroup entry in LDAP.zJThe LDAP attribute that contains the UUID/GUID of an LDAP netgroup object.zNThe LDAP attribute that contains whether or not is user map enabled for usage.z=The LDAP attribute that contains host category such as 'all'.zPThe LDAP attribute that contains all hosts / hostgroups this rule match against.zLThe LDAP attribute that contains all users / groups this rule match against.z=The LDAP attribute that contains the name of SELinux usermap.zuThe LDAP attribute that contains DN of HBAC rule which can be used for matching instead of memberUser and memberHost.z<The LDAP attribute that contains SELinux user string itself.z=The LDAP attribute that contains user category such as 'all'.z;The LDAP attribute that contains unique ID of the user map.zŠThe option denotes that the SSSD is running on IPA server and should perform lookups of users and groups from trusted domains differently.z8Use the given string as search base for trusted domains.zActive Directory domainz Enabled Active Directory domainszActive Directory server addressz&Active Directory backup server addressz Active Directory client hostnamez*LDAP filter to determine access privilegesz-Whether to use the Global Catalog for lookupsz+Operation mode for GPO-based access controlzPThe amount of time between lookups of the GPO policy files against the AD serverzQPAM service names that map to the GPO (Deny)InteractiveLogonRight policy settingszWPAM service names that map to the GPO (Deny)RemoteInteractiveLogonRight policy settingszMPAM service names that map to the GPO (Deny)NetworkLogonRight policy settingszKPAM service names that map to the GPO (Deny)BatchLogonRight policy settingszMPAM service names that map to the GPO (Deny)ServiceLogonRight policy settingsz>PAM service names for which GPO-based access is always grantedz=PAM service names for which GPO-based access is always deniedzJDefault logon right (or permit/deny) to use for unmapped PAM service namesz*a particular site to be used by the clientzIMaximum age in days before the machine account password should be renewedz2Option for tuning the machine account renewal taskzDWhether to update the machine account password in the Samba databasez3Use LDAPS port for LDAP and Global Catalog requestsz4Do not filter domain local groups from other domainszKerberos server addresszKerberos backup server addresszKerberos realmzAuthentication timeoutzWhether to create kdcinfo filesz"Where to drop krb5 config snippetsz$Directory to store credential cachesz'Location of the user's credential cachez.Location of the keytab to validate credentialszEnable credential validationz9Store password if offline for later online authenticationzRenewable lifetime of the TGTzLifetime of the TGTz#Time between two checks for renewalzEnables FASTz%Selects the principal to use for FASTz0Use anonymous PKINIT to request FAST credentialsz"Enables principal canonicalizationzEnables enterprise principalsz5Enables using of subdomains realms for authenticationz5A mapping from user names to Kerberos principal nameszEServer where the change password service is running if not on the KDCz$ldap_uri, The URI of the LDAP serverz+ldap_backup_uri, The URI of the LDAP serverzThe default base DNz2The Schema Type in use on the LDAP server, rfc2307z!Mode used to change user passwordzThe default bind DNz;The type of the authentication token of the default bind DNz/The authentication token of the default bind DNz$Length of time to attempt connectionz5Length of time to attempt synchronous LDAP operationsz:Length of time between attempts to reconnect while offlinez'Use only the upper case for realm namesz"File that contains CA certificatesz Path to CA certificate directoryz)File that contains the client certificatez!File that contains the client keyzList of possible ciphers suitesz$Require TLS certificate verificationz!Specify the sasl mechanism to usez(Specify the sasl