HEX
Server: Apache
System: Linux hp3-stn-1011028.hostingp3.local 3.10.0-1160.119.1.el7.x86_64 #1 SMP Tue Jun 4 14:43:51 UTC 2024 x86_64
User: csh958633 (951153)
PHP: 8.3.30
Disabled: shell_exec,exec,system,popen,set_time_limit
Upload Files
File: //lib/python2.7/site-packages/SSSDConfig/__init__.pyc
�
F>,_c@s,dZddlZddlZddlZddlZddlmZdefd��YZdefd��YZ	d	efd
��YZ
defd��YZd
efd��YZdefd��YZ
defd��YZdefd��YZdefd��YZdefd��YZdefd��YZdefd��YZdefd��YZdefd ��YZd!efd"��YZd#efd$��YZd%Zd&Zejeed'e�Zejd(d)kr�ejZn	ejZiped*�d+6ed*�d,6ed-�d.6ed/�d06ed1�d26ed3�d46ed5�d66ed7�d86ed9�d:6ed;�d<6ed=�d>6ed?�d@6edA�dB6edC�dD6edE�dF6edG�dH6edI�dJ6edK�dL6edM�dN6edO�dP6edQ�dR6edS�dT6edU�dV6edW�dX6edY�dZ6ed[�d\6ed]�d^6ed_�d`6eda�db6edc�dd6ede�df6edg�dh6edi�dj6edk�dl6edm�dn6edo�dp6edq�dr6eds�dt6edu�dv6edw�dx6edy�dz6ed{�d|6ed}�d~6ed�d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed_�d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d|6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed�d6ed�d6ed��d6ed��d6ed��d6ed��d6ed��d6ed��d	6ed
�d6ed�d
6ed�d6ed�d6ed�d6ed�d6ed�d6ed�d6ed�d6ed�d6ed�d6ed �d!6ed"�d#6ed$�d%6edI�dJ6edG�dH6ed&�d'6ed(�d)6ed*�d+6ed,�d-6ed.�d/6ed0�d16ed�d26ed�d36ed4�d56ed6�d76ed8�d96ed:�d;6ed<�d=6ed>�d?6ed@�dA6edB�dC6edD�dE6edF�dG6edH�dI6edJ�dK6edL�dM6edN�dO6edP�dQ6edR�dS6edT�dU6edV�dW6edX�dY6edZ�d[6ed\�d]6ed^�d_6ed`�da6edB�db6edc�dd6ede�df6edg�dh6edi�dj6edk�dl6edm�dn6edo�dp6edq�dr6eds�dt6edu�dv6edw�dx6edy�dz6ed{�d|6ed}�d~6ed�d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d6ed�d6ed�d6ed�d6ed�d6ed	�d
6ed�d6ed
�d6ed�d6ed�d6ed�d6ed�d6ed�d6ed�d6ed�d6ed�d6ed�d 6ed!�d"6ed#�d$6ed%�d&6ed'�d(6ed)�d*6ed+�d,6ed-�d.6ed/�d06ed1�d26ed3�d46ed5�d66ed7�d86ed9�d:6ed;�d<6ed=�d>6ed?�d@6edA�dB6edC�dD6edE�dF6edG�dH6edI�dJ6edK�dL6edM�dN6edO�dP6edQ�dR6edS�dT6edU�dV6edW�dX6edY�dZ6ed[�d\6ed]�d^6ed_�d`6eda�db6ed�dc6edd�de6edf�dg6edh�di6edj�dk6edl�dm6edn�do6edp�dq6edr�ds6edt�du6edv�dw6edx�dy6edz�d{6ed|�d}6ed~�d6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6edc�d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��dx6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6ed��d�6Zd��Z d��Z!d�efd���YZ"d�e#fd���YZ$d�e$fd���YZ%d�e$fd���YZ&d�efd���YZ'dS(s,
Created on Sep 18, 2009

