.\" Automatically generated by Pod::Man version 1.15 .\" Fri Dec 20 09:52:45 2002 .\" .\" Standard preamble: .\" ====================================================================== .de Sh \" Subsection heading .br .if t .Sp .ne 5 .PP \fB\\$1\fR .PP .. .de Sp \" Vertical space (when we can't use .PP) .if t .sp .5v .if n .sp .. .de Ip \" List item .br .ie \\n(.$>=3 .ne \\$3 .el .ne 3 .IP "\\$1" \\$2 .. .de Vb \" Begin verbatim text .ft CW .nf .ne \\$1 .. .de Ve \" End verbatim text .ft R .fi .. .\" Set up some character translations and predefined strings. \*(-- will .\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left .\" double quote, and \*(R" will give a right double quote. | will give a .\" real vertical bar. \*(C+ will give a nicer C++. Capital omega is used .\" to do unbreakable dashes and therefore won't be available. \*(C` and .\" \*(C' expand to `' in nroff, nothing in troff, for use with C<> .tr \(*W-|\(bv\*(Tr .ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' .ie n \{\ . ds -- \(*W- . ds PI pi . if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch . if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch . ds L" "" . ds R" "" . ds C` "" . ds C' "" 'br\} .el\{\ . ds -- \|\(em\| . ds PI \(*p . ds L" `` . ds R" '' 'br\} .\" .\" If the F register is turned on, we'll generate index entries on stderr .\" for titles (.TH), headers (.SH), subsections (.Sh), items (.Ip), and .\" index entries marked with X<> in POD. Of course, you'll have to process .\" the output yourself in some meaningful fashion. .if \nF \{\ . de IX . tm Index:\\$1\t\\n%\t"\\$2" .. . nr % 0 . rr F .\} .\" .\" For nroff, turn off justification. Always turn off hyphenation; it .\" makes way too many mistakes in technical documents. .hy 0 .if n .na .\" .\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). .\" Fear. Run. Save yourself. No user-serviceable parts. .bd B 3 . \" fudge factors for nroff and troff .if n \{\ . ds #H 0 . ds #V .8m . ds #F .3m . ds #[ \f1 . ds #] \fP .\} .if t \{\ . ds #H ((1u-(\\\\n(.fu%2u))*.13m) . ds #V .6m . ds #F 0 . ds #[ \& . ds #] \& .\} . \" simple accents for nroff and troff .if n \{\ . ds ' \& . ds ` \& . ds ^ \& . ds , \& . ds ~ ~ . ds / .\} .if t \{\ . ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" . ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' . ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' . ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' . ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' . ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' .\} . \" troff and (daisy-wheel) nroff accents .ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' .ds 8 \h'\*(#H'\(*b\h'-\*(#H' .ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] .ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' .ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' .ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] .ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] .ds ae a\h'-(\w'a'u*4/10)'e .ds Ae A\h'-(\w'A'u*4/10)'E . \" corrections for vroff .if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' .if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' . \" for low resolution devices (crt and lpr) .if \n(.H>23 .if \n(.V>19 \ \{\ . ds : e . ds 8 ss . ds o a . ds d- d\h'-1'\(ga . ds D- D\h'-1'\(hy . ds th \o'bp' . ds Th \o'LP' . ds ae ae . ds Ae AE .\} .rm #[ #] #H #V #F C .\" ====================================================================== .\" .IX Title "sfs_config 5" .TH sfs_config 5 "SFS 0.7.2" "2002-12-20" "SFS 0.7.2" .UC .SH "NAME" sfs_config \- system-wide configuration parameters .SH "DESCRIPTION" .IX Header "DESCRIPTION" The \fIsfs_config\fR file lets you set the following system-wide parameters: .Ip "sfsdir \fIdirectory\fR" 4 .IX Item "sfsdir directory" The directory in which \s-1SFS\s0 stores its working files. The default is \&\fI/var/sfs\fR, unless you changed this with the \fB\-with-sfsdir\fR option to \fBconfigure\fR. .Ip "sfsuser \fIsfs-user\fR [\fIsfs-group\fR]" 4 .IX Item "sfsuser sfs-user [sfs-group]" As described in \fIBuilding\fR, \s-1SFS\s0 needs its own user and group to run. This configuration directive lets you set the user and group IDs \&\s-1SFS\s0 should use. By default, \fIsfs-user\fR is \fBsfs\fR and \&\fIsfs-group\fR is the same as \fIsfs-user\fR. The \fBsfsuser\fR directive lets you supply either a user and group name, or numeric IDs to change the default. Note: \fBIf you change \fR\fIsfs-group\fR\fB, you must make sure the the program \&\fR\fI/usr/local/lib/sfs-0.7.2/suidconnect\fR\fB is setgid to the new \&\fR\fIsfs-group\fR\fB.