authorization id to usez+Specify the sasl authorization realm to usez3Specify the minimal SSF for LDAP sasl authorizationz3Specify the maximal SSF for LDAP sasl authorizationzKerberos service keytabz%Use Kerberos auth for LDAP connectionzFollow LDAP referralsz#Lifetime of TGT for LDAP connectionzHow to dereference aliasesz$Service name for DNS service lookupsz8The number of records to retrieve in a single LDAP queryzBThe number of members that must be missing to trigger a full derefz!Ignore unreadable LDAP referencesziWhether the LDAP library should perform a reverse lookup to canonicalize the host name during a SASL bindzaAllows to retain local users as members of an LDAP group for servers that use the RFC2307 schema.zentryUSN attributezlastUSN attributezGHow long to retain a connection to the LDAP server before disconnectingzDisable the LDAP paging controlz(Disable Active Directory range retrievalz+Length of time to wait for a search requestz0Length of time to wait for a enumeration requestz*Length of time between enumeration updatesz4Maximum period deviation between enumeration updatesz%Length of time between cache cleanupsz-Maximum time deviation between cache cleanupszRequire TLS for ID lookupsz2Use ID-mapping of objectSID instead of pre-set IDszBase DN for user lookupszScope of user lookupszFilter for user lookupszObjectclass for userszUsername attributezUID attributezPrimary GID attributezGECOS attributezHome directory attributezShell attributezUUID attributezobjectSID attributez7Active Directory primary group attribute for ID-mappingz'User principal attribute (for Kerberos)z	Full NamezmemberOf attributezModification time attributezshadowLastChange attributezshadowMin attributezshadowMax attributezshadowWarning attributezshadowInactive attributezshadowExpire attributezshadowFlag attributez)Attribute listing authorized PAM servicesz)Attribute listing authorized server hostsz*Attribute listing authorized server rhostszkrbLastPwdChange attributezkrbPasswordExpiration attributezBAttribute indicating that server side password policies are activezaccountExpires attribute of ADz"userAccountControl attribute of ADznsAccountLock attributezloginDisabled attribute of NDSz$loginExpirationTime attribute of NDSz$loginAllowedTimeMap attribute of NDSzSSH public key attributez9attribute listing allowed authentication types for a userz5attribute containing the X509 certificate of the userz2attribute containing the email address of the userz9attribute containing the passkey mapping data of the userz@A list of extra attributes to download along with the user entryzBase DN for group lookupszObjectclass for groupsz
Group namezGroup passwordzGID attributezGroup member attributezGroup UUID attributez&Modification time attribute for groupsz!Type of the group and other flagsz(The LDAP group external member attributez&Maximum nesting level SSSD will followzFilter for group lookupszScope of group lookupszBase DN for netgroup lookupszObjectclass for netgroupszNetgroup namezNetgroups members attributezNetgroup triple attributez)Modification time attribute for netgroupszBase DN for service lookupszObjectclass for serviceszService name attributezService port attributezService protocol attributezLower bound for ID-mappingzUpper bound for ID-mappingz,Number of IDs for each slice when ID-mappingz/Use autorid-compatible algorithm for ID-mappingz)Name of the default domain for ID-mappingz(SID of the default domain for ID-mappingzNumber of secondary sliceszWhether to use Token-Groupsz7Set lower boundary for allowed IDs from the LDAP serverz7Set upper boundary for allowed IDs from the LDAP serverzDN for ppolicy queriesz;How many maximum entries to fetch during a wildcard requestzSet libldap debug levelz*Policy to evaluate the password expirationzCWhich attributes shall be used to evaluate if an account is expiredz8URI of an LDAP server where password changes are