@author: sgallagh
i����Ni(tSSSDChangeConftSSSDConfigExceptioncBseZRS((t__name__t
__module__(((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyRstParsingErrorcBseZRS((RR(((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyRstAlreadyInitializedErrorcBseZRS((RR(((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyRstNotInitializedErrorcBseZRS((RR(((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyRstNoOutputFileErrorcBseZRS((RR(((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyRstNoServiceErrorcBseZRS((RR(((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyRstNoSectionErrorcBseZRS((RR(((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyR	st
NoOptionErrorcBseZRS((RR(((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyR
stServiceNotRecognizedErrorcBseZRS((RR(((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyRstServiceAlreadyExistscBseZRS((RR(((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyRst
NoDomainErrorcBseZRS((RR(((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyR
stDomainNotRecognizedcBseZRS((RR(((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyRstDomainAlreadyExistsErrorcBseZRS((RR(((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyRstNoSuchProviderErrorcBseZRS((RR(((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyRstNoSuchProviderSubtypeErrorcBseZRS((RR(((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyRstProviderSubtypeInUsecBseZRS((RR(((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyRst
sss_daemons/usr/share/localetfallbackiis&Set the verbosity of the debug loggingtdebugtdebug_levels Include timestamps in debug logstdebug_timestampss0Include microseconds in timestamps in debug logstdebug_microsecondss Write debug messages to logfilestdebug_to_filess*Watchdog timeout before restarting servicettimeoutsCommand to start servicetcommands7Number of times to attempt connection to Data Providerstreconnection_retriessCThe number of file descriptors that may be opened by this respondertfd_limits4Idle time before automatic disconnection of a clienttclient_idle_timeouts4Idle time before automatic shutdown of the respondertresponder_idle_timeouts>Always query all the caches before querying the Data Providerstcache_firstsSSSD Services to starttservicessSSSD Domains to starttdomainss'Timeout for messages sent over the SBUStsbus_timeouts"Regex to parse username and domaint
re_expressions=Printf-compatible format for displaying fully-qualified namestfull_name_formatsPDirectory on the filesystem where SSSD should store Kerberos replay cache files.tkrb5_rcache_dirs2Domain to add to names without a domain component.tdefault_domain_suffixsThe user to drop privileges totusersTune certificate verificationtcertificate_verificationsFAll spaces in group or user names will be replaced with this charactertoverride_spaces2Tune sssd to honor or ignore netlink state changestdisable_netlinks+Enable or disable the implicit files domaintenable_files_domains/A specific order of the domains to be looked uptdomain_resolution_orders*Enumeration cache timeout length (seconds)tenum_cache_timeouts6Entry cache background update timeout length (seconds)tentry_cache_no_wait_timeouts'Negative cache timeout length (seconds)tentry_negative_timeouts-Files negative cache timeout length (seconds)tlocal_negative_timeouts(Users that SSSD should explicitly ignoretfilter_userss)Groups that SSSD should explicitly ignoret
filter_groupss&Should filtered users appear in groupstfilter_users_in_groupss>The value of the password field the NSS provider should returntpwfieldsAOverride homedir value from the identity provider with this valuetoverride_homedirsISubstitute empty homedir value from the identity provider with this valuetfallback_homedirs?Override shell value from the identity provider with this valuetoverride_shells3The list of shells users are allowed to log in withtallowed_shellssLThe list of shells that will be vetoed, and replaced with the fallback shellt
vetoed_shellssVIf a shell stored in central directory is allowed but not available, use this fallbacktshell_fallbacks.Shell to use if the provider does not list onet
default_shells.How long will be in-memory cache records validtmemcache_timeouts?List of user attributes the NSS responder is allowed to publishtuser_attributess<How long to allow cached logins between online logins (days)toffline_credentials_expirations8How many failed logins attempts are allowed when offlinetoffline_failed_login_attemptssUHow long (minutes) to deny login after offline_failed_login_attempts has been reachedtoffline_failed_login_delaysEWhat kind of messages are displayed to the user during authenticationt
pam_verbositys(Filter PAM responses sent to the pam_ssstpam_response_filtersEHow many seconds to keep identity information cached for PAM requeststpam_id_timeoutsFHow many days before password expiration a warning should be displayedtpam_pwd_expiration_warnings#List of trusted uids or user's nametpam_trusted_userss4List of domains accessible even for untrusted users.tpam_public_domainss-Message printed when user account is expired.tpam_account_expired_messages,Message printed when user account is locked.tpam_account_locked_messages1Allow certificate based/Smartcard authentication.t
pam_cert_auths2Path to certificate database with PKCS#11 modules.tpam_cert_db_paths:How many seconds will pam_sss wait for p11_child to finishtp11_child_timeouts?Which PAM services are permitted to contact application domainstpam_app_servicess%Allowed services for using smartcardstpam_p11_allowed_servicess;Whether to evaluate the time-based attributes in sudo rulest
sudo_timeds;If true, SSSD will switch back to lower-wins ordering logictsudo_inverse_ordersfMaximum number of rules that can be refreshed at once. If this is exceeded, full refresh is performed.tsudo_thresholdtautofs_negative_timeouts@Whether to hash host names and addresses in the known_hosts filetssh_hash_known_hostssZHow many seconds to keep a host in the known_hosts file after its host keys were requestedtssh_known_hosts_timeouts*Path to storage of trusted CA certificatestca_dbs>List of UIDs or user names allowed to access the PAC respondertallowed_uidss)How long the PAC data is considered validtpac_lifetimesCList of UIDs or user names allowed to access the InfoPipe responders:List of user attributes the InfoPipe is allowed to publishs0The provider where the secrets will be stored intproviders/The maximum allowed number of nested containerstcontainers_nest_levels0The maximum number of secrets that can be storedtmax_secretss8The maximum number of secrets that can be stored per UIDtmax_uid_secretss1The maximum payload size of a secret in kilobytestmax_payload_sizes'The URL Custodia server is listening ont	proxy_urls:The method to use when authenticating to a Custodia servert	auth_typesjThe name of the headers that will be added into a HTTP request with the value defined in auth_header_valuetauth_header_names5The value sssd-secrets would use for auth_header_nametauth_header_valuesSThe list of the headers to forward to the Custodia server together with the requesttforward_headerssMThe username to use when authenticating to a Custodia server using basic_authtusernamesMThe password to use when authenticating to a Custodia server using basic_authtpasswordsGIf true peer's certificate is verified if proxy_url uses https protocoltverify_peerseIf false peer's certificate may contain different hostname than proxy_url when https protocol is usedtverify_hostsEPath to directory where certificate authority certificates are storedtcapaths/Path to file containing server's CA certificatetcacerts,Path to file containing client's certificatetcerts,Path to file containing client's private keytkeysIdentity providertid_providersAuthentication providert
auth_providersAccess control providertaccess_providersPassword change providertchpass_providers
SUDO providert
sudo_providersAutofs providertautofs_providersHost identity providerthostid_providersSELinux providertselinux_providersSession management providertsession_providers9Whether the domain is usable by the OS or by applicationstdomain_typesMinimum user IDtmin_idsMaximum user IDtmax_ids#Enable enumerating all users/groupst	enumerates#Cache credentials for offline logintcache_credentialssStore password hasheststore_legacy_passwordss,Display users/groups in fully-qualified formtuse_fully_qualified_namess,Don't include group members in group lookupstignore_group_memberss$Entry cache timeout length (seconds)tentry_cache_timeoutsHRestrict or prefer a specific address family when performing DNS lookupstlookup_family_ordersBHow long to keep cached entries after last successful login (days)taccount_cache_expirationsFHow long to wait for replies from DNS when resolving servers (seconds)tdns_resolver_timeouts.The domain part of service discovery DNS querytdns_discovery_domains=Override GID value from the identity provider with this valuetoverride_gids!Treat usernames as case sensitivetcase_sensitivetentry_cache_user_timeouttentry_cache_group_timeouttentry_cache_netgroup_timeouttentry_cache_service_timeouttentry_cache_autofs_timeouttentry_cache_sudo_timeouts;How often should expired entries be refreshed in backgroundtrefresh_expired_intervals6Whether to automatically update the client's DNS entryt
dyndns_updates<The TTL to apply to the client's DNS entry after updating itt
dyndns_ttls=The interface whose IP should be used for dynamic DNS updatestdyndns_ifaces7How often to periodically update the client's DNS entrytdyndns_refresh_intervalsDWhether the provider should explicitly update the PTR record as welltdyndns_update_ptrs8Whether the nsupdate utility should default to using TCPtdyndns_force_tcpsDWhat kind of authentication should be used to perform the DNS updatetdyndns_auths6Override the DNS server used to perform the DNS updatet
dyndns_servers&Control enumeration of trusted domainstsubdomain_enumerates-How often should subdomains list be refreshedtsubdomain_refresh_intervals9List of options that should be inherited into a subdomaintsubdomain_inheritsDefault subdomain homedir valuetsubdomain_homedirsAHow long can cached credentials be used for cached authenticationtcached_auth_timeouts8Whether to automatically create private groups for userstauto_private_groupss
IPA domaint
ipa_domainsIPA server addresst
ipa_serversAddress of backup IPA servertipa_backup_serversIPA client hostnametipa_hostnamesAWhether to automatically update the client's DNS entry in FreeIPAtipa_dyndns_updatetipa_dyndns_ttltipa_dyndns_ifaces$Search base for HBAC related objectstipa_hbac_search_basesKThe amount of time between lookups of the HBAC rules against the IPA servertipa_hbac_refreshsXThe amount of time in seconds between lookups of the SELinux maps against the IPA servertipa_selinux_refreshs;If set to false, host argument given by PAM will be ignoredtipa_hbac_support_srchosts1The automounter location this IPA client is usingtipa_automount_locations7Search base for object containing info about IPA domaintipa_master_domain_search_bases7Search base for objects containing info about ID rangestipa_ranges_search_bases3Enable DNS sites - location based service discoverytipa_enable_dns_sitessSearch base for view containerstipa_views_search_basesObjectclass for view containerstipa_view_classs#Attribute with the name of the viewt
