From 7a959e81d42bdff1269589b7d17a12ab0b3243be Mon Sep 17 00:00:00 2001 From: Gerald Carter Date: Wed, 8 May 2002 15:37:14 +0000 Subject: [PATCH] merging some changes from SAMBA_2_2 (This used to be commit e8ede079b5af4187573f1b8ed0d94b6f03cbbd22) --- docs/Samba-HOWTO-Collection.pdf | 1713 ++++++++++---------- docs/docbook/manpages/nmbd.8.sgml | 85 +- docs/docbook/manpages/smb.conf.5.sgml | 142 +- docs/docbook/manpages/smbclient.1.sgml | 89 +- docs/docbook/manpages/smbcontrol.1.sgml | 21 +- docs/docbook/manpages/smbd.8.sgml | 4 +- docs/docbook/manpages/smbmount.8.sgml | 2 +- docs/docbook/manpages/smbsh.1.sgml | 130 ++ docs/docbook/manpages/wbinfo.1.sgml | 45 +- docs/docbook/manpages/winbindd.8.sgml | 15 + docs/docbook/projdoc/Samba-LDAP-HOWTO.sgml | 7 +- docs/docbook/projdoc/winbind.sgml | 8 + docs/faq/README | 8 + docs/htmldocs/Samba-HOWTO-Collection.html | 98 +- docs/htmldocs/nmbd.8.html | 85 +- docs/htmldocs/smb.conf.5.html | 265 ++- docs/htmldocs/smbclient.1.html | 105 +- docs/htmldocs/smbcontrol.1.html | 36 +- docs/htmldocs/smbd.8.html | 27 +- docs/htmldocs/smbmount.8.html | 2 +- docs/htmldocs/smbsh.1.html | 229 ++- docs/htmldocs/wbinfo.1.html | 78 +- docs/htmldocs/winbindd.8.html | 47 +- docs/manpages/nmbd.8 | 71 +- docs/manpages/smb.conf.5 | 120 +- docs/manpages/smbclient.1 | 57 +- docs/manpages/smbcontrol.1 | 23 +- docs/manpages/smbd.8 | 6 +- docs/manpages/smbmount.8 | 4 +- docs/manpages/smbsh.1 | 102 +- docs/manpages/wbinfo.1 | 30 +- docs/manpages/winbindd.8 | 14 +- docs/textdocs/BROWSING.txt | 17 +- docs/textdocs/Solaris-Winbind-HOWTO.txt | 361 +++++ examples/LDAP/samba-schema-netscapeds4.x | 54 + examples/LDAP/samba-schema-netscapeds5.x | 74 + examples/LDAP/samba-schema.IBMSecureWay | 43 + examples/README | 8 +- examples/smb.conf.default | 12 +- packaging/RedHat/samba.pamd | 4 +- packaging/RedHat/samba2.spec.tmpl | 212 ++- packaging/RedHat/smb.init | 11 +- 42 files changed, 3107 insertions(+), 1357 deletions(-) create mode 100644 docs/faq/README create mode 100644 docs/textdocs/Solaris-Winbind-HOWTO.txt create mode 100644 examples/LDAP/samba-schema-netscapeds4.x create mode 100644 examples/LDAP/samba-schema-netscapeds5.x create mode 100644 examples/LDAP/samba-schema.IBMSecureWay diff --git a/docs/Samba-HOWTO-Collection.pdf b/docs/Samba-HOWTO-Collection.pdf index 2d9a2009ac3..e9e530034f5 100644 --- a/docs/Samba-HOWTO-Collection.pdf +++ b/docs/Samba-HOWTO-Collection.pdf @@ -1,6 +1,6 @@ %PDF-1.2 %âãÏÓ -1 0 obj<>endobj +1 0 obj<>endobj 2 0 obj<>endobj 3 0 obj<>endobj 4 0 obj<>endobj @@ -403,33 +403,33 @@ 283 0 obj[282 0 R ]endobj 284 0 obj<>endobj -285 0 obj<>endobj +285 0 obj<>endobj 286 0 obj[285 0 R ]endobj 287 0 obj<>endobj -288 0 obj<>endobj +288 0 obj<>endobj 289 0 obj<>endobj -290 0 obj<>endobj -291 0 obj<>endobj -292 0 obj<>endobj -293 0 obj<>endobj -294 0 obj<>endobj -295 0 obj<>endobj -296 0 obj<>endobj -297 0 obj<>endobj -298 0 obj<>endobj -299 0 obj[288 0 R +290 0 obj<>endobj +291 0 obj[288 0 R 290 0 R -292 0 R -294 0 R -296 0 R -298 0 R ]endobj +292 0 obj<>endobj +293 0 obj<>endobj +294 0 obj<>endobj +295 0 obj<>endobj +296 0 obj<>endobj +297 0 obj<>endobj +298 0 obj<>endobj +299 0 obj<>endobj 300 0 obj<>endobj -301 0 obj<>endobj +301 0 obj<>endobj 302 0 obj<>endobj -303 0 obj<>endobj -304 0 obj[301 0 R +303 0 obj<>endobj +304 0 obj[293 0 R +295 0 R +297 0 R +299 0 R +301 0 R 303 0 R ]endobj 305 0 obj<>endobj @@ -677,11 +677,11 @@ 449 0 obj<>endobj 450 0 obj<>endobj 451 0 obj<>endobj -452 0 obj<>endobj -453 0 obj<>endobj -454 0 obj<>endobj -455 0 obj<>endobj -456 0 obj<>endobj +452 0 obj<>endobj +453 0 obj<>endobj +454 0 obj<>endobj +455 0 obj<>endobj +456 0 obj<>endobj 457 0 obj<>endobj 458 0 obj<>endobj 459 0 obj<>endobj @@ -749,7 +749,7 @@ ]endobj 471 0 obj<>endobj 472 0 obj<>endobj -473 0 obj<>endobj +473 0 obj<>endobj 474 0 obj<>endobj 475 0 obj<>endobj 476 0 obj<>endobj @@ -815,22 +815,22 @@ 536 0 obj<>endobj 537 0 obj<>endobj 538 0 obj<>endobj -539 0 obj<>endobj -540 0 obj<>endobj -541 0 obj<>endobj -542 0 obj<>endobj -543 0 obj<>endobj +539 0 obj<>endobj +540 0 obj<>endobj +541 0 obj<>endobj +542 0 obj<>endobj +543 0 obj<>endobj 544 0 obj<>endobj -545 0 obj<>endobj -546 0 obj<>endobj -547 0 obj<>endobj -548 0 obj<>endobj -549 0 obj<>endobj -550 0 obj<>endobj -551 0 obj<>endobj -552 0 obj<>endobj -553 0 obj<>endobj -554 0 obj<>endobj +545 0 obj<>endobj +546 0 obj<>endobj +547 0 obj<>endobj +548 0 obj<>endobj +549 0 obj<>endobj +550 0 obj<>endobj +551 0 obj<>endobj +552 0 obj<>endobj +553 0 obj<>endobj +554 0 obj<>endobj 555 0 obj<>endobj 556 0 obj<>endobj 557 0 obj<>endobj @@ -1794,18 +1794,16 @@ endobj endobj 816 0 obj<>>>/Annots 247 0 R>>endobj 817 0 obj<>stream -xXMs㸽ûWtíeå*‰)É©ÊÁ¯7®šÝqÆڝtHPBL\€´Fÿ>¯B¤d;›¤¦ì1Eýõúõƒþ¸ˆi†1]'4¿¢´¼øÛêbúpKɌV9Þ\]ßÐ*£Y4›á“tôi'êFŠg=7Ú¨jKϢ܈-ýf¥™þ"ҝªäåê_3š$ ìÝ¥©n«†T•kSŠFé -“¨èóýÝÝ+#SœuàMl<Æ.6>™ÇQÂÀZÑSkjmÝÑӇÅq·*¹æ5«²”é´-%LeÒ¦Fm¤¥ÞS£©µòh0  þ†Áë ‰·wÅsïQcD¦8Qw„Ì8¦f'ɖ›ZX»ÏÖ£åú’rUȈèñ[Âçp0Ã:ѸÅFŠŒ-üǁvkh#¬J©­ðÆ6¢Êå3û:÷¹Ku•ÊºÁ¦*ë6ïµyá²ôQ"¤× UáТ¼z@JmäImP.̙IaPÙ•j ÒÊöBᔴcª )c#s˜BÂ9¹. -½gg,vڈOüiuÁhr¢˜ÿúúóE<›EsZ&7Ñ •” Ë·ÝSAόI€s™ÜâíŒ_jY9MÈùzz¬ÙÒh×4õ_¦Óý~i,.2QGÚl§§Ë?X>}H;TM®a -€ÏFëäêڝ¿ãå"‚ñ¿Kšãxéž:/{X²¿ñÖ ýUO…¨dsÌہž}eþÌU»6ÛTÔ2Ju9=Ö÷ÿ f1´¸¹žKº™G³îáM(xq;s¨ïiàWÝHá®¤ƒJŠçÈèéqg%G²½ý7'ùñ«TÜSOí¦P\⡬m(ֈÛ)`ˆ´mU¯´ï níçƒmdIwY©*eѳhulÚ©t×5 '¶’G1qMB‡é „Šv“Âp§·e)Íü8Kœ™ä®If ½&‘Zð´ˆ~°º5):ƛ-Łj£_£I;YÔy[0ŽØ€²%Ãj‘0Ñ •·ËhÙ=õ­°HgY¡ÛNqàZ‹{ÀÑóäéþӄ{eò÷/ßV_N—ö)-…ªü€¡6zÜV"Uš>鶖¢œ…?m’ë ”=s­¼Dcû§7ÈB“,˜Åó…ãøuE¥Ú¢X<'˜Æ™ßr£Ë"|¼ÿéîó??ŠÉQ-ÒK´E ™{5•¢[éÈÞSÙÖ F&pÛÂᥠ`ð9ôÓJs’“ª1 788WÛÖ;ün’Â1C2áüÌo®]£ðï?p28 Áùҏœ¾ùÚ$¢G¶Ÿµ)g‰Ýe~‚¯hž,=tГ7ÝӛÔÃ6`Ëõ?w5œicàUVÇؘÕÁ¹àêy‚r{›leøŒ·‹øôíào¯fw¿<ï è~ü† Î½ýAV©9Ô ¹Y«Mfé¯tö‡p€¢¥ÂK¦Ð=NBŒ0°Á¨Uî?Êbä&÷øDðŠ‰÷舍¡ªñè±nO%J9¦Ï¿Lçà#³ÎÎMKpšÒ¨€ÄF•ü1OÕ >òBl!_ÄkSE‰Â°jé%Çۀ -ä½°0úÑjÀ7†•¢€b°"{`€-øÊÍp–,5ø -ªÎ‹%žã´W͎°Ç)¶A› –ª-7.Lš¬¦,­GNÿõî6;ÝZÄjחŽDA=‹²nPÐ=Ìï¾w‹‚ -­_ÚÚRÙâh³–†µ$Ž´òŠO±CT?«Wd'È«.@Âwé)ÁáÍ^sJ†~w§ãTHH×߅ނ}Ö#]±Œ@£Šµk{Ö210Đã(ÇÌð0]Âw 6HX2/g¶2 'ÖϐÒëË1ÜE¬œê—€ª£nšBÂȋóɕAH}c‰-•”'–i ü•ÉïÝ4„w¬`€'V£2N°b¼ ÈMˆ³÷Ø}~ë$L¯‚z…à -i²Lœ$ƒøf!%·M¡ ¾zçÃW³8‡wDld]¨”G¬èu³k@,ÓJ)EåX+Üý]°Ûõ tҘÑ7µ !¸XdA -Šæ~¸{zì4ŒBRÁ:Ы?Ùß2]çCЗº9¹ûS×°À¶¢Ì6¨. ðÂzTùª©âœ€‘°g©»à¹í\ì‡;~¾8P@b“ÕÄ3êxoýôû35FJfeÜW»q a’Dó1# Èù*×Öµ6gÅ3¼xW7"}‘Àéz$£m¨bzn2áñ1á»–ûëg.pâ?:_ßd›·Ëq½6à° BÖe«¶¥ÁÉP—€šo^ÓðB噿¹`ÆPUZ´|y@ºß7ÿ»¢m4KÒ5‚±ÇÆzä¹µ:Uà6f:œÝ#ïç)ãAî¿Ÿq'zØè¿'9^ø|uð…A¡šC?=x ãšb1áÀÇ/xuN݆;Æôᦫzn¾ô þß~±Cÿ˗9 ܺ{ôՌã†HýÇÅ¿.ƒíendstream +xXMs㸽ûWtíeå*‰’(É©ÊÁ¯7®šÝqÆڝtHHBL\€´Fÿ>¯B¤d;›¤¦ì1Eýõúõƒþ¸˜Òÿ¦tÒ슲òâoˋñÃ-¥Znðæêú†–9M’ÉŸdƒO;QÕÒÒt’Ðsm¬Ò[zåZüèè7'íø‘í”–—Ë]Lh”α{p—e¦Ñ5)½1¶µ2“Ðôùþî‰î••Î:ð&6>Å.6>šM“”€µiBO­ŒóGæ4¶«Òk^³Ü)G¹ÉšRÂT.]fÕZ:ڙ=Ն'óhà¹~¼Î’xëpÐt<ª­È"Šâà9ÇTï$¹r] çöùj°X]ÒF2!zDüŽð9̱NÔ~±•"g‹ÿq ÀZ §2j4Þ¸ZèY>³o6!w™Ñ™¬jlÒy»yoì —¥‹!½öl(C‹Bæðê (•'µAy¸0g&…EekTª±H+ۋ…SÒ ©*¤@Ž­ÜÀΙؘ¢0{vÆa§Køğ–Œ&)šò__¾˜N&ɌéMrC%¥ÈòmûTÐ3cà\¤·xÛã—Jj y_Oµ[ìêºúËx¼ßïƒÅE.ªÄØíøt¹÷ËÇY‹ªÑ5Lðù`•^]ûÓá÷t1OàÇtß%Íð?¼ôO­—,ÙßéÖõýUO…в>æí@Ï¡2濪üÆ›]&*™d¦ëûÿ3Ÿ%sšßÜÏ%Ý̒Iûð&¼¸xÔw4ð«©eÀp[ÒÞ%MgÈèéqg%G²ƒý7'ùñ«TÜSOͺP\ ¬m,րÛ)bˆ´mT¯Lè ní烫eIwy©´rèY´:6íT¶k›…«eÎQŒ¼G£ØáV@硢ݤ°ÜéMYJ;?NRg&¹+d’hoHä‘-¢œil†Ž fKq ÊšWïèZÒNÕ¦)HXOl@قa5O™hÊÛE²hŸºV˜§ó³‚,Ñm§8ð­Å=àéyôtÿiĽ2úû—oË/§K»”–Bé?`¨õ·ZdÊÐ'ÓTR4‰·ð§Mr=g`²'¾•hìðôYh’9³xo¾p¿.©T[‹çÓ8óÛƚò£ïºûüϏbòT‹ômQCæ^C¥Ðb+=Ù*ÛZÄÈî`Cx< ´ !‡aZNr¢k zفƒ7jÛ‡ßMR<¦O&œŸÙ͵oþâNnâŽCp¶#§k>¤6Mè‘íçMÆYbw™Ÿ€à+š¥‹ôäMûô&õ° ØòpíÎ]ögÚx•úsx´Ò;\=KQî`“­ôŸñv>=}Û{ÆÛ« ÀÝíÏ{(ú_¿1¨so:³‡ª&?kÍý•ÒýðP´¨TxÉøºÇKˆ6UoÂÇQY üäž(^1 +±ÑW5=ÎïÑ¢”CúüËxŽ>2ëìü´d§)Û $ÖªäyªFñ±)ÄòE¼F1Q´–( «–Nr¼ ¨§@Þ £­¼qc8 y +('òW؂¯ü gÉR¯ ê‚Xâ9N{Uï{¼bëµI!,bÑM¹†paÒd5åh5ðú¯s·Þ™Æ!V·ºô$ +"èX”uƒ‚îa~½[TóÒTŽÊ/@›•´¬%q¤“4P|Š…¢úY½";Q^µú¾+HO ¯÷†SÒ÷»=§BBúþ.Ìì³Í24k×öœcb`4Đç(ÏÌð0]Âw 6HX²/g¶r  'VϐҫË!ÜE¬œê—€ª£µ©ëBÂȋ÷ɕQH}c‰-ZʜË4þÊå÷všõÂ;V0«Q/X1Þä&ÄÙ{ì>»õ¦SAÂa…4Z¤^’A|3Š’œ‡ÛºÀЅP½óákXœC{"¶²*TÆ#VtºÙ7ž§iV¦8ÅܨWÅ73¬zm»g,rQ´¾üŽÜBãÙ®¥u×ƸˆoÝAg«ÁtuyÞ$܉á³ãbçv.Ý[VDÐiÊáYŕ1ޑ¡0ËÞÍtÇq–éX‰;øµQþÚÁ¸AÞJ·B³õ‰(ˆ Ô ã àãx3!tŒ= a``Ȑ5¯Àù™ë=9#ꪆÛ?ÂHàrUÊK@¤5ù½Rígj2àÁ2,Ӿʣ=ð˜sßnTl¯º«Á×Ç{PÃ{ˆüyáúv˜¼ã~‚üjŠš©¹B r\O2…Ñáï,"Ü}€X¦•R +íY+ÞÃ]°‹Û÷ tҘÓ7µ!¸XäQ +FŠæ~¸{zl5ŒBRÁ :Ðk89Ü2}çCЗFƒœüý©mXà +;QækT€ÞðÂjPYùª©âœ€=‘°g™¿àùí\ì‡;a¾xP@b“3Ä3êxoýôû3ÕVJfeȋ¶ÁRˆÙ€Ðã|“kªÊØ:â\‚§k‘½HÀt5É61-7ñôñU ËC‹u#0 ¯¯óõÛå¸][Ð?È›²ÂMÛOÒèd,KÍ· ix!‡òÌ_\0a( ߐí÷Íà®hjÃʁLœ` ±ø9îœÉ¨‰g÷HûyÊxŽû¹F܉Ü4º¯IŽ÷=þ2A#pQ¨úÐ žÇ¸¥8 8Pàñ»^½¡ƒiâcüpÓÖ-7[ÿo¿×¡ÿ廜9®í5újÂqC£þãâ߃Íendstream endobj 818 0 obj -2086 +2085 endobj 819 0 obj<>>>/Annots 256 0 R>>endobj 820 0 obj<>stream @@ -1930,95 +1928,98 @@ endobj endobj 846 0 obj<>>>/Annots 283 0 R>>endobj 847 0 obj<>stream -xWÛrÛ6}÷W웕›–(ْßêÄMⶹ4Q&}ÈL"! 6 ()Yß³ R¢é4íxr±ìåìÙ³‹ï'#âgDӔÆW”•'/ç'¯'4Ñ|‰o®fSšç4L†Ã!ͳAa^ù=Î=ª7T­M ʜ­¼+hi -M•£\WڗÆjÚ­UE¥ËëBþ¦p*—W5‘ªñ­L¦*ã,ek=²9+w_ÌïO†t>')8ŸkŸÐœ½ 'K•i*Õ¬«<7v“dõ®o8h¿58ºtž¾»0p±ÕÈD«°?#Uˆ¡Z­s$„Hºç;wÈ~åÏß_¼|Ö`£Ê¿wÑt\ü²ErÐ`@l s£…ž… À{tV{Sí/úvûñæÝSÄgŧ;@y]è­²5‰¯Q°\UÑ52v»gøo¢6ú¬QÌÆaD¡b™ÆÒùgéJ™"$̯óІ®Òq2¡ÉlŠÿ§øƒ(–‘e×4šD–]ή“«'<’ ~è Â:¼ñl»»¥ÄÉòäž2W_Á'p æ›(öJ.2ê^Kîµ…˜¹Ûz?—’˜Š)À†„\=8Y Ü)oQøœiº4¸ûmðéîöۋHÃîpD¡0«uUì)7Ë¥ö¸Ç|úòþî/PÚdkZ+”ƒ¼²+MnÉÞÚ7Äâ2qðÆé^²  iC Jï÷Ýs×° 8<\Ž„„î*¦_SßÓ@÷nÁѽh…Š•ô¨DjòC\앤{p,¨„ˆ1îyn¬F~Û¥YÕ9Wx\@KH—)%.bà(l¸‹Ùz~ª)`{ÊIúôJekdÍuèÆFlnA&úöÀ¡¤ ¬´ÕJ‚à -'”Џ€“åþåZo@ʹÖyˆTªvÎ? /ð/¶Kèëlsµme TÞ%X -˜£ðÀØ焱Êv?clý½ÖŽ¢äP¨…ˆhïŞ¥0w¥zÖ`Íp/Pk´þ—§ºjAá2¯«Ú[8dcŠ>Þ¾1@Hø µÜU…‹v¦ZãTQçM|ªŽ{³1 #œ ,Gí=ÜnóK…Ðó¤ŠN»M±ƒjin-e£¢öœ§E'+&¾ƒcb‹|4(Ã:|``-׏ƒ -žItmF˜<Ãzt¤¡çšÁb~d®„Lâ Z¡,@,½ª5ÊÅnÃ@a m?8PS²`!Š”­ûr‚ ‘-ÓIœ‹—›)¬\ˆÁñº‡ÝŽ™Ý=ˆsÇs‘±DlËÅé6 A:KÑq?ïÊt2zҕèÉ;@¥‹|ã^¹8j䓣,µØXiÄ}zs2JgØ/Òt£%¥ãY2j~+èsåMSìO–‘wÌl}+/øÍ­-Í=ÚS²Š¯£C¿¢Á=Öaþþ—`ÕÖ%¨­Tƒ:^áÓ20¶F6Xí퇯óÍ0ÀX -y?u{"Óø.ÍuȼY@7×ØëæJW‡–ã°ýÊÆΰùÚZٕq®ioèXMøº³”cgä!Ú£+$eïjO[?ÒÂ=âT´‡ÐÛ>?8 ÒçïÐõP¢—7XùçX3MQ¯ÿ Æh<}.חɈ©È!¢ ýXË«¡ƒ-c9—¡ƒleóê¢Þ3hԐ}¹Ç|ÈßâÁ0—¢ö·Åiß*ÇòÌ@‰2µQ <Ð¹Ç27€‹íâò jßSñµ"ûÁ­hs,؈µvµí~qd»Mæ ãÔëU]( -EœAù±$BºÀQ ¢`å…8U¬˜X5– ¾ Õ^jó;îò±.4´d‡— ցØüŠN#Hçk¥ÉNeaØ0—·X« ífI̤ø8 -)ˆÕ éÁ•EÍõìËß(k/ PX:ÎMYÀ›88'/PZbåbcIˆäíz ¹q ºx=k^t£+.îÕô2™ñNÑøèÝ= Û+pŸOS¼”óÁÿ}ÁL¦˜—+ÓaÓ žü‘×ûŸendstream +xWÛrÛ6}÷Wì[”›–dْßêÄuⶹ4V&}ÈL"! 6 0)Yß³ R¢è6ÓÑ$¶E`/gϞ]þ8ÑŸMÇtqEiqòf~r~7¡ÑˆæK<¹šMižÑ0‡4O¹Yxåw”;÷¨.©Z›@”:[y—ÓÒäš*G™®´/ŒÕ´]«Š +—Õ¹ü$w*“W5‘ªñÃV&U•q–ÒµNŸHٌŒ•»¯ç'C:]$c2p>Ó>¡9{5N–*ÕT¨'XWYfì +&ÉêmßpÐ~cpté<}3vaàb£‘‰VawJ*ÏBµZgH‘.tÏwæüÊ9žŸŸß>kPªâïm4¶H ˆ ¤®4ZPèY8¼çA§µ7Õî¼oQa·Ÿo>#8+>ÝÊë\o”­¨Iðx‚eªŠ®‘±Û¾Àcµ9ЃF1‡™Kë…Še ç_@¤+eòp0¿ÎO@º_$šÌ¦ø}ŒˆbYvM£IdÙåì:¹:âÙh”Lð¡¯_èðÎ;°íþ–nw$Ë1>È}Ì\|ŸÀšo¢Ø+¹È¨{-¹×bdnèã\Jb*¦: rõàdŽps¤¼Aá3¦éÒàî÷Á—ûÛï¯# {¸Ã…ܬÖU¾£Ì,—ÚãóéëÇû¿@i“®i­PòÊ®4¹%{[hß‹ËÄÁ ?§;É&€¦ ‚*t¼ßwÏ]Ã.àp9bº¯˜~M}_zt >ˆîE+T„¬¤G%R“íãb¯$݃cA%DŒqÏsc5òÛ.ͪöȸÂã +Z*| ]¦”¸ˆ5‚£Pr³õòTSÀö”yá¸Í—BFv+ËÒ°+F%\tj/,ášy\¾AÄ,áÒø€º™BŸÆ,zù觭~®bRHgé] Á×Rbæ‰&)Yé]ªB*ËÜ@²5j™ØFù 8ÃûîymQÞÖZ—l1gñw/¯næ¢hzÌ·‡D‰Ë-t…fEqĀ¤Î«KŒØ ,3T Î¨¾&T`8ØņQîÑö$ÄF-Tдֹ(º¢*[Pûõ´¶ÜiÚ!’’]6‰¶Ä\…GÅìmb ­Úu¥grqÁù¹ô\\_Ëd9Œ8‘žË„¾HúôV¥kdÍuèÆFlnA*úvÀ¡ ¬´ÕJ‚àr'”Ѐ“åþåZ— åÜë¬F D*U[矐øÛ%ôu¶¹Ú¶²* +ï,ÌQx`ì3ÂXe»Aÿ¨µ…£(9j!"Ú{±c)Ì\¡^4X3ÜsÔ­ÿõXW-(\Ä¡àuU{ ‡lLÑçÛ·" ß᫖»*w`ÑÖTkœj#êñ¼‰OåÁqo6†a„3å¨½ûÛm>`©±zžTÑi·)¶P-Í­¥lTԞÓôèdÅÄwrLl‘eX‡ì¬åú¹4¨à©D×fԉÉ3ì GGz®,æGê +È$ª +ÁÄÒÑ«Z£¡\ì6 Òö/‡jJ,D‘Òu_Np!’£±e:‰sñ2R…• ñ 8^÷°Û1³»qî` RVƒ¨‚m¹8Ýf!ÏÆ踟wåx2:êJôä= ÒE¾qHo]5òÍÁ –Zl¬4âÿ¾¼;gØ/Æã!Œ4¾˜%£æ¯œú+ïxŒÝãhùÀ|ÁÖg±ò€ßÜÚÒÜ£=u.; ø:8ô+>>>/Annots 286 0 R>>endobj 850 0 obj<>stream -x¥XMsÛ6¼ûW¼žªÌH´H˒==tœ4i3Çn¢Ž/¾€$$"æ‡JVõï» ”Ìƹt2±%xxûvü÷Y(sü eÉÅR’âìíúìüÃRÂPÖ>Z^­dÊ<˜Ïç²N&ÙAlVµy*¥©¤ÉŒýõÍúv%Ý®Ù*¸‚Ñu:yŒ–+ñ/ÝK¾›EË`Á÷kl•çÕސ–¯7·ooD¥…)mjÕT5Ϩu~ªtKDµXY6&QÁ³B'™ÂêÂö+>¯ÏL}â¹s™…Aijî{'ÚÃ9#Rm$­ -eh®ˆum‘ÞŒ´¤¬$¯Ê­®¥Ô:¥W™zÖbõNÁOÍÃf'§©$©Ú²œò‘ÁÒ³®ƒ.%}–±­OÈCVõٍ5âV©)·.Çp0i þÿ’ýÇÝÃúNõT[³- sb¶ÑÅËÄ37r¨ZQµ1Å.×t€ùp~%“»èO‚÷aŠ*SÙ›1Y“25ʨ•5ùáñ –Þ2w¢ÿAµiv”óM]t ¯*ÜƇfvêS5ÉØ°‘¬3ՈU&¶ª`9?¯¯ïonìtÝLÅV.ÞB¼W# źi€lcø´ÇJxÅj#=Œ•ø²ZeŸAî¿>C÷ÈåEˆŸ‹«~Føœn|·]KˆnØ e×+Öc»…apD|Ñ·¦vù·4zþ¡o(¢‡-:éŠå`©k+Iªrc¶-²Ì^a©à2ÑW5ië%E]sT Æàœ¼½y÷I>®å¯ûŸ^<éàq„ONÀF9CûXfy:BýDb•ý^H^¾8öô;Þ^,ƒðd/¢÷Ç8ê­ôqŒ]lP.ŸÎ½Ží­çßÁ‚3 |*€¡cȃ›Ēä él¦®©7ˆ93ؙ?{ÐiS­+SO߾̫^ !¹0›h´Xªƒ1@Ŝ&ä7¯æ^º‰F›Ü4=Y£e;‡l€¡ìèGvJ˜ìužó÷®"ÁØÄü3ð -ní8øDñvuõlR@8>ø°ûx}×MÌ(n[:ŽªÙͦò©30Ê-Íù,]öº`‹¸ÓçAzMÖHù½E췑±S®=†?a€è75œÍ؝ûź¢”ùÃ)"ýïeÑ ®m‘8î…ÄÕ®ˆ f¶LUº^í°Á¹àö¨Fwî3“dbÛ†=çQ?¹ Èy]*“‹'88õü:"úfìÚÖÉ ¢tCpª=…q #Œ®v µåô1t0È ‰¦-Ÿì£—­­Ïq£ð‡êqù˕'wÎ=…rDtZ ´’c & -§£"¸~Q6%nMN2s’À.óP„úwáùëEãmðر:í ¾g=waìk3ˆ¶3—aöÿqÆÅm w4$ íГá1iŠÅó·GLè䮞š _Å¡+ö*Ý )ƒ‡1”`œOZÿ>k¹ -¼Ì鄫Ä.òåþ–¬Dæy—„ŽlpAX¼Æ5nX›Ër,q8ÎՄ¼ë®~äëSãªò 'óíèyy ¦ü^­.GG¨6þB€Ë»Ùf 0 ¦œa!ø¦v2SkҘÞYLÌ_„È(Ý%ÔÄZ…)?Õ;]º[p»Uí3 ì¸+7¼«õ³©ZK"t¨#¾º; èäÌaéüÃUÇ^áÒ$Ëë ޝ<0ïëê.˜üUۅGÏf~ñl͹úµKÙbµèÿò± -¹Eûóì__ÝAendstream +x¥XMsÛ6¼ûW¼ž¢ÌH´(˖3=tœ4i3Çn¢N.¾€$$!& • ­êßw iŠuzédK&ð>w÷=毳XæøËj!W’go×gç–DzÞàÉÕõJ̣֙ù|.ët²Þ'¿ß}[ßÉN9I´.åP™ºÆÏMe Qòê‹Î~Wõ,Õe]™ô•ìuåö:­Í“žŠ³b6"Gۈª´4Δ[Q¥­wº’Ì8\IšÚØrúzýýl.³ø"Z „ oê·OZj+…ÍÌæ(¸'¦Äµlé +}Ø©š‡6?p​0pêA¶ztýœ¸jSFf‹«hI—ßvGq;Ûä™|¤µÉÿŽ§íñÙ*ºF™pøaqµ’ð°+ŸõÆ|åTžÛƒó!}½¹}{#*+LɬUm+ú¨t~[ú#¢_Ö&UÌM +îN®;ñy}þ͔‹O£ZÝÿúN6´‡ÔG6Än$³…24W$hM$ҙA;ð )­ä¶Ü¢!¥Ö£òEwz¯§¦³Ù 3*MmSÖ}P!3XzÒUԖ¤+/®=W×vÕM4òV¡À#À´)øÿ+v€)Íig¶%2aMÜÑÕ8ž5ø¸éA)¦Øçš0¢ʯ§Üg?H>¤ gr0nÇb=L6ÊTh£VÎäLJׄÖzËډþݦÙQÍ=y9{Õ ôq¬òt„ú‰$*}”fϊµÏ­‚LÎužïUeÁgG• 䰂lÚ +#9Hlí~—'hùªâ‚Rf ¾$ÖÖTÕÇGt{óéý(ü»ÏïåóÝ·‘eoµóz}05ŽTö uw’*ȋz„4×ÐE2€S·´…0Êí¬à'‚¾PéΔ:òØ}åä°—–]<¨Ò«:äBÑ.û}qɱ` ž½5Úg¸8I]ãÄÀE@½ÒUÕÞsÛ Ì@?ñ&2nG'桇£ŠÁ#Ë`+³5¥ÊÅÕä8~u”ƒ†DÐM»­®1!/õ¢¾„žVH~ë™ NڝªË7°nêÇÌÃdŸ7Û­§éh ›\;ŒÅl@ᨆ4Â.&½—#–ùâö!û* 0â, +JYi!L¢ÓƒïJ·b„QQ avBjWn’JUUAeTY\£)Þ{Ø€ãh)T'1§¸ç¶ …ÃØ_EñÔïì«*SMÎù„]Ka7¥ñó½Ö ‚Ù>>>/Annots 299 0 R>>endobj +852 0 obj<>>>/Annots 291 0 R>>endobj 853 0 obj<>stream -x¥WÛnÛF}÷W ‡(ˆEŠÔÕA[ ië"IÚZouQ¬È•Ä„äª\Ҏ~|ÏÌrIÊ!`Híî̙9sÛÏ"šà_D˘¦ JŠ³7ë³_×g“`µ¢þQíð1¡8Æc¶ZâÅÓ`A•¦-öNh:›ãÓ-MVÓþÐb­rZp ª»T„—º õpP¿NeyBëdTS?{±þx^FnÄ΀|ŽTS›Ä”[·ÜŠËú8‚ ¼çÔùB}ҔäZ•ß*¡*ˆd» QÉ^«˜ tR¸h<¾Íê=å&+Óo•È¦}ÏYÊJ[«÷Géêõ»7¯ñEˆ2 -[…¹ITZUlÔ±ŽQ@WZS½×T(vRR“4….kUg¦¤lKw¦ásGS‡æV•5Õæžzk -}»×p¬Î­èm-ˆIåÖЦÉòTTµîNIÖIS«M®I•)åÙ¦RU¦m VH‚Lh¾š"º\ÐsûÈ//ZOaÏ|zÈQÌ@ èg‰æÚYµgF¥µà>Ù}P{y#AÃN|‰ŒÚ±ÿàð3süè~•Z§ÖªšRŒvç^½÷Á±¼¥Jp:ŽT¦ÙíÉÉ,oƒ,2‡Ì Ƭ¢CeºbI†˜sæϞ“5N ê‰DÖõ c;h”(\¸„Ö4U¢C#Gxÿ§…€Wþé؊ü·Žû­iÀoVÊD[«ª;6EJ»ykòÜ@äŽì]±1y–À•å§W_;/ilÎ(þÄO"onÏIYbqtèv#…ºN: "ÊçòˆÍ…+`%5VW`;0| ä‡|KíMf3N‡me -Ö1 ”åÔvL¢€èÝÝ×#ÝfПó  d#QxÔ¶j6,u¼´mdÏ]PûwPH®ô•|±8.\]…e“Ú~á÷Û½JÍíp¿·ýÞFq™ÛG‡—ÞÝãhX7ÉKTPvg‹Ê'WWÎ/nu’E3¿#f% á[‚ÄGXÈS×P9ȤKɁR®½Em­³¾E\Uˆy[ëumƒPCºnššS…àö­ÂRE×#.„©)ŸsµµEŽ\¿hk4Vù`¡Ê†‘w4}Yև=0ôÆÐø†þ£]¥ÞKÇæ r\:ç²½lÇÅâXŠìÊr)þð«ed LÕÉÞXÚ¨ä)B¯ÇÿØ,¤m ñlÖMCO5† ëxÆi[ÃtØl±y$i&^é]©œªR…%È´”¶Ê£qrXx)™ŒaQW&ç҈«½ºÉLEfû…i<@è\7¨ß¾{½[Úi/â‘ïÏßÎâé-9ì -Š/f: |åtÅchŸ5óXvΤÃ÷C!­÷Ú")`oªmReÉ*ŒüRƒDž;ºÌè‡MÁ€‰säɽ­®_0Ô~¼ñ[øw‡±á‘²Õ9×y¢O2©V·Êòïc± ›Q -“fÛ¶Qfe’7©›túnãkoKà_»ÜlTþ7Ypëìè~óŔ{åì‡ ~zláÄrüÔð#Ê tr¤s7(SH€zOÏ_>?we÷—ï^¿}ÿÒ/³@„}¼âKÁ$2£H¨•¯–ÌÞ¯Þ÷1ȟ¸šÓSêë^ ȸ١»$ôœüH/űñòž•Ï85YŠ…Vø㘏åe‹8od „5AÖ„û͌äýöU„ÍÃ+Š‡ÕâäGA š±@9÷ð¥ãáŸ_€ƒ¿¼ŸÂ¿à»ÓCÇCów¡w“„.1¦# xJGUé\Ãï'Œ#ðSö:èBÇÆU”?N¡Ÿ®¤¯?ÄϚ%tExuÃȹÓGš1'3íє闏Sšã弋枔“ªÃK¿L¼ª ®»|›Å]Ê]s~¯ÌG$:ý2¼îH¼D‹%¶—±Ü|ێAkmyúA=ÄÓ҇Fzúl9CٔK™&çœýТe„endstream +x¥W]oÛ6}ϯ¸@ꢱlɎíۀv]†>´Ý¿-Ã@I”ÍF=RŠk`?~璢,»i·v)àZ&yy?Î9÷ꯋ˜¦øÓ2¡Ù‚²êâÕúâ§õÅ4Z­èøa6x˜R’àc¾Zâój-ÈH*° Ëk<ú•Ùl¸rµXôgÜWw—ànî?pÃäæšâ˜ÖZ¬–´ÎÝú”ÖÙ(Ž£«hÅý¨ëBmZ˜uN™®vª”tûòí«—ÏÖ.&7óÞÈ8YDs˜­·;ý9Ñ(]Îúg]x¤,íŒlšÙƵÙ6…6{aòˆØJ¡Œm¨Ù)±Aî,Uâ@µn(•|ý”Æñ,JøÒZfÒZa”˝¬sUo¨ÝáîýV6[iHwð [ڊÉ÷>(ÝÚò@i«J¾‰*”ªZ%mäCœÒ5§)¦qrå#4Z7Oübìg V»|$ÚFsô'gÇn}£Æ¼çKç+qô•RÔßjÁT]ú£Ld[—¨ÉMÄW8MB%Ç{ÕlñQ#7ù·:Æ¡ýŸ³¤jۈ²ô6òÆ ÀµYx ¬·Õ^•å%¥ †B´esŽÜÕñMZk&¥ÎD9± ‚Ó;F݃ ‘J¨º³’묭dÝxP«‚.>7€å^Ô@–>»ÞêJ—`•,­ŒèMã<&QZíИ»«ºtç$?ʬmD +ê1 K•P…hD¼º¼*°rꉎUàï¢'C¢ûÈãŽ×£ÚZÔ>ÛFGPá9o8)pß!ãèÚiþ‘¡:ôP-e.­&ÓÖ.hð*\rpjoD¹؍#F·›-7E¶—²í”7•åõN¶4¨לEÊ^’Õþ(t'Œ½×Æö®Q¶£(òp™XݚLN‚„ˆïvîG¨+ÿtÅ +o|í Ý¢¾ªAAΊ“Ns¡ËRÃä†ì¡Ju©2$¼¾ñun—5­sç3^~ús”|ÖówzIÂgˆ Ð@æˆãÔ³ÑD6YŸ£¢—G\9¤QRk¡Ú ÷ *¼#ðŒ5¹+탲ŠéP]ñƒ‚r¢üµ}¥¾ ¢ˆèíáë=-¸–Zߣl Â#Š^sè¨R_—óþAÝßN€\ù ÷ÄæX¸z…吺~öÛ­Èõ~¸?Ä~¶Ñ¥ÌïC=3|lÚcîi½n"š ,—PPNgçU «+ó‹[]ò@4ÑE¹B4À·F©B™û†â‹s,¹ëRî@-?6!¢®¯7ªBn+Ìc¨ k) º¦mÃTá!¢X2t7b¼0s]?euÚâŽÜ=#¯ÑX僕¨[ö¼/ÓcýÄ¢NB04~ ¿Q¹ Y: oÀqי˜Ëöl§bqj"û TéÄy PKªÌ¶ÚR*²{„^ÿ± p£K×âåª?×â97GZÃlØl•>BÚAˆ·òAQÒNQI”Œ@êT“a¬8d²¿€EctÉ’ÀÆ3…i C¢ÏÄ¿Ñxà¡?0Ðï0†;yƒOK7Ç<ÿöóE2»FâéSDEÉõHvã8;0’BqïF«»g§{ÜnÞðE~7‘­>¹>G’9µÚ Ë¿]ýè\é\]£TuV¶¹ŸtŽÝ&hoWÀß7¥NEùY™qëì t®sa£ åLξ‹¢è‡ÇžÀ,ã§A!/¸“‘ÎÝ ¦@€fKOŸ?½ô²ûúýۗoÞ=ËlõMV€f¬lz9WÖ=t¥ü4ó 6p凢×y£ýàпB ò==wYM–g!>a¯©U9 +} +xÂ>q_ðª"d÷]i&7¡>b¼¿Å´¸æ÷;¼2¸W.úÅèÈ9½Nžîòx±Äöñ2q/!Ý ­¥åFhâÓÒûÖÉë|9GFÜÆ¥kìÈدÿrX+“endstream endobj 854 0 obj -1521 +1516 endobj -855 0 obj<>>>/Annots 304 0 R>>endobj +855 0 obj<>>>/Annots 304 0 R>>endobj 856 0 obj<>stream -x­VkoÛFüî_±MXA$Jԃ’ …ہ $NkA|9‘'‰6ÉcîŽRôÇwöŽ”dE6´q@ˆ¼ÇîÎÌÎÝ÷“zø iܧADq~ò~zr5=é“ íz—õûx 'c<à ZÒSñ֋¶#ÿ܎DÑ0Ökƒ ò#‚eˆ¼} B÷ºGg4#›ѧ‰îÑ4nÿ{M‹t%i³´H¨2RØPdd–2Ëè[Kن -)™P:'»”Z -¬²2+¤%ÇҘooßN|™M!gòçǓ>׍£ O9…!'ïß2ºclv»H»?ÁŒ1æï'le^fÂJZª\&©æx»¥î–¶èWêòŒ.Š*l÷Íe÷Í}šO$!$Òcè"÷öb"x<‡Ð iÓîL˜åŠF£`RsÇÌ;RA÷ú Ð0S€ª?z/ ƒQ0†ý®Ò‚  »‹Oï/l­¤&«Ü·/—(Q¹H Ž×½n7ìô} ­«Âò|l0WY¦€Ð‚b•çÜc—\<‚ÕÃíš ´‹Ð¦õR"w©_Gj]Þ~º¸ùü4|‹Rã6-D.y¨Gpà¸m©9ÑFUš¾B}jmêü‰ó9Øú"ÉÓ"5V «õ»]¨ÖïDŒôD --ÐK®ÒL.¤!äAB~‹ÀÇF֌lÔJÙ×~tÔMÝÊèn¦b‘uÈg¢Ë¼sgè2&‡^Ç8ì:÷ôBÀ¥ái -J­J¥¥)UaÀ‹g¹¡Ë,U•%4“çôŠeædæj À££Ä¼úI™©¼ü¾ÄÔ:МÍÁÏθǼ«=§ò!\,:¦óQ@wVhKUéJªÍ)¡DÈ\NVK©ýÅ×yLé+YØJdÙ¦Í -ƒÃÁËÖ¢°Nç*Iç¯<“ÏÈp8D3±NK7ƒDeÑJ6©p¿´X©º5²9À]áT M%ö5Ä*¯–µiVqòÜ¥2&ež]®Iaè¡Â&³Ž…YÚ¦¨|žjc¢©ò)¡Ãøµ‘³3¤°å6†Z~ÛóhVô¹‡ñ?é½ÁåYFnNsÙZlPµÐ¢Piâ¨ÌRF¶6SÁTœŽ=׌Fà@WE¿ -‚ŸìÎÒPGHú‡Z– ¤É³iN—yÐdhŤŠ%“S‚Ÿ1æµëó°Q&'볬iiúyЃ¥ÿFÔ띻ÿOÒØëûÏjú`ÎÞ¤Ý1ÌRo“ÕiW18Ü HLbrCÌX5ŒZ}€ã›sUøõÿÁ,ìl®¨S½ŒYmH2†óÎDüCÎà׬~­h²úZ{ýöë6YHû¥Ë¿NzÙ¦W/¶=®j`›¤qÇ­‚ëËN§Ï4MZ®nßýà¹|á"֌Ï*àªÓl½7ò±øG¾?؎p:ØéQÏìâ؂©¹á>Ä¡pÖ| -d'tÆϗÖíl•ªÊ°kÝøK[kBù¦qöSTtêßüFÛã·ñ #¹ÃŽŸ“§ïN]í©î/øc, -Dp"Â&!20¨³K¾#ÔÊ[h—Ü—Þ\«œÜ*híYöNÍÐ_G}ЃkhÒ:zx®kÉ-|“ú¨ qÛStæzGý¢ÕƒŒ-]ª¸Êáu®#xU'ŒÆ÷ÝìúESÊ¡Í‹…¡Ûʱ5!7q<àÕ8Çþ8ùçne endstream +x­VێÛ6}߯˜&ê k[’¯ (6Ùl°riã /y¡%ÚæF’Z×@?¾gHÉ·x ©w![ə9gæÌ|»ˆ)Â_L“„cJ‹‹—³‹×³‹¨7Òîb–¸‰h÷N'ø9ãb$-°4¢ÑÕUoܼ¹šö†áM{T=\b¾üýæ"™òþ˜‚ð5lnrúÈæýÚÝØîßFtE³%S,Ò,óF4K;kUÎU™Q­²ç³û½ÍþlîÐïGøt¾ò¢n2¡nŒðpR‡øó”j+i©2K £‹°œ&¿‡ÚP¦ ¡JZ]W–OL!’ñ!´‘ø›G#áÝðd0ÿS!ˆ<×k’e]H#œÒ%émñ±ÒX@êDð@ÔɏýÝÙ†CÝ÷,°q†Òx„vL‘‡ð HDÈ¡±¿;k|p=ozÛYÛ§`©ä1ZÈc‘“]É<§/]æ*¥ÌdFjAn%7´Øåd^JG"M¥µ_ž$Gûäˆã!繿;]œe‡“E• 'i¥ ™)óxŠôyE„—®ÿì¦ÿìӁ#Ã˙=`˜ýÝYG¢ëö+mëˆÇ㌨Çþ\ØUcL@ Pü@$ø啵޿½¢8æÒƚq„ìÛ·´F½AoØ£?5J€ÓÇë·/¯ ö ×'?ûpóª©N¶Ø¿nì&¡Ö:¯KÇë±x¡¹JT¹¤T×N)ÄW°x|ü}ktÏÂ%­WÞKIc©sóþíõÝ»CóRÖZŠBò«¢3ð!vP˜´Ñµ¡ÏÐ.½¶­º°?GG_g…*•u(iíÉßè-h7sÝÁ=¤D¥ï¶qbWF=¨\.¥¥€ä‘CAÝzÁ6¤ºád  ÑÚ= oGmÐÔ¯­éç:yߊb.úÌ:aՕ©‘îŒ2! ¨¹OVi)÷KˆóT¦?ÈÒÕh›KÎ0(´k-Jçó\gj± ™g‹9Y6k65ªò+HԍÎ) +µSåƒnJãț#àÀÔe ½êõ~°:+K]!é_4|Yµú c§ ¥“GE†RÌêT29ø ¯Ð ý¯ÍLv6xÙÐÒÖó JFôQ½ðÿnì§×ˆÏÏY ‚o»iqIÎl¤%TÅ¢½!#1Œq‚rAÌ9kxC˜9ϼª¢#üÌBΚºõ£Ô΀Æ/H2…òÎEú‚œC¯9ûý$´õês£õÛ§[g‘Ú·1å?½^^ҝ—Û¶«ض´ê¸Í`?ÇPRF1Ö¾zýþ·ï4—;P3öòûym2Œ6íÑ{oÞÔÿÄó{×aH=<髙»å© 3{Çuˆ¦ð ¥€œ6 $Æ$Óx2ƒxh팾—©£bŽ-gš÷uãñË»“sÖi4“fp”»9¨(—–Þ×ދá„'T¿p2àÝÐç¿.þ13åendstream endobj 857 0 obj -1268 +1317 endobj -858 0 obj<>>>>>endobj +858 0 obj<>>>>>endobj 859 0 obj<>stream -x½VmoÛ6þî_qHÆÅbɒ;)P ‰“Ŗ—-چaÙY¢#6©TFO·èøÈ9 FÁuzõÀþŎ!šc:c ¥Ö<€(éMϯ¿:“EÌœ¤úMô±3€~€9¢ã¦ýÍÔ æ÷ÓæûTee^Üb*…Q2Ïw;M™2pSÍr®³Ý·IƊ¸½sñKÅ5k÷y¯dUÌy²„©b±‘ -®¢Žè_Œ Ë~ýpŒA”¢ V‰Äp)`ÿž&Ì>$±!0cPi–‚‘€&¨Ÿs|,Ähs˜I“A.“8‡X¤ps6¥JÛ·{JH{©%˜Œ5ý!^`ä9Â%\ÜC"‹W¿%j¸Ë[‰IŽÈUIi^9ëamíQB˜+”±Ö‹Ô›7–þ,+Й¬òÔVÛÔ1›Ø`ÚòAãûƒ¥¬<ßó™Iü]»÷Ü.Dcf«ƒÔqѕ¿àˆ Ö̶ ‰™uåOõÜÛg& rÅlg¹”Íã*7˜9ËsíÕë8¨g:Æu&³ða³°Q©ØJl¹ƒšxŸ—·ÑKèÚ½h¥¨ña¸’.)ßj•ë_¯Ú6Vk©wè ½±ü7‚¥Æ:hši±V‰—ú\pƒt1sù6Ûö@›X$øœç̊uMèb·rÅä،‹t‹#=HcV éc©&†Û€â9Šm#ÍÕN€i}± ñ~+¢Øáæ¢a{2U ó" q‚ü/i4P?Wc¨æŠ‰õÃñÓæIi2åsG9¶Œcì6€&ÀDñÒÐqš6¬°•sñ$Q¾A§*ö‰l·T²Dd4{¬˜Hæ¹Ü– Ø^¶gAísPkÂz ¹lûÀxìÀÙÚ¬­ñs%‹¦ºgó¦¨_iåÛ©æ£Îf±üq{¯Ñl$»¬Å›/©È¾}Ë£}XU‡eƒÿÆØ!ÀWS¯>æúá¡zv›»ÞÝø½iC}²Aýó͇«³w{·—§{-,É$ôt÷nI<4,º´;¨žxÂô[h[Z‹c$κ÷ìú&úp}uÛþûóèǓoßu¿n±Sz-&WÚÕÿ^Q º÷/•þƒÚ~rS© ÿÿ¨u›’ ao1Êulø·Êúºn9ôÙ#^ ûqó!üâË°þò+¼~©J2ðŸb«¹_W3½ÔÄ2øô îîZ(‚"¨ ´x(f*…ìwn[NŸé}}„l߉PŲÜ_k8‹qtãÐTŠéRŠ”´„׺ÙàɑUÏ߅™°R—I$w¨¯¢wYþkrDŽ¬ÜmR;5ï_Õ§o0{Íõºw{ryz7J~Ä œÉ¤*°Ì˜®‡X?Oй? ñžöêƒ"¼@"]H4\W†œG“^¬ãdDðñ]ç[j—endstream +x½WmoâFþί¥èàtÁÆ@ 9éTåStMH·UÕôÃb¯a/ö.Ù]‡¢^ÿ{gwmàU­ZL¼3;/Ï<3»yjÐÇoã CˆóÖyÔºŠZ}o2ÝC.ð¥ÃS/„Ñdì0ÆÞ$…uûp2 ñiDh¬Z‰ÐJÑÃö–üé‚¢‡“1D‰•÷!Š»³ù3…Ê6Çp KòL“œ&o 9a:W³n×ÞFŸ[þtPšë®Ÿ3”(º"’h!¼rצ ó®ã™å>ô¡7BïÝ_D1áèô’‚B „Ô R\`|ZÀ‚jXHQ¬€ñTȜh&8¤Rä`wÝ]^¼wîúpj’ ÐÁ‰s …Ðß8aà„ÃJ0ã¤ëJú™ˆIæ£ã9ñ1T@oñ•ÅžÝÕ °.f'ñîҁr–䌫2­ò•¯ˆ?TéWä"_úU‚k)²ì°ÒE4ïŠyÆÔò°Æ}¼¤9ÆD®8ú_I¦h³ÎG[ž;‘±x’ÀlÍK;ÞõLmB$)¢aÅӂǶœ¬2åºcéÀÅæ +…ü+ Pp–2|LD+ϹÐK°å³œD˜ RÙ7ËåA$7†#U}†ÎsŠp ¤ìb‘çÈè-ªîØ2t@'Ù #1VX¥Ö‰#JÅô¹ÕRYb)Llè ѶxTøþHa# + ٜû®Ouì²Þu6\üˆÆÜfW5¨KÍ̙Iàt]˼`‰:†…}.v$LÒËŨC.¡))2 H—,Sõ†55³]êºÓô.*K‰%w°CBï×éíAôºÖ–Ùi‡"ŽÀðt;èø—€8æüéév¨ ‡[áÝX ïÄz¡Sö».˜ *¦ÅZÆ^â3Î4þ¨|îT*³]PšHó'eµÍº#ô^2·s˔r,Ö8҅„Ðg§4Q†áÖ ’b³í…¹µÖ 3f×<òjΖ!“çH| @bäÿʌtɶc¨ìMÔã±á§Ó„™‹„¥ŽrÎ-9ö8qŒ­XõK¶ÒÆI’Š6sƟvq_¡‚GÍ˖]I±Bd}*()Ƴ©· ØZ6GaÊç Vër>®ëÀxíÀ©k*¼=µÊìüi’((A?t(9Û;4«–Å“Ù6o¶1åDöu,:°«Ë +ÿ½±cßN½ú©iÍúª˜«2,ƒ/_àᡁ"Ø%Á‚ Iu!‘ýN­¦ô§y÷§“rxaˆ×úp>>>>>endobj 862 0 obj<>stream -x­WkoÛ6ýž_q‘…ؒåďŠtmÐ`ëc­±aX†–èXµ$:¤Ïößw.IɲgºlŠ÷uôýIDCüG4Ñù„âüäõüäíüdÌf´è;|Òh\ÐÅlŠÑ-i‰­CšÎðxìE45&£Q0ۛŒG{›)¶Þ‘Só@ìðzH/h¾Džä5Oìë!Íãù¿uše­b2ù"9›=Ò BØÜìùüvþëÕϗÏ^y/ã•:ò꧛o.O?¼}zdÛÒ  g§_VUY¦Å%j‹ïlIFê‡4–æ%³oò/þ+ÿÑwð[Z,Ò"9–ÄÿVÄÖÅyºçÇ ùƒž¹fÑ@ރŸQ/Œ¾Y9÷+Òóç¤s,)|:ÌT¼Mµ0;‚Oõíô Z–•F]2ÿð÷ðú‚¢ˆ¹9ˆh€1ãn–´SmJ¡K*W’Üæ±ßÜ«iº·ïõ»{j*ì!Q$ݍm¸[›)2W…!Á)¤†6*-ʾMͬT•%´$™¤RQ¬ŠBÆØ©8ߺÖsWùBXKMÁî\¤å2_`ékeJ^O]á[‰a„ˆŒ*°?`VW Ó1æÒ©E£"˜ûðú…G{.ÆcEÁ88¦ý¨ŠezWÁ¿'³äÓÕûÃn€3V­öÍX‰I¹H$¥Ž¥ÐŒu¡¶(0ÕHZ§®hP[¥×<Ò¥º“GD¾Å[QXÈPd2ïŠñ„0=¤,*e‹2U-•&Å>­¥Ü€8"A<„™ƒ:‘swlÙÞ2ͤ¡BʄÝ/º¡EV¢ ¡?¶ï¦”øºí½IOLß7Xçb-i!âuµ1¤lÿ–NïÒÍs¨Bï-Ç{Ê2‘P`g»M¶%çôŠq)H–(à܁0·g~±nÏï”-Ôە#lµ¹J*ÇJàºoÊ6-WLN¬9Üj]µ@àä ­?p;Vùiy$,L|–¸bø„ðô‚ШJÇ2,ŒA”xåê®g»GIª1Jïh±®ÊñÝAŒ3yT‹~Z©ò÷¶™~z‹ñüËÓ%0öÚÛò´Ô*çò»Mi²?š´'ÒaŽ½§ÂöˆûI{™ˆÕ&utã x²-‡Â`U³ÿªÌ[#ãJ§åÎwÆ “P}–É; Ô¹”yßñt y¤¾0Kaíèx‡Õµp{´ñ†7Öµnï;ý 'ⷢ̿mÌ~X\ nîâDñ(«²5ίDq'“€nÈIk&—µh¡-,´Ð*a^Ö5ûÛÑ`4Æu šÇJÃ7#-ï+07©¯I¥Ø:qBÅk°®– Kב{`ïÜOq¬*ÈÝ÷;ÝÓ»}j2‚‡s 6€#7Lžtéé'²Ìªµäƒ…«Z{.]‘õAöHbrJç"«Kó)ÈA“y´Ö(ÿ¶-Í­"c Ü·gà«Ì -Yb`gúö¸X–›D°üîtm‡ÄʲV¹ê=¦ßɁo ¹Øað4ÓZÜl^8:t -² Óºï²üwŠ”’o•ÙÖѱ°Ôtûùhqo¹»=C~B§AÄH›N¶J¹¥:(™RW1®K²ßœ;±@‡¸,[ #Ѫ&CôÇj±™Õ^C‡s'=†û°ž–êÚo«úÒµ·JZ{èΎïÖ%˜rh×æjéß5?LšÑkÌw³ðzæœh2–“Q0áýrõþõ}Òê+_»Þ¨¸ÊÑa+«wMúÁt„:IÏ߀hŽ;%_Eæ+< }¬ì!{_PøÁƧc¶Æ]뗓mqü¶endstream +x½WioÛFýî_1pD$R‡-)‚ÀiÄhs4ZUQ¬È¥µ¹«ì’V…¢ÿ½ovIL”~HQä=æxóæÍúÓـúøÐdH£1%ÅÙ³ÙًÙY?