openafs/doc/man-pages/pod1/pts_adduser.pod
Russ Allbery 03b9fcc883 man1-editing-pass-20051209
Complete an initial editing and cleanup pass for all section one man pages.
Fix various conversion problems, formatting inconsistencies, and obvious
problems.  Please note that no editing for content has yet been done; this
is solely editing for formatting and correct conversion to POD.

Also, add some additional section five man pages that were omitted from the
first conversion run due to unusual file names, and globally replace
CAVEATS with CAUTIONS in the man pages to match the original section name.

The section one man pages should now be in reasonable shape and ready for
additional review and further updates, although there are probably still
remaining obvious problems.

====================
This delta was composed from multiple commits as part of the CVS->Git migration.
The checkin message with each commit was inconsistent.
The following are the additional commit messages.
====================

This file got the wrong name when it was originally committed.  Fix.
2005-12-09 14:48:56 +00:00

128 lines
3.6 KiB
Plaintext

=head1 NAME
pts adduser - Adds a user or machine to a Protection Database group
=head1 SYNOPSIS
B<pts adduser> B<-user> <I<user name>>+ B<-group> <I<group name>>+
[B<-cell> <I<cell name>>] [B<-noauth>] [B<-force>] [B<-help>]
B<pts ad> B<-u> <I<user name>>+ B<-g> <I<group name>>+
[B<-c> <I<cell name>>] [B<-n>] [B<-f>] [B<-h>]
=head1 DESCRIPTION
The B<pts adduser> command adds each user or machine entry named by the
B<-user> argument as a member of each group named by the B<-group>
argument.
To remove members of a group, use the B<pts removeuser> command. To list
the groups to which a user or machine belongs, or the members of a
specified group, use the B<pts membership> command.
=head1 CAUTIONS
After being added as a group member, a currently authenticated user must
reauthenticate (for example, by issuing the B<klog> command) to obtain
permissions granted to the group on an access control list (ACL).
=head1 OPTIONS
=over 4
=item B<-user> <I<user name>>+
Specifies the name of each user or machine entry to add to each group
named by the B<-group> argument. The name of a machine entry resembles an
IP address and can use the wildcard notation described on the B<pts
createuser> reference page. The user or machine entry must already exist
in the Protection Database.
=item B<-group> <I<group name>>+
Specifies the complete name (including the owner prefix if applicable) of
each group to which to add members. The group entry must already exist in
the Protection Database.
=item B<-cell> <I<cell name>>
Names the cell in which to run the command. For more details, see
L<pts(1)>.
=item B<-noauth>
Assigns the unprivileged identity anonymous to the issuer. For more
details, see L<pts(1)>.
=item B<-force>
Enables the command to continue executing as far as possible when errors
or other problems occur, rather than halting execution at the first error.
=item B<-help>
Prints the online help for this command. All other valid options are
ignored.
=back
=head1 EXAMPLES
The following example adds user smith to the group system:administrators.
% pts adduser -user smith -group system:administrators
The following example adds users C<jones>, C<terry>, and B<pat> to the
smith:colleagues group.
% pts adduser -user jones terry pat -group smith:colleagues
The following example adds the machine entries in the ABC Corporation
subnet to the group C<bin-prot>. Because of the IP address range of the
ABC Corporation subnet, the system administrator was able to group the
machines into three machine entries (using the wildcard notation discussed
on the B<pts createuser> reference page).
% pts adduser -user 138.255.0.0 192.12.105.0 192.12.106.0 -group bin-prot
=head1 PRIVILEGE REQUIRED
The required privilege depends on the setting of the fourth privacy flag
in the Protection Database entry for each group named by the B<-group>
argument (use the B<pts examine> command to display the flags):
=over 4
=item *
If it is the hyphen, only the group's owner and members of the
system:administrators group can add members.
=item *
If it is lowercase C<a>, current members of the group can add new members.
=item *
If it is uppercase C<A>, anyone who can access the cell's database server
machines can add new members.
=back
=head1 SEE ALSO
L<pts(1)>,
L<pts_createuser(1)>,
L<pts_examine(1)>,
L<pts_membership(1)>,
L<pts_removeuser(1)>,
L<pts_setfields(1)>
=head1 COPYRIGHT
IBM Corporation 2000. <http://www.ibm.com/> All Rights Reserved.
This documentation is covered by the IBM Public License Version 1.0. It was
converted from HTML to POD by software written by Chas Williams and Russ
Allbery, based on work by Alf Wachsmann and Elizabeth Cassell.