ipa_view_names Objectclass for override objectstipa_override_object_classs3Attribute with the reference to the original objecttipa_anchor_uuids%Objectclass for user override objectstipa_user_override_object_classs&Objectclass for group override objectstipa_group_override_object_classs/Search base for Desktop Profile related objectstipa_deskprofile_search_basesaThe amount of time in seconds between lookups of the Desktop Profile rules against the IPA servertipa_deskprofile_refreshs�The amount of time in minutes between lookups of Desktop Profiles rules against the IPA server when the last request did not find any rulet ipa_deskprofile_request_intervalsActive Directory domaint	ad_domains Enabled Active Directory domainstad_enabled_domainssActive Directory server addresst	ad_servers&Active Directory backup server addresstad_backup_servers Active Directory client hostnametad_hostnametad_enable_dns_sitess*LDAP filter to determine access privilegestad_access_filters-Whether to use the Global Catalog for lookupstad_enable_gcs+Operation mode for GPO-based access controltad_gpo_access_controlsPThe amount of time between lookups of the GPO policy files against the AD servertad_gpo_cache_timeoutsQPAM service names that map to the GPO (Deny)InteractiveLogonRight policy settingstad_gpo_map_interactivesWPAM service names that map to the GPO (Deny)RemoteInteractiveLogonRight policy settingstad_gpo_map_remote_interactivesMPAM service names that map to the GPO (Deny)NetworkLogonRight policy settingstad_gpo_map_networksKPAM service names that map to the GPO (Deny)BatchLogonRight policy settingstad_gpo_map_batchsMPAM service names that map to the GPO (Deny)ServiceLogonRight policy settingstad_gpo_map_services>PAM service names for which GPO-based access is always grantedtad_gpo_map_permits=PAM service names for which GPO-based access is always deniedtad_gpo_map_denysJDefault logon right (or permit/deny) to use for unmapped PAM service namestad_gpo_default_rights*a particular site to be used by the clienttad_sitesIMaximum age in days before the machine account password should be renewedt'ad_maximum_machine_account_password_ages2Option for tuning the machine account renewal taskt(ad_machine_account_password_renewal_optss3Use LDAPS port for LDAP and Global Catalog requeststad_use_ldapssKerberos server addresst
krb5_kdciptkrb5_serversKerberos backup server addresstkrb5_backup_serversKerberos realmt
krb5_realmsAuthentication timeouttkrb5_auth_timeoutsWhether to create kdcinfo filestkrb5_use_kdcinfos"Where to drop krb5 config snippetstkrb5_confd_paths$Directory to store credential cachestkrb5_ccachedirs'Location of the user's credential cachetkrb5_ccname_templates.Location of the keytab to validate credentialstkrb5_keytabsEnable credential validationt
krb5_validates9Store password if offline for later online authenticationtkrb5_store_password_if_offlinesRenewable lifetime of the TGTtkrb5_renewable_lifetimesLifetime of the TGTt
krb5_lifetimes#Time between two checks for renewaltkrb5_renew_intervalsEnables FASTt
krb5_use_fasts%Selects the principal to use for FASTtkrb5_fast_principals"Enables principal canonicalizationtkrb5_canonicalizesEnables enterprise principalstkrb5_use_enterprise_principals5A mapping from user names to Kerberos principal namest
krb5_map_usersEServer where the change password service is running if not on the KDCtkrb5_kpasswdtkrb5_backup_kpasswds$ldap_uri, The URI of the LDAP servertldap_uris+ldap_backup_uri, The URI of the LDAP servertldap_backup_urisThe default base DNtldap_search_bases2The Schema Type in use on the LDAP server, rfc2307tldap_schemas!Mode used to change user passwordtldap_pwmodify_modesThe default bind DNtldap_default_bind_dns;The type of the authentication token of the default bind DNtldap_default_authtok_types/The authentication token of the default bind DNtldap_default_authtoks$Length of time to attempt connectiontldap_network_timeouts5Length of time to attempt synchronous LDAP operationstldap_opt_timeouts:Length of time between attempts to reconnect while offlinetldap_offline_timeouts'Use only the upper case for realm namestldap_force_upper_case_realms"File that contains CA certificatestldap_tls_cacerts Path to CA certificate directorytldap_tls_cacertdirs)File that contains the client certificatet
ldap_tls_certs!File that contains the client keytldap_tls_keysList of possible ciphers suitestldap_tls_cipher_suites$Require TLS certificate verificationtldap_tls_reqcerts!Specify the sasl mechanism to usetldap_sasl_mechs(Specify the sasl authorization id to usetldap_sasl_authids+Specify the sasl authorization realm to usetldap_sasl_realms3Specify the minimal SSF for LDAP sasl authorizationtldap_sasl_minssfs3Specify the maximal SSF for LDAP sasl authorizationtldap_sasl_maxssfsKerberos service keytabtldap_krb5_keytabs%Use Kerberos auth for LDAP connectiontldap_krb5_init_credssFollow LDAP referralstldap_referralss#Lifetime of TGT for LDAP connectiontldap_krb5_ticket_lifetimesHow to dereference aliasest
ldap_derefs$Service name for DNS service lookupstldap_dns_service_names8The number of records to retrieve in a single LDAP querytldap_page_sizesBThe number of members that must be missing to trigger a full dereftldap_deref_thresholdsiWhether the LDAP library should perform a reverse lookup to canonicalize the host name during a SASL bindtldap_sasl_canonicalizesentryUSN attributetldap_entry_usnslastUSN attributetldap_rootdse_last_usnsGHow long to retain a connection to the LDAP server before disconnectingt"ldap_connection_expiration_timeoutsDisable the LDAP paging controltldap_disable_pagings(Disable Active Directory range retrievaltldap_disable_range_retrievals+Length of time to wait for a search requesttldap_search_timeouts0Length of time to wait for a enumeration requesttldap_enumeration_search_timeouts*Length of time between enumeration updatest ldap_enumeration_refresh_timeouts%Length of time between cache cleanupstldap_purge_cache_timeoutsRequire TLS for ID lookupstldap_id_use_start_tlss2Use ID-mapping of objectSID instead of pre-set IDstldap_id_mappingsBase DN for user lookupstldap_user_search_basesScope of user lookupstldap_user_search_scopesFilter for user lookupstldap_user_search_filtersObjectclass for userstldap_user_object_classsUsername attributetldap_user_names
UID attributetldap_user_uid_numbersPrimary GID attributetldap_user_gid_numbersGECOS attributetldap_user_gecossHome directory attributetldap_user_home_directorysShell attributetldap_user_shellsUUID attributetldap_user_uuidsobjectSID attributetldap_user_objectsids7Active Directory primary group attribute for ID-mappingtldap_user_primary_groups'User principal attribute (for Kerberos)tldap_user_principals	Full Nametldap_user_fullnamesmemberOf attributetldap_user_member_ofsModification time attributetldap_user_modify_timestampsshadowLastChange attributetldap_user_shadow_last_changesshadowMin attributetldap_user_shadow_minsshadowMax attributetldap_user_shadow_maxsshadowWarning attributetldap_user_shadow_warningsshadowInactive attributetldap_user_shadow_inactivesshadowExpire attributetldap_user_shadow_expiresshadowFlag attributetldap_user_shadow_flags)Attribute listing authorized PAM servicestldap_user_authorized_services)Attribute listing authorized server hoststldap_user_authorized_hosts*Attribute listing authorized server rhoststldap_user_authorized_rhostskrbLastPwdChange attributetldap_user_krb_last_pwd_changeskrbPasswordExpiration attributet!ldap_user_krb_password_expirationsBAttribute indicating that server side password policies are activetldap_pwd_attributesaccountExpires attribute of ADtldap_user_ad_account_expiress"userAccountControl attribute of ADt!ldap_user_ad_user_account_controlsnsAccountLock attributetldap_ns_account_locksloginDisabled attribute of NDStldap_user_nds_login_disableds$loginExpirationTime attribute of NDSt#ldap_user_nds_login_expiration_times$loginAllowedTimeMap attribute of NDSt$ldap_user_nds_login_allowed_time_mapsSSH public key attributetldap_user_ssh_public_keys9attribute listing allowed authentication types for a usertldap_user_auth_types5attribute containing the X509 certificate of the usertldap_user_certificates2attribute containing the email address of the usertldap_user_emails@A list of extra attributes to download along with the user entrytldap_user_extra_attrssBase DN for group lookupstldap_group_search_basesObjectclass for groupstldap_group_object_classs
Group nametldap_group_namesGroup passwordtldap_group_pwds
GID attributetldap_group_gid_numbersGroup member attributetldap_group_membersGroup UUID attributetldap_group_uuidtldap_group_objectsids&Modification time attribute for groupstldap_group_modify_timestamps!Type of the group and other flagstldap_group_types(The LDAP group external member attributetldap_group_external_members&Maximum nesting level SSSD will followtldap_group_nesting_levelsBase DN for netgroup lookupstldap_netgroup_search_basesObjectclass for netgroupstldap_netgroup_object_classs
Netgroup nametldap_netgroup_namesNetgroups members attributetldap_netgroup_membersNetgroup triple attributetldap_netgroup_triples)Modification time attribute for netgroupstldap_netgroup_modify_timestampsBase DN for service lookupstldap_service_search_basesObjectclass for servicestldap_service_object_classsService name attributetldap_service_namesService port attributetldap_service_portsService protocol attributetldap_service_protosLower bound for ID-mappingtldap_idmap_range_minsUpper bound for ID-mappingtldap_idmap_range_maxs,Number of IDs for each slice when ID-mappingtldap_idmap_range_sizes/Use autorid-compatible algorithm for ID-mappingtldap_idmap_autorid_compats)Name of the default domain for ID-mappingtldap_idmap_default_domains(SID of the default domain for ID-mappingtldap_idmap_default_domain_sidsNumber of secondary slicestldap_idmap_helper_table_sizes1Use LDAP_MATCHING_RULE_IN_CHAIN for group lookupst&ldap_groups_use_matching_rule_in_chains5Use LDAP_MATCHING_RULE_IN_CHAIN for initgroup lookupst*ldap_initgroups_use_matching_rule_in_chainsWhether to use Token-Groupstldap_use_tokengroupss7Set lower boundary for allowed IDs from the LDAP servertldap_min_ids7Set upper boundary for allowed IDs from the LDAP servertldap_max_idsDN for ppolicy queriestldap_pwdlockout_dns;How many maximum entries to fetch during a wildcard requesttwildcard_limits*Policy to evaluate the password expirationtldap_pwd_policytldap_access_filtersCWhich attributes shall be used to evaluate if an account is expiredtldap_account_expire_policys5Which rules should be used to evaluate access controltldap_access_orders8URI of an LDAP server where password changes are allowedtldap_chpass_uris>URI of a backup LDAP server where password changes are allowedtldap_chpass_backup_uris0DNS service name for LDAP password change servertldap_chpass_dns_service_namesTWhether to update the ldap_user_shadow_last_change attribute after a password changetldap_chpass_update_last_changesBase DN for sudo rules lookupstldap_sudo_search_basesAutomatic full refresh periodtldap_sudo_full_refresh_intervalsAutomatic smart refresh periodt ldap_sudo_smart_refresh_intervals=Whether to filter rules by hostname, IP addresses and networktldap_sudo_use_host_filtersRHostnames and/or fully qualified domain names of this machine to filter sudo rulestldap_sudo_hostnamessFIPv4 or IPv6 addresses or network of this machine to filter sudo rulestldap_sudo_ipsAWhether to include rules that contains netgroup in host attributetldap_sudo_include_netgroupssKWhether to include rules that contains regular expression in host attributetldap_sudo_include_regexpsObject class for sudo rulestldap_sudorule_object_classsSudo rule nametldap_sudorule_namesSudo rule command attributetldap_sudorule_commandsSudo rule host attributetldap_sudorule_hostsSudo rule user attributetldap_sudorule_usersSudo rule option attributetldap_sudorule_optionsSudo rule runas attributetldap_sudorule_runassSudo rule runasuser attributetldap_sudorule_runasusersSudo rule runasgroup attributetldap_sudorule_runasgroupsSudo rule notbefore attributetldap_sudorule_notbeforesSudo rule notafter attributetldap_sudorule_notaftersSudo rule order attributetldap_sudorule_orders!Object class for automounter mapstldap_autofs_map_object_classsAutomounter map name attributetldap_autofs_map_names(Object class for automounter map entriestldap_autofs_entry_object_classs#Automounter map entry key attributetldap_autofs_entry_keys%Automounter map entry value attributetldap_autofs_entry_values#Base DN for automounter map lookupstldap_autofs_search_bases%Comma separated list of allowed userstsimple_allow_userss(Comma separated list of prohibited userstsimple_deny_userssDefault shell, /bin/bashsBase for home directoriestbase_directorys'The number of preforked proxy children.tproxy_max_childrens"The name of the NSS library to usetproxy_lib_names>Whether to look up canonical group name from cache if possibletproxy_fast_aliassPAM stack to usetproxy_pam_targetsPath of passwd file sources.tpasswd_filessPath of group file sources.tgroup_filescCsg|D]}|j�^qS(N(tstrip(tltx((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyt	striplist�scCs7g}x*|D]"}||kr
|j|�q
q
W|S(N(tappend(toptions1toptions2toverlaptoption((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pytoptions_overlap�s

