425db0
From 069ba5774a5ccc72dcc3567bc6d17141d68ddff5 Mon Sep 17 00:00:00 2001
425db0
From: Andreas Schneider <asn@samba.org>
425db0
Date: Thu, 9 Jul 2020 11:48:26 +0200
425db0
Subject: [PATCH] docs: Fix documentation for require_membership_of of
425db0
 pam_winbind
425db0
425db0
BUG: https://bugzilla.samba.org/show_bug.cgi?id=14358
425db0
425db0
Signed-off-by: Andreas Schneider <asn@samba.org>
425db0
Reviewed-by: Alexander Bokovoy <ab@samba.org>
425db0
425db0
Autobuild-User(master): Andreas Schneider <asn@cryptomilk.org>
425db0
Autobuild-Date(master): Fri Jul 10 09:40:37 UTC 2020 on sn-devel-184
425db0
425db0
(cherry picked from commit 4c74db6978c682f8ba4e74a6ee8157cfcbb54971)
425db0
---
425db0
 docs-xml/manpages/pam_winbind.8.xml | 8 +++++---
425db0
 1 file changed, 5 insertions(+), 3 deletions(-)
425db0
425db0
diff --git a/docs-xml/manpages/pam_winbind.8.xml b/docs-xml/manpages/pam_winbind.8.xml
425db0
index a9a227f1647..a61fb2d58e5 100644
425db0
--- a/docs-xml/manpages/pam_winbind.8.xml
425db0
+++ b/docs-xml/manpages/pam_winbind.8.xml
425db0
@@ -84,9 +84,11 @@
425db0
 		If this option is set, pam_winbind will only succeed if the user is a member of the given SID or NAME. A SID
425db0
 		can be either a group-SID, an alias-SID or even an user-SID. It is also possible to give a NAME instead of the
425db0
 		SID. That name must have the form: <parameter>MYDOMAIN\mygroup</parameter> or
425db0
-		<parameter>MYDOMAIN\myuser</parameter>.  pam_winbind will, in that case, lookup the SID internally. Note that
425db0
-		NAME may not contain any spaces. It is thus recommended to only use SIDs. You can verify the list of SIDs a
425db0
-		user is a member of with <command>wbinfo --user-sids=SID</command>.
425db0
+		<parameter>MYDOMAIN\myuser</parameter> (where '\' character corresponds to the value of
425db0
+		<parameter>winbind separator</parameter> parameter). It is also possible to use a UPN in the form
425db0
+		<parameter>user@REALM</parameter> or <parameter>group@REALM</parameter>. pam_winbind will, in that case, lookup
425db0
+		the SID internally. Note that NAME may not contain any spaces. It is thus recommended to only use SIDs. You can
425db0
+		verify the list of SIDs a user is a member of with <command>wbinfo --user-sids=SID</command>.
425db0
 		</para>
425db0
 
425db0
 		<para>
425db0
-- 
425db0
2.27.0
425db0