šNiÿaïðŽ Gј®¦|£)YIÎöéj| ›þ8º +[0†]xØ}ÀRüòŠšep<žNh–úý>͒Îl)é¡+Íú!e•NJe4-…#A‰±VºµÑ©Òw$ui·Tr˪¤Ôl4•¸JNÚ{•H\Ð)åƬÈQ®V»Ê=¾œ}<‹_öé;Pox@gi‡Î;óKú‹Oô©7@ê¼AõÏ·ož?9ÿðúÙù‰2Yêiº8ÿ€€JÑuÁ7wQ=¦S÷W*Ï×Ö$äŠEzÂÇû³Ÿo~|rñôÄ>Çpb+Äÿæˆ_ÿ[üÃoHà¥J§§@üϊ° ~¾^ˆÑéD~£‹P,êÉO`yO4 ÃÏVFõÊïôàقzÅ÷ÂƹIV±«nëbâDa}Ê秱²¬,H‚i™ø›ÿÞ÷bûaŒ&ío3ښ +-ìJaKßYáðuݸ†¦ûû.µÎ4T8:ã³uðîƒÃ” +Y^攣µQºìúÐÜÒTyJ Ib‘£» ôAk™à¤áxÙ÷ñ($äD±¾ ¥%/'©)„ÒTÈb¥•+y]…Ä7Â& ‰È©‚¦DlÏË"¤nÀòW‹ ¾y „ÐÅ/ídm4 Hî…m0ˆ®£Q4‰è{£3uWáZMgÉ»›×•½6r9¼<ÕåXŠ{I…H%©LØÇJ› ÒP –ÞhH[ÀÕÆØ‹Riî$à±Qmu#´ i¶@«M1¢¦{Ç¢Âe]ªDxeΌ%ÃæöÂÛ¥•”k€"X§áfY^‹‚ëãÓ®oª"­¥LÙü¢íZä%J*ä+ïJ¹†­yç¹Jkj֕ÃíB@ß"YUkGÆWaYu§4ÊPÅìò§C±,“E¾»é–qLOm@³Ôç$€9š_֋My~E«l ß!á³-LZ^×}Q6ª\2=±pkæ• +§ú¢·v'¦X#¬ °f|îE±3•Md¬ƒ—dònØÔ¡TY´‡ÁÔ\lë½ |@uà£À¸< +ÍÓäg)¿ »»þ 7¾Ï?jºDΡ=°–2k +N¿]”]ô'ƒ®‰tcçkn;ÄõÄû ŠÄ¬U GÀ½í9¼# V-Û? 歓IeU¹­+ãÉ[èƖÞËôú\Ê¢xº†|!¿8W‹¸1t:Çãìpûb’51n¬líÚ·êA_ñàeöyaö͵c÷§†[ٔíLÉRè;™FtKA\s™5¢…²°ÔB«Äé'+ ?¾¬üT¹ió;JÅ牕¬Àºæ•õ$T¤ÇšzÖÏ9‘$¦‚Ü}»Ñ=½ç&#xÜ×`8rËäQYM?‘ç^­%¬FhýdÒm‘­%‚üPbric ‘7©Õ.7;Âk™O@kùç´ hiáµ9‡'õü|•¹–%ú÷\׏‹¬\7 ‚å·0gSh;$Vê0f½r5g\·¿ +±EãYŒÓFÜ|\üjW " Lj”¬–å?BJ?WfŸG놧f8Ï£%ìîän~‰ êDFÚµ¢õPÊ 5Nɕ¶Jð`’ÝÝÜI*Äiùd‰ƒlrxÿR.>²Æjpn…Çpçs :Ç÷7Uuiß÷J§õ4Œ9Ññd n^?»¡wÖ|äWÑs“Tà÷šÇ÷záxo2Äÿ]i§~žÐ O>~'̖øtô¶òðjr…ÿ‡üÁÉ5ßÆS觳… šendstream endobj 863 0 obj -1385 +1422 endobj 864 0 obj<>>>>>endobj 865 0 obj<>stream -x­X]oÛ6}ϯ¸ÈIlg@Òv¬E·xØ´DIl$R%©¸ú÷;—”l×q´‹±)òÞ{Îý8̗“)Mð3¥ÅŒÎç”Ö'oV'¿­N&ÉrI»7[àÄΗü~±\à}:¹Jfd%åxxB—³e² K紘ãÏ°‚ð Û7œ4¾½ é”V9 ϗ Zea}B«ttk,å¾!'í£J¥#ohcì5Ö4ÒVÝ)u¦¥ª*•3¤¥Ìø!©|)-Q)%)©G•µ¢¢LY™zcÎÊq8ž¢ÌÔBijaÄý²ú|2¡³é9‚Ye#QY)²椓ړѶ°?ҞNHK¡ ¾-MÓz yY7•ðX3$¨ZÚ=º`_ÀñhÿÀrð&!Z•°L©Ð´–$…SU4<¼UºˆÎðÎñ-( Ž\½NR£óøõ€íˆŠÊ¬aa؎ââå°gç+ǀ6'ü¸ÌæÉã¯ú#¶fÇÒ§ãFÔI6cû)WÕ6ŠˆXçKU™ øÓk¨)xvà ˜ÕB4rªV•Y&‚/êµèˆâóÖû!²qk#õ4†Ü©Œy J=0©ÊýC™Ð§è\F DëKŠ/+¿´ !á5®ÔzìdÚZå;FäS¥œ"A²âšÉ‹ÚÉëLjd¼¿ºÀ<2MZ{íZ !³!XT`Èʝe×æ¹Jçæ1Ë=°‰3Ïñ‚ó΋ô 5xí:‡Î8üŸ?´”U厸•¦¦ ±ÐOG¶;âõ"sHIÅÅOhdßåú%¸vÝîŒsiûÌ÷ë©2…Ò1 wå|¬¢´艡HÈ 4£èPwž4ªŒóÚ½jb‡,—ÞwG˜|Õ}!Z­¾rŠ¢t>åÊ:ÿ©nÛ˟VÍÿäÄªM ñR»„}!Ìç«ywÄë…ÆbÖrS{½C_¯öHØ;Ô4uŠ1ǯ§sÑLŠØ×â}3×ÉSº#‘e¬)¶o;4Ãأ쩹o ۙ¡ -5ÏZB†ÀκõQÁlÍł¬í‰’-<[Kp߈XV?þ”'g¦\¶Ö^€–âëQiéYWq³ØwC< -»x‡æßK¥§Ñ?_•ûN2$rß;òmÔ£ï#ÈqCVedr‚Z0]E™iו<ðš±n|Ô}Cr» l‚Â…žðhzv;hÖñíM¡{X¡ÎÓdþFâ‹„~‡Fñ‚“/ô]„¬šXԎþîEN Öé¶^#dx]ív²êQðÚÁ†‘ne͇ôOaùRxÚH*!9z&0eىyë[{tB”1ô[ 7¸£¶æ09ŒÆ›x[À/(Ԑù¿+Ý~%–ܺ3j€S¤Š/M[”Ô ¿Ù! -ž<  îCü€6•ÖCwÃ`c0]a/!ÖûÐ<{çAõæ,{±|JyŸýÁ­·omô,pä -õÂ"ŒnéÝf7a¥aŸÃ®<*ïãƒî7ÊÃ9ú±j‹"qƒiBT†Î4Y[Éí„éK .hªø]KpÃxÕ¨qÂß54èÿp ÐǛ÷TðåcpGà‰‚þúp÷(י±.éK0íµúÙ"ðü*$áèßÙ|ѯʀ—Ï.gQ)®€I-š> Øsé™ÙÀýy÷.l© k´†Zd(ȪÀ%ɗ5B®8'G&¸„s¸AæxG$›R>j5ÛEæörÖRaMÛDꝔ¸ÏtƒîOX¡Ô¢ã+N¦Xжô,hÂemhQ¤îGÅ叇ûH†€IŜB àkÎ6&ƒU=$7ToU:ß Ñ'zH׌6ßù»—™£!·ªmˆ}ƒ\.‘vÇúã²OÎé|‘ð?pyß»Åßß¼sC­ùŒ»7½3i[£˜BLÌêYÜu·ŽöӋÅ2š-æ¼ ýqòøL?endstream +xÍW[oÛ6~ϯ8È×Ú΀<¤íX‹nñ°= (h‰’ØH¤JRqõï÷êbÇqš]ò0§ìRäùÎùÎåã׳)Mð7¥ÕŒæKŠË³·›³Ÿ6g“h½¦ýÃfø1¡ùdÍh±^áûtr‰ïVRŠ—'´x3ã'–æ´ZFëýÊr¾ˆý&~iس\/»=8nXTÃÖÇ7º¤M +¤K Û$ayB›x$µØ’®H›6_ÎÆ7 šNùՋ)]̖¹IF¾[N¹˜½*¬ Ûéžßc,¥¾"'탊¥#ohgì=UÖTÒÍ95¦¦* +…3¤¥Lø%©|.-Q.$)¨•Ô¢ DY{cÎJq8ޢĔBiªa$@™À8PŠÂJ‘40'ÔžŒ¦°…ñH{N8!΅Îdøßܔ8­³Ð—eU5C‚2©¥=@ÐûÀ[û„ËMD´Éa™b¡i+I +§ŠÑð@«tւiÃ.CøG®ÜF±Ñé㨎(+Ìöá†m¨]|ÓïÙceàÂÑæˆx ìUwÄ`v,}<®D%c0v´ŸR…\é¼h#–<âRfþô$ªE ž8CÌJ¡4rªT…Y¦ ¾(·¢ÔÅç#ZzÏþ ¬pÔÑr§0æž +uϤ*÷cëÊÓ µÏ©ýXùµíp Ÿq¡¶c'ãÚ*ßpD>Êù ªWL.XÔN^%R#€þ*¡ Ì#Ó¤µW®F4dÒ;‹Î²roÙÕiªbŹyÊrØȅ:äôzzÄ àñ=èkðÊ5>\°ûÏãzéÐ\…;+ŽM|¡íÙþˆ—@ü}ÏRRqñÚèw¹~)\§ûä÷ë©0™ÒmöMvt²¢´艡HÈ 4£hP·MzGœ×îU;d¹ô¾9Áä«æè ÉPkõS¥ó9UÖùϕpC/ÿ¤¼6Æ‘Ú'ì n>_Íû#þcz´!f-7µ×;ôõ +ééÁ¡¦ò¨SŒ9þ<íʋÎ`R´ýðt-ÞêÐ÷1­œ<§[Išb˜xÃÐ à€²§æ¶77Bj( ž­„ mí[3˜k ¾·Æîv¢d`ƒgËq [ÃêǟóäL”k‡­5Æ£ ¥8Âz«´ô¬«¸YÂO„ÂÞß¾ùw¨žzÿ|U‚äHH}ä±×£ïGýÊ †¬JȤµ`š ‹SCœ!„f,+ßê¾>¹]P6AyOh6[GËN2êâñÍ%M¡{R–ì—‹0„÷Bx:–ý â'ߑœq³Oíß;‘“ƒuAº.·p¨‹ýNV= +¡léVÐ|H?ðÏ…§¤ò—½gc–Ø™Ö¾¶ÇNw'´2WAÂõpÔ`“Ãh<ă€ÜbqÏ +9dþÏJ×߈%7\„îl5À9RÅç¦ÎrªŒn„B[ý›G´ûà?.#±´º+ƒé +{±Þ‡æ98ª7eًåsbÏ»ì°Þ!x[+ gG®P/,òáÈ覃Í0a¥bÌa×G•wíƒîvÊ€€ýTÔYqiBT†Î4I]´—ƒÂ켋 ÚUüÛJpÃñ*Qã„ï%4èÿxw Чë”ñ壇#ðFF¿}¼ý”ëÄXu%÷׫òo~‰DENý9[®ºõ^ðòn…A)n“RT0 ØSé‰ÙÀ†~½} ¶T À­¡ +²ÈpIòy — Î „#‘ ánÇy†AÞáÉ.W՚í"s;9k)³¦®ZꝔ¸Ï4½îX¡”¢á+N¢XÐÖô,hÂe­oQG¤zÅ受;Oz‡Iµ9®¾ælc2XÕ)’»léÄÏØX[Wx‘‰tޚF&'cß߁ž‹}ÏÍ»¶ˆ<ÎÌ®‘Æː=¸÷apĽÀ]ˆàn?A÷%n»Ð”ÜX hÜUÆ7ÒóG9±îrf:_G—¸Á/Ú[íÝõ‡·×ôɚ/¸ Ó{×%’;Øà(_L—«—øÕ,œw²¿-VÜÃújɛÐB9û ÒSB½endstream endobj 866 0 obj -1577 +1592 endobj 867 0 obj<>>>>>endobj 868 0 obj<>stream -xmRËnÛ0¼ë+昶*9‚䝤z°áÔ*Ú+C®%¦éòa¥Ÿ¥e E‚âÎÎÌÿd% -~J4+ÜՐcvßfŸ¾~FY¡=òI½æB¡È‹¢@+oÊ2orи@蝍]Ï_Bô{¼”;1äÎZp˜týû!vx›È´ù°µ*äF%òËò._%Rq:9{rZ´ÕÒYoß÷bëU$N’•\XrÞ*é•ÑððÄ+ŽÄ7i8òhŒÅ/¥ksqØUYãCõ}©"BQq†|]rñc ÍLü iˆùLžÅ\Þ1§i\Æx6Zö£cúx“š`•¥‹ª#\”>²¸WçiX²Lkƶã790ÍTîÄ@8=+IÀᢼì–Ø÷cۊcO،ܠ½’"Œ‹­©ÇžÜBׁœ)Ó„IÅédÍÉ*áh«¤5Î4?öϐ¢ï:q&pe.T³xî8«šØ210,»©´§ÖÎd,ñ†ssó om¡ôl1X¢~î¾ý¾#˜Á‰½‡rü·µÄYªÇ)AfœŒõ ´â`™›uBçƒIvÔZé–õÞ=1±!dMþbìŸø.åÇ⑳}/åõu½Ò¢ŒÃêñbÝå|ØlŸ6Ø[óBÒ㳑ãÀ!L®ôÕܵšÛïmE^æñšwˆƒ)Ë«¢ïÑDÔà³endstream endobj 869 0 obj -399 +445 endobj 870 0 obj<>>>/Annots 313 0 R>>endobj 871 0 obj<>stream @@ -2306,11 +2307,11 @@ endobj 1016 0 obj<>endobj 1017 0 obj<>endobj 1018 0 obj<>endobj -1019 0 obj<>endobj -1020 0 obj<>endobj -1021 0 obj<>endobj -1022 0 obj<>endobj -1023 0 obj<>endobj +1019 0 obj<>endobj +1020 0 obj<>endobj +1021 0 obj<>endobj +1022 0 obj<>endobj +1023 0 obj<>endobj 1024 0 obj<>endobj 1025 0 obj<>endobj 1026 0 obj<>endobj @@ -2617,754 +2618,754 @@ xref 0000020690 00000 n 0000020777 00000 n 0000020826 00000 n -0000020913 00000 n -0000020956 00000 n -0000021043 00000 n -0000021086 00000 n -0000021172 00000 n -0000021221 00000 n -0000021306 00000 n -0000021355 00000 n -0000021440 00000 n -0000021506 00000 n -0000021554 00000 n -0000021641 00000 n -0000021687 00000 n -0000021774 00000 n -0000021808 00000 n -0000021887 00000 n -0000021974 00000 n -0000022056 00000 n -0000022142 00000 n -0000022217 00000 n -0000022304 00000 n -0000022377 00000 n -0000022464 00000 n -0000022514 00000 n -0000022592 00000 n -0000022679 00000 n -0000022705 00000 n -0000022768 00000 n -0000022855 00000 n -0000022918 00000 n -0000023005 00000 n -0000023059 00000 n -0000023146 00000 n -0000023188 00000 n -0000023229 00000 n -0000023316 00000 n -0000023342 00000 n -0000023447 00000 n -0000023553 00000 n -0000023659 00000 n -0000023765 00000 n -0000023871 00000 n -0000023977 00000 n -0000024083 00000 n -0000024189 00000 n -0000024295 00000 n -0000024401 00000 n -0000024507 00000 n -0000024613 00000 n -0000024719 00000 n -0000024825 00000 n -0000024931 00000 n -0000025037 00000 n -0000025143 00000 n -0000025249 00000 n -0000025355 00000 n -0000025461 00000 n -0000025566 00000 n -0000025672 00000 n -0000025778 00000 n -0000025884 00000 n -0000025990 00000 n -0000026096 00000 n -0000026202 00000 n -0000026308 00000 n -0000026414 00000 n -0000026520 00000 n -0000026626 00000 n -0000026732 00000 n -0000026838 00000 n -0000026944 00000 n -0000027050 00000 n -0000027156 00000 n -0000027262 00000 n -0000027368 00000 n -0000027474 00000 n -0000027579 00000 n -0000027685 00000 n -0000027791 00000 n -0000027897 00000 n -0000028000 00000 n -0000028104 00000 n -0000028482 00000 n -0000028588 00000 n -0000028693 00000 n -0000028799 00000 n -0000028905 00000 n -0000029011 00000 n -0000029117 00000 n -0000029223 00000 n -0000029329 00000 n -0000029435 00000 n -0000029541 00000 n -0000029647 00000 n -0000029752 00000 n -0000029858 00000 n -0000029964 00000 n -0000030070 00000 n -0000030176 00000 n -0000030282 00000 n -0000030388 00000 n -0000030494 00000 n -0000030600 00000 n -0000030706 00000 n -0000030812 00000 n -0000030918 00000 n -0000031024 00000 n -0000031130 00000 n -0000031235 00000 n -0000031341 00000 n -0000031447 00000 n -0000031553 00000 n -0000031658 00000 n -0000031764 00000 n -0000031870 00000 n -0000031976 00000 n -0000032082 00000 n -0000032188 00000 n -0000032294 00000 n -0000032400 00000 n -0000032506 00000 n -0000032612 00000 n -0000032718 00000 n -0000032824 00000 n -0000032929 00000 n -0000033033 00000 n -0000033137 00000 n -0000033507 00000 n -0000033612 00000 n -0000033718 00000 n -0000033824 00000 n -0000033930 00000 n -0000034036 00000 n -0000034142 00000 n -0000034248 00000 n -0000034354 00000 n -0000034460 00000 n -0000034565 00000 n -0000034671 00000 n -0000034777 00000 n -0000034883 00000 n -0000034989 00000 n -0000035095 00000 n -0000035201 00000 n -0000035307 00000 n -0000035413 00000 n -0000035519 00000 n -0000035625 00000 n -0000035731 00000 n -0000035837 00000 n -0000035942 00000 n -0000036048 00000 n -0000036154 00000 n -0000036260 00000 n -0000036366 00000 n -0000036472 00000 n -0000036578 00000 n -0000036684 00000 n -0000036790 00000 n -0000036896 00000 n -0000037002 00000 n -0000037108 00000 n -0000037214 00000 n -0000037320 00000 n -0000037426 00000 n -0000037532 00000 n -0000037638 00000 n -0000037743 00000 n -0000037849 00000 n -0000037955 00000 n -0000038060 00000 n -0000038164 00000 n -0000038268 00000 n -0000038646 00000 n -0000038751 00000 n -0000038857 00000 n -0000038963 00000 n -0000039069 00000 n -0000039175 00000 n -0000039279 00000 n -0000039345 00000 n -0000039379 00000 n -0000039413 00000 n -0000042026 00000 n -0000042075 00000 n -0000042124 00000 n -0000042173 00000 n -0000042222 00000 n -0000042271 00000 n -0000042320 00000 n -0000042369 00000 n -0000042418 00000 n -0000042467 00000 n -0000042516 00000 n -0000042565 00000 n -0000042614 00000 n -0000042663 00000 n -0000042712 00000 n -0000042761 00000 n -0000042810 00000 n -0000042859 00000 n -0000042908 00000 n -0000042957 00000 n -0000043006 00000 n -0000043055 00000 n -0000043104 00000 n -0000043153 00000 n -0000043202 00000 n -0000043251 00000 n -0000043300 00000 n -0000043349 00000 n -0000043398 00000 n -0000043447 00000 n -0000043496 00000 n -0000043545 00000 n -0000043594 00000 n -0000043643 00000 n -0000043692 00000 n -0000043741 00000 n -0000043790 00000 n -0000043839 00000 n -0000043888 00000 n -0000043937 00000 n -0000043986 00000 n -0000044035 00000 n -0000044084 00000 n -0000044133 00000 n -0000044182 00000 n -0000044231 00000 n -0000044280 00000 n -0000044329 00000 n -0000044378 00000 n -0000044427 00000 n -0000044476 00000 n -0000044525 00000 n -0000044574 00000 n -0000044623 00000 n -0000044672 00000 n -0000044721 00000 n -0000044770 00000 n -0000044819 00000 n -0000044868 00000 n -0000044917 00000 n -0000044966 00000 n -0000045015 00000 n -0000045064 00000 n -0000045113 00000 n -0000045162 00000 n -0000045211 00000 n -0000045260 00000 n -0000045309 00000 n -0000045358 00000 n -0000045407 00000 n -0000045456 00000 n -0000045505 00000 n -0000045554 00000 n -0000045603 00000 n -0000045652 00000 n -0000045701 00000 n -0000045750 00000 n -0000045799 00000 n -0000045848 00000 n -0000045897 00000 n -0000045946 00000 n -0000045995 00000 n -0000046044 00000 n -0000046093 00000 n -0000046142 00000 n -0000046191 00000 n -0000046240 00000 n -0000046289 00000 n -0000046338 00000 n -0000046387 00000 n -0000046436 00000 n -0000046485 00000 n -0000046534 00000 n -0000046583 00000 n -0000046632 00000 n -0000046681 00000 n -0000046730 00000 n -0000046779 00000 n -0000046828 00000 n -0000046877 00000 n -0000046926 00000 n -0000046975 00000 n -0000047024 00000 n -0000047073 00000 n -0000047122 00000 n -0000047171 00000 n -0000047220 00000 n -0000047269 00000 n -0000047318 00000 n -0000047367 00000 n -0000047416 00000 n -0000047465 00000 n -0000047514 00000 n -0000047563 00000 n -0000047612 00000 n -0000047661 00000 n -0000047710 00000 n -0000047759 00000 n -0000047808 00000 n -0000047857 00000 n -0000047906 00000 n -0000047955 00000 n -0000048004 00000 n -0000048053 00000 n -0000048102 00000 n -0000048151 00000 n -0000048200 00000 n -0000048249 00000 n -0000048298 00000 n -0000048347 00000 n -0000048396 00000 n -0000048445 00000 n -0000048494 00000 n -0000048543 00000 n -0000048592 00000 n -0000048641 00000 n -0000048690 00000 n -0000048739 00000 n -0000048788 00000 n -0000048837 00000 n -0000048886 00000 n -0000048935 00000 n -0000048984 00000 n -0000049033 00000 n -0000049082 00000 n -0000049131 00000 n -0000049180 00000 n -0000049229 00000 n -0000049278 00000 n -0000049327 00000 n -0000049376 00000 n -0000049425 00000 n -0000049474 00000 n -0000049523 00000 n -0000049572 00000 n -0000049621 00000 n -0000049670 00000 n -0000049719 00000 n -0000049768 00000 n -0000049817 00000 n -0000049866 00000 n -0000049915 00000 n -0000050672 00000 n -0000050828 00000 n -0000051551 00000 n -0000051572 00000 n -0000051746 00000 n -0000052908 00000 n -0000052930 00000 n -0000053081 00000 n -0000054587 00000 n -0000054609 00000 n -0000054769 00000 n -0000056205 00000 n -0000056227 00000 n -0000056405 00000 n -0000057665 00000 n -0000057687 00000 n -0000057829 00000 n -0000059413 00000 n -0000059435 00000 n -0000059568 00000 n -0000061403 00000 n -0000061425 00000 n -0000061558 00000 n -0000062081 00000 n -0000062102 00000 n -0000062263 00000 n -0000063547 00000 n -0000063569 00000 n -0000063730 00000 n -0000065485 00000 n -0000065507 00000 n -0000065667 00000 n -0000067312 00000 n -0000067334 00000 n -0000067476 00000 n -0000069546 00000 n -0000069568 00000 n -0000069710 00000 n -0000071522 00000 n -0000071544 00000 n -0000071686 00000 n -0000073411 00000 n -0000073433 00000 n -0000073584 00000 n -0000075348 00000 n -0000075370 00000 n -0000075545 00000 n -0000077652 00000 n -0000077674 00000 n -0000077834 00000 n -0000079430 00000 n -0000079452 00000 n -0000079627 00000 n -0000081122 00000 n -0000081144 00000 n -0000081296 00000 n -0000082103 00000 n -0000082124 00000 n -0000082275 00000 n -0000083913 00000 n -0000083935 00000 n -0000084100 00000 n -0000085872 00000 n -0000085894 00000 n -0000086059 00000 n -0000086952 00000 n -0000086973 00000 n -0000087147 00000 n -0000088752 00000 n -0000088774 00000 n -0000088917 00000 n -0000089675 00000 n -0000089696 00000 n -0000089879 00000 n -0000091747 00000 n -0000091769 00000 n -0000091938 00000 n -0000093792 00000 n -0000093814 00000 n -0000093974 00000 n -0000095658 00000 n -0000095680 00000 n -0000095853 00000 n -0000097582 00000 n -0000097604 00000 n -0000097755 00000 n -0000098679 00000 n -0000098700 00000 n -0000098884 00000 n -0000100709 00000 n -0000100731 00000 n -0000100905 00000 n -0000103078 00000 n -0000103100 00000 n -0000103293 00000 n -0000105220 00000 n -0000105242 00000 n -0000105426 00000 n -0000107336 00000 n -0000107358 00000 n -0000107534 00000 n -0000109335 00000 n -0000109357 00000 n -0000109527 00000 n -0000111125 00000 n -0000111147 00000 n -0000111332 00000 n -0000112808 00000 n -0000112830 00000 n -0000113023 00000 n -0000114594 00000 n -0000114616 00000 n -0000114791 00000 n -0000116571 00000 n -0000116593 00000 n -0000116749 00000 n -0000118310 00000 n -0000118332 00000 n -0000118517 00000 n -0000120369 00000 n -0000120391 00000 n -0000120557 00000 n -0000122204 00000 n -0000122226 00000 n -0000122411 00000 n -0000124360 00000 n -0000124382 00000 n -0000124566 00000 n -0000126293 00000 n -0000126315 00000 n -0000126485 00000 n -0000128090 00000 n -0000128112 00000 n -0000128281 00000 n -0000130154 00000 n -0000130176 00000 n -0000130361 00000 n -0000132225 00000 n -0000132247 00000 n -0000132423 00000 n -0000134513 00000 n -0000134535 00000 n -0000134710 00000 n -0000136650 00000 n -0000136672 00000 n -0000136848 00000 n -0000139164 00000 n -0000139186 00000 n -0000139338 00000 n -0000141318 00000 n -0000141340 00000 n -0000141500 00000 n -0000143367 00000 n -0000143389 00000 n -0000143540 00000 n -0000145292 00000 n -0000145314 00000 n -0000145446 00000 n -0000147320 00000 n -0000147342 00000 n -0000147484 00000 n -0000149555 00000 n -0000149577 00000 n -0000149728 00000 n -0000151522 00000 n -0000151544 00000 n -0000151676 00000 n -0000153469 00000 n -0000153491 00000 n -0000153614 00000 n -0000154068 00000 n -0000154089 00000 n -0000154246 00000 n -0000155880 00000 n -0000155902 00000 n -0000156054 00000 n -0000157714 00000 n -0000157736 00000 n -0000157878 00000 n -0000158761 00000 n -0000158782 00000 n -0000158967 00000 n -0000161124 00000 n -0000161146 00000 n -0000161322 00000 n -0000163507 00000 n -0000163529 00000 n -0000163680 00000 n -0000164781 00000 n -0000164803 00000 n -0000164979 00000 n -0000166479 00000 n -0000166501 00000 n -0000166686 00000 n -0000168538 00000 n -0000168560 00000 n -0000168745 00000 n -0000170652 00000 n -0000170674 00000 n -0000170831 00000 n -0000171762 00000 n -0000171783 00000 n -0000171935 00000 n -0000173676 00000 n -0000173698 00000 n -0000173840 00000 n -0000175602 00000 n -0000175624 00000 n -0000175775 00000 n -0000177666 00000 n -0000177688 00000 n -0000177845 00000 n -0000179698 00000 n -0000179720 00000 n -0000179914 00000 n -0000181974 00000 n -0000181996 00000 n -0000182171 00000 n -0000183763 00000 n -0000183785 00000 n -0000183969 00000 n -0000185308 00000 n -0000185330 00000 n -0000185490 00000 n -0000186733 00000 n -0000186755 00000 n -0000186906 00000 n -0000188362 00000 n -0000188384 00000 n -0000188545 00000 n -0000190193 00000 n -0000190215 00000 n -0000190348 00000 n -0000190818 00000 n -0000190839 00000 n -0000191006 00000 n -0000192674 00000 n -0000192696 00000 n -0000192853 00000 n -0000194041 00000 n -0000194063 00000 n -0000194220 00000 n -0000195772 00000 n -0000195794 00000 n -0000195978 00000 n -0000196783 00000 n -0000196804 00000 n -0000196961 00000 n -0000202384 00000 n -0000202406 00000 n -0000202563 00000 n -0000207857 00000 n -0000207879 00000 n -0000208036 00000 n -0000213253 00000 n -0000213275 00000 n -0000213432 00000 n -0000214202 00000 n -0000214223 00000 n -0000214280 00000 n -0000214385 00000 n -0000214563 00000 n -0000214682 00000 n -0000214817 00000 n +0000020911 00000 n +0000020945 00000 n +0000020988 00000 n +0000021075 00000 n +0000021118 00000 n +0000021205 00000 n +0000021254 00000 n +0000021341 00000 n +0000021390 00000 n +0000021477 00000 n +0000021525 00000 n +0000021612 00000 n +0000021658 00000 n +0000021745 00000 n +0000021811 00000 n +0000021890 00000 n +0000021977 00000 n +0000022059 00000 n +0000022145 00000 n +0000022220 00000 n +0000022307 00000 n +0000022380 00000 n +0000022467 00000 n +0000022517 00000 n +0000022595 00000 n +0000022682 00000 n +0000022708 00000 n +0000022771 00000 n +0000022858 00000 n +0000022921 00000 n +0000023008 00000 n +0000023062 00000 n +0000023149 00000 n +0000023191 00000 n +0000023232 00000 n +0000023319 00000 n +0000023345 00000 n +0000023450 00000 n +0000023556 00000 n +0000023662 00000 n +0000023768 00000 n +0000023874 00000 n +0000023980 00000 n +0000024086 00000 n +0000024192 00000 n +0000024298 00000 n +0000024404 00000 n +0000024510 00000 n +0000024616 00000 n +0000024722 00000 n +0000024828 00000 n +0000024934 00000 n +0000025040 00000 n +0000025146 00000 n +0000025252 00000 n +0000025358 00000 n +0000025464 00000 n +0000025569 00000 n +0000025675 00000 n +0000025781 00000 n +0000025887 00000 n +0000025993 00000 n +0000026099 00000 n +0000026205 00000 n +0000026311 00000 n +0000026417 00000 n +0000026523 00000 n +0000026629 00000 n +0000026735 00000 n +0000026841 00000 n +0000026947 00000 n +0000027053 00000 n +0000027159 00000 n +0000027265 00000 n +0000027371 00000 n +0000027477 00000 n +0000027582 00000 n +0000027688 00000 n +0000027794 00000 n +0000027900 00000 n +0000028003 00000 n +0000028107 00000 n +0000028485 00000 n +0000028591 00000 n +0000028696 00000 n +0000028802 00000 n +0000028908 00000 n +0000029014 00000 n +0000029120 00000 n +0000029226 00000 n +0000029332 00000 n +0000029438 00000 n +0000029544 00000 n +0000029650 00000 n +0000029755 00000 n +0000029861 00000 n +0000029967 00000 n +0000030073 00000 n +0000030179 00000 n +0000030285 00000 n +0000030391 00000 n +0000030497 00000 n +0000030603 00000 n +0000030709 00000 n +0000030815 00000 n +0000030921 00000 n +0000031027 00000 n +0000031133 00000 n +0000031238 00000 n +0000031344 00000 n +0000031450 00000 n +0000031556 00000 n +0000031661 00000 n +0000031767 00000 n +0000031873 00000 n +0000031979 00000 n +0000032085 00000 n +0000032191 00000 n +0000032297 00000 n +0000032403 00000 n +0000032509 00000 n +0000032615 00000 n +0000032721 00000 n +0000032827 00000 n +0000032932 00000 n +0000033036 00000 n +0000033140 00000 n +0000033510 00000 n +0000033615 00000 n +0000033721 00000 n +0000033827 00000 n +0000033933 00000 n +0000034039 00000 n +0000034145 00000 n +0000034251 00000 n +0000034357 00000 n +0000034463 00000 n +0000034568 00000 n +0000034674 00000 n +0000034780 00000 n +0000034886 00000 n +0000034992 00000 n +0000035098 00000 n +0000035204 00000 n +0000035310 00000 n +0000035416 00000 n +0000035522 00000 n +0000035628 00000 n +0000035734 00000 n +0000035840 00000 n +0000035945 00000 n +0000036051 00000 n +0000036157 00000 n +0000036263 00000 n +0000036369 00000 n +0000036475 00000 n +0000036581 00000 n +0000036687 00000 n +0000036793 00000 n +0000036899 00000 n +0000037005 00000 n +0000037111 00000 n +0000037217 00000 n +0000037323 00000 n +0000037429 00000 n +0000037535 00000 n +0000037641 00000 n +0000037746 00000 n +0000037852 00000 n +0000037958 00000 n +0000038063 00000 n +0000038167 00000 n +0000038271 00000 n +0000038649 00000 n +0000038754 00000 n +0000038860 00000 n +0000038966 00000 n +0000039072 00000 n +0000039178 