allowedz>URI of a backup LDAP server where password changes are allowedz0DNS service name for LDAP password change serverzTWhether to update the ldap_user_shadow_last_change attribute after a password changezBase DN for sudo rules lookupszAutomatic full refresh periodzAutomatic smart refresh periodz$Smart and full refresh random offsetz=Whether to filter rules by hostname, IP addresses and networkzRHostnames and/or fully qualified domain names of this machine to filter sudo ruleszFIPv4 or IPv6 addresses or network of this machine to filter sudo ruleszAWhether to include rules that contains netgroup in host attributezKWhether to include rules that contains regular expression in host attributezObject class for sudo rulesz=Name of attribute that is used as object class for sudo ruleszSudo rule namezSudo rule command attributezSudo rule host attributezSudo rule user attributezSudo rule option attributezSudo rule runas attributezSudo rule runasuser attributezSudo rule runasgroup attributezSudo rule notbefore attributezSudo rule notafter attributezSudo rule order attributez!Object class for automounter mapszAutomounter map name attributez(Object class for automounter map entriesz#Automounter map entry key attributez%Automounter map entry value attributez#Base DN for automounter map lookupsz-The name of the automount master map in LDAP.zBase DN for IP hosts lookupszObject class for IP hostszIP host name attributez"IP host number (address) attributezIP host entryUSN attributezBase DN for IP networks lookupszObject class for IP networkszIP network name attributez%IP network number (address) attributezIP network entryUSN attributez%Comma separated list of allowed usersz(Comma separated list of prohibited userszComma separated list of groups that are allowed to log in. This applies only to groups within this SSSD domain. Local groups are not evaluated.z–Comma separated list of groups that are explicitly denied access. This applies only to groups within this SSSD domain. Local groups are not evaluated.z'The number of preforked proxy children.z"The name of the NSS library to usezAThe name of the NSS library to use for hosts and networks lookupsz>Whether to look up canonical group name from cache if possiblezPAM stack to usezPath of passwd file sources.zPath of group file sources.(¹  ÚdebugZdebug_levelZdebug_timestampsZdebug_microsecondsZdebug_backtrace_enabledZtimeoutZcommandZreconnection_retriesZfd_limitZclient_idle_timeoutZresponder_idle_timeoutZcache_firstZoffline_timeoutZconfig_file_versionZservicesZdomainsZre_expressionZfull_name_formatZkrb5_rcache_dirZdefault_domain_suffixÚuserZcertificate_verificationZoverride_spaceZdisable_netlinkZenable_files_domainZdomain_resolution_orderZmonitor_resolv_confZtry_inotifyZimplicit_pac_responderZcore_dumpableZpasskey_verificationZenum_cache_timeoutZentry_cache_no_wait_timeoutZentry_negative_timeoutZlocal_negative_timeoutZfilter_usersZfilter_groupsZfilter_users_in_groupsZpwfieldZoverride_homedirZfallback_homedirZoverride_shellZallowed_shellsZvetoed_shellsZshell_fallbackZdefault_shellZmemcache_timeoutZmemcache_size_passwdZmemcache_size_groupZmemcache_size_initgroupsZhomedir_substringZget_domains_timeoutZentry_cache_nowait_percentageZoffline_credentials_expirationZoffline_failed_login_attemptsZoffline_failed_login_delayZpam_verbosityZpam_response_filterZpam_id_timeoutZpam_pwd_expiration_warningZpam_trusted_usersZpam_public_domainsZpam_account_expired_messageZpam_account_locked_messageZpam_cert_authZpam_cert_db_pathZpam_cert_verificationZp11_child_timeoutZpam_app_servicesZpam_p11_allowed_servicesZp11_wait_for_card_timeoutZp11_uriZpam_initgroups_schemeZpam_gssapi_servicesZpam_gssapi_check_upnZpam_gssapi_indicators_mapZpam_passkey_authZpasskey_child_timeoutZpasskey_debug_libfido2Z
