smb.conf: Add dsdb group change notification parameter
authorGary Lockyer <gary@catalyst.net.nz>
Sun, 22 Apr 2018 21:00:54 +0000 (09:00 +1200)
committerAndrew Bartlett <abartlet@samba.org>
Wed, 16 May 2018 02:07:16 +0000 (04:07 +0200)
Signed-off-by: Gary Lockyer <gary@catalyst.net.nz>
Reviewed-by: Andrew Bartlett <abartlet@samba.org>
docs-xml/smbdotconf/misc/dsdbgroupchangenotification.xml [new file with mode: 0644]

diff --git a/docs-xml/smbdotconf/misc/dsdbgroupchangenotification.xml b/docs-xml/smbdotconf/misc/dsdbgroupchangenotification.xml
new file mode 100644 (file)
index 0000000..2079f51
--- /dev/null
@@ -0,0 +1,27 @@
+<samba:parameter name="dsdb group change notification"
+                 context="G"
+                 type="boolean"
+                 xmlns:samba="http://www.samba.org/samba/DTD/samba-doc">
+<description>
+       <para>When enabled, this option causes Samba (acting as an
+       Active Directory Domain Controller) to stream group membership change
+       events across the internal message bus.  Scripts built using
+       Samba's python bindings can listen to these events by
+       registering as the service
+       <filename moreinfo="none">dsdb_group_event</filename>.</para>
+
+       <para>This should be considered a developer option (it assists
+       in the Samba testsuite) rather than a facility for external
+       auditing, as message delivery is not guaranteed (a feature
+       that the testsuite works around).  Additionally Samba must be
+       not compiled with the --without-json-audit parameter for this
+       option to be effective.</para>
+
+       <para>The group events are also logged via the normal
+       logging methods when the <smbconfoption name="log level"/> is
+       set appropriately.</para>
+
+</description>
+
+<value type="default">no</value>
+</samba:parameter>