00000 n +0000039282 00000 n +0000039348 00000 n +0000039382 00000 n +0000039416 00000 n +0000042029 00000 n +0000042078 00000 n +0000042127 00000 n +0000042176 00000 n +0000042225 00000 n +0000042274 00000 n +0000042323 00000 n +0000042372 00000 n +0000042421 00000 n +0000042470 00000 n +0000042519 00000 n +0000042568 00000 n +0000042617 00000 n +0000042666 00000 n +0000042715 00000 n +0000042764 00000 n +0000042813 00000 n +0000042862 00000 n +0000042911 00000 n +0000042960 00000 n +0000043009 00000 n +0000043058 00000 n +0000043107 00000 n +0000043156 00000 n +0000043205 00000 n +0000043254 00000 n +0000043303 00000 n +0000043352 00000 n +0000043401 00000 n +0000043450 00000 n +0000043499 00000 n +0000043548 00000 n +0000043597 00000 n +0000043646 00000 n +0000043695 00000 n +0000043744 00000 n +0000043793 00000 n +0000043842 00000 n +0000043891 00000 n +0000043940 00000 n +0000043989 00000 n +0000044038 00000 n +0000044087 00000 n +0000044136 00000 n +0000044185 00000 n +0000044234 00000 n +0000044283 00000 n +0000044332 00000 n +0000044381 00000 n +0000044430 00000 n +0000044479 00000 n +0000044528 00000 n +0000044577 00000 n +0000044626 00000 n +0000044675 00000 n +0000044724 00000 n +0000044773 00000 n +0000044822 00000 n +0000044871 00000 n +0000044920 00000 n +0000044969 00000 n +0000045018 00000 n +0000045067 00000 n +0000045116 00000 n +0000045165 00000 n +0000045214 00000 n +0000045263 00000 n +0000045312 00000 n +0000045361 00000 n +0000045410 00000 n +0000045459 00000 n +0000045508 00000 n +0000045557 00000 n +0000045606 00000 n +0000045655 00000 n +0000045704 00000 n +0000045753 00000 n +0000045802 00000 n +0000045851 00000 n +0000045900 00000 n +0000045949 00000 n +0000045998 00000 n +0000046047 00000 n +0000046096 00000 n +0000046145 00000 n +0000046194 00000 n +0000046243 00000 n +0000046292 00000 n +0000046341 00000 n +0000046390 00000 n +0000046439 00000 n +0000046488 00000 n +0000046537 00000 n +0000046586 00000 n +0000046635 00000 n +0000046684 00000 n +0000046733 00000 n +0000046782 00000 n +0000046831 00000 n +0000046880 00000 n +0000046929 00000 n +0000046978 00000 n +0000047027 00000 n +0000047076 00000 n +0000047125 00000 n +0000047174 00000 n +0000047223 00000 n +0000047272 00000 n +0000047321 00000 n +0000047370 00000 n +0000047419 00000 n +0000047468 00000 n +0000047517 00000 n +0000047566 00000 n +0000047615 00000 n +0000047664 00000 n +0000047713 00000 n +0000047762 00000 n +0000047811 00000 n +0000047860 00000 n +0000047909 00000 n +0000047958 00000 n +0000048007 00000 n +0000048056 00000 n +0000048105 00000 n +0000048154 00000 n +0000048203 00000 n +0000048252 00000 n +0000048301 00000 n +0000048350 00000 n +0000048399 00000 n +0000048448 00000 n +0000048497 00000 n +0000048546 00000 n +0000048595 00000 n +0000048644 00000 n +0000048693 00000 n +0000048742 00000 n +0000048791 00000 n +0000048840 00000 n +0000048889 00000 n +0000048938 00000 n +0000048987 00000 n +0000049036 00000 n +0000049085 00000 n +0000049134 00000 n +0000049183 00000 n +0000049232 00000 n +0000049281 00000 n +0000049330 00000 n +0000049379 00000 n +0000049428 00000 n +0000049477 00000 n +0000049526 00000 n +0000049575 00000 n +0000049624 00000 n +0000049673 00000 n +0000049722 00000 n +0000049771 00000 n +0000049820 00000 n +0000049869 00000 n +0000049918 00000 n +0000050675 00000 n +0000050831 00000 n +0000051554 00000 n +0000051575 00000 n +0000051749 00000 n +0000052911 00000 n +0000052933 00000 n +0000053084 00000 n +0000054590 00000 n +0000054612 00000 n +0000054772 00000 n +0000056208 00000 n +0000056230 00000 n +0000056408 00000 n +0000057668 00000 n +0000057690 00000 n +0000057832 00000 n +0000059416 00000 n +0000059438 00000 n +0000059571 00000 n +0000061406 00000 n +0000061428 00000 n +0000061561 00000 n +0000062084 00000 n +0000062105 00000 n +0000062266 00000 n +0000063550 00000 n +0000063572 00000 n +0000063733 00000 n +0000065488 00000 n +0000065510 00000 n +0000065670 00000 n +0000067315 00000 n +0000067337 00000 n +0000067479 00000 n +0000069549 00000 n +0000069571 00000 n +0000069713 00000 n +0000071525 00000 n +0000071547 00000 n +0000071689 00000 n +0000073414 00000 n +0000073436 00000 n +0000073587 00000 n +0000075351 00000 n +0000075373 00000 n +0000075548 00000 n +0000077655 00000 n +0000077677 00000 n +0000077837 00000 n +0000079433 00000 n +0000079455 00000 n +0000079630 00000 n +0000081125 00000 n +0000081147 00000 n +0000081299 00000 n +0000082106 00000 n +0000082127 00000 n +0000082278 00000 n +0000083916 00000 n +0000083938 00000 n +0000084103 00000 n +0000085875 00000 n +0000085897 00000 n +0000086062 00000 n +0000086955 00000 n +0000086976 00000 n +0000087150 00000 n +0000088755 00000 n +0000088777 00000 n +0000088920 00000 n +0000089678 00000 n +0000089699 00000 n +0000089882 00000 n +0000091750 00000 n +0000091772 00000 n +0000091941 00000 n +0000093795 00000 n +0000093817 00000 n +0000093977 00000 n +0000095661 00000 n +0000095683 00000 n +0000095856 00000 n +0000097585 00000 n +0000097607 00000 n +0000097758 00000 n +0000098682 00000 n +0000098703 00000 n +0000098887 00000 n +0000100712 00000 n +0000100734 00000 n +0000100908 00000 n +0000103081 00000 n +0000103103 00000 n +0000103296 00000 n +0000105223 00000 n +0000105245 00000 n +0000105429 00000 n +0000107339 00000 n +0000107361 00000 n +0000107537 00000 n +0000109338 00000 n +0000109360 00000 n +0000109530 00000 n +0000111128 00000 n +0000111150 00000 n +0000111335 00000 n +0000112811 00000 n +0000112833 00000 n +0000113026 00000 n +0000114597 00000 n +0000114619 00000 n +0000114794 00000 n +0000116574 00000 n +0000116596 00000 n +0000116752 00000 n +0000118313 00000 n +0000118335 00000 n +0000118520 00000 n +0000120372 00000 n +0000120394 00000 n +0000120560 00000 n +0000122207 00000 n +0000122229 00000 n +0000122414 00000 n +0000124363 00000 n +0000124385 00000 n +0000124569 00000 n +0000126296 00000 n +0000126318 00000 n +0000126488 00000 n +0000128093 00000 n +0000128115 00000 n +0000128284 00000 n +0000130157 00000 n +0000130179 00000 n +0000130364 00000 n +0000132228 00000 n +0000132250 00000 n +0000132426 00000 n +0000134516 00000 n +0000134538 00000 n +0000134713 00000 n +0000136653 00000 n +0000136675 00000 n +0000136851 00000 n +0000139167 00000 n +0000139189 00000 n +0000139341 00000 n +0000141321 00000 n +0000141343 00000 n +0000141503 00000 n +0000143370 00000 n +0000143392 00000 n +0000143543 00000 n +0000145295 00000 n +0000145317 00000 n +0000145449 00000 n +0000147323 00000 n +0000147345 00000 n +0000147487 00000 n +0000149558 00000 n +0000149580 00000 n +0000149731 00000 n +0000151525 00000 n +0000151547 00000 n +0000151679 00000 n +0000153472 00000 n +0000153494 00000 n +0000153617 00000 n +0000154071 00000 n +0000154092 00000 n +0000154249 00000 n +0000155883 00000 n +0000155905 00000 n +0000156057 00000 n +0000157717 00000 n +0000157739 00000 n +0000157881 00000 n +0000158764 00000 n +0000158785 00000 n +0000158970 00000 n +0000161126 00000 n +0000161148 00000 n +0000161324 00000 n +0000163509 00000 n +0000163531 00000 n +0000163682 00000 n +0000164783 00000 n +0000164805 00000 n +0000164981 00000 n +0000166481 00000 n +0000166503 00000 n +0000166688 00000 n +0000168540 00000 n +0000168562 00000 n +0000168747 00000 n +0000170654 00000 n +0000170676 00000 n +0000170833 00000 n +0000171764 00000 n +0000171785 00000 n +0000171937 00000 n +0000173678 00000 n +0000173700 00000 n +0000173842 00000 n +0000175604 00000 n +0000175626 00000 n +0000175777 00000 n +0000177668 00000 n +0000177690 00000 n +0000177847 00000 n +0000179684 00000 n +0000179706 00000 n +0000179900 00000 n +0000181922 00000 n +0000181944 00000 n +0000182119 00000 n +0000183706 00000 n +0000183728 00000 n +0000183903 00000 n +0000185291 00000 n +0000185313 00000 n +0000185482 00000 n +0000186771 00000 n +0000186793 00000 n +0000186944 00000 n +0000188437 00000 n +0000188459 00000 n +0000188620 00000 n +0000190283 00000 n +0000190305 00000 n +0000190438 00000 n +0000190954 00000 n +0000190975 00000 n +0000191142 00000 n +0000192810 00000 n +0000192832 00000 n +0000192989 00000 n +0000194177 00000 n +0000194199 00000 n +0000194356 00000 n +0000195908 00000 n +0000195930 00000 n +0000196114 00000 n +0000196919 00000 n +0000196940 00000 n +0000197097 00000 n +0000202520 00000 n +0000202542 00000 n +0000202699 00000 n +0000207993 00000 n +0000208015 00000 n +0000208172 00000 n +0000213389 00000 n +0000213411 00000 n +0000213568 00000 n +0000214338 00000 n +0000214359 00000 n +0000214416 00000 n +0000214521 00000 n +0000214699 00000 n +0000214818 00000 n 0000214953 00000 n -0000215101 00000 n -0000215251 00000 n -0000215391 00000 n -0000215532 00000 n -0000215685 00000 n -0000215847 00000 n -0000215996 00000 n -0000216184 00000 n -0000216317 00000 n -0000216445 00000 n -0000216563 00000 n +0000215089 00000 n +0000215237 00000 n +0000215387 00000 n +0000215527 00000 n +0000215668 00000 n +0000215821 00000 n +0000215983 00000 n +0000216132 00000 n +0000216320 00000 n +0000216453 00000 n +0000216581 00000 n 0000216699 00000 n -0000216841 00000 n -0000216957 00000 n -0000217083 00000 n -0000217199 00000 n -0000217390 00000 n -0000217489 00000 n -0000217637 00000 n -0000217755 00000 n -0000217879 00000 n -0000218001 00000 n -0000218127 00000 n -0000218285 00000 n -0000218415 00000 n -0000218539 00000 n -0000218657 00000 n -0000218775 00000 n -0000218894 00000 n -0000219084 00000 n -0000219270 00000 n -0000219423 00000 n -0000219586 00000 n -0000219737 00000 n -0000219841 00000 n -0000220058 00000 n -0000220164 00000 n -0000220296 00000 n -0000220418 00000 n -0000220623 00000 n -0000220728 00000 n -0000220828 00000 n -0000221032 00000 n -0000221193 00000 n -0000221341 00000 n -0000221469 00000 n -0000221612 00000 n -0000221736 00000 n -0000221865 00000 n -0000222010 00000 n -0000222175 00000 n -0000222327 00000 n -0000222507 00000 n -0000222612 00000 n -0000222731 00000 n -0000222856 00000 n -0000223001 00000 n -0000223143 00000 n -0000223293 00000 n -0000223424 00000 n -0000223550 00000 n -0000223675 00000 n -0000223815 00000 n -0000223942 00000 n -0000224073 00000 n -0000224204 00000 n -0000224382 00000 n -0000224510 00000 n +0000216835 00000 n +0000216977 00000 n +0000217093 00000 n +0000217219 00000 n +0000217335 00000 n +0000217526 00000 n +0000217625 00000 n +0000217773 00000 n +0000217891 00000 n +0000218015 00000 n +0000218137 00000 n +0000218263 00000 n +0000218421 00000 n +0000218551 00000 n +0000218675 00000 n +0000218793 00000 n +0000218911 00000 n +0000219030 00000 n +0000219220 00000 n +0000219406 00000 n +0000219559 00000 n +0000219722 00000 n +0000219873 00000 n +0000219977 00000 n +0000220194 00000 n +0000220300 00000 n +0000220432 00000 n +0000220554 00000 n +0000220759 00000 n +0000220864 00000 n +0000220964 00000 n +0000221168 00000 n +0000221329 00000 n +0000221477 00000 n +0000221605 00000 n +0000221748 00000 n +0000221872 00000 n +0000222001 00000 n +0000222146 00000 n +0000222311 00000 n +0000222463 00000 n +0000222643 00000 n +0000222748 00000 n +0000222867 00000 n +0000222992 00000 n +0000223137 00000 n +0000223279 00000 n +0000223429 00000 n +0000223560 00000 n +0000223686 00000 n +0000223811 00000 n +0000223951 00000 n +0000224078 00000 n +0000224209 00000 n +0000224340 00000 n +0000224518 00000 n 0000224646 00000 n -0000224781 00000 n -0000224987 00000 n -0000225100 00000 n -0000225216 00000 n -0000225361 00000 n -0000225532 00000 n -0000225681 00000 n -0000225836 00000 n -0000225976 00000 n -0000226108 00000 n -0000226242 00000 n -0000226374 00000 n -0000226512 00000 n -0000226662 00000 n -0000226830 00000 n -0000226977 00000 n -0000227201 00000 n -0000227314 00000 n -0000227430 00000 n -0000227586 00000 n -0000227744 00000 n -0000227875 00000 n -0000228021 00000 n -0000228155 00000 n -0000228288 00000 n -0000228509 00000 n -0000228610 00000 n -0000228729 00000 n -0000228858 00000 n -0000229017 00000 n -0000229152 00000 n -0000229285 00000 n -0000229414 00000 n -0000229554 00000 n -0000229689 00000 n -0000229841 00000 n -0000229990 00000 n -0000230095 00000 n -0000230305 00000 n -0000230410 00000 n -0000230533 00000 n -0000230665 00000 n -0000230789 00000 n -0000230917 00000 n -0000231062 00000 n -0000231194 00000 n -0000231339 00000 n -0000231480 00000 n -0000231607 00000 n -0000231748 00000 n -0000231873 00000 n -0000231998 00000 n -0000232129 00000 n -0000232251 00000 n -0000232358 00000 n -0000232528 00000 n -0000232629 00000 n -0000232818 00000 n -0000233012 00000 n -0000233199 00000 n -0000233361 00000 n -0000233553 00000 n -0000233662 00000 n -0000233796 00000 n -0000233926 00000 n -0000234039 00000 n -0000234134 00000 n +0000224782 00000 n +0000224917 00000 n +0000225123 00000 n +0000225236 00000 n +0000225352 00000 n +0000225497 00000 n +0000225668 00000 n +0000225817 00000 n +0000225972 00000 n +0000226112 00000 n +0000226244 00000 n +0000226378 00000 n +0000226510 00000 n +0000226648 00000 n +0000226798 00000 n +0000226966 00000 n +0000227113 00000 n +0000227337 00000 n +0000227450 00000 n +0000227566 00000 n +0000227722 00000 n +0000227880 00000 n +0000228011 00000 n +0000228157 00000 n +0000228291 00000 n +0000228424 00000 n +0000228645 00000 n +0000228746 00000 n +0000228865 00000 n +0000228994 00000 n +0000229153 00000 n +0000229288 00000 n +0000229421 00000 n +0000229550 00000 n +0000229690 00000 n +0000229825 00000 n +0000229977 00000 n +0000230126 00000 n +0000230231 00000 n +0000230441 00000 n +0000230546 00000 n +0000230669 00000 n +0000230801 00000 n +0000230925 00000 n +0000231053 00000 n +0000231198 00000 n +0000231330 00000 n +0000231475 00000 n +0000231616 00000 n +0000231743 00000 n +0000231884 00000 n +0000232009 00000 n +0000232134 00000 n +0000232265 00000 n +0000232387 00000 n +0000232494 00000 n +0000232664 00000 n +0000232765 00000 n +0000232954 00000 n +0000233148 00000 n +0000233335 00000 n +0000233497 00000 n +0000233689 00000 n +0000233798 00000 n +0000233932 00000 n +0000234062 00000 n +0000234175 00000 n +0000234270 00000 n trailer -<<59d643d3d56fb4ff0981d084417582f1>]>> +<<57917625c1363da5bb6b71712e14ebaf>]>> startxref -234349 +234485 %%EOF diff --git a/docs/docbook/manpages/nmbd.8.sgml b/docs/docbook/manpages/nmbd.8.sgml index 46f36834df4..d5c89064e74 100644 --- a/docs/docbook/manpages/nmbd.8.sgml +++ b/docs/docbook/manpages/nmbd.8.sgml @@ -177,13 +177,14 @@ The -l parameter specifies a directory into which the "log.nmbd" log file will be created for operational data from the running - nmbd server. - - The default log directory is compiled into Samba + nmbd server. The default log directory is compiled into Samba as part of the build process. Common defaults are /usr/local/samba/var/log.nmb, /usr/samba/var/log.nmb or - /var/log/log.nmb. + /var/log/log.nmb. Beware: + If the directory specified does not exist, nmbd + will log to the default debug log location defined at compile time. + @@ -198,25 +199,25 @@ smb.conf. - + -p <UDP port number> UDP port number is a positive integer value. - This option changes the default UDP port number (normally 137) - that nmbd responds to name queries on. Don't - use this option unless you are an expert, in which case you + This option changes the default UDP port number (normally 137) + that nmbd responds to name queries on. Don't + use this option unless you are an expert, in which case you won't need help! - + -s <configuration file> - The default configuration file name + The default configuration file name is set at build time, typically as /usr/local/samba/lib/smb.conf, but this may be changed when Samba is autoconfigured. - The file specified contains the configuration details - required by the server. See + The file specified contains the configuration details + required by the server. See smb.conf(5) for more information. @@ -229,55 +230,55 @@ /etc/inetd.conf - If the server is to be run by the - inetd meta-daemon, this file - must contain suitable startup information for the + If the server is to be run by the + inetd meta-daemon, this file + must contain suitable startup information for the meta-daemon. See the UNIX_INSTALL.html document for details. - + /etc/rc - or whatever initialization script your + or whatever initialization script your system uses). - If running the server as a daemon at startup, - this file will need to contain an appropriate startup + If running the server as a daemon at startup, + this file will need to contain an appropriate startup sequence for the server. See the UNIX_INSTALL.html document for details. - + /etc/services - If running the server via the - meta-daemon inetd, this file - must contain a mapping of service name (e.g., netbios-ssn) - to service port (e.g., 139) and protocol type (e.g., tcp). + If running the server via the + meta-daemon inetd, this file + must contain a mapping of service name (e.g., netbios-ssn) + to service port (e.g., 139) and protocol type (e.g., tcp). See the UNIX_INSTALL.html document for details. - + /usr/local/samba/lib/smb.conf - This is the default location of the + This is the default location of the smb.conf - server configuration file. Other common places that systems - install this file are /usr/samba/lib/smb.conf + server configuration file. Other common places that systems + install this file are /usr/samba/lib/smb.conf and /etc/smb.conf. - - When run as a WINS server (see the + + When run as a WINS server (see the wins support parameter in the smb.conf(5) man page), nmbd - will store the WINS database in the file wins.dat - in the var/locks directory configured under + will store the WINS database in the file wins.dat + in the var/locks directory configured under wherever Samba was configured to install itself. If nmbd is acting as a - browse master (see the (see the local master parameter in the smb.conf(5) man page, nmbd @@ -292,20 +293,20 @@ SIGNALS - To shut down an nmbd process it is recommended - that SIGKILL (-9) NOT be used, except as a last - resort, as this may leave the name database in an inconsistent state. - The correct way to terminate nmbd is to send it + To shut down an nmbd process it is recommended + that SIGKILL (-9) NOT be used, except as a last + resort, as this may leave the name database in an inconsistent state. + The correct way to terminate nmbd is to send it a SIGTERM (-15) signal and wait for it to die on its own. - nmbd will accept SIGHUP, which will cause + nmbd will accept SIGHUP, which will cause it to dump out its namelists into the file namelist.debug - in the /usr/local/samba/var/locks - directory (or the var/locks directory configured - under wherever Samba was configured to install itself). This will also + in the /usr/local/samba/var/locks + directory (or the var/locks directory configured + under wherever Samba was configured to install itself). This will also cause nmbd to dump out its server database in the log.nmb file. - + The debug log level of nmbd may be raised or lowered using smbcontrol(1) (SIGUSR[1|2] signals are no longer used in Samba 2.2). This is diff --git a/docs/docbook/manpages/smb.conf.5.sgml b/docs/docbook/manpages/smb.conf.5.sgml index 4a6de97f921..e8846e4b269 100644 --- a/docs/docbook/manpages/smb.conf.5.sgml +++ b/docs/docbook/manpages/smb.conf.5.sgml @@ -542,8 +542,10 @@ steps fail, then the connection request is rejected. However, if one of the steps succeeds, then the following steps are not checked. - If the service is marked "guest only = yes" then - steps 1 to 5 are skipped. + If the service is marked "guest only = yes" and the + server is running with share-level security ("security = share") + then steps 1 to 5 are skipped. + If the client has passed a username/password @@ -653,6 +655,9 @@ local master lock dir lock directory + lock spin count + lock spin time + pid directory log file log level logon drive @@ -833,6 +838,7 @@ hosts allow hosts deny include + inherit acls inherit permissions invalid users level2 oplocks @@ -3093,6 +3099,24 @@ + + inherit acls (S) + This parameter can be used to ensure + that if default acls exist on parent directories, + they are always honored when creating a subdirectory. + The default behavior is to use the mode specified + when creating the directory. Enabling this option + sets the mode to 0777, thus guaranteeing that + default directory acls are propagated. + + + Default: inherit acls = no + + + + + + inherit permissions (S) The permissions on new files and directories @@ -3600,6 +3624,39 @@ + + lock spin count (G) + This parameter controls the number of times + that smbd should attempt to gain a byte range lock on the + behalf of a client request. Experiments have