docs: Update section "ldap ssl" in man smb.conf.
authorKarolin Seeger <kseeger@samba.org>
Wed, 17 Dec 2008 15:18:38 +0000 (16:18 +0100)
committerKarolin Seeger <kseeger@samba.org>
Mon, 12 Jan 2009 09:12:02 +0000 (10:12 +0100)
Remove non-existent value "on".
Change default value to "no".
Add hint about ldaps.

Karolin
(cherry picked from commit 580461629bb88ce3b61770e7abfe2c942a121877)
(cherry picked from commit d74356627579fe7b9961844a77c4e6daa978d62b)
(cherry picked from commit 882ac5e5a79646754dfd1669ea6720ab52c9b6ee)
(cherry picked from commit e147c4679f8095738fea6ab2c9fb37fbecc9bb85)

docs-xml/smbdotconf/ldap/ldapssl.xml

index 383a545ae270a0e91bd6796a4cced91a53b4fffd..d785071ec4c692e84bf80f1225f9f831ee046871 100644 (file)
        <filename moreinfo="none">configure</filename>
        script.</para>
 
+       <para>LDAP connections should be secured where possible. This may be
+       done setting either this parameter to
+       <parameter moreinfo="none">Start_tls</parameter>
+       or by specifying <parameter moreinfo="none">ldaps://</parameter> in
+        the URL argument of <smbconfoption name="passdb backend"/>.</para>
+
        <para>The <smbconfoption name="ldap ssl"/> can be set to one of
-       three values:</para>
+       two values:</para>
        <itemizedlist>
                <listitem>
                        <para><parameter moreinfo="none">Off</parameter> = Never
                        the LDAPv3 StartTLS extended operation (RFC2830) for
                        communicating with the directory server.</para>
                </listitem>
-
-               <listitem>
-                       <para><parameter moreinfo="none">On</parameter>  = Use SSL
-                       on the ldaps port when contacting the <parameter>
-                       moreinfo="none">ldap server</parameter>. Only available when the
-                       backwards-compatiblity <command>
-                       moreinfo="none">--with-ldapsam</command> option is specified
-                       to configure. See <smbconfoption name="passdb backend"/></para>.
-               </listitem>
        </itemizedlist>
 </description>
-<value type="default">start_tls</value>
+<value type="default">no</value>
 </samba:parameter>