xref: /freebsd/usr.sbin/mountd/netgroup.5 (revision 59a3c79da68b53e9d606f0b7991574d982a843e1)
18fae3551SRodney W. Grimes.\" Copyright (c) 1992, 1993
28fae3551SRodney W. Grimes.\"	The Regents of the University of California.  All rights reserved.
38fae3551SRodney W. Grimes.\"
48fae3551SRodney W. Grimes.\" Redistribution and use in source and binary forms, with or without
58fae3551SRodney W. Grimes.\" modification, are permitted provided that the following conditions
68fae3551SRodney W. Grimes.\" are met:
78fae3551SRodney W. Grimes.\" 1. Redistributions of source code must retain the above copyright
88fae3551SRodney W. Grimes.\"    notice, this list of conditions and the following disclaimer.
98fae3551SRodney W. Grimes.\" 2. Redistributions in binary form must reproduce the above copyright
108fae3551SRodney W. Grimes.\"    notice, this list of conditions and the following disclaimer in the
118fae3551SRodney W. Grimes.\"    documentation and/or other materials provided with the distribution.
128fae3551SRodney W. Grimes.\" 4. Neither the name of the University nor the names of its contributors
138fae3551SRodney W. Grimes.\"    may be used to endorse or promote products derived from this software
148fae3551SRodney W. Grimes.\"    without specific prior written permission.
158fae3551SRodney W. Grimes.\"
168fae3551SRodney W. Grimes.\" THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
178fae3551SRodney W. Grimes.\" ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
188fae3551SRodney W. Grimes.\" IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
198fae3551SRodney W. Grimes.\" ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
208fae3551SRodney W. Grimes.\" FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
218fae3551SRodney W. Grimes.\" DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
228fae3551SRodney W. Grimes.\" OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
238fae3551SRodney W. Grimes.\" HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
248fae3551SRodney W. Grimes.\" LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
258fae3551SRodney W. Grimes.\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
268fae3551SRodney W. Grimes.\" SUCH DAMAGE.
278fae3551SRodney W. Grimes.\"
288fae3551SRodney W. Grimes.\"     @(#)netgroup.5	8.2 (Berkeley) 12/11/93
297f3dea24SPeter Wemm.\" $FreeBSD$
308fae3551SRodney W. Grimes.\"
318fae3551SRodney W. Grimes.Dd December 11, 1993
328fae3551SRodney W. Grimes.Dt NETGROUP 5
338fae3551SRodney W. Grimes.Os
348fae3551SRodney W. Grimes.Sh NAME
358fae3551SRodney W. Grimes.Nm netgroup
368fae3551SRodney W. Grimes.Nd defines network groups
378fae3551SRodney W. Grimes.Sh SYNOPSIS
387c7fb079SRuslan Ermilov.Nm
398fae3551SRodney W. Grimes.Sh DESCRIPTION
408fae3551SRodney W. GrimesThe
4174853402SPhilippe Charnier.Nm
428fae3551SRodney W. Grimesfile
438fae3551SRodney W. Grimesspecifies ``netgroups'', which are sets of
448fae3551SRodney W. Grimes.Sy (host, user, domain)
458fae3551SRodney W. Grimestuples that are to be given similar network access.
468fae3551SRodney W. Grimes.Pp
478fae3551SRodney W. GrimesEach line in the file
488fae3551SRodney W. Grimesconsists of a netgroup name followed by a list of the members of the
498fae3551SRodney W. Grimesnetgroup.
508fae3551SRodney W. GrimesEach member can be either the name of another netgroup or a specification
518fae3551SRodney W. Grimesof a tuple as follows:
528fae3551SRodney W. Grimes.Bd -literal -offset indent
538fae3551SRodney W. Grimes(host, user, domain)
548fae3551SRodney W. Grimes.Ed
5574853402SPhilippe Charnier.Pp
568fae3551SRodney W. Grimeswhere the
578fae3551SRodney W. Grimes.Sy host ,
588fae3551SRodney W. Grimes.Sy user ,
598fae3551SRodney W. Grimesand
608fae3551SRodney W. Grimes.Sy domain
618fae3551SRodney W. Grimesare character string names for the corresponding component.
