openafs/doc/man-pages/pod8/kas_unlock.pod
Russ Allbery fc5acc0151 pretty-html-synopsis-20060228
Implement proper synopsis wrapping for HTML generation.

This was done in three pieces.  First, add HTML-specific tags to the POD to
mark the synopsis for HTML purposes so that we can apply style information
to it.  Second, update the style sheet to indent all lines except for the
first in the synopsis section.  Third, add the appropriate S<> tags around
option and argument pairs so that we don't wrap between the option and its
argument.

Unfortunately, due to the <I<foo>> style that looks nicer for other reasons,
we have to use the very verbose S<<< >>>.  Oh well.
2006-03-01 05:02:29 +00:00

107 lines
3.1 KiB
Plaintext

=head1 NAME
kas unlock - Unlocks a locked user account
=head1 SYNOPSIS
=for html
<div class="synopsis">
B<kas unlock> S<<< B<-name> <I<authentication ID>> >>>
S<<< [B<-admin_username> <I<admin principal to use for authentication>>] >>>
S<<< [B<-password_for_admin> <I<admin password>>] >>> S<<< [B<-cell> <I<cell name>>] >>>
S<<< [B<-servers> <I<explicit list of authentication servers>>+] >>>
[B<-noauth>] [B<-help>]
B<kas u> S<<< B<-na> <I<authentication ID>> >>>
S<<< [B<-a> <I<admin principal to use for authentication>>] >>>
S<<< [B<-p> <I<admin password>>] >>> S<<< [B<-c> <I<cell name>>] >>>
S<<< [B<-s> <I<explicit list of authentication servers>>+] >>> [B<-no>] [B<-h>]
=for html
</div>
=head1 DESCRIPTION
The B<kas unlock> command unlocks the Authentication Database entry named
by the B<-name> argument. An entry becomes locked when the user exceeds
the limit on failed authentication attempts, generally by providing the
wrong password to either an AFS-modified login utility or the B<klog>
command. Use the B<kas setfields> command to set the limit and the lockout
time, and the B<kas examine> command to examine the settings.
To unlock all locked user accounts at once, shutdown the B<kaserver>
process on every database server machine, and remove the
F</usr/afs/local/kaauxdb> file from each one. The B<kaserver> process
recreates the file as it restarts.
=head1 OPTIONS
=over 4
=item B<-name> <I<authentication ID>>
Names the Authentication Database entry to unlock.
=item B<-admin_username> <I<admin principal>>
Specifies the user identity under which to authenticate with the
Authentication Server for execution of the command. For more details, see
L<kas(8)>.
=item B<-password_for_admin> <I<admin password>>
Specifies the password of the command's issuer. If it is omitted (as
recommended), the B<kas> command interpreter prompts for it and does not
echo it visibly. For more details, see L<kas(8)>.
=item B<-cell> <I<cell name>>
Names the cell in which to run the command. For more details, see
L<kas(8)>.
=item B<-servers> <I<authentication servers>>+
Names each machine running an Authentication Server with which to
establish a connection. For more details, see L<kas(8)>.
=item B<-noauth>
Assigns the unprivileged identity C<anonymous> to the issuer. For more
details, see L<kas(8)>.
=item B<-help>
Prints the online help for this command. All other valid options are
ignored.
=back
=head1 EXAMPLES
In the following example, an administrator using the C<admin> account
unlocks the entry for C<jones>:
% kas unlock -name jones -admin_username admin
Administrator's (admin) Password:
=head1 PRIVILEGE REQUIRED
The issuer must have the C<ADMIN> flag set on his or her Authentication
Database entry.
=head1 SEE ALSO
L<kas(8)>,
L<kas_examine(8)>,
L<kas_setfields(8)>,
L<klog(1)>
=head1 COPYRIGHT
IBM Corporation 2000. <http://www.ibm.com/> All Rights Reserved.
This documentation is covered by the IBM Public License Version 1.0. It was
converted from HTML to POD by software written by Chas Williams and Russ
Allbery, based on work by Alf Wachsmann and Elizabeth Cassell.