tSSSDConfigSchemacBs>eZd�Zd�Zd�Zd�Zd�Zd�ZRS(cCs?tj|�|sd}n|s+d}nyyt|d��}|j|�WdQXxMtd�tj|��D]0}t|d|��}|j|�WdQXqoWWn*tk
r��ntk
r�t	�nXit
d6td6tj
dd	kr�tntd
6td6td6td
6dd6|_itd6td6|_dS(Ns/usr/share/sssd/sssd.api.confs/usr/share/sssd/sssd.api.dtrcSstjd|�S(Ns^sssd-.*\.conf$(tretsearch(tf((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyt<lambda>�st/tbooltintiitlongtfloattstrtlisttNonetfalsettrue(Rt__init__topentreadfptfiltertostlistdirtIOErrortSyntaxErrorRR�R�tsystversion_infoR�R�R�R�R�ttype_lookuptFalsetTruetbool_lookup(tselft
schemafiletschemaplugindirtfdtfile((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyR��s6
		


 
c	Cs�|j|�st�n|j|�}d}d}d}d}i}x�|j|�D]w}|d}	t|	jd��}
t|
�}|j|
|}|j|
|}
|j|
|}|dt	kr�t	|d}nd}|dkr||
||df||d<qU|dkr�t|
|�|krR||
|||
|f||d<q�|tkr<t|
|�|
kr�||
|||
|gf||d<q�y�|
t
kr�t|
|�tkr�||
|||j|
|j�gf||d<n*||
|||
|
|�gf||d<Wq�tk
r8t�q�Xq�y~|t
kr�t|
|�tkr�||
|||j|
|j�f||d<n'||
||||
|�f||d<Wq�tk
r�t�q�XqU|dkr�|tkr�t�ng}x�|
|D]�}t|�|
kr�yT|
t
krXt|�tkrX|j|j�}n|
|�}|j|g�Wq�tk
r�t�q�Xq	|j|g�q	W||
|||f||d<qUt�qUW|S(	Niiiitvaluet,tnamei(thas_sectionR	toptionststrip_comments_emptyR�tsplittlenR�R�toption_stringsR�ttypeR�R�R�tlowert
ValueErrorRtextend(R�tsectionR�tPRIMARY_TYPEtSUBTYPEt	MANDATORYtDEFAULTtparsed_optionsR�tunparsed_optiontsplit_optiont	optionlentprimarytypetsubtypet	mandatorytdesct
fixed_optionsR�tnewvalue((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pytget_optionss�	
("