shown that + Windows 2k servers do not reply with a failure if the lock + could not be immediately granted, but try a few more times + in case the lock could later be aquired. This behavior + is used to support PC database formats such as MS Access + and FoxPro. + + + Default: lock spin count = 2 + + + + + + + + lock spin time (G) + The time in microseconds that smbd should + pause before attempting to gain a failed lock. See + lock spin + count for more details. + + + Default: lock spin time = 10 + + + + + locking (S) This controls whether or not locking will be @@ -3889,8 +3946,8 @@ takes a printer name as its only parameter and outputs printer status information. - Currently eight styles of printer status information - are supported; BSD, AIX, LPRNG, PLP, SYSV, HPUX, QNX and SOFTQ. + Currently nine styles of printer status information + are supported; BSD, AIX, LPRNG, PLP, SYSV, HPUX, QNX, CUPS, and SOFTQ. This covers most UNIX systems. You control which type is expected using the printing = option. @@ -3906,7 +3963,10 @@ Note that it is good practice to include the absolute path in the lpq command as the $PATH - may not be available to the server. + may not be available to the server. When compiled with + the CUPS libraries, no lpq command is + needed because smbd will make a library call to obtain the + print queue listing. See also the printing parameter. @@ -5478,6 +5538,18 @@ + + pid directory (G) + This option specifies the directory where pid + files will be placed. + + Default: pid directory = ${prefix}/var/locks + Example: pid directory = /var/run/ + + + + + posix locking (S) The smbd(8) @@ -5657,14 +5729,23 @@ manually remove old spool files. The print command is simply a text string. It will be used - verbatim, with two exceptions: All occurrences of %s - and %f will be replaced by the - appropriate spool file name, and all occurrences of %p - will be replaced by the appropriate printer name. The - spool file name is generated automatically by the server. The - %J macro can be used to access the job + verbatim after macro substitutions have been made: + + s, %p - the path to the spool + file name + + %p - the appropriate printer + name + + %J - the job name as transmitted by the client. + %c - The number of printed pages + of the spooled job (if known). + + %z - the size of the spooled + print job (in bytes) + The print command MUST contain at least one occurrence of %s or %f - the %p is optional. At the time @@ -5708,6 +5789,17 @@ For printing = SOFTQ : print command = lp -d%p -s %s; rm %s + For printing = CUPS : If SAMBA is compiled against + libcups, then printcap = cups + uses the CUPS API to + submit jobs, etc. Otherwise it maps to the System V + commands with the -oraw option for printing, i.e. it + uses lp -c -d%p -oraw; rm %s. + With printing = cups, + and if SAMBA is compiled against libcups, any manually + set print command will be ignored. + + Example: print command = /usr/local/samba/bin/myprintscript %p %s @@ -5762,7 +5854,13 @@ why you might want to do this. To use the CUPS printing interface set printcap name = cups - . + . This should be supplemented by an addtional setting + printing = cups in the [global] + section. printcap name = cups will use the + "dummy" printcap created by CUPS, as specified in your CUPS + configuration file. + + On System V systems that use lpstat to list available printers you can use printcap name = lpstat to automatically obtain lists of available printers. This @@ -8089,7 +8187,7 @@ veto files = /.AppleDouble/.bin/.AppleDesktop/Network Trash Folder/ - winbind cache time + winbind cache time (G) This parameter specifies the number of seconds the winbindd(8) daemon will cache user and group information before querying a Windows NT server @@ -8101,8 +8199,8 @@ veto files = /.AppleDouble/.bin/.AppleDesktop/Network Trash Folder/ - winbind enum - users On large installations using + winbind enum users (G) + On large installations using winbindd(8) it may be necessary to suppress the enumeration of users through the setpwent(), @@ -8123,8 +8221,8 @@ veto files = /.AppleDouble/.bin/.AppleDesktop/Network Trash Folder/ - winbind enum - groups On large installations using + winbind enum groups (G) + On large installations using winbindd(8) it may be necessary to suppress the enumeration of groups through the setgrent(), @@ -8144,7 +8242,7 @@ veto files = /.AppleDouble/.bin/.AppleDesktop/Network Trash Folder/ - winbind gid + winbind gid (G) The winbind gid parameter specifies the range of group ids that are allocated by the winbindd(8) daemon. This range of group ids should have no @@ -8160,7 +8258,7 @@ veto files = /.AppleDouble/.bin/.AppleDesktop/Network Trash Folder/ - winbind separator + winbind separator (G) This parameter allows an admin to define the character used when listing a username of the form of DOMAIN \user. This parameter @@ -8172,8 +8270,8 @@ veto files = /.AppleDouble/.bin/.AppleDesktop/Network Trash Folder/ with group membership at least on glibc systems, as the character + is used as a special character for NIS in /etc/group. - Example: winbind separator = \\ - Example: winbind separator = / + Default: winbind separator = '\' + Example: winbind separator = + @@ -8181,7 +8279,7 @@ veto files = /.AppleDouble/.bin/.AppleDesktop/Network Trash Folder/ - winbind uid + winbind uid (G) The winbind gid parameter specifies the range of group ids that are allocated by the winbindd(8) daemon. This range of ids should have no diff --git a/docs/docbook/manpages/smbclient.1.sgml b/docs/docbook/manpages/smbclient.1.sgml index 4f36de15767..31031dafc46 100644 --- a/docs/docbook/manpages/smbclient.1.sgml +++ b/docs/docbook/manpages/smbclient.1.sgml @@ -434,9 +434,9 @@ domain = <value> -W WORKGROUP - Override the default workgroup specified in the - workgroup parameter of the smb.conf file - for this connection. This may be needed to connect to some + Override the default workgroup (domain) specified + in the workgroup parameter of the smb.conf + file for this connection. This may be needed to connect to some servers. @@ -634,6 +634,44 @@ domain = <value> + + altname file + The client will request that the server return + the "alternate" name (the 8.3 name) for a file or directory. + + + + + + cancel jobid0 [jobid1] ... [jobidN] + The client will request that the server cancel + the printjobs identified by the given numeric print job ids. + + + + + + + chmod file mode in octal + This command depends on the server supporting the CIFS + UNIX extensions and will fail if the server does not. The client requests that the server + change the UNIX permissions to the given octal mode, in standard UNIX format. + + + + + + + chown file uid gid + This command depends on the server supporting the CIFS + UNIX extensions and will fail if the server does not. The client requests that the server + change the UNIX user and group ownership to the given decimal values. Note there is + currently no way to remotely look up the UNIX uid and gid values for a given name. + This may be addressed in future versions of the CIFS UNIX extensions. + + + + cd [directory name] @@ -700,6 +738,17 @@ domain = <value> + + link source destination + This command depends on the server supporting the CIFS + UNIX extensions and will fail if the server does not. The client requests that the server + create a hard link between the source and destination files. The source file + must not exist. + + + + + lowercase Toggle lowercasing of filenames for the get and @@ -877,6 +926,30 @@ domain = <value> + + setmode <filename> <perm=[+|\-]rsha> + A version of the DOS attrib command to set + file permissions. For example: + + setmode myfile +r + + would make myfile read only. + + + + + + symlink source destination + This command depends on the server supporting the CIFS + UNIX extensions and will fail if the server does not. The client requests that the server + create a symbolic hard link between the source and destination files. The source file + must not exist. Note that the server will not create a link to any path that lies + outside the currently connected share. This is enforced by the Samba server. + + + + + tar <c|x>[IXbgNa] Performs a tar operation - see the -T @@ -907,16 +980,6 @@ domain = <value> - - setmode <filename> <perm=[+|\-]rsha> - A version of the DOS attrib command to set - file permissions. For example: - - setmode myfile +r - - would make myfile read only. - - diff --git a/docs/docbook/manpages/smbcontrol.1.sgml b/docs/docbook/manpages/smbcontrol.1.sgml index 05e05f4a6ab..517e2ca41f4 100644 --- a/docs/docbook/manpages/smbcontrol.1.sgml +++ b/docs/docbook/manpages/smbcontrol.1.sgml @@ -9,7 +9,7 @@ smbcontrol - send messages to smbd or nmbd processes + send messages to smbd, nmbd or winbindd processes @@ -33,9 +33,10 @@ Samba suite. smbcontrol is a very small program, which - sends messages to an smbd(8) or - an nmbd(8) daemon running on the - system. + sends messages to an smbd(8), + an nmbd(8) + or a winbindd(8) + daemon running on the system. @@ -81,8 +82,9 @@ message to smbd which will then close the client connections to the named share. Note that this doesn't affect client connections to any other shares. This message-type takes an argument of the - share name for which client connections will be close, or the + share name for which client connections will be closed, or the "*" character which will close all currently open shares. + This may be useful if you made changes to the access controls on the share. This message can only be sent to smbd. The debug message-type allows @@ -105,7 +107,7 @@ collection, "off" to turn off profile stats collection, "count" to enable only collection of count stats (time stats are disabled), and "flush" to zero the current profile stats. This can - be sent to any of the destinations. + be sent to any smbd or nmbd destinations. The debuglevel message-type sends a "request debug level" message. The current debug level setting @@ -115,18 +117,13 @@ The profilelevel message-type sends a "request profile level" message. The current profile level setting is returned by a "profilelevel" message. This can be sent - to any of the destinations. + to any smbd or nmbd destinations. The printer-notify message-type sends a message to smbd which in turn sends a printer notify message to any Windows NT clients connected to a printer. This message-type takes an argument of the printer name to send notify messages to. This message can only be sent to smbd. - - The close-share message-type sends a - message to smbd which forces smbd to close the share that was - specified as an argument. This may be useful if you made changes - to the access controls on the share. diff --git a/docs/docbook/manpages/smbd.8.sgml b/docs/docbook/manpages/smbd.8.sgml index 824ae20241c..509007c4bc8 100644 --- a/docs/docbook/manpages/smbd.8.sgml +++ b/docs/docbook/manpages/smbd.8.sgml @@ -176,7 +176,9 @@ its size may be controlled by the max log size option in the - smb.conf(5) file. + smb.conf(5) file. Beware: + If the directory specified does not exist, smbd + will log to the default debug log location defined at compile time. The default log directory is specified at diff --git a/docs/docbook/manpages/smbmount.8.sgml b/docs/docbook/manpages/smbmount.8.sgml index b4a77e51c9f..ec4dbbaff1f 100644 --- a/docs/docbook/manpages/smbmount.8.sgml +++ b/docs/docbook/manpages/smbmount.8.sgml @@ -14,7 +14,7 @@ - smbumount + smbmount service mount-point -o options diff --git a/docs/docbook/manpages/smbsh.1.sgml b/docs/docbook/manpages/smbsh.1.sgml index 46adac6b79d..82efb334ba7 100644 --- a/docs/docbook/manpages/smbsh.1.sgml +++ b/docs/docbook/manpages/smbsh.1.sgml @@ -16,6 +16,13 @@ smbsh + -W workgroup + -U username + -P prefix + -R <name resolve order> + -d <debug level> + -l logfile + -L libdir @@ -30,6 +37,129 @@ egrep, and rcp. You must use a shell that is dynamically linked in order for smbsh to work correctly. + + + + OPTIONS + + + + -W WORKGROUP + Override the default workgroup specified in the + workgroup parameter of the smb.conf file + for this session. This may be needed to connect to some + servers. + + + + -U username[%pass] + Sets the SMB username or username and password. + If this option is not specified, the user will be prompted for + both the username and the password. If %pass is not specified, + the user will be prompted for the password. + + + + + -P prefixThis option allows + the user to set the directory prefix for SMB access. The + default value if this option is not specified is + smb. + + + + + -R <name resolve order> + This option is used to determine what naming + services and in what order to resolve + host names to IP addresses. The option takes a space-separated + string of different name resolution options. + + The options are :"lmhosts", "host", "wins" and "bcast". + They cause names to be resolved as follows : + + + lmhosts : + Lookup an IP address in the Samba lmhosts file. If the + line in lmhosts has no name type attached to the + NetBIOS name + (see the lmhosts(5) + for details) then any name type matches for lookup. + + + host : + Do a standard host name to IP address resolution, using + the system /etc/hosts, NIS, or DNS + lookups. This method of name resolution is operating + system dependent, for instance on IRIX or Solaris this + may be controlled by the /etc/nsswitch.conf + file). Note that this method is only used + if the NetBIOS name type being queried is the 0x20 + (server) name type, otherwise it is ignored. + + + wins : + Query a name with the IP address listed in the + wins server parameter. If no + WINS server has been specified this method will be + ignored. + + + bcast : + Do a broadcast on each of the known local interfaces + listed in the interfaces + parameter. This is the least reliable of the name + resolution methods as it depends on the target host + being on a locally connected subnet. + + + + If this parameter is not set then the name resolve order + defined in the smb.conf file parameter + (name resolve order) will be used. + + The default order is lmhosts, host, wins, bcast. Without + this parameter or any entry in the name resolve order + parameter of the smb.conf + file, the name resolution methods will be attempted in this + order. + + + + -d <debug level> + debug level is an integer from 0 to 10. + + The default value if this parameter is not specified + is zero. + + The higher this value, the more detail will be logged + about the activities of nmblookup. At level + 0, only critical errors and serious warnings will be logged. + + + + + -l logfilename + If specified causes all debug messages to be + written to the file specified by logfilename + . If not specified then all messages will be + written tostderr. + + + + + -L libdir + This parameter specifies the location of the + shared libraries used by smbsh. The default + value is specified at compile time. + + + + + + + + EXAMPLES To use the smbsh command, execute smbsh from the prompt and enter the username and password diff --git a/docs/docbook/manpages/wbinfo.1.sgml b/docs/docbook/manpages/wbinfo.1.sgml index 7f2c4624a9a..f1461b07b9c 100644 --- a/docs/docbook/manpages/wbinfo.1.sgml +++ b/docs/docbook/manpages/wbinfo.1.sgml @@ -17,6 +17,8 @@ wbinfo -u -g + -h name + -i ip -n name -s sid -U uid @@ -25,8 +27,9 @@ -Y sid -t -m + -r user -a user%password - -p + -A user%password @@ -70,6 +73,26 @@ + + -h name + The -h option + queries winbindd(8) to query the WINS + server for the IP address associated with the NetBIOS name + specified by the name parameter. + + + + + + -i ip + The -i option + queries winbindd(8) to send a node status + request to get the NetBIOS name associated with the IP address + specified by the ip parameter. + + + + -n name The -n option @@ -143,6 +166,16 @@ + + + -r username + Try to obtain the list of UNIX group ids + to which the user belongs. This only works for users + defined on a Domain Controller. + + + + -a username%password Attempt to authenticate a user via winbindd. @@ -150,10 +183,14 @@ + - -p - Attempt a simple 'ping' check that the winbindd - is indeed alive. + -A username%password + Store username and password used by winbindd + during session setup to a domain controller. This enables + winbindd to operate in a Windows 2000 domain with Restrict + Anonymous turned on (a.k.a. Permissions compatiable with + Windows 2000 servers only). diff --git a/docs/docbook/manpages/winbindd.8.sgml b/docs/docbook/manpages/winbindd.8.sgml index bd1dafa07e8..0325f9bfe14 100644 --- a/docs/docbook/manpages/winbindd.8.sgml +++ b/docs/docbook/manpages/winbindd.8.sgml @@ -56,6 +56,15 @@ the winbindd service: + + hosts + User information traditionally stored in + the hosts(5) file and used by + gethostbyname(3) functions. Names are + resolved through the WINS server or by broadcast. + + + passwd User information traditionally stored in @@ -81,6 +90,12 @@ passwd: files winbind group: files winbind + + The following simple configuration in the + /etc/nsswitch.conf file can be used to initially + resolve hostnames from /etc/hosts and then from the + WINS server. + diff --git a/docs/docbook/projdoc/Samba-LDAP-HOWTO.sgml b/docs/docbook/projdoc/Samba-LDAP-HOWTO.sgml index 21d2c55ec7a..c6c04ccab83 100644 --- a/docs/docbook/projdoc/Samba-LDAP-HOWTO.sgml +++ b/docs/docbook/projdoc/Samba-LDAP-HOWTO.sgml @@ -13,8 +13,8 @@
olem@IDEALX.org
- - + + (13 Jan 2002) @@ -98,7 +98,7 @@ Identified (RID). As a result of these defeciencies, a more robust means of storing user attributes used by smbd was developed. The API which defines access to user accounts is commonly referred to as the samdb interface (previously this was called the passdb -API, and is still so named in the CVS trees). In Samba 2.2.3, enabling support +API, and is still so named in the CVS trees). In Samba 2.2.3, enabling support for a samdb backend (e.g. --with-ldapsam or --with-tdbsam) requires compile time support. @@ -515,7 +515,6 @@ something other than the default (e.g. \\MOBY\becky). - Example LDIF Entries for a sambaAccount diff --git a/docs/docbook/projdoc/winbind.sgml b/docs/docbook/projdoc/winbind.sgml index fc8d8d52a12..62e065914b4 100644 --- a/docs/docbook/projdoc/winbind.sgml +++ b/docs/docbook/projdoc/winbind.sgml @@ -324,6 +324,14 @@ to control access and authenticate users on your Linux box using the winbind services which come with SAMBA 2.2.2. + +There is also some Solaris specific information in +docs/textdocs/Solaris-Winbind-HOWTO.txt. +Future revisions of this document will incorporate that +information. + + + Introduction diff --git a/docs/faq/README b/docs/faq/README new file mode 100644 index 00000000000..f4f0e8ab69a --- /dev/null +++ b/docs/faq/README @@ -0,0 +1,8 @@ +This directory contains the old Samba FAQ. +It is now horribly outdated and unmaintained. +It is being left here in case there is some +useful information within. + + +--jerry@samba.org + diff --git a/docs/htmldocs/Samba-HOWTO-Collection.html b/docs/htmldocs/Samba-HOWTO-Collection.html index 5b44d17968d..5175bd4c8dd 100644 --- a/docs/htmldocs/Samba-HOWTO-Collection.html +++ b/docs/htmldocs/Samba-HOWTO-Collection.html @@ -878,29 +878,29 @@ HREF="#AEN2015" >
11.5.1. Introduction
11.5.2. Requirements
11.5.3. Testing Things Out
11.5.3.1. Configure and compile SAMBA
11.5.3.2. Configure nsswitch.conf
11.5.3.3. Configure smb.conf
11.5.3.4. Join the SAMBA server to the PDC domain
11.5.3.5. Start up the winbindd daemon and test it!
11.5.3.6. Fix the /etc/rc.d/init.d/smb
11.5.3.7. Configure Winbind and PAM
11.6. Limitations
11.7. Conclusion
12.1. FAQs
12.1.1. How can I configure OS/2 Warp Connect or OS/2 Warp 4 as a client for Samba?
12.1.2. How can I configure OS/2 Warp 3 (not Connect), OS/2 1.2, 1.3 or 2.x for Samba?
12.1.3. Are there any other issues when OS/2 (any version) is used as a client?
12.1.4. How do I get printer driver download working for OS/2 clients?
13.1. Introduction
13.2. CVS Access to samba.org
13.2.1. Access via CVSweb
13.2.2. Access via cvs
Index
As a result of these defeciencies, a more robust means of storing user attributes used by smbd was developed. The API which defines access to user accounts is commonly referred to as the samdb interface (previously this was called the passdb -API, and is still so named in the CVS trees). In Samba 2.2.3, enabling support +API, and is still so named in the CVS trees). In Samba 2.2.3, enabling support for a samdb backend (e.g. This HOWTO describes how to get winbind services up and running to control access and authenticate users on your Linux box using the winbind services which come with SAMBA 2.2.2.

