openafs/doc/man-pages/pod1/pts_removeuser.pod.in
Russ Allbery a792acdadc Add include method for POD documentation
Add a preprocessor for POD documentation that handles a custom
=include directive.  Demonstrate how to use the preprocessor by
factoring out all the standard PTS options into a separate POD
fragment and including that fragment in all the PTS commands that
take the standard options instead of including that documentation
in each separate file.

Change-Id: If5255efc6d3fc670b38a9898b3d7d3c60af04fcf
Reviewed-on: http://gerrit.openafs.org/2440
Reviewed-by: Derrick Brashear <shadow@dementia.org>
Tested-by: Derrick Brashear <shadow@dementia.org>
2010-07-15 21:09:13 -07:00

104 lines
2.8 KiB
Plaintext

=head1 NAME
pts_removeuser - Removes a user from a Protection Database group
=head1 SYNOPSIS
=for html
<div class="synopsis">
B<pts removeuser> S<<< B<-user> <I<user name>>+ >>> S<<< B<-group> <I<group name>>+ >>>
S<<< [B<-cell> <I<cell name>>] >>> [B<-noauth>] [B<-localauth>] [B<-force>]
[B<-help>]
B<pts rem> S<<< B<-u> <I<user name>>+ >>> S<<< B<-g> <I<group name>>+ >>>
S<<< [B<-c> <I<cell name>>] >>> [B<-n>] [B<-l>] [B<-f>] [B<-h>]
=for html
</div>
=head1 DESCRIPTION
The B<pts removeuser> command removes each user or machine named by the
B<-user> argument from each group named by the B<-group> argument.
To add users to a group, use the B<pts adduser> command. To list group
membership, use the B<pts membership> command. To remove users from a
group and delete the group's entry completely in a single step, use the
B<pts delete> command.
=head1 CAUTIONS
AFS compiles each user's group membership as he or she authenticates. Any
users who have valid tokens when they are removed from a group retain the
privileges extended to that group's members until they discard their
tokens or reauthenticate.
=head1 OPTIONS
=over 4
=item B<-name> <I<user name>>+
Specifies the name of each user entry or the IP address (complete or
wildcard-style) of each machine entry to remove.
=item B<-group> <I<group name>>+
Names each group from which to remove members.
=include fragments/pts-common.pod
=back
=head1 EXAMPLES
The following example removes user smith from the groups C<staff> and
C<staff:finance>. Note that no switch names are necessary because only a
single instance is provided for the first argument (the username).
% pts removeuser smith staff staff:finance
The following example removes three machine entries, which represent all
machines in the ABC Corporation network, from the group C<bin-prot>:
% pts removeuser -user 138.255.0.0 192.12.105.0 192.12.106.0 -group bin-prot
=head1 PRIVILEGE REQUIRED
The required privilege depends on the setting of the fifth privacy flag in
the Protection Database for the group named by the B<-group> argument (use
the B<pts examine> command to display the flags):
=over 4
=item *
If it is the hyphen, only the group's owner and members of the
system:administrators group can remove members.
=item *
If it is lowercase C<r>, members of the group can also remove other
members.
=back
(It is not possible to set the fifth flag to uppercase C<R>.)
=head1 SEE ALSO
L<pts(1)>,
L<pts_adduser(1)>,
L<pts_examine(1)>,
L<pts_membership(1)>,
L<pts_setfields(1)>
=head1 COPYRIGHT
IBM Corporation 2000. <http://www.ibm.com/> All Rights Reserved.
This documentation is covered by the IBM Public License Version 1.0. It was
converted from HTML to POD by software written by Chas Williams and Russ
Allbery, based on work by Alf Wachsmann and Elizabeth Cassell.