%

	


cCsZ|j|�st|��n|j||�sItd||f��n|j|�|S(NsSection [%s] has no option [%s](R�R	t
has_optionR
R�(R�R�R�((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyt
get_option�scCsx|j|�st|��n|j|�}tg|j�D].}||ddkr=|||df^q=�}|S(Ni(R�R	R�tdicttkeysR�(R�R�tschema_optionsR�tdefaults((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pytget_defaults�s1cCs_g|j�D]H}|ddkr
|djd�r
|djd�r
|d^q
}|S(NR�tservicetdomainRX(tsectionst
startswith(R�R�tservice_list((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pytget_services�s
$cCs�i}x�|j�D]~}|djd�}|ddkrt|�dkr�|d|krog||d<n||dj|dg�q�qqWx(|j�D]}t||�||<q�W|S(NR�R�iRXiii(R�R�R�R�R�ttuple(R�t	providersR�tsplitsectionRi((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyt
get_providers�s&(RRR�R�R�R�R�R�(((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyR��s	'	v				tSSSDConfigObjectcBs5eZd�Zd�Zd�Zd�Zd�ZRS(cCsd|_i|_dS(N(R�R�R�(R�((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyR��s	cCs|jS(s�
        Return the name of the object

        === Returns ===
        The domain name

        === Errors ===
        No errors
        (R�(R�((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pytget_name�s
cCs0||jj�kr |j|St|��dS(s
        Return the value of an service option

        optionname:
          The option to get.

        === Returns ===
        The value for the requested option.

        === Errors ===
        NoOptionError:
          The specified option was not listed in the service
        N(R�R�R
(R�t
optionname((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyR��scCs|jS(s�
        Return a dictionary of name/value pairs for this object

        === Returns ===
        A dictionary of name/value pairs currently in use for this object

        === Errors ===
        No errors
        (R�(R�((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pytget_all_options�s
cCs ||jkr|j|=ndS(s�
        Remove an option from the object. If the option does not exist, it is ignored.

        === Returns ===
        No return value.

        === Errors ===
        No errors
        N(R�(R�R�((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyt
remove_option�s
(RRR�R�R�R�R�(((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyR��s
				tSSSDServicecBs;eZdZd�Zd�Zd�Zd�Zd�ZRS(s3
    Object to manipulate SSSD service options
    cCs�tj|�t|t�s/t|�tkr8t�n|j|�sVt|��n||_	||_
i|_g|_|jj
|j
jd��|jj
|j
j|j	��dS(s\
        Create a new SSSDService, setting its defaults to those found in the
        schema. This constructor should not be used directly. Use
        SSSDConfig.new_service() instead.

        name:
          The service name
        apischema:
          An SSSDConfigSchema? object created by SSSDConfig.__init__()

        === Returns ===
        The newly-created SSSDService object.

        === Errors ===
        TypeError:
          The API schema passed in was unusable or the name was not a string.
        ServiceNotRecognizedError:
          The service was not listed in the schema
        R�N(R�R�t
isinstanceR�R�R�t	TypeErrorR�RR�tschemaR�thidden_optionstupdateR�(R�tservicenamet	apischema((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyR��s
"					cCsKi}|jjd�}|j|�|jj|j�}|j|�|S(sI
        List options for the service, including the mandatory flag.

        === Returns ===
        A dictionary of configurable options. This dictionary is keyed on the
        option name with a tuple of the variable type, subtype ('None' if the
        type is not  a collection type), whether it is mandatory, the
        translated option description, and the default value (or 'None') as
        the value.

        Example:
        { 'enumerate' :
          (bool, None, False, u'Enable enumerating all users/groups', True) }

        === Errors ===
        No errors
        R�(R�R�R�R�(R�R�R�((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pytlist_options_with_mandatory#s

cCsc|j�}i}xJ|j�D]<}||d||d||d||df||<qW|S(s
        List all options that apply to this service

        === Returns ===
        A dictionary of configurable options. This dictionary is keyed on the
        option name with a tuple of the variable type, subtype ('None' if the
        type is not  a collection type), the translated option description, and
        the default value (or 'None') as the value.

        Example:
        { 'services' :
          (list, str, u'SSSD Services to start', ['nss', 'pam']) }

        === Errors ===
        No Errors
        iiii(R�R�(R�R�tfiltered_optionsRi((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pytlist_options@s
:cCst|j�}i}x[|j�D]M}||dr||d||d||d||df||<qqW|S(s
        List all mandatory options that apply to this service

        === Returns ===
        A dictionary of configurable options. This dictionary is keyed on the
        option name with a tuple of the variable type, subtype ('None' if the
        type is not  a collection type), the translated option description, and
        the default value (or 'None') as the value.

        Example:
        { 'services' :
          (list, str, u'SSSD Services to start', ['nss', 'pam']) }

        === Errors ===
        No Errors
        iiiii(R�R�(R�R�R�Ri((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pytlist_mandatory_options[s=c	Cs�|jj|j|�r3|jj|j|�}nf|jjd|�r`|jjd|�}n9||jkr�||j|<dStd|j|f��|dkr�|j|�dSt	}|dt
krt|�t
krt|�tkrt
|jd��}q|g}nt|�|dkry�|dtkrht|�tkrh|jj|j�}nD|dtkr�t|�tkr�t|d�}n|d|�}Wn-tk
r�t}ntk
r�t}nX|rtd|d|t|�f��qnt|�t
kr�yzg}xm|D]e}|dtkryt|�tkry|j|jj|j�g�q.|j|d|�g�q.WWn-tk
r�t}ntk
r�t}nX|r�td|d��n|}n||j|<dS(	s
        Set a service option to the specified value (or values)

        optionname:
          The option to change
        value:
          The value to set. This may be a single value or a list of values. If
          it is set to None, it resets the option to its default.

        === Returns ===
        No return value

        === Errors ===
        NoOptionError:
          The specified option is not listed in the schema
        TypeError:
          The value specified was not of the expected type
        R�NsSection [%s] has no option [%s]iR�sExpected %s for %s, received %sisExpected %s(R�R�R�R�R�R�R
R�R�R�R�R�R�R�R�R�R�R�R�R�R�tKeyErrorR�R�(R�R�R�t
option_schematraise_errorR�R�((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyt
set_optionws\

"""
	

#
#"
	

	(RRt__doc__R�R�R�R�R�(((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyR��s	+			t
SSSDDomaincBsteZdZd�Zd�Zd�Zd�Zd�Zdd�Z	d�Z
d�Zd	�Zd
�Z
d�ZRS(
s2
    Object to manipulate SSSD domain options
    cCs�tj|�t|t�s/t|�tkr8t�n||_||_t	|_
d|_g|_
i|_|jj|jjd��|jj|jjd��dS(s
        Creates a new, empty SSSDDomain. This domain is inactive by default.
        This constructor should not be used directly. Use
        SSSDConfig.new_domain() instead.

        name:
          The domain name.
        apischema:
          An SSSDConfigSchema object created by SSSDConfig.__init__()

        === Returns ===
        The newly-created SSSDDomain object.

        === Errors ===
        TypeError:
          apischema was not an SSSDConfigSchema object or domainname was not
         a string
        RXR�N(R�R�R�R�R�R�R�R�R�R�tactiveR�toldnameR�R�R�R�(R�t
domainnameR�((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyR��s
"							cCst|�|_dS(sd
        Enable or disable this domain

        active:
          Boolean value. If True, this domain will be added to the active
          domains list when it is saved. If False, it will be removed from the
          active domains list when it is saved.