There is also some Solaris specific information in +docs/textdocs/Solaris-Winbind-HOWTO.txt. +Future revisions of this document will incorporate that +information.

-n <primary NetBIOS name>

UDP port number is a positive integer value. - This option changes the default UDP port number (normally 137) + This option changes the default UDP port number (normally 137) that nmbd responds to name queries on. Don't - use this option unless you are an expert, in which case you +> responds to name queries on. Don't + use this option unless you are an expert, in which case you won't need help!

-s <configuration file>

The default configuration file name +>The default configuration file name is set at build time, typically as /usr/local/samba/lib/smb.conf, but this may be changed when Samba is autoconfigured.

The file specified contains the configuration details +>The file specified contains the configuration details required by the server. See - smb.conf(5)

FILES

If the server is to be run by the +>If the server is to be run by the inetd meta-daemon, this file - must contain suitable startup information for the +> meta-daemon, this file + must contain suitable startup information for the meta-daemon. See the

or whatever initialization script your +>or whatever initialization script your system uses).

If running the server as a daemon at startup, - this file will need to contain an appropriate startup +>If running the server as a daemon at startup, + this file will need to contain an appropriate startup sequence for the server. See the

If running the server via the +>If running the server via the meta-daemon inetd, this file - must contain a mapping of service name (e.g., netbios-ssn) - to service port (e.g., 139) and protocol type (e.g., tcp). +>, this file + must contain a mapping of service name (e.g., netbios-ssn) + to service port (e.g., 139) and protocol type (e.g., tcp). See the

This is the default location of the +>This is the default location of the smb.conf - server configuration file. Other common places that systems + server configuration file. Other common places that systems install this file are /usr/samba/lib/smb.conf +> and /etc/smb.conf.

When run as a WINS server (see the +>When run as a WINS server (see the wins.dat +> in the var/locks directory configured under +> directory configured under wherever Samba was configured to install itself.

If

SIGNALS

To shut down an nmbd process it is recommended +> process it is recommended that SIGKILL (-9) NOT be used, except as a last - resort, as this may leave the name database in an inconsistent state. +> be used, except as a last + resort, as this may leave the name database in an inconsistent state. The correct way to terminate nmbd is to send it +> is to send it a SIGTERM (-15) signal and wait for it to die on its own.

nmbd will accept SIGHUP, which will cause +> will accept SIGHUP, which will cause it to dump out its namelists into the file namelist.debug @@ -562,12 +567,12 @@ CLASS="FILENAME" > in the /usr/local/samba/var/locks +> directory (or the var/locks directory configured - under wherever Samba was configured to install itself). This will also +> directory configured + under wherever Samba was configured to install itself). This will also cause nmbd

VERSION

SEE ALSO

AUTHOR

If the service is marked "guest only = yes" then - steps 1 to 5 are skipped.

If the service is marked "guest only = yes" and the + server is running with share-level security ("security = share") + then steps 1 to 5 are skipped.

  1. lock spin count

  2. lock spin time

  3. pid directory

  4. COMPLETE LIST OF SERVICE PARAMETERS

  5. inherit acls

  6. EXPLANATION OF EACH PARAMETER

inherit acls (S)

This parameter can be used to ensure + that if default acls exist on parent directories, + they are always honored when creating a subdirectory. + The default behavior is to use the mode specified + when creating the directory. Enabling this option + sets the mode to 0777, thus guaranteeing that + default directory acls are propagated. +

Default: inherit acls = no +

inherit permissions (S)
lock spin count (G)

This parameter controls the number of times + that smbd should attempt to gain a byte range lock on the + behalf of a client request. Experiments have shown that + Windows 2k servers do not reply with a failure if the lock + could not be immediately granted, but try a few more times + in case the lock could later be aquired. This behavior + is used to support PC database formats such as MS Access + and FoxPro. +

Default: lock spin count = 2 +

lock spin time (G)

The time in microseconds that smbd should + pause before attempting to gain a failed lock. See + lock spin + count for more details. +

Default: lock spin time = 10 +

locking (S)

Currently eight styles of printer status information - are supported; BSD, AIX, LPRNG, PLP, SYSV, HPUX, QNX and SOFTQ. +>Currently nine styles of printer status information + are supported; BSD, AIX, LPRNG, PLP, SYSV, HPUX, QNX, CUPS, and SOFTQ. This covers most UNIX systems. You control which type is expected using the $PATH may not be available to the server.

may not be available to the server. When compiled with + the CUPS libraries, no lpq command is + needed because smbd will make a library call to obtain the + print queue listing.

See also the

pid directory (G)

This option specifies the directory where pid + files will be placed.

Default: pid directory = ${prefix}/var/locks

Example: pid directory = /var/run/ +

posix locking (S)

The print command is simply a text string. It will be used - verbatim, with two exceptions: All occurrences of %s - and %f will be replaced by the - appropriate spool file name, and all occurrences of %p - will be replaced by the appropriate printer name. The - spool file name is generated automatically by the server. The - %J macro can be used to access the job + verbatim after macro substitutions have been made:

s, %p - the path to the spool + file name

%p - the appropriate printer + name

%J - the job name as transmitted by the client.

%c - The number of printed pages + of the spooled job (if known).