\fR .Ip "anonuser {\fIuser\fR | \fIuid\fR \fIgid\fR}" 4 .IX Item "anonuser {user | uid gid}" Specifies an unprivileged user id to be used for anonymous file access. If specified as \fIuser\fR, the name \fIuser\fR will be looked up in the password file, and the login group of that user used as the group id. Can alternatively be specified as a numeric \fIuid\fR and \fIgid\fR. The default is to use \-1 for both the \fIuid\fR and \fIgid\fR, though the default \fIsfs_config\fR file specifies the user name nobody. .Ip "ResvGids \fIlow-gid\fR \fIhigh-gid\fR" 4 .IX Item "ResvGids low-gid high-gid" \&\s-1SFS\s0 lets users run multiple instances of the \fBsfsagent\fR program. However, it needs to modify processes' group lists so as to know which file system requests correspond to which agents. The \fBResvGids\fR directive gives \s-1SFS\s0 a range of group IDs it can use to tag processes corresponding to a particular agent. (Typically, a range of 16 gids should be plenty.) Note that the range is inclusive\*(--both \&\fIlow-gid\fR and \fIhigh-gid\fR are considered reserved gids. .Sp The setuid root program \fBnewaid\fR lets users take on any of these group IDs. Thus, make sure these groups are not used for anything else, or you will create a security hole. There is no default for \fBResvGids\fR. .Sp Note that after changing \fBResvGids\fR, you must kill and restart \&\fBsfscd\fR for things to work properly. .Ip "RSASize \fIbits\fR" 4 .IX Item "RSASize bits" Sets the default size of public keys for cryptosystems that are based on the diffculty of factoring integers. The Rabin public keys used in self-certifying pathnames are affected by this paremeter. The default value of \fIbits\fR is 1280. .Ip "DlogSize \fIbits\fR" 4 .IX Item "DlogSize bits" Sets the default size of public keys for cryptosystems that are based on the diffculty of taking discrete logs in subgroups of \&\fBZ\fR@emph{p}*. This parameter affects \s-1SRP\s0 paremeter and 2\-Schnorr key generation. The default value of \fIbits\fR is 1024. .Ip "PwdCost \fIcost\fR" 4 .IX Item "PwdCost cost" Sets the computational cost of processing a user-chosen password. \s-1SFS\s0 uses passwords to encrypt users' private keys. Unfortunately, users tend to choose poor passwords. As computers get faster, guessing passwords gets easier. By increasing the \fIcost\fR parameter, you can maintain the cost of guessing passwords as hardware improves. The change will apply to new keys, and to old keys after people run \&\fBsfskey edit\fR. .Sp The default value is 11. \fIcost\fR is an exponential parameter. Thus, you probably don't want anything too much larger. The maximum value is 32\*(--at which point password hashing will not terminate in any tractable amount of time and the \fBsfskey\fR command will be unusable. .Ip "LogPriority \fIfacility\fR.\fIlevel\fR" 4 .IX Item "LogPriority facility.level" Sets the syslog facility and level at which \s-1SFS\s0 should log activity. The default is \fBdaemon.notice\fR. .SH "FILES" .IX Header "FILES" .Ip "\fI/etc/sfs/sfs_config\fR" 4 .IX Item "/etc/sfs/sfs_config" .PD 0 .Ip "\fI/usr/local/share/sfs/sfs_config\fR" 4 .IX Item "/usr/local/share/sfs/sfs_config" .PD system-wide configuration parameters .PP (Files in \fI/etc/sfs\fR supersede default versions in \fI/usr/local/share/sfs\fR.) .SH "SEE ALSO" .IX Header "SEE ALSO" \&\fIdirsearch\fR\|(1), \fInewaid\fR\|(1), \fIrex\fR\|(1), \fIsfsagent\fR\|(1), \fIsfskey\fR\|(1), \fIssu\fR\|(1), \fIsfs_srp_params\fR\|(5), \fIsfs_users\fR\|(5), \fIsfsauthd_config\fR\|(5), \fIsfscd_config\fR\|(5), \fIsfsrwsd_config\fR\|(5), \fIsfssd_config\fR\|(5), \fIfunmount\fR\|(8), \fIsfsauthd\fR\|(8), \fIsfscd\fR\|(8), \fIsfsrwsd\fR\|(8), \fIsfssd\fR\|(8), \fIvidb\fR\|(8) .PP The full documentation for \fB\s-1SFS\s0\fR is maintained as a Texinfo manual. If the \fBinfo\fR and \fB\s-1SFS\s0\fR programs are properly installed at your site, the command \fBinfo \s-1SFS\s0\fR should give you access to the complete manual. .PP For updates, documentation, and software distribution, please see the \fB\s-1SFS\s0\fR website at \fIhttp://www.fs.net\fR. .SH "AUTHOR" .IX Header "AUTHOR" sfsdev@redlab.lcs.mit.edu