        === Returns ===
        No return value

        === Errors ===
        No errors
        N(R�R�(R�R�((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyt
set_active�scCs�i}|j|jjd��|j|jjd��xc|jD]X\}}|jjd|�}|j|�|jjd||f�}|j|�qBW|S(sg
        List options for the currently-configured providers, including the
        mandatory flag

        === Returns ===
        A dictionary of configurable options. This dictionary is keyed on the
        option name with a tuple of the variable type, subtype ('None' if the
        type is not  a collection type), whether it is mandatory, the
        translated option description, and the default value (or 'None') as
        the value.

        Example:
        { 'enumerate' :
          (bool, None, False, u'Enable enumerating all users/groups', True) }

        === Errors ===
        No errors
        RXR�sprovider/%ssprovider/%s/%s(R�R�R�R�(R�R�RXtprovidertypeR�((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyR�s

cCsc|j�}i}xJ|j�D]<}||d||d||d||df||<qW|S(s$
        List options available for the currently-configured providers.

        === Returns ===
        A dictionary of configurable options. This dictionary is keyed on the
        option name with a tuple of the variable type, subtype ('None' if the
        type is not  a collection type), the translated option description, and
        the default value (or 'None') as the value.

        Example:
        { 'enumerate' :
          (bool, None, u'Enable enumerating all users/groups', True) }

        === Errors ===
        No errors
        iiii(R�R�(R�R�R�Ri((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyR�,s
:cCst|j�}i}x[|j�D]M}||dr||d||d||d||df||<qqW|S(s$
        List mandatory options for the currently-configured providers.

        === Returns ===
        A dictionary of configurable options. This dictionary is keyed on the
        option name with a tuple of the variable type, subtype ('None' if the
        type is not  a collection type), the translated option description, and
        the default value (or 'None') as the value.

        Example:
        { 'enumerate' :
          (bool, None, u'Enable enumerating all users/groups', True) }

        === Errors ===
        No errors
        iiiii(R�R�(R�R�R�Ri((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyR�Gs=cCs�|jjd|�}|rB|j|jjd||f��n:|j�}x+||D]}|j|j||��qYW|S(s�
        If provider_type is specified, list all options applicable to that
        target, otherwise list all possible options available for a provider.

        type:
            Provider backend type. (e.g. local, ldap, krb5, etc.)
        provider_type:
            Subtype of the backend type. (e.g. id, auth, access, chpass)

        === Returns ===

        A dictionary of configurable options for the specified provider type.
        This dictionary is keyed on the option name with a tuple of the
        variable type, subtype ('None' if the type is not  a collection type),
        the translated option description, and the default value (or 'None')
        as the value.

        === Errors ===

        NoSuchProviderError:
            The specified provider is not listed in the schema or plugins
        NoSuchProviderSubtypeError:
            The specified provider subtype is not listed in the schema
        sprovider/%ssprovider/%s/%s(R�R�R�tlist_providerstlist_provider_options(R�RXt
provider_typeR�tknown_providers((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyR�cscCs
|jj�S(s>
        Return a dictionary of providers.

        === Returns ===
        Returns a dictionary of providers, keyed on the primary type, with the
        value being a tuple of the subtypes it supports.

        Example:
        { 'ldap' : ('id', 'auth', 'chpass') }

        === Errors ===
        No Errors
        (R�R�(R�((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyR��sc
	Cs|j�}||j�kr:td|j|f��n|dkrW|j|�dS||}t}|dtkr�t|�tkr�t|�t	kr�t
|jd��}q�|g}nt|�|dkr�y�|dtkrt|�t	kr|j
j|j�}nD|dtkrGt|�t	krGt|d�}n|d|�}Wn-tk
rqt}ntk
r�t}nX|r�td|d|t|�f��q�nt|�tkr�yzg}xm|D]e}|dtkr$t|�t	kr$|j|j
j|j�g�q�|j|d|�g�q�WWn-tk
r\t}ntk
rrt}nX|r�td|d��n|}n|jd�}|dkr�|| }	y|j||	�Wq�tk
r�t�q�Xn
||j|<dS(	s
        Set a domain option to the specified value (or values)

        option:
          The option to change.
        value:
          The value to set. This may be a single value or a list of values.
          If it is set to None, it resets the option to its default.

        === Returns ===
        No return value.

        === Errors ===
        NoOptionError:
            The specified option is not listed in the schema
        TypeError:
            The value specified was not of the expected type
        sSection [%s] has no option [%s]NiR�sExpected %s for %s, received %sisExpected %st	_provider(R�R�R
R�R�R�R�R�R�R�R�R�R�R�R�R�R�R�R�R�R�R�trfindtadd_providerRR�(
R�R�R�R�R�R�R�R�tis_providerRX((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyR��sf

""
	

#
#"
	

	


cCs@t|�tkrt�n|js3|j|_n||_dS(s�
        Change the name of the domain

        newname:
          New name for this domain

        === Returns ===
        No return value.

        === Errors ===
        TypeError:
          newname was not a string
        N(R�R�R�R�R�(R�tnewname((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pytset_name�s
		cCsG|j�}||j�kr@|||krFt|��qFnt�g|jD]}|d|krP|^qP}t|�dkr�t�nt|�dkr�|dd|kr�t|dd��q�n|jj||fg�d|}||j|<|jj	|j
jd|��|jj	|j
jd||f��dS(sH
        Add a new provider type to the domain

        type:
          Provider backend type. (e.g. local, ldap, krb5, etc.)
        subtype:
          Subtype of the backend type. (e.g. id, auth, chpass)

        === Returns ===
        No return value.

        === Errors ===
        ProviderSubtypeInUse:
          Another backend is already providing this subtype
        NoSuchProviderError:
          The specified provider is not listed in the schema or plugins
        NoSuchProviderSubtypeError:
          The specified provider subtype is not listed in the schema
        iis%s_providersprovider/%ssprovider/%s/%sN(R�R�RRR�R�RR�R�R�R�R�(R�RXR�tconfigured_providersR�twith_this_typetoption_name((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyR�s&,	

c
Cs<d}x-|jD]"\}}||kr,Pnd}qW|s@dS|j||�}xz|jD]o\}}||f||fkr�q\n|j||�}t|j�|j��}x|D]
}||=q�Wq\Wx*|D]"}	|	|jkr�|j|	=q�q�Wd|}	|	|jkr"|j|	=n|jj||f�dS(s
        Remove a provider from the domain. If the provider is not present, it
        is ignored.

        provider_type:
          Subtype of the backend type. (e.g. id, auth, chpass)

        === Returns ===
        No return value.

        === Errors ===
        No Errors
        Ns%s_provider(R�R�R�R�R�R�tremove(
R�R�RXtptypeR�tprovtprovider_optionsR�toptR�((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pytremove_provider=s,




N(RRR�R�R�R�R�R�R�R�R�R�RR�R	(((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyR��s	%		$		'		[		1t
SSSDConfigcBs�eZdZddd�Zdd�Zd�Zdd�Zd�Zd�Z	d�Z
d�Zd	�Zd
�Z
d�Zd�Zd
�Zd�Zd�Zd�Zd�Zd�Zd�Zd�Zd�Zd�Zd�ZRS(sQ
    class SSSDConfig
    Primary class for operating on SSSD configurations
    cCs>tj|�t||�|_d|_t|_d|_dS(s+
        Initialize the SSSD config parser/editor. This constructor does not
        open or create a config file. If the schemafile and schemaplugindir
        are not passed, it will use the system defaults.

        schemafile:
          The path to the API schema config file. Usually
          /usr/share/sssd/sssd.api.conf
        schemaplugindir:
          The path the directory containing the provider schema config files.
          Usually /usr/share/sssd/sssd.api.d

        === Returns ===
        The newly-created SSSDConfig object.