628fae3551SRodney W. GrimesAny of the comma separated fields may be empty to specify a ``wildcard'' value
638fae3551SRodney W. Grimesor may consist of the string ``-'' to specify ``no valid value''.
648fae3551SRodney W. GrimesThe members of the list may be separated by whitespace and/or commas;
658fae3551SRodney W. Grimesthe ``\e'' character may be used at the end of a line to specify
66f63f700eSSheldon Hearnline continuation.
67f63f700eSSheldon HearnLines are limited to 1024 characters.
688fae3551SRodney W. GrimesThe functions specified in
698fae3551SRodney W. Grimes.Xr getnetgrent 3
708fae3551SRodney W. Grimesshould normally be used to access the
7174853402SPhilippe Charnier.Nm
728fae3551SRodney W. Grimesdatabase.
738fae3551SRodney W. Grimes.Pp
748fae3551SRodney W. GrimesLines that begin with a # are treated as comments.
751e890b05SBill Paul.Sh NIS/YP INTERACTION
761e890b05SBill PaulOn most other platforms,
7774853402SPhilippe Charnier.Nm Ns s
781e890b05SBill Paulare only used in conjunction with
7974853402SPhilippe Charnier.Tn NIS
8074853402SPhilippe Charnierand local
811e890b05SBill Paul.Pa /etc/netgroup
82f63f700eSSheldon Hearnfiles are ignored.
83f63f700eSSheldon HearnWith
84f050f700SMike Pritchard.Fx ,
8574853402SPhilippe Charnier.Nm Ns s
8674853402SPhilippe Charniercan be used with either
8774853402SPhilippe Charnier.Tn NIS
8874853402SPhilippe Charnieror local files, but there are certain
89f63f700eSSheldon Hearncaveats to consider.
90f63f700eSSheldon HearnThe existing
9174853402SPhilippe Charnier.Nm
921e890b05SBill Paulsystem is extremely inefficient where
931e890b05SBill Paul.Fn innetgr 3
941e890b05SBill Paullookups are concerned since
9574853402SPhilippe Charnier.Nm
96f63f700eSSheldon Hearnmemberships are computed on the fly.
97f63f700eSSheldon HearnBy contrast, the
9874853402SPhilippe Charnier.Tn NIS
9974853402SPhilippe Charnier.Nm
100e71057d8SMike Pritcharddatabase consists of three separate maps (netgroup, netgroup.byuser
1011e890b05SBill Pauland netgroup.byhost) that are keyed to allow
1021e890b05SBill Paul.Fn innetgr 3
103f63f700eSSheldon Hearnlookups to be done quickly.
104f63f700eSSheldon HearnThe
105f050f700SMike Pritchard.Fx
10674853402SPhilippe Charnier.Nm
10774853402SPhilippe Charniersystem can interact with the
10874853402SPhilippe Charnier.Tn NIS
10974853402SPhilippe Charnier.Nm
1101e890b05SBill Paulmaps in the following ways:
1111e890b05SBill Paul.Bl -bullet -offset indent
1121e890b05SBill Paul.It
1131e890b05SBill PaulIf the
1141e890b05SBill Paul.Pa /etc/netgroup
1151e890b05SBill Paulfile does not exist, or it exists and is empty, or
11674853402SPhilippe Charnierit exists and contains only a
11774853402SPhilippe Charnier.Sq + ,
11874853402SPhilippe Charnierand
11974853402SPhilippe Charnier.Tn NIS
12074853402SPhilippe Charnieris running,
12174853402SPhilippe Charnier.Nm
12274853402SPhilippe Charnierlookups will be done exclusively through
12374853402SPhilippe Charnier.Tn NIS ,
12474853402SPhilippe Charnierwith
1251e890b05SBill Paul.Fn innetgr 3
1261e890b05SBill Paultaking advantage of the netgroup.byuser and
1274e86fcacSSheldon Hearnnetgroup.byhost maps to speed up searches.