sudo_timedZsudo_inverse_orderZsudo_thresholdZautofs_negative_timeoutZssh_hash_known_hostsZssh_known_hosts_timeoutZca_dbZssh_use_certificate_keysZ"ssh_use_certificate_matching_rulesZallowed_uidsZpac_lifetimeZ	pac_checkZuser_attributesZscopeZusersÚgroupsZexclude_usersZexclude_groupsZid_providerZauth_providerZaccess_providerZchpass_providerZsudo_providerZautofs_providerZhostid_providerZselinux_providerZsession_providerZresolver_providerZdomain_typeZenabledZmin_idZmax_idÚ	enumerateZcache_credentialsZuse_fully_qualified_namesZignore_group_membersZentry_cache_timeoutZlookup_family_orderZaccount_cache_expirationZdns_resolver_server_timeoutZdns_resolver_op_timeoutZdns_resolver_timeoutZdns_discovery_domainZfailover_primary_timeoutZoverride_gidZcase_sensitiveZentry_cache_user_timeoutZentry_cache_group_timeoutZentry_cache_netgroup_timeoutZentry_cache_service_timeoutZentry_cache_autofs_timeoutZentry_cache_sudo_timeoutZentry_cache_resolver_timeoutZrefresh_expired_intervalZrefresh_expired_interval_offsetZdyndns_updateZ
dyndns_ttlZdyndns_ifaceZdyndns_refresh_intervalZdyndns_refresh_interval_offsetZdyndns_update_ptrZdyndns_force_tcpZdyndns_authZdyndns_serverZsubdomain_enumerateZsubdomain_refresh_intervalZ!subdomain_refresh_interval_offsetZsubdomain_inheritZsubdomain_homedirZcached_auth_timeoutZauto_private_groupsZpwd_expiration_warningZrealmd_tagsZsubdomains_providerZentry_cache_ssh_host_timeoutZ-cache_credentials_minimal_first_factor_lengthZlocal_auth_policyZ
ipa_domainZ
ipa_serverZipa_backup_serverZipa_hostnameZipa_dyndns_updateZipa_dyndns_ttlZipa_dyndns_ifaceZipa_hbac_search_baseZipa_hbac_refreshZipa_selinux_refreshZipa_hbac_support_srchostZipa_automount_locationZipa_master_domain_search_baseZipa_ranges_search_baseZipa_enable_dns_sitesZipa_views_search_baseZipa_view_classZipa_view_nameZipa_override_object_classZipa_anchor_uuidZipa_user_override_object_classZipa_group_override_object_classZipa_deskprofile_search_baseZipa_deskprofile_refreshZ ipa_deskprofile_request_intervalZipa_subid_ranges_search_baseZipa_access_orderZipa_host_fqdnZipa_host_object_classZipa_host_search_baseZipa_host_ssh_public_keyZipa_netgroup_domainZipa_netgroup_memberZipa_netgroup_member_ext_hostZipa_netgroup_member_hostZipa_netgroup_member_ofZipa_netgroup_member_userZipa_netgroup_nameZipa_netgroup_object_classZipa_netgroup_uuidZipa_selinux_usermap_enabledZ!ipa_selinux_usermap_host_categoryZipa_selinux_usermap_member_hostZipa_selinux_usermap_member_userZipa_selinux_usermap_nameZ ipa_selinux_usermap_object_classZipa_selinux_usermap_see_alsoZ ipa_selinux_usermap_selinux_userZ!ipa_selinux_usermap_user_categoryZipa_selinux_usermap_uuidZipa_server_modeZipa_subdomains_search_baseZ	ad_domainZad_enabled_domainsZ	ad_serverZad_backup_serverZad_hostnameZad_enable_dns_sitesZad_access_filterZad_enable_gcZad_gpo_access_controlZad_gpo_cache_timeoutZad_gpo_map_interactiveZad_gpo_map_remote_interactiveZad_gpo_map_networkZad_gpo_map_batchZad_gpo_map_serviceZad_gpo_map_permitZad_gpo_map_denyZad_gpo_default_rightZad_siteZ'ad_maximum_machine_account_password_ageZ(ad_machine_account_password_renewal_optsZ(ad_update_samba_machine_account_passwordZad_use_ldapsZ#ad_allow_remote_domain_local_groupsZ
krb5_kdcipZkrb5_serverZkrb5_backup_serverZ
krb5_realmZkrb5_auth_timeoutZkrb5_use_kdcinfoZkrb5_confd_pathZkrb5_ccachedirZkrb5_ccname_templateZkrb5_keytabZkrb5_validateZkrb5_store_password_if_offlineZkrb5_renewable_lifetimeZkrb5_lifetimeZkrb5_renew_intervalZkrb5_use_fastZkrb5_fast_principalZkrb5_fast_use_anonymous_pkinitZkrb5_canonicalizeZkrb5_use_enterprise_principalZkrb5_use_subdomain_realmZkrb5_map_userZkrb5_kpasswdZkrb5_backup_kpasswdZldap_uriZldap_backup_uriZldap_search_baseZldap_schemaZldap_pwmodify_modeZldap_default_bind_dnZldap_default_authtok_typeZldap_default_authtokZldap_network_timeoutZldap_opt_timeoutZldap_offline_timeoutZldap_force_upper_case_realmZldap_tls_cacertZldap_tls_cacertdirZldap_tls_certZldap_tls_keyZldap_tls_cipher_suiteZldap_tls_reqcertZldap_sasl_mechZldap_sasl_authidZldap_sasl_realmZldap_sasl_minssfZldap_sasl_maxssfZldap_krb5_keytabZldap_krb5_init_credsZldap_referralsZldap_krb5_ticket_lifetimeZ