        === Errors ===
        IOError:
          Exception raised when the schema file could not be opened for
          reading.
        ParsingError:
          The main schema file or one of those in the plugin directory could
          not be parsed.
        iN(	RR�R�R�R�t
configfileR�tinitializedtAPI_VERSION(R�R�R�((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyR�ws

		cCs�|jrt�n|s!d}nt|d��(}y|j|�Wn
t�nXWdQX||_t|_y4t|jdd��|j	kr�td��nWnt
k
r�nXdS(s�
        Read in a config file, populating all of the service and domain
        objects with the read values.

        configfile:
          The path to the SSSD config file. If not specified, use the system
          default, usually /etc/sssd.conf

        === Returns ===
        No return value

        === Errors ===
        IOError:
          Exception raised when the file could not be opened for reading
        ParsingError:
          Exception raised when errors occur attempting to parse a file.
        AlreadyInitializedError:
          This SSSDConfig object was already initialized by a call to
          import_config() or new_config()
        s/etc/sssd/sssd.confR�Ntsssdtconfig_file_versionsWrong config_file_version(RRR�R�RRR�R�tgetR
R�(R�RR�((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyt
import_config�s 					!
cCsH|jrt�nt|_x&|jj�D]}|j|�}q+WdS(s/
        Initialize the SSSDConfig object with the defaults from the schema.

        === Returns ===
        No return value

        === Errors ===
        AlreadyInitializedError:
          This SSSDConfig object was already initialized by a call to
          import_config() or new_config()
        N(RRR�R�R�tnew_service(R�R�R�((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyt
new_config�s
			cCs�|jst�n|dkrB|jdkr6t�n|j}ntjd�}t|d��/}|j|j	�j
d�}|j|�WdQXtj|�dS(s�
        Write out the configuration to a file.

        outputfile:
          The path to write the new config file. If it is not specified, it
          will use the path specified by the import() call.
        === Returns ===
        No return value

        === Errors ===
        IOError:
          Exception raised when the file could not be opened for writing
        NotInitializedError:
          This SSSDConfig object has not had import_config() or new_config()
          run on it yet.
        NoOutputFileError:
          No outputfile was specified and this SSSDConfig object was not
          initialized by import()
        itwbsutf-8N(RRR�RRR�tumaskR�tdumptoptstencodetwrite(R�t
outputfilet	old_umasktoftoutput((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyR�s			cCs�|jst�n|jdd�r�t|jdd�jd��}tj|�}d|krj|d=n|j�}x*t	|�D]}||kr�||=q�q�Wt	|�}ng}|S(s
        Return a list of all active services.

        === Returns ===
        The list of active services.

        === Errors ===
        NotInitializedError:
          This SSSDConfig object has not had import_config() or new_config()
          run on it yet.
        RR!R�t(
RRR�R�RR�R�tfromkeyst
list_servicesR�(R�tactive_servicestservice_dicttconfigured_servicestsrv((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pytlist_active_services�s		!
cCs}|jst�n|jdd�rHt|jdd�jd��}ng}g|j�D]}||kr[|^q[}|S(s
        Return a list of all disabled services.

        === Returns ===
        The list of inactive services.

        === Errors ===
        NotInitializedError:
          This SSSDConfig object has not had import_config() or new_config()
          run on it yet.
        RR!R�(RRR�R�RR�R (R�R!R�R!((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pytlist_inactive_servicess		$cCsL|jst�ng|j�D]#}|djd�s|d^q}|S(s
        Retrieve a list of known services.

        === Returns ===
        The list of known services.

        === Errors ===
        NotInitializedError:
          This SSSDConfig object has not had import_config() or new_config()
          run on it yet.
        R�R�(RRR�R�(R�R�R�((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyR 5s
		#cCs�|jst�n|j|�s*t�nt||j�}xP|j|j|��D]6}y|j|d|d�WqUt	k
r�qUXqUW|S(s�
        Get an SSSDService object to edit a service.

        name:
          The name of the service to return.

        === Returns ===
        An SSSDService instance containing the current state of a service in
        the SSSDConfig

        === Errors ===
        NoServiceError:
          There is no such service with the specified name in the SSSDConfig.
        NotInitializedError:
          This SSSDConfig object has not had import_config() or new_config()
          run on it yet.
        R�R�(
RRR�RR�R�R�R�R�R
(R�R�R�R((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pytget_serviceHs			
cCsS|jst�n|j|�r0t|��nt||j�}|j|�|S(s�
        Create a new service from the defaults and return the SSSDService
        object for it. This function will also add this service to the list of
        active services in the [SSSD] section.

        name:
          The name of the service to create and return.

        === Returns ===
        The newly-created SSSDService object

        === Errors ===
        ServiceNotRecognizedError:
          There is no such service in the schema.
        ServiceAlreadyExistsError:
          The service being created already exists in the SSSDConfig object.
        NotInitializedError:
          This SSSDConfig object has not had import_config() or new_config()
          run on it yet.
        (RRR�RR�R�tsave_service(R�R�R�((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyRjs		
cCs�|jst�n||j�kr-t�n|jdd�d}|s`|jdd|�dStjt|dj	d���}d|kr�|d=nd||<|jdddj|j���dS(	s�
        Activate a service

        name:
          The name of the service to activate

        === Returns ===
        No return value

        === Errors ===
        NotInitializedError:
          This SSSDConfig object has not had import_config() or new_config()
          run on it yet.
        NoServiceError:
          There is no such service with the specified name in the SSSDConfig.
        RR!iNR�R�Rs, (
RRR Rtget_option_indextsetR�RR�R�R�tjoinR�(R�R�titemR"((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pytactivate_service�s			"

cCs�|jst�n||j�kr-t�n|jdd�d}|s`|jddd�dStjt|dj	d���}d|kr�|d=n||kr�||=n|jdddj
|j���dS(	s�
        Deactivate a service

        name:
          The name of the service to deactivate

        === Returns ===
        No return value

        === Errors ===
        NotInitializedError:
          This SSSDConfig object has not had import_config() or new_config()
          run on it yet.
        NoServiceError:
          There is no such service with the specified name in the SSSDConfig.
        RR!iRNR�R�s, (RRR RR)R*R�RR�R�R+R�(R�R�R,R"((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pytdeactivate_service�s			"

cCs&|jst�n|jd|�dS(s�
        Remove a service from the SSSDConfig object. This function will also
        remove this service from the list of active services in the [SSSD]
        section. Has no effect if the service does not exist.

        === Returns ===
        No return value

        === Errors ===
        NotInitializedError:
          This SSSDConfig object has not had import_config() or new_config()
          run on it yet.
        R�N(RRt
delete_option(R�R�((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pytdelete_service�s		cCs�|jst�nt|t�s*t�n|j�}|jd|�}g}x�|j�j�D]v\}}t	|�t
kr�dj|�}n|dkr�|j|�}n|j
idd6|d6t|�d6�qaW|j|||�dS(	s�
        Save the changes made to the service object back to the SSSDConfig
        object.

        service_object:
          The SSSDService object to save to the configuration.

