GSSPROXY.CONF(5) (NAME) gssproxy.conf - gssproxy (DESCRIPTION) gssproxy.conf gssproxy . gssproxy. GSS-Proxy ini . key = value . '#' . "1" "true" "yes" "on" . . GSS-Proxy "gssproxy.conf" "##-foo.conf" ( ".conf" ). . . ( ). (SECTIONS) GSS-Proxy ([sectionname]) . gssproxy [gssproxy] . nfs apache ssh [service/nfs] [service/apache] "euid" ( ) . (VARIABLE SUBSTITUTIONS) . gssproxy keytab (credential caches) . : %U (uid) ( 123). %u ( john). (OPTIONS) gssproxy : allow_any_uid () . ( ). allow_any_uid . : false allow_protocol_transition () (ticket to self) . s4u2self . keytab . KDC . : false allow_constrained_delegation () (evidence ticket) . s4u2proxy . KDC . : false allow_client_ccache_sync () . ccache . () ccache . : false cred_store () gssproxy cred_store GSSAPI . . cred_store : cred_store = <_cred_store>:<_cred_store> : keytab keytab . : cred_store = keytab:/path/to/keytab client_keytab client keytab . : cred_store = client_keytab:/path/to/client_keytab ccache (credential cache) . : cred_store = ccache:/path/to/ccache client_keytab ccache ( ) . : cred_store = keytab:/etc/krb5.keytab cred_store = ccache:FILE:/var/lib/gssproxy/krb5cc_%U cred_store = client_keytab:/var/lib/gssproxy/%U.keytab : cred_store = cred_usage () . : initiate accept both : cred_usage = both debug () () syslog . true debug_level 1 . : debug = false debug_level ( ) . 0 1 . 2 (verbosity) . 3 KRB5_TRACE . KRB5_TRACE . docs/KRB5_TRACE.md . : 1 true debug 0 enforce_flags () GSS (context initialization) . +/- . : DELEGATE MUTUAL_AUTH REPLAY_DETECT SEQUENCE CONFIDENTIALITY INTEGRITY ANONYMOUS : enforce_flags = +REPLAY_DETECT enforce_flags = -0x0001 : enforce_flags = euid ( ) (effective uid) ( 48) ( apache) . "euid" . : euid = filter_flags () GSS () . +/- . : gssproxy Delegate . (delegate credentials) . : DELEGATE MUTUAL_AUTH REPLAY_DETECT SEQUENCE CONFIDENTIALITY INTEGRITY ANONYMOUS : filter_flags = -DELEGATE filter_flags = -0x0001 +ANONYMOUS : filter_flags = +DELEGATE impersonate () / (impersonation) (s4u2self + s4u2proxy) . : impersonate = false kernel_nfsd () gssproxy ( /proc/net/rpc/use-gss-proxy). : kernel_nfsd = false krb5_principal () (principal) krb5 . . : krb5_principal = mechs () krb5 . "mechs" . : mechs = min_lifetime ( ) . gssproxy . gssproxy . : min_lifetime = 15 program () . (canonical paths) ( ). '|' . run_as_user () gssproxy (drop privileges). (global section) . : run_as_user = selinux_context () . euid . socket () gssproxy . gssproxy . syslog_status () syslog . gssproxy . : syslog_status = false trusted () . (impersonation) . : trusted = false worker threads ( ) (worker threads) gssproxy . : worker threads = (SEE ALSO) gssproxy(8) gssproxy-mech(8). (AUTHORS) GSS-Proxy - http://fedorahosted.org/gss-proxy gssproxy GSSPROXY.CONF(5)