ldap_derefZldap_dns_service_nameZldap_page_sizeZldap_deref_thresholdZ!ldap_ignore_unreadable_referencesZldap_sasl_canonicalizeZ$ldap_rfc2307_fallback_to_local_usersZldap_entry_usnZldap_rootdse_last_usnZ"ldap_connection_expiration_timeoutZldap_disable_pagingZldap_disable_range_retrievalZldap_search_timeoutZldap_enumeration_search_timeoutZ ldap_enumeration_refresh_timeoutZldap_enumeration_refresh_offsetZldap_purge_cache_timeoutZldap_purge_cache_offsetZldap_id_use_start_tlsZldap_id_mappingZldap_user_search_baseZldap_user_search_scopeZldap_user_search_filterZldap_user_object_classZldap_user_nameZldap_user_uid_numberZldap_user_gid_numberZldap_user_gecosZldap_user_home_directoryZldap_user_shellZldap_user_uuidZldap_user_objectsidZldap_user_primary_groupZldap_user_principalZldap_user_fullnameZldap_user_member_ofZldap_user_modify_timestampZldap_user_shadow_last_changeZldap_user_shadow_minZldap_user_shadow_maxZldap_user_shadow_warningZldap_user_shadow_inactiveZldap_user_shadow_expireZldap_user_shadow_flagZldap_user_authorized_serviceZldap_user_authorized_hostZldap_user_authorized_rhostZldap_user_krb_last_pwd_changeZ!ldap_user_krb_password_expirationZldap_pwd_attributeZldap_user_ad_account_expiresZ!ldap_user_ad_user_account_controlZldap_ns_account_lockZldap_user_nds_login_disabledZ#ldap_user_nds_login_expiration_timeZ$ldap_user_nds_login_allowed_time_mapZldap_user_ssh_public_keyZldap_user_auth_typeZldap_user_certificateZldap_user_emailZldap_user_passkeyZldap_user_extra_attrsZldap_group_search_baseZldap_group_object_classZldap_group_nameZldap_group_pwdZldap_group_gid_numberZldap_group_memberZldap_group_uuidZldap_group_objectsidZldap_group_modify_timestampZldap_group_typeZldap_group_external_memberZldap_group_nesting_levelZldap_group_search_filterZldap_group_search_scopeZldap_netgroup_search_baseZldap_netgroup_object_classZldap_netgroup_nameZldap_netgroup_memberZldap_netgroup_tripleZldap_netgroup_modify_timestampZldap_service_search_baseZldap_service_object_classZldap_service_nameZldap_service_portZldap_service_protoZldap_idmap_range_minZldap_idmap_range_maxZldap_idmap_range_sizeZldap_idmap_autorid_compatZldap_idmap_default_domainZldap_idmap_default_domain_sidZldap_idmap_helper_table_sizeZldap_use_tokengroupsZldap_min_idZldap_max_idZldap_pwdlockout_dnZwildcard_limitZldap_library_debug_levelZldap_pwd_policyZldap_access_filterZldap_account_expire_policyZldap_access_orderZldap_chpass_uriZldap_chpass_backup_uriZldap_chpass_dns_service_nameZldap_chpass_update_last_changeZldap_sudo_search_baseZldap_sudo_full_refresh_intervalZ ldap_sudo_smart_refresh_intervalZldap_sudo_random_offsetZldap_sudo_use_host_filterZldap_sudo_hostnamesZldap_sudo_ipZldap_sudo_include_netgroupsZldap_sudo_include_regexpZldap_sudorule_object_classZldap_sudorule_object_class_attrZldap_sudorule_nameZldap_sudorule_commandZldap_sudorule_hostZldap_sudorule_userZldap_sudorule_optionZldap_sudorule_runasZldap_sudorule_runasuserZldap_sudorule_runasgroupZldap_sudorule_notbeforeZldap_sudorule_notafterZldap_sudorule_orderZldap_autofs_map_object_classZldap_autofs_map_nameZldap_autofs_entry_object_classZldap_autofs_entry_keyZldap_autofs_entry_valueZldap_autofs_search_baseZldap_autofs_map_master_nameZldap_iphost_search_baseZldap_iphost_object_classZldap_iphost_nameZldap_iphost_numberZldap_iphost_entry_usnZldap_ipnetwork_search_baseZldap_ipnetwork_object_classZldap_ipnetwork_nameZldap_ipnetwork_numberZldap_ipnetwork_entry_usnZsimple_allow_usersZsimple_deny_usersZsimple_allow_groupsZsimple_deny_groupsZproxy_max_childrenZproxy_lib_nameZproxy_resolver_lib_nameZproxy_fast_aliasZproxy_pam_targetZpasswd_filesZgroup_filesN)Ú__name__Ú
__module__Ú__qualname__r   Ú_Zoption_stringsr   r   r   r   r      s~  r   )
ÚsysÚgettextZPACKAGEZ	LOCALEDIRZtranslationÚversion_infor   ZugettextÚobjectr   r   r   r   r   Ú<module>   s   