%z - the size of the spooled + print job (in bytes)

The print command MUST contain at least @@ -14065,6 +14204,25 @@ CLASS="COMMAND" >print command = lp -d%p -s %s; rm %s

For printing = CUPS : If SAMBA is compiled against + libcups, then printcap = cups + uses the CUPS API to + submit jobs, etc. Otherwise it maps to the System V + commands with the -oraw option for printing, i.e. it + uses lp -c -d%p -oraw; rm %s. + With printing = cups, + and if SAMBA is compiled against libcups, any manually + set print command will be ignored.

Example: print command = /usr/local/samba/bin/myprintscript @@ -14159,7 +14317,18 @@ HREF="#AEN79" CLASS="COMMAND" >printcap name = cups .

. This should be supplemented by an addtional setting + printing = cups in the [global] + section. printcap name = cups will use the + "dummy" printcap created by CUPS, as specified in your CUPS + configuration file. +

On System V systems that use winbind cache timewinbind cache time (G)

This parameter specifies the number of seconds the @@ -18485,8 +18654,7 @@ CLASS="COMMAND" >winbind enum - userswinbind enum users (G)

On large installations using @@ -18537,8 +18705,7 @@ CLASS="COMMAND" >winbind enum - groupswinbind enum groups (G)

On large installations using @@ -18588,7 +18755,7 @@ CLASS="COMMAND" >winbind gidwinbind gid (G)

The winbind gid parameter specifies the range of group @@ -18615,7 +18782,7 @@ CLASS="COMMAND" >winbind separatorwinbind separator (G)

This parameter allows an admin to define the character @@ -18645,21 +18812,21 @@ CLASS="FILENAME" with group membership at least on glibc systems, as the character + is used as a special character for NIS in /etc/group.

Example: Default: winbind separator = \\winbind separator = '\'

Example: winbind separator = /winbind separator = +

winbind uid
winbind uid (G)

The winbind gid parameter specifies the range of group @@ -19079,7 +19246,7 @@ CLASS="COMMAND" >

WARNINGS

VERSION

SEE ALSO

AUTHOR

-W WORKGROUP

Override the default workgroup specified in the - workgroup parameter of the Override the default workgroup (domain) specified + in the workgroup parameter of the smb.conf file - for this connection. This may be needed to connect to some +> + file for this connection. This may be needed to connect to some servers.

altname file

The client will request that the server return + the "alternate" name (the 8.3 name) for a file or directory. +

cancel jobid0 [jobid1] ... [jobidN]

The client will request that the server cancel + the printjobs identified by the given numeric print job ids. +

chmod file mode in octal

This command depends on the server supporting the CIFS + UNIX extensions and will fail if the server does not. The client requests that the server + change the UNIX permissions to the given octal mode, in standard UNIX format. +

chown file uid gid

This command depends on the server supporting the CIFS + UNIX extensions and will fail if the server does not. The client requests that the server + change the UNIX user and group ownership to the given decimal values. Note there is + currently no way to remotely look up the UNIX uid and gid values for a given name. + This may be addressed in future versions of the CIFS UNIX extensions. +

cd [directory name]

link source destination

This command depends on the server supporting the CIFS + UNIX extensions and will fail if the server does not. The client requests that the server + create a hard link between the source and destination files. The source file + must not exist. +

lowercase

setmode <filename> <perm=[+|\-]rsha>

A version of the DOS attrib command to set + file permissions. For example:

setmode myfile +r

would make myfile read only.

symlink source destination

This command depends on the server supporting the CIFS + UNIX extensions and will fail if the server does not. The client requests that the server + create a symbolic hard link between the source and destination files. The source file + must not exist. Note that the server will not create a link to any path that lies + outside the currently connected share. This is enforced by the Samba server. +

tar <c|x>[IXbgNa]

setmode <filename> <perm=[+|\-]rsha>

A version of the DOS attrib command to set - file permissions. For example:

setmode myfile +r

would make myfile read only.

NOTES

ENVIRONMENT VARIABLES

INSTALLATION

DIAGNOSTICS

VERSION

AUTHOR

Name

smbcontrol -- send messages to smbd or nmbd processes
smbcontrol -- send messages to smbd, nmbd or winbindd processes
smbd(8) or +>, an nmbd(8) daemon running on the - system.

+ or a winbindd(8) + daemon running on the system.

OPTIONS

smbd

The message-type sends a "request profile level" message. The current profile level setting is returned by a "profilelevel" message. This can be sent - to any of the destinations.

The smbd.

The close-share message-type sends a - message to smbd which forces smbd to close the share that was - specified as an argument. This may be useful if you made changes - to the access controls on the share.

parameters

VERSION

SEE ALSO

AUTHOR

smb.conf(5)
file. +> file. Beware: + If the directory specified does not exist, smbd + will log to the default debug log location defined at compile time.

The default log directory is specified at @@ -354,7 +361,7 @@ CLASS="FILENAME" >

FILES

LIMITATIONS

ENVIRONMENT VARIABLES

PAM INTERACTION

VERSION

DIAGNOSTICS

SIGNALS

SEE ALSO

AUTHOR

smbumountsmbmount {service} {mount-point} [-o options]

smbsh

[-W workgroup] [-U username] [-P prefix] [-R <name resolve order>] [-d <debug level>] [-l logfile] [-L libdir]

DESCRIPTION

smbsh to work correctly.

OPTIONS

-W WORKGROUP

Override the default workgroup specified in the + workgroup parameter of the smb.conf file + for this session. This may be needed to connect to some + servers.

-U username[%pass]

Sets the SMB username or username and password. + If this option is not specified, the user will be prompted for + both the username and the password. If %pass is not specified, + the user will be prompted for the password. +

-P prefix

This option allows + the user to set the directory prefix for SMB access. The + default value if this option is not specified is + smb. +

-R <name resolve order>

This option is used to determine what naming + services and in what order to resolve + host names to IP addresses. The option takes a space-separated + string of different name resolution options.

The options are :"lmhosts", "host", "wins" and "bcast". + They cause names to be resolved as follows :

  • lmhosts : + Lookup an IP address in the Samba lmhosts file. If the + line in lmhosts has no name type attached to the + NetBIOS name + (see the lmhosts(5) + for details) then any name type matches for lookup. +

  • host : + Do a standard host name to IP address resolution, using + the system /etc/hosts, NIS, or DNS + lookups. This method of name resolution is operating + system dependent, for instance on IRIX or Solaris this + may be controlled by the /etc/nsswitch.conf + file). Note that this method is only used + if the NetBIOS name type being queried is the 0x20 + (server) name type, otherwise it is ignored. +

  • wins : + Query a name with the IP address listed in the + wins server parameter. If no + WINS server has been specified this method will be + ignored. +

  • bcast : + Do a broadcast on each of the known local interfaces + listed in the interfaces + parameter. This is the least reliable of the name + resolution methods as it depends on the target host + being on a locally connected subnet. +

If this parameter is not set then the name resolve order + defined in the smb.conf file parameter + (name resolve order) will be used.

The default order is lmhosts, host, wins, bcast. Without + this parameter or any entry in the name resolve order + parameter of the smb.conf + file, the name resolution methods will be attempted in this + order.

-d <debug level>

debug level is an integer from 0 to 10.

The default value if this parameter is not specified + is zero.

The higher this value, the more detail will be logged + about the activities of nmblookup. At level + 0, only critical errors and serious warnings will be logged. +

-l logfilename

If specified causes all debug messages to be + written to the file specified by logfilename + . If not specified then all messages will be + written tostderr. +

-L libdir

This parameter specifies the location of the + shared libraries used by smbsh. The default + value is specified at compile time. +

EXAMPLES

To use the

VERSION

BUGS

SEE ALSO

AUTHOR

wbinfo [-u] [-g] [-n name] [-s sid] [-U uid] [-G gid] [-S sid] [-Y sid] [-t] [-m] [-a user%password] [-p]

[-u] [-g] [-h name] [-i ip] [-n name] [-s sid] [-U uid] [-G gid] [-S sid] [-Y sid] [-t] [-m] [-r user] [-a user%password] [-A user%password]

DESCRIPTION

OPTIONS

.

-h name

The -h option + queries winbindd(8) to query the WINS + server for the IP address associated with the NetBIOS name + specified by the name parameter. +

-i ip

The -i option + queries winbindd(8) to send a node status + request to get the NetBIOS name associated with the IP address + specified by the ip parameter. +

-n name

-r username

Try to obtain the list of UNIX group ids + to which the user belongs. This only works for users + defined on a Domain Controller. +

-a username%password

-p
-A username%password

Attempt a simple 'ping' check that the winbindd - is indeed alive. +>Store username and password used by winbindd + during session setup to a domain controller. This enables + winbindd to operate in a Windows 2000 domain with Restrict + Anonymous turned on (a.k.a. Permissions compatiable with + Windows 2000 servers only).

EXIT STATUS

VERSION

SEE ALSO

AUTHOR

hosts

User information traditionally stored in + the hosts(5) file and used by + gethostbyname(3) functions. Names are + resolved through the WINS server or by broadcast. +

passwd

The following simple configuration in the + /etc/nsswitch.conf file can be used to initially + resolve hostnames from /etc/hosts and then from the + WINS server.