        === Returns ===
        No return value
        === Errors ===
        NotInitializedError:
          This SSSDConfig object has not had import_config() or new_config()
          run on it yet.
        TypeError:
          service_object was not of the type SSSDService
        R�s, RR�R�R�R�N(RRR�R�R�R�R/R�titemsR�R�R+t_get_debug_level_valR�R�tadd_section(R�R�R�tindextaddkwR�R�((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyR(�s 			cCs�|jst�n|jdd�r�t|jdd�jd��}tj|�}d|krj|d=n|j�}x*t	|�D]}||kr�||=q�q�Wt	|�}ng}|S(s
        Return a list of all active domains.

        === Returns ===
        The list of configured, active domains.

        === Errors ===
        NotInitializedError:
          This SSSDConfig object has not had import_config() or new_config()
          run on it yet.
        RR"R�R(
RRR�R�RR�R�Rtlist_domainsR�(R�tactive_domainstdomain_dicttconfigured_domainstdom((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pytlist_active_domainss		!
cCs}|jst�n|jdd�rHt|jdd�jd��}ng}g|j�D]}||kr[|^q[}|S(s.
        Return a list of all configured, but disabled domains.

        === Returns ===
        The list of configured, inactive domains.

        === Errors ===
        NotInitializedError:
          This SSSDConfig object has not had import_config() or new_config()
          run on it yet.
        RR"R�(RRR�R�RR�R6(R�R7R�R"((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pytlist_inactive_domains:s		$cCsP|jst�ng|j�D]'}|djd�r|dd^q}|S(sL
        Return a list of all configured domains, including inactive domains.

        === Returns ===
        The list of configured domains, both active and inactive.

        === Errors ===
        NotInitializedError:
          This SSSDConfig object has not had import_config() or new_config()
          run on it yet.
        R�sdomain/i(RRR�R�(R�R�R"((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyR6Rs		:cCse|jst�n|jd|�s4t|��nt||j�}g|j|jd|��D]3}|djd�dkrc|d|df^qc}x<|D]4\}}y|j	||�Wq�t
k
r�q�Xq�Wxq|j|jd|��D]S}|d|df|kr�y|j	|d|d�WqKt
k
rGqKXq�q�W|j|�|_|S(s�
        Get an SSSDDomain object to edit a domain.

        name:
          The name of the domain to return.

        === Returns ===
        An SSSDDomain instance containing the current state of a domain in the
        SSSDConfig

        === Errors ===
        NoDomainError:
          There is no such domain with the specified name in the SSSDConfig.
        NotInitializedError:
          This SSSDConfig object has not had import_config() or new_config()
          run on it yet.
        s	domain/%sR�R�iR�(
RRR�R
R�R�R�R�R�R�R
tis_domain_activeR�(R�R�R�R�R�R�R�R((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyt
get_domaincs(		#3
#
cCsQ|jst�n|jd|�r.t�nt||j�}|j|�|S(s�
        Create a new, empty domain and return the SSSDDomain object for it.

        name:
          The name of the domain to create and return.

        === Returns ===
        The newly-created SSSDDomain object

        === Errors ===
        DomainAlreadyExistsError:
          The service being created already exists in the SSSDConfig object.
        NotInitializedError:
          This SSSDConfig object has not had import_config() or new_config()
          run on it yet.
        s	domain/%s(RRR�RR�R�tsave_domain(R�R�R�((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyt
new_domain�s			
cCs=|jst�n||j�kr-t�n||j�kS(s�
        Is a particular domain set active

        name:
          The name of the configured domain to check

        === Returns ===
        True if the domain is active, False if it is inactive

        === Errors ===
        NotInitializedError:
          This SSSDConfig object has not had import_config() or new_config()
          run on it yet.
        NoDomainError:
          No domain by this name is configured
        (RRR6R
R;(R�R�((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyR=�s
			cCs�|jst�n||j�kr-t�n|jdd�d}|s`|jdd|�dStjt|dj	d���}d|kr�|d=nd||<|jdddj|j���dS(	s�
        Activate a configured domain

        name:
          The name of the configured domain to activate

        === Returns ===
        No return value

        === Errors ===
        NotInitializedError:
          This SSSDConfig object has not had import_config() or new_config()
          run on it yet.
        NoDomainError:
          No domain by this name is configured
        RR"iNR�R�Rs, (
RRR6R
R)R*R�RR�R�R�R+R�(R�R�R,R8((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pytactivate_domain�s			"

cCs�|jst�n||j�kr-t�n|jdd�d}|s`|jddd�dStjt|dj	d���}d|kr�|d=n||kr�||=n|jdddj
|j���dS(	s�
        Deactivate a configured domain

        name:
          The name of the configured domain to deactivate

        === Returns ===
        No return value

        === Errors ===
        NotInitializedError:
          This SSSDConfig object has not had import_config() or new_config()
          run on it yet.
        NoDomainError:
          No domain by this name is configured
        RR"iRNR�R�s, (RRR6R
R)R*R�RR�R�R+R�(R�R�R,R8((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pytdeactivate_domain�s			"

cCs7|jst�n|j|�|jdd|�dS(s�
        Remove a domain from the SSSDConfig object. This function will also
        remove this domain from the list of active domains in the [SSSD]
        section, if it is there.

        === Returns ===
        No return value

        === Errors ===
        NotInitializedError:
          This SSSDConfig object has not had import_config() or new_config()
          run on it yet.
        R�s	domain/%sN(RRRBR/(R�R�((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyt
delete_domain s		
c	Cs�|jst�nt|t�s*t�n|j�}d	}|jr�|j|kr�|j|j�|j	dd|j�}d	|_nd|}|j
|jd|�\}}||j�kr�|j
|g�nxa|j|�D]P}|ddkr�|d|j�kr6|j|dd|dt�q6q�q�Wx{|j�j�D]g\}}t|�tkr}dj|�}n|dkr�|j|�}n|j||t|��qMW|jr�|j|�n
|j|�d	S(
s9
        Save the changes made to the domain object back to the SSSDConfig
        object. If this domain is marked active, ensure it is present in the
        active domain list in the [SSSD] section

        domain_object:
          The SSSDDomain object to save to the configuration.

        === Returns ===
        No return value

        === Errors ===
        NotInitializedError:
          This SSSDConfig object has not had import_config() or new_config()
          run on it yet.
        TypeError:
          domain_object was not of type SSSDDomain
        R�s	domain/%sR�R�R�R�s, RN(RRR�R�R�R�R�R�RBR/tfindOptsRR6R3R�R�tdelete_option_subtreeR�R1R�R�R+R2R*R�R�RA(	R�R�R�toldindextsectionnametnotsection_subtreeR�R�((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyR?5s8			

(	N(RRR�R�R�RRRR%R&R R'RR-R.R0R(R;R<R6R>R@R=RARBRCR?(((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyR
rs0-	$	"			"		*	*		*	"			5			*	*	((R�R�tgettextR�R�t
ipachangeconfRt	ExceptionRRRRRRR	R
RRR
RRRRRtPACKAGEt	LOCALEDIRttranslationR�R�t_tugettextR�R�R�R�tobjectR�R�R�R
(((s7/usr/lib/python2.7/site-packages/SSSDConfig/__init__.pyt<module>s(	














































































































































































































































































































































































		�<���