1284e86fcacSSheldon Hearn(This
1291e890b05SBill Paulis more or less compatible with the behavior of SunOS and
1301e890b05SBill Paulsimilar platforms.)
1311e890b05SBill Paul.It
1321e890b05SBill PaulIf the
1331e890b05SBill Paul.Pa /etc/netgroup
1341e890b05SBill Paulexists and contains only local
13574853402SPhilippe Charnier.Nm
13674853402SPhilippe Charnierinformation (with no
13774853402SPhilippe Charnier.Tn NIS
13874853402SPhilippe Charnier.Sq +
13974853402SPhilippe Charniertoken), then only the local
14074853402SPhilippe Charnier.Nm
14174853402SPhilippe Charnierinformation will be processed (and
14274853402SPhilippe Charnier.Tn NIS
14374853402SPhilippe Charnierwill be ignored).
1441e890b05SBill Paul.It
1451e890b05SBill PaulIf
1461e890b05SBill Paul.Pa /etc/netgroup
1471e890b05SBill Paulexists and contains both local netgroup data
1481e890b05SBill Paul.Pa and
14974853402SPhilippe Charnierthe
15074853402SPhilippe Charnier.Tn NIS
15174853402SPhilippe Charnier.Sq +
15274853402SPhilippe Charniertoken, the local data and the
15374853402SPhilippe Charnier.Tn NIS
15474853402SPhilippe Charniernetgroup
1551e890b05SBill Paulmap will be processed as a single combined
15674853402SPhilippe Charnier.Nm
157f63f700eSSheldon Hearndatabase.
158f63f700eSSheldon HearnWhile this configuration is the most flexible, it
1591e890b05SBill Paulis also the least efficient: in particular,
1601e890b05SBill Paul.Fn innetgr 3
1611e890b05SBill Paullookups will be especially slow if the
1621e890b05SBill Pauldatabase is large.
1631e890b05SBill Paul.El
1648fae3551SRodney W. Grimes.Sh FILES
1658fae3551SRodney W. Grimes.Bl -tag -width /etc/netgroup -compact
1668fae3551SRodney W. Grimes.It Pa /etc/netgroup
16774853402SPhilippe Charnierthe netgroup database
1688fae3551SRodney W. Grimes.El
1698fae3551SRodney W. Grimes.Sh COMPATIBILITY
1708fae3551SRodney W. GrimesThe file format is compatible with that of various vendors, however it
1718fae3551SRodney W. Grimesappears that not all vendors use an identical format.
17259a3c79dSRuslan Ermilov.Sh SEE ALSO
17359a3c79dSRuslan Ermilov.Xr getnetgrent 3 ,
17459a3c79dSRuslan Ermilov.Xr exports 5
1758fae3551SRodney W. Grimes.Sh BUGS
1768fae3551SRodney W. GrimesThe interpretation of access restrictions based on the member tuples of a
1778fae3551SRodney W. Grimesnetgroup is left up to the various network applications.
1788fae3551SRodney W. GrimesAlso, it is not obvious how the domain specification
17974853402SPhilippe Charnierapplies to the
18074853402SPhilippe Charnier.Bx
18174853402SPhilippe Charnierenvironment.
1821e890b05SBill Paul.Pp
1831e890b05SBill PaulThe
18474853402SPhilippe Charnier.Nm
1851e890b05SBill Pauldatabase should be stored in the form of a
1861e890b05SBill Paulhashed
1871e890b05SBill Paul.Xr db 3
1881e890b05SBill Pauldatabase just like the
1891e890b05SBill Paul.Xr passwd 5
1901e890b05SBill Pauldatabase to speed up reverse lookups.
191