OPTIONS

NAME AND ID RESOLUTION

CONFIGURATION

EXAMPLE SETUP

NOTES

SIGNALS

FILES

VERSION

SEE ALSO

AUTHOR

.\" Please send any bug reports, improvements, comments, patches, .\" etc. to Steve Cheng . -.TH "NMBD" "8" "28 January 2002" "" "" +.TH "NMBD" "8" "08 May 2002" "" "" .SH NAME nmbd \- NetBIOS name server to provide NetBIOS over IP naming services to clients .SH SYNOPSIS @@ -126,11 +126,11 @@ parameter in the \fI smb.conf\fRfile. The -l parameter specifies a directory into which the "log.nmbd" log file will be created for operational data from the running -\fBnmbd\fR server. - -The default log directory is compiled into Samba +\fBnmbd\fR server. The default log directory is compiled into Samba as part of the build process. Common defaults are \fI /usr/local/samba/var/log.nmb\fR, \fI /usr/samba/var/log.nmb\fR or -\fI/var/log/log.nmb\fR. +\fI/var/log/log.nmb\fR. \fBBeware:\fR +If the directory specified does not exist, \fBnmbd\fR +will log to the default debug log location defined at compile time. .TP \fB-n \fR This option allows you to override @@ -142,58 +142,57 @@ line setting will take precedence over settings in .TP \fB-p \fR UDP port number is a positive integer value. -This option changes the default UDP port number (normally 137) -that \fBnmbd\fR responds to name queries on. Don't -use this option unless you are an expert, in which case you +This option changes the default UDP port number (normally 137) +that \fBnmbd\fR responds to name queries on. Don't +use this option unless you are an expert, in which case you won't need help! .TP \fB-s \fR -The default configuration file name +The default configuration file name is set at build time, typically as \fI /usr/local/samba/lib/smb.conf\fR, but this may be changed when Samba is autoconfigured. -The file specified contains the configuration details -required by the server. See -\fIsmb.conf(5)\fRfor more information. +The file specified contains the configuration details +required by the server. See \fIsmb.conf(5)\fRfor more information. .SH "FILES" .TP \fB\fI/etc/inetd.conf\fB\fR -If the server is to be run by the -\fBinetd\fR meta-daemon, this file -must contain suitable startup information for the +If the server is to be run by the +\fBinetd\fR meta-daemon, this file +must contain suitable startup information for the meta-daemon. See the UNIX_INSTALL.htmldocument for details. .TP \fB\fI/etc/rc\fB\fR -or whatever initialization script your +or whatever initialization script your system uses). -If running the server as a daemon at startup, -this file will need to contain an appropriate startup +If running the server as a daemon at startup, +this file will need to contain an appropriate startup sequence for the server. See the UNIX_INSTALL.htmldocument for details. .TP \fB\fI/etc/services\fB\fR -If running the server via the -meta-daemon \fBinetd\fR, this file -must contain a mapping of service name (e.g., netbios-ssn) -to service port (e.g., 139) and protocol type (e.g., tcp). +If running the server via the +meta-daemon \fBinetd\fR, this file +must contain a mapping of service name (e.g., netbios-ssn) +to service port (e.g., 139) and protocol type (e.g., tcp). See the UNIX_INSTALL.html document for details. .TP \fB\fI/usr/local/samba/lib/smb.conf\fB\fR -This is the default location of the +This is the default location of the \fIsmb.conf\fR -server configuration file. Other common places that systems -install this file are \fI/usr/samba/lib/smb.conf\fR +server configuration file. Other common places that systems +install this file are \fI/usr/samba/lib/smb.conf\fR and \fI/etc/smb.conf\fR. -When run as a WINS server (see the +When run as a WINS server (see the wins support parameter in the \fIsmb.conf(5)\fR man page), \fBnmbd\fR -will store the WINS database in the file \fIwins.dat\fR -in the \fIvar/locks\fR directory configured under +will store the WINS database in the file \fIwins.dat\fR +in the \fIvar/locks\fR directory configured under wherever Samba was configured to install itself. If \fBnmbd\fR is acting as a \fB browse master\fR (see the local master @@ -204,17 +203,17 @@ will store the browsing database in the file \fIbrowse.dat configured under wherever Samba was configured to install itself. .SH "SIGNALS" .PP -To shut down an \fBnmbd\fR process it is recommended -that SIGKILL (-9) \fBNOT\fR be used, except as a last -resort, as this may leave the name database in an inconsistent state. -The correct way to terminate \fBnmbd\fR is to send it +To shut down an \fBnmbd\fR process it is recommended +that SIGKILL (-9) \fBNOT\fR be used, except as a last +resort, as this may leave the name database in an inconsistent state. +The correct way to terminate \fBnmbd\fR is to send it a SIGTERM (-15) signal and wait for it to die on its own. .PP -\fBnmbd\fR will accept SIGHUP, which will cause +\fBnmbd\fR will accept SIGHUP, which will cause it to dump out its namelists into the file \fInamelist.debug -\fRin the \fI/usr/local/samba/var/locks\fR -directory (or the \fIvar/locks\fR directory configured -under wherever Samba was configured to install itself). This will also +\fRin the \fI/usr/local/samba/var/locks\fR +directory (or the \fIvar/locks\fR directory configured +under wherever Samba was configured to install itself). This will also cause \fBnmbd\fR to dump out its server database in the \fIlog.nmb\fR file. .PP diff --git a/docs/manpages/smb.conf.5 b/docs/manpages/smb.conf.5 index 4d8d0a27857..692530334be 100644 --- a/docs/manpages/smb.conf.5 +++ b/docs/manpages/smb.conf.5 @@ -3,7 +3,7 @@ .\" .\" Please send any bug reports, improvements, comments, patches, .\" etc. to Steve Cheng . -.TH "SMB.CONF" "5" "24 April 2002" "" "" +.TH "SMB.CONF" "5" "08 May 2002" "" "" .SH NAME smb.conf \- The configuration file for the Samba suite .SH "SYNOPSIS" @@ -463,8 +463,9 @@ if it will allow a connection to a specified service. If all the steps fail, then the connection request is rejected. However, if one of the steps succeeds, then the following steps are not checked. .PP -If the service is marked "guest only = yes" then -steps 1 to 5 are skipped. +If the service is marked "guest only = yes" and the +server is running with share-level security ("security = share") +then steps 1 to 5 are skipped. .IP 1. If the client has passed a username/password pair and that username/password pair is validated by the UNIX @@ -686,6 +687,15 @@ each parameter for details. Note that some are synonyms. \fIlock directory\fR .TP 0.2i \(bu +\fIlock spin count\fR +.TP 0.2i +\(bu +\fIlock spin time\fR +.TP 0.2i +\(bu +\fIpid directory\fR +.TP 0.2i +\(bu \fIlog file\fR .TP 0.2i \(bu @@ -1188,6 +1198,9 @@ each parameter for details. Note that some are synonyms. \fIinclude\fR .TP 0.2i \(bu +\fIinherit acls\fR +.TP 0.2i +\(bu \fIinherit permissions\fR .TP 0.2i \(bu @@ -3102,6 +3115,17 @@ Default: \fBno file included\fR Example: \fBinclude = /usr/local/samba/lib/admin_smb.conf \fR.TP +\fBinherit acls (S)\fR +This parameter can be used to ensure +that if default acls exist on parent directories, +they are always honored when creating a subdirectory. +The default behavior is to use the mode specified +when creating the directory. Enabling this option +sets the mode to 0777, thus guaranteeing that +default directory acls are propagated. + +Default: \fBinherit acls = no\fR +.TP \fBinherit permissions (S)\fR The permissions on new files and directories are normally governed by \fI create mask\fR, \fIdirectory mask\fR, \fIforce create mode\fR @@ -3469,6 +3493,26 @@ Default: \fBlock directory = ${prefix}/var/locks\fR Example: \fBlock directory = /var/run/samba/locks\fR .TP +\fBlock spin count (G)\fR +This parameter controls the number of times +that smbd should attempt to gain a byte range lock on the +behalf of a client request. Experiments have shown that +Windows 2k servers do not reply with a failure if the lock +could not be immediately granted, but try a few more times +in case the lock could later be aquired. This behavior +is used to support PC database formats such as MS Access +and FoxPro. + +Default: \fBlock spin count = 2\fR +.TP +\fBlock spin time (G)\fR +The time in microseconds that smbd should +pause before attempting to gain a failed lock. See +\fIlock spin +count\fR for more details. + +Default: \fBlock spin time = 10\fR +.TP \fBlocking (S)\fR This controls whether or not locking will be performed by the server in response to lock requests from the @@ -3712,8 +3756,8 @@ This command should be a program or script which takes a printer name as its only parameter and outputs printer status information. -Currently eight styles of printer status information -are supported; BSD, AIX, LPRNG, PLP, SYSV, HPUX, QNX and SOFTQ. +Currently nine styles of printer status information +are supported; BSD, AIX, LPRNG, PLP, SYSV, HPUX, QNX, CUPS, and SOFTQ. This covers most UNIX systems. You control which type is expected using the \fIprinting =\fR option. @@ -3729,7 +3773,10 @@ command. Note that it is good practice to include the absolute path in the \fIlpq command\fR as the \fB$PATH -\fRmay not be available to the server. +\fRmay not be available to the server. When compiled with +the CUPS libraries, no \fIlpq command\fR is +needed because smbd will make a library call to obtain the +print queue listing. See also the \fIprinting \fRparameter. @@ -5008,6 +5055,14 @@ Default: \fBnone\fR Example: \fBpath = /home/fred\fR .TP +\fBpid directory (G)\fR +This option specifies the directory where pid +files will be placed. + +Default: \fBpid directory = ${prefix}/var/locks\fR + +Example: \fBpid directory = /var/run/\fR +.TP \fBposix locking (S)\fR The \fBsmbd(8)\fR daemon maintains an database of file locks obtained by SMB clients. @@ -5137,14 +5192,23 @@ spool file when it has been processed, otherwise you will need to manually remove old spool files. The print command is simply a text string. It will be used -verbatim, with two exceptions: All occurrences of \fI%s -\fRand \fI%f\fR will be replaced by the -appropriate spool file name, and all occurrences of \fI%p -\fRwill be replaced by the appropriate printer name. The -spool file name is generated automatically by the server. The -\fI%J\fR macro can be used to access the job +verbatim after macro substitutions have been made: + +s, %p - the path to the spool +file name + +%p - the appropriate printer +name + +%J - the job name as transmitted by the client. +%c - The number of printed pages +of the spooled job (if known). + +%z - the size of the spooled +print job (in bytes) + The print command \fBMUST\fR contain at least one occurrence of \fI%s\fR or \fI%f \fR- the \fI%p\fR is optional. At the time @@ -5189,6 +5253,16 @@ For \fBprinting = SOFTQ :\fR \fBprint command = lp -d%p -s %s; rm %s\fR +For printing = CUPS : If SAMBA is compiled against +libcups, then printcap = cups +uses the CUPS API to +submit jobs, etc. Otherwise it maps to the System V +commands with the -oraw option for printing, i.e. it +uses \fBlp -c -d%p -oraw; rm %s\fR. +With \fBprinting = cups\fR, +and if SAMBA is compiled against libcups, any manually +set print command will be ignored. + Example: \fBprint command = /usr/local/samba/bin/myprintscript %p %s\fR .TP @@ -5217,7 +5291,11 @@ compiled-in default printcap name used by the server (usually \fI /etc/printcap\ why you might want to do this. To use the CUPS printing interface set \fBprintcap name = cups -\fR\&. +\fR\&. This should be supplemented by an addtional setting +printing = cups in the [global] +section. \fBprintcap name = cups\fR will use the +"dummy" printcap created by CUPS, as specified in your CUPS +configuration file. On System V systems that use \fBlpstat\fR to list available printers you can use \fBprintcap name = lpstat @@ -7042,7 +7120,7 @@ that Samba has to do in order to perform the link checks. Default: \fBwide links = yes\fR .TP -\fBwinbind cache time\fR +\fBwinbind cache time (G)\fR This parameter specifies the number of seconds the winbindd(8)daemon will cache user and group information before querying a Windows NT server @@ -7050,7 +7128,7 @@ again. Default: \fBwinbind cache type = 15\fR .TP -\fBwinbind enum users\fR +\fBwinbind enum users (G)\fR On large installations using winbindd(8)it may be necessary to suppress the enumeration of users through the @@ -7069,7 +7147,7 @@ usernames. Default: \fBwinbind enum users = yes \fR .TP -\fBwinbind enum groups\fR +\fBwinbind enum groups (G)\fR On large installations using winbindd(8)it may be necessary to suppress the enumeration of groups through the @@ -7085,7 +7163,7 @@ enumeration may cause some programs to behave oddly. Default: \fBwinbind enum groups = yes \fR .TP -\fBwinbind gid\fR +\fBwinbind gid (G)\fR The winbind gid parameter specifies the range of group ids that are allocated by the winbindd(8)daemon. This range of group ids should have no existing local or NIS groups within it as strange conflicts can @@ -7095,7 +7173,7 @@ Default: \fBwinbind gid = \fR Example: \fBwinbind gid = 10000-20000\fR .TP -\fBwinbind separator\fR +\fBwinbind separator (G)\fR This parameter allows an admin to define the character used when listing a username of the form of \fIDOMAIN \fR\\\fIuser\fR. This parameter @@ -7106,11 +7184,11 @@ Please note that setting this parameter to + causes problems with group membership at least on glibc systems, as the character + is used as a special character for NIS in /etc/group. -Example: \fBwinbind separator = \\\\\fR +Default: \fBwinbind separator = '\\'\fR -Example: \fBwinbind separator = /\fR +Example: \fBwinbind separator = +\fR .TP -\fBwinbind uid\fR +\fBwinbind uid (G)\fR The winbind gid parameter specifies the range of group ids that are allocated by the winbindd(8)daemon. This range of ids should have no existing local or NIS users within it as strange conflicts can diff --git a/docs/manpages/smbclient.1 b/docs/manpages/smbclient.1 index 8b969ce4d1a..641f2d4a9f1 100644 --- a/docs/manpages/smbclient.1 +++ b/docs/manpages/smbclient.1 @@ -3,7 +3,7 @@ .\" .\" Please send any bug reports, improvements, comments, patches, .\" etc. to Steve Cheng . -.TH "SMBCLIENT" "1" "28 January 2002" "" "" +.TH "SMBCLIENT" "1" "08 May 2002" "" "" .SH NAME smbclient \- ftp-like client to access SMB/CIFS resources on servers .SH SYNOPSIS @@ -327,9 +327,9 @@ is 65520 bytes. Setting this value smaller (to 1200 bytes) has been observed to speed up file transfers to and from a Win9x server. .TP \fB-W WORKGROUP\fR -Override the default workgroup specified in the -workgroup parameter of the \fIsmb.conf\fR file -for this connection. This may be needed to connect to some +Override the default workgroup (domain) specified +in the workgroup parameter of the \fIsmb.conf\fR +file for this connection. This may be needed to connect to some servers. .TP \fB-T tar options\fR @@ -513,6 +513,26 @@ If \fIshell command\fR is specified, the ! command will execute a shell locally and run the specified shell command. If no command is specified, a local shell will be run. .TP +\fBaltname file\fR +The client will request that the server return +the "alternate" name (the 8.3 name) for a file or directory. +.TP +\fBcancel jobid0 [jobid1] ... [jobidN]\fR +The client will request that the server cancel +the printjobs identified by the given numeric print job ids. +.TP +\fBchmod file mode in octal\fR +This command depends on the server supporting the CIFS +UNIX extensions and will fail if the server does not. The client requests that the server +change the UNIX permissions to the given octal mode, in standard UNIX format. +.TP +\fBchown file uid gid\fR +This command depends on the server supporting the CIFS +UNIX extensions and will fail if the server does not. The client requests that the server +change the UNIX user and group ownership to the given decimal values. Note there is +currently no way to remotely look up the UNIX uid and gid values for a given name. +This may be addressed in future versions of the CIFS UNIX extensions. +.TP \fBcd [directory name]\fR If "directory name" is specified, the current working directory on the server will be changed to the directory @@ -555,6 +575,12 @@ reason the specified directory is inaccessible. If no directory name is specified, the name of the current working directory on the local machine will be reported. .TP +\fBlink source destination\fR +This command depends on the server supporting the CIFS +UNIX extensions and will fail if the server does not. The client requests that the server +create a hard link between the source and destination files. The source file +must not exist. +.TP \fBlowercase\fR Toggle lowercasing of filenames for the get and mget commands. @@ -674,6 +700,21 @@ working directory on the server. Remove the specified directory (user access privileges permitting) from the server. .TP +\fBsetmode \fR +A version of the DOS attrib command to set +file permissions. For example: + +\fBsetmode myfile +r \fR + +would make myfile read only. +.TP +\fBsymlink source destination\fR +This command depends on the server supporting the CIFS +UNIX extensions and will fail if the server does not. The client requests that the server +create a symbolic hard link between the source and destination files. The source file +must not exist. Note that the server will not create a link to any path that lies +outside the currently connected share. This is enforced by the Samba server. +.TP \fBtar [IXbgNa]\fR Performs a tar operation - see the \fI-T \fRcommand line option above. Behavior may be affected @@ -693,14 +734,6 @@ archive bit setting (this is the default mode). In incremental mode, tar will only back up files with the archive bit set. In reset mode, tar will reset the archive bit on all files it backs up (implies read/write share). -.TP -\fBsetmode \fR -A version of the DOS attrib command to set -file permissions. For example: - -\fBsetmode myfile +r \fR - -would make myfile read only. .SH "NOTES" .PP Some servers are fussy about the case of supplied usernames, diff --git a/docs/manpages/smbcontrol.1 b/docs/manpages/smbcontrol.1 index f341b563e15..f3e6c843b59 100644 --- a/docs/manpages/smbcontrol.1 +++ b/docs/manpages/smbcontrol.1 @@ -3,9 +3,9 @@ .\" .\" Please send any bug reports, improvements, comments, patches, .\" etc. to Steve Cheng . -.TH "SMBCONTROL" "1" "28 January 2002" "" "" +.TH "SMBCONTROL" "1" "08 May 2002" "" "" .SH NAME -smbcontrol \- send messages to smbd or nmbd processes +smbcontrol \- send messages to smbd, nmbd or winbindd processes .SH SYNOPSIS .sp \fBsmbcontrol\fR [ \fB-i\fR ] @@ -16,9 +16,10 @@ smbcontrol \- send messages to smbd or nmbd processes This tool is part of the Sambasuite. .PP \fBsmbcontrol\fR is a very small program, which -sends messages to an smbd(8)or -an nmbd(8)daemon running on the -system. +sends messages to an smbd(8), +an nmbd(8) +or a winbindd(8) +daemon running on the system. .SH "OPTIONS" .TP \fB-i\fR @@ -52,8 +53,9 @@ The close-share message-type sends a message to smbd which will then close the client connections to the named share. Note that this doesn't affect client connections to any other shares. This message-type takes an argument of the -share name for which client connections will be close, or the +share name for which client connections will be closed, or the "*" character which will close all currently open shares. +This may be useful if you made changes to the access controls on the share. This message can only be sent to smbd. The debug message-type allows @@ -76,7 +78,7 @@ parameter. The parameter can be "on" to turn on profile stats collection, "off" to turn off profile stats collection, "count" to enable only collection of count stats (time stats are disabled), and "flush" to zero the current profile stats. This can -be sent to any of the destinations. +be sent to any smbd or nmbd destinations. The debuglevel message-type sends a "request debug level" message. The current debug level setting @@ -86,18 +88,13 @@ sent to any of the destinations. The profilelevel message-type sends a "request profile level" message. The current profile level setting is returned by a "profilelevel" message. This can be sent -to any of the destinations. +to any smbd or nmbd destinations. The printer-notify message-type sends a message to smbd which in turn sends a printer notify message to any Windows NT clients connected to a printer. This message-type takes an argument of the printer name to send notify messages to. This message can only be sent to smbd. - -The close-share message-type sends a -message to smbd which forces smbd to close the share that was -specified as an argument. This may be useful if you made changes -to the access controls on the share. .TP \fBparameters\fR any parameters required for the message-type diff --git a/docs/manpages/smbd.8 b/docs/manpages/smbd.8 index f534a59bf3b..83483c88350 100644 --- a/docs/manpages/smbd.8 +++ b/docs/manpages/smbd.8 @@ -3,7 +3,7 @@ .\" .\" Please send any bug reports, improvements, comments, patches, .\" etc. to Steve Cheng . -.TH "SMBD" "8" "28 January 2002" "" "" +.TH "SMBD" "8" "08 May 2002" "" "" .SH NAME smbd \- server to provide SMB/CIFS services to clients .SH SYNOPSIS @@ -124,7 +124,9 @@ file will be created for informational and debug messages from the running server. The log file generated is never removed by the server although its size may be controlled by the max log size -option in the \fI smb.conf(5)\fRfile. +option in the \fI smb.conf(5)\fRfile. \fBBeware:\fR +If the directory specified does not exist, \fBsmbd\fR +will log to the default debug log location defined at compile time. The default log directory is specified at compile time. diff --git a/docs/manpages/smbmount.8 b/docs/manpages/smbmount.8 index 1cef431e47b..0d4a7fc8708 100644 --- a/docs/manpages/smbmount.8 +++ b/docs/manpages/smbmount.8 @@ -3,12 +3,12 @@ .\" .\" Please send any bug reports, improvements, comments, patches, .\" etc. to Steve Cheng . -.TH "SMBMOUNT" "8" "28 January 2002" "" "" +.TH "SMBMOUNT" "8" "08 May 2002" "" "" .SH NAME smbmount \- mount an smbfs filesystem .SH SYNOPSIS .sp -\fBsmbumount\fR \fBservice\fR \fBmount-point\fR [ \fB-o options\fR ] +\fBsmbmount\fR \fBservice\fR \fBmount-point\fR [ \fB-o options\fR ] .SH "DESCRIPTION" .PP \fBsmbmount\fR mounts a Linux SMB filesystem. It diff --git a/docs/manpages/smbsh.1 b/docs/manpages/smbsh.1 index 130df3582b0..774607c3a29 100644 --- a/docs/manpages/smbsh.1 +++ b/docs/manpages/smbsh.1 @@ -3,12 +3,12 @@ .\" .\" Please send any bug reports, improvements, comments, patches, .\" etc. to Steve Cheng . -.TH "SMBSH" "1" "28 January 2002" "" "" +.TH "SMBSH" "1" "08 May 2002" "" "" .SH NAME smbsh \- Allows access to Windows NT filesystem using UNIX commands .SH SYNOPSIS .sp -\fBsmbsh\fR +\fBsmbsh\fR [ \fB-W workgroup\fR ] [ \fB-U username\fR ] [ \fB-P prefix\fR ] [ \fB-R \fR ] [ \fB-d \fR ] [ \fB-l logfile\fR ] [ \fB-L libdir\fR ] .SH "DESCRIPTION" .PP This tool is part of the Sambasuite. @@ -17,6 +17,104 @@ This tool is part of the Sambasuite. using UNIX commands such as \fBls\fR, \fB egrep\fR, and \fBrcp\fR. You must use a shell that is dynamically linked in order for \fBsmbsh\fR to work correctly. +.SH "OPTIONS" +.TP +\fB-W WORKGROUP\fR +Override the default workgroup specified in the +workgroup parameter of the \fIsmb.conf\fR file +for this session. This may be needed to connect to some +servers. +.TP +\fB-U username[%pass]\fR +Sets the SMB username or username and password. +If this option is not specified, the user will be prompted for +both the username and the password. If %pass is not specified, +the user will be prompted for the password. +.TP +\fB-P prefix\fR +This option allows +the user to set the directory prefix for SMB access. The +default value if this option is not specified is +\fBsmb\fR. +.TP +\fB-R \fR +This option is used to determine what naming +services and in what order to resolve +host names to IP addresses. The option takes a space-separated +string of different name resolution options. + +The options are :"lmhosts", "host", "wins" and "bcast". +They cause names to be resolved as follows : +.RS +.TP 0.2i +\(bu +lmhosts : +Lookup an IP address in the Samba lmhosts file. If the +line in lmhosts has no name type attached to the +NetBIOS name +(see the lmhosts(5) +for details) then any name type matches for lookup. +.TP 0.2i +\(bu +host : +Do a standard host name to IP address resolution, using +the system \fI/etc/hosts\fR, NIS, or DNS +lookups. This method of name resolution is operating +system dependent, for instance on IRIX or Solaris this +may be controlled by the \fI/etc/nsswitch.conf +\fRfile). Note that this method is only used +if the NetBIOS name type being queried is the 0x20 +(server) name type, otherwise it is ignored. +.TP 0.2i +\(bu +wins : +Query a name with the IP address listed in the +\fIwins server\fR parameter. If no +WINS server has been specified this method will be +ignored. +.TP 0.2i +\(bu +bcast : +Do a broadcast on each of the known local interfaces +listed in the \fIinterfaces\fR +parameter. This is the least reliable of the name +resolution methods as it depends on the target host +being on a locally connected subnet. +.RE +.PP +If this parameter is not set then the name resolve order +defined in the \fIsmb.conf\fR file parameter +(name resolve order) will be used. +.PP +.PP +The default order is lmhosts, host, wins, bcast. Without +this parameter or any entry in the \fIname resolve order +\fRparameter of the \fIsmb.conf\fR +file, the name resolution methods will be attempted in this +order. +.PP +.TP +\fB-d \fR +debug level is an integer from 0 to 10. + +The default value if this parameter is not specified +is zero. + +The higher this value, the more detail will be logged +about the activities of \fBnmblookup\fR. At level +0, only critical errors and serious warnings will be logged. +.TP +\fB-l logfilename\fR +If specified causes all debug messages to be +written to the file specified by \fIlogfilename +\fR\&. If not specified then all messages will be +written to\fIstderr\fR. +.TP +\fB-L libdir\fR +This parameter specifies the location of the +shared libraries used by \fBsmbsh\fR. The default +value is specified at compile time. +.SH "EXAMPLES" .PP To use the \fBsmbsh\fR command, execute \fB smbsh\fR from the prompt and enter the username and password that authenticates you to the machine running the Windows NT diff --git a/docs/manpages/wbinfo.1 b/docs/manpages/wbinfo.1 index 9537af287b8..57aaf98b626 100644 --- a/docs/manpages/wbinfo.1 +++ b/docs/manpages/wbinfo.1 @@ -3,12 +3,12 @@ .\" .\" Please send any bug reports, improvements, comments, patches, .\" etc. to Steve Cheng . -.TH "WBINFO" "1" "28 January 2002" "" "" +.TH "WBINFO" "1" "08 May 2002" "" "" .SH NAME wbinfo \- Query information from winbind daemon .SH SYNOPSIS .sp -\fBwbinfo\fR [ \fB-u\fR ] [ \fB-g\fR ] [ \fB-n name\fR ] [ \fB-s sid\fR ] [ \fB-U uid\fR ] [ \fB-G gid\fR ] [ \fB-S sid\fR ] [ \fB-Y sid\fR ] [ \fB-t\fR ] [ \fB-m\fR ] [ \fB-a user%password\fR ] [ \fB-p\fR ] +\fBwbinfo\fR [ \fB-u\fR ] [ \fB-g\fR ] [ \fB-h name\fR ] [ \fB-i ip\fR ] [ \fB-n name\fR ] [ \fB-s sid\fR ] [ \fB-U uid\fR ] [ \fB-G gid\fR ] [ \fB-S sid\fR ] [ \fB-Y sid\fR ] [ \fB-t\fR ] [ \fB-m\fR ] [ \fB-r user\fR ] [ \fB-a user%password\fR ] [ \fB-A user%password\fR ] .SH "DESCRIPTION" .PP This tool is part of the Sambasuite. @@ -37,6 +37,18 @@ will also be listed. Note that this operation does not assign group ids to any groups that have not already been seen by \fBwinbindd(8)\fR. .TP +\fB-h name\fR +The \fI-h\fR option +queries \fBwinbindd(8)\fR to query the WINS +server for the IP address associated with the NetBIOS name +specified by the \fIname\fR parameter. +.TP +\fB-i ip\fR +The \fI-i\fR option +queries \fBwinbindd(8)\fR to send a node status +request to get the NetBIOS name associated with the IP address +specified by the \fIip\fR parameter. +.TP \fB-n name\fR The \fI-n\fR option queries \fBwinbindd(8)\fR for the SID @@ -83,13 +95,21 @@ Windows NT server \fBwinbindd(8)\fR contacts when resolving names. This list does not include the Windows NT domain the server is a Primary Domain Controller for. .TP +\fB-r username\fR +Try to obtain the list of UNIX group ids +to which the user belongs. This only works for users +defined on a Domain Controller. +.TP \fB-a username%password\fR Attempt to authenticate a user via winbindd. This checks both authenticaion methods and reports its results. .TP -\fB-p\fR -Attempt a simple 'ping' check that the winbindd -is indeed alive. +\fB-A username%password\fR +Store username and password used by winbindd +during session setup to a domain controller. This enables +winbindd to operate in a Windows 2000 domain with Restrict +Anonymous turned on (a.k.a. Permissions compatiable with +Windows 2000 servers only). .SH "EXIT STATUS" .PP The wbinfo program returns 0 if the operation diff --git a/docs/manpages/winbindd.8 b/docs/manpages/winbindd.8 index cca62f25e4e..ca0c87bd08c 100644 --- a/docs/manpages/winbindd.8 +++ b/docs/manpages/winbindd.8 @@ -3,7 +3,7 @@ .\" .\" Please send any bug reports, improvements, comments, patches, .\" etc. to Steve Cheng . -.TH "WINBINDD" "8" "28 January 2002" "" "" +.TH "WINBINDD" "8" "08 May 2002" "" "" .SH NAME winbindd \- Name Service Switch daemon for resolving names from NT servers .SH SYNOPSIS @@ -38,6 +38,12 @@ installed, this should always suceed. The following nsswitch databases are implemented by the winbindd service: .TP +\fBhosts\fR +User information traditionally stored in +the \fIhosts(5)\fR file and used by +\fBgethostbyname(3)\fR functions. Names are +resolved through the WINS server or by broadcast. +.TP \fBpasswd\fR User information traditionally stored in the \fIpasswd(5)\fR file and used by @@ -63,6 +69,12 @@ group: files winbind .sp .fi .PP +.PP +The following simple configuration in the +\fI/etc/nsswitch.conf\fR file can be used to initially +resolve hostnames from \fI/etc/hosts\fR and then from the +WINS server. +.PP .SH "OPTIONS" .TP \fB-d debuglevel\fR diff --git a/docs/textdocs/BROWSING.txt b/docs/textdocs/BROWSING.txt index ad12d4c7220..2ca41e5624e 100644 --- a/docs/textdocs/BROWSING.txt +++ b/docs/textdocs/BROWSING.txt @@ -7,10 +7,14 @@ Summary: This describes how to configure Samba for improved browsing. OVERVIEW: ========= + SMB networking provides a mechanism by which clients can access a list -of machines that are available within the network. This list is called -the browse list and is heavily used by all SMB clients. Configuration -of SMB browsing has been problematic for some Samba users, hence this +of machines in a network, a so-called "browse list". This list +contains machines that are ready to offer file and/or print services +to other machines within the network. Thus it does not include +machines which aren't currently able to do server tasks. The browse +list is heavily used by all SMB clients. Configuration of SMB +browsing has been problematic for some Samba users, hence this document. Browsing will NOT work if name resolution from NetBIOS names to IP @@ -59,9 +63,10 @@ browsing on another subnet. It is recommended that this option is only used for 'unusual' purposes: announcements over the internet, for example. See "remote announce" in the smb.conf man page. -If something doesn't work then hopefully the log.nmb file will -help you track down the problem. Try a debug level of 2 or 3 for -finding problems. +If something doesn't work then hopefully the log.nmb file will help +you track down the problem. Try a debug level of 2 or 3 for finding +problems. Also note that the current browse list usually gets stored +in text form in a file called browse.dat. Note that if it doesn't work for you, then you should still be able to type the server name as \\SERVER in filemanager then hit enter and diff --git a/docs/textdocs/Solaris-Winbind-HOWTO.txt b/docs/textdocs/Solaris-Winbind-HOWTO.txt new file mode 100644 index 00000000000..a81bacf4864 --- /dev/null +++ b/docs/textdocs/Solaris-Winbind-HOWTO.txt @@ -0,0 +1,361 @@ +!== +!== Solaris-Winbind-HOWTO.txt +!== +Contributors: Naag Mummaneni +Updated: May 2, 2002 +Status: Current + +Subject: Installing and Configuring Winbind on Solaris +============================================================================= + +Installation and Configuration of Winbind on Solaris. +----------------------------------------------------- + +This HOWTO describes how to get winbind services up and running to control +access and authenticate users on your Solaris box using the winbind services +which come with SAMBA 2.2.x latest CVS Checkout.Make sure you are using the +latest Samba 2.2.x cvs checkout as other versions come with a lots of bugs +regarding winbind .And even the Latest Samba Stable Release is also not an +exception to this. + +Introduction +------------ + +This HOWTO describes the procedures used to get winbind up and running on a +Solaris system. Winbind is capable of providing access and authentication +control for Windows Domain users through an NT or Win2K PDC for 'regular' +services, such as telnet and ftp, as well for SAMBA services. + +Why should I to this? + +This allows the SAMBA administrator to rely on the authentication mechanisms +on the NT/Win2K PDC for the authentication of domain members. NT/Win2K users +no longer need to have separate accounts on the SAMBA server. + +Who should be reading this document? + +This HOWTO is designed for system administrators. If you are implementing +SAMBA on a file server and wish to (fairly easily) integrate existing +NT/Win2K users from your PDC onto the SAMBA server, this HOWTO is for you. + +Requirements +------------ + +If you have a samba configuration file that you are currently using... BACK +IT UP! If your system already uses PAM, back up the /etc/pam.conf file ! If +you haven't already made a boot disk, MAKEONE NOW! Messing with the pam +configuration file can make it nearly impossible to log in to yourmachine. +That's why you want to be able to boot back into your machine in single user +mode and restore your /etc/pam.conf back to the original state they were in +if you get frustrated with the way things are going. ;-) Please refer to the +main SAMBA web page or, better yet, your closest SAMBA mirror site for +instructions on downloading the source code of Samba 2.2.x from the SAMBA +CVS repository. To allow Domain users the ability to access SAMBA shares and +files, as well as potentially other services provided by your SAMBA machine, +PAM (pluggable authentication modules) must be setup properly on your +machine. In order to compile the winbind modules, you should have at least +the pam libraries resident on your system. Solaris 7/8 has its pam modules +coming with the distribution itself. + +Testing Things Out +------------------ + +Before starting, it is probably best to kill off all the SAMBA related +daemons running on your server. Kill off all smbd, nmbd, and winbindd +processes that may be running. + + +Configure and compile SAMBA +--------------------------- + +The configuration and compilation of SAMBA is pretty straightforward. The +first three steps may not be necessary depending upon whether or not you +have previously built the Samba binaries. + +root# autoconf +root# make clean +root# rm config.cache +root# ./configure --with-winbind --with-pam +root# make +root# make install + +This will, by default, install SAMBA in /usr/local/samba. See the main SAMBA +documentation if you want to install SAMBA somewhere else. It will also +build the winbindd executable and libraries. + +Configure nsswitch.conf and the winbind libraries +------------------------------------------------- + +The libraries needed to run the winbindd daemon through nsswitch need to be +copied to their proper locations, so + +root# cp ../samba/source/nsswitch/libnss_winbind.so /usr/lib + +I also found it necessary to make the following symbolic links: + +root# ln -s /usr/lib/libnss_winbind.so /usr/lib/libnss_winbind.so.1 +root# ln -s /usr/lib/libnss_winbind.so /usr/lib/libnss_winbind.so.2 +root# ln -s /usr/lib/libnss_winbind.so /usr/lib/nss_winbind.so.1 +root# ln -s /usr/lib/libnss_winbind.so /usr/lib/nss_winbind.so.2 + +Now, as root you need to edit /etc/nsswitch.conf to allow user and group +entries to be visible from the winbindd daemon. My /etc/nsswitch.conf file +look like this after editing: + + passwd: files winbind + group: files winbind + + +Configure smb.conf +------------------ + +Several parameters are needed in the smb.conf file to control the behavior +of winbindd. Configure smb.conf These are described in more detail in the +winbindd(8) man page. My smb.conf file was modified to include the following +entries in the [global] section: + +[global] + <...> + # The previous documentation says to + # as the "winbind seperator " directive also but + # it is no longer supported. + + # use uids from 10000 to 20000 for domain users + winbind uid = 10000-20000 + + # use gids from 10000 to 20000 for domain groups + winbind gid = 10000-20000 + + # allow enumeration of winbind users and groups + winbind enum users = yes + winbind enum groups = yes + + # give winbind users a real shell (only needed if + # they have telnet access) + template homedir = /home/winnt/%D/%U + template shell = /bin/bash + + +Join the SAMBA server to the PDC domain +--------------------------------------- + +Enter the following command to make the SAMBA server join the PDC domain, +where DOMAIN is the name of your Windows domain and Administrator is a +domain user who has administrative privileges in the domain. + +root# /usr/local/samba/bin/smbpasswd -j DOMAIN -r PDC -U Administrator + +The proper response to the command should be: "Joined the domain DOMAIN" +where DOMAIN is your DOMAIN name. + +Start up the winbindd daemon and test it! + +Eventually, you will want to modify your smb startup script to automatically +invoke the winbindd daemon when the other parts of SAMBA start, but it is +possible to test out just the winbind portion first. To start up winbind +services, enter the following command as root: + +root# /usr/local/samba/bin/winbindd + +I'm always paranoid and like to make sure the daemon is really running... + +root# ps -ae | grep winbindd + +This command should produce output like this, if the daemon is running + + 3025 ? 00:00:00 winbindd + +Now... for the real test, try to get some information about the users on +your PDC + +root# /usr/local/samba/bin/wbinfo -u + +This should echo back a list of users on your Windows users on your PDC. For +example, I get the following response: + +CEO\Administrator +CEO\burdell +CEO\Guest +CEO\jt-ad +CEO\krbtgt +CEO\TsInternetUser + +root# /usr/local/samba/bin/wbinfo -g + +CEO\Domain Admins +CEO\Domain Users +CEO\Domain Guests +CEO\Domain Computers +CEO\Domain Controllers +CEO\Cert Publishers +CEO\Schema Admins +CEO\Enterprise Admins +CEO\Group Policy Creator Owners + +The function 'getent' can now be used to get unified lists of both local and +PDC users and groups. Try the following command: + +root# getent passwd + +You should get a list that looks like your /etc/passwd list followed by the domain users with their new +uids, gids, home directories and default shells. + +The same thing can be done for groups with the command + +root# getent group + +Fix the /etc/rc.d/init.d/samba.server startup files The winbindd daemon +needs to start up after the smbd and nmbd daemons are running. To accomplish +this task, you need to modify the /etc/init.d/samba.server script to add +commands to invoke this daemon in the proper sequence. My +/etc/init.d/samba.server file starts up smbd, nmbd, and winbindd from the +/usr/local/samba/bin directory directly. + +## +## samba.server +## + +if [ ! -d /usr/bin ] +then # /usr not mounted + exit +fi + +killproc() { # kill the named process(es) + pid=`/usr/bin/ps -e | + /usr/bin/grep -w $1 | + /usr/bin/sed -e 's/^ *//' -e 's/ .*//'` + [ "$pid" != "" ] && kill $pid +} + +# Start/stop processes required for samba server + +case "$1" in + +'start') +# +# Edit these lines to suit your installation (paths, workgroup, host) +# +echo Starting SMBD + /usr/local/samba/bin/smbd -D -s \ + /usr/local/samba/smb.conf + +echo Starting NMBD + /usr/local/samba/bin/nmbd -D -l \ + /usr/local/samba/var/log -s /usr/local/samba/smb.conf + +echo Starting Winbind Daemon + /usr/local/samba/bin/winbindd + ;; + +'stop') + killproc nmbd + killproc smbd + killproc winbindd + ;; + +*) + echo "Usage: /etc/init.d/samba.server { start | stop }" + ;; +esac + +If you restart the smbd, nmbd, and winbindd daemons at this point, you +should be able to connect to the samba server as a domain member just as if +you were a local user. + + +Configure Winbind and PAM +------------------------- + +If you have made it this far, you know that winbindd and samba are working +together. If you want to use winbind to provide authentication for other +services, keep reading. The pam configuration file need to be altered in +this step. (Did you remember to make backups of your original /etc/pam.conf +file? If not, do it now.) You will need a pam module to use winbindd with +these other services. This module will be compiled in the ../source/nsswitch +directory by default when we used ./configure --with-pam option. + +root# make nsswitch/pam_winbind.so + +from the ../source directory. The pam_winbind.so file should be copied to +the location of your other pam security modules. On my Solaris 8, this was +the /usr/lib/security directory. + +root# cp ../samba/source/nsswitch/pam_winbind.so /usr/lib/security + +The /etc/pam.conf need to be changed. I changed this file so that my Domain +users can logon both locally as well as telnet.The following are the changes +that I made.You can customize the pam.conf file as per your requirements,but +be sure of those changes because in the worst case it will leave your system +nearly impossible to boot. + +# +#ident "@(#)pam.conf 1.14 99/09/16 SMI" +# +# Copyright (c) 1996-1999, Sun Microsystems, Inc. +# All Rights Reserved. +# +# PAM configuration +# +# Authentication management +# +login auth required /usr/lib/security/pam_winbind.so +login auth required /usr/lib/security/$ISA/pam_unix.so.1 try_first_pass +login auth required /usr/lib/security/$ISA/pam_dial_auth.so.1 try_first_pass +# +rlogin auth sufficient /usr/lib/security/pam_winbind.so +rlogin auth sufficient /usr/lib/security/$ISA/pam_rhosts_auth.so.1 +rlogin auth required /usr/lib/security/$ISA/pam_unix.so.1 try_first_pass +# +dtlogin auth sufficient /usr/lib/security/pam_winbind.so +dtlogin auth required /usr/lib/security/$ISA/pam_unix.so.1 try_first_pass +# +rsh auth required /usr/lib/security/$ISA/pam_rhosts_auth.so.1 +other auth sufficient /usr/lib/security/pam_winbind.so +other auth required /usr/lib/security/$ISA/pam_unix.so.1 try_first_pass +# +# Account management +# +login account sufficient /usr/lib/security/pam_winbind.so +login account requisite /usr/lib/security/$ISA/pam_roles.so.1 +login account required /usr/lib/security/$ISA/pam_unix.so.1 +# +dtlogin account sufficient /usr/lib/security/pam_winbind.so +dtlogin account requisite /usr/lib/security/$ISA/pam_roles.so.1 +dtlogin account required /usr/lib/security/$ISA/pam_unix.so.1 +# +other account sufficient /usr/lib/security/pam_winbind.so +other account requisite /usr/lib/security/$ISA/pam_roles.so.1 +other account required /usr/lib/security/$ISA/pam_unix.so.1 +# +# Session management +# +other session required /usr/lib/security/$ISA/pam_unix.so.1 +# +# Password management +# +#other password sufficient /usr/lib/security/pam_winbind.so +other password required /usr/lib/security/$ISA/pam_unix.so.1 +dtsession auth required /usr/lib/security/$ISA/pam_unix.so.1 +# +# Support for Kerberos V5 authentication (uncomment to use Kerberos) +# +#rlogin auth optional /usr/lib/security/$ISA/pam_krb5.so.1 try_first_pass +#login auth optional /usr/lib/security/$ISA/pam_krb5.so.1 try_first_pass +#dtlogin auth optional /usr/lib/security/$ISA/pam_krb5.so.1 try_first_pass +#other auth optional /usr/lib/security/$ISA/pam_krb5.so.1 try_first_pass +#dtlogin account optional /usr/lib/security/$ISA/pam_krb5.so.1 +#other account optional /usr/lib/security/$ISA/pam_krb5.so.1 +#other session optional /usr/lib/security/$ISA/pam_krb5.so.1 +#other password optional /usr/lib/security/$ISA/pam_krb5.so.1 try_first_pass + +I also added a try_first_pass line after the winbind.so line to get rid of +annoying double prompts for passwords. + +Now restart your Samba & try connecting through your application that you +configured in the pam.conf. + + + +!== +!== end of Solaris-Winbind-HOWTO.txt +!== diff --git a/examples/LDAP/samba-schema-netscapeds4.x b/examples/LDAP/samba-schema-netscapeds4.x new file mode 100644 index 00000000000..c5a11b8b66c --- /dev/null +++ b/examples/LDAP/samba-schema-netscapeds4.x @@ -0,0 +1,54 @@ +# +# LDAP Schema file for SAMBA attribute storage +# This file is suitable for usage with Netscape Directory Server 4.1x +# Adapted by Scott Lawson with help from Ron Creamer +# + +attribute lmPassword 1.3.6.1.4.1.7165.2.1.1 cis single +attribute ntPassword 1.3.6.1.4.1.7165.2.1.2 cis single +attribute acctFlags 1.3.6.1.4.1.7165.2.1.4 cis single +attribute pwdLastSet 1.3.6.1.4.1.7165.2.1.3 int single +attribute logonTime 1.3.6.1.4.1.7165.2.1.5 int single +attribute logoffTime 1.3.6.1.4.1.7165.2.1.6 int single +attribute kickoffTime 1.3.6.1.4.1.7165.2.1.7 int single +attribute pwdCanChange 1.3.6.1.4.1.7165.2.1.8 int single +attribute pwdMustChange 1.3.6.1.4.1.7165.2.1.9 int single +attribute homedrive 1.3.6.1.4.1.7165.2.1.10 cis single +attribute scriptPath 1.3.6.1.4.1.7165.2.1.11 cis single +attribute profilePath 1.3.6.1.4.1.7165.2.1.12 cis single +attribute userWorkstations 1.3.6.1.4.1.7165.2.1.13 cis single +attribute rid 1.3.6.1.4.1.7165.2.1.14 int single +attribute primaryGroupID 1.3.6.1.4.1.7165.2.1.15 int single +attribute smbHome 1.3.6.1.4.1.7165.2.1.17 cis single +attribute domain 1.3.6.1.4.1.7165.2.1.18 cis single + +objectclass sambaAccount + oid + 1.3.1.5.1.4.1.7165.2.2.2 + superior + top + requires + objectClass, + uid, + rid + allows + cn, + lmPassword, + ntPassword, + pwdLastSet, + logonTime, + logoffTime, + KickoffTime, + pwdCanChange, + pwdMustChange, + acctFlags, + displayName, + smbHome, + homeDrive, + scriptPath, + profilePath, + description, + userWorkstations, + primaryGroupID, + domain + diff --git a/examples/LDAP/samba-schema-netscapeds5.x b/examples/LDAP/samba-schema-netscapeds5.x new file mode 100644 index 00000000000..0abc9d82e27 --- /dev/null +++ b/examples/LDAP/samba-schema-netscapeds5.x @@ -0,0 +1,74 @@ +## +## submitted by Martin.Dehn@comparex.de +## +## Experiement sambaAccount schema file Netscape DS 5.0 +## +## INSTALL-DIRECTORY/slapd-your_name/config/schema/samba-schema-netscapeds5.ldif +## +dn: cn=schema +objectClass: top +objectClass: ldapSubentry +objectClass: subschema +cn: schema +aci: (target="ldap:///cn=schema")(targetattr !="aci")(version 3.0;acl "anonymo + us, no acis"; allow (read, search, compare) userdn = "ldap:///anyone";) +aci: (targetattr = "*")(version 3.0; acl "Configuration Administrator"; allow + (all) userdn = "ldap:///uid=admin,ou=Administrators, ou=TopologyManagement, + o=NetscapeRoot";) +aci: (targetattr = "*")(version 3.0; acl "Local Directory Administrators Group + "; allow (all) groupdn = "ldap:///cn=Directory Administrators, dc=samba,dc=org";) +aci: (targetattr = "*")(version 3.0; acl "SIE Group"; allow (all)groupdn = "ld + ap:///cn=slapd-sambaldap, cn=iPlanet Directory Server, cn=Server Group, cn=iPlanetDirectory.samba.org, ou=samba.org, o=NetscapeRoot";) +modifiersName: cn=directory manager +modifyTimestamp: 20020322124844Z +objectClasses: ( 1.3.1.5.1.4.1.7165.2.2.2 NAME 'sambaAccount' SUP top STRUCTUR + AL MAY ( acctFlags $ domain $ homeDrive $ kickoffTime $ lmPassword $ logofft + ime $ logonTime $ ntPassword $ primaryGroupID $ profilePath $ pwdCanChange $ + pwdLastSet $ pwdMustChange $ rid $ scriptPath $ smbHome $ userWorkstations + ) X-ORIGIN 'user defined' ) +attributeTypes: ( 1.3.6.1.4.1.7165.2.1.11 NAME 'scriptPath' DESC 'NT script pa + th' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE X-ORIGIN 'user defined + ' ) +attributeTypes: ( 1.3.6.1.4.1.7165.2.1.5 NAME 'logonTime' DESC 'NT logon time' + SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE X-ORIGIN 'user defined' ) +attributeTypes: ( 1.3.6.1.4.1.7165.2.1.12 NAME 'profilePath' DESC 'NT profile + path' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE X-ORIGIN 'user defin + ed' ) +attributeTypes: ( 1.3.6.1.4.1.7165.2.1.8 NAME 'pwdCanChange' DESC 'NT passwd c + an change' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE X-ORIGIN 'user + defined' ) +attributeTypes: ( 1.3.6.1.4.1.7165.2.1.17 NAME 'smbHome' DESC 'smbHome' SYNTAX + 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE X-ORIGIN 'user defined' ) +attributeTypes: ( 1.3.6.1.4.1.7165.2.1.3 NAME 'pwdLastSet' SYNTAX 1.3.6.1.4.1 + .1466.115.121.1.27 SINGLE-VALUE X-ORIGIN 'user defined' ) +attributeTypes: ( 1.3.6.1.4.1.7165.2.1.18 NAME 'domain' DESC 'Windows NT domai + n Samba' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE X-ORIGIN 'user de + fined' ) +attributeTypes: ( 1.3.6.1.4.1.7165.2.1.10 NAME 'homeDrive' DESC 'NT home drive + ' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE X-ORIGIN 'user defined' + ) +attributeTypes: ( 1.3.6.1.4.1.7165.2.1.6 NAME 'logofftime' DESC 'logoff Time' + SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE X-ORIGIN 'user defined' ) +attributeTypes: ( 1.3.6.1.4.1.7165.2.1.15 NAME 'primaryGroupID' DESC 'NT Group + RID' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE X-ORIGIN 'user defin + ed' ) +attributeTypes: ( 1.3.6.1.4.1.7165.2.1.1 NAME 'lmPassword' DESC 'LanManager Pa + sswd' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE X-ORIGIN 'user defin + ed' ) +attributeTypes: ( 1.3.6.1.4.1.7165.2.1.9 NAME 'pwdMustChange' DESC 'NT pwdmust + chnage' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE X-ORIGIN 'user def + ined' ) +attributeTypes: ( 1.3.6.1.4.1.7165.2.1.4 NAME 'acctFlags' DESC 'Account Flags' + SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE X-ORIGIN 'user defined' ) +attributeTypes: ( 1.3.6.1.4.1.7165.2.1.13 NAME 'userWorkstations' DESC 'userWo + rkstations' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE X-ORIGIN 'user + defined' ) +attributeTypes: ( 1.3.6.1.4.1.7165.2.1.7 NAME 'kickoffTime' DESC 'NT kickoff T + ime' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE X-ORIGIN 'user define + d' ) +attributeTypes: ( 1.3.6.1.4.1.7165.2.1.14 NAME 'rid' DESC 'rid' SYNTAX 1.3.6.1 + .4.1.1466.115.121.1.27 SINGLE-VALUE X-ORIGIN 'user defined' ) +attributeTypes: ( 1.3.6.1.4.1.7165.2.1.2 NAME 'ntPassword' DESC 'NT Passwd' SY + NTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE X-ORIGIN 'user defined' ) +nsSchemaCSN: 3c9b282c000000000000 + diff --git a/examples/LDAP/samba-schema.IBMSecureWay b/examples/LDAP/samba-schema.IBMSecureWay new file mode 100644 index 00000000000..1fca4a749a6 --- /dev/null +++ b/examples/LDAP/samba-schema.IBMSecureWay @@ -0,0 +1,43 @@ +## +## Submitted by Dirk Kastens +## +## I translated the samba.schema to be used with IBM +## SecureWay directoy server 3.2.2. You have to load +## it in your slapd32.conf with: +## +## dn: cn=IBM SecureWay, cn=Schemas, cn=Configuration +## cn: IBM SecureWay +## ibm-slapdIncludeSchema: /etc/lapschema/samba.schema +## +objectClasses { +( 1.3.1.5.1.4.1.7165.2.2.2 NAME 'sambaAccount' DESC 'Samba Account' SUP top MUST uid $ rid MAY ( acctFlags $ cn $ description $ displayName $ homeDrive $ kickoffTime $ lmPassword $ logoffTime $ logonTime $ ntPassword $ primaryGroupID $ profilePath $ pwdCanChange $ pwdLastSet $ pwdMustChange $ scriptPath $ smbHome $ userWorkstations ) ) +} + +attributeTypes { +( 1.3.6.1.4.1.7165.2.1.1 NAME 'lmPassword' DESC 'LanManager Passwd' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{32} SINGLE-VALUE ) +( 1.3.6.1.4.1.7165.2.1.10 NAME 'homeDrive' DESC 'NT homeDrive' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{4} SINGLE-VALUE ) +( 1.3.6.1.4.1.7165.2.1.11 NAME 'scriptPath' DESC 'NT scriptPath' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{255} SINGLE-VALUE ) +( 1.3.6.1.4.1.7165.2.1.12 NAME 'profilePath' DESC 'NT profilePath' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{255} SINGLE-VALUE ) +( 1.3.6.1.4.1.7165.2.1.13 NAME 'userWorkstations' DESC 'userWorkstations' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{255} SINGLE-VALUE ) +( 1.3.6.1.4.1.7165.2.1.14 NAME 'rid' DESC 'NT rid' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{255} SINGLE-VALUE ) +( 1.3.6.1.4.1.7165.2.1.15 NAME 'primaryGroupID' DESC 'NT Group RID' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{255} SINGLE-VALUE ) +( 1.3.6.1.4.1.7165.2.1.17 NAME 'smbHome' DESC 'smbHome' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{128} ) +( 1.3.6.1.4.1.7165.2.1.2 NAME 'ntPassword' DESC 'NT Passwd' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{32} SINGLE-VALUE ) +( 1.3.6.1.4.1.7165.2.1.3 NAME 'pwdLastSet' DESC 'NT pwdLastSet' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{32} SINGLE-VALUE ) +( 1.3.6.1.4.1.7165.2.1.4 NAME 'acctFlags' DESC 'Account Flags' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{16} SINGLE-VALUE ) +( 1.3.6.1.4.1.7165.2.1.5 NAME 'logonTime' DESC 'NT logonTime' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{32} SINGLE-VALUE ) +( 1.3.6.1.4.1.7165.2.1.6 NAME 'logoffTime' DESC 'NT logoffTime' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{32} SINGLE-VALUE ) +( 1.3.6.1.4.1.7165.2.1.7 NAME 'kickoffTime' DESC 'NT kickoffTime' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{32} SINGLE-VALUE ) +( 1.3.6.1.4.1.7165.2.1.8 NAME 'pwdCanChange' DESC 'NT pwdCanChange' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{32} SINGLE-VALUE ) +( 1.3.6.1.4.1.7165.2.1.9 NAME 'pwdMustChange' DESC 'NT pwdMustChange' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{32} SINGLE-VALUE ) +} + +IBMattributeTypes { +} + +ldapSyntaxes { +} + +matchingRules { +} + diff --git a/examples/README b/examples/README index 3e11ed4ad82..22226067140 100644 --- a/examples/README +++ b/examples/README @@ -1,11 +1,11 @@ -Copyright(C) Samba-Team 1993-1997 +Copyright(C) Samba-Team 1993-2001 -This directory contains example samba extensions, example config files and -related material for Samba. +This directory contains example config files and related material for +Samba. At a minimum please refer to the smb.conf.default file for current information regarding global and share parameter settings. -Send additions to: samba-bugs@samba.org +Send additions to: samba@samba.org diff --git a/examples/smb.conf.default b/examples/smb.conf.default index f0c86cc6eed..417417d256f 100644 --- a/examples/smb.conf.default +++ b/examples/smb.conf.default @@ -58,9 +58,17 @@ # Security mode. Most people will want user level security. See # security_level.txt for details. security = user + # Use password server option only with security = server +# The argument list may include: +# password server = My_PDC_Name [My_BDC_Name] [My_Next_BDC_Name] +# or to auto-locate the domain controller/s +# password server = * ; password server = +# Note: Do NOT use the now deprecated option of "domain controller" +# This option is no longer implemented. + # You may wish to use password encryption. Please read # ENCRYPTION.txt, Win95.txt and WinNT.txt in the Samba documentation. # Do not enable this option unless you have read those documents @@ -102,10 +110,6 @@ # and gives it a slightly higher chance of winning the election ; preferred master = yes -# Use only if you have an NT server on your network that has been -# configured at install time to be a primary domain controller. -; domain controller = - # Enable this if you want Samba to be a domain logon server for # Windows95 workstations. ; domain logons = yes diff --git a/packaging/RedHat/samba.pamd b/packaging/RedHat/samba.pamd index 1b4a93fb19e..bf7a5b392ca 100644 --- a/packaging/RedHat/samba.pamd +++ b/packaging/RedHat/samba.pamd @@ -1,4 +1,4 @@ -auth required /lib/security/pam_pwdb.so nullok shadow +auth required /lib/security/pam_pwdb.so nullok account required /lib/security/pam_pwdb.so session required /lib/security/pam_pwdb.so -password required /lib/security/pam_pwdb.so +password required /lib/security/pam_pwdb.so # shadow md5 nullok audit diff --git a/packaging/RedHat/samba2.spec.tmpl b/packaging/RedHat/samba2.spec.tmpl index c99b9123825..0766653c234 100644 --- a/packaging/RedHat/samba2.spec.tmpl +++ b/packaging/RedHat/samba2.spec.tmpl @@ -8,6 +8,7 @@ Source: ftp://samba.org/pub/samba/samba-%{version}.tar.gz Packager: John H Terpstra [Samba-Team] Requires: pam >= 0.72 kernel >= 2.2.1 glibc >= 2.1.2 Prereq: chkconfig fileutils +Provides: samba = %{version}, samba-common = %{version}, samba-client = %{version}, samba-swat = %{version} BuildRoot: /var/tmp/samba Prefix: /usr @@ -43,9 +44,16 @@ for Shadow passwords and quotas. Do NOT recompile with the SHADOW_PWD option enabled %changelog +* Mon May 6 2002 Gerald Carter + - moved findsmb to a standard component in samba's + "make install". Removed from specfile. + +* Sun Oct 14 2001 Andrew Bartlett + - Set SBINDIR for codepage/manpage install, cope with + broken Makefile + * Mon Aug 1 2001 Tim Potter - Install winbind daemon, client programs, nss and pam libraries - - Removed codepage stuff so spec file works with current HEAD branch * Sat Mar 31 2001 Andrew Bartlett - Changed prefix/share/man for _mandir/share/man @@ -158,11 +166,11 @@ CFLAGS="$RPM_OPT_FLAGS $EXTRA" ./configure \ --with-privatedir=/etc/samba \ --with-fhs \ --with-quotas \ + --with-msdfs \ --with-smbmount \ --with-pam \ --with-syslog \ --with-utmp \ - --with-netatalk \ --with-sambabook=%{prefix}/share/swat/using_samba \ --with-swatdir=%{prefix}/share/swat make -j${NUMCPU} proto @@ -182,8 +190,8 @@ mkdir -p $RPM_BUILD_ROOT%{prefix}/{bin,sbin} mkdir -p $RPM_BUILD_ROOT%{prefix}/share/swat/{images,help,include,using_samba} mkdir -p $RPM_BUILD_ROOT%{prefix}/share/swat/using_samba/{figs,gifs} mkdir -p $RPM_BUILD_ROOTMANDIR_MACRO -mkdir -p $RPM_BUILD_ROOT/var/lock/samba -mkdir -p $RPM_BUILD_ROOT/var/log/samba +mkdir -p $RPM_BUILD_ROOT/var/cache/samba +mkdir -p $RPM_BUILD_ROOT/var/{log,run}/samba mkdir -p $RPM_BUILD_ROOT/var/spool/samba mkdir -p $RPM_BUILD_ROOT/lib/security @@ -211,19 +219,21 @@ ln -sf %{prefix}/sbin/smbmount $RPM_BUILD_ROOT/sbin/mount.smb # This allows us to get away without duplicating code that # sombody else can maintain for us. cd source -make LIBDIR=$RPM_BUILD_ROOT/etc/samba \ +make BASEDIR=$RPM_BUILD_ROOT/usr \ + LIBDIR=$RPM_BUILD_ROOT/etc/samba \ + SBINDIR=$RPM_BUILD_ROOT%{prefix}/sbin \ BINDIR=$RPM_BUILD_ROOT%{prefix}/bin \ MANDIR=$RPM_BUILD_ROOTMANDIR_MACRO \ SWATDIR=$RPM_BUILD_ROOT/usr/share/swat \ SAMBABOOK=$RPM_BUILD_ROOT/usr/share/swat/using_samba \ - installman installswat + installman installcp installswat cd .. # Install the nsswitch library extension file install -m755 source/nsswitch/libnss_wins.so $RPM_BUILD_ROOT/lib # Make link for wins resolver -( cd $RPM_BUILD_ROOT/lib; ln -s libnss_wins.so libnss_wins.so.2; ) +( cd $RPM_BUILD_ROOT/lib; ln -sf libnss_wins.so libnss_wins.so.2; ) # Install winbind shared libraries install -m755 source/nsswitch/libnss_winbind.so $RPM_BUILD_ROOT/lib @@ -246,7 +256,6 @@ done # Install the miscellany install -m644 swat/README $RPM_BUILD_ROOT%{prefix}/share/swat install -m755 packaging/RedHat/smbprint $RPM_BUILD_ROOT%{prefix}/bin -install -m755 packaging/RedHat/findsmb $RPM_BUILD_ROOT%{prefix}/bin install -m755 packaging/RedHat/smb.init $RPM_BUILD_ROOT/etc/rc.d/init.d/smb install -m755 packaging/RedHat/smb.init $RPM_BUILD_ROOT%{prefix}/sbin/samba install -m644 packaging/RedHat/samba.log $RPM_BUILD_ROOT/etc/logrotate.d/samba @@ -265,35 +274,74 @@ rm -rf $RPM_BUILD_ROOT /sbin/chkconfig smb off echo "Looking for old /etc/smb.conf..." -if [ -f /etc/smb.conf ]; then +if [ -f /etc/smb.conf -a ! -f /etc/samba/smb.conf ]; then echo "Moving old /etc/smb.conf to /etc/samba/smb.conf" mv /etc/smb.conf /etc/samba/smb.conf fi echo "Looking for old /etc/smbusers..." -if [ -f /etc/smbusers ]; then +if [ -f /etc/smbusers -a ! -f /etc/samba/smbusers ]; then echo "Moving old /etc/smbusers to /etc/samba/smbusers" mv /etc/smbusers /etc/samba/smbusers fi echo "Looking for old /etc/lmhosts..." -if [ -f /etc/lmhosts ]; then +if [ -f /etc/lmhosts -a ! -f /etc/samba/lmhosts ]; then echo "Moving old /etc/lmhosts to /etc/samba/lmhosts" mv /etc/lmhosts /etc/samba/lmhosts fi echo "Looking for old /etc/MACHINE.SID..." -if [ -f /etc/MACHINE.SID ]; then +if [ -f /etc/MACHINE.SID -a ! -f /etc/samba/MACHINE.SID ]; then echo "Moving old /etc/MACHINE.SID to /etc/samba/MACHINE.SID" mv /etc/MACHINE.SID /etc/samba/MACHINE.SID fi echo "Looking for old /etc/smbpasswd..." -if [ -f /etc/smbpasswd ]; then +if [ -f /etc/smbpasswd -a ! -f /etc/samba/smbpasswd ]; then echo "Moving old /etc/smbpasswd to /etc/samba/smbpasswd" mv /etc/smbpasswd /etc/samba/smbpasswd fi +# +# For 2.2.1 we move the tdb files from /var/lock/samba to /var/cache/samba +# to preserve across reboots. +# +echo "Moving tdb files in /var/lock/samba/*.tdb to /var/cache/samba/*.tdb" +for i in /var/lock/samba/*.tdb +do +if [ -f $i ]; then + newname=`echo $i | sed -e's|var\/lock\/samba|var\/cache\/samba|'` + echo "Moving $i to $newname" + mv $i $newname +fi +done + +# Remove the transient tdb files. +if [ -e /var/cache/samba/brlock.tdb ]; then + rm -f /var/cache/samba/brlock.tdb +fi + +if [ -e /var/cache/samba/unexpected.tdb ]; then + rm -f /var/cache/samba/unexpected.tdb +fi + +if [ -e /var/cache/samba/connections.tdb ]; then + rm -f /var/cache/samba/connections.tdb +fi + +if [ -e /var/cache/samba/locking.tdb ]; then + rm -f /var/cache/samba/locking.tdb +fi + +if [ -e /var/cache/samba/messages.tdb ]; then + rm -f /var/cache/samba/messages.tdb +fi + +if [ -d /var/lock/samba ]; then + rm -rf /var/lock/samba +fi + # Add swat entry to /etc/services if not already there. if !( grep ^[:space:]*swat /etc/services > /dev/null ) then echo 'swat 901/tcp # Add swat service used via inetd' >> /etc/services @@ -309,7 +357,7 @@ fi # Add swat entry to xinetd.d if needed. if [ -d $RPM_BUILD_ROOT/etc/xinetd.d -a ! -f /etc/xinetd.d/swat ]; then - mv /etc/samba/samba.xinetd /etc/xinetd.d/swat + mv /etc/samba/samba.xinetd /etc/xinetd.d/swat else rm -f /etc/samba/samba.xinetd fi @@ -325,39 +373,41 @@ fi # Create winbind nss client symlink -ln -s /lib/libnss_winbind.so /lib/libnss_winbind.so.2 +if [ -e /lib/libnss_winbind.so ]; then + ln -sf /lib/libnss_winbind.so /lib/libnss_winbind.so.2 +fi %preun if [ $1 = 0 ] ; then - /sbin/chkconfig --del smb + /sbin/chkconfig --del smb - # We want to remove the browse.dat and wins.dat files so they can not interfer with a new version of samba! - if [ -e /var/lock/samba/browse.dat ]; then - rm -f /var/lock/samba/browse.dat - fi - if [ -e /var/lock/samba/wins.dat ]; then - rm -f /var/lock/samba/wins.dat - fi + # We want to remove the browse.dat and wins.dat files so they can not interfer with a new version of samba! + if [ -e /var/cache/samba/browse.dat ]; then + rm -f /var/cache/samba/browse.dat + fi + if [ -e /var/cache/samba/wins.dat ]; then + rm -f /var/cache/samba/wins.dat + fi # Remove the transient tdb files. - if [ -e /var/lock/samba/brlock.tdb ]; then - rm -f /var/lock/samba/brlock.tdb + if [ -e /var/cache/samba/brlock.tdb ]; then + rm -f /var/cache/samba/brlock.tdb fi - if [ -e /var/lock/samba/unexpected.tdb ]; then - rm -f /var/lock/samba/unexpected.tdb + if [ -e /var/cache/samba/unexpected.tdb ]; then + rm -f /var/cache/samba/unexpected.tdb fi - if [ -e /var/lock/samba/connections.tdb ]; then - rm -f /var/lock/samba/connections.tdb + if [ -e /var/cache/samba/connections.tdb ]; then + rm -f /var/cache/samba/connections.tdb fi - if [ -e /var/lock/samba/locking.tdb ]; then - rm -f /var/lock/samba/locking.tdb + if [ -e /var/cache/samba/locking.tdb ]; then + rm -f /var/cache/samba/locking.tdb fi - if [ -e /var/lock/samba/messages.tdb ]; then - rm -f /var/lock/samba/messages.tdb + if [ -e /var/cache/samba/messages.tdb ]; then + rm -f /var/cache/samba/messages.tdb fi # Remove winbind nss client symlink @@ -376,6 +426,9 @@ if [ $1 = 0 ] ; then if [ -e /var/log/samba ]; then rm -rf /var/log/samba fi + if [ -e /var/cache/samba ]; then + rm -rf /var/cache/samba + fi # Remove swat entries from /etc/inetd.conf and /etc/services cd /etc @@ -403,56 +456,61 @@ if [ $0 != 0 ]; then fi %files +%defattr(-,root,root) %doc README COPYING Manifest Read-Manifest-Now %doc WHATSNEW.txt Roadmap %doc docs %doc swat/README %doc examples -%attr(-,root,root) %{prefix}/sbin/smbd -%attr(-,root,root) %{prefix}/sbin/nmbd -%attr(-,root,root) %{prefix}/sbin/swat -%attr(-,root,root) %{prefix}/sbin/smbmnt -%attr(-,root,root) %{prefix}/sbin/smbmount -%attr(-,root,root) %{prefix}/sbin/smbumount -%attr(-,root,root) %{prefix}/sbin/winbindd -%attr(-,root,root) /sbin/mount.smbfs -%attr(-,root,root) /sbin/mount.smb -%attr(-,root,root) %{prefix}/bin/mksmbpasswd.sh -%attr(-,root,root) %{prefix}/bin/smbclient -%attr(-,root,root) %{prefix}/bin/smbspool -%attr(-,root,root) %{prefix}/bin/rpcclient -%attr(-,root,root) %{prefix}/bin/testparm -%attr(-,root,root) %{prefix}/bin/testprns -%attr(-,root,root) %{prefix}/bin/findsmb -%attr(-,root,root) %{prefix}/bin/smbstatus -%attr(-,root,root) %{prefix}/bin/nmblookup -%attr(-,root,root) %{prefix}/bin/make_printerdef -%attr(-,root,root) %{prefix}/bin/smbpasswd -%attr(-,root,root) %{prefix}/bin/smbtar -%attr(-,root,root) %{prefix}/bin/smbprint -%attr(-,root,root) %{prefix}/bin/smbcontrol -%attr(-,root,root) %{prefix}/bin/smbcacls -%attr(-,root,root) %{prefix}/bin/wbinfo +%{prefix}/sbin/smbd +%{prefix}/sbin/nmbd +%{prefix}/sbin/swat +%{prefix}/sbin/smbmnt +%{prefix}/sbin/smbmount +%{prefix}/sbin/smbumount +%{prefix}/sbin/winbindd +/sbin/mount.smbfs +/sbin/mount.smb +%{prefix}/bin/mksmbpasswd.sh +%{prefix}/bin/smbclient +%{prefix}/bin/smbspool +%{prefix}/bin/rpcclient +%{prefix}/bin/testparm +%{prefix}/bin/testprns +%{prefix}/bin/findsmb +%{prefix}/bin/smbstatus +%{prefix}/bin/nmblookup +%{prefix}/bin/make_smbcodepage +%{prefix}/bin/make_unicodemap +%{prefix}/bin/make_printerdef +%{prefix}/bin/smbpasswd +%{prefix}/bin/smbtar +%{prefix}/bin/smbprint +%{prefix}/bin/smbcontrol +%{prefix}/bin/smbcacls +%{prefix}/bin/wbinfo %attr(755,root,root) /lib/libnss_wins.s* -%attr(-,root,root) %{prefix}/share/swat/help/* -%attr(-,root,root) %{prefix}/share/swat/images/* -%attr(-,root,root) %{prefix}/share/swat/include/header.html -%attr(-,root,root) %{prefix}/share/swat/include/footer.html -%attr(-,root,root) %{prefix}/share/swat/using_samba/* -%attr(-,root,root) %config(noreplace) /etc/samba/lmhosts -%attr(-,root,root) %config(noreplace) /etc/samba/smb.conf -%attr(-,root,root) %config(noreplace) /etc/samba/smbusers -%attr(-,root,root) /etc/samba/samba.stack -%attr(-,root,root) /etc/samba/samba.xinetd -%attr(-,root,root) /etc/rc.d/init.d/smb -%attr(-,root,root) /etc/logrotate.d/samba -%attr(-,root,root) %config(noreplace) /etc/pam.d/samba -%attr(-,root,root) MANDIR_MACRO/man1/* -%attr(-,root,root) MANDIR_MACRO/man5/* -%attr(-,root,root) MANDIR_MACRO/man7/* -%attr(-,root,root) MANDIR_MACRO/man8/* -%attr(755,root,root) %dir /var/lock/samba -%attr(-,root,root) %dir /var/log/samba +%{prefix}/share/swat/help/* +%{prefix}/share/swat/images/* +%{prefix}/share/swat/include/header.html +%{prefix}/share/swat/include/footer.html +%{prefix}/share/swat/using_samba/* +%config(noreplace) /etc/samba/lmhosts +%config(noreplace) /etc/samba/smb.conf +%config(noreplace) /etc/samba/smbusers +/etc/samba/samba.stack +/etc/samba/samba.xinetd +/etc/rc.d/init.d/smb +/etc/logrotate.d/samba +%config(noreplace) /etc/pam.d/samba +MANDIR_MACRO/man1/* +MANDIR_MACRO/man5/* +MANDIR_MACRO/man7/* +MANDIR_MACRO/man8/* +%dir /etc/codepages/* +%attr(755,root,root) %dir /var/cache/samba +%dir /var/log/samba +%dir /var/run/samba %attr(1777,root,root) %dir /var/spool/samba %attr(-,root,root) /lib/libnss_winbind.so %attr(-,root,root) /lib/security/pam_winbind.so diff --git a/packaging/RedHat/smb.init b/packaging/RedHat/smb.init index 260439281a3..c43c9a0094b 100755 --- a/packaging/RedHat/smb.init +++ b/packaging/RedHat/smb.init @@ -13,8 +13,10 @@ # Check that networking is up. [ ${NETWORKING} = "no" ] && exit 0 +CONFIG=/etc/samba/smb.conf + # Check that smb.conf exists. -[ -f /etc/samba/smb.conf ] || exit 0 +[ -f $CONFIG ] || exit 0 # See how we were called. case "$1" in @@ -22,6 +24,9 @@ case "$1" in echo -n "Starting SMB services: " daemon smbd -D daemon nmbd -D + if [ "`grep -i 'winbind uid' /etc/samba/smb.conf | egrep -v [\#\;]`" ]; then + daemon winbindd + fi echo touch /var/lock/subsys/smb ;; @@ -29,12 +34,16 @@ case "$1" in echo -n "Shutting down SMB services: " killproc smbd killproc nmbd + if [ "`ps -ef | grep winbind | grep -v grep`" ]; then + killproc winbindd + fi rm -f /var/lock/subsys/smb echo "" ;; status) status smbd status nmbd + status winbindd ;; restart) echo -n "Restarting SMB services: " -- 2.34.1