diff --git a/po/fr/rawhide/nav.po b/po/fr/rawhide/nav.po new file mode 100644 index 00000000000..aac80939a25 --- /dev/null +++ b/po/fr/rawhide/nav.po @@ -0,0 +1,244 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Plain text +#: ./nav.adoc:2 +msgid "xref:index.adoc[System Administrator's Guide]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:3 +msgid "xref:Preface.adoc[Preface]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:4 +msgid "Basic System Configuration" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:5 +msgid "xref:basic-system-configuration/intro-basic-system-configuration.adoc[Introduction]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:6 +msgid "" +"xref:basic-system-configuration/Opening_GUI_Applications.adoc[Opening " +"Graphical Applications]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:7 +msgid "" +"xref:basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc[System " +"Locale and Keyboard Configuration]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:8 +msgid "" +"xref:basic-system-configuration/Configuring_the_Date_and_Time.adoc[Configuring " +"the Date and Time]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:9 +msgid "" +"xref:basic-system-configuration/Managing_Users_and_Groups.adoc[Managing " +"Users and Groups]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:10 +msgid "xref:basic-system-configuration/Gaining_Privileges.adoc[Gaining Privileges]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:11 +msgid "Package Management" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:12 +msgid "xref:package-management/intro-package-management.adoc[Introduction]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:13 +msgid "xref:package-management/DNF.adoc[DNF]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:14 +msgid "xref:package-management/rpm-ostree.adoc[rpm-ostree]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:15 +msgid "Infrastructure Services" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:16 +msgid "xref:infrastructure-services/intro-infrastructure-services.adoc[Introduction]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:17 +msgid "xref:infrastructure-services/Services_and_Daemons.adoc[Services and Daemons]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:18 +msgid "xref:infrastructure-services/OpenSSH.adoc[OpenSSH]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:19 +msgid "xref:infrastructure-services/TigerVNC.adoc[TigerVNC]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:20 +msgid "Servers" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:21 +msgid "xref:servers/intro-servers.adoc[Introduction]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:22 +msgid "xref:servers/Web_Servers.adoc[Web Servers]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:23 +msgid "xref:servers/Mail_Servers.adoc[Mail Servers]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:24 +msgid "xref:servers/Directory_Servers.adoc[Directory Servers]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:25 +msgid "xref:servers/File_and_Print_Servers.adoc[File and Print Servers]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:26 +msgid "" +"xref:servers/Configuring_NTP_Using_the_chrony_Suite.adoc[Configuring NTP " +"Using the chrony Suite]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:27 +msgid "xref:servers/Configuring_PTP_Using_ptp4l.adoc[Configuring PTP Using ptp4l]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:28 +msgid "Monitoring and Automation" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:29 +msgid "xref:monitoring-and-automation/intro-monitoring-and-automation.adoc[Introduction]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:30 +msgid "" +"xref:monitoring-and-automation/System_Monitoring_Tools.adoc[System " +"Monitoring Tools]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:31 +msgid "" +"xref:monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc[Viewing " +"and Managing Log Files]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:32 +msgid "" +"xref:monitoring-and-automation/Automating_System_Tasks.adoc[Automating " +"System Tasks]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:33 +msgid "xref:monitoring-and-automation/OProfile.adoc[OProfile]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:34 +msgid "Kernel, Module and Driver Configuration" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:35 +msgid "xref:kernel-module-driver-configuration/intro-kernel-module-driver-configuration.adoc[Introduction]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:36 +msgid "" +"xref:kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc[Working " +"with the GRUB 2 Boot Loader]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:37 +msgid "" +"xref:kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc[Manually " +"Upgrading the Kernel]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:38 +msgid "" +"xref:kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc[Working " +"with Kernel Modules]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:39 +msgid "xref:RPM.adoc[RPM]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:40 +msgid "xref:Wayland.adoc[The Wayland Display Server]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:41 +msgid "xref:pam_userdb.adoc[pam_userdb]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:41 +msgid "xref:Revision_History.adoc[Revision History]" +msgstr "" diff --git a/po/fr/rawhide/pages/Preface.po b/po/fr/rawhide/pages/Preface.po new file mode 100644 index 00000000000..9c86dd9aa9c --- /dev/null +++ b/po/fr/rawhide/pages/Preface.po @@ -0,0 +1,468 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/Preface.adoc:5 +#, no-wrap +msgid "Preface" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:8 +msgid "" +"The [citetitle]_System Administrator's Guide_ contains information on how to " +"customize the {MAJOROSVER} system to fit your needs. If you are looking for " +"a comprehensive, task-oriented guide for configuring and customizing your " +"system, this is the manual for you." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:10 +msgid "This manual discusses many intermediate topics such as the following:" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:12 +msgid "Installing and managing packages using [application]*DNF*" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:14 +msgid "" +"Configuring [application]*Apache HTTP Server*, [application]*Postfix*, " +"[application]*Sendmail* and other enterprise-class servers and software" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:16 +msgid "Working with kernel modules and upgrading the kernel" +msgstr "" + +#. type: delimited block = +#: ./pages/Preface.adoc:21 +msgid "" +"Some of the graphical procedures and menu locations are specific to GNOME, " +"but most command line instructions will be universally applicable." +msgstr "" + +#. type: Title == +#: ./pages/Preface.adoc:25 +#, no-wrap +msgid "Target Audience" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:28 +msgid "" +"The [citetitle]_System Administrator's Guide_ assumes you have a basic " +"understanding of the {MAJOROS} operating system. If you need help with the " +"installation of this system, refer to the " +"link:++https://docs.fedoraproject.org/install-guide++[{MAJOROS} Installation " +"Guide]." +msgstr "" + +#. type: Title == +#: ./pages/Preface.adoc:30 +#, no-wrap +msgid "How to Read this Book" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:33 +msgid "This manual is divided into the following main categories:" +msgstr "" + +#. type: Labeled list +#: ./pages/Preface.adoc:34 +#, no-wrap +msgid "" +"xref:basic-system-configuration/intro-basic-system-configuration.adoc[Basic " +"System Configuration]" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:35 +msgid "" +"This part covers basic system administration tasks such as keyboard " +"configuration, date and time configuration, managing users and groups, and " +"gaining privileges." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:37 +msgid "" +"xref:basic-system-configuration/Opening_GUI_Applications.adoc[Opening " +"Graphical Applications] describes methods for opening `Graphical User " +"Interface`, or _GUI_, applications in various environments." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:39 +msgid "" +"xref:basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc[System " +"Locale and Keyboard Configuration] covers basic language and keyboard " +"setup. Read this chapter if you need to configure the language of your " +"desktop, change the keyboard layout, or add the keyboard layout indicator to " +"the panel." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:41 +msgid "" +"xref:basic-system-configuration/Configuring_the_Date_and_Time.adoc[Configuring " +"the Date and Time] covers the configuration of the system date and " +"time. Read this chapter if you need to set or change the date and time." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:43 +msgid "" +"xref:basic-system-configuration/Managing_Users_and_Groups.adoc[Managing " +"Users and Groups] covers the management of users and groups in a graphical " +"user interface and on the command line. Read this chapter if you need to " +"manage users and groups on your system, or enable password aging." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:45 +msgid "" +"xref:basic-system-configuration/Gaining_Privileges.adoc[Gaining Privileges] " +"covers ways to gain administrative privileges using setuid programs such as " +"[command]#su# and [command]#sudo#." +msgstr "" + +#. type: Labeled list +#: ./pages/Preface.adoc:46 +#, no-wrap +msgid "xref:package-management/intro-package-management.adoc[Package Management]" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:47 +msgid "" +"This part describes how to manage software packages on {MAJOROS} using " +"[application]*DNF*." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:49 +msgid "" +"xref:package-management/DNF.adoc[DNF] describes the [application]*DNF* " +"package manager. Read this chapter for information how to search, install, " +"update, and uninstall packages on the command line." +msgstr "" + +#. type: Labeled list +#: ./pages/Preface.adoc:50 +#, no-wrap +msgid "" +"xref:infrastructure-services/intro-infrastructure-services.adoc[Infrastructure " +"Services]" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:51 +msgid "" +"This part provides information on how to configure services and daemons, " +"configure authentication, and enable remote logins." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:53 +msgid "" +"xref:infrastructure-services/Services_and_Daemons.adoc[Services and Daemons] " +"covers the configuration of the services to be run when a system is started, " +"and provides information on how to start, stop, and restart the services on " +"the command line using the [command]#systemctl# utility." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:55 +msgid "" +"xref:infrastructure-services/OpenSSH.adoc[OpenSSH] describes how to enable a " +"remote login via the SSH protocol. It covers the configuration of the `sshd` " +"service, as well as a basic usage of the [command]#ssh#, [command]#scp#, " +"[command]#sftp# client utilities. Read this chapter if you need a remote " +"access to a machine." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:57 +msgid "" +"xref:infrastructure-services/TigerVNC.adoc[TigerVNC] describes the _virtual " +"network computing_ (*VNC*) method of graphical desktop sharing which allows " +"you to remotely control other computers." +msgstr "" + +#. type: Labeled list +#: ./pages/Preface.adoc:58 +#, no-wrap +msgid "xref:servers/intro-servers.adoc[Servers]" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:59 +msgid "" +"This part discusses various topics related to servers such as how to set up " +"a Web server or share files and directories over the network." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:61 +msgid "" +"xref:servers/Web_Servers.adoc[Web Servers] focuses on the " +"[application]*Apache HTTP Server*, a robust, full-featured open source web " +"server developed by the Apache Software Foundation. Read this chapter if you " +"need to configure a web server on your system." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:63 +msgid "" +"xref:servers/Mail_Servers.adoc[Mail Servers] reviews modern email protocols " +"in use today, and some of the programs designed to send and receive email, " +"including [application]*Postfix*, [application]*Sendmail*, " +"[application]*Fetchmail*, and [application]*Procmail*. Read this chapter if " +"you need to configure a mail server on your system." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:65 +msgid "" +"xref:servers/Directory_Servers.adoc[Directory Servers] covers the " +"installation and configuration of [application]*OpenLDAP*, an open source " +"implementation of the LDAPv2 and LDAPv3 protocols. Read this chapter if you " +"need to configure a directory server on your system." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:67 +msgid "" +"xref:servers/File_and_Print_Servers.adoc[File and Print Servers] guides you " +"through the installation and configuration of [application]*Samba*, an open " +"source implementation of the Server Message Block (SMB) protocol, and " +"[application]*vsftpd*, the primary FTP server shipped with " +"{MAJOROS}. Additionally, it explains how to use the [application]*Printer " +"Configuration* tool to configure printers. Read this chapter if you need to " +"configure a file or print server on your system." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:69 +msgid "" +"xref:servers/Configuring_NTP_Using_the_chrony_Suite.adoc[Configuring NTP " +"Using the chrony Suite] covers the installation and configuration of the " +"[application]*chrony* suite, a client and a server for the Network Time " +"Protocol (`NTP`). Read this chapter if you need to configure the system to " +"synchronize the clock with a remote `NTP` server, or set up an `NTP` server " +"on this system." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:71 +msgid "" +"xref:servers/Configuring_NTP_Using_ntpd.adoc[Configuring NTP Using ntpd] " +"covers the installation and configuration of the `NTP` daemon, `ntpd`, for " +"the Network Time Protocol (`NTP`). Read this chapter if you need to " +"configure the system to synchronize the clock with a remote `NTP` server, or " +"set up an `NTP` server on this system, and you prefer not to use the " +"[application]*chrony* application." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:73 +msgid "" +"xref:servers/Configuring_PTP_Using_ptp4l.adoc[Configuring PTP Using ptp4l] " +"covers the installation and configuration of the Precision Time Protocol " +"application, [application]*ptp4l*, an application for use with network " +"drivers that support the Precision Network Time Protocol (`PTP`). Read this " +"chapter if you need to configure the system to synchronize the system clock " +"with a master `PTP` clock." +msgstr "" + +#. type: Labeled list +#: ./pages/Preface.adoc:74 +#, no-wrap +msgid "" +"xref:monitoring-and-automation/intro-monitoring-and-automation.adoc[Monitoring " +"and Automation]" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:75 +msgid "" +"This part describes various tools that allow system administrators to " +"monitor system performance, automate system tasks, and report bugs." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:77 +msgid "" +"xref:monitoring-and-automation/System_Monitoring_Tools.adoc[System " +"Monitoring Tools] discusses applications and commands that can be used to " +"retrieve important information about the system. Read this chapter to learn " +"how to gather essential system information." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:79 +msgid "" +"xref:monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc[Viewing " +"and Managing Log Files] describes the configuration of the `rsyslog` daemon, " +"and explains how to locate, view, and monitor log files. Read this chapter " +"to learn how to work with log files." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:81 +msgid "" +"xref:monitoring-and-automation/Automating_System_Tasks.adoc[Automating " +"System Tasks] provides an overview of the [command]#cron#, [command]#at#, " +"and [command]#batch# utilities. Read this chapter to learn how to use these " +"utilities to perform automated tasks." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:83 +msgid "" +"xref:monitoring-and-automation/OProfile.adoc[OProfile] covers " +"[application]*OProfile*, a low overhead, system-wide performance monitoring " +"tool. Read this chapter for information on how to use " +"[application]*OProfile* on your system." +msgstr "" + +#. type: Labeled list +#: ./pages/Preface.adoc:84 +#, no-wrap +msgid "" +"xref:kernel-module-driver-configuration/intro-kernel-module-driver-configuration.adoc[Kernel, " +"Module and Driver Configuration]" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:85 +msgid "" +"This part covers various tools that assist administrators with kernel " +"customization." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:87 +msgid "" +"xref:kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc[Working " +"with the GRUB 2 Boot Loader] describes the GNU GRand Unified Boot loader " +"(GRUB) version 2 boot loader, which enables selecting an operating system or " +"kernel to be loaded at system boot time." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:89 +msgid "" +"xref:kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc[Manually " +"Upgrading the Kernel] provides important information on how to manually " +"update a kernel package using the [command]#rpm# command instead of " +"[command]#dnf#. Read this chapter if you cannot update a kernel package with " +"the [application]*DNF* package manager." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:91 +msgid "" +"xref:kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc[Working " +"with Kernel Modules] explains how to display, query, load, and unload kernel " +"modules and their dependencies, and how to set module " +"parameters. Additionally, it covers specific kernel module capabilities such " +"as using multiple Ethernet cards and using channel bonding. Read this " +"chapter if you need to work with kernel modules." +msgstr "" + +#. type: Labeled list +#: ./pages/Preface.adoc:92 +#, no-wrap +msgid "xref:RPM.adoc[RPM]" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:93 +msgid "" +"This appendix concentrates on the RPM Package Manager (RPM), an open " +"packaging system used by {MAJOROS}, and the use of the [command]#rpm# " +"utility. Read this appendix if you need to use [command]#rpm# instead of " +"[command]#dnf#." +msgstr "" + +#. type: Labeled list +#: ./pages/Preface.adoc:94 +#, no-wrap +msgid "xref:Wayland.adoc[The Wayland Display Server]" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:95 +msgid "" +"This appendix looks at Wayland, a new display server used in GNOME for " +"{MAJOROS} and how to troubleshoot issues with the Wayland display server." +msgstr "" + +#. type: Labeled list +#: ./pages/Preface.adoc:96 +#, no-wrap +msgid "xref:pam_userdb.adoc[pam_userdb]" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:97 +msgid "" +"This appendix looks at pam_userdb, providing instructions on how to update " +"to the new database provider." +msgstr "" + +#. type: Title == +#: ./pages/Preface.adoc:101 +#, no-wrap +msgid "Acknowledgments" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:104 +msgid "" +"Certain portions of this text first appeared in the [citetitle]_Red{nbsp}Hat " +"Enterprise{nbsp}Linux{nbsp}7 System Administrator's Guide_, copyright © " +"2014–{YEAR} Red{nbsp}Hat, Inc., available at " +"link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/System_Administrators_Guide/index.html++[]." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:106 +msgid "" +"xref:monitoring-and-automation/System_Monitoring_Tools.adoc#sect-System_Monitoring_Tools-Net-SNMP[Monitoring " +"Performance with Net-SNMP] is based on an article written by Michael " +"Solberg." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:107 +msgid "" +"The authors of this book would like to thank the following people for their " +"valuable contributions: Adam Tkáč, Andrew Fitzsimon, Andrius Benokraitis, " +"Brian Cleary Edward Bailey, Garrett LeSage, Jeffrey Fearn, Joe Orton, Joshua " +"Wulf, Karsten Wade, Lucy Ringland, Marcela Mašláňová, Mark Johnson, Michael " +"Behm, Miroslav Lichvár, Radek Vokál, Rahul Kavalapara, Rahul Sundaram, " +"Sandra Moore, Zbyšek Mráz, Jan Včelák, Peter Hutterer, T.C. Hollingsworth, " +"and James Antill, among many others." +msgstr "" diff --git a/po/fr/rawhide/pages/RPM.po b/po/fr/rawhide/pages/RPM.po new file mode 100644 index 00000000000..78622ba170d --- /dev/null +++ b/po/fr/rawhide/pages/RPM.po @@ -0,0 +1,1250 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/RPM.adoc:5 +#, no-wrap +msgid "RPM" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:8 +msgid "" +"indexterm:[RPM Package Manager,RPM]indexterm:[RPM]indexterm:[packages,RPM] " +"The _RPM Package Manager_ ([application]*RPM*) is an open packaging system " +"that runs on {MAJOROS} as well as other Linux and UNIX systems. Red{nbsp}Hat " +"and the Fedora Project encourage other vendors to use [application]*RPM* for " +"their own products. [application]*RPM* is distributed under the terms of the " +"_GPL_ (_GNU General Public License_)." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:10 +msgid "" +"The [application]*RPM Package Manager* only works with packages built in the " +"*RPM format*. [application]*RPM* itself is provided as the pre-installed " +"[package]*rpm* package. For the end user, [application]*RPM* makes system " +"updates easy. Installing, uninstalling, and upgrading [application]*RPM* " +"packages can be accomplished with short commands. [application]*RPM* " +"maintains a database of installed packages and their files, so you can make " +"queries and verify installed files on your system. There are several " +"applications, such as [application]*DNF* or [application]*PackageKit*, that " +"can make working with packages in the [application]*RPM* format even easier." +msgstr "" + +#. type: Block title +#: ./pages/RPM.adoc:12 +#, no-wrap +msgid "Use DNF Instead of RPM Whenever Possible" +msgstr "" + +#. type: delimited block = +#: ./pages/RPM.adoc:17 +msgid "" +"indexterm:[packages,DNF instead of RPM] For most package-management tasks, " +"the [application]*DNF* package manager offers equal and often greater " +"capabilities and utility than [application]*RPM*. [application]*DNF* also " +"performs and tracks complicated system-dependency " +"resolutions. [application]*DNF* maintains the system integrity and forces a " +"system integrity check if packages are installed or removed using another " +"application, such as [application]*RPM*, instead of [application]*DNF*. For " +"these reasons, it is highly recommended that you use [application]*DNF* " +"instead of [application]*RPM* whenever possible to perform " +"package-management tasks. See xref:package-management/DNF.adoc#ch-DNF[DNF]." +msgstr "" + +#. type: delimited block = +#: ./pages/RPM.adoc:19 +msgid "" +"If you prefer a graphical interface, you can use the " +"[application]*PackageKit* GUI application, which uses [application]*DNF* as " +"its back end, to manage your system's packages." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:25 +msgid "" +"During upgrades, [application]*RPM* handles configuration files carefully, " +"so that you never lose your customizations — something that you cannot " +"accomplish with regular `.tar.gz` files. indexterm:[packages,RPM,source and " +"binary packages] For the developer, [application]*RPM* enables software " +"source code to be packaged into source and binary packages for end " +"users. This process is quite simple and is driven from a single file and " +"optional patches that you create. This clear delineation between pristine " +"sources and your patches along with build instructions eases the maintenance " +"of the package as new versions of the software are released." +msgstr "" + +#. type: Block title +#: ./pages/RPM.adoc:27 +#, no-wrap +msgid "Note" +msgstr "" + +#. type: delimited block = +#: ./pages/RPM.adoc:32 +msgid "" +"Because [application]*RPM* can make changes to the system itself, performing " +"operations like installing, upgrading, downgrading, and uninstalling binary " +"packages system-wide requires `root` privileges in most cases." +msgstr "" + +#. type: Title == +#: ./pages/RPM.adoc:36 +#, no-wrap +msgid "RPM Design Goals" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:39 +msgid "" +"indexterm:[RPM,design goals] To understand how to use [application]*RPM*, it " +"is helpful to understand the design goals of [application]*RPM*:" +msgstr "" + +#. type: Labeled list +#: ./pages/RPM.adoc:40 +#, no-wrap +msgid "indexterm:[RPM,design goals,upgradability] Upgradability" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:41 +msgid "" +"With [application]*RPM*, you can upgrade individual components of your " +"system without a complete reinstallation. When you get a new release of an " +"operating system based on [application]*RPM*, such as {MAJOROS}, you do not " +"need to reinstall a fresh copy of the operating system on your machine (as " +"you might need to with operating systems based on other packaging " +"systems). [application]*RPM* allows for intelligent, fully-automated, " +"in-place upgrades of your system. In addition, configuration files in " +"packages are preserved across upgrades, so you do not lose your " +"customizations. There are no special upgrade files needed to upgrade a " +"package because the same [application]*RPM* file is used to both install and " +"upgrade the package on the system." +msgstr "" + +#. type: Labeled list +#: ./pages/RPM.adoc:42 +#, no-wrap +msgid "indexterm:[RPM,design goals,powerful querying] Powerful Querying" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:43 +msgid "" +"[application]*RPM* is designed to provide powerful querying options. You can " +"perform searches on your copy of the database for packages or even just " +"certain files. You can also easily find out what package a file belongs to " +"and where the package came from. The files an [application]*RPM* package " +"contains are in a compressed archive, with a custom binary header containing " +"useful information about the package and its contents, allowing you to query " +"individual packages quickly and easily." +msgstr "" + +#. type: Labeled list +#: ./pages/RPM.adoc:44 +#, no-wrap +msgid "" +"indexterm:[RPM,design goals,system verification] System " +"Verification" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:45 +msgid "" +"Another powerful [application]*RPM* feature is the ability to verify " +"packages. It allows you to verify that the files installed on the system are " +"the same as the ones supplied by a given package. If an inconsistency is " +"detected, [application]*RPM* notifies you, and you can reinstall the package " +"if necessary. Any configuration files that you modified are preserved during " +"reinstallation." +msgstr "" + +#. type: Labeled list +#: ./pages/RPM.adoc:46 +#, no-wrap +msgid "indexterm:[packages,RPM,pristine sources] Pristine Sources" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:47 +msgid "" +"A crucial design goal was to allow the use of *pristine* software sources, " +"as distributed by the original authors of the software. With " +"[application]*RPM*, you have the pristine sources along with any patches " +"that were used, plus complete build instructions. This is an important " +"advantage for several reasons. For instance, if a new version of a program " +"is released, you do not necessarily have to start from scratch to get it to " +"compile. You can look at the patch to see what you *might* need to do. All " +"the compiled-in defaults, and all of the changes that were made to get the " +"software to build properly, are easily visible using this technique." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:49 +msgid "" +"The goal of keeping sources pristine may seem important only for developers, " +"but it results in higher quality software for end users." +msgstr "" + +#. type: Title == +#: ./pages/RPM.adoc:51 +#, no-wrap +msgid "Using RPM" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:54 +msgid "" +"[application]*RPM* has five basic modes of operationindexterm:[RPM,basic " +"modes] (not counting package building): installing, uninstalling, upgrading, " +"querying, and verifying. This section contains an overview of each mode. For " +"complete details and options, try [command]#rpm --help# or see " +"*rpm*(8). Also, see xref:RPM.adoc#s1-rpm-additional-resources[Additional " +"Resources] for more information on [application]*RPM*." +msgstr "" + +#. type: Title === +#: ./pages/RPM.adoc:56 +#, no-wrap +msgid "Installing and Upgrading Packages" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:59 +msgid "" +"indexterm:[RPM,installing]indexterm:[RPM,upgrading]indexterm:[packages,installing " +"RPM]indexterm:[packages,upgrading RPM]indexterm:[RPM,file name] " +"[application]*RPM* packages typically have file names in the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:62 +#, no-wrap +msgid "package_name-version-release-operating_system-CPU_architecture.rpm\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:65 +msgid "" +"For example the `tree-1.7.0-3.{PKGOS}.x86_64.rpm` file name includes the " +"package name (`tree`), version (`1.7.0`), release (`3`), operating system " +"major version (`{PKGOS}`) and *CPU* architecture (`x86_64`)." +msgstr "" + +#. type: Block title +#: ./pages/RPM.adoc:66 ./pages/RPM.adoc:359 +#, no-wrap +msgid "Important" +msgstr "" + +#. type: delimited block = +#: ./pages/RPM.adoc:71 +msgid "" +"When installing a package, ensure it is compatible with your operating " +"system and processor architecture. This can usually be determined by " +"checking the package name. For example, the file name of an " +"[application]*RPM* package compiled for the AMD64/Intel{nbsp}64 computer " +"architectures ends with `x86_64.rpm`." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:75 +msgid "" +"The [option]`-U` (or [option]`--upgrade`) option has two functions, it can " +"be used to:" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:77 +msgid "upgrade an existing package on the system to a newer version, or" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:79 +msgid "install a package if an older version is not already installed." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:81 +msgid "" +"The [command]#rpm -U _package.rpm_pass:attributes[{blank}]# command is " +"therefore able to either *upgrade* or *install*, depending on the presence " +"of an older version of _package.rpm_ on the system." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:83 +msgid "" +"Assuming the `tree-1.7.0-3.{PKGOS}.x86_64.rpm` package is in the current " +"directory, log in as `root` and type the following command at a shell prompt " +"to either upgrade or install the [package]*tree* package:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:87 +#, no-wrap +msgid "~]#{nbsp}rpm -Uvh tree-1.7.0-3.{PKGOS}.x86_64.rpm\n" +msgstr "" + +#. type: Block title +#: ./pages/RPM.adoc:90 +#, no-wrap +msgid "Use -Uvh for nicely-formatted RPM installs" +msgstr "" + +#. type: delimited block = +#: ./pages/RPM.adoc:95 +msgid "" +"The [option]`-v` and [option]`-h` options (which are combined with " +"[option]`-U`) cause [application]*rpm* to print more verbose output and " +"display a progress meter using hash signs." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:99 +msgid "" +"If the upgrade or installation is successful, the following output is " +"displayed:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:103 +#, no-wrap +msgid "" +"Preparing... ########################################### " +"[100%]\n" +" 1:tree ########################################### " +"[100%]\n" +msgstr "" + +#. type: Block title +#: ./pages/RPM.adoc:106 +#, no-wrap +msgid "Always use the -i (install) option to install new kernel packages!" +msgstr "" + +#. type: delimited block = +#: ./pages/RPM.adoc:111 +msgid "" +"[command]#rpm# provides two different options for installing packages: the " +"aforementioned [option]`-U` option (which historically stands for " +"*upgrade*), and the [option]`-i` option (which historically stands for " +"*install*). Because the [option]`-U` option includes both install and " +"upgrade functions, the use of [command]#rpm -Uvh# with all packages, *except " +"kernel packages*, is recommended." +msgstr "" + +#. type: delimited block = +#: ./pages/RPM.adoc:113 +msgid "" +"You should always use the [option]`-i` option to *install* a new kernel " +"package instead of upgrading it. This is because using the [option]`-U` " +"option to upgrade a kernel package removes the previous (older) kernel " +"package, which could render the system unable to boot if there is a problem " +"with the new kernel. Therefore, use the [command]#rpm -i " +"_kernel_package_pass:attributes[{blank}]# command to install a new kernel " +"*without replacing any older kernel packages*. For more information on " +"installing [package]*kernel* packages, see " +"xref:kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc#ch-Manually_Upgrading_the_Kernel[Manually " +"Upgrading the Kernel]." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:117 +msgid "" +"The signature of a package is checked automatically when installing or " +"upgrading a package. The signature confirms that the package was signed by " +"an authorized party. If the verification of the signature fails, an error " +"message is displayed." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:119 +msgid "" +"If you do not have the appropriate key installed to verify the signature, " +"the message contains the word `NOKEY`:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:123 +#, no-wrap +msgid "" +"warning: tree-1.7.0-3.{PKGOS}.x86_64.rpm: Header V3 RSA/SHA256 Signature, " +"key ID 431d51: NOKEY\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:126 +msgid "" +"See xref:RPM.adoc#s1-check-rpm-sig[Checking Package Signatures] for more " +"information on checking package signatures." +msgstr "" + +#. type: Title ==== +#: ./pages/RPM.adoc:128 +#, no-wrap +msgid "Replacing Already-Installed Packages" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:131 +msgid "" +"indexterm:[RPM,already installed]indexterm:[packages,RPM,already installed] " +"If a package of the same name and version is already installed, the " +"following output is displayed:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:136 +#, no-wrap +msgid "" +"Preparing... ########################################### " +"[100%]\n" +" package tree-1.7.0-3.{PKGOS}.x86_64 is already installed\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:139 +msgid "" +"To install the package anyway, use the [option]`--replacepkgs` option, which " +"tells [application]*RPM* to ignore the error:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:143 +#, no-wrap +msgid "~]#{nbsp}rpm -Uvh --replacepkgs tree-1.7.0-3.{PKGOS}.x86_64.rpm\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:146 +msgid "" +"This option is helpful if files installed from the package were deleted or " +"if you want the original configuration files to be installed." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:148 +msgid "" +"If you attempt an upgrade to an *older* version of a package (that is, if a " +"newer version of the package is already installed), [application]*RPM* " +"informs you that a newer version is already installed. To force " +"[application]*RPM* to perform the downgrade, use the [command]#--oldpackage# " +"option:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:151 +#, no-wrap +msgid "rpm -Uvh --oldpackage older_package.rpm\n" +msgstr "" + +#. type: Title ==== +#: ./pages/RPM.adoc:154 +#, no-wrap +msgid "Resolving File Conflicts" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:157 +msgid "" +"indexterm:[RPM,file " +"conflicts,resolving]indexterm:[RPM,conflicts]indexterm:[packages,RPM,conflict] " +"If you attempt to install a package that contains a file that has already " +"been installed by another package, a conflict message is displayed. To make " +"[application]*RPM* ignore this error, use the [command]#--replacefiles# " +"option:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:161 +#, no-wrap +msgid "[command]#rpm -Uvh --replacefiles _package.rpm_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Title ==== +#: ./pages/RPM.adoc:164 +#, no-wrap +msgid "Satisfying Unresolved Dependencies" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:167 +msgid "" +"indexterm:[RPM,dependencies]indexterm:[packages,dependencies]indexterm:[RPM,failed " +"dependencies]indexterm:[packages,RPM,failed dependencies] [application]*RPM* " +"packages sometimes depend on other packages, which means that they require " +"other packages to be installed to run properly. If you try to install a " +"package that has an unresolved dependency, a message about a failed " +"dependency is displayed." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:169 +msgid "" +"Find the suggested package(s) on the {MAJOROS} installation media or on one " +"of the active {MAJOROS} mirrors and add it to the installation command. To " +"determine which package contains the required file, use the " +"[option]`--whatprovides` option:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:172 +#, no-wrap +msgid "rpm -q --whatprovides \"required_file\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:175 +msgid "" +"If the package that contains _required_file_ is in the [application]*RPM* " +"database, the name of the package is displayed." +msgstr "" + +#. type: Block title +#: ./pages/RPM.adoc:177 +#, no-wrap +msgid "Warning" +msgstr "" + +#. type: delimited block = +#: ./pages/RPM.adoc:182 +msgid "" +"Although you can *force* [command]#rpm# to install a package that has an " +"unresolved dependency (using the [option]`--nodeps` option), this is *not* " +"recommended and will usually result in the installed software failing to " +"run. Installing packages with [option]`--nodeps` can cause applications to " +"misbehave or terminate unexpectedly. It can also cause serious " +"package-management problems or system failure. For these reasons, heed the " +"warnings about missing dependencies. The [application]*DNF* package manager " +"performs automatic dependency resolution and fetches dependencies from " +"on-line repositories." +msgstr "" + +#. type: Title ==== +#: ./pages/RPM.adoc:186 +#, no-wrap +msgid "Preserving Changes in Configuration Files" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:189 +msgid "" +"indexterm:[RPM,configuration file " +"changes]indexterm:[packages,RPM,configuration file " +"changes]indexterm:[RPM,configuration file changes,conf.rpmsave] Because " +"[application]*RPM* performs intelligent upgrading of packages with " +"configuration files, you may see the following message:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:193 +#, no-wrap +msgid "" +"saving pass:quotes[_/etc/configuration_file.conf_] as " +"pass:quotes[_/etc/configuration_file.conf_].rpmsave\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:196 +msgid "" +"This message means that the changes you made to the configuration file may " +"not be *forward-compatible* with the new configuration file in the package, " +"so [application]*RPM* saved your original file and installed a new one. You " +"should investigate the differences between the two configuration files and " +"resolve them as soon as possible to ensure that your system continues to " +"function properly." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:198 +msgid "" +"Alternatively, [application]*RPM* may save the package's *new* configuration " +"file as, for example, " +"`pass:attributes[{blank}]_configuration_file.conf_.rpmnew` and leave the " +"configuration file you modified untouched. You should still resolve any " +"conflicts between your modified configuration file and the new one, usually " +"by merging changes from the old one to the new one, for example using the " +"[command]#diff# program." +msgstr "" + +#. type: Title === +#: ./pages/RPM.adoc:200 +#, no-wrap +msgid "Uninstalling Packages" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:203 +msgid "" +"indexterm:[RPM,uninstalling]indexterm:[packages,removing]indexterm:[packages,RPM,uninstalling]indexterm:[packages,RPM,removing] " +"Uninstalling a package is just as simple as installing one. Type the " +"following command at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:207 +#, no-wrap +msgid "[command]#rpm -e _package_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Block title +#: ./pages/RPM.adoc:209 +#, no-wrap +msgid "rpm -e and package name errors" +msgstr "" + +#. type: delimited block = +#: ./pages/RPM.adoc:214 +msgid "" +"Note that the command expects only the package *name*, not the name of the " +"original package *file*. If you attempt to uninstall a package using the " +"[command]#rpm{nbsp}-e# command and provide the original full file name, you " +"receive a package-name error." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:218 +msgid "" +"You can encounter dependency errors when uninstalling a package if another " +"installed package depends on the one you are trying to remove. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:228 +#, no-wrap +msgid "" +"~]#{nbsp}rpm -e ghostscript\n" +"error: Failed dependencies:\n" +" ghostscript is needed by (installed) " +"ghostscript-cups-9.07-16.{PKGOS}.x86_64\n" +" ghostscript is needed by (installed) " +"foomatic-4.0.9-6.{PKGOS}.x86_64\n" +" libgs.so.9()(64bit) is needed by (installed) " +"libspectre-0.2.7-4.{PKGOS}.x86_64\n" +" libijs-0.35.so()(64bit) is needed by (installed) " +"gutenprint-5.2.9-15.{PKGOS}.x86_64\n" +" libijs-0.35.so()(64bit) is needed by (installed) " +"cups-filters-1.0.35-15.{PKGOS}.x86_64\n" +msgstr "" + +#. type: Block title +#: ./pages/RPM.adoc:231 +#, no-wrap +msgid "Warning: Forcing Package Installation" +msgstr "" + +#. type: delimited block = +#: ./pages/RPM.adoc:236 +msgid "" +"Although you can *force* [command]#rpm# to uninstall a package that has " +"unresolved dependencies (using the [option]`--nodeps` option), this is *not* " +"recommended. Removing packages with [option]`--nodeps` can cause " +"applications from the packages whose dependencies are removed to misbehave " +"or terminate unexpectedly. It can also cause serious package-management " +"problems or system failure. For these reasons, heed the warnings about " +"failed dependencies." +msgstr "" + +#. type: Title === +#: ./pages/RPM.adoc:240 +#, no-wrap +msgid "Freshening Packages" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:243 +msgid "" +"indexterm:[RPM,freshening]indexterm:[packages,RPM,freshening] Freshening is " +"similar to upgrading, except that only installed packages are upgraded. Type " +"the following command at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:247 +#, no-wrap +msgid "[command]#rpm -Fvh _package.rpm_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:250 +msgid "" +"The [option]`-F` (or [option]`--freshen`) option compares the versions of " +"the packages specified on the command line with the versions of packages " +"that are already installed on the system. When a newer version of an " +"already-installed package is processed by the [option]`--freshen` option, it " +"is upgraded to the newer version. However, the [option]`--freshen` option " +"does not install a package if no previously-installed package of the same " +"name exists. This differs from regular upgrading, as an upgrade installs all " +"specified packages regardless of whether or not older versions of the " +"packages are already installed." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:252 +msgid "" +"Freshening works for single packages or package groups. For example, " +"freshening can help if you download a large number of different packages, " +"and you only want to upgrade those packages that are already installed on " +"the system. In this case, issue the following command with the `*.rpm` " +"global expression:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:256 +#, no-wrap +msgid "~]#{nbsp}rpm -Fvh *.rpm\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:259 +msgid "" +"[application]*RPM* then automatically upgrades only those packages that are " +"already installed." +msgstr "" + +#. type: Title === +#: ./pages/RPM.adoc:261 +#, no-wrap +msgid "Querying Packages" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:264 +msgid "" +"indexterm:[RPM,querying]indexterm:[packages,RPM,querying] The " +"[application]*RPM* database stores information about all [application]*RPM* " +"packages installed on the system. It is stored in the `/var/lib/rpm/` " +"directory and is used for many things, including querying what packages are " +"installed, what version each package is, and for calculating changes to " +"files in packages since their installation. To query this database, use the " +"[command]#rpm# command with the [option]`-q` (or [option]`--query`) option:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:267 +#, no-wrap +msgid "rpm -q package_name\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:270 +msgid "" +"This command displays the package name, version, and release number of the " +"installed package _package_name_. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:275 +#, no-wrap +msgid "" +"~]${nbsp}rpm -q tree\n" +"tree-1.7.0-3.{PKGOS}.x86_64\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:278 +msgid "" +"See the `Package Selection Options` subheading in the *rpm*(8) manual page " +"for a list of options that can be used to further refine or qualify your " +"query. Use options listed below the `Package Query Options` subheading to " +"specify what information to display about the queried packages." +msgstr "" + +#. type: Title === +#: ./pages/RPM.adoc:280 +#, no-wrap +msgid "Verifying Packages" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:283 +msgid "" +"indexterm:[RPM,verifying]indexterm:[packages,RPM,verifying] Verifying a " +"package is comparing information about files on the system installed from a " +"package with the same information from the original package. Among other " +"parameters, verifying compares the file size, MD5 sum, permissions, type, " +"owner, and the group of each file." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:285 +msgid "" +"Use the [command]#rpm# command with the [option]`-V` (or [option]`--verify`) " +"option to verify packages. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:289 +#, no-wrap +msgid "~]${nbsp}pass:attributes[{blank}][command]#rpm -V tree#\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:292 +msgid "" +"See the `Package Selection Options` subheading in the *rpm*(8) manual page " +"for a list of options that can be used to further refine or qualify your " +"query. Use options listed below the `Verify Options` subheading to specify " +"what characteristics to verify in the queried packages." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:294 +msgid "" +"If everything verifies properly, there is no output. If there are any " +"discrepancies, they are displayed. The output consists of lines similar to " +"these:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:300 +#, no-wrap +msgid "" +"~]#{nbsp}rpm -V abrt\n" +"S.5....T. c /etc/abrt/abrt.conf\n" +".M....... /var/spool/abrt-upload\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:303 +msgid "" +"The format of the output is a string of nine characters followed by an " +"optional attribute marker and the name of the processed file." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:305 +msgid "" +"The first nine characters are the results of tests performed on the " +"file. Each test is the comparison of one attribute of the file to the value " +"of that attribute as recorded in the [application]*RPM* database. A single " +"period (`.`) means the test passed, and the question-mark character (`?`) " +"signifies that the test could not be performed. The following table lists " +"symbols that denote specific discrepancies:" +msgstr "" + +#. type: Block title +#: ./pages/RPM.adoc:307 ./pages/RPM.adoc:326 +#, no-wrap +msgid "RPM Verification Symbols" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:309 ./pages/RPM.adoc:328 +msgid "indexterm:[RPM,verification]" +msgstr "" + +#. type: Table +#: ./pages/RPM.adoc:321 +#, no-wrap +msgid "" +"|Symbol|Description\n" +"|`S`|file size differs\n" +"|`M`|mode differs (includes permissions and file type)\n" +"|`5`|digest (formerly MD5 sum) differs\n" +"|`D`|device major/minor number mismatch\n" +"|`L`|*readLink*(2) path mismatch\n" +"|`U`|user ownership differs\n" +"|`G`|group ownership differs\n" +"|`T`|mtime differs\n" +"|`P`|capabilities differ\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:324 +msgid "" +"The attribute marker, if present, describes the purpose of the given " +"file. The following table lists the available attribute markers:" +msgstr "" + +#. type: Table +#: ./pages/RPM.adoc:335 +#, no-wrap +msgid "" +"|Marker|Description\n" +"|`c`|configuration file\n" +"|`d`|documentation file\n" +"|`l`|license file\n" +"|`r`|readme file\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:338 +msgid "" +"If you see any output, use your best judgment to determine if you should " +"remove the package, reinstall it, or fix the problem in another way." +msgstr "" + +#. type: Title == +#: ./pages/RPM.adoc:340 +#, no-wrap +msgid "Finding and Verifying RPM Packages" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:343 +msgid "" +"indexterm:[RPM,finding and verifying RPM packages] Before using any " +"[application]*RPM* packages, you must know where to find them and be able to " +"verify if you can trust them." +msgstr "" + +#. type: Title === +#: ./pages/RPM.adoc:345 +#, no-wrap +msgid "Finding RPM Packages" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:348 +msgid "" +"indexterm:[packages,finding Fedora RPM packages]indexterm:[RPM,finding " +"Fedora RPM packages] Although there are many [application]*RPM* repositories " +"on the Internet, for security and compatibility reasons, you should consider " +"installing only official Fedora-provided RPM packages. The following is a " +"list of sources for [application]*RPM* packages:" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:352 +msgid "" +"indexterm:[{MAJOROS} installation media,installable packages] " +"indexterm:[packages,{MAJOROS} installation media] Official {MAJOROS} " +"installation media." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:356 +msgid "" +"indexterm:[initial RPM repositories,installable packages] " +"indexterm:[packages,initial RPM repositories] Official [application]*RPM* " +"repositories provided with the [application]*DNF* package manager. See " +"xref:package-management/DNF.adoc#ch-DNF[DNF] for details on how to use the " +"official {MAJOROS} package repositories." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:358 +msgid "" +"Unofficial, third-party repositories not affiliated with {OSORG} also " +"provide RPM packages." +msgstr "" + +#. type: delimited block = +#: ./pages/RPM.adoc:364 +msgid "" +"When considering third-party repositories for use with your {MAJOROS} " +"system, pay close attention to the repository's web site with regard to " +"package compatibility before adding the repository as a package " +"source. Alternate package repositories may offer different, incompatible " +"versions of the same software, including packages already included in the " +"{MAJOROS} repositories." +msgstr "" + +#. type: Title === +#: ./pages/RPM.adoc:368 +#, no-wrap +msgid "Checking Package Signatures" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:371 +msgid "" +"indexterm:[RPM,GnuPG]indexterm:[RPM,checking package " +"signatures]indexterm:[GnuPG,checking RPM package signatures] " +"[application]*RPM* packages can be signed using [application]*GNU Privacy " +"Guard* (or [application]*GPG*), which helps you make certain that downloaded " +"packages are trustworthy. [application]*GPG* is a tool for secure " +"communication. With [application]*GPG*, you can authenticate the validity of " +"documents and encrypt or decrypt data." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:373 +msgid "" +"To verify that a package has not been corrupted or tampered with, check its " +"[application]*GPG* signature by using the [command]#rpmkeys# command with " +"the [option]`-K` (or [option]`--checksig`) option:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:377 +#, no-wrap +msgid "[command]#rpmkeys -K _package.rpm_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:380 +msgid "" +"Note that the [application]*DNF* package manager performs automatic checking " +"of [application]*GPG* signatures during installations and upgrades." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:382 +msgid "" +"[application]*GPG* is installed by default, as well as a set of Red{nbsp}Hat " +"keys for verifying packages. To import additional keys for use with " +"[application]*RPM*, see xref:RPM.adoc#s2-keys-importing[Importing GPG Keys]." +msgstr "" + +#. type: Title ==== +#: ./pages/RPM.adoc:384 +#, no-wrap +msgid "Importing GPG Keys" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:387 +msgid "" +"To verify Red Hat packages, a Red{nbsp}Hat [application]*GPG* key needs to " +"be installed. A set of basic keys is installed by default. To view a list of " +"installed keys, execute the following command at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:391 +#, no-wrap +msgid "~]${nbsp}rpm -qa gpg-pubkey*\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:394 +msgid "" +"To display details about a specific key, use [command]#rpm{nbsp}-qi# " +"followed by the output from the previous command. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:398 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#rpm -qi " +"gpg-pubkey-fd431d51-4ae0493b#\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:401 +msgid "" +"Use the [command]#rpmkeys# command with the [option]`--import` option to " +"install a new key for use with [application]*RPM*. The default location for " +"storing [application]*RPM* *GPG* keys is the `/etc/pki/rpm-gpg/` " +"directory. To import new keys, use a command like the following as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:405 +#, no-wrap +msgid "~]#{nbsp}rpmkeys --import /etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:408 +msgid "" +"See the link:++https://access.redhat.com/security/team/key/++[Product " +"Signing (GPG) Keys] article on the Red{nbsp}Hat Customer{nbsp}Portal for " +"additional information about Red{nbsp}Hat package-signing practices." +msgstr "" + +#. type: Title == +#: ./pages/RPM.adoc:410 +#, no-wrap +msgid "Common Examples of RPM Usage" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:413 +msgid "" +"indexterm:[RPM,tips]indexterm:[packages,RPM,tips] [application]*RPM* is a " +"useful tool for both managing your system and diagnosing and fixing " +"problems. See the following examples for an overview of some of the " +"most-used options." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:416 +msgid "" +"To verify your entire system and see what files are missing, issue the " +"following command as `root`: indexterm:[RPM,finding deleted files " +"with]indexterm:[packages,finding deleted files from]" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:420 +#, no-wrap +msgid "[command]#rpm -Va#\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:423 +msgid "" +"If some files are missing or appear corrupted, consider reinstalling " +"relevant packages." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:426 +msgid "" +"To determine which package owns a file, enter: indexterm:[RPM,determining " +"file ownership with]indexterm:[packages,determining file ownership with]" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:430 +#, no-wrap +msgid "[command]#rpm -qf _file_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:433 +msgid "To verify the package that owns a particular file, enter as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:437 +#, no-wrap +msgid "[command]#rpm -Vf _file_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:441 +msgid "" +"To locate documentation files that are a part of a package to which a file " +"belongs, enter: indexterm:[RPM,documentation " +"with]indexterm:[packages,locating documentation " +"for]indexterm:[documentation,finding installed]" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:445 +#, no-wrap +msgid "[command]#rpm -qdf _file_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:449 +msgid "" +"To find information about a (non-installed) package file, use the following " +"command: indexterm:[RPM,querying uninstalled " +"packages]indexterm:[packages,querying uninstalled]" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:453 +#, no-wrap +msgid "[command]#rpm -qip _package.rpm_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:457 +msgid "" +"To list files contained in a package, use: indexterm:[RPM,querying for file " +"list]indexterm:[packages,obtaining list of files]" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:461 +#, no-wrap +msgid "[command]#rpm -qlp _package.rpm_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:464 +msgid "See the *rpm*(8) manual page for more options." +msgstr "" + +#. type: Title == +#: ./pages/RPM.adoc:466 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:469 +msgid "" +"indexterm:[RPM,additional resources] [application]*RPM* is a complex utility " +"with many options and methods for querying, installing, upgrading, and " +"removing packages. See the following resources to learn more about " +"[application]*RPM*." +msgstr "" + +#. type: Block title +#: ./pages/RPM.adoc:470 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:473 +msgid "" +"[command]#rpm --help# — This command displays a quick reference of " +"[application]*RPM* parameters." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:475 +#, no-wrap +msgid "" +"*rpm*(8) — The [application]*RPM* manual page offers an overview of all " +"available [application]*RPM* parameters.\n" +msgstr "" + +#. type: Block title +#: ./pages/RPM.adoc:476 +#, no-wrap +msgid "Online Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:479 +msgid "indexterm:[RPM,website]indexterm:[RPM,online documentation]" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:481 +msgid "The [application]*RPM* website — link:++https://rpm.org++[]" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:483 +msgid "" +"The [application]*RPM* mailing list — " +"link:++http://lists.rpm.org/mailman/listinfo/rpm-list++[]" +msgstr "" + +#. type: Block title +#: ./pages/RPM.adoc:484 +#, no-wrap +msgid "See Also" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:487 +msgid "indexterm:[RPM,see also]" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:488 +msgid "" +"xref:package-management/DNF.adoc#ch-DNF[DNF] describes how to use the " +"[application]*DNF* package manager to search, install, update, and uninstall " +"packages on the command line." +msgstr "" diff --git a/po/fr/rawhide/pages/Revision_History.po b/po/fr/rawhide/pages/Revision_History.po new file mode 100644 index 00000000000..6e30e34877b --- /dev/null +++ b/po/fr/rawhide/pages/Revision_History.po @@ -0,0 +1,262 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/Revision_History.adoc:5 +#, no-wrap +msgid "Revision History" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:8 +msgid "" +"Note that revision numbers relate to the edition of this manual, not to " +"version numbers of Fedora." +msgstr "" + +#. type: Labeled list +#: ./pages/Revision_History.adoc:9 +#, no-wrap +msgid "`1-10`" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:10 +msgid "Tue Oct 30 2018, Petr Bokoč (pbokoc@redhat.com)" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:12 +msgid "Fedora 29 Final release" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:14 +msgid "" +"All external links are now converted to HTTPS where applicable " +"(link:++https://pagure.io/fedora-docs/system-administrators-guide/issue/7++[issue " +"7])" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:16 +msgid "" +"The chapter about *anacron* now mentions that it won't run by default when " +"the system is being powered by a battery " +"(link:++https://pagure.io/fedora-docs/system-administrators-guide/issue/8++[issue " +"8])" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:18 +msgid "" +"Fixed a keyring name in the Kernel Module Authentication chapter " +"(link:++https://pagure.io/fedora-docs/system-administrators-guide/issue/11++[issue " +"11])" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:20 +msgid "Removed mentions of *rsyslog* as a default syslog" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:22 +msgid "Various fixes related to the new publishing system" +msgstr "" + +#. type: Labeled list +#: ./pages/Revision_History.adoc:23 +#, no-wrap +msgid "`1-9`" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:24 +#, no-wrap +msgid "Sun Jun 25, 2017, Ryan (t3rm1n4l@fedoraproject.org)\n" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:26 +msgid "" +"Converted document to asciidocs, updated table refs, removed manual line " +"breaks, fixed formatting and some grammar" +msgstr "" + +#. type: Labeled list +#: ./pages/Revision_History.adoc:27 +#, no-wrap +msgid "`1-8`" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:28 +msgid "Mon Nov 14 2016, Petr Bokoč (pbokoc@redhat.com)" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:30 +msgid "Fedora 25 release of the [citetitle]_System Administrator's Guide_." +msgstr "" + +#. type: Labeled list +#: ./pages/Revision_History.adoc:31 +#, no-wrap +msgid "`1-7`" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:32 +msgid "Tue June 21 2016, Stephen Wadeley (swadeley@redhat.com)" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:34 +msgid "Fedora 24 release of the [citetitle]_System Administrator's Guide_." +msgstr "" + +#. type: Labeled list +#: ./pages/Revision_History.adoc:35 +#, no-wrap +msgid "`1-5`" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:36 +msgid "Mon Nov 02 2015, Stephen Wadeley (swadeley@redhat.com)" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:38 +msgid "Fedora 23 release of the [citetitle]_System Administrator's Guide_." +msgstr "" + +#. type: Labeled list +#: ./pages/Revision_History.adoc:39 +#, no-wrap +msgid "`1-4.1`" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:40 +msgid "Tue Oct 27 2015, Stephen Wadeley (swadeley@redhat.com)" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:42 +msgid "" +"Added \"`Gaining Privileges`\" chapter, \"`Using OpenSSH Certificate " +"Authentication`\" section, and made improvements to the GRUB 2 chapter." +msgstr "" + +#. type: Labeled list +#: ./pages/Revision_History.adoc:43 +#, no-wrap +msgid "`1-4`" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:44 +msgid "Mon May 25 2015, Stephen Wadeley (swadeley@redhat.com)" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:46 +msgid "Fedora 22 release of the [citetitle]_System Administrator's Guide_." +msgstr "" + +#. type: Labeled list +#: ./pages/Revision_History.adoc:47 +#, no-wrap +msgid "`1-3`" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:48 +msgid "Mon Apr 4 2015, Stephen Wadeley (swadeley@redhat.com)" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:50 +msgid "Replaced Yum chapter with DNF chapter." +msgstr "" + +#. type: Labeled list +#: ./pages/Revision_History.adoc:51 +#, no-wrap +msgid "`1-2.1`" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:52 +msgid "Wed Mar 4 2015, Stephen Wadeley (swadeley@redhat.com)" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:54 +msgid "Added \"`Working with the GRUB 2 Boot Loader`\" chapter." +msgstr "" + +#. type: Labeled list +#: ./pages/Revision_History.adoc:55 +#, no-wrap +msgid "`1-2`" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:56 +msgid "Tue Dec 9 2014, Stephen Wadeley (swadeley@redhat.com)" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:58 +msgid "Fedora 21 release of the [citetitle]_System Administrator's Guide_." +msgstr "" + +#. type: Labeled list +#: ./pages/Revision_History.adoc:59 +#, no-wrap +msgid "`1-1`" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:60 +msgid "Thu Aug 9 2012, Jaromír Hradílek (jhradilek@redhat.com)" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:62 +msgid "Updated Network Interfaces." +msgstr "" + +#. type: Labeled list +#: ./pages/Revision_History.adoc:63 +#, no-wrap +msgid "`1-0`" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:64 +msgid "Tue May 29 2012, Jaromír Hradílek (jhradilek@redhat.com)" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:65 +msgid "Fedora 17 release of the [citetitle]_System Administrator's Guide_." +msgstr "" diff --git a/po/fr/rawhide/pages/Wayland.po b/po/fr/rawhide/pages/Wayland.po new file mode 100644 index 00000000000..731fd7c3e89 --- /dev/null +++ b/po/fr/rawhide/pages/Wayland.po @@ -0,0 +1,143 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/Wayland.adoc:6 +#, no-wrap +msgid "The Wayland Protocol" +msgstr "" + +#. type: Plain text +#: ./pages/Wayland.adoc:9 +msgid "" +"Wayland is a display server protocol which was (at the time of writing) " +"introduced as the default in GNOME. It is said that Wayland will eventually " +"replace X11 as the default display server on Linux and many distributions " +"have begun implementation of Wayland. Wayland is a more modern protocol and " +"has a smaller code base currently. Wayland is still under development, and " +"there are still applications and behaviours that don't work as expected, you " +"may find that some applications have not been updated to work properly in " +"Wayland and currently the only way these applications will run is using Xorg " +"instead of Wayland. This includes some legacy system applications and games." +msgstr "" + +#. type: Plain text +#: ./pages/Wayland.adoc:11 +msgid "" +"Wayland is enabled by default in the GNOME Desktop. You can choose to run " +"GNOME in X11 by choosing the Gnome on xorg option in the session chooser on " +"the login screen. Currently KDE still uses X11 and although there is a " +"plasma-wayland session available, it is not considered stable or bugfree at " +"this time." +msgstr "" + +#. type: Title == +#: ./pages/Wayland.adoc:12 +#, no-wrap +msgid "Determining whether you are using Wayland" +msgstr "" + +#. type: Plain text +#: ./pages/Wayland.adoc:14 +msgid "" +"One way to determine if you're running in Wayland, is to check the value of " +"the variable $WAYLAND_DISPLAY. To do this type:" +msgstr "" + +#. type: delimited block - +#: ./pages/Wayland.adoc:19 +#, no-wrap +msgid "" +"$ echo $WAYLAND_DISPLAY\n" +"wayland-0\n" +msgstr "" + +#. type: Plain text +#: ./pages/Wayland.adoc:22 +msgid "" +"If you are not running under Wayland the variable will not contain any " +"values. You can also use loginctl to show you what type of session is " +"running:" +msgstr "" + +#. type: delimited block - +#: ./pages/Wayland.adoc:26 +#, no-wrap +msgid "$ loginctl show-session -p Type\n" +msgstr "" + +#. type: Plain text +#: ./pages/Wayland.adoc:29 +msgid "" +"To determine your session number, simply typing `loginctl` should provide " +"your session details." +msgstr "" + +#. type: Plain text +#: ./pages/Wayland.adoc:31 +msgid "" +"There is also a legacy X11 server provided with Wayland for compatibility " +"purposes. To determine what applications are running in this mode, you can " +"run the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/Wayland.adoc:35 +#, no-wrap +msgid "$ xlsclients\n" +msgstr "" + +#. type: Plain text +#: ./pages/Wayland.adoc:38 +msgid "" +"There is also the `lg` (looking glass) tool in GNOME that will allow you to " +"determine which protocol a specific window is using. To do this, you run the " +"application by typing `lg` in the run dialog or at the command line, select " +"\"`Windows`\" in the upper right corner of the tool, and click on the " +"application name (or open window) you want to know about. If the window is " +"running in wayland it will say \"`MetaWindowWayland`\" and if it is running " +"in X11 it will say \"`MetaWindowX11`\"." +msgstr "" + +#. type: Title == +#: ./pages/Wayland.adoc:39 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/Wayland.adoc:41 +msgid "To find out more about Wayland, please see the following website:" +msgstr "" + +#. type: Plain text +#: ./pages/Wayland.adoc:43 +msgid "https://wayland.freedesktop.org/" +msgstr "" + +#. type: Plain text +#: ./pages/Wayland.adoc:45 +msgid "" +"If you need to determine if an issue you are experiencing is related to " +"wayland, see the Fedora wiki at the link below:" +msgstr "" + +#. type: Plain text +#: ./pages/Wayland.adoc:46 +msgid "https://fedoraproject.org/wiki/How_to_debug_Wayland_problems" +msgstr "" diff --git a/po/fr/rawhide/pages/_partials/Author_Group.po b/po/fr/rawhide/pages/_partials/Author_Group.po new file mode 100644 index 00000000000..2cb1f32e597 --- /dev/null +++ b/po/fr/rawhide/pages/_partials/Author_Group.po @@ -0,0 +1,151 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Block title +#: ./pages/_partials/Author_Group.adoc:1 +#, no-wrap +msgid "Stephen Wadeley" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Author_Group.adoc:5 ./pages/_partials/Author_Group.adoc:12 +#: ./pages/_partials/Author_Group.adoc:26 +#: ./pages/_partials/Author_Group.adoc:33 +#: ./pages/_partials/Author_Group.adoc:40 +#: ./pages/_partials/Author_Group.adoc:47 +#: ./pages/_partials/Author_Group.adoc:52 +#: ./pages/_partials/Author_Group.adoc:57 +#: ./pages/_partials/Author_Group.adoc:62 +#: ./pages/_partials/Author_Group.adoc:67 +#: ./pages/_partials/Author_Group.adoc:72 +#: ./pages/_partials/Author_Group.adoc:76 +#, no-wrap +msgid "" +"*Red Hat*\n" +"Customer Content Services\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Author_Group.adoc:7 +msgid "swadeley@redhat.com" +msgstr "" + +#. type: Block title +#: ./pages/_partials/Author_Group.adoc:8 +#, no-wrap +msgid "Jaromír Hradílek" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Author_Group.adoc:14 +msgid "jhradilek@redhat.com" +msgstr "" + +#. type: Block title +#: ./pages/_partials/Author_Group.adoc:15 +#, no-wrap +msgid "Petr Bokoč" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Author_Group.adoc:19 +#, no-wrap +msgid "" +"*Red{nbsp}Hat*\n" +"Customer Content Services\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Author_Group.adoc:21 +msgid "pbokoc@redhat.com" +msgstr "" + +#. type: Block title +#: ./pages/_partials/Author_Group.adoc:22 +#, no-wrap +msgid "Petr Kovář" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Author_Group.adoc:28 +msgid "pkovar@redhat.com" +msgstr "" + +#. type: Block title +#: ./pages/_partials/Author_Group.adoc:29 +#, no-wrap +msgid "Tomáš Čapek" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Author_Group.adoc:35 +msgid "tcapek@redhat.com" +msgstr "" + +#. type: Block title +#: ./pages/_partials/Author_Group.adoc:36 +#, no-wrap +msgid "Douglas Silas" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Author_Group.adoc:42 +msgid "silas@redhat.com" +msgstr "" + +#. type: Block title +#: ./pages/_partials/Author_Group.adoc:43 +#, no-wrap +msgid "Martin Prpič" +msgstr "" + +#. type: Block title +#: ./pages/_partials/Author_Group.adoc:48 +#, no-wrap +msgid "Eliška Slobodová" +msgstr "" + +#. type: Block title +#: ./pages/_partials/Author_Group.adoc:53 +#, no-wrap +msgid "Miroslav Svoboda" +msgstr "" + +#. type: Block title +#: ./pages/_partials/Author_Group.adoc:58 +#, no-wrap +msgid "John Ha" +msgstr "" + +#. type: Block title +#: ./pages/_partials/Author_Group.adoc:63 +#, no-wrap +msgid "David O'Brien" +msgstr "" + +#. type: Block title +#: ./pages/_partials/Author_Group.adoc:68 +#, no-wrap +msgid "Michael Hideo" +msgstr "" + +#. type: Block title +#: ./pages/_partials/Author_Group.adoc:73 +#, no-wrap +msgid "Don Domingo" +msgstr "" diff --git a/po/fr/rawhide/pages/_partials/Feedback.po b/po/fr/rawhide/pages/_partials/Feedback.po new file mode 100644 index 00000000000..ad411271378 --- /dev/null +++ b/po/fr/rawhide/pages/_partials/Feedback.po @@ -0,0 +1,81 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title == +#: ./pages/_partials/Feedback.adoc:5 +#, no-wrap +msgid "We want feedback" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Feedback.adoc:8 +msgid "" +"indexterm:[feedback,contact information for this manual] If you find errors " +"or have suggestions for improvement, we want your advice. Open an issue at " +"{BZURL}." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Feedback.adoc:10 +msgid "In the issue:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Feedback.adoc:12 +msgid "" +"Provide a short summary of the error or your suggestion in the `Issue Title` " +"field." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Feedback.adoc:14 +msgid "" +"Copy the following template into the `Comment` field and give us the details " +"of the error or suggestion as specifically as you can. If possible, include " +"some surrounding text so we know where the error occurs or the suggestion " +"fits." +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/Feedback.adoc:18 +#, no-wrap +msgid "Document URL:\n" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/Feedback.adoc:20 +#, no-wrap +msgid "Section name:\n" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/Feedback.adoc:22 +#, no-wrap +msgid "Error or suggestion:\n" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/Feedback.adoc:24 +#, no-wrap +msgid "Additional information:\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Feedback.adoc:27 +msgid "Click the btn:[Create Issue] button." +msgstr "" diff --git a/po/fr/rawhide/pages/_partials/Legal_Notice.po b/po/fr/rawhide/pages/_partials/Legal_Notice.po new file mode 100644 index 00000000000..e8a7be041c9 --- /dev/null +++ b/po/fr/rawhide/pages/_partials/Legal_Notice.po @@ -0,0 +1,93 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Plain text +#: ./pages/_partials/Legal_Notice.adoc:5 +msgid "Copyright {YEAR} {HOLDER}." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Legal_Notice.adoc:7 +msgid "" +"The text of and illustrations in this document are licensed by Red Hat under " +"a Creative Commons Attribution–Share Alike 3.0 Unported license " +"(“CC-BY-SA”). An explanation of CC-BY-SA is available at " +"link:++https://creativecommons.org/licenses/by-sa/3.0/++[]. The original " +"authors of this document, and Red Hat, designate the Fedora Project as the " +"“`Attribution Party`” for purposes of CC-BY-SA. In accordance with CC-BY-SA, " +"if you distribute this document or an adaptation of it, you must provide the " +"URL for the original version." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Legal_Notice.adoc:9 +msgid "" +"Red Hat, as the licensor of this document, waives the right to enforce, and " +"agrees not to assert, Section 4d of CC-BY-SA to the fullest extent permitted " +"by applicable law." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Legal_Notice.adoc:11 +msgid "" +"Red Hat, Red Hat Enterprise Linux, the Shadowman logo, JBoss, MetaMatrix, " +"Fedora, the Infinity Logo, and RHCE are trademarks of Red Hat, Inc., " +"registered in the United States and other countries." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Legal_Notice.adoc:13 +msgid "" +"For guidelines on the permitted uses of the Fedora trademarks, refer to " +"link:++https://fedoraproject.org/wiki/Legal:Trademark_guidelines++[]." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Legal_Notice.adoc:15 +#, no-wrap +msgid "" +"*Linux* (R) is the registered trademark of Linus Torvalds in the United " +"States and other countries.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Legal_Notice.adoc:17 +#, no-wrap +msgid "*Java* (R) is a registered trademark of Oracle and/or its affiliates.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Legal_Notice.adoc:19 +#, no-wrap +msgid "" +"*XFS* (R) is a trademark of Silicon Graphics International Corp. or its " +"subsidiaries in the United States and/or other countries.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Legal_Notice.adoc:21 +#, no-wrap +msgid "" +"*MySQL* (R) is a registered trademark of MySQL AB in the United States, the " +"European Union and other countries.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Legal_Notice.adoc:22 +msgid "All other trademarks are the property of their respective owners." +msgstr "" diff --git a/po/fr/rawhide/pages/_partials/entities.po b/po/fr/rawhide/pages/_partials/entities.po new file mode 100644 index 00000000000..ab56d661a0f --- /dev/null +++ b/po/fr/rawhide/pages/_partials/entities.po @@ -0,0 +1,18 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + diff --git a/po/fr/rawhide/pages/_partials/servers/FTP.po b/po/fr/rawhide/pages/_partials/servers/FTP.po new file mode 100644 index 00000000000..5ca6457ccd1 --- /dev/null +++ b/po/fr/rawhide/pages/_partials/servers/FTP.po @@ -0,0 +1,1658 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title == +#: ./pages/_partials/servers/FTP.adoc:3 +#, no-wrap +msgid "FTP" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:6 +msgid "" +"indexterm:[FTP,definition of]indexterm:[FTP,vsftpd] _File Transfer Protocol_ " +"(`FTP`) is one of the oldest and most commonly used protocols found on the " +"Internet today. Its purpose is to reliably transfer files between computer " +"hosts on a network without requiring the user to log directly into the " +"remote host or have knowledge of how to use the remote system. It allows " +"users to access files on remote systems using a standard set of simple " +"commands." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:8 +msgid "" +"This section outlines the basics of the `FTP` protocol, as well as " +"configuration options for the primary `FTP` server shipped with {MAJOROS}, " +"[command]#vsftpd#." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/FTP.adoc:10 +#, no-wrap +msgid "The File Transfer Protocol" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:13 +msgid "" +"indexterm:[FTP,introducing] However, because `FTP` is so prevalent on the " +"Internet, it is often required to share files to the public. System " +"administrators, therefore, should be aware of the `FTP` protocol's unique " +"characteristics." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/FTP.adoc:15 +#, no-wrap +msgid "Multiple Ports, Multiple Modes" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:18 +msgid "" +"indexterm:[FTP,command port]indexterm:[FTP,data port]indexterm:[FTP,active " +"mode]indexterm:[FTP,passive mode] Unlike most protocols used on the " +"Internet, `FTP` requires multiple network ports to work properly. When an " +"`FTP` client application initiates a connection to an `FTP` server, it opens " +"port 21 on the server — known as the _command port_. This port is used to " +"issue all commands to the server. Any data requested from the server is " +"returned to the client via a _data port_. The port number for data " +"connections, and the way in which data connections are initialized, vary " +"depending upon whether the client requests the data in _active_ or _passive_ " +"mode." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:20 +msgid "The following defines these modes:" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/FTP.adoc:21 +#, no-wrap +msgid "active mode" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:22 +msgid "" +"Active mode is the original method used by the `FTP` protocol for " +"transferring data to the client application. When an active mode data " +"transfer is initiated by the `FTP` client, the server opens a connection " +"from port 20 on the server to the `IP` address and a random, unprivileged " +"port (greater than 1024) specified by the client. This arrangement means " +"that the client machine must be allowed to accept connections over any port " +"above 1024. With the growth of insecure networks, such as the Internet, the " +"use of firewalls to protect client machines is now prevalent. Because these " +"client-side firewalls often deny incoming connections from active mode `FTP` " +"servers, passive mode was devised." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/FTP.adoc:23 +#, no-wrap +msgid "passive mode" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:24 +msgid "" +"Passive mode, like active mode, is initiated by the `FTP` client " +"application. When requesting data from the server, the `FTP` client " +"indicates it wants to access the data in passive mode and the server " +"provides the `IP` address and a random, unprivileged port (greater than " +"1024) on the server. The client then connects to that port on the server to " +"download the requested information." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:26 +msgid "" +"While passive mode resolves issues for client-side firewall interference " +"with data connections, it can complicate administration of the server-side " +"firewall. You can reduce the number of open ports on a server by limiting " +"the range of unprivileged ports on the `FTP` server. This also simplifies " +"the process of configuring firewall rules for the server. See " +"xref:File_and_Print_Servers.adoc#s3-ftp-vsftpd-conf-opt-net[Network Options] " +"for more information about limiting passive ports." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/FTP.adoc:28 +#, no-wrap +msgid "FTP Servers" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:31 +msgid "" +"indexterm:[FTP,server software,vsftpd]indexterm:[FTP,server software,Red Hat " +"Content Accelerator]indexterm:[vsftpd,FTP]indexterm:[vsftpd,security " +"features] {MAJOROS} ships with two different `FTP` servers:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:33 +msgid "[command]#proftpd# - A fast, stable, and highly configurable FTP server." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:35 +msgid "" +"[command]#vsftpd# — A fast, secure `FTP` daemon which is the preferred `FTP` " +"server for {MAJOROS}. The remainder of this section focuses on " +"[command]#vsftpd#." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/FTP.adoc:37 +#, no-wrap +msgid "[command]#vsftpd#" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:40 +msgid "" +"_The Very Secure FTP Daemon_ ([command]#vsftpd#) is designed from the ground " +"up to be fast, stable, and, most importantly, secure. [command]#vsftpd# is " +"the only stand-alone `FTP` server distributed with {MAJOROS}, due to its " +"ability to handle large numbers of connections efficiently and securely." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:42 +msgid "The security model used by [command]#vsftpd# has three primary aspects:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:44 +#, no-wrap +msgid "" +"*Strong separation of privileged and non-privileged processes* — Separate " +"processes handle different tasks, and each of these processes run with the " +"minimal privileges required for the task.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:46 +#, no-wrap +msgid "" +"*Tasks requiring elevated privileges are handled by processes with the " +"minimal privilege necessary* — By leveraging compatibilities found in the " +"`libcap` library, tasks that usually require full `root` privileges can be " +"executed more safely from a less privileged process.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:48 +#, no-wrap +msgid "" +"*Most processes run in a [command]#chroot# jail* — Whenever possible, " +"processes are change-rooted to the directory being shared; this directory is " +"then considered a [command]#chroot# jail. For example, if the directory " +"[command]#/var/ftp/# is the primary shared directory, [command]#vsftpd# " +"reassigns [command]#/var/ftp/# to the new root directory, known as " +"[command]#/#. This disallows any potential malicious hacker activities for " +"any directories not contained below the new root directory.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:50 +msgid "" +"Use of these security practices has the following effect on how " +"[command]#vsftpd# deals with requests:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:52 +#, no-wrap +msgid "" +"*The parent process runs with the least privileges required* — The parent " +"process dynamically calculates the level of privileges it requires to " +"minimize the level of risk. Child processes handle direct interaction with " +"the `FTP` clients and run with as close to no privileges as possible.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:54 +#, no-wrap +msgid "" +"*All operations requiring elevated privileges are handled by a small parent " +"process* — Much like the Apache `HTTP` Server, [command]#vsftpd# launches " +"unprivileged child processes to handle incoming connections. This allows the " +"privileged, parent process to be as small as possible and handle relatively " +"few tasks.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:56 +#, no-wrap +msgid "" +"*All requests from unprivileged child processes are distrusted by the parent " +"process* — Communication with child processes are received over a socket, " +"and the validity of any information from child processes is checked before " +"being acted on.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:58 +#, no-wrap +msgid "" +"*Most interaction with `FTP` clients is handled by unprivileged child " +"processes in a [command]#chroot# jail* — Because these child processes are " +"unprivileged and only have access to the directory being shared, any crashed " +"processes only allows the attacker access to the shared files.\n" +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/FTP.adoc:60 +#, no-wrap +msgid "Files Installed with [command]#vsftpd#" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:63 +msgid "" +"indexterm:[vsftpd,RPM,files installed by] The `vsftpd` RPM installs the " +"daemon (`/usr/sbin/vsftpd`), its configuration and related files, as well as " +"`FTP` directories onto the system. The following lists the files and " +"directories related to [command]#vsftpd# configuration:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:65 +msgid "" +"`/etc/rc.d/init.d/vsftpd` — The *initialization script* (_initscript_) used " +"by the [command]#systemctl# command to start, stop, or reload " +"[command]#vsftpd#. See " +"xref:File_and_Print_Servers.adoc#s2-ftp-vsftpd-start[Starting and Stopping " +"[command]#vsftpd#] for more information about using this script." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:67 +msgid "" +"`/etc/pam.d/vsftpd` — The Pluggable Authentication Modules (PAM) " +"configuration file for [command]#vsftpd#. This file specifies the " +"requirements a user must meet to login to the `FTP` server. For more " +"information on PAM, refer to the [citetitle]_Using Pluggable Authentication " +"Modules (PAM)_ chapter of the {MAJOROSVER} [citetitle]_Managing Single " +"Sign-On and Smart Cards_ guide." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:69 +msgid "" +"`/etc/vsftpd/vsftpd.conf` — The configuration file for " +"[command]#vsftpd#. See " +"xref:File_and_Print_Servers.adoc#s2-ftp-vsftpd-conf[[command]#vsftpd# " +"Configuration Options] for a list of important options contained within this " +"file." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:71 +msgid "" +"`/etc/vsftpd/ftpusers` — A list of users not allowed to log into " +"[command]#vsftpd#. By default, this list includes the `root`, `bin`, and " +"`daemon` users, among others." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:73 +msgid "" +"`/etc/vsftpd/user_list` — This file can be configured to either deny or " +"allow access to the users listed, depending on whether the " +"[command]#userlist_deny# directive is set to [command]#YES# (default) or " +"[command]#NO# in `/etc/vsftpd/vsftpd.conf`. If `/etc/vsftpd/user_list` is " +"used to grant access to users, the usernames listed must *not* appear in " +"`/etc/vsftpd/ftpusers`." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:75 +msgid "" +"`/var/ftp/` — The directory containing files served by [command]#vsftpd#. It " +"also contains the `/var/ftp/pub/` directory for anonymous users. Both " +"directories are world-readable, but writable only by the `root` user." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/FTP.adoc:77 +#, no-wrap +msgid "Starting and Stopping [command]#vsftpd#" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:80 +msgid "" +"indexterm:[vsftpd,starting]indexterm:[vsftpd,stopping]indexterm:[vsftpd,status]indexterm:[vsftpd,condrestart]indexterm:[vsftpd,restarting] " +"The `vsftpd` RPM installs the `/etc/rc.d/init.d/vsftpd` script, which can be " +"accessed using the [command]#systemctl# command." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:82 +msgid "To start the server, as `root` type:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/FTP.adoc:86 +#, no-wrap +msgid "[command]#systemctl start vsftpd.service#\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:89 +msgid "To stop the server, as `root` type:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/FTP.adoc:93 +#, no-wrap +msgid "[command]#systemctl stop vsftpd.service#\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:96 +msgid "" +"The [option]`restart` option is a shorthand way of stopping and then " +"starting [command]#vsftpd#. This is the most efficient way to make " +"configuration changes take effect after editing the configuration file for " +"[command]#vsftpd#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:98 +msgid "To restart the server, as `root` type:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/FTP.adoc:102 +#, no-wrap +msgid "[command]#systemctl restart vsftpd.service#\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:105 +msgid "" +"The [option]`condrestart` (_conditional restart_) option only starts " +"[command]#vsftpd# if it is currently running. This option is useful for " +"scripts, because it does not start the daemon if it is not running." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:107 +msgid "To conditionally restart the server, as `root` type:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/FTP.adoc:111 +#, no-wrap +msgid "[command]#systemctl condrestart vsftpd.service#\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:114 +msgid "" +"By default, the [command]#vsftpd# service does *not* start automatically at " +"boot time. To configure the [command]#vsftpd# service to start at boot time, " +"use a service manager such as [command]#systemctl#. See " +"xref:infrastructure-services/Services_and_Daemons.adoc#ch-Services_and_Daemons[Services " +"and Daemons] for more information on how to configure services in {MAJOROS}." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/FTP.adoc:116 +#, no-wrap +msgid "Configuring the Firewall for FTP" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:118 +msgid "" +"By default, `firewalld` blocks incoming FTP connections. To allow FTP " +"connections, as `root` type:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/FTP.adoc:122 +#, no-wrap +msgid "[command]#firewall-cmd --add-service=ftp#\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:125 +msgid "" +"The change will be applied immediately, but will be lost next time " +"`firewalld` is reloaded or the system restarted. To make it permanent, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/FTP.adoc:129 +#, no-wrap +msgid "[command]#firewall-cmd --permanent --add-service=ftp#\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:132 +msgid "" +"For more information on configuring `firewalld`, see the " +"link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Security_Guide/++[Red{nbsp}Hat " +"Enterprise{nbsp}Linux{nbsp}7 Security Guide]." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/FTP.adoc:134 +#, no-wrap +msgid "Starting Multiple Copies of [command]#vsftpd#" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:137 +msgid "" +"indexterm:[vsftpd,starting multiple copies of]indexterm:[vsftpd,multihome " +"configuration] Sometimes one computer is used to serve multiple `FTP` " +"domains. This is a technique called _multihoming_. One way to multihome " +"using [command]#vsftpd# is by running multiple copies of the daemon, each " +"with its own configuration file." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:139 +msgid "" +"To do this, first assign all relevant `IP` addresses to network devices or " +"alias network devices on the system. For more information about configuring " +"network devices, device aliases, and additional information about network " +"configuration scripts, refer to the " +"[citetitle]_link:++https://docs.fedoraproject.org/en-US/Fedora/networking++[{MAJOROS} " +"Networking Guide]_." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:141 +msgid "" +"Next, the DNS server for the `FTP` domains must be configured to reference " +"the correct machine. For information about BIND and its configuration files, " +"refer to the " +"[citetitle]_link:++https://docs.fedoraproject.org/en-US/Fedora/networking++[{MAJOROS} " +"Networking Guide]_." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:143 +msgid "" +"If there is more configuration files present in the `/etc/vsftpd` directory, " +"calling [command]#systemctl start vsftpd.service# results in the " +"`/etc/rc.d/init.d/vsftpd` initscript starting the same number of processes " +"as the number of configuration files. Each configuration file must have a " +"unique name in the `/etc/vsftpd/` directory and must be readable and " +"writable only by `root`." +msgstr "" + +#. type: Title ===== +#: ./pages/_partials/servers/FTP.adoc:145 +#, no-wrap +msgid "[command]#vsftpd# Configuration Options" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:148 +msgid "" +"indexterm:[vsftpd,configuration file,format " +"of]indexterm:[vsftpd,configuration file,/etc/vsftpd/vsftpd.conf] Although " +"[command]#vsftpd# may not offer the level of customization other widely " +"available `FTP` servers have, it offers enough options to fill most " +"administrator's needs. The fact that it is not overly feature-laden limits " +"configuration and programmatic errors." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:150 +msgid "" +"All configuration of [command]#vsftpd# is handled by its configuration file, " +"`/etc/vsftpd/vsftpd.conf`. Each directive is on its own line within the file " +"and follows the following format:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/FTP.adoc:154 +#, no-wrap +msgid "_directive_pass:attributes[{blank}]=pass:attributes[{blank}]_value_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:157 +msgid "" +"For each directive, replace _directive_ with a valid directive and _value_ " +"with a valid value." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/FTP.adoc:158 +#, no-wrap +msgid "Do not use spaces" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/FTP.adoc:163 +msgid "" +"There must not be any spaces between the _directive_, equal symbol, and the " +"_value_ in a directive." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:167 +msgid "" +"Comment lines must be preceded by a hash sign ([command]###) and are ignored " +"by the daemon." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:169 +msgid "" +"For a complete list of all directives available, refer to the man page for " +"`vsftpd.conf`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/FTP.adoc:170 +#, no-wrap +msgid "Securing the vsftpd service" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/FTP.adoc:175 +msgid "" +"For an overview of ways to secure [command]#vsftpd#, see the " +"link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Security_Guide/++[Red{nbsp}Hat " +"Enterprise{nbsp}Linux{nbsp}7 Security Guide]." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:179 +msgid "" +"The following is a list of some of the more important directives within " +"`/etc/vsftpd/vsftpd.conf`. All directives not explicitly found or commented " +"out within [command]#vsftpd#pass:attributes[{blank}]'s configuration file " +"are set to their default value." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/FTP.adoc:181 +#, no-wrap +msgid "Daemon Options" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:184 +msgid "" +"indexterm:[vsftpd,configuration file,daemon options] The following is a list " +"of directives which control the overall behavior of the [command]#vsftpd# " +"daemon." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:186 +msgid "" +"[command]#listen# — When enabled, [command]#vsftpd# runs in stand-alone " +"mode. {MAJOROS} sets this value to [command]#YES#. This directive cannot be " +"used in conjunction with the [command]#listen_ipv6# directive." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:188 +#: ./pages/_partials/servers/FTP.adoc:192 +#: ./pages/_partials/servers/FTP.adoc:223 +#: ./pages/_partials/servers/FTP.adoc:260 +#: ./pages/_partials/servers/FTP.adoc:268 +#: ./pages/_partials/servers/FTP.adoc:280 +#: ./pages/_partials/servers/FTP.adoc:286 +#: ./pages/_partials/servers/FTP.adoc:301 +#: ./pages/_partials/servers/FTP.adoc:309 +#: ./pages/_partials/servers/FTP.adoc:321 +#: ./pages/_partials/servers/FTP.adoc:337 +#: ./pages/_partials/servers/FTP.adoc:358 +#: ./pages/_partials/servers/FTP.adoc:362 +#: ./pages/_partials/servers/FTP.adoc:370 +#: ./pages/_partials/servers/FTP.adoc:374 +#: ./pages/_partials/servers/FTP.adoc:387 +#: ./pages/_partials/servers/FTP.adoc:404 +#: ./pages/_partials/servers/FTP.adoc:408 +#: ./pages/_partials/servers/FTP.adoc:412 +#: ./pages/_partials/servers/FTP.adoc:541 +msgid "The default value is [command]#NO#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:190 +msgid "" +"[command]#listen_ipv6# — When enabled, [command]#vsftpd# runs in stand-alone " +"mode, but listens only to `IPv6` sockets. This directive cannot be used in " +"conjunction with the [command]#listen# directive." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:194 +msgid "" +"[command]#session_support# — When enabled, [command]#vsftpd# attempts to " +"maintain login sessions for each user through Pluggable Authentication " +"Modules (PAM). For more information, refer to the [citetitle]_Using " +"Pluggable Authentication Modules (PAM)_ chapter of the Red Hat Enterprise " +"Linux 6 [citetitle]_Managing Single Sign-On and Smart Cards_ and the PAM man " +"pages. . If session logging is not necessary, disabling this option allows " +"[command]#vsftpd# to run with less processes and lower privileges." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:196 +#: ./pages/_partials/servers/FTP.adoc:205 +#: ./pages/_partials/servers/FTP.adoc:231 +#: ./pages/_partials/servers/FTP.adoc:243 +#: ./pages/_partials/servers/FTP.adoc:272 +#: ./pages/_partials/servers/FTP.adoc:295 +#: ./pages/_partials/servers/FTP.adoc:350 +#: ./pages/_partials/servers/FTP.adoc:383 +#: ./pages/_partials/servers/FTP.adoc:395 +#: ./pages/_partials/servers/FTP.adoc:521 +#: ./pages/_partials/servers/FTP.adoc:545 +msgid "The default value is [command]#YES#." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/FTP.adoc:198 +#, no-wrap +msgid "Log In Options and Access Controls" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:201 +msgid "" +"indexterm:[vsftpd,configuration file,login " +"options]indexterm:[vsftpd,configuration file,access controls] The following " +"is a list of directives which control the login behavior and access control " +"mechanisms." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:203 +msgid "" +"[command]#anonymous_enable# — When enabled, anonymous users are allowed to " +"log in. The usernames `anonymous` and `ftp` are accepted." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:207 +msgid "" +"See xref:File_and_Print_Servers.adoc#s3-ftp-vsftpd-conf-opt-anon[Anonymous " +"User Options] for a list of directives affecting anonymous users." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:209 +msgid "" +"[command]#banned_email_file# — If the [command]#deny_email_enable# directive " +"is set to [command]#YES#, this directive specifies the file containing a " +"list of anonymous email passwords which are not permitted access to the " +"server." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:211 +msgid "The default value is `/etc/vsftpd/banned_emails`." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:213 +msgid "" +"[command]#banner_file# — Specifies the file containing text displayed when a " +"connection is established to the server. This option overrides any text " +"specified in the [command]#ftpd_banner# directive." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:215 +#: ./pages/_partials/servers/FTP.adoc:219 +#: ./pages/_partials/servers/FTP.adoc:264 +#: ./pages/_partials/servers/FTP.adoc:329 +#: ./pages/_partials/servers/FTP.adoc:341 +#: ./pages/_partials/servers/FTP.adoc:477 +#: ./pages/_partials/servers/FTP.adoc:489 +#: ./pages/_partials/servers/FTP.adoc:517 +msgid "There is no default value for this directive." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:217 +msgid "" +"[command]#cmds_allowed# — Specifies a comma-delimited list of `FTP` commands " +"allowed by the server. All other commands are rejected." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:221 +msgid "" +"[command]#deny_email_enable# — When enabled, any anonymous user utilizing " +"email passwords specified in the `/etc/vsftpd/banned_emails` are denied " +"access to the server. The name of the file referenced by this directive can " +"be specified using the [command]#banned_email_file# directive." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:225 +msgid "" +"[command]#ftpd_banner# — When enabled, the string specified within this " +"directive is displayed when a connection is established to the server. This " +"option can be overridden by the [command]#banner_file# directive." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:227 +msgid "By default [command]#vsftpd# displays its standard banner." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:229 +msgid "" +"[command]#local_enable# — When enabled, local users are allowed to log into " +"the system." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:233 +msgid "" +"See xref:File_and_Print_Servers.adoc#s3-ftp-vsftpd-conf-opt-usr[Local User " +"Options] for a list of directives affecting local users." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:235 +msgid "" +"[command]#pam_service_name# — Specifies the PAM service name for " +"[command]#vsftpd#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:237 +msgid "" +"The default value is [command]#ftp#. Note, in {MAJOROS}, the value is set to " +"[command]#vsftpd#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:239 +#: ./pages/_partials/servers/FTP.adoc:354 +#: ./pages/_partials/servers/FTP.adoc:420 +#: ./pages/_partials/servers/FTP.adoc:428 +#: ./pages/_partials/servers/FTP.adoc:457 +msgid "" +"The default value is [command]#NO#. Note, in {MAJOROS}, the value is set to " +"[command]#YES#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:241 +msgid "" +"[command]#userlist_deny# — When used in conjunction with the " +"[command]#userlist_enable# directive and set to [command]#NO#, all local " +"users are denied access unless the username is listed in the file specified " +"by the [command]#userlist_file# directive. Because access is denied before " +"the client is asked for a password, setting this directive to [command]#NO# " +"prevents local users from submitting unencrypted passwords over the network." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:245 +msgid "" +"[command]#userlist_enable# — When enabled, the users listed in the file " +"specified by the [command]#userlist_file# directive are denied " +"access. Because access is denied before the client is asked for a password, " +"users are prevented from submitting unencrypted passwords over the network." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:247 +msgid "" +"The default value is [command]#NO#, however under {MAJOROS} the value is set " +"to [command]#YES#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:249 +msgid "" +"[command]#userlist_file# — Specifies the file referenced by " +"[command]#vsftpd# when the [command]#userlist_enable# directive is enabled." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:251 +msgid "" +"The default value is [command]#/etc/vsftpd/user_list# and is created during " +"installation." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/FTP.adoc:253 +#, no-wrap +msgid "Anonymous User Options" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:256 +msgid "" +"indexterm:[vsftpd,configuration file,anonymous user options] The following " +"lists directives which control anonymous user access to the server. To use " +"these options, the [command]#anonymous_enable# directive must be set to " +"[command]#YES#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:258 +msgid "" +"[command]#anon_mkdir_write_enable# — When enabled in conjunction with the " +"[command]#write_enable# directive, anonymous users are allowed to create new " +"directories within a parent directory which has write permissions." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:262 +msgid "" +"[command]#anon_root# — Specifies the directory [command]#vsftpd# changes to " +"after an anonymous user logs in." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:266 +msgid "" +"[command]#anon_upload_enable# — When enabled in conjunction with the " +"[command]#write_enable# directive, anonymous users are allowed to upload " +"files within a parent directory which has write permissions." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:270 +msgid "" +"[command]#anon_world_readable_only# — When enabled, anonymous users are only " +"allowed to download world-readable files." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:274 +msgid "" +"[command]#ftp_username# — Specifies the local user account (listed in " +"`/etc/passwd`) used for the anonymous `FTP` user. The home directory " +"specified in `/etc/passwd` for the user is the root directory of the " +"anonymous `FTP` user." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:276 +#: ./pages/_partials/servers/FTP.adoc:325 +msgid "The default value is [command]#ftp#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:278 +msgid "" +"[command]#no_anon_password# — When enabled, the anonymous user is not asked " +"for a password." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:282 +msgid "" +"[command]#secure_email_list_enable# — When enabled, only a specified list of " +"email passwords for anonymous logins are accepted. This is a convenient way " +"to offer limited security to public content without the need for virtual " +"users." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:284 +msgid "" +"Anonymous logins are prevented unless the password provided is listed in " +"[command]#/etc/vsftpd/email_passwords#. The file format is one password per " +"line, with no trailing white spaces." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/FTP.adoc:288 +#, no-wrap +msgid "Local User Options" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:291 +msgid "" +"indexterm:[vsftpd,configuration file,local user options] The following lists " +"directives which characterize the way local users access the server. To use " +"these options, the [command]#local_enable# directive must be set to " +"[command]#YES#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:293 +msgid "" +"[command]#chmod_enable# — When enabled, the `FTP` command [command]#SITE " +"CHMOD# is allowed for local users. This command allows the users to change " +"the permissions on files." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:297 +msgid "" +"[command]#chroot_list_enable# — When enabled, the local users listed in the " +"file specified in the [command]#chroot_list_file# directive are placed in a " +"[command]#chroot# jail upon log in." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:299 +msgid "" +"If enabled in conjunction with the [command]#chroot_local_user# directive, " +"the local users listed in the file specified in the " +"[command]#chroot_list_file# directive are *not* placed in a " +"[command]#chroot# jail upon log in." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:303 +msgid "" +"[command]#chroot_list_file# — Specifies the file containing a list of local " +"users referenced when the [command]#chroot_list_enable# directive is set to " +"[command]#YES#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:305 +msgid "The default value is [command]#/etc/vsftpd/chroot_list#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:307 +msgid "" +"[command]#chroot_local_user# — When enabled, local users are change-rooted " +"to their home directories after logging in." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/FTP.adoc:310 +#, no-wrap +msgid "Avoid enabling the chroot_local_user option" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/FTP.adoc:315 +msgid "" +"Enabling [command]#chroot_local_user# opens up a number of security issues, " +"especially for users with upload privileges. For this reason, it is *not* " +"recommended." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:319 +msgid "" +"[command]#guest_enable# — When enabled, all non-anonymous users are logged " +"in as the user [command]#guest#, which is the local user specified in the " +"[command]#guest_username# directive." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:323 +msgid "" +"[command]#guest_username# — Specifies the username the [command]#guest# user " +"is mapped to." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:327 +msgid "" +"[command]#local_root# — Specifies the directory [command]#vsftpd# changes to " +"after a local user logs in." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:331 +msgid "" +"[command]#local_umask# — Specifies the umask value for file creation. Note " +"that the default value is in octal form (a numerical system with a base of " +"eight), which includes a \"`0`\" prefix. Otherwise the value is treated as a " +"base-10 integer." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:333 +msgid "The default value is [command]#022#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:335 +msgid "" +"[command]#passwd_chroot_enable# — When enabled in conjunction with the " +"[command]#chroot_local_user# directive, [command]#vsftpd# change-roots local " +"users based on the occurrence of the [command]#/./# in the home directory " +"field within `/etc/passwd`." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:339 +msgid "" +"[command]#user_config_dir# — Specifies the path to a directory containing " +"configuration files bearing the name of local system users that contain " +"specific setting for that user. Any directive in the user's configuration " +"file overrides those found in `/etc/vsftpd/vsftpd.conf`." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/FTP.adoc:343 +#, no-wrap +msgid "Directory Options" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:346 +msgid "" +"indexterm:[vsftpd,configuration file,directory options] The following lists " +"directives which affect directories." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:348 +msgid "" +"[command]#dirlist_enable# — When enabled, users are allowed to view " +"directory lists." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:352 +msgid "" +"[command]#dirmessage_enable# — When enabled, a message is displayed whenever " +"a user enters a directory with a message file. This message resides within " +"the current directory. The name of this file is specified in the " +"[command]#message_file# directive and is `.message` by default." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:356 +msgid "" +"[command]#force_dot_files# — When enabled, files beginning with a dot (`.`) " +"are listed in directory listings, with the exception of the `.` and `..` " +"files." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:360 +msgid "" +"[command]#hide_ids# — When enabled, all directory listings show `ftp` as the " +"user and group for each file." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:364 +msgid "" +"[command]#message_file# — Specifies the name of the message file when using " +"the [command]#dirmessage_enable# directive." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:366 +msgid "The default value is [command]#.message#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:368 +msgid "" +"[command]#text_userdb_names# — When enabled, text usernames and group names " +"are used in place of UID and GID entries. Enabling this option may slow " +"performance of the server." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:372 +msgid "" +"[command]#use_localtime# — When enabled, directory listings reveal the local " +"time for the computer instead of GMT." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/FTP.adoc:376 +#, no-wrap +msgid "File Transfer Options" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:379 +msgid "" +"indexterm:[vsftpd,configuration file,file transfer options] The following " +"lists directives which affect directories." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:381 +msgid "[command]#download_enable# — When enabled, file downloads are permitted." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:385 +msgid "" +"[command]#chown_uploads# — When enabled, all files uploaded by anonymous " +"users are owned by the user specified in the [command]#chown_username# " +"directive." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:389 +msgid "" +"[command]#chown_username# — Specifies the ownership of anonymously uploaded " +"files if the [command]#chown_uploads# directive is enabled." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:391 +msgid "The default value is [command]#root#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:393 +msgid "" +"[command]#write_enable# — When enabled, `FTP` commands which can change the " +"file system are allowed, such as [command]#DELE#, [command]#RNFR#, and " +"[command]#STOR#." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/FTP.adoc:397 +#, no-wrap +msgid "Logging Options" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:400 +msgid "" +"indexterm:[vsftpd,configuration file,logging options] The following lists " +"directives which affect [command]#vsftpd#pass:attributes[{blank}]'s logging " +"behavior." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:402 +msgid "" +"[command]#dual_log_enable# — When enabled in conjunction with " +"[command]#xferlog_enable#, [command]#vsftpd# writes two files " +"simultaneously: a [command]#wu-ftpd#-compatible log to the file specified in " +"the [command]#xferlog_file# directive (`/var/log/xferlog` by default) and a " +"standard [command]#vsftpd# log file specified in the " +"[command]#vsftpd_log_file# directive (`/var/log/vsftpd.log` by default)." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:406 +msgid "" +"[command]#log_ftp_protocol# — When enabled in conjunction with " +"[command]#xferlog_enable# and with [command]#xferlog_std_format# set to " +"[command]#NO#, all `FTP` commands and responses are logged. This directive " +"is useful for debugging." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:410 +msgid "" +"[command]#syslog_enable# — When enabled in conjunction with " +"[command]#xferlog_enable#, all logging normally written to the standard " +"[command]#vsftpd# log file specified in the [command]#vsftpd_log_file# " +"directive (`/var/log/vsftpd.log` by default) is sent to the system logger " +"instead under the `FTPD` facility." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:414 +msgid "" +"[command]#vsftpd_log_file# — Specifies the [command]#vsftpd# log file. For " +"this file to be used, [command]#xferlog_enable# must be enabled and " +"[command]#xferlog_std_format# must either be set to [command]#NO# or, if " +"[command]#xferlog_std_format# is set to [command]#YES#, " +"[command]#dual_log_enable# must be enabled. It is important to note that if " +"[command]#syslog_enable# is set to [command]#YES#, the system log is used " +"instead of the file specified in this directive." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:416 +msgid "The default value is `/var/log/vsftpd.log`." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:418 +msgid "" +"[command]#xferlog_enable# — When enabled, [command]#vsftpd# logs connections " +"([command]#vsftpd# format only) and file transfer information to the log " +"file specified in the [command]#vsftpd_log_file# directive " +"(`/var/log/vsftpd.log` by default). If [command]#xferlog_std_format# is set " +"to [command]#YES#, file transfer information is logged but connections are " +"not, and the log file specified in [command]#xferlog_file# " +"(`/var/log/xferlog` by default) is used instead. It is important to note " +"that both log files and log formats are used if [command]#dual_log_enable# " +"is set to [command]#YES#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:422 +msgid "" +"[command]#xferlog_file# — Specifies the [command]#wu-ftpd#-compatible log " +"file. For this file to be used, [command]#xferlog_enable# must be enabled " +"and [command]#xferlog_std_format# must be set to [command]#YES#. It is also " +"used if [command]#dual_log_enable# is set to [command]#YES#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:424 +msgid "The default value is `/var/log/xferlog`." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:426 +msgid "" +"[command]#xferlog_std_format# — When enabled in conjunction with " +"[command]#xferlog_enable#, only a [command]#wu-ftpd#-compatible file " +"transfer log is written to the file specified in the [command]#xferlog_file# " +"directive (`/var/log/xferlog` by default). It is important to note that this " +"file only logs file transfers and does not log connections to the server." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/FTP.adoc:429 +#, no-wrap +msgid "Maintaining compatibility with older log file formats" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/FTP.adoc:434 +msgid "" +"To maintain compatibility with log files written by the older " +"[command]#wu-ftpd# `FTP` server, the [command]#xferlog_std_format# directive " +"is set to [command]#YES# under {MAJOROS}. However, this setting means that " +"connections to the server are not logged." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/FTP.adoc:436 +msgid "" +"To both log connections in [command]#vsftpd# format and maintain a " +"[command]#wu-ftpd#-compatible file transfer log, set " +"[command]#dual_log_enable# to [command]#YES#." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/FTP.adoc:438 +msgid "" +"If maintaining a [command]#wu-ftpd#-compatible file transfer log is not " +"important, either set [command]#xferlog_std_format# to [command]#NO#, " +"comment the line with a hash sign ([command]###), or delete the line " +"entirely." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/FTP.adoc:442 +#, no-wrap +msgid "Network Options" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:445 +msgid "" +"indexterm:[vsftpd,configuration file,network options] The following lists " +"directives which affect how [command]#vsftpd# interacts with the network." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:447 +msgid "" +"[command]#accept_timeout# — Specifies the amount of time for a client using " +"passive mode to establish a connection." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:449 +#: ./pages/_partials/servers/FTP.adoc:461 +msgid "The default value is [command]#60#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:451 +msgid "" +"[command]#anon_max_rate# — Specifies the maximum data transfer rate for " +"anonymous users in bytes per second." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:453 +#: ./pages/_partials/servers/FTP.adoc:505 +msgid "The default value is [command]#0#, which does not limit the transfer rate." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:455 +msgid "" +"[command]#connect_from_port_20# When enabled, [command]#vsftpd# runs with " +"enough privileges to open port 20 on the server during active mode data " +"transfers. Disabling this option allows [command]#vsftpd# to run with less " +"privileges, but may be incompatible with some `FTP` clients." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:459 +msgid "" +"[command]#connect_timeout# — Specifies the maximum amount of time a client " +"using active mode has to respond to a data connection, in seconds." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:463 +msgid "" +"[command]#data_connection_timeout# — Specifies maximum amount of time data " +"transfers are allowed to stall, in seconds. Once triggered, the connection " +"to the remote client is closed." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:465 +#: ./pages/_partials/servers/FTP.adoc:473 +msgid "The default value is [command]#300#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:467 +msgid "" +"[command]#ftp_data_port# — Specifies the port used for active data " +"connections when [command]#connect_from_port_20# is set to [command]#YES#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:469 +msgid "The default value is [command]#20#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:471 +msgid "" +"[command]#idle_session_timeout# — Specifies the maximum amount of time " +"between commands from a remote client. Once triggered, the connection to the " +"remote client is closed." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:475 +msgid "" +"[command]#listen_address# — Specifies the `IP` address on which " +"[command]#vsftpd# listens for network connections." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/FTP.adoc:478 +#: ./pages/_partials/servers/FTP.adoc:490 +#, no-wrap +msgid "Running multiple copies of vsftpd" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/FTP.adoc:483 +#: ./pages/_partials/servers/FTP.adoc:495 +msgid "" +"If running multiple copies of [command]#vsftpd# serving different `IP` " +"addresses, the configuration file for each copy of the [command]#vsftpd# " +"daemon must have a different value for this directive. See " +"xref:File_and_Print_Servers.adoc#s3-ftp-vsftpd-start-multi[Starting Multiple " +"Copies of [command]#vsftpd#] for more information about multihomed `FTP` " +"servers." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:487 +msgid "" +"[command]#listen_address6# — Specifies the `IPv6` address on which " +"[command]#vsftpd# listens for network connections when " +"[command]#listen_ipv6# is set to [command]#YES#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:499 +msgid "" +"[command]#listen_port# — Specifies the port on which [command]#vsftpd# " +"listens for network connections." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:501 +msgid "The default value is [command]#21#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:503 +msgid "" +"[command]#local_max_rate# — Specifies the maximum rate data is transferred " +"for local users logged into the server in bytes per second." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:507 +msgid "" +"[command]#max_clients# — Specifies the maximum number of simultaneous " +"clients allowed to connect to the server when it is running in standalone " +"mode. Any additional client connections would result in an error message." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:509 +#: ./pages/_partials/servers/FTP.adoc:513 +msgid "The default value is [command]#0#, which does not limit connections." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:511 +msgid "" +"[command]#max_per_ip# — Specifies the maximum of clients allowed to " +"connected from the same source `IP` address." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:515 +msgid "" +"[command]#pasv_address# — Specifies the `IP` address for the public facing " +"`IP` address of the server for servers behind Network Address Translation " +"(NAT) firewalls. This enables [command]#vsftpd# to hand out the correct " +"return address for passive mode connections." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:519 +msgid "[command]#pasv_enable# — When enabled, passive mode connects are allowed." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:523 +msgid "" +"[command]#pasv_max_port# — Specifies the highest possible port sent to the " +"`FTP` clients for passive mode connections. This setting is used to limit " +"the port range so that firewall rules are easier to create." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:525 +msgid "" +"The default value is [command]#0#, which does not limit the highest passive " +"port range. The value must not exceed [command]#65535#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:527 +msgid "" +"[command]#pasv_min_port# — Specifies the lowest possible port sent to the " +"`FTP` clients for passive mode connections. This setting is used to limit " +"the port range so that firewall rules are easier to create." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:529 +msgid "" +"The default value is [command]#0#, which does not limit the lowest passive " +"port range. The value must not be lower [command]#1024#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:531 +msgid "" +"[command]#pasv_promiscuous# — When enabled, data connections are not checked " +"to make sure they are originating from the same `IP` address. This setting " +"is only useful for certain types of tunneling." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/FTP.adoc:532 +#, no-wrap +msgid "Avoid enabling the pasv_promiscuous option" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/FTP.adoc:537 +msgid "" +"Do not enable this option unless absolutely necessary as it disables an " +"important security feature which verifies that passive mode connections " +"originate from the same `IP` address as the control connection that " +"initiates the data transfer." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:543 +msgid "[command]#port_enable# — When enabled, active mode connects are allowed." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/FTP.adoc:547 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:550 +msgid "" +"indexterm:[vsftpd,additional resources] For more information about " +"[command]#vsftpd#, refer to the following resources." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/FTP.adoc:552 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:554 +msgid "indexterm:[vsftpd,additional resources,installed documentation]" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:556 +msgid "" +"The `/usr/share/doc/vsftpd/` directory — This directory contains a `README` " +"with basic information about the software. The `TUNING` file contains basic " +"performance tuning tips and the `SECURITY/` directory contains information " +"about the security model employed by [command]#vsftpd#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:558 +msgid "" +"[command]#vsftpd# related man pages — There are a number of man pages for " +"the daemon and configuration files. The following lists some of the more " +"important man pages." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/FTP.adoc:559 +#, no-wrap +msgid "Server Applications" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:560 +#: ./pages/_partials/servers/FTP.adoc:564 +msgid "{blank}" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:562 +msgid "" +"[command]#man vsftpd# — Describes available command line options for " +"[command]#vsftpd#." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/FTP.adoc:563 +#, no-wrap +msgid "Configuration Files" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:566 +msgid "" +"[command]#man vsftpd.conf# — Contains a detailed list of options available " +"within the configuration file for [command]#vsftpd#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:568 +msgid "" +"[command]#man 5 hosts_access# — Describes the format and options available " +"within the TCP wrappers configuration files: `hosts.allow` and `hosts.deny`." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/FTP.adoc:570 +#, no-wrap +msgid "Useful Websites" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:572 +msgid "indexterm:[vsftpd,additional resources,useful websites]" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:574 +msgid "" +"link:++https://security.appspot.com/vsftpd.html++[https://security.appspot.com/vsftpd.html] " +"— The [command]#vsftpd# project page is a great place to locate the latest " +"documentation and to contact the author of the software." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:576 +msgid "" +"link:++https://slacksite.com/other/ftp.html++[https://slacksite.com/other/ftp.html] " +"— This website provides a concise explanation of the differences between " +"active and passive mode `FTP`." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:577 +msgid "" +"link:++https://www.ietf.org/rfc/rfc0959.txt++[https://www.ietf.org/rfc/rfc0959.txt] " +"— The original _Request for Comments_ (_RFC_) of the `FTP` protocol from the " +"IETF." +msgstr "" diff --git a/po/fr/rawhide/pages/_partials/servers/OpenLDAP.po b/po/fr/rawhide/pages/_partials/servers/OpenLDAP.po new file mode 100644 index 00000000000..86af7f4944f --- /dev/null +++ b/po/fr/rawhide/pages/_partials/servers/OpenLDAP.po @@ -0,0 +1,2457 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title == +#: ./pages/_partials/servers/OpenLDAP.adoc:3 +#, no-wrap +msgid "OpenLDAP" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:6 +msgid "" +"indexterm:[directory " +"server,OpenLDAP]indexterm:[LDAP,OpenLDAP]indexterm:[X.500,OpenLDAP]indexterm:[X.500 " +"Lite,OpenLDAP] `LDAP` (Lightweight Directory Access Protocol) is a set of " +"open protocols used to access centrally stored information over a " +"network. It is based on the `X.500` standard for directory sharing, but is " +"less complex and resource-intensive. For this reason, LDAP is sometimes " +"referred to as \"`X.500 Lite`\"." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:8 +msgid "" +"Like X.500, LDAP organizes information in a hierarchical manner using " +"directories. These directories can store a variety of information such as " +"names, addresses, or phone numbers, and can even be used in a manner similar " +"to the _Network Information Service_ (*NIS*), enabling anyone to access " +"their account from any machine on the LDAP enabled network." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:10 +msgid "" +"LDAP is commonly used for centrally managed users and groups, user " +"authentication, or system configuration. It can also serve as a virtual " +"phone directory, allowing users to easily access contact information for " +"other users. Additionally, it can refer a user to other LDAP servers " +"throughout the world, and thus provide an ad-hoc global repository of " +"information. However, it is most frequently used within individual " +"organizations such as universities, government departments, and private " +"companies." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:12 +msgid "" +"This section covers the installation and configuration of " +"[application]*OpenLDAP 2.4*, an open source implementation of the LDAPv2 and " +"LDAPv3 protocols." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/OpenLDAP.adoc:14 +#, no-wrap +msgid "Introduction to LDAP" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:17 +msgid "" +"Using a client-server architecture, LDAP provides a reliable means to create " +"a central information directory accessible from the network. When a client " +"attempts to modify information within this directory, the server verifies " +"the user has permission to make the change, and then adds or updates the " +"entry as requested. To ensure the communication is secure, the _Transport " +"Layer Security_ (*TLS*) cryptographic protocol can be used to prevent an " +"attacker from intercepting the transmission." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:18 +#, no-wrap +msgid "Using Mozilla NSS" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:23 +msgid "" +"The OpenLDAP suite in {MAJOROSVER} no longer uses OpenSSL. Instead, it uses " +"the Mozilla implementation of _Network Security Services_ (*NSS*). OpenLDAP " +"continues to work with existing certificates, keys, and other TLS " +"configuration. For more information on how to configure it to use Mozilla " +"certificate and key database, see " +"[citetitle]_link:++https://www.openldap.org/faq/index.cgi?file=1514++[How do " +"I use TLS/SSL with Mozilla NSS]_." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:27 +msgid "" +"The LDAP server supports several database systems, which gives " +"administrators the flexibility to choose the best suited solution for the " +"type of information they are planning to serve. Because of a well-defined " +"client _Application Programming Interface_ (*API*), the number of " +"applications able to communicate with an LDAP server is numerous, and " +"increasing in both quantity and quality." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:29 +#, no-wrap +msgid "LDAP Terminology" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:32 +msgid "" +"The following is a list of LDAP-specific terms that are used within this " +"chapter:" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:33 +#, no-wrap +msgid "indexterm:[OpenLDAP,terminology,entry] entry" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:34 +msgid "" +"A single unit within an LDAP directory. Each entry is identified by its " +"unique _Distinguished Name_ (*DN*)." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:35 +#, no-wrap +msgid "indexterm:[OpenLDAP,terminology,attribute] attribute" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:40 +#, no-wrap +msgid "" +"Information directly associated with an entry. For example, if an " +"organization is represented as an LDAP entry, attributes associated with " +"this organization might include an address, a fax number, etc. Similarly, " +"people can be represented as entries with common attributes such as personal " +"telephone number or email address.\n" +"+\n" +"An attribute can either have a single value, or an unordered space-separated " +"list of values. While certain attributes are optional, others are " +"required. Required attributes are specified using the [option]`objectClass` " +"definition, and can be found in schema files located in the " +"`/etc/openldap/slapd.d/cn=config/cn=schema/` directory.\n" +" +\n" +"The assertion of an attribute and its corresponding value is also referred " +"to as a _Relative Distinguished Name_ (*RDN*). Unlike distinguished names " +"that are unique globally, a relative distinguished name is only unique per " +"entry.\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:41 +#, no-wrap +msgid "indexterm:[OpenLDAP,terminology,LDIF] LDIF" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:43 +msgid "" +"The _LDAP Data Interchange Format_ (*LDIF*) is a plain text representation " +"of an LDAP entry. It takes the following form: +" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:49 +#, no-wrap +msgid "" +"pass:quotes[_id_] dn: pass:quotes[_distinguished_name_]\n" +"pass:quotes[_attribute_type_]: pass:quotes[_attribute_value_]…\n" +"pass:quotes[_attribute_type_]: pass:quotes[_attribute_value_]…\n" +"…\n" +msgstr "" + +#. type: Bullet: ' + +#. type: ' +#: ./pages/_partials/servers/OpenLDAP.adoc:52 +msgid "" +"The optional _id_ is a number determined by the application that is used to " +"edit the entry. Each entry can contain as many _attribute_type_ and " +"_attribute_value_ pairs as needed, as long as they are all defined in a " +"corresponding schema file. A blank line indicates the end of an entry." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:54 +#, no-wrap +msgid "OpenLDAP Features" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:57 +msgid "" +"indexterm:[OpenLDAP,features] OpenLDAP suite provides a number of important " +"features:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:59 +#, no-wrap +msgid "" +"*LDAPv3 Support* — Many of the changes in the protocol since LDAP version 2 " +"are designed to make LDAP more secure. Among other improvements, this " +"includes the support for Simple Authentication and Security Layer (*SASL*), " +"Transport Layer Security (*TLS*), and Secure Sockets Layer (*SSL*) " +"protocols.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:61 +#, no-wrap +msgid "" +"*LDAP Over IPC* — The use of inter-process communication (*IPC*) enhances " +"security by eliminating the need to communicate over a network.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:63 +#, no-wrap +msgid "" +"*IPv6 Support* — OpenLDAP is compliant with Internet Protocol version 6 " +"(*IPv6*), the next generation of the Internet Protocol.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:65 +#, no-wrap +msgid "*LDIFv1 Support* — OpenLDAP is fully compliant with LDIF version 1.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:67 +#, no-wrap +msgid "" +"*Updated C API* — The current C API improves the way programmers can connect " +"to and use LDAP directory servers.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:69 +#, no-wrap +msgid "" +"*Enhanced Standalone LDAP Server* — This includes an updated access control " +"system, thread pooling, better tools, and much more.\n" +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:71 +#, no-wrap +msgid "OpenLDAP Server Setup" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:74 +msgid "" +"indexterm:[OpenLDAP,configuration,overview] The typical steps to set up an " +"LDAP server on {MAJOROS} are as follows:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:76 +msgid "" +"Install the OpenLDAP suite. See " +"xref:Directory_Servers.adoc#s2-ldap-installation[Installing the OpenLDAP " +"Suite] for more information on required packages." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:78 +msgid "" +"Customize the configuration as described in " +"xref:Directory_Servers.adoc#s2-ldap-configuration[Configuring an OpenLDAP " +"Server]." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:80 +msgid "" +"Start the `slapd` service as described in " +"xref:Directory_Servers.adoc#s2-ldap-running[Running an OpenLDAP Server]." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:82 +msgid "Use the [command]#ldapadd# utility to add entries to the LDAP directory." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:84 +msgid "" +"Use the [command]#ldapsearch# utility to verify that the `slapd` service is " +"accessing the information correctly." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/OpenLDAP.adoc:86 +#, no-wrap +msgid "Installing the OpenLDAP Suite" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:89 +msgid "" +"indexterm:[OpenLDAP,installation]indexterm:[OpenLDAP,packages] The suite of " +"OpenLDAP libraries and tools is provided by the following packages:" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:91 +#, no-wrap +msgid "List of OpenLDAP packages" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/OpenLDAP.adoc:100 +#, no-wrap +msgid "" +"|Package|Description\n" +"|[package]*openldap*|A package containing the libraries necessary to run the " +"OpenLDAP server and client applications.\n" +"|[package]*openldap-clients*|A package containing the command line utilities " +"for viewing and modifying directories on an LDAP server.\n" +"|[package]*openldap-servers*|A package containing both the services and " +"utilities to configure and run an LDAP server. This includes the _Standalone " +"LDAP Daemon_, `slapd`.\n" +"|[package]*openldap-servers-sql*|A package containing the SQL support " +"module.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:103 +msgid "" +"Additionally, the following packages are commonly used along with the LDAP " +"server:" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:105 +#, no-wrap +msgid "List of commonly installed additional LDAP packages" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/OpenLDAP.adoc:112 +#, no-wrap +msgid "" +"|Package|Description\n" +"|[package]*nss-pam-ldapd*|A package containing `nslcd`, a local LDAP name " +"service that allows a user to perform local LDAP queries.\n" +"|[package]*mod_ldap*|A package containing the `mod_authnz_ldap` and " +"`mod_ldap` modules. The `mod_authnz_ldap` module is the LDAP authorization " +"module for the Apache HTTP Server. This module can authenticate users' " +"credentials against an LDAP directory, and can enforce access control based " +"on the user name, full DN, group membership, an arbitrary attribute, or a " +"complete filter string. The `mod_ldap` module contained in the same package " +"provides a configurable shared memory cache, to avoid repeated directory " +"access across many HTTP requests, and also support for SSL/TLS.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:115 +msgid "" +"To install these packages, use the [command]#dnf# command in the following " +"form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:119 +#, no-wrap +msgid "[command]#dnf# [option]`install` _package_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:122 +msgid "" +"For example, to perform the basic LDAP server installation, type the " +"following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:126 +#, no-wrap +msgid "~]#{nbsp}dnf install openldap openldap-clients openldap-servers\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:129 +msgid "" +"Note that you must have superuser privileges (that is, you must be logged in " +"as `root`) to run this command. For more information on how to install new " +"packages in {MAJOROS}, see " +"xref:package-management/DNF.adoc#sec-Installing[Installing Packages]." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:131 +#, no-wrap +msgid "Overview of OpenLDAP Server Utilities" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:134 +msgid "" +"indexterm:[OpenLDAP,utilities] To perform administrative tasks, the " +"[package]*openldap-servers* package installs the following utilities along " +"with the `slapd` service:" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:136 +#, no-wrap +msgid "List of OpenLDAP server utilities" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/OpenLDAP.adoc:150 +#, no-wrap +msgid "" +"|Command|Description\n" +"|[command]#slapacl#|Allows you to check the access to a list of " +"attributes.\n" +"|[command]#slapadd#|Allows you to add entries from an LDIF file to an LDAP " +"directory.\n" +"|[command]#slapauth#|Allows you to check a list of IDs for authentication " +"and authorization permissions.\n" +"|[command]#slapcat#|Allows you to pull entries from an LDAP directory in the " +"default format and save them in an LDIF file.\n" +"|[command]#slapdn#|Allows you to check a list of Distinguished Names (DNs) " +"based on available schema syntax.\n" +"|[command]#slapindex#|Allows you to re-index the `slapd` directory based on " +"the current content. Run this utility whenever you change indexing options " +"in the configuration file.\n" +"|[command]#slappasswd#|Allows you to create an encrypted user password to be " +"used with the [command]#ldapmodify# utility, or in the `slapd` configuration " +"file.\n" +"|[command]#slapschema#|Allows you to check the compliance of a database with " +"the corresponding schema.\n" +"|[command]#slaptest#|Allows you to check the LDAP server configuration.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:153 +msgid "" +"For a detailed description of these utilities and their usage, see the " +"corresponding manual pages as referred to in " +"xref:Directory_Servers.adoc#bh-Installed_Documentation_OpenLDAP[Installed " +"Documentation]." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:154 +#, no-wrap +msgid "Make sure the files have correct owner" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:159 +msgid "" +"Although only `root` can run [command]#slapadd#, the `slapd` service runs as " +"the `ldap` user. Because of this, the directory server is unable to modify " +"any files created by [command]#slapadd#. To correct this issue, after " +"running the [command]#slapadd# utility, type the following at a shell " +"prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:163 +#, no-wrap +msgid "[command]#chown -R ldap:ldap /var/lib/ldap#\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:167 +#, no-wrap +msgid "Stop slapd before using these utilities" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:172 +msgid "" +"To preserve the data integrity, stop the `slapd` service before using " +"[command]#slapadd#, [command]#slapcat#, or [command]#slapindex#. You can do " +"so by typing the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:176 +#: ./pages/_partials/servers/OpenLDAP.adoc:797 +#, no-wrap +msgid "~]#{nbsp}systemctl stop slapd.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:179 +msgid "" +"For more information on how to start, stop, restart, and check the current " +"status of the `slapd` service, see " +"xref:Directory_Servers.adoc#s2-ldap-running[Running an OpenLDAP Server]." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:183 +#, no-wrap +msgid "Overview of OpenLDAP Client Utilities" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:186 +msgid "" +"indexterm:[OpenLDAP,utilities] The [package]*openldap-clients* package " +"installs the following utilities which can be used to add, modify, and " +"delete entries in an LDAP directory:" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:188 +#, no-wrap +msgid "List of OpenLDAP client utilities" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/OpenLDAP.adoc:203 +#, no-wrap +msgid "" +"|Command|Description\n" +"|[command]#ldapadd#|Allows you to add entries to an LDAP directory, either " +"from a file, or from standard input. It is a symbolic link to " +"[command]#ldapmodify -a#.\n" +"|[command]#ldapcompare#|Allows you to compare given attribute with an LDAP " +"directory entry.\n" +"|[command]#ldapdelete#|Allows you to delete entries from an LDAP " +"directory.\n" +"|[command]#ldapexop#|Allows you to perform extended LDAP operations.\n" +"|[command]#ldapmodify#|Allows you to modify entries in an LDAP directory, " +"either from a file, or from standard input.\n" +"|[command]#ldapmodrdn#|Allows you to modify the RDN value of an LDAP " +"directory entry.\n" +"|[command]#ldappasswd#|Allows you to set or change the password for an LDAP " +"user.\n" +"|[command]#ldapsearch#|Allows you to search LDAP directory entries.\n" +"|[command]#ldapurl#|Allows you to compose or decompose LDAP URLs.\n" +"|[command]#ldapwhoami#|Allows you to perform a [option]`whoami` operation on " +"an LDAP server.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:206 +msgid "" +"With the exception of [command]#ldapsearch#, each of these utilities is more " +"easily used by referencing a file containing the changes to be made rather " +"than typing a command for each entry to be changed within an LDAP " +"directory. The format of such a file is outlined in the man page for each " +"utility." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:208 +#, no-wrap +msgid "Overview of Common LDAP Client Applications" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:211 +msgid "" +"indexterm:[OpenLDAP,client applications] Although there are various " +"graphical LDAP clients capable of creating and modifying directories on the " +"server, none of them is included in {MAJOROS}. Popular applications that can " +"access directories in a read-only mode include [application]*Mozilla " +"Thunderbird*, [application]*Evolution*, or [application]*Ekiga*." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/OpenLDAP.adoc:213 +#, no-wrap +msgid "Configuring an OpenLDAP Server" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:216 +msgid "" +"By default, the OpenLDAP configuration is stored in the `/etc/openldap/` " +"directory. The following table highlights the most important directories and " +"files within this directory:" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:218 +#, no-wrap +msgid "List of OpenLDAP configuration files and directories" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/OpenLDAP.adoc:227 +#, no-wrap +msgid "" +"|Path|Description\n" +"|indexterm:[OpenLDAP,files,/etc/openldap/ldap.conf]\n" +" `/etc/openldap/ldap.conf`|The configuration file for client " +"applications that use the OpenLDAP libraries. This includes " +"[command]#ldapadd#, [command]#ldapsearch#, [application]*Evolution*, etc.\n" +"|indexterm:[OpenLDAP,directories,/etc/openldap/slapd.d/]\n" +" `/etc/openldap/slapd.d/`|The directory containing the `slapd` " +"configuration.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:230 +msgid "" +"Note that OpenLDAP no longer reads its configuration from the " +"`/etc/openldap/slapd.conf` file. Instead, it uses a configuration database " +"located in the `/etc/openldap/slapd.d/` directory. If you have an existing " +"`slapd.conf` file from a previous installation, you can convert it to the " +"new format by running the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:234 +#, no-wrap +msgid "~]#{nbsp}slaptest -f /etc/openldap/slapd.conf -F /etc/openldap/slapd.d/\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:237 +msgid "" +"The `slapd` configuration consists of LDIF entries organized in a " +"hierarchical directory structure, and the recommended way to edit these " +"entries is to use the server utilities described in " +"xref:Directory_Servers.adoc#s3-ldap-packages-openldap-servers[Overview of " +"OpenLDAP Server Utilities]." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:238 +#, no-wrap +msgid "Do not edit LDIF files directly" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:243 +msgid "" +"An error in an LDIF file can render the `slapd` service unable to " +"start. Because of this, it is strongly advised that you avoid editing the " +"LDIF files within the `/etc/openldap/slapd.d/` directly." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:247 +#, no-wrap +msgid "Changing the Global Configuration" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:250 +msgid "" +"indexterm:[OpenLDAP,configuration,global]indexterm:[OpenLDAP,files,/etc/openldap/slapd.d/cn=config.ldif] " +"Global configuration options for the LDAP server are stored in the " +"`/etc/openldap/slapd.d/cn=config.ldif` file. The following directives are " +"commonly used:" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:251 +#, no-wrap +msgid "indexterm:[OpenLDAP,directives,olcAllows] [option]`olcAllows`" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:252 +msgid "" +"The [option]`olcAllows` directive allows you to specify which features to " +"enable. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:256 +#, no-wrap +msgid "[option]`olcAllows`: _feature_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:259 +msgid "" +"It accepts a space-separated list of features as described in " +"xref:Directory_Servers.adoc#table-ldap-configuration-olcallows[Available " +"olcAllows options]. The default option is [option]`bind_v2`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:261 +#, no-wrap +msgid "Available olcAllows options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/OpenLDAP.adoc:271 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`bind_v2`|Enables the acceptance of LDAP version 2 bind requests.\n" +"|[option]`bind_anon_cred`|Enables an anonymous bind when the Distinguished " +"Name (DN) is empty.\n" +"|[option]`bind_anon_dn`|Enables an anonymous bind when the Distinguished " +"Name (DN) is *not* empty.\n" +"|[option]`update_anon`|Enables processing of anonymous update operations.\n" +"|[option]`proxy_authz_anon`|Enables processing of anonymous proxy " +"authorization control.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:274 +#, no-wrap +msgid "Using the olcAllows directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:279 +#, no-wrap +msgid "olcAllows: bind_v2 update_anon\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:283 +#, no-wrap +msgid "" +"indexterm:[OpenLDAP,directives,olcConnMaxPending] " +"[option]`olcConnMaxPending`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:284 +msgid "" +"The [option]`olcConnMaxPending` directive allows you to specify the maximum " +"number of pending requests for an anonymous session. It takes the following " +"form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:288 +#, no-wrap +msgid "[option]`olcConnMaxPending`: _number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:292 +#, no-wrap +msgid "" +"The default option is [option]`100`.\n" +" +\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:293 +#, no-wrap +msgid "Using the olcConnMaxPending directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:299 +#, no-wrap +msgid "olcConnMaxPending: 100\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:303 +#, no-wrap +msgid "" +"indexterm:[OpenLDAP,directives,olcConnMaxPendingAuth] " +"[option]`olcConnMaxPendingAuth`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:305 +msgid "" +"The [option]`olcConnMaxPendingAuth` directive allows you to specify the " +"maximum number of pending requests for an authenticated session. It takes " +"the following form: +" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:308 +#, no-wrap +msgid "[option]`olcConnMaxPendingAuth`: _number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:311 +msgid "The default option is [option]`1000`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:313 +#, no-wrap +msgid "Using the olcConnMaxPendingAuth directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:319 +#, no-wrap +msgid "olcConnMaxPendingAuth: 1000\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:323 +#, no-wrap +msgid "" +"indexterm:[OpenLDAP,directives,olcDisallows] " +"[option]`olcDisallows`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:325 +msgid "" +"The [option]`olcDisallows` directive allows you to specify which features to " +"disable. It takes the following form: +" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:328 +#, no-wrap +msgid "[option]`olcDisallows`: _feature_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:331 +msgid "" +"It accepts a space-separated list of features as described in " +"xref:Directory_Servers.adoc#table-ldap-configuration-olcdisallows[Available " +"olcDisallows options]. No features are disabled by default." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:333 +#, no-wrap +msgid "Available olcDisallows options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/OpenLDAP.adoc:342 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`bind_anon`|Disables the acceptance of anonymous bind requests.\n" +"|[option]`bind_simple`|Disables the simple bind authentication mechanism.\n" +"|[option]`tls_2_anon`|Disables the enforcing of an anonymous session when " +"the STARTTLS command is received.\n" +"|[option]`tls_authc`|Disallows the STARTTLS command when authenticated.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:345 +#, no-wrap +msgid "Using the olcDisallows directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:350 +#, no-wrap +msgid "olcDisallows: bind_anon\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:354 +#, no-wrap +msgid "" +"indexterm:[OpenLDAP,directives,olcIdleTimeout] " +"[option]`olcIdleTimeout`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:356 +msgid "" +"The [option]`olcIdleTimeout` directive allows you to specify how many " +"seconds to wait before closing an idle connection. It takes the following " +"form: +" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:359 +#, no-wrap +msgid "[option]`olcIdleTimeout`: _number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:362 +#: ./pages/_partials/servers/OpenLDAP.adoc:422 +msgid "This option is disabled by default (that is, set to [option]`0`)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:364 +#, no-wrap +msgid "Using the olcIdleTimeout directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:370 +#, no-wrap +msgid "olcIdleTimeout: 180\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:374 +#, no-wrap +msgid "indexterm:[OpenLDAP,directives,olcLogFile] [option]`olcLogFile`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:376 +msgid "" +"The [option]`olcLogFile` directive allows you to specify a file in which to " +"write log messages. It takes the following form: +" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:379 +#, no-wrap +msgid "olcLogFile: pass:quotes[_file_name_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:382 +msgid "The log messages are written to standard error by default." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:384 +#, no-wrap +msgid "Using the olcLogFile directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:390 +#, no-wrap +msgid "olcLogFile: /var/log/slapd.log\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:394 +#, no-wrap +msgid "indexterm:[OpenLDAP,directives,olcReferral] [option]`olcReferral`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:396 +msgid "" +"The [option]`olcReferral` option allows you to specify a URL of a server to " +"process the request in case the server is not able to handle it. It takes " +"the following form: +" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:399 +#, no-wrap +msgid "[option]`olcReferral`: _URL_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:402 +msgid "This option is disabled by default." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:404 +#, no-wrap +msgid "Using the olcReferral directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:410 +#, no-wrap +msgid "olcReferral: ldap://root.openldap.org\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:414 +#, no-wrap +msgid "" +"indexterm:[OpenLDAP,directives,olcWriteTimeout] " +"[option]`olcWriteTimeout`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:416 +msgid "" +"The [option]`olcWriteTimeout` option allows you to specify how many seconds " +"to wait before closing a connection with an outstanding write request. It " +"takes the following form: +" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:419 +#, no-wrap +msgid "[option]`olcWriteTimeout`\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:424 +#, no-wrap +msgid "Using the olcWriteTimeout directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:430 +#, no-wrap +msgid "olcWriteTimeout: 180\n" +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:435 +#, no-wrap +msgid "Changing the Database-Specific Configuration" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:438 +msgid "" +"indexterm:[OpenLDAP,configuration,database]indexterm:[OpenLDAP,files,/etc/openldap/slapd.d/cn=config/olcDatabase=\\{1}bdb.ldif] " +"By default, the OpenLDAP server uses Berkeley DB (BDB) as a database back " +"end. The configuration for this database is stored in the " +"`/etc/openldap/slapd.d/cn=config/olcDatabase=\\{1}bdb.ldif` file. The " +"following directives are commonly used in a database-specific configuration:" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:439 +#, no-wrap +msgid "indexterm:[OpenLDAP,directives,olcReadOnly] [option]`olcReadOnly`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:441 +msgid "" +"The [option]`olcReadOnly` directive allows you to use the database in a " +"read-only mode. It takes the following form: +" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:444 +#, no-wrap +msgid "[option]`olcReadOnly`: _boolean_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:447 +msgid "" +"It accepts either [option]`TRUE` (enable the read-only mode), or " +"[option]`FALSE` (enable modifications of the database). The default option " +"is [option]`FALSE`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:449 +#, no-wrap +msgid "Using the olcReadOnly directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:455 +#, no-wrap +msgid "olcReadOnly: TRUE\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:459 +#, no-wrap +msgid "indexterm:[OpenLDAP,directives,olcRootDN] [option]`olcRootDN`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:461 +msgid "" +"The [option]`olcRootDN` directive allows you to specify the user that is " +"unrestricted by access controls or administrative limit parameters set for " +"operations on the LDAP directory. It takes the following form: +" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:464 +#, no-wrap +msgid "olcRootDN: pass:quotes[_distinguished_name_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:467 +msgid "" +"It accepts a _Distinguished Name_ (*DN*). The default option is " +"[option]`cn=Manager,dn=my-domain,dc=com`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:469 +#, no-wrap +msgid "Using the olcRootDN directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:475 +#, no-wrap +msgid "olcRootDN: cn=root,dn=example,dn=com\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:479 +#, no-wrap +msgid "indexterm:[OpenLDAP,directives,olcRootPW] [option]`olcRootPW`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:481 +msgid "" +"The [option]`olcRootPW` directive allows you to set a password for the user " +"that is specified using the [option]`olcRootDN` directive. It takes the " +"following form: +" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:484 +#, no-wrap +msgid "[option]`olcRootPW`: _password_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:487 +msgid "" +"It accepts either a plain text string, or a hash. To generate a hash, type " +"the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:494 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#slappaswd#\n" +"New password:\n" +"Re-enter new password:\n" +"\\{SSHA}WczWsyPEnMchFf1GRTweq2q7XJcvmSxD\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:497 +#, no-wrap +msgid "Using the olcRootPW directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:503 +#, no-wrap +msgid "olcRootPW: {SSHA}WczWsyPEnMchFf1GRTweq2q7XJcvmSxD\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:507 +#, no-wrap +msgid "indexterm:[OpenLDAP,directives,olcSuffix] [option]`olcSuffix`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:509 +msgid "" +"The [option]`olcSuffix` directive allows you to specify the domain for which " +"to provide information. It takes the following form: +" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:512 +#, no-wrap +msgid "olcSuffix: pass:quotes[_domain_name_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:515 +msgid "" +"It accepts a _fully qualified domain name_ (*FQDN*). The default option is " +"[option]`dc=my-domain,dc=com`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:517 +#, no-wrap +msgid "Using the olcSuffix directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:523 +#, no-wrap +msgid "olcSuffix: dc=example,dc=com\n" +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:528 +#, no-wrap +msgid "Extending Schema" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:531 +msgid "" +"indexterm:[OpenLDAP,schema]indexterm:[OpenLDAP,directories,/etc/openldap/slapd.d/cn=config/cn=schema/] " +"Since OpenLDAP 2.3, the `/etc/openldap/slapd.d/` directory also contains " +"LDAP definitions that were previously located in `/etc/openldap/schema/`. It " +"is possible to extend the schema used by OpenLDAP to support additional " +"attribute types and object classes using the default schema files as a " +"guide. However, this task is beyond the scope of this chapter. For more " +"information on this topic, see " +"link:++https://www.openldap.org/doc/admin/schema.html++[]." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:533 +#, no-wrap +msgid "Establishing a Secure Connection" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:536 +msgid "" +"indexterm:[OpenLDAP,configuration,TLS]indexterm:[OpenLDAP,files,/etc/openldap/ldap.conf]indexterm:[OpenLDAP,files,/etc/openldap/slapd.d/cn=config.ldif]indexterm:[OpenLDAP,security] " +"OpenLDAP clients and servers can be secured using the Transport Layer " +"Security (TLS) framework. TLS is a cryptographic protocol designed to " +"provide communication security over the network. As noted above, OpenLDAP " +"suite in Fedora uses Mozilla NSS as the TLS implementation." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:538 +msgid "" +"To establish a secure connection using TLS, obtain the required certificates " +"as described in " +"[citetitle]_link:++https://www.openldap.org/faq/index.cgi?file=1514++[How do " +"I use TLS/SSL with Mozilla NSS]_. Then, a number of options must be " +"configured on both the client and the server. At a minimum, a server must be " +"configured with the Certificate Authority (CA) certificates and also its own " +"server certificate and private key. The clients must be configured with the " +"name of the file containing all the trusted CA certificates." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:540 +msgid "" +"Typically, a server only needs to sign a single CA certificate. A client may " +"want to connect to a variety of secure servers, therefore it is common to " +"specify a list of several trusted CAs in its configuration." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:541 +#, no-wrap +msgid "Server Configuration" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:543 +msgid "" +"This section lists global configuration directives for `slapd` that need to " +"be specified in the `/etc/openldap/slapd.d/cn=config.ldif` file on an " +"OpenLDAP server in order to establish TLS." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:545 +msgid "" +"While the old style configuration uses a single file, normally installed as " +"`/usr/local/etc/openldap/slapd.conf`, the new style uses a slapd backend " +"database to store the configuration. The configuration database normally " +"resides in the `/usr/local/etc/openldap/slapd.d/` directory." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:547 +msgid "" +"The following directives are also valid for establishing SSL. In addition to " +"TLS directives, you need to enable a port dedicated to SSL on the server " +"side – typically it is port 636. To do so, edit the `/etc/sysconfig/slapd` " +"file and append the `ldaps:///` string to the list of URLs specified with " +"the [option]`SLAPD_URLS` directive." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:548 +#, no-wrap +msgid "[option]`olcTLSCACertificateFile`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:550 +msgid "" +"The [option]`olcTLSCACertificateFile` directive specifies the file encoded " +"with Privacy-Enhanced Mail (PEM) schema that contains trusted CA " +"certificates. The directive takes the following form: +" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:553 +#, no-wrap +msgid "[option]`olcTLSCACertificateFile`: _path_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:556 +msgid "" +"Replace _path_ either with a path to the CA certificate file, or, if you use " +"Mozilla NSS, with a certificate name." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:557 +#, no-wrap +msgid "[option]`olcTLSCACertificatePath`" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:563 +#, no-wrap +msgid "" +"The [option]`olcTLSCACertificatePath` directive specifies the path to a " +"directory containing individual CA certificates in separate files. This " +"directory must be specially managed with the OpenSSL [application]*c_rehash* " +"utility that generates symbolic links with the hashed names that point to " +"the actual certificate files. In general, it is simpler to use the " +"[option]`olcTLSCACertificateFile` directive instead.\n" +"+\n" +"If Mozilla NSS is used, [option]`olcTLSCACertificatePath` accepts a path to " +"the Mozilla NSS database (as shown in " +"xref:Directory_Servers.adoc#ex-using_olcTLSCACertificatePath_with_Mozilla_NSS[Using " +"olcTLSCACertificatePath with Mozilla NSS]). In such a case, " +"[application]*c_rehash* is not needed.\n" +" +\n" +"The directive takes the following form:\n" +" +\n" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:566 +#, no-wrap +msgid "[option]`olcTLSCACertificatePath`: _path_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:569 +msgid "" +"Replace _path_ with a path to the directory containing the CA certificate " +"files, or with a path to a Mozilla NSS database file." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:571 +#, no-wrap +msgid "Using olcTLSCACertificatePath with Mozilla NSS" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:575 +msgid "" +"With Mozilla NSS, the [option]`olcTLSCACertificatePath` directive specifies " +"the path of the directory containing the NSS certificate and key database " +"files. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:579 +#, no-wrap +msgid "[option]`olcTLSCACertificatePath`: `sql:/home/nssdb/sharednssdb`\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:582 +msgid "" +"The [command]#certutil# command is used to add a CA certificate to these NSS " +"database files:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:586 +#, no-wrap +msgid "" +"certutil -d pass:quotes[`sql:/home/nssdb/sharednssdb`] -A -n " +"\"pass:quotes[_CA_certificate_]\" -t pass:quotes[`CT,,`] -a -i " +"pass:quotes[`certificate.pem`]\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:589 +msgid "" +"The above command adds a CA certificate stored in a PEM-formatted file named " +"_certificate.pem_. The [option]`-d` option specifies the database directory " +"containing the certificate and key database files, the [option]`-n` option " +"sets a name for the certificate, [option]`-t` `CT,,` means that the " +"certificate is trusted to be used in TLS clients and servers. The " +"[option]`-A` option adds an existing certificate to a certificate database, " +"the [option]`-a` option allows the use of ASCII format for input or output, " +"and the [option]`-i` option passes the `certificate.pem` input file to the " +"command." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:592 +#, no-wrap +msgid "[option]`olcTLSCertificateFile`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:594 +msgid "" +"The [option]`olcTLSCertificateFile` directive specifies the file that " +"contains the `slapd` server certificate. The directive takes the following " +"form: +" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:597 +#, no-wrap +msgid "[option]`olcTLSCertificateFile`: _path_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:600 +msgid "" +"Replace _path_ with a path to the `slapd` server certificate file, or, if " +"you use Mozilla NSS, with a certificate name." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:602 +#, no-wrap +msgid "Using olcTLSCertificateFile with Mozilla NSS" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:606 +msgid "" +"When using Mozilla NSS with certificate and key database files specified " +"with the [option]`olcTLSCACertificatePath` directive, " +"[option]`olcTLSCertificateFile` is used to specify the name of the " +"certificate to use. First, execute the following command to view a list of " +"certificates available in your NSS database file:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:610 +#, no-wrap +msgid "" +"[command]#certutil# [option]`-d` `sql:/home/nssdb/sharednssdb` " +"[option]`-L`\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:613 +msgid "" +"Select a certificate from the list and pass its name to " +"[option]`olcTLSCertificateFile`. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:617 +#, no-wrap +msgid "olcTLSCertificateFile pass:quotes[*slapd_cert*]\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:621 +#, no-wrap +msgid "[option]`olcTLSCertificateKeyFile`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:622 +msgid "" +"The [option]`olcTLSCertificateKeyFile` directive specifies the file that " +"contains the private key that matches the certificate stored in the file " +"specified with [option]`olcTLSCertificateFile`. Note that the current " +"implementation does not support encrypted private keys, and therefore the " +"containing file must be sufficiently protected. The directive takes the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:626 +#, no-wrap +msgid "[option]`olcTLSCertificateKeyFile`: _path_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:629 +msgid "" +"Replace _path_ with a path to the private key file if you use PEM " +"certificates. When using Mozilla NSS, _path_ stands for the name of a file " +"that contains the password for the key for the certificate specified with " +"the [option]`olcTLSCertificateFile` directive (see " +"xref:Directory_Servers.adoc#ex-using_olcTLSCertificateKeyFile_with_Mozilla_NSS[Using " +"olcTLSCertificateKeyFile with Mozilla NSS])." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:631 +#, no-wrap +msgid "Using olcTLSCertificateKeyFile with Mozilla NSS" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:635 +msgid "" +"When using Mozilla NSS, this directive specifies the name of a file that " +"contains the password for the key for the certificate specified with " +"[option]`olcTLSCertificateFile`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:639 +#, no-wrap +msgid "olcTLSCertificateKeyFile: pass:quotes[*slapd_cert_key*]\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:642 +msgid "" +"The [command]#modutil# command can be used to turn off password protection " +"or to change the password for NSS database files. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:646 +#, no-wrap +msgid "" +"[command]#modutil# [option]`-dbdir` `sql:/home/nssdb/sharednssdb` " +"[option]`-changepw`\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:650 +#, no-wrap +msgid "Client Configuration" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:652 +msgid "" +"Specify the following directives in the `/etc/openldap/ldap.conf` " +"configuration file on the client system. Most of these directives are " +"parallel to the server configuration options. Directives " +"inpass:attributes[{blank}]`/etc/openldap/ldap.conf` are configured on a " +"system-wide basis, however, individual users may override them in their " +"`~/.ldaprc` files." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:654 +msgid "" +"The same directives can be used to establish an SSL connection. The " +"`ldaps://` string must be used instead of `ldap://` in OpenLDAP commands " +"such as [command]#ldapsearch#. This forces commands to use the default port " +"for SSL, port 636, configured on the server." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:655 +#, no-wrap +msgid "[option]`TLS_CACERT`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:656 +msgid "" +"The [option]`TLS_CACERT` directive specifies a file containing certificates " +"for all of the Certificate Authorities the client will recognize. This is " +"equivalent to the [option]`olcTLSCACertificateFile` directive on a " +"server. [option]`TLS_CACERT` should always be specified before " +"[option]`TLS_CACERTDIR` in `/etc/openldap/ldap.conf`. The directive takes " +"the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:660 +#, no-wrap +msgid "TLS_CACERT pass:quotes[_path_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:663 +msgid "Replace _path_ with a path to the CA certificate file." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:664 +#, no-wrap +msgid "[option]`TLS_CACERTDIR`" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:665 +msgid "" +"The [option]`TLS_CACERTDIR` directive specifies the path to a directory that " +"contains Certificate Authority certificates in separate files. As with " +"[option]`olcTLSCACertificatePath` on a server, the specified directory must " +"be managed with the OpenSSL [application]*c_rehash* utility. Path to Mozilla " +"NSS database file is also accepted, [application]*c_rehash* is not needed in " +"such case. The directive takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:669 +#, no-wrap +msgid "TLS_CACERTDIR pass:quotes[_directory_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:672 +msgid "" +"Replace _directory_ with a path to the directory containing CA certificate " +"files. With Mozilla NSS, _directory_ stands for a path to the certificate or " +"key database file." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:673 +#, no-wrap +msgid "[option]`TLS_CERT`" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:674 +msgid "" +"The [option]`TLS_CERT` specifies the file that contains a client " +"certificate. This directive can only be specified in a user's `~/.ldaprc` " +"file. With Mozilla NSS, this directive specifies the name of the certificate " +"to be chosen from the database specified with the aforementioned " +"[option]`TLS_CACERTDIR` directive. The directive takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:678 +#, no-wrap +msgid "TLS_CERT pass:quotes[_path_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:681 +msgid "" +"Replace _path_ with a path to the client certificate file, or with a name of " +"a certificate from the NSS database." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:682 +#, no-wrap +msgid "[option]`TLS_KEY`" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:688 +#, no-wrap +msgid "" +"The [option]`TLS_KEY` specifies the file that contains the private key that " +"matches the certificate stored in the file specified with the " +"[option]`TLS_CERT` directive. As with [option]`olcTLSCertificateFile` on a " +"server, encrypted key files are not supported, so the file itself must be " +"carefully protected. This option is only configurable in a user's " +"`~/.ldaprc` file.\n" +"+\n" +"When using Mozilla NSS, [option]`TLS_KEY` specifies the name of a file that " +"contains the password for the private key that protects the certificate " +"specified with the [option]`TLS_CERT` directive. Similarly to the " +"[option]`olcTLSCertificateKeyFile` directive on a server (see " +"xref:Directory_Servers.adoc#ex-using_olcTLSCertificateKeyFile_with_Mozilla_NSS[Using " +"olcTLSCertificateKeyFile with Mozilla NSS]), you can use the " +"[command]#modutil# command to manage this password.\n" +" +\n" +"The [option]`TLS_KEY` directive takes the following form:\n" +" +\n" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:691 +#, no-wrap +msgid "TLS_KEY pass:quotes[_path_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:694 +msgid "" +"Replace _path_ with a path to the client certificate file or with a name of " +"the password file in the NSS database." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:696 +#, no-wrap +msgid "Setting Up Replication" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:699 +msgid "" +"indexterm:[OpenLDAP,configuration,TLS]indexterm:[OpenLDAP,directories,/etc/openldap/slapd.d/]indexterm:[OpenLDAP,replication] " +"Replication is the process of copying updates from one LDAP server " +"(*provider*) to one or more other servers or clients (*consumers*). A " +"provider replicates directory updates to consumers, the received updates can " +"be further propagated by the consumer to other servers, so a consumer can " +"also act simultaneously as a provider. Also, a consumer does not have to be " +"an LDAP server, it may be just an LDAP client. In OpenLDAP, you can use " +"several replication modes, most notable are *mirror* and *sync*. For more " +"information on OpenLDAP replication modes, see the *OpenLDAP Software " +"Administrator's Guide* installed with [package]*openldap-servers* package " +"(see " +"xref:Directory_Servers.adoc#bh-Installed_Documentation_OpenLDAP[Installed " +"Documentation])." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:701 +msgid "" +"To enable a chosen replication mode, use one of the following directives in " +"`/etc/openldap/slapd.d/` on both provider and consumers." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:702 +#, no-wrap +msgid "[option]`olcMirrorMode`" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:703 +msgid "" +"The [option]`olcMirrorMode` directive enables the mirror replication " +"mode. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:707 +#, no-wrap +msgid "[option]`olcMirrorMode` [option]`on`\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:710 +msgid "" +"This option needs to be specified both on provider and consumers. Also a " +"[option]`serverID` must be specified along with [option]`syncrepl` " +"options. Find a detailed example in the *18.3.4. MirrorMode* section of the " +"*OpenLDAP Software Administrator's Guide* (see " +"xref:Directory_Servers.adoc#bh-Installed_Documentation_OpenLDAP[Installed " +"Documentation])." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:711 +#, no-wrap +msgid "[option]`olcSyncrepl`" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:712 +msgid "" +"The [option]`olcSyncrepl` directive enables the sync replication mode. It " +"takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:716 +#, no-wrap +msgid "[option]`olcSyncrepl` [option]`on`\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:719 +msgid "" +"The sync replication mode requires a specific configuration on both the " +"provider and the consumers. This configuration is thoroughly described in " +"the *18.3.1. Syncrepl* section of the *OpenLDAP Software Administrator's " +"Guide* (see " +"xref:Directory_Servers.adoc#bh-Installed_Documentation_OpenLDAP[Installed " +"Documentation])." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:721 +#, no-wrap +msgid "Loading Modules and Backends" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:724 +msgid "" +"indexterm:[OpenLDAP,configuration,TLS]indexterm:[OpenLDAP,directories,/etc/openldap/slapd.d/]indexterm:[OpenLDAP,modules]indexterm:[OpenLDAP,backends] " +"You can enhance the `slapd` service with dynamically loaded modules. Support " +"for these modules must be enabled with the [option]`--enable-modules` option " +"when configuring `slapd`. Modules are stored in files with the *.la* " +"extension:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:728 +#, no-wrap +msgid "pass:quotes[_module_name_].la\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:731 +msgid "" +"_Backends_ store or retrieve data in response to LDAP requests. Backends may " +"be compiled statically into `slapd`, or when module support is enabled, they " +"may be dynamically loaded. In the latter case, the following naming " +"convention is applied:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:735 +#, no-wrap +msgid "back_pass:quotes[_backend_name_].la\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:738 +msgid "" +"To load a module or a backend, use the following directive in " +"`/etc/openldap/slapd.d/`:" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:739 +#, no-wrap +msgid "[option]`olcModuleLoad`" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:740 +msgid "" +"The [option]`olcModuleLoad` directive specifies a dynamically loadable " +"module to load. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:744 +#, no-wrap +msgid "[option]`olcModuleLoad`: _module_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:747 +msgid "" +"Here, _module_ stands either for a file containing the module, or a backend, " +"that will be loaded." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/OpenLDAP.adoc:749 +#, no-wrap +msgid "SELinux Policy for Applications Using LDAP" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:752 +msgid "" +"SELinux is an implementation of a mandatory access control mechanism in the " +"Linux kernel. By default, SELinux prevents applications from accessing an " +"OpenLDAP server. To enable authentication through LDAP, which is required by " +"several applications, the `allow_ypbind` SELinux Boolean needs to be " +"enabled. Certain applications also demand an enabled " +"`authlogin_nsswitch_use_ldap` Boolean in this scenario. Execute the " +"following commands to enable the aforementioned Booleans:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:756 +#, no-wrap +msgid "~]#{nbsp}setsebool -P allow_ypbind=pass:quotes[`1`]\n" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:761 +#, no-wrap +msgid "~]#{nbsp}setsebool -P authlogin_nsswitch_use_ldap=pass:quotes[`1`]\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:764 +msgid "" +"The [option]`-P` option makes this setting persistent across system " +"reboots. See the " +"link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/SELinux_Users_and_Administrators_Guide/++[Red{nbsp}Hat " +"Enterprise{nbsp}Linux{nbsp}7 SELinux User's and Administrator's Guide] for " +"more detailed information about SELinux." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/OpenLDAP.adoc:766 +#, no-wrap +msgid "Running an OpenLDAP Server" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:769 +msgid "" +"indexterm:[slapd,OpenLDAP] This section describes how to start, stop, " +"restart, and check the current status of the [application]*Standalone LDAP " +"Daemon*. For more information on how to manage system services in general, " +"see " +"xref:infrastructure-services/Services_and_Daemons.adoc#ch-Services_and_Daemons[Services " +"and Daemons]." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:771 +#, no-wrap +msgid "Starting the Service" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:774 +msgid "" +"indexterm:[OpenLDAP,running] To start the `slapd` service in the current " +"session, type the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:778 +#, no-wrap +msgid "~]#{nbsp}systemctl start slapd.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:781 +msgid "" +"To configure the service to start automatically at the boot time, use the " +"following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:785 +#, no-wrap +msgid "~]#{nbsp}systemctl enable slapd.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:788 +#: ./pages/_partials/servers/OpenLDAP.adoc:808 +msgid "" +"See " +"xref:infrastructure-services/Services_and_Daemons.adoc#ch-Services_and_Daemons[Services " +"and Daemons] for more information on how to configure services in {MAJOROS}." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:790 +#, no-wrap +msgid "Stopping the Service" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:793 +msgid "" +"indexterm:[OpenLDAP,stopping] To stop the running `slapd` service in the " +"current session, type the following at a shell prompt as `root`:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:800 +msgid "" +"To prevent the service from starting automatically at the boot time, type as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:805 +#, no-wrap +msgid "" +"~]#{nbsp}systemctl disable slapd.service\n" +"rm '/etc/systemd/system/multi-user.target.wants/slapd.service'\n" +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:810 +#, no-wrap +msgid "Restarting the Service" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:813 +msgid "" +"indexterm:[OpenLDAP,restarting] To restart the running `slapd` service, type " +"the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:817 +#, no-wrap +msgid "~]#{nbsp}systemctl restart slapd.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:820 +msgid "" +"This stops the service and immediately starts it again. Use this command to " +"reload the configuration." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:822 +#, no-wrap +msgid "Verifying the Service Status" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:825 +msgid "" +"indexterm:[OpenLDAP,checking status] To verify that the `slapd` service is " +"running, type the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:830 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#systemctl is-active " +"slapd.service#\n" +"active\n" +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/OpenLDAP.adoc:833 +#, no-wrap +msgid "Configuring a System to Authenticate Using OpenLDAP" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:836 +msgid "" +"In order to configure a system to authenticate using OpenLDAP, make sure " +"that the appropriate packages are installed on both LDAP server and client " +"machines. For information on how to set up the server, follow the " +"instructions in xref:Directory_Servers.adoc#s2-ldap-installation[Installing " +"the OpenLDAP Suite] and " +"xref:Directory_Servers.adoc#s2-ldap-configuration[Configuring an OpenLDAP " +"Server]. On a client, type the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:840 +#, no-wrap +msgid "~]#{nbsp}dnf install openldap openldap-clients nss-pam-ldapd\n" +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:843 +#, no-wrap +msgid "Migrating Old Authentication Information to LDAP Format" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:846 +msgid "" +"indexterm:[OpenLDAP,migrating authentication information] The " +"[package]*migrationtools* package provides a set of shell and Perl scripts " +"to help you migrate authentication information into an LDAP format. To " +"install this package, type the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:850 +#, no-wrap +msgid "~]#{nbsp}dnf install migrationtools\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:853 +msgid "" +"This will install the scripts to the `/usr/share/migrationtools/` " +"directory. Once installed, edit the " +"`/usr/share/migrationtools/migrate_common.ph` file and change the following " +"lines to reflect the correct domain, for example:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:857 +#, no-wrap +msgid "" +"# Default DNS domain\n" +"$DEFAULT_MAIL_DOMAIN = \"example.com\";\n" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:860 +#, no-wrap +msgid "" +"# Default base\n" +"$DEFAULT_BASE = \"dc=example,dc=com\";\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:863 +msgid "" +"Alternatively, you can specify the environment variables directly on the " +"command line. For example, to run the `migrate_all_online.sh` script with " +"the default base set to `dc=example,dc=com`, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:868 +#, no-wrap +msgid "" +"~]#{nbsp}export DEFAULT_BASE=\"dc=example,dc=com\" \\\n" +"/usr/share/migrationtools/migrate_all_online.sh\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:871 +msgid "" +"To decide which script to run in order to migrate the user database, see " +"xref:Directory_Servers.adoc#table-ldap-migrationtools[Commonly used LDAP " +"migration scripts]." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:873 +#, no-wrap +msgid "Commonly used LDAP migration scripts" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/OpenLDAP.adoc:884 +#, no-wrap +msgid "" +"|Existing Name Service|Is LDAP Running?|Script to Use\n" +"|`/etc` flat files|yes|`migrate_all_online.sh`\n" +"|`/etc` flat files|no|`migrate_all_offline.sh`\n" +"|NetInfo|yes|`migrate_all_netinfo_online.sh`\n" +"|NetInfo|no|`migrate_all_netinfo_offline.sh`\n" +"|NIS (YP)|yes|`migrate_all_nis_online.sh`\n" +"|NIS (YP)|no|`migrate_all_nis_offline.sh`\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:887 +msgid "" +"For more information on how to use these scripts, see the `README` and the " +"`migration-tools.txt` files in the `/usr/share/doc/migrationtools/` " +"directory." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/OpenLDAP.adoc:889 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:892 +msgid "" +"The following resources offer additional information on the Lightweight " +"Directory Access Protocol. Before configuring LDAP on your system, it is " +"highly recommended that you review these resources, especially the " +"[citetitle]_OpenLDAP Software Administrator's Guide_." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:894 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:896 +msgid "" +"The following documentation is installed with the " +"[package]*openldap-servers* package:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:898 +msgid "" +"`/usr/share/doc/openldap-servers/guide.html` — A copy of the " +"[citetitle]_OpenLDAP Software Administrator's Guide_." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:900 +msgid "" +"`/usr/share/doc/openldap-servers/README.schema` — A README file " +"containing the description of installed schema files." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:902 +msgid "" +"Additionally, there is also a number of manual pages that are installed with " +"the [package]*openldap*, [package]*openldap-servers*, and " +"[package]*openldap-clients* packages:" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:903 +#, no-wrap +msgid "Client Applications" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:904 +#: ./pages/_partials/servers/OpenLDAP.adoc:922 +#: ./pages/_partials/servers/OpenLDAP.adoc:926 +#: ./pages/_partials/servers/OpenLDAP.adoc:936 +msgid "{blank}" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:906 +#, no-wrap +msgid "" +"*ldapadd*(1) — The manual page for the [command]#ldapadd# command " +"describes how to add entries to an LDAP directory.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:908 +#, no-wrap +msgid "" +"*ldapdelete*(1) — The manual page for the [command]#ldapdelete# " +"command describes how to delete entries within an LDAP directory.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:910 +#, no-wrap +msgid "" +"*ldapmodify*(1) — The manual page for the [command]#ldapmodify# " +"command describes how to modify entries within an LDAP directory.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:912 +#, no-wrap +msgid "" +"*ldapsearch*(1) — The manual page for the [command]#ldapsearch# " +"command describes how to search for entries within an LDAP directory.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:914 +#, no-wrap +msgid "" +"*ldappasswd*(1) — The manual page for the [command]#ldappasswd# " +"command describes how to set or change the password of an LDAP user.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:916 +#, no-wrap +msgid "" +"*ldapcompare*(1) — Describes how to use the [command]#ldapcompare# " +"tool.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:918 +#, no-wrap +msgid "" +"*ldapwhoami*(1) — Describes how to use the [command]#ldapwhoami# " +"tool.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:920 +#, no-wrap +msgid "*ldapmodrdn*(1) — Describes how to modify the RDNs of entries.\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:921 +#, no-wrap +msgid "Server Applications" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:924 +#, no-wrap +msgid "*slapd*(8C) — Describes command line options for the LDAP server.\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:925 +#, no-wrap +msgid "Administrative Applications" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:928 +#, no-wrap +msgid "" +"*slapadd*(8C) — Describes command line options used to add entries to " +"a [command]#slapd# database.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:930 +#, no-wrap +msgid "" +"*slapcat*(8C) — Describes command line options used to generate an " +"LDIF file from a [command]#slapd# database.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:932 +#, no-wrap +msgid "" +"*slapindex*(8C) — Describes command line options used to regenerate an " +"index based upon the contents of a [command]#slapd# database.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:934 +#, no-wrap +msgid "" +"*slappasswd*(8C) — Describes command line options used to generate " +"user passwords for LDAP directories.\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:935 +#, no-wrap +msgid "Configuration Files" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:938 +#, no-wrap +msgid "" +"*ldap.conf*(5) — The manual page for the `ldap.conf` file describes " +"the format and options available within the configuration file for LDAP " +"clients.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:940 +#, no-wrap +msgid "" +"*slapd-config*(5) — Describes the format and options available within " +"the `/etc/openldap/slapd.d` configuration directory.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:941 +#, no-wrap +msgid "Online Documentation" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:943 +#, no-wrap +msgid "link:++https://www.openldap.org/doc/admin24/++[]" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:944 +msgid "" +"The current version of the [citetitle]_OpenLDAP Software Administrator's " +"Guide_." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:945 +#, no-wrap +msgid "link:++https://www.kingsmountain.com/ldapRoadmap.shtml++[]" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:946 +msgid "" +"Jeff Hodges' [citetitle]_LDAP Roadmap & FAQ_ containing links to several " +"useful resources and emerging news concerning the LDAP protocol." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:947 +#, no-wrap +msgid "link:++http://www.ldapman.org/articles/++[]" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:948 +msgid "" +"A collection of articles that offer a good introduction to LDAP, including " +"methods to design a directory tree and customizing directory structures." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:949 +#, no-wrap +msgid "link:++https://www.padl.com/++[]" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:950 +msgid "A website of developers of several useful LDAP tools." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/OpenLDAP.adoc:952 +#, no-wrap +msgid "Related Books" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:954 +#, no-wrap +msgid "" +"[citetitle]_OpenLDAP by Example_ by John Terpstra and Benjamin Coles; " +"Prentice Hall." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:955 +msgid "A collection of practical exercises in the OpenLDAP deployment." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:956 +#, no-wrap +msgid "[citetitle]_Implementing LDAP_ by Mark Wilcox; Wrox Press, Inc." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:957 +msgid "" +"A book covering LDAP from both the system administrator's and software " +"developer's perspective." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:958 +#, no-wrap +msgid "" +"[citetitle]_Understanding and Deploying LDAP Directory Services_ by Tim " +"Howes et al.; Macmillan Technical Publishing." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:958 +msgid "" +"A book covering LDAP design principles, as well as its deployment in a " +"production environment." +msgstr "" diff --git a/po/fr/rawhide/pages/_partials/servers/Printer_Configuration.po b/po/fr/rawhide/pages/_partials/servers/Printer_Configuration.po new file mode 100644 index 00000000000..48b22ae9e67 --- /dev/null +++ b/po/fr/rawhide/pages/_partials/servers/Printer_Configuration.po @@ -0,0 +1,1426 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title == +#: ./pages/_partials/servers/Printer_Configuration.adoc:3 +#, no-wrap +msgid "Printer Configuration" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:6 +msgid "" +"indexterm:[CUPS,Printer Configuration]indexterm:[printers,Printer " +"Configuration] The [application]*Printers* configuration tool serves for " +"printer configuring, maintenance of printer configuration files, print spool " +"directories and print filters, and printer classes management." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:8 +msgid "" +"The tool is based on the Common Unix Printing System (*CUPS*). If you " +"upgraded the system from a previous {MAJOROS} version that used CUPS, the " +"upgrade process preserved the configured printers." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:9 +#, no-wrap +msgid "Using the CUPS web application or command-line tools" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:14 +msgid "" +"indexterm:[Printer Configuration,CUPS] You can perform the same and " +"additional operations on printers directly from the CUPS web application or " +"command line. To access the application, in a web browser, go to " +"link:++http://localhost:631/++[http://localhost:631/]. For CUPS manuals " +"refer to the links on the `Home` tab of the web site." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/Printer_Configuration.adoc:18 +#, no-wrap +msgid "Starting the Printers Configuration Tool" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:21 +msgid "" +"With the [application]*Printers* configuration tool you can perform various " +"operations on existing printers and set up new printers. You can also use " +"CUPS directly (go to link:++http://localhost:631/++[http://localhost:631/] " +"to access the CUPS web application)." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:23 +msgid "" +"To start the [application]*Printers* configuration tool if using the GNOME " +"desktop, press the kbd:[Super] key to enter the Activities Overview, type " +"[command]#Printers#, and then press kbd:[Enter]. The [application]*Printers* " +"configuration tool appears. The kbd:[Super] key appears in a variety of " +"guises, depending on the keyboard and other hardware, but often as either " +"the Windows or Command key, and typically to the left of the kbd:[Spacebar]." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:25 +msgid "" +"The `Printers` window depicted in " +"xref:File_and_Print_Servers.adoc#fig-printconf-main[Printers Configuration " +"window] appears." +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:27 +#: ./pages/_partials/servers/Printer_Configuration.adoc:29 +#, no-wrap +msgid "Printers Configuration window" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:29 +#, no-wrap +msgid "printconf-main.png" +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/Printer_Configuration.adoc:32 +#, no-wrap +msgid "Starting Printer Setup" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:35 +msgid "" +"indexterm:[Printer Configuration,New Printer] Printer setup process varies " +"depending on the printer queue type." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:37 +msgid "" +"If you are setting up a local printer connected with USB, the printer is " +"discovered and added automatically. You will be prompted to confirm the " +"packages to be installed and provide an administrator or the `root` user " +"password. Local printers connected with other port types and network " +"printers need to be set up manually." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:41 +msgid "Follow this procedure to start a manual printer setup:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:43 +msgid "" +"Start the Printers configuration tool (refer to " +"xref:File_and_Print_Servers.adoc#sec-Starting_Printer_Config[Starting the " +"Printers Configuration Tool])." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:45 +msgid "" +"Select `Unlock` to enable changes to be made. In the `Authentication " +"Required` box, type an administrator or the `root` user password and " +"confirm." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:47 +msgid "" +"Select the plus sign to open the `Add a New Printer` dialog. Select the " +"printer from the list or enter its address below." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/Printer_Configuration.adoc:49 +#, no-wrap +msgid "Adding a Local Printer" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:52 +msgid "" +"indexterm:[Printer Configuration,Local Printers] Follow this procedure to " +"add a local printer connected with other than a serial port:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:56 +msgid "" +"Open the `Add a New Printer` dialog (refer to " +"xref:File_and_Print_Servers.adoc#sec-Setting_Printer[Starting Printer " +"Setup])." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:58 +msgid "" +"If the device does not appear automatically, select the port to which the " +"printer is connected in the list on the left (such as `Serial Port #1` or " +"`LPT #1`)." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:60 +msgid "On the right, enter the connection properties:" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:61 +#, no-wrap +msgid "for `Enter URI`" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:62 +msgid "`URI` (for example file:/dev/lp0)" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:63 +#, no-wrap +msgid "for `Serial Port`" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:64 +msgid "Baud Rate" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:66 +msgid "Parity" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:68 +msgid "Data Bits" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:70 +msgid "Flow Control" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:71 +#: ./pages/_partials/servers/Printer_Configuration.adoc:73 +#, no-wrap +msgid "Adding a local printer" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:73 +#, no-wrap +msgid "print_conf_window.png" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:76 +#: ./pages/_partials/servers/Printer_Configuration.adoc:102 +#: ./pages/_partials/servers/Printer_Configuration.adoc:225 +#: ./pages/_partials/servers/Printer_Configuration.adoc:276 +msgid "Click btn:[Forward]." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:78 +#: ./pages/_partials/servers/Printer_Configuration.adoc:104 +#: ./pages/_partials/servers/Printer_Configuration.adoc:136 +#: ./pages/_partials/servers/Printer_Configuration.adoc:165 +#: ./pages/_partials/servers/Printer_Configuration.adoc:227 +msgid "" +"Select the printer model. See " +"xref:File_and_Print_Servers.adoc#s1-printing-select-model[Selecting the " +"Printer Model and Finishing] for details." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/Printer_Configuration.adoc:80 +#, no-wrap +msgid "Adding an AppSocket/HP JetDirect printer" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:83 +msgid "Follow this procedure to add an AppSocket/HP JetDirect printer:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:87 +msgid "" +"Open the `Add a New Printer` dialog (refer to " +"xref:File_and_Print_Servers.adoc#sec-Starting_Printer_Config[Starting the " +"Printers Configuration Tool])." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:89 +msgid "" +"In the list on the left, select menu:Network " +"Printer[pass:attributes[{blank}]`AppSocket/HP " +"JetDirect`pass:attributes[{blank}]]." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:91 +#: ./pages/_partials/servers/Printer_Configuration.adoc:121 +#: ./pages/_partials/servers/Printer_Configuration.adoc:150 +msgid "On the right, enter the connection settings:" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:92 +#, no-wrap +msgid "`Hostname`" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:93 +msgid "Printer host name or `IP` address." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:94 +#, no-wrap +msgid "`Port Number`" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:95 +msgid "Printer port listening for print jobs (`9100` by default)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:97 +#, no-wrap +msgid "Adding a JetDirect printer" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:99 +#, no-wrap +msgid "Adding a JetDirect Printer" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:99 +#, no-wrap +msgid "printconf-jetdirect.png" +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/Printer_Configuration.adoc:106 +#, no-wrap +msgid "Adding an IPP Printer" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:109 +msgid "" +"indexterm:[Printer Configuration,IPP Printers] An `IPP` printer is a printer " +"attached to a different system on the same TCP/IP network. The system this " +"printer is attached to may either be running CUPS or simply configured to " +"use `IPP`." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:111 +msgid "" +"If a firewall is enabled on the printer server, then the firewall must be " +"configured to allow incoming `TCP` connections on port `631`. Note that the " +"CUPS browsing protocol allows client machines to discover shared CUPS queues " +"automatically. To enable this, the firewall on the client machine must be " +"configured to allow incoming `UDP` packets on port `631`." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:115 +msgid "Follow this procedure to add an `IPP` printer:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:117 +msgid "" +"Open the `Printers` dialog (refer to " +"xref:File_and_Print_Servers.adoc#sec-Setting_Printer[Starting Printer " +"Setup])." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:119 +msgid "" +"In the list of devices on the left, select Network Printer and `Internet " +"Printing Protocol (ipp)` or `Internet Printing Protocol (https)`." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:122 +#: ./pages/_partials/servers/Printer_Configuration.adoc:151 +#, no-wrap +msgid "`Host`" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:123 +msgid "The host name of the `IPP` printer." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:124 +#: ./pages/_partials/servers/Printer_Configuration.adoc:155 +#, no-wrap +msgid "`Queue`" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:125 +#: ./pages/_partials/servers/Printer_Configuration.adoc:156 +msgid "" +"The queue name to be given to the new queue (if the box is left empty, a " +"name based on the device node will be used)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:127 +#, no-wrap +msgid "Adding an IPP printer" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:129 +#, no-wrap +msgid "Networked IPP Printer" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:129 +#, no-wrap +msgid "printconf-ipp.png" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:132 +msgid "Optionally, click btn:[Verify] to detect the printer." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:134 +#: ./pages/_partials/servers/Printer_Configuration.adoc:163 +#: ./pages/_partials/servers/Printer_Configuration.adoc:259 +msgid "Click btn:[Forward] to continue." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/Printer_Configuration.adoc:138 +#, no-wrap +msgid "Adding an LPD/LPR Host or Printer" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:140 +msgid "indexterm:[Printer Configuration,LDP/LPR Printers]" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:144 +msgid "Follow this procedure to add an LPD/LPR host or printer:" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:146 +#: ./pages/_partials/servers/Printer_Configuration.adoc:190 +msgid "" +"Open the `New Printer` dialog (refer to " +"xref:File_and_Print_Servers.adoc#sec-Setting_Printer[Starting Printer " +"Setup])." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:148 +msgid "" +"In the list of devices on the left, select menu:Network " +"Printer[pass:attributes[{blank}]`LPD/LPR Host or " +"Printer`pass:attributes[{blank}]]." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:152 +msgid "The host name of the LPD/LPR printer or host." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:154 +msgid "Optionally, click btn:[Probe] to find queues on the LPD host." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:158 +#, no-wrap +msgid "Adding an LPD/LPR printer" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:160 +#, no-wrap +msgid "Adding an LPD/LPR Printer" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:160 +#, no-wrap +msgid "printconf-lpd.png" +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/Printer_Configuration.adoc:167 +#, no-wrap +msgid "Adding a Samba (SMB) printer" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:169 +msgid "" +"indexterm:[Printer Configuration,Samba Printers]indexterm:[Samba,Samba " +"Printers]" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:173 +msgid "Follow this procedure to add a Samba printer:" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:174 +#, no-wrap +msgid "Installing the samba-client package" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:179 +msgid "" +"Note that in order to add a Samba printer, you need to have the " +"[package]*samba-client* package installed. You can do so by running, as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/Printer_Configuration.adoc:183 +#, no-wrap +msgid "[command]#dnf install samba-client#\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:186 +msgid "" +"For more information on installing packages with DNF, refer to " +"xref:package-management/DNF.adoc#sec-Installing[Installing Packages]." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:192 +msgid "" +"In the list on the left, select menu:Network " +"Printer[pass:attributes[{blank}]`Windows Printer via " +"SAMBA`pass:attributes[{blank}]]." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:194 +msgid "" +"Enter the SMB address in the `smb://` field. Use the format _computer " +"name/printer share_. In " +"xref:File_and_Print_Servers.adoc#fig-printconf-smb[Adding a SMB printer], " +"the _computer name_ is [command]#dellbox# and the _printer share_ is " +"[command]#r2#." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:196 +#, no-wrap +msgid "Adding a SMB printer" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:198 +#, no-wrap +msgid "SMB Printer" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:198 +#, no-wrap +msgid "printconf-smb.png" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:201 +msgid "" +"Click btn:[Browse] to see the available workgroups/domains. To display only " +"queues of a particular host, type in the host name (NetBios name) and click " +"btn:[Browse]." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:203 +msgid "Select either of the options:" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:205 +msgid "" +"`Prompt user if authentication is required`: user name and password are " +"collected from the user when printing a document." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:207 +msgid "" +"`Set authentication details now`: provide authentication information now so " +"it is not required later. In the `Username` field, enter the user name to " +"access the printer. This user must exist on the SMB system, and the user " +"must have permission to access the printer. The default user name is " +"typically `guest` for Windows servers, or `nobody` for Samba servers." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:209 +msgid "" +"Enter the `Password` (if required) for the user specified in the `Username` " +"field." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:210 +#, no-wrap +msgid "Be careful when choosing a password" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:215 +msgid "" +"Samba printer user names and passwords are stored in the printer server as " +"unencrypted files readable by `root` and the Linux Printing Daemon, " +"`lpd`. Thus, other users that have `root` access to the printer server can " +"view the user name and password you use to access the Samba printer." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:217 +msgid "" +"Therefore, when you choose a user name and password to access a Samba " +"printer, it is advisable that you choose a password that is different from " +"what you use to access your local {MAJOROS} system." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:219 +msgid "" +"If there are files shared on the Samba print server, it is recommended that " +"they also use a password different from what is used by the print queue." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:223 +msgid "" +"Click btn:[Verify] to test the connection. Upon successful verification, a " +"dialog box appears confirming printer share accessibility." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/Printer_Configuration.adoc:229 +#, no-wrap +msgid "Selecting the Printer Model and Finishing" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:232 +msgid "" +"Once you have properly selected a printer connection type, the system " +"attempts to acquire a driver. If the process fails, you can locate or search " +"for the driver resources manually." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:236 +msgid "" +"Follow this procedure to provide the printer driver and finish the " +"installation:" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:238 +msgid "" +"In the window displayed after the automatic driver detection has failed, " +"select one of the following options:" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:240 +msgid "" +"`Select printer from database` — the system chooses a driver based on the " +"selected make of your printer from the list of `Makes`. If your printer " +"model is not listed, choose `Generic`." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:242 +msgid "" +"`Provide PPD file` — the system uses the provided _PostScript Printer " +"Description_ (*PPD*) file for installation. A PPD file may also be delivered " +"with your printer as being normally provided by the manufacturer. If the PPD " +"file is available, you can choose this option and use the browser bar below " +"the option description to select the PPD file." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:244 +msgid "" +"`Search for a printer driver to download` — enter the make and model of your " +"printer into the `Make and model` field to search on OpenPrinting.org for " +"the appropriate packages." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:246 +#, no-wrap +msgid "Selecting a printer brand" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:248 +#, no-wrap +msgid "Selecting a printer brand from the printer database brands." +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:248 +#, no-wrap +msgid "printconf-select-model.png" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:251 +msgid "" +"Depending on your previous choice provide details in the area displayed " +"below:" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:253 +msgid "Printer brand for the `Select printer from database` option." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:255 +msgid "PPD file location for the `Provide PPD file` option." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:257 +msgid "" +"Printer make and model for the `Search for a printer driver to download` " +"option." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:261 +msgid "" +"If applicable for your option, window shown in " +"xref:File_and_Print_Servers.adoc#fig-printconf-select-driver[Selecting a " +"printer model] appears. Choose the corresponding model in the `Models` " +"column on the left." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:262 +#, no-wrap +msgid "Selecting a printer driver" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:267 +msgid "" +"On the right, the recommended printer driver is automatically selected; " +"however, you can select another available driver. The print driver processes " +"the data that you want to print into a format the printer can " +"understand. Since a local printer is attached directly to your computer, you " +"need a printer driver to process the data that is sent to the printer." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:271 +#, no-wrap +msgid "Selecting a printer model" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:273 +#, no-wrap +msgid "Selecting a Printer Model with a Driver Menu" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:273 +#, no-wrap +msgid "printconf-select-driver.png" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:278 +msgid "" +"Under the `Describe Printer` enter a unique name for the printer in the " +"`Printer Name` field. The printer name can contain letters, numbers, dashes " +"(-), and underscores (_); it *must not* contain any spaces. You can also use " +"the `Description` and `Location` fields to add further printer " +"information. Both fields are optional, and may contain spaces." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:280 +#, no-wrap +msgid "Printer setup" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:282 +#, no-wrap +msgid "Printer Setup" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:282 +#, no-wrap +msgid "printconf-add-printer.png" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:285 +msgid "" +"Click btn:[Apply] to confirm your printer configuration and add the print " +"queue if the settings are correct. Click btn:[Back] to modify the printer " +"configuration." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:287 +msgid "" +"After the changes are applied, a dialog box appears allowing you to print a " +"test page. Click btn:[Print Test Page] to print a test page " +"now. Alternatively, you can print a test page later as described in " +"xref:File_and_Print_Servers.adoc#s1-printing-test-page[Printing a Test " +"Page]." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/Printer_Configuration.adoc:289 +#, no-wrap +msgid "Printing a Test Page" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:294 +msgid "" +"After you have set up a printer or changed a printer configuration, print a " +"test page to make sure the printer is functioning properly:" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:296 +msgid "Right-click the printer in the `Printing` window and click `Properties`." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:298 +msgid "In the Properties window, click `Settings` on the left." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:300 +msgid "On the displayed `Settings` tab, click the btn:[Print Test Page] button." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/Printer_Configuration.adoc:302 +#, no-wrap +msgid "Modifying Existing Printers" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:305 +msgid "" +"To delete an existing printer, in the `Printer` configuration window, select " +"the printer and go to " +"menu:Printer[pass:attributes[{blank}]`Delete`pass:attributes[{blank}]]. " +"Confirm the printer deletion. Alternatively, press the kbd:[Delete] key." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:307 +msgid "" +"To set the default printer, right-click the printer in the printer list and " +"click the `Set As Default` button in the context menu." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/Printer_Configuration.adoc:308 +#, no-wrap +msgid "The Settings Page" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:311 +msgid "" +"indexterm:[Printer Configuration,Settings] To change printer driver " +"configuration, double-click the corresponding name in the `Printer` list and " +"click the `Settings` label on the left to display the `Settings` page." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:313 +msgid "" +"You can modify printer settings such as make and model, print a test page, " +"change the device location (URI), and more." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:315 +#, no-wrap +msgid "Settings page" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:317 +#, no-wrap +msgid "Settings Page" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:317 +#, no-wrap +msgid "printconf-config1.png" +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/Printer_Configuration.adoc:319 +#, no-wrap +msgid "The Policies Page" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:322 +msgid "" +"Click the `Policies` button on the left to change settings in printer state " +"and print output." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:324 +msgid "" +"You can select the printer states, configure the `Error Policy` of the " +"printer (you can decide to abort the print job, retry, or stop it if an " +"error occurs)." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:326 +msgid "" +"You can also create a _banner page_ (a page that describes aspects of the " +"print job such as the originating printer, the user name from the which the " +"job originated, and the security status of the document being printed): " +"click the `Starting Banner` or `Ending Banner` drop-down menu and choose the " +"option that best describes the nature of the print jobs (for example, " +"`confidential`)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:328 +#, no-wrap +msgid "Sharing Printers" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:331 +msgid "" +"indexterm:[Printer Configuration,Sharing Printers] On the `Policies` page, " +"you can mark a printer as shared: if a printer is shared, users published on " +"the network can use it. To allow the sharing function for printers, go to " +"menu:Server[pass:attributes[{blank}]`Settings`pass:attributes[{blank}]] and " +"select `Publish shared printers connected to this system`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:333 +#, no-wrap +msgid "Policies page" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:335 +#, no-wrap +msgid "Policies Page" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:335 +#, no-wrap +msgid "printconf-config2.png" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:338 +msgid "" +"Make sure that the firewall allows incoming `TCP` connections to port `631`, " +"the port for the Network Printing Server (`IPP`) protocol. To allow `IPP` " +"traffic through the firewall on {MAJOROSVER}, make use of " +"`firewalld`pass:attributes[{blank}]'s `IPP` service. To do so, proceed as " +"follows:" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:340 +#, no-wrap +msgid "Enabling IPP Service in firewalld" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:342 +msgid "" +"To start the graphical [application]*firewall-config* tool, press the " +"kbd:[Super] key to enter the Activities Overview, type [command]#firewall# " +"and then press kbd:[Enter]. The `Firewall Configuration` window opens. You " +"will be prompted for an administrator or `root` password." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:344 +msgid "" +"Alternatively, to start the graphical firewall configuration tool using the " +"command line, enter the following command as `root` user:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/Printer_Configuration.adoc:348 +#, no-wrap +msgid "~]#{nbsp}firewall-config\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:351 +msgid "The `Firewall Configuration` window opens." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:353 +msgid "" +"Look for the word \"`Connected`\" in the lower left corner. This indicates " +"that the [application]*firewall-config* tool is connected to the user space " +"daemon, `firewalld`." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:355 +msgid "" +"To immediately change the current firewall settings, ensure the drop-down " +"selection menu labeled `Configuration` is set to `Runtime`. Alternatively, " +"to edit the settings to be applied at the next system start, or firewall " +"reload, select `Permanent` from the drop-down list." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:357 +msgid "" +"Select the `Zones` tab and then select the firewall zone to correspond with " +"the network interface to be used. The default is the `public` zone. The " +"`Interfaces` tab shows what interfaces have been assigned to a zone." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:359 +msgid "" +"Select the `Services` tab and then select the `ipp` service to enable " +"sharing. The `ipp-client` service is required for accessing network " +"printers." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:361 +msgid "Close the [application]*firewall-config* tool." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:363 +#, no-wrap +msgid "The Access Control Page" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:366 +msgid "" +"You can change user-level access to the configured printer on the `Access " +"Control` page. Click the `Access Control` label on the left to display the " +"page. Select either `Allow printing for everyone except these users` or " +"`Deny printing for everyone except these users` and define the user set " +"below: enter the user name in the text box and click the btn:[Add] button to " +"add the user to the user set." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:368 +#, no-wrap +msgid "Access Control page" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:370 +#, no-wrap +msgid "Access Control Page" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:370 +#, no-wrap +msgid "printconf-config3.png" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:373 +#, no-wrap +msgid "The Printer Options Page" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:376 +msgid "" +"The `Printer Options` page contains various configuration options for the " +"printer media and output, and its content may vary from printer to " +"printer. It contains general printing, paper, quality, and printing size " +"settings." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:378 +#, no-wrap +msgid "Printer Options page" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:380 +#, no-wrap +msgid "Printer Options Page" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:380 +#, no-wrap +msgid "printconf-config4.png" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:383 +#: ./pages/_partials/servers/Printer_Configuration.adoc:390 +#, no-wrap +msgid "Job Options Page" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:386 +msgid "" +"On the `Job Options` page, you can detail the printer job options. Click the " +"`Job Options` label on the left to display the page. Edit the default " +"settings to apply custom job options, such as number of copies, orientation, " +"pages per side, scaling (increase or decrease the size of the printable " +"area, which can be used to fit an oversize print area onto a smaller " +"physical sheet of print medium), detailed text options, and custom job " +"options." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:388 +#, no-wrap +msgid "Job Options page" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:390 +#, no-wrap +msgid "printconf-config5.png" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:393 +#: ./pages/_partials/servers/Printer_Configuration.adoc:400 +#, no-wrap +msgid "Ink/Toner Levels Page" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:396 +msgid "" +"The `Ink/Toner Levels` page contains details on toner status if available " +"and printer status messages. Click the `Ink/Toner Levels` label on the left " +"to display the page." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:398 +#, no-wrap +msgid "Ink/Toner Levels page" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:400 +#, no-wrap +msgid "printconf-config6.png" +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/Printer_Configuration.adoc:403 +#, no-wrap +msgid "Managing Print Jobs" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:406 +msgid "" +"indexterm:[Printer Configuration,Print Jobs] When you send a print job to " +"the printer daemon, such as printing a text file from [application]*Emacs* " +"or printing an image from [application]*GIMP*, the print job is added to the " +"print spool queue. The print spool queue is a list of print jobs that have " +"been sent to the printer and information about each print request, such as " +"the status of the request, the job number, and more." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:408 +msgid "" +"During the printing process, messages informing about the process appear in " +"the notification area." +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:410 +#: ./pages/_partials/servers/Printer_Configuration.adoc:412 +#, no-wrap +msgid "GNOME Print Status" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:412 +#, no-wrap +msgid "gnome-print-queue.png" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:415 +msgid "" +"To cancel, hold, release, reprint or authenticate a print job, select the " +"job in the [application]*GNOME Print Status* and on the Job menu, click the " +"respective command." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:417 +msgid "" +"To view the list of print jobs in the print spool from a shell prompt, type " +"the command [command]#lpstat -o#. The last few lines look similar to the " +"following:" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:419 +#, no-wrap +msgid "Example of [command]#lpstat -o# output" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/Printer_Configuration.adoc:428 +#, no-wrap +msgid "" +"$ [command]#lpstat -o#\n" +"Charlie-60 twaugh 1024 Tue 08 Feb 2011 16:42:11 " +"GMT\n" +"Aaron-61 twaugh 1024 Tue 08 Feb 2011 16:42:44 " +"GMT\n" +"Ben-62 root 1024 Tue 08 Feb 2011 16:45:42 " +"GMT\n" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:433 +msgid "" +"If you want to cancel a print job, find the job number of the request with " +"the command [command]#lpstat -o# and then use the command [command]#cancel " +"_job number_pass:attributes[{blank}]#. For example, [command]#cancel 60# " +"would cancel the print job in " +"xref:File_and_Print_Servers.adoc#lpq-example[Example of [command]#lpstat -o# " +"output]. You cannot cancel print jobs that were started by other users with " +"the [command]#cancel# command. However, you can enforce deletion of such job " +"by issuing the [command]#cancel -U root " +"_job_number_pass:attributes[{blank}]# command. To prevent such canceling, " +"change the printer operation policy to `Authenticated` to force `root` " +"authentication." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:435 +msgid "" +"You can also print a file directly from a shell prompt. For example, the " +"command [command]#lp sample.txt# prints the text file `sample.txt`. The " +"print filter determines what type of file it is and converts it into a " +"format the printer can understand." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/Printer_Configuration.adoc:437 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:440 +msgid "To learn more about printing on {MAJOROS}, see the following resources." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/Printer_Configuration.adoc:442 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:444 +#, no-wrap +msgid "[command]#man lp#" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:445 +msgid "" +"The manual page for the [command]#lpr# command that allows you to print " +"files from the command line." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:446 +#, no-wrap +msgid "[command]#man cancel#" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:447 +msgid "" +"The manual page for the command-line utility to remove print jobs from the " +"print queue." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:448 +#, no-wrap +msgid "[command]#man mpage#" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:449 +msgid "" +"The manual page for the command-line utility to print multiple pages on one " +"sheet of paper." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:450 +#, no-wrap +msgid "[command]#man cupsd#" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:451 +msgid "The manual page for the CUPS printer daemon." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:452 +#, no-wrap +msgid "[command]#man cupsd.conf#" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:453 +msgid "The manual page for the CUPS printer daemon configuration file." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:454 +#, no-wrap +msgid "[command]#man classes.conf#" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:455 +msgid "The manual page for the class configuration file for CUPS." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:456 +#, no-wrap +msgid "[command]#man lpstat#" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:457 +msgid "" +"The manual page for the [command]#lpstat# command, which displays status " +"information about classes, jobs, and printers." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/Printer_Configuration.adoc:459 +#, no-wrap +msgid "Useful Websites" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:461 +#, no-wrap +msgid "link:++https://wiki.linuxfoundation.org/openprinting/start++[]" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:462 +msgid "" +"[citetitle]_Open Printing_ contains a large amount of information about " +"printing in Linux." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:463 +#, no-wrap +msgid "link:++https://www.cups.org/++[]" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:463 +msgid "Documentation, FAQs, and newsgroups about CUPS." +msgstr "" diff --git a/po/fr/rawhide/pages/_partials/servers/Samba.po b/po/fr/rawhide/pages/_partials/servers/Samba.po new file mode 100644 index 00000000000..c056eb6d8f8 --- /dev/null +++ b/po/fr/rawhide/pages/_partials/servers/Samba.po @@ -0,0 +1,32 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title == +#: ./pages/_partials/servers/Samba.adoc:3 +#, no-wrap +msgid "Samba" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Samba.adoc:8 +msgid "" +"Documentation for configuring and using Samba has been removed due to being " +"outdated. Use " +"link:https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html-single/configuring_and_using_network_file_services/index#assembly_using-samba-as-a-server_configuring-and-using-network-file-services[Red " +"Hat Enterprise Linux 9 Samba documentation] instead." +msgstr "" diff --git a/po/fr/rawhide/pages/_partials/servers/The_Apache_HTTP_Server.po b/po/fr/rawhide/pages/_partials/servers/The_Apache_HTTP_Server.po new file mode 100644 index 00000000000..9f1528bc5e4 --- /dev/null +++ b/po/fr/rawhide/pages/_partials/servers/The_Apache_HTTP_Server.po @@ -0,0 +1,5116 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title == +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:3 +#, no-wrap +msgid "The Apache HTTP Server" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:6 +msgid "" +"indexterm:[httpd,Apache HTTP Server] The web server available in {MAJOROS} " +"is the Apache HTTP server daemon, `httpd`, an open source web server " +"developed by the link:++https://www.apache.org/++[Apache Software " +"Foundation]. This section describes the basic configuration of the `httpd` " +"service, and covers some advanced topics such as adding server modules, " +"setting up virtual hosts, or configuring the secure HTTP server." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:8 +#, no-wrap +msgid "Running the httpd Service" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:11 +msgid "" +"This section describes how to start, stop, restart, and check the current " +"status of the Apache HTTP Server. To be able to use the `httpd` service, " +"make sure you have the [package]*httpd* installed. You can do so by using " +"the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:15 +#, no-wrap +msgid "#{nbsp}dnf install httpd\n" +msgstr "" + +#. link to systemd section when ready +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:18 +msgid "" +"For more information on the concept of targets and how to manage system " +"services in {MAJOROS} in general, see" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:20 +#, no-wrap +msgid "" +" " +"xref:infrastructure-services/Services_and_Daemons.adoc#ch-Services_and_Daemons[Services " +"and Daemons].\n" +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:22 +#, no-wrap +msgid "Starting the Service" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:25 +msgid "" +"indexterm:[Apache HTTP Server,starting] To run the `httpd` service, type the " +"following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:29 +#, no-wrap +msgid "#{nbsp}systemctl start httpd.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:32 +msgid "" +"If you want the service to start automatically at boot time, use the " +"following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:37 +#, no-wrap +msgid "" +"#{nbsp}systemctl enable httpd.service\n" +"ln -s '/usr/lib/systemd/system/httpd.service' " +"'/etc/systemd/system/multi-user.target.wants/httpd.service'\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:39 +#, no-wrap +msgid "Using the secure server" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:44 +msgid "" +"If running the Apache HTTP Server as a secure server, a password may be " +"required after the machine boots if using an encrypted private SSL key." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:48 +#, no-wrap +msgid "Stopping the Service" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:51 +msgid "" +"indexterm:[Apache HTTP Server,stopping] To stop the running `httpd` service, " +"type the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:55 +#, no-wrap +msgid "#{nbsp}systemctl stop httpd.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:58 +msgid "To prevent the service from starting automatically at boot time, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:63 +#, no-wrap +msgid "" +"#{nbsp}systemctl disable httpd.service\n" +"rm '/etc/systemd/system/multi-user.target.wants/httpd.service'\n" +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:66 +#, no-wrap +msgid "Restarting the Service" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:69 +msgid "" +"indexterm:[Apache HTTP Server,restarting] There are three different ways to " +"restart a running `httpd` service:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:71 +msgid "To restart the service completely, enter the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:75 +#, no-wrap +msgid "#{nbsp}systemctl restart httpd.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:78 +msgid "" +"This stops the running `httpd` service and immediately starts it again. Use " +"this command after installing or removing a dynamically loaded module such " +"as PHP." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:80 +msgid "" +"To only reload the configuration without interrupting active requests, as " +"`root`, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:84 +#, no-wrap +msgid "#{nbsp}systemctl reload httpd.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:87 +msgid "" +"This causes the running `httpd` service to reload its configuration " +"file. Any requests currently being processed will not be interrupted, so " +"configuration changes will only take effect for new client connections." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:89 +msgid "" +"To reload the configuration and immediately terminate any active " +"connections, enter the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:93 +#, no-wrap +msgid "#{nbsp}systemctl kill --kill-who=main --signal=HUP httpd\n" +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:97 +#, no-wrap +msgid "Verifying the Service Status" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:100 +msgid "" +"indexterm:[Apache HTTP Server,checking status] To verify that the `httpd` " +"service is running, type the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:105 +#, no-wrap +msgid "" +"#{nbsp}systemctl is-active httpd.service\n" +"active\n" +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:108 +#, no-wrap +msgid "Editing the Configuration Files" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:111 +msgid "" +"When the `httpd` service is started, by default, it reads the configuration " +"from locations that are listed in " +"xref:Web_Servers.adoc#table-apache-editing-files[The httpd service " +"configuration files]." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:113 +#, no-wrap +msgid "The httpd service configuration files" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:122 +#, no-wrap +msgid "" +"|Path|Description\n" +"|indexterm:[Apache HTTP Server,files,/etc/httpd/conf/httpd.conf]\n" +" `/etc/httpd/conf/httpd.conf`|The main configuration file.\n" +"|indexterm:[Apache HTTP Server,directories,/etc/httpd/conf.d/]\n" +" `/etc/httpd/conf.d/`|An auxiliary directory for configuration " +"files that are included in the main configuration file.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:127 +msgid "" +"Although the default configuration should be suitable for most situations, " +"it is a good idea to become at least familiar with some of the more " +"important configuration options. Note that for any changes to take effect, " +"the web server has to be restarted first. See " +"xref:Web_Servers.adoc#s3-apache-running-restarting[Restarting the Service] " +"for more information on how to restart the `httpd` service. " +"indexterm:[Apache HTTP Server,checking configuration] To check the " +"configuration for possible errors, type the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:132 +#, no-wrap +msgid "" +"#{nbsp}apachectl configtest\n" +"Syntax OK\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:135 +msgid "" +"To make the recovery from mistakes easier, it is recommended that you make a " +"copy of the original file before editing it." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:137 +#, no-wrap +msgid "Common httpd.conf Directives" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:140 +msgid "" +"indexterm:[Apache HTTP Server,files,/etc/httpd/conf/httpd.conf] The " +"following directives are commonly used in the `/etc/httpd/conf/httpd.conf` " +"configuration file:" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:141 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,] " +"[option]``" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:142 +msgid "" +"The [option]`` directive allows you to apply certain directives " +"to a particular directory only. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:149 +#, no-wrap +msgid "" +"<Directory _directory_pass:attributes[{blank}]>\n" +" _directive_\n" +" …\n" +"</Directory>\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:152 +msgid "" +"The _directory_ can be either a full path to an existing directory in the " +"local file system, or a wildcard expression." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:154 +msgid "" +"This directive can be used to configure additional `cgi-bin` directories for " +"server-side scripts located outside the directory that is specified by " +"[option]`ScriptAlias`. In this case, the [option]`ExecCGI` and " +"[option]`AddHandler` directives must be supplied, and the permissions on the " +"target directory must be set correctly (that is, `0755`)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:156 +#, no-wrap +msgid "Using the directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:167 +#, no-wrap +msgid "" +"<Directory /var/www/html>\n" +" Options Indexes FollowSymLinks\n" +" AllowOverride None\n" +" Order allow,deny\n" +" Allow from all\n" +"</Directory>\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:171 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,] " +"[option]``" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:172 +msgid "" +"The [option]`IfDefine` directive allows you to use certain directives only " +"when a particular parameter is supplied on the command line. It takes the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:179 +#, no-wrap +msgid "" +"<IfDefine !_parameter_pass:attributes[{blank}]>\n" +" _directive_\n" +" …\n" +"</IfDefine>\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:182 +msgid "" +"The _parameter_ can be supplied at a shell prompt using the " +"[option]`-D`pass:attributes[{blank}]pass:attributes[{blank}]_parameter_ " +"command line option (for example, [command]#httpd -DEnableHome#). If the " +"optional exclamation mark (that is, `!`) is present, the enclosed directives " +"are used only when the parameter is *not* specified." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:184 +#, no-wrap +msgid "Using the directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:191 +#, no-wrap +msgid "" +"\n" +" UserDir public_html\n" +"\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:195 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,] " +"[option]``" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:196 +msgid "" +"The [option]`` directive allows you to use certain directive only " +"when a particular module is loaded. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:203 +#, no-wrap +msgid "" +"<IfModule !_module_pass:attributes[{blank}]>\n" +" _directive_\n" +" …\n" +"</IfModule>\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:206 +msgid "" +"The _module_ can be identified either by its name, or by the file name. If " +"the optional exclamation mark (that is, `!`) is present, the enclosed " +"directives are used only when the module is *not* loaded." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:208 +#, no-wrap +msgid "Using the directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:216 +#, no-wrap +msgid "" +"\n" +" CacheEnable disk /\n" +" CacheRoot /var/cache/mod_proxy\n" +"\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:220 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,] " +"[option]``" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:221 +msgid "" +"The [option]`` directive allows you to apply certain directives to " +"a particular URL only. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:228 +#, no-wrap +msgid "" +"<Location _url_pass:attributes[{blank}]>\n" +" _directive_\n" +" …\n" +"</Location>\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:231 +msgid "" +"The _url_ can be either a path relative to the directory specified by the " +"[option]`DocumentRoot` directive (for example, `/server-info`), or an " +"external URL such as `http://example.com/server-info`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:233 +#, no-wrap +msgid "Using the directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:244 +#, no-wrap +msgid "" +"<Location /server-info>\n" +" SetHandler server-info\n" +" Order deny,allow\n" +" Deny from all\n" +" Allow from .example.com\n" +"</Location>\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:248 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,] " +"[option]``" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:249 +msgid "" +"The [option]`` directive allows you to apply certain directives to " +"the proxy server only. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:256 +#, no-wrap +msgid "" +"<Proxy _pattern_pass:attributes[{blank}]>\n" +" _directive_\n" +" …\n" +"</Proxy>\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:259 +msgid "" +"The _pattern_ can be an external URL, or a wildcard expression (for example, " +"`http://example.com/*`)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:261 +#, no-wrap +msgid "Using the directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:270 +#, no-wrap +msgid "" +"\n" +" Order deny,allow\n" +" Deny from all\n" +" Allow from .example.com\n" +"\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:274 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,] " +"[option]``" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:275 +msgid "" +"The [option]`` directive allows you apply certain directives to " +"particular virtual hosts only. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:282 +#, no-wrap +msgid "" +"<VirtualHost " +"_address_:pass:attributes[{blank}]_port_pass:attributes[{blank}]…>\n" +" _directive_\n" +" …\n" +"</VirtualHost>\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:285 +msgid "" +"The _address_ can be an IP address, a fully qualified domain name, or a " +"special form as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-virtualhost[Available " +" options]." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:287 +#, no-wrap +msgid "Available options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:294 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`*`|Represents all IP addresses.\n" +"|[option]`_default_`|Represents unmatched IP addresses.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:297 +#, no-wrap +msgid "Using the directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:308 +#, no-wrap +msgid "" +"\n" +" ServerAdmin webmaster@penguin.example.com\n" +" DocumentRoot /www/docs/penguin.example.com\n" +" ServerName penguin.example.com\n" +" ErrorLog logs/penguin.example.com-error_log\n" +" CustomLog logs/penguin.example.com-access_log common\n" +"\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:312 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,AccessFileName] " +"[option]`AccessFileName`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:313 +msgid "" +"The [option]`AccessFileName` directive allows you to specify the file to be " +"used to customize access control information for each directory. It takes " +"the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:317 +#, no-wrap +msgid "AccessFileName _filename_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:322 +msgid "" +"indexterm:[Apache HTTP Server,files,.htaccess]indexterm:[.htaccess,Apache " +"HTTP Server] The _filename_ is a name of the file to look for in the " +"requested directory. By default, the server looks for `.htaccess`. " +"indexterm:[Apache HTTP Server,files,.htpasswd]indexterm:[.htpasswd,Apache " +"HTTP Server] For security reasons, the directive is typically followed by " +"the `Files` tag to prevent the files beginning with `.ht` from being " +"accessed by web clients. This includes the `.htaccess` and `.htpasswd` " +"files." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:324 +#, no-wrap +msgid "Using the AccessFileName directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:329 +#, no-wrap +msgid "AccessFileName .htaccess\n" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:335 +#, no-wrap +msgid "" +"\n" +" Order allow,deny\n" +" Deny from all\n" +" Satisfy All\n" +"\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:339 +#, no-wrap +msgid "indexterm:[Apache HTTP Server,directives,Action] [option]`Action`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:340 +msgid "" +"The [option]`Action` directive allows you to specify a CGI script to be " +"executed when a certain media type is requested. It takes the following " +"form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:344 +#, no-wrap +msgid "Action _content-type_ _path_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:347 +msgid "" +"The _content-type_ has to be a valid MIME type such as `text/html`, " +"`image/png`, or `application/pdf`. The _path_ refers to an existing CGI " +"script, and must be relative to the directory specified by the " +"[option]`DocumentRoot` directive (for example, " +"`/cgi-bin/process-image.cgi`)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:349 +#, no-wrap +msgid "Using the Action directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:355 +#, no-wrap +msgid "Action image/png /cgi-bin/process-image.cgi\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:359 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,AddDescription] " +"[option]`AddDescription`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:360 +msgid "" +"The [option]`AddDescription` directive allows you to specify a short " +"description to be displayed in server-generated directory listings for a " +"given file. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:364 +#, no-wrap +msgid "" +"AddDescription " +"\"pass:attributes[{blank}]_description_pass:attributes[{blank}]\" " +"_filename_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:367 +msgid "" +"The _description_ should be a short text enclosed in double quotes (that is, " +"`\"`). The _filename_ can be a full file name, a file extension, or a " +"wildcard expression." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:369 +#, no-wrap +msgid "Using the AddDescription directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:375 +#, no-wrap +msgid "AddDescription \"GZIP compressed tar archive\" .tgz\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:379 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,AddEncoding] " +"[option]`AddEncoding`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:380 +msgid "" +"The [option]`AddEncoding` directive allows you to specify an encoding type " +"for a particular file extension. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:384 +#, no-wrap +msgid "AddEncoding _encoding_ _extension_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:387 +msgid "" +"The _encoding_ has to be a valid MIME encoding such as `x-compress`, " +"`x-gzip`, etc. The _extension_ is a case sensitive file extension, and is " +"conventionally written with a leading dot (for example, `.gz`)." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:389 +msgid "" +"This directive is typically used to instruct web browsers to decompress " +"certain file types as they are downloaded." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:391 +#, no-wrap +msgid "Using the AddEncoding directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:397 +#, no-wrap +msgid "AddEncoding x-gzip .gz .tgz\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:401 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,AddHandler] " +"[option]`AddHandler`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:402 +msgid "" +"The [option]`AddHandler` directive allows you to map certain file extensions " +"to a selected handler. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:406 +#, no-wrap +msgid "AddHandler _handler_ _extension_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:409 +msgid "" +"The _handler_ has to be a name of previously defined handler. The " +"_extension_ is a case sensitive file extension, and is conventionally " +"written with a leading dot (for example, `.cgi`)." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:411 +msgid "" +"This directive is typically used to treat files with the `.cgi` extension as " +"CGI scripts regardless of the directory they are in. Additionally, it is " +"also commonly used to process server-parsed HTML and image-map files." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:413 +#, no-wrap +msgid "Using the AddHandler option" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:419 +#, no-wrap +msgid "AddHandler cgi-script .cgi\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:423 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,AddIcon] " +"[option]`AddIcon`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:424 +msgid "" +"The [option]`AddIcon` directive allows you to specify an icon to be " +"displayed for a particular file in server-generated directory listings. It " +"takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:428 +#, no-wrap +msgid "AddIcon _path_ _pattern_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:431 +msgid "" +"The _path_ refers to an existing icon file, and must be relative to the " +"directory specified by the [option]`DocumentRoot` directive (for example, " +"`/icons/folder.png`). The _pattern_ can be a file name, a file extension, a " +"wildcard expression, or a special form as described in the following table:" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:433 +#, no-wrap +msgid "Available AddIcon options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:440 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`^^DIRECTORY^^`|Represents a directory.\n" +"|[option]`^^BLANKICON^^`|Represents a blank line.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:443 +#, no-wrap +msgid "Using the AddIcon directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:449 +#, no-wrap +msgid "AddIcon /icons/text.png .txt README\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:453 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,AddIconByEncoding] " +"[option]`AddIconByEncoding`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:454 +msgid "" +"The [option]`AddIconByEncoding` directive allows you to specify an icon to " +"be displayed for a particular encoding type in server-generated directory " +"listings. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:458 +#, no-wrap +msgid "AddIconByEncoding _path_ _encoding_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:461 +msgid "" +"The _path_ refers to an existing icon file, and must be relative to the " +"directory specified by the [option]`DocumentRoot` directive (for example, " +"`/icons/compressed.png`). The _encoding_ has to be a valid MIME encoding " +"such as `x-compress`, `x-gzip`, etc." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:463 +#, no-wrap +msgid "Using the AddIconByEncoding directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:469 +#, no-wrap +msgid "AddIconByEncoding /icons/compressed.png x-compress x-gzip\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:473 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,AddIconByType] " +"[option]`AddIconByType`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:474 +msgid "" +"The [option]`AddIconByType` directive allows you to specify an icon to be " +"displayed for a particular media type in server-generated directory " +"listings. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:478 +#, no-wrap +msgid "AddIconByType _path_ _content-type_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:481 +msgid "" +"The _path_ refers to an existing icon file, and must be relative to the " +"directory specified by the [option]`DocumentRoot` directive (for example, " +"`/icons/text.png`). The _content-type_ has to be either a valid MIME type " +"(for example, `text/html` or `image/png`), or a wildcard expression such as " +"`text/*`, `image/*`, etc." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:483 +#, no-wrap +msgid "Using the AddIconByType directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:488 +#, no-wrap +msgid "AddIconByType /icons/video.png video/*\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:492 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,AddLanguage] " +"[option]`AddLanguage`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:493 +msgid "" +"The [option]`AddLanguage` directive allows you to associate a file extension " +"with a specific language. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:497 +#, no-wrap +msgid "AddLanguage _language_ _extension_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:500 +msgid "" +"The _language_ has to be a valid MIME language such as `cs`, `en`, or " +"`fr`. The _extension_ is a case sensitive file extension, and is " +"conventionally written with a leading dot (for example, `.cs`)." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:502 +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1215 +msgid "" +"This directive is especially useful for web servers that serve content in " +"multiple languages based on the client's language settings." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:504 +#, no-wrap +msgid "Using the AddLanguage directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:510 +#, no-wrap +msgid "AddLanguage cs .cs .cz\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:514 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,AddType] " +"[option]`AddType`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:515 +msgid "" +"The [option]`AddType` directive allows you to define or override the media " +"type for a particular file extension. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:519 +#, no-wrap +msgid "AddType _content-type_ _extension_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:522 +msgid "" +"The _content-type_ has to be a valid MIME type such as `text/html`, " +"`image/png`, etc. The _extension_ is a case sensitive file extension, and is " +"conventionally written with a leading dot (for example, `.cs`)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:524 +#, no-wrap +msgid "Using the AddType directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:530 +#, no-wrap +msgid "AddType application/x-gzip .gz .tgz\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:534 +#, no-wrap +msgid "indexterm:[Apache HTTP Server,directives,Alias] [option]`Alias`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:535 +msgid "" +"The [option]`Alias` directive allows you to refer to files and directories " +"outside the default directory specified by the [option]`DocumentRoot` " +"directive. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:539 +#, no-wrap +msgid "Alias _url-path_ _real-path_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:544 +msgid "" +"The _url-path_ must be relative to the directory specified by the " +"[option]`DocumentRoot` directive (for example, `/images/`). The _real-path_ " +"is a full path to a file or directory in the local file system. " +"indexterm:[Apache HTTP Server,directories,/var/www/icons/] This directive is " +"typically followed by the [option]`Directory` tag with additional " +"permissions to access the target directory. By default, the `/icons/` alias " +"is created so that the icons from `/var/www/icons/` are displayed in " +"server-generated directory listings." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:546 +#, no-wrap +msgid "Using the Alias directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:552 +#, no-wrap +msgid "Alias /icons/ /var/www/icons/\n" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:559 +#, no-wrap +msgid "" +"<Directory \"/var/www/icons\">\n" +" Options Indexes MultiViews FollowSymLinks\n" +" AllowOverride None\n" +" Order allow,deny\n" +" Allow from all\n" +"<Directory>\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:563 +#, no-wrap +msgid "indexterm:[Apache HTTP Server,directives,Allow] [option]`Allow`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:564 +msgid "" +"The [option]`Allow` directive allows you to specify which clients have " +"permission to access a given directory. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:568 +#, no-wrap +msgid "Allow from _client_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:571 +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:868 +msgid "" +"The _client_ can be a domain name, an IP address (both full and partial), a " +"_network_pass:attributes[{blank}]/pass:attributes[{blank}]_netmask_ pair, or " +"`all` for all clients." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:573 +#, no-wrap +msgid "Using the Allow directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:579 +#, no-wrap +msgid "Allow from 192.168.1.0/255.255.255.0\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:583 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,AllowOverride] " +"[option]`AllowOverride`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:585 +msgid "" +"indexterm:[Apache HTTP Server,files,.htaccess]indexterm:[.htaccess] The " +"[option]`AllowOverride` directive allows you to specify which directives in " +"a `.htaccess` file can override the default configuration. It takes the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:589 +#, no-wrap +msgid "AllowOverride _type_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:592 +msgid "" +"The _type_ has to be one of the available grouping options as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-allowoverride[Available " +"AllowOverride options]." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:594 +#, no-wrap +msgid "Available AllowOverride options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:606 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`All`|All directives in `.htaccess` are allowed to override earlier " +"configuration settings.\n" +"|[option]`None`|No directive in `.htaccess` is allowed to override earlier " +"configuration settings.\n" +"|[option]`AuthConfig`|Allows the use of authorization directives such as " +"[option]`AuthName`, [option]`AuthType`, or [option]`Require`.\n" +"|[option]`FileInfo`|Allows the use of file type, metadata, and `mod_rewrite` " +"directives such as [option]`DefaultType`, [option]`RequestHeader`, or " +"[option]`RewriteEngine`, as well as the [option]`Action` directive.\n" +"|[option]`Indexes`|Allows the use of directory indexing directives such as " +"[option]`AddDescription`, [option]`AddIcon`, or [option]`FancyIndexing`.\n" +"|[option]`Limit`|Allows the use of host access directives, that is, " +"[option]`Allow`, [option]`Deny`, and [option]`Order`.\n" +"|[option]`Options`pass:attributes[{blank}]=pass:attributes[{blank}]_option_,…|Allows " +"the use of the [option]`Options` directive. Additionally, you can provide a " +"comma-separated list of options to customize which options can be set using " +"this directive.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:609 +#, no-wrap +msgid "Using the AllowOverride directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:615 +#, no-wrap +msgid "AllowOverride FileInfo AuthConfig Limit\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:619 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,BrowserMatch] " +"[option]`BrowserMatch`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:620 +msgid "" +"The [option]`BrowserMatch` directive allows you to modify the server " +"behavior based on the client's web browser type. It takes the following " +"form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:624 +#, no-wrap +msgid "BrowserMatch _pattern_ _variable_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:627 +msgid "" +"The _pattern_ is a regular expression to match the User-Agent HTTP header " +"field. The _variable_ is an environment variable that is set when the header " +"field matches the pattern." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:629 +msgid "" +"By default, this directive is used to deny connections to specific browsers " +"with known issues, and to disable keepalives and HTTP header flushes for " +"browsers that are known to have problems with these actions." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:631 +#, no-wrap +msgid "Using the BrowserMatch directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:637 +#, no-wrap +msgid "BrowserMatch \"Mozilla/2\" nokeepalive\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:641 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,CacheDefaultExpire] " +"[option]`CacheDefaultExpire`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:642 +msgid "" +"The [option]`CacheDefaultExpire` option allows you to set how long to cache " +"a document that does not have any expiration date or the date of its last " +"modification specified. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:646 +#, no-wrap +msgid "CacheDefaultExpire _time_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:649 +msgid "" +"The _time_ is specified in seconds. The default option is `3600` (that is, " +"one hour)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:651 +#, no-wrap +msgid "Using the CacheDefaultExpire directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:657 +#, no-wrap +msgid "CacheDefaultExpire 3600\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:661 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,CacheDisable] " +"[option]`CacheDisable`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:662 +msgid "" +"The [option]`CacheDisable` directive allows you to disable caching of " +"certain URLs. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:666 +#, no-wrap +msgid "CacheDisable _path_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:669 +msgid "" +"The _path_ must be relative to the directory specified by the " +"[option]`DocumentRoot` directive (for example, `/files/`)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:671 +#, no-wrap +msgid "Using the CacheDisable directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:677 +#, no-wrap +msgid "CacheDisable /temporary\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:681 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,CacheEnable] " +"[option]`CacheEnable`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:682 +msgid "" +"The [option]`CacheEnable` directive allows you to specify a cache type to be " +"used for certain URLs. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:686 +#, no-wrap +msgid "CacheEnable _type_ _url_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:689 +msgid "" +"The _type_ has to be a valid cache type as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-cacheenable[Available cache " +"types]. The _url_ can be a path relative to the directory specified by the " +"[option]`DocumentRoot` directive (for example, `/images/`), a protocol (for " +"example, `ftp://`), or an external URL such as `http://example.com/`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:691 +#, no-wrap +msgid "Available cache types" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:699 +#, no-wrap +msgid "" +"|Type|Description\n" +"|[option]`mem`|The memory-based storage manager.\n" +"|[option]`disk`|The disk-based storage manager.\n" +"|[option]`fd`|The file descriptor cache.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:702 +#, no-wrap +msgid "Using the CacheEnable directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:708 +#, no-wrap +msgid "CacheEnable disk /\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:712 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,CacheLastModifiedFactor] " +"[option]`CacheLastModifiedFactor`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:713 +msgid "" +"The [option]`CacheLastModifiedFactor` directive allows you to customize how " +"long to cache a document that does not have any expiration date specified, " +"but that provides information about the date of its last modification. It " +"takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:717 +#, no-wrap +msgid "CacheLastModifiedFactor _number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:720 +msgid "" +"The _number_ is a coefficient to be used to multiply the time that passed " +"since the last modification of the document. The default option is `0.1` " +"(that is, one tenth)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:722 +#, no-wrap +msgid "Using the CacheLastModifiedFactor directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:728 +#, no-wrap +msgid "CacheLastModifiedFactor 0.1\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:732 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,CacheMaxExpire] " +"[option]`CacheMaxExpire`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:733 +msgid "" +"The [option]`CacheMaxExpire` directive allows you to specify the maximum " +"amount of time to cache a document. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:737 +#, no-wrap +msgid "CacheMaxExpire _time_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:740 +msgid "" +"The _time_ is specified in seconds. The default option is `86400` (that is, " +"one day)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:742 +#, no-wrap +msgid "Using the CacheMaxExpire directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:748 +#, no-wrap +msgid "CacheMaxExpire 86400\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:752 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,CacheNegotiatedDocs] " +"[option]`CacheNegotiatedDocs`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:753 +msgid "" +"The [option]`CacheNegotiatedDocs` directive allows you to enable caching of " +"the documents that were negotiated on the basis of content. It takes the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:757 +#, no-wrap +msgid "CacheNegotiatedDocs _option_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:760 +msgid "" +"The _option_ has to be a valid keyword as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-cachenegotiateddocs[Available " +"CacheNegotiatedDocs options]. Since the content-negotiated documents may " +"change over time or because of the input from the requester, the default " +"option is [option]`Off`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:762 +#, no-wrap +msgid "Available CacheNegotiatedDocs options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:769 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`On`|Enables caching the content-negotiated documents.\n" +"|[option]`Off`|Disables caching the content-negotiated documents.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:772 +#, no-wrap +msgid "Using the CacheNegotiatedDocs directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:778 +#, no-wrap +msgid "CacheNegotiatedDocs On\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:782 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,CacheRoot] " +"[option]`CacheRoot`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:783 +msgid "" +"The [option]`CacheRoot` directive allows you to specify the directory to " +"store cache files in. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:787 +#, no-wrap +msgid "CacheRoot _directory_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:790 +msgid "" +"indexterm:[Apache HTTP Server,directories,/var/cache/mod_proxy/] The " +"_directory_ must be a full path to an existing directory in the local file " +"system. The default option is `/var/cache/mod_proxy/`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:792 +#, no-wrap +msgid "Using the CacheRoot directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:797 +#, no-wrap +msgid "CacheRoot /var/cache/mod_proxy\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:801 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,CustomLog] " +"[option]`CustomLog`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:802 +msgid "" +"The [option]`CustomLog` directive allows you to specify the log file name " +"and the log file format. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:806 +#, no-wrap +msgid "CustomLog _path_ _format_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:809 +msgid "" +"indexterm:[Apache HTTP Server,files,/etc/httpd/logs/access_log] The _path_ " +"refers to a log file, and must be relative to the directory that is " +"specified by the [option]`ServerRoot` directive (that is, `/etc/httpd/` by " +"default). The _format_ has to be either an explicit format string, or a " +"format name that was previously defined using the [option]`LogFormat` " +"directive." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:811 +#, no-wrap +msgid "Using the CustomLog directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:816 +#, no-wrap +msgid "CustomLog logs/access_log combined\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:820 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,DefaultIcon] " +"[option]`DefaultIcon`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:821 +msgid "" +"The [option]`DefaultIcon` directive allows you to specify an icon to be " +"displayed for a file in server-generated directory listings when no other " +"icon is associated with it. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:825 +#, no-wrap +msgid "DefaultIcon _path_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:828 +msgid "" +"The _path_ refers to an existing icon file, and must be relative to the " +"directory specified by the [option]`DocumentRoot` directive (for example, " +"`/icons/unknown.png`)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:830 +#, no-wrap +msgid "Using the DefaultIcon directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:836 +#, no-wrap +msgid "DefaultIcon /icons/unknown.png\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:840 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,DefaultType] " +"[option]`DefaultType`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:841 +msgid "" +"The [option]`DefaultType` directive allows you to specify a media type to be " +"used in case the proper MIME type cannot be determined by the server. It " +"takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:845 +#, no-wrap +msgid "DefaultType _content-type_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:848 +msgid "" +"The _content-type_ has to be a valid MIME type such as `text/html`, " +"`image/png`, `application/pdf`, etc." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:850 +#, no-wrap +msgid "Using the DefaultType directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:856 +#, no-wrap +msgid "DefaultType text/plain\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:860 +#, no-wrap +msgid "indexterm:[Apache HTTP Server,directives,Deny] [option]`Deny`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:861 +msgid "" +"The [option]`Deny` directive allows you to specify which clients are denied " +"access to a given directory. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:865 +#, no-wrap +msgid "Deny from _client_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:870 +#, no-wrap +msgid "Using the Deny directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:876 +#, no-wrap +msgid "Deny from 192.168.1.1\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:880 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,DirectoryIndex] " +"[option]`DirectoryIndex`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:881 +msgid "" +"The [option]`DirectoryIndex` directive allows you to specify a document to " +"be served to a client when a directory is requested (that is, when the URL " +"ends with the `/` character). It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:885 +#, no-wrap +msgid "DirectoryIndex _filename_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:888 +msgid "" +"The _filename_ is a name of the file to look for in the requested " +"directory. By default, the server looks for `index.html`, and " +"`index.html.var`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:890 +#, no-wrap +msgid "Using the DirectoryIndex directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:896 +#, no-wrap +msgid "DirectoryIndex index.html index.html.var\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:900 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,DocumentRoot] " +"[option]`DocumentRoot`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:901 +msgid "" +"The [option]`DocumentRoot` directive allows you to specify the main " +"directory from which the content is served. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:905 +#, no-wrap +msgid "DocumentRoot _directory_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:908 +msgid "" +"indexterm:[Apache HTTP Server,directories,/var/www/html/] The _directory_ " +"must be a full path to an existing directory in the local file system. The " +"default option is `/var/www/html/`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:910 +#, no-wrap +msgid "Using the DocumentRoot directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:916 +#, no-wrap +msgid "DocumentRoot /var/www/html\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:920 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,ErrorDocument] " +"[option]`ErrorDocument`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:921 +msgid "" +"The [option]`ErrorDocument` directive allows you to specify a document or a " +"message to be displayed as a response to a particular error. It takes the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:925 +#, no-wrap +msgid "ErrorDocument _error-code_ _action_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:928 +msgid "" +"The _error-code_ has to be a valid code such as `403` (Forbidden), `404` " +"(Not Found), or `500` (Internal Server Error). The _action_ can be either a " +"URL (both local and external), or a message string enclosed in double quotes " +"(that is, `\"`)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:930 +#, no-wrap +msgid "Using the ErrorDocument directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:936 +#, no-wrap +msgid "" +"ErrorDocument 403 \"Access Denied\"\n" +"ErrorDocument 404 /404-not_found.html\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:940 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,ErrorLog] " +"[option]`ErrorLog`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:941 +msgid "" +"The [option]`ErrorLog` directive allows you to specify a file to which the " +"server errors are logged. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:945 +#, no-wrap +msgid "ErrorLog _path_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:948 +msgid "" +"indexterm:[Apache HTTP Server,files,/etc/httpd/logs/error_log] The _path_ " +"refers to a log file, and can be either absolute, or relative to the " +"directory that is specified by the [option]`ServerRoot` directive (that is, " +"`/etc/httpd/` by default). The default option is `logs/error_log`" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:950 +#, no-wrap +msgid "Using the ErrorLog directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:955 +#, no-wrap +msgid "ErrorLog logs/error_log\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:959 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,ExtendedStatus] " +"[option]`ExtendedStatus`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:960 +msgid "" +"The [option]`ExtendedStatus` directive allows you to enable detailed server " +"status information. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:964 +#, no-wrap +msgid "ExtendedStatus _option_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:967 +msgid "" +"The _option_ has to be a valid keyword as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-extendedstatus[Available " +"ExtendedStatus options]. The default option is [option]`Off`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:969 +#, no-wrap +msgid "Available ExtendedStatus options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:976 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`On`|Enables generating the detailed server status.\n" +"|[option]`Off`|Disables generating the detailed server status.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:979 +#, no-wrap +msgid "Using the ExtendedStatus directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:985 +#, no-wrap +msgid "ExtendedStatus On\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:989 +#, no-wrap +msgid "indexterm:[Apache HTTP Server,directives,Group] [option]`Group`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:990 +msgid "" +"The [option]`Group` directive allows you to specify the group under which " +"the `httpd` service will run. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:994 +#, no-wrap +msgid "Group _group_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:997 +msgid "" +"The _group_ has to be an existing UNIX group. The default option is " +"[option]`apache`." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:999 +msgid "" +"Note that [option]`Group` is no longer supported inside " +"[option]``, and has been replaced by the " +"[option]`SuexecUserGroup` directive." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1001 +#, no-wrap +msgid "Using the Group directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1007 +#, no-wrap +msgid "Group apache\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1011 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,HeaderName] " +"[option]`HeaderName`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1012 +msgid "" +"The [option]`HeaderName` directive allows you to specify a file to be " +"prepended to the beginning of the server-generated directory listing. It " +"takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1016 +#, no-wrap +msgid "HeaderName _filename_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1019 +msgid "" +"The _filename_ is a name of the file to look for in the requested " +"directory. By default, the server looks for `HEADER.html`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1021 +#, no-wrap +msgid "Using the HeaderName directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1027 +#, no-wrap +msgid "HeaderName HEADER.html\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1031 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,HostnameLookups] " +"[option]`HostnameLookups`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1032 +msgid "" +"The [option]`HostnameLookups` directive allows you to enable automatic " +"resolving of IP addresses. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1036 +#, no-wrap +msgid "HostnameLookups _option_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1039 +msgid "" +"The _option_ has to be a valid keyword as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-hostnamelookup[Available " +"HostnameLookups options]. To conserve resources on the server, the default " +"option is [option]`Off`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1041 +#, no-wrap +msgid "Available HostnameLookups options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1049 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`On`|Enables resolving the IP address for each connection so that " +"the hostname can be logged. However, this also adds a significant processing " +"overhead.\n" +"|[option]`Double`|Enables performing the double-reverse DNS lookup. In " +"comparison to the above option, this adds even more processing overhead.\n" +"|[option]`Off`|Disables resolving the IP address for each connection.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1052 +msgid "" +"Note that when the presence of hostnames is required in server log files, it " +"is often possible to use one of the many log analyzer tools that perform the " +"DNS lookups more efficiently." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1054 +#, no-wrap +msgid "Using the HostnameLookups directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1060 +#, no-wrap +msgid "HostnameLookups Off\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1064 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,Include] " +"[option]`Include`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1065 +msgid "" +"The [option]`Include` directive allows you to include other configuration " +"files. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1069 +#, no-wrap +msgid "Include _filename_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1072 +msgid "" +"indexterm:[Apache HTTP Server,directories,/etc/httpd/conf.d/] The " +"[option]`filename` can be an absolute path, a path relative to the directory " +"specified by the [option]`ServerRoot` directive, or a wildcard " +"expression. All configuration files from the `/etc/httpd/conf.d/` directory " +"are loaded by default." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1074 +#, no-wrap +msgid "Using the Include directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1079 +#, no-wrap +msgid "Include conf.d/*.conf\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1083 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,IndexIgnore] " +"[option]`IndexIgnore`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1084 +msgid "" +"The [option]`IndexIgnore` directive allows you to specify a list of file " +"names to be omitted from the server-generated directory listings. It takes " +"the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1088 +#, no-wrap +msgid "IndexIgnore _filename_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1091 +msgid "" +"The _filename_ option can be either a full file name, or a wildcard " +"expression." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1093 +#, no-wrap +msgid "Using the IndexIgnore directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1098 +#, no-wrap +msgid "IndexIgnore .??* *~ *# HEADER* README* RCS CVS *,v *,t\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1102 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,IndexOptions] " +"[option]`IndexOptions`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1103 +msgid "" +"The [option]`IndexOptions` directive allows you to customize the behavior of " +"server-generated directory listings. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1107 +#, no-wrap +msgid "IndexOptions _option_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1110 +msgid "" +"The _option_ has to be a valid keyword as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-indexoptions[Available " +"directory listing options]. The default options are [option]`Charset=UTF-8`, " +"[option]`FancyIndexing`, [option]`HTMLTable`, [option]`NameWidth=*`, and " +"[option]`VersionSort`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1112 +#, no-wrap +msgid "Available directory listing options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1141 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`Charset`pass:attributes[{blank}]=pass:attributes[{blank}]_encoding_|Specifies " +"the character set of a generated web page. The _encoding_ has to be a valid " +"character set such as `UTF-8` or `ISO-8859-2`.\n" +"|[option]`Type`pass:attributes[{blank}]=pass:attributes[{blank}]_content-type_|Specifies " +"the media type of a generated web page. The _content-type_ has to be a valid " +"MIME type such as `text/html` or `text/plain`.\n" +"|[option]`DescriptionWidth`pass:attributes[{blank}]=pass:attributes[{blank}]_value_|Specifies " +"the width of the description column. The _value_ can be either a number of " +"characters, or an asterisk (that is, `*`) to adjust the width " +"automatically.\n" +"|[option]`FancyIndexing`|Enables advanced features such as different icons " +"for certain files or possibility to re-sort a directory listing by clicking " +"on a column header.\n" +"|[option]`FolderFirst`|Enables listing directories first, always placing " +"them above files.\n" +"|[option]`HTMLTable`|Enables the use of HTML tables for directory " +"listings.\n" +"|[option]`IconsAreLinks`|Enables using the icons as links.\n" +"|[option]`IconHeight`pass:attributes[{blank}]=pass:attributes[{blank}]_value_|Specifies " +"an icon height. The _value_ is a number of pixels.\n" +"|[option]`IconWidth`pass:attributes[{blank}]=pass:attributes[{blank}]_value_|Specifies " +"an icon width. The _value_ is a number of pixels.\n" +"|[option]`IgnoreCase`|Enables sorting files and directories in a " +"case-sensitive manner.\n" +"|[option]`IgnoreClient`|Disables accepting query variables from a client.\n" +"|[option]`NameWidth`pass:attributes[{blank}]=pass:attributes[{blank}]_value_|Specifies " +"the width of the file name column. The _value_ can be either a number of " +"characters, or an asterisk (that is, `*`) to adjust the width " +"automatically.\n" +"|[option]`ScanHTMLTitles`|Enables parsing the file for a description (that " +"is, the `title` element) in case it is not provided by the " +"[option]`AddDescription` directive.\n" +"|[option]`ShowForbidden`|Enables listing the files with otherwise restricted " +"access.\n" +"|[option]`SuppressColumnSorting`|Disables re-sorting a directory listing by " +"clicking on a column header.\n" +"|[option]`SuppressDescription`|Disables reserving a space for file " +"descriptions.\n" +"|[option]`SuppressHTMLPreamble`|Disables the use of standard HTML preamble " +"when a file specified by the [option]`HeaderName` directive is present.\n" +"|[option]`SuppressIcon`|Disables the use of icons in directory listings.\n" +"|[option]`SuppressLastModified`|Disables displaying the date of the last " +"modification field in directory listings.\n" +"|[option]`SuppressRules`|Disables the use of horizontal lines in directory " +"listings.\n" +"|[option]`SuppressSize`|Disables displaying the file size field in directory " +"listings.\n" +"|[option]`TrackModified`|Enables returning the `Last-Modified` and `ETag` " +"values in the HTTP header.\n" +"|[option]`VersionSort`|Enables sorting files that contain a version number " +"in the expected manner.\n" +"|[option]`XHTML`|Enables the use of XHTML 1.0 instead of the default HTML " +"3.2.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1144 +#, no-wrap +msgid "Using the IndexOptions directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1149 +#, no-wrap +msgid "IndexOptions FancyIndexing VersionSort NameWidth=* HTMLTable Charset=UTF-8\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1153 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,KeepAlive] " +"[option]`KeepAlive`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1154 +msgid "" +"The [option]`KeepAlive` directive allows you to enable persistent " +"connections. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1158 +#, no-wrap +msgid "KeepAlive _option_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1161 +msgid "" +"The _option_ has to be a valid keyword as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-keepalive[Available KeepAlive " +"options]. The default option is [option]`Off`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1163 +#, no-wrap +msgid "Available KeepAlive options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1170 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`On`|Enables the persistent connections. In this case, the server " +"will accept more than one request per connection.\n" +"|[option]`Off`|Disables the keep-alive connections.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1173 +msgid "" +"Note that when the persistent connections are enabled, on a busy server, the " +"number of child processes can increase rapidly and eventually reach the " +"maximum limit, slowing down the server significantly. To reduce the risk, it " +"is recommended that you set [option]`KeepAliveTimeout` to a low number, and " +"monitor the `/var/log/httpd/logs/error_log` log file carefully." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1175 +#, no-wrap +msgid "Using the KeepAlive directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1181 +#, no-wrap +msgid "KeepAlive Off\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1185 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,KeepAliveTimeout] " +"[option]`KeepAliveTimeout`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1186 +msgid "" +"The [option]`KeepAliveTimeout` directive allows you to specify the amount of " +"time to wait for another request before closing the connection. It takes the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1190 +#, no-wrap +msgid "KeepAliveTimeout _time_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1193 +msgid "The _time_ is specified in seconds. The default option is `15`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1195 +#, no-wrap +msgid "Using the KeepAliveTimeout directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1201 +#, no-wrap +msgid "KeepAliveTimeout 15\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1205 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,LanguagePriority] " +"[option]`LanguagePriority`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1206 +msgid "" +"The [option]`LanguagePriority` directive allows you to customize the " +"precedence of languages. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1210 +#, no-wrap +msgid "LanguagePriority _language_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1213 +msgid "The _language_ has to be a valid MIME language such as `cs`, `en`, or `fr`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1217 +#, no-wrap +msgid "Using the LanguagePriority directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1223 +#, no-wrap +msgid "LanguagePriority sk cs en\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1227 +#, no-wrap +msgid "indexterm:[Apache HTTP Server,directives,Listen] [option]`Listen`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1228 +msgid "" +"The _Listen_ directive allows you to specify IP addresses or ports to listen " +"to. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1232 +#, no-wrap +msgid "Listen _ip-address_:pass:attributes[{blank}]_port_ _protocol_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1235 +msgid "" +"The _ip-address_ is optional and unless supplied, the server will accept " +"incoming requests on a given _port_ from all IP addresses. Since the " +"_protocol_ is determined automatically from the port number, it can be " +"usually omitted. The default option is to listen to port `80`." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1237 +msgid "" +"Note that if the server is configured to listen to a port under 1024, only " +"superuser will be able to start the `httpd` service." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1239 +#, no-wrap +msgid "Using the Listen directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1245 +#, no-wrap +msgid "Listen 80\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1249 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,LoadModule] " +"[option]`LoadModule`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1250 +msgid "" +"The [option]`LoadModule` directive allows you to load a _Dynamic Shared " +"Object_ (*DSO*) module. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1254 +#, no-wrap +msgid "LoadModule _name_ _path_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1257 +msgid "" +"indexterm:[Apache HTTP " +"Server,directories,/usr/lib/httpd/modules/]indexterm:[Apache HTTP " +"Server,directories,/usr/lib64/httpd/modules/] The _name_ has to be a valid " +"identifier of the required module. The _path_ refers to an existing module " +"file, and must be relative to the directory in which the libraries are " +"placed (that is, `/usr/lib/httpd/` on 32-bit and `/usr/lib64/httpd/` on " +"64-bit systems by default)." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1259 +msgid "" +"See xref:Web_Servers.adoc#s2-apache-dso[Working with Modules] for more " +"information on the Apache HTTP Server's DSO support." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1261 +#, no-wrap +msgid "Using the LoadModule directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1266 +#, no-wrap +msgid "LoadModule php5_module modules/libphp5.so\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1270 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,LogFormat] " +"[option]`LogFormat`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1271 +msgid "" +"The _LogFormat_ directive allows you to specify a log file format. It takes " +"the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1275 +#, no-wrap +msgid "LogFormat _format_ _name_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1278 +msgid "" +"The _format_ is a string consisting of options as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-logformat[Common LogFormat " +"options]. The _name_ can be used instead of the format string in the " +"[option]`CustomLog` directive." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1280 +#, no-wrap +msgid "Common LogFormat options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1293 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`%b`|Represents the size of the response in bytes.\n" +"|[option]`%h`|Represents the IP address or hostname of a remote client.\n" +"|[option]`%l`|Represents the remote log name if supplied. If not, a hyphen " +"(that is, `-`) is used instead.\n" +"|[option]`%r`|Represents the first line of the request string as it came " +"from the browser or client.\n" +"|[option]`%s`|Represents the status code.\n" +"|[option]`%t`|Represents the date and time of the request.\n" +"|[option]`%u`|If the authentication is required, it represents the remote " +"user. If not, a hyphen (that is, `-`) is used instead.\n" +"|[option]`%{pass:attributes[{blank}]_field_pass:attributes[{blank}]}`|Represents " +"the content of the HTTP header _field_. The common options include " +"[option]`%\\{Referer}` (the URL of the web page that referred the client to " +"the server) and [option]`%\\{User-Agent}` (the type of the web browser " +"making the request).\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1296 +#, no-wrap +msgid "Using the LogFormat directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1302 +#, no-wrap +msgid "LogFormat \"%h %l %u %t \\\"%r\\\" %>s %b\" common\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1306 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,LogLevel] " +"[option]`LogLevel`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1307 +msgid "" +"The [option]`LogLevel` directive allows you to customize the verbosity level " +"of the error log. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1311 +#, no-wrap +msgid "LogLevel _option_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1314 +msgid "" +"The _option_ has to be a valid keyword as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-loglevel[Available LogLevel " +"options]. The default option is [option]`warn`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1316 +#, no-wrap +msgid "Available LogLevel options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1329 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`emerg`|Only the emergency situations when the server cannot " +"perform its work are logged.\n" +"|[option]`alert`|All situations when an immediate action is required are " +"logged.\n" +"|[option]`crit`|All critical conditions are logged.\n" +"|[option]`error`|All error messages are logged.\n" +"|[option]`warn`|All warning messages are logged.\n" +"|[option]`notice`|Even normal, but still significant situations are " +"logged.\n" +"|[option]`info`|Various informational messages are logged.\n" +"|[option]`debug`|Various debugging messages are logged.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1332 +#, no-wrap +msgid "Using the LogLevel directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1338 +#, no-wrap +msgid "LogLevel warn\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1342 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,MaxKeepAliveRequests] " +"[option]`MaxKeepAliveRequests`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1343 +msgid "" +"The [option]`MaxKeepAliveRequests` directive allows you to specify the " +"maximum number of requests for a persistent connection. It takes the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1348 +#, no-wrap +msgid "MaxKeepAliveRequests _number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1351 +msgid "" +"A high _number_ can improve the performance of the server. Note that using " +"`0` allows unlimited number of requests. The default option is " +"[option]`100`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1353 +#, no-wrap +msgid "Using the MaxKeepAliveRequests option" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1359 +#, no-wrap +msgid "MaxKeepAliveRequests 100\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1363 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,NameVirtualHost] " +"[option]`NameVirtualHost`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1364 +msgid "" +"The [option]`NameVirtualHost` directive allows you to specify the IP address " +"and port number for a name-based virtual host. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1368 +#, no-wrap +msgid "NameVirtualHost _ip-address_:pass:attributes[{blank}]_port_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1371 +msgid "" +"The _ip-address_ can be either a full IP address, or an asterisk (that is, " +"`*`) representing all interfaces. Note that IPv6 addresses have to be " +"enclosed in square brackets (that is, `[` and `]`). The _port_ is optional." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1373 +msgid "" +"Name-based virtual hosting allows one Apache HTTP Server to serve different " +"domains without using multiple IP addresses." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1374 +#, no-wrap +msgid "Using secure HTTP connections" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1379 +msgid "" +"Name-based virtual hosts *only* work with non-secure HTTP connections. If " +"using virtual hosts with a secure server, use IP address-based virtual hosts " +"instead." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1383 +#, no-wrap +msgid "Using the NameVirtualHost directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1388 +#, no-wrap +msgid "NameVirtualHost *:80\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1392 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,Options] " +"[option]`Options`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1393 +msgid "" +"The [option]`Options` directive allows you to specify which server features " +"are available in a particular directory. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1397 +#, no-wrap +msgid "Options _option_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1400 +msgid "" +"The _option_ has to be a valid keyword as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-options[Available server " +"features]." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1402 +#, no-wrap +msgid "Available server features" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1416 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`ExecCGI`|Enables the execution of CGI scripts.\n" +"|[option]`FollowSymLinks`|Enables following symbolic links in the " +"directory.\n" +"|[option]`Includes`|Enables server-side includes.\n" +"|[option]`IncludesNOEXEC`|Enables server-side includes, but does not allow " +"the execution of commands.\n" +"|[option]`Indexes`|Enables server-generated directory listings.\n" +"|[option]`MultiViews`|Enables content-negotiated \"`MultiViews`\".\n" +"|[option]`SymLinksIfOwnerMatch`|Enables following symbolic links in the " +"directory when both the link and the target file have the same owner.\n" +"|[option]`All`|Enables all of the features above with the exception of " +"[option]`MultiViews`.\n" +"|[option]`None`|Disables all of the features above.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1419 +#, no-wrap +msgid "Using the Options directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1425 +#, no-wrap +msgid "Options Indexes FollowSymLinks\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1429 +#, no-wrap +msgid "indexterm:[Apache HTTP Server,directives,Order] [option]`Order`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1430 +msgid "" +"The [option]`Order` directive allows you to specify the order in which the " +"[option]`Allow` and [option]`Deny` directives are evaluated. It takes the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1434 +#, no-wrap +msgid "Order _option_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1437 +msgid "" +"The _option_ has to be a valid keyword as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-order[Available Order " +"options]. The default option is [option]`allow,deny`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1439 +#, no-wrap +msgid "Available Order options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1446 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`allow,deny`|[option]`Allow` directives are evaluated first.\n" +"|[option]`deny,allow`|[option]`Deny` directives are evaluated first.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1449 +#, no-wrap +msgid "Using the Order directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1455 +#, no-wrap +msgid "Order allow,deny\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1459 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,PidFile] " +"[option]`PidFile`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1460 +msgid "" +"The [option]`PidFile` directive allows you to specify a file to which the " +"_process ID_ (*PID*) of the server is stored. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1464 +#, no-wrap +msgid "PidFile _path_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1467 +msgid "" +"indexterm:[Apache HTTP Server,files,/etc/httpd/run/httpd.pid] The _path_ " +"refers to a pid file, and can be either absolute, or relative to the " +"directory that is specified by the [option]`ServerRoot` directive (that is, " +"`/etc/httpd/` by default). The default option is `run/httpd.pid`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1469 +#, no-wrap +msgid "Using the PidFile directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1475 +#, no-wrap +msgid "PidFile run/httpd.pid\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1479 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,ProxyRequests] " +"[option]`ProxyRequests`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1480 +msgid "" +"The [option]`ProxyRequests` directive allows you to enable forward proxy " +"requests. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1484 +#, no-wrap +msgid "ProxyRequests _option_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1487 +msgid "" +"The _option_ has to be a valid keyword as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-proxyrequests[Available " +"ProxyRequests options]. The default option is [option]`Off`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1489 +#, no-wrap +msgid "Available ProxyRequests options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1496 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`On`|Enables forward proxy requests.\n" +"|[option]`Off`|Disables forward proxy requests.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1499 +#, no-wrap +msgid "Using the ProxyRequests directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1505 +#, no-wrap +msgid "ProxyRequests On\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1509 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,ReadmeName] " +"[option]`ReadmeName`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1510 +msgid "" +"The [option]`ReadmeName` directive allows you to specify a file to be " +"appended to the end of the server-generated directory listing. It takes the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1514 +#, no-wrap +msgid "ReadmeName _filename_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1517 +msgid "" +"The _filename_ is a name of the file to look for in the requested " +"directory. By default, the server looks for `README.html`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1519 +#, no-wrap +msgid "Using the ReadmeName directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1525 +#, no-wrap +msgid "ReadmeName README.html\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1529 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,Redirect] " +"[option]`Redirect`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1530 +msgid "" +"The [option]`Redirect` directive allows you to redirect a client to another " +"URL. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1534 +#, no-wrap +msgid "Redirect _status_ _path_ _url_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1537 +msgid "" +"The _status_ is optional, and if provided, it has to be a valid keyword as " +"described in xref:Web_Servers.adoc#table-apache-httpdconf-redirect[Available " +"status options]. The _path_ refers to the old location, and must be relative " +"to the directory specified by the [option]`DocumentRoot` directive (for " +"example, `/docs`). The _url_ refers to the current location of the content " +"(for example, `http://docs.example.com`)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1539 +#, no-wrap +msgid "Available status options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1548 +#, no-wrap +msgid "" +"|Status|Description\n" +"|[option]`permanent`|Indicates that the requested resource has been moved " +"permanently. The `301` (Moved Permanently) status code is returned to a " +"client.\n" +"|[option]`temp`|Indicates that the requested resource has been moved only " +"temporarily. The `302` (Found) status code is returned to a client.\n" +"|[option]`seeother`|Indicates that the requested resource has been " +"replaced. The `303` (See Other) status code is returned to a client.\n" +"|[option]`gone`|Indicates that the requested resource has been removed " +"permanently. The `410` (Gone) status is returned to a client.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1551 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,modules,mod_rewrite]\n" +"Note that for more advanced redirection techniques, you can use the " +"`mod_rewrite` module that is part of the Apache HTTP Server installation.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1553 +#, no-wrap +msgid "Using the Redirect directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1559 +#, no-wrap +msgid "Redirect permanent /docs http://docs.example.com\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1563 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,ScriptAlias] " +"[option]`ScriptAlias`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1564 +msgid "" +"The [option]`ScriptAlias` directive allows you to specify the location of " +"CGI scripts. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1568 +#, no-wrap +msgid "ScriptAlias _url-path_ _real-path_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1573 +msgid "" +"The _url-path_ must be relative to the directory specified by the " +"[option]`DocumentRoot` directive (for example, `/cgi-bin/`). The _real-path_ " +"is a full path to a file or directory in the local file system. " +"indexterm:[Apache HTTP Server,directories,/var/www/cgi-bin/] This directive " +"is typically followed by the [option]`Directory` tag with additional " +"permissions to access the target directory. By default, the `/cgi-bin/` " +"alias is created so that the scripts located in the `/var/www/cgi-bin/` are " +"accessible." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1575 +msgid "" +"The [option]`ScriptAlias` directive is used for security reasons to prevent " +"CGI scripts from being viewed as ordinary text documents." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1577 +#, no-wrap +msgid "Using the ScriptAlias directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1583 +#, no-wrap +msgid "ScriptAlias /cgi-bin/ /var/www/cgi-bin/\n" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1590 +#, no-wrap +msgid "" +"<Directory \"/var/www/cgi-bin\">\n" +" AllowOverride None\n" +" Options None\n" +" Order allow,deny\n" +" Allow from all\n" +"</Directory>\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1594 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,ServerAdmin] " +"[option]`ServerAdmin`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1595 +msgid "" +"The [option]`ServerAdmin` directive allows you to specify the email address " +"of the server administrator to be displayed in server-generated web " +"pages. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1599 +#, no-wrap +msgid "ServerAdmin _email_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1602 +msgid "The default option is `root@localhost`." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1604 +msgid "" +"This directive is commonly set to " +"`webmaster@pass:attributes[{blank}]_hostname_pass:attributes[{blank}]`, " +"where _hostname_ is the address of the server. Once set, alias `webmaster` " +"to the person responsible for the web server in `/etc/aliases`, and as " +"superuser, run the [command]#newaliases# command." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1606 +#, no-wrap +msgid "Using the ServerAdmin directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1612 +#, no-wrap +msgid "ServerAdmin webmaster@penguin.example.com\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1616 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,ServerName] " +"[option]`ServerName`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1617 +msgid "" +"The [option]`ServerName` directive allows you to specify the hostname and " +"the port number of a web server. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1621 +#, no-wrap +msgid "ServerName _hostname_:pass:attributes[{blank}]_port_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1624 +msgid "" +"The _hostname_ has to be a _fully qualified domain name_ (*FQDN*) of the " +"server. The _port_ is optional, but when supplied, it has to match the " +"number specified by the [option]`Listen` directive." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1626 +msgid "" +"When using this directive, make sure that the IP address and server name " +"pair are included in the `/etc/hosts` file." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1628 +#, no-wrap +msgid "Using the ServerName directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1634 +#, no-wrap +msgid "ServerName penguin.example.com:80\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1638 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,ServerRoot] " +"[option]`ServerRoot`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1639 +msgid "" +"The [option]`ServerRoot` directive allows you to specify the directory in " +"which the server operates. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1643 +#, no-wrap +msgid "ServerRoot _directory_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1646 +msgid "" +"indexterm:[Apache HTTP Server,directories,/etc/httpd/] The _directory_ must " +"be a full path to an existing directory in the local file system. The " +"default option is `/etc/httpd/`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1648 +#, no-wrap +msgid "Using the ServerRoot directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1654 +#, no-wrap +msgid "ServerRoot /etc/httpd\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1658 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,ServerSignature] " +"[option]`ServerSignature`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1659 +msgid "" +"The [option]`ServerSignature` directive allows you to enable displaying " +"information about the server on server-generated documents. It takes the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1663 +#, no-wrap +msgid "ServerSignature _option_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1666 +msgid "" +"The _option_ has to be a valid keyword as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-serversignature[Available " +"ServerSignature options]. The default option is [option]`On`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1668 +#, no-wrap +msgid "Available ServerSignature options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1676 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`On`|Enables appending the server name and version to " +"server-generated pages.\n" +"|[option]`Off`|Disables appending the server name and version to " +"server-generated pages.\n" +"|[option]`EMail`|Enables appending the server name, version, and the email " +"address of the system administrator as specified by the " +"[option]`ServerAdmin` directive to server-generated pages.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1679 +#, no-wrap +msgid "Using the ServerSignature directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1685 +#, no-wrap +msgid "ServerSignature On\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1689 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,ServerTokens] " +"[option]`ServerTokens`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1690 +msgid "" +"The [option]`ServerTokens` directive allows you to customize what " +"information are included in the Server response header. It takes the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1694 +#, no-wrap +msgid "ServerTokens _option_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1697 +msgid "" +"The _option_ has to be a valid keyword as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-servertokens[Available " +"ServerTokens options]. The default option is [option]`OS`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1699 +#, no-wrap +msgid "Available ServerTokens options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1710 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`Prod`|Includes the product name only (that is, `Apache`).\n" +"|[option]`Major`|Includes the product name and the major version of the " +"server (for example, `2`).\n" +"|[option]`Minor`|Includes the product name and the minor version of the " +"server (for example, `2.2`).\n" +"|[option]`Min`|Includes the product name and the minimal version of the " +"server (for example, `2.2.15`).\n" +"|[option]`OS`|Includes the product name, the minimal version of the server, " +"and the type of the operating system it is running on (for example, `Red " +"Hat`).\n" +"|[option]`Full`|Includes all the information above along with the list of " +"loaded modules.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1713 +msgid "" +"Note that for security reasons, it is recommended to reveal as little " +"information about the server as possible." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1715 +#, no-wrap +msgid "Using the ServerTokens directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1721 +#, no-wrap +msgid "ServerTokens Prod\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1725 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,SuexecUserGroup] " +"[option]`SuexecUserGroup`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1726 +msgid "" +"The [option]`SuexecUserGroup` directive allows you to specify the user and " +"group under which the CGI scripts will be run. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1730 +#, no-wrap +msgid "SuexecUserGroup _user_ _group_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1733 +msgid "" +"The _user_ has to be an existing user, and the _group_ must be a valid UNIX " +"group." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1735 +msgid "" +"For security reasons, the CGI scripts should not be run with `root` " +"privileges. Note that in [option]``, [option]`SuexecUserGroup` " +"replaces the [option]`User` and [option]`Group` directives." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1737 +#, no-wrap +msgid "Using the SuexecUserGroup directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1743 +#, no-wrap +msgid "SuexecUserGroup apache apache\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1747 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,Timeout] " +"[option]`Timeout`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1748 +msgid "" +"The [option]`Timeout` directive allows you to specify the amount of time to " +"wait for an event before closing a connection. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1752 +#, no-wrap +msgid "Timeout _time_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1755 +msgid "The _time_ is specified in seconds. The default option is `60`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1757 +#, no-wrap +msgid "Using the Timeout directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1763 +#, no-wrap +msgid "Timeout 60\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1767 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,TypesConfig] " +"[option]`TypesConfig`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1768 +msgid "" +"The [option]`TypesConfig` allows you to specify the location of the MIME " +"types configuration file. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1772 +#, no-wrap +msgid "TypesConfig _path_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1775 +msgid "" +"indexterm:[Apache HTTP Server,files,/etc/mime.types] The _path_ refers to an " +"existing MIME types configuration file, and can be either absolute, or " +"relative to the directory that is specified by the [option]`ServerRoot` " +"directive (that is, `/etc/httpd/` by default). The default option is " +"[option]`/etc/mime.types`." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1777 +msgid "" +"Note that instead of editing `/etc/mime.types`, the recommended way to add " +"MIME type mapping to the Apache HTTP Server is to use the [option]`AddType` " +"directive." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1779 +#, no-wrap +msgid "Using the TypesConfig directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1785 +#, no-wrap +msgid "TypesConfig /etc/mime.types\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1789 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,UseCanonicalName] " +"[option]`UseCanonicalName`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1790 +msgid "" +"The [option]`UseCanonicalName` allows you to specify the way the server " +"refers to itself. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1794 +#, no-wrap +msgid "UseCanonicalName _option_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1797 +msgid "" +"The _option_ has to be a valid keyword as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-usecanonicalname[Available " +"UseCanonicalName options]. The default option is [option]`Off`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1799 +#, no-wrap +msgid "Available UseCanonicalName options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1807 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`On`|Enables the use of the name that is specified by the " +"[option]`ServerName` directive.\n" +"|[option]`Off`|Disables the use of the name that is specified by the " +"[option]`ServerName` directive. The hostname and port number provided by the " +"requesting client are used instead.\n" +"|[option]`DNS`|Disables the use of the name that is specified by the " +"[option]`ServerName` directive. The hostname determined by a reverse DNS " +"lookup is used instead.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1810 +#, no-wrap +msgid "Using the UseCanonicalName directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1816 +#, no-wrap +msgid "UseCanonicalName Off\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1820 +#, no-wrap +msgid "indexterm:[Apache HTTP Server,directives,User] [option]`User`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1821 +msgid "" +"The [option]`User` directive allows you to specify the user under which the " +"`httpd` service will run. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1825 +#, no-wrap +msgid "User _user_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1828 +msgid "" +"The _user_ has to be an existing UNIX user. The default option is " +"[option]`apache`." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1830 +msgid "" +"For security reasons, the `httpd` service should not be run with `root` " +"privileges. Note that [option]`User` is no longer supported inside " +"[option]``, and has been replaced by the " +"[option]`SuexecUserGroup` directive." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1832 +#, no-wrap +msgid "Using the User directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1838 +#, no-wrap +msgid "User apache\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1842 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,UserDir] " +"[option]`UserDir`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1843 +msgid "" +"The [option]`UserDir` directive allows you to enable serving content from " +"users' home directories. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1847 +#, no-wrap +msgid "UserDir _option_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1850 +msgid "" +"indexterm:[Apache HTTP Server,directories,~/public_html/] The _option_ can " +"be either a name of the directory to look for in user's home directory " +"(typically [option]`public_html`), or a valid keyword as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-userdir[Available UserDir " +"options]. The default option is [option]`disabled`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1852 +#, no-wrap +msgid "Available UserDir options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1859 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`enabled`pass:attributes[{blank}] pass:attributes[{blank}]_user_pass:attributes[{blank}]…|Enables " +"serving content from home directories of given " +"_user_pass:attributes[{blank}]s.\n" +"|[option]`disabled`pass:attributes[{blank}] pass:attributes[{blank}]_user_pass:attributes[{blank}]…|Disables " +"serving content from home directories, either for all users, or, if a space " +"separated list of _user_pass:attributes[{blank}]s is supplied, for given " +"users only.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1861 +#, no-wrap +msgid "Set the correct permissions" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1866 +msgid "" +"In order for the web server to access the content, the permissions on " +"relevant directories and files must be set correctly. Make sure that all " +"users are able to access the home directories, and that they can access and " +"read the content of the directory specified by the [option]`UserDir` " +"directive. For example, to allow access to `public_html/` in the home " +"directory of user `joe`, type the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1870 +#, no-wrap +msgid "" +"# chmod a+x /home/joe/\n" +"# chmod a+rx /home/joe/public_html/\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1873 +msgid "All files in this directory must be set accordingly." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1877 +#, no-wrap +msgid "Using the UserDir directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1882 +#, no-wrap +msgid "UserDir public_html\n" +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1887 +#, no-wrap +msgid "Common ssl.conf Directives" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1892 +msgid "" +"The _Secure Sockets Layer_ (*SSL*) directives allow you to customize the " +"behavior of the Apache HTTP Secure Server, and in most cases, they are " +"configured appropriately during the installation. Be careful when changing " +"these settings, as incorrect configuration can lead to security " +"vulnerabilities. indexterm:[Apache HTTP " +"Server,files,/etc/httpd/conf.d/ssl.conf] The following directive is commonly " +"used in `/etc/httpd/conf.d/ssl.conf`:" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1893 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,SetEnvIf] " +"[option]`SetEnvIf`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1894 +msgid "" +"The [option]`SetEnvIf` directive allows you to set environment variables " +"based on the headers of incoming connections. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1898 +#, no-wrap +msgid "" +"SetEnvIf _option_ _pattern_ " +"!_variable_pass:attributes[{blank}]=pass:attributes[{blank}]_value_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1901 +msgid "" +"The _option_ can be either a HTTP header field, a previously defined " +"environment variable name, or a valid keyword as described in " +"xref:Web_Servers.adoc#table-apache-sslconf-setenvif[Available SetEnvIf " +"options]. The _pattern_ is a regular expression. The _variable_ is an " +"environment variable that is set when the option matches the pattern. If the " +"optional exclamation mark (that is, `!`) is present, the variable is removed " +"instead of being set." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1903 +#, no-wrap +msgid "Available SetEnvIf options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1914 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`Remote_Host`|Refers to the client's hostname.\n" +"|[option]`Remote_Addr`|Refers to the client's IP address.\n" +"|[option]`Server_Addr`|Refers to the server's IP address.\n" +"|[option]`Request_Method`|Refers to the request method (for example, " +"`GET`).\n" +"|[option]`Request_Protocol`|Refers to the protocol name and version (for " +"example, `HTTP/1.1`).\n" +"|[option]`Request_URI`|Refers to the requested resource.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1917 +msgid "" +"The [option]`SetEnvIf` directive is used to disable HTTP keepalives, and to " +"allow SSL to close the connection without a closing notification from the " +"client browser. This is necessary for certain web browsers that do not " +"reliably shut down the SSL connection." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1919 +#, no-wrap +msgid "Using the SetEnvIf directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1926 +#, no-wrap +msgid "" +"SetEnvIf User-Agent \".*MSIE.*\" \\\n" +" nokeepalive ssl-unclean-shutdown \\\n" +" downgrade-1.0 force-response-1.0\n" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1931 +msgid "" +"Note that for the `/etc/httpd/conf.d/ssl.conf` file to be present, the " +"[package]*mod_ssl* needs to be installed. See " +"xref:Web_Servers.adoc#s2-apache-mod_ssl[Setting Up an SSL Server] for more " +"information on how to install and configure an SSL server." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1933 +#, no-wrap +msgid "Common Multi-Processing Module Directives" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1938 +msgid "" +"The _Multi-Processing Module_ (*MPM*) directives allow you to customize the " +"behavior of a particular MPM specific server-pool. Since its characteristics " +"differ depending on which MPM is used, the directives are embedded in " +"[option]`IfModule`. By default, the server-pool is defined for both the " +"`prefork` and `worker` MPMs. indexterm:[Apache HTTP " +"Server,files,/etc/httpd/conf/httpd.conf] The following MPM directives are " +"commonly used in `/etc/httpd/conf/httpd.conf`:" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1939 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,MaxClients] " +"[option]`MaxClients`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1940 +msgid "" +"The [option]`MaxClients` directive allows you to specify the maximum number " +"of simultaneously connected clients to process at one time. It takes the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1944 +#, no-wrap +msgid "MaxClients _number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1947 +msgid "" +"A high _number_ can improve the performance of the server, although it is " +"not recommended to exceed `256` when using the `prefork` MPM." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1949 +#, no-wrap +msgid "Using the MaxClients directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1955 +#, no-wrap +msgid "MaxClients 256\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1959 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,MaxClients] " +"[option]`MaxRequestsPerChild`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1960 +msgid "" +"The [option]`MaxRequestsPerChild` directive allows you to specify the " +"maximum number of request a child process can serve before it dies. It takes " +"the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1964 +#, no-wrap +msgid "MaxRequestsPerChild _number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1967 +msgid "Setting the _number_ to `0` allows unlimited number of requests." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1969 +msgid "" +"The [option]`MaxRequestsPerChild` directive is used to prevent long-lived " +"processes from causing memory leaks." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1971 +#, no-wrap +msgid "Using the MaxRequestsPerChild directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1977 +#, no-wrap +msgid "MaxRequestsPerChild 4000\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1981 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,MaxSpareServers] " +"[option]`MaxSpareServers`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1982 +msgid "" +"The [option]`MaxSpareServers` directive allows you to specify the maximum " +"number of spare child processes. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1986 +#, no-wrap +msgid "MaxSpareServers _number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1989 +msgid "This directive is used by the `prefork` MPM only." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1991 +#, no-wrap +msgid "Using the MaxSpareServers directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1997 +#, no-wrap +msgid "MaxSpareServers 20\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2001 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,MaxSpareThreads] " +"[option]`MaxSpareThreads`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2002 +msgid "" +"The [option]`MaxSpareThreads` directive allows you to specify the maximum " +"number of spare server threads. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2006 +#, no-wrap +msgid "MaxSpareThreads _number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2009 +msgid "" +"The _number_ must be greater than or equal to the sum of " +"[option]`MinSpareThreads` and [option]`ThreadsPerChild`. This directive is " +"used by the `worker` MPM only." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2011 +#, no-wrap +msgid "Using the MaxSpareThreads directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2017 +#, no-wrap +msgid "MaxSpareThreads 75\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2021 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,MinSpareServers] " +"[option]`MinSpareServers`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2022 +msgid "" +"The [option]`MinSpareServers` directive allows you to specify the minimum " +"number of spare child processes. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2026 +#, no-wrap +msgid "MinSpareServers _number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2029 +msgid "" +"Note that a high _number_ can create a heavy processing load on the " +"server. This directive is used by the `prefork` MPM only." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2031 +#, no-wrap +msgid "Using the MinSpareServers directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2037 +#, no-wrap +msgid "MinSpareServers 5\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2041 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,MinSpareThreads] " +"[option]`MinSpareThreads`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2042 +msgid "" +"The [option]`MinSpareThreads` directive allows you to specify the minimum " +"number of spare server threads. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2046 +#, no-wrap +msgid "MinSpareThreads _number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2049 +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2089 +msgid "This directive is used by the `worker` MPM only." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2051 +#, no-wrap +msgid "Using the MinSpareThreads directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2057 +#, no-wrap +msgid "MinSpareThreads 75\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2061 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,StartServers] " +"[option]`StartServers`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2062 +msgid "" +"The [option]`StartServers` directive allows you to specify the number of " +"child processes to create when the service is started. It takes the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2066 +#, no-wrap +msgid "StartServers _number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2069 +msgid "" +"Since the child processes are dynamically created and terminated according " +"to the current traffic load, it is usually not necessary to change this " +"value." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2071 +#, no-wrap +msgid "Using the StartServers directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2077 +#, no-wrap +msgid "StartServers 8\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2081 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,ThreadsPerChild] " +"[option]`ThreadsPerChild`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2082 +msgid "" +"The [option]`ThreadsPerChild` directive allows you to specify the number of " +"threads a child process can create. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2086 +#, no-wrap +msgid "ThreadsPerChild _number_\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2091 +#, no-wrap +msgid "Using the ThreadsPerChild directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2097 +#, no-wrap +msgid "ThreadsPerChild 25\n" +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2102 +#, no-wrap +msgid "Working with Modules" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2105 +msgid "" +"indexterm:[Apache HTTP " +"Server,directories,/usr/lib/httpd/modules/]indexterm:[Apache HTTP " +"Server,directories,/usr/lib64/httpd/modules/] Being a modular application, " +"the `httpd` service is distributed along with a number of _Dynamic Shared " +"Objects_ (*DSO*pass:attributes[{blank}]s), which can be dynamically loaded " +"or unloaded at runtime as necessary. By default, these modules are located " +"in `/usr/lib/httpd/modules/` on 32-bit and in `/usr/lib64/httpd/modules/` on " +"64-bit systems." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2107 +#, no-wrap +msgid "Loading a Module" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2110 +msgid "" +"indexterm:[Apache HTTP Server,modules,loading] To load a particular DSO " +"module, use the [option]`LoadModule` directive as described in " +"xref:Web_Servers.adoc#s3-apache-httpdconf-directives[Common httpd.conf " +"Directives]. Note that modules provided by a separate package often have " +"their own configuration file in the `/etc/httpd/conf.d/` directory." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2112 +#, no-wrap +msgid "Loading the mod_ssl DSO" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2117 +#, no-wrap +msgid "LoadModule ssl_module modules/mod_ssl.so\n" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2122 +msgid "" +"Once you are finished, restart the web server to reload the " +"configuration. See " +"xref:Web_Servers.adoc#s3-apache-running-restarting[Restarting the Service] " +"for more information on how to restart the `httpd` service." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2124 +#, no-wrap +msgid "Writing a Module" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2127 +msgid "" +"indexterm:[Apache HTTP Server,modules,developing] If you intend to create a " +"new DSO module, make sure you have the [package]*httpd-devel* package " +"installed. To do so, enter the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2131 +#, no-wrap +msgid "#{nbsp}dnf install httpd-devel\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2134 +msgid "" +"This package contains the include files, the header files, and the " +"[application]*APache eXtenSion* ([command]#apxs#) utility required to " +"compile a module." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2136 +msgid "Once written, you can build the module with the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2140 +#, no-wrap +msgid "#{nbsp}apxs -i -a -c module_name.c\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2143 +msgid "" +"If the build was successful, you should be able to load the module the same " +"way as any other module that is distributed with the Apache HTTP Server." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2145 +#, no-wrap +msgid "Setting Up Virtual Hosts" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2148 +msgid "" +"indexterm:[Apache HTTP Server,virtual host]indexterm:[virtual host,Apache " +"HTTP Server] The Apache HTTP Server's built in virtual hosting allows the " +"server to provide different information based on which IP address, host " +"name, or port is being requested." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2150 +msgid "" +"To create a name-based virtual host, copy the example configuration file " +"`/usr/share/doc/httpd-_VERSION_pass:attributes[{blank}]/httpd-vhosts.conf` " +"into the `/etc/httpd/conf.d/` directory, and replace the `@@Port@@` and " +"`@@ServerRoot@@` placeholder values. Customize the options according to your " +"requirements as shown in " +"xref:Web_Servers.adoc#example-apache-virtualhosts-config[Example virtual " +"host configuration]." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2152 +#, no-wrap +msgid "Example virtual host configuration" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2165 +#, no-wrap +msgid "" +"\n" +" ServerAdmin webmaster@penguin.example.com\n" +" DocumentRoot \"/www/docs/penguin.example.com\"\n" +" ServerName penguin.example.com\n" +" ServerAlias www.penguin.example.com\n" +" ErrorLog \"/var/log/httpd/dummy-host.example.com-error_log\"\n" +" CustomLog \"/var/log/httpd/dummy-host.example.com-access_log\" common\n" +"\n" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2170 +msgid "" +"Note that [option]`ServerName` must be a valid DNS name assigned to the " +"machine. The [option]`` container is highly customizable, and " +"accepts most of the directives available within the main server " +"configuration. Directives that are *not* supported within this container " +"include [option]`User` and [option]`Group`, which were replaced by " +"[option]`SuexecUserGroup`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2171 +#, no-wrap +msgid "Changing the port number" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2176 +msgid "" +"If you configure a virtual host to listen on a non-default port, make sure " +"you update the [option]`Listen` directive in the global settings section of " +"the `/etc/httpd/conf/httpd.conf` file accordingly." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2180 +msgid "" +"To activate a newly created virtual host, the web server has to be restarted " +"first. See xref:Web_Servers.adoc#s3-apache-running-restarting[Restarting the " +"Service] for more information on how to restart the `httpd` service." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2182 +#, no-wrap +msgid "Setting Up an SSL Server" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2185 +msgid "" +"indexterm:[Apache HTTP Server,modules,mod_ssl]indexterm:[SSL server,Apache " +"HTTP Server]indexterm:[SSL,Apache HTTP Server]indexterm:[TLS,Apache HTTP " +"Server]indexterm:[OpenSSL,SSL,SSL]indexterm:[OpenSSL,TLS,TLS] _Secure " +"Sockets Layer_ (*SSL*) is a cryptographic protocol that allows a server and " +"a client to communicate securely. Along with its extended and improved " +"version called _Transport Layer Security_ (*TLS*), it ensures both privacy " +"and data integrity. The Apache HTTP Server in combination with `mod_ssl`, a " +"module that uses the OpenSSL toolkit to provide the SSL/TLS support, is " +"commonly referred to as the _SSL server_." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2187 +msgid "" +"Unlike a regular HTTP connection that can be read and possibly modified by " +"anybody who is able to intercept it, the use of `mod_ssl` prevents any " +"inspection or modification of the transmitted content. This section provides " +"basic information on how to enable this module in the Apache HTTP Server " +"configuration, and guides you through the process of generating private keys " +"and self-signed certificates." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2189 +#, no-wrap +msgid "An Overview of Certificates and Security" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2194 +msgid "" +"indexterm:[Apache HTTP Server,SSL server,private key]indexterm:[Apache HTTP " +"Server,SSL server,public key] Secure communication is based on the use of " +"keys. In conventional or _symmetric cryptography_, both ends of the " +"transaction have the same key they can use to decode each other's " +"transmissions. On the other hand, in public or _asymmetric cryptography_, " +"two keys co-exist: a _private key_ that is kept a secret, and a _public key_ " +"that is usually shared with the public. While the data encoded with the " +"public key can only be decoded with the private key, data encoded with the " +"private key can in turn only be decoded with the public key. " +"indexterm:[Apache HTTP Server,SSL server,certificate]indexterm:[Apache HTTP " +"Server,SSL server,certificate authority] To provide secure communications " +"using SSL, an SSL server must use a digital certificate signed by a " +"_Certificate Authority_ (*CA*). The certificate lists various attributes of " +"the server (that is, the server host name, the name of the company, its " +"location, etc.), and the signature produced using the CA's private key. This " +"signature ensures that a particular certificate authority has signed the " +"certificate, and that the certificate has not been modified in any way." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2196 +msgid "" +"When a web browser establishes a new SSL connection, it checks the " +"certificate provided by the web server. If the certificate does not have a " +"signature from a trusted CA, or if the host name listed in the certificate " +"does not match the host name used to establish the connection, it refuses to " +"communicate with the server and usually presents a user with an appropriate " +"error message." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2198 +msgid "" +"By default, most web browsers are configured to trust a set of widely used " +"certificate authorities. Because of this, an appropriate CA should be chosen " +"when setting up a secure server, so that target users can trust the " +"connection, otherwise they will be presented with an error message, and will " +"have to accept the certificate manually. Since encouraging users to override " +"certificate errors can allow an attacker to intercept the connection, you " +"should use a trusted CA whenever possible. For more information on this, see " +"xref:Web_Servers.adoc#table-apache-mod_ssl-certificates-authorities[Information " +"about CA lists used by common web browsers]." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2200 +#, no-wrap +msgid "Information about CA lists used by common web browsers" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2209 +#, no-wrap +msgid "" +"|Web Browser|Link\n" +"|[application]*Mozilla " +"Firefox*|link:++https://www.mozilla.org/projects/security/certs/included/++[Mozilla " +"root CA list].\n" +"|[application]*Opera*|link:++https://www.opera.com/docs/ca/++[Information on " +"root certificates used by Opera].\n" +"|[application]*Internet " +"Explorer*|link:++https://support.microsoft.com/kb/931125++[Information on " +"root certificates used by Microsoft Windows].\n" +"|[application]*Chromium*|link:++https://www.chromium.org/Home/chromium-security/root-ca-policy++[Information " +"on root certificates used by the Chromium project].\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2212 +msgid "" +"When setting up an SSL server, you need to generate a certificate request " +"and a private key, and then send the certificate request, proof of the " +"company's identity, and payment to a certificate authority. Once the CA " +"verifies the certificate request and your identity, it will send you a " +"signed certificate you can use with your server. Alternatively, you can " +"create a self-signed certificate that does not contain a CA signature, and " +"thus should be used for testing purposes only." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2214 +#, no-wrap +msgid "Enabling the mod_ssl Module" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2217 +msgid "" +"If you intend to set up an SSL server, make sure you have the " +"[package]*mod_ssl* (the `mod_ssl` module) and [package]*openssl* (the " +"OpenSSL toolkit) packages installed. To do so, enter the following command " +"as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2221 +#, no-wrap +msgid "#{nbsp}dnf install mod_ssl openssl\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2224 +msgid "" +"indexterm:[Apache HTTP Server,files,/etc/httpd/conf.d/ssl.conf] This will " +"create the `mod_ssl` configuration file at `/etc/httpd/conf.d/ssl.conf`, " +"which is included in the main Apache HTTP Server configuration file by " +"default. For the module to be loaded, restart the `httpd` service as " +"described in xref:Web_Servers.adoc#s3-apache-running-restarting[Restarting " +"the Service]." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2229 +msgid "" +"Due to the SSL3.0 protocol vulnerability CVE-2014-3566, described in " +"link:++https://www.us-cert.gov/ncas/alerts/TA14-290A++[SSL 3.0 Protocol " +"Vulnerability and POODLE Attack], it is recommended to disable `SSL` and use " +"only `TLSv1.1` or `TLSv1.2`. Backwards compatibility can be achieved using " +"`TLSv1.0`. Many products have the ability to use `SSLv2` or `SSLv3` " +"protocols, or enable them by default. However, the use of `SSLv2` or `SSLv3` " +"is now strongly recommended against." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2233 +#, no-wrap +msgid "Enabling and Disabling SSL and TLS in mod_ssl" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2236 +msgid "" +"To disable and enable specific versions of the SSL and TLS protocol, either " +"do it globally by adding the [command]#SSLProtocol# directive in the " +"\"`\\#\\# SSL Global Context`\" section of the configuration file and " +"removing it everywhere else, or edit the default entry under \"`\\# SSL " +"Protocol support`\" in all \"`VirtualHost`\" sections. If you do not specify " +"it in the per-domain VirtualHost section then it will inherit the settings " +"from the global section. To make sure that a protocol version is being " +"disabled the administrator should either *only* specify " +"[command]#SSLProtocol# in the \"`SSL Global Context`\" section, or specify " +"it in *all* per-domain VirtualHost sections." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2238 +#, no-wrap +msgid "Disable SSLv2 and SSLv3" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2240 +msgid "" +"To disable SSL version 2 and SSL version 3, which implies enabling " +"everything except SSL version 2 and SSL version 3, in all VirtualHost " +"sections, proceed as follows:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2242 +msgid "" +"As `root`, open the `/etc/httpd/conf.d/ssl.conf` file and search for *all* " +"instances of the [command]#SSLProtocol# directive. By default, the " +"configuration file contains one section that looks as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2249 +#, no-wrap +msgid "" +"# vi /etc/httpd/conf.d/ssl.conf\n" +"# SSL Protocol support:\n" +"# List the enable protocol levels with which clients will be able to\n" +"# connect. Disable SSLv2 access by default:\n" +"SSLProtocol all -SSLv2\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2252 +msgid "This section is within the VirtualHost section." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2254 +msgid "Edit the [command]#SSLProtocol# line as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2260 +#, no-wrap +msgid "" +"# SSL Protocol support:\n" +"# List the enable protocol levels with which clients will be able to\n" +"# connect. Disable SSLv2 access by default:\n" +"SSLProtocol All -SSLv2 -SSLv3\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2263 +msgid "Repeat this action for all VirtualHost sections." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2265 +msgid "" +"Verify that all occurrences of the [command]#SSLProtocol# directive have " +"been changed as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2270 +#, no-wrap +msgid "" +"# grep SSLProtocol /etc/httpd/conf.d/ssl.conf\n" +"pass:quotes[*SSLProtocol*] all -SSLv2 -SSLv3\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2273 +msgid "" +"This step is particularly important if you have more than the one default " +"VirtualHost section." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2275 +msgid "Restart the Apache service as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2278 +#, no-wrap +msgid "# systemctl restart httpd\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2281 +msgid "Note that any sessions will be interrupted." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2283 +#, no-wrap +msgid "Using an Existing Key and Certificate" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2286 +msgid "" +"indexterm:[Apache HTTP Server,SSL server,private key]indexterm:[Apache HTTP " +"Server,SSL server,certificate] If you have a previously created key and " +"certificate, you can configure the SSL server to use these files instead of " +"generating new ones. There are only two situations where this is not " +"possible:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2288 +#, no-wrap +msgid "*You are changing the IP address or domain name.*\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2290 +msgid "" +"Certificates are issued for a particular IP address and domain name pair. If " +"one of these values changes, the certificate becomes invalid." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2292 +#, no-wrap +msgid "" +"*You have a certificate from VeriSign, and you are changing the server " +"software.*\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2294 +msgid "" +"VeriSign, a widely used certificate authority, issues certificates for a " +"particular software product, IP address, and domain name. Changing the " +"software product renders the certificate invalid." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2296 +msgid "" +"In either of the above cases, you will need to obtain a new certificate. For " +"more information on this topic, see " +"xref:Web_Servers.adoc#s3-apache-mod_ssl-genkey[Generating a New Certificate " +"Using OpenSSL]." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2298 +msgid "" +"If you want to use an existing key and certificate, move the relevant files " +"to the `/etc/pki/tls/private/` and `/etc/pki/tls/certs/` directories " +"respectively. You can do so by issuing the following commands as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2303 +#, no-wrap +msgid "" +"#{nbsp}mv pass:quotes[`key_file.key`] " +"pass:quotes[`/etc/pki/tls/private/hostname.key`]\n" +"#{nbsp}mv pass:quotes[`certificate.crt`] " +"pass:quotes[`/etc/pki/tls/certs/hostname.crt`]\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2306 +msgid "" +"Then add the following lines to the `/etc/httpd/conf.d/ssl.conf` " +"configuration file:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2311 +#, no-wrap +msgid "" +"SSLCertificateFile " +"/etc/pki/tls/certs/pass:attributes[{blank}]_hostname_.crt\n" +"SSLCertificateKeyFile " +"/etc/pki/tls/private/pass:attributes[{blank}]_hostname_.key\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2314 +msgid "" +"To load the updated configuration, restart the `httpd` service as described " +"in xref:Web_Servers.adoc#s3-apache-running-restarting[Restarting the " +"Service]." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2316 +#, no-wrap +msgid "Using a key and certificate from the Red{nbsp}Hat Secure Web Server" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2323 +#, no-wrap +msgid "" +"#{nbsp}mv /etc/httpd/conf/httpsd.key " +"/etc/pki/tls/private/penguin.example.com.key\n" +"#{nbsp}mv /etc/httpd/conf/httpsd.crt " +"/etc/pki/tls/certs/penguin.example.com.crt\n" +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2328 +#, no-wrap +msgid "Generating a New Certificate Using OpenSSL" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2331 +msgid "First, generate the private key. In this example we will use a 2048 RSA key:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2335 +#, no-wrap +msgid "# openssl genrsa -out myhost.com.key 2048\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2338 +msgid "" +"Create a Certificate Signing Request(CSR). The Common Name field must be " +"your server's hostname:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2342 +#, no-wrap +msgid "# openssl req -new -key myhost.com.key -out myhost.com.csr -sha512\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2345 +msgid "" +"A message digest algorithm like SHA2 or stronger is recommended, but it's " +"more important for the certificate than for the request. However your CA " +"decides which message digest they use for the certificate." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2347 +msgid "" +"Now give your CSR to your Certificate Authority(CA) so they can sign your " +"key and give you a certificate:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2351 +#, no-wrap +msgid "" +"# openssl x509 -req -days 365 -in myhost.com.csr -signkey myhost.com.key " +"-out myhost.com.crt -sha512\n" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2356 +msgid "" +"You can also self-sign the CSR, but bear in mind the security issues that it " +"poses and that browsers will warn users about this." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2359 +msgid "" +"Once your CA has signed it, they will give you the certificate(`.crt` " +"file). Now move the private key and the certificate to their respective " +"directories:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2364 +#, no-wrap +msgid "" +"# cp myhost.com.crt /etc/pki/tls/certs/\n" +"# cp myhost.com.key /etc/pki/tls/private/myhost.com.key\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2367 +msgid "" +"The Certificate Signing Request(CSR) can be deleted as it becomes useless " +"once you have obtained your certificate. Alternatively you can put it along " +"your private key:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2371 +#, no-wrap +msgid "# cp myhost.com.csr /etc/pki/tls/private/myhost.com.csr\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2374 +msgid "Set the correct context of these files for SELinux:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2378 +#, no-wrap +msgid "# restorecon -RvF /etc/pki\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2381 +msgid "" +"The last step is to configure the webserver of your host for the TLS " +"protocol using the key and the certificate files you have just created - see " +"xref:The_Apache_HTTP_Server.adoc#mod-ssl-configuration[mod_ssl " +"configuration]." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2383 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2386 +msgid "To learn more about the Apache HTTP Server, see the following resources." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2387 +#, no-wrap +msgid "" +"Installed Documentationindexterm:[Apache HTTP Server,additional " +"resources,installed documentation]" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2390 +msgid "" +"`httpd(8)` — The manual page for the `httpd` service containing the complete " +"list of its command-line options." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2392 +msgid "" +"`apachectl(8)` — The manual page for the Apache HTTP Server Control " +"Interface." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2394 +#, no-wrap +msgid "" +"Installable Documentationindexterm:[Apache HTTP Server,additional " +"resources,installable documentation]" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2397 +msgid "" +"link:++http://localhost/manual/++[] — The official documentation for the " +"Apache HTTP Server with the full description of its directives and available " +"modules. Note that in order to access this documentation, you must have the " +"[package]*httpd-manual* package installed, and the web server must be " +"running." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2399 +msgid "Before accessing the documentation, issue the following commands as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2403 +#, no-wrap +msgid "" +"# dnf install httpd-manual\n" +"# apachectl graceful\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2405 +#, no-wrap +msgid "" +"Online Documentationindexterm:[Apache HTTP Server,additional " +"resources,useful websites]" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2408 +msgid "" +"link:++https://httpd.apache.org/++[] — The official website for the Apache " +"HTTP Server with documentation on all the directives and default modules." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2410 +msgid "" +"link:++http://www.modssl.org/++[] — The official website for the " +"[application]*mod_ssl* module." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2411 +msgid "" +"link:++https://www.openssl.org/++[] — The OpenSSL home page containing " +"further documentation, frequently asked questions, links to the mailing " +"lists, and other useful resources." +msgstr "" diff --git a/po/fr/rawhide/pages/basic-system-configuration/Configuring_the_Date_and_Time.po b/po/fr/rawhide/pages/basic-system-configuration/Configuring_the_Date_and_Time.po new file mode 100644 index 00000000000..53fd555e0a4 --- /dev/null +++ b/po/fr/rawhide/pages/basic-system-configuration/Configuring_the_Date_and_Time.po @@ -0,0 +1,951 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:6 +#, no-wrap +msgid "Configuring the Date and Time" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:9 +msgid "" +"Modern operating systems distinguish between the following two types of " +"clocks:" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:11 +msgid "" +"A _real-time clock_ (*RTC*), commonly referred to as a _hardware clock_, " +"(typically an integrated circuit on the system board) that is completely " +"independent of the current state of the operating system and runs even when " +"the computer is shut down." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:13 +msgid "" +"A _system clock_, also known as a _software clock_, that is maintained by " +"the kernel and its initial value is based on the real-time clock. Once the " +"system is booted and the system clock is initialized, the system clock is " +"completely independent of the real-time clock." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:15 +msgid "" +"The system time is always kept in _Coordinated Universal Time_ (*UTC*) and " +"converted in applications to local time as needed. _Local time_ is the " +"actual time in your current time zone, taking into account _daylight saving " +"time_ (*DST*). The real-time clock can use either UTC or local time. UTC is " +"recommended." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:17 +msgid "" +"{MAJOROSVER} offers three command line tools that can be used to configure " +"and display information about the system date and time: the " +"[command]#timedatectl# utility, which is new in {MAJOROSVER} and is part of " +"`systemd`pass:attributes[{blank}]; the traditional [command]#date# command; " +"and the [command]#hwclock# utility for accessing the hardware clock." +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:19 +#, no-wrap +msgid "Using the timedatectl Command" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:22 +msgid "" +"The [application]*timedatectl* utility is distributed as part of the " +"`systemd` system and service manager and allows you to review and change the " +"configuration of the system clock. You can use this tool to change the " +"current date and time, set the time zone, or enable automatic " +"synchronization of the system clock with a remote server." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:24 +msgid "" +"For information on how to display the current date and time in a custom " +"format, see also " +"xref:Configuring_the_Date_and_Time.adoc#sect-Configuring_the_Date_and_Time-date[Using " +"the date Command]." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:26 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:38 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:211 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:255 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:363 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:375 +#, no-wrap +msgid "Displaying the Current Date and Time" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:29 +msgid "" +"To display the current date and time along with detailed information about " +"the configuration of the system and hardware clock, run the " +"[command]#timedatectl# command with no additional command line options:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:33 +#, no-wrap +msgid "[command]#timedatectl#\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:36 +msgid "" +"This displays the local and universal time, the currently used time zone, " +"the status of the Network Time Protocol (`NTP`) configuration, and " +"additional information related to DST." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:42 +msgid "" +"The following is an example output of the [command]#timedatectl# command on " +"a system that does not use `NTP` to synchronize the system clock with a " +"remote server:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:59 +#, no-wrap +msgid "" +"~]${nbsp}timedatectl\n" +" Local time: Mon 2013-09-16 19:30:24 CEST\n" +" Universal time: Mon 2013-09-16 17:30:24 UTC\n" +" Timezone: Europe/Prague (CEST, +0200)\n" +" NTP enabled: no\n" +"NTP synchronized: no\n" +" RTC in local TZ: no\n" +" DST active: yes\n" +" Last DST change: DST began at\n" +" Sun 2013-03-31 01:59:59 CET\n" +" Sun 2013-03-31 03:00:00 CEST\n" +" Next DST change: DST ends (the clock jumps one hour backwards) at\n" +" Sun 2013-10-27 02:59:59 CEST\n" +" Sun 2013-10-27 02:00:00 CET\n" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:64 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:80 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:285 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:304 +#, no-wrap +msgid "Changing the Current Time" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:67 +msgid "To change the current time, type the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:71 +#, no-wrap +msgid "[command]#timedatectl# [option]`set-time` _HH:MM:SS_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:74 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:295 +msgid "" +"Replace _HH_ with an hour, _MM_ with a minute, and _SS_ with a second, all " +"typed in two-digit form." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:76 +msgid "" +"This command updates both the system time and the hardware clock. The result " +"it is similar to using both the [command]#date --set# and [command]#hwclock " +"--systohc# commands." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:78 +msgid "" +"The command will fail if an `NTP` service is enabled. See " +"xref:Configuring_the_Date_and_Time.adoc#sect-Configuring_the_Date_and_Time-timedatectl-NTP[Synchronizing " +"the System Clock with a Remote Server] to temporally disable the service." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:84 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:308 +msgid "" +"To change the current time to 11:26 p.m., run the following command as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:88 +#, no-wrap +msgid "~]#{nbsp}timedatectl set-time 23:26:00\n" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:93 +msgid "" +"By default, the system is configured to use UTC. To configure your system to " +"maintain the clock in the local time, run the [command]#timedatectl# command " +"with the [option]`set-local-rtc` option as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:97 +#, no-wrap +msgid "[command]#timedatectl# [option]`set-local-rtc` _boolean_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:100 +msgid "" +"To configure your system to maintain the clock in the local time, replace " +"_boolean_ with `yes` (or, alternatively, `y`, `true`, `t`, or `1`). To " +"configure the system to use UTC, replace _boolean_ with `no` (or, " +"alternatively, `n`, `false`, `f`, or `0`). The default option is `no`." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:102 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:116 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:317 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:331 +#, no-wrap +msgid "Changing the Current Date" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:105 +msgid "To change the current date, type the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:109 +#, no-wrap +msgid "[command]#timedatectl# [option]`set-time` _YYYY-MM-DD_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:112 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:327 +msgid "" +"Replace _YYYY_ with a four-digit year, _MM_ with a two-digit month, and _DD_ " +"with a two-digit day of the month." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:114 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:329 +msgid "" +"Note that changing the date without specifying the current time results in " +"setting the time to 00:00:00." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:120 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:335 +msgid "" +"To change the current date to 2 June 2013 and keep the current time (11:26 " +"p.m.), run the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:124 +#, no-wrap +msgid "~]#{nbsp}timedatectl set-time \"2013-06-02 23:26:00\"\n" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:129 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:148 +#, no-wrap +msgid "Changing the Time Zone" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:132 +msgid "To list all available time zones, type the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:136 +#, no-wrap +msgid "[command]#timedatectl# [option]`list-timezones`\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:139 +msgid "To change the currently used time zone, type as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:143 +#, no-wrap +msgid "timedatectl set-timezone pass:quotes[_time_zone_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:146 +msgid "" +"Replace _time_zone_ with any of the values listed by the " +"[command]#timedatectl list-timezones# command." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:152 +msgid "" +"To identify which time zone is closest to your present location, use the " +"[command]#timedatectl# command with the [option]`list-timezones` command " +"line option. For example, to list all available time zones in Europe, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:163 +#, no-wrap +msgid "" +"~]#{nbsp}timedatectl list-timezones | grep Europe\n" +"Europe/Amsterdam\n" +"Europe/Andorra\n" +"Europe/Athens\n" +"Europe/Belgrade\n" +"Europe/Berlin\n" +"Europe/Bratislava\n" +"pass:quotes[_…_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:166 +msgid "To change the time zone to `Europe/Prague`, type as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:170 +#, no-wrap +msgid "~]#{nbsp}timedatectl set-timezone Europe/Prague\n" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:175 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:189 +#, no-wrap +msgid "Synchronizing the System Clock with a Remote Server" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:178 +msgid "" +"As opposed to the manual adjustments described in the previous sections, the " +"[command]#timedatectl# command also allows you to enable automatic " +"synchronization of your system clock with a group of remote servers using " +"the `NTP` protocol. Enabling NTP enables the `chronyd` or `ntpd` service, " +"depending on which of them is installed." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:180 +msgid "The `NTP` service can be enabled and disabled using a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:184 +#, no-wrap +msgid "[command]#timedatectl# [option]`set-ntp` _boolean_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:187 +msgid "" +"To enable your system to synchronize the system clock with a remote `NTP` " +"server, replace _boolean_ with `yes` (the default option). To disable this " +"feature, replace _boolean_ with `no`." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:193 +msgid "" +"To enable automatic synchronization of the system clock with a remote " +"server, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:197 +#, no-wrap +msgid "~]#{nbsp}timedatectl set-ntp yes\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:200 +msgid "" +"The command will fail if an `NTP` service is not installed. See " +"xref:servers/Configuring_NTP_Using_the_chrony_Suite.adoc#sect-Installing_chrony[Installing " +"chrony] for more information." +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:204 +#, no-wrap +msgid "Using the date Command" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:207 +msgid "" +"The [command]#date# utility is available on all Linux systems and allows you " +"to display and configure the current date and time. It is frequently used in " +"scripts to display detailed information about the system clock in a custom " +"format." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:209 +msgid "" +"For information on how to change the time zone or enable automatic " +"synchronization of the system clock with a remote server, see " +"xref:Configuring_the_Date_and_Time.adoc#sect-Configuring_the_Date_and_Time-timedatectl[Using " +"the timedatectl Command]." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:214 +msgid "" +"To display the current date and time, run the [command]#date# command with " +"no additional command line options:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:218 +#, no-wrap +msgid "[command]#date#\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:221 +msgid "" +"This displays the day of the week followed by the current date, local time, " +"abbreviated time zone, and year." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:223 +msgid "" +"By default, the [command]#date# command displays the local time. To display " +"the time in UTC, run the command with the [option]`--utc` or [option]`-u` " +"command line option:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:227 +#, no-wrap +msgid "[command]#date# [option]`--utc`\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:230 +msgid "" +"You can also customize the format of the displayed information by providing " +"the [option]`+\"pass:attributes[{blank}]_format_pass:attributes[{blank}]\"` " +"option on the command line:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:233 +#, no-wrap +msgid "date +\"format\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:236 +msgid "" +"Replace _format_ with one or more supported control sequences as illustrated " +"in " +"xref:Configuring_the_Date_and_Time.adoc#exam-Configuring_the_Date_and_Time-date-Display[Displaying " +"the Current Date and Time]. See " +"xref:Configuring_the_Date_and_Time.adoc#tabl-Configuring_the_Date_and_Time-date-Format[Commonly " +"Used Control Sequences] for a list of the most frequently used formatting " +"options, or the `date`(1) manual page for a complete list of these options." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:238 +#, no-wrap +msgid "Commonly Used Control Sequences" +msgstr "" + +#. type: Table +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:252 +#, no-wrap +msgid "" +"|Control Sequence|Description\n" +"|[option]`%H`|The hour in the _HH_ format (for example, `17`).\n" +"|[option]`%M`|The minute in the _MM_ format (for example, `30`).\n" +"|[option]`%S`|The second in the _SS_ format (for example, `24`).\n" +"|[option]`%d`|The day of the month in the _DD_ format (for example, `16`).\n" +"|[option]`%m`|The month in the _MM_ format (for example, `09`).\n" +"|[option]`%Y`|The year in the _YYYY_ format (for example, `2013`).\n" +"|`%Z`|The time zone abbreviation (for example, `CEST`).\n" +"|[option]`%F`|The full date in the _YYYY-MM-DD_ format (for example, " +"`2013-09-16`). This option is equal to [option]`%Y-%m-%d`.\n" +"|[option]`%T`|The full time in the _HH:MM:SS_ format (for example, " +"17:30:24). This option is equal to [option]`%H:%M:%S`\n" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:259 +msgid "" +"To display the current date and local time, type the following at a shell " +"prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:264 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#date#\n" +"Mon Sep 16 17:30:24 CEST 2013\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:267 +msgid "" +"To display the current date and time in UTC, type the following at a shell " +"prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:272 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#date --utc#\n" +"Mon Sep 16 15:30:34 UTC 2013\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:275 +msgid "To customize the output of the [command]#date# command, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:280 +#, no-wrap +msgid "" +"~]${nbsp}date +\"%Y-%m-%d %H:%M\"\n" +"2013-09-16 17:30\n" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:288 +msgid "" +"To change the current time, run the [command]#date# command with the " +"[option]`--set` or [option]`-s` option as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:292 +#, no-wrap +msgid "[command]#date# [option]`--set` _HH:MM:SS_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:297 +msgid "" +"By default, the [command]#date# command sets the system clock to the local " +"time. To set the system clock in UTC, run the command with the " +"[option]`--utc` or [option]`-u` command line option:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:301 +#, no-wrap +msgid "[command]#date# [option]`--set` _HH:MM:SS_ [option]`--utc`\n" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:312 +#, no-wrap +msgid "~]#{nbsp}date --set 23:26:00\n" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:320 +msgid "" +"To change the current date, run the [command]#date# command with the " +"[option]`--set` or [option]`-s` option as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:324 +#, no-wrap +msgid "[command]#date# [option]`--set` _YYYY-MM-DD_\n" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:339 +#, no-wrap +msgid "~]#{nbsp}date --set 2013-06-02 23:26:00\n" +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:344 +#, no-wrap +msgid "Using the hwclock Command" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:347 +msgid "" +"`hwclock` is a utility for accessing the hardware clock, also referred to as " +"the Real Time Clock (RTC). The hardware clock is independent of the " +"operating system you use and works even when the machine is shut down. This " +"utility is used for displaying the time from the hardware clock. `hwclock` " +"also contains facilities for compensating for systematic drift in the " +"hardware clock." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:349 +msgid "" +"The hardware clock stores the values of: year, month, day, hour, minute, and " +"second. It is not able to store the time standard, local time or Coordinated " +"Universal Time (UTC), nor set the Daylight Saving Time (DST)." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:351 +msgid "" +"The `hwclock` utility saves its settings in the `/etc/adjtime` file, which " +"is created with the first change you make, for example, when you set the " +"time manually or synchronize the hardware clock with the system time." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:357 +msgid "" +"In {MAJOROS}{nbsp}6, the [command]#hwclock# command was run automatically on " +"every system shutdown or reboot, but it is not in {MAJOROSVER}. When the " +"system clock is synchronized by the Network Time Protocol (NTP) or Precision " +"Time Protocol (PTP), the kernel automatically synchronizes the hardware " +"clock to the system clock every 11 minutes." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:361 +msgid "" +"For details about NTP, see " +"xref:servers/Configuring_NTP_Using_the_chrony_Suite.adoc#ch-Configuring_NTP_Using_the_chrony_Suite[Configuring " +"NTP Using the chrony Suite] and " +"xref:servers/Configuring_NTP_Using_ntpd.adoc#ch-Configuring_NTP_Using_ntpd[Configuring " +"NTP Using ntpd]. For information about PTP, see " +"xref:servers/Configuring_PTP_Using_ptp4l.adoc#ch-Configuring_PTP_Using_ptp4l[Configuring " +"PTP Using ptp4l]. For information about setting the hardware clock after " +"executing [application]*ntpdate*, see " +"xref:servers/Configuring_NTP_Using_ntpd.adoc#s1-Configuring_the_Hardware_Clock_update[Configuring " +"the Hardware Clock Update]." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:366 +msgid "" +"Running [command]#hwclock# with no command line options as the `root` user " +"returns the date and time in local time to standard output." +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:370 +#, no-wrap +msgid "[command]#hwclock#\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:373 +msgid "" +"Note that using the [option]`--utc` or [option]`--localtime` options with " +"the [command]#hwclock# command does not mean you are displaying the hardware " +"clock time in UTC or local time. These options are used for setting the " +"hardware clock to keep time in either of them. The time is always displayed " +"in local time. Additionally, using the [command]#hwclock --utc# or " +"[command]#hwclock --local# commands does not change the record in the " +"`/etc/adjtime` file. This command can be useful when you know that the " +"setting saved in `/etc/adjtime` is incorrect but you do not want to change " +"the setting. On the other hand, you may receive misleading information if " +"you use the command an incorrect way. See the `hwclock`(8) manual page for " +"more details." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:379 +msgid "" +"To display the current date and the current local time from the hardware " +"clock, run as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:384 +#, no-wrap +msgid "" +"~]#{nbsp}hwclock\n" +"Tue 15 Apr 2014 04:23:46 PM CEST -0.329272 seconds\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:387 +msgid "" +"CEST is a time zone abbreviation and stands for Central European Summer " +"Time." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:391 +msgid "" +"For information on how to change the time zone, see " +"xref:Configuring_the_Date_and_Time.adoc#sect-Configuring_the_Date_and_Time-timedatectl-Time_Zone[Changing " +"the Time Zone]." +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:393 +#, no-wrap +msgid "Setting the Date and Time" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:396 +msgid "" +"Besides displaying the date and time, you can manually set the hardware " +"clock to a specific time." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:398 +msgid "" +"When you need to change the hardware clock date and time, you can do so by " +"appending the [option]`--set` and [option]`--date` options along with your " +"specification:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:402 +#, no-wrap +msgid "" +"[command]#hwclock --set --date _\"dd mmm yyyy " +"HH:MM\"_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:405 +msgid "" +"Replace _dd_ with a day (a two-digit number), _mmm_ with a month (a " +"three-letter abbreviation), _yyyy_ with a year (a four-digit number), _HH_ " +"with an hour (a two-digit number), _MM_ with a minute (a two-digit number)." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:407 +msgid "" +"At the same time, you can also set the hardware clock to keep the time in " +"either UTC or local time by adding the [option]`--utc` or " +"[option]`--localtime` options, respectively. In this case, `UTC` or `LOCAL` " +"is recorded in the `/etc/adjtime` file." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:409 +#, no-wrap +msgid "Setting the Hardware Clock to a Specific Date and Time" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:413 +msgid "" +"If you want to set the date and time to a specific value, for example, to " +"\"`21:17, October 21, 2014`\", and keep the hardware clock in UTC, run the " +"command as `root` in the following format:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:417 +#, no-wrap +msgid "~]#{nbsp}hwclock --set --date \"21 Oct 2014 21:17\" --utc\n" +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:422 +#, no-wrap +msgid "Synchronizing the Date and Time" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:425 +msgid "" +"You can synchronize the hardware clock and the current system time in both " +"directions." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:427 +msgid "" +"Either you can set the hardware clock to the current system time by using " +"this command:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:431 +#, no-wrap +msgid "[command]#hwclock --systohc#\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:434 +msgid "" +"Note that if you use NTP, the hardware clock is automatically synchronized " +"to the system clock every 11 minutes, and this command is useful only at " +"boot time to get a reasonable initial system time." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:436 +msgid "" +"Or, you can set the system time from the hardware clock by using the " +"following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:440 +#, no-wrap +msgid "[command]#hwclock --hctosys#\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:443 +msgid "" +"When you synchronize the hardware clock and the system time, you can also " +"specify whether you want to keep the hardware clock in local time or UTC by " +"adding the [option]`--utc` or [option]`--localtime` option. Similarly to " +"using [option]`--set`, `UTC` or `LOCAL` is recorded in the `/etc/adjtime` " +"file." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:445 +msgid "" +"The [command]#hwclock --systohc --utc# command is functionally similar to " +"[command]#timedatectl set-local-rtc false# and the [command]#hwclock " +"--systohc --local# command is an alternative to [command]#timedatectl " +"set-local-rtc true#." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:447 +#, no-wrap +msgid "Synchronizing the Hardware Clock with System Time" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:451 +msgid "" +"To set the hardware clock to the current system time and keep the hardware " +"clock in local time, run the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:455 +#, no-wrap +msgid "~]#{nbsp}hwclock --systohc --localtime\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:458 +msgid "" +"To avoid problems with time zone and DST switching, it is recommended to " +"keep the hardware clock in UTC. The shown " +"xref:Configuring_the_Date_and_Time.adoc#exam4-sect4-synchornizing-systohc-hwclock[Synchronizing " +"the Hardware Clock with System Time] is useful, for example, in case of a " +"multi boot with a Windows system, which assumes the hardware clock runs in " +"local time by default, and all other systems need to accommodate to it by " +"using local time as well. It may also be needed with a virtual machine; if " +"the virtual hardware clock provided by the host is running in local time, " +"the guest system needs to be configured to use local time, too." +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:462 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:465 +msgid "" +"For more information on how to configure the date and time in {MAJOROSVER}, " +"see the resources listed below." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:466 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:469 +msgid "" +"`timedatectl`(1) — The manual page for the [command]#timedatectl# command " +"line utility documents how to use this tool to query and change the system " +"clock and its settings." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:471 +msgid "" +"`date`(1) — The manual page for the [command]#date# command provides a " +"complete list of supported command line options." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:473 +msgid "" +"`hwclock`(8) — The manual page for the [command]#hwclock# command provides a " +"complete list of supported command line options." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:474 +#, no-wrap +msgid "See Also" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:476 +msgid "" +"xref:basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc#ch-System_Locale_and_Keyboard_Configuration[System " +"Locale and Keyboard Configuration] documents how to configure the keyboard " +"layout." +msgstr "" diff --git a/po/fr/rawhide/pages/basic-system-configuration/Gaining_Privileges.po b/po/fr/rawhide/pages/basic-system-configuration/Gaining_Privileges.po new file mode 100644 index 00000000000..4ef442d665b --- /dev/null +++ b/po/fr/rawhide/pages/basic-system-configuration/Gaining_Privileges.po @@ -0,0 +1,456 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:6 +#, no-wrap +msgid "Gaining Privileges" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:9 +msgid "" +"System administrators, and in some cases users, need to perform certain " +"tasks with administrative access. Accessing the system as the `root` user is " +"potentially dangerous and can lead to widespread damage to the system and " +"data. This chapter covers ways to gain administrative privileges using " +"setuid programs such as [command]#su# and [command]#sudo#. These programs " +"allow specific users to perform tasks which would normally be available only " +"to the `root` user while maintaining a higher level of control and system " +"security." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:11 +msgid "" +"See the " +"link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Security_Guide/++[Red{nbsp}Hat " +"Enterprise{nbsp}Linux{nbsp}7 Security Guide] for more information on " +"administrative controls, potential dangers, and ways to prevent data loss " +"resulting from improper use of privileged access." +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:13 +#, no-wrap +msgid "The su Command" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:16 +msgid "" +"When a user executes the [command]#su# command, they are prompted for the " +"`root` password and, after authentication, are given a `root` shell prompt." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:18 +msgid "" +"Once logged in using the [command]#su# command, the user *is* the `root` " +"user and has absolute administrative access to the system. Note that this " +"access is still subject to the restrictions imposed by SELinux, if it is " +"enabled. In addition, once a user has become `root`, it is possible for them " +"to use the [command]#su# command to change to any other user on the system " +"without being prompted for a password." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:20 +msgid "" +"Because this program is so powerful, administrators within an organization " +"may want to limit who has access to the command." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:22 +msgid "" +"One of the simplest ways to do this is to add users to the special " +"administrative group called _wheel_. To do this, type the following command " +"as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:26 +#, no-wrap +msgid "~]# usermod -a -G wheel pass:quotes[_username_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:29 +msgid "" +"In the previous command, replace _username_ with the user name you want to " +"add to the `wheel` group." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:31 +msgid "" +"You can also use the [application]*Users* settings tool to modify group " +"memberships, as follows. Note that you need administrator privileges to " +"perform this procedure." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:33 +msgid "" +"Press the kbd:[Super] key to enter the Activities Overview, type " +"[command]#Users# and then press kbd:[Enter]. The [application]*Users* " +"settings tool appears. The kbd:[Super] key appears in a variety of guises, " +"depending on the keyboard and other hardware, but often as either the " +"Windows or Command key, and typically to the left of the kbd:[Spacebar]." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:35 +msgid "" +"To enable making changes, click the btn:[Unlock] button, and enter a valid " +"administrator password." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:37 +msgid "" +"Click a user icon in the left column to display the user's properties in the " +"right-hand pane." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:39 +msgid "" +"Change the Account Type from `Standard` to `Administrator`. This will add " +"the user to the `wheel` group." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:41 +msgid "" +"See " +"xref:basic-system-configuration/Managing_Users_and_Groups.adoc#s1-users-configui[Managing " +"Users in a Graphical Environment] for more information about the " +"[application]*Users* tool." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:43 +msgid "" +"After you add the desired users to the `wheel` group, it is advisable to " +"only allow these specific users to use the [command]#su# command. To do " +"this, edit the PAM configuration file for [command]#su#, " +"`/etc/pam.d/su`. Open this file in a text editor and uncomment the following " +"line by removing the `#` character:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:46 +#, no-wrap +msgid "#auth required pam_wheel.so use_uid\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:49 +msgid "" +"This change means that only members of the administrative group `wheel` can " +"switch to another user using the [command]#su# command." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:50 +#, no-wrap +msgid "Note" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:55 +msgid "The `root` user is part of the `wheel` group by default." +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:59 +#, no-wrap +msgid "The sudo Command" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:62 +msgid "" +"The [command]#sudo# command offers another approach to giving users " +"administrative access. When trusted users precede an administrative command " +"with [command]#sudo#, they are prompted for *their own* password. Then, when " +"they have been authenticated and assuming that the command is permitted, the " +"administrative command is executed as if they were the `root` user." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:64 +msgid "The basic format of the [command]#sudo# command is as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:68 +#, no-wrap +msgid "[command]#sudo# _command_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:71 +msgid "" +"In the above example, _command_ would be replaced by a command normally " +"reserved for the `root` user, such as [command]#mount#." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:73 +msgid "" +"The [command]#sudo# command allows for a high degree of flexibility. For " +"instance, only users listed in the `/etc/sudoers` configuration file are " +"allowed to use the [command]#sudo# command and the command is executed in " +"*the user's* shell, not a `root` shell. This means the `root` shell can be " +"completely disabled as shown in the " +"link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Security_Guide/++[Red{nbsp}Hat " +"Enterprise{nbsp}Linux{nbsp}7 Security Guide]." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:75 +msgid "" +"Each successful authentication using the [command]#sudo# command is logged " +"to the file `/var/log/messages` and the command issued along with the " +"issuer's user name is logged to the file `/var/log/secure`. If additional " +"logging is required, use the `pam_tty_audit` module to enable TTY auditing " +"for specified users by adding the following line to your " +"`/etc/pam.d/system-auth` file:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:79 +#, no-wrap +msgid "" +"session required pam_tty_audit.so disable=pass:quotes[_pattern_] " +"enable=pass:quotes[_pattern_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:83 +msgid "" +"where _pattern_ represents a comma-separated listing of users with an " +"optional use of globs. For example, the following configuration will enable " +"TTY auditing for the `root` user and disable it for all other users:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:86 +#, no-wrap +msgid "session required pam_tty_audit.so disable=* enable=root\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:89 +msgid "" +"Another advantage of the [command]#sudo# command is that an administrator " +"can allow different users access to specific commands based on their needs." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:91 +msgid "" +"Administrators wanting to edit the [command]#sudo# configuration file, " +"`/etc/sudoers`, should use the [command]#visudo# command." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:93 +msgid "" +"To give someone full administrative privileges, type [command]#visudo# and " +"add a line similar to the following in the user privilege specification " +"section:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:97 +#, no-wrap +msgid "juan ALL=(ALL) ALL\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:100 +msgid "" +"This example states that the user, `juan`, can use [command]#sudo# from any " +"host and execute any command." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:102 +msgid "" +"The example below illustrates the granularity possible when configuring " +"[command]#sudo#:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:106 +#, no-wrap +msgid "%users localhost=/sbin/shutdown -h now\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:109 +msgid "" +"This example states that any member of the `users` system group can issue " +"the command [command]#/sbin/shutdown -h now# as long as it is issued from " +"the console." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:111 +msgid "The man page for `sudoers` has a detailed listing of options for this file." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:112 +#, no-wrap +msgid "Important" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:117 +msgid "" +"There are several potential risks to keep in mind when using the " +"[command]#sudo# command. You can avoid them by editing the `/etc/sudoers` " +"configuration file using [command]#visudo# as described above. Leaving the " +"`/etc/sudoers` file in its default state gives every user in the `wheel` " +"group unlimited `root` access." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:119 +msgid "" +"By default, [command]#sudo# stores the sudoer's password for a five minute " +"timeout period. Any subsequent uses of the command during this period will " +"not prompt the user for a password. This could be exploited by an attacker " +"if the user leaves their workstation unattended and unlocked while still " +"being logged in. This behavior can be changed by adding the following line " +"to the `/etc/sudoers` file:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:123 +#, no-wrap +msgid "Defaults timestamp_timeout=pass:quotes[_value_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:126 +msgid "" +"where _value_ is the desired timeout length in minutes. Setting the _value_ " +"to 0 causes [command]#sudo# to require a password every time." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:128 +msgid "" +"If a sudoer's account is compromised, an attacker can use [command]#sudo# to " +"open a new shell with administrative privileges:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:132 +#, no-wrap +msgid "[command]#sudo /bin/bash#\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:135 +msgid "" +"Opening a new shell as `root` in this or similar fashion gives the attacker " +"administrative access for a theoretically unlimited amount of time, " +"bypassing the timeout period specified in the `/etc/sudoers` file and never " +"requiring the attacker to input a password for [command]#sudo# again until " +"the newly opened session is closed." +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:139 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:142 +msgid "" +"While programs allowing users to gain administrative privileges are a " +"potential security risk, security itself is beyond the scope of this " +"particular book. You should therefore refer to the resources listed below " +"for more information regarding security and privileged access." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:143 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:146 +msgid "" +"`su`(1) — The manual page for [command]#su# provides information regarding " +"the options available with this command." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:148 +msgid "" +"`sudo`(8) — The manual page for [command]#sudo# includes a detailed " +"description of this command and lists options available for customizing its " +"behavior." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:150 +msgid "" +"`pam`(8) — The manual page describing the use of Pluggable Authentication " +"Modules (PAM) for Linux." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:151 +#, no-wrap +msgid "Online Documentation" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:154 +msgid "" +"The " +"link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Security_Guide/++[Red{nbsp}Hat " +"Enterprise{nbsp}Linux{nbsp}7 Security Guide] provides a more in-depth look " +"at potential security issues pertaining to setuid programs as well as " +"techniques used to alleviate these risks." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:155 +#, no-wrap +msgid "See Also" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:157 +msgid "" +"xref:basic-system-configuration/Managing_Users_and_Groups.adoc#ch-Managing_Users_and_Groups[Managing " +"Users and Groups] documents how to manage system users and groups in the " +"graphical user interface and on the command line." +msgstr "" diff --git a/po/fr/rawhide/pages/basic-system-configuration/Managing_Users_and_Groups.po b/po/fr/rawhide/pages/basic-system-configuration/Managing_Users_and_Groups.po new file mode 100644 index 00000000000..f77f108dd60 --- /dev/null +++ b/po/fr/rawhide/pages/basic-system-configuration/Managing_Users_and_Groups.po @@ -0,0 +1,1236 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:5 +#, no-wrap +msgid "Managing Users and Groups" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:8 +msgid "" +"The control of users and groups is a core element of {MAJOROS} system " +"administration. This chapter explains how to add, manage, and delete users " +"and groups in the graphical user interface and on the command line, and " +"covers advanced topics, such as creating group directories." +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:10 +#, no-wrap +msgid "Introduction to Users and Groups" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:13 +msgid "" +"While users can be either people (meaning accounts tied to physical users) " +"or accounts which exist for specific applications to use, groups are logical " +"expressions of organization, tying users together for a common " +"purpose. Users within a group share the same permissions to read, write, or " +"execute files owned by that group." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:15 +msgid "" +"Each user is associated with a unique numerical identification number called " +"a _user ID_ (*UID*). Likewise, each group is associated with a _group ID_ " +"(*GID*). A user who creates a file is also the owner and group owner of that " +"file. The file is assigned separate read, write, and execute permissions for " +"the owner, the group, and everyone else. The file owner can be changed only " +"by `root`, and access permissions can be changed by both the `root` user and " +"file owner." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:17 +msgid "" +"Additionally, {MAJOROS} supports _access control lists_ (*ACLs*) for files " +"and directories which allow permissions for specific users outside of the " +"owner to be set. For more information about this feature, see the " +"[citetitle]_link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/System_Administrators_Guide/ch-Access_Control_Lists.html++[Access " +"Control Lists]_ chapter of the " +"[citetitle]_link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/System_Administrators_Guide/index.html++[Red " +"Hat Enterprise Linux 7 System Administrators Guide]_." +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:19 +#, no-wrap +msgid "User Private Groups" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:22 +msgid "" +"indexterm:[groups,user private]indexterm:[user private " +"groups,groups]indexterm:[groups,tools for management of,groupadd] {MAJOROS} " +"uses a _user private group_ (_UPG_) scheme, which makes UNIX groups easier " +"to manage. A user private group is created whenever a new user is added to " +"the system. It has the same name as the user for which it was created and " +"that user is the only member of the user private group." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:24 +msgid "" +"User private groups make it safe to set default permissions for a newly " +"created file or directory, allowing both the user and *the group of that " +"user* to make modifications to the file or directory." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:26 +msgid "" +"The setting which determines what permissions are applied to a newly created " +"file or directory is called a _umask_ and is configured in the `/etc/bashrc` " +"file. Traditionally on UNIX-based systems, the [command]#umask# is set to " +"[command]#022#, which allows only the user who created the file or directory " +"to make modifications. Under this scheme, all other users, *including " +"members of the creator's group*, are not allowed to make any " +"modifications. However, under the UPG scheme, this \"`group protection`\" is " +"not necessary since every user has their own private group." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:28 +msgid "A list of all groups is stored in the `/etc/group` configuration file." +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:30 +#, no-wrap +msgid "Shadow Passwords" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:33 +msgid "" +"indexterm:[passwords,shadow]indexterm:[shadow passwords,overview of] In " +"environments with multiple users, it is very important to use _shadow " +"passwords_ provided by the [package]*shadow-utils* package to enhance the " +"security of system authentication files. For this reason, the installation " +"program enables shadow passwords by default." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:35 +msgid "" +"The following is a list of the advantages shadow passwords have over the " +"traditional way of storing passwords on UNIX-based systems:" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:37 +msgid "" +"Shadow passwords improve system security by moving encrypted password hashes " +"from the world-readable `/etc/passwd` file to `/etc/shadow`, which is " +"readable only by the `root` user." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:39 +msgid "Shadow passwords store information about password aging." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:41 +msgid "" +"Shadow passwords allow the `/etc/login.defs` file to enforce security " +"policies." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:43 +msgid "" +"Most utilities provided by the [package]*shadow-utils* package work properly " +"whether or not shadow passwords are enabled. However, since password aging " +"information is stored exclusively in the `/etc/shadow` file, some utilities " +"and commands do not work without first enabling shadow passwords:" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:45 +msgid "" +"The [command]#chage# utility for setting password-aging parameters. For " +"details, see the " +"link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Security_Guide/chap-Hardening_Your_System_with_Tools_and_Services.html#sec-Password_Security++[Password " +"Security] section in the [citetitle]_Red{nbsp}Hat " +"Enterprise{nbsp}Linux{nbsp}7 Security Guide_." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:47 +msgid "The [command]#gpasswd# utility for administrating the `/etc/group` file." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:49 +msgid "" +"The [command]#usermod# command with the [option]`-e, --expiredate` or " +"[option]`-f, --inactive` option." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:51 +msgid "" +"The [command]#useradd# command with the [option]`-e, --expiredate` or " +"[option]`-f, --inactive` option." +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:53 +#, no-wrap +msgid "Managing Users in a Graphical Environment" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:56 +msgid "" +"indexterm:[users,user configuration]indexterm:[groups,group " +"configuration]indexterm:[user configuration,viewing list of " +"users]indexterm:[group configuration,viewing list of groups]indexterm:[the " +"Users settings tool,user configuration] The [application]*Users* utility " +"allows you to view, modify, add, and delete local users in the graphical " +"user interface." +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:58 +#, no-wrap +msgid "Using the Users Settings Tool" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:61 +msgid "" +"Press the kbd:[Super] key to enter the Activities Overview, type " +"[command]#Users# and then press kbd:[Enter]. The [application]*Users* " +"settings tool appears. The kbd:[Super] key appears in a variety of guises, " +"depending on the keyboard and other hardware, but often as either the " +"Windows or Command key, and typically to the left of the Spacebar." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:63 +msgid "" +"To make changes to the user accounts, first select the btn:[Unlock] button " +"and authenticate yourself as indicated by the dialog box that appears. Note " +"that unless you have superuser privileges, the application will prompt you " +"to authenticate as `root`. To add and remove users, select the btn:[+] and " +"btn:[-] button respectively. To add a user to the administrative group " +"`wheel`, change the Account Type from `Standard` to `Administrator`. To edit " +"a user's language setting, select the language and a drop-down menu appears." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:65 +#, no-wrap +msgid "The Users Settings Tool" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:67 +#, no-wrap +msgid "The Users settings tool" +msgstr "" + +#. type: Target for macro image +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:67 +#, no-wrap +msgid "managing_users.png" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:72 +msgid "" +"The commandline for call this Gui is : [user@domain ~]$ kcmshell5 " +"user_manager When a new user is created, the account is disabled until a " +"password is set. The Add User menu contains the options to set a password by " +"the administrator immediately, or to allow the user to choose a password at " +"the first login." +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:74 +#, no-wrap +msgid "Using Command Line Tools" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:77 +msgid "" +"indexterm:[users,tools for management of,useradd]indexterm:[users,tools for " +"management of,the Users setting tool]indexterm:[groups,tools for management " +"of,groupadd] Apart from the [application]*Users* settings tool described in " +"xref:basic-system-configuration/Managing_Users_and_Groups.adoc#s1-users-configui[Managing " +"Users in a Graphical Environment], which is designed for basic managing of " +"users, you can use command line tools for managing users and groups that are " +"listed in xref:Managing_Users_and_Groups.adoc#table-users-tools[Command line " +"utilities for managing users and groups]." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:79 +#, no-wrap +msgid "Command line utilities for managing users and groups" +msgstr "" + +#. type: Table +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:91 +#, no-wrap +msgid "" +"|Utilities|Description\n" +"|[command]#id#|Displays user and group IDs.\n" +"|[command]#useradd#, [command]#usermod#, [command]#userdel#|Standard " +"utilities for adding, modifying, and deleting user accounts.\n" +"|[command]#groupadd#, [command]#groupmod#, [command]#groupdel#|Standard " +"utilities for adding, modifying, and deleting groups.\n" +"|[command]#gpasswd#|Standard utility for administering the `/etc/group` " +"configuration file.\n" +"|[command]#pwck#, [command]#grpck#|Utilities that can be used for " +"verification of the password, group, and associated shadow files.\n" +"|[command]#pwconv#, [command]#pwunconv#|Utilities that can be used for the " +"conversion of passwords to shadow passwords, or back from shadow passwords " +"to standard passwords.\n" +"|[command]#grpconv#, [command]#grpunconv#|Similar to the previous, these " +"utilities can be used for conversion of shadowed information for group " +"accounts.\n" +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:94 +#, no-wrap +msgid "Adding a New User" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:97 +msgid "" +"indexterm:[useradd command,user account creation " +"using]indexterm:[adding,user]indexterm:[user configuration,command line " +"configuration,useradd] To add a new user to the system, type the following " +"at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:101 +#, no-wrap +msgid "[command]#useradd# _options_ _username_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:106 +msgid "" +"…where _options_ are command-line options as described in " +"xref:Managing_Users_and_Groups.adoc#table-useradd-options[Common useradd " +"command-line options]. indexterm:[user configuration,command line " +"configuration,passwd] By default, the [command]#useradd# command creates a " +"locked user account. To unlock the account, run the following command as " +"`root` to assign a password:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:110 +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:315 +#, no-wrap +msgid "[command]#passwd# _username_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:113 +msgid "" +"Optionally, you can set a password aging policy. See " +"xref:Managing_Users_and_Groups.adoc#s2-users-tools-password-aging[Enabling " +"Password Aging] for information on how to enable password aging." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:115 +#, no-wrap +msgid "Common useradd command-line options" +msgstr "" + +#. type: Table +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:133 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`-c`pass:attributes[{blank}] 'pass:attributes[{blank}]_comment_pass:attributes[{blank}]'|_comment_ " +"can be replaced with any string. This option is generally used to specify " +"the full name of a user.\n" +"|[option]`-d`pass:attributes[{blank}] pass:attributes[{blank}]_home_directory_|Home " +"directory to be used instead of default " +"`/home/pass:attributes[{blank}]_username_pass:attributes[{blank}]/`.\n" +"|[option]`-e`pass:attributes[{blank}] pass:attributes[{blank}]_date_|Date " +"for the account to be disabled in the format YYYY-MM-DD.\n" +"|[option]`-f`pass:attributes[{blank}] pass:attributes[{blank}]_days_|Number " +"of days after the password expires until the account is disabled. If `0` is " +"specified, the account is disabled immediately after the password " +"expires. If `-1` is specified, the account is not disabled after the " +"password expires.\n" +"|[option]`-g`pass:attributes[{blank}] pass:attributes[{blank}]_group_name_|Group " +"name or group number for the user's default (primary) group. The group must " +"exist prior to being specified here.\n" +"|[option]`-G`pass:attributes[{blank}] pass:attributes[{blank}]_group_list_|List " +"of additional (supplementary, other than default) group names or group " +"numbers, separated by commas, of which the user is a member. The groups must " +"exist prior to being specified here.\n" +"|[option]`-m`|Create the home directory if it does not exist.\n" +"|[option]`-M`|Do not create the home directory.\n" +"|[option]`-N`|Do not create a user private group for the user.\n" +"|[option]`-p`pass:attributes[{blank}] pass:attributes[{blank}]_password_|The " +"password encrypted with [command]#crypt#.\n" +"|[option]`-r`|Create a system account with a UID less than 1000 and without " +"a home directory.\n" +"|[option]`-s`|User's login shell, which defaults to [command]#/bin/bash#.\n" +"|[option]`-u`pass:attributes[{blank}] pass:attributes[{blank}]_uid_|User ID " +"for the user, which must be unique and greater than 999.\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:136 +msgid "" +"The command-line options associated with the [command]#usermod# command are " +"essentially the same. Note that if you want to add a user to another " +"supplementary group, you need to use the [option]`-a, --append` option with " +"the [option]`-G` option. Otherwise the list of supplementary groups for the " +"user will be overwritten by those specified with the [command]#usermod -G# " +"command." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:137 +#, no-wrap +msgid "Explaining the Process" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:139 +msgid "" +"The following steps illustrate what happens if the command [command]#useradd " +"juan# is issued on a system that has shadow passwords enabled:" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:141 +msgid "A new line for `juan` is created in `/etc/passwd`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:145 +#, no-wrap +msgid "juan:x:1001:1001::/home/juan:/bin/bash\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:148 +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:171 +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:211 +msgid "The line has the following characteristics:" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:150 +msgid "It begins with the user name `juan`." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:152 +msgid "" +"There is an `x` for the password field indicating that the system is using " +"shadow passwords." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:154 +msgid "" +"A UID greater than 999 is created. Under {MAJOROS}, UIDs below 1000 are " +"reserved for system use and should not be assigned to users." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:156 +msgid "" +"A GID greater than 999 is created. Under {MAJOROS}, GIDs below 1000 are " +"reserved for system use and should not be assigned to users." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:158 +msgid "" +"The optional _GECOS_ information is left blank. The GECOS field can be used " +"to provide additional information about the user, such as their full name or " +"phone number." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:160 +msgid "The home directory for `juan` is set to `/home/juan/`." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:162 +msgid "The default shell is set to [command]#/bin/bash#." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:164 +msgid "A new line for `juan` is created in `/etc/shadow`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:168 +#, no-wrap +msgid "juan:!!:14798:0:99999:7:::\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:173 +msgid "It begins with the username `juan`." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:175 +msgid "" +"Two exclamation marks (`!!`) appear in the password field of the " +"`/etc/shadow` file, which locks the account." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:176 +#, no-wrap +msgid "Note" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:181 +msgid "" +"If an encrypted password is passed using the [option]`-p` flag, it is placed " +"in the `/etc/shadow` file on the new line for the user." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:185 +msgid "The password is set to never expire." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:187 +msgid "A new line for a group named `juan` is created in `/etc/group`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:191 +#, no-wrap +msgid "juan:x:1001:\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:194 +msgid "" +"A group with the same name as a user is called a _user private group_. For " +"more information on user private groups, see " +"xref:Managing_Users_and_Groups.adoc#s2-users-groups-private-groups[User " +"Private Groups]." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:196 +msgid "The line created in `/etc/group` has the following characteristics:" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:198 +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:213 +msgid "It begins with the group name `juan`." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:200 +msgid "" +"An `x` appears in the password field indicating that the system is using " +"shadow group passwords." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:202 +msgid "" +"The GID matches the one listed for `juan`pass:attributes[{blank}]'s primary " +"group in `/etc/passwd`." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:204 +msgid "A new line for a group named `juan` is created in `/etc/gshadow`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:208 +#, no-wrap +msgid "juan:!::\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:215 +msgid "" +"An exclamation mark (`!`) appears in the password field of the " +"`/etc/gshadow` file, which locks the group." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:217 +msgid "All other fields are blank." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:219 +msgid "A directory for user `juan` is created in the `/home/` directory:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:224 +#, no-wrap +msgid "" +"~]#{nbsp}ls -ld /home/juan\n" +"drwx------. 4 juan juan 4096 Mar 3 18:23 /home/juan\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:227 +msgid "" +"This directory is owned by user `juan` and group `juan`. It has _read_, " +"_write_, and _execute_ privileges *only* for the user `juan`. All other " +"permissions are denied." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:229 +msgid "" +"The files within the `/etc/skel/` directory (which contain default user " +"settings) are copied into the new `/home/juan/` directory. The contents of " +"`/etc/skel/` may vary depending on installed applications:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:239 +#, no-wrap +msgid "" +"~]# ls -la /home/juan\n" +"total 24\n" +"drwx------. 4 juan juan 4096 Mar 3 18:23 .\n" +"drwxr-xr-x. 5 root root 4096 Mar 3 18:23 ..\n" +"-rw-r--r--. 1 juan juan 18 Jul 09 08:43 .bash_logout\n" +"-rw-r--r--. 1 juan juan 176 Jul 09 08:43 .bash_profile\n" +"-rw-r--r--. 1 juan juan 124 Jul 09 08:43 .bashrc\n" +"drwxr-xr-x. 4 juan juan 4096 Jul 09 08:43 .mozilla\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:242 +msgid "" +"At this point, a locked account called `juan` exists on the system. To " +"activate it, the administrator must next assign a password to the account " +"using the [command]#passwd# command and, optionally, set password aging " +"guidelines." +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:244 +#, no-wrap +msgid "Adding a New Group" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:247 +msgid "" +"indexterm:[group configuration,groupadd]indexterm:[adding,group] To add a " +"new group to the system, type the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:251 +#, no-wrap +msgid "groupadd pass:quotes[_options_] pass:quotes[_group_name_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:254 +msgid "" +"…where _options_ are command-line options as described in " +"xref:Managing_Users_and_Groups.adoc#table-groupadd-options[Common groupadd " +"command-line options]." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:256 +#, no-wrap +msgid "Common groupadd command-line options" +msgstr "" + +#. type: Table +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:267 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`-f`, [option]`--force`|When used with " +"[option]`-g`pass:attributes[{blank}] pass:attributes[{blank}]_gid_ and _gid_ " +"already exists, [command]#groupadd# will choose another unique _gid_ for the " +"group.\n" +"|[option]`-g`pass:attributes[{blank}] pass:attributes[{blank}]_gid_|Group ID " +"for the group, which must be unique and greater than 999.\n" +"|[option]`-K`, " +"[option]`--key`pass:attributes[{blank}] pass:attributes[{blank}]_key_pass:attributes[{blank}]=pass:attributes[{blank}]_value_|Override " +"`/etc/login.defs` defaults.\n" +"|[option]`-o`, [option]`--non-unique`|Allows creating groups with duplicate " +"GID.\n" +"|[option]`-p`, " +"[option]`--password`pass:attributes[{blank}] pass:attributes[{blank}]_password_|Use " +"this encrypted password for the new group.\n" +"|[option]`-r`|Create a system group with a GID less than 1000.\n" +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:270 +#, no-wrap +msgid "Enabling Password Aging" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:273 +msgid "" +"indexterm:[password,expire]indexterm:[password,aging]indexterm:[expiration " +"of password, forcing]indexterm:[chage command,forcing password expiration " +"with]indexterm:[user configuration,password,forcing expiration of] For " +"security reasons, it is advisable to require users to change their passwords " +"periodically. This can be done by using the [command]#chage# command." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:274 +#, no-wrap +msgid "Shadow passwords must be enabled to use chage" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:279 +msgid "" +"Shadow passwords must be enabled to use the [command]#chage# command. For " +"more information, see " +"xref:Managing_Users_and_Groups.adoc#s2-users-groups-shadow-utilities[Shadow " +"Passwords]." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:283 +msgid "" +"indexterm:[user configuration,command line configuration,chage] To configure " +"password expiration for a user from a shell prompt, run the following " +"command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:287 +#, no-wrap +msgid "[command]#chage# _options_ _username_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:290 +msgid "" +"…where _options_ are command line options as described in " +"xref:Managing_Users_and_Groups.adoc#table-chage-options[chage command line " +"options]. When the [command]#chage# command is followed directly by a " +"username (that is, when no command line options are specified), it displays " +"the specified users current password aging values and allows you to change " +"these values interactively." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:292 +#, no-wrap +msgid "chage command line options" +msgstr "" + +#. type: Table +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:304 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`-d`pass:attributes[{blank}] pass:attributes[{blank}]_days_|Specifies " +"the number of days since January 1, 1970 the password was changed.\n" +"|[option]`-E`pass:attributes[{blank}] pass:attributes[{blank}]_date_|Specifies " +"the date on which the account is locked, in the format YYYY-MM-DD. Instead " +"of the date, the number of days since January 1, 1970 can also be used.\n" +"|[option]`-I`pass:attributes[{blank}] pass:attributes[{blank}]_days_|Specifies " +"the number of inactive days after the password expiration before locking the " +"account. If the value is `0`, the account is not locked after the password " +"expires.\n" +"|[option]`-l`|Lists current account aging settings.\n" +"|[option]`-m`pass:attributes[{blank}] pass:attributes[{blank}]_days_|Specify " +"the minimum number of days after which the user must change passwords. If " +"the value is `0`, the password does not expire.\n" +"|[option]`-M`pass:attributes[{blank}] pass:attributes[{blank}]_days_|Specify " +"the maximum number of days for which the password is valid. When the number " +"of days specified by this option plus the number of days specified with the " +"[option]`-d` option is less than the current day, the user must change " +"passwords before using the account.\n" +"|[option]`-W`pass:attributes[{blank}] pass:attributes[{blank}]_days_|Specifies " +"the number of days before the password expiration date to warn the user.\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:307 +msgid "" +"You can configure a password to expire the first time a user logs in. This " +"forces users to change passwords immediately." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:309 +msgid "" +"Set up an initial password. There are two common approaches to this step: " +"you can either assign a default password, or you can use a null password." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:311 +msgid "" +"To assign a default password, type the following at a shell prompt as " +"`root`:" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:318 +msgid "To assign a null password instead, use the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:322 +#, no-wrap +msgid "[command]#passwd# [option]`-d` _username_\n" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:324 +#, no-wrap +msgid "Avoid using null passwords whenever possible" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:329 +msgid "" +"Using a null password, while convenient, is a highly insecure practice, as " +"any third party can log in first and access the system using the insecure " +"username. Always make sure that the user is ready to log in before unlocking " +"an account with a null password." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:333 +msgid "" +"Force immediate password expiration by running the following command as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:337 +#, no-wrap +msgid "[command]#chage# [option]`-d` [option]`0` _username_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:340 +msgid "" +"This command sets the value for the date the password was last changed to " +"the epoch (January 1, 1970). This value forces immediate password expiration " +"no matter what password aging policy, if any, is in place." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:342 +msgid "Upon the initial log in, the user is now prompted for a new password." +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:344 +#, no-wrap +msgid "Enabling Automatic Logouts" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:347 +msgid "" +"Especially when the user is logged in as `root`, an unattended login session " +"may pose a significant security risk. To reduce this risk, you can configure " +"the system to automatically log out idle users after a fixed period of time:" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:349 +msgid "" +"Make sure the [package]*screen* package is installed. You can do so by " +"running the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:353 +#, no-wrap +msgid "[command]#dnf# [option]`install` [option]`screen`\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:356 +msgid "" +"For more information on how to install packages in {MAJOROS}, refer to " +"xref:package-management/DNF.adoc#sec-Installing[Installing Packages]." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:358 +msgid "" +"As `root`, add the following line at the beginning of the `/etc/profile` " +"file to make sure the processing of this file cannot be interrupted:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:362 +#, no-wrap +msgid "trap \"\" 1 2 3 15\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:365 +msgid "" +"Add the following lines at the end of the `/etc/profile` file to start a " +"[command]#screen# session each time a user logs in to a virtual console or " +"remotely:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:375 +#, no-wrap +msgid "" +"SCREENEXEC=\"screen\"\n" +"if [ -w $(tty) ]; then\n" +" trap \"exec $SCREENEXEC\" 1 2 3 15\n" +" echo -n 'Starting session in 10 seconds'\n" +" sleep 10\n" +" exec $SCREENEXEC\n" +"fi\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:378 +msgid "" +"Note that each time a new session starts, a message will be displayed and " +"the user will have to wait ten seconds. To adjust the time to wait before " +"starting a session, change the value after the [command]#sleep# command." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:380 +msgid "" +"Add the following lines to the `/etc/screenrc` configuration file to close " +"the [command]#screen# session after a given period of inactivity:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:385 +#, no-wrap +msgid "" +"idle 120 quit\n" +"autodetach off\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:388 +msgid "" +"This will set the time limit to 120 seconds. To adjust this limit, change " +"the value after the [option]`idle` directive." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:390 +msgid "" +"Alternatively, you can configure the system to only lock the session by " +"using the following lines instead:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:395 +#, no-wrap +msgid "" +"idle 120 lockscreen\n" +"autodetach off\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:398 +msgid "This way, a password will be required to unlock the session." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:400 +msgid "The changes take effect the next time a user logs in to the system." +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:402 +#, no-wrap +msgid "Creating Group Directories" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:405 +msgid "" +"indexterm:[groups,shared directories]indexterm:[user private groups,and " +"shared directories] System administrators usually like to create a group for " +"each major project and assign people to the group when they need to access " +"that project's files. With this traditional scheme, file management is " +"difficult; when someone creates a file, it is associated with the primary " +"group to which they belong. When a single person works on multiple projects, " +"it becomes difficult to associate the right files with the right " +"group. However, with the UPG scheme, groups are automatically assigned to " +"files created within a directory with the _setgid_ bit set. The setgid bit " +"makes managing group projects that share a common directory very simple " +"because any files a user creates within the directory are owned by the group " +"that owns the directory." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:407 +msgid "" +"For example, a group of people need to work on files in the " +"`/opt/myproject/` directory. Some people are trusted to modify the contents " +"of this directory, but not everyone." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:409 +msgid "" +"As `root`, create the `/opt/myproject/` directory by typing the following at " +"a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:413 +#, no-wrap +msgid "[command]#mkdir /opt/myproject#\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:416 +msgid "Add the `myproject` group to the system:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:420 +#, no-wrap +msgid "[command]#groupadd myproject#\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:423 +msgid "" +"Associate the contents of the `/opt/myproject/` directory with the " +"`myproject` group:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:427 +#, no-wrap +msgid "[command]#chown root:myproject /opt/myproject#\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:430 +msgid "" +"Allow users in the group to create files within the directory and set the " +"setgid bit:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:434 +#, no-wrap +msgid "[command]#chmod 2775 /opt/myproject#\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:437 +msgid "" +"At this point, all members of the `myproject` group can create and edit " +"files in the `/opt/myproject/` directory without the administrator having to " +"change file permissions every time users write new files. To verify that the " +"permissions have been set correctly, run the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:442 +#, no-wrap +msgid "" +"~]#{nbsp}ls -ld /opt/myproject\n" +"drwxrwsr-x. 3 root myproject 4096 Mar 3 18:31 /opt/myproject\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:446 +msgid "Add users to the `myproject` group:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:450 +#, no-wrap +msgid "[command]#usermod -aG myproject _username_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:453 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:456 +msgid "" +"indexterm:[groups,additional resources]indexterm:[users,additional " +"resources] For more information on how to manage users and groups on Fedora, " +"see the resources listed below." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:457 +#, no-wrap +msgid "" +"Installed Documentationindexterm:[groups,additional resources,installed " +"documentation]indexterm:[users,additional resources,installed documentation]" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:459 +msgid "" +"For information about various utilities for managing users and groups, see " +"the following manual pages:" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:461 +msgid "" +"`useradd`(8) — The manual page for the [command]#useradd# command documents " +"how to use it to create new users." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:463 +msgid "" +"`userdel`(8) — The manual page for the [command]#userdel# command documents " +"how to use it to delete users." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:465 +msgid "" +"`usermod`(8) — The manual page for the [command]#usermod# command documents " +"how to use it to modify users." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:467 +msgid "" +"`groupadd`(8) — The manual page for the [command]#groupadd# command " +"documents how to use it to create new groups." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:469 +msgid "" +"`groupdel`(8) — The manual page for the [command]#groupdel# command " +"documents how to use it to delete groups." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:471 +msgid "" +"`groupmod`(8) — The manual page for the [command]#groupmod# command " +"documents how to use it to modify group membership." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:473 +msgid "" +"`gpasswd`(1) — The manual page for the [command]#gpasswd# command documents " +"how to manage the `/etc/group` file." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:475 +msgid "" +"`grpck`(8) — The manual page for the [command]#grpck# command documents how " +"to use it to verify the integrity of the `/etc/group` file." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:477 +msgid "" +"`pwck`(8) — The manual page for the [command]#pwck# command documents how to " +"use it to verify the integrity of the `/etc/passwd` and `/etc/shadow` files." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:479 +msgid "" +"`pwconv`(8) — The manual page for the [command]#pwconv#, " +"[command]#pwunconv#, [command]#grpconv#, and [command]#grpunconv# commands " +"documents how to convert shadowed information for passwords and groups." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:481 +msgid "" +"`id`(1) — The manual page for the [command]#id# command documents how to " +"display user and group IDs." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:483 +msgid "For information about related configuration files, see:" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:485 +msgid "" +"`group`(5) — The manual page for the `/etc/group` file documents how to use " +"this file to define system groups." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:487 +msgid "" +"`passwd`(5) — The manual page for the `/etc/passwd` file documents how to " +"use this file to define user information." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:488 +msgid "" +"`shadow`(5) — The manual page for the `/etc/shadow` file documents how to " +"use this file to set passwords and account expiration information for the " +"system." +msgstr "" diff --git a/po/fr/rawhide/pages/basic-system-configuration/Opening_GUI_Applications.po b/po/fr/rawhide/pages/basic-system-configuration/Opening_GUI_Applications.po new file mode 100644 index 00000000000..04634bf80f4 --- /dev/null +++ b/po/fr/rawhide/pages/basic-system-configuration/Opening_GUI_Applications.po @@ -0,0 +1,568 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:5 +#, no-wrap +msgid "Opening Graphical Applications" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:8 +msgid "" +"Fedora provides graphical applications in addition to command line utilities " +"for configuring many features. This chapter describes methods for opening " +"`Graphical User Interface`, or _GUI_, applications in various environments." +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:10 +#, no-wrap +msgid "Opening graphical applications from the command line" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:13 +msgid "" +"Graphical applications can be launched from a terminal window or console " +"session by simply typing the name of the application." +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:18 +#, no-wrap +msgid "[fedorauser@localhost]$ [command]#firefox#\n" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:20 +#, no-wrap +msgid "File names vs Application names" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:25 +msgid "" +"Programs are opened from the command line using the name of the executable " +"file provided in the program's package. An entry in the desktop menu will " +"often be named differently from the file it executes. For example, the GNOME " +"disk management utility appears in the menu as [application]*Disks*, and the " +"file it executes is `/usr/bin/gnome-disks`." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:29 +msgid "" +"When a program is executed on the command line, the terminal is occupied " +"until the program completes. When a graphical application is executed from " +"the command line, the program's error output, or `STDERR`, is sent to the " +"terminal window. This can be especially useful when troubleshooting." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:30 +#, no-wrap +msgid "Viewing errors by launching graphical applications from the command line" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:37 +#, no-wrap +msgid "" +"[fedorauser@localhost]$ astromenace-wrapper\n" +"\tAstroMenace 1.3.1 121212\n" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:40 +#, no-wrap +msgid "" +"\tOpen XML file: /home/fedorauser/.config/astromenace/amconfig.xml\n" +"\tVFS file was opened /usr/share/astromenace/gamedata.vfs\n" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:45 +#, no-wrap +msgid "" +"\tVendor : OpenAL Community\n" +"\tRenderer : OpenAL Soft\n" +"\tVersion : 1.1 ALSOFT 1.15.1\n" +"\tALut ver : 1.1\n" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:47 +#, no-wrap +msgid "\tFont initialized: DATA/FONT/LiberationMono-Bold.ttf\n" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:49 +#, no-wrap +msgid "\tCurrent Video Mode: 3200x1080 32bit\n" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:54 +#, no-wrap +msgid "" +"\tXinerama/TwinView detected.\n" +"\tScreen count: 2\n" +"\tScreen #0: (0, 0) x (1920, 1080)\n" +"\tScreen #1: (1920, 0) x (1280, 1024)\n" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:61 +#, no-wrap +msgid "" +"\tSupported resolutions list:\n" +"\t640x480 16bit\n" +"\t640x480 32bit\n" +"\t640x480 0bit\n" +"\t768x480 16bit\n" +"\t\n" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:66 +msgid "" +"To launch a graphical application, but fork the additional output into the " +"background and return the terminal for immediate use, use the shell's `job " +"control` feature." +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:71 +#, no-wrap +msgid "[fedorauser@localhost]$ [command]#emacs foo.txt &#\n" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:73 +#, no-wrap +msgid "Ending a session" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:78 +msgid "" +"Applications that hold the command line prompt until they complete will " +"close when the terminal session ends, even if they are forked into the " +"background." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:82 +msgid "" +"GUI programs can also be launched on one `TTY` and displayed on another by " +"specifying the `DISPLAY` variable. This can be useful when running multiple " +"graphical sessions, or for troubleshooting problems with a desktop session." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:84 +msgid "" +"Switch to another TTY using the key combination kbd:[Ctrl + Alt + F2] and " +"log in. Note that consoles are available by default with kbd:[F2] through " +"kbd:[F6]." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:86 +msgid "" +"Identify the X session you want to target. The `DISPLAY` variable is always " +"an integer preceded by a colon, and will be *:0* in most cases. Check the " +"arguments of the currently running [application]*X* process to verify the " +"value. The command below shows both the `DISPLAY` variable as well as the " +"TTY that [application]*X* is running on, `tty1`." +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:92 +#, no-wrap +msgid "" +"[fedorauser@localhost]$ ps aux|grep /usr/bin/X\n" +"root 1498 7.1 1.0 521396 353984 pass:quotes[`tty1`] Ss+ 00:04 " +"66:34 /usr/bin/X pass:quotes[`:0`] vt1 -background none -nolisten tcp -auth " +"/var/run/kdm/A:0-22Degc\n" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:94 +#, no-wrap +msgid "" +"root 23874 0.0 0.0 109184 900 pts/21 S+ 15:35 0:00 grep " +"--color=auto /usr/bin/X\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:97 +msgid "Specify the `DISPLAY` variable when executing the program." +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:102 +#, no-wrap +msgid "[fedorauser@localhost]$ [command]#DISPLAY=:0 gnome-shell --replace &#\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:105 +msgid "" +"Switch back to the TTY the graphical session is running on. Since the " +"example above shows [application]*X* running on `vt1`, pressing kbd:[Ctrl + " +"Alt + F1] will return to the desktop environment." +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:107 +#, no-wrap +msgid "Launching Applications with kbd:[Alt + F2]" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:110 +msgid "" +"Most desktop environments follow the convention of using the key combination " +"kbd:[Alt + F2] for opening new applications. Pressing kbd:[Alt + F2] brings " +"up a prompt for a command to be entered into." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:112 +msgid "" +"Commands entered into this dialog box function much as they would if entered " +"in a terminal. Applications are known by their file name, and can accept " +"arguments." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:114 +#, no-wrap +msgid "Using kbd:[Alt + F2] with [application]*GNOME*" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:116 +#, no-wrap +msgid "GNOME command entry dialog box" +msgstr "" + +#. type: Target for macro image +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:116 +#, no-wrap +msgid "alt-f2_GNOME.png" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:119 +#, no-wrap +msgid "Using kbd:[Alt + F2] with [application]*KDE*" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:121 +#, no-wrap +msgid "KDE command entry dialog box" +msgstr "" + +#. type: Target for macro image +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:121 +#, no-wrap +msgid "alt-f2_KDE.png" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:124 +#, no-wrap +msgid "Using kbd:[Alt + F2] with [application]*LXDE*" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:126 +#, no-wrap +msgid "LXDE command entry dialog box." +msgstr "" + +#. type: Target for macro image +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:126 +#, no-wrap +msgid "alt-f2_LXDE.png" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:129 +#, no-wrap +msgid "Using kbd:[Alt + F2] with [application]*MATE*" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:131 +#, no-wrap +msgid "MATE command entry dialog box." +msgstr "" + +#. type: Target for macro image +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:131 +#, no-wrap +msgid "alt-f2_MATE.png" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:134 +#, no-wrap +msgid "Using kbd:[Alt + F2] with [application]*XFCE*" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:136 +#, no-wrap +msgid "XFCE command entry dialog box." +msgstr "" + +#. type: Target for macro image +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:136 +#, no-wrap +msgid "alt-f2_XFCE.png" +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:139 +#, no-wrap +msgid "Launching applications from the Desktop Menu" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:142 +msgid "" +"Applications can also be opened from the menu system provided by the desktop " +"environment in use. While the presentation may vary between desktop " +"environments, the menu entries and their categories are provided by the " +"individual application and standardized by the " +"link:++https://standards.freedesktop.org/menu-spec/menu-spec-latest.html++[freedesktop.org " +"Desktop Menu Specification]. Some desktop environments also provide search " +"functionality in their menu system to allow quick and easy access to " +"applications." +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:144 +#, no-wrap +msgid "Using GNOME menus" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:147 +msgid "" +"The GNOME menu, called the `overview`, can be accessed by either clicking " +"the `Activities` button in the top left of the primary display, by moving " +"the mouse past the top left `hot corner`, or by pressing the kbd:[Super] ( " +"kbd:[Windows] ) key. The `overview` presents documents in addition to " +"applications." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:149 +msgid "" +"Selecting an item from the menu is best accomplished using the `search " +"box`. Simply bring up the `overview`, and begin typing the name of the " +"application you want to launch. Pressing enter will launch the highlighted " +"application, or you can use the arrow keys or mouse to choose an " +"alternative." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:151 +#, no-wrap +msgid "Using the GNOME search box" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:153 +#, no-wrap +msgid "" +"Typing the name of an application into the overview search box will display " +"matching menu entries. The search also matches descriptions" +msgstr "" + +#. type: Target for macro image +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:153 +#, no-wrap +msgid "searchmenu_GNOME.png" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:156 +msgid "" +"The `overview` can also be browsed. The bar on the left, called the `dash`, " +"shows frequently used applications and a grid icon. Clicking on the grid " +"icon brings up a grid in the center of the window that displays frequently " +"used applications. The grid will display all available applications if " +"selected using the `All` button at the bottom of the screen." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:158 +#, no-wrap +msgid "Browsing GNOME menu entries" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:160 +#, no-wrap +msgid "The GNOME menu has a bar on the left for frequently used applications" +msgstr "" + +#. type: Target for macro image +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:160 +#, no-wrap +msgid "menu_GNOME.png" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:163 +msgid "" +"To learn more about using [application]*GNOME shell*, visit " +"link:++https://wiki.gnome.org/GnomeShell/CheatSheet++[]" +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:165 +#, no-wrap +msgid "Using KDE menus" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:168 +msgid "" +"The KDE menu is opened by clicking the {MAJOROS} button at the bottom left " +"corner of the screen. The menu initially displays favorite applications, " +"which can be added to by right clicking any menu entry. Hovering over the " +"icons in the lower portion of the menu will display applications, file " +"systems, recently used applications, or options for logging out of the " +"system." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:170 +#, no-wrap +msgid "The KDE desktop menu." +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:172 +#, no-wrap +msgid "" +"The KDE menu displays applications in categories. The contents of the " +"categories are displayed when clicked." +msgstr "" + +#. type: Target for macro image +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:172 +#, no-wrap +msgid "menu_KDE.png" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:175 +msgid "" +"Search functionality is also available in the KDE menu system. To search for " +"applications, open the menu and begin typing. The menu will display matching " +"entries." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:177 +#, no-wrap +msgid "Searching with the KDE menu." +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:179 +#, no-wrap +msgid "" +"The KDE menu will search for matching applications if you type into the " +"search box. For example" +msgstr "" + +#. type: Target for macro image +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:179 +#, no-wrap +msgid "searchmenu_KDE.png" +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:181 +#, no-wrap +msgid "Using menus in LXDE, MATE, and XFCE" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:184 +msgid "" +"Menus in LXDE, MATE, and XFCE have a varied appearance but a very similar " +"structure. They categorize applications, and the contents of a category are " +"displayed by hovering the cursor over the entry. Applications are launched " +"by clicking on an entry." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:186 +#, no-wrap +msgid "The LXDE menu" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:188 +#, no-wrap +msgid "LXDE Menu" +msgstr "" + +#. type: Target for macro image +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:188 +#, no-wrap +msgid "menu_LXDE.png" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:191 +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:193 +#, no-wrap +msgid "MATE menu" +msgstr "" + +#. type: Target for macro image +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:193 +#, no-wrap +msgid "menu_MATE.png" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:196 +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:198 +#, no-wrap +msgid "XFCE Menu" +msgstr "" + +#. type: Target for macro image +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:198 +#, no-wrap +msgid "menu_XFCE.png" +msgstr "" diff --git a/po/fr/rawhide/pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.po b/po/fr/rawhide/pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.po new file mode 100644 index 00000000000..a1eeab7ee81 --- /dev/null +++ b/po/fr/rawhide/pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.po @@ -0,0 +1,548 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:5 +#, no-wrap +msgid "System Locale and Keyboard Configuration" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:8 +msgid "" +"The *system locale* specifies the language settings of system services and " +"user interfaces. The *keyboard layout* settings control the layout used on " +"the text console and graphical user interfaces." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:10 +msgid "" +"These settings can be made by modifying the `/etc/locale.conf` configuration " +"file or by using the [application]*localectl* utility. You can also set " +"these settings during system installation using the installer graphical " +"interface, text mode interface, or the [command]*keyboard* and " +"[command]*lang* Kickstart commands. See the " +"link:https://docs.fedoraproject.org/en-US/fedora/f{MAJOROSVER}/install-guide[{MAJOROS} " +"Installation Guide] for information about these options." +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:12 +#, no-wrap +msgid "Setting the System Locale" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:15 +msgid "" +"System-wide locale settings are stored in the `/etc/locale.conf` file, which " +"is read at early boot by the `systemd` daemon. The locale settings " +"configured in `/etc/locale.conf` are inherited by every service or user, " +"unless individual programs or individual users override them." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:17 +msgid "" +"The basic file format of `/etc/locale.conf` is a newline-separated list of " +"variable assignments. For example, German locale with English messages in " +"`/etc/locale.conf` looks as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:22 +#, no-wrap +msgid "" +"LANG=de_DE.UTF-8\n" +"LC_MESSAGES=C\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:26 +msgid "" +"Here, the LC_MESSAGES option determines the locale used for diagnostic " +"messages written to the standard error output. To further specify locale " +"settings in `/etc/locale.conf`, you can use several other options, the most " +"relevant are summarized in " +"xref:System_Locale_and_Keyboard_Configuration.adoc#tab-locale_options[Options " +"configurable in /etc/locale.conf]. See the `locale(7)` manual page for " +"detailed information on these options. Note that the LC_ALL option, which " +"represents all possible options, should not be configured in " +"`/etc/locale.conf`." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:28 +#, no-wrap +msgid "Options configurable in /etc/locale.conf" +msgstr "" + +#. type: Table +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:39 +#, no-wrap +msgid "" +"|Option|Description\n" +"|LANG|Provides a default value for the system locale.\n" +"|LC_COLLATE|Changes the behavior of functions which compare strings in the " +"local alphabet.\n" +"|LC_CTYPE|Changes the behavior of the character handling and classification " +"functions and the multibyte character functions.\n" +"|LC_NUMERIC|Describes the way numbers are usually printed, with details such " +"as decimal point versus decimal comma.\n" +"|LC_TIME|Changes the display of the current time, 24-hour versus 12-hour " +"clock.\n" +"|LC_MESSAGES|Determines the locale used for diagnostic messages written to " +"the standard error output.\n" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:42 +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:51 +#, no-wrap +msgid "Displaying the Current Status" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:45 +msgid "" +"The [command]#localectl# command can be used to query and change the system " +"locale and keyboard layout settings. To show the current settings, use the " +"[option]`status` option:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:49 +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:139 +#, no-wrap +msgid "[command]#localectl# [option]`status`\n" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:55 +msgid "" +"The output of the previous command lists the currently set locale, keyboard " +"layout configured for the console and for the X11 window system." +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:63 +#, no-wrap +msgid "" +"~]${nbsp}localectl status\n" +" System Locale: LANG=en_US.UTF-8\n" +" VC Keymap: us\n" +" X11 Layout: n/a\n" +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:69 +#, no-wrap +msgid "Listing Available Locales" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:72 +msgid "To list all locales available for your system, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:76 +#, no-wrap +msgid "[command]#localectl# [option]`list-locales`\n" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:78 +#, no-wrap +msgid "Listing Locales" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:82 +msgid "" +"Imagine you want to select a specific English locale, but you are not sure " +"if it is available on the system. You can check that by listing all English " +"locales with the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:95 +#, no-wrap +msgid "" +"~]${nbsp}localectl list-locales | grep pass:quotes[`en_`]\n" +"en_AG\n" +"en_AG.utf8\n" +"en_AU\n" +"en_AU.iso88591\n" +"en_AU.utf8\n" +"en_BW\n" +"en_BW.iso88591\n" +"en_BW.utf8\n" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:97 +#, no-wrap +msgid "pass:quotes[*output truncated*]\n" +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:103 +#, no-wrap +msgid "Setting the Locale" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:106 +msgid "To set the default system locale, use the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:110 +#, no-wrap +msgid "" +"[command]#localectl# [option]`set-locale` " +"[option]`LANG`pass:attributes[{blank}]=pass:attributes[{blank}]_locale_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:113 +msgid "" +"Replace _locale_ with the locale name, found with the [command]#localectl# " +"[option]`list-locales` command. The above syntax can also be used to " +"configure parameters from " +"xref:System_Locale_and_Keyboard_Configuration.adoc#tab-locale_options[Options " +"configurable in /etc/locale.conf]." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:114 +#, no-wrap +msgid "Changing the Default Locale" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:118 +msgid "" +"For example, if you want to set British English as your default locale, " +"first find the name of this locale by using [option]`list-locales`. Then, as " +"`root`, type the command in the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:122 +#, no-wrap +msgid "~]#{nbsp}localectl set-locale LANG=pass:quotes[`en_GB.utf8`]\n" +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:127 +#, no-wrap +msgid "Changing the Keyboard Layout" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:130 +msgid "" +"indexterm:[localectl,keyboard configuration]indexterm:[keyboard " +"configuration,layout] The keyboard layout settings enable the user to " +"control the layout used on the text console and graphical user interfaces." +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:132 +#, no-wrap +msgid "Displaying the Current Settings" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:135 +msgid "" +"As mentioned before, you can check your current keyboard layout " +"configuration with the following command:" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:141 +#, no-wrap +msgid "Displaying the Keyboard Settings" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:145 +msgid "" +"In the following output, you can see the keyboard layout configured for the " +"virtual console and for the X11 window system." +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:153 +#, no-wrap +msgid "" +"~]${nbsp}localectl status\n" +" System Locale: LANG=en_US.utf8\n" +" VC Keymap: us\n" +" X11 Layout: us\n" +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:159 +#, no-wrap +msgid "Listing Available Keymaps" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:162 +msgid "" +"To list all available keyboard layouts that can be configured on your " +"system, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:166 +#, no-wrap +msgid "[command]#localectl# [option]`list-keymaps`\n" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:168 +#, no-wrap +msgid "Searching for a Particular Keymap" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:172 +msgid "" +"You can use [command]#grep# to search the output of the previous command for " +"a specific keymap name. There are often multiple keymaps compatible with " +"your currently set locale. For example, to find available Czech keyboard " +"layouts, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:185 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#localectl# [option]`list-keymaps` " +"| [command]#grep# `cz`\n" +"cz\n" +"cz-cp1250\n" +"cz-lat2\n" +"cz-lat2-prog\n" +"cz-qwerty\n" +"cz-us-qwertz\n" +"sunt5-cz-us\n" +"sunt5-us-cz\n" +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:192 +#, no-wrap +msgid "Setting the Keymap" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:195 +msgid "" +"To set the default keyboard layout for your system, use the following " +"command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:199 +#, no-wrap +msgid "[command]#localectl# [option]`set-keymap` _map_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:202 +msgid "" +"Replace _map_ with the name of the keymap taken from the output of the " +"[command]#localectl# [option]`list-keymaps` command. Unless the " +"[option]`--no-convert` option is passed, the selected setting is also " +"applied to the default keyboard mapping of the X11 window system, after " +"converting it to the closest matching X11 keyboard mapping. This also " +"applies in reverse, you can specify both keymaps with the following command " +"as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:206 +#, no-wrap +msgid "[command]#localectl# [option]`set-x11-keymap` _map_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:209 +msgid "" +"If you want your X11 layout to differ from the console layout, use the " +"[option]`--no-convert` option." +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:213 +#, no-wrap +msgid "[command]#localectl# [option]`--no-convert` [option]`set-x11-keymap` _map_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:216 +msgid "" +"With this option, the X11 keymap is specified without changing the previous " +"console layout setting." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:217 +#, no-wrap +msgid "Setting the X11 Keymap Separately" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:221 +msgid "" +"Imagine you want to use German keyboard layout in the graphical interface, " +"but for console operations you want to retain the US keymap. To do so, type " +"as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:225 +#, no-wrap +msgid "~]#{nbsp}localectl --no-convert set-x11-keymap pass:quotes[_de_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:228 +msgid "" +"Then you can verify if your setting was successful by checking the current " +"status:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:236 +#, no-wrap +msgid "" +"~]${nbsp}localectl status\n" +" System Locale: LANG=de_DE.UTF-8\n" +" VC Keymap: us\n" +" X11 Layout: de\n" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:242 +msgid "Apart from keyboard layout (_map_), three other options can be specified:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:246 +#, no-wrap +msgid "" +"[command]#localectl# [option]`set-x11-keymap` _map_ _model_ _variant_ " +"_options_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:250 +msgid "" +"Replace _model_ with the keyboard model name, _variant_ and _options_ with " +"keyboard variant and option components, which can be used to enhance the " +"keyboard behavior. These options are not set by default. For more " +"information on X11 Model, X11 Variant, and X11 Options see the `kbd(4)` man " +"page." +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:252 +#, no-wrap +msgid "Consider this option if using gnome" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:255 +msgid "This should work if the following conditions apply:" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:257 +msgid "Using gnome as the desktop environment" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:259 +msgid "Your layout is not listed under Settings -> Keyboard -> Input Sources" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:261 +msgid "In your terminal type in:" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:263 +msgid "`gsettings set org.gnome.desktop.input-sources show-all-sources true`" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:266 +msgid "" +"after pressing return, try looking under your keyboard settings again as " +"there should be a lot more options available. As the proper source for help " +"is gnome in this case, here is more information from gnome:" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:268 +msgid "https://help.gnome.org/users/gnome-help/stable/keyboard-layouts.html.en" +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:270 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:273 +msgid "" +"For more information on how to configure the keyboard layout on Fedora, see " +"the resources listed below:" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:274 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:277 +msgid "" +"`localectl`(1) — The manual page for the [command]#localectl# command line " +"utility documents how to use this tool to configure the system locale and " +"keyboard layout." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:278 +msgid "" +"`loadkeys`(1) — The manual page for the [command]#loadkeys# command provides " +"more information on how to use this tool to change the keyboard layout in a " +"virtual console." +msgstr "" diff --git a/po/fr/rawhide/pages/basic-system-configuration/intro-basic-system-configuration.po b/po/fr/rawhide/pages/basic-system-configuration/intro-basic-system-configuration.po new file mode 100644 index 00000000000..c3b03a265d3 --- /dev/null +++ b/po/fr/rawhide/pages/basic-system-configuration/intro-basic-system-configuration.po @@ -0,0 +1,31 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/basic-system-configuration/intro-basic-system-configuration.adoc:1 +#, no-wrap +msgid "Basic System Configuration" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/intro-basic-system-configuration.adoc:3 +msgid "" +"This part covers basic system administration tasks such as keyboard " +"configuration, date and time configuration, managing users and groups, and " +"gaining privileges." +msgstr "" diff --git a/po/fr/rawhide/pages/index.po b/po/fr/rawhide/pages/index.po new file mode 100644 index 00000000000..94beb736f3f --- /dev/null +++ b/po/fr/rawhide/pages/index.po @@ -0,0 +1,56 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/index.adoc:4 +#, no-wrap +msgid "System Administrator's Guide" +msgstr "" + +#. type: Plain text +#: ./pages/index.adoc:7 +msgid "Deployment, Configuration, and Administration of {MAJOROSVER}" +msgstr "" + +#. type: delimited block = +#: ./pages/index.adoc:11 +#, no-wrap +msgid "**Editor's Note** \n" +msgstr "" + +#. type: delimited block = +#: ./pages/index.adoc:13 +msgid "" +"_This guide is deprecated!_ Large parts of it are no longer current and it " +"will not receive any updates. A series of shorter, topic-specific " +"documentation will gradually replace it." +msgstr "" + +#. type: Plain text +#: ./pages/index.adoc:19 +msgid "" +"The [citetitle]_System Administrator's Guide_ documents relevant information " +"regarding the deployment, configuration, and administration of " +"{MAJOROSVER}. It is oriented towards system administrators with a basic " +"understanding of the system." +msgstr "" + +#. type: Plain text +#: ./pages/index.adoc:23 +msgid "image:title_logo.svg[Fedora Documentation Team]" +msgstr "" diff --git a/po/fr/rawhide/pages/infrastructure-services/OpenSSH.po b/po/fr/rawhide/pages/infrastructure-services/OpenSSH.po new file mode 100644 index 00000000000..2d661f7934f --- /dev/null +++ b/po/fr/rawhide/pages/infrastructure-services/OpenSSH.po @@ -0,0 +1,3078 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/infrastructure-services/OpenSSH.adoc:6 +#, no-wrap +msgid "OpenSSH" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:11 +msgid "" +"indexterm:[OpenSSH] `SSH` (Secure Shell) is a protocol which facilitates " +"secure communications between two systems using a client-server architecture " +"and allows users to log into server host systems remotely. Unlike other " +"remote communication protocols, such as `FTP`, `Telnet`, or " +"[command]#rlogin#, SSH encrypts the login session, rendering the connection " +"difficult for intruders to collect unencrypted passwords." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:13 +msgid "" +"The [application]*ssh* program is designed to replace older, less secure " +"terminal applications used to log into remote hosts, such as " +"[command]#telnet# or [command]#rsh#. A related program called [command]#scp# " +"replaces older programs designed to copy files between hosts, such as " +"[command]#rcp#. Because these older applications do not encrypt passwords " +"transmitted between the client and the server, avoid them whenever " +"possible. Using secure methods to log into remote systems decreases the " +"risks for both the client system and the remote host." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:15 +msgid "" +"{MAJOROS} includes the general OpenSSH package, [package]*openssh*, as well " +"as the OpenSSH server, [package]*openssh-server*, and client, " +"[package]*openssh-clients*, packages. Note, the OpenSSH packages require the " +"OpenSSL package [package]*openssl-libs*, which installs several important " +"cryptographic libraries, enabling OpenSSH to provide encrypted " +"communications." +msgstr "" + +#. type: Title == +#: ./pages/infrastructure-services/OpenSSH.adoc:17 +#, no-wrap +msgid "The SSH Protocol" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:20 +#, no-wrap +msgid "Why Use SSH?" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:23 +msgid "" +"indexterm:[SSH protocol,security risks] Potential intruders have a variety " +"of tools at their disposal enabling them to disrupt, intercept, and re-route " +"network traffic in an effort to gain access to a system. In general terms, " +"these threats can be categorized as follows:" +msgstr "" + +#. type: Labeled list +#: ./pages/infrastructure-services/OpenSSH.adoc:24 +#, no-wrap +msgid "Interception of communication between two systems" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:25 +msgid "" +"The attacker can be somewhere on the network between the communicating " +"parties, copying any information passed between them. He may intercept and " +"keep the information, or alter the information and send it on to the " +"intended recipient." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:27 +msgid "" +"This attack is usually performed using a _packet sniffer_, a rather common " +"network utility that captures each packet flowing through the network, and " +"analyzes its content." +msgstr "" + +#. type: Labeled list +#: ./pages/infrastructure-services/OpenSSH.adoc:28 +#, no-wrap +msgid "Impersonation of a particular host" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:29 +msgid "" +"Attacker's system is configured to pose as the intended recipient of a " +"transmission. If this strategy works, the user's system remains unaware that " +"it is communicating with the wrong host." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:31 +msgid "" +"This attack can be performed using a technique known as _DNS poisoning_, or " +"via so-called _IP spoofing_. In the first case, the intruder uses a cracked " +"DNS server to point client systems to a maliciously duplicated host. In the " +"second case, the intruder sends falsified network packets that appear to be " +"from a trusted host." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:33 +msgid "" +"Both techniques intercept potentially sensitive information and, if the " +"interception is made for hostile reasons, the results can be disastrous. If " +"SSH is used for remote shell login and file copying, these security threats " +"can be greatly diminished. This is because the SSH client and server use " +"digital signatures to verify their identity. Additionally, all communication " +"between the client and server systems is encrypted. Attempts to spoof the " +"identity of either side of a communication does not work, since each packet " +"is encrypted using a key known only by the local and remote systems." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:35 +#, no-wrap +msgid "Main Features" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:38 +msgid "" +"indexterm:[SSH protocol,features]indexterm:[OpenSSH,SSH] The SSH protocol " +"provides the following safeguards:" +msgstr "" + +#. type: Labeled list +#: ./pages/infrastructure-services/OpenSSH.adoc:39 +#, no-wrap +msgid "No one can pose as the intended server" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:40 +msgid "" +"After an initial connection, the client can verify that it is connecting to " +"the same server it had connected to previously." +msgstr "" + +#. type: Labeled list +#: ./pages/infrastructure-services/OpenSSH.adoc:41 +#, no-wrap +msgid "No one can capture the authentication information" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:42 +msgid "" +"The client transmits its authentication information to the server using " +"strong encryption." +msgstr "" + +#. type: Labeled list +#: ./pages/infrastructure-services/OpenSSH.adoc:43 +#, no-wrap +msgid "No one can intercept the communication" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:44 +msgid "" +"All data sent and received during a session is transferred using strong " +"encryption, making intercepted transmissions extremely difficult to decrypt " +"and read." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:46 +msgid "Additionally, it also offers the following options:" +msgstr "" + +#. type: Labeled list +#: ./pages/infrastructure-services/OpenSSH.adoc:47 +#, no-wrap +msgid "It provides secure means to use graphical applications over a network" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:48 +msgid "" +"Using a technique called _X11 forwarding_, the client can forward _X11_ (_X " +"Window System_) applications from the server. Note that if you set the " +"[option]`ForwardX11Trusted` option to `yes` or you use SSH with the " +"[option]`-Y` option, you bypass the X11 SECURITY extension controls, which " +"can result in a security threat." +msgstr "" + +#. type: Labeled list +#: ./pages/infrastructure-services/OpenSSH.adoc:49 +#, no-wrap +msgid "It provides a way to secure otherwise insecure protocols" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:50 +msgid "" +"The SSH protocol encrypts everything it sends and receives. Using a " +"technique called _port forwarding_, an SSH server can become a conduit to " +"securing otherwise insecure protocols, like *POP*, and increasing overall " +"system and data security." +msgstr "" + +#. type: Labeled list +#: ./pages/infrastructure-services/OpenSSH.adoc:51 +#, no-wrap +msgid "It can be used to create a secure channel" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:52 +msgid "" +"The OpenSSH server and client can be configured to create a tunnel similar " +"to a virtual private network for traffic between server and client machines." +msgstr "" + +#. type: Labeled list +#: ./pages/infrastructure-services/OpenSSH.adoc:53 +#, no-wrap +msgid "It supports Kerberos authentication" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:54 +msgid "" +"OpenSSH servers and clients can be configured to authenticate using the " +"*GSSAPI* (Generic Security Services Application Program Interface) " +"implementation of the Kerberos network authentication protocol." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:56 +#, no-wrap +msgid "Protocol Versions" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:59 +msgid "" +"indexterm:[SSH protocol,version 1]indexterm:[SSH protocol,version 2] Two " +"varieties of SSH currently exist: version 1 and version 2. The OpenSSH suite " +"under {MAJOROS} uses SSH version 2, which has an enhanced key exchange " +"algorithm not vulnerable to the known exploit in version 1. Protocol version " +"1 was removed from OpenSSH suite and is no longer supported." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:61 +#, no-wrap +msgid "Event Sequence of an SSH Connection" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:64 +msgid "" +"indexterm:[SSH protocol,connection sequence] The following series of events " +"help protect the integrity of SSH communication between two hosts." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:66 +msgid "" +"A cryptographic handshake is made so that the client can verify that it is " +"communicating with the correct server." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:68 +msgid "" +"The transport layer of the connection between the client and remote host is " +"encrypted using a symmetric cipher." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:70 +msgid "The client authenticates itself to the server." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:72 +msgid "The client interacts with the remote host over the encrypted connection." +msgstr "" + +#. type: Title ==== +#: ./pages/infrastructure-services/OpenSSH.adoc:74 +#, no-wrap +msgid "Transport Layer" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:77 +msgid "" +"indexterm:[SSH protocol,layers,transport layer] The primary role of the " +"transport layer is to facilitate safe and secure communication between the " +"two hosts at the time of authentication and during subsequent " +"communication. The transport layer accomplishes this by handling the " +"encryption and decryption of data, and by providing integrity protection of " +"data packets as they are sent and received. The transport layer also " +"provides compression, speeding the transfer of information." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:79 +msgid "" +"Once an SSH client contacts a server, key information is exchanged so that " +"the two systems can correctly construct the transport layer. The following " +"steps occur during this exchange:" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:81 +msgid "The key exchange algorithm is determined" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:83 +msgid "The public key signature algorithm is determined" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:85 +msgid "The symmetric encryption algorithm is determined" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:87 +msgid "The message authentication algorithm is determined" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:89 +msgid "Keys are exchanged" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:91 +msgid "" +"During the key exchange, the server identifies itself to the client with a " +"unique _host key_. If the client has never communicated with this particular " +"server before, the server's host key is unknown to the client and it does " +"not connect. OpenSSH notifies the user that the authenticity of the host " +"cannot be established and prompts the user to accept or reject it. The user " +"is expected to independently verify the new host key before accepting it. In " +"subsequent connections, the server's host key is checked against the saved " +"version on the client, providing confidence that the client is indeed " +"communicating with the intended server. If, in the future, the host key no " +"longer matches, the user must remove the client's saved version before a " +"connection can occur." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:92 +#, no-wrap +msgid "Always verify the integrity of a new SSH server" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:97 +msgid "" +"It is possible for an attacker to masquerade as an SSH server during the " +"initial contact since the local system does not know the difference between " +"the intended server and a false one set up by an attacker. To help prevent " +"this, verify the integrity of a new SSH server by contacting the server " +"administrator before connecting for the first time or in the event of a host " +"key mismatch." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:101 +msgid "" +"SSH is designed to work with almost any kind of public key algorithm or " +"encoding format. After an initial key exchange creates a hash value used for " +"exchanges and a shared secret value, the two systems immediately begin " +"calculating new keys and algorithms to protect authentication and future " +"data sent over the connection." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:103 +msgid "" +"After a certain amount of data has been transmitted using a given key and " +"algorithm (the exact amount depends on the SSH implementation, encryption " +"algorithm and configuration), another key exchange occurs, generating " +"another set of hash values and a new shared secret value. Even if an " +"attacker is able to determine the hash and shared secret value, this " +"information is only useful for a limited period of time." +msgstr "" + +#. type: Title ==== +#: ./pages/infrastructure-services/OpenSSH.adoc:105 +#, no-wrap +msgid "Authentication" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:108 +msgid "" +"indexterm:[SSH protocol,authentication] Once the transport layer has " +"constructed a secure tunnel to pass information between the two systems, the " +"server tells the client the different authentication methods supported, such " +"as using a private key-encoded signature or typing a password. The client " +"then tries to authenticate itself to the server using one of these supported " +"methods." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:110 +msgid "" +"SSH servers and clients can be configured to allow different types of " +"authentication, which gives each side the optimal amount of control. The " +"server can decide which encryption methods it supports based on its security " +"model, and the client can choose the order of authentication methods to " +"attempt from the available options." +msgstr "" + +#. type: Title ==== +#: ./pages/infrastructure-services/OpenSSH.adoc:112 +#, no-wrap +msgid "Channels" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:115 +msgid "" +"indexterm:[SSH protocol,layers,channels] After a successful authentication " +"over the SSH transport layer, multiple channels are opened via a technique " +"called _multiplexing_pass:attributes[{blank}]footnote:[A multiplexed " +"connection consists of several signals being sent over a shared, common " +"medium. With SSH, different channels are sent over a common secure " +"connection.]. Each of these channels handles communication for different " +"terminal sessions and for forwarded X11 sessions." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:117 +msgid "" +"Both clients and servers can create a new channel. Each channel is then " +"assigned a different number on each end of the connection. When the client " +"attempts to open a new channel, the clients sends the channel number along " +"with the request. This information is stored by the server and is used to " +"direct communication to that channel. This is done so that different types " +"of sessions do not affect one another and so that when a given session ends, " +"its channel can be closed without disrupting the primary SSH connection." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:119 +msgid "" +"Channels also support _flow-control_, which allows them to send and receive " +"data in an orderly fashion. In this way, data is not sent over the channel " +"until the client receives a message that the channel is open." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:121 +msgid "" +"The client and server negotiate the characteristics of each channel " +"automatically, depending on the type of service the client requests and the " +"way the user is connected to the network. This allows great flexibility in " +"handling different types of remote connections without having to change the " +"basic infrastructure of the protocol." +msgstr "" + +#. type: Title == +#: ./pages/infrastructure-services/OpenSSH.adoc:123 +#, no-wrap +msgid "Configuring OpenSSH" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:126 +msgid "" +"In order to perform tasks described in this section, you must have superuser " +"privileges. To obtain them, log in as `root` by typing:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:130 +#, no-wrap +msgid "[command]#su -#\n" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:133 +#, no-wrap +msgid "Configuration Files" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:138 +msgid "" +"indexterm:[SSH protocol,configuration files] There are two different sets of " +"configuration files: those for client programs (that is, [command]#ssh#, " +"[command]#scp#, and [command]#sftp#), and those for the server (the " +"[command]#sshd# daemon). indexterm:[SSH protocol,configuration " +"files,system-wide configuration files]indexterm:[SSH protocol,configuration " +"files,user-specific configuration files] System-wide SSH configuration " +"information is stored in the `/etc/ssh/` directory as described in " +"xref:table-ssh-configuration-configs-system[System-wide configuration " +"files]. User-specific SSH configuration information is stored in `~/.ssh/` " +"within the user's home directory as described in " +"xref:table-ssh-configuration-configs-user[User-specific configuration " +"files]." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:140 +#, no-wrap +msgid "System-wide configuration files" +msgstr "" + +#. type: Table +#: ./pages/infrastructure-services/OpenSSH.adoc:156 +#, no-wrap +msgid "" +"|File|Description\n" +"|`/etc/ssh/moduli`|Contains Diffie-Hellman groups used for the " +"\"`Diffie-Hellman group exchange`\" key exchange method, which is critical " +"for constructing a secure transport layer. When keys are exchanged at the " +"beginning of an SSH session, a shared, secret value is created which cannot " +"be determined by either party alone. If the file is not available, fixed " +"groups will be used. Other key exchange methods do not need this file.\n" +"|`/etc/ssh/ssh_config`|The default SSH client configuration file. Note that " +"it is overridden by `~/.ssh/config` if it exists.\n" +"|`/etc/ssh/sshd_config`|The configuration file for the [command]#sshd# " +"daemon.\n" +"|`/etc/ssh/ssh_host_ecdsa_key`|The ECDSA private key used by the " +"[command]#sshd# daemon.\n" +"|`/etc/ssh/ssh_host_ecdsa_key.pub`|The ECDSA public key used by the " +"[command]#sshd# daemon.\n" +"|`/etc/ssh/ssh_host_rsa_key`|The RSA private key used by the [command]#sshd# " +"daemon.\n" +"|`/etc/ssh/ssh_host_rsa_key.pub`|The RSA public key used by the " +"[command]#sshd# daemon.\n" +"|`/etc/ssh/ssh_host_ed25519_key`|The EdDSA private key used by the " +"[command]#sshd# daemon.\n" +"|`/etc/ssh/ssh_host_ed25519_key.pub`|The EdDSA public key used by the " +"[command]#sshd# daemon.\n" +"|`/etc/pam.d/sshd`|The PAM configuration file for the [command]#sshd# " +"daemon.\n" +"|`/etc/sysconfig/sshd`|Configuration file for the `sshd` service.\n" +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:159 +#, no-wrap +msgid "User-specific configuration files" +msgstr "" + +#. type: Table +#: ./pages/infrastructure-services/OpenSSH.adoc:172 +#, no-wrap +msgid "" +"|File|Description\n" +"|`~/.ssh/authorized_keys`|Holds a list of authorized public keys for " +"servers. When the client connects to a server, the server authenticates the " +"client by checking its signed public key stored within this file.\n" +"|`~/.ssh/id_ecdsa`|Contains the ECDSA private key of the user.\n" +"|`~/.ssh/id_ecdsa.pub`|The ECDSA public key of the user.\n" +"|`~/.ssh/id_rsa`|The RSA private key used by [command]#ssh#.\n" +"|`~/.ssh/id_rsa.pub`|The RSA public key used by [command]#ssh#.\n" +"|`~/.ssh/id_ed25519`|The EdDSA private key used by [command]#ssh#.\n" +"|`~/.ssh/id_ed25519.pub`|The EdDSA public key used by [command]#ssh#.\n" +"|`~/.ssh/known_hosts`|Contains host keys of SSH servers accessed by the " +"user. This file is very important for ensuring that the SSH client is " +"connecting to the correct SSH server.\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:175 +msgid "" +"For information concerning various directives that can be used in the SSH " +"configuration files, see the `ssh_config`(5) and `sshd_config`(5) manual " +"pages." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:177 +#, no-wrap +msgid "Starting an OpenSSH Server" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:179 +msgid "indexterm:[OpenSSH,server]" +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:180 +#: ./pages/infrastructure-services/OpenSSH.adoc:1024 +#, no-wrap +msgid "Make sure you have relevant packages installed" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:185 +msgid "" +"To run an OpenSSH server, you must have the [package]*openssh-server* " +"package installed. See " +"xref:package-management/DNF.adoc#sec-Installing[Installing Packages] for " +"more information on how to install new packages in {MAJOROSVER}." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:189 +msgid "" +"indexterm:[OpenSSH,server,starting] To start the [command]#sshd# daemon in " +"the current session, type the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:193 +#, no-wrap +msgid "~]#{nbsp}systemctl start sshd.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:196 +msgid "" +"indexterm:[OpenSSH,server,stopping] To stop the running [command]#sshd# " +"daemon in the current session, use the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:200 +#, no-wrap +msgid "~]#{nbsp}systemctl stop sshd.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:203 +msgid "" +"If you want the daemon to start automatically at the boot time, type as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:208 +#, no-wrap +msgid "" +"~]#{nbsp}systemctl enable sshd.service\n" +"ln -s '/usr/lib/systemd/system/sshd.service' " +"'/etc/systemd/system/multi-user.target.wants/sshd.service'\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:211 +#: ./pages/infrastructure-services/OpenSSH.adoc:252 +msgid "" +"See " +"xref:infrastructure-services/Services_and_Daemons.adoc#ch-Services_and_Daemons[Services " +"and Daemons] for more information on how to configure services in {MAJOROS}." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:213 +msgid "" +"Note that if you reinstall the system, a new set of identification keys will " +"be created. As a result, clients who had connected to the system with any of " +"the OpenSSH tools before the reinstall will see the following message:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:222 +#, no-wrap +msgid "" +"@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@\n" +"@ WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @\n" +"@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@\n" +"IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!\n" +"Someone could be eavesdropping on you right now (man-in-the-middle " +"attack)!\n" +"It is also possible that the RSA host key has just been changed.\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:225 +msgid "" +"To prevent this, you can backup the relevant files from the `/etc/ssh/` " +"directory (see xref:table-ssh-configuration-configs-system[System-wide " +"configuration files] for a complete list), and restore them whenever you " +"reinstall the system." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:227 +#, no-wrap +msgid "Requiring SSH for Remote Connections" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:230 +msgid "" +"indexterm:[SSH protocol,insecure protocols]indexterm:[SSH protocol,requiring " +"for remote login] For SSH to be truly effective, using insecure connection " +"protocols should be prohibited. Otherwise, a user's password may be " +"protected using SSH for one session, only to be captured later while logging " +"in using Telnet. Some services to disable include [command]#telnet#, " +"[command]#rsh#, [command]#rlogin#, and [command]#vsftpd#." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:232 +msgid "" +"These services are not installed by default in {MAJOROS}. If required, to " +"make sure these services are not running, type the following commands at a " +"shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:239 +#, no-wrap +msgid "" +"[command]#systemctl stop telnet.service#\n" +"[command]#systemctl stop rsh.service#\n" +"[command]#systemctl stop rlogin.service#\n" +"[command]#systemctl stop vsftpd.service#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:242 +msgid "To disable running these services at startup, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:249 +#, no-wrap +msgid "" +"[command]#systemctl disable telnet.service#\n" +"[command]#systemctl disable rsh.service#\n" +"[command]#systemctl disable rlogin.service#\n" +"[command]#systemctl disable vsftpd.service#\n" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:254 +#, no-wrap +msgid "Using Key-based Authentication" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:257 +msgid "" +"indexterm:[OpenSSH,using key-based authentication] To improve the system " +"security even further, generate SSH key pairs and then enforce key-based " +"authentication by disabling password authentication. To do so, create a " +"drop-in configuration file, for example " +"`/etc/ssh/sshd_config.d/01-local.conf`. Make sure it is lexicographically " +"before the `50-redhat.conf` file, providing Fedora defaults. In a text " +"editor such as [application]*vi* or [application]*nano* insert the " +"[option]`PasswordAuthentication` option as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:261 +#, no-wrap +msgid "PasswordAuthentication no\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:264 +msgid "" +"If you are working on a system other than a new default installation, check " +"that [command]#PubkeyAuthentication no# has *not* been set in neither " +"`/etc/ssh/sshd_config` nor any included file from drop-in directory. If " +"connected remotely, not using console or out-of-band access, testing the " +"key-based log in process before disabling password authentication is " +"advised." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:266 +msgid "" +"To be able to use [command]#ssh#, [command]#scp#, or [command]#sftp# to " +"connect to the server from a client machine, generate an authorization key " +"pair by following the steps below. Note that keys must be generated for each " +"user separately." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:268 +msgid "" +"{MAJOROSVER} uses SSH Protocol 2 and RSA keys by default (see " +"xref:s2-ssh-versions[Protocol Versions] for more information)." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:269 +#, no-wrap +msgid "Do not generate key pairs as root" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:274 +msgid "" +"If you complete the steps as `root`, only `root` will be able to use the " +"keys." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:277 +#, no-wrap +msgid "Backup your ~/.ssh/ directory" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:282 +msgid "" +"If you reinstall your system and want to keep previously generated key " +"pairs, backup the `~/.ssh/` directory. After reinstalling, copy it back to " +"your home directory. This process can be done for all users on your system, " +"including `root`." +msgstr "" + +#. type: Title ==== +#: ./pages/infrastructure-services/OpenSSH.adoc:286 +#, no-wrap +msgid "Generating Key Pairs" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:290 +msgid "" +"indexterm:[RSA keys,generating]indexterm:[OpenSSH,RSA keys,generating] To " +"generate an RSA key pair for version 2 of the SSH protocol, follow these " +"steps: indexterm:[OpenSSH,ssh-keygen,RSA]" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:292 +msgid "Generate an RSA key pair by typing the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:298 +#, no-wrap +msgid "" +"~]${nbsp}ssh-keygen -t rsa\n" +"Generating public/private rsa key pair.\n" +"Enter file in which to save the key (/home/USER/.ssh/id_rsa):\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:301 +msgid "" +"Press kbd:[Enter] to confirm the default location, `~/.ssh/id_rsa`, for the " +"newly created key." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:303 +#: ./pages/infrastructure-services/OpenSSH.adoc:364 +msgid "" +"Enter a passphrase, and confirm it by entering it again when prompted to do " +"so. For security reasons, avoid using the same password as you use to log in " +"to your account." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:305 +#: ./pages/infrastructure-services/OpenSSH.adoc:366 +msgid "After this, you will be presented with a message similar to this:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:323 +#, no-wrap +msgid "" +"Your identification has been saved in /home/USER/.ssh/id_rsa.\n" +"Your public key has been saved in /home/USER/.ssh/id_rsa.pub.\n" +"The key fingerprint is:\n" +"SHA256:y6f0DGlHe28YWotEypnhfk3WLYQ5TgaQwoSlOFwmmm0 " +"USER@penguin.example.com\n" +"The key's randomart image is:\n" +"+--[ RSA 2048]----+\n" +"| E. |\n" +"| . . |\n" +"| o . |\n" +"| . .|\n" +"| S . . |\n" +"| + o o ..|\n" +"| * * +oo|\n" +"| O +..=|\n" +"| o* o.|\n" +"+-----------------+\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:326 +#: ./pages/infrastructure-services/OpenSSH.adoc:387 +msgid "" +"By default, the permissions of the `~/.ssh/` directory are set to " +"`rwx------` or `700` expressed in octal notation. This is to ensure that " +"only the _USER_ can view the contents. If required, this can be confirmed " +"with the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:331 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#ls -ld ~/.ssh#\n" +"drwx------. 2 USER USER 54 Nov 25 16:56 /home/USER/.ssh/\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:334 +#: ./pages/infrastructure-services/OpenSSH.adoc:396 +msgid "" +"To copy the public key to a remote machine, issue a command in the following " +"format:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:338 +#, no-wrap +msgid " [command]#ssh-copy-id _user@hostname_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:341 +#: ./pages/infrastructure-services/OpenSSH.adoc:403 +msgid "" +"This will copy the most recently modified `~/.ssh/id*.pub` public key if it " +"is not yet installed. Alternatively, specify the public key's file name as " +"follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:344 +#, no-wrap +msgid "ssh-copy-id -i ~/.ssh/id_rsa.pub user@hostname\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:347 +msgid "" +"This will copy the content of `~/.ssh/id_rsa.pub` into the " +"`~/.ssh/authorized_keys` file on the machine to which you want to " +"connect. If the file already exists, the keys are appended to its end." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:351 +msgid "" +"indexterm:[ECDSA keys,generating]indexterm:[OpenSSH,ECDSA keys,generating] " +"To generate an ECDSA key pair for version 2 of the SSH protocol, follow " +"these steps: indexterm:[OpenSSH,ssh-keygen,ECDSA]" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:353 +msgid "Generate an ECDSA key pair by typing the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:359 +#, no-wrap +msgid "" +"~]${nbsp}ssh-keygen -t ecdsa\n" +"Generating public/private ecdsa key pair.\n" +"Enter file in which to save the key (/home/USER/.ssh/id_ecdsa):\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:362 +msgid "" +"Press kbd:[Enter] to confirm the default location, `~/.ssh/id_ecdsa`, for " +"the newly created key." +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:384 +#, no-wrap +msgid "" +"Your identification has been saved in /home/USER/.ssh/id_ecdsa.\n" +"Your public key has been saved in /home/USER/.ssh/id_ecdsa.pub.\n" +"The key fingerprint is:\n" +"SHA256:y6f0DGlHe28YWotEypnhfk3WLYQ5TgaQwoSlOFwmmm0 " +"USER@penguin.example.com\n" +"The key's randomart image is:\n" +"+--[ECDSA 256]---+\n" +"| .+ +o |\n" +"| . =.o |\n" +"| o o + ..|\n" +"| + + o +|\n" +"| S o o oE.|\n" +"| + oo+.|\n" +"| + o |\n" +"| |\n" +"| |\n" +"+-----------------+\n" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:393 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#ls -ld ~/.ssh#\n" +" ~]$ ls -ld ~/.ssh/\n" +"drwx------. 2 USER USER 54 Nov 25 16:56 /home/USER/.ssh/\n" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:400 +#, no-wrap +msgid "[command]#ssh-copy-id _USER@hostname_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:406 +#, no-wrap +msgid "ssh-copy-id -i ~/.ssh/id_ecdsa.pub USER@hostname\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:409 +msgid "" +"This will copy the content of `~/.ssh/id_ecdsa.pub` into the " +"`~/.ssh/authorized_keys` on the machine to which you want to connect. If the " +"file already exists, the keys are appended to its end." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:411 +msgid "" +"See xref:s3-ssh-configuration-keypairs-agent[Configuring ssh-agent] for " +"information on how to set up your system to remember the passphrase." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:412 +#, no-wrap +msgid "Never share your private key" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:417 +msgid "" +"The private key is for your personal use only, and it is important that you " +"never give it to anyone." +msgstr "" + +#. type: Title ==== +#: ./pages/infrastructure-services/OpenSSH.adoc:421 +#, no-wrap +msgid "Configuring ssh-agent" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:424 +msgid "" +"indexterm:[OpenSSH,ssh-agent]indexterm:[ssh-agent] To store your passphrase " +"so that you do not have to enter it each time you initiate a connection with " +"a remote machine, you can use the [command]#ssh-agent# authentication agent." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:426 +msgid "" +"To save your passphrase for a certain shell prompt, use the following " +"command:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:431 +#, no-wrap +msgid "" +"~]${nbsp}ssh-add\n" +"Enter passphrase for /home/USER/.ssh/id_rsa:\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:434 +msgid "" +"Note that when you log out, your passphrase will be forgotten. You must " +"execute the command each time you log in to a virtual console or a terminal " +"window." +msgstr "" + +#. type: Title == +#: ./pages/infrastructure-services/OpenSSH.adoc:436 +#, no-wrap +msgid "Using OpenSSH Certificate Authentication" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:439 +#, no-wrap +msgid "Introduction to SSH Certificates" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:442 +msgid "" +"Using public key cryptography for authentication requires copying the public " +"key from every client to every server that the client intends to log " +"into. This system does not scale well and can be an administrative " +"burden. Using a public key from a _certificate authority_ (*CA*) to " +"authenticate client certificates removes the need to copy keys between " +"multiple systems. While the X.509 Public Key Infrastructure Certificate " +"system provides a solution to this issue, there is a submission and " +"validation process, with associated fees, to go through in order to get a " +"certificate signed. As an alternative, OpenSSH supports the creation of " +"simple certificates and associated CA infrastructure." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:444 +msgid "" +"OpenSSH certificates contain a public key, identity information, and " +"validity constraints. They are signed with a standard SSH public key using " +"the [command]#ssh-keygen# utility. The format of the certificate is " +"described in " +"`/usr/share/doc/openssh-_version_pass:attributes[{blank}]/PROTOCOL.certkeys`." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:446 +msgid "" +"The [command]#ssh-keygen# utility supports two types of certificates: user " +"and host. User certificates authenticate users to servers, whereas host " +"certificates authenticate server hosts to users. For certificates to be used " +"for user or host authentication, `sshd` must be configured to trust the CA " +"public key." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:448 +#, no-wrap +msgid "Support for SSH Certificates" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:451 +msgid "" +"Support for certificate authentication of users and hosts using the new " +"OpenSSH certificate format was introduced in Fedora 13, in the " +"[package]*openssh-5.4p1-1.fc13* package. If required, to ensure the latest " +"OpenSSH package is installed, enter the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:456 +#, no-wrap +msgid "" +"~]# dnf install openssh\n" +"Last metadata expiration check performed 0:58:01 ago on Sun Sep 6 16:07:22 " +"2020.\n" +"Package openssh-7.1p1-1.fc23.x86_64 is already installed, skipping.\n" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:459 +#, no-wrap +msgid "Creating SSH CA Certificate Signing Keys" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:462 +msgid "" +"Two types of certificates are required, host certificates and user " +"certificates. It is considered better to have two separate keys for signing " +"the two certificates, for example `ca_user_key` and `ca_host_key`, however " +"it is possible to use just one CA key to sign both certificates. It is also " +"easier to follow the procedures if separate keys are used, so the examples " +"that follow will use separate keys." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:464 +msgid "" +"The basic format of the command to sign user's public key to create a user " +"certificate is as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:468 +#, no-wrap +msgid "ssh-keygen -s ca_user_key -I pass:quotes[_certificate_ID_] id_rsa.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:471 +msgid "" +"Where [option]`-s` indicates the private key used to sign the certificate, " +"[option]`-I` indicates an identity string, the _certificate_ID_, which can " +"be any alpha numeric value. It is stored as a zero terminated string in the " +"certificate. The _certificate_ID_ is logged whenever the certificate is used " +"for identification and it is also used when revoking a certificate. Having a " +"long value would make logs hard to read, therefore using the host name for " +"host certificates and the user name for user certificates is a safe choice." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:473 +msgid "" +"To sign a host's public key to create a host certificate, add the " +"[option]`-h` option:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:477 +#, no-wrap +msgid "" +"ssh-keygen -s ca_host_key -I pass:quotes[_certificate_ID_] -h " +"ssh_host_rsa_key.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:480 +msgid "" +"Host keys are generated on the system by default, to list the keys, enter a " +"command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:489 +#, no-wrap +msgid "" +"~]# ls -l /etc/ssh/ssh_host*\n" +"-rw-------. 1 root root 668 Jul 9 2014 /etc/ssh/ssh_host_dsa_key\n" +"-rw-r--r--. 1 root root 590 Jul 9 2014 /etc/ssh/ssh_host_dsa_key.pub\n" +"-rw-------. 1 root root 963 Jul 9 2014 /etc/ssh/ssh_host_key\n" +"-rw-r--r--. 1 root root 627 Jul 9 2014 /etc/ssh/ssh_host_key.pub\n" +"-rw-------. 1 root root 1671 Jul 9 2014 /etc/ssh/ssh_host_rsa_key\n" +"-rw-r--r--. 1 root root 382 Jul 9 2014 /etc/ssh/ssh_host_rsa_key.pub\n" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:495 +msgid "" +"It is recommended to create and store CA keys in a safe place just as with " +"any other private key. In these examples the `root` user will be used. In a " +"real production environment using an offline computer with an administrative " +"user account is recommended. For guidance on key lengths see " +"[citetitle]_link:++https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar1.pdf++[NIST " +"Special Publication 800-131A Revision 1]_." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:499 +#, no-wrap +msgid "Generating SSH CA Certificate Signing Keys" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:501 +msgid "" +"On the server designated to be the CA, generate two keys for use in signing " +"certificates. These are the keys that all other hosts need to trust. Choose " +"suitable names, for example `ca_user_key` and `ca_host_key`. To generate the " +"user certificate signing key, enter the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:524 +#, no-wrap +msgid "" +"~]# ssh-keygen -t rsa -f ~/.ssh/ca_user_key\n" +"Generating public/private rsa key pair.\n" +"Created directory '/root/.ssh'.\n" +"Enter passphrase (empty for no passphrase):\n" +"Enter same passphrase again:\n" +"Your identification has been saved in /root/.ssh/ca_user_key.\n" +"Your public key has been saved in /root/.ssh/ca_user_key.pub.\n" +"The key fingerprint is:\n" +"SHA256:y6f0DGlHe28YWotEypnhfk3WLYQ5TgaQwoSlOFwmmm0 " +"root@host_name.example.com\n" +"The key's randomart image is:\n" +"+--[ RSA 2048]----+\n" +"| .+. o|\n" +"| . o +.|\n" +"| o + . . o|\n" +"| o + . . ..|\n" +"| S . ... *|\n" +"| . . . .*.|\n" +"| = E .. |\n" +"| . o . |\n" +"| . |\n" +"+-----------------+\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:527 +msgid "Generate a host certificate signing key, `ca_host_key`, as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:549 +#, no-wrap +msgid "" +"~]# ssh-keygen -t rsa -f ~/.ssh/ca_host_key\n" +"Generating public/private rsa key pair.\n" +"Enter passphrase (empty for no passphrase):\n" +"Enter same passphrase again:\n" +"Your identification has been saved in /root/.ssh/ca_host_key.\n" +"Your public key has been saved in /root/.ssh/ca_host_key.pub.\n" +"The key fingerprint is:\n" +"SHA256:y6f0DGlHe28YWotEypnhfk3WLYQ5TgaQwoSlOFwmmm0 " +"root@host_name.example.com\n" +"The key's randomart image is:\n" +"+--[ RSA 2048]----+\n" +"| .. |\n" +"| . ....|\n" +"| . . o +oo|\n" +"| o . o *o|\n" +"| S = .|\n" +"| o. .|\n" +"| *.E. |\n" +"| +o= |\n" +"| .oo. |\n" +"+-----------------+\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:552 +msgid "If required, confirm the permissions are correct:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:566 +#, no-wrap +msgid "" +"~]# ls -la ~/.ssh\n" +"total 40\n" +"drwxrwxrwx. 2 root root 4096 May 22 13:18 .\n" +"dr-xr-x---. 3 root root 4096 May 8 08:34 ..\n" +"-rw-------. 1 root root 1743 May 22 13:15 ca_host_key\n" +"-rw-r--r--. 1 root root 420 May 22 13:15 ca_host_key.pub\n" +"-rw-------. 1 root root 1743 May 22 13:14 ca_user_key\n" +"-rw-r--r--. 1 root root 420 May 22 13:14 ca_user_key.pub\n" +"-rw-r--r--. 1 root root 854 May 8 05:55 known_hosts\n" +"-r--------. 1 root root 1671 May 6 17:13 ssh_host_rsa\n" +"-rw-r--r--. 1 root root 1370 May 7 14:30 ssh_host_rsa-cert.pub\n" +"-rw-------. 1 root root 420 May 6 17:13 ssh_host_rsa.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:569 +msgid "" +"Create the CA server's own host certificate by signing the server's host " +"public key together with an identification string such as the host name, the " +"CA server's _fully qualified domain name_ (*FQDN*) but without the trailing " +"`.`, and a validity period. The command takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:573 +#, no-wrap +msgid "" +"ssh-keygen -s ~/.ssh/ca_host_key -I pass:quotes[_certificate_ID_] -h -n " +"pass:quotes[_host_name.example.com_] -V pass:quotes[_-start:+end_] " +"/etc/ssh/ssh_host_rsa.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:576 +msgid "" +"The [option]`-n` option restricts this certificate to a specific host within " +"the domain. The [option]`-V` option is for adding a validity period; this is " +"highly recommend. Where the validity period is intended to be one year, " +"fifty two weeks, consider the need for time to change the certificates and " +"any holiday periods around the time of certificate expiry." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:578 +msgid "For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:583 +#, no-wrap +msgid "" +"~]# ssh-keygen -s ~/.ssh/ca_host_key -I host_name -h -n " +"host_name.example.com -V -1w:+54w5d /etc/ssh/ssh_host_rsa.pub\n" +"Enter passphrase:\n" +"Signed host key /root/.ssh/ssh_host_rsa-cert.pub: id \"host_name\" serial 0 " +"for host_name.example.com valid from 2020-05-15T13:52:29 to " +"2021-06-08T13:52:29\n" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:586 +#, no-wrap +msgid "Distributing and Trusting SSH CA Public Keys" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:589 +msgid "" +"Hosts that are to allow certificate authenticated log in from users must be " +"configured to trust the CA's public key that was used to sign the user " +"certificates, in order to authenticate user's certificates. In this example " +"that is the `ca_user_key.pub`." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:591 +msgid "" +"Publish the `ca_user_key.pub` key and download it to all hosts that are " +"required to allow remote users to log in. Alternately, copy the CA user " +"public key to all the hosts. In a production environment, consider copying " +"the public key to an administrator account first. The secure copy command " +"can be used to copy the public key to remote hosts. The command has the " +"following format:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:595 +#, no-wrap +msgid "" +"scp ~/.ssh/ca_user_key.pub " +"root@pass:quotes[_host_name_].example.com:/etc/ssh/\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:598 +msgid "" +"Where _host_name_ is the host name of a server the is required to " +"authenticate user's certificates presented during the login process. Ensure " +"you copy the public key not the private key. For example, as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:607 +#, no-wrap +msgid "" +"~]# scp ~/.ssh/ca_user_key.pub root@host_name.example.com:/etc/ssh/\n" +"The authenticity of host 'host_name.example.com (10.34.74.56)' can't be " +"established.\n" +"ECDSA key fingerprint is " +"SHA256:ZYEUaevOAEASvYjm58PiPdMebxhhlaTZBjTMr/N2I3c.\n" +"Are you sure you want to continue connecting (yes/no/[fingerprint])? yes\n" +"Warning: Permanently added 'host_name.example.com,10.34.74.56' (ECDSA) to " +"the list of known hosts.\n" +"root@host_name.example.com's password:\n" +"ca_user_key.pub 100% 420 0.4KB/s " +"00:00\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:610 +msgid "" +"For remote user authentication, CA keys can be marked as trusted per-user in " +"the `~/.ssh/authorized_keys` file using the [command]#cert-authority# " +"directive or for global use by means of the [command]#TrustedUserCAKeys# " +"directive in the `/etc/ssh/sshd_config` file. For remote host " +"authentication, CA keys can be marked as trusted globally in the " +"`/etc/ssh/known_hosts` file or per-user in the `~/.ssh/ssh_known_hosts` " +"file." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:612 +#, no-wrap +msgid "Trusting the User Signing Key" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:614 +msgid "" +"For user certificates which have one or more principles listed, and where " +"the setting is to have global effect, edit the `/etc/ssh/sshd_config` file " +"as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:617 +#, no-wrap +msgid "TrustedUserCAKeys /etc/ssh/ca_user_key.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:620 +#: ./pages/infrastructure-services/OpenSSH.adoc:748 +msgid "Restart `sshd` to make the changes take effect:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:623 +#: ./pages/infrastructure-services/OpenSSH.adoc:751 +#, no-wrap +msgid "~]#{nbsp}systemctl restart sshd.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:626 +msgid "" +"To avoid being presented with the warning about an unknown host, a user's " +"system must trust the CA's public key that was used to sign the host " +"certificates. In this example that is `ca_host_key.pub`." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:628 +#, no-wrap +msgid "Trusting the Host Signing Key" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:630 +msgid "" +"Extract the contents of the public key used to sign the host " +"certificate. For example, on the CA:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:635 +#, no-wrap +msgid "" +"cat ~/.ssh/ca_host_key.pub\n" +"ssh-rsa pass:quotes[_AAAAB5Wm._]== root@ca-server.example.com\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:638 +msgid "" +"To configure client systems to trust servers' signed host certificates, add " +"the contents of the `ca_host_key.pub` into the global `known_hosts` " +"file. This will automatically check a server's host advertised certificate " +"against the CA public key for all users every time a new machine is " +"connected to in the domain `*.example.com`. Login as `root` and configure " +"the `/etc/ssh/ssh_known_hosts` file, as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:644 +#, no-wrap +msgid "" +"~]# vi /etc/ssh/ssh_known_hosts\n" +"# A CA key, accepted for any host in *.example.com\n" +"@cert-authority *.example.com ssh-rsa pass:quotes[_AAAAB5Wm._]\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:647 +msgid "" +"Where `ssh-rsa _AAAAB5Wm._pass:attributes[{blank}]` is the contents of " +"`ca_host_key.pub`. The above configures the system to trust the CA servers " +"host public key. This enables global authentication of the certificates " +"presented by hosts to remote users." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:649 +#, no-wrap +msgid "Creating SSH Certificates" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:652 +msgid "" +"A certificate is a signed public key. The user's and host's public keys must " +"be copied to the CA server for signing by the CA server's private key." +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:657 +msgid "" +"Copying many keys to the CA to be signed can create confusion if they are " +"not uniquely named. If the default name is always used then the latest key " +"to be copied will overwrite the previously copied key, which may be an " +"acceptable method for one administrator. In the example below the default " +"name is used. In a production environment, consider using easily " +"recognizable names. It is recommend to have a designated directory on the CA " +"server owned by an administrative user for the keys to be copied " +"into. Copying these keys to the `root` user's `/etc/ssh/` directory is not " +"recommend. In the examples below an account named `admin` with a directory " +"named `keys/` will be used." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:661 +msgid "" +"Create an administrator account, in this example `admin`, and a directory to " +"receive the user's keys. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:665 +#, no-wrap +msgid "~]$ [command]#mkdir keys#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:668 +msgid "Set the permissions to allow keys to be copied in:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:675 +#, no-wrap +msgid "" +"~]$ chmod o+w keys\n" +"ls -la keys\n" +"total 8\n" +"drwxrwxrwx. 2 admin admin 4096 May 22 16:17 .\n" +"drwx------. 3 admin admin 4096 May 22 16:17 ..\n" +msgstr "" + +#. type: Title ==== +#: ./pages/infrastructure-services/OpenSSH.adoc:678 +#, no-wrap +msgid "Creating SSH Certificates to Authenticate Hosts" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:681 +msgid "The command to sign a host certificate has the following format:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:685 +#, no-wrap +msgid "" +"ssh-keygen -s ca_host_key -I pass:quotes[_host_name_] -h " +"ssh_host_rsa_key.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:688 +msgid "The host certificate will named `ssh_host_rsa_key-cert.pub`." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:690 +#, no-wrap +msgid "Generating a Host Certificate" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:692 +msgid "" +"To authenticate a host to a user, a public key must be generated on the " +"host, passed to the CA server, signed by the CA, and then passed back to be " +"stored on the host to present to a user attempting to log into the host." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:694 +msgid "" +"Host keys are generated automatically on the system. To list them enter the " +"following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:703 +#, no-wrap +msgid "" +"~]# ls -l /etc/ssh/ssh_host*\n" +"-rw-------. 1 root root 668 May 6 14:38 /etc/ssh/ssh_host_dsa_key\n" +"-rw-r--r--. 1 root root 590 May 6 14:38 /etc/ssh/ssh_host_dsa_key.pub\n" +"-rw-------. 1 root root 963 May 6 14:38 /etc/ssh/ssh_host_key\n" +"-rw-r--r--. 1 root root 627 May 6 14:38 /etc/ssh/ssh_host_key.pub\n" +"-rw-------. 1 root root 1679 May 6 14:38 /etc/ssh/ssh_host_rsa_key\n" +"-rw-r--r--. 1 root root 382 May 6 14:38 /etc/ssh/ssh_host_rsa_key.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:706 +msgid "" +"Copy the chosen public key to the server designated as the CA. For example, " +"from the host:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:715 +#, no-wrap +msgid "" +"~]# scp /etc/ssh/ssh_host_rsa_key.pub " +"admin@ca-server.example.com:~/keys/ssh_host_rsa_key.pub\n" +"The authenticity of host 'ca-server.example.com (10.34.74.58)' can't be " +"established.\n" +"ECDSA key fingerprint is " +"SHA256:ZYEUaevOAEASvYjm58PiPdMebxhhlaTZBjTMr/N2I3c.\n" +"Are you sure you want to continue connecting (yes/no/[fingerprint])? yes\n" +"Warning: Permanently added 'ca-server.example.com,10.34.74.58' (RSA) to the " +"list of known hosts.\n" +"admin@ca-server.example.com's password:\n" +"ssh_host_rsa_key.pub 100% 382 0.4KB/s " +"00:00\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:718 +msgid "Alternately, from the CA:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:721 +#, no-wrap +msgid "" +"~]$ scp root@host_name.example.com:/etc/ssh/ssh_host_rsa_key.pub " +"~/keys/ssh_host_rsa_key.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:724 +msgid "On the CA server, sign the host's public key. For example, as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:729 +#, no-wrap +msgid "" +"~]# ssh-keygen -s ~/.ssh/ca_host_key -I host_name -h -n " +"host_name.example.com -V -1d:+54w /home/admin/keys/ssh_host_rsa_key.pub\n" +"Enter passphrase:\n" +"Signed host key /home/admin/keys/ssh_host_rsa_key-cert.pub: id \"host_name\" " +"serial 0 for host_name.example.com valid from 2020-05-26T12:21:54 to " +"2021-06-08T12:21:54\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:732 +msgid "Where _host_name_ is the host name of the system requiring the certificate." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:734 +msgid "Copy the certificate to the host. For example, from the CA:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:739 +#, no-wrap +msgid "" +"~]# scp /home/admin/keys/ssh_host_rsa_key-cert.pub " +"root@host_name.example.com:/etc/ssh/\n" +"root@host_name.example.com's password:\n" +"ssh_host_rsa_key-cert.pub 100% 1384 1.5KB/s " +"00:00\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:742 +msgid "" +"Configure the host to present the certificate to a user's system when a user " +"initiates the login process. As `root`, edit the `/etc/ssh/sshd_config` file " +"as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:745 +#, no-wrap +msgid "HostCertificate /etc/ssh/ssh_host_rsa_key-cert.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:754 +msgid "" +"On user's systems, remove keys belonging to hosts from the " +"`~/.ssh/known_hosts` file if the user has previously logged into the host " +"configured above. When a user logs into the host they should no longer be " +"presented with the warning about the hosts authenticity." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:756 +msgid "" +"To test the host certificate, on a client system, ensure the client has set " +"up the global `/etc/ssh/known_hosts` file, as described in " +"xref:proc-Trusting_the_Host_Signing_Key[Trusting the Host Signing Key], and " +"that the server's public key is not in the `~/.ssh/known_hosts` file. Then " +"attempt to log into the server over SSH as a remote user. You should not see " +"a warning about the authenticity of the host. If required, add the " +"[option]`-v` option to the SSH command to see logging information." +msgstr "" + +#. type: Title ==== +#: ./pages/infrastructure-services/OpenSSH.adoc:758 +#, no-wrap +msgid "Creating SSH Certificates for Authenticating Users" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:761 +msgid "To sign a user's certificate, use a command in the following format:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:765 +#, no-wrap +msgid "" +"ssh-keygen -s ca_user_key -I pass:quotes[_user_name_] -n " +"pass:quotes[_user_name_] -V pass:quotes[_-start:+end_] id_rsa.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:768 +msgid "The resulting certificate will be named `id_rsa-cert.pub`." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:770 +msgid "" +"The default behavior of OpenSSH is that a user is allowed to log in as a " +"remote user if one of the principals specified in the certificate matches " +"the remote user's name. This can be adjusted in the following ways:" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:772 +msgid "" +"Add more user's names to the certificate during the signing process using " +"the [option]`-n` option:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:776 +#, no-wrap +msgid "-n \"name1[,name2,...]\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:779 +msgid "" +"On the user's system, add the public key of the CA in the " +"`~/.ssh/authorized_keys` file using the [command]#cert-authority# directive " +"and list the principals names as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:785 +#, no-wrap +msgid "" +"~]# vi ~/.ssh/authorized_keys\n" +"# A CA key, accepted for any host in *.example.com\n" +"@cert-authority principals=\"name1,name2\" *.example.com ssh-rsa " +"pass:quotes[_AAAAB5Wm._]\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:788 +msgid "" +"On the server, create an `AuthorizedPrincipalsFile` file, either per user or " +"globally, and add the principles' names to the file for those users allowed " +"to log in. Then in the `/etc/ssh/sshd_config` file, specify the file using " +"the [command]#AuthorizedPrincipalsFile# directive." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:790 +#, no-wrap +msgid "Generating a User Certificate" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:792 +msgid "" +"To authenticate a user to a remote host, a public key must be generated by " +"the user, passed to the CA server, signed by the CA, and then passed back to " +"be stored by the user for use when logging in to a host." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:794 +msgid "" +"On client systems, login as the user who requires the certificate. Check for " +"available keys as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:798 +#, no-wrap +msgid "~]$ [command]#ls -l ~/.ssh/#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:801 +msgid "" +"If no suitable public key exists, generate one and set the directory " +"permissions if the directory is not the default directory. For example, " +"enter the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:825 +#, no-wrap +msgid "" +"~]$ ssh-keygen -t rsa\n" +"Generating public/private rsa key pair.\n" +"Enter file in which to save the key (/home/user1/.ssh/id_rsa):\n" +"Created directory '/home/user1/.ssh'.\n" +"Enter passphrase (empty for no passphrase):\n" +"Enter same passphrase again:\n" +"Your identification has been saved in /home/user1/.ssh/id_rsa.\n" +"Your public key has been saved in /home/user1/.ssh/id_rsa.pub.\n" +"The key fingerprint is:\n" +"SHA256:y6f0DGlHe28YWotEypnhfk3WLYQ5TgaQwoSlOFwmmm0 user1@host1.example.com\n" +"The key's randomart image is:\n" +"+--[ RSA 2048]----+\n" +"| oo++. |\n" +"| o.o.o. |\n" +"| .o o . |\n" +"| oo . o |\n" +"| . oo.S |\n" +"| o=.. |\n" +"| .Eo+ |\n" +"| .= |\n" +"| .. |\n" +"+-----------------+\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:828 +msgid "" +"By default the directory permissions for a user's keys are `drwx------.`, or " +"octal 0700. If required, confirm the permissions are correct:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:836 +#, no-wrap +msgid "" +"~]$ ls -la ~/.ssh\n" +"total 16\n" +"drwx------. 2 user1 user1 4096 May 7 12:37 .\n" +"drwx------. 3 user1 user1 4096 May 7 12:37 ..\n" +"-rw-------. 1 user1 user1 1679 May 7 12:37 id_rsa\n" +"-rw-r--r--. 1 user1 user1 421 May 7 12:37 id_rsa.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:839 +msgid "" +"See xref:s2-ssh-configuration-keypairs[Using Key-based Authentication] for " +"more examples of key generation and for instructions on setting the correct " +"directory permissions." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:841 +msgid "" +"The chosen public key must be copied to the server designated as the CA, in " +"order to be signed. The secure copy command can be used to do this, the " +"command has the following format:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:845 +#, no-wrap +msgid "" +"scp ~/.ssh/id_pass:quotes[_protocol_].pub " +"pass:quotes[_admin_]@ca_server.example.com:~/keys/\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:848 +msgid "" +"Where _protocol_ is the part of the file name indicating the protocol used " +"to generate the key, for example `rsa`, _admin_ is an account on the CA " +"server, and _/keys/_ is a directory setup to receive the keys to be signed." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:850 +msgid "Copy the chosen public key to the server designated as the CA. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:855 +#, no-wrap +msgid "" +"~]$ scp ~/.ssh/id_rsa.pub admin@ca-server.example.com:~/keys/\n" +"admin@ca-server.example.com's password:\n" +"id_rsa.pub 100% 421 0.4KB/s 00:00\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:858 +msgid "" +"If you have configured the client system to trust the host signing key as " +"described in xref:proc-Trusting_the_Host_Signing_Key[Trusting the Host " +"Signing Key] then you should not see a warning about the authenticity of the " +"remote host." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:860 +msgid "On the CA server, sign the user's public key. For example, as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:865 +#, no-wrap +msgid "" +"~]# ssh-keygen -s ~/.ssh/ca_user_key -I user1 -n user1 -V -1d:+54w " +"/home/admin/keys/id_rsa.pub\n" +"Enter passphrase:\n" +"Signed user key /home/admin/keys/id_rsa-cert.pub: id \"user1\" serial 0 for " +"host_name.example.com valid from 2020-05-21T16:43:17 to " +"2021-06-03T16:43:17\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:868 +msgid "" +"Copy the resulting certificate to the user's `~/.ssh/` directory on their " +"system. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:873 +#, no-wrap +msgid "" +"~]# scp /home/admin/keys/id_rsa-cert.pub " +"user1@host_name.example.com:~/.ssh/\n" +"user1@host_name.example.com's password:\n" +"id_rsa-cert.pub 100% 1498 1.5KB/s 00:00\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:876 +msgid "" +"If using the standard file names and location then no further configuration " +"is required as the SSH daemon will search for user certificates ending in " +"`-cert.pub` and use them automatically if it finds them. Note that the " +"default location and file names for for SSH version 2 keys are: " +"`~/.ssh/id_dsa`, `~/.ssh/id_ecdsa` and `~/.ssh/id_rsa` as explained in the " +"`ssh_config(5)` manual page. If you use these locations and naming " +"conventions then there is no need for editing the configuration files to " +"enable `sshd` to present the certificate. They will be used automatically " +"when logging in to a remote system. In this is the case then skip to step 6." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:878 +msgid "" +"If required to use a non-default directory or file naming convention, then " +"as `root`, add the following line to the `/etc/ssh/ssh_config` or " +"`~/.ssh/config` files:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:882 +#, no-wrap +msgid "IdentityFile pass:quotes[_~/path/key_file_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:886 +msgid "" +"Note that this must be the private key name, do not had `.pub` or " +"`-cert.pub`. Ensure the file permission are correct. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:894 +#, no-wrap +msgid "" +"~]$ [command]#ls -la ~/.ssh/config#\n" +"-rw-rw-r--. 1 user1 user1 36 May 27 21:49 /home/user1/.ssh/config\n" +"[command]#chmod 700 ~/.ssh/config#\n" +"~]$ [command]#ls -la ~/.ssh/config#\n" +"-rwx------. 1 user1 user1 36 May 27 21:49 /home/user1/.ssh/config\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:897 +msgid "" +"This will enable the user of this system to be authenticated by a user " +"certificate when logging into a remote system configured to trust the CA " +"user certificate signing key." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:899 +msgid "" +"To test the user certificate, attempt to log into a server over SSH from the " +"user's account. You should do this as the user listed as a principle in the " +"certificate, if any are specified. You should not be prompted for a " +"password. If required, add the [option]`-v` option to the SSH command to see " +"logging information." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:901 +#, no-wrap +msgid "Signing an SSH Certificate Using a PKCS#11 Token" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:904 +msgid "" +"It is possible to sign a host key using a CA key stored in a PKCS#11 token " +"by providing the token library using the [option]`-D` and identifying the CA " +"key by providing its public half as an argument to the [option]`-s` option:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:908 +#, no-wrap +msgid "" +"ssh-keygen -s ca_host_key.pub -D libpkcs11.so -I " +"pass:quotes[_certificate_ID_] host_key.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:911 +msgid "" +"In all cases, _certificate_ID_ is a \"`key identifier`\" that is logged by " +"the server when the certificate is used for authentication." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:913 +msgid "" +"Certificates may be configured to be valid only for a set of users or host " +"names, the principals. By default, generated certificates are valid for all " +"users or hosts. To generate a certificate for a specified set of principals, " +"use a comma separated list with the [option]`-n` option as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:917 +#, no-wrap +msgid "" +"ssh-keygen -s ca_user_key.pub -D libpkcs11.so -I " +"pass:quotes[_certificate_ID_] -n pass:quotes[_user1,user2_] id_rsa.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:920 +msgid "and for hosts:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:924 +#, no-wrap +msgid "" +"ssh-keygen -s ca_host_key.pub -D libpkcs11.so -I " +"pass:quotes[_certificate_ID_] -h -n host.domain ssh_host_rsa_key.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:930 +msgid "" +"Additional limitations on the validity and use of user certificates may be " +"specified through certificate options. A certificate option may disable " +"features of the SSH session, may be valid only when presented from " +"particular source addresses or may force the use of a specific command. For " +"a list of valid certificate options, see the `ssh-keygen(1)` manual page for " +"the [option]`-O` option." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:933 +msgid "" +"Certificates may be defined to be valid for a specific lifetime. The " +"[option]`-V` option allows specifying a certificates start and end " +"times. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:937 +#, no-wrap +msgid "" +"ssh-keygen -s ca_user_key -I pass:quotes[_certificate_ID_] -V \"-1w:+54w5d\" " +"id_rsa.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:941 +msgid "" +"A certificate that is presented at a time outside this range will not be " +"considered valid. By default, certificates are valid indefinitely starting " +"from UNIX Epoch." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:943 +#, no-wrap +msgid "Viewing an SSH CA Certificate" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:946 +msgid "" +"To view a certificate, use the [option]`-L` to list the contents. For " +"example, for a user's certificate:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:965 +#, no-wrap +msgid "" +"~]$ ssh-keygen -L -f ~/.ssh/id_rsa-cert.pub\n" +"/home/user1/.ssh/id_rsa-cert.pub:\n" +" Type: ssh-rsa-cert-v01@openssh.com user certificate\n" +" Public key: RSA-CERT " +"SHA256:y6f0DGlHe28YWotEypnhfk3WLYQ5TgaQwoSlOFwmmm0\n" +" Signing CA: RSA SHA256:y6f0DGlHe28YWotEypnhfk3WLYQ5TgaQwoSlOFwmmm0\n" +" Key ID: \"user1\"\n" +" Serial: 0\n" +" Valid: from 2020-05-27T00:09:16 to 2021-06-09T00:09:16\n" +" Principals:\n" +" user1\n" +" Critical Options: (none)\n" +" Extensions:\n" +" permit-X11-forwarding\n" +" permit-agent-forwarding\n" +" permit-port-forwarding\n" +" permit-pty\n" +" permit-user-rc\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:968 +msgid "To view a host certificate:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:982 +#, no-wrap +msgid "" +"~]# ssh-keygen -L -f /etc/ssh/ssh_host_rsa_key-cert.pub\n" +"/etc/ssh/ssh_host_rsa_key-cert.pub:\n" +" Type: ssh-rsa-cert-v01@openssh.com host certificate\n" +" Public key: RSA-CERT " +"SHA256:y6f0DGlHe28YWotEypnhfk3WLYQ5TgaQwoSlOFwmmm0\n" +" Signing CA: RSA SHA256:y6f0DGlHe28YWotEypnhfk3WLYQ5TgaQwoSlOFwmmm0\n" +" Key ID: \"host_name\"\n" +" Serial: 0\n" +" Valid: from 2020-05-26T17:19:01 to 2021-06-08T17:19:01\n" +" Principals:\n" +" host_name.example.com\n" +" Critical Options: (none)\n" +" Extensions: (none)\n" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:985 +#, no-wrap +msgid "Revoking an SSH CA Certificate" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:988 +msgid "" +"If a certificate is stolen, it should be revoked. Although OpenSSH does not " +"provide a mechanism to distribute the revocation list it is still easier to " +"create the revocation list and distribute it by other means then to change " +"the CA keys and all host and user certificates previously created and " +"distributed." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:990 +msgid "" +"Keys can be revoked by adding them to the `revoked_keys` file and specifying " +"the file name in the `sshd_config` file as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:993 +#, no-wrap +msgid "RevokedKeys /etc/ssh/revoked_keys\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:996 +msgid "" +"Note that if this file is not readable, then public key authentication will " +"be refused for all users." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:998 +msgid "A new key revocation list can be generated as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1001 +#, no-wrap +msgid "~]$ ssh-keygen -kf /etc/ssh/revoked_keys -z 1 ~/.ssh/id_rsa.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1004 +msgid "To add lines to the list, use the [option]`-u` option to update the list:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1008 +#, no-wrap +msgid "" +"ssh-keygen -ukf /etc/ssh/revoked_keys -z pass:quotes[_integer_] " +"~/.ssh/id_rsa.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1011 +msgid "where _integer_ is the line number." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1013 +msgid "" +"To test if a key has been revoked, query the revocation list for the " +"presence of the key. Use a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1016 +#, no-wrap +msgid "ssh-keygen -Qf /etc/ssh/revoked_keys ~/.ssh/id_rsa.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1019 +msgid "" +"A user can revoke a CA certificate by changing the [command]#cert-authority# " +"directive to [command]#revoke# in the `known_hosts` file." +msgstr "" + +#. type: Title == +#: ./pages/infrastructure-services/OpenSSH.adoc:1021 +#, no-wrap +msgid "OpenSSH Clients" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1023 +msgid "indexterm:[OpenSSH,client]" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:1029 +msgid "" +"To connect to an OpenSSH server from a client machine, you must have the " +"[package]*openssh-clients* package installed. See " +"xref:package-management/DNF.adoc#sec-Installing[Installing Packages] for " +"more information on how to install new packages in {MAJOROSVER}." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:1033 +#, no-wrap +msgid "Using the ssh Utility" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1036 +msgid "" +"indexterm:[ssh,OpenSSH]indexterm:[OpenSSH,client,ssh] The [command]#ssh# " +"utility allows you to log in to a remote machine and execute commands " +"there. It is a secure replacement for the [command]#rlogin#, [command]#rsh#, " +"and [command]#telnet# programs." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1038 +msgid "" +"Similarly to the [command]#telnet# command, log in to a remote machine by " +"using the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1042 +#, no-wrap +msgid "[command]#ssh# _hostname_\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1045 +msgid "" +"For example, to log in to a remote machine named `penguin.example.com`, type " +"the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1049 +#, no-wrap +msgid "~]${nbsp}pass:attributes[{blank}][command]#ssh penguin.example.com#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1052 +msgid "" +"This will log you in with the same user name you are using on the local " +"machine. If you want to specify a different user name, use a command in the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1056 +#, no-wrap +msgid "" +"[command]#ssh# " +"_username_pass:attributes[{blank}]@pass:attributes[{blank}]_hostname_\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1059 +msgid "For example, to log in to `penguin.example.com` as `USER`, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1063 +#, no-wrap +msgid "~]${nbsp}pass:attributes[{blank}][command]#ssh USER@penguin.example.com#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1066 +msgid "" +"The first time you initiate a connection, you will be presented with a " +"message similar to this:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1072 +#, no-wrap +msgid "" +"The authenticity of host 'penguin.example.com' can't be established.\n" +"ECDSA key fingerprint is " +"SHA256:ZYEUaevOAEASvYjm58PiPdMebxhhlaTZBjTMr/N2I3c.\n" +"Are you sure you want to continue connecting (yes/no/[fingerprint])?\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1075 +msgid "" +"Users should always check if the fingerprint is correct before answering the " +"question in this dialog. The user can ask the administrator of the server to " +"confirm the key is correct. This should be done in a secure and previously " +"agreed way. If the user has access to the server's host keys, the " +"fingerprint can be checked by using the [command]#ssh-keygen# command as " +"follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1080 +#, no-wrap +msgid "" +"~]#{nbsp}ssh-keygen -l -f /etc/ssh/ssh_host_ecdsa_key.pub\n" +"256 SHA256:ZYEUaevOAEASvYjm58PiPdMebxhhlaTZBjTMr/N2I3c no comment (ECDSA)\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1083 +msgid "" +"Type `yes` to accept the key and confirm the connection. You will see a " +"notice that the server has been added to the list of known hosts, and a " +"prompt asking for your password:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1088 +#, no-wrap +msgid "" +"Warning: Permanently added 'penguin.example.com' (ECDSA) to the list of " +"known hosts.\n" +"USER@penguin.example.com's password:\n" +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:1090 +#, no-wrap +msgid "Updating the host key of an SSH server" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:1095 +msgid "" +"If the SSH server's host key changes, the client notifies the user that the " +"connection cannot proceed until the server's host key is deleted from the " +"`~/.ssh/known_hosts` file. Before doing this, however, contact the system " +"administrator of the SSH server to verify the server is not compromised." +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:1097 +msgid "" +"To remove a key from the `~/.ssh/known_hosts` file, issue a command as " +"follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1104 +#, no-wrap +msgid "" +"~]#{nbsp}ssh-keygen -R pass:quotes[_penguin.example.com_]\n" +"# Host penguin.example.com found: line 15 type ECDSA\n" +"/home/USER/.ssh/known_hosts updated.\n" +"Original contents retained as /home/USER/.ssh/known_hosts.old\n" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:1109 +msgid "" +"After entering the password, you will be provided with a shell prompt for " +"the remote machine." +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:1111 +msgid "" +"Alternatively, the [command]#ssh# program can be used to execute a command " +"on the remote machine without logging in to a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1115 +#, no-wrap +msgid "" +"[command]#ssh# " +"_username_pass:attributes[{blank}]@pass:attributes[{blank}]_hostname_ " +"_command_\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1118 +msgid "" +"For example, the `/etc/redhat-release` file provides information about the " +"{MAJOROS} version. To view the contents of this file on " +"`penguin.example.com`, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1124 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#ssh USER@penguin.example.com cat " +"/etc/redhat-release#\n" +"USER@penguin.example.com's password:\n" +"Fedora release 31 (Thirty One)\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1127 +msgid "" +"After you enter the correct password, the user name will be displayed, and " +"you will return to your local shell prompt." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:1129 +#, no-wrap +msgid "Using the [command]#scp# Utility" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1132 +msgid "" +"indexterm:[scp,OpenSSH]indexterm:[OpenSSH,client,scp]indexterm:[rcp] " +"[command]#scp# can be used to transfer files between machines over a secure, " +"encrypted connection. In its design, it is very similar to [command]#rcp#." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1134 +msgid "" +"To transfer a local file to a remote system, use a command in the following " +"form:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1138 +#, no-wrap +msgid "" +"[command]#scp _localfile_ " +"_username_pass:attributes[{blank}]@pass:attributes[{blank}]_hostname_:pass:attributes[{blank}]_remotefile_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1141 +msgid "" +"For example, if you want to transfer `taglist.vim` to a remote machine named " +"`penguin.example.com`, type the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1147 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#scp taglist.vim " +"USER@penguin.example.com:.vim/plugin/taglist.vim#\n" +"USER@penguin.example.com's password:\n" +"taglist.vim 100% 144KB 144.5KB/s " +"00:00\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1150 +msgid "" +"Multiple files can be specified at once. To transfer the contents of " +"`.vim/plugin/` to the same directory on the remote machine " +"`penguin.example.com`, type the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1158 +#, no-wrap +msgid "" +"~]${nbsp}scp .vim/plugin/* USER@penguin.example.com:.vim/plugin/\n" +"USER@penguin.example.com's password:\n" +"closetag.vim 100% 13KB 12.6KB/s " +"00:00\n" +"snippetsEmu.vim 100% 33KB 33.1KB/s " +"00:00\n" +"taglist.vim 100% 144KB 144.5KB/s " +"00:00\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1161 +msgid "To transfer a remote file to the local system, use the following syntax:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1165 +#, no-wrap +msgid "" +"[command]#scp " +"_username_pass:attributes[{blank}]@pass:attributes[{blank}]_hostname_:pass:attributes[{blank}]_remotefile_ " +"_localfile_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1168 +msgid "" +"For instance, to download the `.vimrc` configuration file from the remote " +"machine, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1174 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#scp " +"USER@penguin.example.com:.vimrc .vimrc#\n" +"USER@penguin.example.com's password:\n" +".vimrc 100% 2233 2.2KB/s " +"00:00\n" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:1180 +msgid "" +"The SCP protocol is not well designed and can cause unexpected results. In " +"the past it was source of several CVEs where malicious server could override " +"files in local filesystem when downloading files. It is recommended to use " +"SFTP when possible. See the next section for more information." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:1183 +#, no-wrap +msgid "Using the [command]#sftp# Utility" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1186 +msgid "" +"indexterm:[sftp,OpenSSH]indexterm:[OpenSSH,client,sftp] The [command]#sftp# " +"utility can be used to open a secure, interactive SFTP session. In its " +"design, it is similar to [command]#ftp# except that it uses a secure, " +"encrypted connection." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1188 +msgid "To connect to a remote system, use a command in the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1192 +#, no-wrap +msgid "" +"[command]#sftp " +"_username_pass:attributes[{blank}]@pass:attributes[{blank}]_hostname_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1195 +#: ./pages/infrastructure-services/OpenSSH.adoc:1238 +msgid "" +"For example, to log in to a remote machine named `penguin.example.com` with " +"`USER` as a user name, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1202 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#sftp USER@penguin.example.com#\n" +"USER@penguin.example.com's password:\n" +"Connected to penguin.example.com.\n" +"sftp>\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1205 +msgid "" +"After you enter the correct password, you will be presented with a " +"prompt. The [command]#sftp# utility accepts a set of commands similar to " +"those used by [command]#ftp# (see xref:OpenSSH.adoc#table-ssh-clients-sftp[A " +"selection of available sftp commands])." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:1207 +#, no-wrap +msgid "A selection of available sftp commands" +msgstr "" + +#. type: Table +#: ./pages/infrastructure-services/OpenSSH.adoc:1218 +#, no-wrap +msgid "" +"|Command|Description\n" +"|[command]#ls# " +"[pass:attributes[{blank}]_directory_pass:attributes[{blank}]]|List the " +"content of a remote _directory_. If none is supplied, a current working " +"directory is used by default.\n" +"|[command]#cd# _directory_|Change the remote working directory to " +"_directory_.\n" +"|[command]#mkdir# _directory_|Create a remote _directory_.\n" +"|[command]#rmdir# _directory_|Remove a remote _directory_.\n" +"|[command]#put# _localfile_ " +"[pass:attributes[{blank}]_remotefile_pass:attributes[{blank}]]|Transfer " +"_localfile_ to a remote machine.\n" +"|[command]#get# _remotefile_ " +"[pass:attributes[{blank}]_localfile_pass:attributes[{blank}]]|Transfer " +"_remotefile_ from a remote machine.\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1221 +msgid "For a complete list of available commands, see the `sftp`(1) manual page." +msgstr "" + +#. type: Title == +#: ./pages/infrastructure-services/OpenSSH.adoc:1223 +#, no-wrap +msgid "More Than a Secure Shell" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1226 +msgid "" +"A secure command line interface is just the beginning of the many ways SSH " +"can be used. Given the proper amount of bandwidth, X11 sessions can be " +"directed over an SSH channel. Or, by using TCP/IP forwarding, previously " +"insecure port connections between systems can be mapped to specific SSH " +"channels." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:1228 +#, no-wrap +msgid "X11 Forwarding" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1231 +msgid "" +"indexterm:[SSH protocol,X11 forwarding] To open an X11 session over an SSH " +"connection, use a command in the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1235 +#, no-wrap +msgid "" +"[command]#ssh -Y " +"_username_pass:attributes[{blank}]@pass:attributes[{blank}]_hostname_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1243 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#ssh -Y " +"USER@penguin.example.com#\n" +"USER@penguin.example.com's password:\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1246 +msgid "" +"When an X program is run from the secure shell prompt, the SSH client and " +"server create a new secure channel, and the X program data is sent over that " +"channel to the client machine transparently." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1248 +msgid "" +"Note that the X Window system must be installed on the remote system before " +"X11 forwarding can take place. Enter the following command as `root` to " +"install the X11 package group:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1251 +#, no-wrap +msgid "~]# dnf group install \"X Window System\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1254 +msgid "" +"X11 forwarding can be very useful. For example, X11 forwarding can be used " +"to create a secure, interactive session of the [application]*Print Settings* " +"utility. To do this, connect to the server using [application]*ssh* and " +"type:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1258 +#, no-wrap +msgid "~]${nbsp}pass:attributes[{blank}][command]#system-config-printer &#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1261 +msgid "" +"The [application]*Print Settings* tool will appear, allowing the remote user " +"to safely configure printing on the remote system." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:1263 +#, no-wrap +msgid "Port Forwarding" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1266 +msgid "" +"indexterm:[SSH protocol,port forwarding] SSH can secure otherwise insecure " +"`TCP/IP` protocols via port forwarding. When using this technique, the SSH " +"server becomes an encrypted conduit to the SSH client." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1268 +msgid "" +"Port forwarding works by mapping a local port on the client to a remote port " +"on the server. SSH can map any port from the server to any port on the " +"client. Port numbers do not need to match for this technique to work." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:1269 +#, no-wrap +msgid "Using reserved port numbers" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:1274 +msgid "" +"Setting up port forwarding to listen on ports below 1024 requires `root` " +"level access." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1278 +msgid "" +"To create a TCP/IP port forwarding channel which listens for connections on " +"the `localhost`, use a command in the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1282 +#, no-wrap +msgid "" +"[command]#ssh -L " +"_local-port_:pass:attributes[{blank}]_remote-hostname_:pass:attributes[{blank}]_remote-port_ " +"_username_pass:attributes[{blank}]@pass:attributes[{blank}]_hostname_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1285 +msgid "" +"For example, to check email on a server called `mail.example.com` using " +"`POP3` through an encrypted connection, use the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1289 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#ssh -L 1100:mail.example.com:110 " +"mail.example.com#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1292 +msgid "" +"Once the port forwarding channel is in place between the client machine and " +"the mail server, direct a POP3 mail client to use port `1100` on the " +"`localhost` to check for new email. Any requests sent to port `1100` on the " +"client system will be directed securely to the `mail.example.com` server." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1294 +msgid "" +"If `mail.example.com` is not running an SSH server, but another machine on " +"the same network is, SSH can still be used to secure part of the " +"connection. However, a slightly different command is necessary:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1298 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#ssh -L 1100:mail.example.com:110 " +"other.example.com#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1301 +msgid "" +"In this example, POP3 requests from port `1100` on the client machine are " +"forwarded through the SSH connection on port `22` to the SSH server, " +"`other.example.com`. Then, `other.example.com` connects to port `110` on " +"`mail.example.com` to check for new email. Note that when using this " +"technique, only the connection between the client system and " +"`other.example.com` SSH server is secure." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1303 +msgid "" +"Port forwarding can also be used to get information securely through network " +"firewalls. If the firewall is configured to allow SSH traffic via its " +"standard port (that is, port 22) but blocks access to other ports, a " +"connection between two hosts using the blocked ports is still possible by " +"redirecting their communication over an established SSH connection." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:1304 +#, no-wrap +msgid "A connection is only as secure as a client system" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:1309 +msgid "" +"Using port forwarding to forward connections in this manner allows any user " +"on the client system to connect to that service. If the client system " +"becomes compromised, the attacker also has access to forwarded services." +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:1311 +msgid "" +"System administrators concerned about port forwarding can disable this " +"functionality on the server by specifying a [option]`No` parameter for the " +"[option]`AllowTcpForwarding` line in `/etc/ssh/sshd_config` and restarting " +"the [command]#sshd# service." +msgstr "" + +#. type: Title == +#: ./pages/infrastructure-services/OpenSSH.adoc:1315 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1318 +msgid "" +"indexterm:[OpenSSH,additional resources]indexterm:[OpenSSL,additional " +"resources] For more information on how to configure or connect to an OpenSSH " +"server on Fedora, see the resources listed below." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:1319 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1322 +msgid "" +"`sshd`(8) — The manual page for the `sshd` daemon documents available " +"command line options and provides a complete list of supported configuration " +"files and directories." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1324 +msgid "" +"`ssh`(1) — The manual page for the [command]#ssh# client application " +"provides a complete list of available command line options and supported " +"configuration files and directories." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1326 +msgid "" +"`scp`(1) — The manual page for the [command]#scp# utility provides a more " +"detailed description of this utility and its usage." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1328 +msgid "`sftp`(1) — The manual page for the [command]#sftp# utility." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1330 +msgid "" +"`ssh-keygen`(1) — The manual page for the [command]#ssh-keygen# utility " +"documents in detail how to use it to generate, manage, and convert " +"authentication keys used by [command]#ssh#." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1332 +msgid "" +"`ssh_config`(5) — The manual page named `ssh_config` documents available SSH " +"client configuration options." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1334 +msgid "" +"`sshd_config`(5) — The manual page named `sshd_config` provides a full " +"description of available SSH daemon configuration options." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:1335 +#, no-wrap +msgid "Online Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1338 +msgid "" +"link:++https://www.openssh.com/++[OpenSSH Home Page] — The OpenSSH home page " +"containing further documentation, frequently asked questions, links to the " +"mailing lists, bug reports, and other useful resources." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1339 +msgid "" +"link:++https://www.openssl.org/++[OpenSSL Home Page] — The OpenSSL home page " +"containing further documentation, frequently asked questions, links to the " +"mailing lists, and other useful resources." +msgstr "" diff --git a/po/fr/rawhide/pages/infrastructure-services/Services_and_Daemons.po b/po/fr/rawhide/pages/infrastructure-services/Services_and_Daemons.po new file mode 100644 index 00000000000..5c7649076ba --- /dev/null +++ b/po/fr/rawhide/pages/infrastructure-services/Services_and_Daemons.po @@ -0,0 +1,560 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:6 +#, no-wrap +msgid "Services and Daemons" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:9 +msgid "" +"indexterm:[services configuration] Maintaining security on your system is " +"extremely important, and one approach for this task is to manage access to " +"system services carefully. Your system may need to provide open access to " +"particular services (for example, `httpd` if you are running a web " +"server). However, if you do not need to provide a service, you should turn " +"it off to minimize your exposure to possible bug exploits." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:11 +msgid "" +"This chapter covers the configuration of the services to be run when a " +"system is started, and provides information on how to start, stop, and " +"restart the services on the command line using the [application]*systemctl* " +"utility." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:12 +#, no-wrap +msgid "Keep the system secure" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:17 +msgid "" +"When you allow access for new services, always remember that both the " +"firewall and [application]*SELinux* need to be configured as well. One of " +"the most common mistakes committed when configuring a new service is " +"neglecting to implement the necessary firewall configuration and SELinux " +"policies to allow access for it." +msgstr "" + +#. type: Title == +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:21 +#, no-wrap +msgid "Configuring Services" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:24 +msgid "" +"indexterm:[systemctl,services configuration]indexterm:[services " +"configuration,systemctl] To allow you to configure which services are " +"started at boot time, {MAJOROS} is shipped with the [application]*systemctl* " +"command line tool." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:25 +#, no-wrap +msgid "Do not use the ntsysv and chkconfig utilities" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:30 +msgid "" +"Although it is still possible to use the [application]*ntsysv* and " +"[application]*chkconfig* utilities to manage services that have init scripts " +"installed in the `/etc/rc.d/init.d/` directory, it is advised that you use " +"the [application]*systemctl* utility." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:33 +#, no-wrap +msgid "Enabling the irqbalance service" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:38 +msgid "" +"To ensure optimal performance on POWER architecture, it is recommended that " +"the `irqbalance` service is enabled. In most cases, this service is " +"installed and configured to run during the {MAJOROSVER} installation. To " +"verify that `irqbalance` is running, type the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:42 +#, no-wrap +msgid "[command]#systemctl status irqbalance.service#\n" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:47 +#, no-wrap +msgid "Enabling the Service" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:50 +msgid "" +"To configure a service to be automatically started at boot time, use the " +"[command]#systemctl# command in the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:53 +#, no-wrap +msgid "systemctl enable service_name.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:56 +msgid "" +"The service will be started the next time you boot the system. For " +"information on how to start the service immediately, refer to " +"xref:Services_and_Daemons.adoc#s3-services-running-running[Running the " +"Service]." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:58 +#, no-wrap +msgid "Enabling the httpd service" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:62 +msgid "" +"Imagine you want to run the Apache HTTP Server on your system. Provided that " +"you have the [package]*httpd* package installed, you can enable the `httpd` " +"service by typing the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:65 +#, no-wrap +msgid "~]# systemctl enable httpd.service\n" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:70 +#, no-wrap +msgid "Disabling the Service" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:73 +msgid "" +"To disable starting a service at boot time, use the [command]#systemctl# " +"command in the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:76 +#, no-wrap +msgid "systemctl disable service_name.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:79 +msgid "" +"The next time you boot the system, the service will *not* be started. For " +"information on how to stop the service immediately, refer to " +"xref:Services_and_Daemons.adoc#s3-services-running-stopping[Stopping the " +"Service]." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:81 +#, no-wrap +msgid "Disabling the telnet service" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:85 +msgid "" +"In order to secure the system, users are advised to disable insecure " +"connection protocols such as Telnet. You can make sure that the `telnet` " +"service is disabled by running the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:88 +#, no-wrap +msgid "~]# systemctl disable telnet.service\n" +msgstr "" + +#. type: Title == +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:93 +#, no-wrap +msgid "Running Services" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:96 +msgid "" +"indexterm:[systemctl,services configuration]indexterm:[services " +"configuration,ssystemctl] The [application]*systemctl* utility also allows " +"you to determine the status of a particular service, as well as to start, " +"stop, or restart a service." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:97 +#, no-wrap +msgid "Do not use the service utility" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:102 +msgid "" +"Although it is still possible to use the [application]*service* utility to " +"manage services that have init scripts installed in the `/etc/rc.d/init.d/` " +"directory, it is advised that you use the [application]*systemctl* utility." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:106 +#, no-wrap +msgid "Checking the Service Status" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:109 +msgid "" +"To determine the status of a particular service, use the " +"[command]#systemctl# command in the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:112 +#, no-wrap +msgid "systemctl status service_name.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:115 +msgid "" +"This command provides detailed information on the service's status. However, " +"if you merely need to verify that a service is running, you can use the " +"[command]#systemctl# command in the following form instead:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:118 +#, no-wrap +msgid "systemctl is-active service_name.service\n" +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:121 +#, no-wrap +msgid "Checking the status of the httpd service" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:125 +msgid "" +"xref:Services_and_Daemons.adoc#exam-services-configuration-enabling[Enabling " +"the httpd service] illustrated how to enable starting the `httpd` service at " +"boot time. Imagine that the system has been restarted and you need to verify " +"that the service is really running. You can do so by typing the following at " +"a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:130 +#, no-wrap +msgid "" +"~]$ [command]#systemctl is-active httpd.service#\n" +"active\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:133 +msgid "" +"You can also display detailed information about the service by running the " +"following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:151 +#, no-wrap +msgid "" +"~]$ systemctl status httpd.service\n" +"httpd.service - LSB: start and stop Apache HTTP Server\n" +" Loaded: loaded (/etc/rc.d/init.d/httpd)\n" +" Active: active (running) since Mon, 23 May 2011 21:38:57 +0200; " +"27s ago\n" +" Process: 2997 ExecStart=/etc/rc.d/init.d/httpd start (code=exited, " +"status=0/SUCCESS)\n" +" Main PID: 3002 (httpd)\n" +" CGroup: name=systemd:/system/httpd.service\n" +" ├ 3002 /usr/sbin/httpd\n" +" ├ 3004 /usr/sbin/httpd\n" +" ├ 3005 /usr/sbin/httpd\n" +" ├ 3006 /usr/sbin/httpd\n" +" ├ 3007 /usr/sbin/httpd\n" +" ├ 3008 /usr/sbin/httpd\n" +" ├ 3009 /usr/sbin/httpd\n" +" ├ 3010 /usr/sbin/httpd\n" +" └ 3011 /usr/sbin/httpd\n" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:156 +msgid "To display a list of all active system services, use the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:160 +#, no-wrap +msgid "[command]#systemctl list-units --type=service#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:163 +msgid "" +"This command provides a tabular output with each line consisting of the " +"following columns:" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:165 +msgid "`UNIT` — A `systemd` unit name. In this case, a service name." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:167 +msgid "`LOAD` — Information whether the `systemd` unit was properly loaded." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:169 +msgid "`ACTIVE` — A high-level unit activation state." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:171 +msgid "`SUB` — A low-level unit activation state." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:173 +msgid "`JOB` — A pending job for the unit." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:175 +msgid "`DESCRIPTION` — A brief description of the unit." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:177 +#, no-wrap +msgid "Listing all active services" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:181 +msgid "You can list all active services by using the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:192 +#, no-wrap +msgid "" +"~]$ [command]#systemctl list-units --type=service#\n" +"UNIT LOAD ACTIVE SUB JOB DESCRIPTION\n" +"abrt-ccpp.service loaded active exited LSB: Installs coredump " +"handler which saves segfault data\n" +"abrt-oops.service loaded active running LSB: Watches system log " +"for oops messages, creates ABRT dump directories for each oops\n" +"abrtd.service loaded active running ABRT Automated Bug " +"Reporting Tool\n" +"accounts-daemon.service loaded active running Accounts Service\n" +"atd.service loaded active running Job spooling tools\n" +"_[output truncated]_\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:195 +msgid "" +"In the example above, the `abrtd` service is loaded, active, and running, " +"and it does not have any pending jobs." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:199 +#, no-wrap +msgid "Running the Service" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:202 +msgid "" +"To run a service, use the [command]#systemctl# command in the following " +"form:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:205 +#, no-wrap +msgid "systemctl start service_name.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:208 +msgid "" +"This will start the service in the current session. To configure the service " +"to be started at boot time, refer to " +"xref:Services_and_Daemons.adoc#s3-services-configuration-enabling[Enabling " +"the Service]." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:210 +#, no-wrap +msgid "Running the httpd service" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:214 +msgid "" +"xref:Services_and_Daemons.adoc#exam-services-configuration-enabling[Enabling " +"the httpd service] illustrated how to run the `httpd` service at boot " +"time. You can start the service immediately by typing the following at a " +"shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:217 +#, no-wrap +msgid "~]# systemctl start httpd.service\n" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:222 +#, no-wrap +msgid "Stopping the Service" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:225 +msgid "" +"To stop a service, use the [command]#systemctl# command in the following " +"form:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:228 +#, no-wrap +msgid "systemctl stop service_name.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:231 +msgid "" +"This will stop the service in the current session. To disable starting the " +"service at boot time, refer to " +"xref:Services_and_Daemons.adoc#s3-services-configuration-enabling[Enabling " +"the Service]." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:233 +#, no-wrap +msgid "Stopping the telnet service" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:237 +msgid "" +"xref:Services_and_Daemons.adoc#exam-services-configuration-disabling[Disabling " +"the telnet service] illustrated how to disable starting the `telnet` service " +"at boot time. You can stop the service immediately by running the following " +"command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:240 +#, no-wrap +msgid "~]# systemctl stop telnet.service\n" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:245 +#, no-wrap +msgid "Restarting the Service" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:248 +msgid "" +"To restart a service, use the [command]#systemctl# command in the following " +"form:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:251 +#, no-wrap +msgid "systemctl restart service_name.service\n" +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:254 +#, no-wrap +msgid "Restarting the sshd service" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:258 +msgid "" +"For any changes in the `/etc/ssh/sshd_config` configuration file to take " +"effect, it is required that you restart the `sshd` service. You can do so by " +"typing the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:261 +#, no-wrap +msgid "~]# systemctl restart sshd.service\n" +msgstr "" + +#. type: Title == +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:266 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:269 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:271 +msgid "`systemctl`(1) — The manual page for the [application]*systemctl* utility." +msgstr "" diff --git a/po/fr/rawhide/pages/infrastructure-services/TigerVNC.po b/po/fr/rawhide/pages/infrastructure-services/TigerVNC.po new file mode 100644 index 00000000000..0604850861f --- /dev/null +++ b/po/fr/rawhide/pages/infrastructure-services/TigerVNC.po @@ -0,0 +1,704 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/infrastructure-services/TigerVNC.adoc:6 +#, no-wrap +msgid "TigerVNC" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:10 +msgid "" +"`TigerVNC` (Tiger Virtual Network Computing) is a system for graphical " +"desktop sharing which allows you to remotely control other computers." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:14 +msgid "" +"`TigerVNC` works on the client-server network: a *server* shares its output " +"(`vncserver`) and a *client* (`vncviewer`) connects to the server." +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/TigerVNC.adoc:21 +msgid "" +"Unlike in Fedora 15 and Red{nbsp}Hat Enterprise{nbsp}Linux{nbsp}6, " +"`TigerVNC` in {MAJOROS} uses the `systemd` system management daemon for its " +"configuration. The `/etc/sysconfig/vncserver` configuration file has been " +"replaced by `/etc/systemd/system/vncserver@.service`." +msgstr "" + +#. type: Title == +#: ./pages/infrastructure-services/TigerVNC.adoc:25 +#, no-wrap +msgid "VNC Server" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:32 +msgid "" +"`vncserver` is a utility which starts a VNC (Virtual Network Computing) " +"desktop. It runs [application]*Xvnc* with appropriate options and starts a " +"window manager on the VNC desktop. `vncserver` allows users to run separate " +"sessions in parallel on a machine which can then be accessed by any number " +"of clients from anywhere." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/TigerVNC.adoc:34 +#, no-wrap +msgid "Installing VNC Server" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:37 +msgid "" +"To install the [application]*TigerVNC* server, issue the following command " +"as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:41 +#, no-wrap +msgid "# dnf install tigervnc-server\n" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/TigerVNC.adoc:44 +#, no-wrap +msgid "Configuring VNC Server" +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/TigerVNC.adoc:47 +#, no-wrap +msgid "Configuring the first VNC connection" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:49 +msgid "" +"A configuration file named `/etc/systemd/system/vncserver@.service` is " +"required. To create this file, copy the " +"`/lib/systemd/system/vncserver@.service` file as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:54 +#, no-wrap +msgid "" +"# cp /lib/systemd/system/vncserver@.service " +"/etc/systemd/system/vncserver@.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:58 +msgid "" +"There is no need to include the display number in the file name because " +"`systemd` automatically creates the appropriately named instance in memory " +"on demand, replacing `'%i'` in the service file by the display number. For a " +"single user it is not necessary to rename the file. For multiple users, a " +"uniquely named service file for each user is required, for example, by " +"adding the user name to the file name in some way. See " +"xref:TigerVNC.adoc#configuring-vncserver-2users[Configuring VNC Server for " +"Two Users] for details." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:64 +msgid "" +"Edit `/etc/systemd/system/vncserver@.service`, replacing _USER_ with the " +"actual user name. Leave the remaining lines of the file unmodified. The " +"[option]`-geometry` argument specifies the size of the VNC desktop to be " +"created; by default, it is set to `1024x768`." +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:70 +#, no-wrap +msgid "" +"ExecStart=/sbin/runuser -l _USER_ -c \"/usr/bin/vncserver %i -geometry " +"1280x1024\"\n" +"PIDFile=/home/pass:attributes[{blank}]_USER_pass:attributes[{blank}]/.vnc/%H%i.pid\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:74 +msgid "Save the changes." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:76 +msgid "To make the changes take effect immediately, issue the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:81 +#, no-wrap +msgid "# pass:quotes[`systemctl daemon-reload`]\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:86 +msgid "" +"Set the password for the user or users defined in the configuration " +"file. Note that you need to switch from `root` to _USER_ first." +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:94 +#, no-wrap +msgid "" +"# su - pass:quotes[_USER_]\n" +"$ pass:quotes[`vncpasswd`]\n" +"Password:\n" +"Verify:\n" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/TigerVNC.adoc:102 +msgid "" +"The stored password is not encrypted; anyone who has access to the password " +"file can find the plain-text password." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:106 +msgid "Proceed to xref:TigerVNC.adoc#s4-starting-vncserver[Starting VNC Server]." +msgstr "" + +#. type: Title ==== +#: ./pages/infrastructure-services/TigerVNC.adoc:108 +#, no-wrap +msgid "Configuring VNC Server for Two Users" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:112 +msgid "" +"If you want to configure more than one user on the same machine, create " +"different template-type service files, one for each user." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:116 +msgid "" +"Create two service files, for example " +"`vncserver-_USER_1_pass:attributes[{blank}]@.service` and " +"`vncserver-_USER_2_pass:attributes[{blank}]@.service`. In both these files " +"substitute _USER_ with the correct user name." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:118 +msgid "Set passwords for both users:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:130 +#, no-wrap +msgid "" +"$ su - USER_1\n" +"$ vncpasswd\n" +"Password:\n" +"Verify:\n" +"$ su - USER_2\n" +"$ vncpasswd\n" +"Password:\n" +"Verify:\n" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/TigerVNC.adoc:134 +#, no-wrap +msgid "Starting VNC Server" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:140 +msgid "" +"To start or enable the service, specify the display number directly in the " +"command. The file configured above in " +"xref:TigerVNC.adoc#configuring-vncserver[Configuring the first VNC " +"connection] works as a template, in which `%i` is substituted with the " +"display number by `systemd`. With a valid display number, execute the " +"following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:145 +#, no-wrap +msgid "# systemctl start vncserver@:display_number.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:149 +msgid "" +"You can also enable the service to start automatically at system " +"start. Then, when you log in, `vncserver` is automatically started. As " +"`root`, issue a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:154 +#, no-wrap +msgid "# systemctl enable vncserver@:display_number.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:158 +msgid "" +"At this point, other users are able to use a VNC viewer program to connect " +"to the VNC server using the display number and password defined. Provided a " +"graphical desktop is installed, an instance of that desktop will be " +"displayed. It will not be the same instance as that currently displayed on " +"the target machine." +msgstr "" + +#. type: Title ==== +#: ./pages/infrastructure-services/TigerVNC.adoc:160 +#, no-wrap +msgid "Configuring VNC Server for Two Users and Two Different Displays" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:165 +msgid "" +"For the two configured VNC servers, vncserver-USER_1@.service and " +"vncserver-USER_2@.service, you can enable different display numbers. For " +"example, the following commands will cause a VNC server for USER_1 to start " +"on display 3, and a VNC server for USER_2 to start on display 5:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:171 +#, no-wrap +msgid "" +"# systemctl start vncserver-USER_1@:3.service\n" +"# systemctl start vncserver-USER_2@:5.service\n" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/TigerVNC.adoc:175 +#, no-wrap +msgid "Terminating a VNC Session" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:179 +msgid "" +"Similarly to enabling the `vncserver` service, you can disable the automatic " +"start of the service at system start:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:184 +#, no-wrap +msgid "# systemctl disable vncserver@:display_number.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:189 +msgid "" +"Or, when your system is running, you can stop the service by issuing the " +"following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:194 +#, no-wrap +msgid "# systemctl stop vncserver@:display_number.service\n" +msgstr "" + +#. type: Title == +#: ./pages/infrastructure-services/TigerVNC.adoc:198 +#, no-wrap +msgid "VNC Viewer" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:202 +msgid "" +"`vncviewer` is the program which shows the shared graphical user interfaces " +"and controls the server." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:207 +msgid "" +"For operating the `vncviewer`, there is a pop-up menu containing entries " +"which perform various actions such as switching in and out of full-screen " +"mode or quitting the viewer. Alternatively, you can operate `vncviewer` " +"through the terminal. Enter [command]#vncviewer -h# on the command line to " +"list `vncviewer`pass:attributes[{blank}]'s parameters." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/TigerVNC.adoc:209 +#, no-wrap +msgid "Installing VNC Viewer" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:212 +msgid "" +"To install the [application]*TigerVNC* client, " +"[command]#vncviewer#pass:attributes[{blank}]>, issue the following command " +"as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:216 +#, no-wrap +msgid "# dnf install tigervnc\n" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/TigerVNC.adoc:219 +#, no-wrap +msgid "Connecting to VNC Server" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:223 +msgid "" +"Once the VNC server is configured, you can connect to it from any VNC " +"viewer. In order to do so, issue the [command]#vncviewer# command in the " +"following format:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:227 +#, no-wrap +msgid "vncviewer pass:quotes[_address_]:pass:quotes[_port_number_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:230 +msgid "Where _address_ is an `IP` or host name." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/TigerVNC.adoc:232 +#, no-wrap +msgid "One Client Connecting to VNC Server" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/TigerVNC.adoc:237 +msgid "" +"With the `IP` address `192.168.0.4` and display number *3* the command looks " +"as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:242 +#, no-wrap +msgid "[command]#$ vncviewer 192.168.0.4:3#\n" +msgstr "" + +#. type: Title ==== +#: ./pages/infrastructure-services/TigerVNC.adoc:248 +#, no-wrap +msgid "Configuring the Firewall for VNC" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/TigerVNC.adoc:252 +msgid "" +"When using a non-encrypted connection, `firewalld` might block the " +"connection. To allow `firewalld` to pass the VNC packets, you can open " +"specific ports to `TCP` traffic. When using the [option]`-via` option, " +"traffic is redirected over `SSH` which is enabled by default in `firewalld`." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:259 +msgid "" +"The default port of VNC server is 5900. To reach the port through which a " +"remote desktop will be accessible, sum the default port and the user's " +"assigned display number. For example, for the second port: 2 + 5900 = 5902." +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/TigerVNC.adoc:263 +msgid "" +"For displays `0` to `3`, make use of `firewalld`pass:attributes[{blank}]'s " +"support for the VNC service by means of the [option]`service` option as " +"described below. Note that for display numbers greater than `3`, the " +"corresponding ports will have to be opened specifically as explained in " +"xref:TigerVNC.adoc#proc-Opening-Ports_in_firewalld[Opening Ports in " +"firewalld]." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/TigerVNC.adoc:265 +#, no-wrap +msgid "Enabling VNC Service in firewalld" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/TigerVNC.adoc:268 +msgid "" +"Run the following command to see the information concerning `firewalld` " +"settings:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:273 +#, no-wrap +msgid "[command]#$ firewall-cmd --list-all#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:277 +msgid "" +"To allow all VNC connections from a specific address, use a command as " +"follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:282 +#, no-wrap +msgid "" +"# firewall-cmd --add-rich-rule='rule family=\"ipv4\" source " +"address=\"192.168.122.116\" service name=vnc-server accept'\n" +"success\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:285 +msgid "" +"See the " +"link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Security_Guide/++[Red{nbsp}Hat " +"Enterprise{nbsp}Linux{nbsp}7 Security Guide] for more information on the use " +"of firewall rich language commands." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:287 +msgid "To verify the above settings, use a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:301 +#, no-wrap +msgid "" +"# firewall-cmd --list-all\n" +"public (default, active)\n" +" interfaces: bond0 bond0.192\n" +" sources:\n" +" services: dhcpv6-client ssh\n" +" ports:\n" +" masquerade: no\n" +" forward-ports:\n" +" icmp-blocks:\n" +" rich rules:\n" +"\trule family=\"ipv4\" source address=\"192.168.122.116\" service " +"name=\"vnc-server\" accept\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:304 +msgid "" +"To open a specific port or range of ports make use of the " +"[option]`--add-port` option to the [command]#firewall-cmd# command Line " +"tool. For example, VNC display `4` requires port `5904` to be opened for " +"`TCP` traffic." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/TigerVNC.adoc:306 +#, no-wrap +msgid "Opening Ports in firewalld" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:308 +msgid "" +"To open a port for `TCP` traffic in the public zone, issue a command as " +"`root` as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:313 +#, no-wrap +msgid "" +"# firewall-cmd --zone=public --add-port=5904/tcp\n" +"success\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:316 +msgid "" +"To view the ports that are currently open for the public zone, issue a " +"command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:321 +#, no-wrap +msgid "" +"# firewall-cmd --zone=public --list-ports\n" +"5904/tcp\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:324 +msgid "" +"A port can be removed using the [command]#firewall-cmd " +"--zone=pass:attributes[{blank}]_zone_ " +"--remove-port=pass:attributes[{blank}]_number/protocol_pass:attributes[{blank}]# " +"command." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:326 +msgid "" +"For more information on opening and closing ports in `firewalld`, see the " +"link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Security_Guide/++[Red{nbsp}Hat " +"Enterprise{nbsp}Linux{nbsp}7 Security Guide]." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/TigerVNC.adoc:328 +#, no-wrap +msgid "Connecting to VNC Server Using SSH" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:331 +#, no-wrap +msgid "" +"*VNC* is a clear text network protocol with no security against possible " +"attacks on the communication. To make the communication secure, you can " +"encrypt your server-client connection by using the [option]`-via` " +"option. This will create an `SSH` tunnel between the VNC server and the " +"client.\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:333 +msgid "" +"The format of the command to encrypt a VNC server-client connection is as " +"follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:338 +#, no-wrap +msgid "$ vncviewer -via user@host:display_number\n" +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/TigerVNC.adoc:342 +#, no-wrap +msgid "Using the -via Option" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/TigerVNC.adoc:346 +msgid "To connect to a VNC server using `SSH`, enter a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:351 +#, no-wrap +msgid "$ vncviewer -via USER_2@192.168.2.101:3\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:355 +msgid "" +"When you are prompted to, type the password, and confirm by pressing " +"kbd:[Enter]." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:357 +msgid "A window with a remote desktop appears on your screen." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/TigerVNC.adoc:360 +#, no-wrap +msgid "Restricting VNC Access" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/TigerVNC.adoc:364 +msgid "" +"If you prefer only encrypted connections, you can prevent unencrypted " +"connections altogether by using the [option]`-localhost` option in the " +"`systemd.service` file, the ExecStart line:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:368 +#, no-wrap +msgid "ExecStart=/sbin/runuser -l _user_ -c \"/usr/bin/vncserver -localhost %i\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:371 +msgid "" +"This will stop `vncserver` from accepting connections from anything but the " +"local host and port-forwarded connections sent using `SSH` as a result of " +"the [option]`-via` option." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:373 +msgid "" +"For more information on using `SSH`, see " +"xref:infrastructure-services/OpenSSH.adoc#ch-OpenSSH[OpenSSH]." +msgstr "" + +#. type: Title == +#: ./pages/infrastructure-services/TigerVNC.adoc:375 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:378 +msgid "For more information about TigerVNC, see the resources listed below." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/TigerVNC.adoc:379 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:382 +msgid "`vncserver(1)` — The *VNC* server manual pages." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:384 +msgid "`vncviewer(1)` — The *VNC* viewer manual pages." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:385 +msgid "`vncpasswd(1)` — The *VNC* password manual pages." +msgstr "" diff --git a/po/fr/rawhide/pages/infrastructure-services/intro-infrastructure-services.po b/po/fr/rawhide/pages/infrastructure-services/intro-infrastructure-services.po new file mode 100644 index 00000000000..ecd9b5e42b6 --- /dev/null +++ b/po/fr/rawhide/pages/infrastructure-services/intro-infrastructure-services.po @@ -0,0 +1,30 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/infrastructure-services/intro-infrastructure-services.adoc:1 +#, no-wrap +msgid "Infrastructure Services" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/intro-infrastructure-services.adoc:3 +msgid "" +"This part provides information on how to configure services and daemons, " +"configure authentication, and enable remote logins." +msgstr "" diff --git a/po/fr/rawhide/pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.po b/po/fr/rawhide/pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.po new file mode 100644 index 00000000000..473542f4776 --- /dev/null +++ b/po/fr/rawhide/pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.po @@ -0,0 +1,1019 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:6 +#, no-wrap +msgid "Manually Upgrading the Kernel" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:9 +msgid "" +"indexterm:[kernel,upgrading the " +"kernel]indexterm:[kernel,package]indexterm:[kernel,RPM " +"package]indexterm:[package,kernel RPM] The {MAJOROS} kernel is custom-built " +"by the {MAJOROS} kernel team to ensure its integrity and compatibility with " +"supported hardware. Before a kernel is released, it must first pass a " +"rigorous set of quality assurance tests." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:11 +msgid "" +"{MAJOROS} kernels are packaged in the RPM format so that they are easy to " +"upgrade and verify using the [application]*DNF* or [application]*PackageKit* " +"package managers. [application]*PackageKit* automatically queries the DNF " +"repositories and informs you of packages with available updates, including " +"kernel packages." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:14 +msgid "" +"This chapter is therefore *only* useful for users who need to manually " +"update a kernel package using the [command]#rpm# command instead of " +"[command]#dnf#. indexterm:[kernel,installing kernel " +"packages]indexterm:[installing the kernel]" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:15 +#, no-wrap +msgid "Use DNF to install kernels whenever possible" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:20 +msgid "" +"Whenever possible, use either the [application]*DNF* or " +"[application]*PackageKit* package manager to install a new kernel because " +"they always *install* a new kernel instead of replacing the current one, " +"which could potentially leave your system unable to boot." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:24 +msgid "" +"indexterm:[kernel,installing kernel packages] For more information on " +"installing kernel packages with [application]*DNF*, see " +"xref:package-management/DNF.adoc#sec-Updating_Packages[Updating Packages]." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:26 +#, no-wrap +msgid "Overview of Kernel Packages" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:29 +msgid "" +"indexterm:[kernel,kernel packages]indexterm:[kernel package,kernel,for " +"single, multicore and multiprocessor systems]indexterm:[packages,kernel,for " +"single, multicore and multiprocessor systems]indexterm:[kernel " +"package,kernel-devel,kernel headers and " +"makefiles]indexterm:[packages,kernel-devel,kernel headers and " +"makefiles]indexterm:[kernel package,kernel-headers,C header files " +"files]indexterm:[packages,kernel-headers,C header files " +"files]indexterm:[kernel package,linux-firmware,firmware " +"files]indexterm:[packages,linux-firmware,firmware files]indexterm:[kernel " +"package,perf,firmware files]indexterm:[packages,perf,firmware files] " +"{MAJOROS} contains the following kernel packages:" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:31 +msgid "" +"[package]*kernel* — Contains the kernel for single, multicore and " +"multiprocessor systems." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:33 +msgid "" +"[package]*kernel-debug* — Contains a kernel with numerous debugging options " +"enabled for kernel diagnosis, at the expense of reduced performance." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:35 +msgid "" +"[package]*kernel-devel* — Contains the kernel headers and makefiles " +"sufficient to build modules against the [package]*kernel* package." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:37 +msgid "" +"[package]*kernel-debug-devel* — Contains the development version of the " +"kernel with numerous debugging options enabled for kernel diagnosis, at the " +"expense of reduced performance." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:39 +msgid "" +"[package]*kernel-headers* — Includes the C header files that specify the " +"interface between the Linux kernel and user-space libraries and " +"programs. The header files define structures and constants that are needed " +"for building most standard programs." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:41 +msgid "" +"[package]*linux-firmware* — Contains all of the firmware files that are " +"required by various devices to operate." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:43 +msgid "" +"[package]*perf* — This package contains supporting scripts and documentation " +"for the [application]*perf* tool shipped in each kernel image subpackage." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:45 +msgid "" +"[package]*kernel-abi-whitelists* — Contains information pertaining to the " +"{MAJOROS} kernel ABI, including a lists of kernel symbols that are needed by " +"external Linux kernel modules and a [package]*dnf* plug-in to aid " +"enforcement." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:47 +msgid "" +"[package]*kernel-tools* — Contains tools for manipulating the Linux kernel " +"and supporting documentation." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:49 +#, no-wrap +msgid "Preparing to Upgrade" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:52 +msgid "" +"indexterm:[boot " +"media]indexterm:[kernel,upgrading,preparing]indexterm:[kernel " +"upgrading,preparing]indexterm:[kernel,upgrading,working boot media] Before " +"upgrading the kernel, it is recommended that you take some precautionary " +"steps." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:54 +msgid "" +"First, ensure that working boot media exists for the system in case a " +"problem occurs. If the boot loader is not configured properly to boot the " +"new kernel, you can use this media to boot into {MAJOROS}." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:56 +msgid "" +"USB media often comes in the form of flash devices sometimes called _pen " +"drives_, _thumb disks_, or _keys_, or as an externally-connected hard disk " +"device. Almost all media of this type is formatted as a `VFAT` file " +"system. You can create bootable USB media on media formatted as `ext2`, " +"`ext3`, `ext4`, or `VFAT`." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:58 +msgid "" +"You can transfer a distribution image file or a minimal boot media image " +"file to USB media. Make sure that sufficient free space is available on the " +"device. Around 4 GB is required for a distribution DVD image, around 700 MB " +"for a distribution CD image, or around 10 MB for a minimal boot media image." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:60 +msgid "" +"You must have a copy of the `boot.iso` file from a {MAJOROS} installation " +"DVD, or installation CD-ROM#1, and you need a USB storage device formatted " +"with the `VFAT` file system and around 16 MB of free space. The following " +"procedure will not affect existing files on the USB storage device unless " +"they have the same path names as the files that you copy onto it. To create " +"USB boot media, perform the following commands as the `root` user:" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:62 +msgid "Install the [application]*SYSLINUX* bootloader on the USB storage device:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:66 +#, no-wrap +msgid "~]#{nbsp}syslinux /dev/sdX1\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:69 +msgid "...where _sdX_ is the device name." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:71 +msgid "Create mount points for `boot.iso` and the USB storage device:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:75 +#, no-wrap +msgid "~]#{nbsp}mkdir /mnt/isoboot /mnt/diskboot\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:78 +msgid "Mount `boot.iso`:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:82 +#, no-wrap +msgid "~]#{nbsp}mount -o loop boot.iso /mnt/isoboot\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:85 +msgid "Mount the USB storage device:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:89 +#, no-wrap +msgid "~]#{nbsp}mount /dev/sdX1 /mnt/diskboot\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:92 +msgid "" +"Copy the [application]*ISOLINUX* files from the `boot.iso` to the USB " +"storage device:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:96 +#, no-wrap +msgid "~]#{nbsp}cp /mnt/isoboot/isolinux/* /mnt/diskboot\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:99 +msgid "" +"Use the `isolinux.cfg` file from `boot.iso` as the `syslinux.cfg` file for " +"the USB device:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:103 +#, no-wrap +msgid "" +"~]#{nbsp}grep -v local /mnt/isoboot/isolinux/isolinux.cfg > " +"/mnt/diskboot/syslinux.cfg\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:107 +msgid "Unmount `boot.iso` and the USB storage device:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:111 +#, no-wrap +msgid "~]#{nbsp}umount /mnt/isoboot /mnt/diskboot\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:115 +msgid "" +"You should reboot the machine with the boot media and verify that you are " +"able to boot with it before continuing." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:117 +msgid "" +"Alternatively, on systems with a floppy drive, you can create a boot " +"diskette by installing the [package]*mkbootdisk* package and running the " +"[command]#mkbootdisk# command as `root`. See [command]#man mkbootdisk# man " +"page after installing the package for usage information." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:119 +msgid "" +"To determine which kernel packages are installed, execute the command " +"[command]#dnf list installed \"kernel-*\"# at a shell prompt. The output " +"will comprise some or all of the following packages, depending on the " +"system's architecture, and the version numbers might differ:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:131 +#, no-wrap +msgid "" +"~]# dnf list installed \"kernel-*\"\n" +"Last metadata expiration check performed 0:28:51 ago on Tue May 26 21:22:39 " +"2015.\n" +"Installed Packages\n" +"kernel-core.x86_64 4.0.3-300.fc22 " +"@System\n" +"kernel-core.x86_64 4.0.4-300.fc22 " +"@System\n" +"kernel-core.x86_64 4.0.4-301.fc22 " +"@System\n" +"kernel-headers.x86_64 4.0.4-301.fc22 " +"@System\n" +"kernel-modules.x86_64 4.0.3-300.fc22 " +"@System\n" +"kernel-modules.x86_64 4.0.4-300.fc22 " +"@System\n" +"kernel-modules.x86_64 4.0.4-301.fc22 " +"@System\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:134 +msgid "" +"From the output, determine which packages need to be downloaded for the " +"kernel upgrade. For a single processor system, the only required package is " +"the [package]*kernel* package. See " +"xref:Manually_Upgrading_the_Kernel.adoc#s1-kernel-packages[Overview of " +"Kernel Packages] for descriptions of the different packages." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:136 +#, no-wrap +msgid "Downloading the Upgraded Kernel" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:139 +msgid "" +"indexterm:[kernel,downloading]indexterm:[kernel,upgrade kernel " +"available]indexterm:[kernel,upgrade kernel available,via Fedora Update " +"System]indexterm:[kernel,upgrade kernel available,Security Advisories] There " +"are several ways to determine if an updated kernel is available for the " +"system." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:141 +msgid "" +"Via Fedora Update System — Download and install the kernel RPM packages. For " +"more information, refer to link:++https://bodhi.fedoraproject.org/++[]." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:143 +msgid "Via `_DNF_` using check-update:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:145 +#, no-wrap +msgid "dnf check-update --enablerepo=updates-testing\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:148 +msgid "" +"To install the kernel manually, continue to " +"xref:Manually_Upgrading_the_Kernel.adoc#s1-kernel-perform-upgrade[Performing " +"the Upgrade]." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:150 +#, no-wrap +msgid "Performing the Upgrade" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:153 +msgid "" +"indexterm:[kernel,performing kernel upgrade] After retrieving all of the " +"necessary packages, it is time to upgrade the existing kernel." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:154 +#, no-wrap +msgid "Keep the old kernel when performing the upgrade" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:159 +msgid "" +"It is strongly recommended that you keep the old kernel in case there are " +"problems with the new kernel." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:163 +msgid "" +"At a shell prompt, change to the directory that contains the kernel RPM " +"packages. Use [option]`-i` argument with the [command]#rpm# command to keep " +"the old kernel. Do *not* use the [option]`-U` option, since it overwrites " +"the currently installed kernel, which creates boot loader problems. For " +"example:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:167 +#, no-wrap +msgid "~]#{nbsp}rpm -ivh kernel-kernel_version.arch.rpm\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:170 +msgid "" +"The next step is to verify that the initial RAM disk image has been " +"created. See " +"xref:kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc#sec-Verifying_the_Initial_RAM_Disk_Image[Verifying " +"the Initial RAM Disk Image] for details." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:172 +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:181 +#, no-wrap +msgid "Verifying the Initial RAM Disk Image" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:175 +msgid "" +"indexterm:[initial RAM disk image,verifying] The job of the initial RAM disk " +"image is to preload the block device modules, such as for IDE, SCSI or RAID, " +"so that the root file system, on which those modules normally reside, can " +"then be accessed and mounted. On {MAJOROSVER} systems, whenever a new kernel " +"is installed using either the [application]*DNF*, [application]*PackageKit*, " +"or [application]*RPM* package manager, the [application]*Dracut* utility is " +"always called by the installation scripts to create an _initramfs_ (initial " +"RAM disk image)." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:177 +msgid "" +"On all architectures other than IBM eServer System i (see " +"xref:Manually_Upgrading_the_Kernel.adoc#bh-Verifying_the_Initial_RAM_Disk_Image_and_Kernel_on_IBM_eServer_System_i[Verifying " +"the Initial RAM Disk Image and Kernel on IBM eServer System i]), you can " +"create an `initramfs` by running the [command]#dracut# command. However, you " +"usually don't need to create an `initramfs` manually: this step is " +"automatically performed if the kernel and its associated packages are " +"installed or upgraded from RPM packages distributed by {OSORG}." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:179 +msgid "" +"On architectures that use the GRUB 2 boot loader, you can verify that an " +"`initramfs` corresponding to your current kernel version exists and is " +"specified correctly in the `/boot/grub2/grub.cfg` configuration file by " +"following this procedure:" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:183 +msgid "" +"As `root`, list the contents in the `/boot/` directory and find the kernel " +"(`vmlinuz-_kernel_version_pass:attributes[{blank}]`) and " +"`initramfs-_kernel_version_pass:attributes[{blank}]` with the latest (most " +"recent) version number:" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:185 +#, no-wrap +msgid "Ensuring that the kernel and initramfs versions match" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:211 +#, no-wrap +msgid "" +"~]# ls /boot/\n" +"config-3.17.4-302.fc21.x86_64\n" +"config-3.17.6-300.fc21.x86_64\n" +"config-3.17.7-300.fc21.x86_64\n" +"efi\n" +"elf-memtest86+-5.01\n" +"extlinux\n" +"grub2\n" +"initramfs-0-rescue-db90b4e3715b42daa871351439343ca4.img\n" +"initramfs-3.17.4-302.fc21.x86_64.img\n" +"initramfs-3.17.6-300.fc21.x86_64.img\n" +"initramfs-3.17.7-300.fc21.x86_64.img\n" +"initrd-plymouth.img\n" +"lost+found\n" +"memtest86+-5.01\n" +"System.map-3.17.4-302.fc21.x86_64\n" +"System.map-3.17.6-300.fc21.x86_64\n" +"System.map-3.17.7-300.fc21.x86_64\n" +"vmlinuz-0-rescue-db90b4e3715b42daa871351439343ca4\n" +"vmlinuz-3.17.4-302.fc21.x86_64\n" +"vmlinuz-3.17.6-300.fc21.x86_64\n" +"vmlinuz-3.17.7-300.fc21.x86_64\n" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:216 +msgid "" +"xref:Manually_Upgrading_the_Kernel.adoc#ex-Ensuring_that_the_kernel_and_initramfs_versions_match[Ensuring " +"that the kernel and initramfs versions match] shows that:" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:218 +msgid "" +"we have three kernels installed (or, more correctly, three kernel files are " +"present in the `/boot/` directory)," +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:220 +msgid "the latest kernel is `vmlinuz-3.17.7-300.fc21.x86_64`, and" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:222 +msgid "" +"an `initramfs` file matching our kernel version, " +"`initramfs-3.17.7-300.fc21.x86_64.img`, also exists." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:224 +#, no-wrap +msgid "initrd files in the /boot/ directory are not the same as initramfs files" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:229 +msgid "" +"In the `/boot/` directory you might find several " +"`initrd-_kernel_version_pass:attributes[{blank}]kdump.img` files. These are " +"special files created by the `kdump` mechanism for kernel debugging " +"purposes, are not used to boot the system, and can safely be ignored. For " +"more information on `kdump`, see the " +"link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Kernel_Crash_Dump_Guide/++[Red{nbsp}Hat " +"Enterprise{nbsp}Linux{nbsp}7 Kernel Crash Dump Guide]." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:233 +msgid "" +"(Optional) If your `initramfs-_kernel_version_pass:attributes[{blank}]` file " +"does not match the version of the latest kernel in `/boot`, or, in certain " +"other situations, you might need to generate an `initramfs` file with the " +"[application]*Dracut* utility. Simply invoking [command]#dracut# as `root` " +"without options causes it to generate an `initramfs` file in the `/boot/` " +"directory for the latest kernel present in that directory:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:236 +#, no-wrap +msgid "~]# dracut\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:239 +msgid "" +"You must use the [option]`--force` option if you want [command]#dracut# to " +"overwrite an existing `initramfs` (for example, if your `initramfs` has " +"become corrupt). Otherwise [command]#dracut# will refuse to overwrite the " +"existing `initramfs` file:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:243 +#, no-wrap +msgid "" +"~]# dracut\n" +"F: Will not override existing initramfs " +"(/boot/initramfs-3.17.7-300.fc21.x86_64.img) without --force\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:246 +msgid "" +"You can create an initramfs in the current directory by calling " +"[command]#dracut _initramfs_name_ _kernel_version_pass:attributes[{blank}]#, " +"for example:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:249 +#, no-wrap +msgid "~]# dracut \"initramfs-$(uname -r).img\" $(uname -r)\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:252 +msgid "" +"If you need to specify specific kernel modules to be preloaded, add the " +"names of those modules (minus any file name suffixes such as `.ko`) inside " +"the parentheses of the `add_dracutmodules=\"pass:attributes[{blank}]_module_ " +"_more_modules_pass:attributes[{blank}]\"` directive of the " +"`/etc/dracut.conf` configuration file. You can list the file contents of an " +"`initramfs` image file created by dracut by using the [command]#lsinitrd " +"_initramfs_file_pass:attributes[{blank}]# command:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:259 +#, no-wrap +msgid "" +"~]# lsinitrd /boot/initramfs-3.17.7-300.fc21.x86_64.img\n" +"Image: /boot/initramfs-3.17.7-300.fc21.x86_64.img: 18M\n" +"========================================================================\n" +"Version: dracut-038-31.git20141204.fc21\n" +"[output truncated]\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:262 +msgid "" +"See [command]#man dracut# and [command]#man dracut.conf# for more " +"information on options and usage." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:264 +msgid "" +"Examine the `/boot/grub2/grub.cfg` configuration file to ensure that an " +"`initramfs-_kernel_version_.img` file exists for the kernel version you are " +"booting. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:271 +#, no-wrap +msgid "" +"~]# grep initramfs /boot/grub2/grub.cfg\n" +"\tinitrd16 /initramfs-3.17.7-300.fc21.x86_64.img\n" +"\tinitrd16 /initramfs-3.17.6-300.fc21.x86_64.img\n" +"\tinitrd16 /initramfs-3.17.4-302.fc21.x86_64.img\n" +"\tinitrd16 /initramfs-0-rescue-db90b4e3715b42daa871351439343ca4.img\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:274 +msgid "" +"See xref:Manually_Upgrading_the_Kernel.adoc#s1-kernel-boot-loader[Verifying " +"the Boot Loader] for more information on how to read and update the " +"`/boot/grub2/grub.cfg` file." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:276 +#, no-wrap +msgid "Verifying the Initial RAM Disk Image and Kernel on IBM eServer System i" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:279 +msgid "" +"On IBM eServer System i machines, the initial RAM disk and kernel files are " +"combined into a single file, which is created with the [command]#addRamDisk# " +"command. This step is performed automatically if the kernel and its " +"associated packages are installed or upgraded from the RPM packages " +"distributed by {OSORG}; thus, it does not need to be executed manually. To " +"verify that it was created, run the following command as `root` to make sure " +"the `/boot/vmlinitrd-_kernel_version_pass:attributes[{blank}]` file already " +"exists:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:283 +#, no-wrap +msgid "[command]#ls -l /boot/#\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:286 +msgid "The _kernel_version_ should match the version of the kernel just installed." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:288 +#, no-wrap +msgid "Verifying the Boot Loader" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:291 +msgid "" +"indexterm:[boot loader,verifying] When you install a kernel using " +"[command]#rpm#, the kernel package creates an entry in the boot loader " +"configuration file for that new kernel. However, [command]#rpm# does *not* " +"configure the new kernel to boot as the default kernel. You must do this " +"manually when installing a new kernel with [command]#rpm#." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:293 +msgid "" +"It is always recommended to double-check the boot loader configuration file " +"after installing a new kernel with [command]#rpm# to ensure that the " +"configuration is correct. Otherwise, the system might not be able to boot " +"into {MAJOROS} properly. If this happens, boot the system with the boot " +"media created earlier and re-configure the boot loader." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:295 +msgid "" +"In the following table, find your system's architecture to determine the " +"boot loader it uses, and then click on the \"`See`\" link to jump to the " +"correct instructions for your system." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:297 +#, no-wrap +msgid "Boot loaders by architecture" +msgstr "" + +#. type: Table +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:307 +#, no-wrap +msgid "" +"|Architecture|Boot Loader|See\n" +"|x86|GRUB 2|xref:Manually_Upgrading_the_Kernel.adoc#s3-kernel-boot-loader-grub[Configuring " +"the GRUB 2 Boot Loader]\n" +"|AMD AMD64 *or* Intel " +"64|GRUB 2|xref:Manually_Upgrading_the_Kernel.adoc#s3-kernel-boot-loader-grub[Configuring " +"the GRUB 2 Boot Loader]\n" +"|IBM eServer System i|OS/400|xref:Manually_Upgrading_the_Kernel.adoc#s2-kernel-boot-loader-iseries[Configuring " +"the OS/400 Boot Loader]\n" +"|IBM eServer System p|YABOOT|xref:Manually_Upgrading_the_Kernel.adoc#s2-kernel-boot-loader-pseries[Configuring " +"the YABOOT Boot Loader]\n" +"|IBM System z|z/IPL|—\n" +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:310 +#, no-wrap +msgid "Configuring the GRUB 2 Boot Loader" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:313 +msgid "" +"indexterm:[GRUB 2 boot loader,configuring]indexterm:[GRUB 2 boot " +"loader,configuration file] {MAJOROSVER} is distributed with GRUB 2, which " +"reads its configuration from the `/boot/grub2/grub.cfg` file. This file is " +"generated by the [application]*grub2-mkconfig* utility based on Linux " +"kernels located in the `/boot` directory, template files located in " +"`/etc/grub.d/`, and custom settings in the `/etc/default/grub` file and is " +"automatically updated each time you install a new kernel from an RPM " +"package. To update this configuration file manually, type the following at a " +"shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:317 +#, no-wrap +msgid "[command]#grub2-mkconfig# [option]`-o` [option]`/boot/grub2/grub.cfg`\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:320 +msgid "" +"Among various code snippets and directives, the `/boot/grub2/grub.cfg` " +"configuration file contains one or more `menuentry` blocks, each " +"representing a single GRUB 2 boot menu entry. These blocks always start with " +"the `menuentry` keyword followed by a title, list of options, and opening " +"curly bracket, and end with a closing curly bracket. Anything between the " +"opening and closing bracket should be indented. For example, the following " +"is a sample `menuentry` block for Fedora 21 with Linux kernel " +"3.17.6-300.fc21.x86_64:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:337 +#, no-wrap +msgid "" +"menuentry 'Fedora (3.17.6-300.fc21.x86_64) 21 (Twenty One)' --class fedora " +"--class gnu-linux --class gnu --class os --unrestricted $menuentry_id_option " +"'gnulinux-3.17.4-301.fc21.x86_64-advanced-effee860-8d55-4e4a-995e-b4c88f9ac9f0' " +"{\n" +" load_video\n" +" set gfxpayload=keep\n" +" insmod gzio\n" +" insmod part_msdos\n" +" insmod ext2\n" +" set root='hd0,msdos1'\n" +" if [ x$feature_platform_search_hint = xy ]; then\n" +" search --no-floppy --fs-uuid --set=root --hint='hd0,msdos1' " +"f19c92f4-9ead-4207-b46a-723b7a2c51c8\n" +" else\n" +" search --no-floppy --fs-uuid --set=root " +"f19c92f4-9ead-4207-b46a-723b7a2c51c8\n" +" fi\n" +" linux16 /vmlinuz-3.17.6-300.fc21.x86_64 root=/dev/mapper/fedora-root " +"ro rd.lvm.lv=fedora/swap rd.lvm.lv=fedora/root rhgb quiet LANG=en_US.UTF-8\n" +" initrd16 /initramfs-3.17.6-300.fc21.x86_64.img\n" +"}\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:340 +msgid "" +"Each `menuentry` block that represents an installed Linux kernel contains " +"`linux` and `initrd` directives followed by the path to the kernel and the " +"`initramfs` image respectively. If a separate `/boot` partition was created, " +"the paths to the kernel and the `initramfs` image are relative to " +"`/boot`. In the example above, the `initrd16 " +"/initramfs-3.17.6-300.fc21.x86_64.img` line means that the `initramfs` image " +"is actually located at `/boot/initramfs-3.17.6-300.fc21.x86_64.img` when the " +"root file system is mounted, and likewise for the kernel path." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:342 +msgid "" +"The kernel version number as given on the `linux " +"/vmlinuz-_kernel_version_pass:attributes[{blank}]` line must match the " +"version number of the `initramfs` image given on the `initrd " +"/initramfs-_kernel_version_.img` line of each `menuentry` block. For more " +"information on how to verify the initial RAM disk image, refer to " +"xref:Manually_Upgrading_the_Kernel.adoc#procedure-Verifying_the_Initial_RAM_Disk_Image[Verifying " +"the Initial RAM Disk Image]." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:344 +#, no-wrap +msgid "The initrd directive in grub.cfg refers to an initramfs image" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:349 +msgid "" +"In `menuentry` blocks, the `initrd` directive must point to the location " +"(relative to the `/boot` directory if it is on a separate partition) of the " +"`initramfs` file corresponding to the same kernel version. This directive is " +"called `initrd` because the previous tool which created initial RAM disk " +"images, [command]#mkinitrd#, created what were known as `initrd` files. The " +"`grub.cfg` directive remains `initrd` to maintain compatibility with other " +"tools. The file-naming convention of systems using the [command]#dracut# " +"utility to create the initial RAM disk image is " +"`initramfs-_kernel_version_.img`." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:351 +msgid "" +"For information on using [application]*Dracut*, refer to " +"xref:kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc#sec-Verifying_the_Initial_RAM_Disk_Image[Verifying " +"the Initial RAM Disk Image]." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:355 +msgid "" +"After installing a new kernel with [command]#rpm#, verify that " +"`/boot/grub2/grub.cfg` is correct and reboot the computer into the new " +"kernel. Ensure your hardware is detected by watching the boot process " +"output. If GRUB 2 presents an error and is unable to boot into the new " +"kernel, it is often easiest to try to boot into an alternative or older " +"kernel so that you can fix the problem. Alternatively, use the boot media " +"you created earlier to boot the system." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:356 +#, no-wrap +msgid "Causing the GRUB 2 boot menu to display" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:361 +msgid "" +"If you set the [option]`GRUB_TIMEOUT` option in the `/etc/default/grub` file " +"to 0, GRUB 2 will not display its list of bootable kernels when the system " +"starts up. In order to display this list when booting, press and hold any " +"alphanumeric key while and immediately after BIOS information is displayed, " +"and GRUB 2 will present you with the GRUB menu." +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:365 +#, no-wrap +msgid "Configuring the OS/400 Boot Loader" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:368 +msgid "" +"indexterm:[OS/400 boot loader,configuring]indexterm:[OS/400 boot " +"loader,configuration file] The " +"`/boot/vmlinitrd-_kernel-version_pass:attributes[{blank}]` file is installed " +"when you upgrade the kernel. However, you must use the [command]#dd# command " +"to configure the system to boot the new kernel." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:370 +msgid "" +"As `root`, issue the command [command]#cat /proc/iSeries/mf/side# to " +"determine the default side (either A, B, or C)." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:372 +msgid "" +"As `root`, issue the following command, where _kernel-version_ is the " +"version of the new kernel and _side_ is the side from the previous command:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:376 +#, no-wrap +msgid "" +"[command]#dd if=/boot/vmlinitrd-_kernel-version_ " +"of=/proc/iSeries/mf/pass:attributes[{blank}]_side_pass:attributes[{blank}]/vmlinux " +"bs=8k#\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:379 +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:403 +msgid "" +"Begin testing the new kernel by rebooting the computer and watching the " +"messages to ensure that the hardware is detected properly." +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:381 +#, no-wrap +msgid "Configuring the YABOOT Boot Loader" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:384 +msgid "" +"IBM eServer System p uses YABOOT as its boot loader. YABOOT uses " +"`/etc/aboot.conf` as its configuration file. Confirm that the file contains " +"an `image` section with the same version as the [package]*kernel* package " +"just installed, and likewise for the `initramfs` image:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:399 +#, no-wrap +msgid "" +"boot=/dev/sda1 init-message=Welcome to {MAJOROS}! Hit <TAB> for boot " +"options\n" +"partition=2 timeout=30 install=/usr/lib/yaboot/yaboot delay=10 nonvram\n" +"image=/vmlinuz-2.6.32-17.EL\n" +"\t label=old\n" +"\t read-only\n" +"\t initrd=/initramfs-2.6.32-17.EL.img\n" +"\t append=\"root=LABEL=/\"\n" +"image=/vmlinuz-2.6.32-19.EL\n" +"\t label=linux\n" +"\t read-only\n" +"\t initrd=/initramfs-2.6.32-19.EL.img\n" +"\t append=\"root=LABEL=/\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:402 +msgid "" +"Notice that the default is not set to the new kernel. The kernel in the " +"first image is booted by default. To change the default kernel to boot " +"either move its image stanza so that it is the first one listed or add the " +"directive `default` and set it to the `label` of the image stanza that " +"contains the new kernel." +msgstr "" diff --git a/po/fr/rawhide/pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.po b/po/fr/rawhide/pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.po new file mode 100644 index 00000000000..f71c5d4be06 --- /dev/null +++ b/po/fr/rawhide/pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.po @@ -0,0 +1,1681 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:6 +#, no-wrap +msgid "Working with Kernel Modules" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:9 +msgid "" +"indexterm:[kernel module,definition]indexterm:[module,kernel " +"module]indexterm:[drivers,kernel module] The Linux kernel is modular, which " +"means it can extend its capabilities through the use of dynamically-loaded " +"_kernel modules_. A kernel module can provide:" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:11 +msgid "a device driver which adds support for new hardware; or," +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:13 +msgid "support for a file system such as `btrfs` or `NFS`." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:15 +msgid "" +"Like the kernel itself, modules can take parameters that customize their " +"behavior, though the default parameters work well in most cases. User-space " +"tools can list the modules currently loaded into a running kernel; query all " +"available modules for available parameters and module-specific information; " +"and load or unload (remove) modules dynamically into or from a running " +"kernel. Many of these utilities, which are provided by the [package]*kmod* " +"package, take module dependencies into account when performing operations so " +"that manual dependency-tracking is rarely necessary." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:17 +msgid "" +"On modern systems, kernel modules are automatically loaded by various " +"mechanisms when the conditions call for it. However, there are occasions " +"when it is necessary to load or unload modules manually, such as when one " +"module is preferred over another although either could provide basic " +"functionality, or when a module is misbehaving." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:19 +msgid "This chapter explains how to:" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:21 +msgid "" +"use the user-space [application]*kmod* utilities to display, query, load and " +"unload kernel modules and their dependencies;" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:23 +msgid "" +"set module parameters both dynamically on the command line and permanently " +"so that you can customize the behavior of your kernel modules; and," +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:25 +msgid "load modules at boot time." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:26 +#, no-wrap +msgid "Installing the kmod package" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:31 +msgid "" +"In order to use the kernel module utilities described in this chapter, first " +"ensure the [package]*kmod* package is installed on your system by running, " +"as root:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:35 +#, no-wrap +msgid "~]#{nbsp}dnf install kmod\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:39 +msgid "" +"For more information on installing packages with DNF, see " +"xref:package-management/DNF.adoc#sec-Installing[Installing Packages]." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:43 +#, no-wrap +msgid "Listing Currently-Loaded Modules" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:46 +msgid "" +"indexterm:[kernel module,listing,currently loaded modules]indexterm:[kernel " +"module,utilities,lsmod]indexterm:[lsmod,kernel module] You can list all " +"kernel modules that are currently loaded into the kernel by running the " +"[command]#lsmod# command, for example:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:82 +#, no-wrap +msgid "" +"~]$ lsmod\n" +"Module Size Used by\n" +"tcp_lp 12663 0\n" +"bnep 19704 2\n" +"bluetooth 372662 7 bnep\n" +"rfkill 26536 3 bluetooth\n" +"fuse 87661 3\n" +"ip6t_rpfilter 12546 1\n" +"ip6t_REJECT 12939 2\n" +"ipt_REJECT 12541 2\n" +"xt_conntrack 12760 7\n" +"ebtable_nat 12807 0\n" +"ebtable_broute 12731 0\n" +"bridge 110196 1 ebtable_broute\n" +"stp 12976 1 bridge\n" +"llc 14552 2 stp,bridge\n" +"ebtable_filter 12827 0\n" +"ebtables 30913 3 ebtable_broute,ebtable_nat,ebtable_filter\n" +"ip6table_nat 13015 1\n" +"nf_conntrack_ipv6 18738 5\n" +"nf_defrag_ipv6 34651 1 nf_conntrack_ipv6\n" +"nf_nat_ipv6 13279 1 ip6table_nat\n" +"ip6table_mangle 12700 1\n" +"ip6table_security 12710 1\n" +"ip6table_raw 12683 1\n" +"ip6table_filter 12815 1\n" +"ip6_tables 27025 5 " +"ip6table_filter,ip6table_mangle,ip6table_security,ip6table_nat,ip6table_raw\n" +"iptable_nat 13011 1\n" +"nf_conntrack_ipv4 14862 4\n" +"nf_defrag_ipv4 12729 1 nf_conntrack_ipv4\n" +"nf_nat_ipv4 13263 1 iptable_nat\n" +"nf_nat 21798 4 " +"nf_nat_ipv4,nf_nat_ipv6,ip6table_nat,iptable_nat\n" +"[output truncated]\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:85 +msgid "Each row of [command]#lsmod# output specifies:" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:87 +msgid "the name of a kernel module currently loaded in memory;" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:89 +msgid "the amount of memory it uses; and," +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:91 +msgid "" +"the sum total of processes that are using the module and other modules which " +"depend on it, followed by a list of the names of those modules, if there are " +"any. Using this list, you can first unload all the modules depending the " +"module you want to unload. For more information, see " +"xref:Working_with_Kernel_Modules.adoc#sec-Unloading_a_Module[Unloading a " +"Module]." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:94 +msgid "" +"indexterm:[kernel module,files,/proc/modules] Finally, note that " +"[command]#lsmod# output is less verbose and considerably easier to read than " +"the content of the `/proc/modules` pseudo-file." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:96 +#, no-wrap +msgid "Displaying Information About a Module" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:99 +msgid "" +"indexterm:[kernel module,listing,module information]indexterm:[kernel " +"module,utilities,modinfo]indexterm:[modinfo,kernel module] You can display " +"detailed information about a kernel module by running the " +"[command]#modinfo{nbsp}pass:attributes[{blank}]_module_name_pass:attributes[{blank}]# " +"command." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:101 +#, no-wrap +msgid "Module names do not end in .ko" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:106 +msgid "" +"When entering the name of a kernel module as an argument to one of the " +"[application]*kmod* utilities, do not append a `.ko` extension to the end of " +"the name. Kernel module names do not have extensions; their corresponding " +"files do." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:110 +#, no-wrap +msgid "Listing information about a kernel module with lsmod" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:114 +msgid "" +"To display information about the `e1000e` module, which is the Intel " +"PRO/1000 network driver, run:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:145 +#, no-wrap +msgid "" +"~]# modinfo e1000e\n" +"filename: " +"/lib/modules/3.17.4-302.fc21.x86_64/kernel/drivers/net/ethernet/intel/e1000e/e1000e.ko\n" +"version: 2.3.2-k\n" +"license: GPL\n" +"description: Intel(R) PRO/1000 Network Driver\n" +"author: Intel Corporation, \n" +"srcversion: 2FBED3F5E2EF40112284D95\n" +"alias: pci:v00008086d00001503sv*sd*bc*sc*i*\n" +"alias: pci:v00008086d00001502sv*sd*bc*sc*i*\n" +"[some alias lines omitted]\n" +"alias: pci:v00008086d0000105Esv*sd*bc*sc*i*\n" +"depends: ptp\n" +"intree: Y\n" +"vermagic: 3.17.4-302.fc21.x86_64 SMP mod_unload\n" +"signer: Fedora kernel signing key\n" +"sig_key: " +"1F:C9:E6:8F:74:19:55:63:48:FD:EE:2F:DE:B7:FF:9D:A6:33:7B:BF\n" +"sig_hashalgo: sha256\n" +"parm: debug:Debug level (0=none,...,16=all) (int)\n" +"parm: copybreak:Maximum size of packet that is copied to a new " +"buffer on receive (uint)\n" +"parm: TxIntDelay:Transmit Interrupt Delay (array of int)\n" +"parm: TxAbsIntDelay:Transmit Absolute Interrupt Delay (array of " +"int)\n" +"parm: RxIntDelay:Receive Interrupt Delay (array of int)\n" +"parm: RxAbsIntDelay:Receive Absolute Interrupt Delay (array of " +"int)\n" +"parm: InterruptThrottleRate:Interrupt Throttling Rate (array of " +"int)\n" +"parm: IntMode:Interrupt Mode (array of int)\n" +"parm: SmartPowerDownEnable:Enable PHY smart power down (array of " +"int)\n" +"parm: KumeranLockLoss:Enable Kumeran lock loss workaround (array " +"of int)\n" +"parm: WriteProtectNVM:Write-protect NVM [WARNING: disabling this " +"can lead to corrupted NVM] (array of int)\n" +"parm: CrcStripping:Enable CRC Stripping, disable if your BMC needs " +"the CRC (array of int)\n" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:150 +msgid "Here are descriptions of a few of the fields in [command]#modinfo# output:" +msgstr "" + +#. type: Labeled list +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:151 +#, no-wrap +msgid "filename" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:152 +msgid "" +"The absolute path to the `.ko` kernel object file. You can use " +"[command]#modinfo -n# as a shortcut command for printing only the `filename` " +"field." +msgstr "" + +#. type: Labeled list +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:153 +#, no-wrap +msgid "description" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:154 +msgid "" +"A short description of the module. You can use [command]#modinfo -d# as a " +"shortcut command for printing only the description field." +msgstr "" + +#. type: Labeled list +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:155 +#, no-wrap +msgid "alias" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:156 +msgid "" +"The `alias` field appears as many times as there are aliases for a module, " +"or is omitted entirely if there are none." +msgstr "" + +#. type: Labeled list +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:157 +#, no-wrap +msgid "depends" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:158 +msgid "" +"This field contains a comma-separated list of all the modules this module " +"depends on." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:160 +#, no-wrap +msgid "Omitting the depends field" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:165 +msgid "" +"If a module has no dependencies, the `depends` field may be omitted from the " +"output." +msgstr "" + +#. type: Labeled list +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:168 +#, no-wrap +msgid "parm" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:169 +msgid "" +"Each `parm` field presents one module parameter in the form " +"`pass:attributes[{blank}]_parameter_name_:pass:attributes[{blank}]_description_pass:attributes[{blank}]`, " +"where:" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:171 +msgid "" +"_parameter_name_ is the exact syntax you should use when using it as a " +"module parameter on the command line, or in an option line in a `.conf` file " +"in the `/etc/modprobe.d/` directory; and," +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:173 +msgid "" +"_description_ is a brief explanation of what the parameter does, along with " +"an expectation for the type of value the parameter accepts (such as `int`, " +"`unit` or `array of int`) in parentheses." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:175 +#, no-wrap +msgid "Listing module parameters" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:179 +msgid "" +"You can list all parameters that the module supports by using the " +"[option]`-p` option. However, because useful value type information is " +"omitted from [command]#modinfo -p# output, it is more useful to run:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:194 +#, no-wrap +msgid "" +"~]# modinfo e1000e | grep \"^parm\" | sort\n" +"parm: copybreak:Maximum size of packet that is copied to a new " +"buffer on receive (uint)\n" +"parm: CrcStripping:Enable CRC Stripping, disable if your BMC needs " +"the CRC (array of int)\n" +"parm: debug:Debug level (0=none,...,16=all) (int)\n" +"parm: InterruptThrottleRate:Interrupt Throttling Rate (array of " +"int)\n" +"parm: IntMode:Interrupt Mode (array of int)\n" +"parm: KumeranLockLoss:Enable Kumeran lock loss workaround (array " +"of int)\n" +"parm: RxAbsIntDelay:Receive Absolute Interrupt Delay (array of " +"int)\n" +"parm: RxIntDelay:Receive Interrupt Delay (array of int)\n" +"parm: SmartPowerDownEnable:Enable PHY smart power down (array of " +"int)\n" +"parm: TxAbsIntDelay:Transmit Absolute Interrupt Delay (array of " +"int)\n" +"parm: TxIntDelay:Transmit Interrupt Delay (array of int)\n" +"parm: WriteProtectNVM:Write-protect NVM [WARNING: disabling this " +"can lead to corrupted NVM] (array of int)\n" +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:199 +#, no-wrap +msgid "Loading a Module" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:202 +msgid "" +"indexterm:[kernel module,loading,for the current session]indexterm:[kernel " +"module,utilities,modprobe]indexterm:[modprobe,kernel module] To load a " +"kernel module, run [command]#modprobe _module_name_pass:attributes[{blank}]# " +"as `root`. For example, to load the `wacom` module, run:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:205 +#, no-wrap +msgid "~]# modprobe wacom\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:209 +msgid "" +"indexterm:[kernel " +"module,directories,/lib/modules/kernel_version/kernel/drivers/] By default, " +"[command]#modprobe# attempts to load the module from " +"`/lib/modules/pass:attributes[{blank}]_kernel_version_pass:attributes[{blank}]/kernel/drivers/`. " +"In this directory, each type of module has its own subdirectory, such as " +"`net/` and `scsi/`, for network and SCSI interface drivers respectively." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:211 +msgid "" +"Some modules have dependencies, which are other kernel modules that must be " +"loaded before the module in question can be loaded. The [command]#modprobe# " +"command always takes dependencies into account when performing " +"operations. When you ask [command]#modprobe# to load a specific kernel " +"module, it first examines the dependencies of that module, if there are any, " +"and loads them if they are not already loaded into the " +"kernel. [command]#modprobe# resolves dependencies recursively: it will load " +"all dependencies of dependencies, and so on, if necessary, thus ensuring " +"that all dependencies are always met." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:213 +msgid "" +"You can use the [option]`-v` (or [option]`--verbose`) option to cause " +"[command]#modprobe# to display detailed information about what it is doing, " +"which can include loading module dependencies." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:215 +#, no-wrap +msgid "modprobe -v shows module dependencies as they are loaded" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:219 +msgid "" +"You can load the `Fibre Channel over Ethernet` module verbosely by typing " +"the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:226 +#, no-wrap +msgid "" +"~]# modprobe -v fcoe\n" +"insmod " +"/lib/modules/3.17.4-302.fc21.x86_64/kernel/drivers/scsi/scsi_transport_fc.ko.xz\n" +"insmod " +"/lib/modules/3.17.4-302.fc21.x86_64/kernel/drivers/scsi/libfc/libfc.ko.xz\n" +"insmod " +"/lib/modules/3.17.4-302.fc21.x86_64/kernel/drivers/scsi/fcoe/libfcoe.ko.xz\n" +"insmod " +"/lib/modules/3.17.4-302.fc21.x86_64/kernel/drivers/scsi/fcoe/fcoe.ko.xz\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:229 +msgid "" +"In this example, you can see that [command]#modprobe# loaded the `scsi_tgt`, " +"`scsi_transport_fc`, `libfc` and `libfcoe` modules as dependencies before " +"finally loading `fcoe`. Also note that [command]#modprobe# used the more " +"primitive [command]#insmod# command to insert the modules into the running " +"kernel." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:232 +msgid "indexterm:[kernel module,utilities,insmod]indexterm:[insmod,kernel module]" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:234 +#, no-wrap +msgid "Always use modprobe instead of insmod!" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:239 +msgid "" +"Although the [command]#insmod# command can also be used to load kernel " +"modules, it does not resolve dependencies. Because of this, you should " +"*always* load modules using [command]#modprobe# instead." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:243 +#, no-wrap +msgid "Unloading a Module" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:246 +msgid "" +"indexterm:[kernel module,unloading]indexterm:[kernel " +"module,utilities,modprobe]indexterm:[modprobe,kernel module] You can unload " +"a kernel module by running [command]#modprobe -r " +"_module_name_pass:attributes[{blank}]# as `root`. For example, assuming that " +"the `wacom` module is already loaded into the kernel, you can unload it by " +"running:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:249 +#, no-wrap +msgid "~]# modprobe -r wacom\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:253 +msgid "However, this command will fail if a process is using:" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:255 +msgid "the `wacom` module;" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:257 +msgid "a module that `wacom` directly depends on, or;" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:259 +msgid "any module that `wacom`, through the dependency tree, depends on indirectly." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:261 +msgid "" +"See " +"xref:Working_with_Kernel_Modules.adoc#sec-Listing_Currently-Loaded_Modules[Listing " +"Currently-Loaded Modules] for more information about using [command]#lsmod# " +"to obtain the names of the modules which are preventing you from unloading a " +"certain module." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:263 +#, no-wrap +msgid "Unloading a kernel module" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:267 +msgid "" +"For example, if you want to unload the `firewire_ohci` module, your terminal " +"session might look similar to this:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:274 +#, no-wrap +msgid "" +"~]# modinfo -F depends firewire_ohci\n" +"firewire-core\n" +"~]# modinfo -F depends firewire_core\n" +"crc-itu-t\n" +"~]# modinfo -F depends crc-itu-t\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:278 +msgid "" +"You have figured out the dependency tree (which does not branch in this " +"example) for the loaded Firewire modules: `firewire_ohci` depends on " +"`firewire_core`, which itself depends on `crc-itu-t`." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:280 +msgid "" +"You can unload `firewire_ohci` using the [command]#modprobe -v -r " +"_module_name_pass:attributes[{blank}]# command, where [option]`-r` is short " +"for [option]`--remove` and [option]`-v` for [option]`--verbose`:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:286 +#, no-wrap +msgid "" +"~]# modprobe -r -v firewire_ohci\n" +"rmmod firewire_ohci\n" +"rmmod firewire_core\n" +"rmmod crc_itu_t\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:289 +msgid "" +"The output shows that modules are unloaded in the reverse order that they " +"are loaded, given that no processes depend on any of the modules being " +"unloaded." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:292 +msgid "indexterm:[kernel module,utilities,rmmod]indexterm:[rmmod,kernel module]" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:294 +#, no-wrap +msgid "Do not use rmmod directly!" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:299 +msgid "" +"Although the [command]#rmmod# command can be used to unload kernel modules, " +"it is recommended to use [command]#modprobe -r# instead." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:303 +#, no-wrap +msgid "Setting Module Parameters" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:306 +msgid "" +"indexterm:[module parameters,kernel module]indexterm:[kernel module,module " +"parameters,supplying] Like the kernel itself, modules can also take " +"parameters that change their behavior. Most of the time, the default ones " +"work well, but occasionally it is necessary or desirable to set custom " +"parameters for a module. Because parameters cannot be dynamically set for a " +"module that is already loaded into a running kernel, there are two different " +"methods for setting them." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:308 +msgid "" +"You can unload all dependencies of the module you want to set parameters " +"for, unload the module using [command]#modprobe -r#, and then load it with " +"[command]#modprobe# along with a list of customized parameters. This method " +"is often used when the module does not have many dependencies, or to test " +"different combinations of parameters without making them persistent, and is " +"the method covered in this section." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:310 +msgid "" +"Alternatively, you can list the new parameters in an existing or newly " +"created file in the `/etc/modprobe.d/` directory. This method makes the " +"module parameters persistent by ensuring that they are set each time the " +"module is loaded, such as after every reboot or [command]#modprobe# " +"command. This method is covered in " +"xref:Working_with_Kernel_Modules.adoc#sec-Persistent_Module_Loading[Persistent " +"Module Loading], though the following information is a prerequisite." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:312 +#, no-wrap +msgid "Supplying optional parameters when loading a kernel module" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:316 +msgid "" +"You can use [command]#modprobe# to load a kernel module with custom " +"parameters using the following command line format:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:320 +#, no-wrap +msgid "~]#{nbsp}modprobe{nbsp}module_name{nbsp}parameter=value\n" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:326 +msgid "" +"When loading a module with custom parameters on the command line, be aware " +"of the following:" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:328 +msgid "You can enter multiple parameters and values by separating them with spaces." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:330 +msgid "" +"Some module parameters expect a list of comma-separated values as their " +"argument. When entering the list of values, do *not* insert a space after " +"each comma, or [command]#modprobe# will incorrectly interpret the values " +"following spaces as additional parameters." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:332 +msgid "" +"The [command]#modprobe# command silently succeeds with an exit status of 0 " +"if:" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:334 +msgid "it successfully loads the module, *or*" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:336 +msgid "the module is *already* loaded into the kernel." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:338 +msgid "" +"Thus, you must ensure that the module is not already loaded before " +"attempting to load it with custom parameters. The [command]#modprobe# " +"command does not automatically reload the module, or alert you that it is " +"already loaded." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:340 +msgid "" +"Here are the recommended steps for setting custom parameters and then " +"loading a kernel module. This procedure illustrates the steps using the " +"`e1000e` module, which is the network driver for Intel PRO/1000 network " +"adapters, as an example:" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:342 +#, no-wrap +msgid "Loading a Kernel Module with Custom Parameters" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:344 +msgid "First, ensure the module is not already loaded into the kernel:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:349 +#, no-wrap +msgid "" +"~]#{nbsp}lsmod |grep e1000e\n" +"~]#{nbsp}\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:352 +msgid "" +"Output would indicate that the module is already loaded into the kernel, in " +"which case you must first unload it before proceeding. See " +"xref:Working_with_Kernel_Modules.adoc#sec-Unloading_a_Module[Unloading a " +"Module] for instructions on safely unloading it." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:354 +msgid "" +"Load the module and list all custom parameters after the module name. For " +"example, if you wanted to load the Intel PRO/1000 network driver with the " +"interrupt throttle rate set to 3000 interrupts per second for the first, " +"second, and third instances of the driver, and turn on debug, you would run, " +"as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:358 +#, no-wrap +msgid "~]#{nbsp}modprobe e1000e InterruptThrottleRate=3000,3000,3000 debug=1\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:362 +msgid "" +"This example illustrates passing multiple values to a single parameter by " +"separating them with commas and omitting any spaces between them." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:364 +#, no-wrap +msgid "Persistent Module Loading" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:367 +msgid "" +"indexterm:[kernel module,loading,at the boot time]indexterm:[kernel " +"module,directories,/etc/modules-load.d/] As shown in " +"xref:Working_with_Kernel_Modules.adoc#ex-Listing_information_about_a_kernel_module_with_lsmod[Listing " +"information about a kernel module with lsmod], many kernel modules are " +"loaded automatically at boot time. You can specify additional modules to be " +"loaded by the `systemd-modules-load.service` daemon by creating a " +"`pass:attributes[{blank}]_program_.conf` file in the `/etc/modules-load.d/` " +"directory, where _program_ is any descriptive name of your choice. The files " +"in `/etc/modules-load.d/` are text files that list the modules to be loaded, " +"one per line." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:369 +#, no-wrap +msgid "A Text File to Load a Module" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:373 +msgid "" +"To create a file to load the `virtio-net.ko` module, create a file " +"`/etc/modules-load.d/virtio-net.conf` with the following content:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:377 +#, no-wrap +msgid "" +"# Load virtio-net.ko at boot\n" +"virtio-net\n" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:382 +msgid "" +"See the `modules-load.d(5)` and `systemd-modules-load.service(8)` man pages " +"for more information." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:384 +#, no-wrap +msgid "Signing Kernel Modules for Secure Boot" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:387 +msgid "" +"Fedora includes support for the UEFI Secure Boot feature, which means that " +"Fedora can be installed and run on systems where UEFI Secure Boot is " +"enabled. footnote:[Fedora does not require the use of Secure Boot on UEFI " +"systems.] When Secure Boot is enabled, the EFI operating system boot " +"loaders, the Fedora kernel, and all kernel modules must be signed with a " +"private key and authenticated with the corresponding public key. The Fedora " +"distribution includes signed boot loaders, signed kernels, and signed kernel " +"modules. In addition, the signed first-stage boot loader and the signed " +"kernel include embedded Fedora public keys. These signed executable binaries " +"and embedded keys enable Fedora to install, boot, and run with the Microsoft " +"UEFI Secure Boot CA keys that are provided by the UEFI firmware on systems " +"that support UEFI Secure Boot.footnote:[Not all UEFI-based systems include " +"support for Secure Boot.]" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:389 +msgid "" +"The information provided in the following sections describes steps necessary " +"to enable you to self-sign privately built kernel modules for use with " +"Fedora on UEFI-based systems where Secure Boot is enabled. These sections " +"also provide an overview of available options for getting your public key " +"onto the target system where you want to deploy your kernel module." +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:391 +#, no-wrap +msgid "Prerequisites" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:394 +msgid "" +"In order to enable signing of externally built modules, the tools listed in " +"the following table are required to be installed on the system." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:396 +#, no-wrap +msgid "Required Tools" +msgstr "" + +#. type: Table +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:405 +#, no-wrap +msgid "" +"|Tool|Provided by Package|Used on|Purpose\n" +"|[command]#openssl#|[package]*openssl*|Build system|Generates public and " +"private X.509 key pair\n" +"|[command]#sign-file#|[package]*kernel-devel*|Build system|C application " +"used to sign kernel modules\n" +"|[command]#mokutil#|[package]*mokutil*|Target system|Optional tool used to " +"manually enroll the public key\n" +"|[command]#keyctl#|[package]*keyutils*|Target system|Optional tool used to " +"display public keys in the system key ring\n" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:411 +msgid "" +"Note that the build system, where you build and sign your kernel module, " +"does not need to have UEFI Secure Boot enabled and does not even need to be " +"a UEFI-based system." +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:415 +#, no-wrap +msgid "Kernel Module Authentication" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:418 +msgid "" +"In Fedora, when a kernel module is loaded, the module's signature is checked " +"using the public X.509 keys on the kernel's system key ring, excluding those " +"keys that are on the kernel's system black list key ring." +msgstr "" + +#. type: Title ==== +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:420 +#, no-wrap +msgid "Sources For Public Keys Used To Authenticate Kernel Modules" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:423 +msgid "" +"During boot, the kernel loads X.509 keys into the system key ring or the " +"system black list key ring from a set of persistent key stores as shown in " +"xref:Working_with_Kernel_Modules.adoc#table-sources-for-system-key-rings[Sources " +"For System Key Rings]" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:425 +#, no-wrap +msgid "Sources For System Key Rings" +msgstr "" + +#. type: Table +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:431 +#, no-wrap +msgid "" +"|Source of X.509 Keys|User Ability to Add Keys|UEFI Secure Boot State|Keys " +"Loaded During Boot\n" +"|Embedded in kernel|No|-|`.system_keyring`\n" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:431 +#, no-wrap +msgid "2+|UEFI Secure Boot \"`db`\"" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:432 +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:436 +#, no-wrap +msgid "2+|Limited" +msgstr "" + +#. type: Table +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:435 +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:439 +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:443 +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:447 +msgid "|Not enabled|No |Enabled|`.system_keyring`" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:435 +#, no-wrap +msgid "2+|UEFI Secure Boot \"`dbx`\"" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:439 +#, no-wrap +msgid "2+|Embedded in `shim.efi` boot loader" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:440 +#, no-wrap +msgid "2+|No" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:443 +#, no-wrap +msgid "2+|Machine Owner Key (MOK) list" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:444 +#, no-wrap +msgid "2+|Yes" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:450 +msgid "" +"Note that if the system is not UEFI-based or if UEFI Secure Boot is not " +"enabled, then only the keys that are embedded in the kernel are loaded onto " +"the system key ring and you have no ability to augment that set of keys " +"without rebuilding the kernel. The system black list key ring is a list of " +"X.509 keys which have been revoked. If your module is signed by a key on the " +"black list then it will fail authentication even if your public key is in " +"the system key ring." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:452 +msgid "To confirm if Secure Boot is enabled, enter a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:457 +#, no-wrap +msgid "" +"~]$ [command]#mokutil --sb-state#\n" +"SecureBoot enabled\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:460 +msgid "" +"If Secure Boot is not enabled then the message `Failed to read SecureBoot` " +"is displayed." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:462 +msgid "" +"You can display information about the keys on the system key rings using the " +"[command]#keyctl# utility. The following is abbreviated example output from " +"a Fedora system where UEFI Secure Boot is not enabled." +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:468 +#, no-wrap +msgid "" +"~]#{nbsp}keyctl list %:.builtin_trusted_keys\n" +"1 key in keyring:\n" +"265061799: ---lswrv 0 0 asymmetric: Fedora kernel signing key: " +"ba8e2919f98f3f8e2e27541cde0d1f...\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:471 +msgid "" +"The following is abbreviated example output from a Fedora system where UEFI " +"Secure Boot is enabled." +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:481 +#, no-wrap +msgid "" +"~]#{nbsp}keyctl list %:.builtin_trusted_keys\n" +" 5 keys in keyring:\n" +" ...asymmetric: Microsoft Windows Production PCA 2011: a92902398e16c497...\n" +" ...asymmetric: Fedora kernel signing key: ba8e2919f98f3f8e2e27541cde0d...\n" +" ...asymmetric: Fedora Secure Boot CA: fde32599c2d61db1bf5807335d7b20e4...\n" +" ...asymmetric: Red Hat Test Certifying CA: 08a0ef5800cb02fb587c12b4032...\n" +" ...asymmetric: Microsoft Corporation UEFI CA 2011: 13adbf4309bd82709c8...\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:484 +msgid "" +"The above output shows the addition of two keys from the UEFI Secure Boot " +"\"`db`\" keys plus the `Fedora Secure Boot CA` which is embedded in the " +"`shim.efi` boot loader." +msgstr "" + +#. type: Title ==== +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:486 +#, no-wrap +msgid "Kernel Module Authentication Requirements" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:489 +msgid "" +"If UEFI Secure Boot is enabled or if the [option]`module.sig_enforce` kernel " +"parameter has been specified, then only signed kernel modules that are " +"authenticated using a key on the system key ring can be successfully " +"loaded.footnote:[Provided that the public key is not on the system black " +"list key ring.] If UEFI Secure Boot is disabled and if the " +"[option]`module.sig_enforce` kernel parameter has not been specified, then " +"unsigned kernel modules and signed kernel modules without a public key can " +"be successfully loaded. This is summarized in " +"xref:Working_with_Kernel_Modules.adoc#table-kernel-module-authentication-requirements-for-loading[Kernel " +"Module Authentication Requirements for Loading]." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:491 +#, no-wrap +msgid "Kernel Module Authentication Requirements for Loading" +msgstr "" + +#. type: Table +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:496 +#, no-wrap +msgid "" +"|Module Signed|Public Key Found and Signature Valid|UEFI Secure Boot " +"State|module.sig_enforce|Module Load|Kernel Tainted\n" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:496 +#, no-wrap +msgid "3+|Unsigned" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:497 +#, no-wrap +msgid "3+|-" +msgstr "" + +#. type: Table +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:501 +msgid "" +"|Not enabled|Not enabled|Succeeds|Yes |Not enabled|Enabled|Fails| " +"|Enabled|-|Fails|-" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:501 +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:506 +#, no-wrap +msgid "3+|Signed" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:502 +#, no-wrap +msgid "3+|No" +msgstr "" + +#. type: Table +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:506 +msgid "" +"|Not enabled|Not enabled|Succeeds|Yes |Not enabled|Enabled|Fails|- " +"|Enabled|-|Fails|-" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:507 +#, no-wrap +msgid "3+|Yes" +msgstr "" + +#. type: Table +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:511 +msgid "" +"|Not enabled|Not enabled|Succeeds|No |Not enabled|Enabled|Succeeds|No " +"|Enabled|-|Succeeds|No" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:514 +msgid "" +"Subsequent sections will describe how to generate a public and private X.509 " +"key pair, how to use the private key to sign a kernel module, and how to " +"enroll the public key into a source for the system key ring." +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:516 +#, no-wrap +msgid "Generating a Public and Private X.509 Key Pair" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:519 +msgid "" +"You need to generate a public and private X.509 key pair that will be used " +"to sign a kernel module after it has been built. The corresponding public " +"key will be used to authenticate the kernel module when it is loaded." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:521 +msgid "" +"The [command]#openssl# tool can be used to generate a key pair that " +"satisfies the requirements for kernel module signing in Fedora. Some of the " +"parameters for this key generation request are best specified with a " +"configuration file; follow the example below to create your own " +"configuration file." +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:531 +#, no-wrap +msgid "" +"~]#{nbsp}cat << EOF > configuration_file.config\n" +"[ req ]\n" +"default_bits = 4096\n" +"distinguished_name = req_distinguished_name\n" +"prompt = no\n" +"string_mask = utf8only\n" +"x509_extensions = myexts\n" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:536 +#, no-wrap +msgid "" +"[ req_distinguished_name ]\n" +"O = pass:quotes[_Organization_]\n" +"CN = pass:quotes[_Organization signing key_]\n" +"emailAddress = pass:quotes[_E-mail address_]\n" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:543 +#, no-wrap +msgid "" +"[ myexts ]\n" +"basicConstraints=critical,CA:FALSE\n" +"keyUsage=digitalSignature\n" +"subjectKeyIdentifier=hash\n" +"authorityKeyIdentifier=keyid\n" +"EOF\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:546 +msgid "" +"After you have created the configuration file, you can create an X.509 " +"public and private key pair. The public key will be written to the " +"`pass:attributes[{blank}]_public_key_.der` file and the private key will be " +"written to the `pass:attributes[{blank}]_private_key_.priv` file." +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:553 +#, no-wrap +msgid "" +"~]#{nbsp}openssl req -x509 -new -nodes -utf8 -sha256 -days 36500 \\\n" +" -batch -config configuration_file.config -outform DER \\\n" +" -out public_key.der \\\n" +" -keyout private_key.priv\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:556 +msgid "" +"Enroll your public key on all systems where you want to authenticate and " +"load your kernel module." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:561 +msgid "" +"Take proper care to guard the contents of your private key. In the wrong " +"hands, the key could be used to compromise any system which has your public " +"key." +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:565 +#, no-wrap +msgid "Enrolling Public Key on Target System" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:568 +msgid "" +"When Fedora boots on a UEFI-based system with Secure Boot enabled, all keys " +"that are in the Secure Boot db key database, but not in the dbx database of " +"revoked keys, are loaded onto the system keyring by the kernel. The system " +"keyring is used to authenticate kernel modules." +msgstr "" + +#. type: Title ==== +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:570 +#, no-wrap +msgid "Factory Firmware Image Including Public Key" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:573 +msgid "" +"To facilitate authentication of your kernel module on your systems, consider " +"requesting your system vendor to incorporate your public key into the UEFI " +"Secure Boot key database in their factory firmware image." +msgstr "" + +#. type: Title ==== +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:575 +#, no-wrap +msgid "Executable Key Enrollment Image Adding Public Key" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:578 +msgid "" +"It is possible to add a key to an existing populated and active Secure Boot " +"key database. This can be done by writing and providing an EFI executable " +"*enrollment* image. Such an enrollment image contains a properly formed " +"request to append a key to the Secure Boot key database. This request must " +"include data that is properly signed by the private key that corresponds to " +"a public key that is already in the system's Secure Boot Key Exchange Key " +"(KEK) database. Additionally, this EFI image must be signed by a private key " +"that corresponds to a public key that is already in the key database." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:580 +msgid "" +"It is also possible to write an enrollment image that runs under " +"Fedora. However, the Fedora image must be properly signed by a private key " +"that corresponds to a public key that is already in the KEK database." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:582 +msgid "" +"The construction of either type of key enrollment images requires assistance " +"from the platform vendor." +msgstr "" + +#. type: Title ==== +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:584 +#, no-wrap +msgid "System Administrator Manually Adding Public Key to the MOK List" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:587 +msgid "" +"The Machine Owner Key (MOK) facility is a feature that is supported by " +"Fedora and can be used to augment the UEFI Secure Boot key database. When " +"Fedora boots on a UEFI-enabled system with Secure Boot enabled, the keys on " +"the MOK list are also added to the system keyring in addition to the keys " +"from the key database. The MOK list keys are also stored persistently and " +"securely in the same fashion as the Secure Boot key database keys, but these " +"are two separate facilities. The MOK facility is supported by shim.efi, " +"MokManager.efi, grubx64.efi, and the Fedora [command]#mokutil# utility." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:589 +msgid "" +"The major capability provided by the MOK facility is the ability to add " +"public keys to the MOK list without needing to have the key chain back to " +"another key that is already in the KEK database. However, enrolling a MOK " +"key requires manual interaction by a *physically present* user at the UEFI " +"system console on each target system. Nevertheless, the MOK facility " +"provides an excellent method for testing newly generated key pairs and " +"testing kernel modules signed with them." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:591 +msgid "Follow these steps to add your public key to the MOK list:" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:593 +msgid "" +"Request addition of your public key to the MOK list using a Fedora userspace " +"utility:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:597 +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:648 +#, no-wrap +msgid "~]#{nbsp}mokutil --import my_signing_key_pub.der\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:600 +msgid "" +"You will be asked to enter and confirm a password for this MOK enrollment " +"request." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:602 +msgid "Reboot the machine." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:604 +msgid "" +"The pending MOK key enrollment request will be noticed by `shim.efi` and it " +"will launch `MokManager.efi` to allow you to complete the enrollment from " +"the UEFI console. You will need to enter the password you previously " +"associated with this request and confirm the enrollment. Your public key is " +"added to the MOK list, which is persistent." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:606 +msgid "" +"Once a key is on the MOK list, it will be automatically propagated to the " +"system key ring on this and subsequent boots when UEFI Secure Boot is " +"enabled." +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:608 +#, no-wrap +msgid "Signing Kernel Module with the Private Key" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:611 +msgid "" +"There are no extra steps required to prepare your kernel module for " +"signing. You build your kernel module normally. Assuming an appropriate " +"Makefile and corresponding sources, follow these steps to build your module " +"and sign it:" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:613 +msgid "Build your `my_module.ko` module the standard way:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:617 +#, no-wrap +msgid "~]#{nbsp}make -C /usr/src/kernels/$(uname -r) M=$PWD modules\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:620 +msgid "" +"Sign your kernel module with your private key. This is done with a C " +"application. Note that the application requires that you provide both the " +"files that contain your private and the public key as well as the kernel " +"module file that you want to sign." +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:628 +#, no-wrap +msgid "" +"~]#{nbsp}/usr/src/kernels/$(uname -r)/scripts/sign-file \\\n" +" sha256 \\\n" +" my_signing_key.priv \\\n" +" my_signing_key_pub.der \\\n" +" my_module.ko\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:631 +msgid "" +"Your kernel module is in ELF image format and this application computes and " +"appends the signature directly to the ELF image in your `my_module.ko` " +"file. The [command]#modinfo# utility can be used to display information " +"about the kernel module's signature, if it is present. For information on " +"using the utility, see " +"xref:Working_with_Kernel_Modules.adoc#sec-Displaying_Information_About_a_Module[Displaying " +"Information About a Module]." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:633 +msgid "" +"Note that this appended signature is not contained in an ELF image section " +"and is not a formal part of the ELF image. Therefore, tools such as " +"[command]#readelf# will not be able to display the signature on your kernel " +"module." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:635 +msgid "" +"Your kernel module is now ready for loading. Note that your signed kernel " +"module is also loadable on systems where UEFI Secure Boot is disabled or on " +"a non-UEFI system. That means you do not need to provide both a signed and " +"unsigned version of your kernel module." +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:637 +#, no-wrap +msgid "Loading Signed Kernel Module" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:640 +msgid "" +"Once your public key is enrolled and is in the system keyring, the normal " +"kernel module loading mechanisms will work transparently. In the following " +"example, you will use [command]#mokutil# to add your public key to the MOK " +"list and you will manually load your kernel module with [command]#modprobe#." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:642 +msgid "" +"Optionally, you can verify that your kernel module will not load before you " +"have enrolled your public key. First, verify what keys have been added to " +"the system key ring on the current boot by running the [command]#keyctl list " +"%:.builtin_trusted_keys# as root. Since your public key has not been " +"enrolled yet, it should not be displayed in the output of the command." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:644 +msgid "Request enrollment of your public key." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:651 +msgid "Reboot, and complete the enrollment at the UEFI console." +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:655 +#, no-wrap +msgid "~]#{nbsp}reboot\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:658 +msgid "After the system reboots, verify the keys on the system key ring again." +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:662 +#, no-wrap +msgid "~]#{nbsp}keyctl list %:.builtin_trusted_keys\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:665 +msgid "You should now be able to load your kernel module successfully." +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:672 +#, no-wrap +msgid "" +"~]#{nbsp}modprobe -v my_module\n" +"insmod " +"/lib/modules/3.17.4-302.fc21.x86_64/extra/pass:quotes[_my_module_].ko\n" +"~]#{nbsp}lsmod | grep my_module\n" +"pass:quotes[_my_module_] 12425 0\n" +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:675 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:678 +msgid "" +"For more information on kernel modules and their utilities, see the " +"following resources." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:679 +#, no-wrap +msgid "Manual Page Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:682 +msgid "`lsmod(8)` — The manual page for the [command]#lsmod# command." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:684 +msgid "`modinfo(8)` — The manual page for the [command]#modinfo# command." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:686 +msgid "`modprobe(8)` — The manual page for the [command]#modprobe# command." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:688 +msgid "`rmmod(8)` — The manual page for the [command]#rmmod# command." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:690 +msgid "`ethtool(8)` — The manual page for the [command]#ethtool# command." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:692 +msgid "`mii-tool(8)` — The manual page for the [command]#mii-tool# command." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:693 +#, no-wrap +msgid "Installable and External Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:695 +msgid "" +"link:++http://tldp.org/HOWTO/Module-HOWTO/++[Linux Loadable Kernel Module " +"HOWTO] — The [citetitle]_Linux Loadable Kernel Module HOWTO_ from the Linux " +"Documentation Project contains further information on working with kernel " +"modules." +msgstr "" diff --git a/po/fr/rawhide/pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.po b/po/fr/rawhide/pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.po new file mode 100644 index 00000000000..34adedc53c7 --- /dev/null +++ b/po/fr/rawhide/pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.po @@ -0,0 +1,2245 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:5 +#, no-wrap +msgid "Working with the GRUB 2 Boot Loader" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:10 +#, no-wrap +msgid "**Editor’s Note**\n" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:13 +msgid "" +"_This guide is deprecated!_ Large parts of it are no longer current and it " +"will not receive any updates. A series of shorter, topic-specific " +"documentation will gradually replace it. For additional information about " +"Grub version 2 on Fedora see " +"https://docs.fedoraproject.org/en-US/quick-docs/installing-grub2/[Bootloading " +"with GRUB2]." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:16 +msgid "" +"{MAJOROSVER} is distributed with the GNU GRand Unified Boot loader (GRUB) " +"version 2 boot loader, which allows the user to select an operating system " +"or kernel to be loaded at system boot time. GRUB 2 also allows the user to " +"pass arguments to the kernel." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:18 +#, no-wrap +msgid "Introduction to GRUB 2" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:21 +msgid "" +"GRUB 2 reads its configuration from the `/boot/grub2/grub.cfg` file. This " +"file contains menu information." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:23 +msgid "" +"The GRUB 2 configuration file, `grub.cfg`, is generated during installation, " +"or by invoking the [application]*/usr/sbin/grub2-mkconfig* utility, and is " +"automatically updated by [command]#grubby# each time a new kernel is " +"installed. When regenerated manually using [application]*grub2-mkconfig*, " +"the file is generated according to the template files located in " +"`/etc/grub.d/`, and custom settings in the `/etc/default/grub` file. Edits " +"of `grub.cfg` will be lost any time [application]*grub2-mkconfig* is used to " +"regenerate the file, so care must be taken to reflect any manual changes in " +"`/etc/default/grub` as well." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:25 +msgid "" +"Normal operations on `grub.cfg`, such as the removal and addition of new " +"kernels, should be done using the [command]#grubby# tool and, for scripts, " +"using [command]#new-kernel-pkg# tool. If you use [command]#grubby# to modify " +"the default kernel the changes will be inherited when new kernels are " +"installed. For more information on [command]#grubby#, see " +"xref:#sec-Making_Persistent_Changes_to_a_GRUB_2_Menu_Using_the_grubby_Tool[Making " +"Persistent Changes to a GRUB 2 Menu Using the grubby Tool]." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:27 +msgid "" +"The `/etc/default/grub` file is used by the [command]#grub2-mkconfig# tool, " +"which is used by `anaconda` when creating `grub.cfg` during the installation " +"process, and can be used in the event of a system failure, for example if " +"the boot loader configurations need to be recreated. In general, it is not " +"recommended to replace the `grub.cfg` file by manually running " +"`grub2-mkconfig` except as a last resort. Note that any manual changes to " +"`/etc/default/grub` require rebuilding the `grub.cfg` file." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:28 +#, no-wrap +msgid "Menu Entries in grub.cfg" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:30 +msgid "" +"Among various code snippets and directives, the `grub.cfg` configuration " +"file contains one or more `menuentry` blocks, each representing a single " +"GRUB 2 boot menu entry. These blocks always start with the `menuentry` " +"keyword followed by a title, list of options, and an opening curly bracket, " +"and end with a closing curly bracket. Anything between the opening and " +"closing bracket should be indented. For example, the following is a sample " +"`menuentry` block for {MAJOROSVER} with Linux kernel 3.17.4-301.fc21.x86_64:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:48 +#, no-wrap +msgid "" +"menuentry 'Fedora, with Linux 3.17.4-301.fc21.x86_64' --class fedora --class " +"gnu-linux --class gnu --class os --unrestricted $menuentry_id_option " +"'gnulinux-3.17.4-301.fc21.x86_64-advanced-effee860-8d55-4e4a-995e-b4c88f9ac9f0' " +"{\n" +" load_video\n" +" set gfxpayload=keep\n" +" insmod gzio\n" +" insmod part_msdos\n" +" insmod ext2\n" +" set root='hd0,msdos1'\n" +" if [ x$feature_platform_search_hint = xy ]; then\n" +" search --no-floppy --fs-uuid --set=root --hint='hd0,msdos1' " +"f19c92f4-9ead-4207-b46a-723b7a2c51c8\n" +" else\n" +" search --no-floppy --fs-uuid --set=root " +"f19c92f4-9ead-4207-b46a-723b7a2c51c8\n" +" fi\n" +" linux16 /vmlinuz-3.17.4-301.fc21.x86_64 root=/dev/mapper/fedora-root " +"ro rd.lvm.lv=fedora/swap rd.lvm.lv=fedora/root rhgb quiet LANG=en_US.UTF-8\n" +" initrd16 /initramfs-3.17.4-301.fc21.x86_64.img\n" +"}\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:52 +msgid "" +"Each `menuentry` block that represents an installed Linux kernel contains " +"`linux` on 64-bit IBM POWER Series, `linux16` on x86_64 BIOS-based systems, " +"and `linuxefi` on UEFI-based systems. Then the `initrd` directives followed " +"by the path to the kernel and the `initramfs` image respectively. If a " +"separate `/boot` partition was created, the paths to the kernel and the " +"`initramfs` image are relative to `/boot`. In the example above, the `initrd " +"/initramfs-3.17.4-301.fc21.x86_64.img` line means that the `initramfs` image " +"is actually located at `/boot/initramfs-3.17.4-301.fc21.x86_64.img` when the " +"`root` file system is mounted, and likewise for the kernel path." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:54 +msgid "" +"The kernel version number as given on the `linux16 /vmlinuz-kernel_version` " +"line must match the version number of the `initramfs` image given on the " +"`initrd /initramfs-kernel_version.img` line of each `menuentry` block. For " +"more information on how to verify the initial RAM disk image, see " +"xref:kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc#sec-Verifying_the_Initial_RAM_Disk_Image[Verifying " +"the Initial RAM Disk Image]." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:59 +msgid "" +"In `menuentry` blocks, the `initrd` directive must point to the location " +"(relative to the `/boot/` directory if it is on a separate partition) of the " +"`initramfs` file corresponding to the same kernel version. This directive is " +"called `initrd` because the previous tool which created initial RAM disk " +"images, [command]#mkinitrd#, created what were known as `initrd` files. The " +"`grub.cfg` directive remains `initrd` to maintain compatibility with other " +"tools. The file-naming convention of systems using the [command]#dracut# " +"utility to create the initial RAM disk image is " +"`initramfs-_kernel_version_.img`." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:61 +msgid "" +"For information on using [application]*Dracut*, see " +"xref:kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc#sec-Verifying_the_Initial_RAM_Disk_Image[Verifying " +"the Initial RAM Disk Image]." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:65 +#, no-wrap +msgid "Configuring the GRUB 2 Boot Loader" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:68 +msgid "" +"Changes to the GRUB 2 menu can be made temporarily at boot time, made " +"persistent for a single system while the system is running, or as part of " +"making a new GRUB 2 configuration file." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:70 +msgid "" +"To make non-persistent changes to the GRUB 2 menu, see " +"xref:#sec-Making_Temporary_Changes_to_a_GRUB_2_Menu[Making Temporary Changes " +"to a GRUB 2 Menu]." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:72 +msgid "" +"To make persistent changes to a running system, see " +"xref:#sec-Making_Persistent_Changes_to_a_GRUB_2_Menu_Using_the_grubby_Tool[Making " +"Persistent Changes to a GRUB 2 Menu Using the grubby Tool]." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:74 +msgid "" +"For information on making and customizing a GRUB 2 configuration file, see " +"xref:#sec-Customizing_the_GRUB_2_Configuration_File[Customizing the GRUB 2 " +"Configuration File]." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:76 +#, no-wrap +msgid "Making Temporary Changes to a GRUB 2 Menu" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:79 +#, no-wrap +msgid "Making Temporary Changes to a Kernel Menu Entry" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:81 +msgid "" +"To change kernel parameters only during a single boot process, proceed as " +"follows:" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:83 +msgid "" +"Start the system and, on the GRUB 2 boot screen, move the cursor to the menu " +"entry you want to edit, and press the kbd:[e] key for edit." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:85 +msgid "" +"Move the cursor down to find the kernel command line. The kernel command " +"line starts with `linux` on 64-Bit IBM Power Series, `linux16` on x86-64 " +"BIOS-based systems, or `linuxefi` on UEFI systems." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:87 +msgid "Move the cursor to the end of the line." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:89 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:718 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:738 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:800 +msgid "" +"Press kbd:[Ctrl + a] and kbd:[Ctrl + e] to jump to the start and end of the " +"line, respectively. On some systems, kbd:[Home] and kbd:[End] might also " +"work." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:91 +msgid "" +"Edit the kernel parameters as required. For example, to run the system in " +"emergency mode, add the *emergency* parameter at the end of the `linux16` " +"line:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:95 +#, no-wrap +msgid "" +"linux16 /vmlinuz-4.2.0-1.fc23.x86_64 root=/dev/mapper/fedora-root ro " +"rd.md=0 rd.dm=0 rd.lvm.lv=fedora/swap crashkernel=auto rd.luks=0 " +"vconsole.keymap=us rd.lvm.lv=fedora/root rhgb quiet " +"pass:quotes[*emergency*]\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:98 +msgid "" +"The [option]`rhgb` and [option]`quiet` parameters can be removed in order to " +"enable system messages." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:100 +msgid "" +"These settings are not persistent and apply only for a single boot. To make " +"persistent changes to a menu entry on a system, use the [command]#grubby# " +"tool. See " +"xref:#bh-Adding_and_Removing_Arguments_from_a_GRUB_Menu_Entry[Adding and " +"Removing Arguments from a GRUB Menu Entry] for more information on using " +"[command]#grubby#." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:102 +#, no-wrap +msgid "Making Persistent Changes to a GRUB 2 Menu Using the grubby Tool" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:105 +msgid "" +"The [command]#grubby# tool can be used to read information from, and make " +"persistent changes to, the `grub.cfg` file. It enables, for example, " +"changing GRUB menu entries to specify what arguments to pass to a kernel on " +"system start and changing the default kernel." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:107 +msgid "" +"In Red{nbsp}Hat Enterprise{nbsp}Linux{nbsp}7, if [command]#grubby# is " +"invoked manually without specifying a GRUB configuration file, it defaults " +"to searching for `/etc/grub2.cfg`, which is a symbolic link to the " +"`grub.cfg` file, whose location is architecture dependent. If that file " +"cannot be found it will search for an architecture dependent default." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:108 +#, no-wrap +msgid "Listing the Default Kernel" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:110 +msgid "To find out the file name of the default kernel, enter a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:114 +#, no-wrap +msgid "" +"~]# grubby --default-kernel\n" +"/boot/vmlinuz-4.2.0-1.fc23.x86_64\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:117 +msgid "" +"To find out the index number of the default kernel, enter a command as " +"follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:121 +#, no-wrap +msgid "" +"~]# grubby --default-index\n" +"0\n" +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:123 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:248 +#, no-wrap +msgid "Changing the Default Boot Entry" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:125 +msgid "" +"To make a persistent change in the kernel designated as the default kernel, " +"use the [command]#grubby# command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:128 +#, no-wrap +msgid "~]# grubby --set-default /boot/vmlinuz-4.2.0-1.fc23.x86_64\n" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:130 +#, no-wrap +msgid "Viewing the GRUB Menu Entry for a Kernel" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:132 +msgid "To list all the kernel menu entries, enter a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:136 +#, no-wrap +msgid "~]$ [command]#grubby --info=ALL#\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:139 +msgid "On UEFI systems, all [command]#grubby# commands must be entered as `root`." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:141 +msgid "" +"To view the GRUB menu entry for a specific kernel, enter a command as " +"follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:150 +#, no-wrap +msgid "" +"~]$ grubby --info /boot/vmlinuz-4.2.0-1.fc23.x86_64\n" +"index=0\n" +"kernel=/boot/vmlinuz-4.2.0-1.fc23.x86_64\n" +"args=\"ro rd.lvm.lv=fedora/root rd.lvm.lv=fedora/swap rhgb quiet " +"LANG=en_US.UTF-8\"\n" +"root=/dev/mapper/fedora-root\n" +"initrd=/boot/initramfs-4.2.0-1.fc23.x86_64.img\n" +"title=Fedora (4.2.0-1.fc23.x86_64) 23 (Workstation Edition)\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:153 +msgid "" +"Try tab completion to see the available kernels within the `/boot/` " +"directory." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:155 +#, no-wrap +msgid "Adding and Removing Arguments from a GRUB Menu Entry" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:157 +msgid "" +"The [option]`--update-kernel` option can be used to update a menu entry when " +"used in combination with [option]`--args` to add new arguments and " +"[option]`--remove-arguments` to remove existing arguments. These options " +"accept a quoted space-separated list. The command to simultaneously add and " +"remove arguments a from GRUB menu entry has the follow format:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:161 +#, no-wrap +msgid "" +"grubby --remove-args=\"pass:attributes[{blank}]_argX " +"argY_pass:attributes[{blank}]\" --args=\"pass:attributes[{blank}]_argA " +"argB_pass:attributes[{blank}]\" --update-kernel " +"/boot/pass:attributes[{blank}]_kernel_\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:164 +msgid "" +"To add and remove arguments from a kernel's GRUB menu entry, use a command " +"as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:167 +#, no-wrap +msgid "" +"~]# grubby --remove-args=\"rhgb quiet\" --args=console=ttyS0,115200 " +"--update-kernel /boot/vmlinuz-4.2.0-1.fc23.x86_64\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:170 +msgid "" +"This command removes the Red Hat graphical boot argument, enables boot " +"message to be seen, and adds a serial console. As the console arguments will " +"be added at the end of the line, the new console will take precedence over " +"any other consoles configured." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:172 +msgid "To review the changes, use the [option]`--info` command option as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:182 +#, no-wrap +msgid "" +"~]# grubby --info /boot/vmlinuz-4.2.0-1.fc23.x86_64\n" +"index=0\n" +"kernel=/boot/vmlinuz-4.2.0-1.fc23.x86_64\n" +"args=\"ro rd.lvm.lv=fedora/root rd.lvm.lv=fedora/swap LANG=en_US.UTF-8 " +"pass:quotes[*console=ttyS0,115200*]\"\n" +"root=/dev/mapper/fedora-root\n" +"initrd=/boot/initramfs-4.2.0-1.fc23.x86_64.img\n" +"title=Fedora (4.2.0-1.fc23.x86_64) 23 (Workstation Edition)\n" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:184 +#, no-wrap +msgid "Updating All Kernel Menus with the Same Arguments" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:186 +msgid "" +"To add the same kernel boot arguments to all the kernel menu entries, enter " +"a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:189 +#, no-wrap +msgid "~]# grubby --update-kernel=ALL --args=console=ttyS0,115200\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:192 +msgid "" +"The [option]`--update-kernel` parameter also accepts DEFAULT or a comma " +"separated list of kernel index numbers." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:193 +#, no-wrap +msgid "Changing a Kernel Argument" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:195 +msgid "" +"To change a value in an existing kernel argument, specify the argument " +"again, changing the value as required. For example, if the virtual console " +"font size has been set to `latarcyrheb-sun16` and you want to change the " +"virtual console font size to `32`, use a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:205 +#, no-wrap +msgid "" +"~]# grubby --args=vconsole.font=latarcyrheb-sun32 --update-kernel " +"/boot/vmlinuz-4.2.0-1.fc23.x86_64\n" +"index=0\n" +"kernel=/boot/vmlinuz-4.2.0-1.fc23.x86_64\n" +"args=\"ro rd.lvm.lv=fedora/root crashkernel=auto rd.lvm.lv=fedora/swap " +"vconsole.font=pass:quotes[*latarcyrheb-sun32*] vconsole.keymap=us " +"LANG=en_US.UTF-8\"\n" +"root=/dev/mapper/fedora-root\n" +"initrd=/boot/initramfs-4.2.0-1.fc23.x86_64.img\n" +"title=Fedora (4.2.0-1.fc23.x86_64) 23 (Workstation Edition)\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:208 +msgid "See the `grubby(8)` manual page for more command options." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:209 +#, no-wrap +msgid "Adding a new entry with additional kernel arguments" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:211 +msgid "" +"To add a new entry with the default kernel but with additional kernel " +"arguments and make it the default entry, use:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:215 +#, no-wrap +msgid "" +"~]# grubby --add-kernel $(grubby --default-kernel) --copy-default " +"--args=crashkernel=128M --title \"Default kernel with kdump support\" " +"--make-default\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:218 +msgid "In this example, we set the `crashkernel=128M` argument for kdump support." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:220 +#, no-wrap +msgid "Customizing the GRUB 2 Configuration File" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:223 +msgid "" +"GRUB 2 scripts search the user's computer and build a boot menu based on " +"what operating systems the scripts find. To reflect the latest system boot " +"options, the boot menu is rebuilt automatically when the kernel is updated " +"or a new kernel is added." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:225 +msgid "" +"However, users may want to build a menu containing specific entries or to " +"have the entries in a specific order. GRUB 2 allows basic customization of " +"the boot menu to give users control of what actually appears on the screen." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:227 +msgid "" +"GRUB 2 uses a series of scripts to build the menu; these are located in the " +"`/etc/grub.d/` directory. The following files are included:" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:229 +msgid "`00_header`, which loads GRUB 2 settings from the `/etc/default/grub` file." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:231 +msgid "" +"`01_users`, which is created only when a boot loader password is assigned in " +"a [application]*kickstart* file." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:233 +msgid "`10_linux`, which locates kernels in the default partition of Fedora." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:235 +msgid "" +"`30_os-prober`, which builds entries for operating systems found on other " +"partitions." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:237 +msgid "" +"`40_custom`, a template, which can be used to create additional menu " +"entries." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:239 +msgid "" +"Scripts from the `/etc/grub.d/` directory are read in alphabetical order and " +"can be therefore renamed to change the boot order of specific menu entries." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:244 +msgid "" +"With the [option]`GRUB_TIMEOUT` key set to `0` in the `/etc/default/grub` " +"file, GRUB 2 does not display the list of bootable kernels when the system " +"starts up. In order to display this list when booting, press and hold any " +"alphanumeric key when the BIOS information is displayed; GRUB 2 will present " +"you with the GRUB menu." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:251 +msgid "" +"By default, the key for the `GRUB_DEFAULT` directive in the " +"`/etc/default/grub` file is the word `saved`. This instructs GRUB 2 to load " +"the kernel specified by the [option]`saved_entry` directive in the GRUB 2 " +"environment file, located at `/boot/grub2/grubenv`. You can set another GRUB " +"record to be the default, using the [command]#grub2-set-default# command, " +"which will update the GRUB 2 environment file." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:253 +msgid "" +"By default, the [option]`saved_entry` value is set to the name of latest " +"installed kernel of package type [package]*kernel*. This is defined in " +"`/etc/sysconfig/kernel` by the `UPDATEDEFAULT` and `DEFAULTKERNEL` " +"directives. The file can be viewed by the `root` user as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:260 +#, no-wrap +msgid "" +"~]#{nbsp}cat /etc/sysconfig/kernel\n" +"# UPDATEDEFAULT specifies if new-kernel-pkg should make\n" +"# new kernels the default\n" +"UPDATEDEFAULT=yes\n" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:263 +#, no-wrap +msgid "" +"# DEFAULTKERNEL specifies the default kernel package type\n" +"DEFAULTKERNEL=kernel-core\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:266 +msgid "" +"The `DEFAULTKERNEL` directive specifies what package type will be used as " +"the default. Installing a package of type [package]*kernel-debug* will not " +"change the default kernel while the `DEFAULTKERNEL` is set to package type " +"[package]*kernel*." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:268 +msgid "" +"GRUB 2 supports using a numeric value as the key for the " +"[option]`saved_entry` directive to change the default order in which the " +"operating systems are loaded. To specify which operating system should be " +"loaded first, pass its number to the [command]#grub2-set-default# " +"command. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:272 +#, no-wrap +msgid "~]#{nbsp}grub2-set-default pass:quotes[`2`]\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:275 +msgid "" +"Note that the position of a menu entry in the list is denoted by a number " +"starting with zero; therefore, in the example above, the third entry will be " +"loaded. This value will be overwritten by the name of the next kernel to be " +"installed." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:277 +msgid "" +"To force a system to always use a particular menu entry, use the menu entry " +"name as the key to the `GRUB_DEFAULT` directive in the `/etc/default/grub` " +"file. To list the available menu entries, run the following command as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:281 +#, no-wrap +msgid "~]#{nbsp}awk -F\\' '$1==\"menuentry \" {print $2}' /etc/grub2.cfg\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:284 +msgid "" +"The file name `/etc/grub2.cfg` is a symlink to the `grub.cfg` file, whose " +"location is architecture dependent. For reliability reasons, the symlink is " +"not used in other examples in this chapter. It is better to use absolute " +"paths when writing to a file, especially when repairing a system." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:286 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:306 +msgid "" +"Changes to `/etc/default/grub` require rebuilding the `grub.cfg` file as " +"follows:" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:288 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:308 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:418 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:498 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:597 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:644 +msgid "" +"On both UEFI-based and BIOS-based machines, issue the following command as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:292 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:312 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:422 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:502 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:601 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:648 +#, no-wrap +msgid "~]#{nbsp}grub2-mkconfig -o /boot/grub2/grub.cfg\n" +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:295 +#, no-wrap +msgid "Editing a Menu Entry" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:298 +msgid "" +"If required to prepare a new GRUB 2 file with different parameters, edit the " +"values of the `GRUB_CMDLINE_LINUX` key in the `/etc/default/grub` file. Note " +"that you can specify multiple parameters for the `GRUB_CMDLINE_LINUX` " +"key. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:301 +#, no-wrap +msgid "GRUB_CMDLINE_LINUX=\"console=tty0 console=ttyS0,9600n8\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:304 +msgid "" +"Where [option]`console=tty0` is the first virtual terminal and " +"[option]`console=ttyS0` is the serial terminal to be used." +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:315 +#, no-wrap +msgid "Adding a new Entry" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:318 +msgid "" +"When executing the [command]#grub2-mkconfig# command, GRUB 2 searches for " +"Linux kernels and other operating systems based on the files located in the " +"`/etc/grub.d/` directory. The `/etc/grub.d/10_linux` script searches for " +"installed Linux kernels on the same partition. The " +"`/etc/grub.d/30_os-prober` script searches for other operating systems. Menu " +"entries are also automatically added to the boot menu when updating the " +"kernel." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:320 +msgid "" +"The `40_custom` file located in the `/etc/grub.d/` directory is a template " +"for custom entries and looks as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:327 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:369 +#, no-wrap +msgid "" +"#!/bin/sh\n" +"exec tail -n +3 $0\n" +"# This file provides an easy way to add custom menu entries. Simply type " +"the\n" +"# menu entries you want to add after this comment. Be careful not to " +"change\n" +"# the 'exec tail' line above.\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:330 +msgid "" +"This file can be edited or copied. Note that as a minimum, a valid menu " +"entry must include at least the following:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:336 +#, no-wrap +msgid "" +"*menuentry* \"<Title>\"pass:attributes[{blank}]*{*\n" +"<Data>\n" +"*}*\n" +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:339 +#, no-wrap +msgid "Creating a Custom Menu" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:342 +msgid "" +"If you do not want menu entries to be updated automatically, you can create " +"a custom menu." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:347 +msgid "" +"Before proceeding, back up the contents of the `/etc/grub.d/` directory in " +"case you need to revert the changes later." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:354 +msgid "" +"Note that modifying the `/etc/default/grub` file does not have any effect on " +"creating custom menus." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:358 +msgid "" +"Copy the contents of `/boot/grub2/grub.cfg`. Put the content of the " +"`grub.cfg` into the `/etc/grub.d/40_custom` file below the existing header " +"lines. The executable part of the `40_custom` script has to be preserved." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:360 +msgid "" +"From the content put into the `/etc/grub.d/40_custom` file, only the " +"`menuentry` blocks are needed to create the custom menu. The " +"`/boot/grub2/grub.cfg` file might contain function specifications and other " +"content above and below the `menuentry` blocks. If you put these unnecessary " +"lines into the `40_custom` file in the previous step, erase them." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:362 +msgid "This is an example of a custom `40_custom` script:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:399 +#, no-wrap +msgid "" +"menuentry 'First custom entry' --class red --class gnu-linux --class gnu " +"--class os $menuentry_id_option " +"'gnulinux-4.2.0-1.fc23.x86_64-advanced-32782dd0-4b47-4d56-a740-2076ab5e5976' " +"{\n" +" load_video\n" +" set gfxpayload=keep\n" +" insmod gzio\n" +" insmod part_msdos\n" +" insmod xfs\n" +" set root='hd0,msdos1'\n" +" if [ x$feature_platform_search_hint = xy ]; then\n" +" search --no-floppy --fs-uuid --set=root --hint='hd0,msdos1' " +"7885bba1-8aa7-4e5d-a7ad-821f4f52170a\n" +" else\n" +" search --no-floppy --fs-uuid --set=root " +"7885bba1-8aa7-4e5d-a7ad-821f4f52170a\n" +" fi\n" +" linux16 /vmlinuz-4.2.0-1.fc23.x86_64 root=/dev/mapper/fedora-root ro " +"rd.lvm.lv=fedora/root vconsole.font=latarcyrheb-sun16 rd.lvm.lv=fedora/swap " +"vconsole.keymap=us crashkernel=auto rhgb quiet LANG=en_US.UTF-8\n" +" initrd16 /initramfs-4.2.0-1.fc23.x86_64.img\n" +"}\n" +"menuentry 'Second custom entry' --class red --class gnu-linux --class gnu " +"--class os $menuentry_id_option " +"'gnulinux-0-rescue-07f43f20a54c4ce8ada8b70d33fd001c-advanced-32782dd0-4b47-4d56-a740-2076ab5e5976' " +"{\n" +" load_video\n" +" insmod gzio\n" +" insmod part_msdos\n" +" insmod xfs\n" +" set root='hd0,msdos1'\n" +" if [ x$feature_platform_search_hint = xy ]; then\n" +" search --no-floppy --fs-uuid --set=root --hint='hd0,msdos1' " +"7885bba1-8aa7-4e5d-a7ad-821f4f52170a\n" +" else\n" +" search --no-floppy --fs-uuid --set=root " +"7885bba1-8aa7-4e5d-a7ad-821f4f52170a\n" +" fi\n" +" linux16 /vmlinuz-0-rescue-07f43f20a54c4ce8ada8b70d33fd001c " +"root=/dev/mapper/fedora-root ro rd.lvm.lv=fedora/root " +"vconsole.font=latarcyrheb-sun16 rd.lvm.lv=fedora/swap vconsole.keymap=us " +"crashkernel=auto rhgb quiet\n" +" initrd16 /initramfs-0-rescue-07f43f20a54c4ce8ada8b70d33fd001c.img\n" +"}\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:402 +msgid "Remove all files from the `/etc/grub.d` directory except the following:" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:404 +msgid "`00_header`," +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:406 +msgid "`40_custom`," +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:408 +msgid "`01_users` (if it exists)," +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:410 +msgid "and `README`." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:412 +msgid "" +"Alternatively, if you want to keep the files in the `/etc/grub2.d/` " +"directory, make them unexecutable by running the [command]#chmod a-x " +"# command." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:414 +msgid "Edit, add, or remove menu entries in the `40_custom` file as desired." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:416 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:496 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:595 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:642 +msgid "" +"Rebuild the `grub.cfg` file by running the [command]#grub2-mkconfig -o# " +"command as follows:" +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:425 +#, no-wrap +msgid "GRUB 2 Password Protection" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:428 +msgid "" +"GRUB 2 supports both plain-text and encrypted passwords in the GRUB 2 " +"template files. To enable the use of passwords, specify a superuser who can " +"reach the protected entries. Other users can be specified to access these " +"entries as well. Menu entries can be password-protected for booting by " +"adding one or more users to the menu entry as described in " +"xref:#sec-Setting_Up_Users_and_Password_Protection_Specifying_Menu_Entries[Setting " +"Up Users and Password Protection, Specifying Menu Entries]. To use encrypted " +"passwords, see xref:#sec-Password_Encryption[Password Encryption]." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:433 +msgid "" +"If you do not use the correct format for the menu, or modify the " +"configuration in an incorrect way, you might be unable to boot your system." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:437 +msgid "" +"All menu entries can be password-protected against changes by setting " +"superusers, which can be done in the `/etc/grub.d/00_header` or the " +"`/etc/grub.d/01_users` file. The `00_header` file is very complicated and, " +"if possible, avoid making modifications in this file. Menu entries should be " +"placed in the `/etc/grub.d/40_custom` and users in the " +"`/etc/grub.d/01_users` file. The `01_users` file is generated by the " +"installation application [application]*anaconda* when a grub boot loader " +"password is used in a [application]*kickstart* template (but it should be " +"created and used it if it does not exist). Examples in this section adopt " +"this policy." +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:439 +#, no-wrap +msgid "Setting Up Users and Password Protection, Specifying Menu Entries" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:442 +msgid "" +"To specify a superuser, add the following lines in the " +"`/etc/grub.d/01_users` file, where `john` is the name of the user designated " +"as the superuser, and `johnspassword` is the superuser's password:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:449 +#, no-wrap +msgid "" +"cat <<EOF\n" +"set superusers=\"john\"\n" +"password john johnspassword\n" +"EOF\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:452 +msgid "" +"To allow other users to access the menu entries, add additional lines per " +"user at the end of the `/etc/grub.d/01_users` file." +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:460 +#, no-wrap +msgid "" +"cat <<EOF\n" +"set superusers=\"john\"\n" +"password john johnspassword\n" +"password jane janespassword\n" +"EOF\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:463 +msgid "" +"When the users and passwords are set up, specify the menu entries that " +"should be password-protected in the `/etc/grub.d/40_custom` file in a " +"similar fashion to the following:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:471 +#, no-wrap +msgid "" +"menuentry 'Red{nbsp}Hat Enterprise{nbsp}Linux Server' --unrestricted {\n" +"set root=(hd0,msdos1)\n" +"linux /vmlinuz\n" +"}\n" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:476 +#, no-wrap +msgid "" +"menuentry 'Fedora' --users jane {\n" +"set root=(hd0,msdos2)\n" +"linux /vmlinuz\n" +"}\n" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:481 +#, no-wrap +msgid "" +"menuentry 'Red{nbsp}Hat Enterprise{nbsp}Linux Workstation' {\n" +"set root=(hd0,msdos3)\n" +"linux /vmlinuz\n" +"}\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:484 +msgid "In the above example:" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:486 +msgid "" +"`john` is the `superuser` and can therefore boot any menu entry, use the " +"GRUB 2 command line, and edit items of the GRUB 2 menu during boot. In this " +"case, `john` can access both Red{nbsp}Hat Enterprise{nbsp}Linux Server, " +"Fedora, and Red{nbsp}Hat Enterprise{nbsp}Linux Workstation. Note that only " +"`john` can access Red{nbsp}Hat Enterprise{nbsp}Linux Workstation because " +"neither the [option]`--users` nor [option]`--unrestricted` options have been " +"used." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:488 +msgid "" +"User `jane` can boot Fedora since she was granted the permission in the " +"configuration." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:490 +msgid "" +"Anyone can boot Red{nbsp}Hat Enterprise{nbsp}Linux Server, because of the " +"[option]`--unrestricted` option, but only `john` can edit the menu entry as " +"a superuser has been defined. When a superuser is defined then all records " +"are protected against unauthorized changes and all records are protected for " +"booting if they do *not* have the [option]`--unrestricted` parameter" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:492 +msgid "" +"If you do not specify a user for a menu entry, or make use of the " +"[option]`--unrestricted` option, then only the superuser will have access to " +"the system." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:494 +msgid "" +"After you have made changes in the template file the GRUB 2 configuration " +"file must be updated." +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:505 +#, no-wrap +msgid "Password Encryption" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:508 +msgid "" +"By default, passwords are saved in plain text in GRUB 2 scripts. Although " +"the files cannot be accessed on boot without the correct password, security " +"can be improved by encrypting the password using the " +"[command]#grub2-mkpasswd-pbkdf2# command. This command converts a desired " +"password into a long hash, which is placed in the GRUB 2 scripts instead of " +"the plain-text password." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:510 +msgid "" +"To generate an encrypted password, run the [command]#grub2-mkpasswd-pbkdf2# " +"command on the command line as `root`." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:512 +msgid "" +"Enter the desired password when prompted and repeat it. The command then " +"outputs your password in an encrypted form." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:514 +msgid "" +"Copy the hash, and paste it in the template file where you configured the " +"users, that is, either in `/etc/grub.d/01_users` or `/etc/grub.d/40_custom`." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:516 +msgid "The following format applies for the `01_users` file:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:522 +#, no-wrap +msgid "" +"cat <` — This directory " +"contains information about using and configuring GRUB 2. `` " +"corresponds to the version of the GRUB 2 package installed." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:934 +msgid "" +"[command]#info grub2# — The GRUB 2 info page contains a tutorial, a " +"user reference manual, a programmer reference manual, and a FAQ document " +"about GRUB 2 and its usage." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:936 +msgid "" +"`grubby(8)` — The manual page for the command-line tool for configuring GRUB " +"and GRUB 2." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:938 +msgid "" +"`new-kernel-pkg(8)` — The manual page for the tool to script kernel " +"installation." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:939 +#, no-wrap +msgid "External Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:941 +msgid "" +"link:++https://docs.fedoraproject.org/install-guide++[ {MAJOROS} " +"Installation Guide] — The Installation Guide provides basic " +"information on GRUB 2, for example, installation, terminology, interfaces, " +"and commands." +msgstr "" diff --git a/po/fr/rawhide/pages/kernel-module-driver-configuration/intro-kernel-module-driver-configuration.po b/po/fr/rawhide/pages/kernel-module-driver-configuration/intro-kernel-module-driver-configuration.po new file mode 100644 index 00000000000..52e3a68fe53 --- /dev/null +++ b/po/fr/rawhide/pages/kernel-module-driver-configuration/intro-kernel-module-driver-configuration.po @@ -0,0 +1,30 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/kernel-module-driver-configuration/intro-kernel-module-driver-configuration.adoc:1 +#, no-wrap +msgid "Kernel, Module and Driver Configuration" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/intro-kernel-module-driver-configuration.adoc:3 +msgid "" +"This part covers various tools that assist administrators with kernel " +"customization." +msgstr "" diff --git a/po/fr/rawhide/pages/monitoring-and-automation/Automating_System_Tasks.po b/po/fr/rawhide/pages/monitoring-and-automation/Automating_System_Tasks.po new file mode 100644 index 00000000000..6e5dc8428da --- /dev/null +++ b/po/fr/rawhide/pages/monitoring-and-automation/Automating_System_Tasks.po @@ -0,0 +1,1362 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:6 +#, no-wrap +msgid "Automating System Tasks" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:9 +msgid "" +"indexterm:[Automated Tasks] Tasks, also known as _jobs_, can be configured " +"to run automatically within a specified period of time, on a specified date, " +"or when the system load average decreases below 0.8." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:11 +msgid "" +"{MAJOROS} is pre-configured to run important system tasks to keep the system " +"updated. For example, the slocate database used by the [command]#locate# " +"command is updated daily. A system administrator can use automated tasks to " +"perform periodic backups, monitor the system, run custom scripts, and so on." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:13 +msgid "" +"{MAJOROS} comes with the following automated task utilities: " +"[command]#cron#, [command]#anacron#, [command]#at#, and [command]#batch#." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:15 +msgid "" +"Every utility is intended for scheduling a different job type: while Cron " +"and Anacron schedule recurring jobs, At and Batch schedule one-time jobs " +"(refer to xref:Automating_System_Tasks.adoc#s1-autotasks-cron-anacron[Cron " +"and Anacron] and xref:Automating_System_Tasks.adoc#s1-autotasks-at-batch[At " +"and Batch] respectively)." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:17 +msgid "" +"{MAJOROS} supports the use of `systemd.timer` for executing a job at a " +"specific time. See man `systemd.timer(5)` for more information." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:19 +#, no-wrap +msgid "Cron and Anacron" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:22 +msgid "" +"indexterm:[anacron]indexterm:[cron] Both Cron and Anacron can schedule " +"execution of recurring tasks to a certain point in time defined by the exact " +"time, day of the month, month, day of the week, and week." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:24 +msgid "" +"Cron jobs can run as often as every minute. However, the utility assumes " +"that the system is running continuously and if the system is not on at the " +"time when a job is scheduled, the job is not executed." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:26 +msgid "" +"On the other hand, Anacron remembers the scheduled jobs if the system is not " +"running at the time when the job is scheduled. The job is then executed as " +"soon as the system is up. However, Anacron can only run a job once a " +"day. Also note that by default, Anacron only runs when your system is " +"running on AC power and will not run if your system is being powered by a " +"battery; this behavior is set up in the " +"[filename]`/etc/cron.hourly/0anacron` script." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:28 +#, no-wrap +msgid "Installing Cron and Anacron" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:31 +msgid "" +"To install Cron and Anacron, you need to install the [package]*cronie* " +"package with Cron and the [package]*cronie-anacron* package with Anacron " +"([package]*cronie-anacron* is a sub-package of [package]*cronie*)." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:33 +msgid "" +"To determine if the packages are already installed on your system, issue the " +"following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:37 +#, no-wrap +msgid "[command]#rpm -q cronie cronie-anacron#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:40 +msgid "" +"The command returns full names of the [package]*cronie* and " +"[package]*cronie-anacron* packages if already installed, or notifies you " +"that the packages are not available." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:42 +msgid "" +"To install these packages, use the [command]#dnf# command in the following " +"form as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:46 +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:342 +#, no-wrap +msgid "[command]#dnf install _package_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:49 +msgid "" +"For example, to install both Cron and Anacron, type the following at a shell " +"prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:53 +#, no-wrap +msgid "~]#{nbsp}dnf install cronie cronie-anacron\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:56 +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:352 +msgid "" +"For more information on how to install new packages in {MAJOROS}, see " +"xref:package-management/DNF.adoc#sec-Installing[Installing Packages]." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:58 +#, no-wrap +msgid "Running the Crond Service" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:61 +msgid "" +"The cron and anacron jobs are both picked by the `crond` service. This " +"section provides information on how to start, stop, and restart the `crond` " +"service, and shows how to configure it to start automatically at boot time." +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:63 +#, no-wrap +msgid "Starting and Stopping the Cron Service" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:66 +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:362 +msgid "To determine if the service is running, use the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:70 +#, no-wrap +msgid "[command]#systemctl status crond.service#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:73 +msgid "" +"To run the `crond` service in the current session, type the following at a " +"shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:77 +#, no-wrap +msgid "[command]#systemctl start crond.service#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:80 +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:376 +msgid "" +"To configure the service to start automatically at boot time, use the " +"following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:84 +#, no-wrap +msgid "[command]#systemctl enable crond.service#\n" +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:87 +#, no-wrap +msgid "Stopping the Cron Service" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:90 +msgid "" +"To stop the `crond` service in the current session, type the following at a " +"shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:94 +#, no-wrap +msgid "[command]#systemctl stop crond.service#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:97 +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:400 +msgid "" +"To prevent the service from starting automatically at boot time, use the " +"following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:101 +#, no-wrap +msgid "[command]#systemctl disable crond.service#\n" +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:104 +#, no-wrap +msgid "Restarting the Cron Service" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:107 +msgid "" +"To restart the `crond` service, type the following at a shell prompt as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:111 +#, no-wrap +msgid "[command]#systemctl restart crond.service#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:114 +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:417 +msgid "This command stops the service and starts it again in quick succession." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:116 +#, no-wrap +msgid "Configuring Anacron Jobs" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:119 +msgid "" +"indexterm:[anacron,anacron configuration " +"file]indexterm:[anacrontab]indexterm:[anacron,user-defined " +"tasks]indexterm:[/var/spool/anacron] The main configuration file to schedule " +"jobs is the `/etc/anacrontab` file, which can be only accessed by the `root` " +"user. The file contains the following:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:128 +#, no-wrap +msgid "" +"SHELL=/bin/sh\n" +"PATH=/sbin:/bin:/usr/sbin:/usr/bin\n" +"MAILTO=root\n" +"# the maximal random delay added to the base delay of the jobs\n" +"RANDOM_DELAY=45\n" +"# the jobs will be started during the following hours only\n" +"START_HOURS_RANGE=3-22\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:133 +#, no-wrap +msgid "" +"#period in days delay in minutes job-identifier command\n" +"1 5 cron.daily nice run-parts /etc/cron.daily\n" +"7 25 cron.weekly nice run-parts /etc/cron.weekly\n" +"@monthly 45 cron.monthly nice run-parts /etc/cron.monthly\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:136 +msgid "" +"The first three lines define the variables that configure the environment in " +"which the anacron tasks run:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:138 +msgid "" +"`SHELL` — shell environment used for running jobs (in the example, the " +"Bash shell)" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:140 +msgid "`PATH` — paths to executable programs" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:142 +msgid "" +"`MAILTO` — username of the user who receives the output of the anacron " +"jobs by email" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:144 +msgid "If the `MAILTO` variable is not defined (`MAILTO=`), the email is not sent." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:146 +msgid "The next two variables modify the scheduled time for the defined jobs:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:148 +msgid "" +"`RANDOM_DELAY` — maximum number of minutes that will be added to the " +"`delay in minutes` variable which is specified for each job" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:150 +msgid "The minimum delay value is set, by default, to 6 minutes." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:152 +msgid "" +"If `RANDOM_DELAY` is, for example, set to `12`, then between 6 and 12 " +"minutes are added to the `delay in minutes` for each job in that particular " +"anacrontab. `RANDOM_DELAY` can also be set to a value below `6`, including " +"`0`. When set to `0`, no random delay is added. This proves to be useful " +"when, for example, more computers that share one network connection need to " +"download the same data every day." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:154 +msgid "" +"`START_HOURS_RANGE` — interval, when scheduled jobs can be run, in " +"hours" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:156 +msgid "" +"In case the time interval is missed, for example due to a power failure, the " +"scheduled jobs are not executed that day." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:158 +msgid "" +"The remaining lines in the `/etc/anacrontab` file represent scheduled jobs " +"and follow this format:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:163 +#, no-wrap +msgid "period in days delay in minutes job-identifier command\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:167 +msgid "`period in days` — frequency of job execution in days" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:169 +msgid "" +"The property value can be defined as an integer or a macro (`@daily`, " +"`@weekly`, `@monthly`), where `@daily` denotes the same value as integer 1, " +"`@weekly` the same as 7, and `@monthly` specifies that the job is run once a " +"month regardless of the length of the month." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:171 +msgid "" +"`delay in minutes` — number of minutes anacron waits before executing " +"the job" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:173 +msgid "" +"The property value is defined as an integer. If the value is set to `0`, no " +"delay applies." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:175 +msgid "" +"`job-identifier` — unique name referring to a particular job used in " +"the log files" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:177 +msgid "`command` — command to be executed" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:179 +msgid "" +"The command can be either a command such as [command]#ls /proc >> /tmp/proc# " +"or a command which executes a custom script." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:181 +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:272 +msgid "" +"Any lines that begin with a hash sign (#) are comments and are not " +"processed." +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:183 +#, no-wrap +msgid "Examples of Anacron Jobs" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:186 +msgid "The following example shows a simple `/etc/anacrontab` file:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:191 +#, no-wrap +msgid "" +"SHELL=/bin/sh\n" +"PATH=/sbin:/bin:/usr/sbin:/usr/bin\n" +"MAILTO=root\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:196 +#, no-wrap +msgid "" +"# the maximal random delay added to the base delay of the jobs\n" +"RANDOM_DELAY=30\n" +"# the jobs will be started during the following hours only\n" +"START_HOURS_RANGE=16-20\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:201 +#, no-wrap +msgid "" +"#period in days delay in minutes job-identifier command\n" +"1 20 dailyjob nice run-parts /etc/cron.daily\n" +"7 25 weeklyjob /etc/weeklyjob.bash\n" +"@monthly 45 monthlyjob ls /proc >> /tmp/proc\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:204 +msgid "" +"All jobs defined in this `anacrontab` file are randomly delayed by 6-30 " +"minutes and can be executed between 16:00 and 20:00." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:206 +msgid "" +"The first defined job is triggered daily between 16:26 and 16:50 " +"(RANDOM_DELAY is between 6 and 30 minutes; the `delay in minutes` property " +"adds 20 minutes). The command specified for this job executes all present " +"programs in the `/etc/cron.daily/` directory using the [command]#run-parts# " +"script (the [command]#run-parts# scripts accepts a directory as a " +"command-line argument and sequentially executes every program in the " +"directory). See the `run-parts` man page for more information on the " +"[command]#run-parts# script." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:208 +msgid "" +"The second job executes the `weeklyjob.bash` script in the `/etc/` directory " +"once a week." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:210 +msgid "" +"The third job runs a command, which writes the contents of `/proc` to the " +"`/tmp/proc` file ([command]#ls /proc >> /tmp/proc#) once a month." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:212 +#, no-wrap +msgid "Configuring Cron Jobs" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:215 +msgid "" +"indexterm:[cron,user-defined " +"tasks]indexterm:[/var/spool/cron]indexterm:[cron,cron configuration " +"file]indexterm:[crontab] The configuration file for cron jobs is " +"`/etc/crontab`, which can be only modified by the `root` user. The file " +"contains the following:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:230 +#, no-wrap +msgid "" +"SHELL=/bin/bash\n" +"PATH=/sbin:/bin:/usr/sbin:/usr/bin\n" +"MAILTO=root\n" +"HOME=/\n" +"# For details see man 4 crontabs\n" +"# Example of job definition:\n" +"# .---------------- minute (0 - 59)\n" +"# | .------------- hour (0 - 23)\n" +"# | | .---------- day of month (1 - 31)\n" +"# | | | .------- month (1 - 12) OR jan,feb,mar,apr ...\n" +"# | | | | .---- day of week (0 - 6) (Sunday=0 or 7) OR " +"sun,mon,tue,wed,thu,fri,sat\n" +"# | | | | |\n" +"# * * * * * user-name command to be executed\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:233 +msgid "" +"The first three lines contain the same variable definitions as an " +"`anacrontab` file: `SHELL`, `PATH`, and `MAILTO`. For more information about " +"these variables, see " +"xref:Automating_System_Tasks.adoc#s2-configuring-anacron-jobs[Configuring " +"Anacron Jobs]." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:235 +msgid "" +"In addition, the file can define the `HOME` variable. The `HOME` variable " +"defines the directory, which will be used as the home directory when " +"executing commands or scripts run by the job." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:237 +msgid "" +"The remaining lines in the `/etc/crontab` file represent scheduled jobs and " +"have the following format:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:241 +#, no-wrap +msgid "minute hour day month day of week username command\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:244 +msgid "The following define the time when the job is to be run:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:246 +msgid "`minute` — any integer from 0 to 59" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:248 +msgid "`hour` — any integer from 0 to 23" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:250 +msgid "" +"`day` — any integer from 1 to 31 (must be a valid day if a month is " +"specified)" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:252 +msgid "" +"`month` — any integer from 1 to 12 (or the short name of the month " +"such as jan or feb)" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:254 +msgid "" +"`day of week` — any integer from 0 to 7, where 0 or 7 represents " +"Sunday (or the short name of the week such as sun or mon)" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:256 +msgid "The following define other job properties:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:258 +msgid "`username` — specifies the user under which the jobs are run." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:260 +msgid "`command` — the command to be executed." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:262 +msgid "" +"The command can be either a command such as [command]#ls /proc /tmp/proc# or " +"a command which executes a custom script." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:264 +msgid "" +"For any of the above values, an asterisk (*) can be used to specify all " +"valid values. If you, for example, define the month value as an asterisk, " +"the job will be executed every month within the constraints of the other " +"values." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:266 +msgid "" +"A hyphen (-) between integers specifies a range of integers. For example, " +"`1-4` means the integers 1, 2, 3, and 4." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:268 +msgid "" +"A list of values separated by commas (,) specifies a list. For example, " +"`3,4,6,8` indicates exactly these four integers." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:270 +msgid "" +"The forward slash (/) can be used to specify step values. The value of an " +"integer will be skipped within a range following the range with " +"`/pass:attributes[{blank}]_integer_pass:attributes[{blank}]`. For example, " +"the minute value defined as `0-59/2` denotes every other minute in the " +"minute field. Step values can also be used with an asterisk. For instance, " +"if the month value is defined as `*/3`, the task will run every third month." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:274 +msgid "" +"Users other than `root` can configure cron tasks with the [command]#crontab# " +"utility. The user-defined crontabs are stored in the `/var/spool/cron/` " +"directory and executed as if run by the users that created them." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:276 +msgid "" +"To create a crontab as a specific user, login as that user and type the " +"command [command]#crontab -e# to edit the user's crontab with the editor " +"specified in the `VISUAL` or `EDITOR` environment variable. The file uses " +"the same format as `/etc/crontab`. When the changes to the crontab are " +"saved, the crontab is stored according to the user name and written to the " +"file " +"`/var/spool/cron/pass:attributes[{blank}]_username_pass:attributes[{blank}]`. " +"To list the contents of the current user's crontab file, use the " +"[command]#crontab -l# command." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:278 +msgid "" +"The `/etc/cron.d/` directory contains files that have the same syntax as the " +"`/etc/crontab` file. Only `root` is allowed to create and modify files in " +"this directory." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:279 +#, no-wrap +msgid "Do not restart the daemon to apply the changes" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:284 +msgid "" +"The cron daemon checks the `/etc/anacrontab` file, the `/etc/crontab` file, " +"the `/etc/cron.d/` directory, and the `/var/spool/cron/` directory every " +"minute for changes and the detected changes are loaded into memory. It is " +"therefore not necessary to restart the daemon after an anacrontab or a " +"crontab file have been changed." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:288 +#, no-wrap +msgid "Controlling Access to Cron" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:291 +msgid "" +"To restrict the access to Cron, you can use the `/etc/cron.allow` and " +"`/etc/cron.deny` files. These access control files use the same format with " +"one user name on each line. Mind that no whitespace characters are permitted " +"in either file." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:293 +msgid "" +"If the `cron.allow` file exists, only users listed in the file are allowed " +"to use cron, and the `cron.deny` file is ignored." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:295 +msgid "" +"If the `cron.allow` file does not exist, users listed in the `cron.deny` " +"file are not allowed to use Cron." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:297 +msgid "" +"The Cron daemon (`crond`) does not have to be restarted if the access " +"control files are modified. The access control files are checked each time a " +"user tries to add or delete a cron job." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:299 +msgid "" +"The `root` user can always use cron, regardless of the user names listed in " +"the access control files." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:301 +msgid "" +"You can control the access also through Pluggable Authentication Modules " +"(PAM). The settings are stored in the `/etc/security/access.conf` file. For " +"example, after adding the following line to the file, no other user but the " +"`root` user can create crontabs:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:305 +#, no-wrap +msgid "-:ALL EXCEPT root :cron\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:308 +msgid "" +"The forbidden jobs are logged in an appropriate log file or, when using " +"[command]#crontab -e#, returned to the standard output. For more " +"information, see the `access.conf.5` manual page." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:310 +#, no-wrap +msgid "Black and White Listing of Cron Jobs" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:313 +msgid "" +"Black and white listing of jobs is used to define parts of a job that do not " +"need to be executed. This is useful when calling the " +"[application]*run-parts* script on a Cron directory, such as " +"`/etc/cron.daily/`: if the user adds programs located in the directory to " +"the job black list, the [application]*run-parts* script will not execute " +"these programs." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:315 +msgid "" +"To define a black list, create a `jobs.deny` file in the directory that " +"[command]#run-parts# scripts will be executing from. For example, if you " +"need to omit a particular program from `/etc/cron.daily/`, create the " +"`/etc/cron.daily/jobs.deny` file. In this file, specify the names of the " +"programs to be omitted from execution (only programs located in the same " +"directory can be enlisted). If a job runs a command which runs the programs " +"from the `/etc/cron.daily/` directory, such as [command]#run-parts " +"/etc/cron.daily#, the programs defined in the `jobs.deny` file will not be " +"executed." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:317 +msgid "To define a white list, create a `jobs.allow` file." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:319 +msgid "" +"The principles of `jobs.deny` and `jobs.allow` are the same as those of " +"`cron.deny` and `cron.allow` described in section " +"xref:Automating_System_Tasks.adoc#s2-autotasks-cron-access[Controlling " +"Access to Cron]." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:321 +#, no-wrap +msgid "At and Batch" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:324 +msgid "" +"indexterm:[at]indexterm:[batch] While Cron is used to schedule recurring " +"tasks, the [application]*At* utility is used to schedule a one-time task at " +"a specific time and the [application]*Batch* utility is used to schedule a " +"one-time task to be executed when the system load average drops below 0.8." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:326 +#, no-wrap +msgid "Installing At and Batch" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:329 +msgid "" +"To determine if the [package]*at* package is already installed on your " +"system, issue the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:333 +#, no-wrap +msgid "[command]#rpm -q at#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:336 +msgid "" +"The command returns the full name of the [package]*at* package if already " +"installed or notifies you that the package is not available." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:338 +msgid "" +"To install the packages, use the [command]#dnf# command in the following " +"form as `root`:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:345 +msgid "" +"For example, to install both At and Batch, type the following at a shell " +"prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:349 +#, no-wrap +msgid "~]#{nbsp}dnf install at\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:354 +#, no-wrap +msgid "Running the At Service" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:357 +msgid "" +"The At and Batch jobs are both picked by the `atd` service. This section " +"provides information on how to start, stop, and restart the `atd` service, " +"and shows how to configure it to start automatically at boot time." +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:359 +#, no-wrap +msgid "Starting and Stopping the At Service" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:366 +#, no-wrap +msgid "[command]#systemctl status atd.service#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:369 +msgid "" +"To run the `atd` service in the current session, type the following at a " +"shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:373 +#, no-wrap +msgid "[command]#systemctl start atd.service#\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:380 +#, no-wrap +msgid "[command]#systemctl enable atd.service#\n" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:386 +msgid "" +"It is recommended that you configure your system to start the `atd` service " +"automatically at boot time." +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:390 +#, no-wrap +msgid "Stopping the At Service" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:393 +msgid "To stop the `atd` service, type the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:397 +#, no-wrap +msgid "[command]#systemctl stop atd.service#\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:404 +#, no-wrap +msgid "[command]#systemctl disable atd.service#\n" +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:407 +#, no-wrap +msgid "Restarting the At Service" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:410 +msgid "" +"To restart the `atd` service, type the following at a shell prompt as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:414 +#, no-wrap +msgid "[command]#systemctl restart atd.service#\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:419 +#, no-wrap +msgid "Configuring an At Job" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:422 +msgid "" +"To schedule a one-time job for a specific time with the [application]*At* " +"utility, do the following:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:424 +msgid "" +"On the command line, type the command [command]#at " +"_TIME_pass:attributes[{blank}]#, where " +"[command]#pass:attributes[{blank}]_TIME_pass:attributes[{blank}]# is the " +"time when the command is to be executed." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:426 +msgid "The _TIME_ argument can be defined in any of the following formats:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:428 +msgid "" +"`pass:attributes[{blank}]_HH_:pass:attributes[{blank}]_MM_pass:attributes[{blank}]` " +"specifies the exact hour and minute; For example, `04:00` specifies 4:00 " +"a.m." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:430 +msgid "`midnight` specifies 12:00 a.m." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:432 +msgid "`noon` specifies 12:00 p.m." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:434 +msgid "`teatime` specifies 4:00 p.m." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:436 +msgid "" +"`pass:attributes[{blank}]_MONTH_pass:attributes[{blank}]pass:attributes[{blank}]_DAY_pass:attributes[{blank}]pass:attributes[{blank}]_YEAR_pass:attributes[{blank}]` " +"format; For example, `January 15 2012` specifies the 15th day of January in " +"the year 2012. The year value is optional." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:438 +msgid "" +"`pass:attributes[{blank}]_MMDDYY_pass:attributes[{blank}]`, " +"`pass:attributes[{blank}]_MM_pass:attributes[{blank}]/pass:attributes[{blank}]_DD_pass:attributes[{blank}]/pass:attributes[{blank}]_YY_pass:attributes[{blank}]`, " +"or `pass:attributes[{blank}]_MM_._DD_._YY_pass:attributes[{blank}]` formats; " +"For example, `011512` for the 15th day of January in the year 2012." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:440 +msgid "" +"`now + _TIME_pass:attributes[{blank}]` where _TIME_ is defined as an integer " +"and the value type: minutes, hours, days, or weeks. For example, `now + 5 " +"days` specifies that the command will be executed at the same time five days " +"from now." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:442 +msgid "" +"The time must be specified first, followed by the optional date. For more " +"information about the time format, see the " +"`/usr/share/doc/at-__pass:attributes[{blank}]/timespec` text file." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:444 +msgid "" +"If the specified time has past, the job is executed at the time the next " +"day." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:446 +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:471 +msgid "In the displayed `at>` prompt, define the job commands:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:448 +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:473 +msgid "" +"Type the command the job should execute and press kbd:[Enter]. Optionally, " +"repeat the step to provide multiple commands." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:450 +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:475 +msgid "" +"Enter a shell script at the prompt and press kbd:[Enter] after each line in " +"the script." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:452 +msgid "" +"The job will use the shell set in the user's `SHELL` environment, the user's " +"login shell, or [command]#/bin/sh# (whichever is found first)." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:454 +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:479 +msgid "Once finished, press kbd:[Ctrl + D] on an empty line to exit the prompt." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:456 +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:481 +msgid "" +"If the set of commands or the script tries to display information to " +"standard output, the output is emailed to the user." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:458 +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:483 +msgid "" +"To view the list of pending jobs, use the [command]#atq# command. See " +"xref:Automating_System_Tasks.adoc#s2-autotasks-at-batch-viewing[Viewing " +"Pending Jobs] for more information." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:460 +msgid "" +"You can also restrict the usage of the [command]#at# command. For more " +"information, see " +"xref:Automating_System_Tasks.adoc#s2-autotasks-at-batch-controlling-access[Controlling " +"Access to At and Batch] for details." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:462 +#, no-wrap +msgid "Configuring a Batch Job" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:465 +msgid "" +"The [application]*Batch* application executes the defined one-time tasks " +"when the system load average decreases below 0.8." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:467 +msgid "To define a Batch job, do the following:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:469 +msgid "On the command line, type the command [command]#batch#." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:477 +msgid "" +"If a script is entered, the job uses the shell set in the user's `SHELL` " +"environment, the user's login shell, or [command]#/bin/sh# (whichever is " +"found first)." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:485 +msgid "" +"You can also restrict the usage of the [command]#batch# command. For more " +"information, see " +"xref:Automating_System_Tasks.adoc#s2-autotasks-at-batch-controlling-access[Controlling " +"Access to At and Batch] for details." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:487 +#, no-wrap +msgid "Viewing Pending Jobs" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:490 +msgid "" +"To view the pending [command]#At# and [command]#Batch# jobs, run the " +"[command]#atq# command. The [command]#atq# command displays a list of " +"pending jobs, with each job on a separate line. Each line follows the job " +"number, date, hour, job class, and user name format. Users can only view " +"their own jobs. If the `root` user executes the [command]#atq# command, all " +"jobs for all users are displayed." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:492 +#, no-wrap +msgid "Additional Command Line Options" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:495 +msgid "" +"Additional command line options for [command]#at# and [command]#batch# " +"include the following:" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:497 +#, no-wrap +msgid "[command]#at# and [command]#batch# Command Line Options" +msgstr "" + +#. type: Table +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:505 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`-f`|Read the commands or shell script from a file instead of " +"specifying them at the prompt.\n" +"|[option]`-m`|Send email to the user when the job has been completed.\n" +"|[option]`-v`|Display the time that the job is executed.\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:508 +#, no-wrap +msgid "Controlling Access to At and Batch" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:511 +msgid "" +"You can restrict the access to the [command]#at# and [command]#batch# " +"commands using the `/etc/at.allow` and `/etc/at.deny` files. These access " +"control files use the same format defining one user name on each line. Mind " +"that no whitespace are permitted in either file." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:513 +msgid "" +"If the file `at.allow` exists, only users listed in the file are allowed to " +"use [command]#at# or [command]#batch#, and the `at.deny` file is ignored." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:515 +msgid "" +"If `at.allow` does not exist, users listed in `at.deny` are not allowed to " +"use [command]#at# or [command]#batch#." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:517 +msgid "" +"The [command]#at# daemon ([command]#atd#) does not have to be restarted if " +"the access control files are modified. The access control files are read " +"each time a user tries to execute the [command]#at# or [command]#batch# " +"commands." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:519 +msgid "" +"The `root` user can always execute [command]#at# and [command]#batch# " +"commands, regardless of the content of the access control files." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:521 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:524 +msgid "" +"indexterm:[cron,additional resources]indexterm:[at,additional " +"resources]indexterm:[batch,additional resources] To learn more about " +"configuring automated tasks, see the following installed documentation:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:526 +msgid "`cron(8)` man page contains an overview of cron." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:528 +msgid "`crontab` man pages in sections 1 and 5:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:530 +msgid "The manual page in section 1 contains an overview of the `crontab` file." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:532 +msgid "" +"The man page in section 5 contains the format for the file and some example " +"entries." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:534 +msgid "`anacron(8)` manual page contains an overview of anacron." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:536 +msgid "`anacrontab(5)` manual page contains an overview of the `anacrontab` file." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:538 +msgid "" +"`run-parts(4)` manual page contains an overview of the [command]#run-parts# " +"script." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:540 +msgid "" +"`/usr/share/doc/at/timespec` contains detailed information about the time " +"values that can be used in cron job definitions." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:541 +msgid "" +"`at` manual page contains descriptions of [command]#at# and [command]#batch# " +"and their command line options." +msgstr "" diff --git a/po/fr/rawhide/pages/monitoring-and-automation/OProfile.po b/po/fr/rawhide/pages/monitoring-and-automation/OProfile.po new file mode 100644 index 00000000000..cd12f711f34 --- /dev/null +++ b/po/fr/rawhide/pages/monitoring-and-automation/OProfile.po @@ -0,0 +1,2280 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/monitoring-and-automation/OProfile.adoc:6 +#, no-wrap +msgid "OProfile" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:9 +msgid "" +"indexterm:[system analysis,OProfile,OProfile]indexterm:[OProfile] OProfile " +"is a low overhead, system-wide performance monitoring tool. It uses the " +"performance monitoring hardware on the processor to retrieve information " +"about the kernel and executables on the system, such as when memory is " +"referenced, the number of L2 cache requests, and the number of hardware " +"interrupts received. On a {MAJOROS} system, the `oprofile` package must be " +"installed to use this tool." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:11 +msgid "" +"Many processors include dedicated performance monitoring hardware. This " +"hardware makes it possible to detect when certain events happen (such as the " +"requested data not being in cache). The hardware normally takes the form of " +"one or more _counters_ that are incremented each time an event takes " +"place. When the counter value increments, an interrupt is generated, making " +"it possible to control the amount of detail (and therefore, overhead) " +"produced by performance monitoring." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:13 +msgid "" +"OProfile uses this hardware (or a timer-based substitute in cases where " +"performance monitoring hardware is not present) to collect _samples_ of " +"performance-related data each time a counter generates an interrupt. These " +"samples are periodically written out to disk; later, the data contained in " +"these samples can then be used to generate reports on system-level and " +"application-level performance." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:15 +msgid "Be aware of the following limitations when using OProfile:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:17 +#, no-wrap +msgid "" +"*Use of shared libraries* — Samples for code in shared libraries are not " +"attributed to the particular application unless the " +"[option]`--separate=library` option is used.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:19 +#, no-wrap +msgid "" +"*Performance monitoring samples are inexact* — When a performance monitoring " +"register triggers a sample, the interrupt handling is not precise like a " +"divide by zero exception. Due to the out-of-order execution of instructions " +"by the processor, the sample may be recorded on a nearby instruction.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:21 +#, no-wrap +msgid "" +"*pass:attributes[{blank}][command]#opreport# does not associate samples for " +"inline functions properly* — [command]#opreport# uses a simple address range " +"mechanism to determine which function an address is in. Inline function " +"samples are not attributed to the inline function but rather to the function " +"the inline function was inserted into.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:23 +#, no-wrap +msgid "" +"*OProfile accumulates data from multiple runs* — OProfile is a system-wide " +"profiler and expects processes to start up and shut down multiple " +"times. Thus, samples from multiple runs accumulate. Use the command " +"[command]#opcontrol --reset# to clear out the samples from previous runs.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:25 +#, no-wrap +msgid "" +"*Hardware performance counters do not work on guest virtual machines* — " +"Because the hardware performance counters are not available on virtual " +"systems, you need to use the `timer` mode. Enter the command " +"[command]#opcontrol --deinit#, and then execute [command]#modprobe oprofile " +"timer=1# to enable the `timer` mode.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:27 +#, no-wrap +msgid "" +"*Non-CPU-limited performance problems* — OProfile is oriented to finding " +"problems with CPU-limited processes. OProfile does not identify processes " +"that are asleep because they are waiting on locks or for some other event to " +"occur (for example an I/O device to finish an operation).\n" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/OProfile.adoc:29 +#, no-wrap +msgid "Overview of Tools" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:32 +msgid "" +"indexterm:[OProfile,overview of tools] " +"xref:OProfile.adoc#tb-oprofile-tools[OProfile Commands] provides a brief " +"overview of the most commonly used tools provided with the `oprofile` " +"package." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:34 +#, no-wrap +msgid "OProfile Commands" +msgstr "" + +#. type: Table +#: ./pages/monitoring-and-automation/OProfile.adoc:47 +#, no-wrap +msgid "" +"|Command|Description\n" +"|[command]#ophelp#|Displays available events for the system's processor " +"along with a brief description of each.\n" +"|[command]#opimport#|Converts sample database files from a foreign binary " +"format to the native format for the system. Only use this option when " +"analyzing a sample database from a different architecture.\n" +"|[command]#opannotate#|Creates annotated source for an executable if the " +"application was compiled with debugging symbols. See " +"xref:OProfile.adoc#s2-oprofile-reading-opannotate[Using " +"[command]#opannotate#] for details.\n" +"|[command]#opcontrol#|Configures what data is collected. See " +"xref:OProfile.adoc#s1-oprofile-configuring[Configuring OProfile Using Legacy " +"Mode] for details.\n" +"|[command]#operf#|Recommended tool to be used in place of " +"[command]#opcontrol# for profiling. See " +"xref:OProfile.adoc#s1-using-operf[Using operf] for details.\n" +" For differences between [command]#operf# and [command]#opcontrol# see " +"xref:OProfile.adoc#s2-operf_vs_opcontrol[operf vs. opcontrol].\n" +"|[command]#opreport#|Retrieves profile data. See " +"xref:OProfile.adoc#s2-oprofile-reading-opreport[Using [command]#opreport#] " +"for details.\n" +"|[command]#oprofiled#|Runs as a daemon to periodically write sample data to " +"disk.\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/OProfile.adoc:50 +#, no-wrap +msgid "operf vs. opcontrol" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:53 +msgid "" +"There are two mutually exclusive methods for collecting profiling data with " +"OProfile. You can either use the newer and preferred [command]#operf# or the " +"[command]#opcontrol# tool." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:54 +#, no-wrap +msgid "operf" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:56 +msgid "" +"This is the recommended mode for profiling. The [command]#operf# tool uses " +"the Linux Performance Events Subsystem, and therefore does not require the " +"*oprofile* kernel driver. The [command]#operf# tool allows you to target " +"your profiling more precisely, as a single process or system-wide, and also " +"allows OProfile to co-exist better with other tools using the performance " +"monitoring hardware on your system. Unlike [command]#opcontrol#, it can be " +"used without the `root` privileges. However, [command]#operf# is also " +"capable of system-wide operations with use of the [option]`--system-wide` " +"option, where root authority is required." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:58 +msgid "" +"With [command]#operf#, there is no initial setup needed. You can invoke " +"[command]#operf# with command-line options to specify your profiling " +"settings. After that, you can run the OProfile post-processing tools " +"described in xref:OProfile.adoc#s1-oprofile-analyzing-data[Analyzing the " +"Data]. See xref:OProfile.adoc#s1-using-operf[Using operf] for further " +"information." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:59 +#, no-wrap +msgid "opcontrol" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:61 +msgid "" +"This mode consists of the [command]#opcontrol# shell script, the `oprofiled` " +"daemon, and several post-processing tools. The [command]#opcontrol# command " +"is used for configuring, starting, and stopping a profiling session. An " +"OProfile kernel driver, usually built as a kernel module, is used for " +"collecting samples, which are then recorded into sample files by " +"`oprofiled`. You can use legacy mode only if you have `root` privileges. In " +"certain cases, such as when you need to sample areas with disabled interrupt " +"request (IRQ), this is a better alternative." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:63 +msgid "" +"Before OProfile can be run in legacy mode, it must be configured as shown in " +"xref:OProfile.adoc#s1-oprofile-configuring[Configuring OProfile Using Legacy " +"Mode]. These settings are then applied when starting OProfile " +"(xref:OProfile.adoc#s1-oprofile-starting[Starting and Stopping OProfile " +"Using Legacy Mode])." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/OProfile.adoc:65 +#, no-wrap +msgid "Using operf" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:68 +msgid "" +"[command]#operf# is the recommended profiling mode that does not require " +"initial setup before starting. All settings are specified as command-line " +"options and there is no separate command to start the profiling process. To " +"stop [command]#operf#, press Ctrl+C. The typical [command]#operf# command " +"syntax looks as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:72 +#, no-wrap +msgid "[command]#operf# _options_ _range_ _command_ _args_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:75 +msgid "" +"Replace _options_ with the desired command-line options to specify your " +"profiling settings. Full set of options is described in `operf(1)` manual " +"page. Replace _range_ with one of the following:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:77 +msgid "" +"[option]`--system-wide` - this setting allows for global profiling, see " +"xref:OProfile.adoc#using_operf_system-wide[Using [command]#operf# in " +"System-wide Mode] +" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:79 +msgid "" +"[option]`--pid=pass:attributes[{blank}]_PID_pass:attributes[{blank}]` - this " +"is to profile a running application, where _PID_ is the process ID of the " +"process you want to profile. +" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:81 +msgid "" +"With _command_ and _args_, you can define a specific command or application " +"to be profiled, and also the input arguments that this command or " +"application requires. Either _command_, [option]`--pid` or " +"[option]`--system-wide` is required, but these cannot be used " +"simultaneously." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:83 +msgid "" +"When you invoke [command]#operf# on a command line without setting the " +"_range_ option, data will be collected for the children processes." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:85 +#, no-wrap +msgid "Using [command]#operf# in System-wide Mode" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:90 +msgid "" +"To run [command]#operf# [option]`--system-wide`, you need `root` " +"authority. When finished profiling, you can stop [command]#operf# with " +"`Ctrl+C`." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:92 +msgid "" +"If you run [command]#operf# [option]`--system-wide` as a background process " +"(with `&`), stop it in a controlled manner in order to process the collected " +"profile data. For this purpose, use:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:96 +#, no-wrap +msgid "[command]#kill -SIGINT operf-PID#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:99 +msgid "" +"When running [command]#operf# [option]`--system-wide`, it is recommended " +"that your current working directory is `/root` or a subdirectory of `/root` " +"so that sample data files are not stored in locations accessible by regular " +"users." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/OProfile.adoc:103 +#: ./pages/monitoring-and-automation/OProfile.adoc:206 +#, no-wrap +msgid "Specifying the Kernel" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:106 +msgid "To monitor the kernel, execute the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:110 +#, no-wrap +msgid "operf --vmlinux=pass:quotes[_vmlinux_path_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:113 +msgid "" +"With this option, you can specify a path to a vmlinux file that matches the " +"running kernel. Kernel samples will be attributed to this binary, allowing " +"post-processing tools to attribute samples to the appropriate kernel " +"symbols. If this option is not specified, all kernel samples will be " +"attributed to a pseudo binary named \"`no-vmlinux`\"." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/OProfile.adoc:115 +#: ./pages/monitoring-and-automation/OProfile.adoc:235 +#, no-wrap +msgid "Setting Events to Monitor" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:118 +msgid "" +"Most processors contain counters, which are used by OProfile to monitor " +"specific events. As shown in " +"xref:OProfile.adoc#tb-oprofile-processors[OProfile Processors and Counters], " +"the number of counters available depends on the processor." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:120 +#: ./pages/monitoring-and-automation/OProfile.adoc:341 +msgid "" +"The events for each counter can be configured via the command line or with a " +"graphical interface. For more information on the graphical interface, see " +"xref:OProfile.adoc#s1-oprofile-gui[Graphical Interface]. If the counter " +"cannot be set to a specific event, an error message is displayed." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:121 +#, no-wrap +msgid "Older Processors and operf" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:126 +msgid "" +"Some older processor models are not supported by the underlying Linux " +"Performance Events Subsystem kernel and therefore are not supported by " +"[command]#operf#. If you receive this message:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:131 +#, no-wrap +msgid "" +"Your kernel's Performance Events Subsystem does not support your processor " +"type\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:135 +msgid "" +"when attempting to use [command]#operf#, try profiling with " +"[command]#opcontrol# to see if your processor type may be supported by " +"OProfile's legacy mode." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:138 +#, no-wrap +msgid "Using operf on Virtual Systems" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:143 +msgid "" +"Since hardware performance counters are not available on guest virtual " +"machines, you have to enable *timer* mode to use [application]*operf* on " +"virtual systems. To do so, type as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:147 +#, no-wrap +msgid "[command]#opcontrol# [option]`--deinit`\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:152 +#, no-wrap +msgid "[command]#modprobe# [command]#oprofile# [option]`timer=1`\n" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:157 +msgid "To set the event for each configurable counter via the command line, use:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:161 +#, no-wrap +msgid "" +"[command]#operf# " +"[option]`--events`pass:attributes[{blank}]=pass:attributes[{blank}]_event1_,_event2_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:164 +msgid "" +"Here, pass a comma-separated list of event specifications for " +"profiling. Each event specification is a colon-separated list of attributes " +"in the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:168 +#, no-wrap +msgid "_event-name_:pass:attributes[{blank}]_sample-rate_:pass:attributes[{blank}]_unit-mask_:pass:attributes[{blank}]_kernel_:pass:attributes[{blank}]_user_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:171 +msgid "" +"xref:OProfile.adoc#tab_event_specifications[Event Specifications] summarizes " +"these options. The last three values are optional, if you omit them, they " +"will be set to their default values. Note that certain events do require a " +"unit mask." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:173 +#, no-wrap +msgid "Event Specifications" +msgstr "" + +#. type: Table +#: ./pages/monitoring-and-automation/OProfile.adoc:184 +#, no-wrap +msgid "" +"|Specification|Description\n" +"|_event-name_|The exact symbolic event name taken from [command]#ophelp#\n" +"|_sample-rate_|The number of events to wait before sampling again. The " +"smaller the count, the more frequent the samples. For events that do not " +"happen frequently, a lower count may be needed to capture a statistically " +"significant number of event instances. On the other hand, sampling too " +"frequently can overload the system. By default, OProfile uses a time-based " +"event set, which creates a sample every 100,000 clock cycles per " +"processor.\n" +"|_unit-mask_|Unit masks, which further define the event, are listed in " +"[command]#ophelp#.\n" +" You can insert either a hexadecimal value, beginning with " +"\"`0x`\", or a string that matches the first word of the unit mask " +"description in [command]#ophelp#. Definition by name is valid only for unit " +"masks having \"`extra:`\" parameters, as shown by the output of " +"[command]#ophelp#. This type of unit mask cannot be defined with a " +"hexadecimal value. Note that on certain architectures, there can be multiple " +"unit masks with the same hexadecimal value. In that case they have to be " +"specified by their names only.\n" +"|_kernel_|Specifies whether to profile kernel code (insert `0` or " +"`1`(default))\n" +"|_user_|Specifies whether to profile user-space code (insert `0` or `1` " +"(default))\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:187 +msgid "" +"The events available vary depending on the processor type. When no event " +"specification is given, the default event for the running processor type " +"will be used for profiling. See " +"xref:OProfile.adoc#tb-oprofile-default-events[Default Events] for a list of " +"these default events. To determine the events available for profiling, use " +"the [command]#ophelp# command." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:191 +#, no-wrap +msgid "[command]#ophelp#\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/OProfile.adoc:194 +#, no-wrap +msgid "Categorization of Samples" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:197 +msgid "" +"The [option]`--separate-thread` option categorizes samples by thread group " +"ID (tgid) and thread ID (tid). This is useful for seeing per-thread samples " +"in multi-threaded applications. When used in conjunction with the " +"[option]`--system-wide` option, [option]`--separate-thread` is also useful " +"for seeing per-process (i.e., per-thread group) samples for the case where " +"multiple processes are executing the same program during a profiling run." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:199 +msgid "The [option]`--separate-cpu` option categorizes samples by CPU." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/OProfile.adoc:201 +#, no-wrap +msgid "Configuring OProfile Using Legacy Mode" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:204 +msgid "" +"indexterm:[OProfile,configuring]indexterm:[OProfile,opcontrol]indexterm:[opcontrol,OProfile] " +"Before OProfile can be run in legacy mode, it must be configured. At a " +"minimum, selecting to monitor the kernel (or selecting not to monitor the " +"kernel) is required. The following sections describe how to use the " +"[command]#opcontrol# utility to configure OProfile. As the " +"[command]#opcontrol# commands are executed, the setup options are saved to " +"the `/root/.oprofile/daemonrc` file." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:209 +msgid "" +"indexterm:[OProfile,monitoring the kernel] First, configure whether OProfile " +"should monitor the kernel. This is the only configuration option that is " +"required before starting OProfile. All others are optional." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:212 +msgid "" +"To monitor the kernel, execute the following command as `root`: " +"indexterm:[OProfile,opcontrol,--vmlinux=]" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:214 +#, no-wrap +msgid "" +"~]# opcontrol --setup --vmlinux=/usr/lib/debug/lib/modules/`uname " +"-r`/vmlinux\n" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:216 +#, no-wrap +msgid "Install the debuginfo package" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:221 +msgid "" +"In order to monitor the kernel, the [package]*debuginfo* package which " +"contains the uncompressed kernel must be installed." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:226 +msgid "" +"To configure OProfile not to monitor the kernel, execute the following " +"command as `root`: indexterm:[OProfile,opcontrol,--no-vmlinux]" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:228 +#, no-wrap +msgid "~]# opcontrol --setup --no-vmlinux\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:231 +msgid "" +"This command also loads the `oprofile` kernel module, if it is not already " +"loaded, and creates the `/dev/oprofile/` directory, if it does not already " +"exist. See xref:OProfile.adoc#s1-oprofile-dev-oprofile[Understanding the " +"/dev/oprofile/ directory] for details about this directory." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:233 +msgid "" +"Setting whether samples should be collected within the kernel only changes " +"what data is collected, not how or where the collected data is stored. To " +"generate different sample files for the kernel and application libraries, " +"see xref:OProfile.adoc#s2-oprofile-starting-separate[Separating Kernel and " +"User-space Profiles]." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:238 +msgid "" +"indexterm:[OProfile,events,setting] Most processors contain _counters_, " +"which are used by OProfile to monitor specific events. As shown in " +"xref:OProfile.adoc#tb-oprofile-processors[OProfile Processors and Counters], " +"the number of counters available depends on the processor." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:240 +#, no-wrap +msgid "OProfile Processors and Counters" +msgstr "" + +#. type: Table +#: ./pages/monitoring-and-automation/OProfile.adoc:278 +#, no-wrap +msgid "" +"|Processor|[command]#cpu_type#|Number of Counters\n" +"|AMD64|x86-64/hammer|4\n" +"|AMD Family 10h|x86-64/family10|4\n" +"|AMD Family 11h|x86-64/family11|4\n" +"|AMD Family 12h|x86-64/family12|4\n" +"|AMD Family 14h|x86-64/family14|4\n" +"|AMD Family 15h|x86-64/family15|6\n" +"|Applied Micro X-Gene|arm/armv8-xgene|4\n" +"|ARM Cortex A53|arm/armv8-ca53|6\n" +"|ARM Cortex A57|arm/armv8-ca57|6\n" +"|IBM eServer System i and IBM eServer System p|timer|1\n" +"|IBM POWER4|ppc64/power4|8\n" +"|IBM POWER5|ppc64/power5|6\n" +"|IBM PowerPC 970|ppc64/970|8\n" +"|IBM PowerPC 970MP|ppc64/970MP|8\n" +"|IBM POWER5+|ppc64/power5+|6\n" +"|IBM POWER5++|ppc64/power5++|6\n" +"|IBM POWER56|ppc64/power6|6\n" +"|IBM POWER7|ppc64/power7|6\n" +"|IBM POWER8|ppc64/power7|8\n" +"|IBM S/390 and IBM System z|timer|1\n" +"|Intel Core i7|i386/core_i7|4\n" +"|Intel Nehalem microarchitecture|i386/nehalem|4\n" +"|Intel Westmere microarchitecture|i386/westmere|4\n" +"|Intel Haswell microarchitecture (non-hyper-threaded)|i386/haswell|8\n" +"|Intel Haswell microarchitecture (hyper-threaded)|i386/haswell-ht|4\n" +"|Intel Ivy Bridge microarchitecture (non-hyper-threaded)|i386/ivybridge|8\n" +"|Intel Ivy Bridge microarchitecture (hyper-threaded)|i386/ivybridge-ht|4\n" +"|Intel Sandy Bridge microarchitecture " +"(non-hyper-threaded)|i386/sandybridge|8\n" +"|Intel Sandy Bridge microarchitecture|i386/sandybridge-ht|4\n" +"|Intel Broadwell microarchitecture (non-hyper-threaded)|i386/broadwell|8\n" +"|Intel Broadwell microarchitecture (hyper-threaded)|i386/broadwell-ht|4\n" +"|Intel Silvermont microarchitecture|i386/silvermont|2\n" +"|TIMER_INT|timer|1\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:281 +msgid "" +"Use xref:OProfile.adoc#tb-oprofile-processors[OProfile Processors and " +"Counters] to determine the number of events that can be monitored " +"simultaneously for your CPU type. If the processor does not have supported " +"performance monitoring hardware, the `timer` is used as the processor type." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:283 +msgid "" +"If `timer` is used, events cannot be set for any processor because the " +"hardware does not have support for hardware performance counters. Instead, " +"the timer interrupt is used for profiling." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:285 +msgid "" +"If `timer` is not used as the processor type, the events monitored can be " +"changed, and counter 0 for the processor is set to a time-based event by " +"default. If more than one counter exists on the processor, the counters " +"other than 0 are not set to an event by default. The default events " +"monitored are shown in xref:OProfile.adoc#tb-oprofile-default-events[Default " +"Events]." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:287 +#, no-wrap +msgid "Default Events" +msgstr "" + +#. type: Table +#: ./pages/monitoring-and-automation/OProfile.adoc:309 +#, no-wrap +msgid "" +"|Processor|Default Event for Counter|Description\n" +"|AMD Athlon and AMD64|CPU_CLK_UNHALTED|The processor's clock is not halted\n" +"|AMD Family 10h, AMD Family 11h, AMD Family 12h|CPU_CLK_UNHALTED|The " +"processor's clock is not halted\n" +"|AMD Family 14h, AMD Family 15h|CPU_CLK_UNHALTED|The processor's clock is " +"not halted\n" +"|Applied Micro X-Gene|CPU_CYCLES|Processor Cycles\n" +"|ARM Cortex A53|CPU_CYCLES|Processor Cycles\n" +"|ARM Cortex A57|CPU_CYCLES|Processor Cycles\n" +"|IBM POWER4|CYCLES|Processor Cycles\n" +"|IBM POWER5|CYCLES|Processor Cycles\n" +"|IBM POWER8|CYCLES|Processor Cycles\n" +"|IBM PowerPC 970|CYCLES|Processor Cycles\n" +"|Intel Core i7|CPU_CLK_UNHALTED|The processor's clock is not halted\n" +"|Intel Nehalem microarchitecture|CPU_CLK_UNHALTED|The processor's clock is " +"not halted\n" +"|Intel Pentium 4 (hyper-threaded and " +"non-hyper-threaded)|GLOBAL_POWER_EVENTS|The time during which the processor " +"is not stopped\n" +"|Intel Westmere microarchitecture|CPU_CLK_UNHALTED|The processor's clock is " +"not halted\n" +"|Intel Broadwell microarchitecture|CPU_CLK_UNHALTED|The processor's clock is " +"not halted\n" +"|Intel Silvermont microarchitecture|CPU_CLK_UNHALTED|The processor's clock " +"is not halted\n" +"|TIMER_INT|(none)|Sample for each timer interrupt\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:312 +msgid "" +"The number of events that can be monitored at one time is determined by the " +"number of counters for the processor. However, it is not a one-to-one " +"correlation; on some processors, certain events must be mapped to specific " +"counters. To determine the number of counters available, execute the " +"following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:315 +#, no-wrap +msgid "~]# ls -d /dev/oprofile/[0-9]*\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:319 +msgid "" +"The events available vary depending on the processor type. To determine the " +"events available for profiling, execute the following command as root (the " +"list is specific to the system's processor type): " +"indexterm:[OProfile,ophelp]indexterm:[ophelp]" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:321 +#, no-wrap +msgid "~]# ophelp\n" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:323 +#, no-wrap +msgid "Make sure that OProfile is configured" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:328 +msgid "" +"Unless OProfile is properly configured, [command]#ophelp# fails with the " +"following error message:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:334 +#, no-wrap +msgid "" +"Unable to open cpu_type file for reading\n" +"Make sure you have done opcontrol --init\n" +"cpu_type 'unset' is not valid\n" +"you should upgrade oprofile or force the use of timer mode\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:337 +msgid "" +"To configure OProfile, follow the instructions in " +"xref:OProfile.adoc#s1-oprofile-configuring[Configuring OProfile Using Legacy " +"Mode]." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:343 +msgid "" +"To set the event for each configurable counter via the command line, use " +"[command]#opcontrol#:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:346 +#: ./pages/monitoring-and-automation/OProfile.adoc:359 +#, no-wrap +msgid "~]# opcontrol --event=event-name:sample-rate\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:349 +msgid "" +"Replace _event-name_ with the exact name of the event from " +"[command]#ophelp#, and replace _sample-rate_ with the number of events " +"between samples." +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/OProfile.adoc:351 +#, no-wrap +msgid "Sampling Rate" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:354 +msgid "" +"indexterm:[OProfile,events,sampling rate] By default, a time-based event set " +"is selected. It creates a sample every 100,000 clock cycles per " +"processor. If the timer interrupt is used, the timer is set to the " +"respective rate and is not user-settable. If the `cpu_type` is not `timer`, " +"each event can have a _sampling rate_ set for it. The sampling rate is the " +"number of events between each sample snapshot." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:356 +msgid "When setting the event for the counter, a sample rate can also be specified:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:362 +msgid "" +"Replace _sample-rate_ with the number of events to wait before sampling " +"again. The smaller the count, the more frequent the samples. For events that " +"do not happen frequently, a lower count may be needed to capture the event " +"instances." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:363 +#, no-wrap +msgid "Sampling too frequently can overload the system" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:368 +msgid "" +"Be extremely careful when setting sampling rates. Sampling too frequently " +"can overload the system, causing the system to appear frozen or causing the " +"system to actually freeze." +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/OProfile.adoc:372 +#, no-wrap +msgid "Unit Masks" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:375 +msgid "" +"indexterm:[OProfile,unit mask] Some user performance monitoring events may " +"also require unit masks to further define the event." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:377 +msgid "" +"Unit masks for each event are listed with the [command]#ophelp# command. The " +"values for each unit mask are listed in hexadecimal format. To specify more " +"than one unit mask, the hexadecimal values must be combined using a bitwise " +"_or_ operation." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:380 +#, no-wrap +msgid "~]# opcontrol --event=event-name:sample-rate:unit-mask\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:383 +msgid "" +"Note that on certain architectures, there can be multiple unit masks with " +"the same hexadecimal value. In that case they have to be specified by their " +"names only." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/OProfile.adoc:385 +#, no-wrap +msgid "Separating Kernel and User-space Profiles" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:388 +msgid "" +"indexterm:[OProfile,configuring,separating profiles] By default, kernel mode " +"and user mode information is gathered for each event. To configure OProfile " +"to ignore events in kernel mode for a specific counter, execute the " +"following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:391 +#, no-wrap +msgid "~]# opcontrol --event=event-name:sample-rate:unit-mask:0\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:394 +msgid "" +"Execute the following command to start profiling kernel mode for the counter " +"again:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:397 +#, no-wrap +msgid "~]# opcontrol --event=event-name:sample-rate:unit-mask:1\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:400 +msgid "" +"To configure OProfile to ignore events in user mode for a specific counter, " +"execute the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:403 +#, no-wrap +msgid "~]# opcontrol --event=event-name:sample-rate:unit-mask:1:0\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:406 +msgid "" +"Execute the following command to start profiling user mode for the counter " +"again:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:409 +#, no-wrap +msgid "~]# opcontrol --event=event-name:sample-rate:unit-mask:1:1\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:412 +msgid "" +"When the OProfile daemon writes the profile data to sample files, it can " +"separate the kernel and library profile data into separate sample files. To " +"configure how the daemon writes to sample files, execute the following " +"command as root:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:415 +#, no-wrap +msgid "~]# opcontrol --separate=choice\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:418 +msgid "The _choice_ argument can be one of the following:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:420 +msgid "`none` — Do not separate the profiles (default)." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:422 +msgid "[command]#library# — Generate per-application profiles for libraries." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:424 +msgid "" +"[command]#kernel# — Generate per-application profiles for the kernel and " +"kernel modules." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:426 +msgid "" +"[command]#all# — Generate per-application profiles for libraries and " +"per-application profiles for the kernel and kernel modules." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:428 +msgid "" +"If [option]`--separate=library` is used, the sample file name includes the " +"name of the executable as well as the name of the library." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:429 +#, no-wrap +msgid "Restart the OProfile profiler" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:434 +msgid "" +"These configuration changes will take effect when the OProfile profiler is " +"restarted." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/OProfile.adoc:438 +#, no-wrap +msgid "Starting and Stopping OProfile Using Legacy Mode" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:442 +msgid "" +"indexterm:[OProfile,starting] To start monitoring the system with OProfile, " +"execute the following command as root: " +"indexterm:[OProfile,opcontrol,--start]" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:444 +#, no-wrap +msgid "~]# opcontrol --start\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:447 +msgid "Output similar to the following is displayed:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:451 +#, no-wrap +msgid "" +"Using log file /var/lib/oprofile/oprofiled.log Daemon started. Profiler " +"running.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:456 +msgid "" +"The settings in `/root/.oprofile/daemonrc` are used. " +"indexterm:[OProfile,oprofiled]indexterm:[oprofiled,OProfile]indexterm:[OProfile,oprofiled,log " +"file] The OProfile daemon, [command]#oprofiled#, is started; it periodically " +"writes the sample data to the `/var/lib/oprofile/samples/` directory. The " +"log file for the daemon is located at `/var/lib/oprofile/oprofiled.log`." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:457 +#, no-wrap +msgid "Disable the nmi_watchdog registers" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:462 +msgid "" +"On a {MAJOROSVER} system, the `nmi_watchdog` registers with the `perf` " +"subsystem. Due to this, the `perf` subsystem grabs control of the " +"performance counter registers at boot time, blocking OProfile from working." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:464 +msgid "" +"To resolve this, either boot with the [command]#nmi_watchdog=0# kernel " +"parameter set, or run the following command as `root` to disable " +"`nmi_watchdog` at run time:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:467 +#, no-wrap +msgid "~]# echo 0 > /proc/sys/kernel/nmi_watchdog\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:470 +msgid "To re-enable `nmi_watchdog`, use the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:473 +#, no-wrap +msgid "~]# echo 1 > /proc/sys/kernel/nmi_watchdog\n" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:478 +msgid "To stop the profiler, execute the following command as root:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:481 +#, no-wrap +msgid "~]# opcontrol --shutdown\n" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/OProfile.adoc:484 +#, no-wrap +msgid "Saving Data in Legacy Mode" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:487 +msgid "" +"indexterm:[OProfile,saving data] Sometimes it is useful to save samples at a " +"specific time. For example, when profiling an executable, it may be useful " +"to gather different samples based on different input data sets. If the " +"number of events to be monitored exceeds the number of counters available " +"for the processor, multiple runs of OProfile can be used to collect data, " +"saving the sample data to different files each time." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:489 +msgid "" +"To save the current set of sample files, execute the following command, " +"replacing _name_ with a unique descriptive name for the current session:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:492 +#, no-wrap +msgid "~]# opcontrol --save=name\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:495 +msgid "" +"The command creates the directory " +"`/var/lib/oprofile/samples/pass:attributes[{blank}]_name_pass:attributes[{blank}]/` " +"and the current sample files are copied to it." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:497 +msgid "" +"To specify the session directory to hold the sample data, use the " +"[option]`--session-dir` option. If not specified, the data is saved in the " +"`oprofile_data/` directory on the current path." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/OProfile.adoc:499 +#, no-wrap +msgid "Analyzing the Data" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:502 +msgid "" +"indexterm:[OProfile,reading data] The same OProfile post-processing tools " +"are used whether you collect your profile with [command]#operf# or " +"[command]#opcontrol# in legacy mode." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:504 +msgid "" +"By default, [command]#operf# stores the profiling data in the " +"`pass:attributes[{blank}]_current_dir_pass:attributes[{blank}]/oprofile_data/` " +"directory. You can change to a different location with the " +"[option]`--session-dir` option. The usual post-profiling analysis tools such " +"as [command]#opreport# and [command]#opannotate# can be used to generate " +"profile reports. These tools search for samples in " +"`pass:attributes[{blank}]_current_dir_pass:attributes[{blank}]/oprofile_data/` " +"first. If this directory does not exist, the analysis tools use the standard " +"session directory of `/var/lib/oprofile/`. Statistics, such as total samples " +"received and lost samples, are written to the " +"`pass:attributes[{blank}]_session_dir_pass:attributes[{blank}]/samples/operf.log` " +"file." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:506 +msgid "" +"When using legacy mode, the OProfile daemon, [command]#oprofiled#, " +"periodically collects the samples and writes them to the " +"`/var/lib/oprofile/samples/` directory. Before reading the data, make sure " +"all data has been written to this directory by executing the following " +"command as root:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:509 +#, no-wrap +msgid "~]# opcontrol --dump\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:512 +msgid "" +"Each sample file name is based on the name of the executable. For example, " +"the samples for the default event on a Pentium III processor for " +"[command]#/bin/bash# becomes:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:515 +#, no-wrap +msgid "\\{root\\}/bin/bash/\\{dep\\}/\\{root\\}/bin/bash/CPU_CLK_UNHALTED.100000\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:518 +msgid "" +"The following tools are available to profile the sample data once it has " +"been collected:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:520 +msgid "[command]#opreport#" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:522 +msgid "[command]#opannotate#" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:524 +msgid "" +"Use these tools, along with the binaries profiled, to generate reports that " +"can be further analyzed." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:525 +#, no-wrap +msgid "Back up the executable and the sample files" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:530 +msgid "" +"The executable being profiled must be used with these tools to analyze the " +"data. If it must change after the data is collected, back up the executable " +"used to create the samples as well as the sample files. Note that the names " +"of the sample file and the binary have to agree. You cannot make a backup if " +"these names do not match. As an alternative, [command]#oparchive# can be " +"used to address this problem." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:534 +msgid "" +"Samples for each executable are written to a single sample file. Samples " +"from each dynamically linked library are also written to a single sample " +"file. While OProfile is running, if the executable being monitored changes " +"and a sample file for the executable exists, the existing sample file is " +"automatically deleted. Thus, if the existing sample file is needed, it must " +"be backed up, along with the executable used to create it before replacing " +"the executable with a new version. The OProfile analysis tools use the " +"executable file that created the samples during analysis. If the executable " +"changes, the analysis tools will be unable to analyze the associated " +"samples. See xref:OProfile.adoc#s1-oprofile-saving-data[Saving Data in " +"Legacy Mode] for details on how to back up the sample file." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/OProfile.adoc:536 +#, no-wrap +msgid "Using [command]#opreport#" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:539 +msgid "" +"indexterm:[OProfile,opreport]indexterm:[opreport,OProfile] The " +"[command]#opreport# tool provides an overview of all the executables being " +"profiled. The following is part of a sample output from the " +"[command]#opreport# command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:546 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#opreport#\n" +"Profiling through timer interrupt\n" +"TIMER:0|\n" +"samples| %|\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:569 +msgid "" +"25926 97.5212 no-vmlinux 359 1.3504 pi 65 0.2445 Xorg 62 0.2332 " +"libvte.so.4.4.0 56 0.2106 libc-2.3.4.so 34 0.1279 libglib-2.0.so.0.400.7 19 " +"0.0715 libXft.so.2.1.2 17 0.0639 bash 8 0.0301 ld-2.3.4.so 8 0.0301 " +"libgdk-x11-2.0.so.0.400.13 6 0.0226 libgobject-2.0.so.0.400.7 5 0.0188 " +"oprofiled 4 0.0150 libpthread-2.3.4.so 4 0.0150 libgtk-x11-2.0.so.0.400.13 3 " +"0.0113 libXrender.so.1.2.2 3 0.0113 du 1 0.0038 libcrypto.so.0.9.7a 1 0.0038 " +"libpam.so.0.77 1 0.0038 libtermcap.so.2.0.8 1 0.0038 libX11.so.6.2 1 0.0038 " +"libgthread-2.0.so.0.400.7 1 0.0038 libwnck-1.so.4.9.0" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:572 +#, no-wrap +msgid "" +"Each executable is listed on its own line. The first column is the number of " +"samples recorded for the executable. The second column is the percentage of " +"samples relative to the total number of samples. The third column is the " +"name of the executable.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:574 +#, no-wrap +msgid "" +"See the `opreport(1)` manual page for a list of available command-line " +"options, such as the [option]`-r` option used to sort the output from the " +"executable with the smallest number of samples to the one with the largest " +"number of samples. You can also use the [option]`-t` or " +"[option]`--threshold` option to trim the output of [command]#opcontrol#.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:576 +#, no-wrap +msgid "[[s2-oprofile-reading-opreport-single]]\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/OProfile.adoc:576 +#, no-wrap +msgid "Using opreport on a Single Executable" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:579 +msgid "" +"indexterm:[OProfile,opreport,on a single " +"executable]indexterm:[opreport,OProfile] To retrieve more detailed profiled " +"information about a specific executable, use the [command]#opreport# " +"command:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:583 +#, no-wrap +msgid "" +"~]# opreport mode\n" +" executable\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:586 +#, no-wrap +msgid "" +"Replace _executable_ with the full path to the executable to be " +"analyzed. _mode_ stands for one of the following options:\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:590 +#, no-wrap +msgid "" +"[option]`-l`:: This option is used to list sample data by symbols. For " +"example, running this command:\n" +"+\n" +"[subs=\"attributes\"]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:592 +msgid "~]#{nbsp}opreport -l /lib/tls/libc-version.so" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:596 +#, no-wrap +msgid "" +"+\n" +"produces the following output:\n" +"+\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:623 +msgid "" +"samples % symbol name 12 21.4286 __gconv_transform_utf8_internal 5 8.9286 " +"_int_malloc 4 7.1429 malloc 3 5.3571 __i686.get_pc_thunk.bx 3 5.3571 " +"_dl_mcount_wrapper_check 3 5.3571 mbrtowc 3 5.3571 memcpy 2 3.5714 " +"_int_realloc 2 3.5714 _nl_intern_locale_data 2 3.5714 free 2 3.5714 strcmp 1 " +"1.7857 __ctype_get_mb_cur_max 1 1.7857 __unregister_atfork 1 1.7857 " +"__write_nocancel 1 1.7857 _dl_addr 1 1.7857 _int_free 1 1.7857 _itoa_word 1 " +"1.7857 calc_eclosure_iter 1 1.7857 fopen@@GLIBC_2.1 1 1.7857 getpid 1 1.7857 " +"memmove 1 1.7857 msort_with_tmp 1 1.7857 strcpy 1 1.7857 strlen 1 1.7857 " +"vfprintf 1 1.7857 write" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:628 +#, no-wrap +msgid "" +"+\n" +"The first column is the number of samples for the symbol, the second column " +"is the percentage of samples for this symbol relative to the overall samples " +"for the executable, and the third column is the symbol name.\n" +"+\n" +"To sort the output from the largest number of samples to the smallest " +"(reverse order), use [option]`-r` in conjunction with the [option]`-l` " +"option.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:632 +#, no-wrap +msgid "" +"[option]`-i _symbol-name_pass:attributes[{blank}]`:: List sample data " +"specific to a symbol name. For example, running:\n" +"+\n" +"[subs=\"attributes\"]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:634 +msgid "" +"~]#{nbsp}opreport -l -i __gconv_transform_utf8_internal " +"/lib/tls/libc-version.so" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:638 +#, no-wrap +msgid "" +"+\n" +"returns the following output:\n" +"+\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:641 +msgid "samples % symbol name 12 100.000 __gconv_transform_utf8_internal" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:646 +#, no-wrap +msgid "" +"+\n" +"The first line is a summary for the symbol/executable combination.\n" +"+\n" +"The first column is the number of samples for the memory symbol. The second " +"column is the percentage of samples for the memory address relative to the " +"total number of samples for the symbol. The third column is the symbol " +"name.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:650 +#, no-wrap +msgid "" +"[option]`-d`:: This option lists sample data by symbols with more detail " +"than the [option]`-l` option. For example, with the following command:\n" +"+\n" +"[subs=\"attributes\"]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:652 +msgid "" +"~]#{nbsp}opreport -d -i __gconv_transform_utf8_internal " +"/lib/tls/libc-version.so" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:656 +#, no-wrap +msgid "" +"+\n" +"this output is returned:\n" +"+\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:670 +msgid "" +"vma samples % symbol name 00a98640 12 100.000 " +"__gconv_transform_utf8_internal 00a98640 1 8.3333 00a9868c 2 16.6667 " +"00a9869a 1 8.3333 00a986c1 1 8.3333 00a98720 1 8.3333 00a98749 1 8.3333 " +"00a98753 1 8.3333 00a98789 1 8.3333 00a98864 1 8.3333 00a98869 1 8.3333 " +"00a98b08 1 8.3333" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:673 +#, no-wrap +msgid "" +"+\n" +"The data is the same as the [option]`-l` option except that for each symbol, " +"each virtual memory address used is shown. For each virtual memory address, " +"the number of samples and percentage of samples relative to the number of " +"samples for the symbol is displayed.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:675 +#, no-wrap +msgid "" +"[option]`-e` _symbol-name_pass:attributes[{blank}]…:: " +"With this option, you can exclude some symbols from the output. Replace " +"_symbol-name_ with the comma-separated list of symbols you want to " +"exclude.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:677 +#, no-wrap +msgid "" +"[option]`session`:pass:attributes[{blank}]_name_:: Here, you can specify " +"the full path to the session, a directory relative to the " +"`/var/lib/oprofile/samples/` directory, or if you are using " +"[command]#operf#, a directory relative to `./oprofile_data/samples/`.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:679 +#, no-wrap +msgid "[[s2-oprofile-module-output]]\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/OProfile.adoc:679 +#, no-wrap +msgid "Getting More Detailed Output on the Modules" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:682 +msgid "" +"indexterm:[OProfile,opreport]indexterm:[OProfile] OProfile collects data on " +"a system-wide basis for kernel- and user-space code running on the " +"machine. However, once a module is loaded into the kernel, the information " +"about the origin of the kernel module is lost. The module could come from " +"the `initrd` file on boot up, the directory with the various kernel modules, " +"or a locally created kernel module. As a result, when OProfile records " +"samples for a module, it just lists the samples for the modules for an " +"executable in the root directory, but this is unlikely to be the place with " +"the actual code for the module. You will need to take some steps to make " +"sure that analysis tools get the proper executable." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:684 +msgid "" +"To get a more detailed view of the actions of the module, you will need to " +"either have the module \"`unstripped`\" (that is installed from a custom " +"build) or have the [package]*debuginfo* package installed for the kernel." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:686 +msgid "" +"Find out which kernel is running with the [command]#uname -a# command, " +"obtain the appropriate [package]*debuginfo* package and install it on the " +"machine." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:688 +msgid "" +"Then proceed with clearing out the samples from previous runs with the " +"following command:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:691 +msgid "~]# opcontrol --reset" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:694 +#, no-wrap +msgid "" +"To start the monitoring process, for example, on a machine with Westmere " +"processor, run the following command:\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:698 +msgid "" +"~]# opcontrol --setup --vmlinux=/usr/lib/debug/lib/modules/`uname " +"-r`/vmlinux \\ --event=CPU_CLK_UNHALTED:500000" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:701 +#, no-wrap +msgid "" +"Then the detailed information, for instance, for the ext4 module can be " +"obtained with:\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:719 +#, no-wrap +msgid "" +"~]# opreport /ext4 -l --image-path /lib/modules/`uname -r`/kernel\n" +"CPU: Intel Westmere microarchitecture, speed 2.667e+06 MHz (estimated)\n" +"Counted CPU_CLK_UNHALTED events (Clock cycles when not halted) with a unit " +"mask of 0x00 (No unit mask) count 500000\n" +"warning: could not check that the binary file " +"/lib/modules/2.6.32-191.el6.x86_64/kernel/fs/ext4/ext4.ko has not been " +"modified since the profile was taken. Results may be inaccurate.\n" +"samples % symbol name\n" +"1622 9.8381 ext4_iget\n" +"1591 9.6500 ext4_find_entry\n" +"1231 7.4665 __ext4_get_inode_loc\n" +"783 4.7492 ext4_ext_get_blocks\n" +"752 4.5612 ext4_check_dir_entry\n" +"644 3.9061 ext4_mark_iloc_dirty\n" +"583 3.5361 ext4_get_blocks\n" +"583 3.5361 ext4_xattr_get\n" +"479 2.9053 ext4_htree_store_dirent\n" +"469 2.8447 ext4_get_group_desc\n" +"414 2.5111 ext4_dx_find_entry\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:722 +#, no-wrap +msgid "[[s2-oprofile-reading-opannotate]]\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/OProfile.adoc:722 +#, no-wrap +msgid "Using [command]#opannotate#" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:725 +msgid "" +"indexterm:[OProfile,opannotate]indexterm:[opannotate,OProfile] The " +"[command]#opannotate# tool tries to match the samples for particular " +"instructions to the corresponding lines in the source code. The resulting " +"generated files should have the samples for the lines at the left. It also " +"puts in a comment at the beginning of each function listing the total " +"samples for the function." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:727 +msgid "" +"For this utility to work, the appropriate [package]*debuginfo* package for " +"the executable must be installed on the system. On {MAJOROS}, the " +"[package]*debuginfo* packages are not automatically installed with the " +"corresponding packages that contain the executable. You have to obtain and " +"install them separately." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:729 +msgid "The general syntax for [command]#opannotate# is as follows:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:732 +msgid "~]# opannotate --search-dirs src-dir --source executable" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:735 +#, no-wrap +msgid "" +"These command-line options are mandatory. Replace _src-dir_ with a path to " +"the directory containing the source code and specify the executable to be " +"analyzed. See the `opannotate(1)` manual page for a list of additional " +"command line options.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:737 +#, no-wrap +msgid "[[s1-oprofile-dev-oprofile]]\n" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/OProfile.adoc:737 +#, no-wrap +msgid "Understanding the /dev/oprofile/ directory" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:740 +msgid "" +"indexterm:[OProfile,/dev/oprofile/]indexterm:[/dev/oprofile/] When using " +"OProfile in legacy mode, the `/dev/oprofile/` directory is used to store the " +"file system for OProfile. On the other hand, [command]#operf# does not " +"require `/dev/oprofile/`. Use the [command]#cat# command to display the " +"values of the virtual files in this file system. For example, the following " +"command displays the type of processor OProfile detected:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:743 +msgid "~]# cat /dev/oprofile/cpu_type" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:746 +#, no-wrap +msgid "" +"A directory exists in `/dev/oprofile/` for each counter. For example, if " +"there are 2 counters, the directories `/dev/oprofile/0/` and " +"`/dev/oprofile/1/` exist.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:748 +#, no-wrap +msgid "Each directory for a counter contains the following files:\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:750 +#, no-wrap +msgid "* `count` — The interval between samples.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:752 +#, no-wrap +msgid "" +"* `enabled` — If 0, the counter is off and no samples are collected for it; " +"if 1, the counter is on and samples are being collected for it.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:754 +#, no-wrap +msgid "* `event` — The event to monitor.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:756 +#, no-wrap +msgid "" +"* `extra` — Used on machines with Nehalem processors to further specify the " +"event to monitor.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:758 +#, no-wrap +msgid "" +"* `kernel` — If 0, samples are not collected for this counter event when the " +"processor is in kernel-space; if 1, samples are collected even if the " +"processor is in kernel-space.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:760 +#, no-wrap +msgid "* `unit_mask` — Defines which unit masks are enabled for the counter.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:762 +#, no-wrap +msgid "" +"* `user` — If 0, samples are not collected for the counter event when the " +"processor is in user-space; if 1, samples are collected even if the " +"processor is in user-space.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:764 +#, no-wrap +msgid "" +"The values of these files can be retrieved with the [command]#cat# " +"command. For example:\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:767 +msgid "~]# cat /dev/oprofile/0/count" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:770 +#, no-wrap +msgid "[[s1-oprofile-example-usage]]\n" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/OProfile.adoc:770 +#, no-wrap +msgid "Example Usage" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:773 +msgid "" +"While OProfile can be used by developers to analyze application performance, " +"it can also be used by system administrators to perform system analysis. For " +"example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:775 +#, no-wrap +msgid "" +"* *Determine which applications and services are used the most on a system* " +"— [command]#opreport# can be used to determine how much processor time an " +"application or service uses. If the system is used for multiple services but " +"is underperforming, the services consuming the most processor time can be " +"moved to dedicated systems.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:777 +#, no-wrap +msgid "" +"* *Determine processor usage* — The `CPU_CLK_UNHALTED` event can be " +"monitored to determine the processor load over a given period of time. This " +"data can then be used to determine if additional processors or a faster " +"processor might improve system performance.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:779 +#, no-wrap +msgid "[[s1-oprofile-java-support]]\n" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/OProfile.adoc:779 +#, no-wrap +msgid "OProfile Support for Java" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:782 +msgid "" +"indexterm:[OProfile,Java] OProfile allows you to profile dynamically " +"compiled code (also known as \"`just-in-time`\" or JIT code) of the Java " +"Virtual Machine (JVM). OProfile in {MAJOROSVER} includes built-in support " +"for the JVM Tools Interface (JVMTI) agent library, which supports Java 1.5 " +"and higher." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:784 +msgid "[[s1-oprofile-java-profiling]]" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/OProfile.adoc:784 +#, no-wrap +msgid "Profiling Java Code" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:787 +msgid "" +"To profile JIT code from the Java Virtual Machine with the JVMTI agent, add " +"the following to the JVM startup parameters:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:789 +msgid "[subs=\"macros\"]" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:791 +msgid "-agentlib:pass:quotes[_jvmti_oprofile_]" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:794 +#, no-wrap +msgid "" +"Where _jvmti_oprofile_ is a path to the OProfile agent. For 64-bit JVM, the " +"path looks as follows:\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:797 +msgid "-agentlib:/usr/lib64/oprofile/libjvmti_oprofile.so" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:800 +#, no-wrap +msgid "" +"Currently, you can add one command-line option: [option]`--debug`, which " +"enables debugging mode.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:804 +#, no-wrap +msgid "" +".Install the oprofile-jit package\n" +"[NOTE]\n" +"====\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:806 +#, no-wrap +msgid "" +"The [package]*oprofile-jit* package must be installed on the system in order " +"to profile JIT code with OProfile. With this package, you gain the " +"capability to show method-level information.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:808 +#, no-wrap +msgid "====\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:810 +#, no-wrap +msgid "" +"Depending on the JVM that you are using, you may have to install the " +"*debuginfo* package for the JVM. For OpenJDK, this package is required, " +"there is no debuginfo package for Oracle JDK. To keep the debug information " +"packages synchronized with their respective non-debug packages, you also " +"need to install the *yum-plugin-auto-update-debug-info* plug-in. This " +"plug-in searches the debug information repository for corresponding " +"updates.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:812 +#, no-wrap +msgid "" +"After successful setup, you can apply the standard profiling and analyzing " +"tools described in previous sections\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:814 +#, no-wrap +msgid "" +"To learn more about Java support in OProfile, see the OProfile Manual, which " +"is linked from " +"xref:OProfile.adoc#s1-oprofile_additional_resources[Additional Resources].\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:816 +#, no-wrap +msgid "[[s1-oprofile-gui]]\n" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/OProfile.adoc:816 +#, no-wrap +msgid "Graphical Interface" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:819 +msgid "" +"indexterm:[oprof_start] Some OProfile preferences can be set with a " +"graphical interface. Make sure you have the `oprofile-gui` package that " +"provides the OProfile GUI installed on your system. To start the interface, " +"execute the [command]#oprof_start# command as root at a shell prompt." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:821 +msgid "" +"After changing any of the options, save them by clicking the btn:[Save and " +"quit] button. The preferences are written to `/root/.oprofile/daemonrc`, and " +"the application exits. Exiting the application does not stop OProfile from " +"sampling." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:823 +msgid "" +"On the `Setup` tab, to set events for the processor counters as discussed in " +"xref:OProfile.adoc#s2-oprofile-events[Setting Events to Monitor], select the " +"counter from the pulldown menu and select the event from the list. A brief " +"description of the event appears in the text box below the list. Only events " +"available for the specific counter and the specific architecture are " +"displayed. The interface also displays whether the profiler is running and " +"some brief statistics about it." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:826 +msgid "[[fig-oprofile-setup]] .OProfile Setup" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:828 +msgid "image::oprof-start-setup.png[oprof_start interface]" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:830 +msgid "" +"On the right side of the tab, select the `Profile kernel` option to count " +"events in kernel mode for the currently selected event, as discussed in " +"xref:OProfile.adoc#s2-oprofile-starting-separate[Separating Kernel and " +"User-space Profiles]. If this option is not selected, no samples are " +"collected for the kernel." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:832 +msgid "" +"Select the `Profile user binaries` option to count events in user mode for " +"the currently selected event, as discussed in " +"xref:OProfile.adoc#s2-oprofile-starting-separate[Separating Kernel and " +"User-space Profiles]. If this option is not selected, no samples are " +"collected for user applications." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:834 +msgid "" +"Use the `Count` text field to set the sampling rate for the currently " +"selected event as discussed in " +"xref:OProfile.adoc#s3-oprofile-events-sampling[Sampling Rate]." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:836 +msgid "" +"If any unit masks are available for the currently selected event, as " +"discussed in xref:OProfile.adoc#s3-oprofile-events-unit-masks[Unit Masks], " +"they are displayed in the `Unit Masks` area on the right side of the `Setup` " +"tab. Select the check box beside the unit mask to enable it for the event." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:838 +msgid "" +"On the `Configuration` tab, to profile the kernel, enter the name and " +"location of the `vmlinux` file for the kernel to monitor in the `Kernel " +"image file` text field. To configure OProfile not to monitor the kernel, " +"select `No kernel image`." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:841 +msgid "[[fig-oprofile-configuration]] .OProfile Configuration" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:843 +msgid "image::oprof-start-config.png[OProfile Configuration]" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:845 +msgid "" +"If the `Verbose` option is selected, the [command]#oprofiled# daemon log " +"includes more detailed information." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:847 +msgid "" +"If `Per-application profiles` is selected, OProfile generates " +"per-application profiles for libraries. This is equivalent to the " +"[command]#opcontrol --separate=library# command. If `Per-application " +"profiles, including kernel` is selected, OProfile generates per-application " +"profiles for the kernel and kernel modules as discussed in " +"xref:OProfile.adoc#s2-oprofile-starting-separate[Separating Kernel and " +"User-space Profiles]. This is equivalent to the [command]#opcontrol " +"--separate=kernel# command." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:849 +msgid "" +"To force data to be written to samples files as discussed in " +"xref:OProfile.adoc#s1-oprofile-analyzing-data[Analyzing the Data], click the " +"btn:[Flush] button. This is equivalent to the [command]#opcontrol --dump# " +"command." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:851 +msgid "" +"To start OProfile from the graphical interface, click btn:[Start]. To stop " +"the profiler, click btn:[Stop]. Exiting the application does not stop " +"OProfile from sampling." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:853 +msgid "[[s1-oprofile-and-systemtap]]" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/OProfile.adoc:853 +#, no-wrap +msgid "OProfile and SystemTap" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:856 +msgid "" +"indexterm:[OProfile,SystemTap] SystemTap is a tracing and probing tool that " +"allows users to study and monitor the activities of the operating system in " +"fine detail. It provides information similar to the output of tools like " +"[command]#netstat#, [command]#ps#, [command]#top#, and " +"[command]#iostat#pass:attributes[{blank}]; however, SystemTap is designed to " +"provide more filtering and analysis options for the collected information." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:858 +msgid "" +"While using OProfile is suggested in cases of collecting data on where and " +"why the processor spends time in a particular area of code, it is less " +"usable when finding out why the processor stays idle." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:860 +msgid "" +"You might want to use SystemTap when instrumenting specific places in " +"code. Because SystemTap allows you to run the code instrumentation without " +"having to stop and restart the instrumented code, it is particularly useful " +"for instrumenting the kernel and daemons." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:862 +msgid "" +"For more information on SystemTap, see " +"xref:OProfile.adoc#br-oprofile_online_documentation[Online Documentation] " +"for the relevant SystemTap documentation." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:864 +msgid "[[s1-oprofile_additional_resources]]" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/OProfile.adoc:864 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:867 +msgid "" +"indexterm:[OProfile,additional resources] To learn more about OProfile and " +"how to configure it, see the following resources." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:869 +msgid ".Installed Documentation" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:871 +#, no-wrap +msgid "* `/usr/share/doc/oprofile/oprofile.html` — [citetitle]_OProfile Manual_\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:873 +#, no-wrap +msgid "" +"* `oprofile(1)` manual page — Discusses [command]#opcontrol#, " +"[command]#opreport#, [command]#opannotate#, and [command]#ophelp#\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:875 +#, no-wrap +msgid "* `operf(1)` manual page\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:878 +#, no-wrap +msgid "" +"[[br-oprofile_online_documentation]]\n" +".Online Documentation\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:880 +#, no-wrap +msgid "" +"* " +"link:++https://oprofile.sourceforge.net/++[http://oprofile.sourceforge.net/] " +"— Contains the latest upstream documentation, mailing lists, IRC channels, " +"and more.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:882 +#, no-wrap +msgid ".See Also\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:883 +#, no-wrap +msgid "" +"* " +"link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/SystemTap_Beginners_Guide/index.html++[SystemTap " +"Beginners Guide] — Provides basic instructions on how to use SystemTap to " +"monitor different subsystems of {MAJOROS} in finer detail.\n" +msgstr "" diff --git a/po/fr/rawhide/pages/monitoring-and-automation/System_Monitoring_Tools.po b/po/fr/rawhide/pages/monitoring-and-automation/System_Monitoring_Tools.po new file mode 100644 index 00000000000..a297dd70623 --- /dev/null +++ b/po/fr/rawhide/pages/monitoring-and-automation/System_Monitoring_Tools.po @@ -0,0 +1,3066 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:5 +#, no-wrap +msgid "System Monitoring Tools" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:8 +msgid "" +"indexterm:[system information,gathering]indexterm:[information,about your " +"system] In order to configure the system, system administrators often need " +"to determine the amount of free memory, how much free disk space is " +"available, how the hard drive is partitioned, or what processes are running." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:10 +#, no-wrap +msgid "Viewing System Processes" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:12 +msgid "indexterm:[system information,processes]indexterm:[processes]" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:14 +#, no-wrap +msgid "Using the ps Command" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:17 +msgid "" +"indexterm:[ps] The [command]#ps# command allows you to display information " +"about running processes. It produces a static list, that is, a snapshot of " +"what is running when you execute the command. If you want a constantly " +"updated list of running processes, use the [command]#top# command or the " +"[application]*System Monitor* application instead." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:19 +msgid "" +"To list all processes that are currently running on the system including " +"processes owned by other users, type the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:23 +#, no-wrap +msgid "[command]#ps# [option]`ax`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:26 +msgid "" +"For each listed process, the [command]#ps ax# command displays the process " +"ID (`PID`), the terminal that is associated with it (`TTY`), the current " +"status (`STAT`), the cumulated CPU time (`TIME`), and the name of the " +"executable file (`COMMAND`). For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:37 +#, no-wrap +msgid "" +"~]$ [command]#ps ax#\n" +" PID TTY STAT TIME COMMAND\n" +" 1 ? Ss 0:02 /usr/lib/systemd/systemd --system --deserialize " +"20\n" +" 2 ? S 0:00 [kthreadd]\n" +" 3 ? S 0:00 [ksoftirqd/0]\n" +" 5 ? S 0:00 [kworker/u:0]\n" +" 6 ? S 0:00 [migration/0]\n" +"_[output truncated]_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:40 +msgid "To display the owner alongside each process, use the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:44 +#, no-wrap +msgid "[command]#ps# [option]`aux`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:47 +msgid "" +"Apart from the information provided by the [command]#ps ax# command, " +"[command]#ps aux# displays the effective username of the process owner " +"(`USER`), the percentage of the CPU (`%CPU`) and memory (`%MEM`) usage, the " +"virtual memory size in kilobytes (`VSZ`), the non-swapped physical memory " +"size in kilobytes (`RSS`), and the time or date the process was started. For " +"instance:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:58 +#, no-wrap +msgid "" +"~]$ [command]#ps aux#\n" +"USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND\n" +"root 1 0.0 0.3 53128 2988 ? Ss 13:28 0:02 " +"/usr/lib/systemd/systemd --system --deserialize 20\n" +"root 2 0.0 0.0 0 0 ? S 13:28 0:00 " +"[kthreadd]\n" +"root 3 0.0 0.0 0 0 ? S 13:28 0:00 " +"[ksoftirqd/0]\n" +"root 5 0.0 0.0 0 0 ? S 13:28 0:00 " +"[kworker/u:0]\n" +"root 6 0.0 0.0 0 0 ? S 13:28 0:00 " +"[migration/0]\n" +"_[output truncated]_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:61 +msgid "" +"You can also use the [command]#ps# command in a combination with " +"[command]#grep# to see if a particular process is running. For example, to " +"determine if [application]*Emacs* is running, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:66 +#, no-wrap +msgid "" +"~]$ [command]#ps ax | grep emacs#\n" +" 2625 ? Sl 0:00 emacs\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:69 +msgid "" +"For a complete list of available command line options, refer to the *ps*(1) " +"manual page." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:71 +#, no-wrap +msgid "Using the top Command" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:74 +msgid "" +"indexterm:[system information,processes,currently running]indexterm:[top] " +"The [command]#top# command displays a real-time list of processes that are " +"running on the system. It also displays additional information about the " +"system uptime, current CPU and memory usage, or total number of running " +"processes, and allows you to perform actions such as sorting the list or " +"killing a process." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:76 +msgid "To run the [command]#top# command, type the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:80 +#, no-wrap +msgid "[command]#top#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:83 +msgid "" +"For each listed process, the [command]#top# command displays the process ID " +"(`PID`), the effective username of the process owner (`USER`), the priority " +"(`PR`), the nice value (`NI`), the amount of virtual memory the process uses " +"(`VIRT`), the amount of non-swapped physical memory the process uses " +"(`RES`), the amount of shared memory the process uses (`SHR`), the " +"percentage of the CPU (`%CPU`) and memory (`%MEM`) usage, the cumulated CPU " +"time (`TIME+`), and the name of the executable file (`COMMAND`). For " +"example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:91 +#, no-wrap +msgid "" +"~]$ top\n" +"top - 19:22:08 up 5:53, 3 users, load average: 1.08, 1.03, 0.82\n" +"Tasks: 117 total, 2 running, 115 sleeping, 0 stopped, 0 zombie\n" +"Cpu(s): 9.3%us, 1.3%sy, 0.0%ni, 85.1%id, 0.0%wa, 1.7%hi, 0.0%si, " +"2.6%st\n" +"Mem: 761956k total, 617256k used, 144700k free, 24356k buffers\n" +"Swap: 1540092k total, 55780k used, 1484312k free, 256408k cached\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:110 +#, no-wrap +msgid "" +" PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND\n" +" 510 john 20 0 1435m 99m 18m S 9.0 13.3 3:30.52 gnome-shell\n" +"32686 root 20 0 156m 27m 3628 R 2.0 3.7 0:48.69 Xorg\n" +" 2625 john 20 0 488m 27m 14m S 0.3 3.7 0:00.70 emacs\n" +" 1 root 20 0 53128 2640 1152 S 0.0 0.3 0:02.83 systemd\n" +" 2 root 20 0 0 0 0 S 0.0 0.0 0:00.01 kthreadd\n" +" 3 root 20 0 0 0 0 S 0.0 0.0 0:00.18 ksoftirqd/0\n" +" 5 root 20 0 0 0 0 S 0.0 0.0 0:00.00 kworker/u:0\n" +" 6 root RT 0 0 0 0 S 0.0 0.0 0:00.00 migration/0\n" +" 7 root RT 0 0 0 0 S 0.0 0.0 0:00.30 watchdog/0\n" +" 8 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 cpuset\n" +" 9 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 khelper\n" +" 10 root 20 0 0 0 0 S 0.0 0.0 0:00.00 kdevtmpfs\n" +" 11 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 netns\n" +" 12 root 20 0 0 0 0 S 0.0 0.0 0:00.11 sync_supers\n" +" 13 root 20 0 0 0 0 S 0.0 0.0 0:00.00 bdi-default\n" +" 14 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 kintegrityd\n" +" 15 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 kblockd\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:113 +msgid "" +"xref:System_Monitoring_Tools.adoc#interactive-top-command[Interactive top " +"commands] contains useful interactive commands that you can use with " +"[command]#top#. For more information, refer to the *top*(1) manual page." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:115 +#, no-wrap +msgid "Interactive top commands" +msgstr "" + +#. type: Table +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:128 +#, no-wrap +msgid "" +"|Command|Description\n" +"|kbd:[Enter], kbd:[Space]|Immediately refreshes the display.\n" +"|kbd:[h], kbd:[?]|Displays a help screen.\n" +"|kbd:[k]|Kills a process. You are prompted for the process ID and the signal " +"to send to it.\n" +"|kbd:[n]|Changes the number of displayed processes. You are prompted to " +"enter the number.\n" +"|kbd:[u]|Sorts the list by user.\n" +"|kbd:[M]|Sorts the list by memory usage.\n" +"|kbd:[P]|Sorts the list by CPU usage.\n" +"|kbd:[q]|Terminates the utility and returns to the shell prompt.\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:131 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:223 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:241 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:579 +#, no-wrap +msgid "Using the System Monitor Tool" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:134 +msgid "" +"indexterm:[gnome-system-monitor]indexterm:[System Monitor] The `Processes` " +"tab of the [application]*System Monitor* tool allows you to view, search " +"for, change the priority of, and kill processes from the graphical user " +"interface." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:136 +msgid "" +"To start the [application]*System Monitor* tool, either select " +"menu:Applications[System Tools > `System Monitor`pass:attributes[{blank}]] " +"from the Activities menu, or type [command]#gnome-system-monitor# at a shell " +"prompt. Then click the `Processes` tab to view the list of running " +"processes." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:146 +msgid "" +"For each listed process, the [application]*System Monitor* tool displays its " +"name (`Process Name`), user (`User`), percentage of the CPU usage (`% CPU`), " +"process ID (`ID`), memory usage (`Memory`), total disk read and write (`Disk " +"read total` and `Disk write total`), current disk read and write (`Disk " +"read` and `Disk write`), and priority (`Priority`). To sort the information " +"by a specific column in ascending order, click the name of that " +"column. Click the name of the column again to toggle the sort between " +"ascending and descending order." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:148 +msgid "" +"By default, the [application]*System Monitor* tool displays a list of " +"processes that are owned by the current user. Selecting various options from " +"the View menu allows you to:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:150 +msgid "view only active processes," +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:152 +msgid "view all processes," +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:154 +msgid "view your processes," +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:156 +msgid "view process dependencies," +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:158 +msgid "view a memory map of a selected process," +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:160 +msgid "view the files opened by a selected process, and" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:162 +msgid "refresh the list of processes." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:164 +msgid "Additionally, various options in the Edit menu allows you to:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:166 +msgid "stop a process," +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:168 +msgid "continue running a stopped process," +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:170 +msgid "end a process," +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:172 +msgid "kill a process," +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:174 +msgid "change the priority of a selected process, and" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:176 +msgid "" +"edit the [application]*System Monitor* preferences, such as the refresh " +"interval for the list of processes, or what information to show." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:178 +msgid "" +"You can also end a process by selecting it from the list and clicking the " +"btn:[End Process] button." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:180 +#, no-wrap +msgid "Viewing Memory Usage" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:182 +msgid "" +"indexterm:[system information,memory usage]indexterm:[memory " +"usage]indexterm:[RAM]" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:184 +#, no-wrap +msgid "Using the free Command" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:187 +msgid "" +"indexterm:[free] The [command]#free# command allows you to display the " +"amount of free and used memory on the system. To do so, type the following " +"at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:191 +#, no-wrap +msgid "[command]#free#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:194 +msgid "" +"The [command]#free# command provides information about both the physical " +"memory (`Mem`) and swap space (`Swap`). It displays the total amount of " +"memory (`total`), as well as the amount of memory that is in use (`used`), " +"free (`free`), shared (`shared`), in kernel buffers (`buffers`), and cached " +"(`cached`). For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:201 +#, no-wrap +msgid "" +"~]$ free\n" +" total used free shared buffers cached\n" +"Mem: 761956 607500 154456 0 37404 156176\n" +"-/+ buffers/cache: 413920 348036\n" +"Swap: 1540092 84408 1455684\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:204 +msgid "" +"By default, [command]#free# displays the values in kilobytes. To display the " +"values in megabytes, supply the [option]`-m` command line option:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:208 +#, no-wrap +msgid "[command]#free# [option]`-m`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:211 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:289 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:430 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:500 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:549 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:681 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:736 +msgid "For instance:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:218 +#, no-wrap +msgid "" +"~]$ free -m\n" +" total used free shared buffers cached\n" +"Mem: 744 593 150 0 36 152\n" +"-/+ buffers/cache: 404 339\n" +"Swap: 1503 82 1421\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:221 +msgid "" +"For a complete list of available command line options, refer to the " +"*free*(1) manual page." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:226 +msgid "" +"indexterm:[gnome-system-monitor]indexterm:[System Monitor] The `Resources` " +"tab of the [application]*System Monitor* tool allows you to view the amount " +"of free and used memory on the system." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:228 +msgid "" +"To start the [application]*System Monitor* tool, either select " +"menu:Applications[System Tools > `System Monitor`pass:attributes[{blank}]] " +"from the Activities menu, or type [command]#gnome-system-monitor# at a shell " +"prompt. Then click the `Resources` tab to view the system's memory usage." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:230 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:248 +#, no-wrap +msgid "System Monitor — Resources" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:232 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:250 +#, no-wrap +msgid "The Resources tab of the System Monitor application." +msgstr "" + +#. type: Target for macro image +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:232 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:250 +#, no-wrap +msgid "system-monitor-resources.png" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:235 +msgid "" +"In the `Memory and Swap History` section, the [application]*System Monitor* " +"tool displays a graphical representation of the memory and swap usage " +"history, as well as the total amount of the physical memory (`Memory`) and " +"swap space (`Swap`) and how much of it is in use." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:237 +#, no-wrap +msgid "Viewing CPU Usage" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:239 +msgid "indexterm:[system information,cpu usage]indexterm:[CPU usage]" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:244 +msgid "" +"indexterm:[gnome-system-monitor]indexterm:[System Monitor] The `Resources` " +"tab of the [application]*System Monitor* tool allows you to view the current " +"CPU usage on the system." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:246 +msgid "" +"To start the [application]*System Monitor* tool, either select " +"menu:Applications[System Tools > `System Monitor`pass:attributes[{blank}]] " +"from the Activities menu, or type [command]#gnome-system-monitor# at a shell " +"prompt. Then click the `Resources` tab to view the system's CPU usage." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:253 +msgid "" +"In the `CPU History` section, the [application]*System Monitor* tool " +"displays a graphical representation of the CPU usage history and shows the " +"percentage of how much CPU is currently in use." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:255 +#, no-wrap +msgid "Viewing Block Devices and File Systems" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:257 +msgid "indexterm:[system information,file systems]indexterm:[file systems]" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:259 +#, no-wrap +msgid "Using the lsblk Command" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:262 +msgid "" +"indexterm:[lsblk] The [command]#lsblk# command allows you to display a list " +"of available block devices. To do so, type the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:266 +#, no-wrap +msgid "[command]#lsblk#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:269 +msgid "" +"For each listed block device, the [command]#lsblk# command displays the " +"device name (`NAME`), major and minor device number (`MAJ:MIN`), if the " +"device is removable (`RM`), what is its size (`SIZE`), if the device is " +"read-only (`RO`), what type is it (`TYPE`), and where the device is mounted " +"(`MOUNTPOINT`). For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:279 +#, no-wrap +msgid "" +"~]$ lsblk\n" +"NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINT\n" +"sr0 11:0 1 1024M 0 rom\n" +"vda 252:0 0 20G 0 disk\n" +"|-vda1 252:1 0 500M 0 part /boot\n" +"`-vda2 252:2 0 19.5G 0 part\n" +" |-vg_fedora-lv_swap (dm-0) 253:0 0 1.5G 0 lvm [SWAP]\n" +" `-vg_fedora-lv_root (dm-1) 253:1 0 18G 0 lvm /\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:282 +msgid "" +"By default, [command]#lsblk# lists block devices in a tree-like format. To " +"display the information as an ordinary list, add the [option]`-l` command " +"line option:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:286 +#, no-wrap +msgid "[command]#lsblk# [option]`-l`\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:299 +#, no-wrap +msgid "" +"~]$ lsblk -l\n" +"NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINT\n" +"sr0 11:0 1 1024M 0 rom\n" +"vda 252:0 0 20G 0 disk\n" +"vda1 252:1 0 500M 0 part /boot\n" +"vda2 252:2 0 19.5G 0 part\n" +"vg_fedora-lv_swap (dm-0) 253:0 0 1.5G 0 lvm [SWAP]\n" +"vg_fedora-lv_root (dm-1) 253:1 0 18G 0 lvm /\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:302 +msgid "" +"For a complete list of available command line options, refer to the " +"*lsblk*(8) manual page." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:304 +#, no-wrap +msgid "Using the blkid Command" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:307 +msgid "" +"indexterm:[blkid] The [command]#blkid# command allows you to display " +"information about available block devices. To do so, type the following at a " +"shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:311 +#, no-wrap +msgid "[command]#blkid#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:314 +msgid "" +"For each listed block device, the [command]#blkid# command displays " +"available attributes such as its _universally unique identifier_ (`UUID`), " +"file system type (`TYPE`), or volume label (`LABEL`). For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:321 +#, no-wrap +msgid "" +"~]# blkid\n" +"/dev/vda1: UUID=\"4ea24c68-ab10-47d4-8a6b-b8d3a002acba\" TYPE=\"ext4\"\n" +"/dev/vda2: UUID=\"iJ9YwJ-leFf-A1zb-VVaK-H9t1-raLW-HoqlUG\" " +"TYPE=\"LVM2_member\"\n" +"/dev/mapper/vg_fedora-lv_swap: UUID=\"d6d755bc-3e3e-4e8f-9bb5-a5e7f4d86ffd\" " +"TYPE=\"swap\"\n" +"/dev/mapper/vg_fedora-lv_root: LABEL=\"_Fedora-17-x86_6\" " +"UUID=\"77ba9149-751a-48e0-974f-ad94911734b9\" TYPE=\"ext4\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:324 +msgid "" +"By default, the [command]#lsblk# command lists all available block " +"devices. To display information about a particular device only, specify the " +"device name on the command line:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:328 +#, no-wrap +msgid "blkid pass:quotes[_device_name_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:331 +msgid "For instance, to display information about `/dev/vda1`, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:335 +#, no-wrap +msgid "" +"~]# blkid /dev/vda1\n" +"/dev/vda1: UUID=\"4ea24c68-ab10-47d4-8a6b-b8d3a002acba\" TYPE=\"ext4\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:338 +msgid "" +"You can also use the above command with the [option]`-p` and [option]`-o " +"udev` command line options to obtain more detailed information. Note that " +"`root` privileges are required to run this command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:342 +#, no-wrap +msgid "blkid -po udev pass:quotes[_device_name_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:345 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:529 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:569 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:607 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:722 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:756 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:794 +msgid "For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:360 +#, no-wrap +msgid "" +"~]# blkid -po udev /dev/vda1\n" +"ID_FS_UUID=4ea24c68-ab10-47d4-8a6b-b8d3a002acba\n" +"ID_FS_UUID_ENC=4ea24c68-ab10-47d4-8a6b-b8d3a002acba\n" +"ID_FS_VERSION=1.0\n" +"ID_FS_TYPE=ext4\n" +"ID_FS_USAGE=filesystem\n" +"ID_PART_ENTRY_SCHEME=dos\n" +"ID_PART_ENTRY_TYPE=0x83\n" +"ID_PART_ENTRY_FLAGS=0x80\n" +"ID_PART_ENTRY_NUMBER=1\n" +"ID_PART_ENTRY_OFFSET=2048\n" +"ID_PART_ENTRY_SIZE=1024000\n" +"ID_PART_ENTRY_DISK=252:0\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:363 +msgid "" +"For a complete list of available command line options, refer to the " +"*blkid*(8) manual page." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:365 +#, no-wrap +msgid "Using the partx Command" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:368 +msgid "" +"indexterm:[partx] The [command]#partx# command allows you to display a list " +"of disk partitions. To list the partition table of a particular disk, as " +"`root`, run this command with the [option]`-s` option followed by the device " +"name:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:372 +#, no-wrap +msgid "partx -s pass:quotes[_device_name_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:375 +msgid "For example, to list partitions on `/dev/vda`, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:381 +#, no-wrap +msgid "" +"~]# partx -s /dev/vda\n" +"NR START END SECTORS SIZE NAME UUID\n" +" 1 2048 1026047 1024000 500M\n" +" 2 1026048 41943039 40916992 19.5G\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:384 +msgid "" +"For a complete list of available command line options, refer to the " +"*partx*(8) manual page." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:386 +#, no-wrap +msgid "Using the findmnt Command" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:389 +msgid "" +"indexterm:[findmnt] The [command]#findmnt# command allows you to display a " +"list of currently mounted file systems. To do so, type the following at a " +"shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:393 +#, no-wrap +msgid "[command]#findmnt#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:396 +msgid "" +"For each listed file system, the [command]#findmnt# command displays the " +"target mount point (`TARGET`), source device (`SOURCE`), file system type " +"(`FSTYPE`), and relevant mount options (`OPTIONS`). For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:420 +#, no-wrap +msgid "" +"~]$ findmnt\n" +"TARGET SOURCE FSTYPE OPTIONS\n" +"/ /dev/mapper/vg_fedora-lv_root\n" +" ext4 " +"rw,relatime,seclabel,data=o\n" +"|-/proc proc proc " +"rw,nosuid,nodev,noexec,rela\n" +"| `-/proc/sys/fs/binfmt_misc systemd-1 autofs " +"rw,relatime,fd=23,pgrp=1,ti\n" +"|-/sys sysfs sysfs " +"rw,nosuid,nodev,noexec,rela\n" +"| |-/sys/kernel/security securityfs security " +"rw,nosuid,nodev,noexec,rela\n" +"| |-/sys/fs/selinux selinuxfs selinuxf rw,relatime\n" +"| |-/sys/fs/cgroup tmpfs tmpfs " +"rw,nosuid,nodev,noexec,secl\n" +"| | |-/sys/fs/cgroup/systemd cgroup cgroup " +"rw,nosuid,nodev,noexec,rela\n" +"| | |-/sys/fs/cgroup/cpuset cgroup cgroup " +"rw,nosuid,nodev,noexec,rela\n" +"| | |-/sys/fs/cgroup/cpu,cpuacct cgroup cgroup " +"rw,nosuid,nodev,noexec,rela\n" +"| | |-/sys/fs/cgroup/memory cgroup cgroup " +"rw,nosuid,nodev,noexec,rela\n" +"| | |-/sys/fs/cgroup/devices cgroup cgroup " +"rw,nosuid,nodev,noexec,rela\n" +"| | |-/sys/fs/cgroup/freezer cgroup cgroup " +"rw,nosuid,nodev,noexec,rela\n" +"| | |-/sys/fs/cgroup/net_cls cgroup cgroup " +"rw,nosuid,nodev,noexec,rela\n" +"| | |-/sys/fs/cgroup/blkio cgroup cgroup " +"rw,nosuid,nodev,noexec,rela\n" +"| | `-/sys/fs/cgroup/perf_event cgroup cgroup " +"rw,nosuid,nodev,noexec,rela\n" +"| |-/sys/kernel/debug debugfs debugfs rw,relatime\n" +"| `-/sys/kernel/config configfs configfs rw,relatime\n" +"[output truncated]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:423 +msgid "" +"By default, [command]#findmnt# lists file systems in a tree-like format. To " +"display the information as an ordinary list, add the [option]`-l` command " +"line option:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:427 +#, no-wrap +msgid "[command]#findmnt# [option]`-l`\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:447 +#, no-wrap +msgid "" +"~]$ findmnt -l\n" +"TARGET SOURCE FSTYPE OPTIONS\n" +"/proc proc proc " +"rw,nosuid,nodev,noexec,relatime\n" +"/sys sysfs sysfs " +"rw,nosuid,nodev,noexec,relatime,s\n" +"/dev devtmpfs devtmpfs " +"rw,nosuid,seclabel,size=370080k,n\n" +"/dev/pts devpts devpts " +"rw,nosuid,noexec,relatime,seclabe\n" +"/dev/shm tmpfs tmpfs rw,nosuid,nodev,seclabel\n" +"/run tmpfs tmpfs " +"rw,nosuid,nodev,seclabel,mode=755\n" +"/ /dev/mapper/vg_fedora-lv_root\n" +" ext4 " +"rw,relatime,seclabel,data=ordered\n" +"/sys/kernel/security securityfs security " +"rw,nosuid,nodev,noexec,relatime\n" +"/sys/fs/selinux selinuxfs selinuxf rw,relatime\n" +"/sys/fs/cgroup tmpfs tmpfs " +"rw,nosuid,nodev,noexec,seclabel,m\n" +"/sys/fs/cgroup/systemd cgroup cgroup " +"rw,nosuid,nodev,noexec,relatime,r\n" +"[output truncated]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:450 +msgid "" +"You can also choose to list only file systems of a particular type. To do " +"so, add the [option]`-t` command line option followed by a file system type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:454 +#, no-wrap +msgid "[command]#findmnt# [option]`-t` _type_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:457 +msgid "For example, to all list `ext4` file systems, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:463 +#, no-wrap +msgid "" +"~]$ findmnt -t ext4\n" +"TARGET SOURCE FSTYPE OPTIONS\n" +"/ /dev/mapper/vg_fedora-lv_root ext4 " +"rw,relatime,seclabel,data=ordered\n" +"/boot /dev/vda1 ext4 " +"rw,relatime,seclabel,data=ordered\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:466 +msgid "" +"For a complete list of available command line options, refer to the " +"*findmnt*(8) manual page." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:468 +#, no-wrap +msgid "Using the df Command" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:471 +msgid "" +"indexterm:[df] The [command]#df# command allows you to display a detailed " +"report on the system's disk space usage. To do so, type the following at a " +"shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:475 +#, no-wrap +msgid "[command]#df#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:478 +msgid "" +"For each listed file system, the [command]#df# command displays its name " +"(`Filesystem`), size (`1K-blocks` or `Size`), how much space is used " +"(`Used`), how much space is still available (`Available`), the percentage of " +"space usage (`Use%`), and where is the file system mounted (`Mounted " +"on`). For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:490 +#, no-wrap +msgid "" +"~]$ df\n" +"Filesystem 1K-blocks Used Available Use% Mounted on\n" +"rootfs 18877356 4605476 14082844 25% /\n" +"devtmpfs 370080 0 370080 0% /dev\n" +"tmpfs 380976 256 380720 1% /dev/shm\n" +"tmpfs 380976 3048 377928 1% /run\n" +"/dev/mapper/vg_fedora-lv_root 18877356 4605476 14082844 25% /\n" +"tmpfs 380976 0 380976 0% " +"/sys/fs/cgroup\n" +"tmpfs 380976 0 380976 0% /media\n" +"/dev/vda1 508745 85018 398127 18% /boot\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:493 +msgid "" +"By default, the [command]#df# command shows the partition size in " +"1{nbsp}kilobyte blocks and the amount of used and available disk space in " +"kilobytes. To view the information in megabytes and gigabytes, supply the " +"[option]`-h` command line option, which causes [command]#df# to display the " +"values in a human-readable format:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:497 +#, no-wrap +msgid "[command]#df# [option]`-h`\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:512 +#, no-wrap +msgid "" +"~]$ df -h\n" +"Filesystem Size Used Avail Use% Mounted on\n" +"rootfs 19G 4.4G 14G 25% /\n" +"devtmpfs 362M 0 362M 0% /dev\n" +"tmpfs 373M 256K 372M 1% /dev/shm\n" +"tmpfs 373M 3.0M 370M 1% /run\n" +"/dev/mapper/vg_fedora-lv_root 19G 4.4G 14G 25% /\n" +"tmpfs 373M 0 373M 0% /sys/fs/cgroup\n" +"tmpfs 373M 0 373M 0% /media\n" +"/dev/vda1 497M 84M 389M 18% /boot\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:515 +msgid "" +"indexterm:[system information,file " +"systems,/dev/shm]indexterm:[/dev/shm]indexterm:[system information,file " +"systems,/sys/fs/cgroup]indexterm:[/sys/fs/cgroup]indexterm:[system " +"information,file systems,/run]indexterm:[/run] Note that the `/dev/shm` " +"entry represents the system's virtual memory file system, `/sys/fs/cgroup` " +"is a cgroup file system, and `/run` contains information about the running " +"system." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:517 +msgid "" +"For a complete list of available command line options, refer to the *df*(1) " +"manual page." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:519 +#, no-wrap +msgid "Using the du Command" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:522 +msgid "" +"indexterm:[du] The [command]#du# command allows you to displays the amount " +"of space that is being used by files in a directory. To display the disk " +"usage for each of the subdirectories in the current working directory, run " +"the command with no additional command line options:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:526 +#, no-wrap +msgid "[command]#du#\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:539 +#, no-wrap +msgid "" +"~]$ [command]#du#\n" +"8 ./.gconf/apps/gnome-terminal/profiles/Default\n" +"12 ./.gconf/apps/gnome-terminal/profiles\n" +"16 ./.gconf/apps/gnome-terminal\n" +"_[output truncated]_\n" +"460 ./.gimp-2.6\n" +"68828 .\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:542 +msgid "" +"By default, the [command]#du# command displays the disk usage in " +"kilobytes. To view the information in megabytes and gigabytes, supply the " +"[option]`-h` command line option, which causes the utility to display the " +"values in a human-readable format:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:546 +#, no-wrap +msgid "[command]#du# [option]`-h`\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:559 +#, no-wrap +msgid "" +"~]$ [command]#du -h#\n" +"8.0K ./.gconf/apps/gnome-terminal/profiles/Default\n" +"12K ./.gconf/apps/gnome-terminal/profiles\n" +"16K ./.gconf/apps/gnome-terminal\n" +"_[output truncated]_\n" +"460K ./.gimp-2.6\n" +"68M .\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:562 +msgid "" +"At the end of the list, the [command]#du# command always shows the grand " +"total for the current directory. To display only this information, supply " +"the [option]`-s` command line option:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:566 +#, no-wrap +msgid "[command]#du# [option]`-sh`\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:574 +#, no-wrap +msgid "" +"~]$ [command]#du -sh#\n" +"68M .\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:577 +msgid "" +"For a complete list of available command line options, refer to the *du*(1) " +"manual page." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:582 +msgid "" +"indexterm:[gnome-system-monitor]indexterm:[System Monitor] The `File " +"Systems` tab of the [application]*System Monitor* tool allows you to view " +"file systems and disk space usage in the graphical user interface." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:584 +msgid "" +"To start the [application]*System Monitor* tool, either select " +"menu:Applications[System Tools > `System Monitor`pass:attributes[{blank}]] " +"from the Activities menu, or type [command]#gnome-system-monitor# at a shell " +"prompt. Then click the `File Systems` tab to view a list of file systems." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:586 +#, no-wrap +msgid "System Monitor — File Systems" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:588 +#, no-wrap +msgid "The File Systems tab of the System Monitor application." +msgstr "" + +#. type: Target for macro image +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:588 +#, no-wrap +msgid "system-monitor-file-systems.png" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:591 +msgid "" +"For each listed file system, the [application]*System Monitor* tool displays " +"the source device (`Device`), target mount point (`Directory`), and file " +"system type (`Type`), as well as its size (`Total`) and how much space is " +"free (`Free`), available (`Available`), and used (`Used`)." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:593 +#, no-wrap +msgid "Viewing Hardware Information" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:595 +msgid "indexterm:[system information,hardware]indexterm:[hardware,viewing]" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:597 +#, no-wrap +msgid "Using the lspci Command" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:600 +msgid "" +"indexterm:[lspci] The [command]#lspci# command lists all PCI devices that " +"are present in the system:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:604 +#, no-wrap +msgid "[command]#lspci#\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:616 +#, no-wrap +msgid "" +"~]$ lspci\n" +"00:00.0 Host bridge: Intel Corporation 82X38/X48 Express DRAM Controller\n" +"00:01.0 PCI bridge: Intel Corporation 82X38/X48 Express Host-Primary PCI " +"Express Bridge\n" +"00:1a.0 USB Controller: Intel Corporation 82801I (ICH9 Family) USB UHCI " +"Controller #4 (rev 02)\n" +"00:1a.1 USB Controller: Intel Corporation 82801I (ICH9 Family) USB UHCI " +"Controller #5 (rev 02)\n" +"00:1a.2 USB Controller: Intel Corporation 82801I (ICH9 Family) USB UHCI " +"Controller #6 (rev 02)\n" +"[output truncated]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:619 +msgid "" +"You can also use the [option]`-v` command line option to display more " +"verbose output, or [option]`-vv` for very verbose output:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:623 +#, no-wrap +msgid "[command]#lspci# [option]`-v`|[option]`-vv`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:626 +msgid "" +"For instance, to determine the manufacturer, model, and memory size of a " +"system's video card, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:631 +#, no-wrap +msgid "" +"~]$ [command]#lspci -v#\n" +"_[output truncated]_\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:644 +#, no-wrap +msgid "" +"01:00.0 VGA compatible controller: nVidia Corporation G84 [Quadro FX 370] " +"(rev a1) (prog-if 00 [VGA controller])\n" +" Subsystem: nVidia Corporation Device 0491\n" +" Physical Slot: 2\n" +" Flags: bus master, fast devsel, latency 0, IRQ 16\n" +" Memory at f2000000 (32-bit, non-prefetchable) [size=16M]\n" +" Memory at e0000000 (64-bit, prefetchable) [size=256M]\n" +" Memory at f0000000 (64-bit, non-prefetchable) [size=32M]\n" +" I/O ports at 1100 [size=128]\n" +" Expansion ROM at <unassigned> [disabled]\n" +" Capabilities: <access denied>\n" +" Kernel driver in use: nouveau\n" +" Kernel modules: nouveau, nvidiafb\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:646 +#, no-wrap +msgid "_[output truncated]_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:649 +msgid "" +"For a complete list of available command line options, refer to the " +"*lspci*(8) manual page." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:651 +#, no-wrap +msgid "Using the lsusb Command" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:654 +msgid "" +"indexterm:[lsusb] The [command]#lsusb# command allows you to display " +"information about USB buses and devices that are attached to them. To list " +"all USB devices that are in the system, type the following at a shell " +"prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:658 +#, no-wrap +msgid "[command]#lsusb#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:661 +msgid "This displays a simple list of devices, for example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:671 +#, no-wrap +msgid "" +"~]$ [command]#lsusb#\n" +"Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub\n" +"Bus 002 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub\n" +"_[output truncated]_\n" +"Bus 001 Device 002: ID 0bda:0151 Realtek Semiconductor Corp. Mass Storage " +"Device (Multicard Reader)\n" +"Bus 008 Device 002: ID 03f0:2c24 Hewlett-Packard Logitech M-UAL-96 Mouse\n" +"Bus 008 Device 003: ID 04b3:3025 IBM Corp.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:674 +msgid "" +"You can also use the [option]`-v` command line option to display more " +"verbose output:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:678 +#, no-wrap +msgid "[command]#lsusb# [option]`-v`\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:686 +#, no-wrap +msgid "" +"~]$ [command]#lsusb -v#\n" +"_[output truncated]_\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:707 +#, no-wrap +msgid "" +"Bus 008 Device 002: ID 03f0:2c24 Hewlett-Packard Logitech M-UAL-96 Mouse\n" +"Device Descriptor:\n" +" bLength 18\n" +" bDescriptorType 1\n" +" bcdUSB 2.00\n" +" bDeviceClass 0 (Defined at Interface level)\n" +" bDeviceSubClass 0\n" +" bDeviceProtocol 0\n" +" bMaxPacketSize0 8\n" +" idVendor 0x03f0 Hewlett-Packard\n" +" idProduct 0x2c24 Logitech M-UAL-96 Mouse\n" +" bcdDevice 31.00\n" +" iManufacturer 1\n" +" iProduct 2\n" +" iSerial 0\n" +" bNumConfigurations 1\n" +" Configuration Descriptor:\n" +" bLength 9\n" +" bDescriptorType 2\n" +"_[output truncated]_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:710 +msgid "" +"For a complete list of available command line options, refer to the " +"*lsusb*(8) manual page." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:712 +#, no-wrap +msgid "Using the lspcmcia Command" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:715 +msgid "" +"indexterm:[lspcmcia] The [command]#lspcmcia# command allows you to list all " +"PCMCIA devices that are present in the system. To do so, type the following " +"at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:719 +#, no-wrap +msgid "[command]#lspcmcia#\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:726 +#, no-wrap +msgid "" +"~]$ lspcmcia\n" +"Socket 0 Bridge: [yenta_cardbus] (bus ID: 0000:15:00.0)\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:729 +msgid "" +"You can also use the [option]`-v` command line option to display more " +"verbose information, or [option]`-vv` to increase the verbosity level even " +"further:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:733 +#, no-wrap +msgid "[command]#lspcmcia# [option]`-v`|[option]`-vv`\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:741 +#, no-wrap +msgid "" +"~]$ lspcmcia -v\n" +"Socket 0 Bridge: [yenta_cardbus] (bus ID: 0000:15:00.0)\n" +" Configuration: state: on ready: unknown\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:744 +msgid "" +"For a complete list of available command line options, refer to the " +"*pccardctl*(8) manual page." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:746 +#, no-wrap +msgid "Using the lscpu Command" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:749 +msgid "" +"indexterm:[lscpu] The [command]#lscpu# command allows you to list " +"information about CPUs that are present in the system, including the number " +"of CPUs, their architecture, vendor, family, model, CPU caches, etc. To do " +"so, type the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:753 +#, no-wrap +msgid "[command]#lscpu#\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:779 +#, no-wrap +msgid "" +"~]$ lscpu\n" +"Architecture: x86_64\n" +"CPU op-mode(s): 32-bit, 64-bit\n" +"Byte Order: Little Endian\n" +"CPU(s): 4\n" +"On-line CPU(s) list: 0-3\n" +"Thread(s) per core: 1\n" +"Core(s) per socket: 4\n" +"Socket(s): 1\n" +"NUMA node(s): 1\n" +"Vendor ID: GenuineIntel\n" +"CPU family: 6\n" +"Model: 23\n" +"Stepping: 7\n" +"CPU MHz: 1998.000\n" +"BogoMIPS: 4999.98\n" +"Virtualization: VT-x\n" +"L1d cache: 32K\n" +"L1i cache: 32K\n" +"L2 cache: 3072K\n" +"NUMA node0 CPU(s): 0-3\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:782 +msgid "" +"For a complete list of available command line options, refer to the " +"*lscpu*(1) manual page." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:784 +#, no-wrap +msgid "Using the Hardware probe" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:787 +msgid "" +"indexterm:[hw-probe] The [command]#hw-probe# command allows you to list all " +"hardware devices, perform sanity tests for some of them and submit result to " +"the link:++https://github.com/linuxhw++[hardware database]. To do so, type " +"the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:791 +#, no-wrap +msgid "[command]#hw-probe -all -upload#\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:801 +#, no-wrap +msgid "" +"~]$ hw-probe -all -upload\n" +"Probe for hardware ... Ok\n" +"Reading logs ... Ok\n" +"Uploaded to DB, Thank you!\n" +"Probe URL: https://linux-hardware.org/?probe=c84b37d646\n" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:804 +#, no-wrap +msgid "Monitoring Performance with Net-SNMP" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:807 +msgid "" +"{MAJOROSVER} includes the [application]*Net-SNMP* software suite, which " +"includes a flexible and extensible _Simple Network Management Protocol_ " +"(*SNMP*) agent. This agent and its associated utilities can be used to " +"provide performance data from a large number of systems to a variety of " +"tools which support polling over the SNMP protocol." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:809 +msgid "" +"This section provides information on configuring the Net-SNMP agent to " +"securely provide performance data over the network, retrieving the data " +"using the SNMP protocol, and extending the SNMP agent to provide custom " +"performance metrics." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:811 +#, no-wrap +msgid "Installing Net-SNMP" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:814 +msgid "" +"The Net-SNMP software suite is available as a set of RPM packages in the " +"{MAJOROS} software " +"distribution. " +"xref:System_Monitoring_Tools.adoc#tabl-System_Monitoring_Tools-Net-SNMP-Packages[Available " +"Net-SNMP packages] summarizes each of the packages and their contents." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:816 +#, no-wrap +msgid "Available Net-SNMP packages" +msgstr "" + +#. type: Table +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:826 +#, no-wrap +msgid "" +"|Package|Provides\n" +"|[package]*net-snmp*|The SNMP Agent Daemon and documentation. This package " +"is required for exporting performance data.\n" +"|[package]*net-snmp-libs*|The `netsnmp` library and the bundled management " +"information bases (MIBs). This package is required for exporting performance " +"data.\n" +"|[package]*net-snmp-utils*|SNMP clients such as [command]#snmpget# and " +"[command]#snmpwalk#. This package is required in order to query a system's " +"performance data over SNMP.\n" +"|[package]*net-snmp-perl*|The [command]#mib2c# utility and the `NetSNMP` " +"Perl module.\n" +"|[package]*net-snmp-python*|An SNMP client library for Python.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:829 +msgid "" +"To install any of these packages, use the [command]#dnf# command in the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:833 +#, no-wrap +msgid "[command]#dnf# [option]`install` _package_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:836 +msgid "" +"For example, to install the SNMP Agent Daemon and SNMP clients used in the " +"rest of this section, type the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:839 +#, no-wrap +msgid "~]# dnf install net-snmp net-snmp-libs net-snmp-utils\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:842 +msgid "" +"Note that you must have superuser privileges (that is, you must be logged in " +"as `root`) to run this command. For more information on how to install new " +"packages in {MAJOROS}, refer to " +"xref:package-management/DNF.adoc#sec-Installing[Installing Packages]." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:844 +#, no-wrap +msgid "Running the Net-SNMP Daemon" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:847 +msgid "" +"The [package]*net-snmp* package contains `snmpd`, the SNMP Agent " +"Daemon. This section provides information on how to start, stop, and restart " +"the `snmpd` service, and shows how to enable or disable it in the " +"`multi-user` target unit. For more information on the concept of target " +"units and how to manage system services in {MAJOROS} in general, refer to " +"xref:infrastructure-services/Services_and_Daemons.adoc#ch-Services_and_Daemons[Services " +"and Daemons]." +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:849 +#, no-wrap +msgid "Starting the Service" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:852 +msgid "" +"To run the `snmpd` service in the current session, type the following at a " +"shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:856 +#, no-wrap +msgid "[command]#systemctl# [option]`start` [option]`snmpd.service`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:859 +msgid "" +"To configure the service to be automatically started at boot time, use the " +"following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:863 +#, no-wrap +msgid "[command]#systemctl# [option]`enable` [option]`snmpd.service`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:866 +msgid "This will enable the service in the `multi-user` target unit." +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:868 +#, no-wrap +msgid "Stopping the Service" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:871 +msgid "" +"To stop the running `snmpd` service, type the following at a shell prompt as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:875 +#, no-wrap +msgid "[command]#systemctl# [option]`stop` [option]`snmpd.service`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:878 +msgid "To disable starting the service at boot time, use the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:882 +#, no-wrap +msgid "[command]#systemctl# [option]`disable` [option]`snmpd.service`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:885 +msgid "This will disable the service in the `multi-user` target unit." +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:887 +#, no-wrap +msgid "Restarting the Service" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:890 +msgid "" +"To restart the running `snmpd` service, type the following at a shell " +"prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:894 +#, no-wrap +msgid "[command]#systemctl# [option]`restart` [option]`snmpd.service`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:897 +msgid "" +"This will stop the service and start it again in quick succession. To only " +"reload the configuration without stopping the service, run the following " +"command instead:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:901 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:923 +#, no-wrap +msgid "[command]#systemctl# [option]`reload` [option]`snmpd.service`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:904 +msgid "This will cause the running `snmpd` service to reload the configuration." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:906 +#, no-wrap +msgid "Configuring Net-SNMP" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:909 +msgid "" +"To change the Net-SNMP Agent Daemon configuration, edit the " +"`/etc/snmp/snmpd.conf` configuration file. The default `snmpd.conf` file " +"shipped with {MAJOROSVER} is heavily commented and serves as a good starting " +"point for agent configuration." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:911 +msgid "" +"This section focuses on two common tasks: setting system information and " +"configuring authentication. For more information about available " +"configuration directives, refer to the *snmpd.conf*(5) manual " +"page. Additionally, there is a utility in the [package]*net-snmp* package " +"named [command]#snmpconf# which can be used to interactively generate a " +"valid agent configuration." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:913 +msgid "" +"Note that the [package]*net-snmp-utils* package must be installed in order " +"to use the [command]#snmpwalk# utility described in this section." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:914 +#, no-wrap +msgid "Applying the changes" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:919 +msgid "" +"For any changes to the configuration file to take effect, force the `snmpd` " +"service to re-read the configuration by running the following command as " +"`root`:" +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:928 +#, no-wrap +msgid "Setting System Information" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:931 +msgid "" +"Net-SNMP provides some rudimentary system information via the `system` " +"tree. For example, the following [command]#snmpwalk# command shows the " +"`system` tree with a default agent configuration." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:940 +#, no-wrap +msgid "" +"~]# snmpwalk -v2c -c public localhost system\n" +"SNMPv2-MIB::sysDescr.0 = STRING: Linux localhost.localdomain " +"2.6.32-122.el6.x86_64 #1 SMP Wed Mar 9 23:54:34 EST 2011 x86_64\n" +"SNMPv2-MIB::sysObjectID.0 = OID: NET-SNMP-MIB::netSnmpAgentOIDs.10\n" +"DISMAN-EVENT-MIB::sysUpTimeInstance = Timeticks: (99554) 0:16:35.54\n" +"SNMPv2-MIB::sysContact.0 = STRING: Root (configure " +"/etc/snmp/snmp.local.conf)\n" +"SNMPv2-MIB::sysName.0 = STRING: localhost.localdomain\n" +"SNMPv2-MIB::sysLocation.0 = STRING: Unknown (edit /etc/snmp/snmpd.conf)\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:943 +msgid "" +"By default, the `sysName` object is set to the hostname. The `sysLocation` " +"and `sysContact` objects can be configured in the `/etc/snmp/snmpd.conf` " +"file by changing the value of the [option]`syslocation` and " +"[option]`syscontact` directives, for example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:948 +#, no-wrap +msgid "" +"syslocation Datacenter, Row 3, Rack 2\n" +"syscontact UNIX Admin <admin@example.com>\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:951 +msgid "" +"After making changes to the configuration file, reload the configuration and " +"test it by running the [command]#snmpwalk# command again:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:961 +#, no-wrap +msgid "" +"~]# systemct reload snmpd.service\n" +"~]# snmpwalk -v2c -c public localhost system\n" +"SNMPv2-MIB::sysDescr.0 = STRING: Linux localhost.localdomain " +"2.6.32-122.el6.x86_64 #1 SMP Wed Mar 9 23:54:34 EST 2011 x86_64\n" +"SNMPv2-MIB::sysObjectID.0 = OID: NET-SNMP-MIB::netSnmpAgentOIDs.10\n" +"DISMAN-EVENT-MIB::sysUpTimeInstance = Timeticks: (158357) 0:26:23.57\n" +"SNMPv2-MIB::sysContact.0 = STRING: UNIX Admin \n" +"SNMPv2-MIB::sysName.0 = STRING: localhost.localdomain\n" +"SNMPv2-MIB::sysLocation.0 = STRING: Datacenter, Row 3, Rack 2\n" +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:964 +#, no-wrap +msgid "Configuring Authentication" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:967 +msgid "" +"The Net-SNMP Agent Daemon supports all three versions of the SNMP " +"protocol. The first two versions (1 and 2c) provide for simple " +"authentication using a _community string_. This string is a shared secret " +"between the agent and any client utilities. The string is passed in clear " +"text over the network however and is not considered secure. Version 3 of the " +"SNMP protocol supports user authentication and message encryption using a " +"variety of protocols. The Net-SNMP agent also supports tunneling over SSH, " +"TLS authentication with X.509 certificates, and Kerberos authentication." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:968 +#, no-wrap +msgid "Configuring SNMP Version 2c Community" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:970 +msgid "" +"To configure an *SNMP version 2c community*, use either the " +"[option]`rocommunity` or [option]`rwcommunity` directive in the " +"`/etc/snmp/snmpd.conf` configuration file. The format of the directives is " +"the following:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:974 +#, no-wrap +msgid "_directive_ _community_ _source_ _OID_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:977 +msgid "" +"… where _community_ is the community string to use, _source_ is an IP " +"address or subnet, and _OID_ is the SNMP tree to provide access to. For " +"example, the following directive provides read-only access to the `system` " +"tree to a client using the community string \"`redhat`\" on the local " +"machine:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:981 +#, no-wrap +msgid "rocommunity redhat 127.0.0.1 .1.3.6.1.2.1.1\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:984 +msgid "" +"To test the configuration, use the [command]#snmpwalk# command with the " +"[option]`-v` and [option]`-c` options." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:993 +#, no-wrap +msgid "" +"~]# snmpwalk -v2c -c redhat localhost system\n" +"SNMPv2-MIB::sysDescr.0 = STRING: Linux localhost.localdomain " +"2.6.32-122.el6.x86_64 #1 SMP Wed Mar 9 23:54:34 EST 2011 x86_64\n" +"SNMPv2-MIB::sysObjectID.0 = OID: NET-SNMP-MIB::netSnmpAgentOIDs.10\n" +"DISMAN-EVENT-MIB::sysUpTimeInstance = Timeticks: (158357) 0:26:23.57\n" +"SNMPv2-MIB::sysContact.0 = STRING: UNIX Admin \n" +"SNMPv2-MIB::sysName.0 = STRING: localhost.localdomain\n" +"SNMPv2-MIB::sysLocation.0 = STRING: Datacenter, Row 3, Rack 2\n" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:995 +#, no-wrap +msgid "Configuring SNMP Version 3 User" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:997 +msgid "" +"To configure an *SNMP version 3 user*, use the " +"[command]#net-snmp-create-v3-user# command. This command adds entries to the " +"`/var/lib/net-snmp/snmpd.conf` and `/etc/snmp/snmpd.conf` files which create " +"the user and grant access to the user. Note that the " +"[command]#net-snmp-create-v3-user# command may only be run when the agent is " +"not running. The following example creates the \"`sysadmin`\" user with the " +"password \"`redhatsnmp`\":" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1007 +#, no-wrap +msgid "" +"~]# systemctl stop snmpd.service\n" +"~]# net-snmp-create-v3-user\n" +"Enter a SNMPv3 user name to create:\n" +"admin\n" +"Enter authentication pass-phrase:\n" +"redhatsnmp\n" +"Enter encryption pass-phrase:\n" +" [press return to reuse the authentication pass-phrase]\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1013 +#, no-wrap +msgid "" +"adding the following line to /var/lib/net-snmp/snmpd.conf:\n" +" createUser admin MD5 \"redhatsnmp\" DES\n" +"adding the following line to /etc/snmp/snmpd.conf:\n" +" rwuser admin\n" +"~]# systemctl start snmpd.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1016 +msgid "" +"The [option]`rwuser` directive (or [option]`rouser` when the [option]`-ro` " +"command line option is supplied) that [command]#net-snmp-create-v3-user# " +"adds to `/etc/snmp/snmpd.conf` has a similar format to the " +"[option]`rwcommunity` and [option]`rocommunity` directives:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1020 +#, no-wrap +msgid "_directive_ _user_ [option]`noauth`|[option]`auth`|[option]`priv` _OID_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1023 +msgid "" +"… where _user_ is a username and _OID_ is the SNMP tree to provide access " +"to. By default, the Net-SNMP Agent Daemon allows only authenticated requests " +"(the [option]`auth` option). The [option]`noauth` option allows you to " +"permit unauthenticated requests, and the [option]`priv` option enforces the " +"use of encryption. The [option]`authpriv` option specifies that requests " +"must be authenticated and replies should be encrypted." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1025 +msgid "" +"For example, the following line grants the user \"`admin`\" read-write " +"access to the entire tree:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1029 +#, no-wrap +msgid "rwuser admin authpriv .1\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1032 +msgid "" +"To test the configuration, create a `.snmp` directory in your user's home " +"directory and a configuration file named `snmp.conf` in that directory " +"(`~/.snmp/snmp.conf`) with the following lines:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1039 +#, no-wrap +msgid "" +"defVersion 3\n" +"defSecurityLevel authPriv\n" +"defSecurityName admin\n" +"defPassphrase redhatsnmp\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1042 +msgid "" +"The [command]#snmpwalk# command will now use these authentication settings " +"when querying the agent:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1047 +#, no-wrap +msgid "" +"~]$ snmpwalk -v3 localhost system\n" +"SNMPv2-MIB::sysDescr.0 = STRING: Linux localhost.localdomain " +"2.6.32-122.el6.x86_64 #1 SMP Wed Mar 9 23:54:34 EST 2011 x86_64\n" +"[output truncated]\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1050 +#, no-wrap +msgid "Retrieving Performance Data over SNMP" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1053 +msgid "" +"The Net-SNMP Agent in {MAJOROS} provides a wide variety of performance " +"information over the SNMP protocol. In addition, the agent can be queried " +"for a listing of the installed RPM packages on the system, a listing of " +"currently running processes on the system, or the network configuration of " +"the system." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1055 +msgid "" +"This section provides an overview of OIDs related to performance tuning " +"available over SNMP. It assumes that the [package]*net-snmp-utils* package " +"is installed and that the user is granted access to the SNMP tree as " +"described in " +"xref:System_Monitoring_Tools.adoc#sect-System_Monitoring_Tools-Net-SNMP-Configuring-Authentication[Configuring " +"Authentication]." +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1057 +#, no-wrap +msgid "Hardware Configuration" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1060 +msgid "" +"The `Host Resources MIB` included with Net-SNMP presents information about " +"the current hardware and software configuration of a host to a client " +"utility. " +"xref:System_Monitoring_Tools.adoc#tabl-System_Monitoring_Tools-Net-SNMP-OIDs[Available " +"OIDs] summarizes the different OIDs available under that MIB." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1062 +#, no-wrap +msgid "Available OIDs" +msgstr "" + +#. type: Table +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1073 +#, no-wrap +msgid "" +"|OID|Description\n" +"|`HOST-RESOURCES-MIB::hrSystem`|Contains general system information such as " +"uptime, number of users, and number of running processes.\n" +"|`HOST-RESOURCES-MIB::hrStorage`|Contains data on memory and file system " +"usage.\n" +"|`HOST-RESOURCES-MIB::hrDevices`|Contains a listing of all processors, " +"network devices, and file systems.\n" +"|`HOST-RESOURCES-MIB::hrSWRun`|Contains a listing of all running " +"processes.\n" +"|`HOST-RESOURCES-MIB::hrSWRunPerf`|Contains memory and CPU statistics on the " +"process table from HOST-RESOURCES-MIB::hrSWRun.\n" +"|`HOST-RESOURCES-MIB::hrSWInstalled`|Contains a listing of the RPM " +"database.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1076 +msgid "" +"There are also a number of SNMP tables available in the Host Resources MIB " +"which can be used to retrieve a summary of the available information. The " +"following example displays `HOST-RESOURCES-MIB::hrFSTable`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1081 +#, no-wrap +msgid "" +"~]$ [command]#snmptable -Cb localhost HOST-RESOURCES-MIB::hrFSTable#\n" +"SNMP table: HOST-RESOURCES-MIB::hrFSTable\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1090 +#, no-wrap +msgid "" +" Index MountPoint RemoteMountPoint Type\n" +" Access Bootable StorageIndex LastFullBackupDate LastPartialBackupDate\n" +" 1 \"/\" \"\" HOST-RESOURCES-TYPES::hrFSLinuxExt2\n" +" readWrite true 31 0-1-1,0:0:0.0 0-1-1,0:0:0.0\n" +" 5 \"/dev/shm\" \"\" HOST-RESOURCES-TYPES::hrFSOther\n" +" readWrite false 35 0-1-1,0:0:0.0 0-1-1,0:0:0.0\n" +" 6 \"/boot\" \"\" HOST-RESOURCES-TYPES::hrFSLinuxExt2\n" +" readWrite false 36 0-1-1,0:0:0.0 0-1-1,0:0:0.0\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1093 +msgid "" +"For more information about `HOST-RESOURCES-MIB`, see the " +"`/usr/share/snmp/mibs/HOST-RESOURCES-MIB.txt` file." +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1095 +#, no-wrap +msgid "CPU and Memory Information" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1098 +msgid "" +"Most system performance data is available in the `UCD SNMP MIB`. The " +"`systemStats` OID provides a number of counters around processor usage:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1127 +#, no-wrap +msgid "" +"~]$ [command]#snmpwalk localhost UCD-SNMP-MIB::systemStats#\n" +"UCD-SNMP-MIB::ssIndex.0 = INTEGER: 1\n" +"UCD-SNMP-MIB::ssErrorName.0 = STRING: systemStats\n" +"UCD-SNMP-MIB::ssSwapIn.0 = INTEGER: 0 kB\n" +"UCD-SNMP-MIB::ssSwapOut.0 = INTEGER: 0 kB\n" +"UCD-SNMP-MIB::ssIOSent.0 = INTEGER: 0 blocks/s\n" +"UCD-SNMP-MIB::ssIOReceive.0 = INTEGER: 0 blocks/s\n" +"UCD-SNMP-MIB::ssSysInterrupts.0 = INTEGER: 29 interrupts/s\n" +"UCD-SNMP-MIB::ssSysContext.0 = INTEGER: 18 switches/s\n" +"UCD-SNMP-MIB::ssCpuUser.0 = INTEGER: 0\n" +"UCD-SNMP-MIB::ssCpuSystem.0 = INTEGER: 0\n" +"UCD-SNMP-MIB::ssCpuIdle.0 = INTEGER: 99\n" +"UCD-SNMP-MIB::ssCpuRawUser.0 = Counter32: 2278\n" +"UCD-SNMP-MIB::ssCpuRawNice.0 = Counter32: 1395\n" +"UCD-SNMP-MIB::ssCpuRawSystem.0 = Counter32: 6826\n" +"UCD-SNMP-MIB::ssCpuRawIdle.0 = Counter32: 3383736\n" +"UCD-SNMP-MIB::ssCpuRawWait.0 = Counter32: 7629\n" +"UCD-SNMP-MIB::ssCpuRawKernel.0 = Counter32: 0\n" +"UCD-SNMP-MIB::ssCpuRawInterrupt.0 = Counter32: 434\n" +"UCD-SNMP-MIB::ssIORawSent.0 = Counter32: 266770\n" +"UCD-SNMP-MIB::ssIORawReceived.0 = Counter32: 427302\n" +"UCD-SNMP-MIB::ssRawInterrupts.0 = Counter32: 743442\n" +"UCD-SNMP-MIB::ssRawContexts.0 = Counter32: 718557\n" +"UCD-SNMP-MIB::ssCpuRawSoftIRQ.0 = Counter32: 128\n" +"UCD-SNMP-MIB::ssRawSwapIn.0 = Counter32: 0\n" +"UCD-SNMP-MIB::ssRawSwapOut.0 = Counter32: 0\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1130 +msgid "" +"In particular, the `ssCpuRawUser`, `ssCpuRawSystem`, `ssCpuRawWait`, and " +"`ssCpuRawIdle` OIDs provide counters which are helpful when determining " +"whether a system is spending most of its processor time in kernel space, " +"user space, or I/O. `ssRawSwapIn` and `ssRawSwapOut` can be helpful when " +"determining whether a system is suffering from memory exhaustion." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1132 +msgid "" +"More memory information is available under the `UCD-SNMP-MIB::memory` OID, " +"which provides similar data to the [command]#free# command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1148 +#, no-wrap +msgid "" +"~]$ [command]#snmpwalk localhost UCD-SNMP-MIB::memory#\n" +"UCD-SNMP-MIB::memIndex.0 = INTEGER: 0\n" +"UCD-SNMP-MIB::memErrorName.0 = STRING: swap\n" +"UCD-SNMP-MIB::memTotalSwap.0 = INTEGER: 1023992 kB\n" +"UCD-SNMP-MIB::memAvailSwap.0 = INTEGER: 1023992 kB\n" +"UCD-SNMP-MIB::memTotalReal.0 = INTEGER: 1021588 kB\n" +"UCD-SNMP-MIB::memAvailReal.0 = INTEGER: 634260 kB\n" +"UCD-SNMP-MIB::memTotalFree.0 = INTEGER: 1658252 kB\n" +"UCD-SNMP-MIB::memMinimumSwap.0 = INTEGER: 16000 kB\n" +"UCD-SNMP-MIB::memBuffer.0 = INTEGER: 30760 kB\n" +"UCD-SNMP-MIB::memCached.0 = INTEGER: 216200 kB\n" +"UCD-SNMP-MIB::memSwapError.0 = INTEGER: noError(0)\n" +"UCD-SNMP-MIB::memSwapErrorMsg.0 = STRING:\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1151 +msgid "" +"Load averages are also available in the `UCD SNMP MIB`. The SNMP table " +"`UCD-SNMP-MIB::laTable` has a listing of the 1, 5, and 15 minute load " +"averages:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1156 +#, no-wrap +msgid "" +"~]$ [command]#snmptable localhost UCD-SNMP-MIB::laTable#\n" +"SNMP table: UCD-SNMP-MIB::laTable\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1161 +#, no-wrap +msgid "" +" laIndex laNames laLoad laConfig laLoadInt laLoadFloat laErrorFlag " +"laErrMessage\n" +" 1 Load-1 0.00 12.00 0 0.000000 noError\n" +" 2 Load-5 0.00 12.00 0 0.000000 noError\n" +" 3 Load-15 0.00 12.00 0 0.000000 noError\n" +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1164 +#, no-wrap +msgid "File System and Disk Information" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1167 +msgid "" +"The `Host Resources MIB` provides information on file system size and " +"usage. Each file system (and also each memory pool) has an entry in the " +"`HOST-RESOURCES-MIB::hrStorageTable` table:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1172 +#, no-wrap +msgid "" +"~]$ [command]#snmptable -Cb localhost HOST-RESOURCES-MIB::hrStorageTable#\n" +"SNMP table: HOST-RESOURCES-MIB::hrStorageTable\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1191 +#, no-wrap +msgid "" +" Index Type Descr\n" +"AllocationUnits Size Used AllocationFailures\n" +" 1 HOST-RESOURCES-TYPES::hrStorageRam Physical memory\n" +"1024 Bytes 1021588 388064 ?\n" +" 3 HOST-RESOURCES-TYPES::hrStorageVirtualMemory Virtual memory\n" +"1024 Bytes 2045580 388064 ?\n" +" 6 HOST-RESOURCES-TYPES::hrStorageOther Memory buffers\n" +"1024 Bytes 1021588 31048 ?\n" +" 7 HOST-RESOURCES-TYPES::hrStorageOther Cached memory\n" +"1024 Bytes 216604 216604 ?\n" +" 10 HOST-RESOURCES-TYPES::hrStorageVirtualMemory Swap space\n" +"1024 Bytes 1023992 0 ?\n" +" 31 HOST-RESOURCES-TYPES::hrStorageFixedDisk /\n" +"4096 Bytes 2277614 250391 ?\n" +" 35 HOST-RESOURCES-TYPES::hrStorageFixedDisk /dev/shm\n" +"4096 Bytes 127698 0 ?\n" +" 36 HOST-RESOURCES-TYPES::hrStorageFixedDisk /boot\n" +"1024 Bytes 198337 26694 ?\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1194 +msgid "" +"The OIDs under `HOST-RESOURCES-MIB::hrStorageSize` and " +"`HOST-RESOURCES-MIB::hrStorageUsed` can be used to calculate the remaining " +"capacity of each mounted file system." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1196 +msgid "" +"I/O data is available both in `UCD-SNMP-MIB::systemStats` (`ssIORawSent.0` " +"and `ssIORawRecieved.0`) and in `UCD-DISKIO-MIB::diskIOTable`. The latter " +"provides much more granular data. Under this table are OIDs for " +"`diskIONReadX` and `diskIONWrittenX`, which provide counters for the number " +"of bytes read from and written to the block device in question since the " +"system boot:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1201 +#, no-wrap +msgid "" +"~]$ [command]#snmptable -Cb localhost UCD-DISKIO-MIB::diskIOTable#\n" +"SNMP table: UCD-DISKIO-MIB::diskIOTable\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1208 +#, no-wrap +msgid "" +" Index Device NRead NWritten Reads Writes LA1 LA5 LA15 NReadX " +"NWrittenX\n" +"...\n" +" 25 sda 216886272 139109376 16409 4894 ? ? ? 216886272 " +"139109376\n" +" 26 sda1 2455552 5120 613 2 ? ? ? 2455552 " +"5120\n" +" 27 sda2 1486848 0 332 0 ? ? ? 1486848 " +"0\n" +" 28 sda3 212321280 139104256 15312 4871 ? ? ? 212321280 " +"139104256\n" +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1211 +#, no-wrap +msgid "Network Information" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1214 +msgid "" +"Information on network devices is provided by the Interfaces " +"MIB. `IF-MIB::ifTable` provides an SNMP table with an entry for each " +"interface on the system, the configuration of the interface, and various " +"packet counters for the interface. The following example shows the first few " +"columns of `ifTable` on a system with two physical network interfaces:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1219 +#, no-wrap +msgid "" +"~]$ [command]#snmptable -Cb localhost IF-MIB::ifTable#\n" +"SNMP table: IF-MIB::ifTable\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1224 +#, no-wrap +msgid "" +" Index Descr Type Mtu Speed PhysAddress AdminStatus\n" +" 1 lo softwareLoopback 16436 10000000 up\n" +" 2 eth0 ethernetCsmacd 1500 0 52:54:0:c7:69:58 up\n" +" 3 eth1 ethernetCsmacd 1500 0 52:54:0:a7:a3:24 down\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1227 +msgid "" +"Network traffic is available under the OIDs `IF-MIB::ifOutOctets` and " +"`IF-MIB::ifInOctets`. The following SNMP queries will retrieve network " +"traffic for each of the interfaces on this system:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1242 +#, no-wrap +msgid "" +"~]$ [command]#snmpwalk localhost IF-MIB::ifDescr#\n" +"IF-MIB::ifDescr.1 = STRING: lo\n" +"IF-MIB::ifDescr.2 = STRING: eth0\n" +"IF-MIB::ifDescr.3 = STRING: eth1\n" +"~]$ [command]#snmpwalk localhost IF-MIB::ifOutOctets#\n" +"IF-MIB::ifOutOctets.1 = Counter32: 10060699\n" +"IF-MIB::ifOutOctets.2 = Counter32: 650\n" +"IF-MIB::ifOutOctets.3 = Counter32: 0\n" +"~]$ [command]#snmpwalk localhost IF-MIB::ifInOctets#\n" +"IF-MIB::ifInOctets.1 = Counter32: 10060699\n" +"IF-MIB::ifInOctets.2 = Counter32: 78650\n" +"IF-MIB::ifInOctets.3 = Counter32: 0\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1245 +#, no-wrap +msgid "Extending Net-SNMP" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1248 +msgid "" +"The Net-SNMP Agent can be extended to provide application metrics in " +"addition to raw system metrics. This allows for capacity planning as well as " +"performance issue troubleshooting. For example, it may be helpful to know " +"that an email system had a 5-minute load average of 15 while being tested, " +"but it is more helpful to know that the email system has a load average of " +"15 while processing 80,000 messages a second. When application metrics are " +"available via the same interface as the system metrics, this also allows for " +"the visualization of the impact of different load scenarios on system " +"performance (for example, each additional 10,000 messages increases the load " +"average linearly until 100,000)." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1250 +msgid "" +"A number of the applications that ship with {MAJOROS} extend the Net-SNMP " +"Agent to provide application metrics over SNMP. There are several ways to " +"extend the agent for custom applications as well. This section describes " +"extending the agent with shell scripts and Perl plug-ins. It assumes that " +"the [package]*net-snmp-utils* and [package]*net-snmp-perl* packages are " +"installed, and that the user is granted access to the SNMP tree as described " +"in " +"xref:System_Monitoring_Tools.adoc#sect-System_Monitoring_Tools-Net-SNMP-Configuring-Authentication[Configuring " +"Authentication]." +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1252 +#, no-wrap +msgid "Extending Net-SNMP with Shell Scripts" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1255 +msgid "" +"The Net-SNMP Agent provides an extension MIB (`NET-SNMP-EXTEND-MIB`) that " +"can be used to query arbitrary shell scripts. To specify the shell script to " +"run, use the [option]`extend` directive in the `/etc/snmp/snmpd.conf` " +"file. Once defined, the Agent will provide the exit code and any output of " +"the command over SNMP. The example below demonstrates this mechanism with a " +"script which determines the number of `httpd` processes in the process " +"table." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1256 +#, no-wrap +msgid "Using the proc directive" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1261 +msgid "" +"The Net-SNMP Agent also provides a built-in mechanism for checking the " +"process table via the [option]`proc` directive. See the *snmpd.conf*(5) " +"manual page for more information." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1265 +msgid "" +"The exit code of the following shell script is the number of " +"[command]#httpd# processes running on the system at a given point in time:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1268 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1311 +#, no-wrap +msgid "#!/bin/sh\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1270 +#, no-wrap +msgid "NUMPIDS=`pgrep httpd | wc -l`\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1272 +#, no-wrap +msgid "exit $NUMPIDS\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1275 +msgid "" +"To make this script available over SNMP, copy the script to a location on " +"the system path, set the executable bit, and add an [option]`extend` " +"directive to the `/etc/snmp/snmpd.conf` file. The format of the " +"[option]`extend` directive is the following:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1279 +#, no-wrap +msgid "[option]`extend` _name_ _prog_ _args_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1282 +msgid "" +"… where _name_ is an identifying string for the extension, _prog_ is the " +"program to run, and _args_ are the arguments to give the program. For " +"instance, if the above shell script is copied to " +"`/usr/local/bin/check_apache.sh`, the following directive will add the " +"script to the SNMP tree:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1285 +#, no-wrap +msgid "extend httpd_pids /bin/sh /usr/local/bin/check_apache.sh\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1288 +msgid "The script can then be queried at `NET-SNMP-EXTEND-MIB::nsExtendObjects`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1305 +#, no-wrap +msgid "" +"~]$ snmpwalk localhost NET-SNMP-EXTEND-MIB::nsExtendObjects\n" +"NET-SNMP-EXTEND-MIB::nsExtendNumEntries.0 = INTEGER: 1\n" +"NET-SNMP-EXTEND-MIB::nsExtendCommand.\"httpd_pids\" = STRING: /bin/sh\n" +"NET-SNMP-EXTEND-MIB::nsExtendArgs.\"httpd_pids\" = STRING: " +"/usr/local/bin/check_apache.sh\n" +"NET-SNMP-EXTEND-MIB::nsExtendInput.\"httpd_pids\" = STRING:\n" +"NET-SNMP-EXTEND-MIB::nsExtendCacheTime.\"httpd_pids\" = INTEGER: 5\n" +"NET-SNMP-EXTEND-MIB::nsExtendExecType.\"httpd_pids\" = INTEGER: exec(1)\n" +"NET-SNMP-EXTEND-MIB::nsExtendRunType.\"httpd_pids\" = INTEGER: " +"run-on-read(1)\n" +"NET-SNMP-EXTEND-MIB::nsExtendStorage.\"httpd_pids\" = INTEGER: " +"permanent(4)\n" +"NET-SNMP-EXTEND-MIB::nsExtendStatus.\"httpd_pids\" = INTEGER: active(1)\n" +"NET-SNMP-EXTEND-MIB::nsExtendOutput1Line.\"httpd_pids\" = STRING:\n" +"NET-SNMP-EXTEND-MIB::nsExtendOutputFull.\"httpd_pids\" = STRING:\n" +"NET-SNMP-EXTEND-MIB::nsExtendOutNumLines.\"httpd_pids\" = INTEGER: 1\n" +"NET-SNMP-EXTEND-MIB::nsExtendResult.\"httpd_pids\" = INTEGER: 8\n" +"NET-SNMP-EXTEND-MIB::nsExtendOutLine.\"httpd_pids\".1 = STRING:\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1308 +msgid "" +"Note that the exit code (\"`8`\" in this example) is provided as an INTEGER " +"type and any output is provided as a STRING type. To expose multiple metrics " +"as integers, supply different arguments to the script using the " +"[option]`extend` directive. For example, the following shell script can be " +"used to determine the number of processes matching an arbitrary string, and " +"will also output a text string giving the number of processes:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1314 +#, no-wrap +msgid "" +"PATTERN=$1\n" +"NUMPIDS=`pgrep $PATTERN | wc -l`\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1317 +#, no-wrap +msgid "" +"echo \"There are $NUMPIDS $PATTERN processes.\"\n" +"exit $NUMPIDS\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1320 +msgid "" +"The following `/etc/snmp/snmpd.conf` directives will give both the number of " +"`httpd` PIDs as well as the number of `snmpd` PIDs when the above script is " +"copied to `/usr/local/bin/check_proc.sh`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1324 +#, no-wrap +msgid "" +"extend httpd_pids /bin/sh /usr/local/bin/check_proc.sh httpd\n" +"extend snmpd_pids /bin/sh /usr/local/bin/check_proc.sh snmpd\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1327 +msgid "" +"The following example shows the output of an [command]#snmpwalk# of the " +"`nsExtendObjects` OID:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1342 +#, no-wrap +msgid "" +"~]$ snmpwalk localhost NET-SNMP-EXTEND-MIB::nsExtendObjects\n" +"NET-SNMP-EXTEND-MIB::nsExtendNumEntries.0 = INTEGER: 2\n" +"NET-SNMP-EXTEND-MIB::nsExtendCommand.\"httpd_pids\" = STRING: /bin/sh\n" +"NET-SNMP-EXTEND-MIB::nsExtendCommand.\"snmpd_pids\" = STRING: /bin/sh\n" +"NET-SNMP-EXTEND-MIB::nsExtendArgs.\"httpd_pids\" = STRING: " +"/usr/local/bin/check_proc.sh httpd\n" +"NET-SNMP-EXTEND-MIB::nsExtendArgs.\"snmpd_pids\" = STRING: " +"/usr/local/bin/check_proc.sh snmpd\n" +"NET-SNMP-EXTEND-MIB::nsExtendInput.\"httpd_pids\" = STRING:\n" +"NET-SNMP-EXTEND-MIB::nsExtendInput.\"snmpd_pids\" = STRING:\n" +"...\n" +"NET-SNMP-EXTEND-MIB::nsExtendResult.\"httpd_pids\" = INTEGER: 8\n" +"NET-SNMP-EXTEND-MIB::nsExtendResult.\"snmpd_pids\" = INTEGER: 1\n" +"NET-SNMP-EXTEND-MIB::nsExtendOutLine.\"httpd_pids\".1 = STRING: There are 8 " +"httpd processes.\n" +"NET-SNMP-EXTEND-MIB::nsExtendOutLine.\"snmpd_pids\".1 = STRING: There are 1 " +"snmpd processes.\n" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1344 +#, no-wrap +msgid "Integer exit codes are limited" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1349 +msgid "" +"Integer exit codes are limited to a range of 0–255. For values that are " +"likely to exceed 256, either use the standard output of the script (which " +"will be typed as a string) or a different method of extending the agent." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1353 +msgid "" +"This last example shows a query for the free memory of the system and the " +"number of `httpd` processes. This query could be used during a performance " +"test to determine the impact of the number of processes on memory pressure:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1360 +#, no-wrap +msgid "" +"~]$ snmpget localhost \\\n" +" 'NET-SNMP-EXTEND-MIB::nsExtendResult.\"httpd_pids\"' \\\n" +" UCD-SNMP-MIB::memAvailReal.0\n" +"NET-SNMP-EXTEND-MIB::nsExtendResult.\"httpd_pids\" = INTEGER: 8\n" +"UCD-SNMP-MIB::memAvailReal.0 = INTEGER: 799664 kB\n" +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1363 +#, no-wrap +msgid "Extending Net-SNMP with Perl" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1366 +msgid "" +"Executing shell scripts using the [option]`extend` directive is a fairly " +"limited method for exposing custom application metrics over SNMP. The " +"Net-SNMP Agent also provides an embedded Perl interface for exposing custom " +"objects. The [package]*net-snmp-perl* package provides the `NetSNMP::agent` " +"Perl module that is used to write embedded Perl plug-ins on {MAJOROS}." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1368 +msgid "" +"The `NetSNMP::agent` Perl module provides an `agent` object which is used to " +"handle requests for a part of the agent's OID tree. The `agent` object's " +"constructor has options for running the agent as a sub-agent of `snmpd` or a " +"standalone agent. No arguments are necessary to create an embedded agent:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1372 +#, no-wrap +msgid "use NetSNMP::agent (':all');\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1374 +#, no-wrap +msgid "my $agent = new NetSNMP::agent();\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1377 +msgid "" +"The `agent` object has a `register` method which is used to register a " +"callback function with a particular OID. The `register` function takes a " +"name, OID, and pointer to the callback function. The following example will " +"register a callback function named `hello_handler` with the SNMP Agent which " +"will handle requests under the OID `.1.3.6.1.4.1.8072.9999.9999`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1381 +#, no-wrap +msgid "" +"$agent->register(\"hello_world\", \".1.3.6.1.4.1.8072.9999.9999\",\n" +" \\&hello_handler);\n" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1383 +#, no-wrap +msgid "Obtaining a root OID" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1388 +msgid "" +"The OID `.1.3.6.1.4.1.8072.9999.9999` (`NET-SNMP-MIB::netSnmpPlaypen`) is " +"typically used for demonstration purposes only. If your organization does " +"not already have a root OID, you can obtain one by contacting your Name " +"Registration Authority (ANSI in the United States)." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1392 +msgid "" +"The handler function will be called with four parameters, `HANDLER`, " +"`REGISTRATION_INFO`, `REQUEST_INFO`, and `REQUESTS`. The `REQUESTS` " +"parameter contains a list of requests in the current call and should be " +"iterated over and populated with data. The `request` objects in the list " +"have get and set methods which allow for manipulating the `OID` and `value` " +"of the request. For example, the following call will set the value of a " +"request object to the string \"`hello world`\":" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1395 +#, no-wrap +msgid "$request->setValue(ASN_OCTET_STR, \"hello world\");\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1398 +msgid "" +"The handler function should respond to two types of SNMP requests: the GET " +"request and the GETNEXT request. The type of request is determined by " +"calling the `getMode` method on the `request_info` object passed as the " +"third parameter to the handler function. If the request is a GET request, " +"the caller will expect the handler to set the `value` of the `request` " +"object, depending on the OID of the request. If the request is a GETNEXT " +"request, the caller will also expect the handler to set the OID of the " +"request to the next available OID in the tree. This is illustrated in the " +"following code example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1403 +#, no-wrap +msgid "" +"my $request;\n" +"my $string_value = \"hello world\";\n" +"my $integer_value = \"8675309\";\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1424 +#, no-wrap +msgid "" +"for($request = $requests; $request; $request = $request->next()) {\n" +" my $oid = $request->getOID();\n" +" if ($request_info->getMode() == MODE_GET) {\n" +" if ($oid == new NetSNMP::OID(\".1.3.6.1.4.1.8072.9999.9999.1.0\")) {\n" +" $request->setValue(ASN_OCTET_STR, $string_value);\n" +" }\n" +" elsif ($oid == new NetSNMP::OID(\".1.3.6.1.4.1.8072.9999.9999.1.1\")) " +"{\n" +" $request->setValue(ASN_INTEGER, $integer_value);\n" +" }\n" +" } elsif ($request_info->getMode() == MODE_GETNEXT) {\n" +" if ($oid == new NetSNMP::OID(\".1.3.6.1.4.1.8072.9999.9999.1.0\")) {\n" +" $request->setOID(\".1.3.6.1.4.1.8072.9999.9999.1.1\");\n" +" $request->setValue(ASN_INTEGER, $integer_value);\n" +" }\n" +" elsif ($oid < new NetSNMP::OID(\".1.3.6.1.4.1.8072.9999.9999.1.0\")) {\n" +" $request->setOID(\".1.3.6.1.4.1.8072.9999.9999.1.0\");\n" +" $request->setValue(ASN_OCTET_STR, $string_value);\n" +" }\n" +" }\n" +"}\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1427 +msgid "" +"When `getMode` returns `MODE_GET`, the handler analyzes the value of the " +"`getOID` call on the `request` object. The `value` of the `request` is set " +"to either `string_value` if the OID ends in \"`.1.0`\", or set to " +"`integer_value` if the OID ends in \"`.1.1`\". If the `getMode` returns " +"`MODE_GETNEXT`, the handler determines whether the OID of the request is " +"\"`.1.0`\", and then sets the OID and value for \"`.1.1`\". If the request " +"is higher on the tree than \"`.1.0`\", the OID and value for \"`.1.0`\" is " +"set. This in effect returns the \"`next`\" value in the tree so that a " +"program like [command]#snmpwalk# can traverse the tree without prior " +"knowledge of the structure." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1429 +msgid "" +"The type of the variable is set using constants from `NetSNMP::ASN`. See the " +"[command]#perldoc# for `NetSNMP::ASN` for a full list of available " +"constants." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1431 +msgid "The entire code listing for this example Perl plug-in is as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1434 +#, no-wrap +msgid "#!/usr/bin/perl\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1437 +#, no-wrap +msgid "" +"use NetSNMP::agent (':all');\n" +"use NetSNMP::ASN qw(ASN_OCTET_STR ASN_INTEGER);\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1443 +#, no-wrap +msgid "" +"sub hello_handler {\n" +" my ($handler, $registration_info, $request_info, $requests) = @_;\n" +" my $request;\n" +" my $string_value = \"hello world\";\n" +" my $integer_value = \"8675309\";\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1465 +#, no-wrap +msgid "" +" for($request = $requests; $request; $request = $request->next()) {\n" +" my $oid = $request->getOID();\n" +" if ($request_info->getMode() == MODE_GET) {\n" +" if ($oid == new NetSNMP::OID(\".1.3.6.1.4.1.8072.9999.9999.1.0\")) {\n" +" $request->setValue(ASN_OCTET_STR, $string_value);\n" +" }\n" +" elsif ($oid == new NetSNMP::OID(\".1.3.6.1.4.1.8072.9999.9999.1.1\")) " +"{\n" +" $request->setValue(ASN_INTEGER, $integer_value);\n" +" }\n" +" } elsif ($request_info->getMode() == MODE_GETNEXT) {\n" +" if ($oid == new NetSNMP::OID(\".1.3.6.1.4.1.8072.9999.9999.1.0\")) {\n" +" $request->setOID(\".1.3.6.1.4.1.8072.9999.9999.1.1\");\n" +" $request->setValue(ASN_INTEGER, $integer_value);\n" +" }\n" +" elsif ($oid < new NetSNMP::OID(\".1.3.6.1.4.1.8072.9999.9999.1.0\")) " +"{\n" +" $request->setOID(\".1.3.6.1.4.1.8072.9999.9999.1.0\");\n" +" $request->setValue(ASN_OCTET_STR, $string_value);\n" +" }\n" +" }\n" +" }\n" +"}\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1469 +#, no-wrap +msgid "" +"my $agent = new NetSNMP::agent();\n" +"$agent->register(\"hello_world\", \".1.3.6.1.4.1.8072.9999.9999\",\n" +" \\&hello_handler);\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1472 +msgid "" +"To test the plug-in, copy the above program to " +"`/usr/share/snmp/hello_world.pl` and add the following line to the " +"`/etc/snmp/snmpd.conf` configuration file:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1475 +#, no-wrap +msgid "perl do \"/usr/share/snmp/hello_world.pl\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1478 +msgid "" +"The SNMP Agent Daemon will need to be restarted to load the new Perl " +"plug-in. Once it has been restarted, an [command]#snmpwalk# should return " +"the new data:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1484 +#, no-wrap +msgid "" +"~]$ [command]#snmpwalk localhost NET-SNMP-MIB::netSnmpPlaypen#\n" +"NET-SNMP-MIB::netSnmpPlaypen.1.0 = STRING: \"hello world\"\n" +"NET-SNMP-MIB::netSnmpPlaypen.1.1 = INTEGER: 8675309\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1487 +msgid "" +"The [command]#snmpget# should also be used to exercise the other mode of the " +"handler:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1495 +#, no-wrap +msgid "" +"~]$ [command]#snmpget localhost \\#\n" +" [command]#NET-SNMP-MIB::netSnmpPlaypen.1.0 \\#\n" +" [command]#NET-SNMP-MIB::netSnmpPlaypen.1.1#\n" +"NET-SNMP-MIB::netSnmpPlaypen.1.0 = STRING: \"hello world\"\n" +"NET-SNMP-MIB::netSnmpPlaypen.1.1 = INTEGER: 8675309\n" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1498 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1501 +msgid "" +"To learn more about gathering system information, refer to the following " +"resources." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1503 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1506 +#, no-wrap +msgid "*ps*(1) — The manual page for the [command]#ps# command.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1508 +#, no-wrap +msgid "*top*(1) — The manual page for the [command]#top# command.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1510 +#, no-wrap +msgid "*free*(1) — The manual page for the [command]#free# command.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1512 +#, no-wrap +msgid "*df*(1) — The manual page for the [command]#df# command.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1514 +#, no-wrap +msgid "*du*(1) — The manual page for the [command]#du# command.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1516 +#, no-wrap +msgid "*lspci*(8) — The manual page for the [command]#lspci# command.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1518 +#, no-wrap +msgid "*snmpd*(8) — The manual page for the `snmpd` service.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1519 +#, no-wrap +msgid "" +"*snmpd.conf*(5) — The manual page for the `/etc/snmp/snmpd.conf` file " +"containing full documentation of available configuration directives.\n" +msgstr "" diff --git a/po/fr/rawhide/pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.po b/po/fr/rawhide/pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.po new file mode 100644 index 00000000000..01da822bb11 --- /dev/null +++ b/po/fr/rawhide/pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.po @@ -0,0 +1,5323 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:5 +#, no-wrap +msgid "Viewing and Managing Log Files" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:8 +msgid "" +"indexterm:[log files,System Log]indexterm:[log files,description] _Log " +"files_ are files that contain messages about the system, including the " +"kernel, services, and applications running on it. There are different log " +"files for different information. For example, there is a default system log " +"file, a log file just for security messages, and a log file for cron tasks." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:12 +msgid "" +"Log files can be very useful when trying to troubleshoot a problem with the " +"system such as trying to load a kernel driver or when looking for " +"unauthorized login attempts to the system. This chapter discusses where to " +"find log files, how to view log files, and what to look for in log files. " +"indexterm:[log files,rsyslogd daemon]indexterm:[rsyslog] Some log files are " +"controlled by a daemon called `rsyslogd`. The `rsyslogd` daemon is an " +"enhanced replacement for [application]*sysklogd*, and provides extended " +"filtering, encryption protected relaying of messages, various configuration " +"options, input and output modules, support for transportation via the `TCP` " +"or `UDP` protocols. Note that [application]*rsyslog* is compatible with " +"[application]*sysklogd*." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:14 +msgid "" +"Log files can also be managed by the `journald` daemon – a component " +"of `systemd`. The `journald` daemon captures Syslog messages, kernel log " +"messages, initial RAM disk and early boot messages as well as messages " +"written to standard output and standard error output of all services, " +"indexes them and makes this available to the user. The native journal file " +"format, which is a structured and indexed binary file, improves searching " +"and provides faster operation, and it also stores meta data information like " +"time stamps or user IDs. Log files produced by `journald` are by default not " +"persistent, log files are stored only in memory or a small ring-buffer in " +"the `/run/log/journal/` directory. The amount of logged data depends on free " +"memory, when you reach the capacity limit, the oldest entries are " +"deleted. However, this setting can be altered – see " +"xref:Viewing_and_Managing_Log_Files.adoc#s2-Enabling_Persistent_Storage[Enabling " +"Persistent Storage]. For more information on Journal see " +"xref:Viewing_and_Managing_Log_Files.adoc#s1-Using_the_Journal[Using the " +"Journal]." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:16 +msgid "" +"By default, only `journald` is installed on your system. You have to install " +"rsyslog youself. Also do not forget to enable and start it after install " +"before continuing with rest of this guide. The `journald` daemon is the " +"primary tool for troubleshooting. It also provides additional data necessary " +"for creating structured log messages. Data acquired by `journald` is " +"forwarded into the `/run/systemd/journal/syslog` socket that may be used by " +"`rsyslogd` to process the data further. However, [application]*rsyslog* does " +"the actual integration by default via the `imjournal` input module, thus " +"avoiding the aforementioned socket. You can also transfer data in the " +"opposite direction, from `rsyslogd` to `journald` with use of `omjournal` " +"module. See " +"xref:Viewing_and_Managing_Log_Files.adoc#s1-interaction_of_rsyslog_and_journal[Interaction " +"of Rsyslog and Journal] for further information. The integration enables " +"maintaining text-based logs in a consistent format to ensure compatibility " +"with possible applications or configurations dependent on `rsyslogd`. Also, " +"you can maintain rsyslog messages in a structured format (see " +"xref:Viewing_and_Managing_Log_Files.adoc#s1-structured_logging_with_rsyslog[Structured " +"Logging with Rsyslog])." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:18 +#, no-wrap +msgid "Locating Log Files" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:23 +msgid "" +"indexterm:[log files,locating] A list of log files maintained by `rsyslogd` " +"can be found in the `/etc/rsyslog.conf` configuration file. Most log files " +"are located in the `/var/log/` directory. Some applications such as " +"[command]#httpd# and [command]#samba# have a directory within `/var/log/` " +"for their log files. indexterm:[log files,rotating]indexterm:[logrotate] " +"You may notice multiple files in the `/var/log/` directory with numbers " +"after them (for example, `cron-20100906`). These numbers represent a time " +"stamp that has been added to a rotated log file. Log files are rotated so " +"their file sizes do not become too large. The `logrotate` package contains a " +"cron task that automatically rotates log files according to the " +"`/etc/logrotate.conf` configuration file and the configuration files in the " +"`/etc/logrotate.d/` directory." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:25 +#, no-wrap +msgid "Basic Configuration of Rsyslog" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:28 +msgid "" +"indexterm:[rsyslog,configuration] The main configuration file for " +"[application]*rsyslog* is `/etc/rsyslog.conf`. Here, you can specify _global " +"directives_, _modules_, and _rules_ that consist of _filter_ and _action_ " +"parts. Also, you can add comments in the form of text following a hash sign " +"(`#`)." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:30 +#, no-wrap +msgid "Filters" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:33 +msgid "" +"indexterm:[rsyslog,filters] A rule is specified by a *filter* part, which " +"selects a subset of syslog messages, and an *action* part, which specifies " +"what to do with the selected messages. To define a rule in your " +"`/etc/rsyslog.conf` configuration file, define both, a filter and an action, " +"on one line and separate them with one or more spaces or tabs." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:35 +msgid "" +"[application]*rsyslog* offers various ways to filter syslog messages " +"according to selected properties. The available filtering methods can be " +"divided into *Facility/Priority-based*, *Property-based*, and " +"*Expression-based* filters." +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:36 +#, no-wrap +msgid "Facility/Priority-based filters" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:37 +msgid "" +"The most used and well-known way to filter syslog messages is to use the " +"facility/priority-based filters which filter syslog messages based on two " +"conditions: _facility_ and _priority_ separated by a dot. To create a " +"selector, use the following syntax:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:42 +#, no-wrap +msgid "_FACILITY_._PRIORITY_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:46 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:99 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:160 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:241 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:290 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:369 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:468 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:516 +msgid "where:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:48 +msgid "" +"_FACILITY_ specifies the subsystem that produces a specific syslog " +"message. For example, the [command]#mail# subsystem handles all mail-related " +"syslog messages. _FACILITY_ can be represented by one of the following " +"keywords (or by a numerical code): [command]#kern# (0), [command]#user# (1), " +"[command]#mail# (2), [command]#daemon# (3), [command]#auth# (4), " +"[command]#syslog# (5), [command]#lpr# (6), [command]#news# (7), " +"[command]#uucp# (8), [command]#cron# (9), [command]#authpriv# (10), " +"[command]#ftp# (11), [command]#ntp# (12), [command]#logaudit# (13), " +"[command]#logalert# (14), [command]#clock# (15), and [command]#local0# " +"through [command]#local7# (16 - 23)." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:50 +msgid "" +"_PRIORITY_ specifies a priority of a syslog message. _PRIORITY_ can be " +"represented by one of the following keywords (or by a number): " +"[command]#debug# (7), [command]#info# (6), [command]#notice# (5), " +"[command]#warning# (4), [command]#err# (3), [command]#crit# (2), " +"[command]#alert# (1), and [command]#emerg# (0)." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:52 +msgid "" +"The aforementioned syntax selects syslog messages with the defined or " +"*higher* priority. By preceding any priority keyword with an equal sign " +"(`=`), you specify that only syslog messages with the specified priority " +"will be selected. All other priorities will be ignored. Conversely, " +"preceding a priority keyword with an exclamation mark (`!`) selects all " +"syslog messages except those with the defined priority." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:54 +msgid "" +"In addition to the keywords specified above, you may also use an asterisk " +"(`*`) to define all facilities or priorities (depending on where you place " +"the asterisk, before or after the comma). Specifying the priority keyword " +"`none` serves for facilities with no given priorities. Both facility and " +"priority conditions are case-insensitive." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:56 +msgid "" +"To define multiple facilities and priorities, separate them with a comma " +"(`,`). To define multiple selectors on one line, separate them with a " +"semi-colon (`;`). Note that each selector in the selector field is capable " +"of overwriting the preceding ones, which can exclude some priorities from " +"the pattern." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:58 +#, no-wrap +msgid "Facility/Priority-based Filters" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:62 +msgid "" +"The following are a few examples of simple facility/priority-based filters " +"that can be specified in `/etc/rsyslog.conf`. To select all kernel syslog " +"messages with any priority, add the following text into the configuration " +"file:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:66 +#, no-wrap +msgid "kern.*\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:70 +msgid "" +"To select all mail syslog messages with priority [command]#crit# and higher, " +"use this form:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:75 +#, no-wrap +msgid "mail.crit\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:79 +msgid "" +"To select all cron syslog messages except those with the [command]#info# or " +"[command]#debug# priority, set the configuration in the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:84 +#, no-wrap +msgid "cron.!info,!debug\n" +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:89 +#, no-wrap +msgid "Property-based filters" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:90 +msgid "" +"Property-based filters let you filter syslog messages by any property, such " +"as `timegenerated` or `syslogtag`. For more information on properties, see " +"xref:Viewing_and_Managing_Log_Files.adoc#brid-properties[Properties]. You " +"can compare each of the specified properties to a particular value using one " +"of the compare-operations listed in " +"xref:Viewing_and_Managing_Log_Files.adoc#table-compare-operations[Property-based " +"compare-operations]. Both property names and compare operations are " +"case-sensitive." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:92 +msgid "" +"Property-based filter must start with a colon (`:`). To define the filter, " +"use the following syntax:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:96 +#, no-wrap +msgid "" +":pass:quotes[_PROPERTY_], [!]pass:quotes[_COMPARE_OPERATION_], " +"\"pass:quotes[_STRING_]\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:101 +msgid "The _PROPERTY_ attribute specifies the desired property." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:103 +msgid "" +"The optional exclamation point (`!`) negates the output of the " +"compare-operation. Other Boolean operators are currently not supported in " +"property-based filters." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:105 +msgid "" +"The _COMPARE_OPERATION_ attribute specifies one of the compare-operations " +"listed in " +"xref:Viewing_and_Managing_Log_Files.adoc#table-compare-operations[Property-based " +"compare-operations]." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:107 +msgid "" +"The _STRING_ attribute specifies the value that the text provided by the " +"property is compared to. This value must be enclosed in quotation marks. To " +"escape certain character inside the string (for example a quotation mark " +"(`\"`)), use the backslash character (`\\`)." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:109 +#, no-wrap +msgid "Property-based compare-operations" +msgstr "" + +#. type: Table +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:120 +#, no-wrap +msgid "" +"|Compare-operation|Description\n" +"|`contains`|Checks whether the provided string matches any part of the text " +"provided by the property. To perform case-insensitive comparisons, use " +"`contains_i`.\n" +"|`isequal`|Compares the provided string against all of the text provided by " +"the property. These two values must be exactly equal to match.\n" +"|`startswith`|Checks whether the provided string is found exactly at the " +"beginning of the text provided by the property. To perform case-insensitive " +"comparisons, use `startswith_i`.\n" +"|`regex`|Compares the provided POSIX BRE (Basic Regular Expression) against " +"the text provided by the property.\n" +"|`ereregex`|Compares the provided POSIX ERE (Extended Regular Expression) " +"regular expression against the text provided by the property.\n" +"|`isempty`|Checks if the property is empty. The value is discarded. This is " +"especially useful when working with normalized data, where some fields may " +"be populated based on normalization result.\n" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:123 +#, no-wrap +msgid "Property-based Filters" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:127 +msgid "" +"The following are a few examples of property-based filters that can be " +"specified in `/etc/rsyslog.conf`. To select syslog messages which contain " +"the string `error` in their message text, use:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:131 +#, no-wrap +msgid ":msg, contains, \"error\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:134 +msgid "" +"The following filter selects syslog messages received from the host name " +"`host1`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:138 +#, no-wrap +msgid ":hostname, isequal, \"host1\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:141 +msgid "" +"To select syslog messages which do not contain any mention of the words " +"`fatal` and `error` with any or no text between them (for example, `fatal " +"lib error`), type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:144 +#, no-wrap +msgid ":msg, !regex, \"fatal .* error\"\n" +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:148 +#, no-wrap +msgid "Expression-based filters" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:149 +msgid "" +"Expression-based filters select syslog messages according to defined " +"arithmetic, Boolean or string operations. Expression-based filters use " +"[application]*rsyslog*pass:attributes[{blank}]'s own scripting language " +"called *RainerScript* to build complex filters." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:151 +msgid "The basic syntax of expression-based filter looks as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:156 +#, no-wrap +msgid "if _EXPRESSION_ then _ACTION_ else _ACTION_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:162 +msgid "" +"The _EXPRESSION_ attribute represents an expression to be evaluated, for " +"example: `$msg startswith 'DEVNAME'` or `$syslogfacility-text == " +"'local0'`. You can specify more than one expression in a single filter by " +"using `and` and `or` operators." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:164 +msgid "" +"The _ACTION_ attribute represents an action to be performed if the " +"expression returns the value `true`. This can be a single action, or an " +"arbitrary complex script enclosed in curly braces." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:166 +msgid "" +"Expression-based filters are indicated by the keyword *if* at the start of a " +"new line. The *then* keyword separates the _EXPRESSION_ from the " +"_ACTION_. Optionally, you can employ the *else* keyword to specify what " +"action is to be performed in case the condition is not met." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:168 +msgid "" +"With expression-based filters, you can nest the conditions by using a script " +"enclosed in curly braces as in " +"xref:Viewing_and_Managing_Log_Files.adoc#ex-expression-based_filters[Expression-based " +"Filters]. The script allows you to use *facility/priority-based* filters " +"inside the expression. On the other hand, *property-based* filters are not " +"recommended here. RainerScript supports regular expressions with specialized " +"functions `re_match()` and `re_extract()`." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:170 +#, no-wrap +msgid "Expression-based Filters" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:174 +msgid "" +"The following expression contains two nested conditions. The log files " +"created by a program called *prog1* are split into two files based on the " +"presence of the \"`test`\" string in the message." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:185 +#, no-wrap +msgid "" +"if $programname == 'prog1' then {\n" +" action(type=\"omfile\" file=\"/var/log/prog1.log\")\n" +" if $msg contains 'test' then\n" +" action(type=\"omfile\" file=\"/var/log/prog1test.log\")\n" +" else\n" +" action(type=\"omfile\" file=\"/var/log/prog1notest.log\")\n" +"}\n" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:191 +msgid "" +"See " +"xref:Viewing_and_Managing_Log_Files.adoc#brid-Log_Files-Resources-Online[Online " +"Documentation] for more examples of various expression-based " +"filters. RainerScript is the basis for " +"[application]*rsyslog*pass:attributes[{blank}]'s new configuration format, " +"see " +"xref:Viewing_and_Managing_Log_Files.adoc#sec-using_the_new_configuration_format[Using " +"the New Configuration Format]" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:193 +#, no-wrap +msgid "Actions" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:196 +msgid "" +"indexterm:[rsyslog,actions] Actions specify what is to be done with the " +"messages filtered out by an already-defined selector. The following are some " +"of the actions you can define in your rule:" +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:197 +#, no-wrap +msgid "Saving syslog messages to log files" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:198 +msgid "" +"The majority of actions specify to which log file a syslog message is " +"saved. This is done by specifying a file path after your already-defined " +"selector:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:202 +#, no-wrap +msgid "_FILTER_ _PATH_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:205 +msgid "" +"where _FILTER_ stands for user-specified selector and _PATH_ is a path of a " +"target file." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:207 +msgid "" +"For instance, the following rule is comprised of a selector that selects all " +"[application]*cron* syslog messages and an action that saves them into the " +"`/var/log/cron.log` log file:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:210 +#, no-wrap +msgid "cron.* /var/log/cron.log\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:213 +msgid "" +"By default, the log file is synchronized every time a syslog message is " +"generated. Use a dash mark (`-`) as a prefix of the file path you specified " +"to omit syncing:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:217 +#, no-wrap +msgid "_FILTER_ -_PATH_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:220 +msgid "" +"Note that you might lose information if the system terminates right after a " +"write attempt. However, this setting can improve performance, especially if " +"you run programs that produce very verbose log messages." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:222 +msgid "" +"Your specified file path can be either *static* or *dynamic*. Static files " +"are represented by a fixed file path as shown in the example above. Dynamic " +"file paths can differ according to the received message. Dynamic file paths " +"are represented by a template and a question mark (`?`) prefix:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:226 +#, no-wrap +msgid "_FILTER_ ?_DynamicFile_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:229 +msgid "" +"where _DynamicFile_ is a name of a predefined template that modifies output " +"paths. You can use the dash prefix (`-`) to disable syncing, also you can " +"use multiple templates separated by a colon (`;`). For more information on " +"templates, see " +"xref:Viewing_and_Managing_Log_Files.adoc#brid-generating-dynamic-fnames[Generating " +"Dynamic File Names]." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:231 +msgid "" +"If the file you specified is an existing [application]*terminal* or " +"`/dev/console` device, syslog messages are sent to standard output (using " +"special [application]*terminal*-handling) or your console (using special " +"`/dev/console`-handling) when using the X Window System, respectively." +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:232 +#, no-wrap +msgid "Sending syslog messages over the network" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:233 +msgid "" +"[application]*rsyslog* allows you to send and receive syslog messages over " +"the network. This feature allows you to administer syslog messages of " +"multiple hosts on one machine. To forward syslog messages to a remote " +"machine, use the following syntax:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:237 +#, no-wrap +msgid "@([command]#zpass:attributes[{blank}]_NUMBER_pass:attributes[{blank}]#)_HOST_:pass:attributes[{blank}]_PORT_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:243 +msgid "" +"The at sign (`@`) indicates that the syslog messages are forwarded to a host " +"using the `UDP` protocol. To use the `TCP` protocol, use two at signs with " +"no space between them (`@@`)." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:245 +msgid "" +"The optional " +"[command]#zpass:attributes[{blank}]_NUMBER_pass:attributes[{blank}]# setting " +"enables [application]*zlib* compression for syslog messages. The _NUMBER_ " +"attribute specifies the level of compression (from 1 – lowest to 9 " +"– maximum). Compression gain is automatically checked by `rsyslogd`, " +"messages are compressed only if there is any compression gain and messages " +"below 60 bytes are never compressed." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:247 +msgid "" +"The _HOST_ attribute specifies the host which receives the selected syslog " +"messages." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:249 +msgid "The _PORT_ attribute specifies the host machine's port." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:251 +msgid "" +"When specifying an `IPv6` address as the host, enclose the address in square " +"brackets (`[`, `]`)." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:253 +#, no-wrap +msgid "Sending syslog Messages over the Network" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:257 +msgid "" +"The following are some examples of actions that forward syslog messages over " +"the network (note that all actions are preceded with a selector that selects " +"all messages with any priority). To forward messages to `192.168.0.1` via " +"the `UDP` protocol, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:261 +#, no-wrap +msgid "*.* @192.168.0.1\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:265 +msgid "" +"To forward messages to \"`example.com`\" using port 18 and the `TCP` " +"protocol, use:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:269 +#, no-wrap +msgid "*.* @@example.com:18\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:273 +msgid "" +"The following compresses messages with [application]*zlib* (level 9 " +"compression) and forwards them to `2001:db8::1` using the `UDP` protocol" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:277 +#, no-wrap +msgid "*.* @(z9)[2001:db8::1]\n" +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:282 +#, no-wrap +msgid "Output channels" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:283 +msgid "" +"Output channels are primarily used to specify the maximum size a log file " +"can grow to. This is very useful for log file rotation (for more information " +"see xref:Viewing_and_Managing_Log_Files.adoc#s2-log_rotation[Log " +"Rotation]). An output channel is basically a collection of information about " +"the output action. Output channels are defined by the `$outchannel` " +"directive. To define an output channel in `/etc/rsyslog.conf`, use the " +"following syntax:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:287 +#, no-wrap +msgid "" +"$outchannel pass:quotes[_NAME_], pass:quotes[_FILE_NAME_], " +"pass:quotes[_MAX_SIZE_], pass:quotes[_ACTION_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:292 +msgid "The _NAME_ attribute specifies the name of the output channel." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:294 +msgid "" +"The _FILE_NAME_ attribute specifies the name of the output file. Output " +"channels can write only into files, not pipes, terminal, or other kind of " +"output." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:296 +msgid "" +"The _MAX_SIZE_ attribute represents the maximum size the specified file (in " +"_FILE_NAME_) can grow to. This value is specified in *bytes*." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:298 +msgid "" +"The _ACTION_ attribute specifies the action that is taken when the maximum " +"size, defined in _MAX_SIZE_, is hit." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:300 +msgid "To use the defined output channel as an action inside a rule, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:304 +#, no-wrap +msgid "_FILTER_ :omfile:$pass:attributes[{blank}]_NAME_\n" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:307 +#, no-wrap +msgid "Output channel log rotation" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:311 +msgid "" +"The following output shows a simple log rotation through the use of an " +"output channel. First, the output channel is defined via the `$outchannel` " +"directive:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:315 +#, no-wrap +msgid "" +" $outchannel log_rotation, /var/log/test_log.log, 104857600, " +"/home/joe/log_rotation_script\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:319 +msgid "" +"and then it is used in a rule that selects every syslog message with any " +"priority and executes the previously-defined output channel on the acquired " +"syslog messages:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:323 +#, no-wrap +msgid "*.* :omfile:$log_rotation\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:327 +msgid "" +"Once the limit (in the example 100{nbsp}MB) is hit, the " +"`/home/joe/log_rotation_script` is executed. This script can contain " +"anything from moving the file into a different folder, editing specific " +"content out of it, or simply removing it." +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:330 +#, no-wrap +msgid "Sending syslog messages to specific users" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:331 +msgid "" +"[application]*rsyslog* can send syslog messages to specific users by " +"specifying a user name of the user you want to send the messages to (as in " +"xref:Viewing_and_Managing_Log_Files.adoc#ex-multiple_actions[Specifying " +"Multiple Actions]). To specify more than one user, separate each user name " +"with a comma (`,`). To send messages to every user that is currently logged " +"on, use an asterisk (`*`)." +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:332 +#, no-wrap +msgid "Executing a program" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:333 +msgid "" +"[application]*rsyslog* lets you execute a program for selected syslog " +"messages and uses the `system()` call to execute the program in shell. To " +"specify a program to be executed, prefix it with a caret character " +"(`^`). Consequently, specify a template that formats the received message " +"and passes it to the specified executable as a one line parameter (for more " +"information on templates, see " +"xref:Viewing_and_Managing_Log_Files.adoc#s2-Templates[Templates])." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:337 +#, no-wrap +msgid "pass:quotes[_FILTER_] ^pass:quotes[_EXECUTABLE_]; pass:quotes[_TEMPLATE_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:340 +msgid "" +"Here an output of the _FILTER_ condition is processed by a program " +"represented by _EXECUTABLE_. This program can be any valid " +"executable. Replace _TEMPLATE_ with the name of the formatting template." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:342 +#, no-wrap +msgid "Executing a Program" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:346 +msgid "" +"In the following example, any syslog message with any priority is selected, " +"formatted with the `template` template and passed as a parameter to the " +"[application]*test-program* program, which is then executed with the " +"provided parameter:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:349 +#, no-wrap +msgid "*.* ^test-program;template\n" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:353 +#, no-wrap +msgid "Be careful when using the shell execute action" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:358 +msgid "" +"When accepting messages from any host, and using the shell execute action, " +"you may be vulnerable to command injection. An attacker may try to inject " +"and execute commands in the program you specified to be executed in your " +"action. To avoid any possible security threats, thoroughly consider the use " +"of the shell execute action." +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:361 +#, no-wrap +msgid "Storing syslog messages in a database" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:362 +msgid "" +"Selected syslog messages can be directly written into a database table using " +"the *database writer* action. The database writer uses the following syntax:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:366 +#, no-wrap +msgid ":pass:quotes[_PLUGIN_]:pass:quotes[_DB_HOST_],pass:quotes[_DB_NAME_],pass:quotes[_DB_USER_],pass:quotes[_DB_PASSWORD_];pass:quotes[_TEMPLATE_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:371 +msgid "" +"The _PLUGIN_ calls the specified plug-in that handles the database writing " +"(for example, the `ommysql` plug-in)." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:373 +msgid "The _DB_HOST_ attribute specifies the database host name." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:375 +msgid "The _DB_NAME_ attribute specifies the name of the database." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:377 +msgid "The _DB_USER_ attribute specifies the database user." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:379 +msgid "" +"The _DB_PASSWORD_ attribute specifies the password used with the " +"aforementioned database user." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:381 +msgid "" +"The _TEMPLATE_ attribute specifies an optional use of a template that " +"modifies the syslog message. For more information on templates, see " +"xref:Viewing_and_Managing_Log_Files.adoc#s2-Templates[Templates]." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:382 +#, no-wrap +msgid "Using MySQL and PostgreSQL" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:388 +msgid "" +"Currently, [application]*rsyslog* provides support for `MySQL` and " +"`PostgreSQL` databases only. In order to use the `MySQL` and `PostgreSQL` " +"database writer functionality, install the [package]*rsyslog-mysql* and " +"[package]*rsyslog-pgsql* packages, respectively. Also, make sure you load " +"the appropriate modules in your `/etc/rsyslog.conf` configuration file:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:393 +#, no-wrap +msgid "" +"$ModLoad ommysql # Output module for MySQL support\n" +"$ModLoad ompgsql # Output module for PostgreSQL support\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:397 +msgid "" +"For more information on [application]*rsyslog* modules, see " +"xref:Viewing_and_Managing_Log_Files.adoc#s1-using_rsyslog_modules[Using " +"Rsyslog Modules]." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:399 +msgid "" +"Alternatively, you may use a generic database interface provided by the " +"`omlibdb` module (supports: Firebird/Interbase, MS SQL, Sybase, SQLLite, " +"Ingres, Oracle, mSQL)." +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:402 +#, no-wrap +msgid "Discarding syslog messages" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:403 +msgid "To discard your selected messages, use the tilde character (`~`)." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:407 +#, no-wrap +msgid "_FILTER_ ~\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:410 +msgid "" +"The discard action is mostly used to filter out messages before carrying on " +"any further processing. It can be effective if you want to omit some " +"repeating messages that would otherwise fill the log files. The results of " +"discard action depend on where in the configuration file it is specified, " +"for the best results place these actions on top of the actions list. Please " +"note that once a message has been discarded there is no way to retrieve it " +"in later configuration file lines." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:412 +msgid "For instance, the following rule discards any cron syslog messages:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:415 +#, no-wrap +msgid "cron.* ~\n" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:417 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:432 +#, no-wrap +msgid "Specifying Multiple Actions" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:419 +msgid "" +"For each selector, you are allowed to specify multiple actions. To specify " +"multiple actions for one selector, write each action on a separate line and " +"precede it with an ampersand (&) character:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:426 +#, no-wrap +msgid "" +"_FILTER_ _ACTION_\n" +"& _ACTION_\n" +"& _ACTION_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:430 +msgid "" +"Specifying multiple actions improves the overall performance of the desired " +"outcome since the specified selector has to be evaluated only once." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:436 +msgid "" +"In the following example, all kernel syslog messages with the critical " +"priority (`crit`) are sent to user `user1`, processed by the template `temp` " +"and passed on to the `test-program` executable, and forwarded to " +"`192.168.0.1` via the `UDP` protocol." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:442 +#, no-wrap +msgid "" +"kern.=crit user1\n" +"& ^test-program;temp\n" +"& @192.168.0.1\n" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:448 +msgid "" +"Any action can be followed by a template that formats the message. To " +"specify a template, suffix an action with a semicolon (`;`) and specify the " +"name of the template. For more information on templates, see " +"xref:Viewing_and_Managing_Log_Files.adoc#s2-Templates[Templates]." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:449 +#, no-wrap +msgid "Using templates" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:454 +msgid "" +"A template must be defined before it is used in an action, otherwise it is " +"ignored. In other words, template definitions should always precede rule " +"definitions in `/etc/rsyslog.conf`." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:458 +#, no-wrap +msgid "Templates" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:461 +msgid "" +"indexterm:[rsyslog,templates] Any output that is generated by " +"[application]*rsyslog* can be modified and formatted according to your needs " +"with the use of *templates*. To create a template use the following syntax " +"in `/etc/rsyslog.conf`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:465 +#, no-wrap +msgid "" +"$template pass:quotes[_TEMPLATE_NAME_],\"pass:quotes[_text %PROPERTY% more " +"text_]\", pass:quotes[_OPTION_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:470 +msgid "" +"`$template` is the template directive that indicates that the text following " +"it, defines a template." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:472 +msgid "" +"`TEMPLATE_NAME` is the name of the template. Use this name to refer to the " +"template." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:474 +msgid "" +"Anything between the two quotation marks " +"(`\"`pass:attributes[{blank}]…pass:attributes[{blank}]`\"`) is the " +"actual template text. Within this text, special characters, such as `\\n` " +"for new line or `\\r` for carriage return, can be used. Other characters, " +"such as `%` or `\"`, have to be escaped if you want to use those characters " +"literally." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:476 +msgid "" +"The text specified between two percent signs (`%`) specifies a _property_ " +"that allows you to access specific contents of a syslog message. For more " +"information on properties, see " +"xref:Viewing_and_Managing_Log_Files.adoc#brid-properties[Properties]." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:478 +msgid "" +"The `OPTION` attribute specifies any options that modify the template " +"functionality. The currently supported template options are `sql` and " +"`stdsql`, which are used for formatting the text as an SQL query." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:479 +#, no-wrap +msgid "The sql and stdsql options" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:484 +msgid "" +"Note that the database writer checks whether the `sql` or `stdsql` options " +"are specified in the template. If they are not, the database writer does not " +"perform any action. This is to prevent any possible security threats, such " +"as SQL injection." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:486 +msgid "" +"See section [citetitle]_Storing syslog messages in a database_ in " +"xref:Viewing_and_Managing_Log_Files.adoc#s2-Actions[Actions] for more " +"information." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:490 +#, no-wrap +msgid "Generating Dynamic File Names" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:493 +msgid "" +"Templates can be used to generate dynamic file names. By specifying a " +"property as a part of the file path, a new file will be created for each " +"unique property, which is a convenient way to classify syslog messages." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:495 +msgid "" +"For example, use the `timegenerated` property, which extracts a time stamp " +"from the message, to generate a unique file name for each syslog message:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:498 +#, no-wrap +msgid "$template DynamicFile,\"/var/log/test_logs/%timegenerated%-test.log\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:501 +msgid "" +"Keep in mind that the `$template` directive only specifies the template. You " +"must use it inside a rule for it to take effect. In `/etc/rsyslog.conf`, use " +"the question mark (`?`) in an action definition to mark the dynamic file " +"name template:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:504 +#, no-wrap +msgid "*.* ?DynamicFile\n" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:507 +#, no-wrap +msgid "Properties" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:509 +msgid "" +"Properties defined inside a template (between two percent signs (`%`)) " +"enable access various contents of a syslog message through the use of a " +"_property replacer_. To define a property inside a template (between the two " +"quotation marks " +"(`\"`pass:attributes[{blank}]…pass:attributes[{blank}]`\"`)), use the " +"following syntax:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:513 +#, no-wrap +msgid "%pass:quotes[_PROPERTY_NAME_]:pass:quotes[_FROM_CHAR_]:pass:quotes[_TO_CHAR_]:pass:quotes[_OPTION_]%\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:518 +msgid "" +"The _PROPERTY_NAME_ attribute specifies the name of a property. A list of " +"all available properties and their detailed description can be found in the " +"`rsyslog.conf(5)` manual page under the section *Available Properties*." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:520 +msgid "" +"_FROM_CHAR_ and _TO_CHAR_ attributes denote a range of characters that the " +"specified property will act upon. Alternatively, regular expressions can be " +"used to specify a range of characters. To do so, set the letter `R` as the " +"_FROM_CHAR_ attribute and specify your desired regular expression as the " +"_TO_CHAR_ attribute." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:522 +msgid "" +"The _OPTION_ attribute specifies any property options, such as the " +"[option]`lowercase` option to convert the input to lowercase. A list of all " +"available property options and their detailed description can be found in " +"the `rsyslog.conf(5)` manual page under the section *Property Options*." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:524 +msgid "The following are some examples of simple properties:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:526 +msgid "The following property obtains the whole message text of a syslog message:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:530 +#, no-wrap +msgid "%msg%\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:533 +msgid "" +"The following property obtains the first two characters of the message text " +"of a syslog message:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:537 +#, no-wrap +msgid "%msg:1:2%\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:540 +msgid "" +"The following property obtains the whole message text of a syslog message " +"and drops its last line feed character:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:544 +#, no-wrap +msgid "%msg:::drop-last-lf%\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:547 +msgid "" +"The following property obtains the first 10 characters of the time stamp " +"that is generated when the syslog message is received and formats it " +"according to the " +"[citetitle]_link:++https://www.rfc-editor.org/info/rfc3339++[RFC 3339]_ date " +"standard." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:551 +#, no-wrap +msgid "%timegenerated:1:10:date-rfc3339%\n" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:553 +#, no-wrap +msgid "Template Examples" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:555 +msgid "This section presents a few examples of [application]*rsyslog* templates." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:557 +msgid "" +"xref:Viewing_and_Managing_Log_Files.adoc#example-temp1[A verbose syslog " +"message template] shows a template that formats a syslog message so that it " +"outputs the message's severity, facility, the time stamp of when the message " +"was received, the host name, the message tag, the message text, and ends " +"with a new line." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:559 +#, no-wrap +msgid "A verbose syslog message template" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:565 +#, no-wrap +msgid "" +"$template verbose, \"%syslogseverity%, %syslogfacility%, %timegenerated%, " +"%HOSTNAME%, %syslogtag%, %msg%\\n\"\n" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:570 +msgid "" +"xref:Viewing_and_Managing_Log_Files.adoc#example-temp2[A wall message " +"template] shows a template that resembles a traditional wall message (a " +"message that is send to every user that is logged in and has their `mesg(1)` " +"permission set to `yes`). This template outputs the message text, along with " +"a host name, message tag and a time stamp, on a new line (using `\\r` and " +"`\\n`) and rings the bell (using `\\7`)." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:572 +#, no-wrap +msgid "A wall message template" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:578 +#, no-wrap +msgid "" +"$template wallmsg,\"\\r\\n\\7Message from syslogd@%HOSTNAME% at " +"%timegenerated% ...\\r\\n %syslogtag% %msg%\\n\\r\"\n" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:583 +msgid "" +"xref:Viewing_and_Managing_Log_Files.adoc#example-temp3[A database formatted " +"message template] shows a template that formats a syslog message so that it " +"can be used as a database query. Notice the use of the `sql` option at the " +"end of the template specified as the template option. It tells the database " +"writer to format the message as an MySQL `SQL` query." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:585 +#, no-wrap +msgid "A database formatted message template" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:591 +#, no-wrap +msgid "" +"$template dbFormat,\"insert into SystemEvents (Message, Facility, FromHost, " +"Priority, DeviceReportedTime, ReceivedAt, InfoUnitID, SysLogTag) values " +"('%msg%', %syslogfacility%, '%HOSTNAME%', %syslogpriority%, " +"'%timereported:::date-mysql%', '%timegenerated:::date-mysql%', %iut%, " +"'%syslogtag%')\", sql\n" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:596 +msgid "" +"[application]*rsyslog* also contains a set of predefined templates " +"identified by the `RSYSLOG_` prefix. These are reserved for the syslog's use " +"and it is advisable to not create a template using this prefix to avoid " +"conflicts. The following list shows these predefined templates along with " +"their definitions." +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:597 +#, no-wrap +msgid "`RSYSLOG_DebugFormat`" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:598 +msgid "A special format used for troubleshooting property problems." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:602 +#, no-wrap +msgid "" +"\"Debug line with all properties:\\nFROMHOST: '%FROMHOST%', fromhost-ip: " +"'%fromhost-ip%', HOSTNAME: '%HOSTNAME%', PRI: %PRI%,\\nsyslogtag " +"'%syslogtag%', programname: '%programname%', APP-NAME: '%APP-NAME%', PROCID: " +"'%PROCID%', MSGID: '%MSGID%',\\nTIMESTAMP: '%TIMESTAMP%', STRUCTURED-DATA: " +"'%STRUCTURED-DATA%',\\nmsg: '%msg%'\\nescaped msg: " +"'%msg:::drop-cc%'\\nrawmsg: '%rawmsg%'\\n\\n\\\"\n" +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:604 +#, no-wrap +msgid "`RSYSLOG_SyslogProtocol23Format`" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:605 +msgid "" +"The format specified in IETF's internet-draft ietf-syslog-protocol-23, which " +"is assumed to become the new syslog standard RFC." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:609 +#, no-wrap +msgid "" +"\"%PRI%1 %TIMESTAMP:::date-rfc3339% %HOSTNAME% %APP-NAME% %PROCID% %MSGID% " +"%STRUCTURED-DATA% %msg%\\n\\\"\n" +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:611 +#, no-wrap +msgid "`RSYSLOG_FileFormat`" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:612 +msgid "" +"A modern-style logfile format similar to TraditionalFileFormat, but with " +"high-precision time stamps and time zone information." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:616 +#, no-wrap +msgid "" +"\"%TIMESTAMP:::date-rfc3339% %HOSTNAME% " +"%syslogtag%%msg:::sp-if-no-1st-sp%%msg:::drop-last-lf%\\n\\\"\n" +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:618 +#, no-wrap +msgid "`RSYSLOG_TraditionalFileFormat`" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:619 +msgid "The older default log file format with low-precision time stamps." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:623 +#, no-wrap +msgid "" +"\"%TIMESTAMP% %HOSTNAME% " +"%syslogtag%%msg:::sp-if-no-1st-sp%%msg:::drop-last-lf%\\n\\\"\n" +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:625 +#, no-wrap +msgid "`RSYSLOG_ForwardFormat`" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:626 +msgid "" +"A forwarding format with high-precision time stamps and time zone " +"information." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:630 +#, no-wrap +msgid "" +"\"%PRI%%TIMESTAMP:::date-rfc3339% %HOSTNAME% " +"%syslogtag:1:32%%msg:::sp-if-no-1st-sp%%msg%\\\"\n" +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:632 +#, no-wrap +msgid "`RSYSLOG_TraditionalForwardFormat`" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:633 +msgid "The traditional forwarding format with low-precision time stamps." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:637 +#, no-wrap +msgid "" +"\"%PRI%%TIMESTAMP% %HOSTNAME% " +"%syslogtag:1:32%%msg:::sp-if-no-1st-sp%%msg%\\\"\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:640 +#, no-wrap +msgid "Global Directives" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:643 +msgid "" +"indexterm:[rsyslog,global directives] Global directives are configuration " +"options that apply to the `rsyslogd` daemon. They usually specify a value " +"for a specific predefined variable that affects the behavior of the " +"`rsyslogd` daemon or a rule that follows. All of the global directives must " +"start with a dollar sign (`$`). Only one directive can be specified per " +"line. The following is an example of a global directive that specifies the " +"maximum size of the syslog message queue:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:648 +#, no-wrap +msgid "$MainMsgQueueSize 50000\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:652 +msgid "" +"The default size defined for this directive (10,000 messages) can be " +"overridden by specifying a different value (as shown in the example above)." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:654 +msgid "" +"You can define multiple directives in your `/etc/rsyslog.conf` configuration " +"file. A directive affects the behavior of all configuration options until " +"another occurrence of that same directive is detected. Global directives can " +"be used to configure actions, queues and for debugging. A comprehensive list " +"of all available configuration directives can be found in " +"xref:Viewing_and_Managing_Log_Files.adoc#brid-Log_Files-Resources-Online[Online " +"Documentation]. Currently, a new configuration format has been developed " +"that replaces the $-based syntax (see " +"xref:Viewing_and_Managing_Log_Files.adoc#sec-using_the_new_configuration_format[Using " +"the New Configuration Format]). However, classic global directives remain " +"supported as a legacy format." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:656 +#, no-wrap +msgid "Log Rotation" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:659 +msgid "" +"indexterm:[rsyslog,log rotation] The following is a sample " +"`/etc/logrotate.conf` configuration file:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:668 +#, no-wrap +msgid "" +"# rotate log files weekly\n" +"weekly\n" +"# keep 4 weeks worth of backlogs\n" +"rotate 4\n" +"# uncomment this if you want your log files compressed\n" +"compress\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:672 +msgid "" +"All of the lines in the sample configuration file define global options that " +"apply to every log file. In our example, log files are rotated weekly, " +"rotated log files are kept for four weeks, and all rotated log files are " +"compressed by [application]*gzip* into the `.gz` format. Any lines that " +"begin with a hash sign (#) are comments and are not processed." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:674 +msgid "" +"You may define configuration options for a specific log file and place it " +"under the global options. However, it is advisable to create a separate " +"configuration file for any specific log file in the `/etc/logrotate.d/` " +"directory and define any configuration options there." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:676 +msgid "" +"The following is an example of a configuration file placed in the " +"`/etc/logrotate.d/` directory:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:687 +#, no-wrap +msgid "" +"/var/log/messages {\n" +" rotate 5\n" +" weekly\n" +" postrotate\n" +" /usr/bin/killall -HUP syslogd\n" +" endscript\n" +"}\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:691 +msgid "" +"The configuration options in this file are specific for the " +"`/var/log/messages` log file only. The settings specified here override the " +"global settings where possible. Thus the rotated `/var/log/messages` log " +"file will be kept for five weeks instead of four weeks as was defined in the " +"global options." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:693 +msgid "" +"The following is a list of some of the directives you can specify in your " +"[application]*logrotate* configuration file:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:695 +msgid "" +"`weekly` — Specifies the rotation of log files to be done weekly. Similar " +"directives include:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:697 +msgid "`daily`" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:699 +msgid "`monthly`" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:701 +msgid "`yearly`" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:703 +msgid "" +"`compress` — Enables compression of rotated log files. Similar directives " +"include:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:705 +msgid "`nocompress`" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:707 +msgid "`compresscmd` — Specifies the command to be used for compressing." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:709 +msgid "`uncompresscmd`" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:711 +msgid "`compressext` — Specifies what extension is to be used for compressing." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:713 +msgid "" +"`compressoptions` — Specifies any options to be passed to the compression " +"program used." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:715 +msgid "" +"`delaycompress` — Postpones the compression of log files to the next " +"rotation of log files." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:717 +msgid "" +"`rotate _INTEGER_pass:attributes[{blank}]` — Specifies the number of " +"rotations a log file undergoes before it is removed or mailed to a specific " +"address. If the value 0 is specified, old log files are removed instead of " +"rotated." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:719 +msgid "" +"`mail _ADDRESS_pass:attributes[{blank}]` — This option enables mailing of " +"log files that have been rotated as many times as is defined by the `rotate` " +"directive to the specified address. Similar directives include:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:721 +msgid "`nomail`" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:723 +msgid "" +"`mailfirst` — Specifies that the just-rotated log files are to be mailed, " +"instead of the about-to-expire log files." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:725 +msgid "" +"`maillast` — Specifies that the about-to-expire log files are to be mailed, " +"instead of the just-rotated log files. This is the default option when " +"`mail` is enabled." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:727 +msgid "" +"For the full list of directives and various configuration options, see the " +"`logrotate(8)` manual page." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:729 +#, no-wrap +msgid "Using the New Configuration Format" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:732 +msgid "" +"indexterm:[rsyslog,new configuration format] In [application]*rsyslog* " +"version 6, a new configuration syntax was introduced. This new configuration " +"format aims to be more powerful, more intuitive, and to prevent common " +"mistakes by not permitting certain invalid constructs. The syntax " +"enhancement is enabled by the new configuration processor that relies on " +"RainerScript. The legacy format is still fully supported and it is used by " +"default in the `/etc/rsyslog.conf` configuration file." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:734 +msgid "" +"RainerScript is a scripting language designed for processing network events " +"and configuring event processors such as " +"[application]*rsyslog*. RainerScript was first used to define " +"expression-based filters, see " +"xref:Viewing_and_Managing_Log_Files.adoc#ex-expression-based_filters[Expression-based " +"Filters]. The version of RainerScript in rsyslog version 7 implemented the " +"`input()` and `ruleset()` statements, which permit the `/etc/rsyslog.conf` " +"configuration file to be written in the new syntax. The new syntax differs " +"mainly in that it is much more structured; parameters are passed as " +"arguments to statements, such as input, action, template, and module " +"load. The scope of options is limited by blocks. This enhances readability " +"and reduces the number of bugs caused by misconfiguration. There is also a " +"significant performance gain. Some functionality is exposed in both " +"syntaxes, some only in the new one." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:736 +msgid "Compare the configuration written with legacy-style parameters:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:744 +#, no-wrap +msgid "" +"$InputFileName /tmp/inputfile\n" +"$InputFileTag tag1:\n" +"$InputFileStateFile inputfile-state\n" +"$InputRunFileMonitor\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:748 +msgid "and the same configuration with the use of the new format statement:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:753 +#, no-wrap +msgid "" +"input(type=\"imfile\" file=\"/tmp/inputfile\" tag=\"tag1:\" " +"statefile=\"inputfile-state\")\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:757 +msgid "" +"This significantly reduces the number of parameters used in configuration, " +"improves readability, and also provides higher execution speed. For more " +"information on RainerScript statements and parameters see " +"xref:Viewing_and_Managing_Log_Files.adoc#brid-Log_Files-Resources-Online[Online " +"Documentation]." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:759 +#, no-wrap +msgid "Rulesets" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:762 +msgid "" +"indexterm:[rsyslog,rulesets] Leaving special directives aside, " +"[application]*rsyslog* handles messages as defined by *rules* that consist " +"of a filter condition and an action to be performed if the condition is " +"true. With a traditionally written `/etc/rsyslog.conf` file, all rules are " +"evaluated in order of appearance for every input message. This process " +"starts with the first rule and continues until all rules have been processed " +"or until the message is discarded by one of the rules." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:764 +msgid "" +"However, rules can be grouped into sequences called _rulesets_. With " +"rulesets, you can limit the effect of certain rules only to selected inputs " +"or enhance the performance of [application]*rsyslog* by defining a distinct " +"set of actions bound to a specific input. In other words, filter conditions " +"that will be inevitably evaluated as false for certain types of messages can " +"be skipped. The legacy ruleset definition in `/etc/rsyslog.conf` can look as " +"follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:771 +#, no-wrap +msgid "" +"$RuleSet _rulesetname_\n" +"_rule_\n" +"_rule2_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:774 +msgid "" +"The rule ends when another rule is defined, or the default ruleset is called " +"as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:777 +#, no-wrap +msgid "$RuleSet RSYSLOG_DefaultRuleset\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:780 +msgid "" +"With the new configuration format in rsyslog 7, the `input()` and " +"`ruleset()` statements are reserved for this operation. The new format " +"ruleset definition in `/etc/rsyslog.conf` can look as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:790 +#, no-wrap +msgid "" +"ruleset(name=\"pass:attributes[{blank}]_rulesetname_pass:attributes[{blank}]\") " +"{\n" +" _rule_\n" +" _rule2_\n" +" call _rulesetname2_\n" +" …\n" +"}\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:794 +msgid "" +"Replace _rulesetname_ with an identifier for your ruleset. The ruleset name " +"cannot start with `RSYSLOG_` since this namespace is reserved for use by " +"[application]*rsyslog*. `RSYSLOG_DefaultRuleset` then defines the default " +"set of rules to be performed if the message has no other ruleset " +"assigned. With _rule_ and _rule2_ you can define rules in filter-action " +"format mentioned above. With the `call` parameter, you can nest rulesets by " +"calling them from inside other ruleset blocks." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:796 +msgid "After creating a ruleset, you need to specify what input it will apply to:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:800 +#, no-wrap +msgid "" +"input(type=\"pass:quotes[_input_type_]\" port=\"pass:quotes[_port_num_]\" " +"ruleset=\"pass:quotes[_rulesetname_]\");\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:803 +msgid "" +"Here you can identify an input message by _input_type_, which is an input " +"module that gathered the message, or by _port_num_ – the port " +"number. Other parameters such as *file* or *tag* can be specified for " +"`input()`. Replace _rulesetname_ with a name of the ruleset to be evaluated " +"against the message. In case an input message is not explicitly bound to a " +"ruleset, the default ruleset is triggered." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:805 +msgid "" +"You can also use the legacy format to define rulesets, for more information " +"see " +"xref:Viewing_and_Managing_Log_Files.adoc#brid-Log_Files-Resources-Online[Online " +"Documentation]." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:807 +#, no-wrap +msgid "Using rulesets" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:811 +msgid "" +"The following rulesets ensure different handling of remote messages coming " +"from different ports. Add the following into `/etc/rsyslog.conf`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:817 +#, no-wrap +msgid "" +"ruleset(name=\"remote-10514\") {\n" +" action(type=\"omfile\" file=\"/var/log/remote-10514\")\n" +"}\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:822 +#, no-wrap +msgid "" +"ruleset(name=\"remote-10515\") {\n" +" cron.* action(type=\"omfile\" file=\"/var/log/remote-10515-cron\")\n" +" mail.* action(type=\"omfile\" file=\"/var/log/remote-10515-mail\")\n" +"}\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:825 +#, no-wrap +msgid "" +"input(type=\"imtcp\" port=\"10514\" ruleset=\"remote-10514\");\n" +"input(type=\"imtcp\" port=\"10515\" ruleset=\"remote-10515\");\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:829 +msgid "" +"Rulesets shown in the above example define log destinations for the remote " +"input from two ports, in case of 10515, messages are sorted according to the " +"facility. Then, the TCP input is enabled and bound to rulesets. Note that " +"you must load the required modules (imtcp) for this configuration to work." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:833 +#, no-wrap +msgid "Compatibility with syslogd" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:836 +msgid "" +"From [application]*rsyslog* version 6, compatibility mode specified via the " +"[option]`-c` option has been removed. Also, the syslogd-style command-line " +"options are deprecated and configuring [application]*rsyslog* through these " +"command-line options should be avoided. However, you can use several " +"templates and directives to configure `rsyslogd` to emulate syslogd-like " +"behavior." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:838 +msgid "" +"For more information on various `rsyslogd` options, see the " +"`rsyslogd(8)`pass:attributes[{blank}]manual page." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:840 +#, no-wrap +msgid "Working with Queues in Rsyslog" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:843 +msgid "" +"indexterm:[rsyslog,queues] Queues are used to pass content, mostly syslog " +"messages, between components of [application]*rsyslog*. With queues, rsyslog " +"is capable of processing multiple messages simultaneously and to apply " +"several actions to a single message at once. The data flow inside " +"[application]*rsyslog* can be illustrated as follows:" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:845 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:847 +#, no-wrap +msgid "Message Flow in Rsyslog" +msgstr "" + +#. type: Target for macro image +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:847 +#, no-wrap +msgid "rsyslog_message_flow.png" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:850 +msgid "" +"Whenever [application]*rsyslog* receives a message, it passes this message " +"to the preprocessor and then places it into the _main message " +"queue_. Messages wait there to be dequeued and passed to the _rule " +"processor_." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:852 +msgid "" +"The *rule processor* is a parsing and filtering engine. Here, the rules " +"defined in `/etc/rsyslog.conf` are applied. Based on these rules, the rule " +"processor evaluates which actions are to be performed. Each action has its " +"own action queue. Messages are passed through this queue to the respective " +"action processor which creates the final output. Note that at this point, " +"several actions can run simultaneously on one message. For this purpose, a " +"message is duplicated and passed to multiple action processors." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:854 +msgid "" +"Only one queue per action is possible. Depending on configuration, the " +"messages can be sent right to the action processor without action " +"queuing. This is the behavior of *direct queues* (see below). In case the " +"output action fails, the action processor notifies the action queue, which " +"then takes an unprocessed element back and after some time interval, the " +"action is attempted again." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:856 +msgid "" +"To sum up, there are two positions where queues stand in " +"[application]*rsyslog*: either in front of the rule processor as a single " +"*main message queue* or in front of various types of output actions as " +"*action queues*. Queues provide two main advantages that both lead to " +"increased performance of message processing:" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:858 +msgid "" +"they serve as buffers that *decouple* producers and consumers in the " +"structure of [application]*rsyslog*" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:860 +msgid "they allow for *parallelization* of actions performed on messages" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:862 +msgid "" +"Apart from this, queues can be configured with several directives to provide " +"optimal performance for your system. These configuration options are covered " +"in the following sections." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:867 +msgid "" +"If an output plug-in is unable to deliver a message, it is stored in the " +"preceding message queue. If the queue fills, the inputs block until it is no " +"longer full. This will prevent new messages from being logged via the " +"blocked queue. In the absence of separate action queues this can have severe " +"consequences, such as preventing `SSH` logging, which in turn can prevent " +"`SSH` access. Therefore it is advised to use dedicated action queues for " +"outputs which are forwarded over a network or to a database." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:871 +#, no-wrap +msgid "Defining Queues" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:874 +msgid "" +"Based on where the messages are stored, there are several types of queues: " +"*direct*, *in-memory*, *disk*, and *disk-assisted in-memory* queues that are " +"most widely used. You can choose one of these types for the main message " +"queue and also for action queues. Add the following into " +"`/etc/rsyslog.conf`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:878 +#, no-wrap +msgid "$pass:quotes[_object_]QueueType pass:quotes[_queue_type_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:881 +msgid "" +"Here, you can apply the setting for the main message queue (replace _object_ " +"with [option]`MainMsg`) or for an action queue (replace _object_ with " +"[option]`Action`). Replace _queue_type_ with one of `direct`, `linkedlist` " +"or `fixedarray` (which are in-memory queues), or `disk`." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:883 +msgid "" +"The default setting for a main message queue is the FixedArray queue with a " +"limit of 10,000 messages. Action queues are by default set as Direct queues." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:884 +#, no-wrap +msgid "Direct Queues" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:886 +msgid "" +"For many simple operations, such as when writing output to a local file, " +"building a queue in front of an action is not needed. To avoid queuing, use:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:890 +#, no-wrap +msgid "$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueType Direct\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:893 +msgid "" +"Replace _object_ with [option]`MainMsg` or with [option]`Action` to use this " +"option to the main message queue or for an action queue respectively. With " +"direct queue, messages are passed directly and immediately from the producer " +"to the consumer." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:894 +#, no-wrap +msgid "Disk Queues" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:896 +msgid "" +"Disk queues store messages strictly on a hard drive, which makes them highly " +"reliable but also the slowest of all possible queuing modes. This mode can " +"be used to prevent the loss of highly important log data. However, disk " +"queues are not recommended in most use cases. To set a disk queue, type the " +"following into `/etc/rsyslog.conf`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:900 +#, no-wrap +msgid "$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueType Disk\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:903 +msgid "" +"Replace _object_ with [option]`MainMsg` or with [option]`Action` to use this " +"option to the main message queue or for an action queue respectively. Disk " +"queues are written in parts, with a default size 10 Mb. This default size " +"can be modified with the following configuration directive:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:907 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueMaxFileSize " +"_size_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:910 +msgid "" +"where _size_ represents the specified size of disk queue part. The defined " +"size limit is not restrictive, [application]*rsyslog* always writes one " +"complete queue entry, even if it violates the size limit. Each part of a " +"disk queue matches with an individual file. The naming directive for these " +"files looks as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:914 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueFilename " +"_name_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:917 +msgid "" +"This sets a _name_ prefix for the file followed by a 7-digit number starting " +"at one and incremented for each file." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:918 +#, no-wrap +msgid "In-memory Queues" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:920 +msgid "" +"With in-memory queue, the enqueued messages are held in memory which makes " +"the process very fast. The queued data is lost if the computer is power " +"cycled or shut down. However, you can use the " +"[option]`$ActionQueueSaveOnShutdown` setting to save the data before " +"shutdown. There are two types of in-memory queues:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:922 +#, no-wrap +msgid "" +"*FixedArray* queue — the default mode for the main message queue, with " +"a limit of 10,000 elements. This type of queue uses a fixed, pre-allocated " +"array that holds pointers to queue elements. Due to these pointers, even if " +"the queue is empty a certain amount of memory is consumed. However, " +"FixedArray offers the best run time performance and is optimal when you " +"expect a relatively low number of queued messages and high performance.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:924 +#, no-wrap +msgid "" +"*LinkedList* queue — here, all structures are dynamically allocated in " +"a linked list, thus the memory is allocated only when needed. LinkedList " +"queues handle occasional message bursts very well.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:926 +msgid "" +"In general, use LinkedList queues when in doubt. Compared to FixedArray, it " +"consumes less memory and lowers the processing overhead." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:928 +msgid "Use the following syntax to configure in-memory queues:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:932 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueType " +"LinkedList\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:937 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueType " +"FixedArray\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:940 +msgid "" +"Replace _object_ with [option]`MainMsg` or with [option]`Action` to use this " +"option to the main message queue or for an action queue respectively." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:941 +#, no-wrap +msgid "Disk-Assisted In-memory Queues" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:943 +msgid "" +"Both disk and in-memory queues have their advantages and " +"[application]*rsyslog* lets you combine them in *disk-assisted in-memory " +"queues*. To do so, configure a normal in-memory queue and then add the " +"[option]`$objectQueueFileName` directive to define a file name for disk " +"assistance. This queue then becomes *disk-assisted*, which means it couples " +"an in-memory queue with a disk queue to work in tandem." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:945 +msgid "" +"The disk queue is activated if the in-memory queue is full or needs to " +"persist after shutdown. With a disk-assisted queue, you can set both " +"disk-specific and in-memory specific configuration parameters. This type of " +"queue is probably the most commonly used, it is especially useful for " +"potentially long-running and unreliable actions." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:947 +msgid "" +"To specify the functioning of a disk-assisted in-memory queue, use the " +"so-called *watermarks*:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:951 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1047 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueHighWatermark " +"_number_\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:956 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueLowWatermark " +"_number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:959 +msgid "" +"Replace _object_ with [option]`MainMsg` or with [option]`Action` to use this " +"option to the main message queue or for an action queue " +"respectively. Replace _number_ with a number of enqueued messages. When an " +"in-memory queue reaches the number defined by the high watermark, it starts " +"writing messages to disk and continues until the in-memory queue size drops " +"to the number defined with the low watermark. Correctly set watermarks " +"minimize unnecessary disk writes, but also leave memory space for message " +"bursts since writing to disk files is rather lengthy. Therefore, the high " +"watermark must be lower than the whole queue capacity set with " +"*$objectQueueSize*. The difference between the high watermark and the " +"overall queue size is a spare memory buffer reserved for message bursts. On " +"the other hand, setting the high watermark too low will turn on disk " +"assistance unnecessarily often." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:961 +#, no-wrap +msgid "Reliable Forwarding of Log Messages to a Server" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:965 +msgid "" +"Rsyslog is often used to maintain a centralized logging system, where log " +"messages are forwarded to a server over the network. To avoid message loss " +"when the server is not available, it is advisable to configure an action " +"queue for the forwarding action. This way, messages that failed to be sent " +"are stored locally until the server is reachable again. Note that such " +"queues are not configurable for connections using the `UDP` protocol. To " +"establish a fully reliable connection, for example when your logging server " +"is outside of your private network, consider using the RELP protocol " +"described in xref:Viewing_and_Managing_Log_Files.adoc#s2-using_RELP[Using " +"RELP]." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:967 +#, no-wrap +msgid "Forwarding To a Single Server" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:969 +msgid "" +"Suppose the task is to forward log messages from the system to a server with " +"host name *example.com*, and to configure an action queue to buffer the " +"messages in case of a server outage. To do so, perform the following steps:" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:971 +msgid "Create a working directory to store the queue files. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:975 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1014 +#, no-wrap +msgid "~]#{nbsp}mkdir pass:quotes[`/rsyslog/work/`]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:978 +msgid "" +"Use the following configuration in `/etc/rsyslog.conf` or create a file with " +"the following content in the `/etc/rsyslog.d/` directory:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:981 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1020 +#, no-wrap +msgid "$WorkDirectory /rsyslog/work\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:987 +#, no-wrap +msgid "" +"$ActionQueueType LinkedList\n" +"$ActionQueueFileName example_fwd\n" +"$ActionResumeRetryCount -1\n" +"$ActionQueueSaveOnShutdown on\n" +"*.* @@example.com:18\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:990 +msgid "Where:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:992 +msgid "" +"the `/rsyslog/work/` directory created in the previous step is marked as a " +"working directory," +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:994 +msgid "[option]`$ActionQueueType` enables a LinkedList in-memory queue," +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:996 +msgid "" +"[option]`$ActionFileName` defines a disk storage, in this case the backup " +"files are created in the `/rsyslog/work/` directory with the *example_fwd* " +"prefix," +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:998 +msgid "" +"the [option]`$ActionResumeRetryCount -1` setting prevents rsyslog form " +"dropping messages when retrying to connect if server is not responding," +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1000 +msgid "" +"enabled [option]`$ActionQueueSaveOnShutdown` saves in-memory data if rsyslog " +"shuts down," +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1002 +msgid "" +"the last line forwards all received messages to the logging server, port " +"specification is optional." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1004 +msgid "" +"With the above configuration, rsyslog keeps messages in memory if the remote " +"server is not reachable. A file on disk is created only if rsyslog runs out " +"of the configured memory queue space or needs to shut down, which benefits " +"the system performance." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1006 +#, no-wrap +msgid "Forwarding To Multiple Servers" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1008 +msgid "" +"The process of forwarding log messages to multiple servers is similar to the " +"previous procedure:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1010 +msgid "" +"Create a working directory for rsyslog to store the queue files. For " +"example:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1017 +msgid "" +"Each destination server requires a separate forwarding rule, action queue " +"specification, and backup file on disk. For example, use the following " +"configuration in `/etc/rsyslog.conf` or create a file with the following " +"content in the `/etc/rsyslog.d/` directory:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1026 +#, no-wrap +msgid "" +"$ActionQueueType LinkedList\n" +"$ActionQueueFileName example_fwd1\n" +"$ActionResumeRetryCount -1\n" +"$ActionQueueSaveOnShutdown on\n" +"*.* @@example1.com\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1032 +#, no-wrap +msgid "" +"$ActionQueueType LinkedList\n" +"$ActionQueueFileName example_fwd2\n" +"$ActionResumeRetryCount -1\n" +"$ActionQueueSaveOnShutdown on\n" +"*.* @@example2.com\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1037 +#, no-wrap +msgid "Managing Queues" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1040 +msgid "" +"All types of queues can be further configured to match your " +"requirements. You can use several directives to modify both action queues " +"and the main message queue. Currently, there are more than 20 queue " +"parameters available, see " +"xref:Viewing_and_Managing_Log_Files.adoc#brid-Log_Files-Resources-Online[Online " +"Documentation]. Some of these settings are used commonly, others, such as " +"worker thread management, provide closer control over the queue behavior and " +"are reserved for advanced users. With advanced settings, you can optimize " +"[application]*rsyslog*pass:attributes[{blank}]'s performance, schedule " +"queuing, or modify the behavior of a queue on system shutdown." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1041 +#, no-wrap +msgid "Limiting Queue Size" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1043 +msgid "" +"You can limit the number of messages that queue can contain with the " +"following setting:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1050 +msgid "" +"Replace _object_ with [option]`MainMsg` or with [option]`Action` to use this " +"option to the main message queue or for an action queue " +"respectively. Replace _number_ with a number of enqueued messages. You can " +"set the queue size only as the number of messages, not as their actual " +"memory size. The default queue size is 10,000 messages for the main message " +"queue and ruleset queues, and 1000 for action queues." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1052 +msgid "" +"Disk assisted queues are unlimited by default and can not be restricted with " +"this directive, but you can reserve them physical disk space in bytes with " +"the following settings:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1056 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueMaxDiscSpace " +"_number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1059 +msgid "" +"Replace _object_ with [option]`MainMsg` or with [option]`Action`. When the " +"size limit specified by _number_ is hit, messages are discarded until " +"sufficient amount of space is freed by dequeued messages." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1060 +#, no-wrap +msgid "Discarding Messages" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1062 +msgid "" +"When a queue reaches a certain number of messages, you can discard less " +"important messages in order to save space in the queue for entries of higher " +"priority. The threshold that launches the discarding process can be set with " +"the so-called *discard mark*:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1066 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueDiscardMark " +"_number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1069 +msgid "" +"Replace _object_ with [option]`MainMsg` or with [option]`Action` to use this " +"option to the main message queue or for an action queue respectively. Here, " +"_number_ stands for a number of messages that have to be in the queue to " +"start the discarding process. To define which messages to discard, use:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1073 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueDiscardSeverity " +"_priority_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1076 +msgid "" +"Replace _priority_ with one of the following keywords (or with a number): " +"[command]#debug# (7), [command]#info# (6), [command]#notice# (5), " +"[command]#warning# (4), [command]#err# (3), [command]#crit# (2), " +"[command]#alert# (1), and [command]#emerg# (0). With this setting, both " +"newly incoming and already queued messages with lower than defined priority " +"are erased from the queue immediately after the discard mark is reached." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1077 +#, no-wrap +msgid "Using Timeframes" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1079 +msgid "" +"You can configure [application]*rsyslog* to process queues during a specific " +"time period. With this option you can, for example, transfer some processing " +"into off-peak hours. To define a time frame, use the following syntax:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1083 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueDequeueTimeBegin " +"_hour_\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1088 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueDequeueTimeEnd " +"_hour_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1091 +msgid "" +"With _hour_ you can specify hours that bound your time frame. Use the " +"24-hour format without minutes." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1092 +#, no-wrap +msgid "Configuring Worker Threads" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1094 +msgid "" +"A _worker thread_ performs a specified action on the enqueued message. For " +"example, in the main message queue, a worker task is to apply filter logic " +"to each incoming message and enqueue them to the relevant action " +"queues. When a message arrives, a worker thread is started " +"automatically. When the number of messages reaches a certain number, another " +"worker thread is turned on. To specify this number, use:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1098 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueWorkerThreadMinimumMessages " +"_number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1101 +msgid "" +"Replace _number_ with a number of messages that will trigger a supplemental " +"worker thread. For example, with _number_ set to 100, a new worker thread is " +"started when more than 100 messages arrive. When more than 200 messages " +"arrive, the third worker thread starts and so on. However, too many working " +"threads running in parallel becomes ineffective, so you can limit the " +"maximum number of them by using:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1105 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueWorkerThreads " +"_number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1108 +msgid "" +"where _number_ stands for a maximum number of working threads that can run " +"in parallel. For the main message queue, the default limit is 1 thread. Once " +"a working thread has been started, it keeps running until an inactivity " +"timeout appears. To set the length of timeout, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1112 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueWorkerTimeoutThreadShutdown " +"_time_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1115 +msgid "" +"Replace _time_ with the duration set in milliseconds. Without this setting, " +"a zero timeout is applied and a worker thread is terminated immediately when " +"it runs out of messages. If you specify _time_ as `-1`, no thread will be " +"closed." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1116 +#, no-wrap +msgid "Batch Dequeuing" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1118 +msgid "" +"To increase performance, you can configure [application]*rsyslog* to dequeue " +"multiple messages at once. To set the upper limit for such dequeueing, use:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1122 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueDequeueBatchSize " +"_number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1125 +msgid "" +"Replace _number_ with the maximum number of messages that can be dequeued at " +"once. Note that a higher setting combined with a higher number of permitted " +"working threads results in greater memory consumption." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1126 +#, no-wrap +msgid "Terminating Queues" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1128 +msgid "" +"When terminating a queue that still contains messages, you can try to " +"minimize the data loss by specifying a time interval for worker threads to " +"finish the queue processing:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1132 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueTimeoutShutdown " +"_time_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1135 +msgid "" +"Specify _time_ in milliseconds. If after that period there are still some " +"enqueued messages, workers finish the current data element and then " +"terminate. Unprocessed messages are therefore lost. Another time interval " +"can be set for workers to finish the final element:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1139 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueTimeoutActionCompletion " +"_time_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1142 +msgid "" +"In case this timeout expires, any remaining workers are shut down. To save " +"data at shutdown, use:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1146 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueTimeoutSaveOnShutdown " +"_time_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1149 +msgid "" +"If set, all queue elements are saved to disk before [application]*rsyslog* " +"terminates." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1151 +#, no-wrap +msgid "Configuring rsyslog on a Logging Server" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1154 +msgid "" +"The `rsyslog` service provides facilities both for running a logging server " +"and for configuring individual systems to send their log files to the " +"logging server. See " +"xref:Viewing_and_Managing_Log_Files.adoc#ex-net_forwarding_with_queue[Reliable " +"Forwarding of Log Messages to a Server] for information on client rsyslog " +"configuration." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1156 +msgid "" +"The `rsyslog` service must be installed on the system that you intend to use " +"as a logging server and all systems that will be configured to send logs to " +"it. Rsyslog is installed by default in {MAJOROSVER}. If required, to ensure " +"that it is, enter the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1160 +#, no-wrap +msgid "~]#{nbsp}dnf install rsyslog\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1163 +msgid "" +"The steps in this procedure must be followed on the system that you intend " +"to use as your logging server. All steps in this procedure must be made as " +"the `root` user:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1165 +msgid "Configure the firewall to allow `rsyslog` `TCP` traffic." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1167 +msgid "" +"The default port for `rsyslog` `TCP` traffic is `514`. To allow `TCP` " +"traffic on this port, enter a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1172 +#, no-wrap +msgid "" +"~]#{nbsp}firewall-cmd --zone=zone --add-port=514/tcp\n" +"success\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1175 +msgid "Where _zone_ is the zone of the interface to use." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1177 +msgid "Open the `/etc/rsyslog.conf` file in a text editor and proceed as follows:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1179 +msgid "" +"Add these lines below the modules section but above the `Provides UDP syslog " +"reception` section:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1182 +#, no-wrap +msgid "# Define templates before the rules that use them\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1186 +#, no-wrap +msgid "" +"### Per-Host Templates for Remote Systems ###\n" +"$template TmplAuthpriv, " +"\"/var/log/remote/auth/%HOSTNAME%/%PROGRAMNAME:::secpath-replace%.log\"\n" +"$template TmplMsg, " +"\"/var/log/remote/msg/%HOSTNAME%/%PROGRAMNAME:::secpath-replace%.log\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1189 +msgid "" +"Replace the default `Provides TCP syslog reception` section with the " +"following:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1200 +#, no-wrap +msgid "" +"# Provides TCP syslog reception\n" +"$ModLoad imtcp\n" +"# Adding this ruleset to process remote messages\n" +"$RuleSet remote1\n" +"authpriv.* ?TmplAuthpriv\n" +"*.info;mail.none;authpriv.none;cron.none ?TmplMsg\n" +"$RuleSet RSYSLOG_DefaultRuleset #End the rule set by switching back to the " +"default rule set\n" +"$InputTCPServerBindRuleset remote1 #Define a new input and bind it to the " +"\"remote1\" rule set\n" +"$InputTCPServerRun 514\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1203 +msgid "Save the changes to the `/etc/rsyslog.conf` file." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1205 +msgid "" +"The `rsyslog` service must be running on both the logging server and the " +"systems attempting to log to it." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1207 +msgid "Use the [command]#systemctl# command to start the `rsyslog` service." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1211 +#, no-wrap +msgid "~]#{nbsp}pass:quotes[`systemctl start rsyslog`]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1214 +msgid "" +"To ensure the `rsyslog` service starts automatically in future, enter the " +"following command as root:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1218 +#, no-wrap +msgid "~]#{nbsp}pass:quotes[`systemctl enable rsyslog`]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1221 +msgid "" +"Your log server is now configured to receive and store log files from the " +"other systems in your environment." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1223 +#, no-wrap +msgid "Using The New Template Syntax on a Logging Server" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1226 +msgid "" +"Rsyslog 7 has a number of different templates styles. The string template " +"most closely resembles the legacy format. Reproducing the templates from the " +"example above using the string format would look as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1232 +#, no-wrap +msgid "" +"template(name=\"TmplAuthpriv\" type=\"string\"\n" +" " +"string=\"/var/log/remote/auth/%HOSTNAME%/%PROGRAMNAME:::secpath-replace%.log\"\n" +" )\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1236 +#, no-wrap +msgid "" +"template(name=\"TmplMsg\" type=\"string\"\n" +" " +"string=\"/var/log/remote/msg/%HOSTNAME%/%PROGRAMNAME:::secpath-replace%.log\"\n" +" )\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1240 +msgid "These templates can also be written in the list format as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1251 +#, no-wrap +msgid "" +"template(name=\"TmplAuthpriv\" type=\"list\") {\n" +" constant(value=\"/var/log/remote/auth/\")\n" +" property(name=\"hostname\")\n" +" constant(value=\"/\")\n" +" property(name=\"programname\" SecurePath=\"replace\")\n" +" constant(value=\".log\")\n" +" }\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1262 +#, no-wrap +msgid "" +"template(name=\"TmplMsg\" type=\"list\") {\n" +" constant(value=\"/var/log/remote/msg/\")\n" +" property(name=\"hostname\")\n" +" constant(value=\"/\")\n" +" property(name=\"programname\" SecurePath=\"replace\")\n" +" constant(value=\".log\")\n" +" }\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1265 +msgid "" +"This template text format might be easier to read for those new to rsyslog " +"and therefore can be easier to adapt as requirements change." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1267 +msgid "" +"To complete the change to the new syntax, we need to reproduce the module " +"load command, add a rule set, and then bind the rule set to the protocol, " +"port, and ruleset:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1271 +#, no-wrap +msgid "module(load=\"imtcp\")\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1276 +#, no-wrap +msgid "" +"ruleset(name=\"remote1\"){\n" +" authpriv.* action(type=\"omfile\" DynaFile=\"TmplAuthpriv\")\n" +" *.info;mail.none;authpriv.none;cron.none action(type=\"omfile\" " +"DynaFile=\"TmplMsg\")\n" +"}\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1278 +#, no-wrap +msgid "input(type=\"imtcp\" port=\"514\" ruleset=\"remote1\")\n" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1281 +#, no-wrap +msgid "Using Rsyslog Modules" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1284 +msgid "" +"indexterm:[rsyslog,modules] Due to its modular design, " +"[application]*rsyslog* offers a variety of _modules_ which provide " +"additional functionality. Note that modules can be written by third " +"parties. Most modules provide additional inputs (see *Input Modules* below) " +"or outputs (see *Output Modules* below). Other modules provide special " +"functionality specific to each module. The modules may provide additional " +"configuration directives that become available after a module is loaded. To " +"load a module, use the following syntax:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1289 +#, no-wrap +msgid "$ModLoad _MODULE_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1293 +msgid "" +"where [option]`$ModLoad` is the global directive that loads the specified " +"module and _MODULE_ represents your desired module. For example, if you want " +"to load the Text File Input Module ([command]#imfile#) that enables " +"[application]*rsyslog* to convert any standard text files into syslog " +"messages, specify the following line in the `/etc/rsyslog.conf` " +"configuration file:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1298 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1379 +#, no-wrap +msgid "$ModLoad imfile\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1302 +msgid "" +"[application]*rsyslog* offers a number of modules which are split into the " +"following main categories:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1304 +msgid "" +"Input Modules — Input modules gather messages from various sources. The name " +"of an input module always starts with the `im` prefix, such as " +"[command]#imfile# and [command]#imjournal#." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1306 +msgid "" +"Output Modules — Output modules provide a facility to issue message to " +"various targets such as sending across a network, storing in a database, or " +"encrypting. The name of an output module always starts with the `om` prefix, " +"such as [command]#omsnmp#, [command]#omrelp#, and so on." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1308 +msgid "" +"Parser Modules — These modules are useful in creating custom parsing rules " +"or to parse malformed messages. With moderate knowledge of the C programming " +"language, you can create your own message parser. The name of a parser " +"module always starts with the `pm` prefix, such as [command]#pmrfc5424#, " +"[command]#pmrfc3164#, and so on." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1310 +msgid "" +"Message Modification Modules — Message modification modules change content " +"of syslog messages. Names of these modules start with the `mm` " +"prefix. Message Modification Modules such as [command]#mmanon#, " +"[command]#mmnormalize#, or [command]#mmjsonparse# are used for anonymization " +"or normalization of messages." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1312 +msgid "" +"String Generator Modules — String generator modules generate strings based " +"on the message content and strongly cooperate with the template feature " +"provided by [application]*rsyslog*. For more information on templates, see " +"xref:Viewing_and_Managing_Log_Files.adoc#s2-Templates[Templates]. The name " +"of a string generator module always starts with the `sm` prefix, such as " +"[command]#smfile# or [command]#smtradfile#." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1314 +msgid "" +"Library Modules — Library modules provide functionality for other loadable " +"modules. These modules are loaded automatically by [application]*rsyslog* " +"when needed and cannot be configured by the user." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1316 +msgid "" +"A comprehensive list of all available modules and their detailed description " +"can be found at " +"link:++https://www.rsyslog.com/doc/rsyslog_conf_modules.html/++[https://www.rsyslog.com/doc/rsyslog_conf_modules.html]." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1321 +msgid "" +"Note that when [application]*rsyslog* loads any modules, it provides them " +"with access to some of its functions and data. This poses a possible " +"security threat. To minimize security risks, use trustworthy modules only." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1325 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1371 +#, no-wrap +msgid "Importing Text Files" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1328 +msgid "" +"The Text File Input Module, abbreviated as [command]#imfile#, enables " +"[application]*rsyslog* to convert any text file into a stream of syslog " +"messages. You can use [command]#imfile# to import log messages from " +"applications that create their own text file logs. To load " +"[command]#imfile#, add the following into `/etc/rsyslog.conf`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1334 +#, no-wrap +msgid "" +"$ModLoad imfile\n" +"$InputFilePollInterval _int_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1338 +msgid "" +"It is sufficient to load [command]#imfile# once, even when importing " +"multiple files. The *$InputFilePollInterval* global directive specifies how " +"often [application]*rsyslog* checks for changes in connected text files. The " +"default interval is 10 seconds, to change it, replace _int_ with a time " +"interval specified in seconds." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1340 +msgid "" +"To identify the text files to import, use the following syntax in " +"`/etc/rsyslog.conf`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1351 +#, no-wrap +msgid "" +"# File 1\n" +"$InputFileName pass:quotes[_path_to_file_]\n" +"$InputFileTag pass:quotes[_tag:_]\n" +"$InputFileStateFile pass:quotes[_state_file_name_]\n" +"$InputFileSeverity pass:quotes[_severity_]\n" +"$InputFileFacility pass:quotes[_facility_]\n" +"$InputRunFileMonitor\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1355 +#, no-wrap +msgid "" +"# File 2\n" +"$InputFileName pass:quotes[_path_to_file2_]\n" +"...\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1359 +msgid "Four settings are required to specify an input text file:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1361 +msgid "replace _path_to_file_ with a path to the text file." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1363 +msgid "replace _tag:_ with a tag name for this message." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1365 +msgid "" +"replace _state_file_name_ with a unique name for the *state file*. *State " +"files*, which are stored in the rsyslog working directory, keep cursors for " +"the monitored files, marking what partition has already been processed. If " +"you delete them, whole files will be read in again. Make sure that you " +"specify a name that does not already exist." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1367 +msgid "" +"add the *$InputRunFileMonitor* directive that enables the file " +"monitoring. Without this setting, the text file will be ignored." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1369 +msgid "" +"Apart from the required directives, there are several other settings that " +"can be applied on the text input. Set the severity of imported messages by " +"replacing _severity_ with an appropriate keyword. Replace _facility_ with a " +"keyword to define the subsystem that produced the message. The keywords for " +"severity and facility are the same as those used in facility/priority-based " +"filters, see xref:Viewing_and_Managing_Log_Files.adoc#s2-Filters[Filters]." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1375 +msgid "" +"The Apache HTTP server creates log files in text format. To apply the " +"processing capabilities of [application]*rsyslog* to apache error messages, " +"first use the [command]#imfile# module to import the messages. Add the " +"following into `/etc/rsyslog.conf`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1384 +#, no-wrap +msgid "" +"$InputFileName /var/log/httpd/error_log\n" +"$InputFileTag apache-error:\n" +"$InputFileStateFile state-apache-error\n" +"$InputRunFileMonitor\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1390 +#, no-wrap +msgid "Exporting Messages to a Database" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1393 +msgid "" +"Processing of log data can be faster and more convenient when performed in a " +"database rather than with text files. Based on the type of DBMS used, choose " +"from various output modules such as [command]#ommysql#, [command]#ompgsql#, " +"[command]#omoracle#, or [command]#ommongodb#. As an alternative, use the " +"generic [command]#omlibdbi# output module that relies on the `libdbi` " +"library. The [command]#omlibdbi# module supports database systems " +"Firebird/Interbase, MS SQL, Sybase, SQLite, Ingres, Oracle, mSQL, MySQL, and " +"PostgreSQL." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1395 +#, no-wrap +msgid "Exporting Rsyslog Messages to a Database" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1399 +msgid "" +"To store the rsyslog messages in a MySQL database, add the following into " +"`/etc/rsyslog.conf`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1403 +#, no-wrap +msgid "$ModLoad ommysql\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1406 +#, no-wrap +msgid "" +"$ActionOmmysqlServerPort 1234\n" +"*.* " +":ommysql:database-server,database-name,database-userid,database-password\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1410 +msgid "" +"First, the output module is loaded, then the communication port is " +"specified. Additional information, such as name of the server and the " +"database, and authentication data, is specified on the last line of the " +"above example." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1414 +#, no-wrap +msgid "Enabling Encrypted Transport" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1417 +msgid "" +"Confidentiality and integrity in network transmissions can be provided by " +"either the *TLS* or *GSSAPI* encryption protocol." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1419 +#, no-wrap +msgid "" +"*Transport Layer Security* (TLS) is a cryptographic protocol designed to " +"provide communication security over the network. When using TLS, rsyslog " +"messages are encrypted before sending, and mutual authentication exists " +"between the sender and receiver.\n" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1421 +#, no-wrap +msgid "" +"*Generic Security Service API* (GSSAPI) is an application programming " +"interface for programs to access security services. To use it in connection " +"with [application]*rsyslog* you must have a functioning " +"[application]*Kerberos* environment.\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1423 +#, no-wrap +msgid "Using RELP" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1426 +#, no-wrap +msgid "" +"*Reliable Event Logging Protocol* (RELP) is a networking protocol for data " +"logging in computer networks. It is designed to provide reliable delivery of " +"event messages, which makes it useful in environments where message loss is " +"not acceptable.\n" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1428 +#, no-wrap +msgid "Interaction of Rsyslog and Journal" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1431 +msgid "" +"As mentioned above, [application]*Rsyslog* and [application]*Journal*, the " +"two logging applications present on your system, have several distinctive " +"features that make them suitable for specific use cases. In many situations " +"it is useful to combine their capabilities, for example to create structured " +"messages and store them in a file database (see " +"xref:Viewing_and_Managing_Log_Files.adoc#s1-structured_logging_with_rsyslog[Structured " +"Logging with Rsyslog]). A communication interface needed for this " +"cooperation is provided by input and output modules on the side of " +"[application]*Rsyslog* and by the " +"[application]*Journal*pass:attributes[{blank}]'s communication socket." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1433 +msgid "" +"By default, `rsyslogd` uses the `imjournal` module as a default input mode " +"for journal files. With this module, you import not only the messages but " +"also the structured data provided by `journald`. Also, older data can be " +"imported from `journald` (unless forbidden with the " +"[option]`$ImjournalIgnorePreviousMessages` directive). See " +"xref:Viewing_and_Managing_Log_Files.adoc#s2-importing_data_from_journal[Importing " +"Data from Journal] for basic configuration of `imjournal`." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1435 +msgid "" +"As an alternative, configure `rsyslogd` to read from the socket provided by " +"`journal` as an output for syslog-based applications. The path to the socket " +"is `/run/systemd/journal/syslog`. Use this option when you want to maintain " +"plain rsyslog messages. Compared to `imjournal` the socket input currently " +"offers more features, such as ruleset binding or filtering. To import " +"[application]*Journal* data through the socket, use the following " +"configuration in `/etc/rsyslog.conf`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1441 +#, no-wrap +msgid "" +"$ModLoad imuxsock\n" +"$OmitLocalLogging off\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1445 +msgid "" +"The above syntax loads the `imuxsock` module and turns off the " +"[option]`$OmitLocalLogging` directive, which enables the import through the " +"system socket. The path to this socket is specified separately in " +"`/etc/rsyslog.d/listen.conf` as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1450 +#, no-wrap +msgid "$SystemLogSocketName /run/systemd/journal/syslog\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1454 +msgid "" +"You can also output messages from [application]*Rsyslog* to " +"[application]*Journal* with the `omjournal` module. Configure the output in " +"`/etc/rsyslog.conf` as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1458 +#, no-wrap +msgid "$ModLoad omjournal\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1460 +#, no-wrap +msgid "*.* :omjournal:\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1464 +msgid "" +"For instance, the following configuration forwards all received messages on " +"tcp port 10514 to the Journal:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1469 +#, no-wrap +msgid "" +"$ModLoad imtcp\n" +"$ModLoad omjournal\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1472 +#, no-wrap +msgid "" +"$RuleSet remote\n" +"*.* :omjournal:\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1475 +#, no-wrap +msgid "" +"$InputTCPServerBindRuleset remote\n" +"$InputTCPServerRun 10514\n" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1479 +#, no-wrap +msgid "Structured Logging with Rsyslog" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1482 +msgid "" +"On systems that produce large amounts of log data, it can be convenient to " +"maintain log messages in a *structured format*. With structured messages, it " +"is easier to search for particular information, to produce statistics and to " +"cope with changes and inconsistencies in message " +"structure. [application]*Rsyslog* uses the *JSON* (JavaScript Object " +"Notation) format to provide structure for log messages." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1484 +msgid "Compare the following unstructured log message:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1488 +#, no-wrap +msgid "" +"Oct 25 10:20:37 localhost anacron[1395]: Jobs will be executed " +"sequentially\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1491 +msgid "with a structured one:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1495 +#, no-wrap +msgid "" +"{\"timestamp\":\"2013-10-25T10:20:37\", \"host\":\"localhost\", " +"\"program\":\"anacron\", \"pid\":\"1395\", \"msg\":\"Jobs will be executed " +"sequentially\"}\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1498 +msgid "" +"Searching structured data with use of key-value pairs is faster and more " +"precise than searching text files with regular expressions. The structure " +"also lets you to search for the same entry in messages produced by various " +"applications. Also, JSON files can be stored in a document database such as " +"MongoDB, which provides additional performance and analysis capabilities. On " +"the other hand, a structured message requires more disk space than the " +"unstructured one." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1500 +msgid "" +"In [application]*rsyslog*, log messages with meta data are pulled from " +"[application]*Journal* with use of the `imjournal` module. With the " +"`mmjsonparse` module, you can parse data imported from " +"[application]*Journal* and from other sources and process them further, for " +"example as a database output. For parsing to be successful, `mmjsonparse` " +"requires input messages to be structured in a way that is defined by the " +"*Lumberjack* project." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1502 +msgid "" +"The *Lumberjack* project aims to add structured logging to " +"[application]*rsyslog* in a backward-compatible way. To identify a " +"structured message, *Lumberjack* specifies the *@cee:* string that prepends " +"the actual JSON structure. Also, *Lumberjack* defines the list of standard " +"field names that should be used for entities in the JSON string. For more " +"information on *Lumberjack*, see " +"xref:Viewing_and_Managing_Log_Files.adoc#brid-Log_Files-Resources-Online[Online " +"Documentation]." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1504 +msgid "The following is an example of a lumberjack-formatted message:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1509 +#, no-wrap +msgid "" +" @cee: {\"pid\":17055, \"uid\":1000, \"gid\":1000, " +"\"appname\":\"logger\", \"msg\":\"Message text.\"}\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1513 +msgid "" +"To build this structure inside [application]*Rsyslog*, a template is used, " +"see " +"xref:Viewing_and_Managing_Log_Files.adoc#s2-filtering_structured_messages[Filtering " +"Structured Messages]. Applications and servers can employ the `libumberlog` " +"library to generate messages in the lumberjack-compliant form. For more " +"information on `libumberlog`, see " +"xref:Viewing_and_Managing_Log_Files.adoc#brid-Log_Files-Resources-Online[Online " +"Documentation]." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1515 +#, no-wrap +msgid "Importing Data from Journal" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1518 +msgid "" +"The [command]#imjournal# module is " +"[application]*Rsyslog*pass:attributes[{blank}]'s input module to natively " +"read the journal files (see " +"xref:Viewing_and_Managing_Log_Files.adoc#s1-interaction_of_rsyslog_and_journal[Interaction " +"of Rsyslog and Journal]). Journal messages are then logged in text format as " +"other rsyslog messages. However, with further processing, it is possible to " +"translate meta data provided by [application]*Journal* into a structured " +"message." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1520 +msgid "" +"To import data from [application]*Journal* to [application]*Rsyslog*, use " +"the following configuration in `/etc/rsyslog.conf`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1525 +#, no-wrap +msgid "$ModLoad imjournal\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1531 +#, no-wrap +msgid "" +"$imjournalPersistStateInterval pass:quotes[_number_of_messages_]\n" +"$imjournalStateFile pass:quotes[_path_]\n" +"$imjournalRatelimitInterval pass:quotes[_seconds_]\n" +"$imjournalRatelimitBurst pass:quotes[_burst_number_]\n" +"$ImjournalIgnorePreviousMessages pass:quotes[_off/on_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1535 +msgid "" +"With _number_of_messages_, you can specify how often the journal data must " +"be saved. This will happen each time the specified number of messages is " +"reached." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1537 +msgid "" +"Replace _path_ with a path to the state file. This file tracks the journal " +"entry that was the last one processed." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1539 +msgid "" +"With _seconds_, you set the length of the rate limit interval. The number of " +"messages processed during this interval can not exceed the value specified " +"in _burst_number_. The default setting is 20,000 messages per 600 " +"seconds. Rsyslog discards messages that come after the maximum burst within " +"the time frame specified." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1541 +msgid "" +"With [option]`$ImjournalIgnorePreviousMessages` you can ignore messages that " +"are currently in Journal and import only new messages, which is used when " +"there is no state file specified. The default setting is `off`. Please note " +"that if this setting is off and there is no state file, all messages in the " +"Journal are processed, even if they were already processed in a previous " +"rsyslog session." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1546 +msgid "" +"You can use `imjournal` simultaneously with `imuxsock` module that is the " +"traditional system log input. However, to avoid message duplication, you " +"must prevent `imuxsock` from reading the Journal's system socket. To do so, " +"use the [option]`$OmitLocalLogging` directive:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1552 +#, no-wrap +msgid "" +"$ModLoad imuxsock\n" +"$ModLoad imjournal\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1555 +#, no-wrap +msgid "" +"$OmitLocalLogging on\n" +"$AddUnixListenSocket /run/systemd/journal/syslog\n" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1561 +msgid "" +"You can translate all data and meta data stored by [application]*Journal* " +"into structured messages. Some of these meta data entries are listed in " +"xref:Viewing_and_Managing_Log_Files.adoc#ex-verbose_journalctl_output[Verbose " +"journalctl Output], for a complete list of journal fields see the " +"`systemd.journal-fields(7)` manual page. For example, it is possible to " +"focus on *kernel journal fields*, that are used by messages originating in " +"the kernel." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1563 +#, no-wrap +msgid "Filtering Structured Messages" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1566 +msgid "" +"To create a lumberjack-formatted message that is required by " +"[application]*rsyslog*pass:attributes[{blank}]'s parsing module, use the " +"following template:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1571 +#, no-wrap +msgid "" +"template(name=\"CEETemplate\" type=\"string\" string=\"%TIMESTAMP% " +"%HOSTNAME% %syslogtag% @cee: %$!all-json%\\n\")\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1575 +msgid "" +"This template prepends the `@cee:` string to the JSON string and can be " +"applied, for example, when creating an output file with `omfile` module. To " +"access JSON field names, use the *$!* prefix. For example, the following " +"filter condition searches for messages with specific *hostname* and *UID*:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1580 +#, no-wrap +msgid "" +"($!hostname == " +"\"pass:attributes[{blank}]_hostname_pass:attributes[{blank}]\" && $!UID== " +"\"pass:attributes[{blank}]_UID_pass:attributes[{blank}]\")\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1584 +#, no-wrap +msgid "Parsing JSON" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1587 +msgid "The `mmjsonparse` module is used for parsing structured messages." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1589 +msgid "" +"These messages can come from [application]*Journal* or from other input " +"sources, and must be formatted in a way defined by the *Lumberjack* " +"project. These messages are identified by the presence of the *@cee:* " +"string. Then, `mmjsonparse` checks if the JSON structure is valid and then " +"the message is parsed." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1591 +msgid "" +"To parse lumberjack-formatted JSON messages with `mmjsonparse`, use the " +"following configuration in the `/etc/rsyslog.conf`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1595 +#, no-wrap +msgid "$ModLoad mmjsonparse\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1597 +#, no-wrap +msgid "*.* :mmjsonparse:\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1601 +msgid "" +"In this example, the `mmjsonparse` module is loaded on the first line, then " +"all messages are forwarded to it. Currently, there are no configuration " +"parameters available for `mmjsonparse`." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1603 +#, no-wrap +msgid "Storing Messages in the MongoDB" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1606 +msgid "" +"[application]*Rsyslog* supports storing JSON logs in the MongoDB document " +"database through the *ommongodb* output module." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1608 +msgid "" +"To forward log messages into MongoDB, use the following syntax in the " +"`/etc/rsyslog.conf` (configuration parameters for *ommongodb* are available " +"only in the new configuration format; see " +"xref:Viewing_and_Managing_Log_Files.adoc#sec-using_the_new_configuration_format[Using " +"the New Configuration Format]):" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1613 +#, no-wrap +msgid "$ModLoad ommongodb\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1615 +#, no-wrap +msgid "" +"*.* action(type=\"ommongodb\" server=\"pass:quotes[_DB_server_]\" " +"serverport=\"pass:quotes[_port_]\" db=\"pass:quotes[_DB_name_]\" " +"collection=\"pass:quotes[_collection_name_]\" uid=\"pass:quotes[_UID_]\" " +"pwd=\"pass:quotes[_password_]\")\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1619 +msgid "" +"Replace _DB_server_ with the name or address of the MongoDB server. Specify " +"_port_ to select a non-standard port from the MongoDB server. The default " +"_port_ value is `0` and usually there is no need to change this parameter." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1621 +msgid "" +"With _DB_name_, you identify to which database on the MongoDB server you " +"want to direct the output. Replace _collection_name_ with the name of a " +"collection in this database. In MongoDB, collection is a group of documents, " +"the equivalent of an RDBMS table." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1623 +msgid "You can set your login details by replacing _UID_ and _password_." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1625 +msgid "" +"You can shape the form of the final database output with use of " +"templates. By default, [application]*rsyslog* uses a template based on " +"standard [application]*lumberjack* field names." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1627 +#, no-wrap +msgid "Debugging Rsyslog" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1630 +msgid "" +"indexterm:[rsyslog,debugging] To run `rsyslogd` in debugging mode, use the " +"following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1634 +#, no-wrap +msgid "`rsyslogd` [option]`-dn`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1637 +msgid "" +"With this command, `rsyslogd` produces debugging information and prints it " +"to the standard output. The [option]`-n` stands for \"`no fork`\". You can " +"modify debugging with environmental variables, for example, you can store " +"the debug output in a log file. Before starting `rsyslogd`, type the " +"following on the command line:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1643 +#, no-wrap +msgid "" +"export RSYSLOG_DEBUGLOG=\"pass:quotes[_path_]\"\n" +"export RSYSLOG_DEBUG=\"Debug\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1647 +msgid "" +"Replace _path_ with a desired location for the file where the debugging " +"information will be logged. For a complete list of options available for the " +"RSYSLOG_DEBUG variable, see the related section in the `rsyslogd(8)` manual " +"page." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1649 +msgid "To check if syntax used in the `/etc/rsyslog.conf` file is valid use:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1653 +#, no-wrap +msgid "`rsyslogd` [option]`-N` `1`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1656 +msgid "" +"Where `1` represents level of verbosity of the output message. This is a " +"forward compatibility option because currently, only one level is " +"provided. However, you must add this argument to run the validation." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1658 +#, no-wrap +msgid "Troubleshooting Logging to a Server" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1661 +msgid "" +"Ensure the time is correctly set on the systems generating the log messages " +"as well as on any logging servers. See " +"xref:basic-system-configuration/Configuring_the_Date_and_Time.adoc#ch-Configuring_the_Date_and_Time[Configuring " +"the Date and Time] for information on checking and setting the time. See " +"xref:servers/Configuring_NTP_Using_ntpd.adoc#ch-Configuring_NTP_Using_ntpd[Configuring " +"NTP Using ntpd] and " +"xref:servers/Configuring_NTP_Using_the_chrony_Suite.adoc#ch-Configuring_NTP_Using_the_chrony_Suite[Configuring " +"NTP Using the chrony Suite] for information on using `NTP` to keep the " +"system clock accurately set." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1663 +msgid "" +"On a logging server, check that the firewall has the appropriate ports open " +"to allow ingress of either `UDP` or `TCP`, depending on what traffic and " +"port the sending systems are configured to use. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1667 +#, no-wrap +msgid "~]#{nbsp}firewall-cmd --zone=public --list-ports\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1670 +msgid "" +"For more information on opening and closing ports in `firewalld`, see the " +"link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Security_Guide/++[Red{nbsp}Hat " +"Enterprise{nbsp}Linux{nbsp}7 Security Guide]. Review the configuration of " +"the logging server to ensure it is listening on the same port the sending " +"systems are configured to send on, and all are set to use the same protocol." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1672 +msgid "" +"Use the [command]#logger# command to generate test log messages. For " +"example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1677 +#, no-wrap +msgid "" +"~]$ [command]#logger -p authpriv.info \"Test Secret\"#\n" +"~]$ [command]#logger -p auth.info \"Test Info\"#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1680 +msgid "" +"See the `logger(1)` manual page for more information on the " +"[command]#logger# command." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1682 +#, no-wrap +msgid "Using the Journal" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1685 +msgid "" +"The Journal is a component of [application]*systemd* that is responsible for " +"viewing and management of log files. It can be used in parallel, or in place " +"of a traditional syslog daemon, such as `rsyslogd`. The Journal was " +"developed to address problems connected with traditional logging. It is " +"closely integrated with the rest of the system, supports various logging " +"technologies and access management for the log files." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1687 +msgid "" +"Logging data is collected, stored, and processed by the Journal's `journald` " +"service. It creates and maintains binary files called *journals* based on " +"logging information that is received from the kernel, from user processes, " +"from standard output, and standard error output of system services or via " +"its native API. These journals are structured and indexed, which provides " +"relatively fast seek times. Journal entries can carry a unique " +"identifier. The `journald` service collects numerous meta data fields for " +"each log message. The actual journal files are secured, and therefore cannot " +"be manually edited." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1689 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2000 +#, no-wrap +msgid "Viewing Log Files" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1692 +msgid "" +"To access the journal logs, use the [application]*journalctl* tool. For a " +"basic view of the logs type as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1696 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1899 +#, no-wrap +msgid "[command]#journalctl#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1699 +msgid "" +"An output of this command is a list of all log files generated on the system " +"including messages generated by system components and by users. The " +"structure of this output is similar to one used in `/var/log/messages/` but " +"with certain improvements:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1701 +msgid "" +"the priority of entries is marked visually. Lines of error priority and " +"higher are highlighted with red color and a bold font is used for lines with " +"notice and warning priority" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1703 +msgid "the time stamps are converted for the local time zone of your system" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1705 +msgid "all logged data is shown, including rotated logs" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1707 +msgid "the beginning of a boot is tagged with a special line" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1709 +#, no-wrap +msgid "Example Output of journalctl" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1713 +msgid "" +"The following is an example output provided by the [application]*journalctl* " +"tool. When called without parameters, the listed entries begin with a time " +"stamp, then the host name and application that performed the operation is " +"mentioned followed by the actual message. This example shows the first three " +"entries in the journal log:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1721 +#, no-wrap +msgid "" +"# journalctl\n" +"-- Logs begin at Thu 2013-08-01 15:42:12 CEST, end at Thu 2013-08-01 " +"15:48:48 CEST. --\n" +"Aug 01 15:42:12 localhost systemd-journal[54]: Allowing runtime journal " +"files to grow to 49.7M.\n" +"Aug 01 15:42:12 localhost kernel: Initializing cgroup subsys cpuset\n" +"Aug 01 15:42:12 localhost kernel: Initializing cgroup subsys cpu\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1723 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1779 +#, no-wrap +msgid "[...]\n" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1729 +msgid "" +"In many cases, only the latest entries in the journal log are relevant. The " +"simplest way to reduce [command]#journalctl# output is to use the " +"[option]`-n` option that lists only the specified number of most recent log " +"entries:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1733 +#, no-wrap +msgid "[command]#journalctl# [option]`-n` _Number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1736 +msgid "" +"Replace _Number_ with the number of lines to be shown. When no number is " +"specified, [command]#journalctl# displays the ten most recent entries." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1738 +msgid "" +"The [command]#journalctl# command allows controlling the form of the output " +"with the following syntax:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1742 +#, no-wrap +msgid "[command]#journalctl# [option]`-o` _form_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1745 +msgid "" +"Replace _form_ with a keyword specifying a desired form of output. There are " +"several options, such as [option]`verbose`, which returns full-structured " +"entry items with all fields, [option]`export`, which creates a binary stream " +"suitable for backups and network transfer, and [option]`json`, which formats " +"entries as JSON data structures. For the full list of keywords, see the " +"`journalctl(1)` manual page." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1747 +#, no-wrap +msgid "Verbose journalctl Output" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1751 +msgid "To view full meta data about all entries, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1756 +#, no-wrap +msgid "" +"# journalctl -o verbose\n" +"[...]\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1777 +#, no-wrap +msgid "" +"Fri 2013-08-02 14:41:22 CEST " +"[s=e1021ca1b81e4fc688fad6a3ea21d35b;i=55c;b=78c81449c920439da57da7bd5c56a770;m=27cc\n" +" _BOOT_ID=78c81449c920439da57da7bd5c56a770\n" +" PRIORITY=5\n" +" SYSLOG_FACILITY=3\n" +" _TRANSPORT=syslog\n" +" _MACHINE_ID=69d27b356a94476da859461d3a3bc6fd\n" +" _HOSTNAME=localhost.localdomain\n" +" _PID=562\n" +" _COMM=dbus-daemon\n" +" _EXE=/usr/bin/dbus-daemon\n" +" _CMDLINE=/bin/dbus-daemon --system --address=systemd: --nofork " +"--nopidfile --systemd-activation\n" +" _SYSTEMD_CGROUP=/system/dbus.service\n" +" _SYSTEMD_UNIT=dbus.service\n" +" SYSLOG_IDENTIFIER=dbus\n" +" SYSLOG_PID=562\n" +" _UID=81\n" +" _GID=81\n" +" _SELINUX_CONTEXT=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023\n" +" MESSAGE=[system] Successfully activated service " +"'net.reactivated.Fprint'\n" +" _SOURCE_REALTIME_TIMESTAMP=1375447282839181\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1783 +msgid "" +"This example lists fields that identify a single log entry. These meta data " +"can be used for message filtering as shown in " +"xref:Viewing_and_Managing_Log_Files.adoc#advanced_filtering[Advanced " +"Filtering]. For a complete description of all possible fields see the " +"`systemd.journal-fields(7)` manual page." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1787 +#, no-wrap +msgid "Access Control" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1790 +msgid "" +"By default, [application]*Journal* users without `root` privileges can only " +"see log files generated by them. The system administrator can add selected " +"users to the *adm* group, which grants them access to complete log files. To " +"do so, type as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1794 +#, no-wrap +msgid "[command]#usermod# [option]`-a` [option]`-G` *adm* _username_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1797 +msgid "" +"Here, replace _username_ with a name of the user to be added to the *adm* " +"group. This user then receives the same output of the [command]#journalctl# " +"command as the root user. Note that access control only works when " +"persistent storage is enabled for [application]*Journal*." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1799 +#, no-wrap +msgid "Using The Live View" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1802 +msgid "" +"When called without parameters, [command]#journalctl# shows the full list of " +"entries, starting with the oldest entry collected. With the live view, you " +"can supervise the log messages in real time as new entries are continuously " +"printed as they appear. To start [application]*journalctl* in live view " +"mode, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1806 +#, no-wrap +msgid "[command]#journalctl# [option]`-f`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1809 +msgid "" +"This command returns a list of the ten most current log lines. The " +"[application]*journalctl* utility then stays running and waits for new " +"changes to show them immediately." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1811 +#, no-wrap +msgid "Filtering Messages" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1814 +msgid "" +"The output of the [command]#journalctl# command executed without parameters " +"is often extensive, therefore you can use various filtering methods to " +"extract information to meet your needs." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1815 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1826 +#, no-wrap +msgid "Filtering by Priority" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1817 +msgid "" +"Log messages are often used to track erroneous behavior on the system. To " +"view only entries with a selected or higher priority, use the following " +"syntax:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1821 +#, no-wrap +msgid "[command]#journalctl# [option]`-p` _priority_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1824 +msgid "" +"Here, replace _priority_ with one of the following keywords (or with a " +"number): [command]#debug# (7), [command]#info# (6), [command]#notice# (5), " +"[command]#warning# (4), [command]#err# (3), [command]#crit# (2), " +"[command]#alert# (1), and [command]#emerg# (0)." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1830 +msgid "To view only entries with *error* or higher priority, use:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1834 +#, no-wrap +msgid "[command]#journalctl# [option]`-p err`\n" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1838 +#, no-wrap +msgid "Filtering by Time" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1840 +msgid "To view log entries only from the current boot, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1844 +#, no-wrap +msgid "[command]#journalctl# [option]`-b`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1847 +msgid "" +"If you reboot your system just occasionally, the [option]`-b` will not " +"significantly reduce the output of [command]#journalctl#. In such cases, " +"time-based filtering is more helpful:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1851 +#, no-wrap +msgid "" +"[command]#journalctl# " +"[option]`--since`pass:attributes[{blank}]=pass:attributes[{blank}]_value_ " +"[option]`--until`pass:attributes[{blank}]=pass:attributes[{blank}]_value_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1854 +msgid "" +"With [option]`--since` and [option]`--until`, you can view only log messages " +"created within a specified time range. You can pass _values_ to these " +"options in form of date or time or both as shown in the following example." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1856 +#, no-wrap +msgid "Filtering by Time and Priority" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1860 +msgid "" +"Filtering options can be combined to reduce the set of results according to " +"specific requests. For example, to view the *warning* or higher priority " +"messages from a certain point in time, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1864 +#, no-wrap +msgid "" +"[command]#journalctl# [option]`-p warning` [option]`--since=\"2013-3-16 " +"23:59:59\"`\n" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1869 +#, no-wrap +msgid "Advanced Filtering" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1871 +msgid "" +"xref:Viewing_and_Managing_Log_Files.adoc#ex-verbose_journalctl_output[Verbose " +"journalctl Output] lists a set of fields that specify a log entry and can " +"all be used for filtering. For a complete description of meta data that " +"`systemd` can store, see the `systemd.journal-fields(7)` manual page. This " +"meta data is collected for each log message, without user " +"intervention. Values are usually text-based, but can take binary and large " +"values; fields can have multiple values assigned though it is not very " +"common." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1873 +msgid "" +"To view a list of unique values that occur in a specified field, use the " +"following syntax:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1877 +#, no-wrap +msgid "[command]#journalctl# [option]`-F` _fieldname_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1880 +msgid "Replace _fieldname_ with a name of a field you are interested in." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1882 +msgid "" +"To show only log entries that fit a specific condition, use the following " +"syntax:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1886 +#, no-wrap +msgid "" +"[command]#journalctl# " +"_fieldname_pass:attributes[{blank}]=pass:attributes[{blank}]_value_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1889 +msgid "" +"Replace _fieldname_ with a name of a field and _value_ with a specific value " +"contained in that field. As a result, only lines that match this condition " +"are returned." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1890 +#, no-wrap +msgid "kbd:[Tab] Completion on Field Names" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1895 +msgid "" +"As the number of meta data fields stored by `systemd` is quite large, it is " +"easy to forget the exact name of the field of interest. When unsure, type:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1902 +msgid "" +"and press the kbd:[Tab] key two times. This shows a list of available field " +"names. kbd:[Tab] completion based on context works on field names, so you " +"can type a distinctive set of letters from a field name and then press " +"kbd:[Tab] to complete the name automatically. Similarly, you can list unique " +"values from a field. Type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1906 +#, no-wrap +msgid "[command]#journalctl# _fieldname_pass:attributes[{blank}]=\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1909 +msgid "" +"and press kbd:[Tab] two times. This serves as an alternative to " +"[command]#journalctl# [option]`-F` _fieldname_." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1913 +msgid "You can specify multiple values for one field:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1917 +#, no-wrap +msgid "" +"[command]#journalctl# " +"_fieldname_pass:attributes[{blank}]=pass:attributes[{blank}]_value1_ " +"_fieldname_pass:attributes[{blank}]=pass:attributes[{blank}]_value2_ ...\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1920 +msgid "" +"Specifying two matches for the same field results in a logical `OR` " +"combination of the matches. Entries matching _value1_ or _value2_ are " +"displayed." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1922 +msgid "" +"Also, you can specify multiple field-value pairs to further reduce the " +"output set:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1926 +#, no-wrap +msgid "" +"[command]#journalctl# " +"_fieldname1_pass:attributes[{blank}]=pass:attributes[{blank}]_value_ " +"_fieldname2_pass:attributes[{blank}]=pass:attributes[{blank}]_value_ ...\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1929 +msgid "" +"If two matches for different field names are specified, they will be " +"combined with a logical `AND`. Entries have to match both conditions to be " +"shown." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1931 +msgid "" +"With use of the *+* symbol, you can set a logical `OR` combination of " +"matches for multiple fields:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1935 +#, no-wrap +msgid "" +"journalctl pass:quotes[_fieldname1_]=pass:quotes[_value_] + " +"pass:quotes[_fieldname2_]=pass:quotes[_value_] ...\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1938 +msgid "" +"This command returns entries that match at least one of the conditions, not " +"only those that match both of them." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1940 +#, no-wrap +msgid "Advanced filtering" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1944 +msgid "" +"To display entries created by `avahi-daemon.service` or `crond.service` " +"under user with UID 70, use the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1948 +#, no-wrap +msgid "" +"journalctl pass:quotes[`_UID=70`] " +"pass:quotes[`_SYSTEMD_UNIT=avahi-daemon.service`] " +"pass:quotes[`_SYSTEMD_UNIT=crond.service`]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1951 +msgid "" +"Since there are two values set for the `_SYSTEMD_UNIT` field, both results " +"will be displayed, but only when matching the `_UID=70` condition. This can " +"be expressed simply as: (UID=70 and (avahi or cron))." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1955 +msgid "" +"You can apply the aforementioned filtering also in the live-view mode to " +"keep track of the latest changes in the selected group of log entries:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1959 +#, no-wrap +msgid "" +"[command]#journalctl# [option]`-f` " +"_fieldname_pass:attributes[{blank}]=pass:attributes[{blank}]_value_ ...\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1962 +#, no-wrap +msgid "Enabling Persistent Storage" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1965 +msgid "" +"By default, [application]*Journal* stores log files only in memory or a " +"small ring-buffer in the `/run/log/journal/` directory. This is sufficient " +"to show recent log history with [command]#journalctl#. This directory is " +"volatile, log data is not saved permanently. With the default configuration, " +"syslog reads the journal logs and stores them in the `/var/log/` " +"directory. With persistent logging enabled, journal files are stored in " +"`/var/log/journal` which means they persist after reboot. Journal can then " +"replace [application]*rsyslog* for some users (but see the chapter " +"introduction)." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1967 +msgid "Enabled persistent storage has the following advantages" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1969 +msgid "Richer data is recorded for troubleshooting in a longer period of time" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1971 +msgid "For immediate troubleshooting, richer data is available after a reboot" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1973 +msgid "Server console currently reads data from journal, not log files" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1975 +msgid "Persistent storage has also certain disadvantages:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1977 +msgid "" +"Even with persistent storage the amount of data stored depends on free " +"memory, there is no guarantee to cover a specific time span" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1979 +msgid "More disk space is needed for logs" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1981 +msgid "" +"To enable persistent storage for Journal, create the journal directory " +"manually as shown in the following example. As `root` type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1985 +#, no-wrap +msgid "[command]#mkdir# [option]`-p` `/var/log/journal`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1988 +msgid "Then, restart `journald` to apply the change:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1992 +#, no-wrap +msgid "[command]#systemctl# [option]`restart` `systemd-journald`\n" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1995 +#, no-wrap +msgid "Managing Log Files in a Graphical Environment" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1998 +msgid "" +"As an alternative to the aforementioned command-line utilities, Red{nbsp}Hat " +"Enterprise{nbsp}Linux{nbsp}7 provides an accessible GUI for managing log " +"messages." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2005 +msgid "" +"indexterm:[log files,viewing] Most log files are stored in plain text " +"format. You can view them with any text editor such as [command]#Vi# or " +"[application]*Emacs*. Some log files are readable by all users on the " +"system; however, root privileges are required to read most log files. " +"indexterm:[gnome-system-log,System Log] To view system log files in an " +"interactive, real-time application, use the [application]*System Log*." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2006 +#, no-wrap +msgid "Installing the gnome-system-log package" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2011 +msgid "" +"In order to use the [application]*System Log*, first ensure the " +"[package]*gnome-system-log* package is installed on your system by running, " +"as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2015 +#, no-wrap +msgid "~]#{nbsp}dnf install gnome-system-log\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2019 +msgid "" +"For more information on installing packages with DNF, see " +"xref:package-management/DNF.adoc#sec-Installing[Installing Packages]." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2023 +msgid "" +"After you have installed the [package]*gnome-system-log* package, open the " +"[application]*System Log* by clicking " +"menu:Applications[pass:attributes[{blank}]`System Tools` > `System " +"Log`pass:attributes[{blank}]], or type the following command at a shell " +"prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2027 +#, no-wrap +msgid "~]${nbsp}pass:attributes[{blank}][command]#gnome-system-log#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2032 +msgid "" +"The application only displays log files that exist; thus, the list might " +"differ from the one shown in " +"xref:Viewing_and_Managing_Log_Files.adoc#fig-redhat-logviewer[System Log]. " +"indexterm:[System Log,searching]indexterm:[System Log,filtering]" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2034 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2036 +#, no-wrap +msgid "System Log" +msgstr "" + +#. type: Target for macro image +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2036 +#, no-wrap +msgid "redhat-logviewer.png" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2039 +msgid "" +"indexterm:[System Log,refresh rate] The [application]*System Log* " +"application lets you filter any existing log file. Click on the button " +"marked with the gear symbol to view the menu, select " +"menu:[pass:attributes[{blank}]`Filters` > > `Manage " +"Filters`pass:attributes[{blank}]] to define or edit the desired filter." +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2041 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2043 +#, no-wrap +msgid "System Log - Filters" +msgstr "" + +#. type: Target for macro image +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2043 +#, no-wrap +msgid "redhat-filters.png" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2046 +msgid "" +"Adding or editing a filter lets you define its parameters as is shown in " +"xref:Viewing_and_Managing_Log_Files.adoc#fig-redhat-filter-sample[System Log " +"- defining a filter]." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2048 +#, no-wrap +msgid "System Log - defining a filter" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2050 +#, no-wrap +msgid "System Log - Defining a Filter" +msgstr "" + +#. type: Target for macro image +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2050 +#, no-wrap +msgid "redhat-filter-sample.png" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2053 +msgid "When defining a filter, the following parameters can be edited:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2055 +msgid "`Name` — Specifies the name of the filter." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2057 +msgid "" +"`Regular Expression` — Specifies the regular expression that will be applied " +"to the log file and will attempt to match any possible strings of text in " +"it." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2059 +msgid "`Effect`" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2061 +msgid "" +"`Highlight` — If checked, the found results will be highlighted with the " +"selected color. You may select whether to highlight the background or the " +"foreground of the text." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2063 +msgid "" +"`Hide` — If checked, the found results will be hidden from the log file you " +"are viewing." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2065 +msgid "" +"When you have at least one filter defined, it can be selected from the " +"`Filters` menu and it will automatically search for the strings you have " +"defined in the filter and highlight or hide every successful match in the " +"log file you are currently viewing." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2067 +#, no-wrap +msgid "System Log - enabling a filter" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2069 +#, no-wrap +msgid "System Log - Enabling a Filter" +msgstr "" + +#. type: Target for macro image +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2069 +#, no-wrap +msgid "redhat-filter-enable.png" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2072 +msgid "" +"When you select the `Show matches only` option, only the matched strings " +"will be shown in the log file you are currently viewing." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2074 +#, no-wrap +msgid "Adding a Log File" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2081 +msgid "" +"To add a log file you want to view in the list, select menu:File[> `Open` " +">]. This will display the `Open Log` window where you can select the " +"directory and file name of the log file you want to view. " +"xref:Viewing_and_Managing_Log_Files.adoc#fig-redhat-logviewer-add[System Log " +"- adding a log file] illustrates the Open Log window." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2083 +#, no-wrap +msgid "System Log - adding a log file" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2085 +#, no-wrap +msgid "System Log - Adding a Log File" +msgstr "" + +#. type: Target for macro image +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2085 +#, no-wrap +msgid "redhat-logviewer-add.png" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2088 +msgid "" +"Click on the btn:[Open] button to open the file. The file is immediately " +"added to the viewing list where you can select it and view its contents." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2089 +#, no-wrap +msgid "Reading zipped log files" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2094 +msgid "" +"The [application]*System Log* also allows you to open log files zipped in " +"the `.gz` format." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2098 +#, no-wrap +msgid "Monitoring Log Files" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2101 +msgid "" +"indexterm:[log files,monitoring]indexterm:[System Log,monitoring] " +"[application]*System Log* monitors all opened logs by default. If a new line " +"is added to a monitored log file, the log name appears in bold in the log " +"list. If the log file is selected or displayed, the new lines appear in bold " +"at the bottom of the log " +"file. " +"xref:Viewing_and_Managing_Log_Files.adoc#fig-redhat-logviewer-monitoring[System " +"Log - new log alert] illustrates a new alert in the `cron` log file and in " +"the `messages` log file. Clicking on the `messages` log file displays the " +"logs in the file with the new lines in bold." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2103 +#, no-wrap +msgid "System Log - new log alert" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2105 +#, no-wrap +msgid "System Log - New Log Alert" +msgstr "" + +#. type: Target for macro image +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2105 +#, no-wrap +msgid "redhat-logviewer-monitoring.png" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2108 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2111 +msgid "" +"For more information on how to configure the `rsyslog` daemon and how to " +"locate, view, and monitor log files, see the resources listed below." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2112 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2115 +msgid "" +"`rsyslogd`(8) — The manual page for the `rsyslogd` daemon documents its " +"usage." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2117 +msgid "" +"`rsyslog.conf`(5) — The manual page named `rsyslog.conf` documents available " +"configuration options." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2119 +msgid "" +"`logrotate`(8) — The manual page for the [application]*logrotate* utility " +"explains in greater detail how to configure and use it." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2121 +msgid "" +"`journalctl`(1) — The manual page for the [command]#journalctl# daemon " +"documents its usage." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2123 +msgid "" +"`journald.conf`(5) — This manual page documents available configuration " +"options." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2125 +msgid "" +"`systemd.journal-fields`(7) — This manual page lists special " +"[application]*Journal* fields." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2127 +#, no-wrap +msgid "Online Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2130 +msgid "" +"link:++https://www.rsyslog.com/++[rsyslog Home Page] — The " +"[application]*rsyslog* home page offers a thorough technical breakdown of " +"its features, documentation, configuration examples, and video tutorials." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2132 +msgid "" +"link:++https://www.rsyslog.com/doc/rainerscript.html++[pass:attributes[{blank}]*RainerScript* " +"documentation on the rsyslog Home Page] — Commented summary of data types, " +"expressions, and functions available in *RainerScript*." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2133 +msgid "" +"link:++https://www.rsyslog.com/doc/queues.html++[Description of *queues* on " +"the rsyslog Home Page] — General information on various types of message " +"queues and their usage." +msgstr "" diff --git a/po/fr/rawhide/pages/monitoring-and-automation/intro-monitoring-and-automation.po b/po/fr/rawhide/pages/monitoring-and-automation/intro-monitoring-and-automation.po new file mode 100644 index 00000000000..ba1303ae45c --- /dev/null +++ b/po/fr/rawhide/pages/monitoring-and-automation/intro-monitoring-and-automation.po @@ -0,0 +1,30 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/monitoring-and-automation/intro-monitoring-and-automation.adoc:1 +#, no-wrap +msgid "Monitoring and Automation" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/intro-monitoring-and-automation.adoc:3 +msgid "" +"This part describes various tools that allow system administrators to " +"monitor system performance, automate system tasks, and report bugs." +msgstr "" diff --git a/po/fr/rawhide/pages/package-management/DNF.po b/po/fr/rawhide/pages/package-management/DNF.po new file mode 100644 index 00000000000..1826686f358 --- /dev/null +++ b/po/fr/rawhide/pages/package-management/DNF.po @@ -0,0 +1,2229 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/package-management/DNF.adoc:5 +#, no-wrap +msgid "DNF" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:8 +msgid "" +"[application]*DNF* is the {OSORG} package manager that is able to query for " +"information about packages, fetch packages from repositories, install and " +"uninstall packages using automatic dependency resolution, and update an " +"entire system to the latest available packages. DNF performs automatic " +"dependency resolution on packages you are updating, installing or removing, " +"and thus is able to automatically determine, fetch and install all available " +"dependent packages. DNF can be configured with new, additional repositories, " +"or _package sources_, and also provides many plug-ins which enhance and " +"extend its capabilities. DNF is able to perform many of the same tasks that " +"[application]*RPM* can; additionally, many of the command line options are " +"similar. DNF enables easy and simple package management on a single machine " +"or on groups of them." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:10 +#, no-wrap +msgid "Secure package management with GPG-signed packages" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:15 +msgid "" +"DNF provides secure package management by enabling GPG (Gnu Privacy Guard; " +"also known as GnuPG) signature verification on GPG-signed packages to be " +"turned on for all package repositories (package sources), or for individual " +"repositories. When signature verification is enabled, DNF will refuse to " +"install any packages not GPG-signed with the correct key for that " +"repository. This means that you can trust that the [application]*RPM* " +"packages you download and install on your system are from a trusted source, " +"such as {OSORG}, and were not modified during transfer. See " +"xref:DNF.adoc#sec-Configuring_DNF_and_DNF_Repositories[Configuring DNF and " +"DNF Repositories] for details on enabling signature-checking with DNF, or " +"xref:RPM.adoc#s1-check-rpm-sig[Checking Package Signatures] for information " +"on working with and verifying GPG-signed [application]*RPM* packages in " +"general." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:19 +msgid "" +"DNF also enables you to easily set up your own repositories of " +"[application]*RPM* packages for download and installation on other machines." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:21 +msgid "" +"Learning DNF is a worthwhile investment because it is often the fastest way " +"to perform system administration tasks, and it provides capabilities beyond " +"those provided by the [application]*PackageKit* graphical package management " +"tools." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:23 +#, no-wrap +msgid "DNF and superuser privileges" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:28 +msgid "" +"You must have superuser privileges in order to use the [command]#dnf# " +"command to install, update or remove packages on your system. All examples " +"in this chapter assume that you have already obtained superuser privileges " +"by using either the [command]#su# or [command]#sudo# command." +msgstr "" + +#. type: Title == +#: ./pages/package-management/DNF.adoc:32 +#, no-wrap +msgid "Checking For and Updating Packages" +msgstr "" + +#. type: Title === +#: ./pages/package-management/DNF.adoc:35 +#, no-wrap +msgid "Checking For Updates" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:38 +msgid "" +"indexterm:[DNF Updates,checking for updates] The quickest way to check for " +"updates is to attempt to install any available updates by using the " +"[command]#dnf upgrade# command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:45 +#, no-wrap +msgid "" +"~]# dnf upgrade\n" +"Last metadata expiration check performed 1:24:32 ago on Thu May 14 23:23:51 " +"2015.\n" +"Dependencies resolved.\n" +"Nothing to do.\n" +"Complete!\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:48 +msgid "" +"Note that [command]#dnf upgrade# installs only those updates that can be " +"installed. If a package cannot be updated, because of dependency problems " +"for example, it is skipped." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:50 +msgid "" +"The [command]#dnf check-update# command can be used see which installed " +"packages on your system have new versions available, however it does not " +"mean that they can be successfully installed. This command is therefore " +"mostly useful in scripts and for checking for updated packages that were not " +"installed after running [command]#dnf upgrade#." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:52 +msgid "For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:56 +#, no-wrap +msgid "" +"~]# dnf check-update\n" +"Using metadata from Mon Apr 20 16:34:10 2015 (2:42:10 hours old)\n" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:60 +#, no-wrap +msgid "" +"python.x86_64 2.7.9-6.fc22 updates\n" +"python-cryptography.x86_64 0.8.2-1.fc22 updates\n" +"python-libs.x86_64 2.7.9-6.fc22 updates\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:63 +msgid "" +"The packages in the above output are listed as having updated versions. The " +"line in the example output tells us:" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:65 +msgid "`python` — the name of the package," +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:67 +msgid "`x86_64` — the CPU architecture the package was built for," +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:69 +msgid "`2.7.9` — the version of the updated package," +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:71 +msgid "`6.fc22` — the release of the updated package," +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:73 +msgid "`updates-testing` — the repository in which the updated package is located." +msgstr "" + +#. type: Title === +#: ./pages/package-management/DNF.adoc:75 +#, no-wrap +msgid "Updating Packages" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:78 +msgid "" +"indexterm:[DNF Updates,updating packages] You can choose to update a single " +"package, multiple packages, or all packages at once. If any dependencies of " +"the package, or packages, you update have updates available themselves, then " +"they are updated too." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:79 +#, no-wrap +msgid "Updating a Single Packageindexterm:[DNF Updates,updating a single package]" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:81 +msgid "To update a single package, run the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:85 +#, no-wrap +msgid "dnf upgrade pass:quotes[_package_name_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:88 +msgid "For example, to update the [package]*python* package, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:99 +#, no-wrap +msgid "" +"~]# dnf upgrade python\n" +"Using metadata from Mon Apr 20 16:38:16 2015 (2:42:14 hours old)\n" +"Dependencies resolved.\n" +"==================================================================\n" +" Package Arch Version Repository Size\n" +"==================================================================\n" +"Upgrading:\n" +" python x86_64 2.7.9-6.fc22 updates 92 k\n" +" python-libs x86_64 2.7.9-6.fc22 updates 5.8 M\n" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:103 +#, no-wrap +msgid "" +"Transaction Summary\n" +"==================================================================\n" +"Upgrade 2 Packages\n" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:106 +#, no-wrap +msgid "" +"Total download size: 5.9 M\n" +"Is this ok [y/N]:\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:109 +msgid "This output contains:" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:111 +msgid "" +"`python.x86_64` — you can download and install new [package]*python* " +"package." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:113 +msgid "" +"`python-libs.x86_64` — DNF has resolved that the " +"[package]*python-libs-2.7.9-6.fc22.x86_64* package is a required dependency " +"of the [package]*python* package." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:115 +msgid "" +"DNF presents the update information and then prompts you as to whether you " +"want it to perform the update; DNF runs interactively by default. If you " +"already know which transactions DNF plans to perform, you can use the " +"[option]`-y` option to automatically answer [command]#yes# to any questions " +"DNF may ask (in which case it runs non-interactively). However, you should " +"always examine which changes DNF plans to make to the system so that you can " +"easily troubleshoot any problems that might arise." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:117 +msgid "" +"If a transaction does go awry, you can view DNF's transaction history by " +"using the [command]#dnf history# command as described in " +"xref:DNF.adoc#sec-DNF-Transaction_History[Working with Transaction History]." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:119 +#, no-wrap +msgid "Updating and installing kernels with DNF" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:124 +msgid "" +"DNF always *installs* a new kernel in the same sense that [application]*RPM* " +"installs a new kernel when you use the command [command]#rpm -i " +"kernel#. Therefore, you do not need to worry about the distinction between " +"*installing* and *upgrading* a kernel package when you use the " +"[command]#dnf# command: it will do the right thing, regardless of whether " +"you are using the [command]#dnf upgrade# or [command]#dnf install# command." +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:126 +msgid "" +"When using [application]*RPM*, on the other hand, it is important to use the " +"[command]#rpm -i kernel# command (which installs a new kernel) instead of " +"[command]#rpm -u kernel# (which *replaces* the current kernel). See " +"xref:RPM.adoc#sec-Installing_and_Upgrading[Installing and Upgrading " +"Packages] for more information on installing and updating kernels with " +"[application]*RPM*." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:129 +#, no-wrap +msgid "" +"Updating All Packages and Their Dependenciesindexterm:[DNF Updates,updating " +"all packages and dependencies]" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:131 +msgid "" +"To update all packages and their dependencies, enter [command]#dnf upgrade# " +"without any arguments:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:135 +#, no-wrap +msgid "[command]#dnf upgrade#\n" +msgstr "" + +#. type: Title === +#: ./pages/package-management/DNF.adoc:138 +#, no-wrap +msgid "Preserving Configuration File Changes" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:141 +msgid "" +"indexterm:[Configuration File Changes] You will inevitably make changes to " +"the configuration files installed by packages as you use your {MAJOROS} " +"system. [application]*RPM*, which DNF uses to perform changes to the system, " +"provides a mechanism for ensuring their integrity. See " +"xref:RPM.adoc#sec-Installing_and_Upgrading[Installing and Upgrading " +"Packages] for details on how to manage changes to configuration files across " +"package upgrades." +msgstr "" + +#. type: Title == +#: ./pages/package-management/DNF.adoc:143 +#, no-wrap +msgid "Packages and Package Groups" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:145 +msgid "" +"indexterm:[packages,packages and package groups]indexterm:[DNF,packages and " +"package groups]" +msgstr "" + +#. type: Title === +#: ./pages/package-management/DNF.adoc:147 +#, no-wrap +msgid "Searching Packages" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:150 +msgid "" +"indexterm:[packages,searching packages with DNF,dnf " +"search]indexterm:[DNF,searching packages with DNF,dnf search] You can search " +"all *RPM* package names and summaries by using the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:154 +#, no-wrap +msgid "[command]#dnf# [option]`search` _term_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:157 +msgid "Add the [option]`all` to match against descriptions and URLs." +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:161 +#, no-wrap +msgid "[command]#dnf# [option]`search all` _term_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:164 +msgid "" +"This command displays the list of matches for each term. For example, to " +"list all packages that match \"`meld`\" or \"`kompare`\", type:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:171 +#, no-wrap +msgid "" +"~]# dnf search meld kompare\n" +"Loaded plugins: langpacks, presto, refresh-packagekit\n" +"============================ N/S Matched: meld " +"===============================\n" +"meld.noarch : Visual diff and merge tool\n" +"python-meld3.x86_64 : HTML/XML templating system for Python\n" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:174 +#, no-wrap +msgid "" +"=========================== N/S Matched: kompare " +"=============================\n" +"komparator.x86_64 : Kompare and merge two folders\n" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:176 +#, no-wrap +msgid " Name and summary matches only, use \"search all\" for everything.\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:178 +msgid "" +"indexterm:[packages,searching for packages with DNF,dnf " +"search]indexterm:[DNF,searching for packages with DNF,dnf search]" +msgstr "" + +#. type: Title === +#: ./pages/package-management/DNF.adoc:180 +#, no-wrap +msgid "Listing Packages" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:183 +msgid "" +"indexterm:[packages,listing packages with DNF,dnf " +"search]indexterm:[DNF,listing packages with DNF,dnf list] [command]#dnf " +"list# and related commands provide information about packages, package " +"groups, and repositories." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:185 +msgid "" +"All of DNF's list commands allow you to filter the results by appending one " +"or more _glob expressions_ as arguments. Glob expressions are normal strings " +"of characters which contain one or more of the wildcard characters " +"[command]#*# (which expands to match any character multiple times) and " +"[command]#?# (which expands to match any one character)." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:187 +#, no-wrap +msgid "Filtering results with glob expressions" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:192 +msgid "" +"indexterm:[packages,listing packages with DNF,Glob " +"expressions]indexterm:[DNF,listing packages with DNF,Glob expressions] Be " +"careful to escape the glob expressions when passing them as arguments to a " +"[command]#dnf# command, otherwise the Bash shell will interpret these " +"expressions as _pathname expansions_, and potentially pass all files in the " +"current directory that match the globs to DNF. To make sure the glob " +"expressions are passed to DNF as intended, either:" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:194 +msgid "" +"escape the wildcard characters by preceding them with a backslash character; " +"or," +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:196 +msgid "double-quote or single-quote the entire glob expression." +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:198 +msgid "" +"DNF searches only package names when using glob expressions. To search for a " +"version of a package, include a dash and part of the version number as " +"follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:208 +#, no-wrap +msgid "" +"~]# dnf list kernel*-4*\n" +"Last metadata expiration check performed 2:46:09 ago on Thu May 14 23:23:51 " +"2015.\n" +"Installed Packages\n" +"kernel.x86_64 4.0.0-1.fc22 " +"@System\n" +"kernel.x86_64 4.0.2-300.fc22 " +"@System\n" +"kernel-core.x86_64 4.0.0-1.fc22 " +"@System\n" +"kernel-core.x86_64 4.0.2-300.fc22 " +"@System\n" +"[output truncated]\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:211 +msgid "" +"See " +"xref:DNF.adoc#ex-Listing_all_ABRT_addons_and_plugins_using_glob_expressions[Listing " +"all ABRT addons and plug-ins using glob expressions] and " +"xref:DNF.adoc#ex-Listing_available_packages_using_a_single_glob_expression_with_escaped_wildcards[Listing " +"available packages using a single glob expression with escaped wildcard " +"characters] for an example usage of both these methods." +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:214 +#, no-wrap +msgid "[command]#dnf list _glob_expression_pass:attributes[{blank}]…#" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:215 +msgid "" +"Lists information on installed and available packages matching all glob " +"expressions." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:217 +#, no-wrap +msgid "Listing all ABRT addons and plug-ins using glob expressions" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:221 +msgid "" +"Packages with various ABRT addons and plug-ins either begin with " +"\"`abrt-addon-`\", or \"`abrt-plugin-`\". To list these packages, type the " +"following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:237 +#, no-wrap +msgid "" +"~]# dnf list abrt-addon\\* abrt-plugin\\*\n" +"Last metadata expiration check performed 0:14:36 ago on Mon May 25 23:38:13 " +"2015.\n" +"Installed Packages\n" +"abrt-addon-ccpp.x86_64 2.5.1-2.fc22 @System\n" +"abrt-addon-coredump-helper.x86_64 2.5.1-2.fc22 @System\n" +"abrt-addon-kerneloops.x86_64 2.5.1-2.fc22 @System\n" +"abrt-addon-pstoreoops.x86_64 2.5.1-2.fc22 @System\n" +"abrt-addon-python.x86_64 2.5.1-2.fc22 @System\n" +"abrt-addon-python3.x86_64 2.5.1-2.fc22 @System\n" +"abrt-addon-vmcore.x86_64 2.5.1-2.fc22 @System\n" +"abrt-addon-xorg.x86_64 2.5.1-2.fc22 @System\n" +"abrt-plugin-bodhi.x86_64 2.5.1-2.fc22 @System\n" +"Available Packages\n" +"abrt-addon-upload-watch.x86_64 2.5.1-2.fc22 fedora\n" +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:241 +#, no-wrap +msgid "" +"indexterm:[packages,listing packages with DNF,dnf list all] " +"indexterm:[DNF,listing packages with DNF,dnf list all] " +"[command]#dnf list all#" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:242 +msgid "Lists all installed *and* available packages." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:244 +#, no-wrap +msgid "Listing all installed and available packages" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:258 +#, no-wrap +msgid "" +"~]# dnf list all\n" +"Last metadata expiration check performed 0:21:11 ago on Mon May 25 23:38:13 " +"2015.\n" +"Installed Packages\n" +"NetworkManager.x86_64 1:1.0.2-1.fc22 @System\n" +"NetworkManager-libnm.x86_64 1:1.0.2-1.fc22 @System\n" +"PackageKit.x86_64 1.0.6-4.fc22 @System\n" +"PackageKit-glib.x86_64 1.0.6-4.fc22 @System\n" +"aajohan-comfortaa-fonts.noarch 2.004-4.fc22 @System\n" +"abrt.x86_64 2.5.1-2.fc22 @System\n" +"[output truncated]\n" +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:262 +#, no-wrap +msgid "" +"indexterm:[packages,listing packages with DNF,dnf list installed] " +"indexterm:[DNF,listing packages with DNF,dnf list installed] " +"[command]#dnf list installed#" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:263 +msgid "" +"Lists all packages installed on your system. The rightmost column in the " +"output lists the repository from which the package was retrieved." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:265 +#, no-wrap +msgid "Listing installed packages using a double-quoted glob expression" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:269 +msgid "" +"To list all installed packages that begin with \"`krb`\" followed by exactly " +"one character and a hyphen, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:276 +#, no-wrap +msgid "" +"~]# dnf list installed \"krb?-*\"\n" +"Last metadata expiration check performed 0:34:45 ago on Mon May 25 23:38:13 " +"2015.\n" +"Installed Packages\n" +"krb5-libs.x86_64 1.13.1-3.fc22 @System\n" +"krb5-workstation.x86_64 1.13.1-3.fc22 @System\n" +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:280 +#, no-wrap +msgid "" +"indexterm:[packages,listing packages with DNF,dnf list available] " +"indexterm:[DNF,listing packages with DNF,dnf list available] " +"[command]#dnf list available#" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:281 +msgid "Lists all available packages in all enabled repositories." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:283 +#, no-wrap +msgid "" +"Listing available packages using a single glob expression with escaped " +"wildcard characters" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:287 +msgid "" +"To list all available packages with names that contain \"`gstreamer`\" and " +"then \"`plugin`\", run the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:299 +#, no-wrap +msgid "" +"~]# dnf list available gstreamer\\*plugin\\*\n" +"Last metadata expiration check performed 0:42:15 ago on Mon May 25 23:38:13 " +"2015.\n" +"Available Packages\n" +"gstreamer-plugin-crystalhd.i686 3.10.0-8.fc22 fedora\n" +"gstreamer-plugin-crystalhd.x86_64 3.10.0-8.fc22 fedora\n" +"gstreamer-plugins-bad-free.i686 0.10.23-24.fc22 fedora\n" +"gstreamer-plugins-bad-free.x86_64 0.10.23-24.fc22 fedora\n" +"gstreamer-plugins-bad-free-devel.i686 0.10.23-24.fc22 fedora\n" +"gstreamer-plugins-bad-free-devel.x86_64 0.10.23-24.fc22 fedora\n" +" [output truncated]\n" +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:303 +#, no-wrap +msgid "" +"indexterm:[packages,listing packages with DNF,dnf group list] " +"indexterm:[DNF,listing packages with DNF,dnf group list] " +"[command]#dnf group list#" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:304 +msgid "Lists all package groups." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:306 +#, no-wrap +msgid "Listing all package groups" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:320 +#, no-wrap +msgid "" +"~]# dnf group list\n" +"Loaded plugins: langpacks, presto, refresh-packagekit\n" +"Setting up Group Process\n" +"Installed Groups:\n" +" Administration Tools\n" +" Design Suite\n" +" Dial-up Networking Support\n" +" Fonts\n" +" GNOME Desktop Environment\n" +"[output truncated]\n" +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:324 +#, no-wrap +msgid "" +"indexterm:[packages,listing packages with DNF,dnf repolist] " +"indexterm:[DNF,listing packages with DNF,dnf repolist] " +"[command]#dnf repolist#" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:325 +msgid "" +"Lists the repository ID, name, and number of packages it provides for each " +"*enabled* repository." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:327 +#, no-wrap +msgid "Listing enabled repositories" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:336 +#, no-wrap +msgid "" +"~]# dnf repolist\n" +"Last metadata expiration check performed 0:48:29 ago on Mon May 25 23:38:13 " +"2015.\n" +"repo id repo name " +"status\n" +"*fedora Fedora 22 - x86_64 " +"44,762\n" +"*updates Fedora 22 - x86_64 - Updates " +"0\n" +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:340 +#, no-wrap +msgid "" +"indexterm:[packages,listing packages from a single repository with DNF,dnf " +"repository-packages] indexterm:[DNF,listing packages from a " +"single repository with DNF,dnf repository-packages] [command]#dnf " +"repository-packages _repo_id_ list#" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:341 +msgid "Lists the packages from the specified repository." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:343 +#, no-wrap +msgid "Listing packages from a single repository" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:354 +#, no-wrap +msgid "" +"~]# dnf repository-packages fedora list [option]\n" +"Last metadata expiration check performed 1:38:25 ago on Wed May 20 22:16:16 " +"2015.\n" +"Installed Packages\n" +"PackageKit.x86_64 1.0.6-3.fc22 " +"@System\n" +"PackageKit-glib.x86_64 1.0.6-3.fc22 " +"@System\n" +"aajohan-comfortaa-fonts.noarch 2.004-4.fc22 " +"@System\n" +"[output truncated]\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:357 +msgid "" +"The default action is to list all packages available and installed from the " +"repository specified. Add the [option]`available` or [option]`installed` " +"option to list only those packages available or installed from the specified " +"repository." +msgstr "" + +#. type: Title === +#: ./pages/package-management/DNF.adoc:361 +#, no-wrap +msgid "Displaying Package Information" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:364 +msgid "" +"indexterm:[packages,displaying packages with DNF,dnf " +"info]indexterm:[DNF,displaying packages with DNF,dnf info] To display " +"information about one or more packages, use a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:368 +#, no-wrap +msgid "dnf info pass:quotes[_package_name_]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:371 +#: ./pages/package-management/DNF.adoc:402 +msgid "For example, to display information about the [package]*abrt* package, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:390 +#, no-wrap +msgid "" +"~]# dnf info abrt\n" +"Last metadata expiration check: 1:09:44 ago on Tue May 31 06:51:51 2016.\n" +"Installed Packages\n" +"Name : abrt\n" +"Arch : x86_64\n" +"Epoch : 0\n" +"Version : 2.8.1\n" +"Release : 1.fc24\n" +"Size : 2.2 M\n" +"Repo : @System\n" +"From repo : updates-testing\n" +"Summary : Automatic bug detection and reporting tool\n" +"URL : https://abrt.readthedocs.org/\n" +"License : GPLv2+\n" +"Description : abrt is a tool to help users to detect defects in applications " +"and\n" +" : to create a bug report with all information needed by " +"maintainer to fix it.\n" +" : It uses plugin system to extend its functionality.\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:393 +msgid "" +"indexterm:[packages,displaying packages,dnf info]indexterm:[DNF,displaying " +"packages,dnf info] The [command]#dnf info " +"_package_name_pass:attributes[{blank}]# command is similar to the " +"[command]#rpm -q --info _package_name_pass:attributes[{blank}]# command, but " +"provides as additional information the name of the DNF repository the RPM " +"package was installed from (look for the `From repo:` line in the " +"output). The [command]#dnf info# command shows only the newest available " +"package if there is a newer version available than the one installed. The " +"[command]#dnf repoquery# command can show *all* installed and available " +"packages." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:395 +msgid "" +"To display information about all available packages, both installed and " +"available from a repository, use a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:399 +#, no-wrap +msgid "dnf repoquery pass:quotes[_package_name_] --info\n" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:421 +#, no-wrap +msgid "" +"~]# dnf repoquery abrt --info\n" +"Last metadata expiration check: 1:01:44 ago on Tue May 31 06:51:51 2016.\n" +"Name : abrt\n" +"Version : 2.8.1\n" +"Release : 1.fc24\n" +"Architecture: x86_64\n" +"Size : 2318452\n" +"License : GPLv2+\n" +"Source RPM : abrt-2.8.1-1.fc24.src.rpm\n" +"Build Date : 2016-05-25 08:54\n" +"Packager : Fedora Project\n" +"URL : https://abrt.readthedocs.org/\n" +"Summary : Automatic bug detection and reporting tool\n" +"Description :\n" +"abrt is a tool to help users to detect defects in applications and\n" +"to create a bug report with all information needed by maintainer to fix " +"it.\n" +"It uses plugin system to extend its functionality.\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:424 +msgid "See the [command]#dnf repoquery# usage statement for more options:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:430 +#, no-wrap +msgid "" +"~]$ [command]#dnf repoquery -h#\n" +"usage: dnf [options] COMMAND\n" +"_output truncated_\n" +msgstr "" + +#. type: Title === +#: ./pages/package-management/DNF.adoc:433 +#, no-wrap +msgid "Installing Packages" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:436 +msgid "" +"indexterm:[packages,installing with DNF]indexterm:[DNF,installing with DNF] " +"DNF allows you to install both a single package and multiple packages, as " +"well as a package group of your choice." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:437 +#, no-wrap +msgid "Installing Individual Packages" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:439 +msgid "" +"To install a single package and all of its non-installed dependencies, enter " +"a command in the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:443 +#, no-wrap +msgid "dnf install pass:quotes[_package_name_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:446 +msgid "" +"You can also install multiple packages simultaneously by appending their " +"names as arguments:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:450 +#, no-wrap +msgid "dnf install pass:quotes[_package_name_] pass:quotes[_package_name_]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:453 +msgid "" +"If you are installing packages on a _multilib_ system, such as an AMD64 or " +"Intel64 machine, you can specify the architecture of the package, as long as " +"it is available in an enabled repository, by appending _.arch_ to the " +"package name. For example, to install the [package]*sqlite2* package for " +"`i586`, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:456 +#, no-wrap +msgid "~]# dnf install sqlite2.i586\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:459 +msgid "" +"You can use glob expressions to quickly install multiple similarly-named " +"packages:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:462 +#, no-wrap +msgid "~]# dnf install audacious-plugins-\\*\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:465 +msgid "" +"In addition to package names and glob expressions, you can also provide file " +"names to [command]#dnf install#. If you know the name of the binary you want " +"to install, but not its package name, you can give [command]#dnf install# " +"the path name:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:468 +#, no-wrap +msgid "~]# dnf install /usr/sbin/named\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:471 +msgid "" +"[command]#dnf# then searches through its package lists, finds the package " +"which provides `/usr/sbin/named`, if any, and prompts you as to whether you " +"want to install it." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:473 +#, no-wrap +msgid "Finding which package owns a file" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:478 +msgid "" +"If you know you want to install the package that contains the `named` " +"binary, but you do not know in which `/usr/bin` or `/usr/sbin` directory the " +"file is installed, use the [command]#dnf provides# command with a glob " +"expression:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:484 +#, no-wrap +msgid "" +"~]# dnf provides \"*bin/named\"\n" +"Using metadata from Thu Apr 16 13:41:45 2015 (4:23:50 hours old)\n" +"bind-32:9.10.2-1.fc22.x86_64 : The Berkeley Internet Name Domain (BIND) DNS " +"(Domain Name System) server\n" +"Repo : @System\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:487 +msgid "" +"[command]#dnf provides " +"\"*/pass:attributes[{blank}]_file_name_pass:attributes[{blank}]\"# will find " +"all the packages that contain _file_name_." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:490 +#, no-wrap +msgid "" +"Installing a Package Groupindexterm:[packages,installing a package group " +"with DNF]indexterm:[DNF,installing a package group with DNF]" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:492 +msgid "" +"A package group is similar to a package: it is not useful by itself, but " +"installing one pulls a group of dependent packages that serve a common " +"purpose. A package group has a name and a _groupid_ (*GID*). The " +"[command]#dnf group list -v# command lists the names of all package groups, " +"and, next to each of them, their groupid in parentheses. The groupid is " +"always the term in the last pair of parentheses, such as " +"`kde-desktop-environment` in the following example:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:508 +#, no-wrap +msgid "" +"~]# dnf -v group list kde\\*\n" +"cachedir: /var/cache/dnf/x86_64/22\n" +"Loaded plugins: builddep, config-manager, copr, playground, " +"debuginfo-install, download, generate_completion_cache, kickstart, " +"needs-restarting, noroot, protected_packages, Query, reposync, langpacks\n" +"initialized Langpacks plugin\n" +"DNF version: 0.6.5\n" +"repo: using cache for: fedora\n" +"not found deltainfo for: Fedora 22 - x86_64\n" +"not found updateinfo for: Fedora 22 - x86_64\n" +"repo: using cache for: updates-testing\n" +"repo: using cache for: updates\n" +"not found updateinfo for: Fedora 22 - x86_64 - Updates\n" +"Using metadata from Thu Apr 16 13:41:45 2015 (4:37:51 hours old)\n" +"Available environment groups:\n" +" KDE Plasma Workspaces (kde-desktop-environment)\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:511 +msgid "" +"You can install a package group by passing its full group name (without the " +"groupid part) to [command]#group install#:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:515 +#, no-wrap +msgid "dnf group install pass:quotes[_group_name_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:518 +msgid "Multi-word names must be quoted." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:520 +msgid "You can also install by groupid:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:524 +#, no-wrap +msgid "[command]#dnf# [option]`group install` _groupid_\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:527 +msgid "" +"You can even pass the groupid, or quoted name, to the [command]#install# " +"command if you prepend it with an @-symbol (which tells [command]#dnf# that " +"you want to perform a [command]#group install#):" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:531 +#, no-wrap +msgid "[command]#dnf# [option]`install` @pass:attributes[{blank}]_group_\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:534 +msgid "" +"For example, the following are alternative but equivalent ways of installing " +"the `KDE Plasma Workspaces` group:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:539 +#, no-wrap +msgid "" +"~]# dnf group install \"KDE Plasma Workspaces\"\n" +"~]# dnf group install kde-desktop-environment\n" +"~]# dnf install @kde-desktop-environment\n" +msgstr "" + +#. type: Title === +#: ./pages/package-management/DNF.adoc:542 +#, no-wrap +msgid "Removing Packages" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:545 +msgid "" +"indexterm:[packages,uninstalling packages with " +"DNF]indexterm:[DNF,uninstalling packages with DNF] Similarly to package " +"installation, DNF allows you to uninstall (remove in [application]*RPM* and " +"DNF terminology) both individual packages and a package group." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:546 +#, no-wrap +msgid "" +"Removing Individual Packagesindexterm:[packages,uninstalling packages with " +"DNF,dnf remove package_name]indexterm:[DNF,uninstalling packages with " +"DNF,dnf remove package_name]" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:548 +msgid "" +"To uninstall a particular package, as well as any packages that depend on " +"it, run the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:552 +#, no-wrap +msgid "dnf remove pass:quotes[_package_name_]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:555 +msgid "" +"As when you install multiple packages, you can remove several at once by " +"adding more package names to the command. For example, to remove " +"[package]*totem*, [package]*rhythmbox*, and [package]*sound-juicer*, type " +"the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:558 +#, no-wrap +msgid "~]# dnf remove totem rhythmbox sound-juicer\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:561 +msgid "Similar to [command]#install#, [command]#remove# can take these arguments:" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:563 +msgid "package names" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:565 +msgid "glob expressions" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:567 +msgid "file lists" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:569 +msgid "package provides" +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:571 +#, no-wrap +msgid "Removing a package when other packages depend on it" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:576 +msgid "" +"DNF is not able to remove a package without also removing packages which " +"depend on it. This type of operation can only be performed by " +"[application]*RPM*, is not advised, and can potentially leave your system in " +"a non-functioning state or cause applications to misbehave and terminate " +"unexpectedly. For further information, refer to " +"xref:RPM.adoc#s2-rpm-uninstalling[Uninstalling Packages] in the " +"[application]*RPM* chapter." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:579 +#, no-wrap +msgid "Removing a Package Group" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:581 +msgid "" +"You can remove a package group using syntax congruent with the " +"[command]#install# syntax:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:585 +#, no-wrap +msgid "[command]#dnf# [option]`group remove` _group_\n" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:590 +#, no-wrap +msgid "[command]#dnf# [option]`remove` @pass:attributes[{blank}]_group_\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:593 +msgid "" +"The following are alternative but equivalent ways of removing the `KDE " +"Plasma Workspaces` group:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:598 +#, no-wrap +msgid "" +"~]# dnf group remove \"KDE Plasma Workspaces\"\n" +"~]# dnf group remove kde-desktop-environment\n" +"~]# dnf remove @kde-desktop-environment\n" +msgstr "" + +#. type: Title === +#: ./pages/package-management/DNF.adoc:601 +#, no-wrap +msgid "Working with Transaction History" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:604 +msgid "" +"The [command]#dnf history# command allows users to review information about " +"a timeline of DNF transactions, the dates and times on when they occurred, " +"the number of packages affected, whether transactions succeeded or were " +"aborted, and if the RPM database was changed between " +"transactions. Additionally, this command can be used to undo or redo certain " +"transactions." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:605 +#, no-wrap +msgid "Listing Transactions" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:607 +msgid "" +"To display a list of all transactions, as `root`, either run [command]#dnf " +"history# with no additional arguments, or enter the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:611 +#, no-wrap +msgid "[command]#dnf# [option]`history` [option]`list`\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:614 +msgid "" +"To display only transactions in a given range, use the command in the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:618 +#, no-wrap +msgid "dnf history list pass:quotes[_start_id_]..pass:quotes[_end_id_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:621 +msgid "" +"You can also list only transactions regarding a particular package or " +"packages. To do so, use the command with a package name or a glob " +"expression:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:625 +#, no-wrap +msgid "dnf history list pass:quotes[_glob_expression_]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:628 +msgid "For example, the list of first five transactions may look as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:633 +#, no-wrap +msgid "" +"~]# dnf history list 1..4\n" +"Using metadata from Thu Apr 16 13:41:45 2015 (5:47:31 hours old)\n" +"ID | Login user | Date a | Action | Altere\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:638 +#, no-wrap +msgid "" +" 4 | root | 2015-04-16 18:35 | Erase | " +"1\n" +" 3 | root | 2015-04-16 18:34 | Install | " +"1\n" +" 2 | root | 2015-04-16 17:53 | Install | " +"1\n" +" 1 | System | 2015-04-16 14:14 | Install | 668 " +"E\n" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:641 +#, no-wrap +msgid "" +"The [command]#dnf history list# command produces tabular output with each " +"row consisting of the following columns:\n" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:643 +#, no-wrap +msgid "* `ID` — an integer value that identifies a particular transaction.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:645 +#, no-wrap +msgid "" +"* `Login user` — the name of the user whose login session was used to " +"initiate a transaction. This information is typically presented in the " +"`pass:attributes[{blank}]_Full Name_ " +"_pass:attributes[{blank}]` form, however " +"sometimes the command used to perform the transaction is displayed. For " +"transactions that were not issued by a user (such as an automatic system " +"update), `System ` is used instead.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:647 +#, no-wrap +msgid "* `Date and time` — the date and time when a transaction was issued.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:649 +#, no-wrap +msgid "" +"* `Action(s)` — a list of actions that were performed during a " +"transaction as described in " +"xref:DNF.adoc#tabl-DNF-Transaction_History-Actions[Possible values of the " +"Action(s) field].\n" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:651 +#, no-wrap +msgid "" +"* `Altered` — the number of packages that were affected by a " +"transaction, possibly followed by additional information.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:654 +#, no-wrap +msgid "" +"[[tabl-DNF-Transaction_History-Actions]]\n" +".Possible values of the Action(s) field\n" +msgstr "" + +#. type: Table +#: ./pages/package-management/DNF.adoc:664 +#, no-wrap +msgid "" +"[options=\"header\"]\n" +"|Action|Abbreviation|Description\n" +"|`Downgrade`|`D`|At least one package has been downgraded to an older " +"version.\n" +"|`Erase`|`E`|At least one package has been removed.\n" +"|`Install`|`I`|At least one new package has been installed.\n" +"|`Obsoleting`|`O`|At least one package has been marked as obsolete.\n" +"|`Reinstall`|`R`|At least one package has been reinstalled.\n" +"|`Update`|`U`|At least one package has been updated to a newer version.\n" +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:666 +#, no-wrap +msgid "Reverting and Repeating Transactions" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:668 +msgid "" +"Apart from reviewing the transaction history, the [command]#dnf history# " +"command provides means to revert or repeat a selected transaction. To revert " +"a transaction, type the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:672 +#, no-wrap +msgid "[command]#dnf# [option]`history` [option]`undo` _id_\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:675 +msgid "To repeat a particular transaction, as `root`, run the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:679 +#, no-wrap +msgid "[command]#dnf# [option]`history` [option]`redo` _id_\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:682 +msgid "" +"Both commands also accept the `last` keyword to undo or repeat the latest " +"transaction." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:684 +msgid "" +"Note that both [command]#dnf history undo# and [command]#dnf history redo# " +"commands merely revert or repeat the steps that were performed during a " +"transaction, and will fail if the required packages are not available. For " +"example, if the transaction installed a new package, the [command]#dnf " +"history undo# command will uninstall it and also attempt to downgrade all " +"updated packages to their previous version, but the command will fail if the " +"required packages are not available." +msgstr "" + +#. type: Title == +#: ./pages/package-management/DNF.adoc:686 +#, no-wrap +msgid "Configuring DNF and DNF Repositories" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:689 +msgid "" +"indexterm:[DNF,configuring DNF and DNF repositories]indexterm:[DNF,DNF " +"repositories,configuring DNF and DNF repositories] The configuration file " +"for DNF and related utilities is located at `/etc/dnf/dnf.conf`. This file " +"contains one mandatory `[main]` section, which allows you to set DNF options " +"that have global effect, and may also contain one or more " +"`[pass:attributes[{blank}]_repository_pass:attributes[{blank}]]` sections, " +"which allow you to set repository-specific options. However, it is " +"recommended to define individual repositories in new or existing `.repo` " +"files in the `/etc/yum.repos.d/` directory. The values you define in " +"individual `[pass:attributes[{blank}]_repository_pass:attributes[{blank}]]` " +"sections of the `/etc/dnf/dnf.conf` file override values set in the `[main]` " +"section." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:691 +msgid "This section shows you how to:" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:693 +msgid "" +"set global DNF options by editing the `[main]` section of the " +"`/etc/dnf/dnf.conf` configuration file;" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:695 +msgid "" +"set options for individual repositories by editing the " +"`[pass:attributes[{blank}]_repository_pass:attributes[{blank}]]` sections in " +"`/etc/dnf/dnf.conf` and `.repo` files in the `/etc/yum.repos.d/` directory;" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:697 +msgid "" +"use DNF variables in `/etc/dnf/dnf.conf` and files in the " +"`/etc/yum.repos.d/` directory so that dynamic version and architecture " +"values are handled correctly;" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:699 +msgid "add, enable, and disable DNF repositories on the command line; and," +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:701 +msgid "set up your own custom DNF repository." +msgstr "" + +#. type: Title === +#: ./pages/package-management/DNF.adoc:703 +#, no-wrap +msgid "Setting [main] Options" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:706 +msgid "" +"indexterm:[DNF,setting [main] options] The `/etc/dnf/dnf.conf` configuration " +"file contains exactly one `[main]` section, and while some of the key-value " +"pairs in this section affect how [command]#dnf# operates, others affect how " +"DNF treats repositories." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:708 +msgid "" +"You can add many additional options under the `[main]` section heading in " +"`/etc/dnf/dnf.conf`." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:710 +msgid "A sample `/etc/dnf/dnf.conf` configuration file can look like this:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:716 +#, no-wrap +msgid "" +"[main]\n" +"gpgcheck=1\n" +"installonly_limit=3\n" +"clean_requirements_on_remove=true\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:719 +msgid "The following are the most commonly-used options in the `[main]` section:" +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:720 +#, no-wrap +msgid "[option]`debuglevel`pass:attributes[{blank}]=pass:attributes[{blank}]_value_" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:721 +#: ./pages/package-management/DNF.adoc:727 +#: ./pages/package-management/DNF.adoc:744 +#: ./pages/package-management/DNF.adoc:750 +#: ./pages/package-management/DNF.adoc:776 +#: ./pages/package-management/DNF.adoc:780 +#: ./pages/package-management/DNF.adoc:805 +msgid "{blank}" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:723 +msgid "" +"…where _value_ is an integer between `0` and `10`. Setting a higher " +"[option]`debuglevel` value causes [command]#dnf# to display more detailed " +"debugging output. [option]`debuglevel=0` disables debugging output, and " +"[option]`debuglevel=2` is the default." +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:724 +#, no-wrap +msgid "[option]`exclude`pass:attributes[{blank}]=pass:attributes[{blank}]_package_name_pass:attributes[{blank}] pass:attributes[{blank}]_more_package_names_" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:725 +msgid "" +"This option allows you to exclude packages by keyword during installation " +"and updates. Listing multiple packages for exclusion can be accomplished by " +"quoting a space-delimited list of packages. Shell globs using wildcards (for " +"example, `*` and `?`) are allowed." +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:726 +#, no-wrap +msgid "[option]`gpgcheck`pass:attributes[{blank}]=pass:attributes[{blank}]_value_" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:729 +#: ./pages/package-management/DNF.adoc:752 +#: ./pages/package-management/DNF.adoc:807 +msgid "…where _value_ is one of:" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:731 +msgid "" +"`0` — Disable GPG signature-checking on packages in all repositories, " +"including local package installation." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:733 +msgid "" +"`1` — Enable GPG signature-checking on all packages in all repositories, " +"including local package installation. [option]`gpgcheck=1` is the default, " +"and thus all packages' signatures are checked." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:735 +msgid "" +"If this option is set in the `[main]` section of the `/etc/dnf/dnf.conf` " +"file, it sets the GPG-checking rule for all repositories. However, you can " +"also set " +"[option]`gpgcheck=pass:attributes[{blank}]_value_pass:attributes[{blank}]` " +"for individual repositories instead; you can enable GPG-checking on one " +"repository while disabling it on another. Setting " +"[option]`gpgcheck=pass:attributes[{blank}]_value_pass:attributes[{blank}]` " +"for an individual repository in its corresponding `.repo` file overrides the " +"default if it is present in `/etc/dnf/dnf.conf`." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:737 +msgid "" +"For more information on GPG signature-checking, refer to " +"xref:RPM.adoc#s1-check-rpm-sig[Checking Package Signatures]." +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:738 +#, no-wrap +msgid "[option]`installonlypkgs`pass:attributes[{blank}]=pass:attributes[{blank}]_space_pass:attributes[{blank}] pass:attributes[{blank}]_separated_pass:attributes[{blank}] pass:attributes[{blank}]_list_pass:attributes[{blank}] pass:attributes[{blank}]_of_pass:attributes[{blank}] pass:attributes[{blank}]_packages_" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:739 +msgid "" +"Here you can provide a space-separated list of packages which [command]#dnf# " +"can *install*, but will never *update*. See the *dnf.conf*(5) manual page " +"for the list of packages which are install-only by default." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:741 +msgid "" +"If you add the [option]`installonlypkgs` directive to `/etc/dnf/dnf.conf`, " +"you should ensure that you list *all* of the packages that should be " +"install-only, including any of those listed under the `installonlypkgs` " +"section of *dnf.conf*(5). In particular, kernel packages should always be " +"listed in [option]`installonlypkgs` (as they are by default), and " +"[option]`installonly_limit` should always be set to a value greater than `2` " +"so that a backup kernel is always available in case the default one fails to " +"boot." +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:743 +#, no-wrap +msgid "[option]`installonly_limit`pass:attributes[{blank}]=pass:attributes[{blank}]_value_" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:746 +msgid "" +"…where _value_ is an integer representing the maximum number of versions " +"that can be installed simultaneously for any single package listed in the " +"[option]`installonlypkgs` directive." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:748 +msgid "" +"The defaults for the [option]`installonlypkgs` directive include several " +"different kernel packages, so be aware that changing the value of " +"[option]`installonly_limit` will also affect the maximum number of installed " +"versions of any single kernel package. The default value listed in " +"`/etc/dnf/dnf.conf` is [option]`installonly_limit=3`, and it is not " +"recommended to decrease this value, particularly below `2`." +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:749 +#, no-wrap +msgid "[option]`keepcache`pass:attributes[{blank}]=pass:attributes[{blank}]_value_" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:754 +msgid "" +"`0` — Do not retain the cache of headers and packages after a successful " +"installation. This is the default." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:756 +msgid "`1` — Retain the cache after a successful installation." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:758 +msgid "" +"For a complete list of available `[main]` options, refer to the `[MAIN] " +"OPTIONS` section of the *dnf.conf*(5) manual page." +msgstr "" + +#. type: Title === +#: ./pages/package-management/DNF.adoc:760 +#, no-wrap +msgid "Setting [repository] Options" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:763 +msgid "" +"indexterm:[DNF,setting [repository] options] The " +"`[pass:attributes[{blank}]_repository_pass:attributes[{blank}]]` sections, " +"where _repository_ is a unique repository ID such as `my_personal_repo` " +"(spaces are not permitted), allow you to define individual DNF repositories." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:765 +msgid "" +"The following is a bare-minimum example of the form a " +"`[pass:attributes[{blank}]_repository_pass:attributes[{blank}]]` section " +"takes:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:771 +#, no-wrap +msgid "" +"[pass:quotes[_repository_]]\n" +"name=pass:quotes[_repository_name_]\n" +"baseurl=pass:quotes[_repository_url_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:774 +msgid "" +"Every `[pass:attributes[{blank}]_repository_pass:attributes[{blank}]]` " +"section must contain the following directives:" +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:775 +#, no-wrap +msgid "[option]`name`pass:attributes[{blank}]=pass:attributes[{blank}]_repository_name_" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:778 +msgid "" +"…where _repository_name_ is a human-readable string describing the " +"repository." +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:779 +#, no-wrap +msgid "_parameter_pass:attributes[{blank}]=pass:attributes[{blank}]_repository_url_" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:782 +msgid "" +"…where _parameter_ is one of the following: [option]`baseurl`, " +"[option]`metalink`, or [option]`mirrorlist`pass:attributes[{blank}];" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:784 +msgid "" +"…where _repository_url_ is a URL to a directory containing a `repodata` " +"directory of a repository, a metalink file, or a mirror list file." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:786 +msgid "If the repository is available over HTTP, use: `http://path/to/repo`" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:788 +msgid "If the repository is available over FTP, use: `ftp://path/to/repo`" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:790 +msgid "If the repository is local to the machine, use: `file:///path/to/local/repo`" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:792 +msgid "" +"If a specific online repository requires basic HTTP authentication, you can " +"specify your user name and password by prepending it to the URL as " +"[option]`pass:attributes[{blank}]_username_:pass:attributes[{blank}]_password_pass:attributes[{blank}]@pass:attributes[{blank}]_link_pass:attributes[{blank}]`. " +"For example, if a repository on http://www.example.com/repo/ requires a " +"username of \"`user`\" and a password of \"`password`\", then the " +"[option]`baseurl` link could be specified as " +"[option]`http://user:password@www.example.com/repo/`." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:794 +msgid "Usually this URL is an HTTP link, such as:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:798 +#, no-wrap +msgid "baseurl=http://path/to/repo/releases/$releasever/server/$basearch/os/\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:801 +msgid "" +"Note that DNF always expands the `$releasever`, `$arch`, and `$basearch` " +"variables in URLs. For more information about DNF variables, refer to " +"xref:DNF.adoc#sec-Using_DNF_Variables[Using DNF Variables]." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:803 +msgid "" +"To configure the default set of repositories, use the [option]`enabled` " +"option as follows:" +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:804 +#, no-wrap +msgid "[option]`enabled`pass:attributes[{blank}]=pass:attributes[{blank}]_value_" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:809 +msgid "" +"`0` — Do not include this repository as a package source when performing " +"updates and installs." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:811 +msgid "`1` — Include this repository as a package source." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:813 +msgid "" +"Turning repositories on and off can also be performed by passing either the " +"[option]`--set-enabled _repo_name_pass:attributes[{blank}]` or " +"[option]`--set-disabled _repo_name_pass:attributes[{blank}]` option to the " +"[command]#dnf# command, or through the `Add/Remove Software` window of the " +"[application]*PackageKit* utility." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:815 +msgid "" +"Many more `[pass:attributes[{blank}]_repository_pass:attributes[{blank}]]` " +"options exist. For a complete list, refer to the `[repository] OPTIONS` " +"section of the *dnf.conf*(5) manual page." +msgstr "" + +#. type: Title === +#: ./pages/package-management/DNF.adoc:817 +#, no-wrap +msgid "Using DNF Variables" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:820 +msgid "" +"indexterm:[DNF,variables] Variables can be used only in the appropriate " +"sections of the DNF configuration files, namely the `/etc/dnf/dnf.conf` file " +"and all `.repo` files in the `/etc/yum.repos.d/` directory. Repository " +"variables include:" +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:821 +#, no-wrap +msgid "`$releasever`" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:822 +msgid "" +"Refers to the release version of operating system which DNF derives from " +"information available in RPMDB." +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:823 +#, no-wrap +msgid "`$arch`" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:824 +msgid "" +"Refers to the system’s CPU architecture. Valid values for `$arch` include: " +"`i586`, `i686` and `x86_64`." +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:825 +#, no-wrap +msgid "`$basearch`" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:826 +msgid "" +"Refers to the base architecture of the system. For example, i686 and i586 " +"machines both have a base architecture of `i386`, and AMD64 and Intel64 " +"machines have a base architecture of `x86_64`." +msgstr "" + +#. type: Title == +#: ./pages/package-management/DNF.adoc:828 +#, no-wrap +msgid "Viewing the Current Configuration" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:831 +msgid "" +"To list all configuration options and their corresponding values, and the " +"repositories, execute the [command]#dnf config-manager# command with the " +"[option]`--dump` option:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:845 +#, no-wrap +msgid "" +"~]${nbsp}dnf config-manager --dump\n" +"============================= main ======================================\n" +"[main]\n" +"alwaysprompt = True\n" +"assumeno = False\n" +"assumeyes = False\n" +"bandwidth = 0\n" +"best = False\n" +"bugtracker_url = " +"https://bugzilla.redhat.com/enter_bug.cgi?product=Fedora&component=dnf\n" +"cachedir = /var/cache/dnf/x86_64/22\n" +"[output truncated]\n" +msgstr "" + +#. type: Title == +#: ./pages/package-management/DNF.adoc:848 +#, no-wrap +msgid "Adding, Enabling, and Disabling a DNF Repository" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:851 +msgid "" +"indexterm:[DNF,repository] " +"xref:DNF.adoc#sec-Setting_repository_Options[Setting [repository] Options] " +"describes various options you can use to define a DNF repository. This " +"section explains how to add, enable, and disable a repository by using the " +"[command]#dnf config-manager# command." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:852 +#, no-wrap +msgid "Adding a DNF Repository" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:854 +msgid "" +"To define a new repository, you can either add a " +"`[pass:attributes[{blank}]_repository_pass:attributes[{blank}]]` section to " +"the `/etc/dnf/dnf.conf` file, or to a `.repo` file in the " +"`/etc/yum.repos.d/` directory. All files with the `.repo` file extension in " +"this directory are read by DNF, and it is recommended to define your " +"repositories here instead of in `/etc/dnf/dnf.conf`." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:856 +msgid "" +"DNF repositories commonly provide their own `.repo` file. To add such a " +"repository to your system and enable it, run the following command as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:860 +#, no-wrap +msgid "dnf config-manager --add-repo pass:quotes[_repository_url_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:863 +msgid "…where _repository_url_ is a link to the `.repo` file." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:865 +#, no-wrap +msgid "Adding example.repo" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:869 +msgid "" +"To add a repository located at http://www.example.com/example.repo, type the " +"following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:874 +#, no-wrap +msgid "" +"~]#{nbsp}dnf config-manager --add-repo http://www.example.com/example.repo\n" +"adding repo from: http://www.example.com/example.repo\n" +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:878 +#, no-wrap +msgid "Enabling a DNF Repository" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:880 +msgid "" +"To enable a particular repository or repositories, type the following at a " +"shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:884 +#, no-wrap +msgid "" +"[command]#dnf config-manager# [option]`--set-enabled` " +"_repository_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:887 +#: ./pages/package-management/DNF.adoc:897 +msgid "" +"…where _repository_ is the unique repository ID. To display the " +"current configuration, add the [option]`--dump` option." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:888 +#, no-wrap +msgid "Disabling a DNF Repository" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:890 +msgid "To disable a DNF repository, run the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:894 +#, no-wrap +msgid "" +"[command]#dnf config-manager# [option]`--set-disabled` " +"_repository_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Title == +#: ./pages/package-management/DNF.adoc:899 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:901 +msgid "indexterm:[DNF,Additional Resources]" +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:901 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:904 +msgid "`dnf(8)` — The DNF command reference manual page." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:906 +msgid "`dnf.conf(8)` — DNF Configuration Reference manual page." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:907 +#, no-wrap +msgid "Online Documentation" +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:909 +#, no-wrap +msgid "link:++https://dnf.readthedocs.org/en/latest/index.html++[]" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:909 +msgid "The DNF wiki contains more documentation." +msgstr "" diff --git a/po/fr/rawhide/pages/package-management/intro-package-management.po b/po/fr/rawhide/pages/package-management/intro-package-management.po new file mode 100644 index 00000000000..62e3f862652 --- /dev/null +++ b/po/fr/rawhide/pages/package-management/intro-package-management.po @@ -0,0 +1,71 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/package-management/intro-package-management.adoc:3 +#, no-wrap +msgid "Package Management" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/intro-package-management.adoc:6 +msgid "" +"There are two types of {MAJOROS} system; \"`traditional`\", which use DNF, " +"and \"`image-based`\" which use rpm-ostree." +msgstr "" + +#. type: Title == +#: ./pages/package-management/intro-package-management.adoc:7 +#, no-wrap +msgid "Traditional package management" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/intro-package-management.adoc:11 +msgid "" +"On a traditional {MAJOROS} system, software is divided into RPM packages, " +"which can be managed via [application]*DNF*." +msgstr "" + +#. type: Title == +#: ./pages/package-management/intro-package-management.adoc:12 +#, no-wrap +msgid "Hybrid image/package management" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/intro-package-management.adoc:19 +msgid "" +"The \"`Atomic`\" variant of {MAJOROS} uses [application]*rpm-ostree* to " +"update the host. `rpm-ostree` is a hybrid image/package system. By default, " +"installations are in \"`image`\" mode using OSTree, but additional packages " +"can be installed. It also supports overrides, rebases, and many other " +"features. For more information, see " +"link:++https://www.projectatomic.io/docs/os-updates/++[its online " +"documentation]." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/intro-package-management.adoc:22 +msgid "" +"Additionally, the `atomic` CLI supports installation of system containers, " +"which are Docker/OCI images distinct from the host user space. For more " +"information, see " +"link:++https://www.projectatomic.io/docs/usr-bin-atomic/++[its online " +"documentation]." +msgstr "" diff --git a/po/fr/rawhide/pages/package-management/rpm-ostree.po b/po/fr/rawhide/pages/package-management/rpm-ostree.po new file mode 100644 index 00000000000..f140c5fc1f5 --- /dev/null +++ b/po/fr/rawhide/pages/package-management/rpm-ostree.po @@ -0,0 +1,38 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/package-management/rpm-ostree.adoc:5 +#, no-wrap +msgid "rpm-ostree" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/rpm-ostree.adoc:10 +msgid "" +"[application]*rpm-ostree* is a hybrid image/package system for {OSORG}. One " +"of the most important things to understand is that available RPMs come from " +"the same `/etc/yum.repos.d` sources." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/rpm-ostree.adoc:11 +msgid "" +"For more information, see the " +"link:https://coreos.github.io/rpm-ostree/[upstream documentation]." +msgstr "" diff --git a/po/fr/rawhide/pages/pam_userdb.po b/po/fr/rawhide/pages/pam_userdb.po new file mode 100644 index 00000000000..b012c09210a --- /dev/null +++ b/po/fr/rawhide/pages/pam_userdb.po @@ -0,0 +1,94 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/pam_userdb.adoc:5 +#, no-wrap +msgid "pam_userdb" +msgstr "" + +#. type: Plain text +#: ./pages/pam_userdb.adoc:8 +msgid "" +"pam_userdb is a PAM module to authenticate against a db database. It is used " +"to verify a username/password pair against values stored in a key/data pairs " +"style database (i.e. Berkeley DB, GDBM). The database is indexed by the " +"username, and the data fields corresponding to the username keys are the " +"passwords. This module is most notably used in vsftpd environments." +msgstr "" + +#. type: Plain text +#: ./pages/pam_userdb.adoc:10 +msgid "" +"Recently, pam_userdb switched its database provider from Berkeley DB to " +"GDBM. If your system uses this module to authenticate users you need to " +"convert the database to the new format." +msgstr "" + +#. type: Title == +#: ./pages/pam_userdb.adoc:11 +#, no-wrap +msgid "Determining whether you are using pam_userdb" +msgstr "" + +#. type: Plain text +#: ./pages/pam_userdb.adoc:13 +msgid "The way to determine if you are using pam_userdb, is to check the PAM stack:" +msgstr "" + +#. type: delimited block - +#: ./pages/pam_userdb.adoc:18 +#, no-wrap +msgid "" +"$ grep -r pam_userdb /etc/pam.d/\n" +"/etc/pam.d/vsftpd:auth sufficient pam_userdb.so " +"db=/etc/vsftpd/login\n" +msgstr "" + +#. type: Plain text +#: ./pages/pam_userdb.adoc:21 +msgid "" +"If you are not using pam_userdb, then the search will return no values and " +"you don't have to do anything." +msgstr "" + +#. type: Title == +#: ./pages/pam_userdb.adoc:22 +#, no-wrap +msgid "Converting the database" +msgstr "" + +#. type: Plain text +#: ./pages/pam_userdb.adoc:25 +msgid "" +"libdb package contains a binary that will handle the conversion for you. You " +"only need to run it by providing the source and destination database " +"files:. Example:" +msgstr "" + +#. type: delimited block - +#: ./pages/pam_userdb.adoc:29 +#, no-wrap +msgid "$ db_converter --src /etc/vsftpd/login.db --dest /etc/vsftpd/login.gdbm\n" +msgstr "" + +#. type: Title == +#: ./pages/pam_userdb.adoc:31 +#, no-wrap +msgid "Additional Resources" +msgstr "" diff --git a/po/fr/rawhide/pages/servers/Configuring_NTP_Using_ntpd.po b/po/fr/rawhide/pages/servers/Configuring_NTP_Using_ntpd.po new file mode 100644 index 00000000000..79fca86d666 --- /dev/null +++ b/po/fr/rawhide/pages/servers/Configuring_NTP_Using_ntpd.po @@ -0,0 +1,2071 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:6 +#, no-wrap +msgid "Configuring NTP Using ntpd" +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:9 +#, no-wrap +msgid "Introduction to NTP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:12 +msgid "" +"The _Network Time Protocol_ (*NTP*) enables the accurate dissemination of " +"time and date information in order to keep the time clocks on networked " +"computer systems synchronized to a common reference over the network or the " +"Internet. Many standards bodies around the world have atomic clocks which " +"may be made available as a reference. The satellites that make up the Global " +"Position System contain more than one atomic clock, making their time " +"signals potentially very accurate. Their signals can be deliberately " +"degraded for military reasons. An ideal situation would be where each site " +"has a server, with its own reference clock attached, to act as a site-wide " +"time server. Many devices which obtain the time and date via low frequency " +"radio transmissions or the Global Position System (GPS) exist. However for " +"most situations, a range of publicly accessible time servers connected to " +"the Internet at geographically dispersed locations can be used. These `NTP` " +"servers provide \"`pass:attributes[{blank}]_Coordinated Universal " +"Time_pass:attributes[{blank}]`\" (*UTC*). Information about these time " +"servers can found at [citetitle]_www.pool.ntp.org_." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:14 +msgid "" +"Accurate time keeping is important for a number of reasons in IT. In " +"networking for example, accurate time stamps in packets and logs are " +"required. Logs are used to investigate service and security issues and so " +"time stamps made on different systems must be made by synchronized clocks to " +"be of real value. As systems and networks become increasingly faster, there " +"is a corresponding need for clocks with greater accuracy and resolution. In " +"some countries there are legal obligations to keep accurately synchronized " +"clocks. Please see [citetitle]_www.ntp.org_ for more information. In Linux " +"systems, `NTP` is implemented by a daemon running in user space. The default " +"`NTP` user space daemon in {MAJOROSVER} is `chronyd`. It must be disabled if " +"you want to use the `ntpd` daemon. See " +"xref:servers/Configuring_NTP_Using_the_chrony_Suite.adoc#ch-Configuring_NTP_Using_the_chrony_Suite[Configuring " +"NTP Using the chrony Suite] for information on [application]*chrony*." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:16 +msgid "" +"The user space daemon updates the system clock, which is a software clock " +"running in the kernel. Linux uses a software clock as its system clock for " +"better resolution than the typical embedded hardware clock referred to as " +"the \"`pass:attributes[{blank}]_Real Time Clock_pass:attributes[{blank}]`\" " +"*(RTC)*. See the `rtc(4)` and `hwclock(8)` man pages for information on " +"hardware clocks. The system clock can keep time by using various clock " +"sources. Usually, the _Time Stamp Counter_ (*TSC*) is used. The TSC is a CPU " +"register which counts the number of cycles since it was last reset. It is " +"very fast, has a high resolution, and there are no interrupts. On system " +"start, the system clock reads the time and date from the RTC. The time kept " +"by the RTC will drift away from actual time by up to 5 minutes per month due " +"to temperature variations. Hence the need for the system clock to be " +"constantly synchronized with external time references. When the system clock " +"is being synchronized by `ntpd`, the kernel will in turn update the RTC " +"every 11 minutes automatically." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:18 +#, no-wrap +msgid "NTP Strata" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:21 +msgid "" +"`NTP` servers are classified according to their synchronization distance " +"from the atomic clocks which are the source of the time signals. The servers " +"are thought of as being arranged in layers, or strata, from 1 at the top " +"down to 15. Hence the word stratum is used when referring to a specific " +"layer. Atomic clocks are referred to as Stratum 0 as this is the source, but " +"no Stratum 0 packet is sent on the Internet, all stratum 0 atomic clocks are " +"attached to a server which is referred to as stratum 1. These servers send " +"out packets marked as Stratum 1. A server which is synchronized by means of " +"packets marked stratum `n` belongs to the next, lower, stratum and will mark " +"its packets as stratum `n+1`. Servers of the same stratum can exchange " +"packets with each other but are still designated as belonging to just the " +"one stratum, the stratum one below the best reference they are synchronized " +"to. The designation Stratum 16 is used to indicate that the server is not " +"currently synchronized to a reliable time source." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:23 +msgid "" +"Note that by default `NTP` clients act as servers for those systems in the " +"stratum below them." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:25 +msgid "Here is a summary of the `NTP` Strata:" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:26 +#, no-wrap +msgid "Stratum 0" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:27 +msgid "Atomic Clocks and their signals broadcast over Radio and GPS" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:29 +msgid "GPS (Global Positioning System)" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:31 +msgid "Mobile Phone Systems" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:34 +msgid "" +"Low Frequency Radio Broadcasts+ WWVB (Colorado, USA.), JJY-40 and JJY-60 " +"(Japan), DCF77 (Germany), and MSF (United Kingdom)" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:36 +msgid "" +"These signals can be received by dedicated devices and are usually connected " +"by RS-232 to a system used as an organizational or site-wide time server." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:37 +#, no-wrap +msgid "Stratum 1" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:38 +msgid "Computer with radio clock, GPS clock, or atomic clock attached" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:39 +#, no-wrap +msgid "Stratum 2" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:40 +msgid "Reads from stratum 1; Serves to lower strata" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:41 +#, no-wrap +msgid "Stratum 3" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:42 +msgid "Reads from stratum 2; Serves to lower strata" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:43 +#, no-wrap +msgid "Stratum _n+1_" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:44 +msgid "Reads from stratum _n_pass:attributes[{blank}]; Serves to lower strata" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:45 +#, no-wrap +msgid "Stratum 15" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:46 +msgid "Reads from stratum 14; This is the lowest stratum." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:48 +msgid "" +"This process continues down to Stratum 15 which is the lowest valid " +"stratum. The label Stratum 16 is used to indicated an unsynchronized state." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:50 +#, no-wrap +msgid "Understanding NTP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:54 +msgid "" +"The version of `NTP` used by {MAJOROS} is as described in " +"[citetitle]_link:++https://www.rfc-editor.org/info/rfc1305++[RFC 1305 " +"Network Time Protocol (Version 3) Specification, Implementation and " +"Analysis]_ and " +"[citetitle]_link:++https://www.rfc-editor.org/info/rfc5905++[RFC 5905 " +"Network Time Protocol Version 4: Protocol and Algorithms Specification]_" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:56 +msgid "" +"This implementation of `NTP` enables sub-second accuracy to be " +"achieved. Over the Internet, accuracy to 10s of milliseconds is normal. On a " +"Local Area Network (LAN), 1 ms accuracy is possible under ideal " +"conditions. This is because clock drift is now accounted and corrected for, " +"which was not done in earlier, simpler, time protocol systems. A resolution " +"of 233 picoseconds is provided by using 64-bit time stamps. The first " +"32-bits of the time stamp is used for seconds, the last 32-bits are used for " +"fractions of seconds." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:58 +msgid "" +"`NTP` represents the time as a count of the number of seconds since 00:00 " +"(midnight) 1 January, 1900 GMT. As 32-bits is used to count the seconds, " +"this means the time will \"`roll over`\" in 2036. However `NTP` works on the " +"difference between time stamps so this does not present the same level of " +"problem as other implementations of time protocols have done. If a hardware " +"clock that is within 68 years of the correct time is available at boot time " +"then `NTP` will correctly interpret the current date. The `NTP4` " +"specification provides for an \"`Era Number`\" and an \"`Era Offset`\" which " +"can be used to make software more robust when dealing with time lengths of " +"more than 68 years. Note, please do not confuse this with the Unix Year 2038 " +"problem." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:60 +msgid "" +"The `NTP` protocol provides additional information to improve accuracy. Four " +"time stamps are used to allow the calculation of round-trip time and server " +"response time. In order for a system in its role as `NTP` client to " +"synchronize with a reference time server, a packet is sent with an " +"\"`originate time stamp`\". When the packet arrives, the time server adds a " +"\"`receive time stamp`\". After processing the request for time and date " +"information and just before returning the packet, it adds a \"`transmit time " +"stamp`\". When the returning packet arrives at the `NTP` client, a " +"\"`receive time stamp`\" is generated. The client can now calculate the " +"total round trip time and by subtracting the processing time derive the " +"actual traveling time. By assuming the outgoing and return trips take equal " +"time, the single-trip delay in receiving the `NTP` data is calculated. The " +"full `NTP` algorithm is much more complex than presented here." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:62 +msgid "" +"When a packet containing time information is received it is not immediately " +"responded to, but is first subject to validation checks and then processed " +"together with several other time samples to arrive at an estimate of the " +"time. This is then compared to the system clock to determine the time " +"offset, the difference between the system clock's time and what `ntpd` has " +"determined the time should be. The system clock is adjusted slowly, at most " +"at a rate of 0.5ms per second, to reduce this offset by changing the " +"frequency of the counter being used. It will take at least 2000 seconds to " +"adjust the clock by 1 second using this method. This slow change is referred " +"to as slewing and cannot go backwards. If the time offset of the clock is " +"more than 128ms (the default setting), `ntpd` can \"`step`\" the clock " +"forwards or backwards. If the time offset at system start is greater than " +"1000 seconds then the user, or an installation script, should make a manual " +"adjustment. See " +"xref:basic-system-configuration/Configuring_the_Date_and_Time.adoc#ch-Configuring_the_Date_and_Time[Configuring " +"the Date and Time]. With the [option]`-g` option to the [command]#ntpd# " +"command (used by default), any offset at system start will be corrected, but " +"during normal operation only offsets of up to 1000 seconds will be " +"corrected." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:64 +msgid "" +"Some software may fail or produce an error if the time is changed " +"backwards. For systems that are sensitive to step changes in the time, the " +"threshold can be changed to 600s instead of 128ms using the [option]`-x` " +"option (unrelated to the [option]`-g` option). Using the [option]`-x` option " +"to increase the stepping limit from 0.128s to 600s has a drawback because a " +"different method of controlling the clock has to be used. It disables the " +"kernel clock discipline and may have a negative impact on the clock " +"accuracy. The [option]`-x` option can be added to the `/etc/sysconfig/ntpd` " +"configuration file." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:66 +#, no-wrap +msgid "Understanding the Drift File" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:69 +msgid "" +"The drift file is used to store the frequency offset between the system " +"clock running at its nominal frequency and the frequency required to remain " +"in synchronization with UTC. If present, the value contained in the drift " +"file is read at system start and used to correct the clock source. Use of " +"the drift file reduces the time required to achieve a stable and accurate " +"time. The value is calculated, and the drift file replaced, once per hour by " +"`ntpd`. The drift file is replaced, rather than just updated, and for this " +"reason the drift file must be in a directory for which the `ntpd` has write " +"permissions." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:71 +#, no-wrap +msgid "UTC, Timezones, and DST" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:74 +msgid "" +"As `NTP` is entirely in UTC (Universal Time, Coordinated), Timezones and DST " +"(Daylight Saving Time) are applied locally by the system. The file " +"`/etc/localtime` is a copy of, or symlink to, a zone information file from " +"`/usr/share/zoneinfo`. The RTC may be in localtime or in UTC, as specified " +"by the 3rd line of `/etc/adjtime`, which will be one of LOCAL or UTC to " +"indicate how the RTC clock has been set. Users can easily change this " +"setting using the checkbox `System Clock Uses UTC` in the [application]*Date " +"and Time* graphical configuration tool. See " +"xref:basic-system-configuration/Configuring_the_Date_and_Time.adoc#ch-Configuring_the_Date_and_Time[Configuring " +"the Date and Time] for information on how to use that tool. Running the RTC " +"in UTC is recommended to avoid various problems when daylight saving time is " +"changed." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:76 +msgid "" +"The operation of `ntpd` is explained in more detail in the man page " +"`ntpd(8)`. The resources section lists useful sources of information. See " +"xref:Configuring_NTP_Using_ntpd.adoc#s1-ntpd_additional-resources[Additional " +"Resources]." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:78 +#, no-wrap +msgid "Authentication Options for NTP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:81 +msgid "" +"`NTPv4` added support for the Autokey Security Architecture, which is based " +"on public asymmetric cryptography while retaining support for symmetric key " +"cryptography. The Autokey Security Architecture is described in " +"[citetitle]_link:++https://www.rfc-editor.org/info/rfc5906++[RFC 5906 " +"Network Time Protocol Version 4: Autokey Specification]_. The man page " +"`ntp_auth(5)` describes the authentication options and commands for `ntpd`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:83 +msgid "" +"An attacker on the network can attempt to disrupt a service by sending `NTP` " +"packets with incorrect time information. On systems using the public pool of " +"`NTP` servers, this risk is mitigated by having more than three `NTP` " +"servers in the list of public `NTP` servers in `/etc/ntp.conf`. If only one " +"time source is compromised or spoofed, `ntpd` will ignore that source. You " +"should conduct a risk assessment and consider the impact of incorrect time " +"on your applications and organization. If you have internal time sources you " +"should consider steps to protect the network over which the `NTP` packets " +"are distributed. If you conduct a risk assessment and conclude that the risk " +"is acceptable, and the impact to your applications minimal, then you can " +"choose not to use authentication." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:85 +msgid "" +"The broadcast and multicast modes require authentication by default. If you " +"have decided to trust the network then you can disable authentication by " +"using [command]#disable auth# directive in the `ntp.conf` " +"file. Alternatively, authentication needs to be configured by using SHA1 or " +"MD5 symmetric keys, or by public (asymmetric) key cryptography using the " +"Autokey scheme. The Autokey scheme for asymmetric cryptography is explained " +"in the `ntp_auth(8)` man page and the generation of keys is explained in " +"`ntp-keygen(8`). To implement symmetric key cryptography, see " +"xref:Configuring_NTP_Using_ntpd.adoc#s2_Configuring_Symmetric_Authentication_Using_a_Key[Configuring " +"Symmetric Authentication Using a Key] for an explanation of the " +"[option]`key` option." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:87 +#, no-wrap +msgid "Managing the Time on Virtual Machines" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:90 +msgid "" +"Virtual machines cannot access a real hardware clock and a virtual clock is " +"not stable enough as the stability is dependent on the host systems work " +"load. For this reason, para-virtualized clocks should be provided by the " +"virtualization application in use (for more information see " +"_https://docs.fedoraproject.org/en-US/Fedora/18/html/Virtualization_Administration_Guide/sect-Virtualization-Tips_and_tricks-Libvirt_Managed_Timers.html[Libvirt " +"Managed Timers]_ in the _Virtualization Administration Guide_). On {MAJOROS} " +"with [application]*KVM* the default clock source is [option]`kvm-clock`. See " +"the " +"[citetitle]_link:++https://docs.fedoraproject.org/en-US/Fedora/13/html/Virtualization_Guide/chap-Virtualization-KVM_guest_timing_management.html++[KVM " +"guest timing management]_ chapter of the [citetitle]_Virtualization Host " +"Configuration and Guest Installation Guide_." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:92 +#, no-wrap +msgid "Understanding Leap Seconds" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:95 +msgid "" +"Greenwich Mean Time (GMT) was derived by measuring the solar day, which is " +"dependent on the Earth's rotation. When atomic clocks were first made, the " +"potential for more accurate definitions of time became possible. In 1958, " +"International Atomic Time (TAI) was introduced based on the more accurate " +"and very stable atomic clocks. A more accurate astronomical time, Universal " +"Time 1 (UT1), was also introduced to replace GMT. The atomic clocks are in " +"fact far more stable than the rotation of the Earth and so the two times " +"began to drift apart. For this reason UTC was introduced as a practical " +"measure. It is kept within one second of UT1 but to avoid making many small " +"trivial adjustments it was decided to introduce the concept of a _leap " +"second_ in order to reconcile the difference in a manageable way. The " +"difference between UT1 and UTC is monitored until they drift apart by more " +"than half a second. Then only is it deemed necessary to introduce a one " +"second adjustment, forward or backward. Due to the erratic nature of the " +"Earth's rotational speed, the need for an adjustment cannot be predicted far " +"into the future. The decision as to when to make an adjustment is made by " +"the [citetitle]_link:++https://www.iers.org++[International Earth Rotation " +"and Reference Systems Service (IERS)]_. However, these announcements are " +"important only to administrators of Stratum 1 servers because `NTP` " +"transmits information about pending leap seconds and applies them " +"automatically." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:97 +#, no-wrap +msgid "Understanding the ntpd Configuration File" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:100 +msgid "" +"The daemon, `ntpd`, reads the configuration file at system start or when the " +"service is restarted. The default location for the file is `/etc/ntp.conf` " +"and you can view the file by entering the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:104 +#, no-wrap +msgid "~]${nbsp}pass:attributes[{blank}][command]#less /etc/ntp.conf#\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:107 +msgid "" +"The configuration commands are explained briefly later in this chapter, see " +"xref:Configuring_NTP_Using_ntpd.adoc#s1-Configure_NTP[Configure NTP], and " +"more verbosely in the `ntp.conf(5)` man page." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:109 +msgid "" +"Here follows a brief explanation of the contents of the default " +"configuration file:" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:110 +#, no-wrap +msgid "The driftfile entry" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:111 +msgid "A path to the drift file is specified, the default entry on {MAJOROS} is:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:115 +#, no-wrap +msgid "driftfile /var/lib/ntp/drift\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:120 +msgid "" +"If you change this be certain that the directory is writable by `ntpd`. The " +"file contains one value used to adjust the system clock frequency after " +"every system or service start. See " +"xref:Configuring_NTP_Using_ntpd.adoc#s1-Understanding_the_Drift_File[Understanding " +"the Drift File] for more information." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:121 +#, no-wrap +msgid "The access control entries" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:122 +msgid "The following line sets the default access control restriction:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:126 +#, no-wrap +msgid "restrict default nomodify notrap nopeer noquery\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:129 +msgid "The [option]`nomodify` options prevents any changes to the configuration." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:131 +msgid "The [option]`notrap` option prevents `ntpdc` control message protocol traps." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:133 +msgid "The [option]`nopeer` option prevents a peer association being formed." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:135 +msgid "" +"The [option]`noquery` option prevents `ntpq` and `ntpdc` queries, but not " +"time queries, from being answered." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:140 +msgid "" +"The `ntpq` and `ntpdc` queries can be used in amplification attacks, " +"therefore do not remove the [option]`noquery` option from the " +"[command]#restrict default# command on publicly accessible systems." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:142 +msgid "" +"See " +"[citetitle]_link:++https://access.redhat.com/security/cve/CVE-2013-5211++[CVE-2013-5211]_ " +"for more details." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:146 +msgid "" +"Addresses within the range `127.0.0.0/8` are sometimes required by various " +"processes or applications. As the \"`restrict default`\" line above prevents " +"access to everything not explicitly allowed, access to the standard loopback " +"address for `IPv4` and `IPv6` is permitted by means of the following lines:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:151 +#, no-wrap +msgid "" +"# the administrative functions.\n" +"restrict 127.0.0.1\n" +"restrict ::1\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:154 +msgid "" +"Addresses can be added underneath if specifically required by another " +"application." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:156 +msgid "" +"Hosts on the local network are not permitted because of the \"`restrict " +"default`\" line above. To change this, for example to allow hosts from the " +"`192.0.2.0/24` network to query the time and statistics but nothing more, a " +"line in the following format is required:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:160 +#, no-wrap +msgid "restrict 192.0.2.0 mask 255.255.255.0 nomodify notrap nopeer\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:163 +msgid "" +"To allow unrestricted access from a specific host, for example " +"`192.0.2.250/32`, a line in the following format is required:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:167 +#, no-wrap +msgid "restrict 192.0.2.250\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:170 +msgid "A mask of `255.255.255.255` is applied if none is specified." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:172 +msgid "The restrict commands are explained in the `ntp_acc(5)` man page." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:173 +#, no-wrap +msgid "The public servers entry" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:174 +msgid "By default, the `ntp.conf` file contains four public server entries:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:182 +#, no-wrap +msgid "" +"server 0.fedora.pool.ntp.org iburst\n" +"server 1.fedora.pool.ntp.org iburst\n" +"server 2.fedora.pool.ntp.org iburst\n" +"server 3.fedora.pool.ntp.org iburst\n" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:184 +#, no-wrap +msgid "The broadcast multicast servers entry" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:185 +msgid "" +"By default, the `ntp.conf` file contains some commented out examples. These " +"are largely self explanatory. See " +"xref:Configuring_NTP_Using_ntpd.adoc#s1-Configure_NTP[Configure NTP] for the " +"explanation of the specific commands. If required, add your commands just " +"below the examples." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:190 +msgid "" +"When the `DHCP` client program, [application]*dhclient*, receives a list of " +"`NTP` servers from the `DHCP` server, it adds them to `ntp.conf` and " +"restarts the service. To disable that feature, add [command]#PEERNTP=no# to " +"`/etc/sysconfig/network`." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:194 +#, no-wrap +msgid "Understanding the ntpd Sysconfig File" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:197 +msgid "" +"The file will be read by the `ntpd` init script on service start. The " +"default contents is as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:201 +#, no-wrap +msgid "" +"# Command line options for ntpd\n" +"OPTIONS=\"-g\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:204 +msgid "" +"The [option]`-g` option enables `ntpd` to ignore the offset limit of 1000s " +"and attempt to synchronize the time even if the offset is larger than 1000s, " +"but only on system start. Without that option [application]*ntpd* will exit " +"if the time offset is greater than 1000s. It will also exit after system " +"start if the service is restarted and the offset is greater than 1000s even " +"with the [option]`-g` option." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:206 +#, no-wrap +msgid "Disabling chrony" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:209 +msgid "" +"In order to use `ntpd` the default user space daemon, `chronyd`, must be " +"stopped and disabled. Issue the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:213 +#, no-wrap +msgid "~]#{nbsp}systemctl stop chronyd\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:216 +msgid "" +"To prevent it restarting at system start, issue the following command as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:220 +#, no-wrap +msgid "~]#{nbsp}systemctl disable chronyd\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:223 +msgid "To check the status of `chronyd`, issue the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:227 +#, no-wrap +msgid "~]${nbsp}pass:attributes[{blank}][command]#systemctl status chronyd#\n" +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:230 +#, no-wrap +msgid "Checking if the NTP Daemon is Installed" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:233 +msgid "To check if `ntpd` is installed, enter the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:237 +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:249 +#, no-wrap +msgid "~]#{nbsp}dnf install ntp\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:240 +msgid "" +"`NTP` is implemented by means of the daemon or service `ntpd`, which is " +"contained within the [package]*ntp* package." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:242 +#, no-wrap +msgid "Installing the NTP Daemon (ntpd)" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:245 +msgid "To install `ntpd`, enter the following command as `root`:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:252 +msgid "To enable `ntpd` at system start, enter the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:256 +#, no-wrap +msgid "~]#{nbsp}systemctl enable ntpd\n" +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:259 +#, no-wrap +msgid "Checking the Status of NTP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:262 +msgid "" +"To check if `ntpd` is running and configured to run at system start, issue " +"the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:266 +#, no-wrap +msgid "~]${nbsp}pass:attributes[{blank}][command]#systemctl status ntpd#\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:269 +msgid "To obtain a brief status report from `ntpd`, issue the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:276 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#ntpstat#\n" +"unsynchronised\n" +" time server re-starting\n" +" polling server every 64 s\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:284 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#ntpstat#\n" +"synchronised to NTP server (10.5.26.10) at stratum 2\n" +" time correct to within 52 ms\n" +" polling server every 1024 s\n" +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:287 +#, no-wrap +msgid "Configure the Firewall to Allow Incoming NTP Packets" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:290 +msgid "" +"The `NTP` traffic consists of `UDP` packets on port `123` and needs to be " +"permitted through network and host-based firewalls in order for `NTP` to " +"function." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:292 +msgid "" +"Check if the firewall is configured to allow incoming `NTP` traffic for " +"clients using the graphical [application]*Firewall Configuration* tool." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:294 +msgid "" +"To start the graphical [application]*firewall-config* tool, press the " +"kbd:[Super] key to enter the Activities Overview, type [command]#firewall# " +"and then press kbd:[Enter]. The `Firewall Configuration` window opens. You " +"will be prompted for your user password." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:296 +msgid "" +"To start the graphical firewall configuration tool using the command line, " +"enter the following command as `root` user:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:300 +#, no-wrap +msgid "~]#{nbsp}firewall-config\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:303 +msgid "" +"The `Firewall Configuration` window opens. Note, this command can be run as " +"normal user but you will then be prompted for the `root` password from time " +"to time." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:305 +msgid "" +"Look for the word \"`Connected`\" in the lower left corner. This indicates " +"that the [application]*firewall-config* tool is connected to the user space " +"daemon, `firewalld`." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:307 +#, no-wrap +msgid "Change the Firewall Settings" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:310 +msgid "" +"To immediately change the current firewall settings, ensure the drop-down " +"selection menu labeled `Configuration` is set to `Runtime`. Alternatively, " +"to edit the settings to be applied at the next system start, or firewall " +"reload, select `Permanent` from the drop-down list." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:315 +msgid "" +"When making changes to the firewall settings in `Runtime` mode, your " +"selection takes immediate effect when you set or clear the check box " +"associated with the service. You should keep this in mind when working on a " +"system that may be in use by other users." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:317 +msgid "" +"When making changes to the firewall settings in `Permanent` mode, your " +"selection will only take effect when you reload the firewall or the system " +"restarts. To reload the firewall, select the Options menu and select `Reload " +"Firewall`." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:321 +#, no-wrap +msgid "Open Ports in the Firewall for NTP Packets" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:324 +msgid "" +"To permit traffic through the firewall to a certain port, start the " +"[application]*firewall-config* tool and select the network zone whose " +"settings you want to change. Select the `Ports` tab and then click the " +"btn:[Add] button. The `Port and Protocol` window opens." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:326 +msgid "Enter the port number `123` and select `udp` from the drop-down list." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:328 +#, no-wrap +msgid "Configure ntpdate Servers" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:331 +msgid "" +"The purpose of the `ntpdate` service is to set the clock during system " +"boot. This was used previously to ensure that the services started after " +"`ntpdate` would have the correct time and not observe a jump in the " +"clock. The use of `ntpdate` and the list of step-tickers is considered " +"deprecated and so Fedora uses the [option]`-g` option to the [command]#ntpd# " +"command and not `ntpdate` by default." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:333 +msgid "" +"The `ntpdate` service in Fedora is mostly useful only when used alone " +"without `ntpd`. With [application]*systemd*, which starts services in " +"parallel, enabling the `ntpdate` service will not ensure that other services " +"started after it will have correct time unless they specify an ordering " +"dependency on `time-sync.target`, which is provided by the `ntpdate` " +"service. The `ntp-wait` service (in the [package]*ntp-perl* subpackage) " +"provides the `time-sync` target for the `ntpd` service. In order to ensure a " +"service starts with correct time, add `After=time-sync.target` to the " +"service and enable one of the services which provide the target (`ntpdate` " +"or [application]*sntp*, or [application]*ntp-wait* if `ntpd` is " +"enabled). Some services on Fedora have the dependency included by default ( " +"for example, `dhcpd`, `dhcpd6`, and `crond`)." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:335 +msgid "" +"To check if the `ntpdate` service is enabled to run at system start, issue " +"the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:339 +#, no-wrap +msgid "~]${nbsp}pass:attributes[{blank}][command]#systemctl status ntpdate#\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:342 +msgid "" +"To enable the service to run at system start, issue the following command as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:346 +#, no-wrap +msgid "~]#{nbsp}systemctl enable ntpdate\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:349 +msgid "" +"In Fedora the default `/etc/ntp/step-tickers` file contains " +"`0.fedora.pool.ntp.org`. To configure additional `ntpdate` servers, using a " +"text editor running as `root`, edit `/etc/ntp/step-tickers`. The number of " +"servers listed is not very important as `ntpdate` will only use this to " +"obtain the date information once when the system is starting. If you have an " +"internal time server then use that host name for the first line. An " +"additional host on the second line as a backup is sensible. The selection of " +"backup servers and whether the second host is internal or external depends " +"on your risk assessment. For example, what is the chance of any problem " +"affecting the first server also affecting the second server? Would " +"connectivity to an external server be more likely to be available than " +"connectivity to internal servers in the event of a network failure " +"disrupting access to the first server?" +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:351 +#, no-wrap +msgid "Configure NTP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:354 +msgid "" +"To change the default configuration of the `NTP` service, use a text editor " +"running as `root` user to edit the `/etc/ntp.conf` file. This file is " +"installed together with `ntpd` and is configured to use time servers from " +"the Fedora pool by default. The man page `ntp.conf(5)` describes the command " +"options that can be used in the configuration file apart from the access and " +"rate limiting commands which are explained in the `ntp_acc(5)` man page." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:356 +#, no-wrap +msgid "Configure Access Control to an NTP Service" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:359 +msgid "" +"To restrict or control access to the `NTP` service running on a system, make " +"use of the [command]#restrict# command in the `ntp.conf` file. See the " +"commented out example:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:364 +#, no-wrap +msgid "" +"# Hosts on local network are less restricted.\n" +"#restrict 192.168.1.0 mask 255.255.255.0 nomodify notrap\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:367 +msgid "The [command]#restrict# command takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:371 +#, no-wrap +msgid "[command]#restrict# _option_\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:374 +msgid "where _option_ is one or more of:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:376 +msgid "" +"[option]`ignore` — All packets will be ignored, including `ntpq` and " +"`ntpdc` queries." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:378 +msgid "" +"[option]`kod` — a \"`Kiss-o'-death`\" packet is to be sent to reduce " +"unwanted queries." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:380 +msgid "" +"[option]`limited` — do not respond to time service requests if the " +"packet violates the rate limit default values or those specified by the " +"[command]#discard# command. `ntpq` and `ntpdc` queries are not affected. For " +"more information on the [command]#discard# command and the default values, " +"see " +"xref:Configuring_NTP_Using_ntpd.adoc#s2_Configure_Rate_Limiting_Access_to_an_NTP_Service[Configure " +"Rate Limiting Access to an NTP Service]." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:382 +msgid "" +"[option]`lowpriotrap` — traps set by matching hosts to be low " +"priority." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:384 +msgid "[option]`nomodify` — prevents any changes to the configuration." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:386 +msgid "" +"[option]`noquery` — prevents `ntpq` and `ntpdc` queries, but not time " +"queries, from being answered." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:388 +msgid "[option]`nopeer` — prevents a peer association being formed." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:390 +msgid "" +"[option]`noserve` — deny all packets except `ntpq` and `ntpdc` " +"queries." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:392 +msgid "[option]`notrap` — prevents `ntpdc` control message protocol traps." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:394 +msgid "" +"[option]`notrust` — deny packets that are not cryptographically " +"authenticated." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:396 +msgid "" +"[option]`ntpport` — modify the match algorithm to only apply the " +"restriction if the source port is the standard `NTP` `UDP` port `123`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:398 +msgid "" +"[option]`version` — deny packets that do not match the current `NTP` " +"version." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:400 +msgid "" +"To configure rate limit access to not respond at all to a query, the " +"respective [command]#restrict# command has to have the [option]`limited` " +"option. If `ntpd` should reply with a `KoD` packet, the [command]#restrict# " +"command needs to have both [option]`limited` and [option]`kod` options." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:402 +msgid "" +"The `ntpq` and `ntpdc` queries can be used in amplification attacks (see " +"[citetitle]_link:++https://access.redhat.com/security/cve/CVE-2013-5211++[CVE-2013-5211]_ " +"for more details), do not remove the [option]`noquery` option from the " +"[command]#restrict default# command on publicly accessible systems." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:404 +#, no-wrap +msgid "Configure Rate Limiting Access to an NTP Service" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:407 +msgid "" +"To enable rate limiting access to the `NTP` service running on a system, add " +"the [option]`limited` option to the [command]#restrict# command as explained " +"in " +"xref:Configuring_NTP_Using_ntpd.adoc#s2-Configure_Access_Control_to_an_NTP_service[Configure " +"Access Control to an NTP Service]. If you do not want to use the default " +"discard parameters, then also use the [command]#discard# command as " +"explained here." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:409 +msgid "The [command]#discard# command takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:413 +#, no-wrap +msgid "" +"[command]#discard# [option]`average` _value_ [option]`minimum` _value_ " +"[option]`monitor` _value_\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:416 +msgid "" +"[option]`average` — specifies the minimum average packet spacing to be " +"permitted, it accepts an argument in _log2_ seconds. The default value is 3 " +"(_2pass:attributes[{blank}]^3^pass:attributes[{blank}]_ equates to 8 " +"seconds)." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:418 +msgid "" +"[option]`minimum` — specifies the minimum packet spacing to be " +"permitted, it accepts an argument in _log2_ seconds. The default value is 1 " +"(_2pass:attributes[{blank}]^1^pass:attributes[{blank}]_ equates to 2 " +"seconds)." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:420 +msgid "" +"[option]`monitor` — specifies the discard probability for packets once " +"the permitted rate limits have been exceeded. The default value is 3000 " +"seconds. This option is intended for servers that receive 1000 or more " +"requests per second." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:422 +msgid "Examples of the [command]#discard# command are as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:426 +#, no-wrap +msgid "discard average 4\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:431 +#, no-wrap +msgid "discard average 4 minimum 2\n" +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:434 +#, no-wrap +msgid "Adding a Peer Address" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:437 +msgid "" +"To add the address of a peer, that is to say, the address of a server " +"running an `NTP` service of the same stratum, make use of the " +"[command]#peer# command in the `ntp.conf` file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:439 +msgid "The [command]#peer# command takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:443 +#, no-wrap +msgid "[command]#peer# _address_\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:446 +msgid "" +"where _address_ is an `IP` unicast address or a `DNS` resolvable name. The " +"address must only be that of a system known to be a member of the same " +"stratum. Peers should have at least one time source that is different to " +"each other. Peers are normally systems under the same administrative " +"control." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:448 +#, no-wrap +msgid "Adding a Server Address" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:451 +msgid "" +"To add the address of a server, that is to say, the address of a server " +"running an `NTP` service of a higher stratum, make use of the " +"[command]#server# command in the `ntp.conf` file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:453 +msgid "The [command]#server# command takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:457 +#, no-wrap +msgid "[command]#server# _address_\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:461 +msgid "" +"where _address_ is an `IP` unicast address or a `DNS` resolvable name. The " +"address of a remote reference server or local reference clock from which " +"packets are to be received." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:463 +#, no-wrap +msgid "Adding a Broadcast or Multicast Server Address" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:466 +msgid "" +"To add a broadcast or multicast address for sending, that is to say, the " +"address to broadcast or multicast `NTP` packets to, make use of the " +"[command]#broadcast# command in the `ntp.conf` file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:468 +msgid "" +"The broadcast and multicast modes require authentication by default. See " +"xref:Configuring_NTP_Using_ntpd.adoc#s1-Authentication_Options_for_NTP[Authentication " +"Options for NTP]." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:470 +msgid "The [command]#broadcast# command takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:474 +#, no-wrap +msgid "[command]#broadcast# _address_\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:477 +msgid "" +"where _address_ is an `IP` broadcast or multicast address to which packets " +"are sent." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:479 +msgid "" +"This command configures a system to act as an `NTP` broadcast server. The " +"address used must be a broadcast or a multicast address. Broadcast address " +"implies the `IPv4` address `255.255.255.255`. By default, routers do not " +"pass broadcast messages. The multicast address can be an `IPv4` Class D " +"address, or an `IPv6` address. The IANA has assigned `IPv4` multicast " +"address `224.0.1.1` and `IPv6` address `FF05::101` (site local) to " +"`NTP`. Administratively scoped `IPv4` multicast addresses can also be used, " +"as described in " +"[citetitle]_link:++https://www.rfc-editor.org/info/rfc2365++[RFC 2365 " +"Administratively Scoped IP Multicast]_." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:481 +#, no-wrap +msgid "Adding a Manycast Client Address" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:484 +msgid "" +"To add a manycast client address, that is to say, to configure a multicast " +"address to be used for `NTP` server discovery, make use of the " +"[command]#manycastclient# command in the `ntp.conf` file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:486 +msgid "The [command]#manycastclient# command takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:490 +#, no-wrap +msgid "[command]#manycastclient# _address_\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:494 +msgid "" +"where _address_ is an `IP` multicast address from which packets are to be " +"received. The client will send a request to the address and select the best " +"servers from the responses and ignore other servers. `NTP` communication " +"then uses unicast associations, as if the discovered `NTP` servers were " +"listed in `ntp.conf`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:496 +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:512 +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:544 +msgid "" +"This command configures a system to act as an `NTP` client. Systems can be " +"both client and server at the same time." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:498 +#, no-wrap +msgid "Adding a Broadcast Client Address" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:501 +msgid "" +"To add a broadcast client address, that is to say, to configure a broadcast " +"address to be monitored for broadcast `NTP` packets, make use of the " +"[command]#broadcastclient# command in the `ntp.conf` file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:503 +msgid "The [command]#broadcastclient# command takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:507 +#, no-wrap +msgid "[command]#broadcastclient#\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:510 +msgid "" +"Enables the receiving of broadcast messages. Requires authentication by " +"default. See " +"xref:Configuring_NTP_Using_ntpd.adoc#s1-Authentication_Options_for_NTP[Authentication " +"Options for NTP]." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:514 +#, no-wrap +msgid "Adding a Manycast Server Address" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:517 +msgid "" +"To add a manycast server address, that is to say, to configure an address to " +"allow the clients to discover the server by multicasting `NTP` packets, make " +"use of the [command]#manycastserver# command in the `ntp.conf` file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:519 +msgid "The [command]#manycastserver# command takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:523 +#, no-wrap +msgid "[command]#manycastserver# _address_\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:526 +msgid "" +"Enables the sending of multicast messages. Where _address_ is the address to " +"multicast to. This should be used together with authentication to prevent " +"service disruption." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:528 +msgid "" +"This command configures a system to act as an `NTP` server. Systems can be " +"both client and server at the same time." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:530 +#, no-wrap +msgid "Adding a Multicast Client Address" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:533 +msgid "" +"To add a multicast client address, that is to say, to configure a multicast " +"address to be monitored for multicast `NTP` packets, make use of the " +"[command]#multicastclient# command in the `ntp.conf` file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:535 +msgid "The [command]#multicastclient# command takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:539 +#, no-wrap +msgid "[command]#multicastclient# _address_\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:542 +msgid "" +"Enables the receiving of multicast messages. Where _address_ is the address " +"to subscribe to. This should be used together with authentication to prevent " +"service disruption." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:546 +#, no-wrap +msgid "Configuring the Burst Option" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:549 +msgid "" +"Using the [command]#burst# option against a public server is considered " +"abuse. Do not use this option with public `NTP` servers. Use it only for " +"applications within your own organization." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:551 +msgid "" +"To increase the average quality of time offset statistics, add the following " +"option to the end of a server command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:555 +#, no-wrap +msgid "[command]#burst#\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:558 +msgid "" +"At every poll interval, when the server responds, the system will send a " +"burst of up to eight packets instead of the usual one packet. For use with " +"the [command]#server# command to improve the average quality of the " +"time-offset calculations." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:560 +#, no-wrap +msgid "Configuring the iburst Option" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:563 +msgid "" +"To improve the time taken for initial synchronization, add the following " +"option to the end of a server command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:567 +#, no-wrap +msgid "[command]#iburst#\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:570 +msgid "" +"At every poll interval, send a burst of eight packets instead of one. When " +"the server is not responding, packets are sent 16s apart. When the server " +"responds, packets are sent every 2s. For use with the [command]#server# " +"command to reduce the time taken for initial synchronization. This is now a " +"default option in the configuration file." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:572 +#, no-wrap +msgid "Configuring Symmetric Authentication Using a Key" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:575 +msgid "" +"To configure symmetric authentication using a key, add the following option " +"to the end of a server or peer command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:579 +#, no-wrap +msgid "[command]#key# _number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:583 +msgid "" +"where _number_ is in the range `1` to `65534` inclusive. This option " +"enables the use of a _message authentication code_ (*MAC*) in packets. This " +"option is for use with the [command]#peer#, [command]#server#, " +"[command]#broadcast#, and [command]#manycastclient# commands." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:585 +msgid "The option can be used in the `/etc/ntp.conf` file as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:591 +#, no-wrap +msgid "" +"server 192.168.1.1 key 10\n" +"broadcast 192.168.1.255 key 20\n" +"manycastclient 239.255.254.254 key 30\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:594 +msgid "" +"See also " +"xref:Configuring_NTP_Using_ntpd.adoc#s1-Authentication_Options_for_NTP[Authentication " +"Options for NTP]." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:596 +#, no-wrap +msgid "Configuring the Poll Interval" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:599 +msgid "" +"To change the default poll interval, add the following options to the end of " +"a server or peer command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:603 +#, no-wrap +msgid "[command]#minpoll# _value_ and [command]#maxpoll# _value_\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:606 +msgid "" +"Options to change the default poll interval, where the interval in seconds " +"will be calculated by raising 2 to the power of _value_, in other words, the " +"interval is expressed in _log2_ seconds. The default [option]`minpoll` value " +"is 6, _2pass:attributes[{blank}]^6^pass:attributes[{blank}]_ equates to " +"64s. The default value for [option]`maxpoll` is 10, which equates to " +"1024s. Allowed values are in the range 3 to 17 inclusive, which equates to " +"8s to 36.4h respectively. These options are for use with the [command]#peer# " +"or [command]#server#. Setting a shorter [option]`maxpoll` may improve clock " +"accuracy." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:608 +#, no-wrap +msgid "Configuring Server Preference" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:611 +msgid "" +"To specify that a particular server should be preferred above others of " +"similar statistical quality, add the following option to the end of a server " +"or peer command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:615 +#, no-wrap +msgid "[command]#prefer#\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:618 +msgid "" +"Use this server for synchronization in preference to other servers of " +"similar statistical quality. This option is for use with the [command]#peer# " +"or [command]#server# commands." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:620 +#, no-wrap +msgid "Configuring the Time-to-Live for NTP Packets" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:623 +msgid "" +"To specify that a particular _time-to-live_ (*TTL*) value should be used in " +"place of the default, add the following option to the end of a server or " +"peer command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:627 +#, no-wrap +msgid "[command]#ttl# _value_\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:630 +msgid "" +"Specify the time-to-live value to be used in packets sent by broadcast " +"servers and multicast `NTP` servers. Specify the maximum time-to-live value " +"to use for the \"`expanding ring search`\" by a manycast client. The default " +"value is `127`." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:632 +#, no-wrap +msgid "Configuring the NTP Version to Use" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:635 +msgid "" +"To specify that a particular version of `NTP` should be used in place of the " +"default, add the following option to the end of a server or peer command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:639 +#, no-wrap +msgid "[command]#version# _value_\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:642 +msgid "" +"Specify the version of `NTP` set in created `NTP` packets. The value can be " +"in the range `1` to `4`. The default is `4`." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:644 +#, no-wrap +msgid "Configuring the Hardware Clock Update" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:647 +msgid "" +"To configure the system clock to update the hardware clock, also known as " +"the real-time clock (RTC), once after executing [application]*ntpdate*, add " +"the following line to `/etc/sysconfig/ntpdate`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:650 +#, no-wrap +msgid "SYNC_HWCLOCK=yes\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:653 +msgid "" +"To update the hardware clock from the system clock, issue the following " +"command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:657 +#, no-wrap +msgid "~]#{nbsp}hwclock --systohc\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:660 +msgid "" +"When the system clock is being synchronized by `ntpd` or `chronyd`, the " +"kernel will in turn update the RTC every 11 minutes automatically." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:662 +#, no-wrap +msgid "Configuring Clock Sources" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:665 +msgid "" +"To list the available clock sources on your system, issue the following " +"commands:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:673 +#, no-wrap +msgid "" +"~]${nbsp}cd /sys/devices/system/clocksource/clocksource0/\n" +"clocksource0]$ cat available_clocksource\n" +"kvm-clock tsc hpet acpi_pm\n" +"clocksource0]$ cat current_clocksource\n" +"kvm-clock\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:676 +msgid "" +"In the above example, the kernel is using [application]*kvm-clock*. This was " +"selected at boot time as this is a virtual machine." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:678 +msgid "" +"To override the default clock source, append the [command]#clocksource# " +"directive to the GRUB_CMDLINE_LINUX line in the `/etc/default/grub` file and " +"rebuild the `grub.cfg` file. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:682 +#, no-wrap +msgid "" +"GRUB_CMDLINE_LINUX=\"rd.lvm.lv=rhel/root crashkernel=auto " +"rd.lvm.lv=rhel/swap vconsole.font=latarcyrheb-sun16 vconsole.keymap=us rhgb " +"quiet pass:quotes[*clocksource=tsc*]\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:685 +msgid "The available clock source is architecture dependent." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:687 +msgid "Rebuild the `grub.cfg` file as follows:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:689 +msgid "On BIOS-based machines, issue the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:693 +#, no-wrap +msgid "~]#{nbsp}grub2-mkconfig -o /boot/grub2/grub.cfg\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:696 +msgid "On UEFI-based machines, issue the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:700 +#, no-wrap +msgid "~]#{nbsp}grub2-mkconfig -o /boot/efi/EFI/redhat/grub.cfg\n" +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:703 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:706 +msgid "" +"The following sources of information provide additional resources regarding " +"`NTP` and `ntpd`." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:708 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:711 +msgid "" +"`ntpd(8)` man page — Describes `ntpd` in detail, including the command line " +"options." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:713 +msgid "" +"`ntp.conf(5)` man page — Contains information on how to configure " +"associations with servers and peers." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:715 +msgid "" +"`ntpq(8)` man page — Describes the `NTP` query utility for monitoring and " +"querying an `NTP` server." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:717 +msgid "" +"`ntpdc(8)` man page — Describes the `ntpd` utility for querying and changing " +"the state of `ntpd`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:719 +msgid "" +"`ntp_auth(5)` man page — Describes authentication options, commands, and key " +"management for `ntpd`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:721 +msgid "" +"`ntp_keygen(8)` man page — Describes generating public and private keys for " +"`ntpd`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:723 +msgid "" +"`ntp_acc(5)` man page — Describes access control options using the " +"[command]#restrict# command." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:725 +msgid "" +"`ntp_mon(5)` man page — Describes monitoring options for the gathering of " +"statistics." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:727 +msgid "" +"`ntp_clock(5)` man page — Describes commands for configuring reference " +"clocks." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:729 +msgid "`ntp_misc(5)` man page — Describes miscellaneous options." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:731 +msgid "" +"`ntp_decode(5)` man page — Lists the status words, event messages and error " +"codes used for `ntpd` reporting and monitoring." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:733 +msgid "" +"`ntpstat(8)` man page — Describes a utility for reporting the " +"synchronization state of the `NTP` daemon running on the local machine." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:735 +msgid "" +"`ntptime(8)` man page — Describes a utility for reading and setting kernel " +"time variables." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:737 +msgid "" +"`tickadj(8)` man page — Describes a utility for reading, and optionally " +"setting, the length of the tick." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:739 +#, no-wrap +msgid "Useful Websites" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:741 +#, no-wrap +msgid "link:++http://doc.ntp.org/++[]" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:742 +msgid "The NTP Documentation Archive" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:743 +#, no-wrap +msgid "link:++https://www.eecis.udel.edu/~mills/ntp.html++[]" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:744 +msgid "Network Time Synchronization Research Project." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:745 +#, no-wrap +msgid "link:++https://www.eecis.udel.edu/~mills/ntp/html/manyopt.html++[]" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:745 +msgid "Information on Automatic Server Discovery in `NTPv4`." +msgstr "" diff --git a/po/fr/rawhide/pages/servers/Configuring_NTP_Using_the_chrony_Suite.po b/po/fr/rawhide/pages/servers/Configuring_NTP_Using_the_chrony_Suite.po new file mode 100644 index 00000000000..9cb380ce7b2 --- /dev/null +++ b/po/fr/rawhide/pages/servers/Configuring_NTP_Using_the_chrony_Suite.po @@ -0,0 +1,2129 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:6 +#, no-wrap +msgid "Configuring NTP Using the chrony Suite" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:9 +msgid "" +"Accurate time keeping is important for a number of reasons in IT. In " +"networking for example, accurate time stamps in packets and logs are " +"required. In Linux systems, the `NTP` protocol is implemented by a daemon " +"running in user space." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:11 +msgid "" +"The user space daemon updates the system clock running in the kernel. The " +"system clock can keep time by using various clock sources. Usually, the " +"_Time Stamp Counter_ (*TSC*) is used. The TSC is a CPU register which counts " +"the number of cycles since it was last reset. It is very fast, has a high " +"resolution, and there are no interrupts." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:13 +msgid "" +"There is a choice between the daemons `ntpd` and `chronyd`, which are " +"available from the repositories in the [package]*ntp* and [package]*chrony* " +"packages respectively. This section describes the use of the " +"[application]*chrony* suite of utilities to update the system clock on " +"systems that do not fit into the conventional permanently networked, always " +"on, dedicated server category." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:15 +#, no-wrap +msgid "Introduction to the chrony Suite" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:18 +msgid "" +"[application]*Chrony* consists of `chronyd`, a daemon that runs in user " +"space, and [application]*chronyc*, a command line program for making " +"adjustments to `chronyd`. Systems which are not permanently connected, or " +"not permanently powered up, take a relatively long time to adjust their " +"system clocks with `ntpd`. This is because many small corrections are made " +"based on observations of the clocks drift and offset. Temperature changes, " +"which may be significant when powering up a system, affect the stability of " +"hardware clocks. Although adjustments begin within a few milliseconds of " +"booting a system, acceptable accuracy may take anything from ten seconds " +"from a warm restart to a number of hours depending on your requirements, " +"operating environment and hardware. [application]*chrony* is a different " +"implementation of the `NTP` protocol than `ntpd`, it can adjust the system " +"clock more rapidly." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:20 +#, no-wrap +msgid "Differences Between ntpd and chronyd" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:23 +msgid "" +"One of the main differences between `ntpd` and `chronyd` is in the " +"algorithms used to control the computer's clock. Things `chronyd` can do " +"better than `ntpd` are:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:25 +msgid "" +"`chronyd` can work well when external time references are only " +"intermittently accessible, whereas `ntpd` needs regular polling of time " +"reference to work well." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:27 +msgid "" +"`chronyd` can perform well even when the network is congested for longer " +"periods of time." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:29 +msgid "" +"`chronyd` can usually synchronize the clock faster and with better time " +"accuracy." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:31 +msgid "" +"`chronyd` quickly adapts to sudden changes in the rate of the clock, for " +"example, due to changes in the temperature of the crystal oscillator, " +"whereas `ntpd` may need a long time to settle down again." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:33 +msgid "" +"In the default configuration, `chronyd` never steps the time after the clock " +"has been synchronized at system start, in order not to upset other running " +"programs. `ntpd` can be configured to never step the time too, but it has to " +"use a different means of adjusting the clock, which has some disadvantages." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:35 +msgid "" +"`chronyd` can adjust the rate of the clock on a Linux system in a larger " +"range, which allows it to operate even on machines with a broken or unstable " +"clock. For example, on some virtual machines." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:37 +msgid "Things `chronyd` can do that `ntpd` cannot do:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:39 +msgid "" +"`chronyd` provides support for isolated networks where the only method of " +"time correction is manual entry. For example, by the administrator looking " +"at a clock. `chronyd` can examine the errors corrected at different updates " +"to estimate the rate at which the computer gains or loses time, and use this " +"estimate to trim the computer clock subsequently." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:41 +msgid "" +"`chronyd` provides support to work out the rate of gain or loss of the " +"real-time clock, the hardware clock, that maintains the time when the " +"computer is turned off. It can use this data when the system boots to set " +"the system time using an adjusted value of the time taken from the real-time " +"clock. This is, at time of writing, only available in Linux." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:43 +msgid "Things `ntpd` can do that `chronyd` cannot do:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:45 +msgid "" +"`ntpd` fully supports `NTP` version 4 ([citetitle]_RFC 5905_), including " +"broadcast, multicast, manycast clients and servers, and the orphan mode. It " +"also supports extra authentication schemes based on public-key cryptography " +"([citetitle]_RFC 5906_). `chronyd` uses `NTP` version 3 ([citetitle]_RFC " +"1305_), which is compatible with version 4." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:47 +msgid "" +"`ntpd` includes drivers for many reference clocks whereas `chronyd` relies " +"on other programs, for example [application]*gpsd*, to access the data from " +"the reference clocks." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:49 +#, no-wrap +msgid "Choosing Between NTP Daemons" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:52 +msgid "" +"[application]*Chrony* should be considered for all systems which are " +"frequently suspended or otherwise intermittently disconnected and " +"reconnected to a network. Mobile and virtual systems for example." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:54 +msgid "" +"The `NTP` daemon (`ntpd`) should be considered for systems which are " +"normally kept permanently on. Systems which are required to use broadcast or " +"multicast `IP`, or to perform authentication of packets with the `Autokey` " +"protocol, should consider using `ntpd`. [application]*Chrony* only supports " +"symmetric key authentication using a message authentication code (MAC) with " +"MD5, SHA1 or stronger hash functions, whereas `ntpd` also supports the " +"`Autokey` authentication protocol which can make use of the PKI " +"system. `Autokey` is described in [citetitle]_RFC 5906_." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:56 +#, no-wrap +msgid "Understanding chrony and Its Configuration" +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:59 +#, no-wrap +msgid "Understanding chronyd" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:62 +msgid "" +"The [application]*chrony* daemon, `chronyd`, running in user space, makes " +"adjustments to the system clock which is running in the kernel. It does this " +"by consulting external time sources, using the `NTP` protocol, when ever " +"network access allows it to do so. When external references are not " +"available, `chronyd` will use the last calculated drift stored in the drift " +"file. It can also be commanded manually to make corrections, by " +"[application]*chronyc*." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:64 +#, no-wrap +msgid "Understanding chronyc" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:67 +msgid "" +"The [application]*chrony* daemon, `chronyd`, can be controlled by the " +"command line utility [application]*chronyc*. This utility provides a command " +"prompt which allows entering of a number of commands to make changes to " +"`chronyd`. The default configuration is for `chronyd` to only accept " +"commands from a local instance of [application]*chronyc*, but " +"[application]*chronyc* can be used to alter the configuration so that " +"`chronyd` will allow external control. [application]*chronyc* can be run " +"remotely after first configuring `chronyd` to accept remote connections. The " +"`IP` addresses allowed to connect to `chronyd` should be tightly controlled." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:69 +#, no-wrap +msgid "Understanding the chrony Configuration Commands" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:72 +msgid "" +"The default configuration file for `chronyd` is `/etc/chrony.conf`. The " +"[option]`-f` option can be used to specify an alternate configuration file " +"path. See the `chronyd` man page for further options. For a complete list of " +"the directives that can be used see " +"[citetitle]_link:++https://chrony-project.org/doc/4.4/chrony.conf.html++[https://chrony-project.org/doc/4.4/chrony.conf.html]_. " +"Below is a selection of configuration options:" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:73 +#, no-wrap +msgid "Comments" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:74 +msgid "Comments should be preceded by #, %, ; or !" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:75 +#, no-wrap +msgid "allow" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:77 +msgid "" +"Optionally specify a host, subnet, or network from which to allow `NTP` " +"connections to a machine acting as `NTP` server. The default is not to allow " +"connections. Examples:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:78 +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:85 +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:92 +msgid "[subs=\"quotes\"]" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:80 +#, no-wrap +msgid "allow server1.example.com\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:83 +msgid "" +"Use this form to specify a particular host, by its host name, to be allowed " +"access." +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:87 +#, no-wrap +msgid "allow 192.0.2.0/24\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:90 +msgid "Use this form to specify a particular network to be allowed access." +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:94 +#, no-wrap +msgid "allow 2001:db8::/32\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:97 +msgid "Use this form to specify an `IPv6` address to be allowed access." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:98 +#, no-wrap +msgid "cmdallow" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:99 +msgid "" +"This is similar to the [command]#allow# directive (see section " +"[command]#allow#), except that it allows control access (rather than `NTP` " +"client access) to a particular subnet or host. (By \"`control access`\" is " +"meant that [application]*chronyc* can be run on those hosts and successfully " +"connect to `chronyd` on this computer.) The syntax is identical. There is " +"also a [command]#cmddeny all# directive with similar behavior to the " +"[command]#cmdallow all# directive." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:100 +#, no-wrap +msgid "dumpdir" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:101 +msgid "" +"Path to the directory to save the measurement history across restarts of " +"`chronyd` (assuming no changes are made to the system clock behavior whilst " +"it is not running). If this capability is to be used (via the " +"[command]#dumponexit# command in the configuration file, or the " +"[command]#dump# command in [application]*chronyc*), the [command]#dumpdir# " +"command should be used to define the directory where the measurement " +"histories are saved." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:102 +#, no-wrap +msgid "dumponexit" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:103 +msgid "" +"If this command is present, it indicates that `chronyd` should save the " +"measurement history for each of its time sources recorded whenever the " +"program exits. (See the [command]#dumpdir# command above)." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:104 +#, no-wrap +msgid "local" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:105 +msgid "" +"The [command]#local# keyword is used to allow `chronyd` to appear " +"synchronized to real time from the viewpoint of clients polling it, even if " +"it has no current synchronization source. This option is normally used on " +"the \"`master`\" computer in an isolated network, where several computers " +"are required to synchronize to one another, and the \"`master`\" is kept in " +"line with real time by manual input." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:107 +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:132 +msgid "An example of the command is:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:111 +#, no-wrap +msgid "local stratum 10\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:114 +msgid "" +"A large value of 10 indicates that the clock is so many hops away from a " +"reference clock that its time is unreliable. If the computer ever has access " +"to another computer which is ultimately synchronized to a reference clock, " +"it will almost certainly be at a stratum less than 10. Therefore, the choice " +"of a high value like 10 for the [command]#local# command prevents the " +"machine’s own time from ever being confused with real time, were it ever to " +"leak out to clients that have visibility of real servers." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:115 +#, no-wrap +msgid "log" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:116 +msgid "" +"The [command]#log# command indicates that certain information is to be " +"logged. It accepts the following options:" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:117 +#, no-wrap +msgid "measurements" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:118 +msgid "" +"This option logs the raw `NTP` measurements and related information to a " +"file called `measurements.log`." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:119 +#, no-wrap +msgid "statistics" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:120 +msgid "" +"This option logs information about the regression processing to a file " +"called `statistics.log`." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:121 +#, no-wrap +msgid "tracking" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:122 +msgid "" +"This option logs changes to the estimate of the system’s gain or loss rate, " +"and any slews made, to a file called `tracking.log`." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:123 +#, no-wrap +msgid "rtc" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:124 +msgid "This option logs information about the system’s real-time clock." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:125 +#, no-wrap +msgid "refclocks" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:126 +msgid "" +"This option logs the raw and filtered reference clock measurements to a file " +"called `refclocks.log`." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:127 +#, no-wrap +msgid "tempcomp" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:128 +msgid "" +"This option logs the temperature measurements and system rate compensations " +"to a file called `tempcomp.log`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:130 +msgid "" +"The log files are written to the directory specified by the " +"[command]#logdir# command." +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:136 +#, no-wrap +msgid "log measurements statistics tracking\n" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:138 +#, no-wrap +msgid "logdir" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:139 +msgid "" +"This directive allows the directory where log files are written to be " +"specified." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:141 +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:150 +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:161 +msgid "An example of the use of this directive is:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:145 +#, no-wrap +msgid "logdir /var/log/chrony\n" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:147 +#, no-wrap +msgid "makestep" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:148 +msgid "" +"Normally `chronyd` will cause the system to gradually correct any time " +"offset, by slowing down or speeding up the clock as required. In certain " +"situations, the system clock may be so far adrift that this slewing process " +"would take a very long time to correct the system clock. This directive " +"forces `chronyd` to step system clock if the adjustment is larger than a " +"threshold value, but only if there were no more clock updates since " +"`chronyd` was started than a specified limit (a negative value can be used " +"to disable the limit). This is particularly useful when using reference " +"clocks, because the [command]#initstepslew# directive only works with `NTP` " +"sources." +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:154 +#, no-wrap +msgid "makestep 1000 10\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:157 +msgid "" +"This would step the system clock if the adjustment is larger than 1000 " +"seconds, but only in the first ten clock updates." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:158 +#, no-wrap +msgid "maxchange" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:159 +msgid "" +"This directive sets the maximum allowed offset corrected on a clock " +"update. The check is performed only after the specified number of updates to " +"allow a large initial adjustment of the system clock. When an offset larger " +"than the specified maximum occurs, it will be ignored for the specified " +"number of times and then `chronyd` will give up and exit (a negative value " +"can be used to never exit). In both cases a message is sent to syslog." +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:165 +#, no-wrap +msgid "maxchange 1000 1 2\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:168 +msgid "" +"After the first clock update, `chronyd` will check the offset on every clock " +"update, it will ignore two adjustments larger than 1000 seconds and exit on " +"another one." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:169 +#, no-wrap +msgid "maxupdateskew" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:170 +msgid "" +"One of `chronyd`pass:attributes[{blank}]'s tasks is to work out how fast or " +"slow the computer’s clock runs relative to its reference sources. In " +"addition, it computes an estimate of the error bounds around the estimated " +"value." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:172 +msgid "" +"If the range of error is too large, it indicates that the measurements have " +"not settled down yet, and that the estimated gain or loss rate is not very " +"reliable." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:174 +msgid "" +"The [command]#maxupdateskew# parameter is the threshold for determining " +"whether an estimate is too unreliable to be used. By default, the threshold " +"is 1000 ppm." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:176 +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:191 +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:200 +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:211 +msgid "The format of the syntax is:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:180 +#, no-wrap +msgid "maxupdateskew _skew-in-ppm_\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:183 +msgid "" +"Typical values for _skew-in-ppm_ might be 100 for a dial-up connection to " +"servers over a telephone line, and 5 or 10 for a computer on a LAN." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:185 +msgid "" +"It should be noted that this is not the only means of protection against " +"using unreliable estimates. At all times, `chronyd` keeps track of both the " +"estimated gain or loss rate, and the error bound on the estimate. When a new " +"estimate is generated following another measurement from one of the sources, " +"a weighted combination algorithm is used to update the master estimate. So " +"if `chronyd` has an existing highly-reliable master estimate and a new " +"estimate is generated which has large error bounds, the existing master " +"estimate will dominate in the new master estimate." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:186 +#, no-wrap +msgid "noclientlog" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:187 +msgid "" +"This directive, which takes no arguments, specifies that client accesses are " +"not to be logged. Normally they are logged, allowing statistics to be " +"reported using the clients command in [application]*chronyc*." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:188 +#, no-wrap +msgid "reselectdist" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:189 +msgid "" +"When `chronyd` selects synchronization source from available sources, it " +"will prefer the one with minimum synchronization distance. However, to avoid " +"frequent reselecting when there are sources with similar distance, a fixed " +"distance is added to the distance for sources that are currently not " +"selected. This can be set with the [option]`reselectdist` option. By " +"default, the distance is 100 microseconds." +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:195 +#, no-wrap +msgid "reselectdist _dist-in-seconds_\n" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:197 +#, no-wrap +msgid "stratumweight" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:198 +msgid "" +"The [command]#stratumweight# directive sets how much distance should be " +"added per stratum to the synchronization distance when `chronyd` selects the " +"synchronization source from available sources." +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:204 +#, no-wrap +msgid "stratumweight _dist-in-seconds_\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:207 +msgid "" +"By default, _dist-in-seconds_ is 1 second. This means that sources with " +"lower stratum are usually preferred to sources with higher stratum even when " +"their distance is significantly worse. Setting [command]#stratumweight# to 0 " +"makes `chronyd` ignore stratum when selecting the source." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:208 +#, no-wrap +msgid "rtcfile" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:209 +msgid "" +"The [command]#rtcfile# directive defines the name of the file in which " +"`chronyd` can save parameters associated with tracking the accuracy of the " +"system’s real-time clock (RTC)." +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:215 +#, no-wrap +msgid "rtcfile /var/lib/chrony/rtc\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:218 +msgid "" +"`chronyd` saves information in this file when it exits and when the " +"[command]#writertc# command is issued in [application]*chronyc*. The " +"information saved is the RTC’s error at some epoch, that epoch (in seconds " +"since January 1 1970), and the rate at which the RTC gains or loses " +"time. Not all real-time clocks are supported as their code is " +"system-specific. Note that if this directive is used then the real-time " +"clock should not be manually adjusted as this would interfere with " +"[application]*chrony*pass:attributes[{blank}]'s need to measure the rate at " +"which the real-time clock drifts if it was adjusted at random intervals." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:219 +#, no-wrap +msgid "rtcsync" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:220 +msgid "" +"The [command]#rtcsync# directive is present in the `/etc/chrony.conf` file " +"by default. This will inform the kernel the system clock is kept " +"synchronized and the kernel will update the real-time clock every 11 " +"minutes." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:222 +#, no-wrap +msgid "Security with chronyc" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:225 +msgid "" +"As access to [application]*chronyc* allows changing `chronyd` just as " +"editing the configuration files would, access to [application]*chronyc* " +"should be limited. Passwords can be specified in the key file, written in " +"ASCII or HEX, to restrict the use of [application]*chronyc*. One of the " +"entries is used to restrict the use of operational commands and is referred " +"to as the command key. In the default configuration, a random command key is " +"generated automatically on start. It should not be necessary to specify or " +"alter it manually." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:227 +msgid "" +"Other entries in the key file can be used as `NTP` keys to authenticate " +"packets received from remote `NTP` servers or peers. The two sides need to " +"share a key with identical ID, hash type and password in their key " +"file. This requires manually creating the keys and copying them over a " +"secure medium, such as `SSH`. If the key ID was, for example, 10 then the " +"systems that act as clients must have a line in their configuration files in " +"the following format:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:232 +#, no-wrap +msgid "" +"server w.x.y.z key 10\n" +"peer w.x.y.z key 10\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:236 +msgid "" +"The location of the key file is specified in the `/etc/chrony.conf` " +"file. The default entry in the configuration file is:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:240 +#, no-wrap +msgid "[command]#keyfile# [option]`/etc/chrony.keys`\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:243 +msgid "" +"The command key number is specified in `/etc/chrony.conf` using the " +"[command]#commandkey# directive, it is the key `chronyd` will use for " +"authentication of user commands. The directive in the configuration file " +"takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:247 +#, no-wrap +msgid "commandkey 1\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:250 +msgid "" +"An example of the format of the default entry in the key file, " +"`/etc/chrony.keys`, for the command key is:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:254 +#, no-wrap +msgid "1 SHA1 HEX:A6CFC50C9C93AB6E5A19754C246242FC5471BCDF\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:257 +msgid "" +"Where `1` is the key ID, SHA1 is the hash function to use, `HEX` is the " +"format of the key, and `A6CFC50C9C93AB6E5A19754C246242FC5471BCDF` is the key " +"randomly generated when [application]*chronyd* was started for the first " +"time. The key can be given in hexadecimal or ASCII format (the default)." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:259 +msgid "" +"A manual entry in the key file, used to authenticate packets from certain " +"`NTP` servers or peers, can be as simple as the following:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:263 +#, no-wrap +msgid "20 foobar\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:266 +msgid "" +"Where `20` is the key ID and `foobar` is the secret authentication key. The " +"default hash is MD5, and ASCII is the default format for the key." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:268 +msgid "" +"By default, `chronyd` is configured to listen for commands only from " +"`localhost` (`127.0.0.1` and `::1`) on port `323`. To access `chronyd` " +"remotely with [application]*chronyc*, any [command]#bindcmdaddress# " +"directives in the `/etc/chrony.conf` file should be removed to enable " +"listening on all interfaces and the [command]#cmdallow# directive should be " +"used to allow commands from the remote `IP` address, network, or subnet. In " +"addition, port `323` has to be opened in the firewall in order to connect " +"from a remote system. Note that the [command]#allow# directive is for `NTP` " +"access whereas the [command]#cmdallow# directive is to enable the receiving " +"of remote commands. It is possible to make these changes temporarily using " +"[application]*chronyc* running locally. Edit the configuration file to make " +"persistent changes." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:270 +msgid "" +"The communication between [application]*chronyc* and [application]*chronyd* " +"is done over `UDP`, so it needs to be authorized before issuing operational " +"commands. To authorize, use the [command]#authhash# and [command]#password# " +"commands as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:276 +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:676 +#, no-wrap +msgid "" +"chronyc> [command]#authhash SHA1#\n" +"chronyc> [command]#password " +"HEX:A6CFC50C9C93AB6E5A19754C246242FC5471BCDF#\n" +"200 OK\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:279 +msgid "" +"If [application]*chronyc* is used to configure the local " +"[application]*chronyd*, the [option]`-a` option will run the " +"[command]#authhash# and [command]#password# commands automatically." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:281 +msgid "Only the following commands can be used without providing a password:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:283 +msgid "[command]#activity#" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:285 +msgid "[command]#authhash#" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:287 +msgid "[command]#dns#" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:289 +msgid "[command]#exit#" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:291 +msgid "[command]#help#" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:293 +msgid "[command]#password#" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:295 +msgid "[command]#quit#" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:297 +msgid "[command]#rtcdata#" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:299 +msgid "[command]#sources#" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:301 +msgid "[command]#sourcestats#" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:303 +msgid "[command]#tracking#" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:305 +msgid "[command]#waitsync#" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:307 +msgid "." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:309 +#, no-wrap +msgid "Using chrony" +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:312 +#, no-wrap +msgid "Installing chrony" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:315 +msgid "" +"The [application]*chrony* suite is installed by default on some versions of " +"Fedora. If required, to ensure that it is, run the following command as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:319 +#, no-wrap +msgid "~]#{nbsp}dnf install chrony\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:322 +msgid "" +"The default location for the [application]*chrony* daemon is " +"`/usr/sbin/chronyd`. The command line utility will be installed to " +"`/usr/bin/chronyc`." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:324 +#, no-wrap +msgid "Checking the Status of chronyd" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:327 +msgid "To check the status of `chronyd`, issue the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:334 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#systemctl status chronyd#\n" +"chronyd.service - NTP client/server\n" +" Loaded: loaded (/usr/lib/systemd/system/chronyd.service; enabled)\n" +" Active: active (running) since Wed 2013-06-12 22:23:16 CEST; 11h ago\n" +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:337 +#, no-wrap +msgid "Starting chronyd" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:340 +msgid "To start `chronyd`, issue the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:344 +#, no-wrap +msgid "~]#{nbsp}systemctl start chronyd\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:347 +msgid "" +"To ensure `chronyd` starts automatically at system start, issue the " +"following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:351 +#, no-wrap +msgid "~]#{nbsp}systemctl enable chronyd\n" +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:354 +#, no-wrap +msgid "Stopping chronyd" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:357 +msgid "To stop `chronyd`, issue the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:361 +#, no-wrap +msgid "~]#{nbsp}systemctl stop chronyd\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:364 +msgid "" +"To prevent `chronyd` from starting automatically at system start, issue the " +"following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:368 +#, no-wrap +msgid "~]#{nbsp}systemctl disable chronyd\n" +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:371 +#, no-wrap +msgid "Checking if chrony is Synchronized" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:374 +msgid "" +"To check if [application]*chrony* is synchronized, make use of the " +"[command]#tracking#, [command]#sources#, and [command]#sourcestats# " +"commands." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:376 +#, no-wrap +msgid "Checking chrony Tracking" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:379 +msgid "To check [application]*chrony* tracking, issue the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:396 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#chronyc tracking#\n" +"Reference ID : 1.2.3.4 (a.b.c)\n" +"Stratum : 3\n" +"Ref time (UTC) : Fri Feb 3 15:00:29 2012\n" +"System time : 0.000001501 seconds slow of NTP time\n" +"Last offset : -0.000001632 seconds\n" +"RMS offset : 0.000002360 seconds\n" +"Frequency : 331.898 ppm fast\n" +"Residual freq : 0.004 ppm\n" +"Skew : 0.154 ppm\n" +"Root delay : 0.373169 seconds\n" +"Root dispersion : 0.024780 seconds\n" +"Update interval : 64.2 seconds\n" +"Leap status : Normal\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:400 +msgid "The fields are as follows:" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:401 +#, no-wrap +msgid "Reference ID" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:402 +msgid "" +"This is the reference ID and name (or `IP` address) if available, of the " +"server to which the computer is currently synchronized. If this is " +"`127.127.1.1` it means the computer is not synchronized to any external " +"source and that you have the \"`local`\" mode operating (via the local " +"command in [application]*chronyc*, or the [command]#local# directive in the " +"`/etc/chrony.conf` file (see section [command]#local#))." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:403 +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:456 +#, no-wrap +msgid "Stratum" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:404 +msgid "" +"The stratum indicates how many hops away from a computer with an attached " +"reference clock we are. Such a computer is a stratum-1 computer, so the " +"computer in the example is two hops away (that is to say, a.b.c is a " +"stratum-2 and is synchronized from a stratum-1)." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:405 +#, no-wrap +msgid "Ref time" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:406 +msgid "" +"This is the time (UTC) at which the last measurement from the reference " +"source was processed." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:407 +#, no-wrap +msgid "System time" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:408 +msgid "" +"In normal operation, `chronyd` never steps the system clock, because any " +"jump in the timescale can have adverse consequences for certain application " +"programs. Instead, any error in the system clock is corrected by slightly " +"speeding up or slowing down the system clock until the error has been " +"removed, and then returning to the system clock’s normal speed. A " +"consequence of this is that there will be a period when the system clock (as " +"read by other programs using the `gettimeofday()` system call, or by the " +"date command in the shell) will be different from " +"`chronyd`pass:attributes[{blank}]'s estimate of the current true time (which " +"it reports to `NTP` clients when it is operating in server mode). The value " +"reported on this line is the difference due to this effect." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:409 +#, no-wrap +msgid "Last offset" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:410 +msgid "This is the estimated local offset on the last clock update." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:411 +#, no-wrap +msgid "RMS offset" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:412 +msgid "This is a long-term average of the offset value." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:413 +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:494 +#, no-wrap +msgid "Frequency" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:414 +msgid "" +"The \"`frequency`\" is the rate by which the system’s clock would be wrong " +"if `chronyd` was not correcting it. It is expressed in ppm (parts per " +"million). For example, a value of 1ppm would mean that when the system’s " +"clock thinks it has advanced 1 second, it has actually advanced by 1.000001 " +"seconds relative to true time." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:415 +#, no-wrap +msgid "Residual freq" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:416 +msgid "" +"This shows the \"`residual frequency`\" for the currently selected reference " +"source. This reflects any difference between what the measurements from the " +"reference source indicate the frequency should be and the frequency " +"currently being used." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:418 +msgid "" +"The reason this is not always zero is that a smoothing procedure is applied " +"to the frequency. Each time a measurement from the reference source is " +"obtained and a new residual frequency computed, the estimated accuracy of " +"this residual is compared with the estimated accuracy (see [option]`skew` " +"next) of the existing frequency value. A weighted average is computed for " +"the new frequency, with weights depending on these accuracies. If the " +"measurements from the reference source follow a consistent trend, the " +"residual will be driven to zero over time." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:419 +#, no-wrap +msgid "Skew" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:420 +msgid "This is the estimated error bound on the frequency." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:421 +#, no-wrap +msgid "Root delay" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:422 +msgid "" +"This is the total of the network path delays to the stratum-1 computer from " +"which the computer is ultimately synchronized." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:424 +msgid "" +"In certain extreme situations, this value can be negative. (This can arise " +"in a symmetric peer arrangement where the computers’ frequencies are not " +"tracking each other and the network delay is very short relative to the " +"turn-around time at each computer.)" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:425 +#, no-wrap +msgid "Root dispersion" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:426 +msgid "" +"This is the total dispersion accumulated through all the computers back to " +"the stratum-1 computer from which the computer is ultimately " +"synchronized. Dispersion is due to system clock resolution, statistical " +"measurement variations etc." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:427 +#, no-wrap +msgid "Leap status" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:428 +msgid "" +"This is the leap status, which can be Normal, Insert second, Delete second " +"or Not synchronized." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:430 +#, no-wrap +msgid "Checking chrony Sources" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:433 +msgid "" +"The sources command displays information about the current time sources that " +"`chronyd` is accessing." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:435 +msgid "" +"The optional argument -v can be specified, meaning verbose. In this case, " +"extra caption lines are shown as a reminder of the meanings of the columns." +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:445 +#, no-wrap +msgid "" +"~]${nbsp}chronyc sources\n" +"\t210 Number of sources = 3\n" +"MS Name/IP address Stratum Poll Reach LastRx Last sample\n" +"===============================================================================\n" +"#* GPS0 0 4 377 11 -479ns[ -621ns] +/- " +"134ns\n" +"^? a.b.c 2 6 377 23 -923us[ -924us] +/- " +"43ms\n" +"^+ d.e.f 1 6 377 21 -2629us[-2619us] +/- " +"86ms\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:448 +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:485 +msgid "The columns are as follows:" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:449 +#, no-wrap +msgid "M" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:450 +msgid "" +"This indicates the mode of the source. `^` means a server, `=` means a peer " +"and `#` indicates a locally connected reference clock." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:451 +#, no-wrap +msgid "S" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:453 +msgid "" +"This column indicates the state of the sources. \"`*`\" indicates the source " +"to which `chronyd` is currently synchronized. \"`+`\" indicates acceptable " +"sources which are combined with the selected source. \"`-`\" indicates " +"acceptable sources which are excluded by the combining algorithm. \"`?`\" " +"indicates sources to which connectivity has been lost or whose packets do " +"not pass all tests. \"`x`\" indicates a clock which `chronyd` thinks is a " +"_falseticker_ (its time is inconsistent with a majority of other " +"sources). \"`~`\" indicates a source whose time appears to have too much " +"variability. The \"`?`\" condition is also shown at start-up, until at least " +"3 samples have been gathered from it." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:454 +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:486 +#, no-wrap +msgid "Name/IP address" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:455 +msgid "" +"This shows the name or the `IP` address of the source, or reference ID for " +"reference clocks." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:457 +msgid "" +"This shows the stratum of the source, as reported in its most recently " +"received sample. Stratum 1 indicates a computer with a locally attached " +"reference clock. A computer that is synchronized to a stratum 1 computer is " +"at stratum 2. A computer that is synchronized to a stratum 2 computer is at " +"stratum 3, and so on." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:458 +#, no-wrap +msgid "Poll" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:459 +msgid "" +"This shows the rate at which the source is being polled, as a base-2 " +"logarithm of the interval in seconds. Thus, a value of 6 would indicate that " +"a measurement is being made every 64 seconds." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:461 +msgid "" +"`chronyd` automatically varies the polling rate in response to prevailing " +"conditions." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:462 +#, no-wrap +msgid "Reach" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:463 +msgid "" +"This shows the source’s reach register printed as an octal number. The " +"register has 8 bits and is updated on every received or missed packet from " +"the source. A value of 377 indicates that a valid reply was received for all " +"of the last eight transmissions." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:464 +#, no-wrap +msgid "LastRx" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:465 +msgid "" +"This column shows how long ago the last sample was received from the " +"source. This is normally in seconds. The letters `m`, `h`, `d` or `y` " +"indicate minutes, hours, days or years. A value of 10 years indicates there " +"were no samples received from this source yet." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:466 +#, no-wrap +msgid "Last sample" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:467 +msgid "" +"This column shows the offset between the local clock and the source at the " +"last measurement. The number in the square brackets shows the actual " +"measured offset. This may be suffixed by `ns` (indicating nanoseconds), `us` " +"(indicating microseconds), `ms` (indicating milliseconds), or `s` " +"(indicating seconds). The number to the left of the square brackets shows " +"the original measurement, adjusted to allow for any slews applied to the " +"local clock since. The number following the `+/-` indicator shows the margin " +"of error in the measurement. Positive offsets indicate that the local clock " +"is ahead of the source." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:469 +#, no-wrap +msgid "Checking chrony Source Statistics" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:472 +msgid "" +"The [command]#sourcestats# command displays information about the drift rate " +"and offset estimation process for each of the sources currently being " +"examined by `chronyd`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:474 +msgid "" +"The optional argument [option]`-v` can be specified, meaning verbose. In " +"this case, extra caption lines are shown as a reminder of the meanings of " +"the columns." +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:482 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#chronyc sourcestats#\n" +"210 Number of sources = 1\n" +"Name/IP Address NP NR Span Frequency Freq Skew Offset Std " +"Dev\n" +"===============================================================================\n" +"abc.def.ghi 11 5 46m -0.001 0.045 1us " +"25us\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:487 +msgid "" +"This is the name or `IP` address of the `NTP` server (or peer) or reference " +"ID of the reference clock to which the rest of the line relates." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:488 +#, no-wrap +msgid "NP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:489 +msgid "" +"This is the number of sample points currently being retained for the " +"server. The drift rate and current offset are estimated by performing a " +"linear regression through these points." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:490 +#, no-wrap +msgid "NR" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:491 +msgid "" +"This is the number of runs of residuals having the same sign following the " +"last regression. If this number starts to become too small relative to the " +"number of samples, it indicates that a straight line is no longer a good fit " +"to the data. If the number of runs is too low, `chronyd` discards older " +"samples and re-runs the regression until the number of runs becomes " +"acceptable." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:492 +#, no-wrap +msgid "Span" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:493 +msgid "" +"This is the interval between the oldest and newest samples. If no unit is " +"shown the value is in seconds. In the example, the interval is 46 minutes." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:495 +msgid "" +"This is the estimated residual frequency for the server, in parts per " +"million. In this case, the computer’s clock is estimated to be running 1 " +"part in _10pass:attributes[{blank}]^9^pass:attributes[{blank}]_ slow " +"relative to the server." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:496 +#, no-wrap +msgid "Freq Skew" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:497 +msgid "This is the estimated error bounds on Freq (again in parts per million)." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:498 +#, no-wrap +msgid "Offset" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:499 +msgid "This is the estimated offset of the source." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:500 +#, no-wrap +msgid "Std Dev" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:501 +msgid "This is the estimated sample standard deviation." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:503 +#, no-wrap +msgid "Manually Adjusting the System Clock" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:506 +msgid "" +"To update, or step, the system clock immediately, bypassing any adjustments " +"in progress by slewing the clock, issue the following commands as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:514 +#, no-wrap +msgid "" +"~]#{nbsp}chronyc\n" +" chrony> password pass:quotes[_commandkey-password_]\n" +" 200 OK\n" +" chrony> makestep\n" +" 200 OK\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:517 +msgid "" +"Where _commandkey-password_ is the command key or password stored in the key " +"file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:519 +msgid "" +"If the [command]#rtcfile# directive is used, the real-time clock should not " +"be manually adjusted. Random adjustments would interfere with " +"[application]*chrony*pass:attributes[{blank}]'s need to measure the rate at " +"which the real-time clock drifts." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:521 +msgid "" +"If [application]*chronyc* is used to configure the local " +"[application]*chronyd*, the [option]`-a` will run the [command]#authhash# " +"and [command]#password# commands automatically. This means that the " +"interactive session illustrated above can be replaced by:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:525 +#, no-wrap +msgid "chronyc -a makestep\n" +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:528 +#, no-wrap +msgid "Setting Up chrony for Different Environments" +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:531 +#, no-wrap +msgid "Setting Up chrony for a System Which is Infrequently Connected" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:534 +msgid "" +"This example is intended for systems which use dial-on-demand " +"connections. The normal configuration should be sufficient for mobile and " +"virtual devices which connect intermittently. First, review and confirm that " +"the default settings in the `/etc/chrony.conf` are similar to the following:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:540 +#, no-wrap +msgid "" +"driftfile /var/lib/chrony/drift\n" +"commandkey 1\n" +"keyfile /etc/chrony.keys\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:544 +msgid "" +"The command key ID is generated at install time and should correspond with " +"the [command]#commandkey# value in the key file, `/etc/chrony.keys`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:546 +msgid "" +"Using your editor running as `root`, add the addresses of four `NTP` servers " +"as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:553 +#, no-wrap +msgid "" +"server 0.pool.ntp.org offline\n" +"server 1.pool.ntp.org offline\n" +"server 2.pool.ntp.org offline\n" +"server 3.pool.ntp.org offline\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:556 +msgid "" +"The [option]`offline` option can be useful in preventing systems from trying " +"to activate connections. The [application]*chrony* daemon will wait for " +"[application]*chronyc* to inform it that the system is connected to the " +"network or Internet." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:558 +#, no-wrap +msgid "Setting Up chrony for a System in an Isolated Network" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:561 +msgid "" +"For a network that is never connected to the Internet, one computer is " +"selected to be the master timeserver. The other computers are either direct " +"clients of the master, or clients of clients. On the master, the drift file " +"must be manually set with the average rate of drift of the system clock. If " +"the master is rebooted it will obtain the time from surrounding systems and " +"take an average to set its system clock. Thereafter it resumes applying " +"adjustments based on the drift file. The drift file will be updated " +"automatically when the [command]#settime# command is used." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:563 +msgid "" +"On the system selected to be the master, using a text editor running as " +"`root`, edit the `/etc/chrony.conf` as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:574 +#, no-wrap +msgid "" +"driftfile /var/lib/chrony/drift\n" +"commandkey 1\n" +"keyfile /etc/chrony.keys\n" +"initstepslew 10 client1 client3 client6\n" +"local stratum 8\n" +"manual\n" +"allow 192.0.2.0\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:578 +msgid "" +"Where `192.0.2.0` is the network or subnet address from which the clients " +"are allowed to connect." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:580 +msgid "" +"On the systems selected to be direct clients of the master, using a text " +"editor running as `root`, edit the `/etc/chrony.conf` as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:592 +#, no-wrap +msgid "" +"server master\n" +"driftfile /var/lib/chrony/drift\n" +"logdir /var/log/chrony\n" +"log measurements statistics tracking\n" +"keyfile /etc/chrony.keys\n" +"commandkey 24\n" +"local stratum 10\n" +"initstepslew 20 master\n" +"allow 192.0.2.123\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:595 +msgid "" +"Where `192.0.2.123` is the address of the master, and `master` is the host " +"name of the master. Clients with this configuration will resynchronize the " +"master if it restarts." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:597 +msgid "" +"On the client systems which are not to be direct clients of the master, the " +"`/etc/chrony.conf` file should be the same except that the [option]`local` " +"and [option]`allow` directives should be omitted." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:599 +#, no-wrap +msgid "Using chronyc" +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:602 +#, no-wrap +msgid "Using chronyc to Control chronyd" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:605 +msgid "" +"To make changes to the local instance of `chronyd` using the command line " +"utility [application]*chronyc* in interactive mode, enter the following " +"command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:609 +#, no-wrap +msgid "~]#{nbsp}chronyc -a\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:612 +msgid "" +"[application]*chronyc* must run as `root` if some of the restricted commands " +"are to be used. The [option]`-a` option is for automatic authentication " +"using the local keys when configuring `chronyd` on the local system. See " +"xref:Configuring_NTP_Using_the_chrony_Suite.adoc#sect-Security_with_chronyc[Security " +"with chronyc] for more information." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:614 +msgid "The [application]*chronyc* command prompt will be displayed as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:618 +#, no-wrap +msgid "chronyc>\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:621 +msgid "You can type [command]#help# to list all of the commands." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:623 +msgid "" +"The utility can also be invoked in non-interactive command mode if called " +"together with a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:627 +#, no-wrap +msgid "[command]#chronyc _command_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:633 +msgid "" +"Changes made using [application]*chronyc* are not permanent, they will be " +"lost after a `chronyd` restart. For permanent changes, modify " +"`/etc/chrony.conf`." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:637 +#, no-wrap +msgid "Using chronyc for Remote Administration" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:640 +msgid "" +"To configure [application]*chrony* to connect to a remote instance of " +"`chronyd`, issue a command in the following format:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:644 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#chronyc -h " +"_hostname_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:647 +msgid "" +"Where _hostname_ is the host name to connect to. The default is to connect " +"to the local daemon." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:649 +msgid "" +"To configure [application]*chrony* to connect to a remote instance of " +"`chronyd` on a non-default port, issue a command in the following format:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:653 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#chronyc -h _hostname_ -p " +"_port_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:656 +msgid "" +"Where _port_ is the port in use for controlling and monitoring by the remote " +"instance of `chronyd`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:658 +msgid "" +"Note that commands issued at the [application]*chronyc* command prompt are " +"not persistent. Only commands in the configuration file are persistent." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:660 +msgid "" +"The first command must be the [command]#password# command at the " +"[application]*chronyc* command prompt as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:665 +#, no-wrap +msgid "" +"chronyc> [command]#password _password_pass:attributes[{blank}]#\n" +"200 OK\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:668 +msgid "The password should not have any spaces." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:670 +msgid "" +"If the password is not an MD5 hash, the hashed password must be preceded by " +"the [command]#authhash# command as follows:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:679 +msgid "" +"The password or hash associated with the command key for a remote system is " +"best obtained by `SSH`. An `SSH` connection should be established to the " +"remote machine and the ID of the command key from `/etc/chrony.conf` and the " +"command key in `/etc/chrony.keys` memorized or stored securely for the " +"duration of the session." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:681 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:684 +msgid "" +"The following sources of information provide additional resources regarding " +"[application]*chrony*." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:686 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:689 +msgid "" +"`chrony(1)` man page — Introduces the [application]*chrony* daemon and the " +"command-line interface tool." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:691 +msgid "" +"`chronyc(1)` man page — Describes the [application]*chronyc* command-line " +"interface tool including commands and command options." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:693 +msgid "" +"`chronyd(1)` man page — Describes the [application]*chronyd* daemon " +"including commands and command options." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:695 +msgid "" +"`chrony.conf(5)` man page — Describes the [application]*chrony* " +"configuration file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:697 +msgid "" +"`/usr/share/doc/chrony/chrony.txt` — User guide for the " +"[application]*chrony* suite." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:699 +#, no-wrap +msgid "Online Documentation" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:701 +#, no-wrap +msgid "link:++https://chrony.tuxfamily.org/manual.html++[]" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:701 +msgid "The online user guide for [application]*chrony*." +msgstr "" diff --git a/po/fr/rawhide/pages/servers/Configuring_PTP_Using_ptp4l.po b/po/fr/rawhide/pages/servers/Configuring_PTP_Using_ptp4l.po new file mode 100644 index 00000000000..d09bc238c8d --- /dev/null +++ b/po/fr/rawhide/pages/servers/Configuring_PTP_Using_ptp4l.po @@ -0,0 +1,1707 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:6 +#, no-wrap +msgid "Configuring PTP Using ptp4l" +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:9 +#, no-wrap +msgid "Introduction to PTP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:12 +msgid "" +"The _Precision Time Protocol_ (*PTP*) is a protocol used to synchronize " +"clocks in a network. When used in conjunction with hardware support, `PTP` " +"is capable of sub-microsecond accuracy, which is far better than is normally " +"obtainable with `NTP`. `PTP` support is divided between the kernel and user " +"space. The kernel in Fedora includes support for `PTP` clocks, which are " +"provided by network drivers. The actual implementation of the protocol is " +"known as [application]*linuxptp*, a `PTPv2` implementation according to the " +"IEEE standard 1588 for Linux." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:14 +msgid "" +"The [package]*linuxptp* package includes the [application]*ptp4l* and " +"[application]*phc2sys* programs for clock synchronization. The " +"[application]*ptp4l* program implements the `PTP` boundary clock and " +"ordinary clock. With hardware time stamping, it is used to synchronize the " +"`PTP` hardware clock to the master clock, and with software time stamping it " +"synchronizes the system clock to the master clock. The " +"[application]*phc2sys* program is needed only with hardware time stamping, " +"for synchronizing the system clock to the `PTP` hardware clock on the " +"_network interface card_ (*NIC*)." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:16 +#, no-wrap +msgid "Understanding PTP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:19 +msgid "" +"The clocks synchronized by `PTP` are organized in a master-slave " +"hierarchy. The slaves are synchronized to their masters which may be slaves " +"to their own masters. The hierarchy is created and updated automatically by " +"the _best master clock_ (*BMC*) algorithm, which runs on every clock. When a " +"clock has only one port, it can be _master_ or _slave_, such a clock is " +"called an _ordinary clock_ (*OC*). A clock with multiple ports can be master " +"on one port and slave on another, such a clock is called a _boundary_ clock " +"(*BC*). The top-level master is called the _grandmaster clock_, which can be " +"synchronized by using a _Global Positioning System_ (*GPS*) time source. By " +"using a GPS-based time source, disparate networks can be synchronized with a " +"high-degree of accuracy." +msgstr "" + +#. type: Block title +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:21 +#, no-wrap +msgid "PTP grandmaster, boundary, and slave Clocks" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:23 +#, no-wrap +msgid "An illustration showing PTP grandmaster" +msgstr "" + +#. type: Target for macro image +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:23 +#, no-wrap +msgid "ptp_grandmaster_boundary_and_slaves.png" +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:26 +#, no-wrap +msgid "Advantages of PTP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:29 +msgid "" +"One of the main advantages that `PTP` has over the _Network Time Protocol_ " +"(*NTP*) is hardware support present in various _network interface " +"controllers_ (*NIC*) and network switches. This specialized hardware allows " +"`PTP` to account for delays in message transfer, and greatly improves the " +"accuracy of time synchronization. While it is possible to use non-PTP " +"enabled hardware components within the network, this will often cause an " +"increase in jitter or introduce an asymmetry in the delay resulting in " +"synchronization inaccuracies, which add up with multiple non-PTP aware " +"components used in the communication path. To achieve the best possible " +"accuracy, it is recommended that all networking components between `PTP` " +"clocks are `PTP` hardware enabled. Time synchronization in larger networks " +"where not all of the networking hardware supports `PTP` might be better " +"suited for `NTP`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:31 +msgid "" +"With hardware `PTP` support, the NIC has its own on-board clock, which is " +"used to time stamp the received and transmitted `PTP` messages. It is this " +"on-board clock that is synchronized to the `PTP` master, and the computer's " +"system clock is synchronized to the `PTP` hardware clock on the NIC. With " +"software `PTP` support, the system clock is used to time stamp the `PTP` " +"messages and it is synchronized to the `PTP` master directly. Hardware `PTP` " +"support provides better accuracy since the NIC can time stamp the `PTP` " +"packets at the exact moment they are sent and received while software `PTP` " +"support requires additional processing of the `PTP` packets by the operating " +"system." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:33 +#, no-wrap +msgid "Using PTP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:36 +msgid "" +"In order to use `PTP`, the kernel network driver for the intended interface " +"has to support either software or hardware time stamping capabilities." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:38 +#, no-wrap +msgid "Checking for Driver and Hardware Support" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:41 +msgid "" +"In addition to hardware time stamping support being present in the driver, " +"the NIC must also be capable of supporting this functionality in the " +"physical hardware. The best way to verify the time stamping capabilities of " +"a particular driver and NIC is to use the [application]*ethtool* utility to " +"query the interface as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:60 +#, no-wrap +msgid "" +"~]#{nbsp}ethtool -T em3\n" +"Time stamping parameters for em3:\n" +"Capabilities:\n" +" hardware-transmit (SOF_TIMESTAMPING_TX_HARDWARE)\n" +" software-transmit (SOF_TIMESTAMPING_TX_SOFTWARE)\n" +" hardware-receive (SOF_TIMESTAMPING_RX_HARDWARE)\n" +" software-receive (SOF_TIMESTAMPING_RX_SOFTWARE)\n" +" software-system-clock (SOF_TIMESTAMPING_SOFTWARE)\n" +" hardware-raw-clock (SOF_TIMESTAMPING_RAW_HARDWARE)\n" +"PTP Hardware Clock: 0\n" +"Hardware Transmit Timestamp Modes:\n" +" off (HWTSTAMP_TX_OFF)\n" +" on (HWTSTAMP_TX_ON)\n" +"Hardware Receive Filter Modes:\n" +" none (HWTSTAMP_FILTER_NONE)\n" +" all (HWTSTAMP_FILTER_ALL)\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:63 +msgid "Where _em3_ is the interface you want to check." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:66 +msgid "For software time stamping support, the parameters list should include:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:68 +msgid "`SOF_TIMESTAMPING_SOFTWARE`" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:70 +msgid "`SOF_TIMESTAMPING_TX_SOFTWARE`" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:72 +msgid "`SOF_TIMESTAMPING_RX_SOFTWARE`" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:75 +msgid "For hardware time stamping support, the parameters list should include:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:77 +msgid "`SOF_TIMESTAMPING_RAW_HARDWARE`" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:79 +msgid "`SOF_TIMESTAMPING_TX_HARDWARE`" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:81 +msgid "`SOF_TIMESTAMPING_RX_HARDWARE`" +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:83 +#, no-wrap +msgid "Installing PTP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:86 +msgid "" +"The kernel in Fedora includes support for `PTP`. User space support is " +"provided by the tools in the [application]*linuxptp* package. To install " +"[application]*linuxptp*, issue the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:90 +#, no-wrap +msgid "~]#{nbsp}dnf install linuxptp\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:93 +msgid "This will install [application]*ptp4l* and [application]*phc2sys*." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:95 +msgid "" +"Do not run more than one service to set the system clock's time at the same " +"time. If you intend to serve `PTP` time using `NTP`, see " +"xref:Configuring_PTP_Using_ptp4l.adoc#sec-Serving_PTP_Time_with_NTP[Serving " +"PTP Time with NTP]." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:97 +#, no-wrap +msgid "Starting ptp4l" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:100 +msgid "" +"The [application]*ptp4l* program can be started from the command line or it " +"can be started as a service. When running as a service, options are " +"specified in the `/etc/sysconfig/ptp4l` file. Options required for use both " +"by the service and on the command line should be specified in the " +"`/etc/ptp4l.conf` file. The `/etc/sysconfig/ptp4l` file includes the " +"[command]#-f /etc/ptp4l.conf# command line option, which causes the `ptp4l` " +"program to read the `/etc/ptp4l.conf` file and process the options it " +"contains. The use of the `/etc/ptp4l.conf` is explained in " +"xref:Configuring_PTP_Using_ptp4l.adoc#sec-Specifying_a_Configuration_File[Specifying " +"a Configuration File]. More information on the different " +"[application]*ptp4l* options and the configuration file settings can be " +"found in the `ptp4l(8)` man page." +msgstr "" + +#. type: Block title +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:101 +#, no-wrap +msgid "Starting ptp4l as a Service" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:103 +msgid "" +"To start [application]*ptp4l* as a service, issue the following command as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:107 +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:145 +#, no-wrap +msgid "~]#{nbsp}systemctl start ptp4l\n" +msgstr "" + +#. type: Block title +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:109 +#, no-wrap +msgid "Using ptp4l From The Command Line" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:111 +msgid "" +"The [application]*ptp4l* program tries to use hardware time stamping by " +"default. To use [application]*ptp4l* with hardware time stamping capable " +"drivers and NICs, you must provide the network interface to use with the " +"[option]`-i` option. Enter the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:115 +#, no-wrap +msgid "~]#{nbsp}ptp4l -i em3 -m\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:118 +msgid "" +"Where _em3_ is the interface you want to configure. Below is example output " +"from [application]*ptp4l* when the `PTP` clock on the NIC is synchronized to " +"a master:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:135 +#, no-wrap +msgid "" +"~]#{nbsp}ptp4l -i em3 -m\n" +"selected em3 as PTP clock\n" +"port 1: INITIALIZING to LISTENING on INITIALIZE\n" +"port 0: INITIALIZING to LISTENING on INITIALIZE\n" +"port 1: new foreign master 00a069.fffe.0b552d-1\n" +"selected best master clock 00a069.fffe.0b552d\n" +"port 1: LISTENING to UNCALIBRATED on RS_SLAVE\n" +"master offset -23947 s0 freq +0 path delay 11350\n" +"master offset -28867 s0 freq +0 path delay 11236\n" +"master offset -32801 s0 freq +0 path delay 10841\n" +"master offset -37203 s1 freq +0 path delay 10583\n" +"master offset -7275 s2 freq -30575 path delay 10583\n" +"port 1: UNCALIBRATED to SLAVE on MASTER_CLOCK_SELECTED\n" +"master offset -4552 s2 freq -30035 path delay 10385\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:139 +msgid "" +"The master offset value is the measured offset from the master in " +"nanoseconds. The `s0`, `s1`, `s2` strings indicate the different clock servo " +"states: `s0` is unlocked, `s1` is clock step and `s2` is locked. Once the " +"servo is in the locked state (`s2`), the clock will not be stepped (only " +"slowly adjusted) unless the [option]`pi_offset_const` option is set to a " +"positive value in the configuration file (described in the `ptp4l(8)` man " +"page). The `adj` value is the frequency adjustment of the clock in parts per " +"billion (ppb). The path delay value is the estimated delay of the " +"synchronization messages sent from the master in nanoseconds. Port 0 is a " +"Unix domain socket used for local `PTP` management. Port 1 is the `em3` " +"interface (based on the example above.) INITIALIZING, LISTENING, " +"UNCALIBRATED and SLAVE are some of possible port states which change on the " +"INITIALIZE, RS_SLAVE, MASTER_CLOCK_SELECTED events. In the last state change " +"message, the port state changed from UNCALIBRATED to SLAVE indicating " +"successful synchronization with a `PTP` master clock." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:141 +msgid "" +"The [application]*ptp4l* program can also be started as a service by " +"running:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:148 +msgid "" +"When running as a service, options are specified in the " +"`/etc/sysconfig/ptp4l` file. More information on the different " +"[application]*ptp4l* options and the configuration file settings can be " +"found in the `ptp4l(8)` man page." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:150 +msgid "" +"By default, messages are sent to `/var/log/messages`. However, specifying " +"the [option]`-m` option enables logging to standard output which can be " +"useful for debugging purposes." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:152 +msgid "" +"To enable software time stamping, the [option]`-S` option needs to be used " +"as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:156 +#, no-wrap +msgid "~]#{nbsp}ptp4l -i em3 -m -S\n" +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:159 +#, no-wrap +msgid "Selecting a Delay Measurement Mechanism" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:162 +msgid "" +"There are two different delay measurement mechanisms and they can be " +"selected by means of an option added to the [command]#ptp4l# command as " +"follows:" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:163 +#, no-wrap +msgid "[option]`-P`" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:164 +msgid "" +"The [option]`-P` selects the _peer-to-peer_ (*P2P*) delay measurement " +"mechanism." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:166 +msgid "" +"The *P2P* mechanism is preferred as it reacts to changes in the network " +"topology faster, and may be more accurate in measuring the delay, than other " +"mechanisms. The *P2P* mechanism can only be used in topologies where each " +"port exchanges *PTP* messages with at most one other *P2P* port. It must be " +"supported and used by all hardware, including transparent clocks, on the " +"communication path." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:167 +#, no-wrap +msgid "[option]`-E`" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:168 +msgid "" +"The [option]`-E` selects the _end-to-end_ (*E2E*) delay measurement " +"mechanism. This is the default." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:170 +msgid "" +"The *E2E* mechanism is also referred to as the delay \"`request-response`\" " +"mechanism." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:171 +#, no-wrap +msgid "[option]`-A`" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:172 +msgid "" +"The [option]`-A` enables automatic selection of the delay measurement " +"mechanism." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:174 +msgid "" +"The automatic option starts [application]*ptp4l* in *E2E* mode. It will " +"change to *P2P* mode if a peer delay request is received." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:179 +msgid "" +"All clocks on a single `PTP` communication path must use the same mechanism " +"to measure the delay. Warnings will be printed in the following " +"circumstances:" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:181 +msgid "When a peer delay request is received on a port using the *E2E* mechanism." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:183 +msgid "When a *E2E* delay request is received on a port using the *P2P* mechanism." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:187 +#, no-wrap +msgid "Specifying a Configuration File" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:190 +msgid "" +"The command line options and other options, which cannot be set on the " +"command line, can be set in an optional configuration file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:192 +msgid "" +"No configuration file is read by default, so it needs to be specified at " +"runtime with the [option]`-f` option. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:196 +#, no-wrap +msgid "~]#{nbsp}ptp4l -f /etc/ptp4l.conf\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:199 +msgid "" +"A configuration file equivalent to the [command]#-i em3 -m -S# options shown " +"above would look as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:207 +#, no-wrap +msgid "" +"~]#{nbsp}cat /etc/ptp4l.conf\n" +"[global]\n" +"verbose 1\n" +"time_stamping software\n" +"[em3]\n" +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:211 +#, no-wrap +msgid "Using the PTP Management Client" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:214 +msgid "" +"The `PTP` management client, [application]*pmc*, can be used to obtain " +"additional information from [application]*ptp4l* as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:223 +#, no-wrap +msgid "" +"~]#{nbsp}pmc -u -b 0 'GET CURRENT_DATA_SET'\n" +"sending: GET CURRENT_DATA_SET\n" +" 90e2ba.fffe.20c7f8-0 seq 0 RESPONSE MANAGMENT CURRENT_DATA_SET\n" +" stepsRemoved 1\n" +" offsetFromMaster -142.0\n" +" meanPathDelay 9310.0\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:238 +#, no-wrap +msgid "" +"~]#{nbsp}pmc -u -b 0 'GET TIME_STATUS_NP'\n" +"sending: GET TIME_STATUS_NP\n" +" 90e2ba.fffe.20c7f8-0 seq 0 RESPONSE MANAGMENT TIME_STATUS_NP\n" +" master_offset 310\n" +" ingress_time 1361545089345029441\n" +" cumulativeScaledRateOffset +1.000000000\n" +" scaledLastGmPhaseChange 0\n" +" gmTimeBaseIndicator 0\n" +" lastGmPhaseChange 0x0000'0000000000000000.0000\n" +" gmPresent true\n" +" gmIdentity 00a069.fffe.0b552d\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:241 +msgid "" +"Setting the [option]`-b` option to `zero` limits the boundary to the locally " +"running [application]*ptp4l* instance. A larger boundary value will retrieve " +"the information also from `PTP` nodes further from the local clock. The " +"retrievable information includes:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:243 +msgid "" +"`stepsRemoved` is the number of communication paths to the grandmaster " +"clock." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:245 +msgid "" +"`offsetFromMaster` and master_offset is the last measured offset of the " +"clock from the master in nanoseconds." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:247 +msgid "" +"`meanPathDelay` is the estimated delay of the synchronization messages sent " +"from the master in nanoseconds." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:249 +msgid "" +"if `gmPresent` is true, the `PTP` clock is synchronized to a master, the " +"local clock is not the grandmaster clock." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:251 +msgid "`gmIdentity` is the grandmaster's identity." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:253 +msgid "" +"For a full list of [application]*pmc* commands, type the following as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:257 +#, no-wrap +msgid "~]#{nbsp}pmc help\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:260 +msgid "Additional information is available in the `pmc(8)` man page." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:262 +#, no-wrap +msgid "Synchronizing the Clocks" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:265 +msgid "" +"The [application]*phc2sys* program is used to synchronize the system clock " +"to the `PTP` hardware clock (*PHC*) on the NIC. The [application]*phc2sys* " +"service is configured in the `/etc/sysconfig/phc2sys` configuration " +"file. The default setting in the `/etc/sysconfig/phc2sys` file is as " +"follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:269 +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:469 +#, no-wrap +msgid "OPTIONS=\"-a -r\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:272 +msgid "" +"The [option]`-a` option causes [application]*phc2sys* to read the clocks to " +"be synchronized from the [application]*ptp4l* application. It will follow " +"changes in the `PTP` port states, adjusting the synchronization between the " +"NIC hardware clocks accordingly. The system clock is not synchronized, " +"unless the [option]`-r` option is also specified. If you want the system " +"clock to be eligible to become a time source, specify the [option]`-r` " +"option twice." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:274 +msgid "" +"After making changes to `/etc/sysconfig/phc2sys`, restart the " +"[application]*phc2sys* service from the command line by issuing a command as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:277 +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:483 +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:681 +#, no-wrap +msgid "~]# systemctl restart phc2sys\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:280 +msgid "" +"Under normal circumstances, use [command]#systemctl# commands to start, " +"stop, and restart the [application]*phc2sys* service." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:282 +msgid "" +"When you do not want to start [application]*phc2sys* as a service, you can " +"start it from the command line. For example, enter the following command as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:286 +#, no-wrap +msgid "~]#{nbsp}phc2sys -a -r\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:289 +msgid "" +"The [option]`-a` option causes [application]*phc2sys* to read the clocks to " +"be synchronized from the [application]*ptp4l* application. If you want the " +"system clock to be eligible to become a time source, specify the " +"[option]`-r` option twice." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:291 +msgid "" +"Alternately, use the [option]`-s` option to synchronize the system clock to " +"a specific interface's `PTP` hardware clock. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:295 +#, no-wrap +msgid "~]#{nbsp}phc2sys -s em3 -w\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:298 +msgid "" +"The [option]`-w` option waits for the running [application]*ptp4l* " +"application to synchronize the `PTP` clock and then retrieves the *TAI* to " +"*UTC* offset from [application]*ptp4l*." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:300 +msgid "" +"Normally, `PTP` operates in the _International Atomic Time_ (*TAI*) " +"timescale, while the system clock is kept in _Coordinated Universal Time_ " +"(*UTC*). The current offset between the TAI and UTC timescales is 35 " +"seconds. The offset changes when leap seconds are inserted or deleted, which " +"typically happens every few years. The [option]`-O` option needs to be used " +"to set this offset manually when the [option]`-w` is not used, as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:304 +#, no-wrap +msgid "~]#{nbsp}phc2sys -s em3 -O -35\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:307 +msgid "" +"Once the [application]*phc2sys* servo is in a locked state, the clock will " +"not be stepped, unless the [option]`-S` option is used. This means that the " +"[application]*phc2sys* program should be started after the " +"[application]*ptp4l* program has synchronized the `PTP` hardware " +"clock. However, with [option]`-w`, it is not necessary to start " +"[application]*phc2sys* after [application]*ptp4l* as it will wait for it to " +"synchronize the clock." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:309 +msgid "" +"The [application]*phc2sys* program can also be started as a service by " +"running:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:313 +#, no-wrap +msgid "~]#{nbsp}systemctl start phc2sys\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:316 +msgid "" +"When running as a service, options are specified in the " +"`/etc/sysconfig/phc2sys` file. More information on the different " +"[application]*phc2sys* options can be found in the `phc2sys(8)` man page." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:318 +msgid "" +"Note that the examples in this section assume the command is run on a slave " +"system or slave port." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:320 +#, no-wrap +msgid "Verifying Time Synchronization" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:323 +msgid "" +"When `PTP` time synchronization is working properly, new messages with " +"offsets and frequency adjustments will be printed periodically to the " +"[application]*ptp4l* and [application]*phc2sys* (if hardware time stamping " +"is used) outputs. These values will eventually converge after a short period " +"of time. These messages can be seen in `/var/log/messages` file. An example " +"of the output follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:347 +#, no-wrap +msgid "" +"ptp4l[352.359]: selected /dev/ptp0 as PTP clock\n" +"ptp4l[352.361]: port 1: INITIALIZING to LISTENING on INITIALIZE\n" +"ptp4l[352.361]: port 0: INITIALIZING to LISTENING on INITIALIZE\n" +"ptp4l[353.210]: port 1: new foreign master 00a069.fffe.0b552d-1\n" +"ptp4l[357.214]: selected best master clock 00a069.fffe.0b552d\n" +"ptp4l[357.214]: port 1: LISTENING to UNCALIBRATED on RS_SLAVE\n" +"ptp4l[359.224]: master offset 3304 s0 freq +0 path delay " +"9202\n" +"ptp4l[360.224]: master offset 3708 s1 freq -29492 path delay " +"9202\n" +"ptp4l[361.224]: master offset -3145 s2 freq -32637 path delay " +"9202\n" +"ptp4l[361.224]: port 1: UNCALIBRATED to SLAVE on MASTER_CLOCK_SELECTED\n" +"ptp4l[362.223]: master offset -145 s2 freq -30580 path delay " +"9202\n" +"ptp4l[363.223]: master offset 1043 s2 freq -29436 path delay " +"8972\n" +"ptp4l[364.223]: master offset 266 s2 freq -29900 path delay " +"9153\n" +"ptp4l[365.223]: master offset 430 s2 freq -29656 path delay " +"9153\n" +"ptp4l[366.223]: master offset 615 s2 freq -29342 path delay " +"9169\n" +"ptp4l[367.222]: master offset -191 s2 freq -29964 path delay " +"9169\n" +"ptp4l[368.223]: master offset 466 s2 freq -29364 path delay " +"9170\n" +"ptp4l[369.235]: master offset 24 s2 freq -29666 path delay " +"9196\n" +"ptp4l[370.235]: master offset -375 s2 freq -30058 path delay " +"9238\n" +"ptp4l[371.235]: master offset 285 s2 freq -29511 path delay " +"9199\n" +"ptp4l[372.235]: master offset -78 s2 freq -29788 path delay " +"9204\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:351 +msgid "An example of the [application]*phc2sys* output follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:375 +#, no-wrap +msgid "" +"phc2sys[526.527]: Waiting for ptp4l...\n" +"phc2sys[527.528]: Waiting for ptp4l...\n" +"phc2sys[528.528]: phc offset 55341 s0 freq +0 delay 2729\n" +"phc2sys[529.528]: phc offset 54658 s1 freq -37690 delay 2725\n" +"phc2sys[530.528]: phc offset 888 s2 freq -36802 delay 2756\n" +"phc2sys[531.528]: phc offset 1156 s2 freq -36268 delay 2766\n" +"phc2sys[532.528]: phc offset 411 s2 freq -36666 delay 2738\n" +"phc2sys[533.528]: phc offset -73 s2 freq -37026 delay 2764\n" +"phc2sys[534.528]: phc offset 39 s2 freq -36936 delay 2746\n" +"phc2sys[535.529]: phc offset 95 s2 freq -36869 delay 2733\n" +"phc2sys[536.529]: phc offset -359 s2 freq -37294 delay 2738\n" +"phc2sys[537.529]: phc offset -257 s2 freq -37300 delay 2753\n" +"phc2sys[538.529]: phc offset 119 s2 freq -37001 delay 2745\n" +"phc2sys[539.529]: phc offset 288 s2 freq -36796 delay 2766\n" +"phc2sys[540.529]: phc offset -149 s2 freq -37147 delay 2760\n" +"phc2sys[541.529]: phc offset -352 s2 freq -37395 delay 2771\n" +"phc2sys[542.529]: phc offset 166 s2 freq -36982 delay 2748\n" +"phc2sys[543.529]: phc offset 50 s2 freq -37048 delay 2756\n" +"phc2sys[544.530]: phc offset -31 s2 freq -37114 delay 2748\n" +"phc2sys[545.530]: phc offset -333 s2 freq -37426 delay 2747\n" +"phc2sys[546.530]: phc offset 194 s2 freq -36999 delay 2749\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:378 +msgid "" +"For [application]*ptp4l* there is also a directive, " +"[option]`summary_interval`, to reduce the output and print only statistics, " +"as normally it will print a message every second or so. For example, to " +"reduce the output to every `1024` seconds, add the following line to the " +"`/etc/ptp4l.conf` file:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:381 +#, no-wrap +msgid "summary_interval 10\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:384 +msgid "" +"An example of the [application]*ptp4l* output, with " +"[option]`summary_interval 6`, follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:403 +#, no-wrap +msgid "" +"ptp4l: [615.253] selected /dev/ptp0 as PTP clock\n" +"ptp4l: [615.255] port 1: INITIALIZING to LISTENING on INITIALIZE\n" +"ptp4l: [615.255] port 0: INITIALIZING to LISTENING on INITIALIZE\n" +"ptp4l: [615.564] port 1: new foreign master 00a069.fffe.0b552d-1\n" +"ptp4l: [619.574] selected best master clock 00a069.fffe.0b552d\n" +"ptp4l: [619.574] port 1: LISTENING to UNCALIBRATED on RS_SLAVE\n" +"ptp4l: [623.573] port 1: UNCALIBRATED to SLAVE on MASTER_CLOCK_SELECTED\n" +"ptp4l: [684.649] rms 669 max 3691 freq -29383 ± 3735 delay 9232 ± 122\n" +"ptp4l: [748.724] rms 253 max 588 freq -29787 ± 221 delay 9219 ± 158\n" +"ptp4l: [812.793] rms 287 max 673 freq -29802 ± 248 delay 9211 ± 183\n" +"ptp4l: [876.853] rms 226 max 534 freq -29795 ± 197 delay 9221 ± 138\n" +"ptp4l: [940.925] rms 250 max 562 freq -29801 ± 218 delay 9199 ± 148\n" +"ptp4l: [1004.988] rms 226 max 525 freq -29802 ± 196 delay 9228 ± 143\n" +"ptp4l: [1069.065] rms 300 max 646 freq -29802 ± 259 delay 9214 ± 176\n" +"ptp4l: [1133.125] rms 226 max 505 freq -29792 ± 197 delay 9225 ± 159\n" +"ptp4l: [1197.185] rms 244 max 688 freq -29790 ± 211 delay 9201 ± 162\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:407 +msgid "" +"To reduce the output from the [application]*phc2sys*, it can be called it " +"with the [option]`-u` option as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:411 +#, no-wrap +msgid "~]#{nbsp}phc2sys -u summary-updates\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:414 +msgid "" +"Where _summary-updates_ is the number of clock updates to include in summary " +"statistics. An example follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:426 +#, no-wrap +msgid "" +"~]#{nbsp}phc2sys -s em3 -w -m -u 60\n" +"phc2sys[700.948]: rms 1837 max 10123 freq -36474 ± 4752 delay 2752 ± 16\n" +"phc2sys[760.954]: rms 194 max 457 freq -37084 ± 174 delay 2753 ± 12\n" +"phc2sys[820.963]: rms 211 max 487 freq -37085 ± 185 delay 2750 ± 19\n" +"phc2sys[880.968]: rms 183 max 440 freq -37102 ± 164 delay 2734 ± 91\n" +"phc2sys[940.973]: rms 244 max 584 freq -37095 ± 216 delay 2748 ± 16\n" +"phc2sys[1000.979]: rms 220 max 573 freq -36666 ± 182 delay 2747 ± 43\n" +"phc2sys[1060.984]: rms 266 max 675 freq -36759 ± 234 delay 2753 ± 17\n" +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:430 +#, no-wrap +msgid "Serving PTP Time with NTP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:433 +msgid "" +"The `ntpd` daemon can be configured to distribute the time from the system " +"clock synchronized by [application]*ptp4l* or [application]*phc2sys* by " +"using the LOCAL reference clock driver. To prevent `ntpd` from adjusting the " +"system clock, the `ntp.conf` file must not specify any `NTP` servers. The " +"following is a minimal example of `ntp.conf`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:440 +#, no-wrap +msgid "" +"~]#{nbsp}cat /etc/ntp.conf\n" +"server 127.127.1.0\n" +"fudge 127.127.1.0 stratum 0\n" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:446 +msgid "" +"When the `DHCP` client program, [application]*dhclient*, receives a list of " +"`NTP` servers from the `DHCP` server, it adds them to `ntp.conf` and " +"restarts the service. To disable that feature, add [command]#PEERNTP=no# to " +"`/etc/sysconfig/network`." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:450 +#, no-wrap +msgid "Serving NTP Time with PTP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:453 +msgid "" +"`NTP` to `PTP` synchronization in the opposite direction is also " +"possible. When `ntpd` is used to synchronize the system clock, " +"[application]*ptp4l* can be configured with the [option]`priority1` option " +"(or other clock options included in the best master clock algorithm) to be " +"the grandmaster clock and distribute the time from the system clock via " +"`PTP`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:461 +#, no-wrap +msgid "" +"~]#{nbsp}cat /etc/ptp4l.conf\n" +"[global]\n" +"priority1 127\n" +"[em3]\n" +"# ptp4l -f /etc/ptp4l.conf\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:465 +msgid "" +"With hardware time stamping, [application]*phc2sys* needs to be used to " +"synchronize the `PTP` hardware clock to the system clock. If running " +"[application]*phc2sys* as a service, edit the `/etc/sysconfig/phc2sys` " +"configuration file. The default setting in the `/etc/sysconfig/phc2sys` file " +"is as follows:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:472 +msgid "As `root`, edit that line as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:476 +#, no-wrap +msgid "" +"~]# vi /etc/sysconfig/phc2sys\n" +"OPTIONS=\"-a -r -r\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:480 +msgid "" +"The [option]`-r` option is used twice here to allow synchronization of the " +"`PTP` hardware clock on the NIC from the system clock. Restart the " +"[application]*phc2sys* service for the changes to take effect:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:486 +msgid "" +"To prevent quick changes in the `PTP` clock's frequency, the synchronization " +"to the system clock can be loosened by using smaller [option]`P` " +"(proportional) and [option]`I` (integral) constants for the PI servo:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:490 +#, no-wrap +msgid "~]#{nbsp}phc2sys -a -r -r -P 0.01 -I 0.0001\n" +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:493 +#, no-wrap +msgid "Synchronize to PTP or NTP Time Using timemaster" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:496 +msgid "" +"When there are multiple `PTP` domains available on the network, or fallback " +"to `NTP` is needed, the [application]*timemaster* program can be used to " +"synchronize the system clock to all available time sources. The `PTP` time " +"is provided by [application]*phc2sys* and [application]*ptp4l* via _shared " +"memory driver_ (*SHM* reference clocks to `chronyd` or `ntpd` (depending on " +"the `NTP` daemon that has been configured on the system). The `NTP` daemon " +"can then compare all time sources, both `PTP` and `NTP`, and use the best " +"sources to synchronize the system clock." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:498 +msgid "" +"On start, [application]*timemaster* reads a configuration file that " +"specifies the `NTP` and `PTP` time sources, checks which network interfaces " +"have their own or share a `PTP` hardware clock (PHC), generates " +"configuration files for [application]*ptp4l* and `chronyd` or `ntpd`, and " +"starts the [application]*ptp4l*, [application]*phc2sys*, and `chronyd` or " +"`ntpd` processes as needed. It will remove the generated configuration files " +"on exit. It writes configuration files for `chronyd`, `ntpd`, and " +"[application]*ptp4l* to `/var/run/timemaster/`." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:500 +#, no-wrap +msgid "Starting timemaster as a Service" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:503 +msgid "" +"To start [application]*timemaster* as a service, issue the following command " +"as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:507 +#, no-wrap +msgid "~]#{nbsp}systemctl start timemaster\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:510 +msgid "This will read the options in `/etc/timemaster.conf`." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:512 +#, no-wrap +msgid "Understanding the timemaster Configuration File" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:515 +msgid "" +"{MAJOROS} provides a default `/etc/timemaster.conf` file with a number of " +"sections containing default options. The section headings are enclosed in " +"brackets." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:517 +msgid "To view the default configuration, issue a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:521 +#, no-wrap +msgid "" +"~]$ less /etc/timemaster.conf\n" +"# Configuration file for timemaster\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:525 +#, no-wrap +msgid "" +"#[ntp_server ntp-server.local]\n" +"#minpoll 4\n" +"#maxpoll 4\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:528 +#, no-wrap +msgid "" +"#[ptp_domain 0]\n" +"#interfaces eth0\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:531 +#, no-wrap +msgid "" +"[timemaster]\n" +"ntp_program chronyd\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:534 +#, no-wrap +msgid "" +"[chrony.conf]\n" +"include /etc/chrony.conf\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:537 +#, no-wrap +msgid "" +"[ntp.conf]\n" +"includefile /etc/ntp.conf\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:539 +#, no-wrap +msgid "[ptp4l.conf]\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:543 +#, no-wrap +msgid "" +"[chronyd]\n" +"path /usr/sbin/chronyd\n" +"options -u chrony\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:547 +#, no-wrap +msgid "" +"[ntpd]\n" +"path /usr/sbin/ntpd\n" +"options -u ntp:ntp -g\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:550 +#, no-wrap +msgid "" +"[phc2sys]\n" +"path /usr/sbin/phc2sys\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:553 +#, no-wrap +msgid "" +"[ptp4l]\n" +"path /usr/sbin/ptp4l\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:556 +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:565 +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:576 +msgid "Notice the section named as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:560 +#, no-wrap +msgid "[ntp_server pass:quotes[_address_]]\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:563 +msgid "" +"This is an example of an `NTP` server section, \"`ntp-server.local`\" is an " +"example of a host name for an `NTP` server on the local LAN. Add more " +"sections as required using a host name or `IP` address as part of the " +"section name. Note that the short polling values in that example section are " +"not suitable for a public server, see " +"xref:servers/Configuring_NTP_Using_ntpd.adoc#ch-Configuring_NTP_Using_ntpd[Configuring " +"NTP Using ntpd] for an explanation of suitable [option]`minpoll` and " +"[option]`maxpoll` values." +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:569 +#, no-wrap +msgid "[ptp_domain pass:quotes[_number_]]\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:572 +msgid "" +"A \"`PTP domain`\" is a group of one or more `PTP` clocks that synchronize " +"to each other. They may or may not be synchronized to clocks in another " +"domain. Clocks that are configured with the same domain number make up the " +"domain. This includes a `PTP` grandmaster clock. The domain number in each " +"\"`PTP domain`\" section needs to correspond to one of the `PTP` domains " +"configured on the network." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:574 +msgid "" +"An instance of [application]*ptp4l* is started for every interface which has " +"its own `PTP` clock and hardware time stamping is enabled " +"automatically. Interfaces that support hardware time stamping have a `PTP` " +"clock (PHC) attached, however it is possible for a group of interfaces on a " +"NIC to share a PHC. A separate [application]*ptp4l* instance will be started " +"for each group of interfaces sharing the same PHC and for each interface " +"that supports only software time stamping. All [application]*ptp4l* " +"instances are configured to run as a slave. If an interface with hardware " +"time stamping is specified in more than one `PTP` domain, then only the " +"first [application]*ptp4l* instance created will have hardware time stamping " +"enabled." +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:580 +#, no-wrap +msgid "[timemaster]\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:583 +msgid "" +"The default [application]*timemaster* configuration includes the system " +"`ntpd` and chrony configuration (`/etc/ntp.conf` or `/etc/chronyd.conf`) in " +"order to include the configuration of access restrictions and authentication " +"keys. That means any `NTP` servers specified there will be used with " +"[application]*timemaster* too." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:585 +msgid "The section headings are as follows:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:587 +msgid "" +"[option]`[ntp_server ntp-server.local]` — Specify polling intervals for this " +"server. Create additional sections as required. Include the host name or " +"`IP` address in the section heading." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:589 +msgid "" +"[option]`[ptp_domain 0]` — Specify interfaces that have `PTP` clocks " +"configured for this domain. Create additional sections with, the appropriate " +"domain number, as required." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:591 +msgid "" +"[option]`[timemaster]` — Specify the `NTP` daemon to be used. Possible " +"values are `chronyd` and `ntpd`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:593 +msgid "" +"[option]`[chrony.conf]` — Specify any additional settings to be copied to " +"the configuration file generated for `chronyd`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:595 +msgid "" +"[option]`[ntp.conf]` — Specify any additional settings to be copied to the " +"configuration file generated for `ntpd`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:597 +msgid "" +"[option]`[ptp4l.conf]` — Specify options to be copied to the configuration " +"file generated for [application]*ptp4l*." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:599 +msgid "" +"[option]`[chronyd]` — Specify any additional settings to be passed on the " +"command line to `chronyd`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:601 +msgid "" +"[option]`[ntpd]` — Specify any additional settings to be passed on the " +"command line to `ntpd`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:603 +msgid "" +"[option]`[phc2sys]` — Specify any additional settings to be passed on the " +"command line to [application]*phc2sys*." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:605 +msgid "" +"[option]`[ptp4l]` — Specify any additional settings to be passed on the " +"command line to all instances of [application]*ptp4l*." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:607 +msgid "" +"The section headings and there contents are explained in detail in the " +"`timemaster(8)` manual page." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:609 +#, no-wrap +msgid "Configuring timemaster Options" +msgstr "" + +#. type: Block title +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:612 +#, no-wrap +msgid "Editing the timemaster Configuration File" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:614 +msgid "" +"To change the default configuration, open the `/etc/timemaster.conf` file " +"for editing as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:617 +#, no-wrap +msgid "~]# vi /etc/timemaster.conf\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:620 +msgid "" +"For each `NTP` server you want to control using [application]*timemaster*, " +"create `[ntp_server _address_pass:attributes[{blank}]]` sections . Note that " +"the short polling values in the example section are not suitable for a " +"public server, see " +"xref:servers/Configuring_NTP_Using_ntpd.adoc#ch-Configuring_NTP_Using_ntpd[Configuring " +"NTP Using ntpd] for an explanation of suitable [option]`minpoll` and " +"[option]`maxpoll` values." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:622 +msgid "" +"To add interfaces that should be used in a domain, edit the `#[ptp_domain " +"0]` section and add the interfaces. Create additional domains as " +"required. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:626 +#, no-wrap +msgid "" +"[ptp_domain 0]\n" +" interfaces eth0\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:629 +#, no-wrap +msgid "" +" [ptp_domain 1]\n" +" interfaces eth1\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:632 +msgid "" +"If required to use `ntpd` as the `NTP` daemon on this system, change the " +"default entry in the `[timemaster]` section from `chronyd` to `ntpd`. See " +"xref:servers/Configuring_NTP_Using_the_chrony_Suite.adoc#ch-Configuring_NTP_Using_the_chrony_Suite[Configuring " +"NTP Using the chrony Suite] for information on the differences between ntpd " +"and chronyd." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:634 +msgid "" +"If using `chronyd` as the `NTP` server on this system, add any additional " +"options below the default [option]`include /etc/chrony.conf` entry in the " +"`[chrony.conf]` section. Edit the default [option]`include` entry if the " +"path to `/etc/chrony.conf` is known to have changed." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:636 +msgid "" +"If using `ntpd` as the `NTP` server on this system, add any additional " +"options below the default [option]`include /etc/ntp.conf` entry in the " +"`[ntp.conf]` section. Edit the default [option]`include` entry if the path " +"to `/etc/ntp.conf` is known to have changed." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:638 +msgid "" +"In the `[ptp4l.conf]` section, add any options to be copied to the " +"configuration file generated for [application]*ptp4l*. This chapter " +"documents common options and more information is available in the `ptp4l(8)` " +"manual page." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:640 +msgid "" +"In the `[chronyd]` section, add any command line options to be passed to " +"`chronyd` when called by [application]*timemaster*. See " +"xref:servers/Configuring_NTP_Using_the_chrony_Suite.adoc#ch-Configuring_NTP_Using_the_chrony_Suite[Configuring " +"NTP Using the chrony Suite] for information on using `chronyd`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:642 +msgid "" +"In the `[ntpd]` section, add any command line options to be passed to `ntpd` " +"when called by [application]*timemaster*. See " +"xref:servers/Configuring_NTP_Using_ntpd.adoc#ch-Configuring_NTP_Using_ntpd[Configuring " +"NTP Using ntpd] for information on using `ntpd`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:644 +msgid "" +"In the `[phc2sys]` section, add any command line options to be passed to " +"[application]*phc2sys* when called by [application]*timemaster*. This " +"chapter documents common options and more information is available in the " +"`phy2sys(8)` manual page." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:646 +msgid "" +"In the `[ptp4l]` section, add any command line options to be passed to " +"[application]*ptp4l* when called by [application]*timemaster*. This chapter " +"documents common options and more information is available in the `ptp4l(8)` " +"manual page." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:648 +msgid "" +"Save the configuration file and restart [application]*timemaster* by issuing " +"the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:651 +#, no-wrap +msgid "~]# systemctl restart timemaster\n" +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:654 +#, no-wrap +msgid "Improving Accuracy" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:657 +msgid "" +"Previously, test results indicated that disabling the tickless kernel " +"capability could significantly improve the stability of the system clock, " +"and thus improve the `PTP` synchronization accuracy (at the cost of " +"increased power consumption). The kernel tickless mode can be disabled by " +"adding [option]`nohz=off` to the kernel boot option parameters. However, " +"recent improvements applied to `kernel-3.10.0-197.fc21` have greatly " +"improved the stability of the system clock and the difference in stability " +"of the clock with and without [option]`nohz=off` should be much smaller now " +"for most users." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:659 +msgid "" +"The [application]*ptp4l* and [application]*phc2sys* applications can be " +"configured to use a new adaptive servo. The advantage over the PI servo is " +"that it does not require configuration of the PI constants to perform " +"well. To make use of this for [application]*ptp4l*, add the following line " +"to the `/etc/ptp4l.conf` file:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:662 +#, no-wrap +msgid "clock_servo linreg\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:665 +msgid "" +"After making changes to `/etc/ptp4l.conf`, restart the [application]*ptp4l* " +"service from the command line by issuing the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:668 +#, no-wrap +msgid "~]# systemctl restart ptp4l\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:671 +msgid "" +"To make use of this for [application]*phc2sys*, add the following line to " +"the `/etc/sysconfig/phc2sys` file:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:675 +#, no-wrap +msgid "-E linreg\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:678 +msgid "" +"After making changes to `/etc/sysconfig/phc2sys`, restart the " +"[application]*phc2sys* service from the command line by issuing the " +"following command as `root`:" +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:684 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:687 +msgid "" +"The following sources of information provide additional resources regarding " +"`PTP` and the [application]*ptp4l* tools." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:689 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:692 +msgid "" +"`ptp4l(8)` man page — Describes [application]*ptp4l* options including the " +"format of the configuration file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:694 +msgid "" +"`pmc(8)` man page — Describes the `PTP` management client and its command " +"options." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:696 +msgid "" +"`phc2sys(8)` man page — Describes a tool for synchronizing the system clock " +"to a `PTP` hardware clock (PHC)." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:698 +msgid "" +"`timemaster(8)` man page — Describes a program that uses " +"[application]*ptp4l* and [application]*phc2sys* to synchronize the system " +"clock using `chronyd` or `ntpd`." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:700 +#, no-wrap +msgid "Useful Websites" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:702 +#, no-wrap +msgid "link:++http://linuxptp.sourceforge.net/++[]" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:703 +msgid "The Linux PTP project." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:704 +#, no-wrap +msgid "link:++https://www.nist.gov/el/isd/ieee/ieee1588.cfm++[]" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:704 +msgid "The IEEE 1588 Standard." +msgstr "" diff --git a/po/fr/rawhide/pages/servers/Directory_Servers.po b/po/fr/rawhide/pages/servers/Directory_Servers.po new file mode 100644 index 00000000000..68c322f05a5 --- /dev/null +++ b/po/fr/rawhide/pages/servers/Directory_Servers.po @@ -0,0 +1,23 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/servers/Directory_Servers.adoc:6 +#, no-wrap +msgid "Directory Servers" +msgstr "" diff --git a/po/fr/rawhide/pages/servers/File_and_Print_Servers.po b/po/fr/rawhide/pages/servers/File_and_Print_Servers.po new file mode 100644 index 00000000000..fca6aa978c4 --- /dev/null +++ b/po/fr/rawhide/pages/servers/File_and_Print_Servers.po @@ -0,0 +1,34 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/servers/File_and_Print_Servers.adoc:6 +#, no-wrap +msgid "File and Print Servers" +msgstr "" + +#. type: Plain text +#: ./pages/servers/File_and_Print_Servers.adoc:9 +msgid "" +"This chapter guides you through the installation and configuration of " +"[application]*Samba*, an open source implementation of the _Server Message " +"Block_ (*SMB*) and _common Internet file system_ (`CIFS`) protocol, and " +"[application]*vsftpd*, the primary FTP server shipped with " +"{MAJOROS}. Additionally, it explains how to use the [application]*Printer* " +"tool to configure printers." +msgstr "" diff --git a/po/fr/rawhide/pages/servers/Mail_Servers.po b/po/fr/rawhide/pages/servers/Mail_Servers.po new file mode 100644 index 00000000000..20f9350deb4 --- /dev/null +++ b/po/fr/rawhide/pages/servers/Mail_Servers.po @@ -0,0 +1,3359 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/servers/Mail_Servers.adoc:6 +#, no-wrap +msgid "Mail Servers" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:9 +msgid "" +"{MAJOROS} offers many advanced applications to serve and access email. This " +"chapter describes modern email protocols in use today, and some of the " +"programs designed to send and receive email." +msgstr "" + +#. type: Title == +#: ./pages/servers/Mail_Servers.adoc:11 +#, no-wrap +msgid "Email Protocols" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:14 +msgid "" +"indexterm:[email,protocols] Today, email is delivered using a client/server " +"architecture. An email message is created using a mail client program. This " +"program then sends the message to a server. The server then forwards the " +"message to the recipient's email server, where the message is then supplied " +"to the recipient's email client." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:16 +msgid "" +"To enable this process, a variety of standard network protocols allow " +"different machines, often running different operating systems and using " +"different email programs, to send and receive email." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:18 +msgid "" +"The following protocols discussed are the most commonly used in the transfer " +"of email." +msgstr "" + +#. type: Title === +#: ./pages/servers/Mail_Servers.adoc:20 +#, no-wrap +msgid "Mail Transport Protocols" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:23 +msgid "" +"Mail delivery from a client application to the server, and from an " +"originating server to the destination server, is handled by the _Simple Mail " +"Transfer Protocol_ (_SMTP_)." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:25 +#, no-wrap +msgid "SMTP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:28 +msgid "" +"indexterm:[email,protocols,SMTP] The primary purpose of SMTP is to transfer " +"email between mail servers. However, it is critical for email clients as " +"well. To send email, the client sends the message to an outgoing mail " +"server, which in turn contacts the destination mail server for delivery. For " +"this reason, it is necessary to specify an SMTP server when configuring an " +"email client." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:30 +msgid "" +"Under {MAJOROS}, a user can configure an SMTP server on the local machine to " +"handle mail delivery. However, it is also possible to configure remote SMTP " +"servers for outgoing mail." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:32 +msgid "" +"One important point to make about the SMTP protocol is that it does not " +"require authentication. This allows anyone on the Internet to send email to " +"anyone else or even to large groups of people. It is this characteristic of " +"SMTP that makes junk email or _spam_ possible. Imposing relay restrictions " +"limits random users on the Internet from sending email through your SMTP " +"server, to other servers on the internet. Servers that do not impose such " +"restrictions are called _open relay_ servers." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:34 +msgid "{MAJOROS} provides the Postfix and Sendmail SMTP programs." +msgstr "" + +#. type: Title === +#: ./pages/servers/Mail_Servers.adoc:36 +#, no-wrap +msgid "Mail Access Protocols" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:39 +msgid "" +"There are two primary protocols used by email client applications to " +"retrieve email from mail servers: the _Post Office Protocol_ (_POP_) and the " +"_Internet Message Access Protocol_ (_IMAP_)." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:41 +#, no-wrap +msgid "POP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:44 +msgid "" +"indexterm:[email,protocols,POP] The default POP server under {MAJOROS} is " +"[application]*Dovecot* and is provided by the [package]*dovecot* package." +msgstr "" + +#. type: Block title +#: ./pages/servers/Mail_Servers.adoc:45 +#, no-wrap +msgid "Installing the dovecot package" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:50 +msgid "" +"In order to use [application]*Dovecot*, first ensure the [package]*dovecot* " +"package is installed on your system by running, as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:54 +#, no-wrap +msgid "~]#{nbsp}dnf install dovecot\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:57 ./pages/servers/Mail_Servers.adoc:343 +#: ./pages/servers/Mail_Servers.adoc:565 ./pages/servers/Mail_Servers.adoc:951 +#: ./pages/servers/Mail_Servers.adoc:1076 +msgid "" +"For more information on installing packages with DNF, see " +"xref:package-management/DNF.adoc#sec-Installing[Installing Packages]." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:61 +msgid "" +"When using a `POP` server, email messages are downloaded by email client " +"applications. By default, most `POP` email clients are automatically " +"configured to delete the message on the email server after it has been " +"successfully transferred, however this setting usually can be changed." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:63 +msgid "" +"`POP` is fully compatible with important Internet messaging standards, such " +"as _Multipurpose Internet Mail Extensions_ (_MIME_), which allow for email " +"attachments." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:65 +msgid "" +"`POP` works best for users who have one system on which to read email. It " +"also works well for users who do not have a persistent connection to the " +"Internet or the network containing the mail server. Unfortunately for those " +"with slow network connections, `POP` requires client programs upon " +"authentication to download the entire content of each message. This can take " +"a long time if any messages have large attachments." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:67 +msgid "The most current version of the standard `POP` protocol is `POP3`." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:69 +msgid "There are, however, a variety of lesser-used `POP` protocol variants:" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:71 +#, no-wrap +msgid "" +"*APOP* — `POP3` with `MD5` authentication. An encoded hash of the user's " +"password is sent from the email client to the server rather than sending an " +"unencrypted password.\n" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:73 +#, no-wrap +msgid "*KPOP* — `POP3` with Kerberos authentication.\n" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:75 +#, no-wrap +msgid "" +"*RPOP* — `POP3` with `RPOP` authentication. This uses a per-user ID, similar " +"to a password, to authenticate POP requests. However, this ID is not " +"encrypted, so `RPOP` is no more secure than standard `POP`.\n" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:77 +msgid "" +"For added security, it is possible to use _Secure Socket Layer_ (_SSL_) " +"encryption for client authentication and data transfer sessions. This can be " +"enabled by using the [command]#pop3s# service, or by using the " +"[command]#stunnel# application. For more information on securing email " +"communication, see xref:Mail_Servers.adoc#s2-email-security[Securing " +"Communication]." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:79 +#, no-wrap +msgid "IMAP" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:82 +msgid "" +"indexterm:[email,protocols,IMAP] The default `IMAP` server under {MAJOROS} " +"is [application]*Dovecot* and is provided by the [package]*dovecot* " +"package. See xref:Mail_Servers.adoc#s3-email-protocols-pop[POP] for " +"information on how to install [application]*Dovecot*." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:84 +msgid "" +"When using an `IMAP` mail server, email messages remain on the server where " +"users can read or delete them. `IMAP` also allows client applications to " +"create, rename, or delete mail directories on the server to organize and " +"store email." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:86 +msgid "" +"`IMAP` is particularly useful for users who access their email using " +"multiple machines. The protocol is also convenient for users connecting to " +"the mail server via a slow connection, because only the email header " +"information is downloaded for messages until opened, saving bandwidth. The " +"user also has the ability to delete messages without viewing or downloading " +"them." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:88 +msgid "" +"For convenience, `IMAP` client applications are capable of caching copies of " +"messages locally, so the user can browse previously read messages when not " +"directly connected to the `IMAP` server." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:90 +msgid "" +"`IMAP`, like `POP`, is fully compatible with important Internet messaging " +"standards, such as MIME, which allow for email attachments." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:92 +msgid "" +"For added security, it is possible to use `SSL` encryption for client " +"authentication and data transfer sessions. This can be enabled by using the " +"[command]#imaps# service, or by using the [command]#stunnel# program. For " +"more information on securing email communication, see " +"xref:Mail_Servers.adoc#s2-email-security[Securing Communication]." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:94 +msgid "" +"Other free, as well as commercial, IMAP clients and servers are available, " +"many of which extend the IMAP protocol and provide additional functionality." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:96 +#, no-wrap +msgid "Dovecot" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:99 +msgid "" +"indexterm:[email,mail server,Dovecot] The [command]#imap-login# and " +"[command]#pop3-login# processes which implement the `IMAP` and `POP3` " +"protocols are spawned by the master `dovecot` daemon included in the " +"[package]*dovecot* package. The use of `IMAP` and `POP` is configured " +"through the `/etc/dovecot/dovecot.conf` configuration file; by default " +"[command]#dovecot# runs `IMAP` and `POP3` together with their secure " +"versions using `SSL`. To configure [command]#dovecot# to use `POP`, complete " +"the following steps:" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:101 +msgid "" +"Edit the `/etc/dovecot/dovecot.conf` configuration file to make sure the " +"`protocols` variable is uncommented (remove the hash sign (`#`) at the " +"beginning of the line) and contains the `pop3` argument. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:105 +#, no-wrap +msgid "protocols = imap pop3 lmtp\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:108 +msgid "" +"When the `protocols` variable is left commented out, [command]#dovecot# will " +"use the default values as described above." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:110 +msgid "" +"Make the change operational for the current session by running the following " +"command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:114 ./pages/servers/Mail_Servers.adoc:145 +#: ./pages/servers/Mail_Servers.adoc:1058 +#, no-wrap +msgid "~]#{nbsp}systemctl restart dovecot\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:117 +msgid "Make the change operational after the next reboot by running the command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:122 +#, no-wrap +msgid "" +"~]#{nbsp}systemctl enable dovecot\n" +"ln -s '/usr/lib/systemd/system/dovecot' " +"'/etc/systemd/system/multi-user.target.wants/dovecot'\n" +msgstr "" + +#. type: Block title +#: ./pages/servers/Mail_Servers.adoc:124 +#, no-wrap +msgid "The dovecot service starts the POP3 server" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:129 +msgid "" +"Please note that [command]#dovecot# only reports that it started the `IMAP` " +"server, but also starts the `POP3` server." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:133 +msgid "" +"Unlike `SMTP`, both `IMAP` and `POP3` require connecting clients to " +"authenticate using a user name and password. By default, passwords for both " +"protocols are passed over the network unencrypted." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:135 +msgid "To configure `SSL` on [command]#dovecot#:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:137 +msgid "" +"Edit the `/etc/pki/dovecot/dovecot-openssl.cnf` configuration file as you " +"prefer. However, in a typical installation, this file does not require " +"modification." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:139 +msgid "" +"Rename, move or delete the files `/etc/pki/dovecot/certs/dovecot.pem` and " +"`/etc/pki/dovecot/private/dovecot.pem`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:141 +msgid "" +"Execute the `/usr/libexec/dovecot/mkcert.sh` script which creates the " +"[command]#dovecot# self signed certificates. These certificates are copied " +"in the `/etc/pki/dovecot/certs` and `/etc/pki/dovecot/private` " +"directories. To implement the changes, restart [command]#dovecot# by issuing " +"the following command as `root`:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:148 +msgid "" +"More details on [command]#dovecot# can be found online at " +"link:++https://www.dovecot.org++[https://www.dovecot.org]." +msgstr "" + +#. type: Title == +#: ./pages/servers/Mail_Servers.adoc:150 +#, no-wrap +msgid "Email Program Classifications" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:153 +msgid "" +"indexterm:[email,program classifications] In general, all email applications " +"fall into at least one of three classifications. Each classification plays a " +"specific role in the process of moving and managing email messages. While " +"most users are only aware of the specific email program they use to receive " +"and send messages, each one is important for ensuring that email arrives at " +"the correct destination." +msgstr "" + +#. type: Title === +#: ./pages/servers/Mail_Servers.adoc:155 +#, no-wrap +msgid "Mail Transport Agent" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:158 +msgid "" +"indexterm:[email,types,Mail Transport Agent]indexterm:[Mail Transport " +"Agent,email]indexterm:[MTA,Mail Transport Agent] A _Mail Transport Agent_ " +"(_MTA_) transports email messages between hosts using `SMTP`. A message may " +"involve several MTAs as it moves to its intended destination." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:160 +msgid "" +"While the delivery of messages between machines may seem rather " +"straightforward, the entire process of deciding if a particular MTA can or " +"should accept a message for delivery is quite complicated. In addition, due " +"to problems from spam, use of a particular MTA is usually restricted by the " +"MTA's configuration or the access configuration for the network on which the " +"MTA resides." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:162 +msgid "" +"Many modern email client programs can act as an MTA when sending " +"email. However, this action should not be confused with the role of a true " +"MTA. The sole reason email client programs are capable of sending email like " +"an MTA is because the host running the application does not have its own " +"MTA. This is particularly true for email client programs on non-UNIX-based " +"operating systems. However, these client programs only send outbound " +"messages to an MTA they are authorized to use and do not directly deliver " +"the message to the intended recipient's email server." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:164 +msgid "" +"Since {MAJOROS} offers two MTAs, _Postfix_ and _Sendmail_, email client " +"programs are often not required to act as an MTA. {MAJOROS} also includes a " +"special purpose MTA called _Fetchmail_." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:166 +msgid "" +"For more information on Postfix, Sendmail, and Fetchmail, see " +"xref:Mail_Servers.adoc#s1-email-mta[Mail Transport Agents]." +msgstr "" + +#. type: Title === +#: ./pages/servers/Mail_Servers.adoc:168 +#, no-wrap +msgid "Mail Delivery Agent" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:171 +msgid "" +"indexterm:[email,types,Mail Delivery Agent]indexterm:[Mail Delivery " +"Agent,email]indexterm:[MDA,Mail Delivery Agent] A _Mail Delivery Agent_ " +"(_MDA_) is invoked by the MTA to file incoming email in the proper user's " +"mailbox. In many cases, the MDA is actually a _Local Delivery Agent_ " +"(_LDA_), such as [command]#mail# or Procmail." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:173 +msgid "" +"Any program that actually handles a message for delivery to the point where " +"it can be read by an email client application can be considered an MDA. For " +"this reason, some MTAs (such as Sendmail and Postfix) can fill the role of " +"an MDA when they append new email messages to a local user's mail spool " +"file. In general, MDAs do not transport messages between systems nor do they " +"provide a user interface; MDAs distribute and sort messages on the local " +"machine for an email client application to access." +msgstr "" + +#. type: Title === +#: ./pages/servers/Mail_Servers.adoc:175 +#, no-wrap +msgid "Mail User Agent" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:178 +msgid "" +"indexterm:[email,types,Mail User Agent]indexterm:[Mail User " +"Agent,email]indexterm:[MUA,Mail User Agent] A _Mail User Agent_ (_MUA_) is " +"synonymous with an email client application. An MUA is a program that, at a " +"minimum, allows a user to read and compose email messages. Many MUAs are " +"capable of retrieving messages via the `POP` or `IMAP` protocols, setting up " +"mailboxes to store messages, and sending outbound messages to an MTA." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:180 +msgid "" +"MUAs may be graphical, such as [application]*Evolution*, or have simple " +"text-based interfaces, such as [application]*Mutt*." +msgstr "" + +#. type: Title == +#: ./pages/servers/Mail_Servers.adoc:182 +#, no-wrap +msgid "Mail Transport Agents" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:185 +msgid "" +"{MAJOROS} offers two primary MTAs: Postfix and Sendmail. Postfix is " +"configured as the default MTA and Sendmail is considered deprecated. If " +"required to switch the default MTA to Sendmail, you can either uninstall " +"Postfix or use the following command as `root` to switch to Sendmail:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:189 +#, no-wrap +msgid "~]#{nbsp}alternatives --config mta\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:192 +msgid "You can also use the following command to enable the desired service:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:196 +#, no-wrap +msgid "~]#{nbsp}systemctl enable service\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:199 +msgid "Similarly, to disable the service, type the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:203 +#, no-wrap +msgid "~]#{nbsp}systemctl disable service\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:206 +msgid "" +"For more information on how to manage system services in {MAJOROSVER}, see " +"xref:infrastructure-services/Services_and_Daemons.adoc#ch-Services_and_Daemons[Services " +"and Daemons]." +msgstr "" + +#. type: Title === +#: ./pages/servers/Mail_Servers.adoc:208 +#, no-wrap +msgid "Postfix" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:211 +msgid "" +"indexterm:[email,Postfix]indexterm:[Postfix] Originally developed at IBM by " +"security expert and programmer Wietse Venema, Postfix is a " +"Sendmail-compatible MTA that is designed to be secure, fast, and easy to " +"configure." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:213 +msgid "" +"To improve security, Postfix uses a modular design, where small processes " +"with limited privileges are launched by a _master_ daemon. The smaller, less " +"privileged processes perform very specific tasks related to the various " +"stages of mail delivery and run in a changed root environment to limit the " +"effects of attacks." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:215 +msgid "" +"Configuring Postfix to accept network connections from hosts other than the " +"local computer takes only a few minor changes in its configuration file. Yet " +"for those with more complex needs, Postfix provides a variety of " +"configuration options, as well as third party add-ons that make it a very " +"versatile and full-featured MTA." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:217 +msgid "" +"The configuration files for Postfix are human readable and support upward of " +"250 directives. Unlike Sendmail, no macro processing is required for changes " +"to take effect and the majority of the most commonly used options are " +"described in the heavily commented files." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:219 +#, no-wrap +msgid "The Default Postfix Installation" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:222 +msgid "" +"indexterm:[Postfix,default installation] The Postfix executable is " +"`postfix`. This daemon launches all related processes needed to handle mail " +"delivery." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:224 +msgid "" +"Postfix stores its configuration files in the `/etc/postfix/` directory. The " +"following is a list of the more commonly used files:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:226 +msgid "" +"`access` — Used for access control, this file specifies which hosts are " +"allowed to connect to Postfix." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:228 +msgid "" +"`main.cf` — The global Postfix configuration file. The majority of " +"configuration options are specified in this file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:230 +msgid "" +"`master.cf` — Specifies how Postfix interacts with various processes to " +"accomplish mail delivery." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:232 +msgid "`transport` — Maps email addresses to relay hosts." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:234 +msgid "" +"The `aliases` file can be found in the `/etc/` directory. This file is " +"shared between Postfix and Sendmail. It is a configurable list required by " +"the mail protocol that describes user ID aliases." +msgstr "" + +#. type: Block title +#: ./pages/servers/Mail_Servers.adoc:235 +#, no-wrap +msgid "Configuring Postfix as a server for other clients" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:240 +msgid "" +"The default `/etc/postfix/main.cf` file does not allow Postfix to accept " +"network connections from a host other than the local computer. For " +"instructions on configuring Postfix as a server for other clients, see " +"xref:Mail_Servers.adoc#s3-email-mta-postfix-conf[Basic Postfix " +"Configuration]." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:244 +msgid "" +"Restart the `postfix` service after changing any options in the " +"configuration files under the `/etc/postfix` directory in order for those " +"changes to take effect. To do so, run the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:248 +#, no-wrap +msgid "~]#{nbsp}systemctl restart postfix\n" +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:251 +#, no-wrap +msgid "Basic Postfix Configuration" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:254 +msgid "" +"By default, Postfix does not accept network connections from any host other " +"than the local host. Perform the following steps as `root` to enable mail " +"delivery for other hosts on the network:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:256 +msgid "" +"Edit the `/etc/postfix/main.cf` file with a text editor, such as " +"[command]#vi#." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:258 +msgid "" +"Uncomment the `mydomain` line by removing the hash sign (`#`), and replace " +"_domain.tld_ with the domain the mail server is servicing, such as " +"`example.com`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:260 +msgid "Uncomment the `myorigin = $mydomain` line." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:262 +msgid "" +"Uncomment the `myhostname` line, and replace _host.domain.tld_ with the host " +"name for the machine." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:264 +msgid "Uncomment the `mydestination = $myhostname, localhost.$mydomain` line." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:266 +msgid "" +"Uncomment the `mynetworks` line, and replace _168.100.189.0/28_ with a valid " +"network setting for hosts that can connect to the server." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:268 +msgid "Uncomment the `inet_interfaces = all` line." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:270 +msgid "Comment the `inet_interfaces = localhost` line." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:272 +msgid "Restart the `postfix` service." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:274 +msgid "Once these steps are complete, the host accepts outside emails for delivery." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:276 +msgid "" +"Postfix has a large assortment of configuration options. One of the best " +"ways to learn how to configure Postfix is to read the comments within the " +"`/etc/postfix/main.cf` configuration file. Additional resources including " +"information about Postfix configuration, SpamAssassin integration, or " +"detailed descriptions of the `/etc/postfix/main.cf` parameters are available " +"online at link:++http://www.postfix.org/++[http://www.postfix.org/]." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:278 +#, no-wrap +msgid "Using Postfix with LDAP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:281 +msgid "" +"Postfix can use an `LDAP` directory as a source for various lookup tables " +"(e.g.: `aliases`, `virtual`, `canonical`, etc.). This allows `LDAP` to store " +"hierarchical user information and Postfix to only be given the result of " +"`LDAP` queries when needed. By not storing this information locally, " +"administrators can easily maintain it." +msgstr "" + +#. type: Block title +#: ./pages/servers/Mail_Servers.adoc:283 +#, no-wrap +msgid "The /etc/aliases lookup example" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:286 +msgid "" +"The following is a basic example for using `LDAP` to look up the " +"`/etc/aliases` file. Make sure your `/etc/postfix/main.cf` file contains the " +"following:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:289 +#, no-wrap +msgid "alias_maps = hash:/etc/aliases, ldap:/etc/postfix/ldap-aliases.cf\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:292 +msgid "" +"Create a `/etc/postfix/ldap-aliases.cf` file if you do not have one already " +"and make sure it contains the following:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:297 +#, no-wrap +msgid "" +"server_host = pass:quotes[_ldap.example.com_]\n" +"search_base = dc=pass:quotes[_example_], dc=pass:quotes[_com_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:300 +msgid "" +"where `ldap.example.com`, `example`, and `com` are parameters that need to " +"be replaced with specification of an existing available `LDAP` server." +msgstr "" + +#. type: Block title +#: ./pages/servers/Mail_Servers.adoc:301 +#, no-wrap +msgid "The /etc/postfix/ldap-aliases.cf file" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:306 +msgid "" +"The `/etc/postfix/ldap-aliases.cf` file can specify various parameters, " +"including parameters that enable `LDAP` `SSL` and `STARTTLS`. For more " +"information, see the `ldap_table(5)` man page." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:310 ./pages/servers/Mail_Servers.adoc:547 +msgid "" +"For more information on `LDAP`, see " +"xref:servers/Directory_Servers.adoc#s1-OpenLDAP[OpenLDAP]." +msgstr "" + +#. type: Title === +#: ./pages/servers/Mail_Servers.adoc:312 +#, no-wrap +msgid "Sendmail" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:315 +msgid "" +"indexterm:[email,Sendmail]indexterm:[Sendmail] Sendmail's core purpose, like " +"other MTAs, is to safely transfer email among hosts, usually using the " +"`SMTP` protocol. Note that Sendmail is considered deprecated and users are " +"encouraged to use Postfix when possible. See " +"xref:Mail_Servers.adoc#s2-email-mta-postfix[Postfix] for more information." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:317 +#, no-wrap +msgid "Purpose and Limitations" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:320 +msgid "" +"indexterm:[Sendmail,purpose]indexterm:[Sendmail,limitations] It is important " +"to be aware of what Sendmail is and what it can do, as opposed to what it is " +"not. In these days of monolithic applications that fulfill multiple roles, " +"Sendmail may seem like the only application needed to run an email server " +"within an organization. Technically, this is true, as Sendmail can spool " +"mail to each users' directory and deliver outbound mail for users. However, " +"most users actually require much more than simple email delivery. Users " +"usually want to interact with their email using an MUA, that uses `POP` or " +"`IMAP`, to download their messages to their local machine. Or, they may " +"prefer a Web interface to gain access to their mailbox. These other " +"applications can work in conjunction with Sendmail, but they actually exist " +"for different reasons and can operate separately from one another." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:322 +msgid "" +"It is beyond the scope of this section to go into all that Sendmail should " +"or could be configured to do. With literally hundreds of different options " +"and rule sets, entire volumes have been dedicated to helping explain " +"everything that can be done and how to fix things that go wrong. See the " +"xref:Mail_Servers.adoc#s1-email-additional-resources[Additional Resources] " +"for a list of Sendmail resources." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:324 +msgid "" +"This section reviews the files installed with Sendmail by default and " +"reviews basic configuration changes, including how to stop unwanted email " +"(spam) and how to extend Sendmail with the _Lightweight Directory Access " +"Protocol (LDAP)_." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:326 +#, no-wrap +msgid "The Default Sendmail Installation" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:329 +msgid "" +"indexterm:[Sendmail,default installation] In order to use Sendmail, first " +"ensure the [package]*sendmail* package is installed on your system by " +"running, as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:333 +#, no-wrap +msgid "~]#{nbsp}dnf install sendmail\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:336 +msgid "" +"In order to configure Sendmail, ensure the [package]*sendmail-cf* package is " +"installed on your system by running, as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:340 +#, no-wrap +msgid "~]#{nbsp}dnf install sendmail-cf\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:345 +msgid "" +"Before using Sendmail, the default MTA has to be switched from Postfix. For " +"more information how to switch the default MTA refer to " +"xref:Mail_Servers.adoc#s1-email-mta[Mail Transport Agents]." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:347 +msgid "The Sendmail executable is `sendmail`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:349 +msgid "" +"Sendmail's lengthy and detailed configuration file is " +"`/etc/mail/sendmail.cf`. Avoid editing the `sendmail.cf` file directly. To " +"make configuration changes to Sendmail, edit the `/etc/mail/sendmail.mc` " +"file, back up the original `/etc/mail/sendmail.cf` file, and use the " +"following alternatives to generate a new configuration file:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:351 +msgid "" +"Use the included makefile in `/etc/mail/` to create a new " +"`/etc/mail/sendmail.cf` configuration file:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:355 +#, no-wrap +msgid "~]#{nbsp}make all -C /etc/mail/\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:358 +msgid "" +"All other generated files in `/etc/mail` (db files) will be regenerated if " +"needed. The old makemap commands are still usable. The make command is " +"automatically used whenever you start or restart the `sendmail` service." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:360 +msgid "" +"More information on configuring Sendmail can be found in " +"xref:Mail_Servers.adoc#s3-email-mta-sendmail-changes[Common Sendmail " +"Configuration Changes]." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:362 +msgid "" +"Various Sendmail configuration files are installed in the `/etc/mail/` " +"directory including:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:364 +msgid "`access` — Specifies which systems can use Sendmail for outbound email." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:366 +msgid "`domaintable` — Specifies domain name mapping." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:368 +msgid "`local-host-names` — Specifies aliases for the host." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:370 +msgid "" +"`mailertable` — Specifies instructions that override routing for particular " +"domains." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:372 +msgid "" +"`virtusertable` — Specifies a domain-specific form of aliasing, allowing " +"multiple virtual domains to be hosted on one machine." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:374 +msgid "" +"Several of the configuration files in the `/etc/mail/` directory, such as " +"`access`, `domaintable`, `mailertable` and `virtusertable`, must actually " +"store their information in database files before Sendmail can use any " +"configuration changes. To include any changes made to these configurations " +"in their database files, run the following commands, as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:379 +#, no-wrap +msgid "" +"~]#{nbsp}cd /etc/mail/\n" +"~]#{nbsp}make all\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:382 +msgid "" +"This will update `virtusertable.db`, `access.db`, `domaintable.db`, " +"`mailertable.db`, `sendmail.cf`, and `submit.cf`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:384 +msgid "" +"To update all the database files listed above and to update a custom " +"database file, use a command in the following format:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:388 +#, no-wrap +msgid "[command]#make _name.db_ all#\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:391 +msgid "where _name_ represents the name of the custom database file to be updated." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:393 +msgid "To update a single database, use a command in the following format:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:397 +#, no-wrap +msgid "[command]#make _name.db_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:400 +msgid "where _name.db_ represents the name of the database file to be updated." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:402 +msgid "" +"You may also restart the `sendmail` service for the changes to take effect " +"by running:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:406 ./pages/servers/Mail_Servers.adoc:443 +#: ./pages/servers/Mail_Servers.adoc:454 ./pages/servers/Mail_Servers.adoc:495 +#, no-wrap +msgid "~]#{nbsp}systemctl restart sendmail\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:409 +msgid "" +"For example, to have all emails addressed to the `example.com` domain " +"delivered to `bob@other-example.com`, add the following line to the " +"`virtusertable` file:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:414 +#, no-wrap +msgid "[command]#@example.com bob@other-example.com#\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:417 +msgid "To finalize the change, the `virtusertable.db` file must be updated:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:421 +#, no-wrap +msgid "~]#{nbsp}make virtusertable.db all\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:424 +msgid "" +"Using the [option]`all` option will result in the `virtusertable.db` and " +"`access.db` being updated at the same time." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:426 +#, no-wrap +msgid "Common Sendmail Configuration Changes" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:429 +msgid "" +"indexterm:[Sendmail,common configuration changes]indexterm:[Sendmail,with " +"UUCP] When altering the Sendmail configuration file, it is best not to edit " +"an existing file, but to generate an entirely new `/etc/mail/sendmail.cf` " +"file." +msgstr "" + +#. type: Block title +#: ./pages/servers/Mail_Servers.adoc:430 +#, no-wrap +msgid "Backup the sendmail.cf file before changing its content" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:435 +msgid "" +"Before replacing or making any changes to the `sendmail.cf` file, create a " +"backup copy." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:439 +msgid "" +"To add the desired functionality to Sendmail, edit the " +"`/etc/mail/sendmail.mc` file as `root`. Once you are finished, restart the " +"`sendmail` service and, if the [package]*m4* package is installed, the " +"[command]#m4# macro processor will automatically generate a new " +"`sendmail.cf` configuration file:" +msgstr "" + +#. type: Block title +#: ./pages/servers/Mail_Servers.adoc:445 +#, no-wrap +msgid "Configuring Sendmail as a server for other clients" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:450 +msgid "" +"The default `sendmail.cf` file does not allow Sendmail to accept network " +"connections from any host other than the local computer. To configure " +"Sendmail as a server for other clients, edit the `/etc/mail/sendmail.mc` " +"file, and either change the address specified in the [command]#Addr=# option " +"of the [command]#DAEMON_OPTIONS# directive from [command]#127.0.0.1# to the " +"IP address of an active network device or comment out the " +"[command]#DAEMON_OPTIONS# directive all together by placing [command]#dnl# " +"at the beginning of the line. When finished, regenerate " +"`/etc/mail/sendmail.cf` by restarting the service:" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:459 +msgid "" +"The default configuration in {MAJOROS} works for most `SMTP`-only " +"sites. However, it does not work for _UUCP_ (_UNIX-to-UNIX Copy Protocol_) " +"sites. If using UUCP mail transfers, the `/etc/mail/sendmail.mc` file must " +"be reconfigured and a new `/etc/mail/sendmail.cf` file must be generated." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:461 +msgid "" +"Consult the `/usr/share/sendmail-cf/README` file before editing any files in " +"the directories under the `/usr/share/sendmail-cf/` directory, as they can " +"affect the future configuration of the `/etc/mail/sendmail.cf` file." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:463 +#, no-wrap +msgid "Masquerading" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:466 +msgid "" +"indexterm:[Sendmail,aliases]indexterm:[Sendmail,masquerading] One common " +"Sendmail configuration is to have a single machine act as a mail gateway for " +"all machines on the network. For example, a company may want to have a " +"machine called `mail.example.com` that handles all of their email and " +"assigns a consistent return address to all outgoing mail." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:468 +msgid "" +"In this situation, the Sendmail server must masquerade the machine names on " +"the company network so that their return address is `user@example.com` " +"instead of `user@host.example.com`." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:470 +msgid "To do this, add the following lines to `/etc/mail/sendmail.mc`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:479 +#, no-wrap +msgid "" +"FEATURE(always_add_domain)dnl\n" +"FEATURE(`masquerade_entire_domain')dnl\n" +"FEATURE(`masquerade_envelope')dnl\n" +"FEATURE(`allmasquerade')dnl\n" +"MASQUERADE_AS(`example.com.')dnl\n" +"MASQUERADE_DOMAIN(`example.com.')dnl\n" +"MASQUERADE_AS(example.com)dnl\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:482 +msgid "" +"After generating a new `sendmail.cf` file using the [command]#m4# macro " +"processor, this configuration makes all mail from inside the network appear " +"as if it were sent from `example.com`." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:484 +#, no-wrap +msgid "Stopping Spam" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:487 +msgid "" +"indexterm:[Sendmail,spam] Email spam can be defined as unnecessary and " +"unwanted email received by a user who never requested the communication. It " +"is a disruptive, costly, and widespread abuse of Internet communication " +"standards." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:489 +msgid "" +"Sendmail makes it relatively easy to block new spamming techniques being " +"employed to send junk email. It even blocks many of the more usual spamming " +"methods by default. Main anti-spam features available in sendmail are " +"_header checks_, _relaying denial_ (default from version 8.9), _access " +"database and sender information checks_." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:491 +msgid "" +"For example, forwarding of `SMTP` messages, also called relaying, has been " +"disabled by default since Sendmail version 8.9. Before this change occurred, " +"Sendmail directed the mail host (`x.edu`) to accept messages from one party " +"(`y.com`) and sent them to a different party (`z.net`). Now, however, " +"Sendmail must be configured to permit any domain to relay mail through the " +"server. To configure relay domains, edit the `/etc/mail/relay-domains` file " +"and restart Sendmail" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:498 +msgid "" +"However users can also be sent spam from from servers on the Internet. In " +"these instances, Sendmail's access control features available through the " +"`/etc/mail/access` file can be used to prevent connections from unwanted " +"hosts. The following example illustrates how this file can be used to both " +"block and specifically allow access to the Sendmail server:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:502 +#, no-wrap +msgid "" +"badspammer.com ERROR:550 \"Go away and do not spam us anymore\" " +"tux.badspammer.com OK 10.0 RELAY\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:505 +msgid "" +"This example shows that any email sent from `badspammer.com` is blocked with " +"a 550 RFC-821 compliant error code, with a message sent back. Email sent " +"from the `tux.badspammer.com` sub-domain, is accepted. The last line shows " +"that any email sent from the 10.0.*.* network can be relayed through the " +"mail server." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:507 +msgid "" +"Because the `/etc/mail/access.db` file is a database, use the " +"[command]#makemap# command to update any changes. Do this using the " +"following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:511 +#, no-wrap +msgid "~]#{nbsp}makemap hash /etc/mail/access < /etc/mail/access\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:514 +msgid "" +"Message header analysis allows you to reject mail based on header " +"contents. `SMTP` servers store information about an email's journey in the " +"message header. As the message travels from one MTA to another, each puts in " +"a `Received` header above all the other `Received` headers. It is important " +"to note that this information may be altered by spammers." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:516 +msgid "" +"The above examples only represent a small part of what Sendmail can do in " +"terms of allowing or blocking access. See the " +"`/usr/share/sendmail-cf/README` file for more information and examples." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:518 +msgid "" +"Since Sendmail calls the Procmail MDA when delivering mail, it is also " +"possible to use a spam filtering program, such as SpamAssassin, to identify " +"and file spam for users. See xref:Mail_Servers.adoc#s3-email-mda-spam[Spam " +"Filters] for more information about using SpamAssassin." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:520 +#, no-wrap +msgid "Using Sendmail with LDAP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:523 +msgid "" +"indexterm:[Sendmail,LDAP and] Using `LDAP` is a very quick and powerful way " +"to find specific information about a particular user from a much larger " +"group. For example, an `LDAP` server can be used to look up a particular " +"email address from a common corporate directory by the user's last name. In " +"this kind of implementation, `LDAP` is largely separate from Sendmail, with " +"`LDAP` storing the hierarchical user information and Sendmail only being " +"given the result of `LDAP` queries in pre-addressed email messages." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:525 +msgid "" +"However, Sendmail supports a much greater integration with `LDAP`, where it " +"uses `LDAP` to replace separately maintained files, such as `/etc/aliases` " +"and `/etc/mail/virtusertables`, on different mail servers that work together " +"to support a medium- to enterprise-level organization. In short, `LDAP` " +"abstracts the mail routing level from Sendmail and its separate " +"configuration files to a powerful `LDAP` cluster that can be leveraged by " +"many different applications." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:527 +msgid "" +"The current version of Sendmail contains support for `LDAP`. To extend the " +"Sendmail server using `LDAP`, first get an `LDAP` server, such as " +"[application]*OpenLDAP*, running and properly configured. Then edit the " +"`/etc/mail/sendmail.mc` to include the following:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:532 +#, no-wrap +msgid "" +"LDAPROUTE_DOMAIN('pass:quotes[_yourdomain.com_]')dnl\n" +"FEATURE('ldap_routing')dnl\n" +msgstr "" + +#. type: Block title +#: ./pages/servers/Mail_Servers.adoc:534 +#, no-wrap +msgid "Advanced configuration" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:539 +msgid "" +"This is only for a very basic configuration of Sendmail with `LDAP`. The " +"configuration can differ greatly from this depending on the implementation " +"of `LDAP`, especially when configuring several Sendmail machines to use a " +"common `LDAP` server." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:541 +msgid "" +"Consult `/usr/share/sendmail-cf/README` for detailed `LDAP` routing " +"configuration instructions and examples." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:545 +msgid "" +"Next, recreate the `/etc/mail/sendmail.cf` file by running the [command]#m4# " +"macro processor and again restarting Sendmail. See " +"xref:Mail_Servers.adoc#s3-email-mta-sendmail-changes[Common Sendmail " +"Configuration Changes] for instructions." +msgstr "" + +#. type: Title === +#: ./pages/servers/Mail_Servers.adoc:549 +#, no-wrap +msgid "Fetchmail" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:552 +msgid "" +"indexterm:[email,Fetchmail]indexterm:[Fetchmail] Fetchmail is an MTA which " +"retrieves email from remote servers and delivers it to the local MTA. Many " +"users appreciate the ability to separate the process of downloading their " +"messages located on a remote server from the process of reading and " +"organizing their email in an MUA. Designed with the needs of dial-up users " +"in mind, Fetchmail connects and quickly downloads all of the email messages " +"to the mail spool file using any number of protocols, including `POP3` and " +"`IMAP`. It can even forward email messages to an `SMTP` server, if " +"necessary." +msgstr "" + +#. type: Block title +#: ./pages/servers/Mail_Servers.adoc:553 +#, no-wrap +msgid "Installing the fetchmail package" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:558 +msgid "" +"In order to use [application]*Fetchmail*, first ensure the " +"[package]*fetchmail* package is installed on your system by running, as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:562 +#, no-wrap +msgid "~]#{nbsp}dnf install fetchmail\n" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:569 +msgid "" +"Fetchmail is configured for each user through the use of a `.fetchmailrc` " +"file in the user's home directory. If it does not already exist, create the " +"`.fetchmailrc` file in your home directory" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:571 +msgid "" +"Using preferences in the `.fetchmailrc` file, Fetchmail checks for email on " +"a remote server and downloads it. It then delivers it to port 25 on the " +"local machine, using the local MTA to place the email in the correct user's " +"spool file. If Procmail is available, it is launched to filter the email and " +"place it in a mailbox so that it can be read by an MUA." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:573 +#, no-wrap +msgid "Fetchmail Configuration Options" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:576 +msgid "" +"indexterm:[Fetchmail,configuration options]indexterm:[.fetchmailrc] Although " +"it is possible to pass all necessary options on the command line to check " +"for email on a remote server when executing Fetchmail, using a " +"`.fetchmailrc` file is much easier. Place any desired configuration options " +"in the `.fetchmailrc` file for those options to be used each time the " +"[command]#fetchmail# command is issued. It is possible to override these at " +"the time Fetchmail is run by specifying that option on the command line." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:578 +msgid "" +"A user's `.fetchmailrc` file contains three classes of configuration " +"options:" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:580 +#, no-wrap +msgid "" +"*global options* — Gives Fetchmail instructions that control the operation " +"of the program or provide settings for every connection that checks for " +"email.\n" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:582 +#, no-wrap +msgid "" +"*server options* — Specifies necessary information about the server being " +"polled, such as the host name, as well as preferences for specific email " +"servers, such as the port to check or number of seconds to wait before " +"timing out. These options affect every user using that server.\n" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:584 +#, no-wrap +msgid "" +"*user options* — Contains information, such as user name and password, " +"necessary to authenticate and check for email using a specified email " +"server.\n" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:586 +msgid "" +"Global options appear at the top of the `.fetchmailrc` file, followed by one " +"or more server options, each of which designate a different email server " +"that Fetchmail should check. User options follow server options for each " +"user account checking that email server. Like server options, multiple user " +"options may be specified for use with a particular server as well as to " +"check multiple email accounts on the same server." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:588 +msgid "" +"Server options are called into service in the `.fetchmailrc` file by the use " +"of a special option verb, [command]#poll# or [command]#skip#, that precedes " +"any of the server information. The [command]#poll# action tells Fetchmail to " +"use this server option when it is run, which checks for email using the " +"specified user options. Any server options after a [command]#skip# action, " +"however, are not checked unless this server's host name is specified when " +"Fetchmail is invoked. The [command]#skip# option is useful when testing " +"configurations in the `.fetchmailrc` file because it only checks skipped " +"servers when specifically invoked, and does not affect any currently working " +"configurations." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:590 +msgid "The following is an example of a `.fetchmailrc` file:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:595 +#, no-wrap +msgid "" +"set postmaster \"user1\"\n" +"set bouncemail\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:598 +#, no-wrap +msgid "" +"poll pop.domain.com proto pop3\n" +" user 'user1' there with password 'secret' is user1 here\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:602 +#, no-wrap +msgid "" +"poll mail.domain2.com\n" +" user 'user5' there with password 'secret2' is user1 here\n" +" user 'user7' there with password 'secret3' is user1 here\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:605 +msgid "" +"In this example, the global options specify that the user is sent email as a " +"last resort ([command]#postmaster# option) and all email errors are sent to " +"the postmaster instead of the sender ([command]#bouncemail# option). The " +"[command]#set# action tells Fetchmail that this line contains a global " +"option. Then, two email servers are specified, one set to check using " +"`POP3`, the other for trying various protocols to find one that works. Two " +"users are checked using the second server option, but all email found for " +"any user is sent to [command]#user1#pass:attributes[{blank}]'s mail " +"spool. This allows multiple mailboxes to be checked on multiple servers, " +"while appearing in a single MUA inbox. Each user's specific information " +"begins with the [command]#user# action." +msgstr "" + +#. type: Block title +#: ./pages/servers/Mail_Servers.adoc:606 +#, no-wrap +msgid "Omitting the password from the configuration" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:611 +msgid "" +"Users are not required to place their password in the `.fetchmailrc` " +"file. Omitting the [command]#with password " +"'pass:attributes[{blank}]_password_pass:attributes[{blank}]'# section causes " +"Fetchmail to ask for a password when it is launched." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:615 +msgid "" +"Fetchmail has numerous global, server, and local options. Many of these " +"options are rarely used or only apply to very specific situations. The " +"`fetchmail` man page explains each option in detail, but the most common " +"ones are listed in the following three sections." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:617 +#, no-wrap +msgid "Global Options" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:620 +msgid "" +"indexterm:[Fetchmail,configuration options,global " +"options]indexterm:[ch-email .fetchmailrc,global options] Each global option " +"should be placed on a single line after a [command]#set# action." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:622 +msgid "" +"[command]#daemon _seconds_pass:attributes[{blank}]# — Specifies daemon-mode, " +"where Fetchmail stays in the background. Replace _seconds_ with the number " +"of seconds Fetchmail is to wait before polling the server." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:624 +msgid "" +"[command]#postmaster# — Specifies a local user to send mail to in case of " +"delivery problems." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:626 +msgid "" +"[command]#syslog# — Specifies the log file for errors and status " +"messages. By default, this is `/var/log/maillog`." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:628 +#, no-wrap +msgid "Server Options" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:631 +msgid "" +"indexterm:[Fetchmail,configuration options,server " +"options]indexterm:[.fetchmailrc,server options] Server options must be " +"placed on their own line in `.fetchmailrc` after a [command]#poll# or " +"[command]#skip# action." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:633 +msgid "" +"[command]#auth _auth-type_pass:attributes[{blank}]# — Replace _auth-type_ " +"with the type of authentication to be used. By default, [command]#password# " +"authentication is used, but some protocols support other types of " +"authentication, including [command]#kerberos_v5#, [command]#kerberos_v4#, " +"and [command]#ssh#. If the [command]#any# authentication type is used, " +"Fetchmail first tries methods that do not require a password, then methods " +"that mask the password, and finally attempts to send the password " +"unencrypted to authenticate to the server." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:635 +msgid "" +"[command]#interval _number_pass:attributes[{blank}]# — Polls the specified " +"server every " +"[command]#pass:attributes[{blank}]_number_pass:attributes[{blank}]# of times " +"that it checks for email on all configured servers. This option is generally " +"used for email servers where the user rarely receives messages." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:637 +msgid "" +"[command]#port _port-number_pass:attributes[{blank}]# — Replace " +"_port-number_ with the port number. This value overrides the default port " +"number for the specified protocol." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:639 +msgid "" +"[command]#proto _protocol_pass:attributes[{blank}]# — Replace _protocol_ " +"with the protocol, such as [command]#pop3# or [command]#imap#, to use when " +"checking for messages on the server." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:641 +msgid "" +"[command]#timeout _seconds_pass:attributes[{blank}]# — Replace _seconds_ " +"with the number of seconds of server inactivity after which Fetchmail gives " +"up on a connection attempt. If this value is not set, a default of " +"[command]#300# seconds is used." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:643 +#, no-wrap +msgid "User Options" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:646 +msgid "" +"indexterm:[Fetchmail,configuration options,user " +"options]indexterm:[.fetchmailrc,user options] User options may be placed on " +"their own lines beneath a server option or on the same line as the server " +"option. In either case, the defined options must follow the [command]#user# " +"option (defined below)." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:648 +msgid "" +"[command]#fetchall# — Orders Fetchmail to download all messages in the " +"queue, including messages that have already been viewed. By default, " +"Fetchmail only pulls down new messages." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:650 +msgid "" +"[command]#fetchlimit _number_pass:attributes[{blank}]# — Replace _number_ " +"with the number of messages to be retrieved before stopping." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:652 +msgid "" +"[command]#flush# — Deletes all previously viewed messages in the queue " +"before retrieving new messages." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:654 +msgid "" +"[command]#limit _max-number-bytes_pass:attributes[{blank}]# — Replace " +"_max-number-bytes_ with the maximum size in bytes that messages are allowed " +"to be when retrieved by Fetchmail. This option is useful with slow network " +"links, when a large message takes too long to download." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:656 +msgid "" +"[command]#password " +"'pass:attributes[{blank}]_password_pass:attributes[{blank}]'# — Replace " +"_password_ with the user's password." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:658 +msgid "" +"[command]#preconnect " +"\"pass:attributes[{blank}]_command_pass:attributes[{blank}]\"# — Replace " +"_command_ with a command to be executed before retrieving messages for the " +"user." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:660 +msgid "" +"[command]#postconnect " +"\"pass:attributes[{blank}]_command_pass:attributes[{blank}]\"# — Replace " +"_command_ with a command to be executed after retrieving messages for the " +"user." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:662 +msgid "[command]#ssl# — Activates SSL encryption." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:664 +msgid "" +"[command]#user " +"\"pass:attributes[{blank}]_username_pass:attributes[{blank}]\"# — Replace " +"_username_ with the username used by Fetchmail to retrieve messages. *This " +"option must precede all other user options.*" +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:666 +#, no-wrap +msgid "Fetchmail Command Options" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:669 +msgid "" +"indexterm:[Fetchmail,command options] Most Fetchmail options used on the " +"command line when executing the [command]#fetchmail# command mirror the " +"`.fetchmailrc` configuration options. In this way, Fetchmail may be used " +"with or without a configuration file. These options are not used on the " +"command line by most users because it is easier to leave them in the " +"`.fetchmailrc` file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:671 +msgid "" +"There may be times when it is desirable to run the [command]#fetchmail# " +"command with other options for a particular purpose. It is possible to issue " +"command options to temporarily override a `.fetchmailrc` setting that is " +"causing an error, as any options specified at the command line override " +"configuration file options." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:673 +#, no-wrap +msgid "Informational or Debugging Options" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:676 +msgid "" +"indexterm:[Fetchmail,command options,informational] Certain options used " +"after the [command]#fetchmail# command can supply important information." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:678 +msgid "" +"[command]#--configdump# — Displays every possible option based on " +"information from `.fetchmailrc` and Fetchmail defaults. No email is " +"retrieved for any users when using this option." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:680 +msgid "" +"[command]#-s# — Executes Fetchmail in silent mode, preventing any messages, " +"other than errors, from appearing after the [command]#fetchmail# command." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:682 +msgid "" +"[command]#-v# — Executes Fetchmail in verbose mode, displaying every " +"communication between Fetchmail and remote email servers." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:684 +msgid "" +"[command]#-V# — Displays detailed version information, lists its global " +"options, and shows settings to be used with each user, including the email " +"protocol and authentication method. No email is retrieved for any users when " +"using this option." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:686 +#, no-wrap +msgid "Special Options" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:689 +msgid "" +"indexterm:[Fetchmail,command options,special] These options are occasionally " +"useful for overriding defaults often found in the `.fetchmailrc` file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:691 +msgid "" +"[command]#-a# — Fetchmail downloads all messages from the remote email " +"server, whether new or previously viewed. By default, Fetchmail only " +"downloads new messages." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:693 +msgid "" +"[command]#-k# — Fetchmail leaves the messages on the remote email server " +"after downloading them. This option overrides the default behavior of " +"deleting messages after downloading them." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:695 +msgid "" +"[command]#-l _max-number-bytes_pass:attributes[{blank}]# — Fetchmail does " +"not download any messages over a particular size and leaves them on the " +"remote email server." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:697 +msgid "[command]#--quit# — Quits the Fetchmail daemon process." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:699 +msgid "" +"More commands and `.fetchmailrc` options can be found in the " +"[command]#fetchmail# man page." +msgstr "" + +#. type: Title === +#: ./pages/servers/Mail_Servers.adoc:701 +#, no-wrap +msgid "Mail Transport Agent (MTA) Configuration" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:704 +msgid "" +"indexterm:[Mail Transport Agent,MTA]indexterm:[MTA,setting " +"default]indexterm:[MTA,switching with Mail Transport Agent " +"Switcher]indexterm:[Mail Transport Agent Switcher]indexterm:[Mail User " +"Agent]indexterm:[MUA] A _Mail Transport Agent_ (MTA) is essential for " +"sending email. A _Mail User Agent_ (MUA) such as [application]*Evolution*, " +"[application]*Thunderbird*, and [application]*Mutt*, is used to read and " +"compose email. When a user sends an email from an MUA, the message is handed " +"off to the MTA, which sends the message through a series of MTAs until it " +"reaches its destination." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:708 +msgid "" +"Even if a user does not plan to send email from the system, some automated " +"tasks or system programs might use the [command]#mail# command to send email " +"containing log messages to the `root` user of the local system. " +"indexterm:[sendmail]indexterm:[postfix] {MAJOROSVER} provides two MTAs: " +"Postfix and Sendmail. If both are installed, Postfix is the default " +"MTA. Note that Sendmail is considered deprecated in MAJOROS;." +msgstr "" + +#. type: Title == +#: ./pages/servers/Mail_Servers.adoc:710 +#, no-wrap +msgid "Mail Delivery Agents" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:713 +msgid "" +"{MAJOROS} includes two primary MDAs, Procmail and [command]#mail#. Both of " +"the applications are considered LDAs and both move email from the MTA's " +"spool file into the user's mailbox. However, Procmail provides a robust " +"filtering system." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:717 +msgid "" +"This section details only Procmail. For information on the [command]#mail# " +"command, consult its man page ([command]#man mail#). " +"indexterm:[email,Procmail]indexterm:[Procmail] Procmail delivers and filters " +"email as it is placed in the mail spool file of the localhost. It is " +"powerful, gentle on system resources, and widely used. Procmail can play a " +"critical role in delivering email to be read by email client applications." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:719 +msgid "" +"Procmail can be invoked in several different ways. Whenever an MTA places an " +"email into the mail spool file, Procmail is launched. Procmail then filters " +"and files the email for the MUA and quits. Alternatively, the MUA can be " +"configured to execute Procmail any time a message is received so that " +"messages are moved into their correct mailboxes. By default, the presence of " +"`/etc/procmailrc` or of a `~/.procmailrc` file (also called an _rc_ file) in " +"the user's home directory invokes Procmail whenever an MTA receives a new " +"message." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:721 +msgid "" +"By default, no system-wide `rc` files exist in the `/etc/` directory and no " +"`.procmailrc` files exist in any user's home directory. Therefore, to use " +"Procmail, each user must construct a `.procmailrc` file with specific " +"environment variables and rules." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:723 +msgid "" +"Whether Procmail acts upon an email message depends upon whether the message " +"matches a specified set of conditions or _recipes_ in the `rc` file. If a " +"message matches a recipe, then the email is placed in a specified file, is " +"deleted, or is otherwise processed." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:725 +msgid "" +"When Procmail starts, it reads the email message and separates the body from " +"the header information. Next, Procmail looks for a `/etc/procmailrc` file " +"and `rc` files in the `/etc/procmailrcs` directory for default, system-wide, " +"Procmail environmental variables and recipes. Procmail then searches for a " +"`.procmailrc` file in the user's home directory. Many users also create " +"additional `rc` files for Procmail that are referred to within the " +"`.procmailrc` file in their home directory." +msgstr "" + +#. type: Title === +#: ./pages/servers/Mail_Servers.adoc:727 +#, no-wrap +msgid "Procmail Configuration" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:730 +msgid "" +"indexterm:[Procmail,configuration]indexterm:[.procmailrc] The Procmail " +"configuration file contains important environmental variables. These " +"variables specify things such as which messages to sort and what to do with " +"the messages that do not match any recipes." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:732 +msgid "" +"These environmental variables usually appear at the beginning of the " +"`~/.procmailrc` file in the following format:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:736 +#, no-wrap +msgid "_env-variable_pass:attributes[{blank}]=\"pass:attributes[{blank}]_value_pass:attributes[{blank}]\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:739 +msgid "" +"In this example, " +"[command]#pass:attributes[{blank}]_env-variable_pass:attributes[{blank}]# is " +"the name of the variable and " +"[command]#pass:attributes[{blank}]_value_pass:attributes[{blank}]# defines " +"the variable." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:741 +msgid "" +"There are many environment variables not used by most Procmail users and " +"many of the more important environment variables are already defined by a " +"default value. Most of the time, the following variables are used:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:743 +msgid "" +"[command]#DEFAULT# — Sets the default mailbox where messages that do not " +"match any recipes are placed." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:745 +msgid "The default [command]#DEFAULT# value is the same as [command]#$ORGMAIL#." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:747 +msgid "" +"[command]#INCLUDERC# — Specifies additional `rc` files containing more " +"recipes for messages to be checked against. This breaks up the Procmail " +"recipe lists into individual files that fulfill different roles, such as " +"blocking spam and managing email lists, that can then be turned off or on by " +"using comment characters in the user's `~/.procmailrc` file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:749 +msgid "For example, lines in a user's `~/.procmailrc` file may look like this:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:755 +#, no-wrap +msgid "" +"MAILDIR=$HOME/Msgs\n" +"INCLUDERC=$MAILDIR/lists.rc\n" +"INCLUDERC=$MAILDIR/spam.rc\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:758 +msgid "" +"To turn off Procmail filtering of email lists but leaving spam control in " +"place, comment out the first [command]#INCLUDERC# line with a hash sign " +"(`#`). Note that it uses paths relative to the current directory." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:760 +msgid "" +"[command]#LOCKSLEEP# — Sets the amount of time, in seconds, between attempts " +"by Procmail to use a particular lockfile. The default is 8 seconds." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:762 +msgid "" +"[command]#LOCKTIMEOUT# — Sets the amount of time, in seconds, that must pass " +"after a lockfile was last modified before Procmail assumes that the lockfile " +"is old and can be deleted. The default is 1024 seconds." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:764 +msgid "" +"[command]#LOGFILE# — The file to which any Procmail information or error " +"messages are written." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:766 +msgid "" +"[command]#MAILDIR# — Sets the current working directory for Procmail. If " +"set, all other Procmail paths are relative to this directory." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:768 +msgid "" +"[command]#ORGMAIL# — Specifies the original mailbox, or another place to put " +"the messages if they cannot be placed in the default or recipe-required " +"location." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:770 +msgid "By default, a value of [command]#/var/spool/mail/$LOGNAME# is used." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:772 +msgid "" +"[command]#SUSPEND# — Sets the amount of time, in seconds, that Procmail " +"pauses if a necessary resource, such as swap space, is not available." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:774 +msgid "" +"[command]#SWITCHRC# — Allows a user to specify an external file containing " +"additional Procmail recipes, much like the [command]#INCLUDERC# option, " +"except that recipe checking is actually stopped on the referring " +"configuration file and only the recipes on the [command]#SWITCHRC#-specified " +"file are used." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:776 +msgid "" +"[command]#VERBOSE# — Causes Procmail to log more information. This option is " +"useful for debugging." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:778 +msgid "" +"Other important environmental variables are pulled from the shell, such as " +"[command]#LOGNAME#, the login name; [command]#HOME#, the location of the " +"home directory; and [command]#SHELL#, the default shell." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:780 +msgid "" +"A comprehensive explanation of all environments variables, and their default " +"values, is available in the `procmailrc` man page." +msgstr "" + +#. type: Title === +#: ./pages/servers/Mail_Servers.adoc:782 +#, no-wrap +msgid "Procmail Recipes" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:785 +msgid "" +"indexterm:[Procmail,recipes] New users often find the construction of " +"recipes the most difficult part of learning to use Procmail. This difficulty " +"is often attributed to recipes matching messages by using _regular " +"expressions_ which are used to specify qualifications for string " +"matching. However, regular expressions are not very difficult to construct " +"and even less difficult to understand when read. Additionally, the " +"consistency of the way Procmail recipes are written, regardless of regular " +"expressions, makes it easy to learn by example. To see example Procmail " +"recipes, see " +"xref:Mail_Servers.adoc#s3-email-procmail-recipes-examples[Recipe Examples]." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:787 +msgid "Procmail recipes take the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:796 +#, no-wrap +msgid "" +":0 pass:quotes[_flags_] : pass:quotes[_lockfile-name_]\n" +"* pass:quotes[_condition_1_special-condition-character_] " +"pass:quotes[_condition_1_regular_expression_]\n" +"* pass:quotes[_condition_2_special-condition-character_] " +"pass:quotes[_condition-2_regular_expression_]\n" +"* pass:quotes[_condition_N_special-condition-character_] " +"pass:quotes[_condition-N_regular_expression_]\n" +" pass:quotes[_special-action-character_]\n" +" pass:quotes[_action-to-perform_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:799 +msgid "" +"The first two characters in a Procmail recipe are a colon and a " +"zero. Various flags can be placed after the zero to control how Procmail " +"processes the recipe. A colon after the " +"[command]#pass:attributes[{blank}]_flags_pass:attributes[{blank}]# section " +"specifies that a lockfile is created for this message. If a lockfile is " +"created, the name can be specified by replacing " +"[command]#pass:attributes[{blank}]_lockfile-name_pass:attributes[{blank}]#." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:801 +msgid "" +"A recipe can contain several conditions to match against the message. If it " +"has no conditions, every message matches the recipe. Regular expressions are " +"placed in some conditions to facilitate message matching. If multiple " +"conditions are used, they must all match for the action to be " +"performed. Conditions are checked based on the flags set in the recipe's " +"first line. Optional special characters placed after the asterisk character " +"([command]#*#) can further control the condition." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:803 +msgid "" +"The " +"[command]#pass:attributes[{blank}]_action-to-perform_pass:attributes[{blank}]# " +"argument specifies the action taken when the message matches one of the " +"conditions. There can only be one action per recipe. In many cases, the name " +"of a mailbox is used here to direct matching messages into that file, " +"effectively sorting the email. Special action characters may also be used " +"before the action is specified. See " +"xref:Mail_Servers.adoc#s3-email-procmail-recipes-special[Special Conditions " +"and Actions] for more information." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:805 +#, no-wrap +msgid "Delivering vs. Non-Delivering Recipes" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:809 +msgid "" +"indexterm:[Procmail,recipes,delivering]indexterm:[Procmail,recipes,non-delivering] " +"The action used if the recipe matches a particular message determines " +"whether it is considered a _delivering_ or _non-delivering_ recipe. A " +"delivering recipe contains an action that writes the message to a file, " +"sends the message to another program, or forwards the message to another " +"email address. A non-delivering recipe covers any other actions, such as a " +"_nesting block_. A nesting block is a set of actions, contained in braces " +"[command]#{# [command]#}#, that are performed on messages which match the " +"recipe's conditions. Nesting blocks can be nested inside one another, " +"providing greater control for identifying and performing actions on " +"messages." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:811 +msgid "" +"When messages match a delivering recipe, Procmail performs the specified " +"action and stops comparing the message against any other recipes. Messages " +"that match non-delivering recipes continue to be compared against other " +"recipes." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:813 +#, no-wrap +msgid "Flags" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:816 +msgid "" +"indexterm:[Procmail,recipes,flags] Flags are essential to determine how or " +"if a recipe's conditions are compared to a message. The [application]*egrep* " +"utility is used internally for matching of the conditions. The following " +"flags are commonly used:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:818 +msgid "" +"[command]#A# — Specifies that this recipe is only used if the previous " +"recipe without an [command]#A# or [command]#a# flag also matched this " +"message." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:820 +msgid "" +"[command]#a# — Specifies that this recipe is only used if the previous " +"recipe with an [command]#A# or [command]#a# flag also matched this message " +"*and* was successfully completed." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:822 +msgid "" +"[command]#B# — Parses the body of the message and looks for matching " +"conditions." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:824 +msgid "" +"[command]#b# — Uses the body in any resulting action, such as writing the " +"message to a file or forwarding it. This is the default behavior." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:826 +msgid "" +"[command]#c# — Generates a carbon copy of the email. This is useful with " +"delivering recipes, since the required action can be performed on the " +"message and a copy of the message can continue being processed in the `rc` " +"files." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:828 +msgid "" +"[command]#D# — Makes the [command]#egrep# comparison case-sensitive. By " +"default, the comparison process is not case-sensitive." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:830 +msgid "" +"[command]#E# — While similar to the [command]#A# flag, the conditions in the " +"recipe are only compared to the message if the immediately preceding recipe " +"without an [command]#E# flag did not match. This is comparable to an `else` " +"action." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:832 +msgid "" +"[command]#e# — The recipe is compared to the message only if the action " +"specified in the immediately preceding recipe fails." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:834 +msgid "[command]#f# — Uses the pipe as a filter." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:836 +msgid "" +"[command]#H# — Parses the header of the message and looks for matching " +"conditions. This is the default behavior." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:838 +msgid "" +"[command]#h# — Uses the header in a resulting action. This is the default " +"behavior." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:840 +msgid "" +"[command]#w# — Tells Procmail to wait for the specified filter or program to " +"finish, and reports whether or not it was successful before considering the " +"message filtered." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:842 +msgid "" +"[command]#W# — Is identical to [command]#w# except that \"`Program " +"failure`\" messages are suppressed." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:844 +msgid "For a detailed list of additional flags, see the `procmailrc` man page." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:846 +#, no-wrap +msgid "Specifying a Local Lockfile" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:849 +msgid "" +"indexterm:[Procmail,recipes,local lockfiles] Lockfiles are very useful with " +"Procmail to ensure that more than one process does not try to alter a " +"message simultaneously. Specify a local lockfile by placing a colon " +"([command]#:#) after any flags on a recipe's first line. This creates a " +"local lockfile based on the destination file name plus whatever has been set " +"in the [command]#LOCKEXT# global environment variable." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:851 +msgid "" +"Alternatively, specify the name of the local lockfile to be used with this " +"recipe after the colon." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:853 +#, no-wrap +msgid "Special Conditions and Actions" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:856 +msgid "" +"indexterm:[Procmail,recipes,special " +"conditions]indexterm:[Procmail,recipes,special actions] Special characters " +"used before Procmail recipe conditions and actions change the way they are " +"interpreted." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:858 +msgid "" +"The following characters may be used after the asterisk character " +"([command]#*#) at the beginning of a recipe's condition line:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:860 +msgid "" +"[command]#!# — In the condition line, this character inverts the condition, " +"causing a match to occur only if the condition does not match the message." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:862 +msgid "[command]#<# — Checks if the message is under a specified number of bytes." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:864 +msgid "[command]#># — Checks if the message is over a specified number of bytes." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:866 +msgid "The following characters are used to perform special actions:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:868 +msgid "" +"[command]#!# — In the action line, this character tells Procmail to forward " +"the message to the specified email addresses." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:870 +msgid "" +"[command]#$# — Refers to a variable set earlier in the `rc` file. This is " +"often used to set a common mailbox that is referred to by various recipes." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:872 +msgid "[command]#|# — Starts a specified program to process the message." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:874 +msgid "" +"[command]#{# and [command]#}# — Constructs a nesting block, used to contain " +"additional recipes to apply to matching messages." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:876 +msgid "" +"If no special character is used at the beginning of the action line, " +"Procmail assumes that the action line is specifying the mailbox in which to " +"write the message." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:878 +#, no-wrap +msgid "Recipe Examples" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:881 +msgid "" +"indexterm:[Procmail,recipes,examples] Procmail is an extremely flexible " +"program, but as a result of this flexibility, composing Procmail recipes " +"from scratch can be difficult for new users." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:883 +msgid "" +"The best way to develop the skills to build Procmail recipe conditions stems " +"from a strong understanding of regular expressions combined with looking at " +"many examples built by others. A thorough explanation of regular expressions " +"is beyond the scope of this section. The structure of Procmail recipes and " +"useful sample Procmail recipes can be found at various places on the " +"Internet. The proper use and adaptation of regular expressions can be " +"derived by viewing these recipe examples. In addition, introductory " +"information about basic regular expression rules can be found in the " +"`grep(1)` man page." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:885 +msgid "" +"The following simple examples demonstrate the basic structure of Procmail " +"recipes and can provide the foundation for more intricate constructions." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:887 +msgid "" +"A basic recipe may not even contain conditions, as is illustrated in the " +"following example:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:892 +#, no-wrap +msgid "" +":0:\n" +"new-mail.spool\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:895 +msgid "" +"The first line specifies that a local lockfile is to be created but does not " +"specify a name, so Procmail uses the destination file name and appends the " +"value specified in the [command]#LOCKEXT# environment variable. No condition " +"is specified, so every message matches this recipe and is placed in the " +"single spool file called `new-mail.spool`, located within the directory " +"specified by the [command]#MAILDIR# environment variable. An MUA can then " +"view messages in this file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:897 +msgid "" +"A basic recipe, such as this, can be placed at the end of all `rc` files to " +"direct messages to a default location." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:899 +msgid "" +"The following example matched messages from a specific email address and " +"throws them away." +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:904 +#, no-wrap +msgid "" +":0\n" +"* ^From: spammer@domain.com\n" +"/dev/null\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:907 +msgid "" +"With this example, any messages sent by `spammer@domain.com` are sent to the " +"`/dev/null` device, deleting them." +msgstr "" + +#. type: Block title +#: ./pages/servers/Mail_Servers.adoc:908 +#, no-wrap +msgid "Sending messages to /dev/null" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:913 +msgid "" +"Be certain that rules are working as intended before sending messages to " +"`/dev/null` for permanent deletion. If a recipe inadvertently catches " +"unintended messages, and those messages disappear, it becomes difficult to " +"troubleshoot the rule." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:915 +msgid "" +"A better solution is to point the recipe's action to a special mailbox, " +"which can be checked from time to time to look for false positives. Once " +"satisfied that no messages are accidentally being matched, delete the " +"mailbox and direct the action to send the messages to `/dev/null`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:919 +msgid "" +"The following recipe grabs email sent from a particular mailing list and " +"places it in a specified folder." +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:924 +#, no-wrap +msgid "" +":0:\n" +"* ^(From|Cc|To).*tux-lug\n" +"tuxlug\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:927 +msgid "" +"Any messages sent from the `tux-lug@domain.com` mailing list are placed in " +"the `tuxlug` mailbox automatically for the MUA. Note that the condition in " +"this example matches the message if it has the mailing list's email address " +"on the `From`, `Cc`, or `To` lines." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:929 +msgid "" +"Consult the many Procmail online resources available in " +"xref:Mail_Servers.adoc#s1-email-additional-resources[Additional Resources] " +"for more detailed and powerful recipes." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:931 +#, no-wrap +msgid "Spam Filters" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:934 +msgid "" +"indexterm:[Procmail,recipes,SpamAssassin]indexterm:[SpamAssassin,using with " +"Procmail]indexterm:[email,spam,filtering out] Because it is called by " +"Sendmail, Postfix, and Fetchmail upon receiving new emails, Procmail can be " +"used as a powerful tool for combating spam." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:936 +msgid "" +"This is particularly true when Procmail is used in conjunction with " +"SpamAssassin. When used together, these two applications can quickly " +"identify spam emails, and sort or destroy them." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:938 +msgid "" +"SpamAssassin uses header analysis, text analysis, blacklists, a " +"spam-tracking database, and self-learning Bayesian spam analysis to quickly " +"and accurately identify and tag spam." +msgstr "" + +#. type: Block title +#: ./pages/servers/Mail_Servers.adoc:939 +#, no-wrap +msgid "Installing the spamassassin package" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:944 +msgid "" +"In order to use [application]*SpamAssassin*, first ensure the " +"[package]*spamassassin* package is installed on your system by running, as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:948 +#, no-wrap +msgid "~]#{nbsp}dnf install spamassassin\n" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:955 +msgid "" +"The easiest way for a local user to use SpamAssassin is to place the " +"following line near the top of the `~/.procmailrc` file:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:959 +#, no-wrap +msgid "INCLUDERC=/etc/mail/spamassassin/spamassassin-default.rc\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:962 +msgid "" +"The `/etc/mail/spamassassin/spamassassin-default.rc` contains a simple " +"Procmail rule that activates SpamAssassin for all incoming email. If an " +"email is determined to be spam, it is tagged in the header as such and the " +"title is prepended with the following pattern:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:965 +#, no-wrap +msgid "*****SPAM*****\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:968 +msgid "" +"The message body of the email is also prepended with a running tally of what " +"elements caused it to be diagnosed as spam." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:970 +msgid "To file email tagged as spam, a rule similar to the following can be used:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:973 +#, no-wrap +msgid ":0 Hw * ^X-Spam-Status: Yes spam\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:976 +msgid "" +"This rule files all email tagged in the header as spam into a mailbox called " +"`spam`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:978 +msgid "" +"Since SpamAssassin is a Perl script, it may be necessary on busy servers to " +"use the binary SpamAssassin daemon (`spamd`) and the client application " +"([application]*spamc*). Configuring SpamAssassin this way, however, requires " +"`root` access to the host." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:980 +msgid "To start the `spamd` daemon, type the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:984 +#, no-wrap +msgid "~]#{nbsp}systemctl start spamassassin.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:987 +msgid "To start the SpamAssassin daemon when the system is booted, run:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:991 +#, no-wrap +msgid "[command]#systemctl enable spamassassin.service#\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:994 +msgid "" +"See " +"xref:infrastructure-services/Services_and_Daemons.adoc#ch-Services_and_Daemons[Services " +"and Daemons] for more information on how to configure services in {MAJOROS}." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:996 +msgid "" +"To configure Procmail to use the SpamAssassin client application instead of " +"the Perl script, place the following line near the top of the " +"`~/.procmailrc` file. For a system-wide configuration, place it in " +"`/etc/procmailrc`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:1000 +#, no-wrap +msgid "INCLUDERC=/etc/mail/spamassassin/spamassassin-spamc.rc\n" +msgstr "" + +#. type: Title == +#: ./pages/servers/Mail_Servers.adoc:1003 +#, no-wrap +msgid "Mail User Agents" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:1006 +msgid "" +"{MAJOROS} offers a variety of email programs, both, graphical email client " +"programs, such as [application]*Evolution*, and text-based email programs " +"such as [command]#mutt#." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:1008 +msgid "" +"The remainder of this section focuses on securing communication between a " +"client and a server." +msgstr "" + +#. type: Title === +#: ./pages/servers/Mail_Servers.adoc:1010 +#, no-wrap +msgid "Securing Communication" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:1015 +msgid "" +"Popular MUAs included with {MAJOROS}, such as [application]*Evolution* and " +"[application]*Mutt* offer SSL-encrypted email sessions. " +"indexterm:[email,security] Like any other service that flows over a network " +"unencrypted, important email information, such as user names, passwords, and " +"entire messages, may be intercepted and viewed by users on the " +"network. Additionally, since the standard `POP` and `IMAP` protocols pass " +"authentication information unencrypted, it is possible for an attacker to " +"gain access to user accounts by collecting user names and passwords as they " +"are passed over the network." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:1017 +#, no-wrap +msgid "Secure Email Clients" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:1020 +msgid "" +"indexterm:[email,security,clients] Most Linux MUAs designed to check email " +"on remote servers support SSL encryption. To use SSL when retrieving email, " +"it must be enabled on both the email client and the server." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:1022 +msgid "" +"SSL is easy to enable on the client-side, often done with the click of a " +"button in the MUA's configuration window or via an option in the MUA's " +"configuration file. Secure `IMAP` and `POP` have known port numbers (993 and " +"995, respectively) that the MUA uses to authenticate and download messages." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:1024 +#, no-wrap +msgid "Securing Email Client Communications" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:1027 +msgid "" +"indexterm:[email,security,servers]indexterm:[stunnel] Offering SSL " +"encryption to `IMAP` and `POP` users on the email server is a simple matter." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:1029 +msgid "" +"First, create an SSL certificate. This can be done in two ways: by applying " +"to a _Certificate Authority_ (_CA_) for an SSL certificate or by creating a " +"self-signed certificate." +msgstr "" + +#. type: Block title +#: ./pages/servers/Mail_Servers.adoc:1030 +#, no-wrap +msgid "Avoid using self-signed certificates" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:1035 +msgid "" +"Self-signed certificates should be used for testing purposes only. Any " +"server used in a production environment should use an SSL certificate signed " +"by a CA." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:1039 +msgid "" +"To create a self-signed SSL certificate for `IMAP` or `POP`, change to the " +"`/etc/pki/dovecot/` directory, edit the certificate parameters in the " +"`/etc/pki/dovecot/dovecot-openssl.cnf` configuration file as you prefer, and " +"type the following commands, as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:1044 +#, no-wrap +msgid "" +"dovecot]#{nbsp}rm -f certs/dovecot.pem private/dovecot.pem\n" +"dovecot]#{nbsp}/usr/libexec/dovecot/mkcert.sh\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:1047 +msgid "" +"Once finished, make sure you have the following configurations in your " +"`/etc/dovecot/conf.d/10-ssl.conf` file:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:1051 +#, no-wrap +msgid "" +"ssl_cert = , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/servers/Web_Servers.adoc:6 +#, no-wrap +msgid "Web Servers" +msgstr "" + +#. indexterm:[HTTP server,Apache HTTP Server]indexterm:[web server,Apache HTTP Server] +#. type: delimited block = +#: ./pages/servers/Web_Servers.adoc:12 +#, no-wrap +msgid "**Editor's Note** \n" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Web_Servers.adoc:14 +msgid "" +"_This guide is deprecated!_ Large parts of it are no longer current and it " +"will not receive any updates. A series of shorter, topic-specific " +"documentation will gradually replace it." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Web_Servers.adoc:16 +msgid "" +"For additional information about Apache Webserver on Fedora see " +"https://docs.fedoraproject.org/en-US/quick-docs/getting-started-with-apache-http-server/[Getting " +"started with Apache HTTP Server]" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Web_Servers.adoc:20 +msgid "" +"A _web server_ is a network service that serves content to a client over the " +"web. This typically means web pages, but any other documents can be served " +"as well. Web servers are also known as HTTP servers, as they use the " +"_hypertext transport protocol_ (*HTTP*)." +msgstr "" diff --git a/po/fr/rawhide/pages/servers/intro-servers.po b/po/fr/rawhide/pages/servers/intro-servers.po new file mode 100644 index 00000000000..c568da14f1b --- /dev/null +++ b/po/fr/rawhide/pages/servers/intro-servers.po @@ -0,0 +1,30 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/servers/intro-servers.adoc:1 +#, no-wrap +msgid "Servers" +msgstr "" + +#. type: Plain text +#: ./pages/servers/intro-servers.adoc:3 +msgid "" +"This part discusses various topics related to servers such as how to set up " +"a web server or share files and directories over a network." +msgstr "" diff --git a/pot/rawhide/nav.pot b/pot/rawhide/nav.pot new file mode 100644 index 00000000000..aac80939a25 --- /dev/null +++ b/pot/rawhide/nav.pot @@ -0,0 +1,244 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Plain text +#: ./nav.adoc:2 +msgid "xref:index.adoc[System Administrator's Guide]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:3 +msgid "xref:Preface.adoc[Preface]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:4 +msgid "Basic System Configuration" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:5 +msgid "xref:basic-system-configuration/intro-basic-system-configuration.adoc[Introduction]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:6 +msgid "" +"xref:basic-system-configuration/Opening_GUI_Applications.adoc[Opening " +"Graphical Applications]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:7 +msgid "" +"xref:basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc[System " +"Locale and Keyboard Configuration]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:8 +msgid "" +"xref:basic-system-configuration/Configuring_the_Date_and_Time.adoc[Configuring " +"the Date and Time]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:9 +msgid "" +"xref:basic-system-configuration/Managing_Users_and_Groups.adoc[Managing " +"Users and Groups]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:10 +msgid "xref:basic-system-configuration/Gaining_Privileges.adoc[Gaining Privileges]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:11 +msgid "Package Management" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:12 +msgid "xref:package-management/intro-package-management.adoc[Introduction]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:13 +msgid "xref:package-management/DNF.adoc[DNF]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:14 +msgid "xref:package-management/rpm-ostree.adoc[rpm-ostree]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:15 +msgid "Infrastructure Services" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:16 +msgid "xref:infrastructure-services/intro-infrastructure-services.adoc[Introduction]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:17 +msgid "xref:infrastructure-services/Services_and_Daemons.adoc[Services and Daemons]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:18 +msgid "xref:infrastructure-services/OpenSSH.adoc[OpenSSH]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:19 +msgid "xref:infrastructure-services/TigerVNC.adoc[TigerVNC]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:20 +msgid "Servers" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:21 +msgid "xref:servers/intro-servers.adoc[Introduction]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:22 +msgid "xref:servers/Web_Servers.adoc[Web Servers]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:23 +msgid "xref:servers/Mail_Servers.adoc[Mail Servers]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:24 +msgid "xref:servers/Directory_Servers.adoc[Directory Servers]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:25 +msgid "xref:servers/File_and_Print_Servers.adoc[File and Print Servers]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:26 +msgid "" +"xref:servers/Configuring_NTP_Using_the_chrony_Suite.adoc[Configuring NTP " +"Using the chrony Suite]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:27 +msgid "xref:servers/Configuring_PTP_Using_ptp4l.adoc[Configuring PTP Using ptp4l]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:28 +msgid "Monitoring and Automation" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:29 +msgid "xref:monitoring-and-automation/intro-monitoring-and-automation.adoc[Introduction]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:30 +msgid "" +"xref:monitoring-and-automation/System_Monitoring_Tools.adoc[System " +"Monitoring Tools]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:31 +msgid "" +"xref:monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc[Viewing " +"and Managing Log Files]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:32 +msgid "" +"xref:monitoring-and-automation/Automating_System_Tasks.adoc[Automating " +"System Tasks]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:33 +msgid "xref:monitoring-and-automation/OProfile.adoc[OProfile]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:34 +msgid "Kernel, Module and Driver Configuration" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:35 +msgid "xref:kernel-module-driver-configuration/intro-kernel-module-driver-configuration.adoc[Introduction]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:36 +msgid "" +"xref:kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc[Working " +"with the GRUB 2 Boot Loader]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:37 +msgid "" +"xref:kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc[Manually " +"Upgrading the Kernel]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:38 +msgid "" +"xref:kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc[Working " +"with Kernel Modules]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:39 +msgid "xref:RPM.adoc[RPM]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:40 +msgid "xref:Wayland.adoc[The Wayland Display Server]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:41 +msgid "xref:pam_userdb.adoc[pam_userdb]" +msgstr "" + +#. type: Plain text +#: ./nav.adoc:41 +msgid "xref:Revision_History.adoc[Revision History]" +msgstr "" diff --git a/pot/rawhide/pages/Preface.pot b/pot/rawhide/pages/Preface.pot new file mode 100644 index 00000000000..9c86dd9aa9c --- /dev/null +++ b/pot/rawhide/pages/Preface.pot @@ -0,0 +1,468 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/Preface.adoc:5 +#, no-wrap +msgid "Preface" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:8 +msgid "" +"The [citetitle]_System Administrator's Guide_ contains information on how to " +"customize the {MAJOROSVER} system to fit your needs. If you are looking for " +"a comprehensive, task-oriented guide for configuring and customizing your " +"system, this is the manual for you." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:10 +msgid "This manual discusses many intermediate topics such as the following:" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:12 +msgid "Installing and managing packages using [application]*DNF*" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:14 +msgid "" +"Configuring [application]*Apache HTTP Server*, [application]*Postfix*, " +"[application]*Sendmail* and other enterprise-class servers and software" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:16 +msgid "Working with kernel modules and upgrading the kernel" +msgstr "" + +#. type: delimited block = +#: ./pages/Preface.adoc:21 +msgid "" +"Some of the graphical procedures and menu locations are specific to GNOME, " +"but most command line instructions will be universally applicable." +msgstr "" + +#. type: Title == +#: ./pages/Preface.adoc:25 +#, no-wrap +msgid "Target Audience" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:28 +msgid "" +"The [citetitle]_System Administrator's Guide_ assumes you have a basic " +"understanding of the {MAJOROS} operating system. If you need help with the " +"installation of this system, refer to the " +"link:++https://docs.fedoraproject.org/install-guide++[{MAJOROS} Installation " +"Guide]." +msgstr "" + +#. type: Title == +#: ./pages/Preface.adoc:30 +#, no-wrap +msgid "How to Read this Book" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:33 +msgid "This manual is divided into the following main categories:" +msgstr "" + +#. type: Labeled list +#: ./pages/Preface.adoc:34 +#, no-wrap +msgid "" +"xref:basic-system-configuration/intro-basic-system-configuration.adoc[Basic " +"System Configuration]" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:35 +msgid "" +"This part covers basic system administration tasks such as keyboard " +"configuration, date and time configuration, managing users and groups, and " +"gaining privileges." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:37 +msgid "" +"xref:basic-system-configuration/Opening_GUI_Applications.adoc[Opening " +"Graphical Applications] describes methods for opening `Graphical User " +"Interface`, or _GUI_, applications in various environments." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:39 +msgid "" +"xref:basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc[System " +"Locale and Keyboard Configuration] covers basic language and keyboard " +"setup. Read this chapter if you need to configure the language of your " +"desktop, change the keyboard layout, or add the keyboard layout indicator to " +"the panel." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:41 +msgid "" +"xref:basic-system-configuration/Configuring_the_Date_and_Time.adoc[Configuring " +"the Date and Time] covers the configuration of the system date and " +"time. Read this chapter if you need to set or change the date and time." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:43 +msgid "" +"xref:basic-system-configuration/Managing_Users_and_Groups.adoc[Managing " +"Users and Groups] covers the management of users and groups in a graphical " +"user interface and on the command line. Read this chapter if you need to " +"manage users and groups on your system, or enable password aging." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:45 +msgid "" +"xref:basic-system-configuration/Gaining_Privileges.adoc[Gaining Privileges] " +"covers ways to gain administrative privileges using setuid programs such as " +"[command]#su# and [command]#sudo#." +msgstr "" + +#. type: Labeled list +#: ./pages/Preface.adoc:46 +#, no-wrap +msgid "xref:package-management/intro-package-management.adoc[Package Management]" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:47 +msgid "" +"This part describes how to manage software packages on {MAJOROS} using " +"[application]*DNF*." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:49 +msgid "" +"xref:package-management/DNF.adoc[DNF] describes the [application]*DNF* " +"package manager. Read this chapter for information how to search, install, " +"update, and uninstall packages on the command line." +msgstr "" + +#. type: Labeled list +#: ./pages/Preface.adoc:50 +#, no-wrap +msgid "" +"xref:infrastructure-services/intro-infrastructure-services.adoc[Infrastructure " +"Services]" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:51 +msgid "" +"This part provides information on how to configure services and daemons, " +"configure authentication, and enable remote logins." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:53 +msgid "" +"xref:infrastructure-services/Services_and_Daemons.adoc[Services and Daemons] " +"covers the configuration of the services to be run when a system is started, " +"and provides information on how to start, stop, and restart the services on " +"the command line using the [command]#systemctl# utility." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:55 +msgid "" +"xref:infrastructure-services/OpenSSH.adoc[OpenSSH] describes how to enable a " +"remote login via the SSH protocol. It covers the configuration of the `sshd` " +"service, as well as a basic usage of the [command]#ssh#, [command]#scp#, " +"[command]#sftp# client utilities. Read this chapter if you need a remote " +"access to a machine." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:57 +msgid "" +"xref:infrastructure-services/TigerVNC.adoc[TigerVNC] describes the _virtual " +"network computing_ (*VNC*) method of graphical desktop sharing which allows " +"you to remotely control other computers." +msgstr "" + +#. type: Labeled list +#: ./pages/Preface.adoc:58 +#, no-wrap +msgid "xref:servers/intro-servers.adoc[Servers]" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:59 +msgid "" +"This part discusses various topics related to servers such as how to set up " +"a Web server or share files and directories over the network." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:61 +msgid "" +"xref:servers/Web_Servers.adoc[Web Servers] focuses on the " +"[application]*Apache HTTP Server*, a robust, full-featured open source web " +"server developed by the Apache Software Foundation. Read this chapter if you " +"need to configure a web server on your system." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:63 +msgid "" +"xref:servers/Mail_Servers.adoc[Mail Servers] reviews modern email protocols " +"in use today, and some of the programs designed to send and receive email, " +"including [application]*Postfix*, [application]*Sendmail*, " +"[application]*Fetchmail*, and [application]*Procmail*. Read this chapter if " +"you need to configure a mail server on your system." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:65 +msgid "" +"xref:servers/Directory_Servers.adoc[Directory Servers] covers the " +"installation and configuration of [application]*OpenLDAP*, an open source " +"implementation of the LDAPv2 and LDAPv3 protocols. Read this chapter if you " +"need to configure a directory server on your system." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:67 +msgid "" +"xref:servers/File_and_Print_Servers.adoc[File and Print Servers] guides you " +"through the installation and configuration of [application]*Samba*, an open " +"source implementation of the Server Message Block (SMB) protocol, and " +"[application]*vsftpd*, the primary FTP server shipped with " +"{MAJOROS}. Additionally, it explains how to use the [application]*Printer " +"Configuration* tool to configure printers. Read this chapter if you need to " +"configure a file or print server on your system." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:69 +msgid "" +"xref:servers/Configuring_NTP_Using_the_chrony_Suite.adoc[Configuring NTP " +"Using the chrony Suite] covers the installation and configuration of the " +"[application]*chrony* suite, a client and a server for the Network Time " +"Protocol (`NTP`). Read this chapter if you need to configure the system to " +"synchronize the clock with a remote `NTP` server, or set up an `NTP` server " +"on this system." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:71 +msgid "" +"xref:servers/Configuring_NTP_Using_ntpd.adoc[Configuring NTP Using ntpd] " +"covers the installation and configuration of the `NTP` daemon, `ntpd`, for " +"the Network Time Protocol (`NTP`). Read this chapter if you need to " +"configure the system to synchronize the clock with a remote `NTP` server, or " +"set up an `NTP` server on this system, and you prefer not to use the " +"[application]*chrony* application." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:73 +msgid "" +"xref:servers/Configuring_PTP_Using_ptp4l.adoc[Configuring PTP Using ptp4l] " +"covers the installation and configuration of the Precision Time Protocol " +"application, [application]*ptp4l*, an application for use with network " +"drivers that support the Precision Network Time Protocol (`PTP`). Read this " +"chapter if you need to configure the system to synchronize the system clock " +"with a master `PTP` clock." +msgstr "" + +#. type: Labeled list +#: ./pages/Preface.adoc:74 +#, no-wrap +msgid "" +"xref:monitoring-and-automation/intro-monitoring-and-automation.adoc[Monitoring " +"and Automation]" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:75 +msgid "" +"This part describes various tools that allow system administrators to " +"monitor system performance, automate system tasks, and report bugs." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:77 +msgid "" +"xref:monitoring-and-automation/System_Monitoring_Tools.adoc[System " +"Monitoring Tools] discusses applications and commands that can be used to " +"retrieve important information about the system. Read this chapter to learn " +"how to gather essential system information." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:79 +msgid "" +"xref:monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc[Viewing " +"and Managing Log Files] describes the configuration of the `rsyslog` daemon, " +"and explains how to locate, view, and monitor log files. Read this chapter " +"to learn how to work with log files." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:81 +msgid "" +"xref:monitoring-and-automation/Automating_System_Tasks.adoc[Automating " +"System Tasks] provides an overview of the [command]#cron#, [command]#at#, " +"and [command]#batch# utilities. Read this chapter to learn how to use these " +"utilities to perform automated tasks." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:83 +msgid "" +"xref:monitoring-and-automation/OProfile.adoc[OProfile] covers " +"[application]*OProfile*, a low overhead, system-wide performance monitoring " +"tool. Read this chapter for information on how to use " +"[application]*OProfile* on your system." +msgstr "" + +#. type: Labeled list +#: ./pages/Preface.adoc:84 +#, no-wrap +msgid "" +"xref:kernel-module-driver-configuration/intro-kernel-module-driver-configuration.adoc[Kernel, " +"Module and Driver Configuration]" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:85 +msgid "" +"This part covers various tools that assist administrators with kernel " +"customization." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:87 +msgid "" +"xref:kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc[Working " +"with the GRUB 2 Boot Loader] describes the GNU GRand Unified Boot loader " +"(GRUB) version 2 boot loader, which enables selecting an operating system or " +"kernel to be loaded at system boot time." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:89 +msgid "" +"xref:kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc[Manually " +"Upgrading the Kernel] provides important information on how to manually " +"update a kernel package using the [command]#rpm# command instead of " +"[command]#dnf#. Read this chapter if you cannot update a kernel package with " +"the [application]*DNF* package manager." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:91 +msgid "" +"xref:kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc[Working " +"with Kernel Modules] explains how to display, query, load, and unload kernel " +"modules and their dependencies, and how to set module " +"parameters. Additionally, it covers specific kernel module capabilities such " +"as using multiple Ethernet cards and using channel bonding. Read this " +"chapter if you need to work with kernel modules." +msgstr "" + +#. type: Labeled list +#: ./pages/Preface.adoc:92 +#, no-wrap +msgid "xref:RPM.adoc[RPM]" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:93 +msgid "" +"This appendix concentrates on the RPM Package Manager (RPM), an open " +"packaging system used by {MAJOROS}, and the use of the [command]#rpm# " +"utility. Read this appendix if you need to use [command]#rpm# instead of " +"[command]#dnf#." +msgstr "" + +#. type: Labeled list +#: ./pages/Preface.adoc:94 +#, no-wrap +msgid "xref:Wayland.adoc[The Wayland Display Server]" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:95 +msgid "" +"This appendix looks at Wayland, a new display server used in GNOME for " +"{MAJOROS} and how to troubleshoot issues with the Wayland display server." +msgstr "" + +#. type: Labeled list +#: ./pages/Preface.adoc:96 +#, no-wrap +msgid "xref:pam_userdb.adoc[pam_userdb]" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:97 +msgid "" +"This appendix looks at pam_userdb, providing instructions on how to update " +"to the new database provider." +msgstr "" + +#. type: Title == +#: ./pages/Preface.adoc:101 +#, no-wrap +msgid "Acknowledgments" +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:104 +msgid "" +"Certain portions of this text first appeared in the [citetitle]_Red{nbsp}Hat " +"Enterprise{nbsp}Linux{nbsp}7 System Administrator's Guide_, copyright © " +"2014–{YEAR} Red{nbsp}Hat, Inc., available at " +"link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/System_Administrators_Guide/index.html++[]." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:106 +msgid "" +"xref:monitoring-and-automation/System_Monitoring_Tools.adoc#sect-System_Monitoring_Tools-Net-SNMP[Monitoring " +"Performance with Net-SNMP] is based on an article written by Michael " +"Solberg." +msgstr "" + +#. type: Plain text +#: ./pages/Preface.adoc:107 +msgid "" +"The authors of this book would like to thank the following people for their " +"valuable contributions: Adam Tkáč, Andrew Fitzsimon, Andrius Benokraitis, " +"Brian Cleary Edward Bailey, Garrett LeSage, Jeffrey Fearn, Joe Orton, Joshua " +"Wulf, Karsten Wade, Lucy Ringland, Marcela Mašláňová, Mark Johnson, Michael " +"Behm, Miroslav Lichvár, Radek Vokál, Rahul Kavalapara, Rahul Sundaram, " +"Sandra Moore, Zbyšek Mráz, Jan Včelák, Peter Hutterer, T.C. Hollingsworth, " +"and James Antill, among many others." +msgstr "" diff --git a/pot/rawhide/pages/RPM.pot b/pot/rawhide/pages/RPM.pot new file mode 100644 index 00000000000..78622ba170d --- /dev/null +++ b/pot/rawhide/pages/RPM.pot @@ -0,0 +1,1250 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/RPM.adoc:5 +#, no-wrap +msgid "RPM" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:8 +msgid "" +"indexterm:[RPM Package Manager,RPM]indexterm:[RPM]indexterm:[packages,RPM] " +"The _RPM Package Manager_ ([application]*RPM*) is an open packaging system " +"that runs on {MAJOROS} as well as other Linux and UNIX systems. Red{nbsp}Hat " +"and the Fedora Project encourage other vendors to use [application]*RPM* for " +"their own products. [application]*RPM* is distributed under the terms of the " +"_GPL_ (_GNU General Public License_)." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:10 +msgid "" +"The [application]*RPM Package Manager* only works with packages built in the " +"*RPM format*. [application]*RPM* itself is provided as the pre-installed " +"[package]*rpm* package. For the end user, [application]*RPM* makes system " +"updates easy. Installing, uninstalling, and upgrading [application]*RPM* " +"packages can be accomplished with short commands. [application]*RPM* " +"maintains a database of installed packages and their files, so you can make " +"queries and verify installed files on your system. There are several " +"applications, such as [application]*DNF* or [application]*PackageKit*, that " +"can make working with packages in the [application]*RPM* format even easier." +msgstr "" + +#. type: Block title +#: ./pages/RPM.adoc:12 +#, no-wrap +msgid "Use DNF Instead of RPM Whenever Possible" +msgstr "" + +#. type: delimited block = +#: ./pages/RPM.adoc:17 +msgid "" +"indexterm:[packages,DNF instead of RPM] For most package-management tasks, " +"the [application]*DNF* package manager offers equal and often greater " +"capabilities and utility than [application]*RPM*. [application]*DNF* also " +"performs and tracks complicated system-dependency " +"resolutions. [application]*DNF* maintains the system integrity and forces a " +"system integrity check if packages are installed or removed using another " +"application, such as [application]*RPM*, instead of [application]*DNF*. For " +"these reasons, it is highly recommended that you use [application]*DNF* " +"instead of [application]*RPM* whenever possible to perform " +"package-management tasks. See xref:package-management/DNF.adoc#ch-DNF[DNF]." +msgstr "" + +#. type: delimited block = +#: ./pages/RPM.adoc:19 +msgid "" +"If you prefer a graphical interface, you can use the " +"[application]*PackageKit* GUI application, which uses [application]*DNF* as " +"its back end, to manage your system's packages." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:25 +msgid "" +"During upgrades, [application]*RPM* handles configuration files carefully, " +"so that you never lose your customizations — something that you cannot " +"accomplish with regular `.tar.gz` files. indexterm:[packages,RPM,source and " +"binary packages] For the developer, [application]*RPM* enables software " +"source code to be packaged into source and binary packages for end " +"users. This process is quite simple and is driven from a single file and " +"optional patches that you create. This clear delineation between pristine " +"sources and your patches along with build instructions eases the maintenance " +"of the package as new versions of the software are released." +msgstr "" + +#. type: Block title +#: ./pages/RPM.adoc:27 +#, no-wrap +msgid "Note" +msgstr "" + +#. type: delimited block = +#: ./pages/RPM.adoc:32 +msgid "" +"Because [application]*RPM* can make changes to the system itself, performing " +"operations like installing, upgrading, downgrading, and uninstalling binary " +"packages system-wide requires `root` privileges in most cases." +msgstr "" + +#. type: Title == +#: ./pages/RPM.adoc:36 +#, no-wrap +msgid "RPM Design Goals" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:39 +msgid "" +"indexterm:[RPM,design goals] To understand how to use [application]*RPM*, it " +"is helpful to understand the design goals of [application]*RPM*:" +msgstr "" + +#. type: Labeled list +#: ./pages/RPM.adoc:40 +#, no-wrap +msgid "indexterm:[RPM,design goals,upgradability] Upgradability" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:41 +msgid "" +"With [application]*RPM*, you can upgrade individual components of your " +"system without a complete reinstallation. When you get a new release of an " +"operating system based on [application]*RPM*, such as {MAJOROS}, you do not " +"need to reinstall a fresh copy of the operating system on your machine (as " +"you might need to with operating systems based on other packaging " +"systems). [application]*RPM* allows for intelligent, fully-automated, " +"in-place upgrades of your system. In addition, configuration files in " +"packages are preserved across upgrades, so you do not lose your " +"customizations. There are no special upgrade files needed to upgrade a " +"package because the same [application]*RPM* file is used to both install and " +"upgrade the package on the system." +msgstr "" + +#. type: Labeled list +#: ./pages/RPM.adoc:42 +#, no-wrap +msgid "indexterm:[RPM,design goals,powerful querying] Powerful Querying" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:43 +msgid "" +"[application]*RPM* is designed to provide powerful querying options. You can " +"perform searches on your copy of the database for packages or even just " +"certain files. You can also easily find out what package a file belongs to " +"and where the package came from. The files an [application]*RPM* package " +"contains are in a compressed archive, with a custom binary header containing " +"useful information about the package and its contents, allowing you to query " +"individual packages quickly and easily." +msgstr "" + +#. type: Labeled list +#: ./pages/RPM.adoc:44 +#, no-wrap +msgid "" +"indexterm:[RPM,design goals,system verification] System " +"Verification" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:45 +msgid "" +"Another powerful [application]*RPM* feature is the ability to verify " +"packages. It allows you to verify that the files installed on the system are " +"the same as the ones supplied by a given package. If an inconsistency is " +"detected, [application]*RPM* notifies you, and you can reinstall the package " +"if necessary. Any configuration files that you modified are preserved during " +"reinstallation." +msgstr "" + +#. type: Labeled list +#: ./pages/RPM.adoc:46 +#, no-wrap +msgid "indexterm:[packages,RPM,pristine sources] Pristine Sources" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:47 +msgid "" +"A crucial design goal was to allow the use of *pristine* software sources, " +"as distributed by the original authors of the software. With " +"[application]*RPM*, you have the pristine sources along with any patches " +"that were used, plus complete build instructions. This is an important " +"advantage for several reasons. For instance, if a new version of a program " +"is released, you do not necessarily have to start from scratch to get it to " +"compile. You can look at the patch to see what you *might* need to do. All " +"the compiled-in defaults, and all of the changes that were made to get the " +"software to build properly, are easily visible using this technique." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:49 +msgid "" +"The goal of keeping sources pristine may seem important only for developers, " +"but it results in higher quality software for end users." +msgstr "" + +#. type: Title == +#: ./pages/RPM.adoc:51 +#, no-wrap +msgid "Using RPM" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:54 +msgid "" +"[application]*RPM* has five basic modes of operationindexterm:[RPM,basic " +"modes] (not counting package building): installing, uninstalling, upgrading, " +"querying, and verifying. This section contains an overview of each mode. For " +"complete details and options, try [command]#rpm --help# or see " +"*rpm*(8). Also, see xref:RPM.adoc#s1-rpm-additional-resources[Additional " +"Resources] for more information on [application]*RPM*." +msgstr "" + +#. type: Title === +#: ./pages/RPM.adoc:56 +#, no-wrap +msgid "Installing and Upgrading Packages" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:59 +msgid "" +"indexterm:[RPM,installing]indexterm:[RPM,upgrading]indexterm:[packages,installing " +"RPM]indexterm:[packages,upgrading RPM]indexterm:[RPM,file name] " +"[application]*RPM* packages typically have file names in the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:62 +#, no-wrap +msgid "package_name-version-release-operating_system-CPU_architecture.rpm\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:65 +msgid "" +"For example the `tree-1.7.0-3.{PKGOS}.x86_64.rpm` file name includes the " +"package name (`tree`), version (`1.7.0`), release (`3`), operating system " +"major version (`{PKGOS}`) and *CPU* architecture (`x86_64`)." +msgstr "" + +#. type: Block title +#: ./pages/RPM.adoc:66 ./pages/RPM.adoc:359 +#, no-wrap +msgid "Important" +msgstr "" + +#. type: delimited block = +#: ./pages/RPM.adoc:71 +msgid "" +"When installing a package, ensure it is compatible with your operating " +"system and processor architecture. This can usually be determined by " +"checking the package name. For example, the file name of an " +"[application]*RPM* package compiled for the AMD64/Intel{nbsp}64 computer " +"architectures ends with `x86_64.rpm`." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:75 +msgid "" +"The [option]`-U` (or [option]`--upgrade`) option has two functions, it can " +"be used to:" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:77 +msgid "upgrade an existing package on the system to a newer version, or" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:79 +msgid "install a package if an older version is not already installed." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:81 +msgid "" +"The [command]#rpm -U _package.rpm_pass:attributes[{blank}]# command is " +"therefore able to either *upgrade* or *install*, depending on the presence " +"of an older version of _package.rpm_ on the system." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:83 +msgid "" +"Assuming the `tree-1.7.0-3.{PKGOS}.x86_64.rpm` package is in the current " +"directory, log in as `root` and type the following command at a shell prompt " +"to either upgrade or install the [package]*tree* package:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:87 +#, no-wrap +msgid "~]#{nbsp}rpm -Uvh tree-1.7.0-3.{PKGOS}.x86_64.rpm\n" +msgstr "" + +#. type: Block title +#: ./pages/RPM.adoc:90 +#, no-wrap +msgid "Use -Uvh for nicely-formatted RPM installs" +msgstr "" + +#. type: delimited block = +#: ./pages/RPM.adoc:95 +msgid "" +"The [option]`-v` and [option]`-h` options (which are combined with " +"[option]`-U`) cause [application]*rpm* to print more verbose output and " +"display a progress meter using hash signs." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:99 +msgid "" +"If the upgrade or installation is successful, the following output is " +"displayed:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:103 +#, no-wrap +msgid "" +"Preparing... ########################################### " +"[100%]\n" +" 1:tree ########################################### " +"[100%]\n" +msgstr "" + +#. type: Block title +#: ./pages/RPM.adoc:106 +#, no-wrap +msgid "Always use the -i (install) option to install new kernel packages!" +msgstr "" + +#. type: delimited block = +#: ./pages/RPM.adoc:111 +msgid "" +"[command]#rpm# provides two different options for installing packages: the " +"aforementioned [option]`-U` option (which historically stands for " +"*upgrade*), and the [option]`-i` option (which historically stands for " +"*install*). Because the [option]`-U` option includes both install and " +"upgrade functions, the use of [command]#rpm -Uvh# with all packages, *except " +"kernel packages*, is recommended." +msgstr "" + +#. type: delimited block = +#: ./pages/RPM.adoc:113 +msgid "" +"You should always use the [option]`-i` option to *install* a new kernel " +"package instead of upgrading it. This is because using the [option]`-U` " +"option to upgrade a kernel package removes the previous (older) kernel " +"package, which could render the system unable to boot if there is a problem " +"with the new kernel. Therefore, use the [command]#rpm -i " +"_kernel_package_pass:attributes[{blank}]# command to install a new kernel " +"*without replacing any older kernel packages*. For more information on " +"installing [package]*kernel* packages, see " +"xref:kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc#ch-Manually_Upgrading_the_Kernel[Manually " +"Upgrading the Kernel]." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:117 +msgid "" +"The signature of a package is checked automatically when installing or " +"upgrading a package. The signature confirms that the package was signed by " +"an authorized party. If the verification of the signature fails, an error " +"message is displayed." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:119 +msgid "" +"If you do not have the appropriate key installed to verify the signature, " +"the message contains the word `NOKEY`:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:123 +#, no-wrap +msgid "" +"warning: tree-1.7.0-3.{PKGOS}.x86_64.rpm: Header V3 RSA/SHA256 Signature, " +"key ID 431d51: NOKEY\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:126 +msgid "" +"See xref:RPM.adoc#s1-check-rpm-sig[Checking Package Signatures] for more " +"information on checking package signatures." +msgstr "" + +#. type: Title ==== +#: ./pages/RPM.adoc:128 +#, no-wrap +msgid "Replacing Already-Installed Packages" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:131 +msgid "" +"indexterm:[RPM,already installed]indexterm:[packages,RPM,already installed] " +"If a package of the same name and version is already installed, the " +"following output is displayed:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:136 +#, no-wrap +msgid "" +"Preparing... ########################################### " +"[100%]\n" +" package tree-1.7.0-3.{PKGOS}.x86_64 is already installed\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:139 +msgid "" +"To install the package anyway, use the [option]`--replacepkgs` option, which " +"tells [application]*RPM* to ignore the error:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:143 +#, no-wrap +msgid "~]#{nbsp}rpm -Uvh --replacepkgs tree-1.7.0-3.{PKGOS}.x86_64.rpm\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:146 +msgid "" +"This option is helpful if files installed from the package were deleted or " +"if you want the original configuration files to be installed." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:148 +msgid "" +"If you attempt an upgrade to an *older* version of a package (that is, if a " +"newer version of the package is already installed), [application]*RPM* " +"informs you that a newer version is already installed. To force " +"[application]*RPM* to perform the downgrade, use the [command]#--oldpackage# " +"option:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:151 +#, no-wrap +msgid "rpm -Uvh --oldpackage older_package.rpm\n" +msgstr "" + +#. type: Title ==== +#: ./pages/RPM.adoc:154 +#, no-wrap +msgid "Resolving File Conflicts" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:157 +msgid "" +"indexterm:[RPM,file " +"conflicts,resolving]indexterm:[RPM,conflicts]indexterm:[packages,RPM,conflict] " +"If you attempt to install a package that contains a file that has already " +"been installed by another package, a conflict message is displayed. To make " +"[application]*RPM* ignore this error, use the [command]#--replacefiles# " +"option:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:161 +#, no-wrap +msgid "[command]#rpm -Uvh --replacefiles _package.rpm_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Title ==== +#: ./pages/RPM.adoc:164 +#, no-wrap +msgid "Satisfying Unresolved Dependencies" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:167 +msgid "" +"indexterm:[RPM,dependencies]indexterm:[packages,dependencies]indexterm:[RPM,failed " +"dependencies]indexterm:[packages,RPM,failed dependencies] [application]*RPM* " +"packages sometimes depend on other packages, which means that they require " +"other packages to be installed to run properly. If you try to install a " +"package that has an unresolved dependency, a message about a failed " +"dependency is displayed." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:169 +msgid "" +"Find the suggested package(s) on the {MAJOROS} installation media or on one " +"of the active {MAJOROS} mirrors and add it to the installation command. To " +"determine which package contains the required file, use the " +"[option]`--whatprovides` option:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:172 +#, no-wrap +msgid "rpm -q --whatprovides \"required_file\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:175 +msgid "" +"If the package that contains _required_file_ is in the [application]*RPM* " +"database, the name of the package is displayed." +msgstr "" + +#. type: Block title +#: ./pages/RPM.adoc:177 +#, no-wrap +msgid "Warning" +msgstr "" + +#. type: delimited block = +#: ./pages/RPM.adoc:182 +msgid "" +"Although you can *force* [command]#rpm# to install a package that has an " +"unresolved dependency (using the [option]`--nodeps` option), this is *not* " +"recommended and will usually result in the installed software failing to " +"run. Installing packages with [option]`--nodeps` can cause applications to " +"misbehave or terminate unexpectedly. It can also cause serious " +"package-management problems or system failure. For these reasons, heed the " +"warnings about missing dependencies. The [application]*DNF* package manager " +"performs automatic dependency resolution and fetches dependencies from " +"on-line repositories." +msgstr "" + +#. type: Title ==== +#: ./pages/RPM.adoc:186 +#, no-wrap +msgid "Preserving Changes in Configuration Files" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:189 +msgid "" +"indexterm:[RPM,configuration file " +"changes]indexterm:[packages,RPM,configuration file " +"changes]indexterm:[RPM,configuration file changes,conf.rpmsave] Because " +"[application]*RPM* performs intelligent upgrading of packages with " +"configuration files, you may see the following message:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:193 +#, no-wrap +msgid "" +"saving pass:quotes[_/etc/configuration_file.conf_] as " +"pass:quotes[_/etc/configuration_file.conf_].rpmsave\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:196 +msgid "" +"This message means that the changes you made to the configuration file may " +"not be *forward-compatible* with the new configuration file in the package, " +"so [application]*RPM* saved your original file and installed a new one. You " +"should investigate the differences between the two configuration files and " +"resolve them as soon as possible to ensure that your system continues to " +"function properly." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:198 +msgid "" +"Alternatively, [application]*RPM* may save the package's *new* configuration " +"file as, for example, " +"`pass:attributes[{blank}]_configuration_file.conf_.rpmnew` and leave the " +"configuration file you modified untouched. You should still resolve any " +"conflicts between your modified configuration file and the new one, usually " +"by merging changes from the old one to the new one, for example using the " +"[command]#diff# program." +msgstr "" + +#. type: Title === +#: ./pages/RPM.adoc:200 +#, no-wrap +msgid "Uninstalling Packages" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:203 +msgid "" +"indexterm:[RPM,uninstalling]indexterm:[packages,removing]indexterm:[packages,RPM,uninstalling]indexterm:[packages,RPM,removing] " +"Uninstalling a package is just as simple as installing one. Type the " +"following command at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:207 +#, no-wrap +msgid "[command]#rpm -e _package_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Block title +#: ./pages/RPM.adoc:209 +#, no-wrap +msgid "rpm -e and package name errors" +msgstr "" + +#. type: delimited block = +#: ./pages/RPM.adoc:214 +msgid "" +"Note that the command expects only the package *name*, not the name of the " +"original package *file*. If you attempt to uninstall a package using the " +"[command]#rpm{nbsp}-e# command and provide the original full file name, you " +"receive a package-name error." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:218 +msgid "" +"You can encounter dependency errors when uninstalling a package if another " +"installed package depends on the one you are trying to remove. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:228 +#, no-wrap +msgid "" +"~]#{nbsp}rpm -e ghostscript\n" +"error: Failed dependencies:\n" +" ghostscript is needed by (installed) " +"ghostscript-cups-9.07-16.{PKGOS}.x86_64\n" +" ghostscript is needed by (installed) " +"foomatic-4.0.9-6.{PKGOS}.x86_64\n" +" libgs.so.9()(64bit) is needed by (installed) " +"libspectre-0.2.7-4.{PKGOS}.x86_64\n" +" libijs-0.35.so()(64bit) is needed by (installed) " +"gutenprint-5.2.9-15.{PKGOS}.x86_64\n" +" libijs-0.35.so()(64bit) is needed by (installed) " +"cups-filters-1.0.35-15.{PKGOS}.x86_64\n" +msgstr "" + +#. type: Block title +#: ./pages/RPM.adoc:231 +#, no-wrap +msgid "Warning: Forcing Package Installation" +msgstr "" + +#. type: delimited block = +#: ./pages/RPM.adoc:236 +msgid "" +"Although you can *force* [command]#rpm# to uninstall a package that has " +"unresolved dependencies (using the [option]`--nodeps` option), this is *not* " +"recommended. Removing packages with [option]`--nodeps` can cause " +"applications from the packages whose dependencies are removed to misbehave " +"or terminate unexpectedly. It can also cause serious package-management " +"problems or system failure. For these reasons, heed the warnings about " +"failed dependencies." +msgstr "" + +#. type: Title === +#: ./pages/RPM.adoc:240 +#, no-wrap +msgid "Freshening Packages" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:243 +msgid "" +"indexterm:[RPM,freshening]indexterm:[packages,RPM,freshening] Freshening is " +"similar to upgrading, except that only installed packages are upgraded. Type " +"the following command at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:247 +#, no-wrap +msgid "[command]#rpm -Fvh _package.rpm_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:250 +msgid "" +"The [option]`-F` (or [option]`--freshen`) option compares the versions of " +"the packages specified on the command line with the versions of packages " +"that are already installed on the system. When a newer version of an " +"already-installed package is processed by the [option]`--freshen` option, it " +"is upgraded to the newer version. However, the [option]`--freshen` option " +"does not install a package if no previously-installed package of the same " +"name exists. This differs from regular upgrading, as an upgrade installs all " +"specified packages regardless of whether or not older versions of the " +"packages are already installed." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:252 +msgid "" +"Freshening works for single packages or package groups. For example, " +"freshening can help if you download a large number of different packages, " +"and you only want to upgrade those packages that are already installed on " +"the system. In this case, issue the following command with the `*.rpm` " +"global expression:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:256 +#, no-wrap +msgid "~]#{nbsp}rpm -Fvh *.rpm\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:259 +msgid "" +"[application]*RPM* then automatically upgrades only those packages that are " +"already installed." +msgstr "" + +#. type: Title === +#: ./pages/RPM.adoc:261 +#, no-wrap +msgid "Querying Packages" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:264 +msgid "" +"indexterm:[RPM,querying]indexterm:[packages,RPM,querying] The " +"[application]*RPM* database stores information about all [application]*RPM* " +"packages installed on the system. It is stored in the `/var/lib/rpm/` " +"directory and is used for many things, including querying what packages are " +"installed, what version each package is, and for calculating changes to " +"files in packages since their installation. To query this database, use the " +"[command]#rpm# command with the [option]`-q` (or [option]`--query`) option:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:267 +#, no-wrap +msgid "rpm -q package_name\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:270 +msgid "" +"This command displays the package name, version, and release number of the " +"installed package _package_name_. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:275 +#, no-wrap +msgid "" +"~]${nbsp}rpm -q tree\n" +"tree-1.7.0-3.{PKGOS}.x86_64\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:278 +msgid "" +"See the `Package Selection Options` subheading in the *rpm*(8) manual page " +"for a list of options that can be used to further refine or qualify your " +"query. Use options listed below the `Package Query Options` subheading to " +"specify what information to display about the queried packages." +msgstr "" + +#. type: Title === +#: ./pages/RPM.adoc:280 +#, no-wrap +msgid "Verifying Packages" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:283 +msgid "" +"indexterm:[RPM,verifying]indexterm:[packages,RPM,verifying] Verifying a " +"package is comparing information about files on the system installed from a " +"package with the same information from the original package. Among other " +"parameters, verifying compares the file size, MD5 sum, permissions, type, " +"owner, and the group of each file." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:285 +msgid "" +"Use the [command]#rpm# command with the [option]`-V` (or [option]`--verify`) " +"option to verify packages. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:289 +#, no-wrap +msgid "~]${nbsp}pass:attributes[{blank}][command]#rpm -V tree#\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:292 +msgid "" +"See the `Package Selection Options` subheading in the *rpm*(8) manual page " +"for a list of options that can be used to further refine or qualify your " +"query. Use options listed below the `Verify Options` subheading to specify " +"what characteristics to verify in the queried packages." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:294 +msgid "" +"If everything verifies properly, there is no output. If there are any " +"discrepancies, they are displayed. The output consists of lines similar to " +"these:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:300 +#, no-wrap +msgid "" +"~]#{nbsp}rpm -V abrt\n" +"S.5....T. c /etc/abrt/abrt.conf\n" +".M....... /var/spool/abrt-upload\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:303 +msgid "" +"The format of the output is a string of nine characters followed by an " +"optional attribute marker and the name of the processed file." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:305 +msgid "" +"The first nine characters are the results of tests performed on the " +"file. Each test is the comparison of one attribute of the file to the value " +"of that attribute as recorded in the [application]*RPM* database. A single " +"period (`.`) means the test passed, and the question-mark character (`?`) " +"signifies that the test could not be performed. The following table lists " +"symbols that denote specific discrepancies:" +msgstr "" + +#. type: Block title +#: ./pages/RPM.adoc:307 ./pages/RPM.adoc:326 +#, no-wrap +msgid "RPM Verification Symbols" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:309 ./pages/RPM.adoc:328 +msgid "indexterm:[RPM,verification]" +msgstr "" + +#. type: Table +#: ./pages/RPM.adoc:321 +#, no-wrap +msgid "" +"|Symbol|Description\n" +"|`S`|file size differs\n" +"|`M`|mode differs (includes permissions and file type)\n" +"|`5`|digest (formerly MD5 sum) differs\n" +"|`D`|device major/minor number mismatch\n" +"|`L`|*readLink*(2) path mismatch\n" +"|`U`|user ownership differs\n" +"|`G`|group ownership differs\n" +"|`T`|mtime differs\n" +"|`P`|capabilities differ\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:324 +msgid "" +"The attribute marker, if present, describes the purpose of the given " +"file. The following table lists the available attribute markers:" +msgstr "" + +#. type: Table +#: ./pages/RPM.adoc:335 +#, no-wrap +msgid "" +"|Marker|Description\n" +"|`c`|configuration file\n" +"|`d`|documentation file\n" +"|`l`|license file\n" +"|`r`|readme file\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:338 +msgid "" +"If you see any output, use your best judgment to determine if you should " +"remove the package, reinstall it, or fix the problem in another way." +msgstr "" + +#. type: Title == +#: ./pages/RPM.adoc:340 +#, no-wrap +msgid "Finding and Verifying RPM Packages" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:343 +msgid "" +"indexterm:[RPM,finding and verifying RPM packages] Before using any " +"[application]*RPM* packages, you must know where to find them and be able to " +"verify if you can trust them." +msgstr "" + +#. type: Title === +#: ./pages/RPM.adoc:345 +#, no-wrap +msgid "Finding RPM Packages" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:348 +msgid "" +"indexterm:[packages,finding Fedora RPM packages]indexterm:[RPM,finding " +"Fedora RPM packages] Although there are many [application]*RPM* repositories " +"on the Internet, for security and compatibility reasons, you should consider " +"installing only official Fedora-provided RPM packages. The following is a " +"list of sources for [application]*RPM* packages:" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:352 +msgid "" +"indexterm:[{MAJOROS} installation media,installable packages] " +"indexterm:[packages,{MAJOROS} installation media] Official {MAJOROS} " +"installation media." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:356 +msgid "" +"indexterm:[initial RPM repositories,installable packages] " +"indexterm:[packages,initial RPM repositories] Official [application]*RPM* " +"repositories provided with the [application]*DNF* package manager. See " +"xref:package-management/DNF.adoc#ch-DNF[DNF] for details on how to use the " +"official {MAJOROS} package repositories." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:358 +msgid "" +"Unofficial, third-party repositories not affiliated with {OSORG} also " +"provide RPM packages." +msgstr "" + +#. type: delimited block = +#: ./pages/RPM.adoc:364 +msgid "" +"When considering third-party repositories for use with your {MAJOROS} " +"system, pay close attention to the repository's web site with regard to " +"package compatibility before adding the repository as a package " +"source. Alternate package repositories may offer different, incompatible " +"versions of the same software, including packages already included in the " +"{MAJOROS} repositories." +msgstr "" + +#. type: Title === +#: ./pages/RPM.adoc:368 +#, no-wrap +msgid "Checking Package Signatures" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:371 +msgid "" +"indexterm:[RPM,GnuPG]indexterm:[RPM,checking package " +"signatures]indexterm:[GnuPG,checking RPM package signatures] " +"[application]*RPM* packages can be signed using [application]*GNU Privacy " +"Guard* (or [application]*GPG*), which helps you make certain that downloaded " +"packages are trustworthy. [application]*GPG* is a tool for secure " +"communication. With [application]*GPG*, you can authenticate the validity of " +"documents and encrypt or decrypt data." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:373 +msgid "" +"To verify that a package has not been corrupted or tampered with, check its " +"[application]*GPG* signature by using the [command]#rpmkeys# command with " +"the [option]`-K` (or [option]`--checksig`) option:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:377 +#, no-wrap +msgid "[command]#rpmkeys -K _package.rpm_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:380 +msgid "" +"Note that the [application]*DNF* package manager performs automatic checking " +"of [application]*GPG* signatures during installations and upgrades." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:382 +msgid "" +"[application]*GPG* is installed by default, as well as a set of Red{nbsp}Hat " +"keys for verifying packages. To import additional keys for use with " +"[application]*RPM*, see xref:RPM.adoc#s2-keys-importing[Importing GPG Keys]." +msgstr "" + +#. type: Title ==== +#: ./pages/RPM.adoc:384 +#, no-wrap +msgid "Importing GPG Keys" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:387 +msgid "" +"To verify Red Hat packages, a Red{nbsp}Hat [application]*GPG* key needs to " +"be installed. A set of basic keys is installed by default. To view a list of " +"installed keys, execute the following command at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:391 +#, no-wrap +msgid "~]${nbsp}rpm -qa gpg-pubkey*\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:394 +msgid "" +"To display details about a specific key, use [command]#rpm{nbsp}-qi# " +"followed by the output from the previous command. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:398 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#rpm -qi " +"gpg-pubkey-fd431d51-4ae0493b#\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:401 +msgid "" +"Use the [command]#rpmkeys# command with the [option]`--import` option to " +"install a new key for use with [application]*RPM*. The default location for " +"storing [application]*RPM* *GPG* keys is the `/etc/pki/rpm-gpg/` " +"directory. To import new keys, use a command like the following as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:405 +#, no-wrap +msgid "~]#{nbsp}rpmkeys --import /etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:408 +msgid "" +"See the link:++https://access.redhat.com/security/team/key/++[Product " +"Signing (GPG) Keys] article on the Red{nbsp}Hat Customer{nbsp}Portal for " +"additional information about Red{nbsp}Hat package-signing practices." +msgstr "" + +#. type: Title == +#: ./pages/RPM.adoc:410 +#, no-wrap +msgid "Common Examples of RPM Usage" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:413 +msgid "" +"indexterm:[RPM,tips]indexterm:[packages,RPM,tips] [application]*RPM* is a " +"useful tool for both managing your system and diagnosing and fixing " +"problems. See the following examples for an overview of some of the " +"most-used options." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:416 +msgid "" +"To verify your entire system and see what files are missing, issue the " +"following command as `root`: indexterm:[RPM,finding deleted files " +"with]indexterm:[packages,finding deleted files from]" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:420 +#, no-wrap +msgid "[command]#rpm -Va#\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:423 +msgid "" +"If some files are missing or appear corrupted, consider reinstalling " +"relevant packages." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:426 +msgid "" +"To determine which package owns a file, enter: indexterm:[RPM,determining " +"file ownership with]indexterm:[packages,determining file ownership with]" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:430 +#, no-wrap +msgid "[command]#rpm -qf _file_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:433 +msgid "To verify the package that owns a particular file, enter as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:437 +#, no-wrap +msgid "[command]#rpm -Vf _file_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:441 +msgid "" +"To locate documentation files that are a part of a package to which a file " +"belongs, enter: indexterm:[RPM,documentation " +"with]indexterm:[packages,locating documentation " +"for]indexterm:[documentation,finding installed]" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:445 +#, no-wrap +msgid "[command]#rpm -qdf _file_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:449 +msgid "" +"To find information about a (non-installed) package file, use the following " +"command: indexterm:[RPM,querying uninstalled " +"packages]indexterm:[packages,querying uninstalled]" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:453 +#, no-wrap +msgid "[command]#rpm -qip _package.rpm_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:457 +msgid "" +"To list files contained in a package, use: indexterm:[RPM,querying for file " +"list]indexterm:[packages,obtaining list of files]" +msgstr "" + +#. type: delimited block - +#: ./pages/RPM.adoc:461 +#, no-wrap +msgid "[command]#rpm -qlp _package.rpm_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:464 +msgid "See the *rpm*(8) manual page for more options." +msgstr "" + +#. type: Title == +#: ./pages/RPM.adoc:466 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:469 +msgid "" +"indexterm:[RPM,additional resources] [application]*RPM* is a complex utility " +"with many options and methods for querying, installing, upgrading, and " +"removing packages. See the following resources to learn more about " +"[application]*RPM*." +msgstr "" + +#. type: Block title +#: ./pages/RPM.adoc:470 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:473 +msgid "" +"[command]#rpm --help# — This command displays a quick reference of " +"[application]*RPM* parameters." +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:475 +#, no-wrap +msgid "" +"*rpm*(8) — The [application]*RPM* manual page offers an overview of all " +"available [application]*RPM* parameters.\n" +msgstr "" + +#. type: Block title +#: ./pages/RPM.adoc:476 +#, no-wrap +msgid "Online Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:479 +msgid "indexterm:[RPM,website]indexterm:[RPM,online documentation]" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:481 +msgid "The [application]*RPM* website — link:++https://rpm.org++[]" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:483 +msgid "" +"The [application]*RPM* mailing list — " +"link:++http://lists.rpm.org/mailman/listinfo/rpm-list++[]" +msgstr "" + +#. type: Block title +#: ./pages/RPM.adoc:484 +#, no-wrap +msgid "See Also" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:487 +msgid "indexterm:[RPM,see also]" +msgstr "" + +#. type: Plain text +#: ./pages/RPM.adoc:488 +msgid "" +"xref:package-management/DNF.adoc#ch-DNF[DNF] describes how to use the " +"[application]*DNF* package manager to search, install, update, and uninstall " +"packages on the command line." +msgstr "" diff --git a/pot/rawhide/pages/Revision_History.pot b/pot/rawhide/pages/Revision_History.pot new file mode 100644 index 00000000000..6e30e34877b --- /dev/null +++ b/pot/rawhide/pages/Revision_History.pot @@ -0,0 +1,262 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/Revision_History.adoc:5 +#, no-wrap +msgid "Revision History" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:8 +msgid "" +"Note that revision numbers relate to the edition of this manual, not to " +"version numbers of Fedora." +msgstr "" + +#. type: Labeled list +#: ./pages/Revision_History.adoc:9 +#, no-wrap +msgid "`1-10`" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:10 +msgid "Tue Oct 30 2018, Petr Bokoč (pbokoc@redhat.com)" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:12 +msgid "Fedora 29 Final release" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:14 +msgid "" +"All external links are now converted to HTTPS where applicable " +"(link:++https://pagure.io/fedora-docs/system-administrators-guide/issue/7++[issue " +"7])" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:16 +msgid "" +"The chapter about *anacron* now mentions that it won't run by default when " +"the system is being powered by a battery " +"(link:++https://pagure.io/fedora-docs/system-administrators-guide/issue/8++[issue " +"8])" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:18 +msgid "" +"Fixed a keyring name in the Kernel Module Authentication chapter " +"(link:++https://pagure.io/fedora-docs/system-administrators-guide/issue/11++[issue " +"11])" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:20 +msgid "Removed mentions of *rsyslog* as a default syslog" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:22 +msgid "Various fixes related to the new publishing system" +msgstr "" + +#. type: Labeled list +#: ./pages/Revision_History.adoc:23 +#, no-wrap +msgid "`1-9`" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:24 +#, no-wrap +msgid "Sun Jun 25, 2017, Ryan (t3rm1n4l@fedoraproject.org)\n" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:26 +msgid "" +"Converted document to asciidocs, updated table refs, removed manual line " +"breaks, fixed formatting and some grammar" +msgstr "" + +#. type: Labeled list +#: ./pages/Revision_History.adoc:27 +#, no-wrap +msgid "`1-8`" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:28 +msgid "Mon Nov 14 2016, Petr Bokoč (pbokoc@redhat.com)" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:30 +msgid "Fedora 25 release of the [citetitle]_System Administrator's Guide_." +msgstr "" + +#. type: Labeled list +#: ./pages/Revision_History.adoc:31 +#, no-wrap +msgid "`1-7`" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:32 +msgid "Tue June 21 2016, Stephen Wadeley (swadeley@redhat.com)" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:34 +msgid "Fedora 24 release of the [citetitle]_System Administrator's Guide_." +msgstr "" + +#. type: Labeled list +#: ./pages/Revision_History.adoc:35 +#, no-wrap +msgid "`1-5`" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:36 +msgid "Mon Nov 02 2015, Stephen Wadeley (swadeley@redhat.com)" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:38 +msgid "Fedora 23 release of the [citetitle]_System Administrator's Guide_." +msgstr "" + +#. type: Labeled list +#: ./pages/Revision_History.adoc:39 +#, no-wrap +msgid "`1-4.1`" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:40 +msgid "Tue Oct 27 2015, Stephen Wadeley (swadeley@redhat.com)" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:42 +msgid "" +"Added \"`Gaining Privileges`\" chapter, \"`Using OpenSSH Certificate " +"Authentication`\" section, and made improvements to the GRUB 2 chapter." +msgstr "" + +#. type: Labeled list +#: ./pages/Revision_History.adoc:43 +#, no-wrap +msgid "`1-4`" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:44 +msgid "Mon May 25 2015, Stephen Wadeley (swadeley@redhat.com)" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:46 +msgid "Fedora 22 release of the [citetitle]_System Administrator's Guide_." +msgstr "" + +#. type: Labeled list +#: ./pages/Revision_History.adoc:47 +#, no-wrap +msgid "`1-3`" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:48 +msgid "Mon Apr 4 2015, Stephen Wadeley (swadeley@redhat.com)" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:50 +msgid "Replaced Yum chapter with DNF chapter." +msgstr "" + +#. type: Labeled list +#: ./pages/Revision_History.adoc:51 +#, no-wrap +msgid "`1-2.1`" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:52 +msgid "Wed Mar 4 2015, Stephen Wadeley (swadeley@redhat.com)" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:54 +msgid "Added \"`Working with the GRUB 2 Boot Loader`\" chapter." +msgstr "" + +#. type: Labeled list +#: ./pages/Revision_History.adoc:55 +#, no-wrap +msgid "`1-2`" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:56 +msgid "Tue Dec 9 2014, Stephen Wadeley (swadeley@redhat.com)" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:58 +msgid "Fedora 21 release of the [citetitle]_System Administrator's Guide_." +msgstr "" + +#. type: Labeled list +#: ./pages/Revision_History.adoc:59 +#, no-wrap +msgid "`1-1`" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:60 +msgid "Thu Aug 9 2012, Jaromír Hradílek (jhradilek@redhat.com)" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:62 +msgid "Updated Network Interfaces." +msgstr "" + +#. type: Labeled list +#: ./pages/Revision_History.adoc:63 +#, no-wrap +msgid "`1-0`" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:64 +msgid "Tue May 29 2012, Jaromír Hradílek (jhradilek@redhat.com)" +msgstr "" + +#. type: Plain text +#: ./pages/Revision_History.adoc:65 +msgid "Fedora 17 release of the [citetitle]_System Administrator's Guide_." +msgstr "" diff --git a/pot/rawhide/pages/Wayland.pot b/pot/rawhide/pages/Wayland.pot new file mode 100644 index 00000000000..731fd7c3e89 --- /dev/null +++ b/pot/rawhide/pages/Wayland.pot @@ -0,0 +1,143 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/Wayland.adoc:6 +#, no-wrap +msgid "The Wayland Protocol" +msgstr "" + +#. type: Plain text +#: ./pages/Wayland.adoc:9 +msgid "" +"Wayland is a display server protocol which was (at the time of writing) " +"introduced as the default in GNOME. It is said that Wayland will eventually " +"replace X11 as the default display server on Linux and many distributions " +"have begun implementation of Wayland. Wayland is a more modern protocol and " +"has a smaller code base currently. Wayland is still under development, and " +"there are still applications and behaviours that don't work as expected, you " +"may find that some applications have not been updated to work properly in " +"Wayland and currently the only way these applications will run is using Xorg " +"instead of Wayland. This includes some legacy system applications and games." +msgstr "" + +#. type: Plain text +#: ./pages/Wayland.adoc:11 +msgid "" +"Wayland is enabled by default in the GNOME Desktop. You can choose to run " +"GNOME in X11 by choosing the Gnome on xorg option in the session chooser on " +"the login screen. Currently KDE still uses X11 and although there is a " +"plasma-wayland session available, it is not considered stable or bugfree at " +"this time." +msgstr "" + +#. type: Title == +#: ./pages/Wayland.adoc:12 +#, no-wrap +msgid "Determining whether you are using Wayland" +msgstr "" + +#. type: Plain text +#: ./pages/Wayland.adoc:14 +msgid "" +"One way to determine if you're running in Wayland, is to check the value of " +"the variable $WAYLAND_DISPLAY. To do this type:" +msgstr "" + +#. type: delimited block - +#: ./pages/Wayland.adoc:19 +#, no-wrap +msgid "" +"$ echo $WAYLAND_DISPLAY\n" +"wayland-0\n" +msgstr "" + +#. type: Plain text +#: ./pages/Wayland.adoc:22 +msgid "" +"If you are not running under Wayland the variable will not contain any " +"values. You can also use loginctl to show you what type of session is " +"running:" +msgstr "" + +#. type: delimited block - +#: ./pages/Wayland.adoc:26 +#, no-wrap +msgid "$ loginctl show-session -p Type\n" +msgstr "" + +#. type: Plain text +#: ./pages/Wayland.adoc:29 +msgid "" +"To determine your session number, simply typing `loginctl` should provide " +"your session details." +msgstr "" + +#. type: Plain text +#: ./pages/Wayland.adoc:31 +msgid "" +"There is also a legacy X11 server provided with Wayland for compatibility " +"purposes. To determine what applications are running in this mode, you can " +"run the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/Wayland.adoc:35 +#, no-wrap +msgid "$ xlsclients\n" +msgstr "" + +#. type: Plain text +#: ./pages/Wayland.adoc:38 +msgid "" +"There is also the `lg` (looking glass) tool in GNOME that will allow you to " +"determine which protocol a specific window is using. To do this, you run the " +"application by typing `lg` in the run dialog or at the command line, select " +"\"`Windows`\" in the upper right corner of the tool, and click on the " +"application name (or open window) you want to know about. If the window is " +"running in wayland it will say \"`MetaWindowWayland`\" and if it is running " +"in X11 it will say \"`MetaWindowX11`\"." +msgstr "" + +#. type: Title == +#: ./pages/Wayland.adoc:39 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/Wayland.adoc:41 +msgid "To find out more about Wayland, please see the following website:" +msgstr "" + +#. type: Plain text +#: ./pages/Wayland.adoc:43 +msgid "https://wayland.freedesktop.org/" +msgstr "" + +#. type: Plain text +#: ./pages/Wayland.adoc:45 +msgid "" +"If you need to determine if an issue you are experiencing is related to " +"wayland, see the Fedora wiki at the link below:" +msgstr "" + +#. type: Plain text +#: ./pages/Wayland.adoc:46 +msgid "https://fedoraproject.org/wiki/How_to_debug_Wayland_problems" +msgstr "" diff --git a/pot/rawhide/pages/_partials/Author_Group.pot b/pot/rawhide/pages/_partials/Author_Group.pot new file mode 100644 index 00000000000..2cb1f32e597 --- /dev/null +++ b/pot/rawhide/pages/_partials/Author_Group.pot @@ -0,0 +1,151 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Block title +#: ./pages/_partials/Author_Group.adoc:1 +#, no-wrap +msgid "Stephen Wadeley" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Author_Group.adoc:5 ./pages/_partials/Author_Group.adoc:12 +#: ./pages/_partials/Author_Group.adoc:26 +#: ./pages/_partials/Author_Group.adoc:33 +#: ./pages/_partials/Author_Group.adoc:40 +#: ./pages/_partials/Author_Group.adoc:47 +#: ./pages/_partials/Author_Group.adoc:52 +#: ./pages/_partials/Author_Group.adoc:57 +#: ./pages/_partials/Author_Group.adoc:62 +#: ./pages/_partials/Author_Group.adoc:67 +#: ./pages/_partials/Author_Group.adoc:72 +#: ./pages/_partials/Author_Group.adoc:76 +#, no-wrap +msgid "" +"*Red Hat*\n" +"Customer Content Services\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Author_Group.adoc:7 +msgid "swadeley@redhat.com" +msgstr "" + +#. type: Block title +#: ./pages/_partials/Author_Group.adoc:8 +#, no-wrap +msgid "Jaromír Hradílek" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Author_Group.adoc:14 +msgid "jhradilek@redhat.com" +msgstr "" + +#. type: Block title +#: ./pages/_partials/Author_Group.adoc:15 +#, no-wrap +msgid "Petr Bokoč" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Author_Group.adoc:19 +#, no-wrap +msgid "" +"*Red{nbsp}Hat*\n" +"Customer Content Services\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Author_Group.adoc:21 +msgid "pbokoc@redhat.com" +msgstr "" + +#. type: Block title +#: ./pages/_partials/Author_Group.adoc:22 +#, no-wrap +msgid "Petr Kovář" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Author_Group.adoc:28 +msgid "pkovar@redhat.com" +msgstr "" + +#. type: Block title +#: ./pages/_partials/Author_Group.adoc:29 +#, no-wrap +msgid "Tomáš Čapek" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Author_Group.adoc:35 +msgid "tcapek@redhat.com" +msgstr "" + +#. type: Block title +#: ./pages/_partials/Author_Group.adoc:36 +#, no-wrap +msgid "Douglas Silas" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Author_Group.adoc:42 +msgid "silas@redhat.com" +msgstr "" + +#. type: Block title +#: ./pages/_partials/Author_Group.adoc:43 +#, no-wrap +msgid "Martin Prpič" +msgstr "" + +#. type: Block title +#: ./pages/_partials/Author_Group.adoc:48 +#, no-wrap +msgid "Eliška Slobodová" +msgstr "" + +#. type: Block title +#: ./pages/_partials/Author_Group.adoc:53 +#, no-wrap +msgid "Miroslav Svoboda" +msgstr "" + +#. type: Block title +#: ./pages/_partials/Author_Group.adoc:58 +#, no-wrap +msgid "John Ha" +msgstr "" + +#. type: Block title +#: ./pages/_partials/Author_Group.adoc:63 +#, no-wrap +msgid "David O'Brien" +msgstr "" + +#. type: Block title +#: ./pages/_partials/Author_Group.adoc:68 +#, no-wrap +msgid "Michael Hideo" +msgstr "" + +#. type: Block title +#: ./pages/_partials/Author_Group.adoc:73 +#, no-wrap +msgid "Don Domingo" +msgstr "" diff --git a/pot/rawhide/pages/_partials/Feedback.pot b/pot/rawhide/pages/_partials/Feedback.pot new file mode 100644 index 00000000000..ad411271378 --- /dev/null +++ b/pot/rawhide/pages/_partials/Feedback.pot @@ -0,0 +1,81 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title == +#: ./pages/_partials/Feedback.adoc:5 +#, no-wrap +msgid "We want feedback" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Feedback.adoc:8 +msgid "" +"indexterm:[feedback,contact information for this manual] If you find errors " +"or have suggestions for improvement, we want your advice. Open an issue at " +"{BZURL}." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Feedback.adoc:10 +msgid "In the issue:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Feedback.adoc:12 +msgid "" +"Provide a short summary of the error or your suggestion in the `Issue Title` " +"field." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Feedback.adoc:14 +msgid "" +"Copy the following template into the `Comment` field and give us the details " +"of the error or suggestion as specifically as you can. If possible, include " +"some surrounding text so we know where the error occurs or the suggestion " +"fits." +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/Feedback.adoc:18 +#, no-wrap +msgid "Document URL:\n" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/Feedback.adoc:20 +#, no-wrap +msgid "Section name:\n" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/Feedback.adoc:22 +#, no-wrap +msgid "Error or suggestion:\n" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/Feedback.adoc:24 +#, no-wrap +msgid "Additional information:\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Feedback.adoc:27 +msgid "Click the btn:[Create Issue] button." +msgstr "" diff --git a/pot/rawhide/pages/_partials/Legal_Notice.pot b/pot/rawhide/pages/_partials/Legal_Notice.pot new file mode 100644 index 00000000000..e8a7be041c9 --- /dev/null +++ b/pot/rawhide/pages/_partials/Legal_Notice.pot @@ -0,0 +1,93 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Plain text +#: ./pages/_partials/Legal_Notice.adoc:5 +msgid "Copyright {YEAR} {HOLDER}." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Legal_Notice.adoc:7 +msgid "" +"The text of and illustrations in this document are licensed by Red Hat under " +"a Creative Commons Attribution–Share Alike 3.0 Unported license " +"(“CC-BY-SA”). An explanation of CC-BY-SA is available at " +"link:++https://creativecommons.org/licenses/by-sa/3.0/++[]. The original " +"authors of this document, and Red Hat, designate the Fedora Project as the " +"“`Attribution Party`” for purposes of CC-BY-SA. In accordance with CC-BY-SA, " +"if you distribute this document or an adaptation of it, you must provide the " +"URL for the original version." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Legal_Notice.adoc:9 +msgid "" +"Red Hat, as the licensor of this document, waives the right to enforce, and " +"agrees not to assert, Section 4d of CC-BY-SA to the fullest extent permitted " +"by applicable law." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Legal_Notice.adoc:11 +msgid "" +"Red Hat, Red Hat Enterprise Linux, the Shadowman logo, JBoss, MetaMatrix, " +"Fedora, the Infinity Logo, and RHCE are trademarks of Red Hat, Inc., " +"registered in the United States and other countries." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Legal_Notice.adoc:13 +msgid "" +"For guidelines on the permitted uses of the Fedora trademarks, refer to " +"link:++https://fedoraproject.org/wiki/Legal:Trademark_guidelines++[]." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Legal_Notice.adoc:15 +#, no-wrap +msgid "" +"*Linux* (R) is the registered trademark of Linus Torvalds in the United " +"States and other countries.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Legal_Notice.adoc:17 +#, no-wrap +msgid "*Java* (R) is a registered trademark of Oracle and/or its affiliates.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Legal_Notice.adoc:19 +#, no-wrap +msgid "" +"*XFS* (R) is a trademark of Silicon Graphics International Corp. or its " +"subsidiaries in the United States and/or other countries.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Legal_Notice.adoc:21 +#, no-wrap +msgid "" +"*MySQL* (R) is a registered trademark of MySQL AB in the United States, the " +"European Union and other countries.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/Legal_Notice.adoc:22 +msgid "All other trademarks are the property of their respective owners." +msgstr "" diff --git a/pot/rawhide/pages/_partials/entities.pot b/pot/rawhide/pages/_partials/entities.pot new file mode 100644 index 00000000000..ab56d661a0f --- /dev/null +++ b/pot/rawhide/pages/_partials/entities.pot @@ -0,0 +1,18 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + diff --git a/pot/rawhide/pages/_partials/servers/FTP.pot b/pot/rawhide/pages/_partials/servers/FTP.pot new file mode 100644 index 00000000000..5ca6457ccd1 --- /dev/null +++ b/pot/rawhide/pages/_partials/servers/FTP.pot @@ -0,0 +1,1658 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title == +#: ./pages/_partials/servers/FTP.adoc:3 +#, no-wrap +msgid "FTP" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:6 +msgid "" +"indexterm:[FTP,definition of]indexterm:[FTP,vsftpd] _File Transfer Protocol_ " +"(`FTP`) is one of the oldest and most commonly used protocols found on the " +"Internet today. Its purpose is to reliably transfer files between computer " +"hosts on a network without requiring the user to log directly into the " +"remote host or have knowledge of how to use the remote system. It allows " +"users to access files on remote systems using a standard set of simple " +"commands." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:8 +msgid "" +"This section outlines the basics of the `FTP` protocol, as well as " +"configuration options for the primary `FTP` server shipped with {MAJOROS}, " +"[command]#vsftpd#." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/FTP.adoc:10 +#, no-wrap +msgid "The File Transfer Protocol" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:13 +msgid "" +"indexterm:[FTP,introducing] However, because `FTP` is so prevalent on the " +"Internet, it is often required to share files to the public. System " +"administrators, therefore, should be aware of the `FTP` protocol's unique " +"characteristics." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/FTP.adoc:15 +#, no-wrap +msgid "Multiple Ports, Multiple Modes" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:18 +msgid "" +"indexterm:[FTP,command port]indexterm:[FTP,data port]indexterm:[FTP,active " +"mode]indexterm:[FTP,passive mode] Unlike most protocols used on the " +"Internet, `FTP` requires multiple network ports to work properly. When an " +"`FTP` client application initiates a connection to an `FTP` server, it opens " +"port 21 on the server — known as the _command port_. This port is used to " +"issue all commands to the server. Any data requested from the server is " +"returned to the client via a _data port_. The port number for data " +"connections, and the way in which data connections are initialized, vary " +"depending upon whether the client requests the data in _active_ or _passive_ " +"mode." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:20 +msgid "The following defines these modes:" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/FTP.adoc:21 +#, no-wrap +msgid "active mode" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:22 +msgid "" +"Active mode is the original method used by the `FTP` protocol for " +"transferring data to the client application. When an active mode data " +"transfer is initiated by the `FTP` client, the server opens a connection " +"from port 20 on the server to the `IP` address and a random, unprivileged " +"port (greater than 1024) specified by the client. This arrangement means " +"that the client machine must be allowed to accept connections over any port " +"above 1024. With the growth of insecure networks, such as the Internet, the " +"use of firewalls to protect client machines is now prevalent. Because these " +"client-side firewalls often deny incoming connections from active mode `FTP` " +"servers, passive mode was devised." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/FTP.adoc:23 +#, no-wrap +msgid "passive mode" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:24 +msgid "" +"Passive mode, like active mode, is initiated by the `FTP` client " +"application. When requesting data from the server, the `FTP` client " +"indicates it wants to access the data in passive mode and the server " +"provides the `IP` address and a random, unprivileged port (greater than " +"1024) on the server. The client then connects to that port on the server to " +"download the requested information." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:26 +msgid "" +"While passive mode resolves issues for client-side firewall interference " +"with data connections, it can complicate administration of the server-side " +"firewall. You can reduce the number of open ports on a server by limiting " +"the range of unprivileged ports on the `FTP` server. This also simplifies " +"the process of configuring firewall rules for the server. See " +"xref:File_and_Print_Servers.adoc#s3-ftp-vsftpd-conf-opt-net[Network Options] " +"for more information about limiting passive ports." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/FTP.adoc:28 +#, no-wrap +msgid "FTP Servers" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:31 +msgid "" +"indexterm:[FTP,server software,vsftpd]indexterm:[FTP,server software,Red Hat " +"Content Accelerator]indexterm:[vsftpd,FTP]indexterm:[vsftpd,security " +"features] {MAJOROS} ships with two different `FTP` servers:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:33 +msgid "[command]#proftpd# - A fast, stable, and highly configurable FTP server." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:35 +msgid "" +"[command]#vsftpd# — A fast, secure `FTP` daemon which is the preferred `FTP` " +"server for {MAJOROS}. The remainder of this section focuses on " +"[command]#vsftpd#." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/FTP.adoc:37 +#, no-wrap +msgid "[command]#vsftpd#" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:40 +msgid "" +"_The Very Secure FTP Daemon_ ([command]#vsftpd#) is designed from the ground " +"up to be fast, stable, and, most importantly, secure. [command]#vsftpd# is " +"the only stand-alone `FTP` server distributed with {MAJOROS}, due to its " +"ability to handle large numbers of connections efficiently and securely." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:42 +msgid "The security model used by [command]#vsftpd# has three primary aspects:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:44 +#, no-wrap +msgid "" +"*Strong separation of privileged and non-privileged processes* — Separate " +"processes handle different tasks, and each of these processes run with the " +"minimal privileges required for the task.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:46 +#, no-wrap +msgid "" +"*Tasks requiring elevated privileges are handled by processes with the " +"minimal privilege necessary* — By leveraging compatibilities found in the " +"`libcap` library, tasks that usually require full `root` privileges can be " +"executed more safely from a less privileged process.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:48 +#, no-wrap +msgid "" +"*Most processes run in a [command]#chroot# jail* — Whenever possible, " +"processes are change-rooted to the directory being shared; this directory is " +"then considered a [command]#chroot# jail. For example, if the directory " +"[command]#/var/ftp/# is the primary shared directory, [command]#vsftpd# " +"reassigns [command]#/var/ftp/# to the new root directory, known as " +"[command]#/#. This disallows any potential malicious hacker activities for " +"any directories not contained below the new root directory.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:50 +msgid "" +"Use of these security practices has the following effect on how " +"[command]#vsftpd# deals with requests:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:52 +#, no-wrap +msgid "" +"*The parent process runs with the least privileges required* — The parent " +"process dynamically calculates the level of privileges it requires to " +"minimize the level of risk. Child processes handle direct interaction with " +"the `FTP` clients and run with as close to no privileges as possible.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:54 +#, no-wrap +msgid "" +"*All operations requiring elevated privileges are handled by a small parent " +"process* — Much like the Apache `HTTP` Server, [command]#vsftpd# launches " +"unprivileged child processes to handle incoming connections. This allows the " +"privileged, parent process to be as small as possible and handle relatively " +"few tasks.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:56 +#, no-wrap +msgid "" +"*All requests from unprivileged child processes are distrusted by the parent " +"process* — Communication with child processes are received over a socket, " +"and the validity of any information from child processes is checked before " +"being acted on.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:58 +#, no-wrap +msgid "" +"*Most interaction with `FTP` clients is handled by unprivileged child " +"processes in a [command]#chroot# jail* — Because these child processes are " +"unprivileged and only have access to the directory being shared, any crashed " +"processes only allows the attacker access to the shared files.\n" +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/FTP.adoc:60 +#, no-wrap +msgid "Files Installed with [command]#vsftpd#" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:63 +msgid "" +"indexterm:[vsftpd,RPM,files installed by] The `vsftpd` RPM installs the " +"daemon (`/usr/sbin/vsftpd`), its configuration and related files, as well as " +"`FTP` directories onto the system. The following lists the files and " +"directories related to [command]#vsftpd# configuration:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:65 +msgid "" +"`/etc/rc.d/init.d/vsftpd` — The *initialization script* (_initscript_) used " +"by the [command]#systemctl# command to start, stop, or reload " +"[command]#vsftpd#. See " +"xref:File_and_Print_Servers.adoc#s2-ftp-vsftpd-start[Starting and Stopping " +"[command]#vsftpd#] for more information about using this script." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:67 +msgid "" +"`/etc/pam.d/vsftpd` — The Pluggable Authentication Modules (PAM) " +"configuration file for [command]#vsftpd#. This file specifies the " +"requirements a user must meet to login to the `FTP` server. For more " +"information on PAM, refer to the [citetitle]_Using Pluggable Authentication " +"Modules (PAM)_ chapter of the {MAJOROSVER} [citetitle]_Managing Single " +"Sign-On and Smart Cards_ guide." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:69 +msgid "" +"`/etc/vsftpd/vsftpd.conf` — The configuration file for " +"[command]#vsftpd#. See " +"xref:File_and_Print_Servers.adoc#s2-ftp-vsftpd-conf[[command]#vsftpd# " +"Configuration Options] for a list of important options contained within this " +"file." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:71 +msgid "" +"`/etc/vsftpd/ftpusers` — A list of users not allowed to log into " +"[command]#vsftpd#. By default, this list includes the `root`, `bin`, and " +"`daemon` users, among others." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:73 +msgid "" +"`/etc/vsftpd/user_list` — This file can be configured to either deny or " +"allow access to the users listed, depending on whether the " +"[command]#userlist_deny# directive is set to [command]#YES# (default) or " +"[command]#NO# in `/etc/vsftpd/vsftpd.conf`. If `/etc/vsftpd/user_list` is " +"used to grant access to users, the usernames listed must *not* appear in " +"`/etc/vsftpd/ftpusers`." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:75 +msgid "" +"`/var/ftp/` — The directory containing files served by [command]#vsftpd#. It " +"also contains the `/var/ftp/pub/` directory for anonymous users. Both " +"directories are world-readable, but writable only by the `root` user." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/FTP.adoc:77 +#, no-wrap +msgid "Starting and Stopping [command]#vsftpd#" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:80 +msgid "" +"indexterm:[vsftpd,starting]indexterm:[vsftpd,stopping]indexterm:[vsftpd,status]indexterm:[vsftpd,condrestart]indexterm:[vsftpd,restarting] " +"The `vsftpd` RPM installs the `/etc/rc.d/init.d/vsftpd` script, which can be " +"accessed using the [command]#systemctl# command." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:82 +msgid "To start the server, as `root` type:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/FTP.adoc:86 +#, no-wrap +msgid "[command]#systemctl start vsftpd.service#\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:89 +msgid "To stop the server, as `root` type:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/FTP.adoc:93 +#, no-wrap +msgid "[command]#systemctl stop vsftpd.service#\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:96 +msgid "" +"The [option]`restart` option is a shorthand way of stopping and then " +"starting [command]#vsftpd#. This is the most efficient way to make " +"configuration changes take effect after editing the configuration file for " +"[command]#vsftpd#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:98 +msgid "To restart the server, as `root` type:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/FTP.adoc:102 +#, no-wrap +msgid "[command]#systemctl restart vsftpd.service#\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:105 +msgid "" +"The [option]`condrestart` (_conditional restart_) option only starts " +"[command]#vsftpd# if it is currently running. This option is useful for " +"scripts, because it does not start the daemon if it is not running." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:107 +msgid "To conditionally restart the server, as `root` type:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/FTP.adoc:111 +#, no-wrap +msgid "[command]#systemctl condrestart vsftpd.service#\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:114 +msgid "" +"By default, the [command]#vsftpd# service does *not* start automatically at " +"boot time. To configure the [command]#vsftpd# service to start at boot time, " +"use a service manager such as [command]#systemctl#. See " +"xref:infrastructure-services/Services_and_Daemons.adoc#ch-Services_and_Daemons[Services " +"and Daemons] for more information on how to configure services in {MAJOROS}." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/FTP.adoc:116 +#, no-wrap +msgid "Configuring the Firewall for FTP" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:118 +msgid "" +"By default, `firewalld` blocks incoming FTP connections. To allow FTP " +"connections, as `root` type:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/FTP.adoc:122 +#, no-wrap +msgid "[command]#firewall-cmd --add-service=ftp#\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:125 +msgid "" +"The change will be applied immediately, but will be lost next time " +"`firewalld` is reloaded or the system restarted. To make it permanent, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/FTP.adoc:129 +#, no-wrap +msgid "[command]#firewall-cmd --permanent --add-service=ftp#\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:132 +msgid "" +"For more information on configuring `firewalld`, see the " +"link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Security_Guide/++[Red{nbsp}Hat " +"Enterprise{nbsp}Linux{nbsp}7 Security Guide]." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/FTP.adoc:134 +#, no-wrap +msgid "Starting Multiple Copies of [command]#vsftpd#" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:137 +msgid "" +"indexterm:[vsftpd,starting multiple copies of]indexterm:[vsftpd,multihome " +"configuration] Sometimes one computer is used to serve multiple `FTP` " +"domains. This is a technique called _multihoming_. One way to multihome " +"using [command]#vsftpd# is by running multiple copies of the daemon, each " +"with its own configuration file." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:139 +msgid "" +"To do this, first assign all relevant `IP` addresses to network devices or " +"alias network devices on the system. For more information about configuring " +"network devices, device aliases, and additional information about network " +"configuration scripts, refer to the " +"[citetitle]_link:++https://docs.fedoraproject.org/en-US/Fedora/networking++[{MAJOROS} " +"Networking Guide]_." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:141 +msgid "" +"Next, the DNS server for the `FTP` domains must be configured to reference " +"the correct machine. For information about BIND and its configuration files, " +"refer to the " +"[citetitle]_link:++https://docs.fedoraproject.org/en-US/Fedora/networking++[{MAJOROS} " +"Networking Guide]_." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:143 +msgid "" +"If there is more configuration files present in the `/etc/vsftpd` directory, " +"calling [command]#systemctl start vsftpd.service# results in the " +"`/etc/rc.d/init.d/vsftpd` initscript starting the same number of processes " +"as the number of configuration files. Each configuration file must have a " +"unique name in the `/etc/vsftpd/` directory and must be readable and " +"writable only by `root`." +msgstr "" + +#. type: Title ===== +#: ./pages/_partials/servers/FTP.adoc:145 +#, no-wrap +msgid "[command]#vsftpd# Configuration Options" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:148 +msgid "" +"indexterm:[vsftpd,configuration file,format " +"of]indexterm:[vsftpd,configuration file,/etc/vsftpd/vsftpd.conf] Although " +"[command]#vsftpd# may not offer the level of customization other widely " +"available `FTP` servers have, it offers enough options to fill most " +"administrator's needs. The fact that it is not overly feature-laden limits " +"configuration and programmatic errors." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:150 +msgid "" +"All configuration of [command]#vsftpd# is handled by its configuration file, " +"`/etc/vsftpd/vsftpd.conf`. Each directive is on its own line within the file " +"and follows the following format:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/FTP.adoc:154 +#, no-wrap +msgid "_directive_pass:attributes[{blank}]=pass:attributes[{blank}]_value_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:157 +msgid "" +"For each directive, replace _directive_ with a valid directive and _value_ " +"with a valid value." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/FTP.adoc:158 +#, no-wrap +msgid "Do not use spaces" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/FTP.adoc:163 +msgid "" +"There must not be any spaces between the _directive_, equal symbol, and the " +"_value_ in a directive." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:167 +msgid "" +"Comment lines must be preceded by a hash sign ([command]###) and are ignored " +"by the daemon." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:169 +msgid "" +"For a complete list of all directives available, refer to the man page for " +"`vsftpd.conf`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/FTP.adoc:170 +#, no-wrap +msgid "Securing the vsftpd service" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/FTP.adoc:175 +msgid "" +"For an overview of ways to secure [command]#vsftpd#, see the " +"link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Security_Guide/++[Red{nbsp}Hat " +"Enterprise{nbsp}Linux{nbsp}7 Security Guide]." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:179 +msgid "" +"The following is a list of some of the more important directives within " +"`/etc/vsftpd/vsftpd.conf`. All directives not explicitly found or commented " +"out within [command]#vsftpd#pass:attributes[{blank}]'s configuration file " +"are set to their default value." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/FTP.adoc:181 +#, no-wrap +msgid "Daemon Options" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:184 +msgid "" +"indexterm:[vsftpd,configuration file,daemon options] The following is a list " +"of directives which control the overall behavior of the [command]#vsftpd# " +"daemon." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:186 +msgid "" +"[command]#listen# — When enabled, [command]#vsftpd# runs in stand-alone " +"mode. {MAJOROS} sets this value to [command]#YES#. This directive cannot be " +"used in conjunction with the [command]#listen_ipv6# directive." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:188 +#: ./pages/_partials/servers/FTP.adoc:192 +#: ./pages/_partials/servers/FTP.adoc:223 +#: ./pages/_partials/servers/FTP.adoc:260 +#: ./pages/_partials/servers/FTP.adoc:268 +#: ./pages/_partials/servers/FTP.adoc:280 +#: ./pages/_partials/servers/FTP.adoc:286 +#: ./pages/_partials/servers/FTP.adoc:301 +#: ./pages/_partials/servers/FTP.adoc:309 +#: ./pages/_partials/servers/FTP.adoc:321 +#: ./pages/_partials/servers/FTP.adoc:337 +#: ./pages/_partials/servers/FTP.adoc:358 +#: ./pages/_partials/servers/FTP.adoc:362 +#: ./pages/_partials/servers/FTP.adoc:370 +#: ./pages/_partials/servers/FTP.adoc:374 +#: ./pages/_partials/servers/FTP.adoc:387 +#: ./pages/_partials/servers/FTP.adoc:404 +#: ./pages/_partials/servers/FTP.adoc:408 +#: ./pages/_partials/servers/FTP.adoc:412 +#: ./pages/_partials/servers/FTP.adoc:541 +msgid "The default value is [command]#NO#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:190 +msgid "" +"[command]#listen_ipv6# — When enabled, [command]#vsftpd# runs in stand-alone " +"mode, but listens only to `IPv6` sockets. This directive cannot be used in " +"conjunction with the [command]#listen# directive." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:194 +msgid "" +"[command]#session_support# — When enabled, [command]#vsftpd# attempts to " +"maintain login sessions for each user through Pluggable Authentication " +"Modules (PAM). For more information, refer to the [citetitle]_Using " +"Pluggable Authentication Modules (PAM)_ chapter of the Red Hat Enterprise " +"Linux 6 [citetitle]_Managing Single Sign-On and Smart Cards_ and the PAM man " +"pages. . If session logging is not necessary, disabling this option allows " +"[command]#vsftpd# to run with less processes and lower privileges." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:196 +#: ./pages/_partials/servers/FTP.adoc:205 +#: ./pages/_partials/servers/FTP.adoc:231 +#: ./pages/_partials/servers/FTP.adoc:243 +#: ./pages/_partials/servers/FTP.adoc:272 +#: ./pages/_partials/servers/FTP.adoc:295 +#: ./pages/_partials/servers/FTP.adoc:350 +#: ./pages/_partials/servers/FTP.adoc:383 +#: ./pages/_partials/servers/FTP.adoc:395 +#: ./pages/_partials/servers/FTP.adoc:521 +#: ./pages/_partials/servers/FTP.adoc:545 +msgid "The default value is [command]#YES#." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/FTP.adoc:198 +#, no-wrap +msgid "Log In Options and Access Controls" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:201 +msgid "" +"indexterm:[vsftpd,configuration file,login " +"options]indexterm:[vsftpd,configuration file,access controls] The following " +"is a list of directives which control the login behavior and access control " +"mechanisms." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:203 +msgid "" +"[command]#anonymous_enable# — When enabled, anonymous users are allowed to " +"log in. The usernames `anonymous` and `ftp` are accepted." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:207 +msgid "" +"See xref:File_and_Print_Servers.adoc#s3-ftp-vsftpd-conf-opt-anon[Anonymous " +"User Options] for a list of directives affecting anonymous users." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:209 +msgid "" +"[command]#banned_email_file# — If the [command]#deny_email_enable# directive " +"is set to [command]#YES#, this directive specifies the file containing a " +"list of anonymous email passwords which are not permitted access to the " +"server." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:211 +msgid "The default value is `/etc/vsftpd/banned_emails`." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:213 +msgid "" +"[command]#banner_file# — Specifies the file containing text displayed when a " +"connection is established to the server. This option overrides any text " +"specified in the [command]#ftpd_banner# directive." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:215 +#: ./pages/_partials/servers/FTP.adoc:219 +#: ./pages/_partials/servers/FTP.adoc:264 +#: ./pages/_partials/servers/FTP.adoc:329 +#: ./pages/_partials/servers/FTP.adoc:341 +#: ./pages/_partials/servers/FTP.adoc:477 +#: ./pages/_partials/servers/FTP.adoc:489 +#: ./pages/_partials/servers/FTP.adoc:517 +msgid "There is no default value for this directive." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:217 +msgid "" +"[command]#cmds_allowed# — Specifies a comma-delimited list of `FTP` commands " +"allowed by the server. All other commands are rejected." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:221 +msgid "" +"[command]#deny_email_enable# — When enabled, any anonymous user utilizing " +"email passwords specified in the `/etc/vsftpd/banned_emails` are denied " +"access to the server. The name of the file referenced by this directive can " +"be specified using the [command]#banned_email_file# directive." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:225 +msgid "" +"[command]#ftpd_banner# — When enabled, the string specified within this " +"directive is displayed when a connection is established to the server. This " +"option can be overridden by the [command]#banner_file# directive." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:227 +msgid "By default [command]#vsftpd# displays its standard banner." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:229 +msgid "" +"[command]#local_enable# — When enabled, local users are allowed to log into " +"the system." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:233 +msgid "" +"See xref:File_and_Print_Servers.adoc#s3-ftp-vsftpd-conf-opt-usr[Local User " +"Options] for a list of directives affecting local users." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:235 +msgid "" +"[command]#pam_service_name# — Specifies the PAM service name for " +"[command]#vsftpd#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:237 +msgid "" +"The default value is [command]#ftp#. Note, in {MAJOROS}, the value is set to " +"[command]#vsftpd#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:239 +#: ./pages/_partials/servers/FTP.adoc:354 +#: ./pages/_partials/servers/FTP.adoc:420 +#: ./pages/_partials/servers/FTP.adoc:428 +#: ./pages/_partials/servers/FTP.adoc:457 +msgid "" +"The default value is [command]#NO#. Note, in {MAJOROS}, the value is set to " +"[command]#YES#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:241 +msgid "" +"[command]#userlist_deny# — When used in conjunction with the " +"[command]#userlist_enable# directive and set to [command]#NO#, all local " +"users are denied access unless the username is listed in the file specified " +"by the [command]#userlist_file# directive. Because access is denied before " +"the client is asked for a password, setting this directive to [command]#NO# " +"prevents local users from submitting unencrypted passwords over the network." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:245 +msgid "" +"[command]#userlist_enable# — When enabled, the users listed in the file " +"specified by the [command]#userlist_file# directive are denied " +"access. Because access is denied before the client is asked for a password, " +"users are prevented from submitting unencrypted passwords over the network." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:247 +msgid "" +"The default value is [command]#NO#, however under {MAJOROS} the value is set " +"to [command]#YES#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:249 +msgid "" +"[command]#userlist_file# — Specifies the file referenced by " +"[command]#vsftpd# when the [command]#userlist_enable# directive is enabled." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:251 +msgid "" +"The default value is [command]#/etc/vsftpd/user_list# and is created during " +"installation." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/FTP.adoc:253 +#, no-wrap +msgid "Anonymous User Options" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:256 +msgid "" +"indexterm:[vsftpd,configuration file,anonymous user options] The following " +"lists directives which control anonymous user access to the server. To use " +"these options, the [command]#anonymous_enable# directive must be set to " +"[command]#YES#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:258 +msgid "" +"[command]#anon_mkdir_write_enable# — When enabled in conjunction with the " +"[command]#write_enable# directive, anonymous users are allowed to create new " +"directories within a parent directory which has write permissions." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:262 +msgid "" +"[command]#anon_root# — Specifies the directory [command]#vsftpd# changes to " +"after an anonymous user logs in." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:266 +msgid "" +"[command]#anon_upload_enable# — When enabled in conjunction with the " +"[command]#write_enable# directive, anonymous users are allowed to upload " +"files within a parent directory which has write permissions." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:270 +msgid "" +"[command]#anon_world_readable_only# — When enabled, anonymous users are only " +"allowed to download world-readable files." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:274 +msgid "" +"[command]#ftp_username# — Specifies the local user account (listed in " +"`/etc/passwd`) used for the anonymous `FTP` user. The home directory " +"specified in `/etc/passwd` for the user is the root directory of the " +"anonymous `FTP` user." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:276 +#: ./pages/_partials/servers/FTP.adoc:325 +msgid "The default value is [command]#ftp#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:278 +msgid "" +"[command]#no_anon_password# — When enabled, the anonymous user is not asked " +"for a password." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:282 +msgid "" +"[command]#secure_email_list_enable# — When enabled, only a specified list of " +"email passwords for anonymous logins are accepted. This is a convenient way " +"to offer limited security to public content without the need for virtual " +"users." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:284 +msgid "" +"Anonymous logins are prevented unless the password provided is listed in " +"[command]#/etc/vsftpd/email_passwords#. The file format is one password per " +"line, with no trailing white spaces." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/FTP.adoc:288 +#, no-wrap +msgid "Local User Options" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:291 +msgid "" +"indexterm:[vsftpd,configuration file,local user options] The following lists " +"directives which characterize the way local users access the server. To use " +"these options, the [command]#local_enable# directive must be set to " +"[command]#YES#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:293 +msgid "" +"[command]#chmod_enable# — When enabled, the `FTP` command [command]#SITE " +"CHMOD# is allowed for local users. This command allows the users to change " +"the permissions on files." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:297 +msgid "" +"[command]#chroot_list_enable# — When enabled, the local users listed in the " +"file specified in the [command]#chroot_list_file# directive are placed in a " +"[command]#chroot# jail upon log in." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:299 +msgid "" +"If enabled in conjunction with the [command]#chroot_local_user# directive, " +"the local users listed in the file specified in the " +"[command]#chroot_list_file# directive are *not* placed in a " +"[command]#chroot# jail upon log in." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:303 +msgid "" +"[command]#chroot_list_file# — Specifies the file containing a list of local " +"users referenced when the [command]#chroot_list_enable# directive is set to " +"[command]#YES#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:305 +msgid "The default value is [command]#/etc/vsftpd/chroot_list#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:307 +msgid "" +"[command]#chroot_local_user# — When enabled, local users are change-rooted " +"to their home directories after logging in." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/FTP.adoc:310 +#, no-wrap +msgid "Avoid enabling the chroot_local_user option" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/FTP.adoc:315 +msgid "" +"Enabling [command]#chroot_local_user# opens up a number of security issues, " +"especially for users with upload privileges. For this reason, it is *not* " +"recommended." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:319 +msgid "" +"[command]#guest_enable# — When enabled, all non-anonymous users are logged " +"in as the user [command]#guest#, which is the local user specified in the " +"[command]#guest_username# directive." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:323 +msgid "" +"[command]#guest_username# — Specifies the username the [command]#guest# user " +"is mapped to." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:327 +msgid "" +"[command]#local_root# — Specifies the directory [command]#vsftpd# changes to " +"after a local user logs in." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:331 +msgid "" +"[command]#local_umask# — Specifies the umask value for file creation. Note " +"that the default value is in octal form (a numerical system with a base of " +"eight), which includes a \"`0`\" prefix. Otherwise the value is treated as a " +"base-10 integer." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:333 +msgid "The default value is [command]#022#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:335 +msgid "" +"[command]#passwd_chroot_enable# — When enabled in conjunction with the " +"[command]#chroot_local_user# directive, [command]#vsftpd# change-roots local " +"users based on the occurrence of the [command]#/./# in the home directory " +"field within `/etc/passwd`." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:339 +msgid "" +"[command]#user_config_dir# — Specifies the path to a directory containing " +"configuration files bearing the name of local system users that contain " +"specific setting for that user. Any directive in the user's configuration " +"file overrides those found in `/etc/vsftpd/vsftpd.conf`." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/FTP.adoc:343 +#, no-wrap +msgid "Directory Options" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:346 +msgid "" +"indexterm:[vsftpd,configuration file,directory options] The following lists " +"directives which affect directories." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:348 +msgid "" +"[command]#dirlist_enable# — When enabled, users are allowed to view " +"directory lists." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:352 +msgid "" +"[command]#dirmessage_enable# — When enabled, a message is displayed whenever " +"a user enters a directory with a message file. This message resides within " +"the current directory. The name of this file is specified in the " +"[command]#message_file# directive and is `.message` by default." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:356 +msgid "" +"[command]#force_dot_files# — When enabled, files beginning with a dot (`.`) " +"are listed in directory listings, with the exception of the `.` and `..` " +"files." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:360 +msgid "" +"[command]#hide_ids# — When enabled, all directory listings show `ftp` as the " +"user and group for each file." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:364 +msgid "" +"[command]#message_file# — Specifies the name of the message file when using " +"the [command]#dirmessage_enable# directive." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:366 +msgid "The default value is [command]#.message#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:368 +msgid "" +"[command]#text_userdb_names# — When enabled, text usernames and group names " +"are used in place of UID and GID entries. Enabling this option may slow " +"performance of the server." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:372 +msgid "" +"[command]#use_localtime# — When enabled, directory listings reveal the local " +"time for the computer instead of GMT." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/FTP.adoc:376 +#, no-wrap +msgid "File Transfer Options" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:379 +msgid "" +"indexterm:[vsftpd,configuration file,file transfer options] The following " +"lists directives which affect directories." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:381 +msgid "[command]#download_enable# — When enabled, file downloads are permitted." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:385 +msgid "" +"[command]#chown_uploads# — When enabled, all files uploaded by anonymous " +"users are owned by the user specified in the [command]#chown_username# " +"directive." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:389 +msgid "" +"[command]#chown_username# — Specifies the ownership of anonymously uploaded " +"files if the [command]#chown_uploads# directive is enabled." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:391 +msgid "The default value is [command]#root#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:393 +msgid "" +"[command]#write_enable# — When enabled, `FTP` commands which can change the " +"file system are allowed, such as [command]#DELE#, [command]#RNFR#, and " +"[command]#STOR#." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/FTP.adoc:397 +#, no-wrap +msgid "Logging Options" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:400 +msgid "" +"indexterm:[vsftpd,configuration file,logging options] The following lists " +"directives which affect [command]#vsftpd#pass:attributes[{blank}]'s logging " +"behavior." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:402 +msgid "" +"[command]#dual_log_enable# — When enabled in conjunction with " +"[command]#xferlog_enable#, [command]#vsftpd# writes two files " +"simultaneously: a [command]#wu-ftpd#-compatible log to the file specified in " +"the [command]#xferlog_file# directive (`/var/log/xferlog` by default) and a " +"standard [command]#vsftpd# log file specified in the " +"[command]#vsftpd_log_file# directive (`/var/log/vsftpd.log` by default)." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:406 +msgid "" +"[command]#log_ftp_protocol# — When enabled in conjunction with " +"[command]#xferlog_enable# and with [command]#xferlog_std_format# set to " +"[command]#NO#, all `FTP` commands and responses are logged. This directive " +"is useful for debugging." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:410 +msgid "" +"[command]#syslog_enable# — When enabled in conjunction with " +"[command]#xferlog_enable#, all logging normally written to the standard " +"[command]#vsftpd# log file specified in the [command]#vsftpd_log_file# " +"directive (`/var/log/vsftpd.log` by default) is sent to the system logger " +"instead under the `FTPD` facility." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:414 +msgid "" +"[command]#vsftpd_log_file# — Specifies the [command]#vsftpd# log file. For " +"this file to be used, [command]#xferlog_enable# must be enabled and " +"[command]#xferlog_std_format# must either be set to [command]#NO# or, if " +"[command]#xferlog_std_format# is set to [command]#YES#, " +"[command]#dual_log_enable# must be enabled. It is important to note that if " +"[command]#syslog_enable# is set to [command]#YES#, the system log is used " +"instead of the file specified in this directive." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:416 +msgid "The default value is `/var/log/vsftpd.log`." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:418 +msgid "" +"[command]#xferlog_enable# — When enabled, [command]#vsftpd# logs connections " +"([command]#vsftpd# format only) and file transfer information to the log " +"file specified in the [command]#vsftpd_log_file# directive " +"(`/var/log/vsftpd.log` by default). If [command]#xferlog_std_format# is set " +"to [command]#YES#, file transfer information is logged but connections are " +"not, and the log file specified in [command]#xferlog_file# " +"(`/var/log/xferlog` by default) is used instead. It is important to note " +"that both log files and log formats are used if [command]#dual_log_enable# " +"is set to [command]#YES#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:422 +msgid "" +"[command]#xferlog_file# — Specifies the [command]#wu-ftpd#-compatible log " +"file. For this file to be used, [command]#xferlog_enable# must be enabled " +"and [command]#xferlog_std_format# must be set to [command]#YES#. It is also " +"used if [command]#dual_log_enable# is set to [command]#YES#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:424 +msgid "The default value is `/var/log/xferlog`." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:426 +msgid "" +"[command]#xferlog_std_format# — When enabled in conjunction with " +"[command]#xferlog_enable#, only a [command]#wu-ftpd#-compatible file " +"transfer log is written to the file specified in the [command]#xferlog_file# " +"directive (`/var/log/xferlog` by default). It is important to note that this " +"file only logs file transfers and does not log connections to the server." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/FTP.adoc:429 +#, no-wrap +msgid "Maintaining compatibility with older log file formats" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/FTP.adoc:434 +msgid "" +"To maintain compatibility with log files written by the older " +"[command]#wu-ftpd# `FTP` server, the [command]#xferlog_std_format# directive " +"is set to [command]#YES# under {MAJOROS}. However, this setting means that " +"connections to the server are not logged." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/FTP.adoc:436 +msgid "" +"To both log connections in [command]#vsftpd# format and maintain a " +"[command]#wu-ftpd#-compatible file transfer log, set " +"[command]#dual_log_enable# to [command]#YES#." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/FTP.adoc:438 +msgid "" +"If maintaining a [command]#wu-ftpd#-compatible file transfer log is not " +"important, either set [command]#xferlog_std_format# to [command]#NO#, " +"comment the line with a hash sign ([command]###), or delete the line " +"entirely." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/FTP.adoc:442 +#, no-wrap +msgid "Network Options" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:445 +msgid "" +"indexterm:[vsftpd,configuration file,network options] The following lists " +"directives which affect how [command]#vsftpd# interacts with the network." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:447 +msgid "" +"[command]#accept_timeout# — Specifies the amount of time for a client using " +"passive mode to establish a connection." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:449 +#: ./pages/_partials/servers/FTP.adoc:461 +msgid "The default value is [command]#60#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:451 +msgid "" +"[command]#anon_max_rate# — Specifies the maximum data transfer rate for " +"anonymous users in bytes per second." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:453 +#: ./pages/_partials/servers/FTP.adoc:505 +msgid "The default value is [command]#0#, which does not limit the transfer rate." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:455 +msgid "" +"[command]#connect_from_port_20# When enabled, [command]#vsftpd# runs with " +"enough privileges to open port 20 on the server during active mode data " +"transfers. Disabling this option allows [command]#vsftpd# to run with less " +"privileges, but may be incompatible with some `FTP` clients." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:459 +msgid "" +"[command]#connect_timeout# — Specifies the maximum amount of time a client " +"using active mode has to respond to a data connection, in seconds." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:463 +msgid "" +"[command]#data_connection_timeout# — Specifies maximum amount of time data " +"transfers are allowed to stall, in seconds. Once triggered, the connection " +"to the remote client is closed." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:465 +#: ./pages/_partials/servers/FTP.adoc:473 +msgid "The default value is [command]#300#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:467 +msgid "" +"[command]#ftp_data_port# — Specifies the port used for active data " +"connections when [command]#connect_from_port_20# is set to [command]#YES#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:469 +msgid "The default value is [command]#20#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:471 +msgid "" +"[command]#idle_session_timeout# — Specifies the maximum amount of time " +"between commands from a remote client. Once triggered, the connection to the " +"remote client is closed." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:475 +msgid "" +"[command]#listen_address# — Specifies the `IP` address on which " +"[command]#vsftpd# listens for network connections." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/FTP.adoc:478 +#: ./pages/_partials/servers/FTP.adoc:490 +#, no-wrap +msgid "Running multiple copies of vsftpd" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/FTP.adoc:483 +#: ./pages/_partials/servers/FTP.adoc:495 +msgid "" +"If running multiple copies of [command]#vsftpd# serving different `IP` " +"addresses, the configuration file for each copy of the [command]#vsftpd# " +"daemon must have a different value for this directive. See " +"xref:File_and_Print_Servers.adoc#s3-ftp-vsftpd-start-multi[Starting Multiple " +"Copies of [command]#vsftpd#] for more information about multihomed `FTP` " +"servers." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:487 +msgid "" +"[command]#listen_address6# — Specifies the `IPv6` address on which " +"[command]#vsftpd# listens for network connections when " +"[command]#listen_ipv6# is set to [command]#YES#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:499 +msgid "" +"[command]#listen_port# — Specifies the port on which [command]#vsftpd# " +"listens for network connections." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:501 +msgid "The default value is [command]#21#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:503 +msgid "" +"[command]#local_max_rate# — Specifies the maximum rate data is transferred " +"for local users logged into the server in bytes per second." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:507 +msgid "" +"[command]#max_clients# — Specifies the maximum number of simultaneous " +"clients allowed to connect to the server when it is running in standalone " +"mode. Any additional client connections would result in an error message." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:509 +#: ./pages/_partials/servers/FTP.adoc:513 +msgid "The default value is [command]#0#, which does not limit connections." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:511 +msgid "" +"[command]#max_per_ip# — Specifies the maximum of clients allowed to " +"connected from the same source `IP` address." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:515 +msgid "" +"[command]#pasv_address# — Specifies the `IP` address for the public facing " +"`IP` address of the server for servers behind Network Address Translation " +"(NAT) firewalls. This enables [command]#vsftpd# to hand out the correct " +"return address for passive mode connections." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:519 +msgid "[command]#pasv_enable# — When enabled, passive mode connects are allowed." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:523 +msgid "" +"[command]#pasv_max_port# — Specifies the highest possible port sent to the " +"`FTP` clients for passive mode connections. This setting is used to limit " +"the port range so that firewall rules are easier to create." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:525 +msgid "" +"The default value is [command]#0#, which does not limit the highest passive " +"port range. The value must not exceed [command]#65535#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:527 +msgid "" +"[command]#pasv_min_port# — Specifies the lowest possible port sent to the " +"`FTP` clients for passive mode connections. This setting is used to limit " +"the port range so that firewall rules are easier to create." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:529 +msgid "" +"The default value is [command]#0#, which does not limit the lowest passive " +"port range. The value must not be lower [command]#1024#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:531 +msgid "" +"[command]#pasv_promiscuous# — When enabled, data connections are not checked " +"to make sure they are originating from the same `IP` address. This setting " +"is only useful for certain types of tunneling." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/FTP.adoc:532 +#, no-wrap +msgid "Avoid enabling the pasv_promiscuous option" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/FTP.adoc:537 +msgid "" +"Do not enable this option unless absolutely necessary as it disables an " +"important security feature which verifies that passive mode connections " +"originate from the same `IP` address as the control connection that " +"initiates the data transfer." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:543 +msgid "[command]#port_enable# — When enabled, active mode connects are allowed." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/FTP.adoc:547 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:550 +msgid "" +"indexterm:[vsftpd,additional resources] For more information about " +"[command]#vsftpd#, refer to the following resources." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/FTP.adoc:552 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:554 +msgid "indexterm:[vsftpd,additional resources,installed documentation]" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:556 +msgid "" +"The `/usr/share/doc/vsftpd/` directory — This directory contains a `README` " +"with basic information about the software. The `TUNING` file contains basic " +"performance tuning tips and the `SECURITY/` directory contains information " +"about the security model employed by [command]#vsftpd#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:558 +msgid "" +"[command]#vsftpd# related man pages — There are a number of man pages for " +"the daemon and configuration files. The following lists some of the more " +"important man pages." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/FTP.adoc:559 +#, no-wrap +msgid "Server Applications" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:560 +#: ./pages/_partials/servers/FTP.adoc:564 +msgid "{blank}" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:562 +msgid "" +"[command]#man vsftpd# — Describes available command line options for " +"[command]#vsftpd#." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/FTP.adoc:563 +#, no-wrap +msgid "Configuration Files" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:566 +msgid "" +"[command]#man vsftpd.conf# — Contains a detailed list of options available " +"within the configuration file for [command]#vsftpd#." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:568 +msgid "" +"[command]#man 5 hosts_access# — Describes the format and options available " +"within the TCP wrappers configuration files: `hosts.allow` and `hosts.deny`." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/FTP.adoc:570 +#, no-wrap +msgid "Useful Websites" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:572 +msgid "indexterm:[vsftpd,additional resources,useful websites]" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:574 +msgid "" +"link:++https://security.appspot.com/vsftpd.html++[https://security.appspot.com/vsftpd.html] " +"— The [command]#vsftpd# project page is a great place to locate the latest " +"documentation and to contact the author of the software." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:576 +msgid "" +"link:++https://slacksite.com/other/ftp.html++[https://slacksite.com/other/ftp.html] " +"— This website provides a concise explanation of the differences between " +"active and passive mode `FTP`." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/FTP.adoc:577 +msgid "" +"link:++https://www.ietf.org/rfc/rfc0959.txt++[https://www.ietf.org/rfc/rfc0959.txt] " +"— The original _Request for Comments_ (_RFC_) of the `FTP` protocol from the " +"IETF." +msgstr "" diff --git a/pot/rawhide/pages/_partials/servers/OpenLDAP.pot b/pot/rawhide/pages/_partials/servers/OpenLDAP.pot new file mode 100644 index 00000000000..86af7f4944f --- /dev/null +++ b/pot/rawhide/pages/_partials/servers/OpenLDAP.pot @@ -0,0 +1,2457 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title == +#: ./pages/_partials/servers/OpenLDAP.adoc:3 +#, no-wrap +msgid "OpenLDAP" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:6 +msgid "" +"indexterm:[directory " +"server,OpenLDAP]indexterm:[LDAP,OpenLDAP]indexterm:[X.500,OpenLDAP]indexterm:[X.500 " +"Lite,OpenLDAP] `LDAP` (Lightweight Directory Access Protocol) is a set of " +"open protocols used to access centrally stored information over a " +"network. It is based on the `X.500` standard for directory sharing, but is " +"less complex and resource-intensive. For this reason, LDAP is sometimes " +"referred to as \"`X.500 Lite`\"." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:8 +msgid "" +"Like X.500, LDAP organizes information in a hierarchical manner using " +"directories. These directories can store a variety of information such as " +"names, addresses, or phone numbers, and can even be used in a manner similar " +"to the _Network Information Service_ (*NIS*), enabling anyone to access " +"their account from any machine on the LDAP enabled network." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:10 +msgid "" +"LDAP is commonly used for centrally managed users and groups, user " +"authentication, or system configuration. It can also serve as a virtual " +"phone directory, allowing users to easily access contact information for " +"other users. Additionally, it can refer a user to other LDAP servers " +"throughout the world, and thus provide an ad-hoc global repository of " +"information. However, it is most frequently used within individual " +"organizations such as universities, government departments, and private " +"companies." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:12 +msgid "" +"This section covers the installation and configuration of " +"[application]*OpenLDAP 2.4*, an open source implementation of the LDAPv2 and " +"LDAPv3 protocols." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/OpenLDAP.adoc:14 +#, no-wrap +msgid "Introduction to LDAP" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:17 +msgid "" +"Using a client-server architecture, LDAP provides a reliable means to create " +"a central information directory accessible from the network. When a client " +"attempts to modify information within this directory, the server verifies " +"the user has permission to make the change, and then adds or updates the " +"entry as requested. To ensure the communication is secure, the _Transport " +"Layer Security_ (*TLS*) cryptographic protocol can be used to prevent an " +"attacker from intercepting the transmission." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:18 +#, no-wrap +msgid "Using Mozilla NSS" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:23 +msgid "" +"The OpenLDAP suite in {MAJOROSVER} no longer uses OpenSSL. Instead, it uses " +"the Mozilla implementation of _Network Security Services_ (*NSS*). OpenLDAP " +"continues to work with existing certificates, keys, and other TLS " +"configuration. For more information on how to configure it to use Mozilla " +"certificate and key database, see " +"[citetitle]_link:++https://www.openldap.org/faq/index.cgi?file=1514++[How do " +"I use TLS/SSL with Mozilla NSS]_." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:27 +msgid "" +"The LDAP server supports several database systems, which gives " +"administrators the flexibility to choose the best suited solution for the " +"type of information they are planning to serve. Because of a well-defined " +"client _Application Programming Interface_ (*API*), the number of " +"applications able to communicate with an LDAP server is numerous, and " +"increasing in both quantity and quality." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:29 +#, no-wrap +msgid "LDAP Terminology" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:32 +msgid "" +"The following is a list of LDAP-specific terms that are used within this " +"chapter:" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:33 +#, no-wrap +msgid "indexterm:[OpenLDAP,terminology,entry] entry" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:34 +msgid "" +"A single unit within an LDAP directory. Each entry is identified by its " +"unique _Distinguished Name_ (*DN*)." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:35 +#, no-wrap +msgid "indexterm:[OpenLDAP,terminology,attribute] attribute" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:40 +#, no-wrap +msgid "" +"Information directly associated with an entry. For example, if an " +"organization is represented as an LDAP entry, attributes associated with " +"this organization might include an address, a fax number, etc. Similarly, " +"people can be represented as entries with common attributes such as personal " +"telephone number or email address.\n" +"+\n" +"An attribute can either have a single value, or an unordered space-separated " +"list of values. While certain attributes are optional, others are " +"required. Required attributes are specified using the [option]`objectClass` " +"definition, and can be found in schema files located in the " +"`/etc/openldap/slapd.d/cn=config/cn=schema/` directory.\n" +" +\n" +"The assertion of an attribute and its corresponding value is also referred " +"to as a _Relative Distinguished Name_ (*RDN*). Unlike distinguished names " +"that are unique globally, a relative distinguished name is only unique per " +"entry.\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:41 +#, no-wrap +msgid "indexterm:[OpenLDAP,terminology,LDIF] LDIF" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:43 +msgid "" +"The _LDAP Data Interchange Format_ (*LDIF*) is a plain text representation " +"of an LDAP entry. It takes the following form: +" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:49 +#, no-wrap +msgid "" +"pass:quotes[_id_] dn: pass:quotes[_distinguished_name_]\n" +"pass:quotes[_attribute_type_]: pass:quotes[_attribute_value_]…\n" +"pass:quotes[_attribute_type_]: pass:quotes[_attribute_value_]…\n" +"…\n" +msgstr "" + +#. type: Bullet: ' + +#. type: ' +#: ./pages/_partials/servers/OpenLDAP.adoc:52 +msgid "" +"The optional _id_ is a number determined by the application that is used to " +"edit the entry. Each entry can contain as many _attribute_type_ and " +"_attribute_value_ pairs as needed, as long as they are all defined in a " +"corresponding schema file. A blank line indicates the end of an entry." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:54 +#, no-wrap +msgid "OpenLDAP Features" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:57 +msgid "" +"indexterm:[OpenLDAP,features] OpenLDAP suite provides a number of important " +"features:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:59 +#, no-wrap +msgid "" +"*LDAPv3 Support* — Many of the changes in the protocol since LDAP version 2 " +"are designed to make LDAP more secure. Among other improvements, this " +"includes the support for Simple Authentication and Security Layer (*SASL*), " +"Transport Layer Security (*TLS*), and Secure Sockets Layer (*SSL*) " +"protocols.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:61 +#, no-wrap +msgid "" +"*LDAP Over IPC* — The use of inter-process communication (*IPC*) enhances " +"security by eliminating the need to communicate over a network.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:63 +#, no-wrap +msgid "" +"*IPv6 Support* — OpenLDAP is compliant with Internet Protocol version 6 " +"(*IPv6*), the next generation of the Internet Protocol.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:65 +#, no-wrap +msgid "*LDIFv1 Support* — OpenLDAP is fully compliant with LDIF version 1.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:67 +#, no-wrap +msgid "" +"*Updated C API* — The current C API improves the way programmers can connect " +"to and use LDAP directory servers.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:69 +#, no-wrap +msgid "" +"*Enhanced Standalone LDAP Server* — This includes an updated access control " +"system, thread pooling, better tools, and much more.\n" +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:71 +#, no-wrap +msgid "OpenLDAP Server Setup" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:74 +msgid "" +"indexterm:[OpenLDAP,configuration,overview] The typical steps to set up an " +"LDAP server on {MAJOROS} are as follows:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:76 +msgid "" +"Install the OpenLDAP suite. See " +"xref:Directory_Servers.adoc#s2-ldap-installation[Installing the OpenLDAP " +"Suite] for more information on required packages." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:78 +msgid "" +"Customize the configuration as described in " +"xref:Directory_Servers.adoc#s2-ldap-configuration[Configuring an OpenLDAP " +"Server]." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:80 +msgid "" +"Start the `slapd` service as described in " +"xref:Directory_Servers.adoc#s2-ldap-running[Running an OpenLDAP Server]." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:82 +msgid "Use the [command]#ldapadd# utility to add entries to the LDAP directory." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:84 +msgid "" +"Use the [command]#ldapsearch# utility to verify that the `slapd` service is " +"accessing the information correctly." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/OpenLDAP.adoc:86 +#, no-wrap +msgid "Installing the OpenLDAP Suite" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:89 +msgid "" +"indexterm:[OpenLDAP,installation]indexterm:[OpenLDAP,packages] The suite of " +"OpenLDAP libraries and tools is provided by the following packages:" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:91 +#, no-wrap +msgid "List of OpenLDAP packages" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/OpenLDAP.adoc:100 +#, no-wrap +msgid "" +"|Package|Description\n" +"|[package]*openldap*|A package containing the libraries necessary to run the " +"OpenLDAP server and client applications.\n" +"|[package]*openldap-clients*|A package containing the command line utilities " +"for viewing and modifying directories on an LDAP server.\n" +"|[package]*openldap-servers*|A package containing both the services and " +"utilities to configure and run an LDAP server. This includes the _Standalone " +"LDAP Daemon_, `slapd`.\n" +"|[package]*openldap-servers-sql*|A package containing the SQL support " +"module.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:103 +msgid "" +"Additionally, the following packages are commonly used along with the LDAP " +"server:" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:105 +#, no-wrap +msgid "List of commonly installed additional LDAP packages" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/OpenLDAP.adoc:112 +#, no-wrap +msgid "" +"|Package|Description\n" +"|[package]*nss-pam-ldapd*|A package containing `nslcd`, a local LDAP name " +"service that allows a user to perform local LDAP queries.\n" +"|[package]*mod_ldap*|A package containing the `mod_authnz_ldap` and " +"`mod_ldap` modules. The `mod_authnz_ldap` module is the LDAP authorization " +"module for the Apache HTTP Server. This module can authenticate users' " +"credentials against an LDAP directory, and can enforce access control based " +"on the user name, full DN, group membership, an arbitrary attribute, or a " +"complete filter string. The `mod_ldap` module contained in the same package " +"provides a configurable shared memory cache, to avoid repeated directory " +"access across many HTTP requests, and also support for SSL/TLS.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:115 +msgid "" +"To install these packages, use the [command]#dnf# command in the following " +"form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:119 +#, no-wrap +msgid "[command]#dnf# [option]`install` _package_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:122 +msgid "" +"For example, to perform the basic LDAP server installation, type the " +"following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:126 +#, no-wrap +msgid "~]#{nbsp}dnf install openldap openldap-clients openldap-servers\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:129 +msgid "" +"Note that you must have superuser privileges (that is, you must be logged in " +"as `root`) to run this command. For more information on how to install new " +"packages in {MAJOROS}, see " +"xref:package-management/DNF.adoc#sec-Installing[Installing Packages]." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:131 +#, no-wrap +msgid "Overview of OpenLDAP Server Utilities" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:134 +msgid "" +"indexterm:[OpenLDAP,utilities] To perform administrative tasks, the " +"[package]*openldap-servers* package installs the following utilities along " +"with the `slapd` service:" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:136 +#, no-wrap +msgid "List of OpenLDAP server utilities" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/OpenLDAP.adoc:150 +#, no-wrap +msgid "" +"|Command|Description\n" +"|[command]#slapacl#|Allows you to check the access to a list of " +"attributes.\n" +"|[command]#slapadd#|Allows you to add entries from an LDIF file to an LDAP " +"directory.\n" +"|[command]#slapauth#|Allows you to check a list of IDs for authentication " +"and authorization permissions.\n" +"|[command]#slapcat#|Allows you to pull entries from an LDAP directory in the " +"default format and save them in an LDIF file.\n" +"|[command]#slapdn#|Allows you to check a list of Distinguished Names (DNs) " +"based on available schema syntax.\n" +"|[command]#slapindex#|Allows you to re-index the `slapd` directory based on " +"the current content. Run this utility whenever you change indexing options " +"in the configuration file.\n" +"|[command]#slappasswd#|Allows you to create an encrypted user password to be " +"used with the [command]#ldapmodify# utility, or in the `slapd` configuration " +"file.\n" +"|[command]#slapschema#|Allows you to check the compliance of a database with " +"the corresponding schema.\n" +"|[command]#slaptest#|Allows you to check the LDAP server configuration.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:153 +msgid "" +"For a detailed description of these utilities and their usage, see the " +"corresponding manual pages as referred to in " +"xref:Directory_Servers.adoc#bh-Installed_Documentation_OpenLDAP[Installed " +"Documentation]." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:154 +#, no-wrap +msgid "Make sure the files have correct owner" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:159 +msgid "" +"Although only `root` can run [command]#slapadd#, the `slapd` service runs as " +"the `ldap` user. Because of this, the directory server is unable to modify " +"any files created by [command]#slapadd#. To correct this issue, after " +"running the [command]#slapadd# utility, type the following at a shell " +"prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:163 +#, no-wrap +msgid "[command]#chown -R ldap:ldap /var/lib/ldap#\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:167 +#, no-wrap +msgid "Stop slapd before using these utilities" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:172 +msgid "" +"To preserve the data integrity, stop the `slapd` service before using " +"[command]#slapadd#, [command]#slapcat#, or [command]#slapindex#. You can do " +"so by typing the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:176 +#: ./pages/_partials/servers/OpenLDAP.adoc:797 +#, no-wrap +msgid "~]#{nbsp}systemctl stop slapd.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:179 +msgid "" +"For more information on how to start, stop, restart, and check the current " +"status of the `slapd` service, see " +"xref:Directory_Servers.adoc#s2-ldap-running[Running an OpenLDAP Server]." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:183 +#, no-wrap +msgid "Overview of OpenLDAP Client Utilities" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:186 +msgid "" +"indexterm:[OpenLDAP,utilities] The [package]*openldap-clients* package " +"installs the following utilities which can be used to add, modify, and " +"delete entries in an LDAP directory:" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:188 +#, no-wrap +msgid "List of OpenLDAP client utilities" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/OpenLDAP.adoc:203 +#, no-wrap +msgid "" +"|Command|Description\n" +"|[command]#ldapadd#|Allows you to add entries to an LDAP directory, either " +"from a file, or from standard input. It is a symbolic link to " +"[command]#ldapmodify -a#.\n" +"|[command]#ldapcompare#|Allows you to compare given attribute with an LDAP " +"directory entry.\n" +"|[command]#ldapdelete#|Allows you to delete entries from an LDAP " +"directory.\n" +"|[command]#ldapexop#|Allows you to perform extended LDAP operations.\n" +"|[command]#ldapmodify#|Allows you to modify entries in an LDAP directory, " +"either from a file, or from standard input.\n" +"|[command]#ldapmodrdn#|Allows you to modify the RDN value of an LDAP " +"directory entry.\n" +"|[command]#ldappasswd#|Allows you to set or change the password for an LDAP " +"user.\n" +"|[command]#ldapsearch#|Allows you to search LDAP directory entries.\n" +"|[command]#ldapurl#|Allows you to compose or decompose LDAP URLs.\n" +"|[command]#ldapwhoami#|Allows you to perform a [option]`whoami` operation on " +"an LDAP server.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:206 +msgid "" +"With the exception of [command]#ldapsearch#, each of these utilities is more " +"easily used by referencing a file containing the changes to be made rather " +"than typing a command for each entry to be changed within an LDAP " +"directory. The format of such a file is outlined in the man page for each " +"utility." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:208 +#, no-wrap +msgid "Overview of Common LDAP Client Applications" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:211 +msgid "" +"indexterm:[OpenLDAP,client applications] Although there are various " +"graphical LDAP clients capable of creating and modifying directories on the " +"server, none of them is included in {MAJOROS}. Popular applications that can " +"access directories in a read-only mode include [application]*Mozilla " +"Thunderbird*, [application]*Evolution*, or [application]*Ekiga*." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/OpenLDAP.adoc:213 +#, no-wrap +msgid "Configuring an OpenLDAP Server" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:216 +msgid "" +"By default, the OpenLDAP configuration is stored in the `/etc/openldap/` " +"directory. The following table highlights the most important directories and " +"files within this directory:" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:218 +#, no-wrap +msgid "List of OpenLDAP configuration files and directories" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/OpenLDAP.adoc:227 +#, no-wrap +msgid "" +"|Path|Description\n" +"|indexterm:[OpenLDAP,files,/etc/openldap/ldap.conf]\n" +" `/etc/openldap/ldap.conf`|The configuration file for client " +"applications that use the OpenLDAP libraries. This includes " +"[command]#ldapadd#, [command]#ldapsearch#, [application]*Evolution*, etc.\n" +"|indexterm:[OpenLDAP,directories,/etc/openldap/slapd.d/]\n" +" `/etc/openldap/slapd.d/`|The directory containing the `slapd` " +"configuration.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:230 +msgid "" +"Note that OpenLDAP no longer reads its configuration from the " +"`/etc/openldap/slapd.conf` file. Instead, it uses a configuration database " +"located in the `/etc/openldap/slapd.d/` directory. If you have an existing " +"`slapd.conf` file from a previous installation, you can convert it to the " +"new format by running the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:234 +#, no-wrap +msgid "~]#{nbsp}slaptest -f /etc/openldap/slapd.conf -F /etc/openldap/slapd.d/\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:237 +msgid "" +"The `slapd` configuration consists of LDIF entries organized in a " +"hierarchical directory structure, and the recommended way to edit these " +"entries is to use the server utilities described in " +"xref:Directory_Servers.adoc#s3-ldap-packages-openldap-servers[Overview of " +"OpenLDAP Server Utilities]." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:238 +#, no-wrap +msgid "Do not edit LDIF files directly" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:243 +msgid "" +"An error in an LDIF file can render the `slapd` service unable to " +"start. Because of this, it is strongly advised that you avoid editing the " +"LDIF files within the `/etc/openldap/slapd.d/` directly." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:247 +#, no-wrap +msgid "Changing the Global Configuration" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:250 +msgid "" +"indexterm:[OpenLDAP,configuration,global]indexterm:[OpenLDAP,files,/etc/openldap/slapd.d/cn=config.ldif] " +"Global configuration options for the LDAP server are stored in the " +"`/etc/openldap/slapd.d/cn=config.ldif` file. The following directives are " +"commonly used:" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:251 +#, no-wrap +msgid "indexterm:[OpenLDAP,directives,olcAllows] [option]`olcAllows`" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:252 +msgid "" +"The [option]`olcAllows` directive allows you to specify which features to " +"enable. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:256 +#, no-wrap +msgid "[option]`olcAllows`: _feature_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:259 +msgid "" +"It accepts a space-separated list of features as described in " +"xref:Directory_Servers.adoc#table-ldap-configuration-olcallows[Available " +"olcAllows options]. The default option is [option]`bind_v2`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:261 +#, no-wrap +msgid "Available olcAllows options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/OpenLDAP.adoc:271 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`bind_v2`|Enables the acceptance of LDAP version 2 bind requests.\n" +"|[option]`bind_anon_cred`|Enables an anonymous bind when the Distinguished " +"Name (DN) is empty.\n" +"|[option]`bind_anon_dn`|Enables an anonymous bind when the Distinguished " +"Name (DN) is *not* empty.\n" +"|[option]`update_anon`|Enables processing of anonymous update operations.\n" +"|[option]`proxy_authz_anon`|Enables processing of anonymous proxy " +"authorization control.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:274 +#, no-wrap +msgid "Using the olcAllows directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:279 +#, no-wrap +msgid "olcAllows: bind_v2 update_anon\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:283 +#, no-wrap +msgid "" +"indexterm:[OpenLDAP,directives,olcConnMaxPending] " +"[option]`olcConnMaxPending`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:284 +msgid "" +"The [option]`olcConnMaxPending` directive allows you to specify the maximum " +"number of pending requests for an anonymous session. It takes the following " +"form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:288 +#, no-wrap +msgid "[option]`olcConnMaxPending`: _number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:292 +#, no-wrap +msgid "" +"The default option is [option]`100`.\n" +" +\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:293 +#, no-wrap +msgid "Using the olcConnMaxPending directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:299 +#, no-wrap +msgid "olcConnMaxPending: 100\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:303 +#, no-wrap +msgid "" +"indexterm:[OpenLDAP,directives,olcConnMaxPendingAuth] " +"[option]`olcConnMaxPendingAuth`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:305 +msgid "" +"The [option]`olcConnMaxPendingAuth` directive allows you to specify the " +"maximum number of pending requests for an authenticated session. It takes " +"the following form: +" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:308 +#, no-wrap +msgid "[option]`olcConnMaxPendingAuth`: _number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:311 +msgid "The default option is [option]`1000`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:313 +#, no-wrap +msgid "Using the olcConnMaxPendingAuth directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:319 +#, no-wrap +msgid "olcConnMaxPendingAuth: 1000\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:323 +#, no-wrap +msgid "" +"indexterm:[OpenLDAP,directives,olcDisallows] " +"[option]`olcDisallows`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:325 +msgid "" +"The [option]`olcDisallows` directive allows you to specify which features to " +"disable. It takes the following form: +" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:328 +#, no-wrap +msgid "[option]`olcDisallows`: _feature_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:331 +msgid "" +"It accepts a space-separated list of features as described in " +"xref:Directory_Servers.adoc#table-ldap-configuration-olcdisallows[Available " +"olcDisallows options]. No features are disabled by default." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:333 +#, no-wrap +msgid "Available olcDisallows options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/OpenLDAP.adoc:342 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`bind_anon`|Disables the acceptance of anonymous bind requests.\n" +"|[option]`bind_simple`|Disables the simple bind authentication mechanism.\n" +"|[option]`tls_2_anon`|Disables the enforcing of an anonymous session when " +"the STARTTLS command is received.\n" +"|[option]`tls_authc`|Disallows the STARTTLS command when authenticated.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:345 +#, no-wrap +msgid "Using the olcDisallows directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:350 +#, no-wrap +msgid "olcDisallows: bind_anon\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:354 +#, no-wrap +msgid "" +"indexterm:[OpenLDAP,directives,olcIdleTimeout] " +"[option]`olcIdleTimeout`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:356 +msgid "" +"The [option]`olcIdleTimeout` directive allows you to specify how many " +"seconds to wait before closing an idle connection. It takes the following " +"form: +" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:359 +#, no-wrap +msgid "[option]`olcIdleTimeout`: _number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:362 +#: ./pages/_partials/servers/OpenLDAP.adoc:422 +msgid "This option is disabled by default (that is, set to [option]`0`)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:364 +#, no-wrap +msgid "Using the olcIdleTimeout directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:370 +#, no-wrap +msgid "olcIdleTimeout: 180\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:374 +#, no-wrap +msgid "indexterm:[OpenLDAP,directives,olcLogFile] [option]`olcLogFile`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:376 +msgid "" +"The [option]`olcLogFile` directive allows you to specify a file in which to " +"write log messages. It takes the following form: +" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:379 +#, no-wrap +msgid "olcLogFile: pass:quotes[_file_name_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:382 +msgid "The log messages are written to standard error by default." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:384 +#, no-wrap +msgid "Using the olcLogFile directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:390 +#, no-wrap +msgid "olcLogFile: /var/log/slapd.log\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:394 +#, no-wrap +msgid "indexterm:[OpenLDAP,directives,olcReferral] [option]`olcReferral`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:396 +msgid "" +"The [option]`olcReferral` option allows you to specify a URL of a server to " +"process the request in case the server is not able to handle it. It takes " +"the following form: +" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:399 +#, no-wrap +msgid "[option]`olcReferral`: _URL_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:402 +msgid "This option is disabled by default." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:404 +#, no-wrap +msgid "Using the olcReferral directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:410 +#, no-wrap +msgid "olcReferral: ldap://root.openldap.org\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:414 +#, no-wrap +msgid "" +"indexterm:[OpenLDAP,directives,olcWriteTimeout] " +"[option]`olcWriteTimeout`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:416 +msgid "" +"The [option]`olcWriteTimeout` option allows you to specify how many seconds " +"to wait before closing a connection with an outstanding write request. It " +"takes the following form: +" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:419 +#, no-wrap +msgid "[option]`olcWriteTimeout`\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:424 +#, no-wrap +msgid "Using the olcWriteTimeout directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:430 +#, no-wrap +msgid "olcWriteTimeout: 180\n" +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:435 +#, no-wrap +msgid "Changing the Database-Specific Configuration" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:438 +msgid "" +"indexterm:[OpenLDAP,configuration,database]indexterm:[OpenLDAP,files,/etc/openldap/slapd.d/cn=config/olcDatabase=\\{1}bdb.ldif] " +"By default, the OpenLDAP server uses Berkeley DB (BDB) as a database back " +"end. The configuration for this database is stored in the " +"`/etc/openldap/slapd.d/cn=config/olcDatabase=\\{1}bdb.ldif` file. The " +"following directives are commonly used in a database-specific configuration:" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:439 +#, no-wrap +msgid "indexterm:[OpenLDAP,directives,olcReadOnly] [option]`olcReadOnly`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:441 +msgid "" +"The [option]`olcReadOnly` directive allows you to use the database in a " +"read-only mode. It takes the following form: +" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:444 +#, no-wrap +msgid "[option]`olcReadOnly`: _boolean_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:447 +msgid "" +"It accepts either [option]`TRUE` (enable the read-only mode), or " +"[option]`FALSE` (enable modifications of the database). The default option " +"is [option]`FALSE`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:449 +#, no-wrap +msgid "Using the olcReadOnly directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:455 +#, no-wrap +msgid "olcReadOnly: TRUE\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:459 +#, no-wrap +msgid "indexterm:[OpenLDAP,directives,olcRootDN] [option]`olcRootDN`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:461 +msgid "" +"The [option]`olcRootDN` directive allows you to specify the user that is " +"unrestricted by access controls or administrative limit parameters set for " +"operations on the LDAP directory. It takes the following form: +" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:464 +#, no-wrap +msgid "olcRootDN: pass:quotes[_distinguished_name_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:467 +msgid "" +"It accepts a _Distinguished Name_ (*DN*). The default option is " +"[option]`cn=Manager,dn=my-domain,dc=com`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:469 +#, no-wrap +msgid "Using the olcRootDN directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:475 +#, no-wrap +msgid "olcRootDN: cn=root,dn=example,dn=com\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:479 +#, no-wrap +msgid "indexterm:[OpenLDAP,directives,olcRootPW] [option]`olcRootPW`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:481 +msgid "" +"The [option]`olcRootPW` directive allows you to set a password for the user " +"that is specified using the [option]`olcRootDN` directive. It takes the " +"following form: +" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:484 +#, no-wrap +msgid "[option]`olcRootPW`: _password_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:487 +msgid "" +"It accepts either a plain text string, or a hash. To generate a hash, type " +"the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:494 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#slappaswd#\n" +"New password:\n" +"Re-enter new password:\n" +"\\{SSHA}WczWsyPEnMchFf1GRTweq2q7XJcvmSxD\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:497 +#, no-wrap +msgid "Using the olcRootPW directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:503 +#, no-wrap +msgid "olcRootPW: {SSHA}WczWsyPEnMchFf1GRTweq2q7XJcvmSxD\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:507 +#, no-wrap +msgid "indexterm:[OpenLDAP,directives,olcSuffix] [option]`olcSuffix`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:509 +msgid "" +"The [option]`olcSuffix` directive allows you to specify the domain for which " +"to provide information. It takes the following form: +" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:512 +#, no-wrap +msgid "olcSuffix: pass:quotes[_domain_name_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:515 +msgid "" +"It accepts a _fully qualified domain name_ (*FQDN*). The default option is " +"[option]`dc=my-domain,dc=com`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:517 +#, no-wrap +msgid "Using the olcSuffix directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:523 +#, no-wrap +msgid "olcSuffix: dc=example,dc=com\n" +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:528 +#, no-wrap +msgid "Extending Schema" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:531 +msgid "" +"indexterm:[OpenLDAP,schema]indexterm:[OpenLDAP,directories,/etc/openldap/slapd.d/cn=config/cn=schema/] " +"Since OpenLDAP 2.3, the `/etc/openldap/slapd.d/` directory also contains " +"LDAP definitions that were previously located in `/etc/openldap/schema/`. It " +"is possible to extend the schema used by OpenLDAP to support additional " +"attribute types and object classes using the default schema files as a " +"guide. However, this task is beyond the scope of this chapter. For more " +"information on this topic, see " +"link:++https://www.openldap.org/doc/admin/schema.html++[]." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:533 +#, no-wrap +msgid "Establishing a Secure Connection" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:536 +msgid "" +"indexterm:[OpenLDAP,configuration,TLS]indexterm:[OpenLDAP,files,/etc/openldap/ldap.conf]indexterm:[OpenLDAP,files,/etc/openldap/slapd.d/cn=config.ldif]indexterm:[OpenLDAP,security] " +"OpenLDAP clients and servers can be secured using the Transport Layer " +"Security (TLS) framework. TLS is a cryptographic protocol designed to " +"provide communication security over the network. As noted above, OpenLDAP " +"suite in Fedora uses Mozilla NSS as the TLS implementation." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:538 +msgid "" +"To establish a secure connection using TLS, obtain the required certificates " +"as described in " +"[citetitle]_link:++https://www.openldap.org/faq/index.cgi?file=1514++[How do " +"I use TLS/SSL with Mozilla NSS]_. Then, a number of options must be " +"configured on both the client and the server. At a minimum, a server must be " +"configured with the Certificate Authority (CA) certificates and also its own " +"server certificate and private key. The clients must be configured with the " +"name of the file containing all the trusted CA certificates." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:540 +msgid "" +"Typically, a server only needs to sign a single CA certificate. A client may " +"want to connect to a variety of secure servers, therefore it is common to " +"specify a list of several trusted CAs in its configuration." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:541 +#, no-wrap +msgid "Server Configuration" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:543 +msgid "" +"This section lists global configuration directives for `slapd` that need to " +"be specified in the `/etc/openldap/slapd.d/cn=config.ldif` file on an " +"OpenLDAP server in order to establish TLS." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:545 +msgid "" +"While the old style configuration uses a single file, normally installed as " +"`/usr/local/etc/openldap/slapd.conf`, the new style uses a slapd backend " +"database to store the configuration. The configuration database normally " +"resides in the `/usr/local/etc/openldap/slapd.d/` directory." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:547 +msgid "" +"The following directives are also valid for establishing SSL. In addition to " +"TLS directives, you need to enable a port dedicated to SSL on the server " +"side – typically it is port 636. To do so, edit the `/etc/sysconfig/slapd` " +"file and append the `ldaps:///` string to the list of URLs specified with " +"the [option]`SLAPD_URLS` directive." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:548 +#, no-wrap +msgid "[option]`olcTLSCACertificateFile`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:550 +msgid "" +"The [option]`olcTLSCACertificateFile` directive specifies the file encoded " +"with Privacy-Enhanced Mail (PEM) schema that contains trusted CA " +"certificates. The directive takes the following form: +" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:553 +#, no-wrap +msgid "[option]`olcTLSCACertificateFile`: _path_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:556 +msgid "" +"Replace _path_ either with a path to the CA certificate file, or, if you use " +"Mozilla NSS, with a certificate name." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:557 +#, no-wrap +msgid "[option]`olcTLSCACertificatePath`" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:563 +#, no-wrap +msgid "" +"The [option]`olcTLSCACertificatePath` directive specifies the path to a " +"directory containing individual CA certificates in separate files. This " +"directory must be specially managed with the OpenSSL [application]*c_rehash* " +"utility that generates symbolic links with the hashed names that point to " +"the actual certificate files. In general, it is simpler to use the " +"[option]`olcTLSCACertificateFile` directive instead.\n" +"+\n" +"If Mozilla NSS is used, [option]`olcTLSCACertificatePath` accepts a path to " +"the Mozilla NSS database (as shown in " +"xref:Directory_Servers.adoc#ex-using_olcTLSCACertificatePath_with_Mozilla_NSS[Using " +"olcTLSCACertificatePath with Mozilla NSS]). In such a case, " +"[application]*c_rehash* is not needed.\n" +" +\n" +"The directive takes the following form:\n" +" +\n" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:566 +#, no-wrap +msgid "[option]`olcTLSCACertificatePath`: _path_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:569 +msgid "" +"Replace _path_ with a path to the directory containing the CA certificate " +"files, or with a path to a Mozilla NSS database file." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:571 +#, no-wrap +msgid "Using olcTLSCACertificatePath with Mozilla NSS" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:575 +msgid "" +"With Mozilla NSS, the [option]`olcTLSCACertificatePath` directive specifies " +"the path of the directory containing the NSS certificate and key database " +"files. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:579 +#, no-wrap +msgid "[option]`olcTLSCACertificatePath`: `sql:/home/nssdb/sharednssdb`\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:582 +msgid "" +"The [command]#certutil# command is used to add a CA certificate to these NSS " +"database files:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:586 +#, no-wrap +msgid "" +"certutil -d pass:quotes[`sql:/home/nssdb/sharednssdb`] -A -n " +"\"pass:quotes[_CA_certificate_]\" -t pass:quotes[`CT,,`] -a -i " +"pass:quotes[`certificate.pem`]\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:589 +msgid "" +"The above command adds a CA certificate stored in a PEM-formatted file named " +"_certificate.pem_. The [option]`-d` option specifies the database directory " +"containing the certificate and key database files, the [option]`-n` option " +"sets a name for the certificate, [option]`-t` `CT,,` means that the " +"certificate is trusted to be used in TLS clients and servers. The " +"[option]`-A` option adds an existing certificate to a certificate database, " +"the [option]`-a` option allows the use of ASCII format for input or output, " +"and the [option]`-i` option passes the `certificate.pem` input file to the " +"command." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:592 +#, no-wrap +msgid "[option]`olcTLSCertificateFile`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:594 +msgid "" +"The [option]`olcTLSCertificateFile` directive specifies the file that " +"contains the `slapd` server certificate. The directive takes the following " +"form: +" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:597 +#, no-wrap +msgid "[option]`olcTLSCertificateFile`: _path_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:600 +msgid "" +"Replace _path_ with a path to the `slapd` server certificate file, or, if " +"you use Mozilla NSS, with a certificate name." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:602 +#, no-wrap +msgid "Using olcTLSCertificateFile with Mozilla NSS" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:606 +msgid "" +"When using Mozilla NSS with certificate and key database files specified " +"with the [option]`olcTLSCACertificatePath` directive, " +"[option]`olcTLSCertificateFile` is used to specify the name of the " +"certificate to use. First, execute the following command to view a list of " +"certificates available in your NSS database file:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:610 +#, no-wrap +msgid "" +"[command]#certutil# [option]`-d` `sql:/home/nssdb/sharednssdb` " +"[option]`-L`\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:613 +msgid "" +"Select a certificate from the list and pass its name to " +"[option]`olcTLSCertificateFile`. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:617 +#, no-wrap +msgid "olcTLSCertificateFile pass:quotes[*slapd_cert*]\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:621 +#, no-wrap +msgid "[option]`olcTLSCertificateKeyFile`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:622 +msgid "" +"The [option]`olcTLSCertificateKeyFile` directive specifies the file that " +"contains the private key that matches the certificate stored in the file " +"specified with [option]`olcTLSCertificateFile`. Note that the current " +"implementation does not support encrypted private keys, and therefore the " +"containing file must be sufficiently protected. The directive takes the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:626 +#, no-wrap +msgid "[option]`olcTLSCertificateKeyFile`: _path_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:629 +msgid "" +"Replace _path_ with a path to the private key file if you use PEM " +"certificates. When using Mozilla NSS, _path_ stands for the name of a file " +"that contains the password for the key for the certificate specified with " +"the [option]`olcTLSCertificateFile` directive (see " +"xref:Directory_Servers.adoc#ex-using_olcTLSCertificateKeyFile_with_Mozilla_NSS[Using " +"olcTLSCertificateKeyFile with Mozilla NSS])." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:631 +#, no-wrap +msgid "Using olcTLSCertificateKeyFile with Mozilla NSS" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:635 +msgid "" +"When using Mozilla NSS, this directive specifies the name of a file that " +"contains the password for the key for the certificate specified with " +"[option]`olcTLSCertificateFile`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:639 +#, no-wrap +msgid "olcTLSCertificateKeyFile: pass:quotes[*slapd_cert_key*]\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:642 +msgid "" +"The [command]#modutil# command can be used to turn off password protection " +"or to change the password for NSS database files. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:646 +#, no-wrap +msgid "" +"[command]#modutil# [option]`-dbdir` `sql:/home/nssdb/sharednssdb` " +"[option]`-changepw`\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:650 +#, no-wrap +msgid "Client Configuration" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:652 +msgid "" +"Specify the following directives in the `/etc/openldap/ldap.conf` " +"configuration file on the client system. Most of these directives are " +"parallel to the server configuration options. Directives " +"inpass:attributes[{blank}]`/etc/openldap/ldap.conf` are configured on a " +"system-wide basis, however, individual users may override them in their " +"`~/.ldaprc` files." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:654 +msgid "" +"The same directives can be used to establish an SSL connection. The " +"`ldaps://` string must be used instead of `ldap://` in OpenLDAP commands " +"such as [command]#ldapsearch#. This forces commands to use the default port " +"for SSL, port 636, configured on the server." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:655 +#, no-wrap +msgid "[option]`TLS_CACERT`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/OpenLDAP.adoc:656 +msgid "" +"The [option]`TLS_CACERT` directive specifies a file containing certificates " +"for all of the Certificate Authorities the client will recognize. This is " +"equivalent to the [option]`olcTLSCACertificateFile` directive on a " +"server. [option]`TLS_CACERT` should always be specified before " +"[option]`TLS_CACERTDIR` in `/etc/openldap/ldap.conf`. The directive takes " +"the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:660 +#, no-wrap +msgid "TLS_CACERT pass:quotes[_path_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:663 +msgid "Replace _path_ with a path to the CA certificate file." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:664 +#, no-wrap +msgid "[option]`TLS_CACERTDIR`" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:665 +msgid "" +"The [option]`TLS_CACERTDIR` directive specifies the path to a directory that " +"contains Certificate Authority certificates in separate files. As with " +"[option]`olcTLSCACertificatePath` on a server, the specified directory must " +"be managed with the OpenSSL [application]*c_rehash* utility. Path to Mozilla " +"NSS database file is also accepted, [application]*c_rehash* is not needed in " +"such case. The directive takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:669 +#, no-wrap +msgid "TLS_CACERTDIR pass:quotes[_directory_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:672 +msgid "" +"Replace _directory_ with a path to the directory containing CA certificate " +"files. With Mozilla NSS, _directory_ stands for a path to the certificate or " +"key database file." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:673 +#, no-wrap +msgid "[option]`TLS_CERT`" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:674 +msgid "" +"The [option]`TLS_CERT` specifies the file that contains a client " +"certificate. This directive can only be specified in a user's `~/.ldaprc` " +"file. With Mozilla NSS, this directive specifies the name of the certificate " +"to be chosen from the database specified with the aforementioned " +"[option]`TLS_CACERTDIR` directive. The directive takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:678 +#, no-wrap +msgid "TLS_CERT pass:quotes[_path_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:681 +msgid "" +"Replace _path_ with a path to the client certificate file, or with a name of " +"a certificate from the NSS database." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:682 +#, no-wrap +msgid "[option]`TLS_KEY`" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:688 +#, no-wrap +msgid "" +"The [option]`TLS_KEY` specifies the file that contains the private key that " +"matches the certificate stored in the file specified with the " +"[option]`TLS_CERT` directive. As with [option]`olcTLSCertificateFile` on a " +"server, encrypted key files are not supported, so the file itself must be " +"carefully protected. This option is only configurable in a user's " +"`~/.ldaprc` file.\n" +"+\n" +"When using Mozilla NSS, [option]`TLS_KEY` specifies the name of a file that " +"contains the password for the private key that protects the certificate " +"specified with the [option]`TLS_CERT` directive. Similarly to the " +"[option]`olcTLSCertificateKeyFile` directive on a server (see " +"xref:Directory_Servers.adoc#ex-using_olcTLSCertificateKeyFile_with_Mozilla_NSS[Using " +"olcTLSCertificateKeyFile with Mozilla NSS]), you can use the " +"[command]#modutil# command to manage this password.\n" +" +\n" +"The [option]`TLS_KEY` directive takes the following form:\n" +" +\n" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:691 +#, no-wrap +msgid "TLS_KEY pass:quotes[_path_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:694 +msgid "" +"Replace _path_ with a path to the client certificate file or with a name of " +"the password file in the NSS database." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:696 +#, no-wrap +msgid "Setting Up Replication" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:699 +msgid "" +"indexterm:[OpenLDAP,configuration,TLS]indexterm:[OpenLDAP,directories,/etc/openldap/slapd.d/]indexterm:[OpenLDAP,replication] " +"Replication is the process of copying updates from one LDAP server " +"(*provider*) to one or more other servers or clients (*consumers*). A " +"provider replicates directory updates to consumers, the received updates can " +"be further propagated by the consumer to other servers, so a consumer can " +"also act simultaneously as a provider. Also, a consumer does not have to be " +"an LDAP server, it may be just an LDAP client. In OpenLDAP, you can use " +"several replication modes, most notable are *mirror* and *sync*. For more " +"information on OpenLDAP replication modes, see the *OpenLDAP Software " +"Administrator's Guide* installed with [package]*openldap-servers* package " +"(see " +"xref:Directory_Servers.adoc#bh-Installed_Documentation_OpenLDAP[Installed " +"Documentation])." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:701 +msgid "" +"To enable a chosen replication mode, use one of the following directives in " +"`/etc/openldap/slapd.d/` on both provider and consumers." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:702 +#, no-wrap +msgid "[option]`olcMirrorMode`" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:703 +msgid "" +"The [option]`olcMirrorMode` directive enables the mirror replication " +"mode. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:707 +#, no-wrap +msgid "[option]`olcMirrorMode` [option]`on`\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:710 +msgid "" +"This option needs to be specified both on provider and consumers. Also a " +"[option]`serverID` must be specified along with [option]`syncrepl` " +"options. Find a detailed example in the *18.3.4. MirrorMode* section of the " +"*OpenLDAP Software Administrator's Guide* (see " +"xref:Directory_Servers.adoc#bh-Installed_Documentation_OpenLDAP[Installed " +"Documentation])." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:711 +#, no-wrap +msgid "[option]`olcSyncrepl`" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:712 +msgid "" +"The [option]`olcSyncrepl` directive enables the sync replication mode. It " +"takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:716 +#, no-wrap +msgid "[option]`olcSyncrepl` [option]`on`\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:719 +msgid "" +"The sync replication mode requires a specific configuration on both the " +"provider and the consumers. This configuration is thoroughly described in " +"the *18.3.1. Syncrepl* section of the *OpenLDAP Software Administrator's " +"Guide* (see " +"xref:Directory_Servers.adoc#bh-Installed_Documentation_OpenLDAP[Installed " +"Documentation])." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:721 +#, no-wrap +msgid "Loading Modules and Backends" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:724 +msgid "" +"indexterm:[OpenLDAP,configuration,TLS]indexterm:[OpenLDAP,directories,/etc/openldap/slapd.d/]indexterm:[OpenLDAP,modules]indexterm:[OpenLDAP,backends] " +"You can enhance the `slapd` service with dynamically loaded modules. Support " +"for these modules must be enabled with the [option]`--enable-modules` option " +"when configuring `slapd`. Modules are stored in files with the *.la* " +"extension:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:728 +#, no-wrap +msgid "pass:quotes[_module_name_].la\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:731 +msgid "" +"_Backends_ store or retrieve data in response to LDAP requests. Backends may " +"be compiled statically into `slapd`, or when module support is enabled, they " +"may be dynamically loaded. In the latter case, the following naming " +"convention is applied:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:735 +#, no-wrap +msgid "back_pass:quotes[_backend_name_].la\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:738 +msgid "" +"To load a module or a backend, use the following directive in " +"`/etc/openldap/slapd.d/`:" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:739 +#, no-wrap +msgid "[option]`olcModuleLoad`" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:740 +msgid "" +"The [option]`olcModuleLoad` directive specifies a dynamically loadable " +"module to load. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:744 +#, no-wrap +msgid "[option]`olcModuleLoad`: _module_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:747 +msgid "" +"Here, _module_ stands either for a file containing the module, or a backend, " +"that will be loaded." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/OpenLDAP.adoc:749 +#, no-wrap +msgid "SELinux Policy for Applications Using LDAP" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:752 +msgid "" +"SELinux is an implementation of a mandatory access control mechanism in the " +"Linux kernel. By default, SELinux prevents applications from accessing an " +"OpenLDAP server. To enable authentication through LDAP, which is required by " +"several applications, the `allow_ypbind` SELinux Boolean needs to be " +"enabled. Certain applications also demand an enabled " +"`authlogin_nsswitch_use_ldap` Boolean in this scenario. Execute the " +"following commands to enable the aforementioned Booleans:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:756 +#, no-wrap +msgid "~]#{nbsp}setsebool -P allow_ypbind=pass:quotes[`1`]\n" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:761 +#, no-wrap +msgid "~]#{nbsp}setsebool -P authlogin_nsswitch_use_ldap=pass:quotes[`1`]\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:764 +msgid "" +"The [option]`-P` option makes this setting persistent across system " +"reboots. See the " +"link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/SELinux_Users_and_Administrators_Guide/++[Red{nbsp}Hat " +"Enterprise{nbsp}Linux{nbsp}7 SELinux User's and Administrator's Guide] for " +"more detailed information about SELinux." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/OpenLDAP.adoc:766 +#, no-wrap +msgid "Running an OpenLDAP Server" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:769 +msgid "" +"indexterm:[slapd,OpenLDAP] This section describes how to start, stop, " +"restart, and check the current status of the [application]*Standalone LDAP " +"Daemon*. For more information on how to manage system services in general, " +"see " +"xref:infrastructure-services/Services_and_Daemons.adoc#ch-Services_and_Daemons[Services " +"and Daemons]." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:771 +#, no-wrap +msgid "Starting the Service" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:774 +msgid "" +"indexterm:[OpenLDAP,running] To start the `slapd` service in the current " +"session, type the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:778 +#, no-wrap +msgid "~]#{nbsp}systemctl start slapd.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:781 +msgid "" +"To configure the service to start automatically at the boot time, use the " +"following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:785 +#, no-wrap +msgid "~]#{nbsp}systemctl enable slapd.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:788 +#: ./pages/_partials/servers/OpenLDAP.adoc:808 +msgid "" +"See " +"xref:infrastructure-services/Services_and_Daemons.adoc#ch-Services_and_Daemons[Services " +"and Daemons] for more information on how to configure services in {MAJOROS}." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:790 +#, no-wrap +msgid "Stopping the Service" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:793 +msgid "" +"indexterm:[OpenLDAP,stopping] To stop the running `slapd` service in the " +"current session, type the following at a shell prompt as `root`:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:800 +msgid "" +"To prevent the service from starting automatically at the boot time, type as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:805 +#, no-wrap +msgid "" +"~]#{nbsp}systemctl disable slapd.service\n" +"rm '/etc/systemd/system/multi-user.target.wants/slapd.service'\n" +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:810 +#, no-wrap +msgid "Restarting the Service" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:813 +msgid "" +"indexterm:[OpenLDAP,restarting] To restart the running `slapd` service, type " +"the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:817 +#, no-wrap +msgid "~]#{nbsp}systemctl restart slapd.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:820 +msgid "" +"This stops the service and immediately starts it again. Use this command to " +"reload the configuration." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:822 +#, no-wrap +msgid "Verifying the Service Status" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:825 +msgid "" +"indexterm:[OpenLDAP,checking status] To verify that the `slapd` service is " +"running, type the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:830 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#systemctl is-active " +"slapd.service#\n" +"active\n" +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/OpenLDAP.adoc:833 +#, no-wrap +msgid "Configuring a System to Authenticate Using OpenLDAP" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:836 +msgid "" +"In order to configure a system to authenticate using OpenLDAP, make sure " +"that the appropriate packages are installed on both LDAP server and client " +"machines. For information on how to set up the server, follow the " +"instructions in xref:Directory_Servers.adoc#s2-ldap-installation[Installing " +"the OpenLDAP Suite] and " +"xref:Directory_Servers.adoc#s2-ldap-configuration[Configuring an OpenLDAP " +"Server]. On a client, type the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:840 +#, no-wrap +msgid "~]#{nbsp}dnf install openldap openldap-clients nss-pam-ldapd\n" +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/OpenLDAP.adoc:843 +#, no-wrap +msgid "Migrating Old Authentication Information to LDAP Format" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:846 +msgid "" +"indexterm:[OpenLDAP,migrating authentication information] The " +"[package]*migrationtools* package provides a set of shell and Perl scripts " +"to help you migrate authentication information into an LDAP format. To " +"install this package, type the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:850 +#, no-wrap +msgid "~]#{nbsp}dnf install migrationtools\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:853 +msgid "" +"This will install the scripts to the `/usr/share/migrationtools/` " +"directory. Once installed, edit the " +"`/usr/share/migrationtools/migrate_common.ph` file and change the following " +"lines to reflect the correct domain, for example:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:857 +#, no-wrap +msgid "" +"# Default DNS domain\n" +"$DEFAULT_MAIL_DOMAIN = \"example.com\";\n" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:860 +#, no-wrap +msgid "" +"# Default base\n" +"$DEFAULT_BASE = \"dc=example,dc=com\";\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:863 +msgid "" +"Alternatively, you can specify the environment variables directly on the " +"command line. For example, to run the `migrate_all_online.sh` script with " +"the default base set to `dc=example,dc=com`, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/OpenLDAP.adoc:868 +#, no-wrap +msgid "" +"~]#{nbsp}export DEFAULT_BASE=\"dc=example,dc=com\" \\\n" +"/usr/share/migrationtools/migrate_all_online.sh\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:871 +msgid "" +"To decide which script to run in order to migrate the user database, see " +"xref:Directory_Servers.adoc#table-ldap-migrationtools[Commonly used LDAP " +"migration scripts]." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:873 +#, no-wrap +msgid "Commonly used LDAP migration scripts" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/OpenLDAP.adoc:884 +#, no-wrap +msgid "" +"|Existing Name Service|Is LDAP Running?|Script to Use\n" +"|`/etc` flat files|yes|`migrate_all_online.sh`\n" +"|`/etc` flat files|no|`migrate_all_offline.sh`\n" +"|NetInfo|yes|`migrate_all_netinfo_online.sh`\n" +"|NetInfo|no|`migrate_all_netinfo_offline.sh`\n" +"|NIS (YP)|yes|`migrate_all_nis_online.sh`\n" +"|NIS (YP)|no|`migrate_all_nis_offline.sh`\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:887 +msgid "" +"For more information on how to use these scripts, see the `README` and the " +"`migration-tools.txt` files in the `/usr/share/doc/migrationtools/` " +"directory." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/OpenLDAP.adoc:889 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:892 +msgid "" +"The following resources offer additional information on the Lightweight " +"Directory Access Protocol. Before configuring LDAP on your system, it is " +"highly recommended that you review these resources, especially the " +"[citetitle]_OpenLDAP Software Administrator's Guide_." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:894 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:896 +msgid "" +"The following documentation is installed with the " +"[package]*openldap-servers* package:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:898 +msgid "" +"`/usr/share/doc/openldap-servers/guide.html` — A copy of the " +"[citetitle]_OpenLDAP Software Administrator's Guide_." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:900 +msgid "" +"`/usr/share/doc/openldap-servers/README.schema` — A README file " +"containing the description of installed schema files." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:902 +msgid "" +"Additionally, there is also a number of manual pages that are installed with " +"the [package]*openldap*, [package]*openldap-servers*, and " +"[package]*openldap-clients* packages:" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:903 +#, no-wrap +msgid "Client Applications" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:904 +#: ./pages/_partials/servers/OpenLDAP.adoc:922 +#: ./pages/_partials/servers/OpenLDAP.adoc:926 +#: ./pages/_partials/servers/OpenLDAP.adoc:936 +msgid "{blank}" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:906 +#, no-wrap +msgid "" +"*ldapadd*(1) — The manual page for the [command]#ldapadd# command " +"describes how to add entries to an LDAP directory.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:908 +#, no-wrap +msgid "" +"*ldapdelete*(1) — The manual page for the [command]#ldapdelete# " +"command describes how to delete entries within an LDAP directory.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:910 +#, no-wrap +msgid "" +"*ldapmodify*(1) — The manual page for the [command]#ldapmodify# " +"command describes how to modify entries within an LDAP directory.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:912 +#, no-wrap +msgid "" +"*ldapsearch*(1) — The manual page for the [command]#ldapsearch# " +"command describes how to search for entries within an LDAP directory.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:914 +#, no-wrap +msgid "" +"*ldappasswd*(1) — The manual page for the [command]#ldappasswd# " +"command describes how to set or change the password of an LDAP user.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:916 +#, no-wrap +msgid "" +"*ldapcompare*(1) — Describes how to use the [command]#ldapcompare# " +"tool.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:918 +#, no-wrap +msgid "" +"*ldapwhoami*(1) — Describes how to use the [command]#ldapwhoami# " +"tool.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:920 +#, no-wrap +msgid "*ldapmodrdn*(1) — Describes how to modify the RDNs of entries.\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:921 +#, no-wrap +msgid "Server Applications" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:924 +#, no-wrap +msgid "*slapd*(8C) — Describes command line options for the LDAP server.\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:925 +#, no-wrap +msgid "Administrative Applications" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:928 +#, no-wrap +msgid "" +"*slapadd*(8C) — Describes command line options used to add entries to " +"a [command]#slapd# database.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:930 +#, no-wrap +msgid "" +"*slapcat*(8C) — Describes command line options used to generate an " +"LDIF file from a [command]#slapd# database.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:932 +#, no-wrap +msgid "" +"*slapindex*(8C) — Describes command line options used to regenerate an " +"index based upon the contents of a [command]#slapd# database.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:934 +#, no-wrap +msgid "" +"*slappasswd*(8C) — Describes command line options used to generate " +"user passwords for LDAP directories.\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:935 +#, no-wrap +msgid "Configuration Files" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:938 +#, no-wrap +msgid "" +"*ldap.conf*(5) — The manual page for the `ldap.conf` file describes " +"the format and options available within the configuration file for LDAP " +"clients.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:940 +#, no-wrap +msgid "" +"*slapd-config*(5) — Describes the format and options available within " +"the `/etc/openldap/slapd.d` configuration directory.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/OpenLDAP.adoc:941 +#, no-wrap +msgid "Online Documentation" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:943 +#, no-wrap +msgid "link:++https://www.openldap.org/doc/admin24/++[]" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:944 +msgid "" +"The current version of the [citetitle]_OpenLDAP Software Administrator's " +"Guide_." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:945 +#, no-wrap +msgid "link:++https://www.kingsmountain.com/ldapRoadmap.shtml++[]" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:946 +msgid "" +"Jeff Hodges' [citetitle]_LDAP Roadmap & FAQ_ containing links to several " +"useful resources and emerging news concerning the LDAP protocol." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:947 +#, no-wrap +msgid "link:++http://www.ldapman.org/articles/++[]" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:948 +msgid "" +"A collection of articles that offer a good introduction to LDAP, including " +"methods to design a directory tree and customizing directory structures." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:949 +#, no-wrap +msgid "link:++https://www.padl.com/++[]" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:950 +msgid "A website of developers of several useful LDAP tools." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/OpenLDAP.adoc:952 +#, no-wrap +msgid "Related Books" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:954 +#, no-wrap +msgid "" +"[citetitle]_OpenLDAP by Example_ by John Terpstra and Benjamin Coles; " +"Prentice Hall." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:955 +msgid "A collection of practical exercises in the OpenLDAP deployment." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:956 +#, no-wrap +msgid "[citetitle]_Implementing LDAP_ by Mark Wilcox; Wrox Press, Inc." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:957 +msgid "" +"A book covering LDAP from both the system administrator's and software " +"developer's perspective." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/OpenLDAP.adoc:958 +#, no-wrap +msgid "" +"[citetitle]_Understanding and Deploying LDAP Directory Services_ by Tim " +"Howes et al.; Macmillan Technical Publishing." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/OpenLDAP.adoc:958 +msgid "" +"A book covering LDAP design principles, as well as its deployment in a " +"production environment." +msgstr "" diff --git a/pot/rawhide/pages/_partials/servers/Printer_Configuration.pot b/pot/rawhide/pages/_partials/servers/Printer_Configuration.pot new file mode 100644 index 00000000000..48b22ae9e67 --- /dev/null +++ b/pot/rawhide/pages/_partials/servers/Printer_Configuration.pot @@ -0,0 +1,1426 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title == +#: ./pages/_partials/servers/Printer_Configuration.adoc:3 +#, no-wrap +msgid "Printer Configuration" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:6 +msgid "" +"indexterm:[CUPS,Printer Configuration]indexterm:[printers,Printer " +"Configuration] The [application]*Printers* configuration tool serves for " +"printer configuring, maintenance of printer configuration files, print spool " +"directories and print filters, and printer classes management." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:8 +msgid "" +"The tool is based on the Common Unix Printing System (*CUPS*). If you " +"upgraded the system from a previous {MAJOROS} version that used CUPS, the " +"upgrade process preserved the configured printers." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:9 +#, no-wrap +msgid "Using the CUPS web application or command-line tools" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:14 +msgid "" +"indexterm:[Printer Configuration,CUPS] You can perform the same and " +"additional operations on printers directly from the CUPS web application or " +"command line. To access the application, in a web browser, go to " +"link:++http://localhost:631/++[http://localhost:631/]. For CUPS manuals " +"refer to the links on the `Home` tab of the web site." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/Printer_Configuration.adoc:18 +#, no-wrap +msgid "Starting the Printers Configuration Tool" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:21 +msgid "" +"With the [application]*Printers* configuration tool you can perform various " +"operations on existing printers and set up new printers. You can also use " +"CUPS directly (go to link:++http://localhost:631/++[http://localhost:631/] " +"to access the CUPS web application)." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:23 +msgid "" +"To start the [application]*Printers* configuration tool if using the GNOME " +"desktop, press the kbd:[Super] key to enter the Activities Overview, type " +"[command]#Printers#, and then press kbd:[Enter]. The [application]*Printers* " +"configuration tool appears. The kbd:[Super] key appears in a variety of " +"guises, depending on the keyboard and other hardware, but often as either " +"the Windows or Command key, and typically to the left of the kbd:[Spacebar]." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:25 +msgid "" +"The `Printers` window depicted in " +"xref:File_and_Print_Servers.adoc#fig-printconf-main[Printers Configuration " +"window] appears." +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:27 +#: ./pages/_partials/servers/Printer_Configuration.adoc:29 +#, no-wrap +msgid "Printers Configuration window" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:29 +#, no-wrap +msgid "printconf-main.png" +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/Printer_Configuration.adoc:32 +#, no-wrap +msgid "Starting Printer Setup" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:35 +msgid "" +"indexterm:[Printer Configuration,New Printer] Printer setup process varies " +"depending on the printer queue type." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:37 +msgid "" +"If you are setting up a local printer connected with USB, the printer is " +"discovered and added automatically. You will be prompted to confirm the " +"packages to be installed and provide an administrator or the `root` user " +"password. Local printers connected with other port types and network " +"printers need to be set up manually." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:41 +msgid "Follow this procedure to start a manual printer setup:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:43 +msgid "" +"Start the Printers configuration tool (refer to " +"xref:File_and_Print_Servers.adoc#sec-Starting_Printer_Config[Starting the " +"Printers Configuration Tool])." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:45 +msgid "" +"Select `Unlock` to enable changes to be made. In the `Authentication " +"Required` box, type an administrator or the `root` user password and " +"confirm." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:47 +msgid "" +"Select the plus sign to open the `Add a New Printer` dialog. Select the " +"printer from the list or enter its address below." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/Printer_Configuration.adoc:49 +#, no-wrap +msgid "Adding a Local Printer" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:52 +msgid "" +"indexterm:[Printer Configuration,Local Printers] Follow this procedure to " +"add a local printer connected with other than a serial port:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:56 +msgid "" +"Open the `Add a New Printer` dialog (refer to " +"xref:File_and_Print_Servers.adoc#sec-Setting_Printer[Starting Printer " +"Setup])." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:58 +msgid "" +"If the device does not appear automatically, select the port to which the " +"printer is connected in the list on the left (such as `Serial Port #1` or " +"`LPT #1`)." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:60 +msgid "On the right, enter the connection properties:" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:61 +#, no-wrap +msgid "for `Enter URI`" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:62 +msgid "`URI` (for example file:/dev/lp0)" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:63 +#, no-wrap +msgid "for `Serial Port`" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:64 +msgid "Baud Rate" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:66 +msgid "Parity" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:68 +msgid "Data Bits" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:70 +msgid "Flow Control" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:71 +#: ./pages/_partials/servers/Printer_Configuration.adoc:73 +#, no-wrap +msgid "Adding a local printer" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:73 +#, no-wrap +msgid "print_conf_window.png" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:76 +#: ./pages/_partials/servers/Printer_Configuration.adoc:102 +#: ./pages/_partials/servers/Printer_Configuration.adoc:225 +#: ./pages/_partials/servers/Printer_Configuration.adoc:276 +msgid "Click btn:[Forward]." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:78 +#: ./pages/_partials/servers/Printer_Configuration.adoc:104 +#: ./pages/_partials/servers/Printer_Configuration.adoc:136 +#: ./pages/_partials/servers/Printer_Configuration.adoc:165 +#: ./pages/_partials/servers/Printer_Configuration.adoc:227 +msgid "" +"Select the printer model. See " +"xref:File_and_Print_Servers.adoc#s1-printing-select-model[Selecting the " +"Printer Model and Finishing] for details." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/Printer_Configuration.adoc:80 +#, no-wrap +msgid "Adding an AppSocket/HP JetDirect printer" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:83 +msgid "Follow this procedure to add an AppSocket/HP JetDirect printer:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:87 +msgid "" +"Open the `Add a New Printer` dialog (refer to " +"xref:File_and_Print_Servers.adoc#sec-Starting_Printer_Config[Starting the " +"Printers Configuration Tool])." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:89 +msgid "" +"In the list on the left, select menu:Network " +"Printer[pass:attributes[{blank}]`AppSocket/HP " +"JetDirect`pass:attributes[{blank}]]." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:91 +#: ./pages/_partials/servers/Printer_Configuration.adoc:121 +#: ./pages/_partials/servers/Printer_Configuration.adoc:150 +msgid "On the right, enter the connection settings:" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:92 +#, no-wrap +msgid "`Hostname`" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:93 +msgid "Printer host name or `IP` address." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:94 +#, no-wrap +msgid "`Port Number`" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:95 +msgid "Printer port listening for print jobs (`9100` by default)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:97 +#, no-wrap +msgid "Adding a JetDirect printer" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:99 +#, no-wrap +msgid "Adding a JetDirect Printer" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:99 +#, no-wrap +msgid "printconf-jetdirect.png" +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/Printer_Configuration.adoc:106 +#, no-wrap +msgid "Adding an IPP Printer" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:109 +msgid "" +"indexterm:[Printer Configuration,IPP Printers] An `IPP` printer is a printer " +"attached to a different system on the same TCP/IP network. The system this " +"printer is attached to may either be running CUPS or simply configured to " +"use `IPP`." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:111 +msgid "" +"If a firewall is enabled on the printer server, then the firewall must be " +"configured to allow incoming `TCP` connections on port `631`. Note that the " +"CUPS browsing protocol allows client machines to discover shared CUPS queues " +"automatically. To enable this, the firewall on the client machine must be " +"configured to allow incoming `UDP` packets on port `631`." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:115 +msgid "Follow this procedure to add an `IPP` printer:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:117 +msgid "" +"Open the `Printers` dialog (refer to " +"xref:File_and_Print_Servers.adoc#sec-Setting_Printer[Starting Printer " +"Setup])." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:119 +msgid "" +"In the list of devices on the left, select Network Printer and `Internet " +"Printing Protocol (ipp)` or `Internet Printing Protocol (https)`." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:122 +#: ./pages/_partials/servers/Printer_Configuration.adoc:151 +#, no-wrap +msgid "`Host`" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:123 +msgid "The host name of the `IPP` printer." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:124 +#: ./pages/_partials/servers/Printer_Configuration.adoc:155 +#, no-wrap +msgid "`Queue`" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:125 +#: ./pages/_partials/servers/Printer_Configuration.adoc:156 +msgid "" +"The queue name to be given to the new queue (if the box is left empty, a " +"name based on the device node will be used)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:127 +#, no-wrap +msgid "Adding an IPP printer" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:129 +#, no-wrap +msgid "Networked IPP Printer" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:129 +#, no-wrap +msgid "printconf-ipp.png" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:132 +msgid "Optionally, click btn:[Verify] to detect the printer." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:134 +#: ./pages/_partials/servers/Printer_Configuration.adoc:163 +#: ./pages/_partials/servers/Printer_Configuration.adoc:259 +msgid "Click btn:[Forward] to continue." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/Printer_Configuration.adoc:138 +#, no-wrap +msgid "Adding an LPD/LPR Host or Printer" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:140 +msgid "indexterm:[Printer Configuration,LDP/LPR Printers]" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:144 +msgid "Follow this procedure to add an LPD/LPR host or printer:" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:146 +#: ./pages/_partials/servers/Printer_Configuration.adoc:190 +msgid "" +"Open the `New Printer` dialog (refer to " +"xref:File_and_Print_Servers.adoc#sec-Setting_Printer[Starting Printer " +"Setup])." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:148 +msgid "" +"In the list of devices on the left, select menu:Network " +"Printer[pass:attributes[{blank}]`LPD/LPR Host or " +"Printer`pass:attributes[{blank}]]." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:152 +msgid "The host name of the LPD/LPR printer or host." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:154 +msgid "Optionally, click btn:[Probe] to find queues on the LPD host." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:158 +#, no-wrap +msgid "Adding an LPD/LPR printer" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:160 +#, no-wrap +msgid "Adding an LPD/LPR Printer" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:160 +#, no-wrap +msgid "printconf-lpd.png" +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/Printer_Configuration.adoc:167 +#, no-wrap +msgid "Adding a Samba (SMB) printer" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:169 +msgid "" +"indexterm:[Printer Configuration,Samba Printers]indexterm:[Samba,Samba " +"Printers]" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:173 +msgid "Follow this procedure to add a Samba printer:" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:174 +#, no-wrap +msgid "Installing the samba-client package" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:179 +msgid "" +"Note that in order to add a Samba printer, you need to have the " +"[package]*samba-client* package installed. You can do so by running, as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/Printer_Configuration.adoc:183 +#, no-wrap +msgid "[command]#dnf install samba-client#\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:186 +msgid "" +"For more information on installing packages with DNF, refer to " +"xref:package-management/DNF.adoc#sec-Installing[Installing Packages]." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:192 +msgid "" +"In the list on the left, select menu:Network " +"Printer[pass:attributes[{blank}]`Windows Printer via " +"SAMBA`pass:attributes[{blank}]]." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:194 +msgid "" +"Enter the SMB address in the `smb://` field. Use the format _computer " +"name/printer share_. In " +"xref:File_and_Print_Servers.adoc#fig-printconf-smb[Adding a SMB printer], " +"the _computer name_ is [command]#dellbox# and the _printer share_ is " +"[command]#r2#." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:196 +#, no-wrap +msgid "Adding a SMB printer" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:198 +#, no-wrap +msgid "SMB Printer" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:198 +#, no-wrap +msgid "printconf-smb.png" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:201 +msgid "" +"Click btn:[Browse] to see the available workgroups/domains. To display only " +"queues of a particular host, type in the host name (NetBios name) and click " +"btn:[Browse]." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:203 +msgid "Select either of the options:" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:205 +msgid "" +"`Prompt user if authentication is required`: user name and password are " +"collected from the user when printing a document." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:207 +msgid "" +"`Set authentication details now`: provide authentication information now so " +"it is not required later. In the `Username` field, enter the user name to " +"access the printer. This user must exist on the SMB system, and the user " +"must have permission to access the printer. The default user name is " +"typically `guest` for Windows servers, or `nobody` for Samba servers." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:209 +msgid "" +"Enter the `Password` (if required) for the user specified in the `Username` " +"field." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:210 +#, no-wrap +msgid "Be careful when choosing a password" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:215 +msgid "" +"Samba printer user names and passwords are stored in the printer server as " +"unencrypted files readable by `root` and the Linux Printing Daemon, " +"`lpd`. Thus, other users that have `root` access to the printer server can " +"view the user name and password you use to access the Samba printer." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:217 +msgid "" +"Therefore, when you choose a user name and password to access a Samba " +"printer, it is advisable that you choose a password that is different from " +"what you use to access your local {MAJOROS} system." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:219 +msgid "" +"If there are files shared on the Samba print server, it is recommended that " +"they also use a password different from what is used by the print queue." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:223 +msgid "" +"Click btn:[Verify] to test the connection. Upon successful verification, a " +"dialog box appears confirming printer share accessibility." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/Printer_Configuration.adoc:229 +#, no-wrap +msgid "Selecting the Printer Model and Finishing" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:232 +msgid "" +"Once you have properly selected a printer connection type, the system " +"attempts to acquire a driver. If the process fails, you can locate or search " +"for the driver resources manually." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:236 +msgid "" +"Follow this procedure to provide the printer driver and finish the " +"installation:" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:238 +msgid "" +"In the window displayed after the automatic driver detection has failed, " +"select one of the following options:" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:240 +msgid "" +"`Select printer from database` — the system chooses a driver based on the " +"selected make of your printer from the list of `Makes`. If your printer " +"model is not listed, choose `Generic`." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:242 +msgid "" +"`Provide PPD file` — the system uses the provided _PostScript Printer " +"Description_ (*PPD*) file for installation. A PPD file may also be delivered " +"with your printer as being normally provided by the manufacturer. If the PPD " +"file is available, you can choose this option and use the browser bar below " +"the option description to select the PPD file." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:244 +msgid "" +"`Search for a printer driver to download` — enter the make and model of your " +"printer into the `Make and model` field to search on OpenPrinting.org for " +"the appropriate packages." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:246 +#, no-wrap +msgid "Selecting a printer brand" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:248 +#, no-wrap +msgid "Selecting a printer brand from the printer database brands." +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:248 +#, no-wrap +msgid "printconf-select-model.png" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:251 +msgid "" +"Depending on your previous choice provide details in the area displayed " +"below:" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:253 +msgid "Printer brand for the `Select printer from database` option." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:255 +msgid "PPD file location for the `Provide PPD file` option." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:257 +msgid "" +"Printer make and model for the `Search for a printer driver to download` " +"option." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:261 +msgid "" +"If applicable for your option, window shown in " +"xref:File_and_Print_Servers.adoc#fig-printconf-select-driver[Selecting a " +"printer model] appears. Choose the corresponding model in the `Models` " +"column on the left." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:262 +#, no-wrap +msgid "Selecting a printer driver" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:267 +msgid "" +"On the right, the recommended printer driver is automatically selected; " +"however, you can select another available driver. The print driver processes " +"the data that you want to print into a format the printer can " +"understand. Since a local printer is attached directly to your computer, you " +"need a printer driver to process the data that is sent to the printer." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:271 +#, no-wrap +msgid "Selecting a printer model" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:273 +#, no-wrap +msgid "Selecting a Printer Model with a Driver Menu" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:273 +#, no-wrap +msgid "printconf-select-driver.png" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:278 +msgid "" +"Under the `Describe Printer` enter a unique name for the printer in the " +"`Printer Name` field. The printer name can contain letters, numbers, dashes " +"(-), and underscores (_); it *must not* contain any spaces. You can also use " +"the `Description` and `Location` fields to add further printer " +"information. Both fields are optional, and may contain spaces." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:280 +#, no-wrap +msgid "Printer setup" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:282 +#, no-wrap +msgid "Printer Setup" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:282 +#, no-wrap +msgid "printconf-add-printer.png" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:285 +msgid "" +"Click btn:[Apply] to confirm your printer configuration and add the print " +"queue if the settings are correct. Click btn:[Back] to modify the printer " +"configuration." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:287 +msgid "" +"After the changes are applied, a dialog box appears allowing you to print a " +"test page. Click btn:[Print Test Page] to print a test page " +"now. Alternatively, you can print a test page later as described in " +"xref:File_and_Print_Servers.adoc#s1-printing-test-page[Printing a Test " +"Page]." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/Printer_Configuration.adoc:289 +#, no-wrap +msgid "Printing a Test Page" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:294 +msgid "" +"After you have set up a printer or changed a printer configuration, print a " +"test page to make sure the printer is functioning properly:" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:296 +msgid "Right-click the printer in the `Printing` window and click `Properties`." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:298 +msgid "In the Properties window, click `Settings` on the left." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:300 +msgid "On the displayed `Settings` tab, click the btn:[Print Test Page] button." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/Printer_Configuration.adoc:302 +#, no-wrap +msgid "Modifying Existing Printers" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:305 +msgid "" +"To delete an existing printer, in the `Printer` configuration window, select " +"the printer and go to " +"menu:Printer[pass:attributes[{blank}]`Delete`pass:attributes[{blank}]]. " +"Confirm the printer deletion. Alternatively, press the kbd:[Delete] key." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:307 +msgid "" +"To set the default printer, right-click the printer in the printer list and " +"click the `Set As Default` button in the context menu." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/Printer_Configuration.adoc:308 +#, no-wrap +msgid "The Settings Page" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:311 +msgid "" +"indexterm:[Printer Configuration,Settings] To change printer driver " +"configuration, double-click the corresponding name in the `Printer` list and " +"click the `Settings` label on the left to display the `Settings` page." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:313 +msgid "" +"You can modify printer settings such as make and model, print a test page, " +"change the device location (URI), and more." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:315 +#, no-wrap +msgid "Settings page" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:317 +#, no-wrap +msgid "Settings Page" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:317 +#, no-wrap +msgid "printconf-config1.png" +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/Printer_Configuration.adoc:319 +#, no-wrap +msgid "The Policies Page" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:322 +msgid "" +"Click the `Policies` button on the left to change settings in printer state " +"and print output." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:324 +msgid "" +"You can select the printer states, configure the `Error Policy` of the " +"printer (you can decide to abort the print job, retry, or stop it if an " +"error occurs)." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:326 +msgid "" +"You can also create a _banner page_ (a page that describes aspects of the " +"print job such as the originating printer, the user name from the which the " +"job originated, and the security status of the document being printed): " +"click the `Starting Banner` or `Ending Banner` drop-down menu and choose the " +"option that best describes the nature of the print jobs (for example, " +"`confidential`)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:328 +#, no-wrap +msgid "Sharing Printers" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:331 +msgid "" +"indexterm:[Printer Configuration,Sharing Printers] On the `Policies` page, " +"you can mark a printer as shared: if a printer is shared, users published on " +"the network can use it. To allow the sharing function for printers, go to " +"menu:Server[pass:attributes[{blank}]`Settings`pass:attributes[{blank}]] and " +"select `Publish shared printers connected to this system`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:333 +#, no-wrap +msgid "Policies page" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:335 +#, no-wrap +msgid "Policies Page" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:335 +#, no-wrap +msgid "printconf-config2.png" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:338 +msgid "" +"Make sure that the firewall allows incoming `TCP` connections to port `631`, " +"the port for the Network Printing Server (`IPP`) protocol. To allow `IPP` " +"traffic through the firewall on {MAJOROSVER}, make use of " +"`firewalld`pass:attributes[{blank}]'s `IPP` service. To do so, proceed as " +"follows:" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:340 +#, no-wrap +msgid "Enabling IPP Service in firewalld" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:342 +msgid "" +"To start the graphical [application]*firewall-config* tool, press the " +"kbd:[Super] key to enter the Activities Overview, type [command]#firewall# " +"and then press kbd:[Enter]. The `Firewall Configuration` window opens. You " +"will be prompted for an administrator or `root` password." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:344 +msgid "" +"Alternatively, to start the graphical firewall configuration tool using the " +"command line, enter the following command as `root` user:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/Printer_Configuration.adoc:348 +#, no-wrap +msgid "~]#{nbsp}firewall-config\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:351 +msgid "The `Firewall Configuration` window opens." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:353 +msgid "" +"Look for the word \"`Connected`\" in the lower left corner. This indicates " +"that the [application]*firewall-config* tool is connected to the user space " +"daemon, `firewalld`." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:355 +msgid "" +"To immediately change the current firewall settings, ensure the drop-down " +"selection menu labeled `Configuration` is set to `Runtime`. Alternatively, " +"to edit the settings to be applied at the next system start, or firewall " +"reload, select `Permanent` from the drop-down list." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:357 +msgid "" +"Select the `Zones` tab and then select the firewall zone to correspond with " +"the network interface to be used. The default is the `public` zone. The " +"`Interfaces` tab shows what interfaces have been assigned to a zone." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:359 +msgid "" +"Select the `Services` tab and then select the `ipp` service to enable " +"sharing. The `ipp-client` service is required for accessing network " +"printers." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:361 +msgid "Close the [application]*firewall-config* tool." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:363 +#, no-wrap +msgid "The Access Control Page" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:366 +msgid "" +"You can change user-level access to the configured printer on the `Access " +"Control` page. Click the `Access Control` label on the left to display the " +"page. Select either `Allow printing for everyone except these users` or " +"`Deny printing for everyone except these users` and define the user set " +"below: enter the user name in the text box and click the btn:[Add] button to " +"add the user to the user set." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:368 +#, no-wrap +msgid "Access Control page" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:370 +#, no-wrap +msgid "Access Control Page" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:370 +#, no-wrap +msgid "printconf-config3.png" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:373 +#, no-wrap +msgid "The Printer Options Page" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:376 +msgid "" +"The `Printer Options` page contains various configuration options for the " +"printer media and output, and its content may vary from printer to " +"printer. It contains general printing, paper, quality, and printing size " +"settings." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:378 +#, no-wrap +msgid "Printer Options page" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:380 +#, no-wrap +msgid "Printer Options Page" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:380 +#, no-wrap +msgid "printconf-config4.png" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:383 +#: ./pages/_partials/servers/Printer_Configuration.adoc:390 +#, no-wrap +msgid "Job Options Page" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:386 +msgid "" +"On the `Job Options` page, you can detail the printer job options. Click the " +"`Job Options` label on the left to display the page. Edit the default " +"settings to apply custom job options, such as number of copies, orientation, " +"pages per side, scaling (increase or decrease the size of the printable " +"area, which can be used to fit an oversize print area onto a smaller " +"physical sheet of print medium), detailed text options, and custom job " +"options." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:388 +#, no-wrap +msgid "Job Options page" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:390 +#, no-wrap +msgid "printconf-config5.png" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:393 +#: ./pages/_partials/servers/Printer_Configuration.adoc:400 +#, no-wrap +msgid "Ink/Toner Levels Page" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:396 +msgid "" +"The `Ink/Toner Levels` page contains details on toner status if available " +"and printer status messages. Click the `Ink/Toner Levels` label on the left " +"to display the page." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:398 +#, no-wrap +msgid "Ink/Toner Levels page" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:400 +#, no-wrap +msgid "printconf-config6.png" +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/Printer_Configuration.adoc:403 +#, no-wrap +msgid "Managing Print Jobs" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:406 +msgid "" +"indexterm:[Printer Configuration,Print Jobs] When you send a print job to " +"the printer daemon, such as printing a text file from [application]*Emacs* " +"or printing an image from [application]*GIMP*, the print job is added to the " +"print spool queue. The print spool queue is a list of print jobs that have " +"been sent to the printer and information about each print request, such as " +"the status of the request, the job number, and more." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:408 +msgid "" +"During the printing process, messages informing about the process appear in " +"the notification area." +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/_partials/servers/Printer_Configuration.adoc:410 +#: ./pages/_partials/servers/Printer_Configuration.adoc:412 +#, no-wrap +msgid "GNOME Print Status" +msgstr "" + +#. type: Target for macro image +#: ./pages/_partials/servers/Printer_Configuration.adoc:412 +#, no-wrap +msgid "gnome-print-queue.png" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:415 +msgid "" +"To cancel, hold, release, reprint or authenticate a print job, select the " +"job in the [application]*GNOME Print Status* and on the Job menu, click the " +"respective command." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/Printer_Configuration.adoc:417 +msgid "" +"To view the list of print jobs in the print spool from a shell prompt, type " +"the command [command]#lpstat -o#. The last few lines look similar to the " +"following:" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/Printer_Configuration.adoc:419 +#, no-wrap +msgid "Example of [command]#lpstat -o# output" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/Printer_Configuration.adoc:428 +#, no-wrap +msgid "" +"$ [command]#lpstat -o#\n" +"Charlie-60 twaugh 1024 Tue 08 Feb 2011 16:42:11 " +"GMT\n" +"Aaron-61 twaugh 1024 Tue 08 Feb 2011 16:42:44 " +"GMT\n" +"Ben-62 root 1024 Tue 08 Feb 2011 16:45:42 " +"GMT\n" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:433 +msgid "" +"If you want to cancel a print job, find the job number of the request with " +"the command [command]#lpstat -o# and then use the command [command]#cancel " +"_job number_pass:attributes[{blank}]#. For example, [command]#cancel 60# " +"would cancel the print job in " +"xref:File_and_Print_Servers.adoc#lpq-example[Example of [command]#lpstat -o# " +"output]. You cannot cancel print jobs that were started by other users with " +"the [command]#cancel# command. However, you can enforce deletion of such job " +"by issuing the [command]#cancel -U root " +"_job_number_pass:attributes[{blank}]# command. To prevent such canceling, " +"change the printer operation policy to `Authenticated` to force `root` " +"authentication." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:435 +msgid "" +"You can also print a file directly from a shell prompt. For example, the " +"command [command]#lp sample.txt# prints the text file `sample.txt`. The " +"print filter determines what type of file it is and converts it into a " +"format the printer can understand." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/Printer_Configuration.adoc:437 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:440 +msgid "To learn more about printing on {MAJOROS}, see the following resources." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/Printer_Configuration.adoc:442 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:444 +#, no-wrap +msgid "[command]#man lp#" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:445 +msgid "" +"The manual page for the [command]#lpr# command that allows you to print " +"files from the command line." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:446 +#, no-wrap +msgid "[command]#man cancel#" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:447 +msgid "" +"The manual page for the command-line utility to remove print jobs from the " +"print queue." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:448 +#, no-wrap +msgid "[command]#man mpage#" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:449 +msgid "" +"The manual page for the command-line utility to print multiple pages on one " +"sheet of paper." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:450 +#, no-wrap +msgid "[command]#man cupsd#" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:451 +msgid "The manual page for the CUPS printer daemon." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:452 +#, no-wrap +msgid "[command]#man cupsd.conf#" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:453 +msgid "The manual page for the CUPS printer daemon configuration file." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:454 +#, no-wrap +msgid "[command]#man classes.conf#" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:455 +msgid "The manual page for the class configuration file for CUPS." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:456 +#, no-wrap +msgid "[command]#man lpstat#" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:457 +msgid "" +"The manual page for the [command]#lpstat# command, which displays status " +"information about classes, jobs, and printers." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/Printer_Configuration.adoc:459 +#, no-wrap +msgid "Useful Websites" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:461 +#, no-wrap +msgid "link:++https://wiki.linuxfoundation.org/openprinting/start++[]" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:462 +msgid "" +"[citetitle]_Open Printing_ contains a large amount of information about " +"printing in Linux." +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/Printer_Configuration.adoc:463 +#, no-wrap +msgid "link:++https://www.cups.org/++[]" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Printer_Configuration.adoc:463 +msgid "Documentation, FAQs, and newsgroups about CUPS." +msgstr "" diff --git a/pot/rawhide/pages/_partials/servers/Samba.pot b/pot/rawhide/pages/_partials/servers/Samba.pot new file mode 100644 index 00000000000..c056eb6d8f8 --- /dev/null +++ b/pot/rawhide/pages/_partials/servers/Samba.pot @@ -0,0 +1,32 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title == +#: ./pages/_partials/servers/Samba.adoc:3 +#, no-wrap +msgid "Samba" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/Samba.adoc:8 +msgid "" +"Documentation for configuring and using Samba has been removed due to being " +"outdated. Use " +"link:https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html-single/configuring_and_using_network_file_services/index#assembly_using-samba-as-a-server_configuring-and-using-network-file-services[Red " +"Hat Enterprise Linux 9 Samba documentation] instead." +msgstr "" diff --git a/pot/rawhide/pages/_partials/servers/The_Apache_HTTP_Server.pot b/pot/rawhide/pages/_partials/servers/The_Apache_HTTP_Server.pot new file mode 100644 index 00000000000..9f1528bc5e4 --- /dev/null +++ b/pot/rawhide/pages/_partials/servers/The_Apache_HTTP_Server.pot @@ -0,0 +1,5116 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title == +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:3 +#, no-wrap +msgid "The Apache HTTP Server" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:6 +msgid "" +"indexterm:[httpd,Apache HTTP Server] The web server available in {MAJOROS} " +"is the Apache HTTP server daemon, `httpd`, an open source web server " +"developed by the link:++https://www.apache.org/++[Apache Software " +"Foundation]. This section describes the basic configuration of the `httpd` " +"service, and covers some advanced topics such as adding server modules, " +"setting up virtual hosts, or configuring the secure HTTP server." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:8 +#, no-wrap +msgid "Running the httpd Service" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:11 +msgid "" +"This section describes how to start, stop, restart, and check the current " +"status of the Apache HTTP Server. To be able to use the `httpd` service, " +"make sure you have the [package]*httpd* installed. You can do so by using " +"the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:15 +#, no-wrap +msgid "#{nbsp}dnf install httpd\n" +msgstr "" + +#. link to systemd section when ready +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:18 +msgid "" +"For more information on the concept of targets and how to manage system " +"services in {MAJOROS} in general, see" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:20 +#, no-wrap +msgid "" +" " +"xref:infrastructure-services/Services_and_Daemons.adoc#ch-Services_and_Daemons[Services " +"and Daemons].\n" +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:22 +#, no-wrap +msgid "Starting the Service" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:25 +msgid "" +"indexterm:[Apache HTTP Server,starting] To run the `httpd` service, type the " +"following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:29 +#, no-wrap +msgid "#{nbsp}systemctl start httpd.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:32 +msgid "" +"If you want the service to start automatically at boot time, use the " +"following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:37 +#, no-wrap +msgid "" +"#{nbsp}systemctl enable httpd.service\n" +"ln -s '/usr/lib/systemd/system/httpd.service' " +"'/etc/systemd/system/multi-user.target.wants/httpd.service'\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:39 +#, no-wrap +msgid "Using the secure server" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:44 +msgid "" +"If running the Apache HTTP Server as a secure server, a password may be " +"required after the machine boots if using an encrypted private SSL key." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:48 +#, no-wrap +msgid "Stopping the Service" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:51 +msgid "" +"indexterm:[Apache HTTP Server,stopping] To stop the running `httpd` service, " +"type the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:55 +#, no-wrap +msgid "#{nbsp}systemctl stop httpd.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:58 +msgid "To prevent the service from starting automatically at boot time, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:63 +#, no-wrap +msgid "" +"#{nbsp}systemctl disable httpd.service\n" +"rm '/etc/systemd/system/multi-user.target.wants/httpd.service'\n" +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:66 +#, no-wrap +msgid "Restarting the Service" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:69 +msgid "" +"indexterm:[Apache HTTP Server,restarting] There are three different ways to " +"restart a running `httpd` service:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:71 +msgid "To restart the service completely, enter the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:75 +#, no-wrap +msgid "#{nbsp}systemctl restart httpd.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:78 +msgid "" +"This stops the running `httpd` service and immediately starts it again. Use " +"this command after installing or removing a dynamically loaded module such " +"as PHP." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:80 +msgid "" +"To only reload the configuration without interrupting active requests, as " +"`root`, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:84 +#, no-wrap +msgid "#{nbsp}systemctl reload httpd.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:87 +msgid "" +"This causes the running `httpd` service to reload its configuration " +"file. Any requests currently being processed will not be interrupted, so " +"configuration changes will only take effect for new client connections." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:89 +msgid "" +"To reload the configuration and immediately terminate any active " +"connections, enter the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:93 +#, no-wrap +msgid "#{nbsp}systemctl kill --kill-who=main --signal=HUP httpd\n" +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:97 +#, no-wrap +msgid "Verifying the Service Status" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:100 +msgid "" +"indexterm:[Apache HTTP Server,checking status] To verify that the `httpd` " +"service is running, type the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:105 +#, no-wrap +msgid "" +"#{nbsp}systemctl is-active httpd.service\n" +"active\n" +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:108 +#, no-wrap +msgid "Editing the Configuration Files" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:111 +msgid "" +"When the `httpd` service is started, by default, it reads the configuration " +"from locations that are listed in " +"xref:Web_Servers.adoc#table-apache-editing-files[The httpd service " +"configuration files]." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:113 +#, no-wrap +msgid "The httpd service configuration files" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:122 +#, no-wrap +msgid "" +"|Path|Description\n" +"|indexterm:[Apache HTTP Server,files,/etc/httpd/conf/httpd.conf]\n" +" `/etc/httpd/conf/httpd.conf`|The main configuration file.\n" +"|indexterm:[Apache HTTP Server,directories,/etc/httpd/conf.d/]\n" +" `/etc/httpd/conf.d/`|An auxiliary directory for configuration " +"files that are included in the main configuration file.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:127 +msgid "" +"Although the default configuration should be suitable for most situations, " +"it is a good idea to become at least familiar with some of the more " +"important configuration options. Note that for any changes to take effect, " +"the web server has to be restarted first. See " +"xref:Web_Servers.adoc#s3-apache-running-restarting[Restarting the Service] " +"for more information on how to restart the `httpd` service. " +"indexterm:[Apache HTTP Server,checking configuration] To check the " +"configuration for possible errors, type the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:132 +#, no-wrap +msgid "" +"#{nbsp}apachectl configtest\n" +"Syntax OK\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:135 +msgid "" +"To make the recovery from mistakes easier, it is recommended that you make a " +"copy of the original file before editing it." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:137 +#, no-wrap +msgid "Common httpd.conf Directives" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:140 +msgid "" +"indexterm:[Apache HTTP Server,files,/etc/httpd/conf/httpd.conf] The " +"following directives are commonly used in the `/etc/httpd/conf/httpd.conf` " +"configuration file:" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:141 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,] " +"[option]``" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:142 +msgid "" +"The [option]`` directive allows you to apply certain directives " +"to a particular directory only. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:149 +#, no-wrap +msgid "" +"<Directory _directory_pass:attributes[{blank}]>\n" +" _directive_\n" +" …\n" +"</Directory>\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:152 +msgid "" +"The _directory_ can be either a full path to an existing directory in the " +"local file system, or a wildcard expression." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:154 +msgid "" +"This directive can be used to configure additional `cgi-bin` directories for " +"server-side scripts located outside the directory that is specified by " +"[option]`ScriptAlias`. In this case, the [option]`ExecCGI` and " +"[option]`AddHandler` directives must be supplied, and the permissions on the " +"target directory must be set correctly (that is, `0755`)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:156 +#, no-wrap +msgid "Using the directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:167 +#, no-wrap +msgid "" +"<Directory /var/www/html>\n" +" Options Indexes FollowSymLinks\n" +" AllowOverride None\n" +" Order allow,deny\n" +" Allow from all\n" +"</Directory>\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:171 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,] " +"[option]``" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:172 +msgid "" +"The [option]`IfDefine` directive allows you to use certain directives only " +"when a particular parameter is supplied on the command line. It takes the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:179 +#, no-wrap +msgid "" +"<IfDefine !_parameter_pass:attributes[{blank}]>\n" +" _directive_\n" +" …\n" +"</IfDefine>\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:182 +msgid "" +"The _parameter_ can be supplied at a shell prompt using the " +"[option]`-D`pass:attributes[{blank}]pass:attributes[{blank}]_parameter_ " +"command line option (for example, [command]#httpd -DEnableHome#). If the " +"optional exclamation mark (that is, `!`) is present, the enclosed directives " +"are used only when the parameter is *not* specified." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:184 +#, no-wrap +msgid "Using the directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:191 +#, no-wrap +msgid "" +"\n" +" UserDir public_html\n" +"\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:195 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,] " +"[option]``" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:196 +msgid "" +"The [option]`` directive allows you to use certain directive only " +"when a particular module is loaded. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:203 +#, no-wrap +msgid "" +"<IfModule !_module_pass:attributes[{blank}]>\n" +" _directive_\n" +" …\n" +"</IfModule>\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:206 +msgid "" +"The _module_ can be identified either by its name, or by the file name. If " +"the optional exclamation mark (that is, `!`) is present, the enclosed " +"directives are used only when the module is *not* loaded." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:208 +#, no-wrap +msgid "Using the directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:216 +#, no-wrap +msgid "" +"\n" +" CacheEnable disk /\n" +" CacheRoot /var/cache/mod_proxy\n" +"\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:220 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,] " +"[option]``" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:221 +msgid "" +"The [option]`` directive allows you to apply certain directives to " +"a particular URL only. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:228 +#, no-wrap +msgid "" +"<Location _url_pass:attributes[{blank}]>\n" +" _directive_\n" +" …\n" +"</Location>\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:231 +msgid "" +"The _url_ can be either a path relative to the directory specified by the " +"[option]`DocumentRoot` directive (for example, `/server-info`), or an " +"external URL such as `http://example.com/server-info`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:233 +#, no-wrap +msgid "Using the directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:244 +#, no-wrap +msgid "" +"<Location /server-info>\n" +" SetHandler server-info\n" +" Order deny,allow\n" +" Deny from all\n" +" Allow from .example.com\n" +"</Location>\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:248 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,] " +"[option]``" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:249 +msgid "" +"The [option]`` directive allows you to apply certain directives to " +"the proxy server only. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:256 +#, no-wrap +msgid "" +"<Proxy _pattern_pass:attributes[{blank}]>\n" +" _directive_\n" +" …\n" +"</Proxy>\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:259 +msgid "" +"The _pattern_ can be an external URL, or a wildcard expression (for example, " +"`http://example.com/*`)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:261 +#, no-wrap +msgid "Using the directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:270 +#, no-wrap +msgid "" +"\n" +" Order deny,allow\n" +" Deny from all\n" +" Allow from .example.com\n" +"\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:274 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,] " +"[option]``" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:275 +msgid "" +"The [option]`` directive allows you apply certain directives to " +"particular virtual hosts only. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:282 +#, no-wrap +msgid "" +"<VirtualHost " +"_address_:pass:attributes[{blank}]_port_pass:attributes[{blank}]…>\n" +" _directive_\n" +" …\n" +"</VirtualHost>\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:285 +msgid "" +"The _address_ can be an IP address, a fully qualified domain name, or a " +"special form as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-virtualhost[Available " +" options]." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:287 +#, no-wrap +msgid "Available options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:294 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`*`|Represents all IP addresses.\n" +"|[option]`_default_`|Represents unmatched IP addresses.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:297 +#, no-wrap +msgid "Using the directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:308 +#, no-wrap +msgid "" +"\n" +" ServerAdmin webmaster@penguin.example.com\n" +" DocumentRoot /www/docs/penguin.example.com\n" +" ServerName penguin.example.com\n" +" ErrorLog logs/penguin.example.com-error_log\n" +" CustomLog logs/penguin.example.com-access_log common\n" +"\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:312 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,AccessFileName] " +"[option]`AccessFileName`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:313 +msgid "" +"The [option]`AccessFileName` directive allows you to specify the file to be " +"used to customize access control information for each directory. It takes " +"the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:317 +#, no-wrap +msgid "AccessFileName _filename_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:322 +msgid "" +"indexterm:[Apache HTTP Server,files,.htaccess]indexterm:[.htaccess,Apache " +"HTTP Server] The _filename_ is a name of the file to look for in the " +"requested directory. By default, the server looks for `.htaccess`. " +"indexterm:[Apache HTTP Server,files,.htpasswd]indexterm:[.htpasswd,Apache " +"HTTP Server] For security reasons, the directive is typically followed by " +"the `Files` tag to prevent the files beginning with `.ht` from being " +"accessed by web clients. This includes the `.htaccess` and `.htpasswd` " +"files." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:324 +#, no-wrap +msgid "Using the AccessFileName directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:329 +#, no-wrap +msgid "AccessFileName .htaccess\n" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:335 +#, no-wrap +msgid "" +"\n" +" Order allow,deny\n" +" Deny from all\n" +" Satisfy All\n" +"\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:339 +#, no-wrap +msgid "indexterm:[Apache HTTP Server,directives,Action] [option]`Action`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:340 +msgid "" +"The [option]`Action` directive allows you to specify a CGI script to be " +"executed when a certain media type is requested. It takes the following " +"form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:344 +#, no-wrap +msgid "Action _content-type_ _path_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:347 +msgid "" +"The _content-type_ has to be a valid MIME type such as `text/html`, " +"`image/png`, or `application/pdf`. The _path_ refers to an existing CGI " +"script, and must be relative to the directory specified by the " +"[option]`DocumentRoot` directive (for example, " +"`/cgi-bin/process-image.cgi`)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:349 +#, no-wrap +msgid "Using the Action directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:355 +#, no-wrap +msgid "Action image/png /cgi-bin/process-image.cgi\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:359 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,AddDescription] " +"[option]`AddDescription`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:360 +msgid "" +"The [option]`AddDescription` directive allows you to specify a short " +"description to be displayed in server-generated directory listings for a " +"given file. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:364 +#, no-wrap +msgid "" +"AddDescription " +"\"pass:attributes[{blank}]_description_pass:attributes[{blank}]\" " +"_filename_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:367 +msgid "" +"The _description_ should be a short text enclosed in double quotes (that is, " +"`\"`). The _filename_ can be a full file name, a file extension, or a " +"wildcard expression." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:369 +#, no-wrap +msgid "Using the AddDescription directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:375 +#, no-wrap +msgid "AddDescription \"GZIP compressed tar archive\" .tgz\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:379 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,AddEncoding] " +"[option]`AddEncoding`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:380 +msgid "" +"The [option]`AddEncoding` directive allows you to specify an encoding type " +"for a particular file extension. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:384 +#, no-wrap +msgid "AddEncoding _encoding_ _extension_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:387 +msgid "" +"The _encoding_ has to be a valid MIME encoding such as `x-compress`, " +"`x-gzip`, etc. The _extension_ is a case sensitive file extension, and is " +"conventionally written with a leading dot (for example, `.gz`)." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:389 +msgid "" +"This directive is typically used to instruct web browsers to decompress " +"certain file types as they are downloaded." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:391 +#, no-wrap +msgid "Using the AddEncoding directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:397 +#, no-wrap +msgid "AddEncoding x-gzip .gz .tgz\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:401 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,AddHandler] " +"[option]`AddHandler`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:402 +msgid "" +"The [option]`AddHandler` directive allows you to map certain file extensions " +"to a selected handler. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:406 +#, no-wrap +msgid "AddHandler _handler_ _extension_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:409 +msgid "" +"The _handler_ has to be a name of previously defined handler. The " +"_extension_ is a case sensitive file extension, and is conventionally " +"written with a leading dot (for example, `.cgi`)." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:411 +msgid "" +"This directive is typically used to treat files with the `.cgi` extension as " +"CGI scripts regardless of the directory they are in. Additionally, it is " +"also commonly used to process server-parsed HTML and image-map files." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:413 +#, no-wrap +msgid "Using the AddHandler option" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:419 +#, no-wrap +msgid "AddHandler cgi-script .cgi\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:423 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,AddIcon] " +"[option]`AddIcon`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:424 +msgid "" +"The [option]`AddIcon` directive allows you to specify an icon to be " +"displayed for a particular file in server-generated directory listings. It " +"takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:428 +#, no-wrap +msgid "AddIcon _path_ _pattern_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:431 +msgid "" +"The _path_ refers to an existing icon file, and must be relative to the " +"directory specified by the [option]`DocumentRoot` directive (for example, " +"`/icons/folder.png`). The _pattern_ can be a file name, a file extension, a " +"wildcard expression, or a special form as described in the following table:" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:433 +#, no-wrap +msgid "Available AddIcon options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:440 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`^^DIRECTORY^^`|Represents a directory.\n" +"|[option]`^^BLANKICON^^`|Represents a blank line.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:443 +#, no-wrap +msgid "Using the AddIcon directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:449 +#, no-wrap +msgid "AddIcon /icons/text.png .txt README\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:453 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,AddIconByEncoding] " +"[option]`AddIconByEncoding`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:454 +msgid "" +"The [option]`AddIconByEncoding` directive allows you to specify an icon to " +"be displayed for a particular encoding type in server-generated directory " +"listings. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:458 +#, no-wrap +msgid "AddIconByEncoding _path_ _encoding_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:461 +msgid "" +"The _path_ refers to an existing icon file, and must be relative to the " +"directory specified by the [option]`DocumentRoot` directive (for example, " +"`/icons/compressed.png`). The _encoding_ has to be a valid MIME encoding " +"such as `x-compress`, `x-gzip`, etc." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:463 +#, no-wrap +msgid "Using the AddIconByEncoding directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:469 +#, no-wrap +msgid "AddIconByEncoding /icons/compressed.png x-compress x-gzip\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:473 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,AddIconByType] " +"[option]`AddIconByType`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:474 +msgid "" +"The [option]`AddIconByType` directive allows you to specify an icon to be " +"displayed for a particular media type in server-generated directory " +"listings. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:478 +#, no-wrap +msgid "AddIconByType _path_ _content-type_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:481 +msgid "" +"The _path_ refers to an existing icon file, and must be relative to the " +"directory specified by the [option]`DocumentRoot` directive (for example, " +"`/icons/text.png`). The _content-type_ has to be either a valid MIME type " +"(for example, `text/html` or `image/png`), or a wildcard expression such as " +"`text/*`, `image/*`, etc." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:483 +#, no-wrap +msgid "Using the AddIconByType directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:488 +#, no-wrap +msgid "AddIconByType /icons/video.png video/*\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:492 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,AddLanguage] " +"[option]`AddLanguage`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:493 +msgid "" +"The [option]`AddLanguage` directive allows you to associate a file extension " +"with a specific language. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:497 +#, no-wrap +msgid "AddLanguage _language_ _extension_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:500 +msgid "" +"The _language_ has to be a valid MIME language such as `cs`, `en`, or " +"`fr`. The _extension_ is a case sensitive file extension, and is " +"conventionally written with a leading dot (for example, `.cs`)." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:502 +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1215 +msgid "" +"This directive is especially useful for web servers that serve content in " +"multiple languages based on the client's language settings." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:504 +#, no-wrap +msgid "Using the AddLanguage directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:510 +#, no-wrap +msgid "AddLanguage cs .cs .cz\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:514 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,AddType] " +"[option]`AddType`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:515 +msgid "" +"The [option]`AddType` directive allows you to define or override the media " +"type for a particular file extension. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:519 +#, no-wrap +msgid "AddType _content-type_ _extension_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:522 +msgid "" +"The _content-type_ has to be a valid MIME type such as `text/html`, " +"`image/png`, etc. The _extension_ is a case sensitive file extension, and is " +"conventionally written with a leading dot (for example, `.cs`)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:524 +#, no-wrap +msgid "Using the AddType directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:530 +#, no-wrap +msgid "AddType application/x-gzip .gz .tgz\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:534 +#, no-wrap +msgid "indexterm:[Apache HTTP Server,directives,Alias] [option]`Alias`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:535 +msgid "" +"The [option]`Alias` directive allows you to refer to files and directories " +"outside the default directory specified by the [option]`DocumentRoot` " +"directive. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:539 +#, no-wrap +msgid "Alias _url-path_ _real-path_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:544 +msgid "" +"The _url-path_ must be relative to the directory specified by the " +"[option]`DocumentRoot` directive (for example, `/images/`). The _real-path_ " +"is a full path to a file or directory in the local file system. " +"indexterm:[Apache HTTP Server,directories,/var/www/icons/] This directive is " +"typically followed by the [option]`Directory` tag with additional " +"permissions to access the target directory. By default, the `/icons/` alias " +"is created so that the icons from `/var/www/icons/` are displayed in " +"server-generated directory listings." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:546 +#, no-wrap +msgid "Using the Alias directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:552 +#, no-wrap +msgid "Alias /icons/ /var/www/icons/\n" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:559 +#, no-wrap +msgid "" +"<Directory \"/var/www/icons\">\n" +" Options Indexes MultiViews FollowSymLinks\n" +" AllowOverride None\n" +" Order allow,deny\n" +" Allow from all\n" +"<Directory>\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:563 +#, no-wrap +msgid "indexterm:[Apache HTTP Server,directives,Allow] [option]`Allow`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:564 +msgid "" +"The [option]`Allow` directive allows you to specify which clients have " +"permission to access a given directory. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:568 +#, no-wrap +msgid "Allow from _client_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:571 +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:868 +msgid "" +"The _client_ can be a domain name, an IP address (both full and partial), a " +"_network_pass:attributes[{blank}]/pass:attributes[{blank}]_netmask_ pair, or " +"`all` for all clients." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:573 +#, no-wrap +msgid "Using the Allow directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:579 +#, no-wrap +msgid "Allow from 192.168.1.0/255.255.255.0\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:583 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,AllowOverride] " +"[option]`AllowOverride`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:585 +msgid "" +"indexterm:[Apache HTTP Server,files,.htaccess]indexterm:[.htaccess] The " +"[option]`AllowOverride` directive allows you to specify which directives in " +"a `.htaccess` file can override the default configuration. It takes the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:589 +#, no-wrap +msgid "AllowOverride _type_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:592 +msgid "" +"The _type_ has to be one of the available grouping options as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-allowoverride[Available " +"AllowOverride options]." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:594 +#, no-wrap +msgid "Available AllowOverride options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:606 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`All`|All directives in `.htaccess` are allowed to override earlier " +"configuration settings.\n" +"|[option]`None`|No directive in `.htaccess` is allowed to override earlier " +"configuration settings.\n" +"|[option]`AuthConfig`|Allows the use of authorization directives such as " +"[option]`AuthName`, [option]`AuthType`, or [option]`Require`.\n" +"|[option]`FileInfo`|Allows the use of file type, metadata, and `mod_rewrite` " +"directives such as [option]`DefaultType`, [option]`RequestHeader`, or " +"[option]`RewriteEngine`, as well as the [option]`Action` directive.\n" +"|[option]`Indexes`|Allows the use of directory indexing directives such as " +"[option]`AddDescription`, [option]`AddIcon`, or [option]`FancyIndexing`.\n" +"|[option]`Limit`|Allows the use of host access directives, that is, " +"[option]`Allow`, [option]`Deny`, and [option]`Order`.\n" +"|[option]`Options`pass:attributes[{blank}]=pass:attributes[{blank}]_option_,…|Allows " +"the use of the [option]`Options` directive. Additionally, you can provide a " +"comma-separated list of options to customize which options can be set using " +"this directive.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:609 +#, no-wrap +msgid "Using the AllowOverride directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:615 +#, no-wrap +msgid "AllowOverride FileInfo AuthConfig Limit\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:619 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,BrowserMatch] " +"[option]`BrowserMatch`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:620 +msgid "" +"The [option]`BrowserMatch` directive allows you to modify the server " +"behavior based on the client's web browser type. It takes the following " +"form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:624 +#, no-wrap +msgid "BrowserMatch _pattern_ _variable_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:627 +msgid "" +"The _pattern_ is a regular expression to match the User-Agent HTTP header " +"field. The _variable_ is an environment variable that is set when the header " +"field matches the pattern." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:629 +msgid "" +"By default, this directive is used to deny connections to specific browsers " +"with known issues, and to disable keepalives and HTTP header flushes for " +"browsers that are known to have problems with these actions." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:631 +#, no-wrap +msgid "Using the BrowserMatch directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:637 +#, no-wrap +msgid "BrowserMatch \"Mozilla/2\" nokeepalive\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:641 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,CacheDefaultExpire] " +"[option]`CacheDefaultExpire`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:642 +msgid "" +"The [option]`CacheDefaultExpire` option allows you to set how long to cache " +"a document that does not have any expiration date or the date of its last " +"modification specified. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:646 +#, no-wrap +msgid "CacheDefaultExpire _time_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:649 +msgid "" +"The _time_ is specified in seconds. The default option is `3600` (that is, " +"one hour)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:651 +#, no-wrap +msgid "Using the CacheDefaultExpire directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:657 +#, no-wrap +msgid "CacheDefaultExpire 3600\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:661 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,CacheDisable] " +"[option]`CacheDisable`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:662 +msgid "" +"The [option]`CacheDisable` directive allows you to disable caching of " +"certain URLs. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:666 +#, no-wrap +msgid "CacheDisable _path_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:669 +msgid "" +"The _path_ must be relative to the directory specified by the " +"[option]`DocumentRoot` directive (for example, `/files/`)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:671 +#, no-wrap +msgid "Using the CacheDisable directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:677 +#, no-wrap +msgid "CacheDisable /temporary\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:681 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,CacheEnable] " +"[option]`CacheEnable`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:682 +msgid "" +"The [option]`CacheEnable` directive allows you to specify a cache type to be " +"used for certain URLs. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:686 +#, no-wrap +msgid "CacheEnable _type_ _url_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:689 +msgid "" +"The _type_ has to be a valid cache type as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-cacheenable[Available cache " +"types]. The _url_ can be a path relative to the directory specified by the " +"[option]`DocumentRoot` directive (for example, `/images/`), a protocol (for " +"example, `ftp://`), or an external URL such as `http://example.com/`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:691 +#, no-wrap +msgid "Available cache types" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:699 +#, no-wrap +msgid "" +"|Type|Description\n" +"|[option]`mem`|The memory-based storage manager.\n" +"|[option]`disk`|The disk-based storage manager.\n" +"|[option]`fd`|The file descriptor cache.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:702 +#, no-wrap +msgid "Using the CacheEnable directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:708 +#, no-wrap +msgid "CacheEnable disk /\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:712 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,CacheLastModifiedFactor] " +"[option]`CacheLastModifiedFactor`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:713 +msgid "" +"The [option]`CacheLastModifiedFactor` directive allows you to customize how " +"long to cache a document that does not have any expiration date specified, " +"but that provides information about the date of its last modification. It " +"takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:717 +#, no-wrap +msgid "CacheLastModifiedFactor _number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:720 +msgid "" +"The _number_ is a coefficient to be used to multiply the time that passed " +"since the last modification of the document. The default option is `0.1` " +"(that is, one tenth)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:722 +#, no-wrap +msgid "Using the CacheLastModifiedFactor directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:728 +#, no-wrap +msgid "CacheLastModifiedFactor 0.1\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:732 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,CacheMaxExpire] " +"[option]`CacheMaxExpire`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:733 +msgid "" +"The [option]`CacheMaxExpire` directive allows you to specify the maximum " +"amount of time to cache a document. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:737 +#, no-wrap +msgid "CacheMaxExpire _time_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:740 +msgid "" +"The _time_ is specified in seconds. The default option is `86400` (that is, " +"one day)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:742 +#, no-wrap +msgid "Using the CacheMaxExpire directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:748 +#, no-wrap +msgid "CacheMaxExpire 86400\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:752 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,CacheNegotiatedDocs] " +"[option]`CacheNegotiatedDocs`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:753 +msgid "" +"The [option]`CacheNegotiatedDocs` directive allows you to enable caching of " +"the documents that were negotiated on the basis of content. It takes the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:757 +#, no-wrap +msgid "CacheNegotiatedDocs _option_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:760 +msgid "" +"The _option_ has to be a valid keyword as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-cachenegotiateddocs[Available " +"CacheNegotiatedDocs options]. Since the content-negotiated documents may " +"change over time or because of the input from the requester, the default " +"option is [option]`Off`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:762 +#, no-wrap +msgid "Available CacheNegotiatedDocs options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:769 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`On`|Enables caching the content-negotiated documents.\n" +"|[option]`Off`|Disables caching the content-negotiated documents.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:772 +#, no-wrap +msgid "Using the CacheNegotiatedDocs directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:778 +#, no-wrap +msgid "CacheNegotiatedDocs On\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:782 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,CacheRoot] " +"[option]`CacheRoot`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:783 +msgid "" +"The [option]`CacheRoot` directive allows you to specify the directory to " +"store cache files in. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:787 +#, no-wrap +msgid "CacheRoot _directory_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:790 +msgid "" +"indexterm:[Apache HTTP Server,directories,/var/cache/mod_proxy/] The " +"_directory_ must be a full path to an existing directory in the local file " +"system. The default option is `/var/cache/mod_proxy/`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:792 +#, no-wrap +msgid "Using the CacheRoot directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:797 +#, no-wrap +msgid "CacheRoot /var/cache/mod_proxy\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:801 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,CustomLog] " +"[option]`CustomLog`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:802 +msgid "" +"The [option]`CustomLog` directive allows you to specify the log file name " +"and the log file format. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:806 +#, no-wrap +msgid "CustomLog _path_ _format_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:809 +msgid "" +"indexterm:[Apache HTTP Server,files,/etc/httpd/logs/access_log] The _path_ " +"refers to a log file, and must be relative to the directory that is " +"specified by the [option]`ServerRoot` directive (that is, `/etc/httpd/` by " +"default). The _format_ has to be either an explicit format string, or a " +"format name that was previously defined using the [option]`LogFormat` " +"directive." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:811 +#, no-wrap +msgid "Using the CustomLog directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:816 +#, no-wrap +msgid "CustomLog logs/access_log combined\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:820 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,DefaultIcon] " +"[option]`DefaultIcon`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:821 +msgid "" +"The [option]`DefaultIcon` directive allows you to specify an icon to be " +"displayed for a file in server-generated directory listings when no other " +"icon is associated with it. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:825 +#, no-wrap +msgid "DefaultIcon _path_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:828 +msgid "" +"The _path_ refers to an existing icon file, and must be relative to the " +"directory specified by the [option]`DocumentRoot` directive (for example, " +"`/icons/unknown.png`)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:830 +#, no-wrap +msgid "Using the DefaultIcon directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:836 +#, no-wrap +msgid "DefaultIcon /icons/unknown.png\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:840 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,DefaultType] " +"[option]`DefaultType`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:841 +msgid "" +"The [option]`DefaultType` directive allows you to specify a media type to be " +"used in case the proper MIME type cannot be determined by the server. It " +"takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:845 +#, no-wrap +msgid "DefaultType _content-type_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:848 +msgid "" +"The _content-type_ has to be a valid MIME type such as `text/html`, " +"`image/png`, `application/pdf`, etc." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:850 +#, no-wrap +msgid "Using the DefaultType directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:856 +#, no-wrap +msgid "DefaultType text/plain\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:860 +#, no-wrap +msgid "indexterm:[Apache HTTP Server,directives,Deny] [option]`Deny`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:861 +msgid "" +"The [option]`Deny` directive allows you to specify which clients are denied " +"access to a given directory. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:865 +#, no-wrap +msgid "Deny from _client_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:870 +#, no-wrap +msgid "Using the Deny directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:876 +#, no-wrap +msgid "Deny from 192.168.1.1\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:880 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,DirectoryIndex] " +"[option]`DirectoryIndex`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:881 +msgid "" +"The [option]`DirectoryIndex` directive allows you to specify a document to " +"be served to a client when a directory is requested (that is, when the URL " +"ends with the `/` character). It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:885 +#, no-wrap +msgid "DirectoryIndex _filename_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:888 +msgid "" +"The _filename_ is a name of the file to look for in the requested " +"directory. By default, the server looks for `index.html`, and " +"`index.html.var`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:890 +#, no-wrap +msgid "Using the DirectoryIndex directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:896 +#, no-wrap +msgid "DirectoryIndex index.html index.html.var\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:900 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,DocumentRoot] " +"[option]`DocumentRoot`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:901 +msgid "" +"The [option]`DocumentRoot` directive allows you to specify the main " +"directory from which the content is served. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:905 +#, no-wrap +msgid "DocumentRoot _directory_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:908 +msgid "" +"indexterm:[Apache HTTP Server,directories,/var/www/html/] The _directory_ " +"must be a full path to an existing directory in the local file system. The " +"default option is `/var/www/html/`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:910 +#, no-wrap +msgid "Using the DocumentRoot directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:916 +#, no-wrap +msgid "DocumentRoot /var/www/html\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:920 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,ErrorDocument] " +"[option]`ErrorDocument`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:921 +msgid "" +"The [option]`ErrorDocument` directive allows you to specify a document or a " +"message to be displayed as a response to a particular error. It takes the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:925 +#, no-wrap +msgid "ErrorDocument _error-code_ _action_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:928 +msgid "" +"The _error-code_ has to be a valid code such as `403` (Forbidden), `404` " +"(Not Found), or `500` (Internal Server Error). The _action_ can be either a " +"URL (both local and external), or a message string enclosed in double quotes " +"(that is, `\"`)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:930 +#, no-wrap +msgid "Using the ErrorDocument directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:936 +#, no-wrap +msgid "" +"ErrorDocument 403 \"Access Denied\"\n" +"ErrorDocument 404 /404-not_found.html\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:940 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,ErrorLog] " +"[option]`ErrorLog`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:941 +msgid "" +"The [option]`ErrorLog` directive allows you to specify a file to which the " +"server errors are logged. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:945 +#, no-wrap +msgid "ErrorLog _path_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:948 +msgid "" +"indexterm:[Apache HTTP Server,files,/etc/httpd/logs/error_log] The _path_ " +"refers to a log file, and can be either absolute, or relative to the " +"directory that is specified by the [option]`ServerRoot` directive (that is, " +"`/etc/httpd/` by default). The default option is `logs/error_log`" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:950 +#, no-wrap +msgid "Using the ErrorLog directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:955 +#, no-wrap +msgid "ErrorLog logs/error_log\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:959 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,ExtendedStatus] " +"[option]`ExtendedStatus`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:960 +msgid "" +"The [option]`ExtendedStatus` directive allows you to enable detailed server " +"status information. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:964 +#, no-wrap +msgid "ExtendedStatus _option_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:967 +msgid "" +"The _option_ has to be a valid keyword as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-extendedstatus[Available " +"ExtendedStatus options]. The default option is [option]`Off`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:969 +#, no-wrap +msgid "Available ExtendedStatus options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:976 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`On`|Enables generating the detailed server status.\n" +"|[option]`Off`|Disables generating the detailed server status.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:979 +#, no-wrap +msgid "Using the ExtendedStatus directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:985 +#, no-wrap +msgid "ExtendedStatus On\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:989 +#, no-wrap +msgid "indexterm:[Apache HTTP Server,directives,Group] [option]`Group`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:990 +msgid "" +"The [option]`Group` directive allows you to specify the group under which " +"the `httpd` service will run. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:994 +#, no-wrap +msgid "Group _group_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:997 +msgid "" +"The _group_ has to be an existing UNIX group. The default option is " +"[option]`apache`." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:999 +msgid "" +"Note that [option]`Group` is no longer supported inside " +"[option]``, and has been replaced by the " +"[option]`SuexecUserGroup` directive." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1001 +#, no-wrap +msgid "Using the Group directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1007 +#, no-wrap +msgid "Group apache\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1011 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,HeaderName] " +"[option]`HeaderName`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1012 +msgid "" +"The [option]`HeaderName` directive allows you to specify a file to be " +"prepended to the beginning of the server-generated directory listing. It " +"takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1016 +#, no-wrap +msgid "HeaderName _filename_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1019 +msgid "" +"The _filename_ is a name of the file to look for in the requested " +"directory. By default, the server looks for `HEADER.html`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1021 +#, no-wrap +msgid "Using the HeaderName directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1027 +#, no-wrap +msgid "HeaderName HEADER.html\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1031 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,HostnameLookups] " +"[option]`HostnameLookups`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1032 +msgid "" +"The [option]`HostnameLookups` directive allows you to enable automatic " +"resolving of IP addresses. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1036 +#, no-wrap +msgid "HostnameLookups _option_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1039 +msgid "" +"The _option_ has to be a valid keyword as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-hostnamelookup[Available " +"HostnameLookups options]. To conserve resources on the server, the default " +"option is [option]`Off`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1041 +#, no-wrap +msgid "Available HostnameLookups options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1049 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`On`|Enables resolving the IP address for each connection so that " +"the hostname can be logged. However, this also adds a significant processing " +"overhead.\n" +"|[option]`Double`|Enables performing the double-reverse DNS lookup. In " +"comparison to the above option, this adds even more processing overhead.\n" +"|[option]`Off`|Disables resolving the IP address for each connection.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1052 +msgid "" +"Note that when the presence of hostnames is required in server log files, it " +"is often possible to use one of the many log analyzer tools that perform the " +"DNS lookups more efficiently." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1054 +#, no-wrap +msgid "Using the HostnameLookups directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1060 +#, no-wrap +msgid "HostnameLookups Off\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1064 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,Include] " +"[option]`Include`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1065 +msgid "" +"The [option]`Include` directive allows you to include other configuration " +"files. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1069 +#, no-wrap +msgid "Include _filename_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1072 +msgid "" +"indexterm:[Apache HTTP Server,directories,/etc/httpd/conf.d/] The " +"[option]`filename` can be an absolute path, a path relative to the directory " +"specified by the [option]`ServerRoot` directive, or a wildcard " +"expression. All configuration files from the `/etc/httpd/conf.d/` directory " +"are loaded by default." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1074 +#, no-wrap +msgid "Using the Include directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1079 +#, no-wrap +msgid "Include conf.d/*.conf\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1083 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,IndexIgnore] " +"[option]`IndexIgnore`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1084 +msgid "" +"The [option]`IndexIgnore` directive allows you to specify a list of file " +"names to be omitted from the server-generated directory listings. It takes " +"the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1088 +#, no-wrap +msgid "IndexIgnore _filename_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1091 +msgid "" +"The _filename_ option can be either a full file name, or a wildcard " +"expression." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1093 +#, no-wrap +msgid "Using the IndexIgnore directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1098 +#, no-wrap +msgid "IndexIgnore .??* *~ *# HEADER* README* RCS CVS *,v *,t\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1102 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,IndexOptions] " +"[option]`IndexOptions`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1103 +msgid "" +"The [option]`IndexOptions` directive allows you to customize the behavior of " +"server-generated directory listings. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1107 +#, no-wrap +msgid "IndexOptions _option_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1110 +msgid "" +"The _option_ has to be a valid keyword as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-indexoptions[Available " +"directory listing options]. The default options are [option]`Charset=UTF-8`, " +"[option]`FancyIndexing`, [option]`HTMLTable`, [option]`NameWidth=*`, and " +"[option]`VersionSort`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1112 +#, no-wrap +msgid "Available directory listing options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1141 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`Charset`pass:attributes[{blank}]=pass:attributes[{blank}]_encoding_|Specifies " +"the character set of a generated web page. The _encoding_ has to be a valid " +"character set such as `UTF-8` or `ISO-8859-2`.\n" +"|[option]`Type`pass:attributes[{blank}]=pass:attributes[{blank}]_content-type_|Specifies " +"the media type of a generated web page. The _content-type_ has to be a valid " +"MIME type such as `text/html` or `text/plain`.\n" +"|[option]`DescriptionWidth`pass:attributes[{blank}]=pass:attributes[{blank}]_value_|Specifies " +"the width of the description column. The _value_ can be either a number of " +"characters, or an asterisk (that is, `*`) to adjust the width " +"automatically.\n" +"|[option]`FancyIndexing`|Enables advanced features such as different icons " +"for certain files or possibility to re-sort a directory listing by clicking " +"on a column header.\n" +"|[option]`FolderFirst`|Enables listing directories first, always placing " +"them above files.\n" +"|[option]`HTMLTable`|Enables the use of HTML tables for directory " +"listings.\n" +"|[option]`IconsAreLinks`|Enables using the icons as links.\n" +"|[option]`IconHeight`pass:attributes[{blank}]=pass:attributes[{blank}]_value_|Specifies " +"an icon height. The _value_ is a number of pixels.\n" +"|[option]`IconWidth`pass:attributes[{blank}]=pass:attributes[{blank}]_value_|Specifies " +"an icon width. The _value_ is a number of pixels.\n" +"|[option]`IgnoreCase`|Enables sorting files and directories in a " +"case-sensitive manner.\n" +"|[option]`IgnoreClient`|Disables accepting query variables from a client.\n" +"|[option]`NameWidth`pass:attributes[{blank}]=pass:attributes[{blank}]_value_|Specifies " +"the width of the file name column. The _value_ can be either a number of " +"characters, or an asterisk (that is, `*`) to adjust the width " +"automatically.\n" +"|[option]`ScanHTMLTitles`|Enables parsing the file for a description (that " +"is, the `title` element) in case it is not provided by the " +"[option]`AddDescription` directive.\n" +"|[option]`ShowForbidden`|Enables listing the files with otherwise restricted " +"access.\n" +"|[option]`SuppressColumnSorting`|Disables re-sorting a directory listing by " +"clicking on a column header.\n" +"|[option]`SuppressDescription`|Disables reserving a space for file " +"descriptions.\n" +"|[option]`SuppressHTMLPreamble`|Disables the use of standard HTML preamble " +"when a file specified by the [option]`HeaderName` directive is present.\n" +"|[option]`SuppressIcon`|Disables the use of icons in directory listings.\n" +"|[option]`SuppressLastModified`|Disables displaying the date of the last " +"modification field in directory listings.\n" +"|[option]`SuppressRules`|Disables the use of horizontal lines in directory " +"listings.\n" +"|[option]`SuppressSize`|Disables displaying the file size field in directory " +"listings.\n" +"|[option]`TrackModified`|Enables returning the `Last-Modified` and `ETag` " +"values in the HTTP header.\n" +"|[option]`VersionSort`|Enables sorting files that contain a version number " +"in the expected manner.\n" +"|[option]`XHTML`|Enables the use of XHTML 1.0 instead of the default HTML " +"3.2.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1144 +#, no-wrap +msgid "Using the IndexOptions directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1149 +#, no-wrap +msgid "IndexOptions FancyIndexing VersionSort NameWidth=* HTMLTable Charset=UTF-8\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1153 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,KeepAlive] " +"[option]`KeepAlive`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1154 +msgid "" +"The [option]`KeepAlive` directive allows you to enable persistent " +"connections. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1158 +#, no-wrap +msgid "KeepAlive _option_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1161 +msgid "" +"The _option_ has to be a valid keyword as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-keepalive[Available KeepAlive " +"options]. The default option is [option]`Off`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1163 +#, no-wrap +msgid "Available KeepAlive options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1170 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`On`|Enables the persistent connections. In this case, the server " +"will accept more than one request per connection.\n" +"|[option]`Off`|Disables the keep-alive connections.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1173 +msgid "" +"Note that when the persistent connections are enabled, on a busy server, the " +"number of child processes can increase rapidly and eventually reach the " +"maximum limit, slowing down the server significantly. To reduce the risk, it " +"is recommended that you set [option]`KeepAliveTimeout` to a low number, and " +"monitor the `/var/log/httpd/logs/error_log` log file carefully." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1175 +#, no-wrap +msgid "Using the KeepAlive directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1181 +#, no-wrap +msgid "KeepAlive Off\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1185 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,KeepAliveTimeout] " +"[option]`KeepAliveTimeout`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1186 +msgid "" +"The [option]`KeepAliveTimeout` directive allows you to specify the amount of " +"time to wait for another request before closing the connection. It takes the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1190 +#, no-wrap +msgid "KeepAliveTimeout _time_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1193 +msgid "The _time_ is specified in seconds. The default option is `15`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1195 +#, no-wrap +msgid "Using the KeepAliveTimeout directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1201 +#, no-wrap +msgid "KeepAliveTimeout 15\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1205 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,LanguagePriority] " +"[option]`LanguagePriority`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1206 +msgid "" +"The [option]`LanguagePriority` directive allows you to customize the " +"precedence of languages. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1210 +#, no-wrap +msgid "LanguagePriority _language_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1213 +msgid "The _language_ has to be a valid MIME language such as `cs`, `en`, or `fr`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1217 +#, no-wrap +msgid "Using the LanguagePriority directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1223 +#, no-wrap +msgid "LanguagePriority sk cs en\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1227 +#, no-wrap +msgid "indexterm:[Apache HTTP Server,directives,Listen] [option]`Listen`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1228 +msgid "" +"The _Listen_ directive allows you to specify IP addresses or ports to listen " +"to. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1232 +#, no-wrap +msgid "Listen _ip-address_:pass:attributes[{blank}]_port_ _protocol_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1235 +msgid "" +"The _ip-address_ is optional and unless supplied, the server will accept " +"incoming requests on a given _port_ from all IP addresses. Since the " +"_protocol_ is determined automatically from the port number, it can be " +"usually omitted. The default option is to listen to port `80`." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1237 +msgid "" +"Note that if the server is configured to listen to a port under 1024, only " +"superuser will be able to start the `httpd` service." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1239 +#, no-wrap +msgid "Using the Listen directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1245 +#, no-wrap +msgid "Listen 80\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1249 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,LoadModule] " +"[option]`LoadModule`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1250 +msgid "" +"The [option]`LoadModule` directive allows you to load a _Dynamic Shared " +"Object_ (*DSO*) module. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1254 +#, no-wrap +msgid "LoadModule _name_ _path_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1257 +msgid "" +"indexterm:[Apache HTTP " +"Server,directories,/usr/lib/httpd/modules/]indexterm:[Apache HTTP " +"Server,directories,/usr/lib64/httpd/modules/] The _name_ has to be a valid " +"identifier of the required module. The _path_ refers to an existing module " +"file, and must be relative to the directory in which the libraries are " +"placed (that is, `/usr/lib/httpd/` on 32-bit and `/usr/lib64/httpd/` on " +"64-bit systems by default)." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1259 +msgid "" +"See xref:Web_Servers.adoc#s2-apache-dso[Working with Modules] for more " +"information on the Apache HTTP Server's DSO support." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1261 +#, no-wrap +msgid "Using the LoadModule directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1266 +#, no-wrap +msgid "LoadModule php5_module modules/libphp5.so\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1270 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,LogFormat] " +"[option]`LogFormat`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1271 +msgid "" +"The _LogFormat_ directive allows you to specify a log file format. It takes " +"the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1275 +#, no-wrap +msgid "LogFormat _format_ _name_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1278 +msgid "" +"The _format_ is a string consisting of options as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-logformat[Common LogFormat " +"options]. The _name_ can be used instead of the format string in the " +"[option]`CustomLog` directive." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1280 +#, no-wrap +msgid "Common LogFormat options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1293 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`%b`|Represents the size of the response in bytes.\n" +"|[option]`%h`|Represents the IP address or hostname of a remote client.\n" +"|[option]`%l`|Represents the remote log name if supplied. If not, a hyphen " +"(that is, `-`) is used instead.\n" +"|[option]`%r`|Represents the first line of the request string as it came " +"from the browser or client.\n" +"|[option]`%s`|Represents the status code.\n" +"|[option]`%t`|Represents the date and time of the request.\n" +"|[option]`%u`|If the authentication is required, it represents the remote " +"user. If not, a hyphen (that is, `-`) is used instead.\n" +"|[option]`%{pass:attributes[{blank}]_field_pass:attributes[{blank}]}`|Represents " +"the content of the HTTP header _field_. The common options include " +"[option]`%\\{Referer}` (the URL of the web page that referred the client to " +"the server) and [option]`%\\{User-Agent}` (the type of the web browser " +"making the request).\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1296 +#, no-wrap +msgid "Using the LogFormat directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1302 +#, no-wrap +msgid "LogFormat \"%h %l %u %t \\\"%r\\\" %>s %b\" common\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1306 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,LogLevel] " +"[option]`LogLevel`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1307 +msgid "" +"The [option]`LogLevel` directive allows you to customize the verbosity level " +"of the error log. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1311 +#, no-wrap +msgid "LogLevel _option_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1314 +msgid "" +"The _option_ has to be a valid keyword as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-loglevel[Available LogLevel " +"options]. The default option is [option]`warn`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1316 +#, no-wrap +msgid "Available LogLevel options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1329 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`emerg`|Only the emergency situations when the server cannot " +"perform its work are logged.\n" +"|[option]`alert`|All situations when an immediate action is required are " +"logged.\n" +"|[option]`crit`|All critical conditions are logged.\n" +"|[option]`error`|All error messages are logged.\n" +"|[option]`warn`|All warning messages are logged.\n" +"|[option]`notice`|Even normal, but still significant situations are " +"logged.\n" +"|[option]`info`|Various informational messages are logged.\n" +"|[option]`debug`|Various debugging messages are logged.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1332 +#, no-wrap +msgid "Using the LogLevel directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1338 +#, no-wrap +msgid "LogLevel warn\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1342 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,MaxKeepAliveRequests] " +"[option]`MaxKeepAliveRequests`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1343 +msgid "" +"The [option]`MaxKeepAliveRequests` directive allows you to specify the " +"maximum number of requests for a persistent connection. It takes the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1348 +#, no-wrap +msgid "MaxKeepAliveRequests _number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1351 +msgid "" +"A high _number_ can improve the performance of the server. Note that using " +"`0` allows unlimited number of requests. The default option is " +"[option]`100`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1353 +#, no-wrap +msgid "Using the MaxKeepAliveRequests option" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1359 +#, no-wrap +msgid "MaxKeepAliveRequests 100\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1363 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,NameVirtualHost] " +"[option]`NameVirtualHost`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1364 +msgid "" +"The [option]`NameVirtualHost` directive allows you to specify the IP address " +"and port number for a name-based virtual host. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1368 +#, no-wrap +msgid "NameVirtualHost _ip-address_:pass:attributes[{blank}]_port_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1371 +msgid "" +"The _ip-address_ can be either a full IP address, or an asterisk (that is, " +"`*`) representing all interfaces. Note that IPv6 addresses have to be " +"enclosed in square brackets (that is, `[` and `]`). The _port_ is optional." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1373 +msgid "" +"Name-based virtual hosting allows one Apache HTTP Server to serve different " +"domains without using multiple IP addresses." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1374 +#, no-wrap +msgid "Using secure HTTP connections" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1379 +msgid "" +"Name-based virtual hosts *only* work with non-secure HTTP connections. If " +"using virtual hosts with a secure server, use IP address-based virtual hosts " +"instead." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1383 +#, no-wrap +msgid "Using the NameVirtualHost directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1388 +#, no-wrap +msgid "NameVirtualHost *:80\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1392 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,Options] " +"[option]`Options`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1393 +msgid "" +"The [option]`Options` directive allows you to specify which server features " +"are available in a particular directory. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1397 +#, no-wrap +msgid "Options _option_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1400 +msgid "" +"The _option_ has to be a valid keyword as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-options[Available server " +"features]." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1402 +#, no-wrap +msgid "Available server features" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1416 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`ExecCGI`|Enables the execution of CGI scripts.\n" +"|[option]`FollowSymLinks`|Enables following symbolic links in the " +"directory.\n" +"|[option]`Includes`|Enables server-side includes.\n" +"|[option]`IncludesNOEXEC`|Enables server-side includes, but does not allow " +"the execution of commands.\n" +"|[option]`Indexes`|Enables server-generated directory listings.\n" +"|[option]`MultiViews`|Enables content-negotiated \"`MultiViews`\".\n" +"|[option]`SymLinksIfOwnerMatch`|Enables following symbolic links in the " +"directory when both the link and the target file have the same owner.\n" +"|[option]`All`|Enables all of the features above with the exception of " +"[option]`MultiViews`.\n" +"|[option]`None`|Disables all of the features above.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1419 +#, no-wrap +msgid "Using the Options directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1425 +#, no-wrap +msgid "Options Indexes FollowSymLinks\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1429 +#, no-wrap +msgid "indexterm:[Apache HTTP Server,directives,Order] [option]`Order`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1430 +msgid "" +"The [option]`Order` directive allows you to specify the order in which the " +"[option]`Allow` and [option]`Deny` directives are evaluated. It takes the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1434 +#, no-wrap +msgid "Order _option_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1437 +msgid "" +"The _option_ has to be a valid keyword as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-order[Available Order " +"options]. The default option is [option]`allow,deny`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1439 +#, no-wrap +msgid "Available Order options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1446 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`allow,deny`|[option]`Allow` directives are evaluated first.\n" +"|[option]`deny,allow`|[option]`Deny` directives are evaluated first.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1449 +#, no-wrap +msgid "Using the Order directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1455 +#, no-wrap +msgid "Order allow,deny\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1459 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,PidFile] " +"[option]`PidFile`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1460 +msgid "" +"The [option]`PidFile` directive allows you to specify a file to which the " +"_process ID_ (*PID*) of the server is stored. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1464 +#, no-wrap +msgid "PidFile _path_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1467 +msgid "" +"indexterm:[Apache HTTP Server,files,/etc/httpd/run/httpd.pid] The _path_ " +"refers to a pid file, and can be either absolute, or relative to the " +"directory that is specified by the [option]`ServerRoot` directive (that is, " +"`/etc/httpd/` by default). The default option is `run/httpd.pid`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1469 +#, no-wrap +msgid "Using the PidFile directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1475 +#, no-wrap +msgid "PidFile run/httpd.pid\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1479 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,ProxyRequests] " +"[option]`ProxyRequests`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1480 +msgid "" +"The [option]`ProxyRequests` directive allows you to enable forward proxy " +"requests. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1484 +#, no-wrap +msgid "ProxyRequests _option_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1487 +msgid "" +"The _option_ has to be a valid keyword as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-proxyrequests[Available " +"ProxyRequests options]. The default option is [option]`Off`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1489 +#, no-wrap +msgid "Available ProxyRequests options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1496 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`On`|Enables forward proxy requests.\n" +"|[option]`Off`|Disables forward proxy requests.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1499 +#, no-wrap +msgid "Using the ProxyRequests directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1505 +#, no-wrap +msgid "ProxyRequests On\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1509 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,ReadmeName] " +"[option]`ReadmeName`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1510 +msgid "" +"The [option]`ReadmeName` directive allows you to specify a file to be " +"appended to the end of the server-generated directory listing. It takes the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1514 +#, no-wrap +msgid "ReadmeName _filename_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1517 +msgid "" +"The _filename_ is a name of the file to look for in the requested " +"directory. By default, the server looks for `README.html`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1519 +#, no-wrap +msgid "Using the ReadmeName directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1525 +#, no-wrap +msgid "ReadmeName README.html\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1529 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,Redirect] " +"[option]`Redirect`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1530 +msgid "" +"The [option]`Redirect` directive allows you to redirect a client to another " +"URL. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1534 +#, no-wrap +msgid "Redirect _status_ _path_ _url_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1537 +msgid "" +"The _status_ is optional, and if provided, it has to be a valid keyword as " +"described in xref:Web_Servers.adoc#table-apache-httpdconf-redirect[Available " +"status options]. The _path_ refers to the old location, and must be relative " +"to the directory specified by the [option]`DocumentRoot` directive (for " +"example, `/docs`). The _url_ refers to the current location of the content " +"(for example, `http://docs.example.com`)." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1539 +#, no-wrap +msgid "Available status options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1548 +#, no-wrap +msgid "" +"|Status|Description\n" +"|[option]`permanent`|Indicates that the requested resource has been moved " +"permanently. The `301` (Moved Permanently) status code is returned to a " +"client.\n" +"|[option]`temp`|Indicates that the requested resource has been moved only " +"temporarily. The `302` (Found) status code is returned to a client.\n" +"|[option]`seeother`|Indicates that the requested resource has been " +"replaced. The `303` (See Other) status code is returned to a client.\n" +"|[option]`gone`|Indicates that the requested resource has been removed " +"permanently. The `410` (Gone) status is returned to a client.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1551 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,modules,mod_rewrite]\n" +"Note that for more advanced redirection techniques, you can use the " +"`mod_rewrite` module that is part of the Apache HTTP Server installation.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1553 +#, no-wrap +msgid "Using the Redirect directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1559 +#, no-wrap +msgid "Redirect permanent /docs http://docs.example.com\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1563 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,ScriptAlias] " +"[option]`ScriptAlias`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1564 +msgid "" +"The [option]`ScriptAlias` directive allows you to specify the location of " +"CGI scripts. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1568 +#, no-wrap +msgid "ScriptAlias _url-path_ _real-path_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1573 +msgid "" +"The _url-path_ must be relative to the directory specified by the " +"[option]`DocumentRoot` directive (for example, `/cgi-bin/`). The _real-path_ " +"is a full path to a file or directory in the local file system. " +"indexterm:[Apache HTTP Server,directories,/var/www/cgi-bin/] This directive " +"is typically followed by the [option]`Directory` tag with additional " +"permissions to access the target directory. By default, the `/cgi-bin/` " +"alias is created so that the scripts located in the `/var/www/cgi-bin/` are " +"accessible." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1575 +msgid "" +"The [option]`ScriptAlias` directive is used for security reasons to prevent " +"CGI scripts from being viewed as ordinary text documents." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1577 +#, no-wrap +msgid "Using the ScriptAlias directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1583 +#, no-wrap +msgid "ScriptAlias /cgi-bin/ /var/www/cgi-bin/\n" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1590 +#, no-wrap +msgid "" +"<Directory \"/var/www/cgi-bin\">\n" +" AllowOverride None\n" +" Options None\n" +" Order allow,deny\n" +" Allow from all\n" +"</Directory>\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1594 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,ServerAdmin] " +"[option]`ServerAdmin`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1595 +msgid "" +"The [option]`ServerAdmin` directive allows you to specify the email address " +"of the server administrator to be displayed in server-generated web " +"pages. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1599 +#, no-wrap +msgid "ServerAdmin _email_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1602 +msgid "The default option is `root@localhost`." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1604 +msgid "" +"This directive is commonly set to " +"`webmaster@pass:attributes[{blank}]_hostname_pass:attributes[{blank}]`, " +"where _hostname_ is the address of the server. Once set, alias `webmaster` " +"to the person responsible for the web server in `/etc/aliases`, and as " +"superuser, run the [command]#newaliases# command." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1606 +#, no-wrap +msgid "Using the ServerAdmin directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1612 +#, no-wrap +msgid "ServerAdmin webmaster@penguin.example.com\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1616 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,ServerName] " +"[option]`ServerName`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1617 +msgid "" +"The [option]`ServerName` directive allows you to specify the hostname and " +"the port number of a web server. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1621 +#, no-wrap +msgid "ServerName _hostname_:pass:attributes[{blank}]_port_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1624 +msgid "" +"The _hostname_ has to be a _fully qualified domain name_ (*FQDN*) of the " +"server. The _port_ is optional, but when supplied, it has to match the " +"number specified by the [option]`Listen` directive." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1626 +msgid "" +"When using this directive, make sure that the IP address and server name " +"pair are included in the `/etc/hosts` file." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1628 +#, no-wrap +msgid "Using the ServerName directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1634 +#, no-wrap +msgid "ServerName penguin.example.com:80\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1638 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,ServerRoot] " +"[option]`ServerRoot`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1639 +msgid "" +"The [option]`ServerRoot` directive allows you to specify the directory in " +"which the server operates. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1643 +#, no-wrap +msgid "ServerRoot _directory_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1646 +msgid "" +"indexterm:[Apache HTTP Server,directories,/etc/httpd/] The _directory_ must " +"be a full path to an existing directory in the local file system. The " +"default option is `/etc/httpd/`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1648 +#, no-wrap +msgid "Using the ServerRoot directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1654 +#, no-wrap +msgid "ServerRoot /etc/httpd\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1658 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,ServerSignature] " +"[option]`ServerSignature`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1659 +msgid "" +"The [option]`ServerSignature` directive allows you to enable displaying " +"information about the server on server-generated documents. It takes the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1663 +#, no-wrap +msgid "ServerSignature _option_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1666 +msgid "" +"The _option_ has to be a valid keyword as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-serversignature[Available " +"ServerSignature options]. The default option is [option]`On`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1668 +#, no-wrap +msgid "Available ServerSignature options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1676 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`On`|Enables appending the server name and version to " +"server-generated pages.\n" +"|[option]`Off`|Disables appending the server name and version to " +"server-generated pages.\n" +"|[option]`EMail`|Enables appending the server name, version, and the email " +"address of the system administrator as specified by the " +"[option]`ServerAdmin` directive to server-generated pages.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1679 +#, no-wrap +msgid "Using the ServerSignature directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1685 +#, no-wrap +msgid "ServerSignature On\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1689 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,ServerTokens] " +"[option]`ServerTokens`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1690 +msgid "" +"The [option]`ServerTokens` directive allows you to customize what " +"information are included in the Server response header. It takes the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1694 +#, no-wrap +msgid "ServerTokens _option_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1697 +msgid "" +"The _option_ has to be a valid keyword as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-servertokens[Available " +"ServerTokens options]. The default option is [option]`OS`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1699 +#, no-wrap +msgid "Available ServerTokens options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1710 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`Prod`|Includes the product name only (that is, `Apache`).\n" +"|[option]`Major`|Includes the product name and the major version of the " +"server (for example, `2`).\n" +"|[option]`Minor`|Includes the product name and the minor version of the " +"server (for example, `2.2`).\n" +"|[option]`Min`|Includes the product name and the minimal version of the " +"server (for example, `2.2.15`).\n" +"|[option]`OS`|Includes the product name, the minimal version of the server, " +"and the type of the operating system it is running on (for example, `Red " +"Hat`).\n" +"|[option]`Full`|Includes all the information above along with the list of " +"loaded modules.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1713 +msgid "" +"Note that for security reasons, it is recommended to reveal as little " +"information about the server as possible." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1715 +#, no-wrap +msgid "Using the ServerTokens directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1721 +#, no-wrap +msgid "ServerTokens Prod\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1725 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,SuexecUserGroup] " +"[option]`SuexecUserGroup`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1726 +msgid "" +"The [option]`SuexecUserGroup` directive allows you to specify the user and " +"group under which the CGI scripts will be run. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1730 +#, no-wrap +msgid "SuexecUserGroup _user_ _group_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1733 +msgid "" +"The _user_ has to be an existing user, and the _group_ must be a valid UNIX " +"group." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1735 +msgid "" +"For security reasons, the CGI scripts should not be run with `root` " +"privileges. Note that in [option]``, [option]`SuexecUserGroup` " +"replaces the [option]`User` and [option]`Group` directives." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1737 +#, no-wrap +msgid "Using the SuexecUserGroup directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1743 +#, no-wrap +msgid "SuexecUserGroup apache apache\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1747 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,Timeout] " +"[option]`Timeout`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1748 +msgid "" +"The [option]`Timeout` directive allows you to specify the amount of time to " +"wait for an event before closing a connection. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1752 +#, no-wrap +msgid "Timeout _time_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1755 +msgid "The _time_ is specified in seconds. The default option is `60`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1757 +#, no-wrap +msgid "Using the Timeout directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1763 +#, no-wrap +msgid "Timeout 60\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1767 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,TypesConfig] " +"[option]`TypesConfig`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1768 +msgid "" +"The [option]`TypesConfig` allows you to specify the location of the MIME " +"types configuration file. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1772 +#, no-wrap +msgid "TypesConfig _path_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1775 +msgid "" +"indexterm:[Apache HTTP Server,files,/etc/mime.types] The _path_ refers to an " +"existing MIME types configuration file, and can be either absolute, or " +"relative to the directory that is specified by the [option]`ServerRoot` " +"directive (that is, `/etc/httpd/` by default). The default option is " +"[option]`/etc/mime.types`." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1777 +msgid "" +"Note that instead of editing `/etc/mime.types`, the recommended way to add " +"MIME type mapping to the Apache HTTP Server is to use the [option]`AddType` " +"directive." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1779 +#, no-wrap +msgid "Using the TypesConfig directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1785 +#, no-wrap +msgid "TypesConfig /etc/mime.types\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1789 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,UseCanonicalName] " +"[option]`UseCanonicalName`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1790 +msgid "" +"The [option]`UseCanonicalName` allows you to specify the way the server " +"refers to itself. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1794 +#, no-wrap +msgid "UseCanonicalName _option_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1797 +msgid "" +"The _option_ has to be a valid keyword as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-usecanonicalname[Available " +"UseCanonicalName options]. The default option is [option]`Off`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1799 +#, no-wrap +msgid "Available UseCanonicalName options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1807 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`On`|Enables the use of the name that is specified by the " +"[option]`ServerName` directive.\n" +"|[option]`Off`|Disables the use of the name that is specified by the " +"[option]`ServerName` directive. The hostname and port number provided by the " +"requesting client are used instead.\n" +"|[option]`DNS`|Disables the use of the name that is specified by the " +"[option]`ServerName` directive. The hostname determined by a reverse DNS " +"lookup is used instead.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1810 +#, no-wrap +msgid "Using the UseCanonicalName directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1816 +#, no-wrap +msgid "UseCanonicalName Off\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1820 +#, no-wrap +msgid "indexterm:[Apache HTTP Server,directives,User] [option]`User`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1821 +msgid "" +"The [option]`User` directive allows you to specify the user under which the " +"`httpd` service will run. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1825 +#, no-wrap +msgid "User _user_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1828 +msgid "" +"The _user_ has to be an existing UNIX user. The default option is " +"[option]`apache`." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1830 +msgid "" +"For security reasons, the `httpd` service should not be run with `root` " +"privileges. Note that [option]`User` is no longer supported inside " +"[option]``, and has been replaced by the " +"[option]`SuexecUserGroup` directive." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1832 +#, no-wrap +msgid "Using the User directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1838 +#, no-wrap +msgid "User apache\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1842 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,UserDir] " +"[option]`UserDir`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1843 +msgid "" +"The [option]`UserDir` directive allows you to enable serving content from " +"users' home directories. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1847 +#, no-wrap +msgid "UserDir _option_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1850 +msgid "" +"indexterm:[Apache HTTP Server,directories,~/public_html/] The _option_ can " +"be either a name of the directory to look for in user's home directory " +"(typically [option]`public_html`), or a valid keyword as described in " +"xref:Web_Servers.adoc#table-apache-httpdconf-userdir[Available UserDir " +"options]. The default option is [option]`disabled`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1852 +#, no-wrap +msgid "Available UserDir options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1859 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`enabled`pass:attributes[{blank}] pass:attributes[{blank}]_user_pass:attributes[{blank}]…|Enables " +"serving content from home directories of given " +"_user_pass:attributes[{blank}]s.\n" +"|[option]`disabled`pass:attributes[{blank}] pass:attributes[{blank}]_user_pass:attributes[{blank}]…|Disables " +"serving content from home directories, either for all users, or, if a space " +"separated list of _user_pass:attributes[{blank}]s is supplied, for given " +"users only.\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1861 +#, no-wrap +msgid "Set the correct permissions" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1866 +msgid "" +"In order for the web server to access the content, the permissions on " +"relevant directories and files must be set correctly. Make sure that all " +"users are able to access the home directories, and that they can access and " +"read the content of the directory specified by the [option]`UserDir` " +"directive. For example, to allow access to `public_html/` in the home " +"directory of user `joe`, type the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1870 +#, no-wrap +msgid "" +"# chmod a+x /home/joe/\n" +"# chmod a+rx /home/joe/public_html/\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1873 +msgid "All files in this directory must be set accordingly." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1877 +#, no-wrap +msgid "Using the UserDir directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1882 +#, no-wrap +msgid "UserDir public_html\n" +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1887 +#, no-wrap +msgid "Common ssl.conf Directives" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1892 +msgid "" +"The _Secure Sockets Layer_ (*SSL*) directives allow you to customize the " +"behavior of the Apache HTTP Secure Server, and in most cases, they are " +"configured appropriately during the installation. Be careful when changing " +"these settings, as incorrect configuration can lead to security " +"vulnerabilities. indexterm:[Apache HTTP " +"Server,files,/etc/httpd/conf.d/ssl.conf] The following directive is commonly " +"used in `/etc/httpd/conf.d/ssl.conf`:" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1893 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,SetEnvIf] " +"[option]`SetEnvIf`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1894 +msgid "" +"The [option]`SetEnvIf` directive allows you to set environment variables " +"based on the headers of incoming connections. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1898 +#, no-wrap +msgid "" +"SetEnvIf _option_ _pattern_ " +"!_variable_pass:attributes[{blank}]=pass:attributes[{blank}]_value_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1901 +msgid "" +"The _option_ can be either a HTTP header field, a previously defined " +"environment variable name, or a valid keyword as described in " +"xref:Web_Servers.adoc#table-apache-sslconf-setenvif[Available SetEnvIf " +"options]. The _pattern_ is a regular expression. The _variable_ is an " +"environment variable that is set when the option matches the pattern. If the " +"optional exclamation mark (that is, `!`) is present, the variable is removed " +"instead of being set." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1903 +#, no-wrap +msgid "Available SetEnvIf options" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1914 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`Remote_Host`|Refers to the client's hostname.\n" +"|[option]`Remote_Addr`|Refers to the client's IP address.\n" +"|[option]`Server_Addr`|Refers to the server's IP address.\n" +"|[option]`Request_Method`|Refers to the request method (for example, " +"`GET`).\n" +"|[option]`Request_Protocol`|Refers to the protocol name and version (for " +"example, `HTTP/1.1`).\n" +"|[option]`Request_URI`|Refers to the requested resource.\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1917 +msgid "" +"The [option]`SetEnvIf` directive is used to disable HTTP keepalives, and to " +"allow SSL to close the connection without a closing notification from the " +"client browser. This is necessary for certain web browsers that do not " +"reliably shut down the SSL connection." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1919 +#, no-wrap +msgid "Using the SetEnvIf directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1926 +#, no-wrap +msgid "" +"SetEnvIf User-Agent \".*MSIE.*\" \\\n" +" nokeepalive ssl-unclean-shutdown \\\n" +" downgrade-1.0 force-response-1.0\n" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1931 +msgid "" +"Note that for the `/etc/httpd/conf.d/ssl.conf` file to be present, the " +"[package]*mod_ssl* needs to be installed. See " +"xref:Web_Servers.adoc#s2-apache-mod_ssl[Setting Up an SSL Server] for more " +"information on how to install and configure an SSL server." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1933 +#, no-wrap +msgid "Common Multi-Processing Module Directives" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1938 +msgid "" +"The _Multi-Processing Module_ (*MPM*) directives allow you to customize the " +"behavior of a particular MPM specific server-pool. Since its characteristics " +"differ depending on which MPM is used, the directives are embedded in " +"[option]`IfModule`. By default, the server-pool is defined for both the " +"`prefork` and `worker` MPMs. indexterm:[Apache HTTP " +"Server,files,/etc/httpd/conf/httpd.conf] The following MPM directives are " +"commonly used in `/etc/httpd/conf/httpd.conf`:" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1939 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,MaxClients] " +"[option]`MaxClients`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1940 +msgid "" +"The [option]`MaxClients` directive allows you to specify the maximum number " +"of simultaneously connected clients to process at one time. It takes the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1944 +#, no-wrap +msgid "MaxClients _number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1947 +msgid "" +"A high _number_ can improve the performance of the server, although it is " +"not recommended to exceed `256` when using the `prefork` MPM." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1949 +#, no-wrap +msgid "Using the MaxClients directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1955 +#, no-wrap +msgid "MaxClients 256\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1959 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,MaxClients] " +"[option]`MaxRequestsPerChild`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1960 +msgid "" +"The [option]`MaxRequestsPerChild` directive allows you to specify the " +"maximum number of request a child process can serve before it dies. It takes " +"the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1964 +#, no-wrap +msgid "MaxRequestsPerChild _number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1967 +msgid "Setting the _number_ to `0` allows unlimited number of requests." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1969 +msgid "" +"The [option]`MaxRequestsPerChild` directive is used to prevent long-lived " +"processes from causing memory leaks." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1971 +#, no-wrap +msgid "Using the MaxRequestsPerChild directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1977 +#, no-wrap +msgid "MaxRequestsPerChild 4000\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1981 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,MaxSpareServers] " +"[option]`MaxSpareServers`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1982 +msgid "" +"The [option]`MaxSpareServers` directive allows you to specify the maximum " +"number of spare child processes. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1986 +#, no-wrap +msgid "MaxSpareServers _number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1989 +msgid "This directive is used by the `prefork` MPM only." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1991 +#, no-wrap +msgid "Using the MaxSpareServers directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:1997 +#, no-wrap +msgid "MaxSpareServers 20\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2001 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,MaxSpareThreads] " +"[option]`MaxSpareThreads`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2002 +msgid "" +"The [option]`MaxSpareThreads` directive allows you to specify the maximum " +"number of spare server threads. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2006 +#, no-wrap +msgid "MaxSpareThreads _number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2009 +msgid "" +"The _number_ must be greater than or equal to the sum of " +"[option]`MinSpareThreads` and [option]`ThreadsPerChild`. This directive is " +"used by the `worker` MPM only." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2011 +#, no-wrap +msgid "Using the MaxSpareThreads directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2017 +#, no-wrap +msgid "MaxSpareThreads 75\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2021 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,MinSpareServers] " +"[option]`MinSpareServers`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2022 +msgid "" +"The [option]`MinSpareServers` directive allows you to specify the minimum " +"number of spare child processes. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2026 +#, no-wrap +msgid "MinSpareServers _number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2029 +msgid "" +"Note that a high _number_ can create a heavy processing load on the " +"server. This directive is used by the `prefork` MPM only." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2031 +#, no-wrap +msgid "Using the MinSpareServers directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2037 +#, no-wrap +msgid "MinSpareServers 5\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2041 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,MinSpareThreads] " +"[option]`MinSpareThreads`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2042 +msgid "" +"The [option]`MinSpareThreads` directive allows you to specify the minimum " +"number of spare server threads. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2046 +#, no-wrap +msgid "MinSpareThreads _number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2049 +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2089 +msgid "This directive is used by the `worker` MPM only." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2051 +#, no-wrap +msgid "Using the MinSpareThreads directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2057 +#, no-wrap +msgid "MinSpareThreads 75\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2061 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,StartServers] " +"[option]`StartServers`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2062 +msgid "" +"The [option]`StartServers` directive allows you to specify the number of " +"child processes to create when the service is started. It takes the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2066 +#, no-wrap +msgid "StartServers _number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2069 +msgid "" +"Since the child processes are dynamically created and terminated according " +"to the current traffic load, it is usually not necessary to change this " +"value." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2071 +#, no-wrap +msgid "Using the StartServers directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2077 +#, no-wrap +msgid "StartServers 8\n" +msgstr "" + +#. type: Labeled list +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2081 +#, no-wrap +msgid "" +"indexterm:[Apache HTTP Server,directives,ThreadsPerChild] " +"[option]`ThreadsPerChild`" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2082 +msgid "" +"The [option]`ThreadsPerChild` directive allows you to specify the number of " +"threads a child process can create. It takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2086 +#, no-wrap +msgid "ThreadsPerChild _number_\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2091 +#, no-wrap +msgid "Using the ThreadsPerChild directive" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2097 +#, no-wrap +msgid "ThreadsPerChild 25\n" +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2102 +#, no-wrap +msgid "Working with Modules" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2105 +msgid "" +"indexterm:[Apache HTTP " +"Server,directories,/usr/lib/httpd/modules/]indexterm:[Apache HTTP " +"Server,directories,/usr/lib64/httpd/modules/] Being a modular application, " +"the `httpd` service is distributed along with a number of _Dynamic Shared " +"Objects_ (*DSO*pass:attributes[{blank}]s), which can be dynamically loaded " +"or unloaded at runtime as necessary. By default, these modules are located " +"in `/usr/lib/httpd/modules/` on 32-bit and in `/usr/lib64/httpd/modules/` on " +"64-bit systems." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2107 +#, no-wrap +msgid "Loading a Module" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2110 +msgid "" +"indexterm:[Apache HTTP Server,modules,loading] To load a particular DSO " +"module, use the [option]`LoadModule` directive as described in " +"xref:Web_Servers.adoc#s3-apache-httpdconf-directives[Common httpd.conf " +"Directives]. Note that modules provided by a separate package often have " +"their own configuration file in the `/etc/httpd/conf.d/` directory." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2112 +#, no-wrap +msgid "Loading the mod_ssl DSO" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2117 +#, no-wrap +msgid "LoadModule ssl_module modules/mod_ssl.so\n" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2122 +msgid "" +"Once you are finished, restart the web server to reload the " +"configuration. See " +"xref:Web_Servers.adoc#s3-apache-running-restarting[Restarting the Service] " +"for more information on how to restart the `httpd` service." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2124 +#, no-wrap +msgid "Writing a Module" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2127 +msgid "" +"indexterm:[Apache HTTP Server,modules,developing] If you intend to create a " +"new DSO module, make sure you have the [package]*httpd-devel* package " +"installed. To do so, enter the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2131 +#, no-wrap +msgid "#{nbsp}dnf install httpd-devel\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2134 +msgid "" +"This package contains the include files, the header files, and the " +"[application]*APache eXtenSion* ([command]#apxs#) utility required to " +"compile a module." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2136 +msgid "Once written, you can build the module with the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2140 +#, no-wrap +msgid "#{nbsp}apxs -i -a -c module_name.c\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2143 +msgid "" +"If the build was successful, you should be able to load the module the same " +"way as any other module that is distributed with the Apache HTTP Server." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2145 +#, no-wrap +msgid "Setting Up Virtual Hosts" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2148 +msgid "" +"indexterm:[Apache HTTP Server,virtual host]indexterm:[virtual host,Apache " +"HTTP Server] The Apache HTTP Server's built in virtual hosting allows the " +"server to provide different information based on which IP address, host " +"name, or port is being requested." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2150 +msgid "" +"To create a name-based virtual host, copy the example configuration file " +"`/usr/share/doc/httpd-_VERSION_pass:attributes[{blank}]/httpd-vhosts.conf` " +"into the `/etc/httpd/conf.d/` directory, and replace the `@@Port@@` and " +"`@@ServerRoot@@` placeholder values. Customize the options according to your " +"requirements as shown in " +"xref:Web_Servers.adoc#example-apache-virtualhosts-config[Example virtual " +"host configuration]." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2152 +#, no-wrap +msgid "Example virtual host configuration" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2165 +#, no-wrap +msgid "" +"\n" +" ServerAdmin webmaster@penguin.example.com\n" +" DocumentRoot \"/www/docs/penguin.example.com\"\n" +" ServerName penguin.example.com\n" +" ServerAlias www.penguin.example.com\n" +" ErrorLog \"/var/log/httpd/dummy-host.example.com-error_log\"\n" +" CustomLog \"/var/log/httpd/dummy-host.example.com-access_log\" common\n" +"\n" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2170 +msgid "" +"Note that [option]`ServerName` must be a valid DNS name assigned to the " +"machine. The [option]`` container is highly customizable, and " +"accepts most of the directives available within the main server " +"configuration. Directives that are *not* supported within this container " +"include [option]`User` and [option]`Group`, which were replaced by " +"[option]`SuexecUserGroup`." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2171 +#, no-wrap +msgid "Changing the port number" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2176 +msgid "" +"If you configure a virtual host to listen on a non-default port, make sure " +"you update the [option]`Listen` directive in the global settings section of " +"the `/etc/httpd/conf/httpd.conf` file accordingly." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2180 +msgid "" +"To activate a newly created virtual host, the web server has to be restarted " +"first. See xref:Web_Servers.adoc#s3-apache-running-restarting[Restarting the " +"Service] for more information on how to restart the `httpd` service." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2182 +#, no-wrap +msgid "Setting Up an SSL Server" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2185 +msgid "" +"indexterm:[Apache HTTP Server,modules,mod_ssl]indexterm:[SSL server,Apache " +"HTTP Server]indexterm:[SSL,Apache HTTP Server]indexterm:[TLS,Apache HTTP " +"Server]indexterm:[OpenSSL,SSL,SSL]indexterm:[OpenSSL,TLS,TLS] _Secure " +"Sockets Layer_ (*SSL*) is a cryptographic protocol that allows a server and " +"a client to communicate securely. Along with its extended and improved " +"version called _Transport Layer Security_ (*TLS*), it ensures both privacy " +"and data integrity. The Apache HTTP Server in combination with `mod_ssl`, a " +"module that uses the OpenSSL toolkit to provide the SSL/TLS support, is " +"commonly referred to as the _SSL server_." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2187 +msgid "" +"Unlike a regular HTTP connection that can be read and possibly modified by " +"anybody who is able to intercept it, the use of `mod_ssl` prevents any " +"inspection or modification of the transmitted content. This section provides " +"basic information on how to enable this module in the Apache HTTP Server " +"configuration, and guides you through the process of generating private keys " +"and self-signed certificates." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2189 +#, no-wrap +msgid "An Overview of Certificates and Security" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2194 +msgid "" +"indexterm:[Apache HTTP Server,SSL server,private key]indexterm:[Apache HTTP " +"Server,SSL server,public key] Secure communication is based on the use of " +"keys. In conventional or _symmetric cryptography_, both ends of the " +"transaction have the same key they can use to decode each other's " +"transmissions. On the other hand, in public or _asymmetric cryptography_, " +"two keys co-exist: a _private key_ that is kept a secret, and a _public key_ " +"that is usually shared with the public. While the data encoded with the " +"public key can only be decoded with the private key, data encoded with the " +"private key can in turn only be decoded with the public key. " +"indexterm:[Apache HTTP Server,SSL server,certificate]indexterm:[Apache HTTP " +"Server,SSL server,certificate authority] To provide secure communications " +"using SSL, an SSL server must use a digital certificate signed by a " +"_Certificate Authority_ (*CA*). The certificate lists various attributes of " +"the server (that is, the server host name, the name of the company, its " +"location, etc.), and the signature produced using the CA's private key. This " +"signature ensures that a particular certificate authority has signed the " +"certificate, and that the certificate has not been modified in any way." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2196 +msgid "" +"When a web browser establishes a new SSL connection, it checks the " +"certificate provided by the web server. If the certificate does not have a " +"signature from a trusted CA, or if the host name listed in the certificate " +"does not match the host name used to establish the connection, it refuses to " +"communicate with the server and usually presents a user with an appropriate " +"error message." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2198 +msgid "" +"By default, most web browsers are configured to trust a set of widely used " +"certificate authorities. Because of this, an appropriate CA should be chosen " +"when setting up a secure server, so that target users can trust the " +"connection, otherwise they will be presented with an error message, and will " +"have to accept the certificate manually. Since encouraging users to override " +"certificate errors can allow an attacker to intercept the connection, you " +"should use a trusted CA whenever possible. For more information on this, see " +"xref:Web_Servers.adoc#table-apache-mod_ssl-certificates-authorities[Information " +"about CA lists used by common web browsers]." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2200 +#, no-wrap +msgid "Information about CA lists used by common web browsers" +msgstr "" + +#. type: Table +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2209 +#, no-wrap +msgid "" +"|Web Browser|Link\n" +"|[application]*Mozilla " +"Firefox*|link:++https://www.mozilla.org/projects/security/certs/included/++[Mozilla " +"root CA list].\n" +"|[application]*Opera*|link:++https://www.opera.com/docs/ca/++[Information on " +"root certificates used by Opera].\n" +"|[application]*Internet " +"Explorer*|link:++https://support.microsoft.com/kb/931125++[Information on " +"root certificates used by Microsoft Windows].\n" +"|[application]*Chromium*|link:++https://www.chromium.org/Home/chromium-security/root-ca-policy++[Information " +"on root certificates used by the Chromium project].\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2212 +msgid "" +"When setting up an SSL server, you need to generate a certificate request " +"and a private key, and then send the certificate request, proof of the " +"company's identity, and payment to a certificate authority. Once the CA " +"verifies the certificate request and your identity, it will send you a " +"signed certificate you can use with your server. Alternatively, you can " +"create a self-signed certificate that does not contain a CA signature, and " +"thus should be used for testing purposes only." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2214 +#, no-wrap +msgid "Enabling the mod_ssl Module" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2217 +msgid "" +"If you intend to set up an SSL server, make sure you have the " +"[package]*mod_ssl* (the `mod_ssl` module) and [package]*openssl* (the " +"OpenSSL toolkit) packages installed. To do so, enter the following command " +"as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2221 +#, no-wrap +msgid "#{nbsp}dnf install mod_ssl openssl\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2224 +msgid "" +"indexterm:[Apache HTTP Server,files,/etc/httpd/conf.d/ssl.conf] This will " +"create the `mod_ssl` configuration file at `/etc/httpd/conf.d/ssl.conf`, " +"which is included in the main Apache HTTP Server configuration file by " +"default. For the module to be loaded, restart the `httpd` service as " +"described in xref:Web_Servers.adoc#s3-apache-running-restarting[Restarting " +"the Service]." +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2229 +msgid "" +"Due to the SSL3.0 protocol vulnerability CVE-2014-3566, described in " +"link:++https://www.us-cert.gov/ncas/alerts/TA14-290A++[SSL 3.0 Protocol " +"Vulnerability and POODLE Attack], it is recommended to disable `SSL` and use " +"only `TLSv1.1` or `TLSv1.2`. Backwards compatibility can be achieved using " +"`TLSv1.0`. Many products have the ability to use `SSLv2` or `SSLv3` " +"protocols, or enable them by default. However, the use of `SSLv2` or `SSLv3` " +"is now strongly recommended against." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2233 +#, no-wrap +msgid "Enabling and Disabling SSL and TLS in mod_ssl" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2236 +msgid "" +"To disable and enable specific versions of the SSL and TLS protocol, either " +"do it globally by adding the [command]#SSLProtocol# directive in the " +"\"`\\#\\# SSL Global Context`\" section of the configuration file and " +"removing it everywhere else, or edit the default entry under \"`\\# SSL " +"Protocol support`\" in all \"`VirtualHost`\" sections. If you do not specify " +"it in the per-domain VirtualHost section then it will inherit the settings " +"from the global section. To make sure that a protocol version is being " +"disabled the administrator should either *only* specify " +"[command]#SSLProtocol# in the \"`SSL Global Context`\" section, or specify " +"it in *all* per-domain VirtualHost sections." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2238 +#, no-wrap +msgid "Disable SSLv2 and SSLv3" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2240 +msgid "" +"To disable SSL version 2 and SSL version 3, which implies enabling " +"everything except SSL version 2 and SSL version 3, in all VirtualHost " +"sections, proceed as follows:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2242 +msgid "" +"As `root`, open the `/etc/httpd/conf.d/ssl.conf` file and search for *all* " +"instances of the [command]#SSLProtocol# directive. By default, the " +"configuration file contains one section that looks as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2249 +#, no-wrap +msgid "" +"# vi /etc/httpd/conf.d/ssl.conf\n" +"# SSL Protocol support:\n" +"# List the enable protocol levels with which clients will be able to\n" +"# connect. Disable SSLv2 access by default:\n" +"SSLProtocol all -SSLv2\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2252 +msgid "This section is within the VirtualHost section." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2254 +msgid "Edit the [command]#SSLProtocol# line as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2260 +#, no-wrap +msgid "" +"# SSL Protocol support:\n" +"# List the enable protocol levels with which clients will be able to\n" +"# connect. Disable SSLv2 access by default:\n" +"SSLProtocol All -SSLv2 -SSLv3\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2263 +msgid "Repeat this action for all VirtualHost sections." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2265 +msgid "" +"Verify that all occurrences of the [command]#SSLProtocol# directive have " +"been changed as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2270 +#, no-wrap +msgid "" +"# grep SSLProtocol /etc/httpd/conf.d/ssl.conf\n" +"pass:quotes[*SSLProtocol*] all -SSLv2 -SSLv3\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2273 +msgid "" +"This step is particularly important if you have more than the one default " +"VirtualHost section." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2275 +msgid "Restart the Apache service as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2278 +#, no-wrap +msgid "# systemctl restart httpd\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2281 +msgid "Note that any sessions will be interrupted." +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2283 +#, no-wrap +msgid "Using an Existing Key and Certificate" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2286 +msgid "" +"indexterm:[Apache HTTP Server,SSL server,private key]indexterm:[Apache HTTP " +"Server,SSL server,certificate] If you have a previously created key and " +"certificate, you can configure the SSL server to use these files instead of " +"generating new ones. There are only two situations where this is not " +"possible:" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2288 +#, no-wrap +msgid "*You are changing the IP address or domain name.*\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2290 +msgid "" +"Certificates are issued for a particular IP address and domain name pair. If " +"one of these values changes, the certificate becomes invalid." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2292 +#, no-wrap +msgid "" +"*You have a certificate from VeriSign, and you are changing the server " +"software.*\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2294 +msgid "" +"VeriSign, a widely used certificate authority, issues certificates for a " +"particular software product, IP address, and domain name. Changing the " +"software product renders the certificate invalid." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2296 +msgid "" +"In either of the above cases, you will need to obtain a new certificate. For " +"more information on this topic, see " +"xref:Web_Servers.adoc#s3-apache-mod_ssl-genkey[Generating a New Certificate " +"Using OpenSSL]." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2298 +msgid "" +"If you want to use an existing key and certificate, move the relevant files " +"to the `/etc/pki/tls/private/` and `/etc/pki/tls/certs/` directories " +"respectively. You can do so by issuing the following commands as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2303 +#, no-wrap +msgid "" +"#{nbsp}mv pass:quotes[`key_file.key`] " +"pass:quotes[`/etc/pki/tls/private/hostname.key`]\n" +"#{nbsp}mv pass:quotes[`certificate.crt`] " +"pass:quotes[`/etc/pki/tls/certs/hostname.crt`]\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2306 +msgid "" +"Then add the following lines to the `/etc/httpd/conf.d/ssl.conf` " +"configuration file:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2311 +#, no-wrap +msgid "" +"SSLCertificateFile " +"/etc/pki/tls/certs/pass:attributes[{blank}]_hostname_.crt\n" +"SSLCertificateKeyFile " +"/etc/pki/tls/private/pass:attributes[{blank}]_hostname_.key\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2314 +msgid "" +"To load the updated configuration, restart the `httpd` service as described " +"in xref:Web_Servers.adoc#s3-apache-running-restarting[Restarting the " +"Service]." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2316 +#, no-wrap +msgid "Using a key and certificate from the Red{nbsp}Hat Secure Web Server" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2323 +#, no-wrap +msgid "" +"#{nbsp}mv /etc/httpd/conf/httpsd.key " +"/etc/pki/tls/private/penguin.example.com.key\n" +"#{nbsp}mv /etc/httpd/conf/httpsd.crt " +"/etc/pki/tls/certs/penguin.example.com.crt\n" +msgstr "" + +#. type: Title ==== +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2328 +#, no-wrap +msgid "Generating a New Certificate Using OpenSSL" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2331 +msgid "First, generate the private key. In this example we will use a 2048 RSA key:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2335 +#, no-wrap +msgid "# openssl genrsa -out myhost.com.key 2048\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2338 +msgid "" +"Create a Certificate Signing Request(CSR). The Common Name field must be " +"your server's hostname:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2342 +#, no-wrap +msgid "# openssl req -new -key myhost.com.key -out myhost.com.csr -sha512\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2345 +msgid "" +"A message digest algorithm like SHA2 or stronger is recommended, but it's " +"more important for the certificate than for the request. However your CA " +"decides which message digest they use for the certificate." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2347 +msgid "" +"Now give your CSR to your Certificate Authority(CA) so they can sign your " +"key and give you a certificate:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2351 +#, no-wrap +msgid "" +"# openssl x509 -req -days 365 -in myhost.com.csr -signkey myhost.com.key " +"-out myhost.com.crt -sha512\n" +msgstr "" + +#. type: delimited block = +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2356 +msgid "" +"You can also self-sign the CSR, but bear in mind the security issues that it " +"poses and that browsers will warn users about this." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2359 +msgid "" +"Once your CA has signed it, they will give you the certificate(`.crt` " +"file). Now move the private key and the certificate to their respective " +"directories:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2364 +#, no-wrap +msgid "" +"# cp myhost.com.crt /etc/pki/tls/certs/\n" +"# cp myhost.com.key /etc/pki/tls/private/myhost.com.key\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2367 +msgid "" +"The Certificate Signing Request(CSR) can be deleted as it becomes useless " +"once you have obtained your certificate. Alternatively you can put it along " +"your private key:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2371 +#, no-wrap +msgid "# cp myhost.com.csr /etc/pki/tls/private/myhost.com.csr\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2374 +msgid "Set the correct context of these files for SELinux:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2378 +#, no-wrap +msgid "# restorecon -RvF /etc/pki\n" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2381 +msgid "" +"The last step is to configure the webserver of your host for the TLS " +"protocol using the key and the certificate files you have just created - see " +"xref:The_Apache_HTTP_Server.adoc#mod-ssl-configuration[mod_ssl " +"configuration]." +msgstr "" + +#. type: Title === +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2383 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2386 +msgid "To learn more about the Apache HTTP Server, see the following resources." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2387 +#, no-wrap +msgid "" +"Installed Documentationindexterm:[Apache HTTP Server,additional " +"resources,installed documentation]" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2390 +msgid "" +"`httpd(8)` — The manual page for the `httpd` service containing the complete " +"list of its command-line options." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2392 +msgid "" +"`apachectl(8)` — The manual page for the Apache HTTP Server Control " +"Interface." +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2394 +#, no-wrap +msgid "" +"Installable Documentationindexterm:[Apache HTTP Server,additional " +"resources,installable documentation]" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2397 +msgid "" +"link:++http://localhost/manual/++[] — The official documentation for the " +"Apache HTTP Server with the full description of its directives and available " +"modules. Note that in order to access this documentation, you must have the " +"[package]*httpd-manual* package installed, and the web server must be " +"running." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2399 +msgid "Before accessing the documentation, issue the following commands as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2403 +#, no-wrap +msgid "" +"# dnf install httpd-manual\n" +"# apachectl graceful\n" +msgstr "" + +#. type: Block title +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2405 +#, no-wrap +msgid "" +"Online Documentationindexterm:[Apache HTTP Server,additional " +"resources,useful websites]" +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2408 +msgid "" +"link:++https://httpd.apache.org/++[] — The official website for the Apache " +"HTTP Server with documentation on all the directives and default modules." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2410 +msgid "" +"link:++http://www.modssl.org/++[] — The official website for the " +"[application]*mod_ssl* module." +msgstr "" + +#. type: Plain text +#: ./pages/_partials/servers/The_Apache_HTTP_Server.adoc:2411 +msgid "" +"link:++https://www.openssl.org/++[] — The OpenSSL home page containing " +"further documentation, frequently asked questions, links to the mailing " +"lists, and other useful resources." +msgstr "" diff --git a/pot/rawhide/pages/basic-system-configuration/Configuring_the_Date_and_Time.pot b/pot/rawhide/pages/basic-system-configuration/Configuring_the_Date_and_Time.pot new file mode 100644 index 00000000000..53fd555e0a4 --- /dev/null +++ b/pot/rawhide/pages/basic-system-configuration/Configuring_the_Date_and_Time.pot @@ -0,0 +1,951 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:6 +#, no-wrap +msgid "Configuring the Date and Time" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:9 +msgid "" +"Modern operating systems distinguish between the following two types of " +"clocks:" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:11 +msgid "" +"A _real-time clock_ (*RTC*), commonly referred to as a _hardware clock_, " +"(typically an integrated circuit on the system board) that is completely " +"independent of the current state of the operating system and runs even when " +"the computer is shut down." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:13 +msgid "" +"A _system clock_, also known as a _software clock_, that is maintained by " +"the kernel and its initial value is based on the real-time clock. Once the " +"system is booted and the system clock is initialized, the system clock is " +"completely independent of the real-time clock." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:15 +msgid "" +"The system time is always kept in _Coordinated Universal Time_ (*UTC*) and " +"converted in applications to local time as needed. _Local time_ is the " +"actual time in your current time zone, taking into account _daylight saving " +"time_ (*DST*). The real-time clock can use either UTC or local time. UTC is " +"recommended." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:17 +msgid "" +"{MAJOROSVER} offers three command line tools that can be used to configure " +"and display information about the system date and time: the " +"[command]#timedatectl# utility, which is new in {MAJOROSVER} and is part of " +"`systemd`pass:attributes[{blank}]; the traditional [command]#date# command; " +"and the [command]#hwclock# utility for accessing the hardware clock." +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:19 +#, no-wrap +msgid "Using the timedatectl Command" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:22 +msgid "" +"The [application]*timedatectl* utility is distributed as part of the " +"`systemd` system and service manager and allows you to review and change the " +"configuration of the system clock. You can use this tool to change the " +"current date and time, set the time zone, or enable automatic " +"synchronization of the system clock with a remote server." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:24 +msgid "" +"For information on how to display the current date and time in a custom " +"format, see also " +"xref:Configuring_the_Date_and_Time.adoc#sect-Configuring_the_Date_and_Time-date[Using " +"the date Command]." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:26 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:38 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:211 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:255 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:363 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:375 +#, no-wrap +msgid "Displaying the Current Date and Time" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:29 +msgid "" +"To display the current date and time along with detailed information about " +"the configuration of the system and hardware clock, run the " +"[command]#timedatectl# command with no additional command line options:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:33 +#, no-wrap +msgid "[command]#timedatectl#\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:36 +msgid "" +"This displays the local and universal time, the currently used time zone, " +"the status of the Network Time Protocol (`NTP`) configuration, and " +"additional information related to DST." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:42 +msgid "" +"The following is an example output of the [command]#timedatectl# command on " +"a system that does not use `NTP` to synchronize the system clock with a " +"remote server:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:59 +#, no-wrap +msgid "" +"~]${nbsp}timedatectl\n" +" Local time: Mon 2013-09-16 19:30:24 CEST\n" +" Universal time: Mon 2013-09-16 17:30:24 UTC\n" +" Timezone: Europe/Prague (CEST, +0200)\n" +" NTP enabled: no\n" +"NTP synchronized: no\n" +" RTC in local TZ: no\n" +" DST active: yes\n" +" Last DST change: DST began at\n" +" Sun 2013-03-31 01:59:59 CET\n" +" Sun 2013-03-31 03:00:00 CEST\n" +" Next DST change: DST ends (the clock jumps one hour backwards) at\n" +" Sun 2013-10-27 02:59:59 CEST\n" +" Sun 2013-10-27 02:00:00 CET\n" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:64 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:80 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:285 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:304 +#, no-wrap +msgid "Changing the Current Time" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:67 +msgid "To change the current time, type the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:71 +#, no-wrap +msgid "[command]#timedatectl# [option]`set-time` _HH:MM:SS_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:74 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:295 +msgid "" +"Replace _HH_ with an hour, _MM_ with a minute, and _SS_ with a second, all " +"typed in two-digit form." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:76 +msgid "" +"This command updates both the system time and the hardware clock. The result " +"it is similar to using both the [command]#date --set# and [command]#hwclock " +"--systohc# commands." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:78 +msgid "" +"The command will fail if an `NTP` service is enabled. See " +"xref:Configuring_the_Date_and_Time.adoc#sect-Configuring_the_Date_and_Time-timedatectl-NTP[Synchronizing " +"the System Clock with a Remote Server] to temporally disable the service." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:84 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:308 +msgid "" +"To change the current time to 11:26 p.m., run the following command as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:88 +#, no-wrap +msgid "~]#{nbsp}timedatectl set-time 23:26:00\n" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:93 +msgid "" +"By default, the system is configured to use UTC. To configure your system to " +"maintain the clock in the local time, run the [command]#timedatectl# command " +"with the [option]`set-local-rtc` option as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:97 +#, no-wrap +msgid "[command]#timedatectl# [option]`set-local-rtc` _boolean_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:100 +msgid "" +"To configure your system to maintain the clock in the local time, replace " +"_boolean_ with `yes` (or, alternatively, `y`, `true`, `t`, or `1`). To " +"configure the system to use UTC, replace _boolean_ with `no` (or, " +"alternatively, `n`, `false`, `f`, or `0`). The default option is `no`." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:102 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:116 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:317 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:331 +#, no-wrap +msgid "Changing the Current Date" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:105 +msgid "To change the current date, type the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:109 +#, no-wrap +msgid "[command]#timedatectl# [option]`set-time` _YYYY-MM-DD_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:112 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:327 +msgid "" +"Replace _YYYY_ with a four-digit year, _MM_ with a two-digit month, and _DD_ " +"with a two-digit day of the month." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:114 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:329 +msgid "" +"Note that changing the date without specifying the current time results in " +"setting the time to 00:00:00." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:120 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:335 +msgid "" +"To change the current date to 2 June 2013 and keep the current time (11:26 " +"p.m.), run the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:124 +#, no-wrap +msgid "~]#{nbsp}timedatectl set-time \"2013-06-02 23:26:00\"\n" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:129 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:148 +#, no-wrap +msgid "Changing the Time Zone" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:132 +msgid "To list all available time zones, type the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:136 +#, no-wrap +msgid "[command]#timedatectl# [option]`list-timezones`\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:139 +msgid "To change the currently used time zone, type as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:143 +#, no-wrap +msgid "timedatectl set-timezone pass:quotes[_time_zone_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:146 +msgid "" +"Replace _time_zone_ with any of the values listed by the " +"[command]#timedatectl list-timezones# command." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:152 +msgid "" +"To identify which time zone is closest to your present location, use the " +"[command]#timedatectl# command with the [option]`list-timezones` command " +"line option. For example, to list all available time zones in Europe, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:163 +#, no-wrap +msgid "" +"~]#{nbsp}timedatectl list-timezones | grep Europe\n" +"Europe/Amsterdam\n" +"Europe/Andorra\n" +"Europe/Athens\n" +"Europe/Belgrade\n" +"Europe/Berlin\n" +"Europe/Bratislava\n" +"pass:quotes[_…_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:166 +msgid "To change the time zone to `Europe/Prague`, type as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:170 +#, no-wrap +msgid "~]#{nbsp}timedatectl set-timezone Europe/Prague\n" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:175 +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:189 +#, no-wrap +msgid "Synchronizing the System Clock with a Remote Server" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:178 +msgid "" +"As opposed to the manual adjustments described in the previous sections, the " +"[command]#timedatectl# command also allows you to enable automatic " +"synchronization of your system clock with a group of remote servers using " +"the `NTP` protocol. Enabling NTP enables the `chronyd` or `ntpd` service, " +"depending on which of them is installed." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:180 +msgid "The `NTP` service can be enabled and disabled using a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:184 +#, no-wrap +msgid "[command]#timedatectl# [option]`set-ntp` _boolean_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:187 +msgid "" +"To enable your system to synchronize the system clock with a remote `NTP` " +"server, replace _boolean_ with `yes` (the default option). To disable this " +"feature, replace _boolean_ with `no`." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:193 +msgid "" +"To enable automatic synchronization of the system clock with a remote " +"server, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:197 +#, no-wrap +msgid "~]#{nbsp}timedatectl set-ntp yes\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:200 +msgid "" +"The command will fail if an `NTP` service is not installed. See " +"xref:servers/Configuring_NTP_Using_the_chrony_Suite.adoc#sect-Installing_chrony[Installing " +"chrony] for more information." +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:204 +#, no-wrap +msgid "Using the date Command" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:207 +msgid "" +"The [command]#date# utility is available on all Linux systems and allows you " +"to display and configure the current date and time. It is frequently used in " +"scripts to display detailed information about the system clock in a custom " +"format." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:209 +msgid "" +"For information on how to change the time zone or enable automatic " +"synchronization of the system clock with a remote server, see " +"xref:Configuring_the_Date_and_Time.adoc#sect-Configuring_the_Date_and_Time-timedatectl[Using " +"the timedatectl Command]." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:214 +msgid "" +"To display the current date and time, run the [command]#date# command with " +"no additional command line options:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:218 +#, no-wrap +msgid "[command]#date#\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:221 +msgid "" +"This displays the day of the week followed by the current date, local time, " +"abbreviated time zone, and year." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:223 +msgid "" +"By default, the [command]#date# command displays the local time. To display " +"the time in UTC, run the command with the [option]`--utc` or [option]`-u` " +"command line option:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:227 +#, no-wrap +msgid "[command]#date# [option]`--utc`\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:230 +msgid "" +"You can also customize the format of the displayed information by providing " +"the [option]`+\"pass:attributes[{blank}]_format_pass:attributes[{blank}]\"` " +"option on the command line:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:233 +#, no-wrap +msgid "date +\"format\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:236 +msgid "" +"Replace _format_ with one or more supported control sequences as illustrated " +"in " +"xref:Configuring_the_Date_and_Time.adoc#exam-Configuring_the_Date_and_Time-date-Display[Displaying " +"the Current Date and Time]. See " +"xref:Configuring_the_Date_and_Time.adoc#tabl-Configuring_the_Date_and_Time-date-Format[Commonly " +"Used Control Sequences] for a list of the most frequently used formatting " +"options, or the `date`(1) manual page for a complete list of these options." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:238 +#, no-wrap +msgid "Commonly Used Control Sequences" +msgstr "" + +#. type: Table +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:252 +#, no-wrap +msgid "" +"|Control Sequence|Description\n" +"|[option]`%H`|The hour in the _HH_ format (for example, `17`).\n" +"|[option]`%M`|The minute in the _MM_ format (for example, `30`).\n" +"|[option]`%S`|The second in the _SS_ format (for example, `24`).\n" +"|[option]`%d`|The day of the month in the _DD_ format (for example, `16`).\n" +"|[option]`%m`|The month in the _MM_ format (for example, `09`).\n" +"|[option]`%Y`|The year in the _YYYY_ format (for example, `2013`).\n" +"|`%Z`|The time zone abbreviation (for example, `CEST`).\n" +"|[option]`%F`|The full date in the _YYYY-MM-DD_ format (for example, " +"`2013-09-16`). This option is equal to [option]`%Y-%m-%d`.\n" +"|[option]`%T`|The full time in the _HH:MM:SS_ format (for example, " +"17:30:24). This option is equal to [option]`%H:%M:%S`\n" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:259 +msgid "" +"To display the current date and local time, type the following at a shell " +"prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:264 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#date#\n" +"Mon Sep 16 17:30:24 CEST 2013\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:267 +msgid "" +"To display the current date and time in UTC, type the following at a shell " +"prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:272 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#date --utc#\n" +"Mon Sep 16 15:30:34 UTC 2013\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:275 +msgid "To customize the output of the [command]#date# command, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:280 +#, no-wrap +msgid "" +"~]${nbsp}date +\"%Y-%m-%d %H:%M\"\n" +"2013-09-16 17:30\n" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:288 +msgid "" +"To change the current time, run the [command]#date# command with the " +"[option]`--set` or [option]`-s` option as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:292 +#, no-wrap +msgid "[command]#date# [option]`--set` _HH:MM:SS_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:297 +msgid "" +"By default, the [command]#date# command sets the system clock to the local " +"time. To set the system clock in UTC, run the command with the " +"[option]`--utc` or [option]`-u` command line option:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:301 +#, no-wrap +msgid "[command]#date# [option]`--set` _HH:MM:SS_ [option]`--utc`\n" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:312 +#, no-wrap +msgid "~]#{nbsp}date --set 23:26:00\n" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:320 +msgid "" +"To change the current date, run the [command]#date# command with the " +"[option]`--set` or [option]`-s` option as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:324 +#, no-wrap +msgid "[command]#date# [option]`--set` _YYYY-MM-DD_\n" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:339 +#, no-wrap +msgid "~]#{nbsp}date --set 2013-06-02 23:26:00\n" +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:344 +#, no-wrap +msgid "Using the hwclock Command" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:347 +msgid "" +"`hwclock` is a utility for accessing the hardware clock, also referred to as " +"the Real Time Clock (RTC). The hardware clock is independent of the " +"operating system you use and works even when the machine is shut down. This " +"utility is used for displaying the time from the hardware clock. `hwclock` " +"also contains facilities for compensating for systematic drift in the " +"hardware clock." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:349 +msgid "" +"The hardware clock stores the values of: year, month, day, hour, minute, and " +"second. It is not able to store the time standard, local time or Coordinated " +"Universal Time (UTC), nor set the Daylight Saving Time (DST)." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:351 +msgid "" +"The `hwclock` utility saves its settings in the `/etc/adjtime` file, which " +"is created with the first change you make, for example, when you set the " +"time manually or synchronize the hardware clock with the system time." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:357 +msgid "" +"In {MAJOROS}{nbsp}6, the [command]#hwclock# command was run automatically on " +"every system shutdown or reboot, but it is not in {MAJOROSVER}. When the " +"system clock is synchronized by the Network Time Protocol (NTP) or Precision " +"Time Protocol (PTP), the kernel automatically synchronizes the hardware " +"clock to the system clock every 11 minutes." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:361 +msgid "" +"For details about NTP, see " +"xref:servers/Configuring_NTP_Using_the_chrony_Suite.adoc#ch-Configuring_NTP_Using_the_chrony_Suite[Configuring " +"NTP Using the chrony Suite] and " +"xref:servers/Configuring_NTP_Using_ntpd.adoc#ch-Configuring_NTP_Using_ntpd[Configuring " +"NTP Using ntpd]. For information about PTP, see " +"xref:servers/Configuring_PTP_Using_ptp4l.adoc#ch-Configuring_PTP_Using_ptp4l[Configuring " +"PTP Using ptp4l]. For information about setting the hardware clock after " +"executing [application]*ntpdate*, see " +"xref:servers/Configuring_NTP_Using_ntpd.adoc#s1-Configuring_the_Hardware_Clock_update[Configuring " +"the Hardware Clock Update]." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:366 +msgid "" +"Running [command]#hwclock# with no command line options as the `root` user " +"returns the date and time in local time to standard output." +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:370 +#, no-wrap +msgid "[command]#hwclock#\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:373 +msgid "" +"Note that using the [option]`--utc` or [option]`--localtime` options with " +"the [command]#hwclock# command does not mean you are displaying the hardware " +"clock time in UTC or local time. These options are used for setting the " +"hardware clock to keep time in either of them. The time is always displayed " +"in local time. Additionally, using the [command]#hwclock --utc# or " +"[command]#hwclock --local# commands does not change the record in the " +"`/etc/adjtime` file. This command can be useful when you know that the " +"setting saved in `/etc/adjtime` is incorrect but you do not want to change " +"the setting. On the other hand, you may receive misleading information if " +"you use the command an incorrect way. See the `hwclock`(8) manual page for " +"more details." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:379 +msgid "" +"To display the current date and the current local time from the hardware " +"clock, run as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:384 +#, no-wrap +msgid "" +"~]#{nbsp}hwclock\n" +"Tue 15 Apr 2014 04:23:46 PM CEST -0.329272 seconds\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:387 +msgid "" +"CEST is a time zone abbreviation and stands for Central European Summer " +"Time." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:391 +msgid "" +"For information on how to change the time zone, see " +"xref:Configuring_the_Date_and_Time.adoc#sect-Configuring_the_Date_and_Time-timedatectl-Time_Zone[Changing " +"the Time Zone]." +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:393 +#, no-wrap +msgid "Setting the Date and Time" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:396 +msgid "" +"Besides displaying the date and time, you can manually set the hardware " +"clock to a specific time." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:398 +msgid "" +"When you need to change the hardware clock date and time, you can do so by " +"appending the [option]`--set` and [option]`--date` options along with your " +"specification:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:402 +#, no-wrap +msgid "" +"[command]#hwclock --set --date _\"dd mmm yyyy " +"HH:MM\"_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:405 +msgid "" +"Replace _dd_ with a day (a two-digit number), _mmm_ with a month (a " +"three-letter abbreviation), _yyyy_ with a year (a four-digit number), _HH_ " +"with an hour (a two-digit number), _MM_ with a minute (a two-digit number)." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:407 +msgid "" +"At the same time, you can also set the hardware clock to keep the time in " +"either UTC or local time by adding the [option]`--utc` or " +"[option]`--localtime` options, respectively. In this case, `UTC` or `LOCAL` " +"is recorded in the `/etc/adjtime` file." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:409 +#, no-wrap +msgid "Setting the Hardware Clock to a Specific Date and Time" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:413 +msgid "" +"If you want to set the date and time to a specific value, for example, to " +"\"`21:17, October 21, 2014`\", and keep the hardware clock in UTC, run the " +"command as `root` in the following format:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:417 +#, no-wrap +msgid "~]#{nbsp}hwclock --set --date \"21 Oct 2014 21:17\" --utc\n" +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:422 +#, no-wrap +msgid "Synchronizing the Date and Time" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:425 +msgid "" +"You can synchronize the hardware clock and the current system time in both " +"directions." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:427 +msgid "" +"Either you can set the hardware clock to the current system time by using " +"this command:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:431 +#, no-wrap +msgid "[command]#hwclock --systohc#\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:434 +msgid "" +"Note that if you use NTP, the hardware clock is automatically synchronized " +"to the system clock every 11 minutes, and this command is useful only at " +"boot time to get a reasonable initial system time." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:436 +msgid "" +"Or, you can set the system time from the hardware clock by using the " +"following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:440 +#, no-wrap +msgid "[command]#hwclock --hctosys#\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:443 +msgid "" +"When you synchronize the hardware clock and the system time, you can also " +"specify whether you want to keep the hardware clock in local time or UTC by " +"adding the [option]`--utc` or [option]`--localtime` option. Similarly to " +"using [option]`--set`, `UTC` or `LOCAL` is recorded in the `/etc/adjtime` " +"file." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:445 +msgid "" +"The [command]#hwclock --systohc --utc# command is functionally similar to " +"[command]#timedatectl set-local-rtc false# and the [command]#hwclock " +"--systohc --local# command is an alternative to [command]#timedatectl " +"set-local-rtc true#." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:447 +#, no-wrap +msgid "Synchronizing the Hardware Clock with System Time" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:451 +msgid "" +"To set the hardware clock to the current system time and keep the hardware " +"clock in local time, run the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:455 +#, no-wrap +msgid "~]#{nbsp}hwclock --systohc --localtime\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:458 +msgid "" +"To avoid problems with time zone and DST switching, it is recommended to " +"keep the hardware clock in UTC. The shown " +"xref:Configuring_the_Date_and_Time.adoc#exam4-sect4-synchornizing-systohc-hwclock[Synchronizing " +"the Hardware Clock with System Time] is useful, for example, in case of a " +"multi boot with a Windows system, which assumes the hardware clock runs in " +"local time by default, and all other systems need to accommodate to it by " +"using local time as well. It may also be needed with a virtual machine; if " +"the virtual hardware clock provided by the host is running in local time, " +"the guest system needs to be configured to use local time, too." +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:462 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:465 +msgid "" +"For more information on how to configure the date and time in {MAJOROSVER}, " +"see the resources listed below." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:466 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:469 +msgid "" +"`timedatectl`(1) — The manual page for the [command]#timedatectl# command " +"line utility documents how to use this tool to query and change the system " +"clock and its settings." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:471 +msgid "" +"`date`(1) — The manual page for the [command]#date# command provides a " +"complete list of supported command line options." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:473 +msgid "" +"`hwclock`(8) — The manual page for the [command]#hwclock# command provides a " +"complete list of supported command line options." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:474 +#, no-wrap +msgid "See Also" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Configuring_the_Date_and_Time.adoc:476 +msgid "" +"xref:basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc#ch-System_Locale_and_Keyboard_Configuration[System " +"Locale and Keyboard Configuration] documents how to configure the keyboard " +"layout." +msgstr "" diff --git a/pot/rawhide/pages/basic-system-configuration/Gaining_Privileges.pot b/pot/rawhide/pages/basic-system-configuration/Gaining_Privileges.pot new file mode 100644 index 00000000000..4ef442d665b --- /dev/null +++ b/pot/rawhide/pages/basic-system-configuration/Gaining_Privileges.pot @@ -0,0 +1,456 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:6 +#, no-wrap +msgid "Gaining Privileges" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:9 +msgid "" +"System administrators, and in some cases users, need to perform certain " +"tasks with administrative access. Accessing the system as the `root` user is " +"potentially dangerous and can lead to widespread damage to the system and " +"data. This chapter covers ways to gain administrative privileges using " +"setuid programs such as [command]#su# and [command]#sudo#. These programs " +"allow specific users to perform tasks which would normally be available only " +"to the `root` user while maintaining a higher level of control and system " +"security." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:11 +msgid "" +"See the " +"link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Security_Guide/++[Red{nbsp}Hat " +"Enterprise{nbsp}Linux{nbsp}7 Security Guide] for more information on " +"administrative controls, potential dangers, and ways to prevent data loss " +"resulting from improper use of privileged access." +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:13 +#, no-wrap +msgid "The su Command" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:16 +msgid "" +"When a user executes the [command]#su# command, they are prompted for the " +"`root` password and, after authentication, are given a `root` shell prompt." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:18 +msgid "" +"Once logged in using the [command]#su# command, the user *is* the `root` " +"user and has absolute administrative access to the system. Note that this " +"access is still subject to the restrictions imposed by SELinux, if it is " +"enabled. In addition, once a user has become `root`, it is possible for them " +"to use the [command]#su# command to change to any other user on the system " +"without being prompted for a password." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:20 +msgid "" +"Because this program is so powerful, administrators within an organization " +"may want to limit who has access to the command." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:22 +msgid "" +"One of the simplest ways to do this is to add users to the special " +"administrative group called _wheel_. To do this, type the following command " +"as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:26 +#, no-wrap +msgid "~]# usermod -a -G wheel pass:quotes[_username_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:29 +msgid "" +"In the previous command, replace _username_ with the user name you want to " +"add to the `wheel` group." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:31 +msgid "" +"You can also use the [application]*Users* settings tool to modify group " +"memberships, as follows. Note that you need administrator privileges to " +"perform this procedure." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:33 +msgid "" +"Press the kbd:[Super] key to enter the Activities Overview, type " +"[command]#Users# and then press kbd:[Enter]. The [application]*Users* " +"settings tool appears. The kbd:[Super] key appears in a variety of guises, " +"depending on the keyboard and other hardware, but often as either the " +"Windows or Command key, and typically to the left of the kbd:[Spacebar]." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:35 +msgid "" +"To enable making changes, click the btn:[Unlock] button, and enter a valid " +"administrator password." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:37 +msgid "" +"Click a user icon in the left column to display the user's properties in the " +"right-hand pane." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:39 +msgid "" +"Change the Account Type from `Standard` to `Administrator`. This will add " +"the user to the `wheel` group." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:41 +msgid "" +"See " +"xref:basic-system-configuration/Managing_Users_and_Groups.adoc#s1-users-configui[Managing " +"Users in a Graphical Environment] for more information about the " +"[application]*Users* tool." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:43 +msgid "" +"After you add the desired users to the `wheel` group, it is advisable to " +"only allow these specific users to use the [command]#su# command. To do " +"this, edit the PAM configuration file for [command]#su#, " +"`/etc/pam.d/su`. Open this file in a text editor and uncomment the following " +"line by removing the `#` character:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:46 +#, no-wrap +msgid "#auth required pam_wheel.so use_uid\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:49 +msgid "" +"This change means that only members of the administrative group `wheel` can " +"switch to another user using the [command]#su# command." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:50 +#, no-wrap +msgid "Note" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:55 +msgid "The `root` user is part of the `wheel` group by default." +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:59 +#, no-wrap +msgid "The sudo Command" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:62 +msgid "" +"The [command]#sudo# command offers another approach to giving users " +"administrative access. When trusted users precede an administrative command " +"with [command]#sudo#, they are prompted for *their own* password. Then, when " +"they have been authenticated and assuming that the command is permitted, the " +"administrative command is executed as if they were the `root` user." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:64 +msgid "The basic format of the [command]#sudo# command is as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:68 +#, no-wrap +msgid "[command]#sudo# _command_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:71 +msgid "" +"In the above example, _command_ would be replaced by a command normally " +"reserved for the `root` user, such as [command]#mount#." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:73 +msgid "" +"The [command]#sudo# command allows for a high degree of flexibility. For " +"instance, only users listed in the `/etc/sudoers` configuration file are " +"allowed to use the [command]#sudo# command and the command is executed in " +"*the user's* shell, not a `root` shell. This means the `root` shell can be " +"completely disabled as shown in the " +"link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Security_Guide/++[Red{nbsp}Hat " +"Enterprise{nbsp}Linux{nbsp}7 Security Guide]." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:75 +msgid "" +"Each successful authentication using the [command]#sudo# command is logged " +"to the file `/var/log/messages` and the command issued along with the " +"issuer's user name is logged to the file `/var/log/secure`. If additional " +"logging is required, use the `pam_tty_audit` module to enable TTY auditing " +"for specified users by adding the following line to your " +"`/etc/pam.d/system-auth` file:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:79 +#, no-wrap +msgid "" +"session required pam_tty_audit.so disable=pass:quotes[_pattern_] " +"enable=pass:quotes[_pattern_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:83 +msgid "" +"where _pattern_ represents a comma-separated listing of users with an " +"optional use of globs. For example, the following configuration will enable " +"TTY auditing for the `root` user and disable it for all other users:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:86 +#, no-wrap +msgid "session required pam_tty_audit.so disable=* enable=root\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:89 +msgid "" +"Another advantage of the [command]#sudo# command is that an administrator " +"can allow different users access to specific commands based on their needs." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:91 +msgid "" +"Administrators wanting to edit the [command]#sudo# configuration file, " +"`/etc/sudoers`, should use the [command]#visudo# command." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:93 +msgid "" +"To give someone full administrative privileges, type [command]#visudo# and " +"add a line similar to the following in the user privilege specification " +"section:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:97 +#, no-wrap +msgid "juan ALL=(ALL) ALL\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:100 +msgid "" +"This example states that the user, `juan`, can use [command]#sudo# from any " +"host and execute any command." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:102 +msgid "" +"The example below illustrates the granularity possible when configuring " +"[command]#sudo#:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:106 +#, no-wrap +msgid "%users localhost=/sbin/shutdown -h now\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:109 +msgid "" +"This example states that any member of the `users` system group can issue " +"the command [command]#/sbin/shutdown -h now# as long as it is issued from " +"the console." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:111 +msgid "The man page for `sudoers` has a detailed listing of options for this file." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:112 +#, no-wrap +msgid "Important" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:117 +msgid "" +"There are several potential risks to keep in mind when using the " +"[command]#sudo# command. You can avoid them by editing the `/etc/sudoers` " +"configuration file using [command]#visudo# as described above. Leaving the " +"`/etc/sudoers` file in its default state gives every user in the `wheel` " +"group unlimited `root` access." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:119 +msgid "" +"By default, [command]#sudo# stores the sudoer's password for a five minute " +"timeout period. Any subsequent uses of the command during this period will " +"not prompt the user for a password. This could be exploited by an attacker " +"if the user leaves their workstation unattended and unlocked while still " +"being logged in. This behavior can be changed by adding the following line " +"to the `/etc/sudoers` file:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:123 +#, no-wrap +msgid "Defaults timestamp_timeout=pass:quotes[_value_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:126 +msgid "" +"where _value_ is the desired timeout length in minutes. Setting the _value_ " +"to 0 causes [command]#sudo# to require a password every time." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:128 +msgid "" +"If a sudoer's account is compromised, an attacker can use [command]#sudo# to " +"open a new shell with administrative privileges:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:132 +#, no-wrap +msgid "[command]#sudo /bin/bash#\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:135 +msgid "" +"Opening a new shell as `root` in this or similar fashion gives the attacker " +"administrative access for a theoretically unlimited amount of time, " +"bypassing the timeout period specified in the `/etc/sudoers` file and never " +"requiring the attacker to input a password for [command]#sudo# again until " +"the newly opened session is closed." +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:139 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:142 +msgid "" +"While programs allowing users to gain administrative privileges are a " +"potential security risk, security itself is beyond the scope of this " +"particular book. You should therefore refer to the resources listed below " +"for more information regarding security and privileged access." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:143 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:146 +msgid "" +"`su`(1) — The manual page for [command]#su# provides information regarding " +"the options available with this command." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:148 +msgid "" +"`sudo`(8) — The manual page for [command]#sudo# includes a detailed " +"description of this command and lists options available for customizing its " +"behavior." +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:150 +msgid "" +"`pam`(8) — The manual page describing the use of Pluggable Authentication " +"Modules (PAM) for Linux." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:151 +#, no-wrap +msgid "Online Documentation" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:154 +msgid "" +"The " +"link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Security_Guide/++[Red{nbsp}Hat " +"Enterprise{nbsp}Linux{nbsp}7 Security Guide] provides a more in-depth look " +"at potential security issues pertaining to setuid programs as well as " +"techniques used to alleviate these risks." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:155 +#, no-wrap +msgid "See Also" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Gaining_Privileges.adoc:157 +msgid "" +"xref:basic-system-configuration/Managing_Users_and_Groups.adoc#ch-Managing_Users_and_Groups[Managing " +"Users and Groups] documents how to manage system users and groups in the " +"graphical user interface and on the command line." +msgstr "" diff --git a/pot/rawhide/pages/basic-system-configuration/Managing_Users_and_Groups.pot b/pot/rawhide/pages/basic-system-configuration/Managing_Users_and_Groups.pot new file mode 100644 index 00000000000..f77f108dd60 --- /dev/null +++ b/pot/rawhide/pages/basic-system-configuration/Managing_Users_and_Groups.pot @@ -0,0 +1,1236 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:5 +#, no-wrap +msgid "Managing Users and Groups" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:8 +msgid "" +"The control of users and groups is a core element of {MAJOROS} system " +"administration. This chapter explains how to add, manage, and delete users " +"and groups in the graphical user interface and on the command line, and " +"covers advanced topics, such as creating group directories." +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:10 +#, no-wrap +msgid "Introduction to Users and Groups" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:13 +msgid "" +"While users can be either people (meaning accounts tied to physical users) " +"or accounts which exist for specific applications to use, groups are logical " +"expressions of organization, tying users together for a common " +"purpose. Users within a group share the same permissions to read, write, or " +"execute files owned by that group." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:15 +msgid "" +"Each user is associated with a unique numerical identification number called " +"a _user ID_ (*UID*). Likewise, each group is associated with a _group ID_ " +"(*GID*). A user who creates a file is also the owner and group owner of that " +"file. The file is assigned separate read, write, and execute permissions for " +"the owner, the group, and everyone else. The file owner can be changed only " +"by `root`, and access permissions can be changed by both the `root` user and " +"file owner." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:17 +msgid "" +"Additionally, {MAJOROS} supports _access control lists_ (*ACLs*) for files " +"and directories which allow permissions for specific users outside of the " +"owner to be set. For more information about this feature, see the " +"[citetitle]_link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/System_Administrators_Guide/ch-Access_Control_Lists.html++[Access " +"Control Lists]_ chapter of the " +"[citetitle]_link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/System_Administrators_Guide/index.html++[Red " +"Hat Enterprise Linux 7 System Administrators Guide]_." +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:19 +#, no-wrap +msgid "User Private Groups" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:22 +msgid "" +"indexterm:[groups,user private]indexterm:[user private " +"groups,groups]indexterm:[groups,tools for management of,groupadd] {MAJOROS} " +"uses a _user private group_ (_UPG_) scheme, which makes UNIX groups easier " +"to manage. A user private group is created whenever a new user is added to " +"the system. It has the same name as the user for which it was created and " +"that user is the only member of the user private group." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:24 +msgid "" +"User private groups make it safe to set default permissions for a newly " +"created file or directory, allowing both the user and *the group of that " +"user* to make modifications to the file or directory." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:26 +msgid "" +"The setting which determines what permissions are applied to a newly created " +"file or directory is called a _umask_ and is configured in the `/etc/bashrc` " +"file. Traditionally on UNIX-based systems, the [command]#umask# is set to " +"[command]#022#, which allows only the user who created the file or directory " +"to make modifications. Under this scheme, all other users, *including " +"members of the creator's group*, are not allowed to make any " +"modifications. However, under the UPG scheme, this \"`group protection`\" is " +"not necessary since every user has their own private group." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:28 +msgid "A list of all groups is stored in the `/etc/group` configuration file." +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:30 +#, no-wrap +msgid "Shadow Passwords" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:33 +msgid "" +"indexterm:[passwords,shadow]indexterm:[shadow passwords,overview of] In " +"environments with multiple users, it is very important to use _shadow " +"passwords_ provided by the [package]*shadow-utils* package to enhance the " +"security of system authentication files. For this reason, the installation " +"program enables shadow passwords by default." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:35 +msgid "" +"The following is a list of the advantages shadow passwords have over the " +"traditional way of storing passwords on UNIX-based systems:" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:37 +msgid "" +"Shadow passwords improve system security by moving encrypted password hashes " +"from the world-readable `/etc/passwd` file to `/etc/shadow`, which is " +"readable only by the `root` user." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:39 +msgid "Shadow passwords store information about password aging." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:41 +msgid "" +"Shadow passwords allow the `/etc/login.defs` file to enforce security " +"policies." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:43 +msgid "" +"Most utilities provided by the [package]*shadow-utils* package work properly " +"whether or not shadow passwords are enabled. However, since password aging " +"information is stored exclusively in the `/etc/shadow` file, some utilities " +"and commands do not work without first enabling shadow passwords:" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:45 +msgid "" +"The [command]#chage# utility for setting password-aging parameters. For " +"details, see the " +"link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Security_Guide/chap-Hardening_Your_System_with_Tools_and_Services.html#sec-Password_Security++[Password " +"Security] section in the [citetitle]_Red{nbsp}Hat " +"Enterprise{nbsp}Linux{nbsp}7 Security Guide_." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:47 +msgid "The [command]#gpasswd# utility for administrating the `/etc/group` file." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:49 +msgid "" +"The [command]#usermod# command with the [option]`-e, --expiredate` or " +"[option]`-f, --inactive` option." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:51 +msgid "" +"The [command]#useradd# command with the [option]`-e, --expiredate` or " +"[option]`-f, --inactive` option." +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:53 +#, no-wrap +msgid "Managing Users in a Graphical Environment" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:56 +msgid "" +"indexterm:[users,user configuration]indexterm:[groups,group " +"configuration]indexterm:[user configuration,viewing list of " +"users]indexterm:[group configuration,viewing list of groups]indexterm:[the " +"Users settings tool,user configuration] The [application]*Users* utility " +"allows you to view, modify, add, and delete local users in the graphical " +"user interface." +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:58 +#, no-wrap +msgid "Using the Users Settings Tool" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:61 +msgid "" +"Press the kbd:[Super] key to enter the Activities Overview, type " +"[command]#Users# and then press kbd:[Enter]. The [application]*Users* " +"settings tool appears. The kbd:[Super] key appears in a variety of guises, " +"depending on the keyboard and other hardware, but often as either the " +"Windows or Command key, and typically to the left of the Spacebar." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:63 +msgid "" +"To make changes to the user accounts, first select the btn:[Unlock] button " +"and authenticate yourself as indicated by the dialog box that appears. Note " +"that unless you have superuser privileges, the application will prompt you " +"to authenticate as `root`. To add and remove users, select the btn:[+] and " +"btn:[-] button respectively. To add a user to the administrative group " +"`wheel`, change the Account Type from `Standard` to `Administrator`. To edit " +"a user's language setting, select the language and a drop-down menu appears." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:65 +#, no-wrap +msgid "The Users Settings Tool" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:67 +#, no-wrap +msgid "The Users settings tool" +msgstr "" + +#. type: Target for macro image +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:67 +#, no-wrap +msgid "managing_users.png" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:72 +msgid "" +"The commandline for call this Gui is : [user@domain ~]$ kcmshell5 " +"user_manager When a new user is created, the account is disabled until a " +"password is set. The Add User menu contains the options to set a password by " +"the administrator immediately, or to allow the user to choose a password at " +"the first login." +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:74 +#, no-wrap +msgid "Using Command Line Tools" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:77 +msgid "" +"indexterm:[users,tools for management of,useradd]indexterm:[users,tools for " +"management of,the Users setting tool]indexterm:[groups,tools for management " +"of,groupadd] Apart from the [application]*Users* settings tool described in " +"xref:basic-system-configuration/Managing_Users_and_Groups.adoc#s1-users-configui[Managing " +"Users in a Graphical Environment], which is designed for basic managing of " +"users, you can use command line tools for managing users and groups that are " +"listed in xref:Managing_Users_and_Groups.adoc#table-users-tools[Command line " +"utilities for managing users and groups]." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:79 +#, no-wrap +msgid "Command line utilities for managing users and groups" +msgstr "" + +#. type: Table +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:91 +#, no-wrap +msgid "" +"|Utilities|Description\n" +"|[command]#id#|Displays user and group IDs.\n" +"|[command]#useradd#, [command]#usermod#, [command]#userdel#|Standard " +"utilities for adding, modifying, and deleting user accounts.\n" +"|[command]#groupadd#, [command]#groupmod#, [command]#groupdel#|Standard " +"utilities for adding, modifying, and deleting groups.\n" +"|[command]#gpasswd#|Standard utility for administering the `/etc/group` " +"configuration file.\n" +"|[command]#pwck#, [command]#grpck#|Utilities that can be used for " +"verification of the password, group, and associated shadow files.\n" +"|[command]#pwconv#, [command]#pwunconv#|Utilities that can be used for the " +"conversion of passwords to shadow passwords, or back from shadow passwords " +"to standard passwords.\n" +"|[command]#grpconv#, [command]#grpunconv#|Similar to the previous, these " +"utilities can be used for conversion of shadowed information for group " +"accounts.\n" +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:94 +#, no-wrap +msgid "Adding a New User" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:97 +msgid "" +"indexterm:[useradd command,user account creation " +"using]indexterm:[adding,user]indexterm:[user configuration,command line " +"configuration,useradd] To add a new user to the system, type the following " +"at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:101 +#, no-wrap +msgid "[command]#useradd# _options_ _username_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:106 +msgid "" +"…where _options_ are command-line options as described in " +"xref:Managing_Users_and_Groups.adoc#table-useradd-options[Common useradd " +"command-line options]. indexterm:[user configuration,command line " +"configuration,passwd] By default, the [command]#useradd# command creates a " +"locked user account. To unlock the account, run the following command as " +"`root` to assign a password:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:110 +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:315 +#, no-wrap +msgid "[command]#passwd# _username_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:113 +msgid "" +"Optionally, you can set a password aging policy. See " +"xref:Managing_Users_and_Groups.adoc#s2-users-tools-password-aging[Enabling " +"Password Aging] for information on how to enable password aging." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:115 +#, no-wrap +msgid "Common useradd command-line options" +msgstr "" + +#. type: Table +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:133 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`-c`pass:attributes[{blank}] 'pass:attributes[{blank}]_comment_pass:attributes[{blank}]'|_comment_ " +"can be replaced with any string. This option is generally used to specify " +"the full name of a user.\n" +"|[option]`-d`pass:attributes[{blank}] pass:attributes[{blank}]_home_directory_|Home " +"directory to be used instead of default " +"`/home/pass:attributes[{blank}]_username_pass:attributes[{blank}]/`.\n" +"|[option]`-e`pass:attributes[{blank}] pass:attributes[{blank}]_date_|Date " +"for the account to be disabled in the format YYYY-MM-DD.\n" +"|[option]`-f`pass:attributes[{blank}] pass:attributes[{blank}]_days_|Number " +"of days after the password expires until the account is disabled. If `0` is " +"specified, the account is disabled immediately after the password " +"expires. If `-1` is specified, the account is not disabled after the " +"password expires.\n" +"|[option]`-g`pass:attributes[{blank}] pass:attributes[{blank}]_group_name_|Group " +"name or group number for the user's default (primary) group. The group must " +"exist prior to being specified here.\n" +"|[option]`-G`pass:attributes[{blank}] pass:attributes[{blank}]_group_list_|List " +"of additional (supplementary, other than default) group names or group " +"numbers, separated by commas, of which the user is a member. The groups must " +"exist prior to being specified here.\n" +"|[option]`-m`|Create the home directory if it does not exist.\n" +"|[option]`-M`|Do not create the home directory.\n" +"|[option]`-N`|Do not create a user private group for the user.\n" +"|[option]`-p`pass:attributes[{blank}] pass:attributes[{blank}]_password_|The " +"password encrypted with [command]#crypt#.\n" +"|[option]`-r`|Create a system account with a UID less than 1000 and without " +"a home directory.\n" +"|[option]`-s`|User's login shell, which defaults to [command]#/bin/bash#.\n" +"|[option]`-u`pass:attributes[{blank}] pass:attributes[{blank}]_uid_|User ID " +"for the user, which must be unique and greater than 999.\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:136 +msgid "" +"The command-line options associated with the [command]#usermod# command are " +"essentially the same. Note that if you want to add a user to another " +"supplementary group, you need to use the [option]`-a, --append` option with " +"the [option]`-G` option. Otherwise the list of supplementary groups for the " +"user will be overwritten by those specified with the [command]#usermod -G# " +"command." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:137 +#, no-wrap +msgid "Explaining the Process" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:139 +msgid "" +"The following steps illustrate what happens if the command [command]#useradd " +"juan# is issued on a system that has shadow passwords enabled:" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:141 +msgid "A new line for `juan` is created in `/etc/passwd`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:145 +#, no-wrap +msgid "juan:x:1001:1001::/home/juan:/bin/bash\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:148 +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:171 +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:211 +msgid "The line has the following characteristics:" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:150 +msgid "It begins with the user name `juan`." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:152 +msgid "" +"There is an `x` for the password field indicating that the system is using " +"shadow passwords." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:154 +msgid "" +"A UID greater than 999 is created. Under {MAJOROS}, UIDs below 1000 are " +"reserved for system use and should not be assigned to users." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:156 +msgid "" +"A GID greater than 999 is created. Under {MAJOROS}, GIDs below 1000 are " +"reserved for system use and should not be assigned to users." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:158 +msgid "" +"The optional _GECOS_ information is left blank. The GECOS field can be used " +"to provide additional information about the user, such as their full name or " +"phone number." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:160 +msgid "The home directory for `juan` is set to `/home/juan/`." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:162 +msgid "The default shell is set to [command]#/bin/bash#." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:164 +msgid "A new line for `juan` is created in `/etc/shadow`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:168 +#, no-wrap +msgid "juan:!!:14798:0:99999:7:::\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:173 +msgid "It begins with the username `juan`." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:175 +msgid "" +"Two exclamation marks (`!!`) appear in the password field of the " +"`/etc/shadow` file, which locks the account." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:176 +#, no-wrap +msgid "Note" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:181 +msgid "" +"If an encrypted password is passed using the [option]`-p` flag, it is placed " +"in the `/etc/shadow` file on the new line for the user." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:185 +msgid "The password is set to never expire." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:187 +msgid "A new line for a group named `juan` is created in `/etc/group`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:191 +#, no-wrap +msgid "juan:x:1001:\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:194 +msgid "" +"A group with the same name as a user is called a _user private group_. For " +"more information on user private groups, see " +"xref:Managing_Users_and_Groups.adoc#s2-users-groups-private-groups[User " +"Private Groups]." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:196 +msgid "The line created in `/etc/group` has the following characteristics:" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:198 +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:213 +msgid "It begins with the group name `juan`." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:200 +msgid "" +"An `x` appears in the password field indicating that the system is using " +"shadow group passwords." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:202 +msgid "" +"The GID matches the one listed for `juan`pass:attributes[{blank}]'s primary " +"group in `/etc/passwd`." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:204 +msgid "A new line for a group named `juan` is created in `/etc/gshadow`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:208 +#, no-wrap +msgid "juan:!::\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:215 +msgid "" +"An exclamation mark (`!`) appears in the password field of the " +"`/etc/gshadow` file, which locks the group." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:217 +msgid "All other fields are blank." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:219 +msgid "A directory for user `juan` is created in the `/home/` directory:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:224 +#, no-wrap +msgid "" +"~]#{nbsp}ls -ld /home/juan\n" +"drwx------. 4 juan juan 4096 Mar 3 18:23 /home/juan\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:227 +msgid "" +"This directory is owned by user `juan` and group `juan`. It has _read_, " +"_write_, and _execute_ privileges *only* for the user `juan`. All other " +"permissions are denied." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:229 +msgid "" +"The files within the `/etc/skel/` directory (which contain default user " +"settings) are copied into the new `/home/juan/` directory. The contents of " +"`/etc/skel/` may vary depending on installed applications:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:239 +#, no-wrap +msgid "" +"~]# ls -la /home/juan\n" +"total 24\n" +"drwx------. 4 juan juan 4096 Mar 3 18:23 .\n" +"drwxr-xr-x. 5 root root 4096 Mar 3 18:23 ..\n" +"-rw-r--r--. 1 juan juan 18 Jul 09 08:43 .bash_logout\n" +"-rw-r--r--. 1 juan juan 176 Jul 09 08:43 .bash_profile\n" +"-rw-r--r--. 1 juan juan 124 Jul 09 08:43 .bashrc\n" +"drwxr-xr-x. 4 juan juan 4096 Jul 09 08:43 .mozilla\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:242 +msgid "" +"At this point, a locked account called `juan` exists on the system. To " +"activate it, the administrator must next assign a password to the account " +"using the [command]#passwd# command and, optionally, set password aging " +"guidelines." +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:244 +#, no-wrap +msgid "Adding a New Group" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:247 +msgid "" +"indexterm:[group configuration,groupadd]indexterm:[adding,group] To add a " +"new group to the system, type the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:251 +#, no-wrap +msgid "groupadd pass:quotes[_options_] pass:quotes[_group_name_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:254 +msgid "" +"…where _options_ are command-line options as described in " +"xref:Managing_Users_and_Groups.adoc#table-groupadd-options[Common groupadd " +"command-line options]." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:256 +#, no-wrap +msgid "Common groupadd command-line options" +msgstr "" + +#. type: Table +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:267 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`-f`, [option]`--force`|When used with " +"[option]`-g`pass:attributes[{blank}] pass:attributes[{blank}]_gid_ and _gid_ " +"already exists, [command]#groupadd# will choose another unique _gid_ for the " +"group.\n" +"|[option]`-g`pass:attributes[{blank}] pass:attributes[{blank}]_gid_|Group ID " +"for the group, which must be unique and greater than 999.\n" +"|[option]`-K`, " +"[option]`--key`pass:attributes[{blank}] pass:attributes[{blank}]_key_pass:attributes[{blank}]=pass:attributes[{blank}]_value_|Override " +"`/etc/login.defs` defaults.\n" +"|[option]`-o`, [option]`--non-unique`|Allows creating groups with duplicate " +"GID.\n" +"|[option]`-p`, " +"[option]`--password`pass:attributes[{blank}] pass:attributes[{blank}]_password_|Use " +"this encrypted password for the new group.\n" +"|[option]`-r`|Create a system group with a GID less than 1000.\n" +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:270 +#, no-wrap +msgid "Enabling Password Aging" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:273 +msgid "" +"indexterm:[password,expire]indexterm:[password,aging]indexterm:[expiration " +"of password, forcing]indexterm:[chage command,forcing password expiration " +"with]indexterm:[user configuration,password,forcing expiration of] For " +"security reasons, it is advisable to require users to change their passwords " +"periodically. This can be done by using the [command]#chage# command." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:274 +#, no-wrap +msgid "Shadow passwords must be enabled to use chage" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:279 +msgid "" +"Shadow passwords must be enabled to use the [command]#chage# command. For " +"more information, see " +"xref:Managing_Users_and_Groups.adoc#s2-users-groups-shadow-utilities[Shadow " +"Passwords]." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:283 +msgid "" +"indexterm:[user configuration,command line configuration,chage] To configure " +"password expiration for a user from a shell prompt, run the following " +"command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:287 +#, no-wrap +msgid "[command]#chage# _options_ _username_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:290 +msgid "" +"…where _options_ are command line options as described in " +"xref:Managing_Users_and_Groups.adoc#table-chage-options[chage command line " +"options]. When the [command]#chage# command is followed directly by a " +"username (that is, when no command line options are specified), it displays " +"the specified users current password aging values and allows you to change " +"these values interactively." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:292 +#, no-wrap +msgid "chage command line options" +msgstr "" + +#. type: Table +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:304 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`-d`pass:attributes[{blank}] pass:attributes[{blank}]_days_|Specifies " +"the number of days since January 1, 1970 the password was changed.\n" +"|[option]`-E`pass:attributes[{blank}] pass:attributes[{blank}]_date_|Specifies " +"the date on which the account is locked, in the format YYYY-MM-DD. Instead " +"of the date, the number of days since January 1, 1970 can also be used.\n" +"|[option]`-I`pass:attributes[{blank}] pass:attributes[{blank}]_days_|Specifies " +"the number of inactive days after the password expiration before locking the " +"account. If the value is `0`, the account is not locked after the password " +"expires.\n" +"|[option]`-l`|Lists current account aging settings.\n" +"|[option]`-m`pass:attributes[{blank}] pass:attributes[{blank}]_days_|Specify " +"the minimum number of days after which the user must change passwords. If " +"the value is `0`, the password does not expire.\n" +"|[option]`-M`pass:attributes[{blank}] pass:attributes[{blank}]_days_|Specify " +"the maximum number of days for which the password is valid. When the number " +"of days specified by this option plus the number of days specified with the " +"[option]`-d` option is less than the current day, the user must change " +"passwords before using the account.\n" +"|[option]`-W`pass:attributes[{blank}] pass:attributes[{blank}]_days_|Specifies " +"the number of days before the password expiration date to warn the user.\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:307 +msgid "" +"You can configure a password to expire the first time a user logs in. This " +"forces users to change passwords immediately." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:309 +msgid "" +"Set up an initial password. There are two common approaches to this step: " +"you can either assign a default password, or you can use a null password." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:311 +msgid "" +"To assign a default password, type the following at a shell prompt as " +"`root`:" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:318 +msgid "To assign a null password instead, use the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:322 +#, no-wrap +msgid "[command]#passwd# [option]`-d` _username_\n" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:324 +#, no-wrap +msgid "Avoid using null passwords whenever possible" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:329 +msgid "" +"Using a null password, while convenient, is a highly insecure practice, as " +"any third party can log in first and access the system using the insecure " +"username. Always make sure that the user is ready to log in before unlocking " +"an account with a null password." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:333 +msgid "" +"Force immediate password expiration by running the following command as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:337 +#, no-wrap +msgid "[command]#chage# [option]`-d` [option]`0` _username_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:340 +msgid "" +"This command sets the value for the date the password was last changed to " +"the epoch (January 1, 1970). This value forces immediate password expiration " +"no matter what password aging policy, if any, is in place." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:342 +msgid "Upon the initial log in, the user is now prompted for a new password." +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:344 +#, no-wrap +msgid "Enabling Automatic Logouts" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:347 +msgid "" +"Especially when the user is logged in as `root`, an unattended login session " +"may pose a significant security risk. To reduce this risk, you can configure " +"the system to automatically log out idle users after a fixed period of time:" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:349 +msgid "" +"Make sure the [package]*screen* package is installed. You can do so by " +"running the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:353 +#, no-wrap +msgid "[command]#dnf# [option]`install` [option]`screen`\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:356 +msgid "" +"For more information on how to install packages in {MAJOROS}, refer to " +"xref:package-management/DNF.adoc#sec-Installing[Installing Packages]." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:358 +msgid "" +"As `root`, add the following line at the beginning of the `/etc/profile` " +"file to make sure the processing of this file cannot be interrupted:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:362 +#, no-wrap +msgid "trap \"\" 1 2 3 15\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:365 +msgid "" +"Add the following lines at the end of the `/etc/profile` file to start a " +"[command]#screen# session each time a user logs in to a virtual console or " +"remotely:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:375 +#, no-wrap +msgid "" +"SCREENEXEC=\"screen\"\n" +"if [ -w $(tty) ]; then\n" +" trap \"exec $SCREENEXEC\" 1 2 3 15\n" +" echo -n 'Starting session in 10 seconds'\n" +" sleep 10\n" +" exec $SCREENEXEC\n" +"fi\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:378 +msgid "" +"Note that each time a new session starts, a message will be displayed and " +"the user will have to wait ten seconds. To adjust the time to wait before " +"starting a session, change the value after the [command]#sleep# command." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:380 +msgid "" +"Add the following lines to the `/etc/screenrc` configuration file to close " +"the [command]#screen# session after a given period of inactivity:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:385 +#, no-wrap +msgid "" +"idle 120 quit\n" +"autodetach off\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:388 +msgid "" +"This will set the time limit to 120 seconds. To adjust this limit, change " +"the value after the [option]`idle` directive." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:390 +msgid "" +"Alternatively, you can configure the system to only lock the session by " +"using the following lines instead:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:395 +#, no-wrap +msgid "" +"idle 120 lockscreen\n" +"autodetach off\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:398 +msgid "This way, a password will be required to unlock the session." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:400 +msgid "The changes take effect the next time a user logs in to the system." +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:402 +#, no-wrap +msgid "Creating Group Directories" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:405 +msgid "" +"indexterm:[groups,shared directories]indexterm:[user private groups,and " +"shared directories] System administrators usually like to create a group for " +"each major project and assign people to the group when they need to access " +"that project's files. With this traditional scheme, file management is " +"difficult; when someone creates a file, it is associated with the primary " +"group to which they belong. When a single person works on multiple projects, " +"it becomes difficult to associate the right files with the right " +"group. However, with the UPG scheme, groups are automatically assigned to " +"files created within a directory with the _setgid_ bit set. The setgid bit " +"makes managing group projects that share a common directory very simple " +"because any files a user creates within the directory are owned by the group " +"that owns the directory." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:407 +msgid "" +"For example, a group of people need to work on files in the " +"`/opt/myproject/` directory. Some people are trusted to modify the contents " +"of this directory, but not everyone." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:409 +msgid "" +"As `root`, create the `/opt/myproject/` directory by typing the following at " +"a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:413 +#, no-wrap +msgid "[command]#mkdir /opt/myproject#\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:416 +msgid "Add the `myproject` group to the system:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:420 +#, no-wrap +msgid "[command]#groupadd myproject#\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:423 +msgid "" +"Associate the contents of the `/opt/myproject/` directory with the " +"`myproject` group:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:427 +#, no-wrap +msgid "[command]#chown root:myproject /opt/myproject#\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:430 +msgid "" +"Allow users in the group to create files within the directory and set the " +"setgid bit:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:434 +#, no-wrap +msgid "[command]#chmod 2775 /opt/myproject#\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:437 +msgid "" +"At this point, all members of the `myproject` group can create and edit " +"files in the `/opt/myproject/` directory without the administrator having to " +"change file permissions every time users write new files. To verify that the " +"permissions have been set correctly, run the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:442 +#, no-wrap +msgid "" +"~]#{nbsp}ls -ld /opt/myproject\n" +"drwxrwsr-x. 3 root myproject 4096 Mar 3 18:31 /opt/myproject\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:446 +msgid "Add users to the `myproject` group:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:450 +#, no-wrap +msgid "[command]#usermod -aG myproject _username_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:453 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:456 +msgid "" +"indexterm:[groups,additional resources]indexterm:[users,additional " +"resources] For more information on how to manage users and groups on Fedora, " +"see the resources listed below." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:457 +#, no-wrap +msgid "" +"Installed Documentationindexterm:[groups,additional resources,installed " +"documentation]indexterm:[users,additional resources,installed documentation]" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:459 +msgid "" +"For information about various utilities for managing users and groups, see " +"the following manual pages:" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:461 +msgid "" +"`useradd`(8) — The manual page for the [command]#useradd# command documents " +"how to use it to create new users." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:463 +msgid "" +"`userdel`(8) — The manual page for the [command]#userdel# command documents " +"how to use it to delete users." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:465 +msgid "" +"`usermod`(8) — The manual page for the [command]#usermod# command documents " +"how to use it to modify users." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:467 +msgid "" +"`groupadd`(8) — The manual page for the [command]#groupadd# command " +"documents how to use it to create new groups." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:469 +msgid "" +"`groupdel`(8) — The manual page for the [command]#groupdel# command " +"documents how to use it to delete groups." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:471 +msgid "" +"`groupmod`(8) — The manual page for the [command]#groupmod# command " +"documents how to use it to modify group membership." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:473 +msgid "" +"`gpasswd`(1) — The manual page for the [command]#gpasswd# command documents " +"how to manage the `/etc/group` file." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:475 +msgid "" +"`grpck`(8) — The manual page for the [command]#grpck# command documents how " +"to use it to verify the integrity of the `/etc/group` file." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:477 +msgid "" +"`pwck`(8) — The manual page for the [command]#pwck# command documents how to " +"use it to verify the integrity of the `/etc/passwd` and `/etc/shadow` files." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:479 +msgid "" +"`pwconv`(8) — The manual page for the [command]#pwconv#, " +"[command]#pwunconv#, [command]#grpconv#, and [command]#grpunconv# commands " +"documents how to convert shadowed information for passwords and groups." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:481 +msgid "" +"`id`(1) — The manual page for the [command]#id# command documents how to " +"display user and group IDs." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:483 +msgid "For information about related configuration files, see:" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:485 +msgid "" +"`group`(5) — The manual page for the `/etc/group` file documents how to use " +"this file to define system groups." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:487 +msgid "" +"`passwd`(5) — The manual page for the `/etc/passwd` file documents how to " +"use this file to define user information." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Managing_Users_and_Groups.adoc:488 +msgid "" +"`shadow`(5) — The manual page for the `/etc/shadow` file documents how to " +"use this file to set passwords and account expiration information for the " +"system." +msgstr "" diff --git a/pot/rawhide/pages/basic-system-configuration/Opening_GUI_Applications.pot b/pot/rawhide/pages/basic-system-configuration/Opening_GUI_Applications.pot new file mode 100644 index 00000000000..04634bf80f4 --- /dev/null +++ b/pot/rawhide/pages/basic-system-configuration/Opening_GUI_Applications.pot @@ -0,0 +1,568 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:5 +#, no-wrap +msgid "Opening Graphical Applications" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:8 +msgid "" +"Fedora provides graphical applications in addition to command line utilities " +"for configuring many features. This chapter describes methods for opening " +"`Graphical User Interface`, or _GUI_, applications in various environments." +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:10 +#, no-wrap +msgid "Opening graphical applications from the command line" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:13 +msgid "" +"Graphical applications can be launched from a terminal window or console " +"session by simply typing the name of the application." +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:18 +#, no-wrap +msgid "[fedorauser@localhost]$ [command]#firefox#\n" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:20 +#, no-wrap +msgid "File names vs Application names" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:25 +msgid "" +"Programs are opened from the command line using the name of the executable " +"file provided in the program's package. An entry in the desktop menu will " +"often be named differently from the file it executes. For example, the GNOME " +"disk management utility appears in the menu as [application]*Disks*, and the " +"file it executes is `/usr/bin/gnome-disks`." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:29 +msgid "" +"When a program is executed on the command line, the terminal is occupied " +"until the program completes. When a graphical application is executed from " +"the command line, the program's error output, or `STDERR`, is sent to the " +"terminal window. This can be especially useful when troubleshooting." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:30 +#, no-wrap +msgid "Viewing errors by launching graphical applications from the command line" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:37 +#, no-wrap +msgid "" +"[fedorauser@localhost]$ astromenace-wrapper\n" +"\tAstroMenace 1.3.1 121212\n" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:40 +#, no-wrap +msgid "" +"\tOpen XML file: /home/fedorauser/.config/astromenace/amconfig.xml\n" +"\tVFS file was opened /usr/share/astromenace/gamedata.vfs\n" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:45 +#, no-wrap +msgid "" +"\tVendor : OpenAL Community\n" +"\tRenderer : OpenAL Soft\n" +"\tVersion : 1.1 ALSOFT 1.15.1\n" +"\tALut ver : 1.1\n" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:47 +#, no-wrap +msgid "\tFont initialized: DATA/FONT/LiberationMono-Bold.ttf\n" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:49 +#, no-wrap +msgid "\tCurrent Video Mode: 3200x1080 32bit\n" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:54 +#, no-wrap +msgid "" +"\tXinerama/TwinView detected.\n" +"\tScreen count: 2\n" +"\tScreen #0: (0, 0) x (1920, 1080)\n" +"\tScreen #1: (1920, 0) x (1280, 1024)\n" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:61 +#, no-wrap +msgid "" +"\tSupported resolutions list:\n" +"\t640x480 16bit\n" +"\t640x480 32bit\n" +"\t640x480 0bit\n" +"\t768x480 16bit\n" +"\t\n" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:66 +msgid "" +"To launch a graphical application, but fork the additional output into the " +"background and return the terminal for immediate use, use the shell's `job " +"control` feature." +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:71 +#, no-wrap +msgid "[fedorauser@localhost]$ [command]#emacs foo.txt &#\n" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:73 +#, no-wrap +msgid "Ending a session" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:78 +msgid "" +"Applications that hold the command line prompt until they complete will " +"close when the terminal session ends, even if they are forked into the " +"background." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:82 +msgid "" +"GUI programs can also be launched on one `TTY` and displayed on another by " +"specifying the `DISPLAY` variable. This can be useful when running multiple " +"graphical sessions, or for troubleshooting problems with a desktop session." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:84 +msgid "" +"Switch to another TTY using the key combination kbd:[Ctrl + Alt + F2] and " +"log in. Note that consoles are available by default with kbd:[F2] through " +"kbd:[F6]." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:86 +msgid "" +"Identify the X session you want to target. The `DISPLAY` variable is always " +"an integer preceded by a colon, and will be *:0* in most cases. Check the " +"arguments of the currently running [application]*X* process to verify the " +"value. The command below shows both the `DISPLAY` variable as well as the " +"TTY that [application]*X* is running on, `tty1`." +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:92 +#, no-wrap +msgid "" +"[fedorauser@localhost]$ ps aux|grep /usr/bin/X\n" +"root 1498 7.1 1.0 521396 353984 pass:quotes[`tty1`] Ss+ 00:04 " +"66:34 /usr/bin/X pass:quotes[`:0`] vt1 -background none -nolisten tcp -auth " +"/var/run/kdm/A:0-22Degc\n" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:94 +#, no-wrap +msgid "" +"root 23874 0.0 0.0 109184 900 pts/21 S+ 15:35 0:00 grep " +"--color=auto /usr/bin/X\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:97 +msgid "Specify the `DISPLAY` variable when executing the program." +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:102 +#, no-wrap +msgid "[fedorauser@localhost]$ [command]#DISPLAY=:0 gnome-shell --replace &#\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:105 +msgid "" +"Switch back to the TTY the graphical session is running on. Since the " +"example above shows [application]*X* running on `vt1`, pressing kbd:[Ctrl + " +"Alt + F1] will return to the desktop environment." +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:107 +#, no-wrap +msgid "Launching Applications with kbd:[Alt + F2]" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:110 +msgid "" +"Most desktop environments follow the convention of using the key combination " +"kbd:[Alt + F2] for opening new applications. Pressing kbd:[Alt + F2] brings " +"up a prompt for a command to be entered into." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:112 +msgid "" +"Commands entered into this dialog box function much as they would if entered " +"in a terminal. Applications are known by their file name, and can accept " +"arguments." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:114 +#, no-wrap +msgid "Using kbd:[Alt + F2] with [application]*GNOME*" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:116 +#, no-wrap +msgid "GNOME command entry dialog box" +msgstr "" + +#. type: Target for macro image +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:116 +#, no-wrap +msgid "alt-f2_GNOME.png" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:119 +#, no-wrap +msgid "Using kbd:[Alt + F2] with [application]*KDE*" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:121 +#, no-wrap +msgid "KDE command entry dialog box" +msgstr "" + +#. type: Target for macro image +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:121 +#, no-wrap +msgid "alt-f2_KDE.png" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:124 +#, no-wrap +msgid "Using kbd:[Alt + F2] with [application]*LXDE*" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:126 +#, no-wrap +msgid "LXDE command entry dialog box." +msgstr "" + +#. type: Target for macro image +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:126 +#, no-wrap +msgid "alt-f2_LXDE.png" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:129 +#, no-wrap +msgid "Using kbd:[Alt + F2] with [application]*MATE*" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:131 +#, no-wrap +msgid "MATE command entry dialog box." +msgstr "" + +#. type: Target for macro image +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:131 +#, no-wrap +msgid "alt-f2_MATE.png" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:134 +#, no-wrap +msgid "Using kbd:[Alt + F2] with [application]*XFCE*" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:136 +#, no-wrap +msgid "XFCE command entry dialog box." +msgstr "" + +#. type: Target for macro image +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:136 +#, no-wrap +msgid "alt-f2_XFCE.png" +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:139 +#, no-wrap +msgid "Launching applications from the Desktop Menu" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:142 +msgid "" +"Applications can also be opened from the menu system provided by the desktop " +"environment in use. While the presentation may vary between desktop " +"environments, the menu entries and their categories are provided by the " +"individual application and standardized by the " +"link:++https://standards.freedesktop.org/menu-spec/menu-spec-latest.html++[freedesktop.org " +"Desktop Menu Specification]. Some desktop environments also provide search " +"functionality in their menu system to allow quick and easy access to " +"applications." +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:144 +#, no-wrap +msgid "Using GNOME menus" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:147 +msgid "" +"The GNOME menu, called the `overview`, can be accessed by either clicking " +"the `Activities` button in the top left of the primary display, by moving " +"the mouse past the top left `hot corner`, or by pressing the kbd:[Super] ( " +"kbd:[Windows] ) key. The `overview` presents documents in addition to " +"applications." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:149 +msgid "" +"Selecting an item from the menu is best accomplished using the `search " +"box`. Simply bring up the `overview`, and begin typing the name of the " +"application you want to launch. Pressing enter will launch the highlighted " +"application, or you can use the arrow keys or mouse to choose an " +"alternative." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:151 +#, no-wrap +msgid "Using the GNOME search box" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:153 +#, no-wrap +msgid "" +"Typing the name of an application into the overview search box will display " +"matching menu entries. The search also matches descriptions" +msgstr "" + +#. type: Target for macro image +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:153 +#, no-wrap +msgid "searchmenu_GNOME.png" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:156 +msgid "" +"The `overview` can also be browsed. The bar on the left, called the `dash`, " +"shows frequently used applications and a grid icon. Clicking on the grid " +"icon brings up a grid in the center of the window that displays frequently " +"used applications. The grid will display all available applications if " +"selected using the `All` button at the bottom of the screen." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:158 +#, no-wrap +msgid "Browsing GNOME menu entries" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:160 +#, no-wrap +msgid "The GNOME menu has a bar on the left for frequently used applications" +msgstr "" + +#. type: Target for macro image +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:160 +#, no-wrap +msgid "menu_GNOME.png" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:163 +msgid "" +"To learn more about using [application]*GNOME shell*, visit " +"link:++https://wiki.gnome.org/GnomeShell/CheatSheet++[]" +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:165 +#, no-wrap +msgid "Using KDE menus" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:168 +msgid "" +"The KDE menu is opened by clicking the {MAJOROS} button at the bottom left " +"corner of the screen. The menu initially displays favorite applications, " +"which can be added to by right clicking any menu entry. Hovering over the " +"icons in the lower portion of the menu will display applications, file " +"systems, recently used applications, or options for logging out of the " +"system." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:170 +#, no-wrap +msgid "The KDE desktop menu." +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:172 +#, no-wrap +msgid "" +"The KDE menu displays applications in categories. The contents of the " +"categories are displayed when clicked." +msgstr "" + +#. type: Target for macro image +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:172 +#, no-wrap +msgid "menu_KDE.png" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:175 +msgid "" +"Search functionality is also available in the KDE menu system. To search for " +"applications, open the menu and begin typing. The menu will display matching " +"entries." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:177 +#, no-wrap +msgid "Searching with the KDE menu." +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:179 +#, no-wrap +msgid "" +"The KDE menu will search for matching applications if you type into the " +"search box. For example" +msgstr "" + +#. type: Target for macro image +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:179 +#, no-wrap +msgid "searchmenu_KDE.png" +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:181 +#, no-wrap +msgid "Using menus in LXDE, MATE, and XFCE" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:184 +msgid "" +"Menus in LXDE, MATE, and XFCE have a varied appearance but a very similar " +"structure. They categorize applications, and the contents of a category are " +"displayed by hovering the cursor over the entry. Applications are launched " +"by clicking on an entry." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:186 +#, no-wrap +msgid "The LXDE menu" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:188 +#, no-wrap +msgid "LXDE Menu" +msgstr "" + +#. type: Target for macro image +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:188 +#, no-wrap +msgid "menu_LXDE.png" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:191 +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:193 +#, no-wrap +msgid "MATE menu" +msgstr "" + +#. type: Target for macro image +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:193 +#, no-wrap +msgid "menu_MATE.png" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:196 +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:198 +#, no-wrap +msgid "XFCE Menu" +msgstr "" + +#. type: Target for macro image +#: ./pages/basic-system-configuration/Opening_GUI_Applications.adoc:198 +#, no-wrap +msgid "menu_XFCE.png" +msgstr "" diff --git a/pot/rawhide/pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.pot b/pot/rawhide/pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.pot new file mode 100644 index 00000000000..a1eeab7ee81 --- /dev/null +++ b/pot/rawhide/pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.pot @@ -0,0 +1,548 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:5 +#, no-wrap +msgid "System Locale and Keyboard Configuration" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:8 +msgid "" +"The *system locale* specifies the language settings of system services and " +"user interfaces. The *keyboard layout* settings control the layout used on " +"the text console and graphical user interfaces." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:10 +msgid "" +"These settings can be made by modifying the `/etc/locale.conf` configuration " +"file or by using the [application]*localectl* utility. You can also set " +"these settings during system installation using the installer graphical " +"interface, text mode interface, or the [command]*keyboard* and " +"[command]*lang* Kickstart commands. See the " +"link:https://docs.fedoraproject.org/en-US/fedora/f{MAJOROSVER}/install-guide[{MAJOROS} " +"Installation Guide] for information about these options." +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:12 +#, no-wrap +msgid "Setting the System Locale" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:15 +msgid "" +"System-wide locale settings are stored in the `/etc/locale.conf` file, which " +"is read at early boot by the `systemd` daemon. The locale settings " +"configured in `/etc/locale.conf` are inherited by every service or user, " +"unless individual programs or individual users override them." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:17 +msgid "" +"The basic file format of `/etc/locale.conf` is a newline-separated list of " +"variable assignments. For example, German locale with English messages in " +"`/etc/locale.conf` looks as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:22 +#, no-wrap +msgid "" +"LANG=de_DE.UTF-8\n" +"LC_MESSAGES=C\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:26 +msgid "" +"Here, the LC_MESSAGES option determines the locale used for diagnostic " +"messages written to the standard error output. To further specify locale " +"settings in `/etc/locale.conf`, you can use several other options, the most " +"relevant are summarized in " +"xref:System_Locale_and_Keyboard_Configuration.adoc#tab-locale_options[Options " +"configurable in /etc/locale.conf]. See the `locale(7)` manual page for " +"detailed information on these options. Note that the LC_ALL option, which " +"represents all possible options, should not be configured in " +"`/etc/locale.conf`." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:28 +#, no-wrap +msgid "Options configurable in /etc/locale.conf" +msgstr "" + +#. type: Table +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:39 +#, no-wrap +msgid "" +"|Option|Description\n" +"|LANG|Provides a default value for the system locale.\n" +"|LC_COLLATE|Changes the behavior of functions which compare strings in the " +"local alphabet.\n" +"|LC_CTYPE|Changes the behavior of the character handling and classification " +"functions and the multibyte character functions.\n" +"|LC_NUMERIC|Describes the way numbers are usually printed, with details such " +"as decimal point versus decimal comma.\n" +"|LC_TIME|Changes the display of the current time, 24-hour versus 12-hour " +"clock.\n" +"|LC_MESSAGES|Determines the locale used for diagnostic messages written to " +"the standard error output.\n" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:42 +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:51 +#, no-wrap +msgid "Displaying the Current Status" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:45 +msgid "" +"The [command]#localectl# command can be used to query and change the system " +"locale and keyboard layout settings. To show the current settings, use the " +"[option]`status` option:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:49 +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:139 +#, no-wrap +msgid "[command]#localectl# [option]`status`\n" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:55 +msgid "" +"The output of the previous command lists the currently set locale, keyboard " +"layout configured for the console and for the X11 window system." +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:63 +#, no-wrap +msgid "" +"~]${nbsp}localectl status\n" +" System Locale: LANG=en_US.UTF-8\n" +" VC Keymap: us\n" +" X11 Layout: n/a\n" +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:69 +#, no-wrap +msgid "Listing Available Locales" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:72 +msgid "To list all locales available for your system, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:76 +#, no-wrap +msgid "[command]#localectl# [option]`list-locales`\n" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:78 +#, no-wrap +msgid "Listing Locales" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:82 +msgid "" +"Imagine you want to select a specific English locale, but you are not sure " +"if it is available on the system. You can check that by listing all English " +"locales with the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:95 +#, no-wrap +msgid "" +"~]${nbsp}localectl list-locales | grep pass:quotes[`en_`]\n" +"en_AG\n" +"en_AG.utf8\n" +"en_AU\n" +"en_AU.iso88591\n" +"en_AU.utf8\n" +"en_BW\n" +"en_BW.iso88591\n" +"en_BW.utf8\n" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:97 +#, no-wrap +msgid "pass:quotes[*output truncated*]\n" +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:103 +#, no-wrap +msgid "Setting the Locale" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:106 +msgid "To set the default system locale, use the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:110 +#, no-wrap +msgid "" +"[command]#localectl# [option]`set-locale` " +"[option]`LANG`pass:attributes[{blank}]=pass:attributes[{blank}]_locale_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:113 +msgid "" +"Replace _locale_ with the locale name, found with the [command]#localectl# " +"[option]`list-locales` command. The above syntax can also be used to " +"configure parameters from " +"xref:System_Locale_and_Keyboard_Configuration.adoc#tab-locale_options[Options " +"configurable in /etc/locale.conf]." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:114 +#, no-wrap +msgid "Changing the Default Locale" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:118 +msgid "" +"For example, if you want to set British English as your default locale, " +"first find the name of this locale by using [option]`list-locales`. Then, as " +"`root`, type the command in the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:122 +#, no-wrap +msgid "~]#{nbsp}localectl set-locale LANG=pass:quotes[`en_GB.utf8`]\n" +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:127 +#, no-wrap +msgid "Changing the Keyboard Layout" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:130 +msgid "" +"indexterm:[localectl,keyboard configuration]indexterm:[keyboard " +"configuration,layout] The keyboard layout settings enable the user to " +"control the layout used on the text console and graphical user interfaces." +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:132 +#, no-wrap +msgid "Displaying the Current Settings" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:135 +msgid "" +"As mentioned before, you can check your current keyboard layout " +"configuration with the following command:" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:141 +#, no-wrap +msgid "Displaying the Keyboard Settings" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:145 +msgid "" +"In the following output, you can see the keyboard layout configured for the " +"virtual console and for the X11 window system." +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:153 +#, no-wrap +msgid "" +"~]${nbsp}localectl status\n" +" System Locale: LANG=en_US.utf8\n" +" VC Keymap: us\n" +" X11 Layout: us\n" +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:159 +#, no-wrap +msgid "Listing Available Keymaps" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:162 +msgid "" +"To list all available keyboard layouts that can be configured on your " +"system, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:166 +#, no-wrap +msgid "[command]#localectl# [option]`list-keymaps`\n" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:168 +#, no-wrap +msgid "Searching for a Particular Keymap" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:172 +msgid "" +"You can use [command]#grep# to search the output of the previous command for " +"a specific keymap name. There are often multiple keymaps compatible with " +"your currently set locale. For example, to find available Czech keyboard " +"layouts, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:185 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#localectl# [option]`list-keymaps` " +"| [command]#grep# `cz`\n" +"cz\n" +"cz-cp1250\n" +"cz-lat2\n" +"cz-lat2-prog\n" +"cz-qwerty\n" +"cz-us-qwertz\n" +"sunt5-cz-us\n" +"sunt5-us-cz\n" +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:192 +#, no-wrap +msgid "Setting the Keymap" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:195 +msgid "" +"To set the default keyboard layout for your system, use the following " +"command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:199 +#, no-wrap +msgid "[command]#localectl# [option]`set-keymap` _map_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:202 +msgid "" +"Replace _map_ with the name of the keymap taken from the output of the " +"[command]#localectl# [option]`list-keymaps` command. Unless the " +"[option]`--no-convert` option is passed, the selected setting is also " +"applied to the default keyboard mapping of the X11 window system, after " +"converting it to the closest matching X11 keyboard mapping. This also " +"applies in reverse, you can specify both keymaps with the following command " +"as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:206 +#, no-wrap +msgid "[command]#localectl# [option]`set-x11-keymap` _map_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:209 +msgid "" +"If you want your X11 layout to differ from the console layout, use the " +"[option]`--no-convert` option." +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:213 +#, no-wrap +msgid "[command]#localectl# [option]`--no-convert` [option]`set-x11-keymap` _map_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:216 +msgid "" +"With this option, the X11 keymap is specified without changing the previous " +"console layout setting." +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:217 +#, no-wrap +msgid "Setting the X11 Keymap Separately" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:221 +msgid "" +"Imagine you want to use German keyboard layout in the graphical interface, " +"but for console operations you want to retain the US keymap. To do so, type " +"as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:225 +#, no-wrap +msgid "~]#{nbsp}localectl --no-convert set-x11-keymap pass:quotes[_de_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:228 +msgid "" +"Then you can verify if your setting was successful by checking the current " +"status:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:236 +#, no-wrap +msgid "" +"~]${nbsp}localectl status\n" +" System Locale: LANG=de_DE.UTF-8\n" +" VC Keymap: us\n" +" X11 Layout: de\n" +msgstr "" + +#. type: delimited block = +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:242 +msgid "Apart from keyboard layout (_map_), three other options can be specified:" +msgstr "" + +#. type: delimited block - +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:246 +#, no-wrap +msgid "" +"[command]#localectl# [option]`set-x11-keymap` _map_ _model_ _variant_ " +"_options_\n" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:250 +msgid "" +"Replace _model_ with the keyboard model name, _variant_ and _options_ with " +"keyboard variant and option components, which can be used to enhance the " +"keyboard behavior. These options are not set by default. For more " +"information on X11 Model, X11 Variant, and X11 Options see the `kbd(4)` man " +"page." +msgstr "" + +#. type: Title === +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:252 +#, no-wrap +msgid "Consider this option if using gnome" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:255 +msgid "This should work if the following conditions apply:" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:257 +msgid "Using gnome as the desktop environment" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:259 +msgid "Your layout is not listed under Settings -> Keyboard -> Input Sources" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:261 +msgid "In your terminal type in:" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:263 +msgid "`gsettings set org.gnome.desktop.input-sources show-all-sources true`" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:266 +msgid "" +"after pressing return, try looking under your keyboard settings again as " +"there should be a lot more options available. As the proper source for help " +"is gnome in this case, here is more information from gnome:" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:268 +msgid "https://help.gnome.org/users/gnome-help/stable/keyboard-layouts.html.en" +msgstr "" + +#. type: Title == +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:270 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:273 +msgid "" +"For more information on how to configure the keyboard layout on Fedora, see " +"the resources listed below:" +msgstr "" + +#. type: Block title +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:274 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:277 +msgid "" +"`localectl`(1) — The manual page for the [command]#localectl# command line " +"utility documents how to use this tool to configure the system locale and " +"keyboard layout." +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/System_Locale_and_Keyboard_Configuration.adoc:278 +msgid "" +"`loadkeys`(1) — The manual page for the [command]#loadkeys# command provides " +"more information on how to use this tool to change the keyboard layout in a " +"virtual console." +msgstr "" diff --git a/pot/rawhide/pages/basic-system-configuration/intro-basic-system-configuration.pot b/pot/rawhide/pages/basic-system-configuration/intro-basic-system-configuration.pot new file mode 100644 index 00000000000..c3b03a265d3 --- /dev/null +++ b/pot/rawhide/pages/basic-system-configuration/intro-basic-system-configuration.pot @@ -0,0 +1,31 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/basic-system-configuration/intro-basic-system-configuration.adoc:1 +#, no-wrap +msgid "Basic System Configuration" +msgstr "" + +#. type: Plain text +#: ./pages/basic-system-configuration/intro-basic-system-configuration.adoc:3 +msgid "" +"This part covers basic system administration tasks such as keyboard " +"configuration, date and time configuration, managing users and groups, and " +"gaining privileges." +msgstr "" diff --git a/pot/rawhide/pages/index.pot b/pot/rawhide/pages/index.pot new file mode 100644 index 00000000000..94beb736f3f --- /dev/null +++ b/pot/rawhide/pages/index.pot @@ -0,0 +1,56 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/index.adoc:4 +#, no-wrap +msgid "System Administrator's Guide" +msgstr "" + +#. type: Plain text +#: ./pages/index.adoc:7 +msgid "Deployment, Configuration, and Administration of {MAJOROSVER}" +msgstr "" + +#. type: delimited block = +#: ./pages/index.adoc:11 +#, no-wrap +msgid "**Editor's Note** \n" +msgstr "" + +#. type: delimited block = +#: ./pages/index.adoc:13 +msgid "" +"_This guide is deprecated!_ Large parts of it are no longer current and it " +"will not receive any updates. A series of shorter, topic-specific " +"documentation will gradually replace it." +msgstr "" + +#. type: Plain text +#: ./pages/index.adoc:19 +msgid "" +"The [citetitle]_System Administrator's Guide_ documents relevant information " +"regarding the deployment, configuration, and administration of " +"{MAJOROSVER}. It is oriented towards system administrators with a basic " +"understanding of the system." +msgstr "" + +#. type: Plain text +#: ./pages/index.adoc:23 +msgid "image:title_logo.svg[Fedora Documentation Team]" +msgstr "" diff --git a/pot/rawhide/pages/infrastructure-services/OpenSSH.pot b/pot/rawhide/pages/infrastructure-services/OpenSSH.pot new file mode 100644 index 00000000000..2d661f7934f --- /dev/null +++ b/pot/rawhide/pages/infrastructure-services/OpenSSH.pot @@ -0,0 +1,3078 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/infrastructure-services/OpenSSH.adoc:6 +#, no-wrap +msgid "OpenSSH" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:11 +msgid "" +"indexterm:[OpenSSH] `SSH` (Secure Shell) is a protocol which facilitates " +"secure communications between two systems using a client-server architecture " +"and allows users to log into server host systems remotely. Unlike other " +"remote communication protocols, such as `FTP`, `Telnet`, or " +"[command]#rlogin#, SSH encrypts the login session, rendering the connection " +"difficult for intruders to collect unencrypted passwords." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:13 +msgid "" +"The [application]*ssh* program is designed to replace older, less secure " +"terminal applications used to log into remote hosts, such as " +"[command]#telnet# or [command]#rsh#. A related program called [command]#scp# " +"replaces older programs designed to copy files between hosts, such as " +"[command]#rcp#. Because these older applications do not encrypt passwords " +"transmitted between the client and the server, avoid them whenever " +"possible. Using secure methods to log into remote systems decreases the " +"risks for both the client system and the remote host." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:15 +msgid "" +"{MAJOROS} includes the general OpenSSH package, [package]*openssh*, as well " +"as the OpenSSH server, [package]*openssh-server*, and client, " +"[package]*openssh-clients*, packages. Note, the OpenSSH packages require the " +"OpenSSL package [package]*openssl-libs*, which installs several important " +"cryptographic libraries, enabling OpenSSH to provide encrypted " +"communications." +msgstr "" + +#. type: Title == +#: ./pages/infrastructure-services/OpenSSH.adoc:17 +#, no-wrap +msgid "The SSH Protocol" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:20 +#, no-wrap +msgid "Why Use SSH?" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:23 +msgid "" +"indexterm:[SSH protocol,security risks] Potential intruders have a variety " +"of tools at their disposal enabling them to disrupt, intercept, and re-route " +"network traffic in an effort to gain access to a system. In general terms, " +"these threats can be categorized as follows:" +msgstr "" + +#. type: Labeled list +#: ./pages/infrastructure-services/OpenSSH.adoc:24 +#, no-wrap +msgid "Interception of communication between two systems" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:25 +msgid "" +"The attacker can be somewhere on the network between the communicating " +"parties, copying any information passed between them. He may intercept and " +"keep the information, or alter the information and send it on to the " +"intended recipient." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:27 +msgid "" +"This attack is usually performed using a _packet sniffer_, a rather common " +"network utility that captures each packet flowing through the network, and " +"analyzes its content." +msgstr "" + +#. type: Labeled list +#: ./pages/infrastructure-services/OpenSSH.adoc:28 +#, no-wrap +msgid "Impersonation of a particular host" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:29 +msgid "" +"Attacker's system is configured to pose as the intended recipient of a " +"transmission. If this strategy works, the user's system remains unaware that " +"it is communicating with the wrong host." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:31 +msgid "" +"This attack can be performed using a technique known as _DNS poisoning_, or " +"via so-called _IP spoofing_. In the first case, the intruder uses a cracked " +"DNS server to point client systems to a maliciously duplicated host. In the " +"second case, the intruder sends falsified network packets that appear to be " +"from a trusted host." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:33 +msgid "" +"Both techniques intercept potentially sensitive information and, if the " +"interception is made for hostile reasons, the results can be disastrous. If " +"SSH is used for remote shell login and file copying, these security threats " +"can be greatly diminished. This is because the SSH client and server use " +"digital signatures to verify their identity. Additionally, all communication " +"between the client and server systems is encrypted. Attempts to spoof the " +"identity of either side of a communication does not work, since each packet " +"is encrypted using a key known only by the local and remote systems." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:35 +#, no-wrap +msgid "Main Features" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:38 +msgid "" +"indexterm:[SSH protocol,features]indexterm:[OpenSSH,SSH] The SSH protocol " +"provides the following safeguards:" +msgstr "" + +#. type: Labeled list +#: ./pages/infrastructure-services/OpenSSH.adoc:39 +#, no-wrap +msgid "No one can pose as the intended server" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:40 +msgid "" +"After an initial connection, the client can verify that it is connecting to " +"the same server it had connected to previously." +msgstr "" + +#. type: Labeled list +#: ./pages/infrastructure-services/OpenSSH.adoc:41 +#, no-wrap +msgid "No one can capture the authentication information" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:42 +msgid "" +"The client transmits its authentication information to the server using " +"strong encryption." +msgstr "" + +#. type: Labeled list +#: ./pages/infrastructure-services/OpenSSH.adoc:43 +#, no-wrap +msgid "No one can intercept the communication" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:44 +msgid "" +"All data sent and received during a session is transferred using strong " +"encryption, making intercepted transmissions extremely difficult to decrypt " +"and read." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:46 +msgid "Additionally, it also offers the following options:" +msgstr "" + +#. type: Labeled list +#: ./pages/infrastructure-services/OpenSSH.adoc:47 +#, no-wrap +msgid "It provides secure means to use graphical applications over a network" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:48 +msgid "" +"Using a technique called _X11 forwarding_, the client can forward _X11_ (_X " +"Window System_) applications from the server. Note that if you set the " +"[option]`ForwardX11Trusted` option to `yes` or you use SSH with the " +"[option]`-Y` option, you bypass the X11 SECURITY extension controls, which " +"can result in a security threat." +msgstr "" + +#. type: Labeled list +#: ./pages/infrastructure-services/OpenSSH.adoc:49 +#, no-wrap +msgid "It provides a way to secure otherwise insecure protocols" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:50 +msgid "" +"The SSH protocol encrypts everything it sends and receives. Using a " +"technique called _port forwarding_, an SSH server can become a conduit to " +"securing otherwise insecure protocols, like *POP*, and increasing overall " +"system and data security." +msgstr "" + +#. type: Labeled list +#: ./pages/infrastructure-services/OpenSSH.adoc:51 +#, no-wrap +msgid "It can be used to create a secure channel" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:52 +msgid "" +"The OpenSSH server and client can be configured to create a tunnel similar " +"to a virtual private network for traffic between server and client machines." +msgstr "" + +#. type: Labeled list +#: ./pages/infrastructure-services/OpenSSH.adoc:53 +#, no-wrap +msgid "It supports Kerberos authentication" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:54 +msgid "" +"OpenSSH servers and clients can be configured to authenticate using the " +"*GSSAPI* (Generic Security Services Application Program Interface) " +"implementation of the Kerberos network authentication protocol." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:56 +#, no-wrap +msgid "Protocol Versions" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:59 +msgid "" +"indexterm:[SSH protocol,version 1]indexterm:[SSH protocol,version 2] Two " +"varieties of SSH currently exist: version 1 and version 2. The OpenSSH suite " +"under {MAJOROS} uses SSH version 2, which has an enhanced key exchange " +"algorithm not vulnerable to the known exploit in version 1. Protocol version " +"1 was removed from OpenSSH suite and is no longer supported." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:61 +#, no-wrap +msgid "Event Sequence of an SSH Connection" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:64 +msgid "" +"indexterm:[SSH protocol,connection sequence] The following series of events " +"help protect the integrity of SSH communication between two hosts." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:66 +msgid "" +"A cryptographic handshake is made so that the client can verify that it is " +"communicating with the correct server." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:68 +msgid "" +"The transport layer of the connection between the client and remote host is " +"encrypted using a symmetric cipher." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:70 +msgid "The client authenticates itself to the server." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:72 +msgid "The client interacts with the remote host over the encrypted connection." +msgstr "" + +#. type: Title ==== +#: ./pages/infrastructure-services/OpenSSH.adoc:74 +#, no-wrap +msgid "Transport Layer" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:77 +msgid "" +"indexterm:[SSH protocol,layers,transport layer] The primary role of the " +"transport layer is to facilitate safe and secure communication between the " +"two hosts at the time of authentication and during subsequent " +"communication. The transport layer accomplishes this by handling the " +"encryption and decryption of data, and by providing integrity protection of " +"data packets as they are sent and received. The transport layer also " +"provides compression, speeding the transfer of information." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:79 +msgid "" +"Once an SSH client contacts a server, key information is exchanged so that " +"the two systems can correctly construct the transport layer. The following " +"steps occur during this exchange:" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:81 +msgid "The key exchange algorithm is determined" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:83 +msgid "The public key signature algorithm is determined" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:85 +msgid "The symmetric encryption algorithm is determined" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:87 +msgid "The message authentication algorithm is determined" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:89 +msgid "Keys are exchanged" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:91 +msgid "" +"During the key exchange, the server identifies itself to the client with a " +"unique _host key_. If the client has never communicated with this particular " +"server before, the server's host key is unknown to the client and it does " +"not connect. OpenSSH notifies the user that the authenticity of the host " +"cannot be established and prompts the user to accept or reject it. The user " +"is expected to independently verify the new host key before accepting it. In " +"subsequent connections, the server's host key is checked against the saved " +"version on the client, providing confidence that the client is indeed " +"communicating with the intended server. If, in the future, the host key no " +"longer matches, the user must remove the client's saved version before a " +"connection can occur." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:92 +#, no-wrap +msgid "Always verify the integrity of a new SSH server" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:97 +msgid "" +"It is possible for an attacker to masquerade as an SSH server during the " +"initial contact since the local system does not know the difference between " +"the intended server and a false one set up by an attacker. To help prevent " +"this, verify the integrity of a new SSH server by contacting the server " +"administrator before connecting for the first time or in the event of a host " +"key mismatch." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:101 +msgid "" +"SSH is designed to work with almost any kind of public key algorithm or " +"encoding format. After an initial key exchange creates a hash value used for " +"exchanges and a shared secret value, the two systems immediately begin " +"calculating new keys and algorithms to protect authentication and future " +"data sent over the connection." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:103 +msgid "" +"After a certain amount of data has been transmitted using a given key and " +"algorithm (the exact amount depends on the SSH implementation, encryption " +"algorithm and configuration), another key exchange occurs, generating " +"another set of hash values and a new shared secret value. Even if an " +"attacker is able to determine the hash and shared secret value, this " +"information is only useful for a limited period of time." +msgstr "" + +#. type: Title ==== +#: ./pages/infrastructure-services/OpenSSH.adoc:105 +#, no-wrap +msgid "Authentication" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:108 +msgid "" +"indexterm:[SSH protocol,authentication] Once the transport layer has " +"constructed a secure tunnel to pass information between the two systems, the " +"server tells the client the different authentication methods supported, such " +"as using a private key-encoded signature or typing a password. The client " +"then tries to authenticate itself to the server using one of these supported " +"methods." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:110 +msgid "" +"SSH servers and clients can be configured to allow different types of " +"authentication, which gives each side the optimal amount of control. The " +"server can decide which encryption methods it supports based on its security " +"model, and the client can choose the order of authentication methods to " +"attempt from the available options." +msgstr "" + +#. type: Title ==== +#: ./pages/infrastructure-services/OpenSSH.adoc:112 +#, no-wrap +msgid "Channels" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:115 +msgid "" +"indexterm:[SSH protocol,layers,channels] After a successful authentication " +"over the SSH transport layer, multiple channels are opened via a technique " +"called _multiplexing_pass:attributes[{blank}]footnote:[A multiplexed " +"connection consists of several signals being sent over a shared, common " +"medium. With SSH, different channels are sent over a common secure " +"connection.]. Each of these channels handles communication for different " +"terminal sessions and for forwarded X11 sessions." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:117 +msgid "" +"Both clients and servers can create a new channel. Each channel is then " +"assigned a different number on each end of the connection. When the client " +"attempts to open a new channel, the clients sends the channel number along " +"with the request. This information is stored by the server and is used to " +"direct communication to that channel. This is done so that different types " +"of sessions do not affect one another and so that when a given session ends, " +"its channel can be closed without disrupting the primary SSH connection." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:119 +msgid "" +"Channels also support _flow-control_, which allows them to send and receive " +"data in an orderly fashion. In this way, data is not sent over the channel " +"until the client receives a message that the channel is open." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:121 +msgid "" +"The client and server negotiate the characteristics of each channel " +"automatically, depending on the type of service the client requests and the " +"way the user is connected to the network. This allows great flexibility in " +"handling different types of remote connections without having to change the " +"basic infrastructure of the protocol." +msgstr "" + +#. type: Title == +#: ./pages/infrastructure-services/OpenSSH.adoc:123 +#, no-wrap +msgid "Configuring OpenSSH" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:126 +msgid "" +"In order to perform tasks described in this section, you must have superuser " +"privileges. To obtain them, log in as `root` by typing:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:130 +#, no-wrap +msgid "[command]#su -#\n" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:133 +#, no-wrap +msgid "Configuration Files" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:138 +msgid "" +"indexterm:[SSH protocol,configuration files] There are two different sets of " +"configuration files: those for client programs (that is, [command]#ssh#, " +"[command]#scp#, and [command]#sftp#), and those for the server (the " +"[command]#sshd# daemon). indexterm:[SSH protocol,configuration " +"files,system-wide configuration files]indexterm:[SSH protocol,configuration " +"files,user-specific configuration files] System-wide SSH configuration " +"information is stored in the `/etc/ssh/` directory as described in " +"xref:table-ssh-configuration-configs-system[System-wide configuration " +"files]. User-specific SSH configuration information is stored in `~/.ssh/` " +"within the user's home directory as described in " +"xref:table-ssh-configuration-configs-user[User-specific configuration " +"files]." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:140 +#, no-wrap +msgid "System-wide configuration files" +msgstr "" + +#. type: Table +#: ./pages/infrastructure-services/OpenSSH.adoc:156 +#, no-wrap +msgid "" +"|File|Description\n" +"|`/etc/ssh/moduli`|Contains Diffie-Hellman groups used for the " +"\"`Diffie-Hellman group exchange`\" key exchange method, which is critical " +"for constructing a secure transport layer. When keys are exchanged at the " +"beginning of an SSH session, a shared, secret value is created which cannot " +"be determined by either party alone. If the file is not available, fixed " +"groups will be used. Other key exchange methods do not need this file.\n" +"|`/etc/ssh/ssh_config`|The default SSH client configuration file. Note that " +"it is overridden by `~/.ssh/config` if it exists.\n" +"|`/etc/ssh/sshd_config`|The configuration file for the [command]#sshd# " +"daemon.\n" +"|`/etc/ssh/ssh_host_ecdsa_key`|The ECDSA private key used by the " +"[command]#sshd# daemon.\n" +"|`/etc/ssh/ssh_host_ecdsa_key.pub`|The ECDSA public key used by the " +"[command]#sshd# daemon.\n" +"|`/etc/ssh/ssh_host_rsa_key`|The RSA private key used by the [command]#sshd# " +"daemon.\n" +"|`/etc/ssh/ssh_host_rsa_key.pub`|The RSA public key used by the " +"[command]#sshd# daemon.\n" +"|`/etc/ssh/ssh_host_ed25519_key`|The EdDSA private key used by the " +"[command]#sshd# daemon.\n" +"|`/etc/ssh/ssh_host_ed25519_key.pub`|The EdDSA public key used by the " +"[command]#sshd# daemon.\n" +"|`/etc/pam.d/sshd`|The PAM configuration file for the [command]#sshd# " +"daemon.\n" +"|`/etc/sysconfig/sshd`|Configuration file for the `sshd` service.\n" +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:159 +#, no-wrap +msgid "User-specific configuration files" +msgstr "" + +#. type: Table +#: ./pages/infrastructure-services/OpenSSH.adoc:172 +#, no-wrap +msgid "" +"|File|Description\n" +"|`~/.ssh/authorized_keys`|Holds a list of authorized public keys for " +"servers. When the client connects to a server, the server authenticates the " +"client by checking its signed public key stored within this file.\n" +"|`~/.ssh/id_ecdsa`|Contains the ECDSA private key of the user.\n" +"|`~/.ssh/id_ecdsa.pub`|The ECDSA public key of the user.\n" +"|`~/.ssh/id_rsa`|The RSA private key used by [command]#ssh#.\n" +"|`~/.ssh/id_rsa.pub`|The RSA public key used by [command]#ssh#.\n" +"|`~/.ssh/id_ed25519`|The EdDSA private key used by [command]#ssh#.\n" +"|`~/.ssh/id_ed25519.pub`|The EdDSA public key used by [command]#ssh#.\n" +"|`~/.ssh/known_hosts`|Contains host keys of SSH servers accessed by the " +"user. This file is very important for ensuring that the SSH client is " +"connecting to the correct SSH server.\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:175 +msgid "" +"For information concerning various directives that can be used in the SSH " +"configuration files, see the `ssh_config`(5) and `sshd_config`(5) manual " +"pages." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:177 +#, no-wrap +msgid "Starting an OpenSSH Server" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:179 +msgid "indexterm:[OpenSSH,server]" +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:180 +#: ./pages/infrastructure-services/OpenSSH.adoc:1024 +#, no-wrap +msgid "Make sure you have relevant packages installed" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:185 +msgid "" +"To run an OpenSSH server, you must have the [package]*openssh-server* " +"package installed. See " +"xref:package-management/DNF.adoc#sec-Installing[Installing Packages] for " +"more information on how to install new packages in {MAJOROSVER}." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:189 +msgid "" +"indexterm:[OpenSSH,server,starting] To start the [command]#sshd# daemon in " +"the current session, type the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:193 +#, no-wrap +msgid "~]#{nbsp}systemctl start sshd.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:196 +msgid "" +"indexterm:[OpenSSH,server,stopping] To stop the running [command]#sshd# " +"daemon in the current session, use the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:200 +#, no-wrap +msgid "~]#{nbsp}systemctl stop sshd.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:203 +msgid "" +"If you want the daemon to start automatically at the boot time, type as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:208 +#, no-wrap +msgid "" +"~]#{nbsp}systemctl enable sshd.service\n" +"ln -s '/usr/lib/systemd/system/sshd.service' " +"'/etc/systemd/system/multi-user.target.wants/sshd.service'\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:211 +#: ./pages/infrastructure-services/OpenSSH.adoc:252 +msgid "" +"See " +"xref:infrastructure-services/Services_and_Daemons.adoc#ch-Services_and_Daemons[Services " +"and Daemons] for more information on how to configure services in {MAJOROS}." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:213 +msgid "" +"Note that if you reinstall the system, a new set of identification keys will " +"be created. As a result, clients who had connected to the system with any of " +"the OpenSSH tools before the reinstall will see the following message:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:222 +#, no-wrap +msgid "" +"@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@\n" +"@ WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @\n" +"@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@\n" +"IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!\n" +"Someone could be eavesdropping on you right now (man-in-the-middle " +"attack)!\n" +"It is also possible that the RSA host key has just been changed.\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:225 +msgid "" +"To prevent this, you can backup the relevant files from the `/etc/ssh/` " +"directory (see xref:table-ssh-configuration-configs-system[System-wide " +"configuration files] for a complete list), and restore them whenever you " +"reinstall the system." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:227 +#, no-wrap +msgid "Requiring SSH for Remote Connections" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:230 +msgid "" +"indexterm:[SSH protocol,insecure protocols]indexterm:[SSH protocol,requiring " +"for remote login] For SSH to be truly effective, using insecure connection " +"protocols should be prohibited. Otherwise, a user's password may be " +"protected using SSH for one session, only to be captured later while logging " +"in using Telnet. Some services to disable include [command]#telnet#, " +"[command]#rsh#, [command]#rlogin#, and [command]#vsftpd#." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:232 +msgid "" +"These services are not installed by default in {MAJOROS}. If required, to " +"make sure these services are not running, type the following commands at a " +"shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:239 +#, no-wrap +msgid "" +"[command]#systemctl stop telnet.service#\n" +"[command]#systemctl stop rsh.service#\n" +"[command]#systemctl stop rlogin.service#\n" +"[command]#systemctl stop vsftpd.service#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:242 +msgid "To disable running these services at startup, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:249 +#, no-wrap +msgid "" +"[command]#systemctl disable telnet.service#\n" +"[command]#systemctl disable rsh.service#\n" +"[command]#systemctl disable rlogin.service#\n" +"[command]#systemctl disable vsftpd.service#\n" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:254 +#, no-wrap +msgid "Using Key-based Authentication" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:257 +msgid "" +"indexterm:[OpenSSH,using key-based authentication] To improve the system " +"security even further, generate SSH key pairs and then enforce key-based " +"authentication by disabling password authentication. To do so, create a " +"drop-in configuration file, for example " +"`/etc/ssh/sshd_config.d/01-local.conf`. Make sure it is lexicographically " +"before the `50-redhat.conf` file, providing Fedora defaults. In a text " +"editor such as [application]*vi* or [application]*nano* insert the " +"[option]`PasswordAuthentication` option as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:261 +#, no-wrap +msgid "PasswordAuthentication no\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:264 +msgid "" +"If you are working on a system other than a new default installation, check " +"that [command]#PubkeyAuthentication no# has *not* been set in neither " +"`/etc/ssh/sshd_config` nor any included file from drop-in directory. If " +"connected remotely, not using console or out-of-band access, testing the " +"key-based log in process before disabling password authentication is " +"advised." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:266 +msgid "" +"To be able to use [command]#ssh#, [command]#scp#, or [command]#sftp# to " +"connect to the server from a client machine, generate an authorization key " +"pair by following the steps below. Note that keys must be generated for each " +"user separately." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:268 +msgid "" +"{MAJOROSVER} uses SSH Protocol 2 and RSA keys by default (see " +"xref:s2-ssh-versions[Protocol Versions] for more information)." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:269 +#, no-wrap +msgid "Do not generate key pairs as root" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:274 +msgid "" +"If you complete the steps as `root`, only `root` will be able to use the " +"keys." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:277 +#, no-wrap +msgid "Backup your ~/.ssh/ directory" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:282 +msgid "" +"If you reinstall your system and want to keep previously generated key " +"pairs, backup the `~/.ssh/` directory. After reinstalling, copy it back to " +"your home directory. This process can be done for all users on your system, " +"including `root`." +msgstr "" + +#. type: Title ==== +#: ./pages/infrastructure-services/OpenSSH.adoc:286 +#, no-wrap +msgid "Generating Key Pairs" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:290 +msgid "" +"indexterm:[RSA keys,generating]indexterm:[OpenSSH,RSA keys,generating] To " +"generate an RSA key pair for version 2 of the SSH protocol, follow these " +"steps: indexterm:[OpenSSH,ssh-keygen,RSA]" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:292 +msgid "Generate an RSA key pair by typing the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:298 +#, no-wrap +msgid "" +"~]${nbsp}ssh-keygen -t rsa\n" +"Generating public/private rsa key pair.\n" +"Enter file in which to save the key (/home/USER/.ssh/id_rsa):\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:301 +msgid "" +"Press kbd:[Enter] to confirm the default location, `~/.ssh/id_rsa`, for the " +"newly created key." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:303 +#: ./pages/infrastructure-services/OpenSSH.adoc:364 +msgid "" +"Enter a passphrase, and confirm it by entering it again when prompted to do " +"so. For security reasons, avoid using the same password as you use to log in " +"to your account." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:305 +#: ./pages/infrastructure-services/OpenSSH.adoc:366 +msgid "After this, you will be presented with a message similar to this:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:323 +#, no-wrap +msgid "" +"Your identification has been saved in /home/USER/.ssh/id_rsa.\n" +"Your public key has been saved in /home/USER/.ssh/id_rsa.pub.\n" +"The key fingerprint is:\n" +"SHA256:y6f0DGlHe28YWotEypnhfk3WLYQ5TgaQwoSlOFwmmm0 " +"USER@penguin.example.com\n" +"The key's randomart image is:\n" +"+--[ RSA 2048]----+\n" +"| E. |\n" +"| . . |\n" +"| o . |\n" +"| . .|\n" +"| S . . |\n" +"| + o o ..|\n" +"| * * +oo|\n" +"| O +..=|\n" +"| o* o.|\n" +"+-----------------+\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:326 +#: ./pages/infrastructure-services/OpenSSH.adoc:387 +msgid "" +"By default, the permissions of the `~/.ssh/` directory are set to " +"`rwx------` or `700` expressed in octal notation. This is to ensure that " +"only the _USER_ can view the contents. If required, this can be confirmed " +"with the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:331 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#ls -ld ~/.ssh#\n" +"drwx------. 2 USER USER 54 Nov 25 16:56 /home/USER/.ssh/\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:334 +#: ./pages/infrastructure-services/OpenSSH.adoc:396 +msgid "" +"To copy the public key to a remote machine, issue a command in the following " +"format:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:338 +#, no-wrap +msgid " [command]#ssh-copy-id _user@hostname_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:341 +#: ./pages/infrastructure-services/OpenSSH.adoc:403 +msgid "" +"This will copy the most recently modified `~/.ssh/id*.pub` public key if it " +"is not yet installed. Alternatively, specify the public key's file name as " +"follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:344 +#, no-wrap +msgid "ssh-copy-id -i ~/.ssh/id_rsa.pub user@hostname\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:347 +msgid "" +"This will copy the content of `~/.ssh/id_rsa.pub` into the " +"`~/.ssh/authorized_keys` file on the machine to which you want to " +"connect. If the file already exists, the keys are appended to its end." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:351 +msgid "" +"indexterm:[ECDSA keys,generating]indexterm:[OpenSSH,ECDSA keys,generating] " +"To generate an ECDSA key pair for version 2 of the SSH protocol, follow " +"these steps: indexterm:[OpenSSH,ssh-keygen,ECDSA]" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:353 +msgid "Generate an ECDSA key pair by typing the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:359 +#, no-wrap +msgid "" +"~]${nbsp}ssh-keygen -t ecdsa\n" +"Generating public/private ecdsa key pair.\n" +"Enter file in which to save the key (/home/USER/.ssh/id_ecdsa):\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:362 +msgid "" +"Press kbd:[Enter] to confirm the default location, `~/.ssh/id_ecdsa`, for " +"the newly created key." +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:384 +#, no-wrap +msgid "" +"Your identification has been saved in /home/USER/.ssh/id_ecdsa.\n" +"Your public key has been saved in /home/USER/.ssh/id_ecdsa.pub.\n" +"The key fingerprint is:\n" +"SHA256:y6f0DGlHe28YWotEypnhfk3WLYQ5TgaQwoSlOFwmmm0 " +"USER@penguin.example.com\n" +"The key's randomart image is:\n" +"+--[ECDSA 256]---+\n" +"| .+ +o |\n" +"| . =.o |\n" +"| o o + ..|\n" +"| + + o +|\n" +"| S o o oE.|\n" +"| + oo+.|\n" +"| + o |\n" +"| |\n" +"| |\n" +"+-----------------+\n" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:393 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#ls -ld ~/.ssh#\n" +" ~]$ ls -ld ~/.ssh/\n" +"drwx------. 2 USER USER 54 Nov 25 16:56 /home/USER/.ssh/\n" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:400 +#, no-wrap +msgid "[command]#ssh-copy-id _USER@hostname_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:406 +#, no-wrap +msgid "ssh-copy-id -i ~/.ssh/id_ecdsa.pub USER@hostname\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:409 +msgid "" +"This will copy the content of `~/.ssh/id_ecdsa.pub` into the " +"`~/.ssh/authorized_keys` on the machine to which you want to connect. If the " +"file already exists, the keys are appended to its end." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:411 +msgid "" +"See xref:s3-ssh-configuration-keypairs-agent[Configuring ssh-agent] for " +"information on how to set up your system to remember the passphrase." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:412 +#, no-wrap +msgid "Never share your private key" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:417 +msgid "" +"The private key is for your personal use only, and it is important that you " +"never give it to anyone." +msgstr "" + +#. type: Title ==== +#: ./pages/infrastructure-services/OpenSSH.adoc:421 +#, no-wrap +msgid "Configuring ssh-agent" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:424 +msgid "" +"indexterm:[OpenSSH,ssh-agent]indexterm:[ssh-agent] To store your passphrase " +"so that you do not have to enter it each time you initiate a connection with " +"a remote machine, you can use the [command]#ssh-agent# authentication agent." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:426 +msgid "" +"To save your passphrase for a certain shell prompt, use the following " +"command:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:431 +#, no-wrap +msgid "" +"~]${nbsp}ssh-add\n" +"Enter passphrase for /home/USER/.ssh/id_rsa:\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:434 +msgid "" +"Note that when you log out, your passphrase will be forgotten. You must " +"execute the command each time you log in to a virtual console or a terminal " +"window." +msgstr "" + +#. type: Title == +#: ./pages/infrastructure-services/OpenSSH.adoc:436 +#, no-wrap +msgid "Using OpenSSH Certificate Authentication" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:439 +#, no-wrap +msgid "Introduction to SSH Certificates" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:442 +msgid "" +"Using public key cryptography for authentication requires copying the public " +"key from every client to every server that the client intends to log " +"into. This system does not scale well and can be an administrative " +"burden. Using a public key from a _certificate authority_ (*CA*) to " +"authenticate client certificates removes the need to copy keys between " +"multiple systems. While the X.509 Public Key Infrastructure Certificate " +"system provides a solution to this issue, there is a submission and " +"validation process, with associated fees, to go through in order to get a " +"certificate signed. As an alternative, OpenSSH supports the creation of " +"simple certificates and associated CA infrastructure." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:444 +msgid "" +"OpenSSH certificates contain a public key, identity information, and " +"validity constraints. They are signed with a standard SSH public key using " +"the [command]#ssh-keygen# utility. The format of the certificate is " +"described in " +"`/usr/share/doc/openssh-_version_pass:attributes[{blank}]/PROTOCOL.certkeys`." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:446 +msgid "" +"The [command]#ssh-keygen# utility supports two types of certificates: user " +"and host. User certificates authenticate users to servers, whereas host " +"certificates authenticate server hosts to users. For certificates to be used " +"for user or host authentication, `sshd` must be configured to trust the CA " +"public key." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:448 +#, no-wrap +msgid "Support for SSH Certificates" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:451 +msgid "" +"Support for certificate authentication of users and hosts using the new " +"OpenSSH certificate format was introduced in Fedora 13, in the " +"[package]*openssh-5.4p1-1.fc13* package. If required, to ensure the latest " +"OpenSSH package is installed, enter the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:456 +#, no-wrap +msgid "" +"~]# dnf install openssh\n" +"Last metadata expiration check performed 0:58:01 ago on Sun Sep 6 16:07:22 " +"2020.\n" +"Package openssh-7.1p1-1.fc23.x86_64 is already installed, skipping.\n" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:459 +#, no-wrap +msgid "Creating SSH CA Certificate Signing Keys" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:462 +msgid "" +"Two types of certificates are required, host certificates and user " +"certificates. It is considered better to have two separate keys for signing " +"the two certificates, for example `ca_user_key` and `ca_host_key`, however " +"it is possible to use just one CA key to sign both certificates. It is also " +"easier to follow the procedures if separate keys are used, so the examples " +"that follow will use separate keys." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:464 +msgid "" +"The basic format of the command to sign user's public key to create a user " +"certificate is as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:468 +#, no-wrap +msgid "ssh-keygen -s ca_user_key -I pass:quotes[_certificate_ID_] id_rsa.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:471 +msgid "" +"Where [option]`-s` indicates the private key used to sign the certificate, " +"[option]`-I` indicates an identity string, the _certificate_ID_, which can " +"be any alpha numeric value. It is stored as a zero terminated string in the " +"certificate. The _certificate_ID_ is logged whenever the certificate is used " +"for identification and it is also used when revoking a certificate. Having a " +"long value would make logs hard to read, therefore using the host name for " +"host certificates and the user name for user certificates is a safe choice." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:473 +msgid "" +"To sign a host's public key to create a host certificate, add the " +"[option]`-h` option:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:477 +#, no-wrap +msgid "" +"ssh-keygen -s ca_host_key -I pass:quotes[_certificate_ID_] -h " +"ssh_host_rsa_key.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:480 +msgid "" +"Host keys are generated on the system by default, to list the keys, enter a " +"command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:489 +#, no-wrap +msgid "" +"~]# ls -l /etc/ssh/ssh_host*\n" +"-rw-------. 1 root root 668 Jul 9 2014 /etc/ssh/ssh_host_dsa_key\n" +"-rw-r--r--. 1 root root 590 Jul 9 2014 /etc/ssh/ssh_host_dsa_key.pub\n" +"-rw-------. 1 root root 963 Jul 9 2014 /etc/ssh/ssh_host_key\n" +"-rw-r--r--. 1 root root 627 Jul 9 2014 /etc/ssh/ssh_host_key.pub\n" +"-rw-------. 1 root root 1671 Jul 9 2014 /etc/ssh/ssh_host_rsa_key\n" +"-rw-r--r--. 1 root root 382 Jul 9 2014 /etc/ssh/ssh_host_rsa_key.pub\n" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:495 +msgid "" +"It is recommended to create and store CA keys in a safe place just as with " +"any other private key. In these examples the `root` user will be used. In a " +"real production environment using an offline computer with an administrative " +"user account is recommended. For guidance on key lengths see " +"[citetitle]_link:++https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar1.pdf++[NIST " +"Special Publication 800-131A Revision 1]_." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:499 +#, no-wrap +msgid "Generating SSH CA Certificate Signing Keys" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:501 +msgid "" +"On the server designated to be the CA, generate two keys for use in signing " +"certificates. These are the keys that all other hosts need to trust. Choose " +"suitable names, for example `ca_user_key` and `ca_host_key`. To generate the " +"user certificate signing key, enter the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:524 +#, no-wrap +msgid "" +"~]# ssh-keygen -t rsa -f ~/.ssh/ca_user_key\n" +"Generating public/private rsa key pair.\n" +"Created directory '/root/.ssh'.\n" +"Enter passphrase (empty for no passphrase):\n" +"Enter same passphrase again:\n" +"Your identification has been saved in /root/.ssh/ca_user_key.\n" +"Your public key has been saved in /root/.ssh/ca_user_key.pub.\n" +"The key fingerprint is:\n" +"SHA256:y6f0DGlHe28YWotEypnhfk3WLYQ5TgaQwoSlOFwmmm0 " +"root@host_name.example.com\n" +"The key's randomart image is:\n" +"+--[ RSA 2048]----+\n" +"| .+. o|\n" +"| . o +.|\n" +"| o + . . o|\n" +"| o + . . ..|\n" +"| S . ... *|\n" +"| . . . .*.|\n" +"| = E .. |\n" +"| . o . |\n" +"| . |\n" +"+-----------------+\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:527 +msgid "Generate a host certificate signing key, `ca_host_key`, as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:549 +#, no-wrap +msgid "" +"~]# ssh-keygen -t rsa -f ~/.ssh/ca_host_key\n" +"Generating public/private rsa key pair.\n" +"Enter passphrase (empty for no passphrase):\n" +"Enter same passphrase again:\n" +"Your identification has been saved in /root/.ssh/ca_host_key.\n" +"Your public key has been saved in /root/.ssh/ca_host_key.pub.\n" +"The key fingerprint is:\n" +"SHA256:y6f0DGlHe28YWotEypnhfk3WLYQ5TgaQwoSlOFwmmm0 " +"root@host_name.example.com\n" +"The key's randomart image is:\n" +"+--[ RSA 2048]----+\n" +"| .. |\n" +"| . ....|\n" +"| . . o +oo|\n" +"| o . o *o|\n" +"| S = .|\n" +"| o. .|\n" +"| *.E. |\n" +"| +o= |\n" +"| .oo. |\n" +"+-----------------+\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:552 +msgid "If required, confirm the permissions are correct:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:566 +#, no-wrap +msgid "" +"~]# ls -la ~/.ssh\n" +"total 40\n" +"drwxrwxrwx. 2 root root 4096 May 22 13:18 .\n" +"dr-xr-x---. 3 root root 4096 May 8 08:34 ..\n" +"-rw-------. 1 root root 1743 May 22 13:15 ca_host_key\n" +"-rw-r--r--. 1 root root 420 May 22 13:15 ca_host_key.pub\n" +"-rw-------. 1 root root 1743 May 22 13:14 ca_user_key\n" +"-rw-r--r--. 1 root root 420 May 22 13:14 ca_user_key.pub\n" +"-rw-r--r--. 1 root root 854 May 8 05:55 known_hosts\n" +"-r--------. 1 root root 1671 May 6 17:13 ssh_host_rsa\n" +"-rw-r--r--. 1 root root 1370 May 7 14:30 ssh_host_rsa-cert.pub\n" +"-rw-------. 1 root root 420 May 6 17:13 ssh_host_rsa.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:569 +msgid "" +"Create the CA server's own host certificate by signing the server's host " +"public key together with an identification string such as the host name, the " +"CA server's _fully qualified domain name_ (*FQDN*) but without the trailing " +"`.`, and a validity period. The command takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:573 +#, no-wrap +msgid "" +"ssh-keygen -s ~/.ssh/ca_host_key -I pass:quotes[_certificate_ID_] -h -n " +"pass:quotes[_host_name.example.com_] -V pass:quotes[_-start:+end_] " +"/etc/ssh/ssh_host_rsa.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:576 +msgid "" +"The [option]`-n` option restricts this certificate to a specific host within " +"the domain. The [option]`-V` option is for adding a validity period; this is " +"highly recommend. Where the validity period is intended to be one year, " +"fifty two weeks, consider the need for time to change the certificates and " +"any holiday periods around the time of certificate expiry." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:578 +msgid "For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:583 +#, no-wrap +msgid "" +"~]# ssh-keygen -s ~/.ssh/ca_host_key -I host_name -h -n " +"host_name.example.com -V -1w:+54w5d /etc/ssh/ssh_host_rsa.pub\n" +"Enter passphrase:\n" +"Signed host key /root/.ssh/ssh_host_rsa-cert.pub: id \"host_name\" serial 0 " +"for host_name.example.com valid from 2020-05-15T13:52:29 to " +"2021-06-08T13:52:29\n" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:586 +#, no-wrap +msgid "Distributing and Trusting SSH CA Public Keys" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:589 +msgid "" +"Hosts that are to allow certificate authenticated log in from users must be " +"configured to trust the CA's public key that was used to sign the user " +"certificates, in order to authenticate user's certificates. In this example " +"that is the `ca_user_key.pub`." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:591 +msgid "" +"Publish the `ca_user_key.pub` key and download it to all hosts that are " +"required to allow remote users to log in. Alternately, copy the CA user " +"public key to all the hosts. In a production environment, consider copying " +"the public key to an administrator account first. The secure copy command " +"can be used to copy the public key to remote hosts. The command has the " +"following format:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:595 +#, no-wrap +msgid "" +"scp ~/.ssh/ca_user_key.pub " +"root@pass:quotes[_host_name_].example.com:/etc/ssh/\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:598 +msgid "" +"Where _host_name_ is the host name of a server the is required to " +"authenticate user's certificates presented during the login process. Ensure " +"you copy the public key not the private key. For example, as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:607 +#, no-wrap +msgid "" +"~]# scp ~/.ssh/ca_user_key.pub root@host_name.example.com:/etc/ssh/\n" +"The authenticity of host 'host_name.example.com (10.34.74.56)' can't be " +"established.\n" +"ECDSA key fingerprint is " +"SHA256:ZYEUaevOAEASvYjm58PiPdMebxhhlaTZBjTMr/N2I3c.\n" +"Are you sure you want to continue connecting (yes/no/[fingerprint])? yes\n" +"Warning: Permanently added 'host_name.example.com,10.34.74.56' (ECDSA) to " +"the list of known hosts.\n" +"root@host_name.example.com's password:\n" +"ca_user_key.pub 100% 420 0.4KB/s " +"00:00\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:610 +msgid "" +"For remote user authentication, CA keys can be marked as trusted per-user in " +"the `~/.ssh/authorized_keys` file using the [command]#cert-authority# " +"directive or for global use by means of the [command]#TrustedUserCAKeys# " +"directive in the `/etc/ssh/sshd_config` file. For remote host " +"authentication, CA keys can be marked as trusted globally in the " +"`/etc/ssh/known_hosts` file or per-user in the `~/.ssh/ssh_known_hosts` " +"file." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:612 +#, no-wrap +msgid "Trusting the User Signing Key" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:614 +msgid "" +"For user certificates which have one or more principles listed, and where " +"the setting is to have global effect, edit the `/etc/ssh/sshd_config` file " +"as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:617 +#, no-wrap +msgid "TrustedUserCAKeys /etc/ssh/ca_user_key.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:620 +#: ./pages/infrastructure-services/OpenSSH.adoc:748 +msgid "Restart `sshd` to make the changes take effect:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:623 +#: ./pages/infrastructure-services/OpenSSH.adoc:751 +#, no-wrap +msgid "~]#{nbsp}systemctl restart sshd.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:626 +msgid "" +"To avoid being presented with the warning about an unknown host, a user's " +"system must trust the CA's public key that was used to sign the host " +"certificates. In this example that is `ca_host_key.pub`." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:628 +#, no-wrap +msgid "Trusting the Host Signing Key" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:630 +msgid "" +"Extract the contents of the public key used to sign the host " +"certificate. For example, on the CA:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:635 +#, no-wrap +msgid "" +"cat ~/.ssh/ca_host_key.pub\n" +"ssh-rsa pass:quotes[_AAAAB5Wm._]== root@ca-server.example.com\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:638 +msgid "" +"To configure client systems to trust servers' signed host certificates, add " +"the contents of the `ca_host_key.pub` into the global `known_hosts` " +"file. This will automatically check a server's host advertised certificate " +"against the CA public key for all users every time a new machine is " +"connected to in the domain `*.example.com`. Login as `root` and configure " +"the `/etc/ssh/ssh_known_hosts` file, as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:644 +#, no-wrap +msgid "" +"~]# vi /etc/ssh/ssh_known_hosts\n" +"# A CA key, accepted for any host in *.example.com\n" +"@cert-authority *.example.com ssh-rsa pass:quotes[_AAAAB5Wm._]\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:647 +msgid "" +"Where `ssh-rsa _AAAAB5Wm._pass:attributes[{blank}]` is the contents of " +"`ca_host_key.pub`. The above configures the system to trust the CA servers " +"host public key. This enables global authentication of the certificates " +"presented by hosts to remote users." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:649 +#, no-wrap +msgid "Creating SSH Certificates" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:652 +msgid "" +"A certificate is a signed public key. The user's and host's public keys must " +"be copied to the CA server for signing by the CA server's private key." +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:657 +msgid "" +"Copying many keys to the CA to be signed can create confusion if they are " +"not uniquely named. If the default name is always used then the latest key " +"to be copied will overwrite the previously copied key, which may be an " +"acceptable method for one administrator. In the example below the default " +"name is used. In a production environment, consider using easily " +"recognizable names. It is recommend to have a designated directory on the CA " +"server owned by an administrative user for the keys to be copied " +"into. Copying these keys to the `root` user's `/etc/ssh/` directory is not " +"recommend. In the examples below an account named `admin` with a directory " +"named `keys/` will be used." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:661 +msgid "" +"Create an administrator account, in this example `admin`, and a directory to " +"receive the user's keys. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:665 +#, no-wrap +msgid "~]$ [command]#mkdir keys#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:668 +msgid "Set the permissions to allow keys to be copied in:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:675 +#, no-wrap +msgid "" +"~]$ chmod o+w keys\n" +"ls -la keys\n" +"total 8\n" +"drwxrwxrwx. 2 admin admin 4096 May 22 16:17 .\n" +"drwx------. 3 admin admin 4096 May 22 16:17 ..\n" +msgstr "" + +#. type: Title ==== +#: ./pages/infrastructure-services/OpenSSH.adoc:678 +#, no-wrap +msgid "Creating SSH Certificates to Authenticate Hosts" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:681 +msgid "The command to sign a host certificate has the following format:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:685 +#, no-wrap +msgid "" +"ssh-keygen -s ca_host_key -I pass:quotes[_host_name_] -h " +"ssh_host_rsa_key.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:688 +msgid "The host certificate will named `ssh_host_rsa_key-cert.pub`." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:690 +#, no-wrap +msgid "Generating a Host Certificate" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:692 +msgid "" +"To authenticate a host to a user, a public key must be generated on the " +"host, passed to the CA server, signed by the CA, and then passed back to be " +"stored on the host to present to a user attempting to log into the host." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:694 +msgid "" +"Host keys are generated automatically on the system. To list them enter the " +"following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:703 +#, no-wrap +msgid "" +"~]# ls -l /etc/ssh/ssh_host*\n" +"-rw-------. 1 root root 668 May 6 14:38 /etc/ssh/ssh_host_dsa_key\n" +"-rw-r--r--. 1 root root 590 May 6 14:38 /etc/ssh/ssh_host_dsa_key.pub\n" +"-rw-------. 1 root root 963 May 6 14:38 /etc/ssh/ssh_host_key\n" +"-rw-r--r--. 1 root root 627 May 6 14:38 /etc/ssh/ssh_host_key.pub\n" +"-rw-------. 1 root root 1679 May 6 14:38 /etc/ssh/ssh_host_rsa_key\n" +"-rw-r--r--. 1 root root 382 May 6 14:38 /etc/ssh/ssh_host_rsa_key.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:706 +msgid "" +"Copy the chosen public key to the server designated as the CA. For example, " +"from the host:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:715 +#, no-wrap +msgid "" +"~]# scp /etc/ssh/ssh_host_rsa_key.pub " +"admin@ca-server.example.com:~/keys/ssh_host_rsa_key.pub\n" +"The authenticity of host 'ca-server.example.com (10.34.74.58)' can't be " +"established.\n" +"ECDSA key fingerprint is " +"SHA256:ZYEUaevOAEASvYjm58PiPdMebxhhlaTZBjTMr/N2I3c.\n" +"Are you sure you want to continue connecting (yes/no/[fingerprint])? yes\n" +"Warning: Permanently added 'ca-server.example.com,10.34.74.58' (RSA) to the " +"list of known hosts.\n" +"admin@ca-server.example.com's password:\n" +"ssh_host_rsa_key.pub 100% 382 0.4KB/s " +"00:00\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:718 +msgid "Alternately, from the CA:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:721 +#, no-wrap +msgid "" +"~]$ scp root@host_name.example.com:/etc/ssh/ssh_host_rsa_key.pub " +"~/keys/ssh_host_rsa_key.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:724 +msgid "On the CA server, sign the host's public key. For example, as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:729 +#, no-wrap +msgid "" +"~]# ssh-keygen -s ~/.ssh/ca_host_key -I host_name -h -n " +"host_name.example.com -V -1d:+54w /home/admin/keys/ssh_host_rsa_key.pub\n" +"Enter passphrase:\n" +"Signed host key /home/admin/keys/ssh_host_rsa_key-cert.pub: id \"host_name\" " +"serial 0 for host_name.example.com valid from 2020-05-26T12:21:54 to " +"2021-06-08T12:21:54\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:732 +msgid "Where _host_name_ is the host name of the system requiring the certificate." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:734 +msgid "Copy the certificate to the host. For example, from the CA:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:739 +#, no-wrap +msgid "" +"~]# scp /home/admin/keys/ssh_host_rsa_key-cert.pub " +"root@host_name.example.com:/etc/ssh/\n" +"root@host_name.example.com's password:\n" +"ssh_host_rsa_key-cert.pub 100% 1384 1.5KB/s " +"00:00\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:742 +msgid "" +"Configure the host to present the certificate to a user's system when a user " +"initiates the login process. As `root`, edit the `/etc/ssh/sshd_config` file " +"as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:745 +#, no-wrap +msgid "HostCertificate /etc/ssh/ssh_host_rsa_key-cert.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:754 +msgid "" +"On user's systems, remove keys belonging to hosts from the " +"`~/.ssh/known_hosts` file if the user has previously logged into the host " +"configured above. When a user logs into the host they should no longer be " +"presented with the warning about the hosts authenticity." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:756 +msgid "" +"To test the host certificate, on a client system, ensure the client has set " +"up the global `/etc/ssh/known_hosts` file, as described in " +"xref:proc-Trusting_the_Host_Signing_Key[Trusting the Host Signing Key], and " +"that the server's public key is not in the `~/.ssh/known_hosts` file. Then " +"attempt to log into the server over SSH as a remote user. You should not see " +"a warning about the authenticity of the host. If required, add the " +"[option]`-v` option to the SSH command to see logging information." +msgstr "" + +#. type: Title ==== +#: ./pages/infrastructure-services/OpenSSH.adoc:758 +#, no-wrap +msgid "Creating SSH Certificates for Authenticating Users" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:761 +msgid "To sign a user's certificate, use a command in the following format:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:765 +#, no-wrap +msgid "" +"ssh-keygen -s ca_user_key -I pass:quotes[_user_name_] -n " +"pass:quotes[_user_name_] -V pass:quotes[_-start:+end_] id_rsa.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:768 +msgid "The resulting certificate will be named `id_rsa-cert.pub`." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:770 +msgid "" +"The default behavior of OpenSSH is that a user is allowed to log in as a " +"remote user if one of the principals specified in the certificate matches " +"the remote user's name. This can be adjusted in the following ways:" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:772 +msgid "" +"Add more user's names to the certificate during the signing process using " +"the [option]`-n` option:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:776 +#, no-wrap +msgid "-n \"name1[,name2,...]\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:779 +msgid "" +"On the user's system, add the public key of the CA in the " +"`~/.ssh/authorized_keys` file using the [command]#cert-authority# directive " +"and list the principals names as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:785 +#, no-wrap +msgid "" +"~]# vi ~/.ssh/authorized_keys\n" +"# A CA key, accepted for any host in *.example.com\n" +"@cert-authority principals=\"name1,name2\" *.example.com ssh-rsa " +"pass:quotes[_AAAAB5Wm._]\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:788 +msgid "" +"On the server, create an `AuthorizedPrincipalsFile` file, either per user or " +"globally, and add the principles' names to the file for those users allowed " +"to log in. Then in the `/etc/ssh/sshd_config` file, specify the file using " +"the [command]#AuthorizedPrincipalsFile# directive." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:790 +#, no-wrap +msgid "Generating a User Certificate" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:792 +msgid "" +"To authenticate a user to a remote host, a public key must be generated by " +"the user, passed to the CA server, signed by the CA, and then passed back to " +"be stored by the user for use when logging in to a host." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:794 +msgid "" +"On client systems, login as the user who requires the certificate. Check for " +"available keys as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:798 +#, no-wrap +msgid "~]$ [command]#ls -l ~/.ssh/#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:801 +msgid "" +"If no suitable public key exists, generate one and set the directory " +"permissions if the directory is not the default directory. For example, " +"enter the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:825 +#, no-wrap +msgid "" +"~]$ ssh-keygen -t rsa\n" +"Generating public/private rsa key pair.\n" +"Enter file in which to save the key (/home/user1/.ssh/id_rsa):\n" +"Created directory '/home/user1/.ssh'.\n" +"Enter passphrase (empty for no passphrase):\n" +"Enter same passphrase again:\n" +"Your identification has been saved in /home/user1/.ssh/id_rsa.\n" +"Your public key has been saved in /home/user1/.ssh/id_rsa.pub.\n" +"The key fingerprint is:\n" +"SHA256:y6f0DGlHe28YWotEypnhfk3WLYQ5TgaQwoSlOFwmmm0 user1@host1.example.com\n" +"The key's randomart image is:\n" +"+--[ RSA 2048]----+\n" +"| oo++. |\n" +"| o.o.o. |\n" +"| .o o . |\n" +"| oo . o |\n" +"| . oo.S |\n" +"| o=.. |\n" +"| .Eo+ |\n" +"| .= |\n" +"| .. |\n" +"+-----------------+\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:828 +msgid "" +"By default the directory permissions for a user's keys are `drwx------.`, or " +"octal 0700. If required, confirm the permissions are correct:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:836 +#, no-wrap +msgid "" +"~]$ ls -la ~/.ssh\n" +"total 16\n" +"drwx------. 2 user1 user1 4096 May 7 12:37 .\n" +"drwx------. 3 user1 user1 4096 May 7 12:37 ..\n" +"-rw-------. 1 user1 user1 1679 May 7 12:37 id_rsa\n" +"-rw-r--r--. 1 user1 user1 421 May 7 12:37 id_rsa.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:839 +msgid "" +"See xref:s2-ssh-configuration-keypairs[Using Key-based Authentication] for " +"more examples of key generation and for instructions on setting the correct " +"directory permissions." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:841 +msgid "" +"The chosen public key must be copied to the server designated as the CA, in " +"order to be signed. The secure copy command can be used to do this, the " +"command has the following format:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:845 +#, no-wrap +msgid "" +"scp ~/.ssh/id_pass:quotes[_protocol_].pub " +"pass:quotes[_admin_]@ca_server.example.com:~/keys/\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:848 +msgid "" +"Where _protocol_ is the part of the file name indicating the protocol used " +"to generate the key, for example `rsa`, _admin_ is an account on the CA " +"server, and _/keys/_ is a directory setup to receive the keys to be signed." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:850 +msgid "Copy the chosen public key to the server designated as the CA. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:855 +#, no-wrap +msgid "" +"~]$ scp ~/.ssh/id_rsa.pub admin@ca-server.example.com:~/keys/\n" +"admin@ca-server.example.com's password:\n" +"id_rsa.pub 100% 421 0.4KB/s 00:00\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:858 +msgid "" +"If you have configured the client system to trust the host signing key as " +"described in xref:proc-Trusting_the_Host_Signing_Key[Trusting the Host " +"Signing Key] then you should not see a warning about the authenticity of the " +"remote host." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:860 +msgid "On the CA server, sign the user's public key. For example, as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:865 +#, no-wrap +msgid "" +"~]# ssh-keygen -s ~/.ssh/ca_user_key -I user1 -n user1 -V -1d:+54w " +"/home/admin/keys/id_rsa.pub\n" +"Enter passphrase:\n" +"Signed user key /home/admin/keys/id_rsa-cert.pub: id \"user1\" serial 0 for " +"host_name.example.com valid from 2020-05-21T16:43:17 to " +"2021-06-03T16:43:17\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:868 +msgid "" +"Copy the resulting certificate to the user's `~/.ssh/` directory on their " +"system. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:873 +#, no-wrap +msgid "" +"~]# scp /home/admin/keys/id_rsa-cert.pub " +"user1@host_name.example.com:~/.ssh/\n" +"user1@host_name.example.com's password:\n" +"id_rsa-cert.pub 100% 1498 1.5KB/s 00:00\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:876 +msgid "" +"If using the standard file names and location then no further configuration " +"is required as the SSH daemon will search for user certificates ending in " +"`-cert.pub` and use them automatically if it finds them. Note that the " +"default location and file names for for SSH version 2 keys are: " +"`~/.ssh/id_dsa`, `~/.ssh/id_ecdsa` and `~/.ssh/id_rsa` as explained in the " +"`ssh_config(5)` manual page. If you use these locations and naming " +"conventions then there is no need for editing the configuration files to " +"enable `sshd` to present the certificate. They will be used automatically " +"when logging in to a remote system. In this is the case then skip to step 6." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:878 +msgid "" +"If required to use a non-default directory or file naming convention, then " +"as `root`, add the following line to the `/etc/ssh/ssh_config` or " +"`~/.ssh/config` files:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:882 +#, no-wrap +msgid "IdentityFile pass:quotes[_~/path/key_file_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:886 +msgid "" +"Note that this must be the private key name, do not had `.pub` or " +"`-cert.pub`. Ensure the file permission are correct. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:894 +#, no-wrap +msgid "" +"~]$ [command]#ls -la ~/.ssh/config#\n" +"-rw-rw-r--. 1 user1 user1 36 May 27 21:49 /home/user1/.ssh/config\n" +"[command]#chmod 700 ~/.ssh/config#\n" +"~]$ [command]#ls -la ~/.ssh/config#\n" +"-rwx------. 1 user1 user1 36 May 27 21:49 /home/user1/.ssh/config\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:897 +msgid "" +"This will enable the user of this system to be authenticated by a user " +"certificate when logging into a remote system configured to trust the CA " +"user certificate signing key." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:899 +msgid "" +"To test the user certificate, attempt to log into a server over SSH from the " +"user's account. You should do this as the user listed as a principle in the " +"certificate, if any are specified. You should not be prompted for a " +"password. If required, add the [option]`-v` option to the SSH command to see " +"logging information." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:901 +#, no-wrap +msgid "Signing an SSH Certificate Using a PKCS#11 Token" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:904 +msgid "" +"It is possible to sign a host key using a CA key stored in a PKCS#11 token " +"by providing the token library using the [option]`-D` and identifying the CA " +"key by providing its public half as an argument to the [option]`-s` option:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:908 +#, no-wrap +msgid "" +"ssh-keygen -s ca_host_key.pub -D libpkcs11.so -I " +"pass:quotes[_certificate_ID_] host_key.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:911 +msgid "" +"In all cases, _certificate_ID_ is a \"`key identifier`\" that is logged by " +"the server when the certificate is used for authentication." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:913 +msgid "" +"Certificates may be configured to be valid only for a set of users or host " +"names, the principals. By default, generated certificates are valid for all " +"users or hosts. To generate a certificate for a specified set of principals, " +"use a comma separated list with the [option]`-n` option as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:917 +#, no-wrap +msgid "" +"ssh-keygen -s ca_user_key.pub -D libpkcs11.so -I " +"pass:quotes[_certificate_ID_] -n pass:quotes[_user1,user2_] id_rsa.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:920 +msgid "and for hosts:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:924 +#, no-wrap +msgid "" +"ssh-keygen -s ca_host_key.pub -D libpkcs11.so -I " +"pass:quotes[_certificate_ID_] -h -n host.domain ssh_host_rsa_key.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:930 +msgid "" +"Additional limitations on the validity and use of user certificates may be " +"specified through certificate options. A certificate option may disable " +"features of the SSH session, may be valid only when presented from " +"particular source addresses or may force the use of a specific command. For " +"a list of valid certificate options, see the `ssh-keygen(1)` manual page for " +"the [option]`-O` option." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:933 +msgid "" +"Certificates may be defined to be valid for a specific lifetime. The " +"[option]`-V` option allows specifying a certificates start and end " +"times. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:937 +#, no-wrap +msgid "" +"ssh-keygen -s ca_user_key -I pass:quotes[_certificate_ID_] -V \"-1w:+54w5d\" " +"id_rsa.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:941 +msgid "" +"A certificate that is presented at a time outside this range will not be " +"considered valid. By default, certificates are valid indefinitely starting " +"from UNIX Epoch." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:943 +#, no-wrap +msgid "Viewing an SSH CA Certificate" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:946 +msgid "" +"To view a certificate, use the [option]`-L` to list the contents. For " +"example, for a user's certificate:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:965 +#, no-wrap +msgid "" +"~]$ ssh-keygen -L -f ~/.ssh/id_rsa-cert.pub\n" +"/home/user1/.ssh/id_rsa-cert.pub:\n" +" Type: ssh-rsa-cert-v01@openssh.com user certificate\n" +" Public key: RSA-CERT " +"SHA256:y6f0DGlHe28YWotEypnhfk3WLYQ5TgaQwoSlOFwmmm0\n" +" Signing CA: RSA SHA256:y6f0DGlHe28YWotEypnhfk3WLYQ5TgaQwoSlOFwmmm0\n" +" Key ID: \"user1\"\n" +" Serial: 0\n" +" Valid: from 2020-05-27T00:09:16 to 2021-06-09T00:09:16\n" +" Principals:\n" +" user1\n" +" Critical Options: (none)\n" +" Extensions:\n" +" permit-X11-forwarding\n" +" permit-agent-forwarding\n" +" permit-port-forwarding\n" +" permit-pty\n" +" permit-user-rc\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:968 +msgid "To view a host certificate:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:982 +#, no-wrap +msgid "" +"~]# ssh-keygen -L -f /etc/ssh/ssh_host_rsa_key-cert.pub\n" +"/etc/ssh/ssh_host_rsa_key-cert.pub:\n" +" Type: ssh-rsa-cert-v01@openssh.com host certificate\n" +" Public key: RSA-CERT " +"SHA256:y6f0DGlHe28YWotEypnhfk3WLYQ5TgaQwoSlOFwmmm0\n" +" Signing CA: RSA SHA256:y6f0DGlHe28YWotEypnhfk3WLYQ5TgaQwoSlOFwmmm0\n" +" Key ID: \"host_name\"\n" +" Serial: 0\n" +" Valid: from 2020-05-26T17:19:01 to 2021-06-08T17:19:01\n" +" Principals:\n" +" host_name.example.com\n" +" Critical Options: (none)\n" +" Extensions: (none)\n" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:985 +#, no-wrap +msgid "Revoking an SSH CA Certificate" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:988 +msgid "" +"If a certificate is stolen, it should be revoked. Although OpenSSH does not " +"provide a mechanism to distribute the revocation list it is still easier to " +"create the revocation list and distribute it by other means then to change " +"the CA keys and all host and user certificates previously created and " +"distributed." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:990 +msgid "" +"Keys can be revoked by adding them to the `revoked_keys` file and specifying " +"the file name in the `sshd_config` file as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:993 +#, no-wrap +msgid "RevokedKeys /etc/ssh/revoked_keys\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:996 +msgid "" +"Note that if this file is not readable, then public key authentication will " +"be refused for all users." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:998 +msgid "A new key revocation list can be generated as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1001 +#, no-wrap +msgid "~]$ ssh-keygen -kf /etc/ssh/revoked_keys -z 1 ~/.ssh/id_rsa.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1004 +msgid "To add lines to the list, use the [option]`-u` option to update the list:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1008 +#, no-wrap +msgid "" +"ssh-keygen -ukf /etc/ssh/revoked_keys -z pass:quotes[_integer_] " +"~/.ssh/id_rsa.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1011 +msgid "where _integer_ is the line number." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1013 +msgid "" +"To test if a key has been revoked, query the revocation list for the " +"presence of the key. Use a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1016 +#, no-wrap +msgid "ssh-keygen -Qf /etc/ssh/revoked_keys ~/.ssh/id_rsa.pub\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1019 +msgid "" +"A user can revoke a CA certificate by changing the [command]#cert-authority# " +"directive to [command]#revoke# in the `known_hosts` file." +msgstr "" + +#. type: Title == +#: ./pages/infrastructure-services/OpenSSH.adoc:1021 +#, no-wrap +msgid "OpenSSH Clients" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1023 +msgid "indexterm:[OpenSSH,client]" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:1029 +msgid "" +"To connect to an OpenSSH server from a client machine, you must have the " +"[package]*openssh-clients* package installed. See " +"xref:package-management/DNF.adoc#sec-Installing[Installing Packages] for " +"more information on how to install new packages in {MAJOROSVER}." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:1033 +#, no-wrap +msgid "Using the ssh Utility" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1036 +msgid "" +"indexterm:[ssh,OpenSSH]indexterm:[OpenSSH,client,ssh] The [command]#ssh# " +"utility allows you to log in to a remote machine and execute commands " +"there. It is a secure replacement for the [command]#rlogin#, [command]#rsh#, " +"and [command]#telnet# programs." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1038 +msgid "" +"Similarly to the [command]#telnet# command, log in to a remote machine by " +"using the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1042 +#, no-wrap +msgid "[command]#ssh# _hostname_\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1045 +msgid "" +"For example, to log in to a remote machine named `penguin.example.com`, type " +"the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1049 +#, no-wrap +msgid "~]${nbsp}pass:attributes[{blank}][command]#ssh penguin.example.com#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1052 +msgid "" +"This will log you in with the same user name you are using on the local " +"machine. If you want to specify a different user name, use a command in the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1056 +#, no-wrap +msgid "" +"[command]#ssh# " +"_username_pass:attributes[{blank}]@pass:attributes[{blank}]_hostname_\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1059 +msgid "For example, to log in to `penguin.example.com` as `USER`, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1063 +#, no-wrap +msgid "~]${nbsp}pass:attributes[{blank}][command]#ssh USER@penguin.example.com#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1066 +msgid "" +"The first time you initiate a connection, you will be presented with a " +"message similar to this:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1072 +#, no-wrap +msgid "" +"The authenticity of host 'penguin.example.com' can't be established.\n" +"ECDSA key fingerprint is " +"SHA256:ZYEUaevOAEASvYjm58PiPdMebxhhlaTZBjTMr/N2I3c.\n" +"Are you sure you want to continue connecting (yes/no/[fingerprint])?\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1075 +msgid "" +"Users should always check if the fingerprint is correct before answering the " +"question in this dialog. The user can ask the administrator of the server to " +"confirm the key is correct. This should be done in a secure and previously " +"agreed way. If the user has access to the server's host keys, the " +"fingerprint can be checked by using the [command]#ssh-keygen# command as " +"follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1080 +#, no-wrap +msgid "" +"~]#{nbsp}ssh-keygen -l -f /etc/ssh/ssh_host_ecdsa_key.pub\n" +"256 SHA256:ZYEUaevOAEASvYjm58PiPdMebxhhlaTZBjTMr/N2I3c no comment (ECDSA)\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1083 +msgid "" +"Type `yes` to accept the key and confirm the connection. You will see a " +"notice that the server has been added to the list of known hosts, and a " +"prompt asking for your password:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1088 +#, no-wrap +msgid "" +"Warning: Permanently added 'penguin.example.com' (ECDSA) to the list of " +"known hosts.\n" +"USER@penguin.example.com's password:\n" +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:1090 +#, no-wrap +msgid "Updating the host key of an SSH server" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:1095 +msgid "" +"If the SSH server's host key changes, the client notifies the user that the " +"connection cannot proceed until the server's host key is deleted from the " +"`~/.ssh/known_hosts` file. Before doing this, however, contact the system " +"administrator of the SSH server to verify the server is not compromised." +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:1097 +msgid "" +"To remove a key from the `~/.ssh/known_hosts` file, issue a command as " +"follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1104 +#, no-wrap +msgid "" +"~]#{nbsp}ssh-keygen -R pass:quotes[_penguin.example.com_]\n" +"# Host penguin.example.com found: line 15 type ECDSA\n" +"/home/USER/.ssh/known_hosts updated.\n" +"Original contents retained as /home/USER/.ssh/known_hosts.old\n" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:1109 +msgid "" +"After entering the password, you will be provided with a shell prompt for " +"the remote machine." +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:1111 +msgid "" +"Alternatively, the [command]#ssh# program can be used to execute a command " +"on the remote machine without logging in to a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1115 +#, no-wrap +msgid "" +"[command]#ssh# " +"_username_pass:attributes[{blank}]@pass:attributes[{blank}]_hostname_ " +"_command_\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1118 +msgid "" +"For example, the `/etc/redhat-release` file provides information about the " +"{MAJOROS} version. To view the contents of this file on " +"`penguin.example.com`, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1124 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#ssh USER@penguin.example.com cat " +"/etc/redhat-release#\n" +"USER@penguin.example.com's password:\n" +"Fedora release 31 (Thirty One)\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1127 +msgid "" +"After you enter the correct password, the user name will be displayed, and " +"you will return to your local shell prompt." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:1129 +#, no-wrap +msgid "Using the [command]#scp# Utility" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1132 +msgid "" +"indexterm:[scp,OpenSSH]indexterm:[OpenSSH,client,scp]indexterm:[rcp] " +"[command]#scp# can be used to transfer files between machines over a secure, " +"encrypted connection. In its design, it is very similar to [command]#rcp#." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1134 +msgid "" +"To transfer a local file to a remote system, use a command in the following " +"form:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1138 +#, no-wrap +msgid "" +"[command]#scp _localfile_ " +"_username_pass:attributes[{blank}]@pass:attributes[{blank}]_hostname_:pass:attributes[{blank}]_remotefile_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1141 +msgid "" +"For example, if you want to transfer `taglist.vim` to a remote machine named " +"`penguin.example.com`, type the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1147 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#scp taglist.vim " +"USER@penguin.example.com:.vim/plugin/taglist.vim#\n" +"USER@penguin.example.com's password:\n" +"taglist.vim 100% 144KB 144.5KB/s " +"00:00\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1150 +msgid "" +"Multiple files can be specified at once. To transfer the contents of " +"`.vim/plugin/` to the same directory on the remote machine " +"`penguin.example.com`, type the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1158 +#, no-wrap +msgid "" +"~]${nbsp}scp .vim/plugin/* USER@penguin.example.com:.vim/plugin/\n" +"USER@penguin.example.com's password:\n" +"closetag.vim 100% 13KB 12.6KB/s " +"00:00\n" +"snippetsEmu.vim 100% 33KB 33.1KB/s " +"00:00\n" +"taglist.vim 100% 144KB 144.5KB/s " +"00:00\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1161 +msgid "To transfer a remote file to the local system, use the following syntax:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1165 +#, no-wrap +msgid "" +"[command]#scp " +"_username_pass:attributes[{blank}]@pass:attributes[{blank}]_hostname_:pass:attributes[{blank}]_remotefile_ " +"_localfile_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1168 +msgid "" +"For instance, to download the `.vimrc` configuration file from the remote " +"machine, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1174 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#scp " +"USER@penguin.example.com:.vimrc .vimrc#\n" +"USER@penguin.example.com's password:\n" +".vimrc 100% 2233 2.2KB/s " +"00:00\n" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:1180 +msgid "" +"The SCP protocol is not well designed and can cause unexpected results. In " +"the past it was source of several CVEs where malicious server could override " +"files in local filesystem when downloading files. It is recommended to use " +"SFTP when possible. See the next section for more information." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:1183 +#, no-wrap +msgid "Using the [command]#sftp# Utility" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1186 +msgid "" +"indexterm:[sftp,OpenSSH]indexterm:[OpenSSH,client,sftp] The [command]#sftp# " +"utility can be used to open a secure, interactive SFTP session. In its " +"design, it is similar to [command]#ftp# except that it uses a secure, " +"encrypted connection." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1188 +msgid "To connect to a remote system, use a command in the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1192 +#, no-wrap +msgid "" +"[command]#sftp " +"_username_pass:attributes[{blank}]@pass:attributes[{blank}]_hostname_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1195 +#: ./pages/infrastructure-services/OpenSSH.adoc:1238 +msgid "" +"For example, to log in to a remote machine named `penguin.example.com` with " +"`USER` as a user name, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1202 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#sftp USER@penguin.example.com#\n" +"USER@penguin.example.com's password:\n" +"Connected to penguin.example.com.\n" +"sftp>\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1205 +msgid "" +"After you enter the correct password, you will be presented with a " +"prompt. The [command]#sftp# utility accepts a set of commands similar to " +"those used by [command]#ftp# (see xref:OpenSSH.adoc#table-ssh-clients-sftp[A " +"selection of available sftp commands])." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:1207 +#, no-wrap +msgid "A selection of available sftp commands" +msgstr "" + +#. type: Table +#: ./pages/infrastructure-services/OpenSSH.adoc:1218 +#, no-wrap +msgid "" +"|Command|Description\n" +"|[command]#ls# " +"[pass:attributes[{blank}]_directory_pass:attributes[{blank}]]|List the " +"content of a remote _directory_. If none is supplied, a current working " +"directory is used by default.\n" +"|[command]#cd# _directory_|Change the remote working directory to " +"_directory_.\n" +"|[command]#mkdir# _directory_|Create a remote _directory_.\n" +"|[command]#rmdir# _directory_|Remove a remote _directory_.\n" +"|[command]#put# _localfile_ " +"[pass:attributes[{blank}]_remotefile_pass:attributes[{blank}]]|Transfer " +"_localfile_ to a remote machine.\n" +"|[command]#get# _remotefile_ " +"[pass:attributes[{blank}]_localfile_pass:attributes[{blank}]]|Transfer " +"_remotefile_ from a remote machine.\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1221 +msgid "For a complete list of available commands, see the `sftp`(1) manual page." +msgstr "" + +#. type: Title == +#: ./pages/infrastructure-services/OpenSSH.adoc:1223 +#, no-wrap +msgid "More Than a Secure Shell" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1226 +msgid "" +"A secure command line interface is just the beginning of the many ways SSH " +"can be used. Given the proper amount of bandwidth, X11 sessions can be " +"directed over an SSH channel. Or, by using TCP/IP forwarding, previously " +"insecure port connections between systems can be mapped to specific SSH " +"channels." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:1228 +#, no-wrap +msgid "X11 Forwarding" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1231 +msgid "" +"indexterm:[SSH protocol,X11 forwarding] To open an X11 session over an SSH " +"connection, use a command in the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1235 +#, no-wrap +msgid "" +"[command]#ssh -Y " +"_username_pass:attributes[{blank}]@pass:attributes[{blank}]_hostname_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1243 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#ssh -Y " +"USER@penguin.example.com#\n" +"USER@penguin.example.com's password:\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1246 +msgid "" +"When an X program is run from the secure shell prompt, the SSH client and " +"server create a new secure channel, and the X program data is sent over that " +"channel to the client machine transparently." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1248 +msgid "" +"Note that the X Window system must be installed on the remote system before " +"X11 forwarding can take place. Enter the following command as `root` to " +"install the X11 package group:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1251 +#, no-wrap +msgid "~]# dnf group install \"X Window System\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1254 +msgid "" +"X11 forwarding can be very useful. For example, X11 forwarding can be used " +"to create a secure, interactive session of the [application]*Print Settings* " +"utility. To do this, connect to the server using [application]*ssh* and " +"type:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1258 +#, no-wrap +msgid "~]${nbsp}pass:attributes[{blank}][command]#system-config-printer &#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1261 +msgid "" +"The [application]*Print Settings* tool will appear, allowing the remote user " +"to safely configure printing on the remote system." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/OpenSSH.adoc:1263 +#, no-wrap +msgid "Port Forwarding" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1266 +msgid "" +"indexterm:[SSH protocol,port forwarding] SSH can secure otherwise insecure " +"`TCP/IP` protocols via port forwarding. When using this technique, the SSH " +"server becomes an encrypted conduit to the SSH client." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1268 +msgid "" +"Port forwarding works by mapping a local port on the client to a remote port " +"on the server. SSH can map any port from the server to any port on the " +"client. Port numbers do not need to match for this technique to work." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:1269 +#, no-wrap +msgid "Using reserved port numbers" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:1274 +msgid "" +"Setting up port forwarding to listen on ports below 1024 requires `root` " +"level access." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1278 +msgid "" +"To create a TCP/IP port forwarding channel which listens for connections on " +"the `localhost`, use a command in the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1282 +#, no-wrap +msgid "" +"[command]#ssh -L " +"_local-port_:pass:attributes[{blank}]_remote-hostname_:pass:attributes[{blank}]_remote-port_ " +"_username_pass:attributes[{blank}]@pass:attributes[{blank}]_hostname_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1285 +msgid "" +"For example, to check email on a server called `mail.example.com` using " +"`POP3` through an encrypted connection, use the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1289 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#ssh -L 1100:mail.example.com:110 " +"mail.example.com#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1292 +msgid "" +"Once the port forwarding channel is in place between the client machine and " +"the mail server, direct a POP3 mail client to use port `1100` on the " +"`localhost` to check for new email. Any requests sent to port `1100` on the " +"client system will be directed securely to the `mail.example.com` server." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1294 +msgid "" +"If `mail.example.com` is not running an SSH server, but another machine on " +"the same network is, SSH can still be used to secure part of the " +"connection. However, a slightly different command is necessary:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/OpenSSH.adoc:1298 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#ssh -L 1100:mail.example.com:110 " +"other.example.com#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1301 +msgid "" +"In this example, POP3 requests from port `1100` on the client machine are " +"forwarded through the SSH connection on port `22` to the SSH server, " +"`other.example.com`. Then, `other.example.com` connects to port `110` on " +"`mail.example.com` to check for new email. Note that when using this " +"technique, only the connection between the client system and " +"`other.example.com` SSH server is secure." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1303 +msgid "" +"Port forwarding can also be used to get information securely through network " +"firewalls. If the firewall is configured to allow SSH traffic via its " +"standard port (that is, port 22) but blocks access to other ports, a " +"connection between two hosts using the blocked ports is still possible by " +"redirecting their communication over an established SSH connection." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:1304 +#, no-wrap +msgid "A connection is only as secure as a client system" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:1309 +msgid "" +"Using port forwarding to forward connections in this manner allows any user " +"on the client system to connect to that service. If the client system " +"becomes compromised, the attacker also has access to forwarded services." +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/OpenSSH.adoc:1311 +msgid "" +"System administrators concerned about port forwarding can disable this " +"functionality on the server by specifying a [option]`No` parameter for the " +"[option]`AllowTcpForwarding` line in `/etc/ssh/sshd_config` and restarting " +"the [command]#sshd# service." +msgstr "" + +#. type: Title == +#: ./pages/infrastructure-services/OpenSSH.adoc:1315 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1318 +msgid "" +"indexterm:[OpenSSH,additional resources]indexterm:[OpenSSL,additional " +"resources] For more information on how to configure or connect to an OpenSSH " +"server on Fedora, see the resources listed below." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:1319 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1322 +msgid "" +"`sshd`(8) — The manual page for the `sshd` daemon documents available " +"command line options and provides a complete list of supported configuration " +"files and directories." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1324 +msgid "" +"`ssh`(1) — The manual page for the [command]#ssh# client application " +"provides a complete list of available command line options and supported " +"configuration files and directories." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1326 +msgid "" +"`scp`(1) — The manual page for the [command]#scp# utility provides a more " +"detailed description of this utility and its usage." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1328 +msgid "`sftp`(1) — The manual page for the [command]#sftp# utility." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1330 +msgid "" +"`ssh-keygen`(1) — The manual page for the [command]#ssh-keygen# utility " +"documents in detail how to use it to generate, manage, and convert " +"authentication keys used by [command]#ssh#." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1332 +msgid "" +"`ssh_config`(5) — The manual page named `ssh_config` documents available SSH " +"client configuration options." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1334 +msgid "" +"`sshd_config`(5) — The manual page named `sshd_config` provides a full " +"description of available SSH daemon configuration options." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/OpenSSH.adoc:1335 +#, no-wrap +msgid "Online Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1338 +msgid "" +"link:++https://www.openssh.com/++[OpenSSH Home Page] — The OpenSSH home page " +"containing further documentation, frequently asked questions, links to the " +"mailing lists, bug reports, and other useful resources." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/OpenSSH.adoc:1339 +msgid "" +"link:++https://www.openssl.org/++[OpenSSL Home Page] — The OpenSSL home page " +"containing further documentation, frequently asked questions, links to the " +"mailing lists, and other useful resources." +msgstr "" diff --git a/pot/rawhide/pages/infrastructure-services/Services_and_Daemons.pot b/pot/rawhide/pages/infrastructure-services/Services_and_Daemons.pot new file mode 100644 index 00000000000..5c7649076ba --- /dev/null +++ b/pot/rawhide/pages/infrastructure-services/Services_and_Daemons.pot @@ -0,0 +1,560 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:6 +#, no-wrap +msgid "Services and Daemons" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:9 +msgid "" +"indexterm:[services configuration] Maintaining security on your system is " +"extremely important, and one approach for this task is to manage access to " +"system services carefully. Your system may need to provide open access to " +"particular services (for example, `httpd` if you are running a web " +"server). However, if you do not need to provide a service, you should turn " +"it off to minimize your exposure to possible bug exploits." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:11 +msgid "" +"This chapter covers the configuration of the services to be run when a " +"system is started, and provides information on how to start, stop, and " +"restart the services on the command line using the [application]*systemctl* " +"utility." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:12 +#, no-wrap +msgid "Keep the system secure" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:17 +msgid "" +"When you allow access for new services, always remember that both the " +"firewall and [application]*SELinux* need to be configured as well. One of " +"the most common mistakes committed when configuring a new service is " +"neglecting to implement the necessary firewall configuration and SELinux " +"policies to allow access for it." +msgstr "" + +#. type: Title == +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:21 +#, no-wrap +msgid "Configuring Services" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:24 +msgid "" +"indexterm:[systemctl,services configuration]indexterm:[services " +"configuration,systemctl] To allow you to configure which services are " +"started at boot time, {MAJOROS} is shipped with the [application]*systemctl* " +"command line tool." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:25 +#, no-wrap +msgid "Do not use the ntsysv and chkconfig utilities" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:30 +msgid "" +"Although it is still possible to use the [application]*ntsysv* and " +"[application]*chkconfig* utilities to manage services that have init scripts " +"installed in the `/etc/rc.d/init.d/` directory, it is advised that you use " +"the [application]*systemctl* utility." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:33 +#, no-wrap +msgid "Enabling the irqbalance service" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:38 +msgid "" +"To ensure optimal performance on POWER architecture, it is recommended that " +"the `irqbalance` service is enabled. In most cases, this service is " +"installed and configured to run during the {MAJOROSVER} installation. To " +"verify that `irqbalance` is running, type the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:42 +#, no-wrap +msgid "[command]#systemctl status irqbalance.service#\n" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:47 +#, no-wrap +msgid "Enabling the Service" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:50 +msgid "" +"To configure a service to be automatically started at boot time, use the " +"[command]#systemctl# command in the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:53 +#, no-wrap +msgid "systemctl enable service_name.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:56 +msgid "" +"The service will be started the next time you boot the system. For " +"information on how to start the service immediately, refer to " +"xref:Services_and_Daemons.adoc#s3-services-running-running[Running the " +"Service]." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:58 +#, no-wrap +msgid "Enabling the httpd service" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:62 +msgid "" +"Imagine you want to run the Apache HTTP Server on your system. Provided that " +"you have the [package]*httpd* package installed, you can enable the `httpd` " +"service by typing the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:65 +#, no-wrap +msgid "~]# systemctl enable httpd.service\n" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:70 +#, no-wrap +msgid "Disabling the Service" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:73 +msgid "" +"To disable starting a service at boot time, use the [command]#systemctl# " +"command in the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:76 +#, no-wrap +msgid "systemctl disable service_name.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:79 +msgid "" +"The next time you boot the system, the service will *not* be started. For " +"information on how to stop the service immediately, refer to " +"xref:Services_and_Daemons.adoc#s3-services-running-stopping[Stopping the " +"Service]." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:81 +#, no-wrap +msgid "Disabling the telnet service" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:85 +msgid "" +"In order to secure the system, users are advised to disable insecure " +"connection protocols such as Telnet. You can make sure that the `telnet` " +"service is disabled by running the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:88 +#, no-wrap +msgid "~]# systemctl disable telnet.service\n" +msgstr "" + +#. type: Title == +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:93 +#, no-wrap +msgid "Running Services" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:96 +msgid "" +"indexterm:[systemctl,services configuration]indexterm:[services " +"configuration,ssystemctl] The [application]*systemctl* utility also allows " +"you to determine the status of a particular service, as well as to start, " +"stop, or restart a service." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:97 +#, no-wrap +msgid "Do not use the service utility" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:102 +msgid "" +"Although it is still possible to use the [application]*service* utility to " +"manage services that have init scripts installed in the `/etc/rc.d/init.d/` " +"directory, it is advised that you use the [application]*systemctl* utility." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:106 +#, no-wrap +msgid "Checking the Service Status" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:109 +msgid "" +"To determine the status of a particular service, use the " +"[command]#systemctl# command in the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:112 +#, no-wrap +msgid "systemctl status service_name.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:115 +msgid "" +"This command provides detailed information on the service's status. However, " +"if you merely need to verify that a service is running, you can use the " +"[command]#systemctl# command in the following form instead:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:118 +#, no-wrap +msgid "systemctl is-active service_name.service\n" +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:121 +#, no-wrap +msgid "Checking the status of the httpd service" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:125 +msgid "" +"xref:Services_and_Daemons.adoc#exam-services-configuration-enabling[Enabling " +"the httpd service] illustrated how to enable starting the `httpd` service at " +"boot time. Imagine that the system has been restarted and you need to verify " +"that the service is really running. You can do so by typing the following at " +"a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:130 +#, no-wrap +msgid "" +"~]$ [command]#systemctl is-active httpd.service#\n" +"active\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:133 +msgid "" +"You can also display detailed information about the service by running the " +"following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:151 +#, no-wrap +msgid "" +"~]$ systemctl status httpd.service\n" +"httpd.service - LSB: start and stop Apache HTTP Server\n" +" Loaded: loaded (/etc/rc.d/init.d/httpd)\n" +" Active: active (running) since Mon, 23 May 2011 21:38:57 +0200; " +"27s ago\n" +" Process: 2997 ExecStart=/etc/rc.d/init.d/httpd start (code=exited, " +"status=0/SUCCESS)\n" +" Main PID: 3002 (httpd)\n" +" CGroup: name=systemd:/system/httpd.service\n" +" ├ 3002 /usr/sbin/httpd\n" +" ├ 3004 /usr/sbin/httpd\n" +" ├ 3005 /usr/sbin/httpd\n" +" ├ 3006 /usr/sbin/httpd\n" +" ├ 3007 /usr/sbin/httpd\n" +" ├ 3008 /usr/sbin/httpd\n" +" ├ 3009 /usr/sbin/httpd\n" +" ├ 3010 /usr/sbin/httpd\n" +" └ 3011 /usr/sbin/httpd\n" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:156 +msgid "To display a list of all active system services, use the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:160 +#, no-wrap +msgid "[command]#systemctl list-units --type=service#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:163 +msgid "" +"This command provides a tabular output with each line consisting of the " +"following columns:" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:165 +msgid "`UNIT` — A `systemd` unit name. In this case, a service name." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:167 +msgid "`LOAD` — Information whether the `systemd` unit was properly loaded." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:169 +msgid "`ACTIVE` — A high-level unit activation state." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:171 +msgid "`SUB` — A low-level unit activation state." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:173 +msgid "`JOB` — A pending job for the unit." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:175 +msgid "`DESCRIPTION` — A brief description of the unit." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:177 +#, no-wrap +msgid "Listing all active services" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:181 +msgid "You can list all active services by using the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:192 +#, no-wrap +msgid "" +"~]$ [command]#systemctl list-units --type=service#\n" +"UNIT LOAD ACTIVE SUB JOB DESCRIPTION\n" +"abrt-ccpp.service loaded active exited LSB: Installs coredump " +"handler which saves segfault data\n" +"abrt-oops.service loaded active running LSB: Watches system log " +"for oops messages, creates ABRT dump directories for each oops\n" +"abrtd.service loaded active running ABRT Automated Bug " +"Reporting Tool\n" +"accounts-daemon.service loaded active running Accounts Service\n" +"atd.service loaded active running Job spooling tools\n" +"_[output truncated]_\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:195 +msgid "" +"In the example above, the `abrtd` service is loaded, active, and running, " +"and it does not have any pending jobs." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:199 +#, no-wrap +msgid "Running the Service" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:202 +msgid "" +"To run a service, use the [command]#systemctl# command in the following " +"form:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:205 +#, no-wrap +msgid "systemctl start service_name.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:208 +msgid "" +"This will start the service in the current session. To configure the service " +"to be started at boot time, refer to " +"xref:Services_and_Daemons.adoc#s3-services-configuration-enabling[Enabling " +"the Service]." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:210 +#, no-wrap +msgid "Running the httpd service" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:214 +msgid "" +"xref:Services_and_Daemons.adoc#exam-services-configuration-enabling[Enabling " +"the httpd service] illustrated how to run the `httpd` service at boot " +"time. You can start the service immediately by typing the following at a " +"shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:217 +#, no-wrap +msgid "~]# systemctl start httpd.service\n" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:222 +#, no-wrap +msgid "Stopping the Service" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:225 +msgid "" +"To stop a service, use the [command]#systemctl# command in the following " +"form:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:228 +#, no-wrap +msgid "systemctl stop service_name.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:231 +msgid "" +"This will stop the service in the current session. To disable starting the " +"service at boot time, refer to " +"xref:Services_and_Daemons.adoc#s3-services-configuration-enabling[Enabling " +"the Service]." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:233 +#, no-wrap +msgid "Stopping the telnet service" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:237 +msgid "" +"xref:Services_and_Daemons.adoc#exam-services-configuration-disabling[Disabling " +"the telnet service] illustrated how to disable starting the `telnet` service " +"at boot time. You can stop the service immediately by running the following " +"command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:240 +#, no-wrap +msgid "~]# systemctl stop telnet.service\n" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:245 +#, no-wrap +msgid "Restarting the Service" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:248 +msgid "" +"To restart a service, use the [command]#systemctl# command in the following " +"form:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:251 +#, no-wrap +msgid "systemctl restart service_name.service\n" +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:254 +#, no-wrap +msgid "Restarting the sshd service" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:258 +msgid "" +"For any changes in the `/etc/ssh/sshd_config` configuration file to take " +"effect, it is required that you restart the `sshd` service. You can do so by " +"typing the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:261 +#, no-wrap +msgid "~]# systemctl restart sshd.service\n" +msgstr "" + +#. type: Title == +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:266 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:269 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/Services_and_Daemons.adoc:271 +msgid "`systemctl`(1) — The manual page for the [application]*systemctl* utility." +msgstr "" diff --git a/pot/rawhide/pages/infrastructure-services/TigerVNC.pot b/pot/rawhide/pages/infrastructure-services/TigerVNC.pot new file mode 100644 index 00000000000..0604850861f --- /dev/null +++ b/pot/rawhide/pages/infrastructure-services/TigerVNC.pot @@ -0,0 +1,704 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/infrastructure-services/TigerVNC.adoc:6 +#, no-wrap +msgid "TigerVNC" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:10 +msgid "" +"`TigerVNC` (Tiger Virtual Network Computing) is a system for graphical " +"desktop sharing which allows you to remotely control other computers." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:14 +msgid "" +"`TigerVNC` works on the client-server network: a *server* shares its output " +"(`vncserver`) and a *client* (`vncviewer`) connects to the server." +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/TigerVNC.adoc:21 +msgid "" +"Unlike in Fedora 15 and Red{nbsp}Hat Enterprise{nbsp}Linux{nbsp}6, " +"`TigerVNC` in {MAJOROS} uses the `systemd` system management daemon for its " +"configuration. The `/etc/sysconfig/vncserver` configuration file has been " +"replaced by `/etc/systemd/system/vncserver@.service`." +msgstr "" + +#. type: Title == +#: ./pages/infrastructure-services/TigerVNC.adoc:25 +#, no-wrap +msgid "VNC Server" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:32 +msgid "" +"`vncserver` is a utility which starts a VNC (Virtual Network Computing) " +"desktop. It runs [application]*Xvnc* with appropriate options and starts a " +"window manager on the VNC desktop. `vncserver` allows users to run separate " +"sessions in parallel on a machine which can then be accessed by any number " +"of clients from anywhere." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/TigerVNC.adoc:34 +#, no-wrap +msgid "Installing VNC Server" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:37 +msgid "" +"To install the [application]*TigerVNC* server, issue the following command " +"as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:41 +#, no-wrap +msgid "# dnf install tigervnc-server\n" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/TigerVNC.adoc:44 +#, no-wrap +msgid "Configuring VNC Server" +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/TigerVNC.adoc:47 +#, no-wrap +msgid "Configuring the first VNC connection" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:49 +msgid "" +"A configuration file named `/etc/systemd/system/vncserver@.service` is " +"required. To create this file, copy the " +"`/lib/systemd/system/vncserver@.service` file as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:54 +#, no-wrap +msgid "" +"# cp /lib/systemd/system/vncserver@.service " +"/etc/systemd/system/vncserver@.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:58 +msgid "" +"There is no need to include the display number in the file name because " +"`systemd` automatically creates the appropriately named instance in memory " +"on demand, replacing `'%i'` in the service file by the display number. For a " +"single user it is not necessary to rename the file. For multiple users, a " +"uniquely named service file for each user is required, for example, by " +"adding the user name to the file name in some way. See " +"xref:TigerVNC.adoc#configuring-vncserver-2users[Configuring VNC Server for " +"Two Users] for details." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:64 +msgid "" +"Edit `/etc/systemd/system/vncserver@.service`, replacing _USER_ with the " +"actual user name. Leave the remaining lines of the file unmodified. The " +"[option]`-geometry` argument specifies the size of the VNC desktop to be " +"created; by default, it is set to `1024x768`." +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:70 +#, no-wrap +msgid "" +"ExecStart=/sbin/runuser -l _USER_ -c \"/usr/bin/vncserver %i -geometry " +"1280x1024\"\n" +"PIDFile=/home/pass:attributes[{blank}]_USER_pass:attributes[{blank}]/.vnc/%H%i.pid\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:74 +msgid "Save the changes." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:76 +msgid "To make the changes take effect immediately, issue the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:81 +#, no-wrap +msgid "# pass:quotes[`systemctl daemon-reload`]\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:86 +msgid "" +"Set the password for the user or users defined in the configuration " +"file. Note that you need to switch from `root` to _USER_ first." +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:94 +#, no-wrap +msgid "" +"# su - pass:quotes[_USER_]\n" +"$ pass:quotes[`vncpasswd`]\n" +"Password:\n" +"Verify:\n" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/TigerVNC.adoc:102 +msgid "" +"The stored password is not encrypted; anyone who has access to the password " +"file can find the plain-text password." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:106 +msgid "Proceed to xref:TigerVNC.adoc#s4-starting-vncserver[Starting VNC Server]." +msgstr "" + +#. type: Title ==== +#: ./pages/infrastructure-services/TigerVNC.adoc:108 +#, no-wrap +msgid "Configuring VNC Server for Two Users" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:112 +msgid "" +"If you want to configure more than one user on the same machine, create " +"different template-type service files, one for each user." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:116 +msgid "" +"Create two service files, for example " +"`vncserver-_USER_1_pass:attributes[{blank}]@.service` and " +"`vncserver-_USER_2_pass:attributes[{blank}]@.service`. In both these files " +"substitute _USER_ with the correct user name." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:118 +msgid "Set passwords for both users:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:130 +#, no-wrap +msgid "" +"$ su - USER_1\n" +"$ vncpasswd\n" +"Password:\n" +"Verify:\n" +"$ su - USER_2\n" +"$ vncpasswd\n" +"Password:\n" +"Verify:\n" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/TigerVNC.adoc:134 +#, no-wrap +msgid "Starting VNC Server" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:140 +msgid "" +"To start or enable the service, specify the display number directly in the " +"command. The file configured above in " +"xref:TigerVNC.adoc#configuring-vncserver[Configuring the first VNC " +"connection] works as a template, in which `%i` is substituted with the " +"display number by `systemd`. With a valid display number, execute the " +"following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:145 +#, no-wrap +msgid "# systemctl start vncserver@:display_number.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:149 +msgid "" +"You can also enable the service to start automatically at system " +"start. Then, when you log in, `vncserver` is automatically started. As " +"`root`, issue a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:154 +#, no-wrap +msgid "# systemctl enable vncserver@:display_number.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:158 +msgid "" +"At this point, other users are able to use a VNC viewer program to connect " +"to the VNC server using the display number and password defined. Provided a " +"graphical desktop is installed, an instance of that desktop will be " +"displayed. It will not be the same instance as that currently displayed on " +"the target machine." +msgstr "" + +#. type: Title ==== +#: ./pages/infrastructure-services/TigerVNC.adoc:160 +#, no-wrap +msgid "Configuring VNC Server for Two Users and Two Different Displays" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:165 +msgid "" +"For the two configured VNC servers, vncserver-USER_1@.service and " +"vncserver-USER_2@.service, you can enable different display numbers. For " +"example, the following commands will cause a VNC server for USER_1 to start " +"on display 3, and a VNC server for USER_2 to start on display 5:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:171 +#, no-wrap +msgid "" +"# systemctl start vncserver-USER_1@:3.service\n" +"# systemctl start vncserver-USER_2@:5.service\n" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/TigerVNC.adoc:175 +#, no-wrap +msgid "Terminating a VNC Session" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:179 +msgid "" +"Similarly to enabling the `vncserver` service, you can disable the automatic " +"start of the service at system start:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:184 +#, no-wrap +msgid "# systemctl disable vncserver@:display_number.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:189 +msgid "" +"Or, when your system is running, you can stop the service by issuing the " +"following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:194 +#, no-wrap +msgid "# systemctl stop vncserver@:display_number.service\n" +msgstr "" + +#. type: Title == +#: ./pages/infrastructure-services/TigerVNC.adoc:198 +#, no-wrap +msgid "VNC Viewer" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:202 +msgid "" +"`vncviewer` is the program which shows the shared graphical user interfaces " +"and controls the server." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:207 +msgid "" +"For operating the `vncviewer`, there is a pop-up menu containing entries " +"which perform various actions such as switching in and out of full-screen " +"mode or quitting the viewer. Alternatively, you can operate `vncviewer` " +"through the terminal. Enter [command]#vncviewer -h# on the command line to " +"list `vncviewer`pass:attributes[{blank}]'s parameters." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/TigerVNC.adoc:209 +#, no-wrap +msgid "Installing VNC Viewer" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:212 +msgid "" +"To install the [application]*TigerVNC* client, " +"[command]#vncviewer#pass:attributes[{blank}]>, issue the following command " +"as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:216 +#, no-wrap +msgid "# dnf install tigervnc\n" +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/TigerVNC.adoc:219 +#, no-wrap +msgid "Connecting to VNC Server" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:223 +msgid "" +"Once the VNC server is configured, you can connect to it from any VNC " +"viewer. In order to do so, issue the [command]#vncviewer# command in the " +"following format:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:227 +#, no-wrap +msgid "vncviewer pass:quotes[_address_]:pass:quotes[_port_number_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:230 +msgid "Where _address_ is an `IP` or host name." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/TigerVNC.adoc:232 +#, no-wrap +msgid "One Client Connecting to VNC Server" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/TigerVNC.adoc:237 +msgid "" +"With the `IP` address `192.168.0.4` and display number *3* the command looks " +"as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:242 +#, no-wrap +msgid "[command]#$ vncviewer 192.168.0.4:3#\n" +msgstr "" + +#. type: Title ==== +#: ./pages/infrastructure-services/TigerVNC.adoc:248 +#, no-wrap +msgid "Configuring the Firewall for VNC" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/TigerVNC.adoc:252 +msgid "" +"When using a non-encrypted connection, `firewalld` might block the " +"connection. To allow `firewalld` to pass the VNC packets, you can open " +"specific ports to `TCP` traffic. When using the [option]`-via` option, " +"traffic is redirected over `SSH` which is enabled by default in `firewalld`." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:259 +msgid "" +"The default port of VNC server is 5900. To reach the port through which a " +"remote desktop will be accessible, sum the default port and the user's " +"assigned display number. For example, for the second port: 2 + 5900 = 5902." +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/TigerVNC.adoc:263 +msgid "" +"For displays `0` to `3`, make use of `firewalld`pass:attributes[{blank}]'s " +"support for the VNC service by means of the [option]`service` option as " +"described below. Note that for display numbers greater than `3`, the " +"corresponding ports will have to be opened specifically as explained in " +"xref:TigerVNC.adoc#proc-Opening-Ports_in_firewalld[Opening Ports in " +"firewalld]." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/TigerVNC.adoc:265 +#, no-wrap +msgid "Enabling VNC Service in firewalld" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/TigerVNC.adoc:268 +msgid "" +"Run the following command to see the information concerning `firewalld` " +"settings:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:273 +#, no-wrap +msgid "[command]#$ firewall-cmd --list-all#\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:277 +msgid "" +"To allow all VNC connections from a specific address, use a command as " +"follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:282 +#, no-wrap +msgid "" +"# firewall-cmd --add-rich-rule='rule family=\"ipv4\" source " +"address=\"192.168.122.116\" service name=vnc-server accept'\n" +"success\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:285 +msgid "" +"See the " +"link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Security_Guide/++[Red{nbsp}Hat " +"Enterprise{nbsp}Linux{nbsp}7 Security Guide] for more information on the use " +"of firewall rich language commands." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:287 +msgid "To verify the above settings, use a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:301 +#, no-wrap +msgid "" +"# firewall-cmd --list-all\n" +"public (default, active)\n" +" interfaces: bond0 bond0.192\n" +" sources:\n" +" services: dhcpv6-client ssh\n" +" ports:\n" +" masquerade: no\n" +" forward-ports:\n" +" icmp-blocks:\n" +" rich rules:\n" +"\trule family=\"ipv4\" source address=\"192.168.122.116\" service " +"name=\"vnc-server\" accept\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:304 +msgid "" +"To open a specific port or range of ports make use of the " +"[option]`--add-port` option to the [command]#firewall-cmd# command Line " +"tool. For example, VNC display `4` requires port `5904` to be opened for " +"`TCP` traffic." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/TigerVNC.adoc:306 +#, no-wrap +msgid "Opening Ports in firewalld" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:308 +msgid "" +"To open a port for `TCP` traffic in the public zone, issue a command as " +"`root` as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:313 +#, no-wrap +msgid "" +"# firewall-cmd --zone=public --add-port=5904/tcp\n" +"success\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:316 +msgid "" +"To view the ports that are currently open for the public zone, issue a " +"command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:321 +#, no-wrap +msgid "" +"# firewall-cmd --zone=public --list-ports\n" +"5904/tcp\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:324 +msgid "" +"A port can be removed using the [command]#firewall-cmd " +"--zone=pass:attributes[{blank}]_zone_ " +"--remove-port=pass:attributes[{blank}]_number/protocol_pass:attributes[{blank}]# " +"command." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:326 +msgid "" +"For more information on opening and closing ports in `firewalld`, see the " +"link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Security_Guide/++[Red{nbsp}Hat " +"Enterprise{nbsp}Linux{nbsp}7 Security Guide]." +msgstr "" + +#. type: Title === +#: ./pages/infrastructure-services/TigerVNC.adoc:328 +#, no-wrap +msgid "Connecting to VNC Server Using SSH" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:331 +#, no-wrap +msgid "" +"*VNC* is a clear text network protocol with no security against possible " +"attacks on the communication. To make the communication secure, you can " +"encrypt your server-client connection by using the [option]`-via` " +"option. This will create an `SSH` tunnel between the VNC server and the " +"client.\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:333 +msgid "" +"The format of the command to encrypt a VNC server-client connection is as " +"follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:338 +#, no-wrap +msgid "$ vncviewer -via user@host:display_number\n" +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/TigerVNC.adoc:342 +#, no-wrap +msgid "Using the -via Option" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/TigerVNC.adoc:346 +msgid "To connect to a VNC server using `SSH`, enter a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:351 +#, no-wrap +msgid "$ vncviewer -via USER_2@192.168.2.101:3\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:355 +msgid "" +"When you are prompted to, type the password, and confirm by pressing " +"kbd:[Enter]." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:357 +msgid "A window with a remote desktop appears on your screen." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/TigerVNC.adoc:360 +#, no-wrap +msgid "Restricting VNC Access" +msgstr "" + +#. type: delimited block = +#: ./pages/infrastructure-services/TigerVNC.adoc:364 +msgid "" +"If you prefer only encrypted connections, you can prevent unencrypted " +"connections altogether by using the [option]`-localhost` option in the " +"`systemd.service` file, the ExecStart line:" +msgstr "" + +#. type: delimited block - +#: ./pages/infrastructure-services/TigerVNC.adoc:368 +#, no-wrap +msgid "ExecStart=/sbin/runuser -l _user_ -c \"/usr/bin/vncserver -localhost %i\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:371 +msgid "" +"This will stop `vncserver` from accepting connections from anything but the " +"local host and port-forwarded connections sent using `SSH` as a result of " +"the [option]`-via` option." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:373 +msgid "" +"For more information on using `SSH`, see " +"xref:infrastructure-services/OpenSSH.adoc#ch-OpenSSH[OpenSSH]." +msgstr "" + +#. type: Title == +#: ./pages/infrastructure-services/TigerVNC.adoc:375 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:378 +msgid "For more information about TigerVNC, see the resources listed below." +msgstr "" + +#. type: Block title +#: ./pages/infrastructure-services/TigerVNC.adoc:379 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:382 +msgid "`vncserver(1)` — The *VNC* server manual pages." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:384 +msgid "`vncviewer(1)` — The *VNC* viewer manual pages." +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/TigerVNC.adoc:385 +msgid "`vncpasswd(1)` — The *VNC* password manual pages." +msgstr "" diff --git a/pot/rawhide/pages/infrastructure-services/intro-infrastructure-services.pot b/pot/rawhide/pages/infrastructure-services/intro-infrastructure-services.pot new file mode 100644 index 00000000000..ecd9b5e42b6 --- /dev/null +++ b/pot/rawhide/pages/infrastructure-services/intro-infrastructure-services.pot @@ -0,0 +1,30 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/infrastructure-services/intro-infrastructure-services.adoc:1 +#, no-wrap +msgid "Infrastructure Services" +msgstr "" + +#. type: Plain text +#: ./pages/infrastructure-services/intro-infrastructure-services.adoc:3 +msgid "" +"This part provides information on how to configure services and daemons, " +"configure authentication, and enable remote logins." +msgstr "" diff --git a/pot/rawhide/pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.pot b/pot/rawhide/pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.pot new file mode 100644 index 00000000000..473542f4776 --- /dev/null +++ b/pot/rawhide/pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.pot @@ -0,0 +1,1019 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:6 +#, no-wrap +msgid "Manually Upgrading the Kernel" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:9 +msgid "" +"indexterm:[kernel,upgrading the " +"kernel]indexterm:[kernel,package]indexterm:[kernel,RPM " +"package]indexterm:[package,kernel RPM] The {MAJOROS} kernel is custom-built " +"by the {MAJOROS} kernel team to ensure its integrity and compatibility with " +"supported hardware. Before a kernel is released, it must first pass a " +"rigorous set of quality assurance tests." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:11 +msgid "" +"{MAJOROS} kernels are packaged in the RPM format so that they are easy to " +"upgrade and verify using the [application]*DNF* or [application]*PackageKit* " +"package managers. [application]*PackageKit* automatically queries the DNF " +"repositories and informs you of packages with available updates, including " +"kernel packages." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:14 +msgid "" +"This chapter is therefore *only* useful for users who need to manually " +"update a kernel package using the [command]#rpm# command instead of " +"[command]#dnf#. indexterm:[kernel,installing kernel " +"packages]indexterm:[installing the kernel]" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:15 +#, no-wrap +msgid "Use DNF to install kernels whenever possible" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:20 +msgid "" +"Whenever possible, use either the [application]*DNF* or " +"[application]*PackageKit* package manager to install a new kernel because " +"they always *install* a new kernel instead of replacing the current one, " +"which could potentially leave your system unable to boot." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:24 +msgid "" +"indexterm:[kernel,installing kernel packages] For more information on " +"installing kernel packages with [application]*DNF*, see " +"xref:package-management/DNF.adoc#sec-Updating_Packages[Updating Packages]." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:26 +#, no-wrap +msgid "Overview of Kernel Packages" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:29 +msgid "" +"indexterm:[kernel,kernel packages]indexterm:[kernel package,kernel,for " +"single, multicore and multiprocessor systems]indexterm:[packages,kernel,for " +"single, multicore and multiprocessor systems]indexterm:[kernel " +"package,kernel-devel,kernel headers and " +"makefiles]indexterm:[packages,kernel-devel,kernel headers and " +"makefiles]indexterm:[kernel package,kernel-headers,C header files " +"files]indexterm:[packages,kernel-headers,C header files " +"files]indexterm:[kernel package,linux-firmware,firmware " +"files]indexterm:[packages,linux-firmware,firmware files]indexterm:[kernel " +"package,perf,firmware files]indexterm:[packages,perf,firmware files] " +"{MAJOROS} contains the following kernel packages:" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:31 +msgid "" +"[package]*kernel* — Contains the kernel for single, multicore and " +"multiprocessor systems." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:33 +msgid "" +"[package]*kernel-debug* — Contains a kernel with numerous debugging options " +"enabled for kernel diagnosis, at the expense of reduced performance." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:35 +msgid "" +"[package]*kernel-devel* — Contains the kernel headers and makefiles " +"sufficient to build modules against the [package]*kernel* package." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:37 +msgid "" +"[package]*kernel-debug-devel* — Contains the development version of the " +"kernel with numerous debugging options enabled for kernel diagnosis, at the " +"expense of reduced performance." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:39 +msgid "" +"[package]*kernel-headers* — Includes the C header files that specify the " +"interface between the Linux kernel and user-space libraries and " +"programs. The header files define structures and constants that are needed " +"for building most standard programs." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:41 +msgid "" +"[package]*linux-firmware* — Contains all of the firmware files that are " +"required by various devices to operate." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:43 +msgid "" +"[package]*perf* — This package contains supporting scripts and documentation " +"for the [application]*perf* tool shipped in each kernel image subpackage." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:45 +msgid "" +"[package]*kernel-abi-whitelists* — Contains information pertaining to the " +"{MAJOROS} kernel ABI, including a lists of kernel symbols that are needed by " +"external Linux kernel modules and a [package]*dnf* plug-in to aid " +"enforcement." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:47 +msgid "" +"[package]*kernel-tools* — Contains tools for manipulating the Linux kernel " +"and supporting documentation." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:49 +#, no-wrap +msgid "Preparing to Upgrade" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:52 +msgid "" +"indexterm:[boot " +"media]indexterm:[kernel,upgrading,preparing]indexterm:[kernel " +"upgrading,preparing]indexterm:[kernel,upgrading,working boot media] Before " +"upgrading the kernel, it is recommended that you take some precautionary " +"steps." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:54 +msgid "" +"First, ensure that working boot media exists for the system in case a " +"problem occurs. If the boot loader is not configured properly to boot the " +"new kernel, you can use this media to boot into {MAJOROS}." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:56 +msgid "" +"USB media often comes in the form of flash devices sometimes called _pen " +"drives_, _thumb disks_, or _keys_, or as an externally-connected hard disk " +"device. Almost all media of this type is formatted as a `VFAT` file " +"system. You can create bootable USB media on media formatted as `ext2`, " +"`ext3`, `ext4`, or `VFAT`." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:58 +msgid "" +"You can transfer a distribution image file or a minimal boot media image " +"file to USB media. Make sure that sufficient free space is available on the " +"device. Around 4 GB is required for a distribution DVD image, around 700 MB " +"for a distribution CD image, or around 10 MB for a minimal boot media image." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:60 +msgid "" +"You must have a copy of the `boot.iso` file from a {MAJOROS} installation " +"DVD, or installation CD-ROM#1, and you need a USB storage device formatted " +"with the `VFAT` file system and around 16 MB of free space. The following " +"procedure will not affect existing files on the USB storage device unless " +"they have the same path names as the files that you copy onto it. To create " +"USB boot media, perform the following commands as the `root` user:" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:62 +msgid "Install the [application]*SYSLINUX* bootloader on the USB storage device:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:66 +#, no-wrap +msgid "~]#{nbsp}syslinux /dev/sdX1\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:69 +msgid "...where _sdX_ is the device name." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:71 +msgid "Create mount points for `boot.iso` and the USB storage device:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:75 +#, no-wrap +msgid "~]#{nbsp}mkdir /mnt/isoboot /mnt/diskboot\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:78 +msgid "Mount `boot.iso`:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:82 +#, no-wrap +msgid "~]#{nbsp}mount -o loop boot.iso /mnt/isoboot\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:85 +msgid "Mount the USB storage device:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:89 +#, no-wrap +msgid "~]#{nbsp}mount /dev/sdX1 /mnt/diskboot\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:92 +msgid "" +"Copy the [application]*ISOLINUX* files from the `boot.iso` to the USB " +"storage device:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:96 +#, no-wrap +msgid "~]#{nbsp}cp /mnt/isoboot/isolinux/* /mnt/diskboot\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:99 +msgid "" +"Use the `isolinux.cfg` file from `boot.iso` as the `syslinux.cfg` file for " +"the USB device:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:103 +#, no-wrap +msgid "" +"~]#{nbsp}grep -v local /mnt/isoboot/isolinux/isolinux.cfg > " +"/mnt/diskboot/syslinux.cfg\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:107 +msgid "Unmount `boot.iso` and the USB storage device:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:111 +#, no-wrap +msgid "~]#{nbsp}umount /mnt/isoboot /mnt/diskboot\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:115 +msgid "" +"You should reboot the machine with the boot media and verify that you are " +"able to boot with it before continuing." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:117 +msgid "" +"Alternatively, on systems with a floppy drive, you can create a boot " +"diskette by installing the [package]*mkbootdisk* package and running the " +"[command]#mkbootdisk# command as `root`. See [command]#man mkbootdisk# man " +"page after installing the package for usage information." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:119 +msgid "" +"To determine which kernel packages are installed, execute the command " +"[command]#dnf list installed \"kernel-*\"# at a shell prompt. The output " +"will comprise some or all of the following packages, depending on the " +"system's architecture, and the version numbers might differ:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:131 +#, no-wrap +msgid "" +"~]# dnf list installed \"kernel-*\"\n" +"Last metadata expiration check performed 0:28:51 ago on Tue May 26 21:22:39 " +"2015.\n" +"Installed Packages\n" +"kernel-core.x86_64 4.0.3-300.fc22 " +"@System\n" +"kernel-core.x86_64 4.0.4-300.fc22 " +"@System\n" +"kernel-core.x86_64 4.0.4-301.fc22 " +"@System\n" +"kernel-headers.x86_64 4.0.4-301.fc22 " +"@System\n" +"kernel-modules.x86_64 4.0.3-300.fc22 " +"@System\n" +"kernel-modules.x86_64 4.0.4-300.fc22 " +"@System\n" +"kernel-modules.x86_64 4.0.4-301.fc22 " +"@System\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:134 +msgid "" +"From the output, determine which packages need to be downloaded for the " +"kernel upgrade. For a single processor system, the only required package is " +"the [package]*kernel* package. See " +"xref:Manually_Upgrading_the_Kernel.adoc#s1-kernel-packages[Overview of " +"Kernel Packages] for descriptions of the different packages." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:136 +#, no-wrap +msgid "Downloading the Upgraded Kernel" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:139 +msgid "" +"indexterm:[kernel,downloading]indexterm:[kernel,upgrade kernel " +"available]indexterm:[kernel,upgrade kernel available,via Fedora Update " +"System]indexterm:[kernel,upgrade kernel available,Security Advisories] There " +"are several ways to determine if an updated kernel is available for the " +"system." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:141 +msgid "" +"Via Fedora Update System — Download and install the kernel RPM packages. For " +"more information, refer to link:++https://bodhi.fedoraproject.org/++[]." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:143 +msgid "Via `_DNF_` using check-update:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:145 +#, no-wrap +msgid "dnf check-update --enablerepo=updates-testing\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:148 +msgid "" +"To install the kernel manually, continue to " +"xref:Manually_Upgrading_the_Kernel.adoc#s1-kernel-perform-upgrade[Performing " +"the Upgrade]." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:150 +#, no-wrap +msgid "Performing the Upgrade" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:153 +msgid "" +"indexterm:[kernel,performing kernel upgrade] After retrieving all of the " +"necessary packages, it is time to upgrade the existing kernel." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:154 +#, no-wrap +msgid "Keep the old kernel when performing the upgrade" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:159 +msgid "" +"It is strongly recommended that you keep the old kernel in case there are " +"problems with the new kernel." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:163 +msgid "" +"At a shell prompt, change to the directory that contains the kernel RPM " +"packages. Use [option]`-i` argument with the [command]#rpm# command to keep " +"the old kernel. Do *not* use the [option]`-U` option, since it overwrites " +"the currently installed kernel, which creates boot loader problems. For " +"example:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:167 +#, no-wrap +msgid "~]#{nbsp}rpm -ivh kernel-kernel_version.arch.rpm\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:170 +msgid "" +"The next step is to verify that the initial RAM disk image has been " +"created. See " +"xref:kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc#sec-Verifying_the_Initial_RAM_Disk_Image[Verifying " +"the Initial RAM Disk Image] for details." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:172 +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:181 +#, no-wrap +msgid "Verifying the Initial RAM Disk Image" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:175 +msgid "" +"indexterm:[initial RAM disk image,verifying] The job of the initial RAM disk " +"image is to preload the block device modules, such as for IDE, SCSI or RAID, " +"so that the root file system, on which those modules normally reside, can " +"then be accessed and mounted. On {MAJOROSVER} systems, whenever a new kernel " +"is installed using either the [application]*DNF*, [application]*PackageKit*, " +"or [application]*RPM* package manager, the [application]*Dracut* utility is " +"always called by the installation scripts to create an _initramfs_ (initial " +"RAM disk image)." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:177 +msgid "" +"On all architectures other than IBM eServer System i (see " +"xref:Manually_Upgrading_the_Kernel.adoc#bh-Verifying_the_Initial_RAM_Disk_Image_and_Kernel_on_IBM_eServer_System_i[Verifying " +"the Initial RAM Disk Image and Kernel on IBM eServer System i]), you can " +"create an `initramfs` by running the [command]#dracut# command. However, you " +"usually don't need to create an `initramfs` manually: this step is " +"automatically performed if the kernel and its associated packages are " +"installed or upgraded from RPM packages distributed by {OSORG}." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:179 +msgid "" +"On architectures that use the GRUB 2 boot loader, you can verify that an " +"`initramfs` corresponding to your current kernel version exists and is " +"specified correctly in the `/boot/grub2/grub.cfg` configuration file by " +"following this procedure:" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:183 +msgid "" +"As `root`, list the contents in the `/boot/` directory and find the kernel " +"(`vmlinuz-_kernel_version_pass:attributes[{blank}]`) and " +"`initramfs-_kernel_version_pass:attributes[{blank}]` with the latest (most " +"recent) version number:" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:185 +#, no-wrap +msgid "Ensuring that the kernel and initramfs versions match" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:211 +#, no-wrap +msgid "" +"~]# ls /boot/\n" +"config-3.17.4-302.fc21.x86_64\n" +"config-3.17.6-300.fc21.x86_64\n" +"config-3.17.7-300.fc21.x86_64\n" +"efi\n" +"elf-memtest86+-5.01\n" +"extlinux\n" +"grub2\n" +"initramfs-0-rescue-db90b4e3715b42daa871351439343ca4.img\n" +"initramfs-3.17.4-302.fc21.x86_64.img\n" +"initramfs-3.17.6-300.fc21.x86_64.img\n" +"initramfs-3.17.7-300.fc21.x86_64.img\n" +"initrd-plymouth.img\n" +"lost+found\n" +"memtest86+-5.01\n" +"System.map-3.17.4-302.fc21.x86_64\n" +"System.map-3.17.6-300.fc21.x86_64\n" +"System.map-3.17.7-300.fc21.x86_64\n" +"vmlinuz-0-rescue-db90b4e3715b42daa871351439343ca4\n" +"vmlinuz-3.17.4-302.fc21.x86_64\n" +"vmlinuz-3.17.6-300.fc21.x86_64\n" +"vmlinuz-3.17.7-300.fc21.x86_64\n" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:216 +msgid "" +"xref:Manually_Upgrading_the_Kernel.adoc#ex-Ensuring_that_the_kernel_and_initramfs_versions_match[Ensuring " +"that the kernel and initramfs versions match] shows that:" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:218 +msgid "" +"we have three kernels installed (or, more correctly, three kernel files are " +"present in the `/boot/` directory)," +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:220 +msgid "the latest kernel is `vmlinuz-3.17.7-300.fc21.x86_64`, and" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:222 +msgid "" +"an `initramfs` file matching our kernel version, " +"`initramfs-3.17.7-300.fc21.x86_64.img`, also exists." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:224 +#, no-wrap +msgid "initrd files in the /boot/ directory are not the same as initramfs files" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:229 +msgid "" +"In the `/boot/` directory you might find several " +"`initrd-_kernel_version_pass:attributes[{blank}]kdump.img` files. These are " +"special files created by the `kdump` mechanism for kernel debugging " +"purposes, are not used to boot the system, and can safely be ignored. For " +"more information on `kdump`, see the " +"link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Kernel_Crash_Dump_Guide/++[Red{nbsp}Hat " +"Enterprise{nbsp}Linux{nbsp}7 Kernel Crash Dump Guide]." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:233 +msgid "" +"(Optional) If your `initramfs-_kernel_version_pass:attributes[{blank}]` file " +"does not match the version of the latest kernel in `/boot`, or, in certain " +"other situations, you might need to generate an `initramfs` file with the " +"[application]*Dracut* utility. Simply invoking [command]#dracut# as `root` " +"without options causes it to generate an `initramfs` file in the `/boot/` " +"directory for the latest kernel present in that directory:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:236 +#, no-wrap +msgid "~]# dracut\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:239 +msgid "" +"You must use the [option]`--force` option if you want [command]#dracut# to " +"overwrite an existing `initramfs` (for example, if your `initramfs` has " +"become corrupt). Otherwise [command]#dracut# will refuse to overwrite the " +"existing `initramfs` file:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:243 +#, no-wrap +msgid "" +"~]# dracut\n" +"F: Will not override existing initramfs " +"(/boot/initramfs-3.17.7-300.fc21.x86_64.img) without --force\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:246 +msgid "" +"You can create an initramfs in the current directory by calling " +"[command]#dracut _initramfs_name_ _kernel_version_pass:attributes[{blank}]#, " +"for example:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:249 +#, no-wrap +msgid "~]# dracut \"initramfs-$(uname -r).img\" $(uname -r)\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:252 +msgid "" +"If you need to specify specific kernel modules to be preloaded, add the " +"names of those modules (minus any file name suffixes such as `.ko`) inside " +"the parentheses of the `add_dracutmodules=\"pass:attributes[{blank}]_module_ " +"_more_modules_pass:attributes[{blank}]\"` directive of the " +"`/etc/dracut.conf` configuration file. You can list the file contents of an " +"`initramfs` image file created by dracut by using the [command]#lsinitrd " +"_initramfs_file_pass:attributes[{blank}]# command:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:259 +#, no-wrap +msgid "" +"~]# lsinitrd /boot/initramfs-3.17.7-300.fc21.x86_64.img\n" +"Image: /boot/initramfs-3.17.7-300.fc21.x86_64.img: 18M\n" +"========================================================================\n" +"Version: dracut-038-31.git20141204.fc21\n" +"[output truncated]\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:262 +msgid "" +"See [command]#man dracut# and [command]#man dracut.conf# for more " +"information on options and usage." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:264 +msgid "" +"Examine the `/boot/grub2/grub.cfg` configuration file to ensure that an " +"`initramfs-_kernel_version_.img` file exists for the kernel version you are " +"booting. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:271 +#, no-wrap +msgid "" +"~]# grep initramfs /boot/grub2/grub.cfg\n" +"\tinitrd16 /initramfs-3.17.7-300.fc21.x86_64.img\n" +"\tinitrd16 /initramfs-3.17.6-300.fc21.x86_64.img\n" +"\tinitrd16 /initramfs-3.17.4-302.fc21.x86_64.img\n" +"\tinitrd16 /initramfs-0-rescue-db90b4e3715b42daa871351439343ca4.img\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:274 +msgid "" +"See xref:Manually_Upgrading_the_Kernel.adoc#s1-kernel-boot-loader[Verifying " +"the Boot Loader] for more information on how to read and update the " +"`/boot/grub2/grub.cfg` file." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:276 +#, no-wrap +msgid "Verifying the Initial RAM Disk Image and Kernel on IBM eServer System i" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:279 +msgid "" +"On IBM eServer System i machines, the initial RAM disk and kernel files are " +"combined into a single file, which is created with the [command]#addRamDisk# " +"command. This step is performed automatically if the kernel and its " +"associated packages are installed or upgraded from the RPM packages " +"distributed by {OSORG}; thus, it does not need to be executed manually. To " +"verify that it was created, run the following command as `root` to make sure " +"the `/boot/vmlinitrd-_kernel_version_pass:attributes[{blank}]` file already " +"exists:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:283 +#, no-wrap +msgid "[command]#ls -l /boot/#\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:286 +msgid "The _kernel_version_ should match the version of the kernel just installed." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:288 +#, no-wrap +msgid "Verifying the Boot Loader" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:291 +msgid "" +"indexterm:[boot loader,verifying] When you install a kernel using " +"[command]#rpm#, the kernel package creates an entry in the boot loader " +"configuration file for that new kernel. However, [command]#rpm# does *not* " +"configure the new kernel to boot as the default kernel. You must do this " +"manually when installing a new kernel with [command]#rpm#." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:293 +msgid "" +"It is always recommended to double-check the boot loader configuration file " +"after installing a new kernel with [command]#rpm# to ensure that the " +"configuration is correct. Otherwise, the system might not be able to boot " +"into {MAJOROS} properly. If this happens, boot the system with the boot " +"media created earlier and re-configure the boot loader." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:295 +msgid "" +"In the following table, find your system's architecture to determine the " +"boot loader it uses, and then click on the \"`See`\" link to jump to the " +"correct instructions for your system." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:297 +#, no-wrap +msgid "Boot loaders by architecture" +msgstr "" + +#. type: Table +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:307 +#, no-wrap +msgid "" +"|Architecture|Boot Loader|See\n" +"|x86|GRUB 2|xref:Manually_Upgrading_the_Kernel.adoc#s3-kernel-boot-loader-grub[Configuring " +"the GRUB 2 Boot Loader]\n" +"|AMD AMD64 *or* Intel " +"64|GRUB 2|xref:Manually_Upgrading_the_Kernel.adoc#s3-kernel-boot-loader-grub[Configuring " +"the GRUB 2 Boot Loader]\n" +"|IBM eServer System i|OS/400|xref:Manually_Upgrading_the_Kernel.adoc#s2-kernel-boot-loader-iseries[Configuring " +"the OS/400 Boot Loader]\n" +"|IBM eServer System p|YABOOT|xref:Manually_Upgrading_the_Kernel.adoc#s2-kernel-boot-loader-pseries[Configuring " +"the YABOOT Boot Loader]\n" +"|IBM System z|z/IPL|—\n" +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:310 +#, no-wrap +msgid "Configuring the GRUB 2 Boot Loader" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:313 +msgid "" +"indexterm:[GRUB 2 boot loader,configuring]indexterm:[GRUB 2 boot " +"loader,configuration file] {MAJOROSVER} is distributed with GRUB 2, which " +"reads its configuration from the `/boot/grub2/grub.cfg` file. This file is " +"generated by the [application]*grub2-mkconfig* utility based on Linux " +"kernels located in the `/boot` directory, template files located in " +"`/etc/grub.d/`, and custom settings in the `/etc/default/grub` file and is " +"automatically updated each time you install a new kernel from an RPM " +"package. To update this configuration file manually, type the following at a " +"shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:317 +#, no-wrap +msgid "[command]#grub2-mkconfig# [option]`-o` [option]`/boot/grub2/grub.cfg`\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:320 +msgid "" +"Among various code snippets and directives, the `/boot/grub2/grub.cfg` " +"configuration file contains one or more `menuentry` blocks, each " +"representing a single GRUB 2 boot menu entry. These blocks always start with " +"the `menuentry` keyword followed by a title, list of options, and opening " +"curly bracket, and end with a closing curly bracket. Anything between the " +"opening and closing bracket should be indented. For example, the following " +"is a sample `menuentry` block for Fedora 21 with Linux kernel " +"3.17.6-300.fc21.x86_64:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:337 +#, no-wrap +msgid "" +"menuentry 'Fedora (3.17.6-300.fc21.x86_64) 21 (Twenty One)' --class fedora " +"--class gnu-linux --class gnu --class os --unrestricted $menuentry_id_option " +"'gnulinux-3.17.4-301.fc21.x86_64-advanced-effee860-8d55-4e4a-995e-b4c88f9ac9f0' " +"{\n" +" load_video\n" +" set gfxpayload=keep\n" +" insmod gzio\n" +" insmod part_msdos\n" +" insmod ext2\n" +" set root='hd0,msdos1'\n" +" if [ x$feature_platform_search_hint = xy ]; then\n" +" search --no-floppy --fs-uuid --set=root --hint='hd0,msdos1' " +"f19c92f4-9ead-4207-b46a-723b7a2c51c8\n" +" else\n" +" search --no-floppy --fs-uuid --set=root " +"f19c92f4-9ead-4207-b46a-723b7a2c51c8\n" +" fi\n" +" linux16 /vmlinuz-3.17.6-300.fc21.x86_64 root=/dev/mapper/fedora-root " +"ro rd.lvm.lv=fedora/swap rd.lvm.lv=fedora/root rhgb quiet LANG=en_US.UTF-8\n" +" initrd16 /initramfs-3.17.6-300.fc21.x86_64.img\n" +"}\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:340 +msgid "" +"Each `menuentry` block that represents an installed Linux kernel contains " +"`linux` and `initrd` directives followed by the path to the kernel and the " +"`initramfs` image respectively. If a separate `/boot` partition was created, " +"the paths to the kernel and the `initramfs` image are relative to " +"`/boot`. In the example above, the `initrd16 " +"/initramfs-3.17.6-300.fc21.x86_64.img` line means that the `initramfs` image " +"is actually located at `/boot/initramfs-3.17.6-300.fc21.x86_64.img` when the " +"root file system is mounted, and likewise for the kernel path." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:342 +msgid "" +"The kernel version number as given on the `linux " +"/vmlinuz-_kernel_version_pass:attributes[{blank}]` line must match the " +"version number of the `initramfs` image given on the `initrd " +"/initramfs-_kernel_version_.img` line of each `menuentry` block. For more " +"information on how to verify the initial RAM disk image, refer to " +"xref:Manually_Upgrading_the_Kernel.adoc#procedure-Verifying_the_Initial_RAM_Disk_Image[Verifying " +"the Initial RAM Disk Image]." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:344 +#, no-wrap +msgid "The initrd directive in grub.cfg refers to an initramfs image" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:349 +msgid "" +"In `menuentry` blocks, the `initrd` directive must point to the location " +"(relative to the `/boot` directory if it is on a separate partition) of the " +"`initramfs` file corresponding to the same kernel version. This directive is " +"called `initrd` because the previous tool which created initial RAM disk " +"images, [command]#mkinitrd#, created what were known as `initrd` files. The " +"`grub.cfg` directive remains `initrd` to maintain compatibility with other " +"tools. The file-naming convention of systems using the [command]#dracut# " +"utility to create the initial RAM disk image is " +"`initramfs-_kernel_version_.img`." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:351 +msgid "" +"For information on using [application]*Dracut*, refer to " +"xref:kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc#sec-Verifying_the_Initial_RAM_Disk_Image[Verifying " +"the Initial RAM Disk Image]." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:355 +msgid "" +"After installing a new kernel with [command]#rpm#, verify that " +"`/boot/grub2/grub.cfg` is correct and reboot the computer into the new " +"kernel. Ensure your hardware is detected by watching the boot process " +"output. If GRUB 2 presents an error and is unable to boot into the new " +"kernel, it is often easiest to try to boot into an alternative or older " +"kernel so that you can fix the problem. Alternatively, use the boot media " +"you created earlier to boot the system." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:356 +#, no-wrap +msgid "Causing the GRUB 2 boot menu to display" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:361 +msgid "" +"If you set the [option]`GRUB_TIMEOUT` option in the `/etc/default/grub` file " +"to 0, GRUB 2 will not display its list of bootable kernels when the system " +"starts up. In order to display this list when booting, press and hold any " +"alphanumeric key while and immediately after BIOS information is displayed, " +"and GRUB 2 will present you with the GRUB menu." +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:365 +#, no-wrap +msgid "Configuring the OS/400 Boot Loader" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:368 +msgid "" +"indexterm:[OS/400 boot loader,configuring]indexterm:[OS/400 boot " +"loader,configuration file] The " +"`/boot/vmlinitrd-_kernel-version_pass:attributes[{blank}]` file is installed " +"when you upgrade the kernel. However, you must use the [command]#dd# command " +"to configure the system to boot the new kernel." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:370 +msgid "" +"As `root`, issue the command [command]#cat /proc/iSeries/mf/side# to " +"determine the default side (either A, B, or C)." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:372 +msgid "" +"As `root`, issue the following command, where _kernel-version_ is the " +"version of the new kernel and _side_ is the side from the previous command:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:376 +#, no-wrap +msgid "" +"[command]#dd if=/boot/vmlinitrd-_kernel-version_ " +"of=/proc/iSeries/mf/pass:attributes[{blank}]_side_pass:attributes[{blank}]/vmlinux " +"bs=8k#\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:379 +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:403 +msgid "" +"Begin testing the new kernel by rebooting the computer and watching the " +"messages to ensure that the hardware is detected properly." +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:381 +#, no-wrap +msgid "Configuring the YABOOT Boot Loader" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:384 +msgid "" +"IBM eServer System p uses YABOOT as its boot loader. YABOOT uses " +"`/etc/aboot.conf` as its configuration file. Confirm that the file contains " +"an `image` section with the same version as the [package]*kernel* package " +"just installed, and likewise for the `initramfs` image:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:399 +#, no-wrap +msgid "" +"boot=/dev/sda1 init-message=Welcome to {MAJOROS}! Hit <TAB> for boot " +"options\n" +"partition=2 timeout=30 install=/usr/lib/yaboot/yaboot delay=10 nonvram\n" +"image=/vmlinuz-2.6.32-17.EL\n" +"\t label=old\n" +"\t read-only\n" +"\t initrd=/initramfs-2.6.32-17.EL.img\n" +"\t append=\"root=LABEL=/\"\n" +"image=/vmlinuz-2.6.32-19.EL\n" +"\t label=linux\n" +"\t read-only\n" +"\t initrd=/initramfs-2.6.32-19.EL.img\n" +"\t append=\"root=LABEL=/\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc:402 +msgid "" +"Notice that the default is not set to the new kernel. The kernel in the " +"first image is booted by default. To change the default kernel to boot " +"either move its image stanza so that it is the first one listed or add the " +"directive `default` and set it to the `label` of the image stanza that " +"contains the new kernel." +msgstr "" diff --git a/pot/rawhide/pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.pot b/pot/rawhide/pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.pot new file mode 100644 index 00000000000..f71c5d4be06 --- /dev/null +++ b/pot/rawhide/pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.pot @@ -0,0 +1,1681 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:6 +#, no-wrap +msgid "Working with Kernel Modules" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:9 +msgid "" +"indexterm:[kernel module,definition]indexterm:[module,kernel " +"module]indexterm:[drivers,kernel module] The Linux kernel is modular, which " +"means it can extend its capabilities through the use of dynamically-loaded " +"_kernel modules_. A kernel module can provide:" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:11 +msgid "a device driver which adds support for new hardware; or," +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:13 +msgid "support for a file system such as `btrfs` or `NFS`." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:15 +msgid "" +"Like the kernel itself, modules can take parameters that customize their " +"behavior, though the default parameters work well in most cases. User-space " +"tools can list the modules currently loaded into a running kernel; query all " +"available modules for available parameters and module-specific information; " +"and load or unload (remove) modules dynamically into or from a running " +"kernel. Many of these utilities, which are provided by the [package]*kmod* " +"package, take module dependencies into account when performing operations so " +"that manual dependency-tracking is rarely necessary." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:17 +msgid "" +"On modern systems, kernel modules are automatically loaded by various " +"mechanisms when the conditions call for it. However, there are occasions " +"when it is necessary to load or unload modules manually, such as when one " +"module is preferred over another although either could provide basic " +"functionality, or when a module is misbehaving." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:19 +msgid "This chapter explains how to:" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:21 +msgid "" +"use the user-space [application]*kmod* utilities to display, query, load and " +"unload kernel modules and their dependencies;" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:23 +msgid "" +"set module parameters both dynamically on the command line and permanently " +"so that you can customize the behavior of your kernel modules; and," +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:25 +msgid "load modules at boot time." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:26 +#, no-wrap +msgid "Installing the kmod package" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:31 +msgid "" +"In order to use the kernel module utilities described in this chapter, first " +"ensure the [package]*kmod* package is installed on your system by running, " +"as root:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:35 +#, no-wrap +msgid "~]#{nbsp}dnf install kmod\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:39 +msgid "" +"For more information on installing packages with DNF, see " +"xref:package-management/DNF.adoc#sec-Installing[Installing Packages]." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:43 +#, no-wrap +msgid "Listing Currently-Loaded Modules" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:46 +msgid "" +"indexterm:[kernel module,listing,currently loaded modules]indexterm:[kernel " +"module,utilities,lsmod]indexterm:[lsmod,kernel module] You can list all " +"kernel modules that are currently loaded into the kernel by running the " +"[command]#lsmod# command, for example:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:82 +#, no-wrap +msgid "" +"~]$ lsmod\n" +"Module Size Used by\n" +"tcp_lp 12663 0\n" +"bnep 19704 2\n" +"bluetooth 372662 7 bnep\n" +"rfkill 26536 3 bluetooth\n" +"fuse 87661 3\n" +"ip6t_rpfilter 12546 1\n" +"ip6t_REJECT 12939 2\n" +"ipt_REJECT 12541 2\n" +"xt_conntrack 12760 7\n" +"ebtable_nat 12807 0\n" +"ebtable_broute 12731 0\n" +"bridge 110196 1 ebtable_broute\n" +"stp 12976 1 bridge\n" +"llc 14552 2 stp,bridge\n" +"ebtable_filter 12827 0\n" +"ebtables 30913 3 ebtable_broute,ebtable_nat,ebtable_filter\n" +"ip6table_nat 13015 1\n" +"nf_conntrack_ipv6 18738 5\n" +"nf_defrag_ipv6 34651 1 nf_conntrack_ipv6\n" +"nf_nat_ipv6 13279 1 ip6table_nat\n" +"ip6table_mangle 12700 1\n" +"ip6table_security 12710 1\n" +"ip6table_raw 12683 1\n" +"ip6table_filter 12815 1\n" +"ip6_tables 27025 5 " +"ip6table_filter,ip6table_mangle,ip6table_security,ip6table_nat,ip6table_raw\n" +"iptable_nat 13011 1\n" +"nf_conntrack_ipv4 14862 4\n" +"nf_defrag_ipv4 12729 1 nf_conntrack_ipv4\n" +"nf_nat_ipv4 13263 1 iptable_nat\n" +"nf_nat 21798 4 " +"nf_nat_ipv4,nf_nat_ipv6,ip6table_nat,iptable_nat\n" +"[output truncated]\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:85 +msgid "Each row of [command]#lsmod# output specifies:" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:87 +msgid "the name of a kernel module currently loaded in memory;" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:89 +msgid "the amount of memory it uses; and," +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:91 +msgid "" +"the sum total of processes that are using the module and other modules which " +"depend on it, followed by a list of the names of those modules, if there are " +"any. Using this list, you can first unload all the modules depending the " +"module you want to unload. For more information, see " +"xref:Working_with_Kernel_Modules.adoc#sec-Unloading_a_Module[Unloading a " +"Module]." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:94 +msgid "" +"indexterm:[kernel module,files,/proc/modules] Finally, note that " +"[command]#lsmod# output is less verbose and considerably easier to read than " +"the content of the `/proc/modules` pseudo-file." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:96 +#, no-wrap +msgid "Displaying Information About a Module" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:99 +msgid "" +"indexterm:[kernel module,listing,module information]indexterm:[kernel " +"module,utilities,modinfo]indexterm:[modinfo,kernel module] You can display " +"detailed information about a kernel module by running the " +"[command]#modinfo{nbsp}pass:attributes[{blank}]_module_name_pass:attributes[{blank}]# " +"command." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:101 +#, no-wrap +msgid "Module names do not end in .ko" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:106 +msgid "" +"When entering the name of a kernel module as an argument to one of the " +"[application]*kmod* utilities, do not append a `.ko` extension to the end of " +"the name. Kernel module names do not have extensions; their corresponding " +"files do." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:110 +#, no-wrap +msgid "Listing information about a kernel module with lsmod" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:114 +msgid "" +"To display information about the `e1000e` module, which is the Intel " +"PRO/1000 network driver, run:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:145 +#, no-wrap +msgid "" +"~]# modinfo e1000e\n" +"filename: " +"/lib/modules/3.17.4-302.fc21.x86_64/kernel/drivers/net/ethernet/intel/e1000e/e1000e.ko\n" +"version: 2.3.2-k\n" +"license: GPL\n" +"description: Intel(R) PRO/1000 Network Driver\n" +"author: Intel Corporation, \n" +"srcversion: 2FBED3F5E2EF40112284D95\n" +"alias: pci:v00008086d00001503sv*sd*bc*sc*i*\n" +"alias: pci:v00008086d00001502sv*sd*bc*sc*i*\n" +"[some alias lines omitted]\n" +"alias: pci:v00008086d0000105Esv*sd*bc*sc*i*\n" +"depends: ptp\n" +"intree: Y\n" +"vermagic: 3.17.4-302.fc21.x86_64 SMP mod_unload\n" +"signer: Fedora kernel signing key\n" +"sig_key: " +"1F:C9:E6:8F:74:19:55:63:48:FD:EE:2F:DE:B7:FF:9D:A6:33:7B:BF\n" +"sig_hashalgo: sha256\n" +"parm: debug:Debug level (0=none,...,16=all) (int)\n" +"parm: copybreak:Maximum size of packet that is copied to a new " +"buffer on receive (uint)\n" +"parm: TxIntDelay:Transmit Interrupt Delay (array of int)\n" +"parm: TxAbsIntDelay:Transmit Absolute Interrupt Delay (array of " +"int)\n" +"parm: RxIntDelay:Receive Interrupt Delay (array of int)\n" +"parm: RxAbsIntDelay:Receive Absolute Interrupt Delay (array of " +"int)\n" +"parm: InterruptThrottleRate:Interrupt Throttling Rate (array of " +"int)\n" +"parm: IntMode:Interrupt Mode (array of int)\n" +"parm: SmartPowerDownEnable:Enable PHY smart power down (array of " +"int)\n" +"parm: KumeranLockLoss:Enable Kumeran lock loss workaround (array " +"of int)\n" +"parm: WriteProtectNVM:Write-protect NVM [WARNING: disabling this " +"can lead to corrupted NVM] (array of int)\n" +"parm: CrcStripping:Enable CRC Stripping, disable if your BMC needs " +"the CRC (array of int)\n" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:150 +msgid "Here are descriptions of a few of the fields in [command]#modinfo# output:" +msgstr "" + +#. type: Labeled list +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:151 +#, no-wrap +msgid "filename" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:152 +msgid "" +"The absolute path to the `.ko` kernel object file. You can use " +"[command]#modinfo -n# as a shortcut command for printing only the `filename` " +"field." +msgstr "" + +#. type: Labeled list +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:153 +#, no-wrap +msgid "description" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:154 +msgid "" +"A short description of the module. You can use [command]#modinfo -d# as a " +"shortcut command for printing only the description field." +msgstr "" + +#. type: Labeled list +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:155 +#, no-wrap +msgid "alias" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:156 +msgid "" +"The `alias` field appears as many times as there are aliases for a module, " +"or is omitted entirely if there are none." +msgstr "" + +#. type: Labeled list +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:157 +#, no-wrap +msgid "depends" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:158 +msgid "" +"This field contains a comma-separated list of all the modules this module " +"depends on." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:160 +#, no-wrap +msgid "Omitting the depends field" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:165 +msgid "" +"If a module has no dependencies, the `depends` field may be omitted from the " +"output." +msgstr "" + +#. type: Labeled list +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:168 +#, no-wrap +msgid "parm" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:169 +msgid "" +"Each `parm` field presents one module parameter in the form " +"`pass:attributes[{blank}]_parameter_name_:pass:attributes[{blank}]_description_pass:attributes[{blank}]`, " +"where:" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:171 +msgid "" +"_parameter_name_ is the exact syntax you should use when using it as a " +"module parameter on the command line, or in an option line in a `.conf` file " +"in the `/etc/modprobe.d/` directory; and," +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:173 +msgid "" +"_description_ is a brief explanation of what the parameter does, along with " +"an expectation for the type of value the parameter accepts (such as `int`, " +"`unit` or `array of int`) in parentheses." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:175 +#, no-wrap +msgid "Listing module parameters" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:179 +msgid "" +"You can list all parameters that the module supports by using the " +"[option]`-p` option. However, because useful value type information is " +"omitted from [command]#modinfo -p# output, it is more useful to run:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:194 +#, no-wrap +msgid "" +"~]# modinfo e1000e | grep \"^parm\" | sort\n" +"parm: copybreak:Maximum size of packet that is copied to a new " +"buffer on receive (uint)\n" +"parm: CrcStripping:Enable CRC Stripping, disable if your BMC needs " +"the CRC (array of int)\n" +"parm: debug:Debug level (0=none,...,16=all) (int)\n" +"parm: InterruptThrottleRate:Interrupt Throttling Rate (array of " +"int)\n" +"parm: IntMode:Interrupt Mode (array of int)\n" +"parm: KumeranLockLoss:Enable Kumeran lock loss workaround (array " +"of int)\n" +"parm: RxAbsIntDelay:Receive Absolute Interrupt Delay (array of " +"int)\n" +"parm: RxIntDelay:Receive Interrupt Delay (array of int)\n" +"parm: SmartPowerDownEnable:Enable PHY smart power down (array of " +"int)\n" +"parm: TxAbsIntDelay:Transmit Absolute Interrupt Delay (array of " +"int)\n" +"parm: TxIntDelay:Transmit Interrupt Delay (array of int)\n" +"parm: WriteProtectNVM:Write-protect NVM [WARNING: disabling this " +"can lead to corrupted NVM] (array of int)\n" +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:199 +#, no-wrap +msgid "Loading a Module" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:202 +msgid "" +"indexterm:[kernel module,loading,for the current session]indexterm:[kernel " +"module,utilities,modprobe]indexterm:[modprobe,kernel module] To load a " +"kernel module, run [command]#modprobe _module_name_pass:attributes[{blank}]# " +"as `root`. For example, to load the `wacom` module, run:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:205 +#, no-wrap +msgid "~]# modprobe wacom\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:209 +msgid "" +"indexterm:[kernel " +"module,directories,/lib/modules/kernel_version/kernel/drivers/] By default, " +"[command]#modprobe# attempts to load the module from " +"`/lib/modules/pass:attributes[{blank}]_kernel_version_pass:attributes[{blank}]/kernel/drivers/`. " +"In this directory, each type of module has its own subdirectory, such as " +"`net/` and `scsi/`, for network and SCSI interface drivers respectively." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:211 +msgid "" +"Some modules have dependencies, which are other kernel modules that must be " +"loaded before the module in question can be loaded. The [command]#modprobe# " +"command always takes dependencies into account when performing " +"operations. When you ask [command]#modprobe# to load a specific kernel " +"module, it first examines the dependencies of that module, if there are any, " +"and loads them if they are not already loaded into the " +"kernel. [command]#modprobe# resolves dependencies recursively: it will load " +"all dependencies of dependencies, and so on, if necessary, thus ensuring " +"that all dependencies are always met." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:213 +msgid "" +"You can use the [option]`-v` (or [option]`--verbose`) option to cause " +"[command]#modprobe# to display detailed information about what it is doing, " +"which can include loading module dependencies." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:215 +#, no-wrap +msgid "modprobe -v shows module dependencies as they are loaded" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:219 +msgid "" +"You can load the `Fibre Channel over Ethernet` module verbosely by typing " +"the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:226 +#, no-wrap +msgid "" +"~]# modprobe -v fcoe\n" +"insmod " +"/lib/modules/3.17.4-302.fc21.x86_64/kernel/drivers/scsi/scsi_transport_fc.ko.xz\n" +"insmod " +"/lib/modules/3.17.4-302.fc21.x86_64/kernel/drivers/scsi/libfc/libfc.ko.xz\n" +"insmod " +"/lib/modules/3.17.4-302.fc21.x86_64/kernel/drivers/scsi/fcoe/libfcoe.ko.xz\n" +"insmod " +"/lib/modules/3.17.4-302.fc21.x86_64/kernel/drivers/scsi/fcoe/fcoe.ko.xz\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:229 +msgid "" +"In this example, you can see that [command]#modprobe# loaded the `scsi_tgt`, " +"`scsi_transport_fc`, `libfc` and `libfcoe` modules as dependencies before " +"finally loading `fcoe`. Also note that [command]#modprobe# used the more " +"primitive [command]#insmod# command to insert the modules into the running " +"kernel." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:232 +msgid "indexterm:[kernel module,utilities,insmod]indexterm:[insmod,kernel module]" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:234 +#, no-wrap +msgid "Always use modprobe instead of insmod!" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:239 +msgid "" +"Although the [command]#insmod# command can also be used to load kernel " +"modules, it does not resolve dependencies. Because of this, you should " +"*always* load modules using [command]#modprobe# instead." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:243 +#, no-wrap +msgid "Unloading a Module" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:246 +msgid "" +"indexterm:[kernel module,unloading]indexterm:[kernel " +"module,utilities,modprobe]indexterm:[modprobe,kernel module] You can unload " +"a kernel module by running [command]#modprobe -r " +"_module_name_pass:attributes[{blank}]# as `root`. For example, assuming that " +"the `wacom` module is already loaded into the kernel, you can unload it by " +"running:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:249 +#, no-wrap +msgid "~]# modprobe -r wacom\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:253 +msgid "However, this command will fail if a process is using:" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:255 +msgid "the `wacom` module;" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:257 +msgid "a module that `wacom` directly depends on, or;" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:259 +msgid "any module that `wacom`, through the dependency tree, depends on indirectly." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:261 +msgid "" +"See " +"xref:Working_with_Kernel_Modules.adoc#sec-Listing_Currently-Loaded_Modules[Listing " +"Currently-Loaded Modules] for more information about using [command]#lsmod# " +"to obtain the names of the modules which are preventing you from unloading a " +"certain module." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:263 +#, no-wrap +msgid "Unloading a kernel module" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:267 +msgid "" +"For example, if you want to unload the `firewire_ohci` module, your terminal " +"session might look similar to this:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:274 +#, no-wrap +msgid "" +"~]# modinfo -F depends firewire_ohci\n" +"firewire-core\n" +"~]# modinfo -F depends firewire_core\n" +"crc-itu-t\n" +"~]# modinfo -F depends crc-itu-t\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:278 +msgid "" +"You have figured out the dependency tree (which does not branch in this " +"example) for the loaded Firewire modules: `firewire_ohci` depends on " +"`firewire_core`, which itself depends on `crc-itu-t`." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:280 +msgid "" +"You can unload `firewire_ohci` using the [command]#modprobe -v -r " +"_module_name_pass:attributes[{blank}]# command, where [option]`-r` is short " +"for [option]`--remove` and [option]`-v` for [option]`--verbose`:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:286 +#, no-wrap +msgid "" +"~]# modprobe -r -v firewire_ohci\n" +"rmmod firewire_ohci\n" +"rmmod firewire_core\n" +"rmmod crc_itu_t\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:289 +msgid "" +"The output shows that modules are unloaded in the reverse order that they " +"are loaded, given that no processes depend on any of the modules being " +"unloaded." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:292 +msgid "indexterm:[kernel module,utilities,rmmod]indexterm:[rmmod,kernel module]" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:294 +#, no-wrap +msgid "Do not use rmmod directly!" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:299 +msgid "" +"Although the [command]#rmmod# command can be used to unload kernel modules, " +"it is recommended to use [command]#modprobe -r# instead." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:303 +#, no-wrap +msgid "Setting Module Parameters" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:306 +msgid "" +"indexterm:[module parameters,kernel module]indexterm:[kernel module,module " +"parameters,supplying] Like the kernel itself, modules can also take " +"parameters that change their behavior. Most of the time, the default ones " +"work well, but occasionally it is necessary or desirable to set custom " +"parameters for a module. Because parameters cannot be dynamically set for a " +"module that is already loaded into a running kernel, there are two different " +"methods for setting them." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:308 +msgid "" +"You can unload all dependencies of the module you want to set parameters " +"for, unload the module using [command]#modprobe -r#, and then load it with " +"[command]#modprobe# along with a list of customized parameters. This method " +"is often used when the module does not have many dependencies, or to test " +"different combinations of parameters without making them persistent, and is " +"the method covered in this section." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:310 +msgid "" +"Alternatively, you can list the new parameters in an existing or newly " +"created file in the `/etc/modprobe.d/` directory. This method makes the " +"module parameters persistent by ensuring that they are set each time the " +"module is loaded, such as after every reboot or [command]#modprobe# " +"command. This method is covered in " +"xref:Working_with_Kernel_Modules.adoc#sec-Persistent_Module_Loading[Persistent " +"Module Loading], though the following information is a prerequisite." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:312 +#, no-wrap +msgid "Supplying optional parameters when loading a kernel module" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:316 +msgid "" +"You can use [command]#modprobe# to load a kernel module with custom " +"parameters using the following command line format:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:320 +#, no-wrap +msgid "~]#{nbsp}modprobe{nbsp}module_name{nbsp}parameter=value\n" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:326 +msgid "" +"When loading a module with custom parameters on the command line, be aware " +"of the following:" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:328 +msgid "You can enter multiple parameters and values by separating them with spaces." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:330 +msgid "" +"Some module parameters expect a list of comma-separated values as their " +"argument. When entering the list of values, do *not* insert a space after " +"each comma, or [command]#modprobe# will incorrectly interpret the values " +"following spaces as additional parameters." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:332 +msgid "" +"The [command]#modprobe# command silently succeeds with an exit status of 0 " +"if:" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:334 +msgid "it successfully loads the module, *or*" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:336 +msgid "the module is *already* loaded into the kernel." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:338 +msgid "" +"Thus, you must ensure that the module is not already loaded before " +"attempting to load it with custom parameters. The [command]#modprobe# " +"command does not automatically reload the module, or alert you that it is " +"already loaded." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:340 +msgid "" +"Here are the recommended steps for setting custom parameters and then " +"loading a kernel module. This procedure illustrates the steps using the " +"`e1000e` module, which is the network driver for Intel PRO/1000 network " +"adapters, as an example:" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:342 +#, no-wrap +msgid "Loading a Kernel Module with Custom Parameters" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:344 +msgid "First, ensure the module is not already loaded into the kernel:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:349 +#, no-wrap +msgid "" +"~]#{nbsp}lsmod |grep e1000e\n" +"~]#{nbsp}\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:352 +msgid "" +"Output would indicate that the module is already loaded into the kernel, in " +"which case you must first unload it before proceeding. See " +"xref:Working_with_Kernel_Modules.adoc#sec-Unloading_a_Module[Unloading a " +"Module] for instructions on safely unloading it." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:354 +msgid "" +"Load the module and list all custom parameters after the module name. For " +"example, if you wanted to load the Intel PRO/1000 network driver with the " +"interrupt throttle rate set to 3000 interrupts per second for the first, " +"second, and third instances of the driver, and turn on debug, you would run, " +"as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:358 +#, no-wrap +msgid "~]#{nbsp}modprobe e1000e InterruptThrottleRate=3000,3000,3000 debug=1\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:362 +msgid "" +"This example illustrates passing multiple values to a single parameter by " +"separating them with commas and omitting any spaces between them." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:364 +#, no-wrap +msgid "Persistent Module Loading" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:367 +msgid "" +"indexterm:[kernel module,loading,at the boot time]indexterm:[kernel " +"module,directories,/etc/modules-load.d/] As shown in " +"xref:Working_with_Kernel_Modules.adoc#ex-Listing_information_about_a_kernel_module_with_lsmod[Listing " +"information about a kernel module with lsmod], many kernel modules are " +"loaded automatically at boot time. You can specify additional modules to be " +"loaded by the `systemd-modules-load.service` daemon by creating a " +"`pass:attributes[{blank}]_program_.conf` file in the `/etc/modules-load.d/` " +"directory, where _program_ is any descriptive name of your choice. The files " +"in `/etc/modules-load.d/` are text files that list the modules to be loaded, " +"one per line." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:369 +#, no-wrap +msgid "A Text File to Load a Module" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:373 +msgid "" +"To create a file to load the `virtio-net.ko` module, create a file " +"`/etc/modules-load.d/virtio-net.conf` with the following content:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:377 +#, no-wrap +msgid "" +"# Load virtio-net.ko at boot\n" +"virtio-net\n" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:382 +msgid "" +"See the `modules-load.d(5)` and `systemd-modules-load.service(8)` man pages " +"for more information." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:384 +#, no-wrap +msgid "Signing Kernel Modules for Secure Boot" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:387 +msgid "" +"Fedora includes support for the UEFI Secure Boot feature, which means that " +"Fedora can be installed and run on systems where UEFI Secure Boot is " +"enabled. footnote:[Fedora does not require the use of Secure Boot on UEFI " +"systems.] When Secure Boot is enabled, the EFI operating system boot " +"loaders, the Fedora kernel, and all kernel modules must be signed with a " +"private key and authenticated with the corresponding public key. The Fedora " +"distribution includes signed boot loaders, signed kernels, and signed kernel " +"modules. In addition, the signed first-stage boot loader and the signed " +"kernel include embedded Fedora public keys. These signed executable binaries " +"and embedded keys enable Fedora to install, boot, and run with the Microsoft " +"UEFI Secure Boot CA keys that are provided by the UEFI firmware on systems " +"that support UEFI Secure Boot.footnote:[Not all UEFI-based systems include " +"support for Secure Boot.]" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:389 +msgid "" +"The information provided in the following sections describes steps necessary " +"to enable you to self-sign privately built kernel modules for use with " +"Fedora on UEFI-based systems where Secure Boot is enabled. These sections " +"also provide an overview of available options for getting your public key " +"onto the target system where you want to deploy your kernel module." +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:391 +#, no-wrap +msgid "Prerequisites" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:394 +msgid "" +"In order to enable signing of externally built modules, the tools listed in " +"the following table are required to be installed on the system." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:396 +#, no-wrap +msgid "Required Tools" +msgstr "" + +#. type: Table +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:405 +#, no-wrap +msgid "" +"|Tool|Provided by Package|Used on|Purpose\n" +"|[command]#openssl#|[package]*openssl*|Build system|Generates public and " +"private X.509 key pair\n" +"|[command]#sign-file#|[package]*kernel-devel*|Build system|C application " +"used to sign kernel modules\n" +"|[command]#mokutil#|[package]*mokutil*|Target system|Optional tool used to " +"manually enroll the public key\n" +"|[command]#keyctl#|[package]*keyutils*|Target system|Optional tool used to " +"display public keys in the system key ring\n" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:411 +msgid "" +"Note that the build system, where you build and sign your kernel module, " +"does not need to have UEFI Secure Boot enabled and does not even need to be " +"a UEFI-based system." +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:415 +#, no-wrap +msgid "Kernel Module Authentication" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:418 +msgid "" +"In Fedora, when a kernel module is loaded, the module's signature is checked " +"using the public X.509 keys on the kernel's system key ring, excluding those " +"keys that are on the kernel's system black list key ring." +msgstr "" + +#. type: Title ==== +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:420 +#, no-wrap +msgid "Sources For Public Keys Used To Authenticate Kernel Modules" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:423 +msgid "" +"During boot, the kernel loads X.509 keys into the system key ring or the " +"system black list key ring from a set of persistent key stores as shown in " +"xref:Working_with_Kernel_Modules.adoc#table-sources-for-system-key-rings[Sources " +"For System Key Rings]" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:425 +#, no-wrap +msgid "Sources For System Key Rings" +msgstr "" + +#. type: Table +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:431 +#, no-wrap +msgid "" +"|Source of X.509 Keys|User Ability to Add Keys|UEFI Secure Boot State|Keys " +"Loaded During Boot\n" +"|Embedded in kernel|No|-|`.system_keyring`\n" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:431 +#, no-wrap +msgid "2+|UEFI Secure Boot \"`db`\"" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:432 +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:436 +#, no-wrap +msgid "2+|Limited" +msgstr "" + +#. type: Table +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:435 +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:439 +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:443 +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:447 +msgid "|Not enabled|No |Enabled|`.system_keyring`" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:435 +#, no-wrap +msgid "2+|UEFI Secure Boot \"`dbx`\"" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:439 +#, no-wrap +msgid "2+|Embedded in `shim.efi` boot loader" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:440 +#, no-wrap +msgid "2+|No" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:443 +#, no-wrap +msgid "2+|Machine Owner Key (MOK) list" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:444 +#, no-wrap +msgid "2+|Yes" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:450 +msgid "" +"Note that if the system is not UEFI-based or if UEFI Secure Boot is not " +"enabled, then only the keys that are embedded in the kernel are loaded onto " +"the system key ring and you have no ability to augment that set of keys " +"without rebuilding the kernel. The system black list key ring is a list of " +"X.509 keys which have been revoked. If your module is signed by a key on the " +"black list then it will fail authentication even if your public key is in " +"the system key ring." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:452 +msgid "To confirm if Secure Boot is enabled, enter a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:457 +#, no-wrap +msgid "" +"~]$ [command]#mokutil --sb-state#\n" +"SecureBoot enabled\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:460 +msgid "" +"If Secure Boot is not enabled then the message `Failed to read SecureBoot` " +"is displayed." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:462 +msgid "" +"You can display information about the keys on the system key rings using the " +"[command]#keyctl# utility. The following is abbreviated example output from " +"a Fedora system where UEFI Secure Boot is not enabled." +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:468 +#, no-wrap +msgid "" +"~]#{nbsp}keyctl list %:.builtin_trusted_keys\n" +"1 key in keyring:\n" +"265061799: ---lswrv 0 0 asymmetric: Fedora kernel signing key: " +"ba8e2919f98f3f8e2e27541cde0d1f...\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:471 +msgid "" +"The following is abbreviated example output from a Fedora system where UEFI " +"Secure Boot is enabled." +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:481 +#, no-wrap +msgid "" +"~]#{nbsp}keyctl list %:.builtin_trusted_keys\n" +" 5 keys in keyring:\n" +" ...asymmetric: Microsoft Windows Production PCA 2011: a92902398e16c497...\n" +" ...asymmetric: Fedora kernel signing key: ba8e2919f98f3f8e2e27541cde0d...\n" +" ...asymmetric: Fedora Secure Boot CA: fde32599c2d61db1bf5807335d7b20e4...\n" +" ...asymmetric: Red Hat Test Certifying CA: 08a0ef5800cb02fb587c12b4032...\n" +" ...asymmetric: Microsoft Corporation UEFI CA 2011: 13adbf4309bd82709c8...\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:484 +msgid "" +"The above output shows the addition of two keys from the UEFI Secure Boot " +"\"`db`\" keys plus the `Fedora Secure Boot CA` which is embedded in the " +"`shim.efi` boot loader." +msgstr "" + +#. type: Title ==== +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:486 +#, no-wrap +msgid "Kernel Module Authentication Requirements" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:489 +msgid "" +"If UEFI Secure Boot is enabled or if the [option]`module.sig_enforce` kernel " +"parameter has been specified, then only signed kernel modules that are " +"authenticated using a key on the system key ring can be successfully " +"loaded.footnote:[Provided that the public key is not on the system black " +"list key ring.] If UEFI Secure Boot is disabled and if the " +"[option]`module.sig_enforce` kernel parameter has not been specified, then " +"unsigned kernel modules and signed kernel modules without a public key can " +"be successfully loaded. This is summarized in " +"xref:Working_with_Kernel_Modules.adoc#table-kernel-module-authentication-requirements-for-loading[Kernel " +"Module Authentication Requirements for Loading]." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:491 +#, no-wrap +msgid "Kernel Module Authentication Requirements for Loading" +msgstr "" + +#. type: Table +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:496 +#, no-wrap +msgid "" +"|Module Signed|Public Key Found and Signature Valid|UEFI Secure Boot " +"State|module.sig_enforce|Module Load|Kernel Tainted\n" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:496 +#, no-wrap +msgid "3+|Unsigned" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:497 +#, no-wrap +msgid "3+|-" +msgstr "" + +#. type: Table +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:501 +msgid "" +"|Not enabled|Not enabled|Succeeds|Yes |Not enabled|Enabled|Fails| " +"|Enabled|-|Fails|-" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:501 +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:506 +#, no-wrap +msgid "3+|Signed" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:502 +#, no-wrap +msgid "3+|No" +msgstr "" + +#. type: Table +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:506 +msgid "" +"|Not enabled|Not enabled|Succeeds|Yes |Not enabled|Enabled|Fails|- " +"|Enabled|-|Fails|-" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:507 +#, no-wrap +msgid "3+|Yes" +msgstr "" + +#. type: Table +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:511 +msgid "" +"|Not enabled|Not enabled|Succeeds|No |Not enabled|Enabled|Succeeds|No " +"|Enabled|-|Succeeds|No" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:514 +msgid "" +"Subsequent sections will describe how to generate a public and private X.509 " +"key pair, how to use the private key to sign a kernel module, and how to " +"enroll the public key into a source for the system key ring." +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:516 +#, no-wrap +msgid "Generating a Public and Private X.509 Key Pair" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:519 +msgid "" +"You need to generate a public and private X.509 key pair that will be used " +"to sign a kernel module after it has been built. The corresponding public " +"key will be used to authenticate the kernel module when it is loaded." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:521 +msgid "" +"The [command]#openssl# tool can be used to generate a key pair that " +"satisfies the requirements for kernel module signing in Fedora. Some of the " +"parameters for this key generation request are best specified with a " +"configuration file; follow the example below to create your own " +"configuration file." +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:531 +#, no-wrap +msgid "" +"~]#{nbsp}cat << EOF > configuration_file.config\n" +"[ req ]\n" +"default_bits = 4096\n" +"distinguished_name = req_distinguished_name\n" +"prompt = no\n" +"string_mask = utf8only\n" +"x509_extensions = myexts\n" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:536 +#, no-wrap +msgid "" +"[ req_distinguished_name ]\n" +"O = pass:quotes[_Organization_]\n" +"CN = pass:quotes[_Organization signing key_]\n" +"emailAddress = pass:quotes[_E-mail address_]\n" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:543 +#, no-wrap +msgid "" +"[ myexts ]\n" +"basicConstraints=critical,CA:FALSE\n" +"keyUsage=digitalSignature\n" +"subjectKeyIdentifier=hash\n" +"authorityKeyIdentifier=keyid\n" +"EOF\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:546 +msgid "" +"After you have created the configuration file, you can create an X.509 " +"public and private key pair. The public key will be written to the " +"`pass:attributes[{blank}]_public_key_.der` file and the private key will be " +"written to the `pass:attributes[{blank}]_private_key_.priv` file." +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:553 +#, no-wrap +msgid "" +"~]#{nbsp}openssl req -x509 -new -nodes -utf8 -sha256 -days 36500 \\\n" +" -batch -config configuration_file.config -outform DER \\\n" +" -out public_key.der \\\n" +" -keyout private_key.priv\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:556 +msgid "" +"Enroll your public key on all systems where you want to authenticate and " +"load your kernel module." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:561 +msgid "" +"Take proper care to guard the contents of your private key. In the wrong " +"hands, the key could be used to compromise any system which has your public " +"key." +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:565 +#, no-wrap +msgid "Enrolling Public Key on Target System" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:568 +msgid "" +"When Fedora boots on a UEFI-based system with Secure Boot enabled, all keys " +"that are in the Secure Boot db key database, but not in the dbx database of " +"revoked keys, are loaded onto the system keyring by the kernel. The system " +"keyring is used to authenticate kernel modules." +msgstr "" + +#. type: Title ==== +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:570 +#, no-wrap +msgid "Factory Firmware Image Including Public Key" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:573 +msgid "" +"To facilitate authentication of your kernel module on your systems, consider " +"requesting your system vendor to incorporate your public key into the UEFI " +"Secure Boot key database in their factory firmware image." +msgstr "" + +#. type: Title ==== +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:575 +#, no-wrap +msgid "Executable Key Enrollment Image Adding Public Key" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:578 +msgid "" +"It is possible to add a key to an existing populated and active Secure Boot " +"key database. This can be done by writing and providing an EFI executable " +"*enrollment* image. Such an enrollment image contains a properly formed " +"request to append a key to the Secure Boot key database. This request must " +"include data that is properly signed by the private key that corresponds to " +"a public key that is already in the system's Secure Boot Key Exchange Key " +"(KEK) database. Additionally, this EFI image must be signed by a private key " +"that corresponds to a public key that is already in the key database." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:580 +msgid "" +"It is also possible to write an enrollment image that runs under " +"Fedora. However, the Fedora image must be properly signed by a private key " +"that corresponds to a public key that is already in the KEK database." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:582 +msgid "" +"The construction of either type of key enrollment images requires assistance " +"from the platform vendor." +msgstr "" + +#. type: Title ==== +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:584 +#, no-wrap +msgid "System Administrator Manually Adding Public Key to the MOK List" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:587 +msgid "" +"The Machine Owner Key (MOK) facility is a feature that is supported by " +"Fedora and can be used to augment the UEFI Secure Boot key database. When " +"Fedora boots on a UEFI-enabled system with Secure Boot enabled, the keys on " +"the MOK list are also added to the system keyring in addition to the keys " +"from the key database. The MOK list keys are also stored persistently and " +"securely in the same fashion as the Secure Boot key database keys, but these " +"are two separate facilities. The MOK facility is supported by shim.efi, " +"MokManager.efi, grubx64.efi, and the Fedora [command]#mokutil# utility." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:589 +msgid "" +"The major capability provided by the MOK facility is the ability to add " +"public keys to the MOK list without needing to have the key chain back to " +"another key that is already in the KEK database. However, enrolling a MOK " +"key requires manual interaction by a *physically present* user at the UEFI " +"system console on each target system. Nevertheless, the MOK facility " +"provides an excellent method for testing newly generated key pairs and " +"testing kernel modules signed with them." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:591 +msgid "Follow these steps to add your public key to the MOK list:" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:593 +msgid "" +"Request addition of your public key to the MOK list using a Fedora userspace " +"utility:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:597 +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:648 +#, no-wrap +msgid "~]#{nbsp}mokutil --import my_signing_key_pub.der\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:600 +msgid "" +"You will be asked to enter and confirm a password for this MOK enrollment " +"request." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:602 +msgid "Reboot the machine." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:604 +msgid "" +"The pending MOK key enrollment request will be noticed by `shim.efi` and it " +"will launch `MokManager.efi` to allow you to complete the enrollment from " +"the UEFI console. You will need to enter the password you previously " +"associated with this request and confirm the enrollment. Your public key is " +"added to the MOK list, which is persistent." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:606 +msgid "" +"Once a key is on the MOK list, it will be automatically propagated to the " +"system key ring on this and subsequent boots when UEFI Secure Boot is " +"enabled." +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:608 +#, no-wrap +msgid "Signing Kernel Module with the Private Key" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:611 +msgid "" +"There are no extra steps required to prepare your kernel module for " +"signing. You build your kernel module normally. Assuming an appropriate " +"Makefile and corresponding sources, follow these steps to build your module " +"and sign it:" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:613 +msgid "Build your `my_module.ko` module the standard way:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:617 +#, no-wrap +msgid "~]#{nbsp}make -C /usr/src/kernels/$(uname -r) M=$PWD modules\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:620 +msgid "" +"Sign your kernel module with your private key. This is done with a C " +"application. Note that the application requires that you provide both the " +"files that contain your private and the public key as well as the kernel " +"module file that you want to sign." +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:628 +#, no-wrap +msgid "" +"~]#{nbsp}/usr/src/kernels/$(uname -r)/scripts/sign-file \\\n" +" sha256 \\\n" +" my_signing_key.priv \\\n" +" my_signing_key_pub.der \\\n" +" my_module.ko\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:631 +msgid "" +"Your kernel module is in ELF image format and this application computes and " +"appends the signature directly to the ELF image in your `my_module.ko` " +"file. The [command]#modinfo# utility can be used to display information " +"about the kernel module's signature, if it is present. For information on " +"using the utility, see " +"xref:Working_with_Kernel_Modules.adoc#sec-Displaying_Information_About_a_Module[Displaying " +"Information About a Module]." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:633 +msgid "" +"Note that this appended signature is not contained in an ELF image section " +"and is not a formal part of the ELF image. Therefore, tools such as " +"[command]#readelf# will not be able to display the signature on your kernel " +"module." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:635 +msgid "" +"Your kernel module is now ready for loading. Note that your signed kernel " +"module is also loadable on systems where UEFI Secure Boot is disabled or on " +"a non-UEFI system. That means you do not need to provide both a signed and " +"unsigned version of your kernel module." +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:637 +#, no-wrap +msgid "Loading Signed Kernel Module" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:640 +msgid "" +"Once your public key is enrolled and is in the system keyring, the normal " +"kernel module loading mechanisms will work transparently. In the following " +"example, you will use [command]#mokutil# to add your public key to the MOK " +"list and you will manually load your kernel module with [command]#modprobe#." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:642 +msgid "" +"Optionally, you can verify that your kernel module will not load before you " +"have enrolled your public key. First, verify what keys have been added to " +"the system key ring on the current boot by running the [command]#keyctl list " +"%:.builtin_trusted_keys# as root. Since your public key has not been " +"enrolled yet, it should not be displayed in the output of the command." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:644 +msgid "Request enrollment of your public key." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:651 +msgid "Reboot, and complete the enrollment at the UEFI console." +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:655 +#, no-wrap +msgid "~]#{nbsp}reboot\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:658 +msgid "After the system reboots, verify the keys on the system key ring again." +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:662 +#, no-wrap +msgid "~]#{nbsp}keyctl list %:.builtin_trusted_keys\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:665 +msgid "You should now be able to load your kernel module successfully." +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:672 +#, no-wrap +msgid "" +"~]#{nbsp}modprobe -v my_module\n" +"insmod " +"/lib/modules/3.17.4-302.fc21.x86_64/extra/pass:quotes[_my_module_].ko\n" +"~]#{nbsp}lsmod | grep my_module\n" +"pass:quotes[_my_module_] 12425 0\n" +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:675 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:678 +msgid "" +"For more information on kernel modules and their utilities, see the " +"following resources." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:679 +#, no-wrap +msgid "Manual Page Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:682 +msgid "`lsmod(8)` — The manual page for the [command]#lsmod# command." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:684 +msgid "`modinfo(8)` — The manual page for the [command]#modinfo# command." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:686 +msgid "`modprobe(8)` — The manual page for the [command]#modprobe# command." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:688 +msgid "`rmmod(8)` — The manual page for the [command]#rmmod# command." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:690 +msgid "`ethtool(8)` — The manual page for the [command]#ethtool# command." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:692 +msgid "`mii-tool(8)` — The manual page for the [command]#mii-tool# command." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:693 +#, no-wrap +msgid "Installable and External Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_Kernel_Modules.adoc:695 +msgid "" +"link:++http://tldp.org/HOWTO/Module-HOWTO/++[Linux Loadable Kernel Module " +"HOWTO] — The [citetitle]_Linux Loadable Kernel Module HOWTO_ from the Linux " +"Documentation Project contains further information on working with kernel " +"modules." +msgstr "" diff --git a/pot/rawhide/pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.pot b/pot/rawhide/pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.pot new file mode 100644 index 00000000000..34adedc53c7 --- /dev/null +++ b/pot/rawhide/pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.pot @@ -0,0 +1,2245 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:5 +#, no-wrap +msgid "Working with the GRUB 2 Boot Loader" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:10 +#, no-wrap +msgid "**Editor’s Note**\n" +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:13 +msgid "" +"_This guide is deprecated!_ Large parts of it are no longer current and it " +"will not receive any updates. A series of shorter, topic-specific " +"documentation will gradually replace it. For additional information about " +"Grub version 2 on Fedora see " +"https://docs.fedoraproject.org/en-US/quick-docs/installing-grub2/[Bootloading " +"with GRUB2]." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:16 +msgid "" +"{MAJOROSVER} is distributed with the GNU GRand Unified Boot loader (GRUB) " +"version 2 boot loader, which allows the user to select an operating system " +"or kernel to be loaded at system boot time. GRUB 2 also allows the user to " +"pass arguments to the kernel." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:18 +#, no-wrap +msgid "Introduction to GRUB 2" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:21 +msgid "" +"GRUB 2 reads its configuration from the `/boot/grub2/grub.cfg` file. This " +"file contains menu information." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:23 +msgid "" +"The GRUB 2 configuration file, `grub.cfg`, is generated during installation, " +"or by invoking the [application]*/usr/sbin/grub2-mkconfig* utility, and is " +"automatically updated by [command]#grubby# each time a new kernel is " +"installed. When regenerated manually using [application]*grub2-mkconfig*, " +"the file is generated according to the template files located in " +"`/etc/grub.d/`, and custom settings in the `/etc/default/grub` file. Edits " +"of `grub.cfg` will be lost any time [application]*grub2-mkconfig* is used to " +"regenerate the file, so care must be taken to reflect any manual changes in " +"`/etc/default/grub` as well." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:25 +msgid "" +"Normal operations on `grub.cfg`, such as the removal and addition of new " +"kernels, should be done using the [command]#grubby# tool and, for scripts, " +"using [command]#new-kernel-pkg# tool. If you use [command]#grubby# to modify " +"the default kernel the changes will be inherited when new kernels are " +"installed. For more information on [command]#grubby#, see " +"xref:#sec-Making_Persistent_Changes_to_a_GRUB_2_Menu_Using_the_grubby_Tool[Making " +"Persistent Changes to a GRUB 2 Menu Using the grubby Tool]." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:27 +msgid "" +"The `/etc/default/grub` file is used by the [command]#grub2-mkconfig# tool, " +"which is used by `anaconda` when creating `grub.cfg` during the installation " +"process, and can be used in the event of a system failure, for example if " +"the boot loader configurations need to be recreated. In general, it is not " +"recommended to replace the `grub.cfg` file by manually running " +"`grub2-mkconfig` except as a last resort. Note that any manual changes to " +"`/etc/default/grub` require rebuilding the `grub.cfg` file." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:28 +#, no-wrap +msgid "Menu Entries in grub.cfg" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:30 +msgid "" +"Among various code snippets and directives, the `grub.cfg` configuration " +"file contains one or more `menuentry` blocks, each representing a single " +"GRUB 2 boot menu entry. These blocks always start with the `menuentry` " +"keyword followed by a title, list of options, and an opening curly bracket, " +"and end with a closing curly bracket. Anything between the opening and " +"closing bracket should be indented. For example, the following is a sample " +"`menuentry` block for {MAJOROSVER} with Linux kernel 3.17.4-301.fc21.x86_64:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:48 +#, no-wrap +msgid "" +"menuentry 'Fedora, with Linux 3.17.4-301.fc21.x86_64' --class fedora --class " +"gnu-linux --class gnu --class os --unrestricted $menuentry_id_option " +"'gnulinux-3.17.4-301.fc21.x86_64-advanced-effee860-8d55-4e4a-995e-b4c88f9ac9f0' " +"{\n" +" load_video\n" +" set gfxpayload=keep\n" +" insmod gzio\n" +" insmod part_msdos\n" +" insmod ext2\n" +" set root='hd0,msdos1'\n" +" if [ x$feature_platform_search_hint = xy ]; then\n" +" search --no-floppy --fs-uuid --set=root --hint='hd0,msdos1' " +"f19c92f4-9ead-4207-b46a-723b7a2c51c8\n" +" else\n" +" search --no-floppy --fs-uuid --set=root " +"f19c92f4-9ead-4207-b46a-723b7a2c51c8\n" +" fi\n" +" linux16 /vmlinuz-3.17.4-301.fc21.x86_64 root=/dev/mapper/fedora-root " +"ro rd.lvm.lv=fedora/swap rd.lvm.lv=fedora/root rhgb quiet LANG=en_US.UTF-8\n" +" initrd16 /initramfs-3.17.4-301.fc21.x86_64.img\n" +"}\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:52 +msgid "" +"Each `menuentry` block that represents an installed Linux kernel contains " +"`linux` on 64-bit IBM POWER Series, `linux16` on x86_64 BIOS-based systems, " +"and `linuxefi` on UEFI-based systems. Then the `initrd` directives followed " +"by the path to the kernel and the `initramfs` image respectively. If a " +"separate `/boot` partition was created, the paths to the kernel and the " +"`initramfs` image are relative to `/boot`. In the example above, the `initrd " +"/initramfs-3.17.4-301.fc21.x86_64.img` line means that the `initramfs` image " +"is actually located at `/boot/initramfs-3.17.4-301.fc21.x86_64.img` when the " +"`root` file system is mounted, and likewise for the kernel path." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:54 +msgid "" +"The kernel version number as given on the `linux16 /vmlinuz-kernel_version` " +"line must match the version number of the `initramfs` image given on the " +"`initrd /initramfs-kernel_version.img` line of each `menuentry` block. For " +"more information on how to verify the initial RAM disk image, see " +"xref:kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc#sec-Verifying_the_Initial_RAM_Disk_Image[Verifying " +"the Initial RAM Disk Image]." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:59 +msgid "" +"In `menuentry` blocks, the `initrd` directive must point to the location " +"(relative to the `/boot/` directory if it is on a separate partition) of the " +"`initramfs` file corresponding to the same kernel version. This directive is " +"called `initrd` because the previous tool which created initial RAM disk " +"images, [command]#mkinitrd#, created what were known as `initrd` files. The " +"`grub.cfg` directive remains `initrd` to maintain compatibility with other " +"tools. The file-naming convention of systems using the [command]#dracut# " +"utility to create the initial RAM disk image is " +"`initramfs-_kernel_version_.img`." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:61 +msgid "" +"For information on using [application]*Dracut*, see " +"xref:kernel-module-driver-configuration/Manually_Upgrading_the_Kernel.adoc#sec-Verifying_the_Initial_RAM_Disk_Image[Verifying " +"the Initial RAM Disk Image]." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:65 +#, no-wrap +msgid "Configuring the GRUB 2 Boot Loader" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:68 +msgid "" +"Changes to the GRUB 2 menu can be made temporarily at boot time, made " +"persistent for a single system while the system is running, or as part of " +"making a new GRUB 2 configuration file." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:70 +msgid "" +"To make non-persistent changes to the GRUB 2 menu, see " +"xref:#sec-Making_Temporary_Changes_to_a_GRUB_2_Menu[Making Temporary Changes " +"to a GRUB 2 Menu]." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:72 +msgid "" +"To make persistent changes to a running system, see " +"xref:#sec-Making_Persistent_Changes_to_a_GRUB_2_Menu_Using_the_grubby_Tool[Making " +"Persistent Changes to a GRUB 2 Menu Using the grubby Tool]." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:74 +msgid "" +"For information on making and customizing a GRUB 2 configuration file, see " +"xref:#sec-Customizing_the_GRUB_2_Configuration_File[Customizing the GRUB 2 " +"Configuration File]." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:76 +#, no-wrap +msgid "Making Temporary Changes to a GRUB 2 Menu" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:79 +#, no-wrap +msgid "Making Temporary Changes to a Kernel Menu Entry" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:81 +msgid "" +"To change kernel parameters only during a single boot process, proceed as " +"follows:" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:83 +msgid "" +"Start the system and, on the GRUB 2 boot screen, move the cursor to the menu " +"entry you want to edit, and press the kbd:[e] key for edit." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:85 +msgid "" +"Move the cursor down to find the kernel command line. The kernel command " +"line starts with `linux` on 64-Bit IBM Power Series, `linux16` on x86-64 " +"BIOS-based systems, or `linuxefi` on UEFI systems." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:87 +msgid "Move the cursor to the end of the line." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:89 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:718 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:738 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:800 +msgid "" +"Press kbd:[Ctrl + a] and kbd:[Ctrl + e] to jump to the start and end of the " +"line, respectively. On some systems, kbd:[Home] and kbd:[End] might also " +"work." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:91 +msgid "" +"Edit the kernel parameters as required. For example, to run the system in " +"emergency mode, add the *emergency* parameter at the end of the `linux16` " +"line:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:95 +#, no-wrap +msgid "" +"linux16 /vmlinuz-4.2.0-1.fc23.x86_64 root=/dev/mapper/fedora-root ro " +"rd.md=0 rd.dm=0 rd.lvm.lv=fedora/swap crashkernel=auto rd.luks=0 " +"vconsole.keymap=us rd.lvm.lv=fedora/root rhgb quiet " +"pass:quotes[*emergency*]\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:98 +msgid "" +"The [option]`rhgb` and [option]`quiet` parameters can be removed in order to " +"enable system messages." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:100 +msgid "" +"These settings are not persistent and apply only for a single boot. To make " +"persistent changes to a menu entry on a system, use the [command]#grubby# " +"tool. See " +"xref:#bh-Adding_and_Removing_Arguments_from_a_GRUB_Menu_Entry[Adding and " +"Removing Arguments from a GRUB Menu Entry] for more information on using " +"[command]#grubby#." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:102 +#, no-wrap +msgid "Making Persistent Changes to a GRUB 2 Menu Using the grubby Tool" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:105 +msgid "" +"The [command]#grubby# tool can be used to read information from, and make " +"persistent changes to, the `grub.cfg` file. It enables, for example, " +"changing GRUB menu entries to specify what arguments to pass to a kernel on " +"system start and changing the default kernel." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:107 +msgid "" +"In Red{nbsp}Hat Enterprise{nbsp}Linux{nbsp}7, if [command]#grubby# is " +"invoked manually without specifying a GRUB configuration file, it defaults " +"to searching for `/etc/grub2.cfg`, which is a symbolic link to the " +"`grub.cfg` file, whose location is architecture dependent. If that file " +"cannot be found it will search for an architecture dependent default." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:108 +#, no-wrap +msgid "Listing the Default Kernel" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:110 +msgid "To find out the file name of the default kernel, enter a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:114 +#, no-wrap +msgid "" +"~]# grubby --default-kernel\n" +"/boot/vmlinuz-4.2.0-1.fc23.x86_64\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:117 +msgid "" +"To find out the index number of the default kernel, enter a command as " +"follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:121 +#, no-wrap +msgid "" +"~]# grubby --default-index\n" +"0\n" +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:123 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:248 +#, no-wrap +msgid "Changing the Default Boot Entry" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:125 +msgid "" +"To make a persistent change in the kernel designated as the default kernel, " +"use the [command]#grubby# command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:128 +#, no-wrap +msgid "~]# grubby --set-default /boot/vmlinuz-4.2.0-1.fc23.x86_64\n" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:130 +#, no-wrap +msgid "Viewing the GRUB Menu Entry for a Kernel" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:132 +msgid "To list all the kernel menu entries, enter a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:136 +#, no-wrap +msgid "~]$ [command]#grubby --info=ALL#\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:139 +msgid "On UEFI systems, all [command]#grubby# commands must be entered as `root`." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:141 +msgid "" +"To view the GRUB menu entry for a specific kernel, enter a command as " +"follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:150 +#, no-wrap +msgid "" +"~]$ grubby --info /boot/vmlinuz-4.2.0-1.fc23.x86_64\n" +"index=0\n" +"kernel=/boot/vmlinuz-4.2.0-1.fc23.x86_64\n" +"args=\"ro rd.lvm.lv=fedora/root rd.lvm.lv=fedora/swap rhgb quiet " +"LANG=en_US.UTF-8\"\n" +"root=/dev/mapper/fedora-root\n" +"initrd=/boot/initramfs-4.2.0-1.fc23.x86_64.img\n" +"title=Fedora (4.2.0-1.fc23.x86_64) 23 (Workstation Edition)\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:153 +msgid "" +"Try tab completion to see the available kernels within the `/boot/` " +"directory." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:155 +#, no-wrap +msgid "Adding and Removing Arguments from a GRUB Menu Entry" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:157 +msgid "" +"The [option]`--update-kernel` option can be used to update a menu entry when " +"used in combination with [option]`--args` to add new arguments and " +"[option]`--remove-arguments` to remove existing arguments. These options " +"accept a quoted space-separated list. The command to simultaneously add and " +"remove arguments a from GRUB menu entry has the follow format:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:161 +#, no-wrap +msgid "" +"grubby --remove-args=\"pass:attributes[{blank}]_argX " +"argY_pass:attributes[{blank}]\" --args=\"pass:attributes[{blank}]_argA " +"argB_pass:attributes[{blank}]\" --update-kernel " +"/boot/pass:attributes[{blank}]_kernel_\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:164 +msgid "" +"To add and remove arguments from a kernel's GRUB menu entry, use a command " +"as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:167 +#, no-wrap +msgid "" +"~]# grubby --remove-args=\"rhgb quiet\" --args=console=ttyS0,115200 " +"--update-kernel /boot/vmlinuz-4.2.0-1.fc23.x86_64\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:170 +msgid "" +"This command removes the Red Hat graphical boot argument, enables boot " +"message to be seen, and adds a serial console. As the console arguments will " +"be added at the end of the line, the new console will take precedence over " +"any other consoles configured." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:172 +msgid "To review the changes, use the [option]`--info` command option as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:182 +#, no-wrap +msgid "" +"~]# grubby --info /boot/vmlinuz-4.2.0-1.fc23.x86_64\n" +"index=0\n" +"kernel=/boot/vmlinuz-4.2.0-1.fc23.x86_64\n" +"args=\"ro rd.lvm.lv=fedora/root rd.lvm.lv=fedora/swap LANG=en_US.UTF-8 " +"pass:quotes[*console=ttyS0,115200*]\"\n" +"root=/dev/mapper/fedora-root\n" +"initrd=/boot/initramfs-4.2.0-1.fc23.x86_64.img\n" +"title=Fedora (4.2.0-1.fc23.x86_64) 23 (Workstation Edition)\n" +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:184 +#, no-wrap +msgid "Updating All Kernel Menus with the Same Arguments" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:186 +msgid "" +"To add the same kernel boot arguments to all the kernel menu entries, enter " +"a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:189 +#, no-wrap +msgid "~]# grubby --update-kernel=ALL --args=console=ttyS0,115200\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:192 +msgid "" +"The [option]`--update-kernel` parameter also accepts DEFAULT or a comma " +"separated list of kernel index numbers." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:193 +#, no-wrap +msgid "Changing a Kernel Argument" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:195 +msgid "" +"To change a value in an existing kernel argument, specify the argument " +"again, changing the value as required. For example, if the virtual console " +"font size has been set to `latarcyrheb-sun16` and you want to change the " +"virtual console font size to `32`, use a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:205 +#, no-wrap +msgid "" +"~]# grubby --args=vconsole.font=latarcyrheb-sun32 --update-kernel " +"/boot/vmlinuz-4.2.0-1.fc23.x86_64\n" +"index=0\n" +"kernel=/boot/vmlinuz-4.2.0-1.fc23.x86_64\n" +"args=\"ro rd.lvm.lv=fedora/root crashkernel=auto rd.lvm.lv=fedora/swap " +"vconsole.font=pass:quotes[*latarcyrheb-sun32*] vconsole.keymap=us " +"LANG=en_US.UTF-8\"\n" +"root=/dev/mapper/fedora-root\n" +"initrd=/boot/initramfs-4.2.0-1.fc23.x86_64.img\n" +"title=Fedora (4.2.0-1.fc23.x86_64) 23 (Workstation Edition)\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:208 +msgid "See the `grubby(8)` manual page for more command options." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:209 +#, no-wrap +msgid "Adding a new entry with additional kernel arguments" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:211 +msgid "" +"To add a new entry with the default kernel but with additional kernel " +"arguments and make it the default entry, use:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:215 +#, no-wrap +msgid "" +"~]# grubby --add-kernel $(grubby --default-kernel) --copy-default " +"--args=crashkernel=128M --title \"Default kernel with kdump support\" " +"--make-default\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:218 +msgid "In this example, we set the `crashkernel=128M` argument for kdump support." +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:220 +#, no-wrap +msgid "Customizing the GRUB 2 Configuration File" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:223 +msgid "" +"GRUB 2 scripts search the user's computer and build a boot menu based on " +"what operating systems the scripts find. To reflect the latest system boot " +"options, the boot menu is rebuilt automatically when the kernel is updated " +"or a new kernel is added." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:225 +msgid "" +"However, users may want to build a menu containing specific entries or to " +"have the entries in a specific order. GRUB 2 allows basic customization of " +"the boot menu to give users control of what actually appears on the screen." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:227 +msgid "" +"GRUB 2 uses a series of scripts to build the menu; these are located in the " +"`/etc/grub.d/` directory. The following files are included:" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:229 +msgid "`00_header`, which loads GRUB 2 settings from the `/etc/default/grub` file." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:231 +msgid "" +"`01_users`, which is created only when a boot loader password is assigned in " +"a [application]*kickstart* file." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:233 +msgid "`10_linux`, which locates kernels in the default partition of Fedora." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:235 +msgid "" +"`30_os-prober`, which builds entries for operating systems found on other " +"partitions." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:237 +msgid "" +"`40_custom`, a template, which can be used to create additional menu " +"entries." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:239 +msgid "" +"Scripts from the `/etc/grub.d/` directory are read in alphabetical order and " +"can be therefore renamed to change the boot order of specific menu entries." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:244 +msgid "" +"With the [option]`GRUB_TIMEOUT` key set to `0` in the `/etc/default/grub` " +"file, GRUB 2 does not display the list of bootable kernels when the system " +"starts up. In order to display this list when booting, press and hold any " +"alphanumeric key when the BIOS information is displayed; GRUB 2 will present " +"you with the GRUB menu." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:251 +msgid "" +"By default, the key for the `GRUB_DEFAULT` directive in the " +"`/etc/default/grub` file is the word `saved`. This instructs GRUB 2 to load " +"the kernel specified by the [option]`saved_entry` directive in the GRUB 2 " +"environment file, located at `/boot/grub2/grubenv`. You can set another GRUB " +"record to be the default, using the [command]#grub2-set-default# command, " +"which will update the GRUB 2 environment file." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:253 +msgid "" +"By default, the [option]`saved_entry` value is set to the name of latest " +"installed kernel of package type [package]*kernel*. This is defined in " +"`/etc/sysconfig/kernel` by the `UPDATEDEFAULT` and `DEFAULTKERNEL` " +"directives. The file can be viewed by the `root` user as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:260 +#, no-wrap +msgid "" +"~]#{nbsp}cat /etc/sysconfig/kernel\n" +"# UPDATEDEFAULT specifies if new-kernel-pkg should make\n" +"# new kernels the default\n" +"UPDATEDEFAULT=yes\n" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:263 +#, no-wrap +msgid "" +"# DEFAULTKERNEL specifies the default kernel package type\n" +"DEFAULTKERNEL=kernel-core\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:266 +msgid "" +"The `DEFAULTKERNEL` directive specifies what package type will be used as " +"the default. Installing a package of type [package]*kernel-debug* will not " +"change the default kernel while the `DEFAULTKERNEL` is set to package type " +"[package]*kernel*." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:268 +msgid "" +"GRUB 2 supports using a numeric value as the key for the " +"[option]`saved_entry` directive to change the default order in which the " +"operating systems are loaded. To specify which operating system should be " +"loaded first, pass its number to the [command]#grub2-set-default# " +"command. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:272 +#, no-wrap +msgid "~]#{nbsp}grub2-set-default pass:quotes[`2`]\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:275 +msgid "" +"Note that the position of a menu entry in the list is denoted by a number " +"starting with zero; therefore, in the example above, the third entry will be " +"loaded. This value will be overwritten by the name of the next kernel to be " +"installed." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:277 +msgid "" +"To force a system to always use a particular menu entry, use the menu entry " +"name as the key to the `GRUB_DEFAULT` directive in the `/etc/default/grub` " +"file. To list the available menu entries, run the following command as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:281 +#, no-wrap +msgid "~]#{nbsp}awk -F\\' '$1==\"menuentry \" {print $2}' /etc/grub2.cfg\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:284 +msgid "" +"The file name `/etc/grub2.cfg` is a symlink to the `grub.cfg` file, whose " +"location is architecture dependent. For reliability reasons, the symlink is " +"not used in other examples in this chapter. It is better to use absolute " +"paths when writing to a file, especially when repairing a system." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:286 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:306 +msgid "" +"Changes to `/etc/default/grub` require rebuilding the `grub.cfg` file as " +"follows:" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:288 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:308 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:418 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:498 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:597 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:644 +msgid "" +"On both UEFI-based and BIOS-based machines, issue the following command as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:292 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:312 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:422 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:502 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:601 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:648 +#, no-wrap +msgid "~]#{nbsp}grub2-mkconfig -o /boot/grub2/grub.cfg\n" +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:295 +#, no-wrap +msgid "Editing a Menu Entry" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:298 +msgid "" +"If required to prepare a new GRUB 2 file with different parameters, edit the " +"values of the `GRUB_CMDLINE_LINUX` key in the `/etc/default/grub` file. Note " +"that you can specify multiple parameters for the `GRUB_CMDLINE_LINUX` " +"key. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:301 +#, no-wrap +msgid "GRUB_CMDLINE_LINUX=\"console=tty0 console=ttyS0,9600n8\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:304 +msgid "" +"Where [option]`console=tty0` is the first virtual terminal and " +"[option]`console=ttyS0` is the serial terminal to be used." +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:315 +#, no-wrap +msgid "Adding a new Entry" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:318 +msgid "" +"When executing the [command]#grub2-mkconfig# command, GRUB 2 searches for " +"Linux kernels and other operating systems based on the files located in the " +"`/etc/grub.d/` directory. The `/etc/grub.d/10_linux` script searches for " +"installed Linux kernels on the same partition. The " +"`/etc/grub.d/30_os-prober` script searches for other operating systems. Menu " +"entries are also automatically added to the boot menu when updating the " +"kernel." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:320 +msgid "" +"The `40_custom` file located in the `/etc/grub.d/` directory is a template " +"for custom entries and looks as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:327 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:369 +#, no-wrap +msgid "" +"#!/bin/sh\n" +"exec tail -n +3 $0\n" +"# This file provides an easy way to add custom menu entries. Simply type " +"the\n" +"# menu entries you want to add after this comment. Be careful not to " +"change\n" +"# the 'exec tail' line above.\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:330 +msgid "" +"This file can be edited or copied. Note that as a minimum, a valid menu " +"entry must include at least the following:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:336 +#, no-wrap +msgid "" +"*menuentry* \"<Title>\"pass:attributes[{blank}]*{*\n" +"<Data>\n" +"*}*\n" +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:339 +#, no-wrap +msgid "Creating a Custom Menu" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:342 +msgid "" +"If you do not want menu entries to be updated automatically, you can create " +"a custom menu." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:347 +msgid "" +"Before proceeding, back up the contents of the `/etc/grub.d/` directory in " +"case you need to revert the changes later." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:354 +msgid "" +"Note that modifying the `/etc/default/grub` file does not have any effect on " +"creating custom menus." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:358 +msgid "" +"Copy the contents of `/boot/grub2/grub.cfg`. Put the content of the " +"`grub.cfg` into the `/etc/grub.d/40_custom` file below the existing header " +"lines. The executable part of the `40_custom` script has to be preserved." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:360 +msgid "" +"From the content put into the `/etc/grub.d/40_custom` file, only the " +"`menuentry` blocks are needed to create the custom menu. The " +"`/boot/grub2/grub.cfg` file might contain function specifications and other " +"content above and below the `menuentry` blocks. If you put these unnecessary " +"lines into the `40_custom` file in the previous step, erase them." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:362 +msgid "This is an example of a custom `40_custom` script:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:399 +#, no-wrap +msgid "" +"menuentry 'First custom entry' --class red --class gnu-linux --class gnu " +"--class os $menuentry_id_option " +"'gnulinux-4.2.0-1.fc23.x86_64-advanced-32782dd0-4b47-4d56-a740-2076ab5e5976' " +"{\n" +" load_video\n" +" set gfxpayload=keep\n" +" insmod gzio\n" +" insmod part_msdos\n" +" insmod xfs\n" +" set root='hd0,msdos1'\n" +" if [ x$feature_platform_search_hint = xy ]; then\n" +" search --no-floppy --fs-uuid --set=root --hint='hd0,msdos1' " +"7885bba1-8aa7-4e5d-a7ad-821f4f52170a\n" +" else\n" +" search --no-floppy --fs-uuid --set=root " +"7885bba1-8aa7-4e5d-a7ad-821f4f52170a\n" +" fi\n" +" linux16 /vmlinuz-4.2.0-1.fc23.x86_64 root=/dev/mapper/fedora-root ro " +"rd.lvm.lv=fedora/root vconsole.font=latarcyrheb-sun16 rd.lvm.lv=fedora/swap " +"vconsole.keymap=us crashkernel=auto rhgb quiet LANG=en_US.UTF-8\n" +" initrd16 /initramfs-4.2.0-1.fc23.x86_64.img\n" +"}\n" +"menuentry 'Second custom entry' --class red --class gnu-linux --class gnu " +"--class os $menuentry_id_option " +"'gnulinux-0-rescue-07f43f20a54c4ce8ada8b70d33fd001c-advanced-32782dd0-4b47-4d56-a740-2076ab5e5976' " +"{\n" +" load_video\n" +" insmod gzio\n" +" insmod part_msdos\n" +" insmod xfs\n" +" set root='hd0,msdos1'\n" +" if [ x$feature_platform_search_hint = xy ]; then\n" +" search --no-floppy --fs-uuid --set=root --hint='hd0,msdos1' " +"7885bba1-8aa7-4e5d-a7ad-821f4f52170a\n" +" else\n" +" search --no-floppy --fs-uuid --set=root " +"7885bba1-8aa7-4e5d-a7ad-821f4f52170a\n" +" fi\n" +" linux16 /vmlinuz-0-rescue-07f43f20a54c4ce8ada8b70d33fd001c " +"root=/dev/mapper/fedora-root ro rd.lvm.lv=fedora/root " +"vconsole.font=latarcyrheb-sun16 rd.lvm.lv=fedora/swap vconsole.keymap=us " +"crashkernel=auto rhgb quiet\n" +" initrd16 /initramfs-0-rescue-07f43f20a54c4ce8ada8b70d33fd001c.img\n" +"}\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:402 +msgid "Remove all files from the `/etc/grub.d` directory except the following:" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:404 +msgid "`00_header`," +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:406 +msgid "`40_custom`," +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:408 +msgid "`01_users` (if it exists)," +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:410 +msgid "and `README`." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:412 +msgid "" +"Alternatively, if you want to keep the files in the `/etc/grub2.d/` " +"directory, make them unexecutable by running the [command]#chmod a-x " +"# command." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:414 +msgid "Edit, add, or remove menu entries in the `40_custom` file as desired." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:416 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:496 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:595 +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:642 +msgid "" +"Rebuild the `grub.cfg` file by running the [command]#grub2-mkconfig -o# " +"command as follows:" +msgstr "" + +#. type: Title == +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:425 +#, no-wrap +msgid "GRUB 2 Password Protection" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:428 +msgid "" +"GRUB 2 supports both plain-text and encrypted passwords in the GRUB 2 " +"template files. To enable the use of passwords, specify a superuser who can " +"reach the protected entries. Other users can be specified to access these " +"entries as well. Menu entries can be password-protected for booting by " +"adding one or more users to the menu entry as described in " +"xref:#sec-Setting_Up_Users_and_Password_Protection_Specifying_Menu_Entries[Setting " +"Up Users and Password Protection, Specifying Menu Entries]. To use encrypted " +"passwords, see xref:#sec-Password_Encryption[Password Encryption]." +msgstr "" + +#. type: delimited block = +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:433 +msgid "" +"If you do not use the correct format for the menu, or modify the " +"configuration in an incorrect way, you might be unable to boot your system." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:437 +msgid "" +"All menu entries can be password-protected against changes by setting " +"superusers, which can be done in the `/etc/grub.d/00_header` or the " +"`/etc/grub.d/01_users` file. The `00_header` file is very complicated and, " +"if possible, avoid making modifications in this file. Menu entries should be " +"placed in the `/etc/grub.d/40_custom` and users in the " +"`/etc/grub.d/01_users` file. The `01_users` file is generated by the " +"installation application [application]*anaconda* when a grub boot loader " +"password is used in a [application]*kickstart* template (but it should be " +"created and used it if it does not exist). Examples in this section adopt " +"this policy." +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:439 +#, no-wrap +msgid "Setting Up Users and Password Protection, Specifying Menu Entries" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:442 +msgid "" +"To specify a superuser, add the following lines in the " +"`/etc/grub.d/01_users` file, where `john` is the name of the user designated " +"as the superuser, and `johnspassword` is the superuser's password:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:449 +#, no-wrap +msgid "" +"cat <<EOF\n" +"set superusers=\"john\"\n" +"password john johnspassword\n" +"EOF\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:452 +msgid "" +"To allow other users to access the menu entries, add additional lines per " +"user at the end of the `/etc/grub.d/01_users` file." +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:460 +#, no-wrap +msgid "" +"cat <<EOF\n" +"set superusers=\"john\"\n" +"password john johnspassword\n" +"password jane janespassword\n" +"EOF\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:463 +msgid "" +"When the users and passwords are set up, specify the menu entries that " +"should be password-protected in the `/etc/grub.d/40_custom` file in a " +"similar fashion to the following:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:471 +#, no-wrap +msgid "" +"menuentry 'Red{nbsp}Hat Enterprise{nbsp}Linux Server' --unrestricted {\n" +"set root=(hd0,msdos1)\n" +"linux /vmlinuz\n" +"}\n" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:476 +#, no-wrap +msgid "" +"menuentry 'Fedora' --users jane {\n" +"set root=(hd0,msdos2)\n" +"linux /vmlinuz\n" +"}\n" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:481 +#, no-wrap +msgid "" +"menuentry 'Red{nbsp}Hat Enterprise{nbsp}Linux Workstation' {\n" +"set root=(hd0,msdos3)\n" +"linux /vmlinuz\n" +"}\n" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:484 +msgid "In the above example:" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:486 +msgid "" +"`john` is the `superuser` and can therefore boot any menu entry, use the " +"GRUB 2 command line, and edit items of the GRUB 2 menu during boot. In this " +"case, `john` can access both Red{nbsp}Hat Enterprise{nbsp}Linux Server, " +"Fedora, and Red{nbsp}Hat Enterprise{nbsp}Linux Workstation. Note that only " +"`john` can access Red{nbsp}Hat Enterprise{nbsp}Linux Workstation because " +"neither the [option]`--users` nor [option]`--unrestricted` options have been " +"used." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:488 +msgid "" +"User `jane` can boot Fedora since she was granted the permission in the " +"configuration." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:490 +msgid "" +"Anyone can boot Red{nbsp}Hat Enterprise{nbsp}Linux Server, because of the " +"[option]`--unrestricted` option, but only `john` can edit the menu entry as " +"a superuser has been defined. When a superuser is defined then all records " +"are protected against unauthorized changes and all records are protected for " +"booting if they do *not* have the [option]`--unrestricted` parameter" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:492 +msgid "" +"If you do not specify a user for a menu entry, or make use of the " +"[option]`--unrestricted` option, then only the superuser will have access to " +"the system." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:494 +msgid "" +"After you have made changes in the template file the GRUB 2 configuration " +"file must be updated." +msgstr "" + +#. type: Title === +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:505 +#, no-wrap +msgid "Password Encryption" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:508 +msgid "" +"By default, passwords are saved in plain text in GRUB 2 scripts. Although " +"the files cannot be accessed on boot without the correct password, security " +"can be improved by encrypting the password using the " +"[command]#grub2-mkpasswd-pbkdf2# command. This command converts a desired " +"password into a long hash, which is placed in the GRUB 2 scripts instead of " +"the plain-text password." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:510 +msgid "" +"To generate an encrypted password, run the [command]#grub2-mkpasswd-pbkdf2# " +"command on the command line as `root`." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:512 +msgid "" +"Enter the desired password when prompted and repeat it. The command then " +"outputs your password in an encrypted form." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:514 +msgid "" +"Copy the hash, and paste it in the template file where you configured the " +"users, that is, either in `/etc/grub.d/01_users` or `/etc/grub.d/40_custom`." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:516 +msgid "The following format applies for the `01_users` file:" +msgstr "" + +#. type: delimited block - +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:522 +#, no-wrap +msgid "" +"cat <` — This directory " +"contains information about using and configuring GRUB 2. `` " +"corresponds to the version of the GRUB 2 package installed." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:934 +msgid "" +"[command]#info grub2# — The GRUB 2 info page contains a tutorial, a " +"user reference manual, a programmer reference manual, and a FAQ document " +"about GRUB 2 and its usage." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:936 +msgid "" +"`grubby(8)` — The manual page for the command-line tool for configuring GRUB " +"and GRUB 2." +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:938 +msgid "" +"`new-kernel-pkg(8)` — The manual page for the tool to script kernel " +"installation." +msgstr "" + +#. type: Block title +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:939 +#, no-wrap +msgid "External Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader.adoc:941 +msgid "" +"link:++https://docs.fedoraproject.org/install-guide++[ {MAJOROS} " +"Installation Guide] — The Installation Guide provides basic " +"information on GRUB 2, for example, installation, terminology, interfaces, " +"and commands." +msgstr "" diff --git a/pot/rawhide/pages/kernel-module-driver-configuration/intro-kernel-module-driver-configuration.pot b/pot/rawhide/pages/kernel-module-driver-configuration/intro-kernel-module-driver-configuration.pot new file mode 100644 index 00000000000..52e3a68fe53 --- /dev/null +++ b/pot/rawhide/pages/kernel-module-driver-configuration/intro-kernel-module-driver-configuration.pot @@ -0,0 +1,30 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/kernel-module-driver-configuration/intro-kernel-module-driver-configuration.adoc:1 +#, no-wrap +msgid "Kernel, Module and Driver Configuration" +msgstr "" + +#. type: Plain text +#: ./pages/kernel-module-driver-configuration/intro-kernel-module-driver-configuration.adoc:3 +msgid "" +"This part covers various tools that assist administrators with kernel " +"customization." +msgstr "" diff --git a/pot/rawhide/pages/monitoring-and-automation/Automating_System_Tasks.pot b/pot/rawhide/pages/monitoring-and-automation/Automating_System_Tasks.pot new file mode 100644 index 00000000000..6e5dc8428da --- /dev/null +++ b/pot/rawhide/pages/monitoring-and-automation/Automating_System_Tasks.pot @@ -0,0 +1,1362 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:6 +#, no-wrap +msgid "Automating System Tasks" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:9 +msgid "" +"indexterm:[Automated Tasks] Tasks, also known as _jobs_, can be configured " +"to run automatically within a specified period of time, on a specified date, " +"or when the system load average decreases below 0.8." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:11 +msgid "" +"{MAJOROS} is pre-configured to run important system tasks to keep the system " +"updated. For example, the slocate database used by the [command]#locate# " +"command is updated daily. A system administrator can use automated tasks to " +"perform periodic backups, monitor the system, run custom scripts, and so on." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:13 +msgid "" +"{MAJOROS} comes with the following automated task utilities: " +"[command]#cron#, [command]#anacron#, [command]#at#, and [command]#batch#." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:15 +msgid "" +"Every utility is intended for scheduling a different job type: while Cron " +"and Anacron schedule recurring jobs, At and Batch schedule one-time jobs " +"(refer to xref:Automating_System_Tasks.adoc#s1-autotasks-cron-anacron[Cron " +"and Anacron] and xref:Automating_System_Tasks.adoc#s1-autotasks-at-batch[At " +"and Batch] respectively)." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:17 +msgid "" +"{MAJOROS} supports the use of `systemd.timer` for executing a job at a " +"specific time. See man `systemd.timer(5)` for more information." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:19 +#, no-wrap +msgid "Cron and Anacron" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:22 +msgid "" +"indexterm:[anacron]indexterm:[cron] Both Cron and Anacron can schedule " +"execution of recurring tasks to a certain point in time defined by the exact " +"time, day of the month, month, day of the week, and week." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:24 +msgid "" +"Cron jobs can run as often as every minute. However, the utility assumes " +"that the system is running continuously and if the system is not on at the " +"time when a job is scheduled, the job is not executed." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:26 +msgid "" +"On the other hand, Anacron remembers the scheduled jobs if the system is not " +"running at the time when the job is scheduled. The job is then executed as " +"soon as the system is up. However, Anacron can only run a job once a " +"day. Also note that by default, Anacron only runs when your system is " +"running on AC power and will not run if your system is being powered by a " +"battery; this behavior is set up in the " +"[filename]`/etc/cron.hourly/0anacron` script." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:28 +#, no-wrap +msgid "Installing Cron and Anacron" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:31 +msgid "" +"To install Cron and Anacron, you need to install the [package]*cronie* " +"package with Cron and the [package]*cronie-anacron* package with Anacron " +"([package]*cronie-anacron* is a sub-package of [package]*cronie*)." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:33 +msgid "" +"To determine if the packages are already installed on your system, issue the " +"following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:37 +#, no-wrap +msgid "[command]#rpm -q cronie cronie-anacron#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:40 +msgid "" +"The command returns full names of the [package]*cronie* and " +"[package]*cronie-anacron* packages if already installed, or notifies you " +"that the packages are not available." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:42 +msgid "" +"To install these packages, use the [command]#dnf# command in the following " +"form as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:46 +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:342 +#, no-wrap +msgid "[command]#dnf install _package_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:49 +msgid "" +"For example, to install both Cron and Anacron, type the following at a shell " +"prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:53 +#, no-wrap +msgid "~]#{nbsp}dnf install cronie cronie-anacron\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:56 +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:352 +msgid "" +"For more information on how to install new packages in {MAJOROS}, see " +"xref:package-management/DNF.adoc#sec-Installing[Installing Packages]." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:58 +#, no-wrap +msgid "Running the Crond Service" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:61 +msgid "" +"The cron and anacron jobs are both picked by the `crond` service. This " +"section provides information on how to start, stop, and restart the `crond` " +"service, and shows how to configure it to start automatically at boot time." +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:63 +#, no-wrap +msgid "Starting and Stopping the Cron Service" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:66 +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:362 +msgid "To determine if the service is running, use the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:70 +#, no-wrap +msgid "[command]#systemctl status crond.service#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:73 +msgid "" +"To run the `crond` service in the current session, type the following at a " +"shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:77 +#, no-wrap +msgid "[command]#systemctl start crond.service#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:80 +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:376 +msgid "" +"To configure the service to start automatically at boot time, use the " +"following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:84 +#, no-wrap +msgid "[command]#systemctl enable crond.service#\n" +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:87 +#, no-wrap +msgid "Stopping the Cron Service" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:90 +msgid "" +"To stop the `crond` service in the current session, type the following at a " +"shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:94 +#, no-wrap +msgid "[command]#systemctl stop crond.service#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:97 +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:400 +msgid "" +"To prevent the service from starting automatically at boot time, use the " +"following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:101 +#, no-wrap +msgid "[command]#systemctl disable crond.service#\n" +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:104 +#, no-wrap +msgid "Restarting the Cron Service" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:107 +msgid "" +"To restart the `crond` service, type the following at a shell prompt as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:111 +#, no-wrap +msgid "[command]#systemctl restart crond.service#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:114 +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:417 +msgid "This command stops the service and starts it again in quick succession." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:116 +#, no-wrap +msgid "Configuring Anacron Jobs" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:119 +msgid "" +"indexterm:[anacron,anacron configuration " +"file]indexterm:[anacrontab]indexterm:[anacron,user-defined " +"tasks]indexterm:[/var/spool/anacron] The main configuration file to schedule " +"jobs is the `/etc/anacrontab` file, which can be only accessed by the `root` " +"user. The file contains the following:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:128 +#, no-wrap +msgid "" +"SHELL=/bin/sh\n" +"PATH=/sbin:/bin:/usr/sbin:/usr/bin\n" +"MAILTO=root\n" +"# the maximal random delay added to the base delay of the jobs\n" +"RANDOM_DELAY=45\n" +"# the jobs will be started during the following hours only\n" +"START_HOURS_RANGE=3-22\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:133 +#, no-wrap +msgid "" +"#period in days delay in minutes job-identifier command\n" +"1 5 cron.daily nice run-parts /etc/cron.daily\n" +"7 25 cron.weekly nice run-parts /etc/cron.weekly\n" +"@monthly 45 cron.monthly nice run-parts /etc/cron.monthly\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:136 +msgid "" +"The first three lines define the variables that configure the environment in " +"which the anacron tasks run:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:138 +msgid "" +"`SHELL` — shell environment used for running jobs (in the example, the " +"Bash shell)" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:140 +msgid "`PATH` — paths to executable programs" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:142 +msgid "" +"`MAILTO` — username of the user who receives the output of the anacron " +"jobs by email" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:144 +msgid "If the `MAILTO` variable is not defined (`MAILTO=`), the email is not sent." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:146 +msgid "The next two variables modify the scheduled time for the defined jobs:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:148 +msgid "" +"`RANDOM_DELAY` — maximum number of minutes that will be added to the " +"`delay in minutes` variable which is specified for each job" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:150 +msgid "The minimum delay value is set, by default, to 6 minutes." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:152 +msgid "" +"If `RANDOM_DELAY` is, for example, set to `12`, then between 6 and 12 " +"minutes are added to the `delay in minutes` for each job in that particular " +"anacrontab. `RANDOM_DELAY` can also be set to a value below `6`, including " +"`0`. When set to `0`, no random delay is added. This proves to be useful " +"when, for example, more computers that share one network connection need to " +"download the same data every day." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:154 +msgid "" +"`START_HOURS_RANGE` — interval, when scheduled jobs can be run, in " +"hours" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:156 +msgid "" +"In case the time interval is missed, for example due to a power failure, the " +"scheduled jobs are not executed that day." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:158 +msgid "" +"The remaining lines in the `/etc/anacrontab` file represent scheduled jobs " +"and follow this format:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:163 +#, no-wrap +msgid "period in days delay in minutes job-identifier command\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:167 +msgid "`period in days` — frequency of job execution in days" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:169 +msgid "" +"The property value can be defined as an integer or a macro (`@daily`, " +"`@weekly`, `@monthly`), where `@daily` denotes the same value as integer 1, " +"`@weekly` the same as 7, and `@monthly` specifies that the job is run once a " +"month regardless of the length of the month." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:171 +msgid "" +"`delay in minutes` — number of minutes anacron waits before executing " +"the job" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:173 +msgid "" +"The property value is defined as an integer. If the value is set to `0`, no " +"delay applies." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:175 +msgid "" +"`job-identifier` — unique name referring to a particular job used in " +"the log files" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:177 +msgid "`command` — command to be executed" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:179 +msgid "" +"The command can be either a command such as [command]#ls /proc >> /tmp/proc# " +"or a command which executes a custom script." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:181 +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:272 +msgid "" +"Any lines that begin with a hash sign (#) are comments and are not " +"processed." +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:183 +#, no-wrap +msgid "Examples of Anacron Jobs" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:186 +msgid "The following example shows a simple `/etc/anacrontab` file:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:191 +#, no-wrap +msgid "" +"SHELL=/bin/sh\n" +"PATH=/sbin:/bin:/usr/sbin:/usr/bin\n" +"MAILTO=root\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:196 +#, no-wrap +msgid "" +"# the maximal random delay added to the base delay of the jobs\n" +"RANDOM_DELAY=30\n" +"# the jobs will be started during the following hours only\n" +"START_HOURS_RANGE=16-20\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:201 +#, no-wrap +msgid "" +"#period in days delay in minutes job-identifier command\n" +"1 20 dailyjob nice run-parts /etc/cron.daily\n" +"7 25 weeklyjob /etc/weeklyjob.bash\n" +"@monthly 45 monthlyjob ls /proc >> /tmp/proc\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:204 +msgid "" +"All jobs defined in this `anacrontab` file are randomly delayed by 6-30 " +"minutes and can be executed between 16:00 and 20:00." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:206 +msgid "" +"The first defined job is triggered daily between 16:26 and 16:50 " +"(RANDOM_DELAY is between 6 and 30 minutes; the `delay in minutes` property " +"adds 20 minutes). The command specified for this job executes all present " +"programs in the `/etc/cron.daily/` directory using the [command]#run-parts# " +"script (the [command]#run-parts# scripts accepts a directory as a " +"command-line argument and sequentially executes every program in the " +"directory). See the `run-parts` man page for more information on the " +"[command]#run-parts# script." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:208 +msgid "" +"The second job executes the `weeklyjob.bash` script in the `/etc/` directory " +"once a week." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:210 +msgid "" +"The third job runs a command, which writes the contents of `/proc` to the " +"`/tmp/proc` file ([command]#ls /proc >> /tmp/proc#) once a month." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:212 +#, no-wrap +msgid "Configuring Cron Jobs" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:215 +msgid "" +"indexterm:[cron,user-defined " +"tasks]indexterm:[/var/spool/cron]indexterm:[cron,cron configuration " +"file]indexterm:[crontab] The configuration file for cron jobs is " +"`/etc/crontab`, which can be only modified by the `root` user. The file " +"contains the following:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:230 +#, no-wrap +msgid "" +"SHELL=/bin/bash\n" +"PATH=/sbin:/bin:/usr/sbin:/usr/bin\n" +"MAILTO=root\n" +"HOME=/\n" +"# For details see man 4 crontabs\n" +"# Example of job definition:\n" +"# .---------------- minute (0 - 59)\n" +"# | .------------- hour (0 - 23)\n" +"# | | .---------- day of month (1 - 31)\n" +"# | | | .------- month (1 - 12) OR jan,feb,mar,apr ...\n" +"# | | | | .---- day of week (0 - 6) (Sunday=0 or 7) OR " +"sun,mon,tue,wed,thu,fri,sat\n" +"# | | | | |\n" +"# * * * * * user-name command to be executed\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:233 +msgid "" +"The first three lines contain the same variable definitions as an " +"`anacrontab` file: `SHELL`, `PATH`, and `MAILTO`. For more information about " +"these variables, see " +"xref:Automating_System_Tasks.adoc#s2-configuring-anacron-jobs[Configuring " +"Anacron Jobs]." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:235 +msgid "" +"In addition, the file can define the `HOME` variable. The `HOME` variable " +"defines the directory, which will be used as the home directory when " +"executing commands or scripts run by the job." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:237 +msgid "" +"The remaining lines in the `/etc/crontab` file represent scheduled jobs and " +"have the following format:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:241 +#, no-wrap +msgid "minute hour day month day of week username command\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:244 +msgid "The following define the time when the job is to be run:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:246 +msgid "`minute` — any integer from 0 to 59" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:248 +msgid "`hour` — any integer from 0 to 23" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:250 +msgid "" +"`day` — any integer from 1 to 31 (must be a valid day if a month is " +"specified)" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:252 +msgid "" +"`month` — any integer from 1 to 12 (or the short name of the month " +"such as jan or feb)" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:254 +msgid "" +"`day of week` — any integer from 0 to 7, where 0 or 7 represents " +"Sunday (or the short name of the week such as sun or mon)" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:256 +msgid "The following define other job properties:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:258 +msgid "`username` — specifies the user under which the jobs are run." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:260 +msgid "`command` — the command to be executed." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:262 +msgid "" +"The command can be either a command such as [command]#ls /proc /tmp/proc# or " +"a command which executes a custom script." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:264 +msgid "" +"For any of the above values, an asterisk (*) can be used to specify all " +"valid values. If you, for example, define the month value as an asterisk, " +"the job will be executed every month within the constraints of the other " +"values." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:266 +msgid "" +"A hyphen (-) between integers specifies a range of integers. For example, " +"`1-4` means the integers 1, 2, 3, and 4." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:268 +msgid "" +"A list of values separated by commas (,) specifies a list. For example, " +"`3,4,6,8` indicates exactly these four integers." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:270 +msgid "" +"The forward slash (/) can be used to specify step values. The value of an " +"integer will be skipped within a range following the range with " +"`/pass:attributes[{blank}]_integer_pass:attributes[{blank}]`. For example, " +"the minute value defined as `0-59/2` denotes every other minute in the " +"minute field. Step values can also be used with an asterisk. For instance, " +"if the month value is defined as `*/3`, the task will run every third month." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:274 +msgid "" +"Users other than `root` can configure cron tasks with the [command]#crontab# " +"utility. The user-defined crontabs are stored in the `/var/spool/cron/` " +"directory and executed as if run by the users that created them." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:276 +msgid "" +"To create a crontab as a specific user, login as that user and type the " +"command [command]#crontab -e# to edit the user's crontab with the editor " +"specified in the `VISUAL` or `EDITOR` environment variable. The file uses " +"the same format as `/etc/crontab`. When the changes to the crontab are " +"saved, the crontab is stored according to the user name and written to the " +"file " +"`/var/spool/cron/pass:attributes[{blank}]_username_pass:attributes[{blank}]`. " +"To list the contents of the current user's crontab file, use the " +"[command]#crontab -l# command." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:278 +msgid "" +"The `/etc/cron.d/` directory contains files that have the same syntax as the " +"`/etc/crontab` file. Only `root` is allowed to create and modify files in " +"this directory." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:279 +#, no-wrap +msgid "Do not restart the daemon to apply the changes" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:284 +msgid "" +"The cron daemon checks the `/etc/anacrontab` file, the `/etc/crontab` file, " +"the `/etc/cron.d/` directory, and the `/var/spool/cron/` directory every " +"minute for changes and the detected changes are loaded into memory. It is " +"therefore not necessary to restart the daemon after an anacrontab or a " +"crontab file have been changed." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:288 +#, no-wrap +msgid "Controlling Access to Cron" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:291 +msgid "" +"To restrict the access to Cron, you can use the `/etc/cron.allow` and " +"`/etc/cron.deny` files. These access control files use the same format with " +"one user name on each line. Mind that no whitespace characters are permitted " +"in either file." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:293 +msgid "" +"If the `cron.allow` file exists, only users listed in the file are allowed " +"to use cron, and the `cron.deny` file is ignored." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:295 +msgid "" +"If the `cron.allow` file does not exist, users listed in the `cron.deny` " +"file are not allowed to use Cron." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:297 +msgid "" +"The Cron daemon (`crond`) does not have to be restarted if the access " +"control files are modified. The access control files are checked each time a " +"user tries to add or delete a cron job." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:299 +msgid "" +"The `root` user can always use cron, regardless of the user names listed in " +"the access control files." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:301 +msgid "" +"You can control the access also through Pluggable Authentication Modules " +"(PAM). The settings are stored in the `/etc/security/access.conf` file. For " +"example, after adding the following line to the file, no other user but the " +"`root` user can create crontabs:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:305 +#, no-wrap +msgid "-:ALL EXCEPT root :cron\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:308 +msgid "" +"The forbidden jobs are logged in an appropriate log file or, when using " +"[command]#crontab -e#, returned to the standard output. For more " +"information, see the `access.conf.5` manual page." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:310 +#, no-wrap +msgid "Black and White Listing of Cron Jobs" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:313 +msgid "" +"Black and white listing of jobs is used to define parts of a job that do not " +"need to be executed. This is useful when calling the " +"[application]*run-parts* script on a Cron directory, such as " +"`/etc/cron.daily/`: if the user adds programs located in the directory to " +"the job black list, the [application]*run-parts* script will not execute " +"these programs." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:315 +msgid "" +"To define a black list, create a `jobs.deny` file in the directory that " +"[command]#run-parts# scripts will be executing from. For example, if you " +"need to omit a particular program from `/etc/cron.daily/`, create the " +"`/etc/cron.daily/jobs.deny` file. In this file, specify the names of the " +"programs to be omitted from execution (only programs located in the same " +"directory can be enlisted). If a job runs a command which runs the programs " +"from the `/etc/cron.daily/` directory, such as [command]#run-parts " +"/etc/cron.daily#, the programs defined in the `jobs.deny` file will not be " +"executed." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:317 +msgid "To define a white list, create a `jobs.allow` file." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:319 +msgid "" +"The principles of `jobs.deny` and `jobs.allow` are the same as those of " +"`cron.deny` and `cron.allow` described in section " +"xref:Automating_System_Tasks.adoc#s2-autotasks-cron-access[Controlling " +"Access to Cron]." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:321 +#, no-wrap +msgid "At and Batch" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:324 +msgid "" +"indexterm:[at]indexterm:[batch] While Cron is used to schedule recurring " +"tasks, the [application]*At* utility is used to schedule a one-time task at " +"a specific time and the [application]*Batch* utility is used to schedule a " +"one-time task to be executed when the system load average drops below 0.8." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:326 +#, no-wrap +msgid "Installing At and Batch" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:329 +msgid "" +"To determine if the [package]*at* package is already installed on your " +"system, issue the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:333 +#, no-wrap +msgid "[command]#rpm -q at#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:336 +msgid "" +"The command returns the full name of the [package]*at* package if already " +"installed or notifies you that the package is not available." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:338 +msgid "" +"To install the packages, use the [command]#dnf# command in the following " +"form as `root`:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:345 +msgid "" +"For example, to install both At and Batch, type the following at a shell " +"prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:349 +#, no-wrap +msgid "~]#{nbsp}dnf install at\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:354 +#, no-wrap +msgid "Running the At Service" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:357 +msgid "" +"The At and Batch jobs are both picked by the `atd` service. This section " +"provides information on how to start, stop, and restart the `atd` service, " +"and shows how to configure it to start automatically at boot time." +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:359 +#, no-wrap +msgid "Starting and Stopping the At Service" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:366 +#, no-wrap +msgid "[command]#systemctl status atd.service#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:369 +msgid "" +"To run the `atd` service in the current session, type the following at a " +"shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:373 +#, no-wrap +msgid "[command]#systemctl start atd.service#\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:380 +#, no-wrap +msgid "[command]#systemctl enable atd.service#\n" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:386 +msgid "" +"It is recommended that you configure your system to start the `atd` service " +"automatically at boot time." +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:390 +#, no-wrap +msgid "Stopping the At Service" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:393 +msgid "To stop the `atd` service, type the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:397 +#, no-wrap +msgid "[command]#systemctl stop atd.service#\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:404 +#, no-wrap +msgid "[command]#systemctl disable atd.service#\n" +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:407 +#, no-wrap +msgid "Restarting the At Service" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:410 +msgid "" +"To restart the `atd` service, type the following at a shell prompt as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:414 +#, no-wrap +msgid "[command]#systemctl restart atd.service#\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:419 +#, no-wrap +msgid "Configuring an At Job" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:422 +msgid "" +"To schedule a one-time job for a specific time with the [application]*At* " +"utility, do the following:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:424 +msgid "" +"On the command line, type the command [command]#at " +"_TIME_pass:attributes[{blank}]#, where " +"[command]#pass:attributes[{blank}]_TIME_pass:attributes[{blank}]# is the " +"time when the command is to be executed." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:426 +msgid "The _TIME_ argument can be defined in any of the following formats:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:428 +msgid "" +"`pass:attributes[{blank}]_HH_:pass:attributes[{blank}]_MM_pass:attributes[{blank}]` " +"specifies the exact hour and minute; For example, `04:00` specifies 4:00 " +"a.m." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:430 +msgid "`midnight` specifies 12:00 a.m." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:432 +msgid "`noon` specifies 12:00 p.m." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:434 +msgid "`teatime` specifies 4:00 p.m." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:436 +msgid "" +"`pass:attributes[{blank}]_MONTH_pass:attributes[{blank}]pass:attributes[{blank}]_DAY_pass:attributes[{blank}]pass:attributes[{blank}]_YEAR_pass:attributes[{blank}]` " +"format; For example, `January 15 2012` specifies the 15th day of January in " +"the year 2012. The year value is optional." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:438 +msgid "" +"`pass:attributes[{blank}]_MMDDYY_pass:attributes[{blank}]`, " +"`pass:attributes[{blank}]_MM_pass:attributes[{blank}]/pass:attributes[{blank}]_DD_pass:attributes[{blank}]/pass:attributes[{blank}]_YY_pass:attributes[{blank}]`, " +"or `pass:attributes[{blank}]_MM_._DD_._YY_pass:attributes[{blank}]` formats; " +"For example, `011512` for the 15th day of January in the year 2012." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:440 +msgid "" +"`now + _TIME_pass:attributes[{blank}]` where _TIME_ is defined as an integer " +"and the value type: minutes, hours, days, or weeks. For example, `now + 5 " +"days` specifies that the command will be executed at the same time five days " +"from now." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:442 +msgid "" +"The time must be specified first, followed by the optional date. For more " +"information about the time format, see the " +"`/usr/share/doc/at-__pass:attributes[{blank}]/timespec` text file." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:444 +msgid "" +"If the specified time has past, the job is executed at the time the next " +"day." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:446 +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:471 +msgid "In the displayed `at>` prompt, define the job commands:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:448 +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:473 +msgid "" +"Type the command the job should execute and press kbd:[Enter]. Optionally, " +"repeat the step to provide multiple commands." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:450 +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:475 +msgid "" +"Enter a shell script at the prompt and press kbd:[Enter] after each line in " +"the script." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:452 +msgid "" +"The job will use the shell set in the user's `SHELL` environment, the user's " +"login shell, or [command]#/bin/sh# (whichever is found first)." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:454 +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:479 +msgid "Once finished, press kbd:[Ctrl + D] on an empty line to exit the prompt." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:456 +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:481 +msgid "" +"If the set of commands or the script tries to display information to " +"standard output, the output is emailed to the user." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:458 +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:483 +msgid "" +"To view the list of pending jobs, use the [command]#atq# command. See " +"xref:Automating_System_Tasks.adoc#s2-autotasks-at-batch-viewing[Viewing " +"Pending Jobs] for more information." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:460 +msgid "" +"You can also restrict the usage of the [command]#at# command. For more " +"information, see " +"xref:Automating_System_Tasks.adoc#s2-autotasks-at-batch-controlling-access[Controlling " +"Access to At and Batch] for details." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:462 +#, no-wrap +msgid "Configuring a Batch Job" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:465 +msgid "" +"The [application]*Batch* application executes the defined one-time tasks " +"when the system load average decreases below 0.8." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:467 +msgid "To define a Batch job, do the following:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:469 +msgid "On the command line, type the command [command]#batch#." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:477 +msgid "" +"If a script is entered, the job uses the shell set in the user's `SHELL` " +"environment, the user's login shell, or [command]#/bin/sh# (whichever is " +"found first)." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:485 +msgid "" +"You can also restrict the usage of the [command]#batch# command. For more " +"information, see " +"xref:Automating_System_Tasks.adoc#s2-autotasks-at-batch-controlling-access[Controlling " +"Access to At and Batch] for details." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:487 +#, no-wrap +msgid "Viewing Pending Jobs" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:490 +msgid "" +"To view the pending [command]#At# and [command]#Batch# jobs, run the " +"[command]#atq# command. The [command]#atq# command displays a list of " +"pending jobs, with each job on a separate line. Each line follows the job " +"number, date, hour, job class, and user name format. Users can only view " +"their own jobs. If the `root` user executes the [command]#atq# command, all " +"jobs for all users are displayed." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:492 +#, no-wrap +msgid "Additional Command Line Options" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:495 +msgid "" +"Additional command line options for [command]#at# and [command]#batch# " +"include the following:" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:497 +#, no-wrap +msgid "[command]#at# and [command]#batch# Command Line Options" +msgstr "" + +#. type: Table +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:505 +#, no-wrap +msgid "" +"|Option|Description\n" +"|[option]`-f`|Read the commands or shell script from a file instead of " +"specifying them at the prompt.\n" +"|[option]`-m`|Send email to the user when the job has been completed.\n" +"|[option]`-v`|Display the time that the job is executed.\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:508 +#, no-wrap +msgid "Controlling Access to At and Batch" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:511 +msgid "" +"You can restrict the access to the [command]#at# and [command]#batch# " +"commands using the `/etc/at.allow` and `/etc/at.deny` files. These access " +"control files use the same format defining one user name on each line. Mind " +"that no whitespace are permitted in either file." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:513 +msgid "" +"If the file `at.allow` exists, only users listed in the file are allowed to " +"use [command]#at# or [command]#batch#, and the `at.deny` file is ignored." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:515 +msgid "" +"If `at.allow` does not exist, users listed in `at.deny` are not allowed to " +"use [command]#at# or [command]#batch#." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:517 +msgid "" +"The [command]#at# daemon ([command]#atd#) does not have to be restarted if " +"the access control files are modified. The access control files are read " +"each time a user tries to execute the [command]#at# or [command]#batch# " +"commands." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:519 +msgid "" +"The `root` user can always execute [command]#at# and [command]#batch# " +"commands, regardless of the content of the access control files." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:521 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:524 +msgid "" +"indexterm:[cron,additional resources]indexterm:[at,additional " +"resources]indexterm:[batch,additional resources] To learn more about " +"configuring automated tasks, see the following installed documentation:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:526 +msgid "`cron(8)` man page contains an overview of cron." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:528 +msgid "`crontab` man pages in sections 1 and 5:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:530 +msgid "The manual page in section 1 contains an overview of the `crontab` file." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:532 +msgid "" +"The man page in section 5 contains the format for the file and some example " +"entries." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:534 +msgid "`anacron(8)` manual page contains an overview of anacron." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:536 +msgid "`anacrontab(5)` manual page contains an overview of the `anacrontab` file." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:538 +msgid "" +"`run-parts(4)` manual page contains an overview of the [command]#run-parts# " +"script." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:540 +msgid "" +"`/usr/share/doc/at/timespec` contains detailed information about the time " +"values that can be used in cron job definitions." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Automating_System_Tasks.adoc:541 +msgid "" +"`at` manual page contains descriptions of [command]#at# and [command]#batch# " +"and their command line options." +msgstr "" diff --git a/pot/rawhide/pages/monitoring-and-automation/OProfile.pot b/pot/rawhide/pages/monitoring-and-automation/OProfile.pot new file mode 100644 index 00000000000..cd12f711f34 --- /dev/null +++ b/pot/rawhide/pages/monitoring-and-automation/OProfile.pot @@ -0,0 +1,2280 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/monitoring-and-automation/OProfile.adoc:6 +#, no-wrap +msgid "OProfile" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:9 +msgid "" +"indexterm:[system analysis,OProfile,OProfile]indexterm:[OProfile] OProfile " +"is a low overhead, system-wide performance monitoring tool. It uses the " +"performance monitoring hardware on the processor to retrieve information " +"about the kernel and executables on the system, such as when memory is " +"referenced, the number of L2 cache requests, and the number of hardware " +"interrupts received. On a {MAJOROS} system, the `oprofile` package must be " +"installed to use this tool." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:11 +msgid "" +"Many processors include dedicated performance monitoring hardware. This " +"hardware makes it possible to detect when certain events happen (such as the " +"requested data not being in cache). The hardware normally takes the form of " +"one or more _counters_ that are incremented each time an event takes " +"place. When the counter value increments, an interrupt is generated, making " +"it possible to control the amount of detail (and therefore, overhead) " +"produced by performance monitoring." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:13 +msgid "" +"OProfile uses this hardware (or a timer-based substitute in cases where " +"performance monitoring hardware is not present) to collect _samples_ of " +"performance-related data each time a counter generates an interrupt. These " +"samples are periodically written out to disk; later, the data contained in " +"these samples can then be used to generate reports on system-level and " +"application-level performance." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:15 +msgid "Be aware of the following limitations when using OProfile:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:17 +#, no-wrap +msgid "" +"*Use of shared libraries* — Samples for code in shared libraries are not " +"attributed to the particular application unless the " +"[option]`--separate=library` option is used.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:19 +#, no-wrap +msgid "" +"*Performance monitoring samples are inexact* — When a performance monitoring " +"register triggers a sample, the interrupt handling is not precise like a " +"divide by zero exception. Due to the out-of-order execution of instructions " +"by the processor, the sample may be recorded on a nearby instruction.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:21 +#, no-wrap +msgid "" +"*pass:attributes[{blank}][command]#opreport# does not associate samples for " +"inline functions properly* — [command]#opreport# uses a simple address range " +"mechanism to determine which function an address is in. Inline function " +"samples are not attributed to the inline function but rather to the function " +"the inline function was inserted into.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:23 +#, no-wrap +msgid "" +"*OProfile accumulates data from multiple runs* — OProfile is a system-wide " +"profiler and expects processes to start up and shut down multiple " +"times. Thus, samples from multiple runs accumulate. Use the command " +"[command]#opcontrol --reset# to clear out the samples from previous runs.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:25 +#, no-wrap +msgid "" +"*Hardware performance counters do not work on guest virtual machines* — " +"Because the hardware performance counters are not available on virtual " +"systems, you need to use the `timer` mode. Enter the command " +"[command]#opcontrol --deinit#, and then execute [command]#modprobe oprofile " +"timer=1# to enable the `timer` mode.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:27 +#, no-wrap +msgid "" +"*Non-CPU-limited performance problems* — OProfile is oriented to finding " +"problems with CPU-limited processes. OProfile does not identify processes " +"that are asleep because they are waiting on locks or for some other event to " +"occur (for example an I/O device to finish an operation).\n" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/OProfile.adoc:29 +#, no-wrap +msgid "Overview of Tools" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:32 +msgid "" +"indexterm:[OProfile,overview of tools] " +"xref:OProfile.adoc#tb-oprofile-tools[OProfile Commands] provides a brief " +"overview of the most commonly used tools provided with the `oprofile` " +"package." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:34 +#, no-wrap +msgid "OProfile Commands" +msgstr "" + +#. type: Table +#: ./pages/monitoring-and-automation/OProfile.adoc:47 +#, no-wrap +msgid "" +"|Command|Description\n" +"|[command]#ophelp#|Displays available events for the system's processor " +"along with a brief description of each.\n" +"|[command]#opimport#|Converts sample database files from a foreign binary " +"format to the native format for the system. Only use this option when " +"analyzing a sample database from a different architecture.\n" +"|[command]#opannotate#|Creates annotated source for an executable if the " +"application was compiled with debugging symbols. See " +"xref:OProfile.adoc#s2-oprofile-reading-opannotate[Using " +"[command]#opannotate#] for details.\n" +"|[command]#opcontrol#|Configures what data is collected. See " +"xref:OProfile.adoc#s1-oprofile-configuring[Configuring OProfile Using Legacy " +"Mode] for details.\n" +"|[command]#operf#|Recommended tool to be used in place of " +"[command]#opcontrol# for profiling. See " +"xref:OProfile.adoc#s1-using-operf[Using operf] for details.\n" +" For differences between [command]#operf# and [command]#opcontrol# see " +"xref:OProfile.adoc#s2-operf_vs_opcontrol[operf vs. opcontrol].\n" +"|[command]#opreport#|Retrieves profile data. See " +"xref:OProfile.adoc#s2-oprofile-reading-opreport[Using [command]#opreport#] " +"for details.\n" +"|[command]#oprofiled#|Runs as a daemon to periodically write sample data to " +"disk.\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/OProfile.adoc:50 +#, no-wrap +msgid "operf vs. opcontrol" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:53 +msgid "" +"There are two mutually exclusive methods for collecting profiling data with " +"OProfile. You can either use the newer and preferred [command]#operf# or the " +"[command]#opcontrol# tool." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:54 +#, no-wrap +msgid "operf" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:56 +msgid "" +"This is the recommended mode for profiling. The [command]#operf# tool uses " +"the Linux Performance Events Subsystem, and therefore does not require the " +"*oprofile* kernel driver. The [command]#operf# tool allows you to target " +"your profiling more precisely, as a single process or system-wide, and also " +"allows OProfile to co-exist better with other tools using the performance " +"monitoring hardware on your system. Unlike [command]#opcontrol#, it can be " +"used without the `root` privileges. However, [command]#operf# is also " +"capable of system-wide operations with use of the [option]`--system-wide` " +"option, where root authority is required." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:58 +msgid "" +"With [command]#operf#, there is no initial setup needed. You can invoke " +"[command]#operf# with command-line options to specify your profiling " +"settings. After that, you can run the OProfile post-processing tools " +"described in xref:OProfile.adoc#s1-oprofile-analyzing-data[Analyzing the " +"Data]. See xref:OProfile.adoc#s1-using-operf[Using operf] for further " +"information." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:59 +#, no-wrap +msgid "opcontrol" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:61 +msgid "" +"This mode consists of the [command]#opcontrol# shell script, the `oprofiled` " +"daemon, and several post-processing tools. The [command]#opcontrol# command " +"is used for configuring, starting, and stopping a profiling session. An " +"OProfile kernel driver, usually built as a kernel module, is used for " +"collecting samples, which are then recorded into sample files by " +"`oprofiled`. You can use legacy mode only if you have `root` privileges. In " +"certain cases, such as when you need to sample areas with disabled interrupt " +"request (IRQ), this is a better alternative." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:63 +msgid "" +"Before OProfile can be run in legacy mode, it must be configured as shown in " +"xref:OProfile.adoc#s1-oprofile-configuring[Configuring OProfile Using Legacy " +"Mode]. These settings are then applied when starting OProfile " +"(xref:OProfile.adoc#s1-oprofile-starting[Starting and Stopping OProfile " +"Using Legacy Mode])." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/OProfile.adoc:65 +#, no-wrap +msgid "Using operf" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:68 +msgid "" +"[command]#operf# is the recommended profiling mode that does not require " +"initial setup before starting. All settings are specified as command-line " +"options and there is no separate command to start the profiling process. To " +"stop [command]#operf#, press Ctrl+C. The typical [command]#operf# command " +"syntax looks as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:72 +#, no-wrap +msgid "[command]#operf# _options_ _range_ _command_ _args_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:75 +msgid "" +"Replace _options_ with the desired command-line options to specify your " +"profiling settings. Full set of options is described in `operf(1)` manual " +"page. Replace _range_ with one of the following:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:77 +msgid "" +"[option]`--system-wide` - this setting allows for global profiling, see " +"xref:OProfile.adoc#using_operf_system-wide[Using [command]#operf# in " +"System-wide Mode] +" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:79 +msgid "" +"[option]`--pid=pass:attributes[{blank}]_PID_pass:attributes[{blank}]` - this " +"is to profile a running application, where _PID_ is the process ID of the " +"process you want to profile. +" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:81 +msgid "" +"With _command_ and _args_, you can define a specific command or application " +"to be profiled, and also the input arguments that this command or " +"application requires. Either _command_, [option]`--pid` or " +"[option]`--system-wide` is required, but these cannot be used " +"simultaneously." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:83 +msgid "" +"When you invoke [command]#operf# on a command line without setting the " +"_range_ option, data will be collected for the children processes." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:85 +#, no-wrap +msgid "Using [command]#operf# in System-wide Mode" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:90 +msgid "" +"To run [command]#operf# [option]`--system-wide`, you need `root` " +"authority. When finished profiling, you can stop [command]#operf# with " +"`Ctrl+C`." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:92 +msgid "" +"If you run [command]#operf# [option]`--system-wide` as a background process " +"(with `&`), stop it in a controlled manner in order to process the collected " +"profile data. For this purpose, use:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:96 +#, no-wrap +msgid "[command]#kill -SIGINT operf-PID#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:99 +msgid "" +"When running [command]#operf# [option]`--system-wide`, it is recommended " +"that your current working directory is `/root` or a subdirectory of `/root` " +"so that sample data files are not stored in locations accessible by regular " +"users." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/OProfile.adoc:103 +#: ./pages/monitoring-and-automation/OProfile.adoc:206 +#, no-wrap +msgid "Specifying the Kernel" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:106 +msgid "To monitor the kernel, execute the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:110 +#, no-wrap +msgid "operf --vmlinux=pass:quotes[_vmlinux_path_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:113 +msgid "" +"With this option, you can specify a path to a vmlinux file that matches the " +"running kernel. Kernel samples will be attributed to this binary, allowing " +"post-processing tools to attribute samples to the appropriate kernel " +"symbols. If this option is not specified, all kernel samples will be " +"attributed to a pseudo binary named \"`no-vmlinux`\"." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/OProfile.adoc:115 +#: ./pages/monitoring-and-automation/OProfile.adoc:235 +#, no-wrap +msgid "Setting Events to Monitor" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:118 +msgid "" +"Most processors contain counters, which are used by OProfile to monitor " +"specific events. As shown in " +"xref:OProfile.adoc#tb-oprofile-processors[OProfile Processors and Counters], " +"the number of counters available depends on the processor." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:120 +#: ./pages/monitoring-and-automation/OProfile.adoc:341 +msgid "" +"The events for each counter can be configured via the command line or with a " +"graphical interface. For more information on the graphical interface, see " +"xref:OProfile.adoc#s1-oprofile-gui[Graphical Interface]. If the counter " +"cannot be set to a specific event, an error message is displayed." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:121 +#, no-wrap +msgid "Older Processors and operf" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:126 +msgid "" +"Some older processor models are not supported by the underlying Linux " +"Performance Events Subsystem kernel and therefore are not supported by " +"[command]#operf#. If you receive this message:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:131 +#, no-wrap +msgid "" +"Your kernel's Performance Events Subsystem does not support your processor " +"type\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:135 +msgid "" +"when attempting to use [command]#operf#, try profiling with " +"[command]#opcontrol# to see if your processor type may be supported by " +"OProfile's legacy mode." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:138 +#, no-wrap +msgid "Using operf on Virtual Systems" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:143 +msgid "" +"Since hardware performance counters are not available on guest virtual " +"machines, you have to enable *timer* mode to use [application]*operf* on " +"virtual systems. To do so, type as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:147 +#, no-wrap +msgid "[command]#opcontrol# [option]`--deinit`\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:152 +#, no-wrap +msgid "[command]#modprobe# [command]#oprofile# [option]`timer=1`\n" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:157 +msgid "To set the event for each configurable counter via the command line, use:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:161 +#, no-wrap +msgid "" +"[command]#operf# " +"[option]`--events`pass:attributes[{blank}]=pass:attributes[{blank}]_event1_,_event2_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:164 +msgid "" +"Here, pass a comma-separated list of event specifications for " +"profiling. Each event specification is a colon-separated list of attributes " +"in the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:168 +#, no-wrap +msgid "_event-name_:pass:attributes[{blank}]_sample-rate_:pass:attributes[{blank}]_unit-mask_:pass:attributes[{blank}]_kernel_:pass:attributes[{blank}]_user_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:171 +msgid "" +"xref:OProfile.adoc#tab_event_specifications[Event Specifications] summarizes " +"these options. The last three values are optional, if you omit them, they " +"will be set to their default values. Note that certain events do require a " +"unit mask." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:173 +#, no-wrap +msgid "Event Specifications" +msgstr "" + +#. type: Table +#: ./pages/monitoring-and-automation/OProfile.adoc:184 +#, no-wrap +msgid "" +"|Specification|Description\n" +"|_event-name_|The exact symbolic event name taken from [command]#ophelp#\n" +"|_sample-rate_|The number of events to wait before sampling again. The " +"smaller the count, the more frequent the samples. For events that do not " +"happen frequently, a lower count may be needed to capture a statistically " +"significant number of event instances. On the other hand, sampling too " +"frequently can overload the system. By default, OProfile uses a time-based " +"event set, which creates a sample every 100,000 clock cycles per " +"processor.\n" +"|_unit-mask_|Unit masks, which further define the event, are listed in " +"[command]#ophelp#.\n" +" You can insert either a hexadecimal value, beginning with " +"\"`0x`\", or a string that matches the first word of the unit mask " +"description in [command]#ophelp#. Definition by name is valid only for unit " +"masks having \"`extra:`\" parameters, as shown by the output of " +"[command]#ophelp#. This type of unit mask cannot be defined with a " +"hexadecimal value. Note that on certain architectures, there can be multiple " +"unit masks with the same hexadecimal value. In that case they have to be " +"specified by their names only.\n" +"|_kernel_|Specifies whether to profile kernel code (insert `0` or " +"`1`(default))\n" +"|_user_|Specifies whether to profile user-space code (insert `0` or `1` " +"(default))\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:187 +msgid "" +"The events available vary depending on the processor type. When no event " +"specification is given, the default event for the running processor type " +"will be used for profiling. See " +"xref:OProfile.adoc#tb-oprofile-default-events[Default Events] for a list of " +"these default events. To determine the events available for profiling, use " +"the [command]#ophelp# command." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:191 +#, no-wrap +msgid "[command]#ophelp#\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/OProfile.adoc:194 +#, no-wrap +msgid "Categorization of Samples" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:197 +msgid "" +"The [option]`--separate-thread` option categorizes samples by thread group " +"ID (tgid) and thread ID (tid). This is useful for seeing per-thread samples " +"in multi-threaded applications. When used in conjunction with the " +"[option]`--system-wide` option, [option]`--separate-thread` is also useful " +"for seeing per-process (i.e., per-thread group) samples for the case where " +"multiple processes are executing the same program during a profiling run." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:199 +msgid "The [option]`--separate-cpu` option categorizes samples by CPU." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/OProfile.adoc:201 +#, no-wrap +msgid "Configuring OProfile Using Legacy Mode" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:204 +msgid "" +"indexterm:[OProfile,configuring]indexterm:[OProfile,opcontrol]indexterm:[opcontrol,OProfile] " +"Before OProfile can be run in legacy mode, it must be configured. At a " +"minimum, selecting to monitor the kernel (or selecting not to monitor the " +"kernel) is required. The following sections describe how to use the " +"[command]#opcontrol# utility to configure OProfile. As the " +"[command]#opcontrol# commands are executed, the setup options are saved to " +"the `/root/.oprofile/daemonrc` file." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:209 +msgid "" +"indexterm:[OProfile,monitoring the kernel] First, configure whether OProfile " +"should monitor the kernel. This is the only configuration option that is " +"required before starting OProfile. All others are optional." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:212 +msgid "" +"To monitor the kernel, execute the following command as `root`: " +"indexterm:[OProfile,opcontrol,--vmlinux=]" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:214 +#, no-wrap +msgid "" +"~]# opcontrol --setup --vmlinux=/usr/lib/debug/lib/modules/`uname " +"-r`/vmlinux\n" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:216 +#, no-wrap +msgid "Install the debuginfo package" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:221 +msgid "" +"In order to monitor the kernel, the [package]*debuginfo* package which " +"contains the uncompressed kernel must be installed." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:226 +msgid "" +"To configure OProfile not to monitor the kernel, execute the following " +"command as `root`: indexterm:[OProfile,opcontrol,--no-vmlinux]" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:228 +#, no-wrap +msgid "~]# opcontrol --setup --no-vmlinux\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:231 +msgid "" +"This command also loads the `oprofile` kernel module, if it is not already " +"loaded, and creates the `/dev/oprofile/` directory, if it does not already " +"exist. See xref:OProfile.adoc#s1-oprofile-dev-oprofile[Understanding the " +"/dev/oprofile/ directory] for details about this directory." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:233 +msgid "" +"Setting whether samples should be collected within the kernel only changes " +"what data is collected, not how or where the collected data is stored. To " +"generate different sample files for the kernel and application libraries, " +"see xref:OProfile.adoc#s2-oprofile-starting-separate[Separating Kernel and " +"User-space Profiles]." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:238 +msgid "" +"indexterm:[OProfile,events,setting] Most processors contain _counters_, " +"which are used by OProfile to monitor specific events. As shown in " +"xref:OProfile.adoc#tb-oprofile-processors[OProfile Processors and Counters], " +"the number of counters available depends on the processor." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:240 +#, no-wrap +msgid "OProfile Processors and Counters" +msgstr "" + +#. type: Table +#: ./pages/monitoring-and-automation/OProfile.adoc:278 +#, no-wrap +msgid "" +"|Processor|[command]#cpu_type#|Number of Counters\n" +"|AMD64|x86-64/hammer|4\n" +"|AMD Family 10h|x86-64/family10|4\n" +"|AMD Family 11h|x86-64/family11|4\n" +"|AMD Family 12h|x86-64/family12|4\n" +"|AMD Family 14h|x86-64/family14|4\n" +"|AMD Family 15h|x86-64/family15|6\n" +"|Applied Micro X-Gene|arm/armv8-xgene|4\n" +"|ARM Cortex A53|arm/armv8-ca53|6\n" +"|ARM Cortex A57|arm/armv8-ca57|6\n" +"|IBM eServer System i and IBM eServer System p|timer|1\n" +"|IBM POWER4|ppc64/power4|8\n" +"|IBM POWER5|ppc64/power5|6\n" +"|IBM PowerPC 970|ppc64/970|8\n" +"|IBM PowerPC 970MP|ppc64/970MP|8\n" +"|IBM POWER5+|ppc64/power5+|6\n" +"|IBM POWER5++|ppc64/power5++|6\n" +"|IBM POWER56|ppc64/power6|6\n" +"|IBM POWER7|ppc64/power7|6\n" +"|IBM POWER8|ppc64/power7|8\n" +"|IBM S/390 and IBM System z|timer|1\n" +"|Intel Core i7|i386/core_i7|4\n" +"|Intel Nehalem microarchitecture|i386/nehalem|4\n" +"|Intel Westmere microarchitecture|i386/westmere|4\n" +"|Intel Haswell microarchitecture (non-hyper-threaded)|i386/haswell|8\n" +"|Intel Haswell microarchitecture (hyper-threaded)|i386/haswell-ht|4\n" +"|Intel Ivy Bridge microarchitecture (non-hyper-threaded)|i386/ivybridge|8\n" +"|Intel Ivy Bridge microarchitecture (hyper-threaded)|i386/ivybridge-ht|4\n" +"|Intel Sandy Bridge microarchitecture " +"(non-hyper-threaded)|i386/sandybridge|8\n" +"|Intel Sandy Bridge microarchitecture|i386/sandybridge-ht|4\n" +"|Intel Broadwell microarchitecture (non-hyper-threaded)|i386/broadwell|8\n" +"|Intel Broadwell microarchitecture (hyper-threaded)|i386/broadwell-ht|4\n" +"|Intel Silvermont microarchitecture|i386/silvermont|2\n" +"|TIMER_INT|timer|1\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:281 +msgid "" +"Use xref:OProfile.adoc#tb-oprofile-processors[OProfile Processors and " +"Counters] to determine the number of events that can be monitored " +"simultaneously for your CPU type. If the processor does not have supported " +"performance monitoring hardware, the `timer` is used as the processor type." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:283 +msgid "" +"If `timer` is used, events cannot be set for any processor because the " +"hardware does not have support for hardware performance counters. Instead, " +"the timer interrupt is used for profiling." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:285 +msgid "" +"If `timer` is not used as the processor type, the events monitored can be " +"changed, and counter 0 for the processor is set to a time-based event by " +"default. If more than one counter exists on the processor, the counters " +"other than 0 are not set to an event by default. The default events " +"monitored are shown in xref:OProfile.adoc#tb-oprofile-default-events[Default " +"Events]." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:287 +#, no-wrap +msgid "Default Events" +msgstr "" + +#. type: Table +#: ./pages/monitoring-and-automation/OProfile.adoc:309 +#, no-wrap +msgid "" +"|Processor|Default Event for Counter|Description\n" +"|AMD Athlon and AMD64|CPU_CLK_UNHALTED|The processor's clock is not halted\n" +"|AMD Family 10h, AMD Family 11h, AMD Family 12h|CPU_CLK_UNHALTED|The " +"processor's clock is not halted\n" +"|AMD Family 14h, AMD Family 15h|CPU_CLK_UNHALTED|The processor's clock is " +"not halted\n" +"|Applied Micro X-Gene|CPU_CYCLES|Processor Cycles\n" +"|ARM Cortex A53|CPU_CYCLES|Processor Cycles\n" +"|ARM Cortex A57|CPU_CYCLES|Processor Cycles\n" +"|IBM POWER4|CYCLES|Processor Cycles\n" +"|IBM POWER5|CYCLES|Processor Cycles\n" +"|IBM POWER8|CYCLES|Processor Cycles\n" +"|IBM PowerPC 970|CYCLES|Processor Cycles\n" +"|Intel Core i7|CPU_CLK_UNHALTED|The processor's clock is not halted\n" +"|Intel Nehalem microarchitecture|CPU_CLK_UNHALTED|The processor's clock is " +"not halted\n" +"|Intel Pentium 4 (hyper-threaded and " +"non-hyper-threaded)|GLOBAL_POWER_EVENTS|The time during which the processor " +"is not stopped\n" +"|Intel Westmere microarchitecture|CPU_CLK_UNHALTED|The processor's clock is " +"not halted\n" +"|Intel Broadwell microarchitecture|CPU_CLK_UNHALTED|The processor's clock is " +"not halted\n" +"|Intel Silvermont microarchitecture|CPU_CLK_UNHALTED|The processor's clock " +"is not halted\n" +"|TIMER_INT|(none)|Sample for each timer interrupt\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:312 +msgid "" +"The number of events that can be monitored at one time is determined by the " +"number of counters for the processor. However, it is not a one-to-one " +"correlation; on some processors, certain events must be mapped to specific " +"counters. To determine the number of counters available, execute the " +"following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:315 +#, no-wrap +msgid "~]# ls -d /dev/oprofile/[0-9]*\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:319 +msgid "" +"The events available vary depending on the processor type. To determine the " +"events available for profiling, execute the following command as root (the " +"list is specific to the system's processor type): " +"indexterm:[OProfile,ophelp]indexterm:[ophelp]" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:321 +#, no-wrap +msgid "~]# ophelp\n" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:323 +#, no-wrap +msgid "Make sure that OProfile is configured" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:328 +msgid "" +"Unless OProfile is properly configured, [command]#ophelp# fails with the " +"following error message:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:334 +#, no-wrap +msgid "" +"Unable to open cpu_type file for reading\n" +"Make sure you have done opcontrol --init\n" +"cpu_type 'unset' is not valid\n" +"you should upgrade oprofile or force the use of timer mode\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:337 +msgid "" +"To configure OProfile, follow the instructions in " +"xref:OProfile.adoc#s1-oprofile-configuring[Configuring OProfile Using Legacy " +"Mode]." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:343 +msgid "" +"To set the event for each configurable counter via the command line, use " +"[command]#opcontrol#:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:346 +#: ./pages/monitoring-and-automation/OProfile.adoc:359 +#, no-wrap +msgid "~]# opcontrol --event=event-name:sample-rate\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:349 +msgid "" +"Replace _event-name_ with the exact name of the event from " +"[command]#ophelp#, and replace _sample-rate_ with the number of events " +"between samples." +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/OProfile.adoc:351 +#, no-wrap +msgid "Sampling Rate" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:354 +msgid "" +"indexterm:[OProfile,events,sampling rate] By default, a time-based event set " +"is selected. It creates a sample every 100,000 clock cycles per " +"processor. If the timer interrupt is used, the timer is set to the " +"respective rate and is not user-settable. If the `cpu_type` is not `timer`, " +"each event can have a _sampling rate_ set for it. The sampling rate is the " +"number of events between each sample snapshot." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:356 +msgid "When setting the event for the counter, a sample rate can also be specified:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:362 +msgid "" +"Replace _sample-rate_ with the number of events to wait before sampling " +"again. The smaller the count, the more frequent the samples. For events that " +"do not happen frequently, a lower count may be needed to capture the event " +"instances." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:363 +#, no-wrap +msgid "Sampling too frequently can overload the system" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:368 +msgid "" +"Be extremely careful when setting sampling rates. Sampling too frequently " +"can overload the system, causing the system to appear frozen or causing the " +"system to actually freeze." +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/OProfile.adoc:372 +#, no-wrap +msgid "Unit Masks" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:375 +msgid "" +"indexterm:[OProfile,unit mask] Some user performance monitoring events may " +"also require unit masks to further define the event." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:377 +msgid "" +"Unit masks for each event are listed with the [command]#ophelp# command. The " +"values for each unit mask are listed in hexadecimal format. To specify more " +"than one unit mask, the hexadecimal values must be combined using a bitwise " +"_or_ operation." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:380 +#, no-wrap +msgid "~]# opcontrol --event=event-name:sample-rate:unit-mask\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:383 +msgid "" +"Note that on certain architectures, there can be multiple unit masks with " +"the same hexadecimal value. In that case they have to be specified by their " +"names only." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/OProfile.adoc:385 +#, no-wrap +msgid "Separating Kernel and User-space Profiles" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:388 +msgid "" +"indexterm:[OProfile,configuring,separating profiles] By default, kernel mode " +"and user mode information is gathered for each event. To configure OProfile " +"to ignore events in kernel mode for a specific counter, execute the " +"following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:391 +#, no-wrap +msgid "~]# opcontrol --event=event-name:sample-rate:unit-mask:0\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:394 +msgid "" +"Execute the following command to start profiling kernel mode for the counter " +"again:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:397 +#, no-wrap +msgid "~]# opcontrol --event=event-name:sample-rate:unit-mask:1\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:400 +msgid "" +"To configure OProfile to ignore events in user mode for a specific counter, " +"execute the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:403 +#, no-wrap +msgid "~]# opcontrol --event=event-name:sample-rate:unit-mask:1:0\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:406 +msgid "" +"Execute the following command to start profiling user mode for the counter " +"again:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:409 +#, no-wrap +msgid "~]# opcontrol --event=event-name:sample-rate:unit-mask:1:1\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:412 +msgid "" +"When the OProfile daemon writes the profile data to sample files, it can " +"separate the kernel and library profile data into separate sample files. To " +"configure how the daemon writes to sample files, execute the following " +"command as root:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:415 +#, no-wrap +msgid "~]# opcontrol --separate=choice\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:418 +msgid "The _choice_ argument can be one of the following:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:420 +msgid "`none` — Do not separate the profiles (default)." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:422 +msgid "[command]#library# — Generate per-application profiles for libraries." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:424 +msgid "" +"[command]#kernel# — Generate per-application profiles for the kernel and " +"kernel modules." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:426 +msgid "" +"[command]#all# — Generate per-application profiles for libraries and " +"per-application profiles for the kernel and kernel modules." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:428 +msgid "" +"If [option]`--separate=library` is used, the sample file name includes the " +"name of the executable as well as the name of the library." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:429 +#, no-wrap +msgid "Restart the OProfile profiler" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:434 +msgid "" +"These configuration changes will take effect when the OProfile profiler is " +"restarted." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/OProfile.adoc:438 +#, no-wrap +msgid "Starting and Stopping OProfile Using Legacy Mode" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:442 +msgid "" +"indexterm:[OProfile,starting] To start monitoring the system with OProfile, " +"execute the following command as root: " +"indexterm:[OProfile,opcontrol,--start]" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:444 +#, no-wrap +msgid "~]# opcontrol --start\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:447 +msgid "Output similar to the following is displayed:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:451 +#, no-wrap +msgid "" +"Using log file /var/lib/oprofile/oprofiled.log Daemon started. Profiler " +"running.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:456 +msgid "" +"The settings in `/root/.oprofile/daemonrc` are used. " +"indexterm:[OProfile,oprofiled]indexterm:[oprofiled,OProfile]indexterm:[OProfile,oprofiled,log " +"file] The OProfile daemon, [command]#oprofiled#, is started; it periodically " +"writes the sample data to the `/var/lib/oprofile/samples/` directory. The " +"log file for the daemon is located at `/var/lib/oprofile/oprofiled.log`." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:457 +#, no-wrap +msgid "Disable the nmi_watchdog registers" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:462 +msgid "" +"On a {MAJOROSVER} system, the `nmi_watchdog` registers with the `perf` " +"subsystem. Due to this, the `perf` subsystem grabs control of the " +"performance counter registers at boot time, blocking OProfile from working." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:464 +msgid "" +"To resolve this, either boot with the [command]#nmi_watchdog=0# kernel " +"parameter set, or run the following command as `root` to disable " +"`nmi_watchdog` at run time:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:467 +#, no-wrap +msgid "~]# echo 0 > /proc/sys/kernel/nmi_watchdog\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:470 +msgid "To re-enable `nmi_watchdog`, use the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:473 +#, no-wrap +msgid "~]# echo 1 > /proc/sys/kernel/nmi_watchdog\n" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:478 +msgid "To stop the profiler, execute the following command as root:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:481 +#, no-wrap +msgid "~]# opcontrol --shutdown\n" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/OProfile.adoc:484 +#, no-wrap +msgid "Saving Data in Legacy Mode" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:487 +msgid "" +"indexterm:[OProfile,saving data] Sometimes it is useful to save samples at a " +"specific time. For example, when profiling an executable, it may be useful " +"to gather different samples based on different input data sets. If the " +"number of events to be monitored exceeds the number of counters available " +"for the processor, multiple runs of OProfile can be used to collect data, " +"saving the sample data to different files each time." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:489 +msgid "" +"To save the current set of sample files, execute the following command, " +"replacing _name_ with a unique descriptive name for the current session:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:492 +#, no-wrap +msgid "~]# opcontrol --save=name\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:495 +msgid "" +"The command creates the directory " +"`/var/lib/oprofile/samples/pass:attributes[{blank}]_name_pass:attributes[{blank}]/` " +"and the current sample files are copied to it." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:497 +msgid "" +"To specify the session directory to hold the sample data, use the " +"[option]`--session-dir` option. If not specified, the data is saved in the " +"`oprofile_data/` directory on the current path." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/OProfile.adoc:499 +#, no-wrap +msgid "Analyzing the Data" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:502 +msgid "" +"indexterm:[OProfile,reading data] The same OProfile post-processing tools " +"are used whether you collect your profile with [command]#operf# or " +"[command]#opcontrol# in legacy mode." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:504 +msgid "" +"By default, [command]#operf# stores the profiling data in the " +"`pass:attributes[{blank}]_current_dir_pass:attributes[{blank}]/oprofile_data/` " +"directory. You can change to a different location with the " +"[option]`--session-dir` option. The usual post-profiling analysis tools such " +"as [command]#opreport# and [command]#opannotate# can be used to generate " +"profile reports. These tools search for samples in " +"`pass:attributes[{blank}]_current_dir_pass:attributes[{blank}]/oprofile_data/` " +"first. If this directory does not exist, the analysis tools use the standard " +"session directory of `/var/lib/oprofile/`. Statistics, such as total samples " +"received and lost samples, are written to the " +"`pass:attributes[{blank}]_session_dir_pass:attributes[{blank}]/samples/operf.log` " +"file." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:506 +msgid "" +"When using legacy mode, the OProfile daemon, [command]#oprofiled#, " +"periodically collects the samples and writes them to the " +"`/var/lib/oprofile/samples/` directory. Before reading the data, make sure " +"all data has been written to this directory by executing the following " +"command as root:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:509 +#, no-wrap +msgid "~]# opcontrol --dump\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:512 +msgid "" +"Each sample file name is based on the name of the executable. For example, " +"the samples for the default event on a Pentium III processor for " +"[command]#/bin/bash# becomes:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:515 +#, no-wrap +msgid "\\{root\\}/bin/bash/\\{dep\\}/\\{root\\}/bin/bash/CPU_CLK_UNHALTED.100000\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:518 +msgid "" +"The following tools are available to profile the sample data once it has " +"been collected:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:520 +msgid "[command]#opreport#" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:522 +msgid "[command]#opannotate#" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:524 +msgid "" +"Use these tools, along with the binaries profiled, to generate reports that " +"can be further analyzed." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/OProfile.adoc:525 +#, no-wrap +msgid "Back up the executable and the sample files" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/OProfile.adoc:530 +msgid "" +"The executable being profiled must be used with these tools to analyze the " +"data. If it must change after the data is collected, back up the executable " +"used to create the samples as well as the sample files. Note that the names " +"of the sample file and the binary have to agree. You cannot make a backup if " +"these names do not match. As an alternative, [command]#oparchive# can be " +"used to address this problem." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:534 +msgid "" +"Samples for each executable are written to a single sample file. Samples " +"from each dynamically linked library are also written to a single sample " +"file. While OProfile is running, if the executable being monitored changes " +"and a sample file for the executable exists, the existing sample file is " +"automatically deleted. Thus, if the existing sample file is needed, it must " +"be backed up, along with the executable used to create it before replacing " +"the executable with a new version. The OProfile analysis tools use the " +"executable file that created the samples during analysis. If the executable " +"changes, the analysis tools will be unable to analyze the associated " +"samples. See xref:OProfile.adoc#s1-oprofile-saving-data[Saving Data in " +"Legacy Mode] for details on how to back up the sample file." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/OProfile.adoc:536 +#, no-wrap +msgid "Using [command]#opreport#" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:539 +msgid "" +"indexterm:[OProfile,opreport]indexterm:[opreport,OProfile] The " +"[command]#opreport# tool provides an overview of all the executables being " +"profiled. The following is part of a sample output from the " +"[command]#opreport# command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:546 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#opreport#\n" +"Profiling through timer interrupt\n" +"TIMER:0|\n" +"samples| %|\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:569 +msgid "" +"25926 97.5212 no-vmlinux 359 1.3504 pi 65 0.2445 Xorg 62 0.2332 " +"libvte.so.4.4.0 56 0.2106 libc-2.3.4.so 34 0.1279 libglib-2.0.so.0.400.7 19 " +"0.0715 libXft.so.2.1.2 17 0.0639 bash 8 0.0301 ld-2.3.4.so 8 0.0301 " +"libgdk-x11-2.0.so.0.400.13 6 0.0226 libgobject-2.0.so.0.400.7 5 0.0188 " +"oprofiled 4 0.0150 libpthread-2.3.4.so 4 0.0150 libgtk-x11-2.0.so.0.400.13 3 " +"0.0113 libXrender.so.1.2.2 3 0.0113 du 1 0.0038 libcrypto.so.0.9.7a 1 0.0038 " +"libpam.so.0.77 1 0.0038 libtermcap.so.2.0.8 1 0.0038 libX11.so.6.2 1 0.0038 " +"libgthread-2.0.so.0.400.7 1 0.0038 libwnck-1.so.4.9.0" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:572 +#, no-wrap +msgid "" +"Each executable is listed on its own line. The first column is the number of " +"samples recorded for the executable. The second column is the percentage of " +"samples relative to the total number of samples. The third column is the " +"name of the executable.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:574 +#, no-wrap +msgid "" +"See the `opreport(1)` manual page for a list of available command-line " +"options, such as the [option]`-r` option used to sort the output from the " +"executable with the smallest number of samples to the one with the largest " +"number of samples. You can also use the [option]`-t` or " +"[option]`--threshold` option to trim the output of [command]#opcontrol#.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:576 +#, no-wrap +msgid "[[s2-oprofile-reading-opreport-single]]\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/OProfile.adoc:576 +#, no-wrap +msgid "Using opreport on a Single Executable" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:579 +msgid "" +"indexterm:[OProfile,opreport,on a single " +"executable]indexterm:[opreport,OProfile] To retrieve more detailed profiled " +"information about a specific executable, use the [command]#opreport# " +"command:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:583 +#, no-wrap +msgid "" +"~]# opreport mode\n" +" executable\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:586 +#, no-wrap +msgid "" +"Replace _executable_ with the full path to the executable to be " +"analyzed. _mode_ stands for one of the following options:\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:590 +#, no-wrap +msgid "" +"[option]`-l`:: This option is used to list sample data by symbols. For " +"example, running this command:\n" +"+\n" +"[subs=\"attributes\"]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:592 +msgid "~]#{nbsp}opreport -l /lib/tls/libc-version.so" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:596 +#, no-wrap +msgid "" +"+\n" +"produces the following output:\n" +"+\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:623 +msgid "" +"samples % symbol name 12 21.4286 __gconv_transform_utf8_internal 5 8.9286 " +"_int_malloc 4 7.1429 malloc 3 5.3571 __i686.get_pc_thunk.bx 3 5.3571 " +"_dl_mcount_wrapper_check 3 5.3571 mbrtowc 3 5.3571 memcpy 2 3.5714 " +"_int_realloc 2 3.5714 _nl_intern_locale_data 2 3.5714 free 2 3.5714 strcmp 1 " +"1.7857 __ctype_get_mb_cur_max 1 1.7857 __unregister_atfork 1 1.7857 " +"__write_nocancel 1 1.7857 _dl_addr 1 1.7857 _int_free 1 1.7857 _itoa_word 1 " +"1.7857 calc_eclosure_iter 1 1.7857 fopen@@GLIBC_2.1 1 1.7857 getpid 1 1.7857 " +"memmove 1 1.7857 msort_with_tmp 1 1.7857 strcpy 1 1.7857 strlen 1 1.7857 " +"vfprintf 1 1.7857 write" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:628 +#, no-wrap +msgid "" +"+\n" +"The first column is the number of samples for the symbol, the second column " +"is the percentage of samples for this symbol relative to the overall samples " +"for the executable, and the third column is the symbol name.\n" +"+\n" +"To sort the output from the largest number of samples to the smallest " +"(reverse order), use [option]`-r` in conjunction with the [option]`-l` " +"option.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:632 +#, no-wrap +msgid "" +"[option]`-i _symbol-name_pass:attributes[{blank}]`:: List sample data " +"specific to a symbol name. For example, running:\n" +"+\n" +"[subs=\"attributes\"]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:634 +msgid "" +"~]#{nbsp}opreport -l -i __gconv_transform_utf8_internal " +"/lib/tls/libc-version.so" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:638 +#, no-wrap +msgid "" +"+\n" +"returns the following output:\n" +"+\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:641 +msgid "samples % symbol name 12 100.000 __gconv_transform_utf8_internal" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:646 +#, no-wrap +msgid "" +"+\n" +"The first line is a summary for the symbol/executable combination.\n" +"+\n" +"The first column is the number of samples for the memory symbol. The second " +"column is the percentage of samples for the memory address relative to the " +"total number of samples for the symbol. The third column is the symbol " +"name.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:650 +#, no-wrap +msgid "" +"[option]`-d`:: This option lists sample data by symbols with more detail " +"than the [option]`-l` option. For example, with the following command:\n" +"+\n" +"[subs=\"attributes\"]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:652 +msgid "" +"~]#{nbsp}opreport -d -i __gconv_transform_utf8_internal " +"/lib/tls/libc-version.so" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:656 +#, no-wrap +msgid "" +"+\n" +"this output is returned:\n" +"+\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:670 +msgid "" +"vma samples % symbol name 00a98640 12 100.000 " +"__gconv_transform_utf8_internal 00a98640 1 8.3333 00a9868c 2 16.6667 " +"00a9869a 1 8.3333 00a986c1 1 8.3333 00a98720 1 8.3333 00a98749 1 8.3333 " +"00a98753 1 8.3333 00a98789 1 8.3333 00a98864 1 8.3333 00a98869 1 8.3333 " +"00a98b08 1 8.3333" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:673 +#, no-wrap +msgid "" +"+\n" +"The data is the same as the [option]`-l` option except that for each symbol, " +"each virtual memory address used is shown. For each virtual memory address, " +"the number of samples and percentage of samples relative to the number of " +"samples for the symbol is displayed.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:675 +#, no-wrap +msgid "" +"[option]`-e` _symbol-name_pass:attributes[{blank}]…:: " +"With this option, you can exclude some symbols from the output. Replace " +"_symbol-name_ with the comma-separated list of symbols you want to " +"exclude.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:677 +#, no-wrap +msgid "" +"[option]`session`:pass:attributes[{blank}]_name_:: Here, you can specify " +"the full path to the session, a directory relative to the " +"`/var/lib/oprofile/samples/` directory, or if you are using " +"[command]#operf#, a directory relative to `./oprofile_data/samples/`.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:679 +#, no-wrap +msgid "[[s2-oprofile-module-output]]\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/OProfile.adoc:679 +#, no-wrap +msgid "Getting More Detailed Output on the Modules" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:682 +msgid "" +"indexterm:[OProfile,opreport]indexterm:[OProfile] OProfile collects data on " +"a system-wide basis for kernel- and user-space code running on the " +"machine. However, once a module is loaded into the kernel, the information " +"about the origin of the kernel module is lost. The module could come from " +"the `initrd` file on boot up, the directory with the various kernel modules, " +"or a locally created kernel module. As a result, when OProfile records " +"samples for a module, it just lists the samples for the modules for an " +"executable in the root directory, but this is unlikely to be the place with " +"the actual code for the module. You will need to take some steps to make " +"sure that analysis tools get the proper executable." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:684 +msgid "" +"To get a more detailed view of the actions of the module, you will need to " +"either have the module \"`unstripped`\" (that is installed from a custom " +"build) or have the [package]*debuginfo* package installed for the kernel." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:686 +msgid "" +"Find out which kernel is running with the [command]#uname -a# command, " +"obtain the appropriate [package]*debuginfo* package and install it on the " +"machine." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:688 +msgid "" +"Then proceed with clearing out the samples from previous runs with the " +"following command:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:691 +msgid "~]# opcontrol --reset" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:694 +#, no-wrap +msgid "" +"To start the monitoring process, for example, on a machine with Westmere " +"processor, run the following command:\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:698 +msgid "" +"~]# opcontrol --setup --vmlinux=/usr/lib/debug/lib/modules/`uname " +"-r`/vmlinux \\ --event=CPU_CLK_UNHALTED:500000" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:701 +#, no-wrap +msgid "" +"Then the detailed information, for instance, for the ext4 module can be " +"obtained with:\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:719 +#, no-wrap +msgid "" +"~]# opreport /ext4 -l --image-path /lib/modules/`uname -r`/kernel\n" +"CPU: Intel Westmere microarchitecture, speed 2.667e+06 MHz (estimated)\n" +"Counted CPU_CLK_UNHALTED events (Clock cycles when not halted) with a unit " +"mask of 0x00 (No unit mask) count 500000\n" +"warning: could not check that the binary file " +"/lib/modules/2.6.32-191.el6.x86_64/kernel/fs/ext4/ext4.ko has not been " +"modified since the profile was taken. Results may be inaccurate.\n" +"samples % symbol name\n" +"1622 9.8381 ext4_iget\n" +"1591 9.6500 ext4_find_entry\n" +"1231 7.4665 __ext4_get_inode_loc\n" +"783 4.7492 ext4_ext_get_blocks\n" +"752 4.5612 ext4_check_dir_entry\n" +"644 3.9061 ext4_mark_iloc_dirty\n" +"583 3.5361 ext4_get_blocks\n" +"583 3.5361 ext4_xattr_get\n" +"479 2.9053 ext4_htree_store_dirent\n" +"469 2.8447 ext4_get_group_desc\n" +"414 2.5111 ext4_dx_find_entry\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:722 +#, no-wrap +msgid "[[s2-oprofile-reading-opannotate]]\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/OProfile.adoc:722 +#, no-wrap +msgid "Using [command]#opannotate#" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:725 +msgid "" +"indexterm:[OProfile,opannotate]indexterm:[opannotate,OProfile] The " +"[command]#opannotate# tool tries to match the samples for particular " +"instructions to the corresponding lines in the source code. The resulting " +"generated files should have the samples for the lines at the left. It also " +"puts in a comment at the beginning of each function listing the total " +"samples for the function." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:727 +msgid "" +"For this utility to work, the appropriate [package]*debuginfo* package for " +"the executable must be installed on the system. On {MAJOROS}, the " +"[package]*debuginfo* packages are not automatically installed with the " +"corresponding packages that contain the executable. You have to obtain and " +"install them separately." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:729 +msgid "The general syntax for [command]#opannotate# is as follows:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:732 +msgid "~]# opannotate --search-dirs src-dir --source executable" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:735 +#, no-wrap +msgid "" +"These command-line options are mandatory. Replace _src-dir_ with a path to " +"the directory containing the source code and specify the executable to be " +"analyzed. See the `opannotate(1)` manual page for a list of additional " +"command line options.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:737 +#, no-wrap +msgid "[[s1-oprofile-dev-oprofile]]\n" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/OProfile.adoc:737 +#, no-wrap +msgid "Understanding the /dev/oprofile/ directory" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:740 +msgid "" +"indexterm:[OProfile,/dev/oprofile/]indexterm:[/dev/oprofile/] When using " +"OProfile in legacy mode, the `/dev/oprofile/` directory is used to store the " +"file system for OProfile. On the other hand, [command]#operf# does not " +"require `/dev/oprofile/`. Use the [command]#cat# command to display the " +"values of the virtual files in this file system. For example, the following " +"command displays the type of processor OProfile detected:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:743 +msgid "~]# cat /dev/oprofile/cpu_type" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:746 +#, no-wrap +msgid "" +"A directory exists in `/dev/oprofile/` for each counter. For example, if " +"there are 2 counters, the directories `/dev/oprofile/0/` and " +"`/dev/oprofile/1/` exist.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:748 +#, no-wrap +msgid "Each directory for a counter contains the following files:\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:750 +#, no-wrap +msgid "* `count` — The interval between samples.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:752 +#, no-wrap +msgid "" +"* `enabled` — If 0, the counter is off and no samples are collected for it; " +"if 1, the counter is on and samples are being collected for it.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:754 +#, no-wrap +msgid "* `event` — The event to monitor.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:756 +#, no-wrap +msgid "" +"* `extra` — Used on machines with Nehalem processors to further specify the " +"event to monitor.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:758 +#, no-wrap +msgid "" +"* `kernel` — If 0, samples are not collected for this counter event when the " +"processor is in kernel-space; if 1, samples are collected even if the " +"processor is in kernel-space.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:760 +#, no-wrap +msgid "* `unit_mask` — Defines which unit masks are enabled for the counter.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:762 +#, no-wrap +msgid "" +"* `user` — If 0, samples are not collected for the counter event when the " +"processor is in user-space; if 1, samples are collected even if the " +"processor is in user-space.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:764 +#, no-wrap +msgid "" +"The values of these files can be retrieved with the [command]#cat# " +"command. For example:\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:767 +msgid "~]# cat /dev/oprofile/0/count" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:770 +#, no-wrap +msgid "[[s1-oprofile-example-usage]]\n" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/OProfile.adoc:770 +#, no-wrap +msgid "Example Usage" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:773 +msgid "" +"While OProfile can be used by developers to analyze application performance, " +"it can also be used by system administrators to perform system analysis. For " +"example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:775 +#, no-wrap +msgid "" +"* *Determine which applications and services are used the most on a system* " +"— [command]#opreport# can be used to determine how much processor time an " +"application or service uses. If the system is used for multiple services but " +"is underperforming, the services consuming the most processor time can be " +"moved to dedicated systems.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:777 +#, no-wrap +msgid "" +"* *Determine processor usage* — The `CPU_CLK_UNHALTED` event can be " +"monitored to determine the processor load over a given period of time. This " +"data can then be used to determine if additional processors or a faster " +"processor might improve system performance.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:779 +#, no-wrap +msgid "[[s1-oprofile-java-support]]\n" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/OProfile.adoc:779 +#, no-wrap +msgid "OProfile Support for Java" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:782 +msgid "" +"indexterm:[OProfile,Java] OProfile allows you to profile dynamically " +"compiled code (also known as \"`just-in-time`\" or JIT code) of the Java " +"Virtual Machine (JVM). OProfile in {MAJOROSVER} includes built-in support " +"for the JVM Tools Interface (JVMTI) agent library, which supports Java 1.5 " +"and higher." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:784 +msgid "[[s1-oprofile-java-profiling]]" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/OProfile.adoc:784 +#, no-wrap +msgid "Profiling Java Code" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:787 +msgid "" +"To profile JIT code from the Java Virtual Machine with the JVMTI agent, add " +"the following to the JVM startup parameters:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:789 +msgid "[subs=\"macros\"]" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:791 +msgid "-agentlib:pass:quotes[_jvmti_oprofile_]" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:794 +#, no-wrap +msgid "" +"Where _jvmti_oprofile_ is a path to the OProfile agent. For 64-bit JVM, the " +"path looks as follows:\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/OProfile.adoc:797 +msgid "-agentlib:/usr/lib64/oprofile/libjvmti_oprofile.so" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:800 +#, no-wrap +msgid "" +"Currently, you can add one command-line option: [option]`--debug`, which " +"enables debugging mode.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:804 +#, no-wrap +msgid "" +".Install the oprofile-jit package\n" +"[NOTE]\n" +"====\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:806 +#, no-wrap +msgid "" +"The [package]*oprofile-jit* package must be installed on the system in order " +"to profile JIT code with OProfile. With this package, you gain the " +"capability to show method-level information.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:808 +#, no-wrap +msgid "====\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:810 +#, no-wrap +msgid "" +"Depending on the JVM that you are using, you may have to install the " +"*debuginfo* package for the JVM. For OpenJDK, this package is required, " +"there is no debuginfo package for Oracle JDK. To keep the debug information " +"packages synchronized with their respective non-debug packages, you also " +"need to install the *yum-plugin-auto-update-debug-info* plug-in. This " +"plug-in searches the debug information repository for corresponding " +"updates.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:812 +#, no-wrap +msgid "" +"After successful setup, you can apply the standard profiling and analyzing " +"tools described in previous sections\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:814 +#, no-wrap +msgid "" +"To learn more about Java support in OProfile, see the OProfile Manual, which " +"is linked from " +"xref:OProfile.adoc#s1-oprofile_additional_resources[Additional Resources].\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:816 +#, no-wrap +msgid "[[s1-oprofile-gui]]\n" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/OProfile.adoc:816 +#, no-wrap +msgid "Graphical Interface" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:819 +msgid "" +"indexterm:[oprof_start] Some OProfile preferences can be set with a " +"graphical interface. Make sure you have the `oprofile-gui` package that " +"provides the OProfile GUI installed on your system. To start the interface, " +"execute the [command]#oprof_start# command as root at a shell prompt." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:821 +msgid "" +"After changing any of the options, save them by clicking the btn:[Save and " +"quit] button. The preferences are written to `/root/.oprofile/daemonrc`, and " +"the application exits. Exiting the application does not stop OProfile from " +"sampling." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:823 +msgid "" +"On the `Setup` tab, to set events for the processor counters as discussed in " +"xref:OProfile.adoc#s2-oprofile-events[Setting Events to Monitor], select the " +"counter from the pulldown menu and select the event from the list. A brief " +"description of the event appears in the text box below the list. Only events " +"available for the specific counter and the specific architecture are " +"displayed. The interface also displays whether the profiler is running and " +"some brief statistics about it." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:826 +msgid "[[fig-oprofile-setup]] .OProfile Setup" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:828 +msgid "image::oprof-start-setup.png[oprof_start interface]" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:830 +msgid "" +"On the right side of the tab, select the `Profile kernel` option to count " +"events in kernel mode for the currently selected event, as discussed in " +"xref:OProfile.adoc#s2-oprofile-starting-separate[Separating Kernel and " +"User-space Profiles]. If this option is not selected, no samples are " +"collected for the kernel." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:832 +msgid "" +"Select the `Profile user binaries` option to count events in user mode for " +"the currently selected event, as discussed in " +"xref:OProfile.adoc#s2-oprofile-starting-separate[Separating Kernel and " +"User-space Profiles]. If this option is not selected, no samples are " +"collected for user applications." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:834 +msgid "" +"Use the `Count` text field to set the sampling rate for the currently " +"selected event as discussed in " +"xref:OProfile.adoc#s3-oprofile-events-sampling[Sampling Rate]." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:836 +msgid "" +"If any unit masks are available for the currently selected event, as " +"discussed in xref:OProfile.adoc#s3-oprofile-events-unit-masks[Unit Masks], " +"they are displayed in the `Unit Masks` area on the right side of the `Setup` " +"tab. Select the check box beside the unit mask to enable it for the event." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:838 +msgid "" +"On the `Configuration` tab, to profile the kernel, enter the name and " +"location of the `vmlinux` file for the kernel to monitor in the `Kernel " +"image file` text field. To configure OProfile not to monitor the kernel, " +"select `No kernel image`." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:841 +msgid "[[fig-oprofile-configuration]] .OProfile Configuration" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:843 +msgid "image::oprof-start-config.png[OProfile Configuration]" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:845 +msgid "" +"If the `Verbose` option is selected, the [command]#oprofiled# daemon log " +"includes more detailed information." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:847 +msgid "" +"If `Per-application profiles` is selected, OProfile generates " +"per-application profiles for libraries. This is equivalent to the " +"[command]#opcontrol --separate=library# command. If `Per-application " +"profiles, including kernel` is selected, OProfile generates per-application " +"profiles for the kernel and kernel modules as discussed in " +"xref:OProfile.adoc#s2-oprofile-starting-separate[Separating Kernel and " +"User-space Profiles]. This is equivalent to the [command]#opcontrol " +"--separate=kernel# command." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:849 +msgid "" +"To force data to be written to samples files as discussed in " +"xref:OProfile.adoc#s1-oprofile-analyzing-data[Analyzing the Data], click the " +"btn:[Flush] button. This is equivalent to the [command]#opcontrol --dump# " +"command." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:851 +msgid "" +"To start OProfile from the graphical interface, click btn:[Start]. To stop " +"the profiler, click btn:[Stop]. Exiting the application does not stop " +"OProfile from sampling." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:853 +msgid "[[s1-oprofile-and-systemtap]]" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/OProfile.adoc:853 +#, no-wrap +msgid "OProfile and SystemTap" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:856 +msgid "" +"indexterm:[OProfile,SystemTap] SystemTap is a tracing and probing tool that " +"allows users to study and monitor the activities of the operating system in " +"fine detail. It provides information similar to the output of tools like " +"[command]#netstat#, [command]#ps#, [command]#top#, and " +"[command]#iostat#pass:attributes[{blank}]; however, SystemTap is designed to " +"provide more filtering and analysis options for the collected information." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:858 +msgid "" +"While using OProfile is suggested in cases of collecting data on where and " +"why the processor spends time in a particular area of code, it is less " +"usable when finding out why the processor stays idle." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:860 +msgid "" +"You might want to use SystemTap when instrumenting specific places in " +"code. Because SystemTap allows you to run the code instrumentation without " +"having to stop and restart the instrumented code, it is particularly useful " +"for instrumenting the kernel and daemons." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:862 +msgid "" +"For more information on SystemTap, see " +"xref:OProfile.adoc#br-oprofile_online_documentation[Online Documentation] " +"for the relevant SystemTap documentation." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:864 +msgid "[[s1-oprofile_additional_resources]]" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/OProfile.adoc:864 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:867 +msgid "" +"indexterm:[OProfile,additional resources] To learn more about OProfile and " +"how to configure it, see the following resources." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:869 +msgid ".Installed Documentation" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:871 +#, no-wrap +msgid "* `/usr/share/doc/oprofile/oprofile.html` — [citetitle]_OProfile Manual_\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:873 +#, no-wrap +msgid "" +"* `oprofile(1)` manual page — Discusses [command]#opcontrol#, " +"[command]#opreport#, [command]#opannotate#, and [command]#ophelp#\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:875 +#, no-wrap +msgid "* `operf(1)` manual page\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:878 +#, no-wrap +msgid "" +"[[br-oprofile_online_documentation]]\n" +".Online Documentation\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:880 +#, no-wrap +msgid "" +"* " +"link:++https://oprofile.sourceforge.net/++[http://oprofile.sourceforge.net/] " +"— Contains the latest upstream documentation, mailing lists, IRC channels, " +"and more.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:882 +#, no-wrap +msgid ".See Also\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/OProfile.adoc:883 +#, no-wrap +msgid "" +"* " +"link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/SystemTap_Beginners_Guide/index.html++[SystemTap " +"Beginners Guide] — Provides basic instructions on how to use SystemTap to " +"monitor different subsystems of {MAJOROS} in finer detail.\n" +msgstr "" diff --git a/pot/rawhide/pages/monitoring-and-automation/System_Monitoring_Tools.pot b/pot/rawhide/pages/monitoring-and-automation/System_Monitoring_Tools.pot new file mode 100644 index 00000000000..a297dd70623 --- /dev/null +++ b/pot/rawhide/pages/monitoring-and-automation/System_Monitoring_Tools.pot @@ -0,0 +1,3066 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:5 +#, no-wrap +msgid "System Monitoring Tools" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:8 +msgid "" +"indexterm:[system information,gathering]indexterm:[information,about your " +"system] In order to configure the system, system administrators often need " +"to determine the amount of free memory, how much free disk space is " +"available, how the hard drive is partitioned, or what processes are running." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:10 +#, no-wrap +msgid "Viewing System Processes" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:12 +msgid "indexterm:[system information,processes]indexterm:[processes]" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:14 +#, no-wrap +msgid "Using the ps Command" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:17 +msgid "" +"indexterm:[ps] The [command]#ps# command allows you to display information " +"about running processes. It produces a static list, that is, a snapshot of " +"what is running when you execute the command. If you want a constantly " +"updated list of running processes, use the [command]#top# command or the " +"[application]*System Monitor* application instead." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:19 +msgid "" +"To list all processes that are currently running on the system including " +"processes owned by other users, type the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:23 +#, no-wrap +msgid "[command]#ps# [option]`ax`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:26 +msgid "" +"For each listed process, the [command]#ps ax# command displays the process " +"ID (`PID`), the terminal that is associated with it (`TTY`), the current " +"status (`STAT`), the cumulated CPU time (`TIME`), and the name of the " +"executable file (`COMMAND`). For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:37 +#, no-wrap +msgid "" +"~]$ [command]#ps ax#\n" +" PID TTY STAT TIME COMMAND\n" +" 1 ? Ss 0:02 /usr/lib/systemd/systemd --system --deserialize " +"20\n" +" 2 ? S 0:00 [kthreadd]\n" +" 3 ? S 0:00 [ksoftirqd/0]\n" +" 5 ? S 0:00 [kworker/u:0]\n" +" 6 ? S 0:00 [migration/0]\n" +"_[output truncated]_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:40 +msgid "To display the owner alongside each process, use the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:44 +#, no-wrap +msgid "[command]#ps# [option]`aux`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:47 +msgid "" +"Apart from the information provided by the [command]#ps ax# command, " +"[command]#ps aux# displays the effective username of the process owner " +"(`USER`), the percentage of the CPU (`%CPU`) and memory (`%MEM`) usage, the " +"virtual memory size in kilobytes (`VSZ`), the non-swapped physical memory " +"size in kilobytes (`RSS`), and the time or date the process was started. For " +"instance:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:58 +#, no-wrap +msgid "" +"~]$ [command]#ps aux#\n" +"USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND\n" +"root 1 0.0 0.3 53128 2988 ? Ss 13:28 0:02 " +"/usr/lib/systemd/systemd --system --deserialize 20\n" +"root 2 0.0 0.0 0 0 ? S 13:28 0:00 " +"[kthreadd]\n" +"root 3 0.0 0.0 0 0 ? S 13:28 0:00 " +"[ksoftirqd/0]\n" +"root 5 0.0 0.0 0 0 ? S 13:28 0:00 " +"[kworker/u:0]\n" +"root 6 0.0 0.0 0 0 ? S 13:28 0:00 " +"[migration/0]\n" +"_[output truncated]_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:61 +msgid "" +"You can also use the [command]#ps# command in a combination with " +"[command]#grep# to see if a particular process is running. For example, to " +"determine if [application]*Emacs* is running, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:66 +#, no-wrap +msgid "" +"~]$ [command]#ps ax | grep emacs#\n" +" 2625 ? Sl 0:00 emacs\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:69 +msgid "" +"For a complete list of available command line options, refer to the *ps*(1) " +"manual page." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:71 +#, no-wrap +msgid "Using the top Command" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:74 +msgid "" +"indexterm:[system information,processes,currently running]indexterm:[top] " +"The [command]#top# command displays a real-time list of processes that are " +"running on the system. It also displays additional information about the " +"system uptime, current CPU and memory usage, or total number of running " +"processes, and allows you to perform actions such as sorting the list or " +"killing a process." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:76 +msgid "To run the [command]#top# command, type the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:80 +#, no-wrap +msgid "[command]#top#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:83 +msgid "" +"For each listed process, the [command]#top# command displays the process ID " +"(`PID`), the effective username of the process owner (`USER`), the priority " +"(`PR`), the nice value (`NI`), the amount of virtual memory the process uses " +"(`VIRT`), the amount of non-swapped physical memory the process uses " +"(`RES`), the amount of shared memory the process uses (`SHR`), the " +"percentage of the CPU (`%CPU`) and memory (`%MEM`) usage, the cumulated CPU " +"time (`TIME+`), and the name of the executable file (`COMMAND`). For " +"example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:91 +#, no-wrap +msgid "" +"~]$ top\n" +"top - 19:22:08 up 5:53, 3 users, load average: 1.08, 1.03, 0.82\n" +"Tasks: 117 total, 2 running, 115 sleeping, 0 stopped, 0 zombie\n" +"Cpu(s): 9.3%us, 1.3%sy, 0.0%ni, 85.1%id, 0.0%wa, 1.7%hi, 0.0%si, " +"2.6%st\n" +"Mem: 761956k total, 617256k used, 144700k free, 24356k buffers\n" +"Swap: 1540092k total, 55780k used, 1484312k free, 256408k cached\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:110 +#, no-wrap +msgid "" +" PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND\n" +" 510 john 20 0 1435m 99m 18m S 9.0 13.3 3:30.52 gnome-shell\n" +"32686 root 20 0 156m 27m 3628 R 2.0 3.7 0:48.69 Xorg\n" +" 2625 john 20 0 488m 27m 14m S 0.3 3.7 0:00.70 emacs\n" +" 1 root 20 0 53128 2640 1152 S 0.0 0.3 0:02.83 systemd\n" +" 2 root 20 0 0 0 0 S 0.0 0.0 0:00.01 kthreadd\n" +" 3 root 20 0 0 0 0 S 0.0 0.0 0:00.18 ksoftirqd/0\n" +" 5 root 20 0 0 0 0 S 0.0 0.0 0:00.00 kworker/u:0\n" +" 6 root RT 0 0 0 0 S 0.0 0.0 0:00.00 migration/0\n" +" 7 root RT 0 0 0 0 S 0.0 0.0 0:00.30 watchdog/0\n" +" 8 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 cpuset\n" +" 9 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 khelper\n" +" 10 root 20 0 0 0 0 S 0.0 0.0 0:00.00 kdevtmpfs\n" +" 11 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 netns\n" +" 12 root 20 0 0 0 0 S 0.0 0.0 0:00.11 sync_supers\n" +" 13 root 20 0 0 0 0 S 0.0 0.0 0:00.00 bdi-default\n" +" 14 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 kintegrityd\n" +" 15 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 kblockd\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:113 +msgid "" +"xref:System_Monitoring_Tools.adoc#interactive-top-command[Interactive top " +"commands] contains useful interactive commands that you can use with " +"[command]#top#. For more information, refer to the *top*(1) manual page." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:115 +#, no-wrap +msgid "Interactive top commands" +msgstr "" + +#. type: Table +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:128 +#, no-wrap +msgid "" +"|Command|Description\n" +"|kbd:[Enter], kbd:[Space]|Immediately refreshes the display.\n" +"|kbd:[h], kbd:[?]|Displays a help screen.\n" +"|kbd:[k]|Kills a process. You are prompted for the process ID and the signal " +"to send to it.\n" +"|kbd:[n]|Changes the number of displayed processes. You are prompted to " +"enter the number.\n" +"|kbd:[u]|Sorts the list by user.\n" +"|kbd:[M]|Sorts the list by memory usage.\n" +"|kbd:[P]|Sorts the list by CPU usage.\n" +"|kbd:[q]|Terminates the utility and returns to the shell prompt.\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:131 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:223 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:241 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:579 +#, no-wrap +msgid "Using the System Monitor Tool" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:134 +msgid "" +"indexterm:[gnome-system-monitor]indexterm:[System Monitor] The `Processes` " +"tab of the [application]*System Monitor* tool allows you to view, search " +"for, change the priority of, and kill processes from the graphical user " +"interface." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:136 +msgid "" +"To start the [application]*System Monitor* tool, either select " +"menu:Applications[System Tools > `System Monitor`pass:attributes[{blank}]] " +"from the Activities menu, or type [command]#gnome-system-monitor# at a shell " +"prompt. Then click the `Processes` tab to view the list of running " +"processes." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:146 +msgid "" +"For each listed process, the [application]*System Monitor* tool displays its " +"name (`Process Name`), user (`User`), percentage of the CPU usage (`% CPU`), " +"process ID (`ID`), memory usage (`Memory`), total disk read and write (`Disk " +"read total` and `Disk write total`), current disk read and write (`Disk " +"read` and `Disk write`), and priority (`Priority`). To sort the information " +"by a specific column in ascending order, click the name of that " +"column. Click the name of the column again to toggle the sort between " +"ascending and descending order." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:148 +msgid "" +"By default, the [application]*System Monitor* tool displays a list of " +"processes that are owned by the current user. Selecting various options from " +"the View menu allows you to:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:150 +msgid "view only active processes," +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:152 +msgid "view all processes," +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:154 +msgid "view your processes," +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:156 +msgid "view process dependencies," +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:158 +msgid "view a memory map of a selected process," +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:160 +msgid "view the files opened by a selected process, and" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:162 +msgid "refresh the list of processes." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:164 +msgid "Additionally, various options in the Edit menu allows you to:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:166 +msgid "stop a process," +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:168 +msgid "continue running a stopped process," +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:170 +msgid "end a process," +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:172 +msgid "kill a process," +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:174 +msgid "change the priority of a selected process, and" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:176 +msgid "" +"edit the [application]*System Monitor* preferences, such as the refresh " +"interval for the list of processes, or what information to show." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:178 +msgid "" +"You can also end a process by selecting it from the list and clicking the " +"btn:[End Process] button." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:180 +#, no-wrap +msgid "Viewing Memory Usage" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:182 +msgid "" +"indexterm:[system information,memory usage]indexterm:[memory " +"usage]indexterm:[RAM]" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:184 +#, no-wrap +msgid "Using the free Command" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:187 +msgid "" +"indexterm:[free] The [command]#free# command allows you to display the " +"amount of free and used memory on the system. To do so, type the following " +"at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:191 +#, no-wrap +msgid "[command]#free#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:194 +msgid "" +"The [command]#free# command provides information about both the physical " +"memory (`Mem`) and swap space (`Swap`). It displays the total amount of " +"memory (`total`), as well as the amount of memory that is in use (`used`), " +"free (`free`), shared (`shared`), in kernel buffers (`buffers`), and cached " +"(`cached`). For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:201 +#, no-wrap +msgid "" +"~]$ free\n" +" total used free shared buffers cached\n" +"Mem: 761956 607500 154456 0 37404 156176\n" +"-/+ buffers/cache: 413920 348036\n" +"Swap: 1540092 84408 1455684\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:204 +msgid "" +"By default, [command]#free# displays the values in kilobytes. To display the " +"values in megabytes, supply the [option]`-m` command line option:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:208 +#, no-wrap +msgid "[command]#free# [option]`-m`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:211 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:289 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:430 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:500 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:549 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:681 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:736 +msgid "For instance:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:218 +#, no-wrap +msgid "" +"~]$ free -m\n" +" total used free shared buffers cached\n" +"Mem: 744 593 150 0 36 152\n" +"-/+ buffers/cache: 404 339\n" +"Swap: 1503 82 1421\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:221 +msgid "" +"For a complete list of available command line options, refer to the " +"*free*(1) manual page." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:226 +msgid "" +"indexterm:[gnome-system-monitor]indexterm:[System Monitor] The `Resources` " +"tab of the [application]*System Monitor* tool allows you to view the amount " +"of free and used memory on the system." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:228 +msgid "" +"To start the [application]*System Monitor* tool, either select " +"menu:Applications[System Tools > `System Monitor`pass:attributes[{blank}]] " +"from the Activities menu, or type [command]#gnome-system-monitor# at a shell " +"prompt. Then click the `Resources` tab to view the system's memory usage." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:230 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:248 +#, no-wrap +msgid "System Monitor — Resources" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:232 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:250 +#, no-wrap +msgid "The Resources tab of the System Monitor application." +msgstr "" + +#. type: Target for macro image +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:232 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:250 +#, no-wrap +msgid "system-monitor-resources.png" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:235 +msgid "" +"In the `Memory and Swap History` section, the [application]*System Monitor* " +"tool displays a graphical representation of the memory and swap usage " +"history, as well as the total amount of the physical memory (`Memory`) and " +"swap space (`Swap`) and how much of it is in use." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:237 +#, no-wrap +msgid "Viewing CPU Usage" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:239 +msgid "indexterm:[system information,cpu usage]indexterm:[CPU usage]" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:244 +msgid "" +"indexterm:[gnome-system-monitor]indexterm:[System Monitor] The `Resources` " +"tab of the [application]*System Monitor* tool allows you to view the current " +"CPU usage on the system." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:246 +msgid "" +"To start the [application]*System Monitor* tool, either select " +"menu:Applications[System Tools > `System Monitor`pass:attributes[{blank}]] " +"from the Activities menu, or type [command]#gnome-system-monitor# at a shell " +"prompt. Then click the `Resources` tab to view the system's CPU usage." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:253 +msgid "" +"In the `CPU History` section, the [application]*System Monitor* tool " +"displays a graphical representation of the CPU usage history and shows the " +"percentage of how much CPU is currently in use." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:255 +#, no-wrap +msgid "Viewing Block Devices and File Systems" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:257 +msgid "indexterm:[system information,file systems]indexterm:[file systems]" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:259 +#, no-wrap +msgid "Using the lsblk Command" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:262 +msgid "" +"indexterm:[lsblk] The [command]#lsblk# command allows you to display a list " +"of available block devices. To do so, type the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:266 +#, no-wrap +msgid "[command]#lsblk#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:269 +msgid "" +"For each listed block device, the [command]#lsblk# command displays the " +"device name (`NAME`), major and minor device number (`MAJ:MIN`), if the " +"device is removable (`RM`), what is its size (`SIZE`), if the device is " +"read-only (`RO`), what type is it (`TYPE`), and where the device is mounted " +"(`MOUNTPOINT`). For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:279 +#, no-wrap +msgid "" +"~]$ lsblk\n" +"NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINT\n" +"sr0 11:0 1 1024M 0 rom\n" +"vda 252:0 0 20G 0 disk\n" +"|-vda1 252:1 0 500M 0 part /boot\n" +"`-vda2 252:2 0 19.5G 0 part\n" +" |-vg_fedora-lv_swap (dm-0) 253:0 0 1.5G 0 lvm [SWAP]\n" +" `-vg_fedora-lv_root (dm-1) 253:1 0 18G 0 lvm /\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:282 +msgid "" +"By default, [command]#lsblk# lists block devices in a tree-like format. To " +"display the information as an ordinary list, add the [option]`-l` command " +"line option:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:286 +#, no-wrap +msgid "[command]#lsblk# [option]`-l`\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:299 +#, no-wrap +msgid "" +"~]$ lsblk -l\n" +"NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINT\n" +"sr0 11:0 1 1024M 0 rom\n" +"vda 252:0 0 20G 0 disk\n" +"vda1 252:1 0 500M 0 part /boot\n" +"vda2 252:2 0 19.5G 0 part\n" +"vg_fedora-lv_swap (dm-0) 253:0 0 1.5G 0 lvm [SWAP]\n" +"vg_fedora-lv_root (dm-1) 253:1 0 18G 0 lvm /\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:302 +msgid "" +"For a complete list of available command line options, refer to the " +"*lsblk*(8) manual page." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:304 +#, no-wrap +msgid "Using the blkid Command" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:307 +msgid "" +"indexterm:[blkid] The [command]#blkid# command allows you to display " +"information about available block devices. To do so, type the following at a " +"shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:311 +#, no-wrap +msgid "[command]#blkid#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:314 +msgid "" +"For each listed block device, the [command]#blkid# command displays " +"available attributes such as its _universally unique identifier_ (`UUID`), " +"file system type (`TYPE`), or volume label (`LABEL`). For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:321 +#, no-wrap +msgid "" +"~]# blkid\n" +"/dev/vda1: UUID=\"4ea24c68-ab10-47d4-8a6b-b8d3a002acba\" TYPE=\"ext4\"\n" +"/dev/vda2: UUID=\"iJ9YwJ-leFf-A1zb-VVaK-H9t1-raLW-HoqlUG\" " +"TYPE=\"LVM2_member\"\n" +"/dev/mapper/vg_fedora-lv_swap: UUID=\"d6d755bc-3e3e-4e8f-9bb5-a5e7f4d86ffd\" " +"TYPE=\"swap\"\n" +"/dev/mapper/vg_fedora-lv_root: LABEL=\"_Fedora-17-x86_6\" " +"UUID=\"77ba9149-751a-48e0-974f-ad94911734b9\" TYPE=\"ext4\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:324 +msgid "" +"By default, the [command]#lsblk# command lists all available block " +"devices. To display information about a particular device only, specify the " +"device name on the command line:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:328 +#, no-wrap +msgid "blkid pass:quotes[_device_name_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:331 +msgid "For instance, to display information about `/dev/vda1`, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:335 +#, no-wrap +msgid "" +"~]# blkid /dev/vda1\n" +"/dev/vda1: UUID=\"4ea24c68-ab10-47d4-8a6b-b8d3a002acba\" TYPE=\"ext4\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:338 +msgid "" +"You can also use the above command with the [option]`-p` and [option]`-o " +"udev` command line options to obtain more detailed information. Note that " +"`root` privileges are required to run this command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:342 +#, no-wrap +msgid "blkid -po udev pass:quotes[_device_name_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:345 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:529 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:569 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:607 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:722 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:756 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:794 +msgid "For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:360 +#, no-wrap +msgid "" +"~]# blkid -po udev /dev/vda1\n" +"ID_FS_UUID=4ea24c68-ab10-47d4-8a6b-b8d3a002acba\n" +"ID_FS_UUID_ENC=4ea24c68-ab10-47d4-8a6b-b8d3a002acba\n" +"ID_FS_VERSION=1.0\n" +"ID_FS_TYPE=ext4\n" +"ID_FS_USAGE=filesystem\n" +"ID_PART_ENTRY_SCHEME=dos\n" +"ID_PART_ENTRY_TYPE=0x83\n" +"ID_PART_ENTRY_FLAGS=0x80\n" +"ID_PART_ENTRY_NUMBER=1\n" +"ID_PART_ENTRY_OFFSET=2048\n" +"ID_PART_ENTRY_SIZE=1024000\n" +"ID_PART_ENTRY_DISK=252:0\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:363 +msgid "" +"For a complete list of available command line options, refer to the " +"*blkid*(8) manual page." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:365 +#, no-wrap +msgid "Using the partx Command" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:368 +msgid "" +"indexterm:[partx] The [command]#partx# command allows you to display a list " +"of disk partitions. To list the partition table of a particular disk, as " +"`root`, run this command with the [option]`-s` option followed by the device " +"name:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:372 +#, no-wrap +msgid "partx -s pass:quotes[_device_name_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:375 +msgid "For example, to list partitions on `/dev/vda`, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:381 +#, no-wrap +msgid "" +"~]# partx -s /dev/vda\n" +"NR START END SECTORS SIZE NAME UUID\n" +" 1 2048 1026047 1024000 500M\n" +" 2 1026048 41943039 40916992 19.5G\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:384 +msgid "" +"For a complete list of available command line options, refer to the " +"*partx*(8) manual page." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:386 +#, no-wrap +msgid "Using the findmnt Command" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:389 +msgid "" +"indexterm:[findmnt] The [command]#findmnt# command allows you to display a " +"list of currently mounted file systems. To do so, type the following at a " +"shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:393 +#, no-wrap +msgid "[command]#findmnt#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:396 +msgid "" +"For each listed file system, the [command]#findmnt# command displays the " +"target mount point (`TARGET`), source device (`SOURCE`), file system type " +"(`FSTYPE`), and relevant mount options (`OPTIONS`). For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:420 +#, no-wrap +msgid "" +"~]$ findmnt\n" +"TARGET SOURCE FSTYPE OPTIONS\n" +"/ /dev/mapper/vg_fedora-lv_root\n" +" ext4 " +"rw,relatime,seclabel,data=o\n" +"|-/proc proc proc " +"rw,nosuid,nodev,noexec,rela\n" +"| `-/proc/sys/fs/binfmt_misc systemd-1 autofs " +"rw,relatime,fd=23,pgrp=1,ti\n" +"|-/sys sysfs sysfs " +"rw,nosuid,nodev,noexec,rela\n" +"| |-/sys/kernel/security securityfs security " +"rw,nosuid,nodev,noexec,rela\n" +"| |-/sys/fs/selinux selinuxfs selinuxf rw,relatime\n" +"| |-/sys/fs/cgroup tmpfs tmpfs " +"rw,nosuid,nodev,noexec,secl\n" +"| | |-/sys/fs/cgroup/systemd cgroup cgroup " +"rw,nosuid,nodev,noexec,rela\n" +"| | |-/sys/fs/cgroup/cpuset cgroup cgroup " +"rw,nosuid,nodev,noexec,rela\n" +"| | |-/sys/fs/cgroup/cpu,cpuacct cgroup cgroup " +"rw,nosuid,nodev,noexec,rela\n" +"| | |-/sys/fs/cgroup/memory cgroup cgroup " +"rw,nosuid,nodev,noexec,rela\n" +"| | |-/sys/fs/cgroup/devices cgroup cgroup " +"rw,nosuid,nodev,noexec,rela\n" +"| | |-/sys/fs/cgroup/freezer cgroup cgroup " +"rw,nosuid,nodev,noexec,rela\n" +"| | |-/sys/fs/cgroup/net_cls cgroup cgroup " +"rw,nosuid,nodev,noexec,rela\n" +"| | |-/sys/fs/cgroup/blkio cgroup cgroup " +"rw,nosuid,nodev,noexec,rela\n" +"| | `-/sys/fs/cgroup/perf_event cgroup cgroup " +"rw,nosuid,nodev,noexec,rela\n" +"| |-/sys/kernel/debug debugfs debugfs rw,relatime\n" +"| `-/sys/kernel/config configfs configfs rw,relatime\n" +"[output truncated]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:423 +msgid "" +"By default, [command]#findmnt# lists file systems in a tree-like format. To " +"display the information as an ordinary list, add the [option]`-l` command " +"line option:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:427 +#, no-wrap +msgid "[command]#findmnt# [option]`-l`\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:447 +#, no-wrap +msgid "" +"~]$ findmnt -l\n" +"TARGET SOURCE FSTYPE OPTIONS\n" +"/proc proc proc " +"rw,nosuid,nodev,noexec,relatime\n" +"/sys sysfs sysfs " +"rw,nosuid,nodev,noexec,relatime,s\n" +"/dev devtmpfs devtmpfs " +"rw,nosuid,seclabel,size=370080k,n\n" +"/dev/pts devpts devpts " +"rw,nosuid,noexec,relatime,seclabe\n" +"/dev/shm tmpfs tmpfs rw,nosuid,nodev,seclabel\n" +"/run tmpfs tmpfs " +"rw,nosuid,nodev,seclabel,mode=755\n" +"/ /dev/mapper/vg_fedora-lv_root\n" +" ext4 " +"rw,relatime,seclabel,data=ordered\n" +"/sys/kernel/security securityfs security " +"rw,nosuid,nodev,noexec,relatime\n" +"/sys/fs/selinux selinuxfs selinuxf rw,relatime\n" +"/sys/fs/cgroup tmpfs tmpfs " +"rw,nosuid,nodev,noexec,seclabel,m\n" +"/sys/fs/cgroup/systemd cgroup cgroup " +"rw,nosuid,nodev,noexec,relatime,r\n" +"[output truncated]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:450 +msgid "" +"You can also choose to list only file systems of a particular type. To do " +"so, add the [option]`-t` command line option followed by a file system type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:454 +#, no-wrap +msgid "[command]#findmnt# [option]`-t` _type_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:457 +msgid "For example, to all list `ext4` file systems, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:463 +#, no-wrap +msgid "" +"~]$ findmnt -t ext4\n" +"TARGET SOURCE FSTYPE OPTIONS\n" +"/ /dev/mapper/vg_fedora-lv_root ext4 " +"rw,relatime,seclabel,data=ordered\n" +"/boot /dev/vda1 ext4 " +"rw,relatime,seclabel,data=ordered\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:466 +msgid "" +"For a complete list of available command line options, refer to the " +"*findmnt*(8) manual page." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:468 +#, no-wrap +msgid "Using the df Command" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:471 +msgid "" +"indexterm:[df] The [command]#df# command allows you to display a detailed " +"report on the system's disk space usage. To do so, type the following at a " +"shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:475 +#, no-wrap +msgid "[command]#df#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:478 +msgid "" +"For each listed file system, the [command]#df# command displays its name " +"(`Filesystem`), size (`1K-blocks` or `Size`), how much space is used " +"(`Used`), how much space is still available (`Available`), the percentage of " +"space usage (`Use%`), and where is the file system mounted (`Mounted " +"on`). For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:490 +#, no-wrap +msgid "" +"~]$ df\n" +"Filesystem 1K-blocks Used Available Use% Mounted on\n" +"rootfs 18877356 4605476 14082844 25% /\n" +"devtmpfs 370080 0 370080 0% /dev\n" +"tmpfs 380976 256 380720 1% /dev/shm\n" +"tmpfs 380976 3048 377928 1% /run\n" +"/dev/mapper/vg_fedora-lv_root 18877356 4605476 14082844 25% /\n" +"tmpfs 380976 0 380976 0% " +"/sys/fs/cgroup\n" +"tmpfs 380976 0 380976 0% /media\n" +"/dev/vda1 508745 85018 398127 18% /boot\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:493 +msgid "" +"By default, the [command]#df# command shows the partition size in " +"1{nbsp}kilobyte blocks and the amount of used and available disk space in " +"kilobytes. To view the information in megabytes and gigabytes, supply the " +"[option]`-h` command line option, which causes [command]#df# to display the " +"values in a human-readable format:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:497 +#, no-wrap +msgid "[command]#df# [option]`-h`\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:512 +#, no-wrap +msgid "" +"~]$ df -h\n" +"Filesystem Size Used Avail Use% Mounted on\n" +"rootfs 19G 4.4G 14G 25% /\n" +"devtmpfs 362M 0 362M 0% /dev\n" +"tmpfs 373M 256K 372M 1% /dev/shm\n" +"tmpfs 373M 3.0M 370M 1% /run\n" +"/dev/mapper/vg_fedora-lv_root 19G 4.4G 14G 25% /\n" +"tmpfs 373M 0 373M 0% /sys/fs/cgroup\n" +"tmpfs 373M 0 373M 0% /media\n" +"/dev/vda1 497M 84M 389M 18% /boot\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:515 +msgid "" +"indexterm:[system information,file " +"systems,/dev/shm]indexterm:[/dev/shm]indexterm:[system information,file " +"systems,/sys/fs/cgroup]indexterm:[/sys/fs/cgroup]indexterm:[system " +"information,file systems,/run]indexterm:[/run] Note that the `/dev/shm` " +"entry represents the system's virtual memory file system, `/sys/fs/cgroup` " +"is a cgroup file system, and `/run` contains information about the running " +"system." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:517 +msgid "" +"For a complete list of available command line options, refer to the *df*(1) " +"manual page." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:519 +#, no-wrap +msgid "Using the du Command" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:522 +msgid "" +"indexterm:[du] The [command]#du# command allows you to displays the amount " +"of space that is being used by files in a directory. To display the disk " +"usage for each of the subdirectories in the current working directory, run " +"the command with no additional command line options:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:526 +#, no-wrap +msgid "[command]#du#\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:539 +#, no-wrap +msgid "" +"~]$ [command]#du#\n" +"8 ./.gconf/apps/gnome-terminal/profiles/Default\n" +"12 ./.gconf/apps/gnome-terminal/profiles\n" +"16 ./.gconf/apps/gnome-terminal\n" +"_[output truncated]_\n" +"460 ./.gimp-2.6\n" +"68828 .\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:542 +msgid "" +"By default, the [command]#du# command displays the disk usage in " +"kilobytes. To view the information in megabytes and gigabytes, supply the " +"[option]`-h` command line option, which causes the utility to display the " +"values in a human-readable format:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:546 +#, no-wrap +msgid "[command]#du# [option]`-h`\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:559 +#, no-wrap +msgid "" +"~]$ [command]#du -h#\n" +"8.0K ./.gconf/apps/gnome-terminal/profiles/Default\n" +"12K ./.gconf/apps/gnome-terminal/profiles\n" +"16K ./.gconf/apps/gnome-terminal\n" +"_[output truncated]_\n" +"460K ./.gimp-2.6\n" +"68M .\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:562 +msgid "" +"At the end of the list, the [command]#du# command always shows the grand " +"total for the current directory. To display only this information, supply " +"the [option]`-s` command line option:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:566 +#, no-wrap +msgid "[command]#du# [option]`-sh`\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:574 +#, no-wrap +msgid "" +"~]$ [command]#du -sh#\n" +"68M .\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:577 +msgid "" +"For a complete list of available command line options, refer to the *du*(1) " +"manual page." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:582 +msgid "" +"indexterm:[gnome-system-monitor]indexterm:[System Monitor] The `File " +"Systems` tab of the [application]*System Monitor* tool allows you to view " +"file systems and disk space usage in the graphical user interface." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:584 +msgid "" +"To start the [application]*System Monitor* tool, either select " +"menu:Applications[System Tools > `System Monitor`pass:attributes[{blank}]] " +"from the Activities menu, or type [command]#gnome-system-monitor# at a shell " +"prompt. Then click the `File Systems` tab to view a list of file systems." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:586 +#, no-wrap +msgid "System Monitor — File Systems" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:588 +#, no-wrap +msgid "The File Systems tab of the System Monitor application." +msgstr "" + +#. type: Target for macro image +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:588 +#, no-wrap +msgid "system-monitor-file-systems.png" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:591 +msgid "" +"For each listed file system, the [application]*System Monitor* tool displays " +"the source device (`Device`), target mount point (`Directory`), and file " +"system type (`Type`), as well as its size (`Total`) and how much space is " +"free (`Free`), available (`Available`), and used (`Used`)." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:593 +#, no-wrap +msgid "Viewing Hardware Information" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:595 +msgid "indexterm:[system information,hardware]indexterm:[hardware,viewing]" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:597 +#, no-wrap +msgid "Using the lspci Command" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:600 +msgid "" +"indexterm:[lspci] The [command]#lspci# command lists all PCI devices that " +"are present in the system:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:604 +#, no-wrap +msgid "[command]#lspci#\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:616 +#, no-wrap +msgid "" +"~]$ lspci\n" +"00:00.0 Host bridge: Intel Corporation 82X38/X48 Express DRAM Controller\n" +"00:01.0 PCI bridge: Intel Corporation 82X38/X48 Express Host-Primary PCI " +"Express Bridge\n" +"00:1a.0 USB Controller: Intel Corporation 82801I (ICH9 Family) USB UHCI " +"Controller #4 (rev 02)\n" +"00:1a.1 USB Controller: Intel Corporation 82801I (ICH9 Family) USB UHCI " +"Controller #5 (rev 02)\n" +"00:1a.2 USB Controller: Intel Corporation 82801I (ICH9 Family) USB UHCI " +"Controller #6 (rev 02)\n" +"[output truncated]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:619 +msgid "" +"You can also use the [option]`-v` command line option to display more " +"verbose output, or [option]`-vv` for very verbose output:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:623 +#, no-wrap +msgid "[command]#lspci# [option]`-v`|[option]`-vv`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:626 +msgid "" +"For instance, to determine the manufacturer, model, and memory size of a " +"system's video card, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:631 +#, no-wrap +msgid "" +"~]$ [command]#lspci -v#\n" +"_[output truncated]_\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:644 +#, no-wrap +msgid "" +"01:00.0 VGA compatible controller: nVidia Corporation G84 [Quadro FX 370] " +"(rev a1) (prog-if 00 [VGA controller])\n" +" Subsystem: nVidia Corporation Device 0491\n" +" Physical Slot: 2\n" +" Flags: bus master, fast devsel, latency 0, IRQ 16\n" +" Memory at f2000000 (32-bit, non-prefetchable) [size=16M]\n" +" Memory at e0000000 (64-bit, prefetchable) [size=256M]\n" +" Memory at f0000000 (64-bit, non-prefetchable) [size=32M]\n" +" I/O ports at 1100 [size=128]\n" +" Expansion ROM at <unassigned> [disabled]\n" +" Capabilities: <access denied>\n" +" Kernel driver in use: nouveau\n" +" Kernel modules: nouveau, nvidiafb\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:646 +#, no-wrap +msgid "_[output truncated]_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:649 +msgid "" +"For a complete list of available command line options, refer to the " +"*lspci*(8) manual page." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:651 +#, no-wrap +msgid "Using the lsusb Command" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:654 +msgid "" +"indexterm:[lsusb] The [command]#lsusb# command allows you to display " +"information about USB buses and devices that are attached to them. To list " +"all USB devices that are in the system, type the following at a shell " +"prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:658 +#, no-wrap +msgid "[command]#lsusb#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:661 +msgid "This displays a simple list of devices, for example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:671 +#, no-wrap +msgid "" +"~]$ [command]#lsusb#\n" +"Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub\n" +"Bus 002 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub\n" +"_[output truncated]_\n" +"Bus 001 Device 002: ID 0bda:0151 Realtek Semiconductor Corp. Mass Storage " +"Device (Multicard Reader)\n" +"Bus 008 Device 002: ID 03f0:2c24 Hewlett-Packard Logitech M-UAL-96 Mouse\n" +"Bus 008 Device 003: ID 04b3:3025 IBM Corp.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:674 +msgid "" +"You can also use the [option]`-v` command line option to display more " +"verbose output:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:678 +#, no-wrap +msgid "[command]#lsusb# [option]`-v`\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:686 +#, no-wrap +msgid "" +"~]$ [command]#lsusb -v#\n" +"_[output truncated]_\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:707 +#, no-wrap +msgid "" +"Bus 008 Device 002: ID 03f0:2c24 Hewlett-Packard Logitech M-UAL-96 Mouse\n" +"Device Descriptor:\n" +" bLength 18\n" +" bDescriptorType 1\n" +" bcdUSB 2.00\n" +" bDeviceClass 0 (Defined at Interface level)\n" +" bDeviceSubClass 0\n" +" bDeviceProtocol 0\n" +" bMaxPacketSize0 8\n" +" idVendor 0x03f0 Hewlett-Packard\n" +" idProduct 0x2c24 Logitech M-UAL-96 Mouse\n" +" bcdDevice 31.00\n" +" iManufacturer 1\n" +" iProduct 2\n" +" iSerial 0\n" +" bNumConfigurations 1\n" +" Configuration Descriptor:\n" +" bLength 9\n" +" bDescriptorType 2\n" +"_[output truncated]_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:710 +msgid "" +"For a complete list of available command line options, refer to the " +"*lsusb*(8) manual page." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:712 +#, no-wrap +msgid "Using the lspcmcia Command" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:715 +msgid "" +"indexterm:[lspcmcia] The [command]#lspcmcia# command allows you to list all " +"PCMCIA devices that are present in the system. To do so, type the following " +"at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:719 +#, no-wrap +msgid "[command]#lspcmcia#\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:726 +#, no-wrap +msgid "" +"~]$ lspcmcia\n" +"Socket 0 Bridge: [yenta_cardbus] (bus ID: 0000:15:00.0)\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:729 +msgid "" +"You can also use the [option]`-v` command line option to display more " +"verbose information, or [option]`-vv` to increase the verbosity level even " +"further:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:733 +#, no-wrap +msgid "[command]#lspcmcia# [option]`-v`|[option]`-vv`\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:741 +#, no-wrap +msgid "" +"~]$ lspcmcia -v\n" +"Socket 0 Bridge: [yenta_cardbus] (bus ID: 0000:15:00.0)\n" +" Configuration: state: on ready: unknown\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:744 +msgid "" +"For a complete list of available command line options, refer to the " +"*pccardctl*(8) manual page." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:746 +#, no-wrap +msgid "Using the lscpu Command" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:749 +msgid "" +"indexterm:[lscpu] The [command]#lscpu# command allows you to list " +"information about CPUs that are present in the system, including the number " +"of CPUs, their architecture, vendor, family, model, CPU caches, etc. To do " +"so, type the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:753 +#, no-wrap +msgid "[command]#lscpu#\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:779 +#, no-wrap +msgid "" +"~]$ lscpu\n" +"Architecture: x86_64\n" +"CPU op-mode(s): 32-bit, 64-bit\n" +"Byte Order: Little Endian\n" +"CPU(s): 4\n" +"On-line CPU(s) list: 0-3\n" +"Thread(s) per core: 1\n" +"Core(s) per socket: 4\n" +"Socket(s): 1\n" +"NUMA node(s): 1\n" +"Vendor ID: GenuineIntel\n" +"CPU family: 6\n" +"Model: 23\n" +"Stepping: 7\n" +"CPU MHz: 1998.000\n" +"BogoMIPS: 4999.98\n" +"Virtualization: VT-x\n" +"L1d cache: 32K\n" +"L1i cache: 32K\n" +"L2 cache: 3072K\n" +"NUMA node0 CPU(s): 0-3\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:782 +msgid "" +"For a complete list of available command line options, refer to the " +"*lscpu*(1) manual page." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:784 +#, no-wrap +msgid "Using the Hardware probe" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:787 +msgid "" +"indexterm:[hw-probe] The [command]#hw-probe# command allows you to list all " +"hardware devices, perform sanity tests for some of them and submit result to " +"the link:++https://github.com/linuxhw++[hardware database]. To do so, type " +"the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:791 +#, no-wrap +msgid "[command]#hw-probe -all -upload#\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:801 +#, no-wrap +msgid "" +"~]$ hw-probe -all -upload\n" +"Probe for hardware ... Ok\n" +"Reading logs ... Ok\n" +"Uploaded to DB, Thank you!\n" +"Probe URL: https://linux-hardware.org/?probe=c84b37d646\n" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:804 +#, no-wrap +msgid "Monitoring Performance with Net-SNMP" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:807 +msgid "" +"{MAJOROSVER} includes the [application]*Net-SNMP* software suite, which " +"includes a flexible and extensible _Simple Network Management Protocol_ " +"(*SNMP*) agent. This agent and its associated utilities can be used to " +"provide performance data from a large number of systems to a variety of " +"tools which support polling over the SNMP protocol." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:809 +msgid "" +"This section provides information on configuring the Net-SNMP agent to " +"securely provide performance data over the network, retrieving the data " +"using the SNMP protocol, and extending the SNMP agent to provide custom " +"performance metrics." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:811 +#, no-wrap +msgid "Installing Net-SNMP" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:814 +msgid "" +"The Net-SNMP software suite is available as a set of RPM packages in the " +"{MAJOROS} software " +"distribution. " +"xref:System_Monitoring_Tools.adoc#tabl-System_Monitoring_Tools-Net-SNMP-Packages[Available " +"Net-SNMP packages] summarizes each of the packages and their contents." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:816 +#, no-wrap +msgid "Available Net-SNMP packages" +msgstr "" + +#. type: Table +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:826 +#, no-wrap +msgid "" +"|Package|Provides\n" +"|[package]*net-snmp*|The SNMP Agent Daemon and documentation. This package " +"is required for exporting performance data.\n" +"|[package]*net-snmp-libs*|The `netsnmp` library and the bundled management " +"information bases (MIBs). This package is required for exporting performance " +"data.\n" +"|[package]*net-snmp-utils*|SNMP clients such as [command]#snmpget# and " +"[command]#snmpwalk#. This package is required in order to query a system's " +"performance data over SNMP.\n" +"|[package]*net-snmp-perl*|The [command]#mib2c# utility and the `NetSNMP` " +"Perl module.\n" +"|[package]*net-snmp-python*|An SNMP client library for Python.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:829 +msgid "" +"To install any of these packages, use the [command]#dnf# command in the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:833 +#, no-wrap +msgid "[command]#dnf# [option]`install` _package_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:836 +msgid "" +"For example, to install the SNMP Agent Daemon and SNMP clients used in the " +"rest of this section, type the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:839 +#, no-wrap +msgid "~]# dnf install net-snmp net-snmp-libs net-snmp-utils\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:842 +msgid "" +"Note that you must have superuser privileges (that is, you must be logged in " +"as `root`) to run this command. For more information on how to install new " +"packages in {MAJOROS}, refer to " +"xref:package-management/DNF.adoc#sec-Installing[Installing Packages]." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:844 +#, no-wrap +msgid "Running the Net-SNMP Daemon" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:847 +msgid "" +"The [package]*net-snmp* package contains `snmpd`, the SNMP Agent " +"Daemon. This section provides information on how to start, stop, and restart " +"the `snmpd` service, and shows how to enable or disable it in the " +"`multi-user` target unit. For more information on the concept of target " +"units and how to manage system services in {MAJOROS} in general, refer to " +"xref:infrastructure-services/Services_and_Daemons.adoc#ch-Services_and_Daemons[Services " +"and Daemons]." +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:849 +#, no-wrap +msgid "Starting the Service" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:852 +msgid "" +"To run the `snmpd` service in the current session, type the following at a " +"shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:856 +#, no-wrap +msgid "[command]#systemctl# [option]`start` [option]`snmpd.service`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:859 +msgid "" +"To configure the service to be automatically started at boot time, use the " +"following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:863 +#, no-wrap +msgid "[command]#systemctl# [option]`enable` [option]`snmpd.service`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:866 +msgid "This will enable the service in the `multi-user` target unit." +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:868 +#, no-wrap +msgid "Stopping the Service" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:871 +msgid "" +"To stop the running `snmpd` service, type the following at a shell prompt as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:875 +#, no-wrap +msgid "[command]#systemctl# [option]`stop` [option]`snmpd.service`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:878 +msgid "To disable starting the service at boot time, use the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:882 +#, no-wrap +msgid "[command]#systemctl# [option]`disable` [option]`snmpd.service`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:885 +msgid "This will disable the service in the `multi-user` target unit." +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:887 +#, no-wrap +msgid "Restarting the Service" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:890 +msgid "" +"To restart the running `snmpd` service, type the following at a shell " +"prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:894 +#, no-wrap +msgid "[command]#systemctl# [option]`restart` [option]`snmpd.service`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:897 +msgid "" +"This will stop the service and start it again in quick succession. To only " +"reload the configuration without stopping the service, run the following " +"command instead:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:901 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:923 +#, no-wrap +msgid "[command]#systemctl# [option]`reload` [option]`snmpd.service`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:904 +msgid "This will cause the running `snmpd` service to reload the configuration." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:906 +#, no-wrap +msgid "Configuring Net-SNMP" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:909 +msgid "" +"To change the Net-SNMP Agent Daemon configuration, edit the " +"`/etc/snmp/snmpd.conf` configuration file. The default `snmpd.conf` file " +"shipped with {MAJOROSVER} is heavily commented and serves as a good starting " +"point for agent configuration." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:911 +msgid "" +"This section focuses on two common tasks: setting system information and " +"configuring authentication. For more information about available " +"configuration directives, refer to the *snmpd.conf*(5) manual " +"page. Additionally, there is a utility in the [package]*net-snmp* package " +"named [command]#snmpconf# which can be used to interactively generate a " +"valid agent configuration." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:913 +msgid "" +"Note that the [package]*net-snmp-utils* package must be installed in order " +"to use the [command]#snmpwalk# utility described in this section." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:914 +#, no-wrap +msgid "Applying the changes" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:919 +msgid "" +"For any changes to the configuration file to take effect, force the `snmpd` " +"service to re-read the configuration by running the following command as " +"`root`:" +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:928 +#, no-wrap +msgid "Setting System Information" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:931 +msgid "" +"Net-SNMP provides some rudimentary system information via the `system` " +"tree. For example, the following [command]#snmpwalk# command shows the " +"`system` tree with a default agent configuration." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:940 +#, no-wrap +msgid "" +"~]# snmpwalk -v2c -c public localhost system\n" +"SNMPv2-MIB::sysDescr.0 = STRING: Linux localhost.localdomain " +"2.6.32-122.el6.x86_64 #1 SMP Wed Mar 9 23:54:34 EST 2011 x86_64\n" +"SNMPv2-MIB::sysObjectID.0 = OID: NET-SNMP-MIB::netSnmpAgentOIDs.10\n" +"DISMAN-EVENT-MIB::sysUpTimeInstance = Timeticks: (99554) 0:16:35.54\n" +"SNMPv2-MIB::sysContact.0 = STRING: Root (configure " +"/etc/snmp/snmp.local.conf)\n" +"SNMPv2-MIB::sysName.0 = STRING: localhost.localdomain\n" +"SNMPv2-MIB::sysLocation.0 = STRING: Unknown (edit /etc/snmp/snmpd.conf)\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:943 +msgid "" +"By default, the `sysName` object is set to the hostname. The `sysLocation` " +"and `sysContact` objects can be configured in the `/etc/snmp/snmpd.conf` " +"file by changing the value of the [option]`syslocation` and " +"[option]`syscontact` directives, for example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:948 +#, no-wrap +msgid "" +"syslocation Datacenter, Row 3, Rack 2\n" +"syscontact UNIX Admin <admin@example.com>\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:951 +msgid "" +"After making changes to the configuration file, reload the configuration and " +"test it by running the [command]#snmpwalk# command again:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:961 +#, no-wrap +msgid "" +"~]# systemct reload snmpd.service\n" +"~]# snmpwalk -v2c -c public localhost system\n" +"SNMPv2-MIB::sysDescr.0 = STRING: Linux localhost.localdomain " +"2.6.32-122.el6.x86_64 #1 SMP Wed Mar 9 23:54:34 EST 2011 x86_64\n" +"SNMPv2-MIB::sysObjectID.0 = OID: NET-SNMP-MIB::netSnmpAgentOIDs.10\n" +"DISMAN-EVENT-MIB::sysUpTimeInstance = Timeticks: (158357) 0:26:23.57\n" +"SNMPv2-MIB::sysContact.0 = STRING: UNIX Admin \n" +"SNMPv2-MIB::sysName.0 = STRING: localhost.localdomain\n" +"SNMPv2-MIB::sysLocation.0 = STRING: Datacenter, Row 3, Rack 2\n" +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:964 +#, no-wrap +msgid "Configuring Authentication" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:967 +msgid "" +"The Net-SNMP Agent Daemon supports all three versions of the SNMP " +"protocol. The first two versions (1 and 2c) provide for simple " +"authentication using a _community string_. This string is a shared secret " +"between the agent and any client utilities. The string is passed in clear " +"text over the network however and is not considered secure. Version 3 of the " +"SNMP protocol supports user authentication and message encryption using a " +"variety of protocols. The Net-SNMP agent also supports tunneling over SSH, " +"TLS authentication with X.509 certificates, and Kerberos authentication." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:968 +#, no-wrap +msgid "Configuring SNMP Version 2c Community" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:970 +msgid "" +"To configure an *SNMP version 2c community*, use either the " +"[option]`rocommunity` or [option]`rwcommunity` directive in the " +"`/etc/snmp/snmpd.conf` configuration file. The format of the directives is " +"the following:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:974 +#, no-wrap +msgid "_directive_ _community_ _source_ _OID_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:977 +msgid "" +"… where _community_ is the community string to use, _source_ is an IP " +"address or subnet, and _OID_ is the SNMP tree to provide access to. For " +"example, the following directive provides read-only access to the `system` " +"tree to a client using the community string \"`redhat`\" on the local " +"machine:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:981 +#, no-wrap +msgid "rocommunity redhat 127.0.0.1 .1.3.6.1.2.1.1\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:984 +msgid "" +"To test the configuration, use the [command]#snmpwalk# command with the " +"[option]`-v` and [option]`-c` options." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:993 +#, no-wrap +msgid "" +"~]# snmpwalk -v2c -c redhat localhost system\n" +"SNMPv2-MIB::sysDescr.0 = STRING: Linux localhost.localdomain " +"2.6.32-122.el6.x86_64 #1 SMP Wed Mar 9 23:54:34 EST 2011 x86_64\n" +"SNMPv2-MIB::sysObjectID.0 = OID: NET-SNMP-MIB::netSnmpAgentOIDs.10\n" +"DISMAN-EVENT-MIB::sysUpTimeInstance = Timeticks: (158357) 0:26:23.57\n" +"SNMPv2-MIB::sysContact.0 = STRING: UNIX Admin \n" +"SNMPv2-MIB::sysName.0 = STRING: localhost.localdomain\n" +"SNMPv2-MIB::sysLocation.0 = STRING: Datacenter, Row 3, Rack 2\n" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:995 +#, no-wrap +msgid "Configuring SNMP Version 3 User" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:997 +msgid "" +"To configure an *SNMP version 3 user*, use the " +"[command]#net-snmp-create-v3-user# command. This command adds entries to the " +"`/var/lib/net-snmp/snmpd.conf` and `/etc/snmp/snmpd.conf` files which create " +"the user and grant access to the user. Note that the " +"[command]#net-snmp-create-v3-user# command may only be run when the agent is " +"not running. The following example creates the \"`sysadmin`\" user with the " +"password \"`redhatsnmp`\":" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1007 +#, no-wrap +msgid "" +"~]# systemctl stop snmpd.service\n" +"~]# net-snmp-create-v3-user\n" +"Enter a SNMPv3 user name to create:\n" +"admin\n" +"Enter authentication pass-phrase:\n" +"redhatsnmp\n" +"Enter encryption pass-phrase:\n" +" [press return to reuse the authentication pass-phrase]\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1013 +#, no-wrap +msgid "" +"adding the following line to /var/lib/net-snmp/snmpd.conf:\n" +" createUser admin MD5 \"redhatsnmp\" DES\n" +"adding the following line to /etc/snmp/snmpd.conf:\n" +" rwuser admin\n" +"~]# systemctl start snmpd.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1016 +msgid "" +"The [option]`rwuser` directive (or [option]`rouser` when the [option]`-ro` " +"command line option is supplied) that [command]#net-snmp-create-v3-user# " +"adds to `/etc/snmp/snmpd.conf` has a similar format to the " +"[option]`rwcommunity` and [option]`rocommunity` directives:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1020 +#, no-wrap +msgid "_directive_ _user_ [option]`noauth`|[option]`auth`|[option]`priv` _OID_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1023 +msgid "" +"… where _user_ is a username and _OID_ is the SNMP tree to provide access " +"to. By default, the Net-SNMP Agent Daemon allows only authenticated requests " +"(the [option]`auth` option). The [option]`noauth` option allows you to " +"permit unauthenticated requests, and the [option]`priv` option enforces the " +"use of encryption. The [option]`authpriv` option specifies that requests " +"must be authenticated and replies should be encrypted." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1025 +msgid "" +"For example, the following line grants the user \"`admin`\" read-write " +"access to the entire tree:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1029 +#, no-wrap +msgid "rwuser admin authpriv .1\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1032 +msgid "" +"To test the configuration, create a `.snmp` directory in your user's home " +"directory and a configuration file named `snmp.conf` in that directory " +"(`~/.snmp/snmp.conf`) with the following lines:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1039 +#, no-wrap +msgid "" +"defVersion 3\n" +"defSecurityLevel authPriv\n" +"defSecurityName admin\n" +"defPassphrase redhatsnmp\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1042 +msgid "" +"The [command]#snmpwalk# command will now use these authentication settings " +"when querying the agent:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1047 +#, no-wrap +msgid "" +"~]$ snmpwalk -v3 localhost system\n" +"SNMPv2-MIB::sysDescr.0 = STRING: Linux localhost.localdomain " +"2.6.32-122.el6.x86_64 #1 SMP Wed Mar 9 23:54:34 EST 2011 x86_64\n" +"[output truncated]\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1050 +#, no-wrap +msgid "Retrieving Performance Data over SNMP" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1053 +msgid "" +"The Net-SNMP Agent in {MAJOROS} provides a wide variety of performance " +"information over the SNMP protocol. In addition, the agent can be queried " +"for a listing of the installed RPM packages on the system, a listing of " +"currently running processes on the system, or the network configuration of " +"the system." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1055 +msgid "" +"This section provides an overview of OIDs related to performance tuning " +"available over SNMP. It assumes that the [package]*net-snmp-utils* package " +"is installed and that the user is granted access to the SNMP tree as " +"described in " +"xref:System_Monitoring_Tools.adoc#sect-System_Monitoring_Tools-Net-SNMP-Configuring-Authentication[Configuring " +"Authentication]." +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1057 +#, no-wrap +msgid "Hardware Configuration" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1060 +msgid "" +"The `Host Resources MIB` included with Net-SNMP presents information about " +"the current hardware and software configuration of a host to a client " +"utility. " +"xref:System_Monitoring_Tools.adoc#tabl-System_Monitoring_Tools-Net-SNMP-OIDs[Available " +"OIDs] summarizes the different OIDs available under that MIB." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1062 +#, no-wrap +msgid "Available OIDs" +msgstr "" + +#. type: Table +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1073 +#, no-wrap +msgid "" +"|OID|Description\n" +"|`HOST-RESOURCES-MIB::hrSystem`|Contains general system information such as " +"uptime, number of users, and number of running processes.\n" +"|`HOST-RESOURCES-MIB::hrStorage`|Contains data on memory and file system " +"usage.\n" +"|`HOST-RESOURCES-MIB::hrDevices`|Contains a listing of all processors, " +"network devices, and file systems.\n" +"|`HOST-RESOURCES-MIB::hrSWRun`|Contains a listing of all running " +"processes.\n" +"|`HOST-RESOURCES-MIB::hrSWRunPerf`|Contains memory and CPU statistics on the " +"process table from HOST-RESOURCES-MIB::hrSWRun.\n" +"|`HOST-RESOURCES-MIB::hrSWInstalled`|Contains a listing of the RPM " +"database.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1076 +msgid "" +"There are also a number of SNMP tables available in the Host Resources MIB " +"which can be used to retrieve a summary of the available information. The " +"following example displays `HOST-RESOURCES-MIB::hrFSTable`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1081 +#, no-wrap +msgid "" +"~]$ [command]#snmptable -Cb localhost HOST-RESOURCES-MIB::hrFSTable#\n" +"SNMP table: HOST-RESOURCES-MIB::hrFSTable\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1090 +#, no-wrap +msgid "" +" Index MountPoint RemoteMountPoint Type\n" +" Access Bootable StorageIndex LastFullBackupDate LastPartialBackupDate\n" +" 1 \"/\" \"\" HOST-RESOURCES-TYPES::hrFSLinuxExt2\n" +" readWrite true 31 0-1-1,0:0:0.0 0-1-1,0:0:0.0\n" +" 5 \"/dev/shm\" \"\" HOST-RESOURCES-TYPES::hrFSOther\n" +" readWrite false 35 0-1-1,0:0:0.0 0-1-1,0:0:0.0\n" +" 6 \"/boot\" \"\" HOST-RESOURCES-TYPES::hrFSLinuxExt2\n" +" readWrite false 36 0-1-1,0:0:0.0 0-1-1,0:0:0.0\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1093 +msgid "" +"For more information about `HOST-RESOURCES-MIB`, see the " +"`/usr/share/snmp/mibs/HOST-RESOURCES-MIB.txt` file." +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1095 +#, no-wrap +msgid "CPU and Memory Information" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1098 +msgid "" +"Most system performance data is available in the `UCD SNMP MIB`. The " +"`systemStats` OID provides a number of counters around processor usage:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1127 +#, no-wrap +msgid "" +"~]$ [command]#snmpwalk localhost UCD-SNMP-MIB::systemStats#\n" +"UCD-SNMP-MIB::ssIndex.0 = INTEGER: 1\n" +"UCD-SNMP-MIB::ssErrorName.0 = STRING: systemStats\n" +"UCD-SNMP-MIB::ssSwapIn.0 = INTEGER: 0 kB\n" +"UCD-SNMP-MIB::ssSwapOut.0 = INTEGER: 0 kB\n" +"UCD-SNMP-MIB::ssIOSent.0 = INTEGER: 0 blocks/s\n" +"UCD-SNMP-MIB::ssIOReceive.0 = INTEGER: 0 blocks/s\n" +"UCD-SNMP-MIB::ssSysInterrupts.0 = INTEGER: 29 interrupts/s\n" +"UCD-SNMP-MIB::ssSysContext.0 = INTEGER: 18 switches/s\n" +"UCD-SNMP-MIB::ssCpuUser.0 = INTEGER: 0\n" +"UCD-SNMP-MIB::ssCpuSystem.0 = INTEGER: 0\n" +"UCD-SNMP-MIB::ssCpuIdle.0 = INTEGER: 99\n" +"UCD-SNMP-MIB::ssCpuRawUser.0 = Counter32: 2278\n" +"UCD-SNMP-MIB::ssCpuRawNice.0 = Counter32: 1395\n" +"UCD-SNMP-MIB::ssCpuRawSystem.0 = Counter32: 6826\n" +"UCD-SNMP-MIB::ssCpuRawIdle.0 = Counter32: 3383736\n" +"UCD-SNMP-MIB::ssCpuRawWait.0 = Counter32: 7629\n" +"UCD-SNMP-MIB::ssCpuRawKernel.0 = Counter32: 0\n" +"UCD-SNMP-MIB::ssCpuRawInterrupt.0 = Counter32: 434\n" +"UCD-SNMP-MIB::ssIORawSent.0 = Counter32: 266770\n" +"UCD-SNMP-MIB::ssIORawReceived.0 = Counter32: 427302\n" +"UCD-SNMP-MIB::ssRawInterrupts.0 = Counter32: 743442\n" +"UCD-SNMP-MIB::ssRawContexts.0 = Counter32: 718557\n" +"UCD-SNMP-MIB::ssCpuRawSoftIRQ.0 = Counter32: 128\n" +"UCD-SNMP-MIB::ssRawSwapIn.0 = Counter32: 0\n" +"UCD-SNMP-MIB::ssRawSwapOut.0 = Counter32: 0\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1130 +msgid "" +"In particular, the `ssCpuRawUser`, `ssCpuRawSystem`, `ssCpuRawWait`, and " +"`ssCpuRawIdle` OIDs provide counters which are helpful when determining " +"whether a system is spending most of its processor time in kernel space, " +"user space, or I/O. `ssRawSwapIn` and `ssRawSwapOut` can be helpful when " +"determining whether a system is suffering from memory exhaustion." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1132 +msgid "" +"More memory information is available under the `UCD-SNMP-MIB::memory` OID, " +"which provides similar data to the [command]#free# command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1148 +#, no-wrap +msgid "" +"~]$ [command]#snmpwalk localhost UCD-SNMP-MIB::memory#\n" +"UCD-SNMP-MIB::memIndex.0 = INTEGER: 0\n" +"UCD-SNMP-MIB::memErrorName.0 = STRING: swap\n" +"UCD-SNMP-MIB::memTotalSwap.0 = INTEGER: 1023992 kB\n" +"UCD-SNMP-MIB::memAvailSwap.0 = INTEGER: 1023992 kB\n" +"UCD-SNMP-MIB::memTotalReal.0 = INTEGER: 1021588 kB\n" +"UCD-SNMP-MIB::memAvailReal.0 = INTEGER: 634260 kB\n" +"UCD-SNMP-MIB::memTotalFree.0 = INTEGER: 1658252 kB\n" +"UCD-SNMP-MIB::memMinimumSwap.0 = INTEGER: 16000 kB\n" +"UCD-SNMP-MIB::memBuffer.0 = INTEGER: 30760 kB\n" +"UCD-SNMP-MIB::memCached.0 = INTEGER: 216200 kB\n" +"UCD-SNMP-MIB::memSwapError.0 = INTEGER: noError(0)\n" +"UCD-SNMP-MIB::memSwapErrorMsg.0 = STRING:\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1151 +msgid "" +"Load averages are also available in the `UCD SNMP MIB`. The SNMP table " +"`UCD-SNMP-MIB::laTable` has a listing of the 1, 5, and 15 minute load " +"averages:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1156 +#, no-wrap +msgid "" +"~]$ [command]#snmptable localhost UCD-SNMP-MIB::laTable#\n" +"SNMP table: UCD-SNMP-MIB::laTable\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1161 +#, no-wrap +msgid "" +" laIndex laNames laLoad laConfig laLoadInt laLoadFloat laErrorFlag " +"laErrMessage\n" +" 1 Load-1 0.00 12.00 0 0.000000 noError\n" +" 2 Load-5 0.00 12.00 0 0.000000 noError\n" +" 3 Load-15 0.00 12.00 0 0.000000 noError\n" +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1164 +#, no-wrap +msgid "File System and Disk Information" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1167 +msgid "" +"The `Host Resources MIB` provides information on file system size and " +"usage. Each file system (and also each memory pool) has an entry in the " +"`HOST-RESOURCES-MIB::hrStorageTable` table:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1172 +#, no-wrap +msgid "" +"~]$ [command]#snmptable -Cb localhost HOST-RESOURCES-MIB::hrStorageTable#\n" +"SNMP table: HOST-RESOURCES-MIB::hrStorageTable\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1191 +#, no-wrap +msgid "" +" Index Type Descr\n" +"AllocationUnits Size Used AllocationFailures\n" +" 1 HOST-RESOURCES-TYPES::hrStorageRam Physical memory\n" +"1024 Bytes 1021588 388064 ?\n" +" 3 HOST-RESOURCES-TYPES::hrStorageVirtualMemory Virtual memory\n" +"1024 Bytes 2045580 388064 ?\n" +" 6 HOST-RESOURCES-TYPES::hrStorageOther Memory buffers\n" +"1024 Bytes 1021588 31048 ?\n" +" 7 HOST-RESOURCES-TYPES::hrStorageOther Cached memory\n" +"1024 Bytes 216604 216604 ?\n" +" 10 HOST-RESOURCES-TYPES::hrStorageVirtualMemory Swap space\n" +"1024 Bytes 1023992 0 ?\n" +" 31 HOST-RESOURCES-TYPES::hrStorageFixedDisk /\n" +"4096 Bytes 2277614 250391 ?\n" +" 35 HOST-RESOURCES-TYPES::hrStorageFixedDisk /dev/shm\n" +"4096 Bytes 127698 0 ?\n" +" 36 HOST-RESOURCES-TYPES::hrStorageFixedDisk /boot\n" +"1024 Bytes 198337 26694 ?\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1194 +msgid "" +"The OIDs under `HOST-RESOURCES-MIB::hrStorageSize` and " +"`HOST-RESOURCES-MIB::hrStorageUsed` can be used to calculate the remaining " +"capacity of each mounted file system." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1196 +msgid "" +"I/O data is available both in `UCD-SNMP-MIB::systemStats` (`ssIORawSent.0` " +"and `ssIORawRecieved.0`) and in `UCD-DISKIO-MIB::diskIOTable`. The latter " +"provides much more granular data. Under this table are OIDs for " +"`diskIONReadX` and `diskIONWrittenX`, which provide counters for the number " +"of bytes read from and written to the block device in question since the " +"system boot:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1201 +#, no-wrap +msgid "" +"~]$ [command]#snmptable -Cb localhost UCD-DISKIO-MIB::diskIOTable#\n" +"SNMP table: UCD-DISKIO-MIB::diskIOTable\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1208 +#, no-wrap +msgid "" +" Index Device NRead NWritten Reads Writes LA1 LA5 LA15 NReadX " +"NWrittenX\n" +"...\n" +" 25 sda 216886272 139109376 16409 4894 ? ? ? 216886272 " +"139109376\n" +" 26 sda1 2455552 5120 613 2 ? ? ? 2455552 " +"5120\n" +" 27 sda2 1486848 0 332 0 ? ? ? 1486848 " +"0\n" +" 28 sda3 212321280 139104256 15312 4871 ? ? ? 212321280 " +"139104256\n" +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1211 +#, no-wrap +msgid "Network Information" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1214 +msgid "" +"Information on network devices is provided by the Interfaces " +"MIB. `IF-MIB::ifTable` provides an SNMP table with an entry for each " +"interface on the system, the configuration of the interface, and various " +"packet counters for the interface. The following example shows the first few " +"columns of `ifTable` on a system with two physical network interfaces:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1219 +#, no-wrap +msgid "" +"~]$ [command]#snmptable -Cb localhost IF-MIB::ifTable#\n" +"SNMP table: IF-MIB::ifTable\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1224 +#, no-wrap +msgid "" +" Index Descr Type Mtu Speed PhysAddress AdminStatus\n" +" 1 lo softwareLoopback 16436 10000000 up\n" +" 2 eth0 ethernetCsmacd 1500 0 52:54:0:c7:69:58 up\n" +" 3 eth1 ethernetCsmacd 1500 0 52:54:0:a7:a3:24 down\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1227 +msgid "" +"Network traffic is available under the OIDs `IF-MIB::ifOutOctets` and " +"`IF-MIB::ifInOctets`. The following SNMP queries will retrieve network " +"traffic for each of the interfaces on this system:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1242 +#, no-wrap +msgid "" +"~]$ [command]#snmpwalk localhost IF-MIB::ifDescr#\n" +"IF-MIB::ifDescr.1 = STRING: lo\n" +"IF-MIB::ifDescr.2 = STRING: eth0\n" +"IF-MIB::ifDescr.3 = STRING: eth1\n" +"~]$ [command]#snmpwalk localhost IF-MIB::ifOutOctets#\n" +"IF-MIB::ifOutOctets.1 = Counter32: 10060699\n" +"IF-MIB::ifOutOctets.2 = Counter32: 650\n" +"IF-MIB::ifOutOctets.3 = Counter32: 0\n" +"~]$ [command]#snmpwalk localhost IF-MIB::ifInOctets#\n" +"IF-MIB::ifInOctets.1 = Counter32: 10060699\n" +"IF-MIB::ifInOctets.2 = Counter32: 78650\n" +"IF-MIB::ifInOctets.3 = Counter32: 0\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1245 +#, no-wrap +msgid "Extending Net-SNMP" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1248 +msgid "" +"The Net-SNMP Agent can be extended to provide application metrics in " +"addition to raw system metrics. This allows for capacity planning as well as " +"performance issue troubleshooting. For example, it may be helpful to know " +"that an email system had a 5-minute load average of 15 while being tested, " +"but it is more helpful to know that the email system has a load average of " +"15 while processing 80,000 messages a second. When application metrics are " +"available via the same interface as the system metrics, this also allows for " +"the visualization of the impact of different load scenarios on system " +"performance (for example, each additional 10,000 messages increases the load " +"average linearly until 100,000)." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1250 +msgid "" +"A number of the applications that ship with {MAJOROS} extend the Net-SNMP " +"Agent to provide application metrics over SNMP. There are several ways to " +"extend the agent for custom applications as well. This section describes " +"extending the agent with shell scripts and Perl plug-ins. It assumes that " +"the [package]*net-snmp-utils* and [package]*net-snmp-perl* packages are " +"installed, and that the user is granted access to the SNMP tree as described " +"in " +"xref:System_Monitoring_Tools.adoc#sect-System_Monitoring_Tools-Net-SNMP-Configuring-Authentication[Configuring " +"Authentication]." +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1252 +#, no-wrap +msgid "Extending Net-SNMP with Shell Scripts" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1255 +msgid "" +"The Net-SNMP Agent provides an extension MIB (`NET-SNMP-EXTEND-MIB`) that " +"can be used to query arbitrary shell scripts. To specify the shell script to " +"run, use the [option]`extend` directive in the `/etc/snmp/snmpd.conf` " +"file. Once defined, the Agent will provide the exit code and any output of " +"the command over SNMP. The example below demonstrates this mechanism with a " +"script which determines the number of `httpd` processes in the process " +"table." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1256 +#, no-wrap +msgid "Using the proc directive" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1261 +msgid "" +"The Net-SNMP Agent also provides a built-in mechanism for checking the " +"process table via the [option]`proc` directive. See the *snmpd.conf*(5) " +"manual page for more information." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1265 +msgid "" +"The exit code of the following shell script is the number of " +"[command]#httpd# processes running on the system at a given point in time:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1268 +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1311 +#, no-wrap +msgid "#!/bin/sh\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1270 +#, no-wrap +msgid "NUMPIDS=`pgrep httpd | wc -l`\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1272 +#, no-wrap +msgid "exit $NUMPIDS\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1275 +msgid "" +"To make this script available over SNMP, copy the script to a location on " +"the system path, set the executable bit, and add an [option]`extend` " +"directive to the `/etc/snmp/snmpd.conf` file. The format of the " +"[option]`extend` directive is the following:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1279 +#, no-wrap +msgid "[option]`extend` _name_ _prog_ _args_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1282 +msgid "" +"… where _name_ is an identifying string for the extension, _prog_ is the " +"program to run, and _args_ are the arguments to give the program. For " +"instance, if the above shell script is copied to " +"`/usr/local/bin/check_apache.sh`, the following directive will add the " +"script to the SNMP tree:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1285 +#, no-wrap +msgid "extend httpd_pids /bin/sh /usr/local/bin/check_apache.sh\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1288 +msgid "The script can then be queried at `NET-SNMP-EXTEND-MIB::nsExtendObjects`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1305 +#, no-wrap +msgid "" +"~]$ snmpwalk localhost NET-SNMP-EXTEND-MIB::nsExtendObjects\n" +"NET-SNMP-EXTEND-MIB::nsExtendNumEntries.0 = INTEGER: 1\n" +"NET-SNMP-EXTEND-MIB::nsExtendCommand.\"httpd_pids\" = STRING: /bin/sh\n" +"NET-SNMP-EXTEND-MIB::nsExtendArgs.\"httpd_pids\" = STRING: " +"/usr/local/bin/check_apache.sh\n" +"NET-SNMP-EXTEND-MIB::nsExtendInput.\"httpd_pids\" = STRING:\n" +"NET-SNMP-EXTEND-MIB::nsExtendCacheTime.\"httpd_pids\" = INTEGER: 5\n" +"NET-SNMP-EXTEND-MIB::nsExtendExecType.\"httpd_pids\" = INTEGER: exec(1)\n" +"NET-SNMP-EXTEND-MIB::nsExtendRunType.\"httpd_pids\" = INTEGER: " +"run-on-read(1)\n" +"NET-SNMP-EXTEND-MIB::nsExtendStorage.\"httpd_pids\" = INTEGER: " +"permanent(4)\n" +"NET-SNMP-EXTEND-MIB::nsExtendStatus.\"httpd_pids\" = INTEGER: active(1)\n" +"NET-SNMP-EXTEND-MIB::nsExtendOutput1Line.\"httpd_pids\" = STRING:\n" +"NET-SNMP-EXTEND-MIB::nsExtendOutputFull.\"httpd_pids\" = STRING:\n" +"NET-SNMP-EXTEND-MIB::nsExtendOutNumLines.\"httpd_pids\" = INTEGER: 1\n" +"NET-SNMP-EXTEND-MIB::nsExtendResult.\"httpd_pids\" = INTEGER: 8\n" +"NET-SNMP-EXTEND-MIB::nsExtendOutLine.\"httpd_pids\".1 = STRING:\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1308 +msgid "" +"Note that the exit code (\"`8`\" in this example) is provided as an INTEGER " +"type and any output is provided as a STRING type. To expose multiple metrics " +"as integers, supply different arguments to the script using the " +"[option]`extend` directive. For example, the following shell script can be " +"used to determine the number of processes matching an arbitrary string, and " +"will also output a text string giving the number of processes:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1314 +#, no-wrap +msgid "" +"PATTERN=$1\n" +"NUMPIDS=`pgrep $PATTERN | wc -l`\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1317 +#, no-wrap +msgid "" +"echo \"There are $NUMPIDS $PATTERN processes.\"\n" +"exit $NUMPIDS\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1320 +msgid "" +"The following `/etc/snmp/snmpd.conf` directives will give both the number of " +"`httpd` PIDs as well as the number of `snmpd` PIDs when the above script is " +"copied to `/usr/local/bin/check_proc.sh`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1324 +#, no-wrap +msgid "" +"extend httpd_pids /bin/sh /usr/local/bin/check_proc.sh httpd\n" +"extend snmpd_pids /bin/sh /usr/local/bin/check_proc.sh snmpd\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1327 +msgid "" +"The following example shows the output of an [command]#snmpwalk# of the " +"`nsExtendObjects` OID:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1342 +#, no-wrap +msgid "" +"~]$ snmpwalk localhost NET-SNMP-EXTEND-MIB::nsExtendObjects\n" +"NET-SNMP-EXTEND-MIB::nsExtendNumEntries.0 = INTEGER: 2\n" +"NET-SNMP-EXTEND-MIB::nsExtendCommand.\"httpd_pids\" = STRING: /bin/sh\n" +"NET-SNMP-EXTEND-MIB::nsExtendCommand.\"snmpd_pids\" = STRING: /bin/sh\n" +"NET-SNMP-EXTEND-MIB::nsExtendArgs.\"httpd_pids\" = STRING: " +"/usr/local/bin/check_proc.sh httpd\n" +"NET-SNMP-EXTEND-MIB::nsExtendArgs.\"snmpd_pids\" = STRING: " +"/usr/local/bin/check_proc.sh snmpd\n" +"NET-SNMP-EXTEND-MIB::nsExtendInput.\"httpd_pids\" = STRING:\n" +"NET-SNMP-EXTEND-MIB::nsExtendInput.\"snmpd_pids\" = STRING:\n" +"...\n" +"NET-SNMP-EXTEND-MIB::nsExtendResult.\"httpd_pids\" = INTEGER: 8\n" +"NET-SNMP-EXTEND-MIB::nsExtendResult.\"snmpd_pids\" = INTEGER: 1\n" +"NET-SNMP-EXTEND-MIB::nsExtendOutLine.\"httpd_pids\".1 = STRING: There are 8 " +"httpd processes.\n" +"NET-SNMP-EXTEND-MIB::nsExtendOutLine.\"snmpd_pids\".1 = STRING: There are 1 " +"snmpd processes.\n" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1344 +#, no-wrap +msgid "Integer exit codes are limited" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1349 +msgid "" +"Integer exit codes are limited to a range of 0–255. For values that are " +"likely to exceed 256, either use the standard output of the script (which " +"will be typed as a string) or a different method of extending the agent." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1353 +msgid "" +"This last example shows a query for the free memory of the system and the " +"number of `httpd` processes. This query could be used during a performance " +"test to determine the impact of the number of processes on memory pressure:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1360 +#, no-wrap +msgid "" +"~]$ snmpget localhost \\\n" +" 'NET-SNMP-EXTEND-MIB::nsExtendResult.\"httpd_pids\"' \\\n" +" UCD-SNMP-MIB::memAvailReal.0\n" +"NET-SNMP-EXTEND-MIB::nsExtendResult.\"httpd_pids\" = INTEGER: 8\n" +"UCD-SNMP-MIB::memAvailReal.0 = INTEGER: 799664 kB\n" +msgstr "" + +#. type: Title ==== +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1363 +#, no-wrap +msgid "Extending Net-SNMP with Perl" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1366 +msgid "" +"Executing shell scripts using the [option]`extend` directive is a fairly " +"limited method for exposing custom application metrics over SNMP. The " +"Net-SNMP Agent also provides an embedded Perl interface for exposing custom " +"objects. The [package]*net-snmp-perl* package provides the `NetSNMP::agent` " +"Perl module that is used to write embedded Perl plug-ins on {MAJOROS}." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1368 +msgid "" +"The `NetSNMP::agent` Perl module provides an `agent` object which is used to " +"handle requests for a part of the agent's OID tree. The `agent` object's " +"constructor has options for running the agent as a sub-agent of `snmpd` or a " +"standalone agent. No arguments are necessary to create an embedded agent:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1372 +#, no-wrap +msgid "use NetSNMP::agent (':all');\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1374 +#, no-wrap +msgid "my $agent = new NetSNMP::agent();\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1377 +msgid "" +"The `agent` object has a `register` method which is used to register a " +"callback function with a particular OID. The `register` function takes a " +"name, OID, and pointer to the callback function. The following example will " +"register a callback function named `hello_handler` with the SNMP Agent which " +"will handle requests under the OID `.1.3.6.1.4.1.8072.9999.9999`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1381 +#, no-wrap +msgid "" +"$agent->register(\"hello_world\", \".1.3.6.1.4.1.8072.9999.9999\",\n" +" \\&hello_handler);\n" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1383 +#, no-wrap +msgid "Obtaining a root OID" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1388 +msgid "" +"The OID `.1.3.6.1.4.1.8072.9999.9999` (`NET-SNMP-MIB::netSnmpPlaypen`) is " +"typically used for demonstration purposes only. If your organization does " +"not already have a root OID, you can obtain one by contacting your Name " +"Registration Authority (ANSI in the United States)." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1392 +msgid "" +"The handler function will be called with four parameters, `HANDLER`, " +"`REGISTRATION_INFO`, `REQUEST_INFO`, and `REQUESTS`. The `REQUESTS` " +"parameter contains a list of requests in the current call and should be " +"iterated over and populated with data. The `request` objects in the list " +"have get and set methods which allow for manipulating the `OID` and `value` " +"of the request. For example, the following call will set the value of a " +"request object to the string \"`hello world`\":" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1395 +#, no-wrap +msgid "$request->setValue(ASN_OCTET_STR, \"hello world\");\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1398 +msgid "" +"The handler function should respond to two types of SNMP requests: the GET " +"request and the GETNEXT request. The type of request is determined by " +"calling the `getMode` method on the `request_info` object passed as the " +"third parameter to the handler function. If the request is a GET request, " +"the caller will expect the handler to set the `value` of the `request` " +"object, depending on the OID of the request. If the request is a GETNEXT " +"request, the caller will also expect the handler to set the OID of the " +"request to the next available OID in the tree. This is illustrated in the " +"following code example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1403 +#, no-wrap +msgid "" +"my $request;\n" +"my $string_value = \"hello world\";\n" +"my $integer_value = \"8675309\";\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1424 +#, no-wrap +msgid "" +"for($request = $requests; $request; $request = $request->next()) {\n" +" my $oid = $request->getOID();\n" +" if ($request_info->getMode() == MODE_GET) {\n" +" if ($oid == new NetSNMP::OID(\".1.3.6.1.4.1.8072.9999.9999.1.0\")) {\n" +" $request->setValue(ASN_OCTET_STR, $string_value);\n" +" }\n" +" elsif ($oid == new NetSNMP::OID(\".1.3.6.1.4.1.8072.9999.9999.1.1\")) " +"{\n" +" $request->setValue(ASN_INTEGER, $integer_value);\n" +" }\n" +" } elsif ($request_info->getMode() == MODE_GETNEXT) {\n" +" if ($oid == new NetSNMP::OID(\".1.3.6.1.4.1.8072.9999.9999.1.0\")) {\n" +" $request->setOID(\".1.3.6.1.4.1.8072.9999.9999.1.1\");\n" +" $request->setValue(ASN_INTEGER, $integer_value);\n" +" }\n" +" elsif ($oid < new NetSNMP::OID(\".1.3.6.1.4.1.8072.9999.9999.1.0\")) {\n" +" $request->setOID(\".1.3.6.1.4.1.8072.9999.9999.1.0\");\n" +" $request->setValue(ASN_OCTET_STR, $string_value);\n" +" }\n" +" }\n" +"}\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1427 +msgid "" +"When `getMode` returns `MODE_GET`, the handler analyzes the value of the " +"`getOID` call on the `request` object. The `value` of the `request` is set " +"to either `string_value` if the OID ends in \"`.1.0`\", or set to " +"`integer_value` if the OID ends in \"`.1.1`\". If the `getMode` returns " +"`MODE_GETNEXT`, the handler determines whether the OID of the request is " +"\"`.1.0`\", and then sets the OID and value for \"`.1.1`\". If the request " +"is higher on the tree than \"`.1.0`\", the OID and value for \"`.1.0`\" is " +"set. This in effect returns the \"`next`\" value in the tree so that a " +"program like [command]#snmpwalk# can traverse the tree without prior " +"knowledge of the structure." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1429 +msgid "" +"The type of the variable is set using constants from `NetSNMP::ASN`. See the " +"[command]#perldoc# for `NetSNMP::ASN` for a full list of available " +"constants." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1431 +msgid "The entire code listing for this example Perl plug-in is as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1434 +#, no-wrap +msgid "#!/usr/bin/perl\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1437 +#, no-wrap +msgid "" +"use NetSNMP::agent (':all');\n" +"use NetSNMP::ASN qw(ASN_OCTET_STR ASN_INTEGER);\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1443 +#, no-wrap +msgid "" +"sub hello_handler {\n" +" my ($handler, $registration_info, $request_info, $requests) = @_;\n" +" my $request;\n" +" my $string_value = \"hello world\";\n" +" my $integer_value = \"8675309\";\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1465 +#, no-wrap +msgid "" +" for($request = $requests; $request; $request = $request->next()) {\n" +" my $oid = $request->getOID();\n" +" if ($request_info->getMode() == MODE_GET) {\n" +" if ($oid == new NetSNMP::OID(\".1.3.6.1.4.1.8072.9999.9999.1.0\")) {\n" +" $request->setValue(ASN_OCTET_STR, $string_value);\n" +" }\n" +" elsif ($oid == new NetSNMP::OID(\".1.3.6.1.4.1.8072.9999.9999.1.1\")) " +"{\n" +" $request->setValue(ASN_INTEGER, $integer_value);\n" +" }\n" +" } elsif ($request_info->getMode() == MODE_GETNEXT) {\n" +" if ($oid == new NetSNMP::OID(\".1.3.6.1.4.1.8072.9999.9999.1.0\")) {\n" +" $request->setOID(\".1.3.6.1.4.1.8072.9999.9999.1.1\");\n" +" $request->setValue(ASN_INTEGER, $integer_value);\n" +" }\n" +" elsif ($oid < new NetSNMP::OID(\".1.3.6.1.4.1.8072.9999.9999.1.0\")) " +"{\n" +" $request->setOID(\".1.3.6.1.4.1.8072.9999.9999.1.0\");\n" +" $request->setValue(ASN_OCTET_STR, $string_value);\n" +" }\n" +" }\n" +" }\n" +"}\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1469 +#, no-wrap +msgid "" +"my $agent = new NetSNMP::agent();\n" +"$agent->register(\"hello_world\", \".1.3.6.1.4.1.8072.9999.9999\",\n" +" \\&hello_handler);\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1472 +msgid "" +"To test the plug-in, copy the above program to " +"`/usr/share/snmp/hello_world.pl` and add the following line to the " +"`/etc/snmp/snmpd.conf` configuration file:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1475 +#, no-wrap +msgid "perl do \"/usr/share/snmp/hello_world.pl\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1478 +msgid "" +"The SNMP Agent Daemon will need to be restarted to load the new Perl " +"plug-in. Once it has been restarted, an [command]#snmpwalk# should return " +"the new data:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1484 +#, no-wrap +msgid "" +"~]$ [command]#snmpwalk localhost NET-SNMP-MIB::netSnmpPlaypen#\n" +"NET-SNMP-MIB::netSnmpPlaypen.1.0 = STRING: \"hello world\"\n" +"NET-SNMP-MIB::netSnmpPlaypen.1.1 = INTEGER: 8675309\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1487 +msgid "" +"The [command]#snmpget# should also be used to exercise the other mode of the " +"handler:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1495 +#, no-wrap +msgid "" +"~]$ [command]#snmpget localhost \\#\n" +" [command]#NET-SNMP-MIB::netSnmpPlaypen.1.0 \\#\n" +" [command]#NET-SNMP-MIB::netSnmpPlaypen.1.1#\n" +"NET-SNMP-MIB::netSnmpPlaypen.1.0 = STRING: \"hello world\"\n" +"NET-SNMP-MIB::netSnmpPlaypen.1.1 = INTEGER: 8675309\n" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1498 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1501 +msgid "" +"To learn more about gathering system information, refer to the following " +"resources." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1503 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1506 +#, no-wrap +msgid "*ps*(1) — The manual page for the [command]#ps# command.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1508 +#, no-wrap +msgid "*top*(1) — The manual page for the [command]#top# command.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1510 +#, no-wrap +msgid "*free*(1) — The manual page for the [command]#free# command.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1512 +#, no-wrap +msgid "*df*(1) — The manual page for the [command]#df# command.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1514 +#, no-wrap +msgid "*du*(1) — The manual page for the [command]#du# command.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1516 +#, no-wrap +msgid "*lspci*(8) — The manual page for the [command]#lspci# command.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1518 +#, no-wrap +msgid "*snmpd*(8) — The manual page for the `snmpd` service.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/System_Monitoring_Tools.adoc:1519 +#, no-wrap +msgid "" +"*snmpd.conf*(5) — The manual page for the `/etc/snmp/snmpd.conf` file " +"containing full documentation of available configuration directives.\n" +msgstr "" diff --git a/pot/rawhide/pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.pot b/pot/rawhide/pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.pot new file mode 100644 index 00000000000..01da822bb11 --- /dev/null +++ b/pot/rawhide/pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.pot @@ -0,0 +1,5323 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:5 +#, no-wrap +msgid "Viewing and Managing Log Files" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:8 +msgid "" +"indexterm:[log files,System Log]indexterm:[log files,description] _Log " +"files_ are files that contain messages about the system, including the " +"kernel, services, and applications running on it. There are different log " +"files for different information. For example, there is a default system log " +"file, a log file just for security messages, and a log file for cron tasks." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:12 +msgid "" +"Log files can be very useful when trying to troubleshoot a problem with the " +"system such as trying to load a kernel driver or when looking for " +"unauthorized login attempts to the system. This chapter discusses where to " +"find log files, how to view log files, and what to look for in log files. " +"indexterm:[log files,rsyslogd daemon]indexterm:[rsyslog] Some log files are " +"controlled by a daemon called `rsyslogd`. The `rsyslogd` daemon is an " +"enhanced replacement for [application]*sysklogd*, and provides extended " +"filtering, encryption protected relaying of messages, various configuration " +"options, input and output modules, support for transportation via the `TCP` " +"or `UDP` protocols. Note that [application]*rsyslog* is compatible with " +"[application]*sysklogd*." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:14 +msgid "" +"Log files can also be managed by the `journald` daemon – a component " +"of `systemd`. The `journald` daemon captures Syslog messages, kernel log " +"messages, initial RAM disk and early boot messages as well as messages " +"written to standard output and standard error output of all services, " +"indexes them and makes this available to the user. The native journal file " +"format, which is a structured and indexed binary file, improves searching " +"and provides faster operation, and it also stores meta data information like " +"time stamps or user IDs. Log files produced by `journald` are by default not " +"persistent, log files are stored only in memory or a small ring-buffer in " +"the `/run/log/journal/` directory. The amount of logged data depends on free " +"memory, when you reach the capacity limit, the oldest entries are " +"deleted. However, this setting can be altered – see " +"xref:Viewing_and_Managing_Log_Files.adoc#s2-Enabling_Persistent_Storage[Enabling " +"Persistent Storage]. For more information on Journal see " +"xref:Viewing_and_Managing_Log_Files.adoc#s1-Using_the_Journal[Using the " +"Journal]." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:16 +msgid "" +"By default, only `journald` is installed on your system. You have to install " +"rsyslog youself. Also do not forget to enable and start it after install " +"before continuing with rest of this guide. The `journald` daemon is the " +"primary tool for troubleshooting. It also provides additional data necessary " +"for creating structured log messages. Data acquired by `journald` is " +"forwarded into the `/run/systemd/journal/syslog` socket that may be used by " +"`rsyslogd` to process the data further. However, [application]*rsyslog* does " +"the actual integration by default via the `imjournal` input module, thus " +"avoiding the aforementioned socket. You can also transfer data in the " +"opposite direction, from `rsyslogd` to `journald` with use of `omjournal` " +"module. See " +"xref:Viewing_and_Managing_Log_Files.adoc#s1-interaction_of_rsyslog_and_journal[Interaction " +"of Rsyslog and Journal] for further information. The integration enables " +"maintaining text-based logs in a consistent format to ensure compatibility " +"with possible applications or configurations dependent on `rsyslogd`. Also, " +"you can maintain rsyslog messages in a structured format (see " +"xref:Viewing_and_Managing_Log_Files.adoc#s1-structured_logging_with_rsyslog[Structured " +"Logging with Rsyslog])." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:18 +#, no-wrap +msgid "Locating Log Files" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:23 +msgid "" +"indexterm:[log files,locating] A list of log files maintained by `rsyslogd` " +"can be found in the `/etc/rsyslog.conf` configuration file. Most log files " +"are located in the `/var/log/` directory. Some applications such as " +"[command]#httpd# and [command]#samba# have a directory within `/var/log/` " +"for their log files. indexterm:[log files,rotating]indexterm:[logrotate] " +"You may notice multiple files in the `/var/log/` directory with numbers " +"after them (for example, `cron-20100906`). These numbers represent a time " +"stamp that has been added to a rotated log file. Log files are rotated so " +"their file sizes do not become too large. The `logrotate` package contains a " +"cron task that automatically rotates log files according to the " +"`/etc/logrotate.conf` configuration file and the configuration files in the " +"`/etc/logrotate.d/` directory." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:25 +#, no-wrap +msgid "Basic Configuration of Rsyslog" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:28 +msgid "" +"indexterm:[rsyslog,configuration] The main configuration file for " +"[application]*rsyslog* is `/etc/rsyslog.conf`. Here, you can specify _global " +"directives_, _modules_, and _rules_ that consist of _filter_ and _action_ " +"parts. Also, you can add comments in the form of text following a hash sign " +"(`#`)." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:30 +#, no-wrap +msgid "Filters" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:33 +msgid "" +"indexterm:[rsyslog,filters] A rule is specified by a *filter* part, which " +"selects a subset of syslog messages, and an *action* part, which specifies " +"what to do with the selected messages. To define a rule in your " +"`/etc/rsyslog.conf` configuration file, define both, a filter and an action, " +"on one line and separate them with one or more spaces or tabs." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:35 +msgid "" +"[application]*rsyslog* offers various ways to filter syslog messages " +"according to selected properties. The available filtering methods can be " +"divided into *Facility/Priority-based*, *Property-based*, and " +"*Expression-based* filters." +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:36 +#, no-wrap +msgid "Facility/Priority-based filters" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:37 +msgid "" +"The most used and well-known way to filter syslog messages is to use the " +"facility/priority-based filters which filter syslog messages based on two " +"conditions: _facility_ and _priority_ separated by a dot. To create a " +"selector, use the following syntax:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:42 +#, no-wrap +msgid "_FACILITY_._PRIORITY_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:46 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:99 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:160 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:241 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:290 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:369 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:468 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:516 +msgid "where:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:48 +msgid "" +"_FACILITY_ specifies the subsystem that produces a specific syslog " +"message. For example, the [command]#mail# subsystem handles all mail-related " +"syslog messages. _FACILITY_ can be represented by one of the following " +"keywords (or by a numerical code): [command]#kern# (0), [command]#user# (1), " +"[command]#mail# (2), [command]#daemon# (3), [command]#auth# (4), " +"[command]#syslog# (5), [command]#lpr# (6), [command]#news# (7), " +"[command]#uucp# (8), [command]#cron# (9), [command]#authpriv# (10), " +"[command]#ftp# (11), [command]#ntp# (12), [command]#logaudit# (13), " +"[command]#logalert# (14), [command]#clock# (15), and [command]#local0# " +"through [command]#local7# (16 - 23)." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:50 +msgid "" +"_PRIORITY_ specifies a priority of a syslog message. _PRIORITY_ can be " +"represented by one of the following keywords (or by a number): " +"[command]#debug# (7), [command]#info# (6), [command]#notice# (5), " +"[command]#warning# (4), [command]#err# (3), [command]#crit# (2), " +"[command]#alert# (1), and [command]#emerg# (0)." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:52 +msgid "" +"The aforementioned syntax selects syslog messages with the defined or " +"*higher* priority. By preceding any priority keyword with an equal sign " +"(`=`), you specify that only syslog messages with the specified priority " +"will be selected. All other priorities will be ignored. Conversely, " +"preceding a priority keyword with an exclamation mark (`!`) selects all " +"syslog messages except those with the defined priority." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:54 +msgid "" +"In addition to the keywords specified above, you may also use an asterisk " +"(`*`) to define all facilities or priorities (depending on where you place " +"the asterisk, before or after the comma). Specifying the priority keyword " +"`none` serves for facilities with no given priorities. Both facility and " +"priority conditions are case-insensitive." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:56 +msgid "" +"To define multiple facilities and priorities, separate them with a comma " +"(`,`). To define multiple selectors on one line, separate them with a " +"semi-colon (`;`). Note that each selector in the selector field is capable " +"of overwriting the preceding ones, which can exclude some priorities from " +"the pattern." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:58 +#, no-wrap +msgid "Facility/Priority-based Filters" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:62 +msgid "" +"The following are a few examples of simple facility/priority-based filters " +"that can be specified in `/etc/rsyslog.conf`. To select all kernel syslog " +"messages with any priority, add the following text into the configuration " +"file:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:66 +#, no-wrap +msgid "kern.*\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:70 +msgid "" +"To select all mail syslog messages with priority [command]#crit# and higher, " +"use this form:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:75 +#, no-wrap +msgid "mail.crit\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:79 +msgid "" +"To select all cron syslog messages except those with the [command]#info# or " +"[command]#debug# priority, set the configuration in the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:84 +#, no-wrap +msgid "cron.!info,!debug\n" +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:89 +#, no-wrap +msgid "Property-based filters" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:90 +msgid "" +"Property-based filters let you filter syslog messages by any property, such " +"as `timegenerated` or `syslogtag`. For more information on properties, see " +"xref:Viewing_and_Managing_Log_Files.adoc#brid-properties[Properties]. You " +"can compare each of the specified properties to a particular value using one " +"of the compare-operations listed in " +"xref:Viewing_and_Managing_Log_Files.adoc#table-compare-operations[Property-based " +"compare-operations]. Both property names and compare operations are " +"case-sensitive." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:92 +msgid "" +"Property-based filter must start with a colon (`:`). To define the filter, " +"use the following syntax:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:96 +#, no-wrap +msgid "" +":pass:quotes[_PROPERTY_], [!]pass:quotes[_COMPARE_OPERATION_], " +"\"pass:quotes[_STRING_]\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:101 +msgid "The _PROPERTY_ attribute specifies the desired property." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:103 +msgid "" +"The optional exclamation point (`!`) negates the output of the " +"compare-operation. Other Boolean operators are currently not supported in " +"property-based filters." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:105 +msgid "" +"The _COMPARE_OPERATION_ attribute specifies one of the compare-operations " +"listed in " +"xref:Viewing_and_Managing_Log_Files.adoc#table-compare-operations[Property-based " +"compare-operations]." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:107 +msgid "" +"The _STRING_ attribute specifies the value that the text provided by the " +"property is compared to. This value must be enclosed in quotation marks. To " +"escape certain character inside the string (for example a quotation mark " +"(`\"`)), use the backslash character (`\\`)." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:109 +#, no-wrap +msgid "Property-based compare-operations" +msgstr "" + +#. type: Table +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:120 +#, no-wrap +msgid "" +"|Compare-operation|Description\n" +"|`contains`|Checks whether the provided string matches any part of the text " +"provided by the property. To perform case-insensitive comparisons, use " +"`contains_i`.\n" +"|`isequal`|Compares the provided string against all of the text provided by " +"the property. These two values must be exactly equal to match.\n" +"|`startswith`|Checks whether the provided string is found exactly at the " +"beginning of the text provided by the property. To perform case-insensitive " +"comparisons, use `startswith_i`.\n" +"|`regex`|Compares the provided POSIX BRE (Basic Regular Expression) against " +"the text provided by the property.\n" +"|`ereregex`|Compares the provided POSIX ERE (Extended Regular Expression) " +"regular expression against the text provided by the property.\n" +"|`isempty`|Checks if the property is empty. The value is discarded. This is " +"especially useful when working with normalized data, where some fields may " +"be populated based on normalization result.\n" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:123 +#, no-wrap +msgid "Property-based Filters" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:127 +msgid "" +"The following are a few examples of property-based filters that can be " +"specified in `/etc/rsyslog.conf`. To select syslog messages which contain " +"the string `error` in their message text, use:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:131 +#, no-wrap +msgid ":msg, contains, \"error\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:134 +msgid "" +"The following filter selects syslog messages received from the host name " +"`host1`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:138 +#, no-wrap +msgid ":hostname, isequal, \"host1\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:141 +msgid "" +"To select syslog messages which do not contain any mention of the words " +"`fatal` and `error` with any or no text between them (for example, `fatal " +"lib error`), type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:144 +#, no-wrap +msgid ":msg, !regex, \"fatal .* error\"\n" +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:148 +#, no-wrap +msgid "Expression-based filters" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:149 +msgid "" +"Expression-based filters select syslog messages according to defined " +"arithmetic, Boolean or string operations. Expression-based filters use " +"[application]*rsyslog*pass:attributes[{blank}]'s own scripting language " +"called *RainerScript* to build complex filters." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:151 +msgid "The basic syntax of expression-based filter looks as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:156 +#, no-wrap +msgid "if _EXPRESSION_ then _ACTION_ else _ACTION_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:162 +msgid "" +"The _EXPRESSION_ attribute represents an expression to be evaluated, for " +"example: `$msg startswith 'DEVNAME'` or `$syslogfacility-text == " +"'local0'`. You can specify more than one expression in a single filter by " +"using `and` and `or` operators." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:164 +msgid "" +"The _ACTION_ attribute represents an action to be performed if the " +"expression returns the value `true`. This can be a single action, or an " +"arbitrary complex script enclosed in curly braces." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:166 +msgid "" +"Expression-based filters are indicated by the keyword *if* at the start of a " +"new line. The *then* keyword separates the _EXPRESSION_ from the " +"_ACTION_. Optionally, you can employ the *else* keyword to specify what " +"action is to be performed in case the condition is not met." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:168 +msgid "" +"With expression-based filters, you can nest the conditions by using a script " +"enclosed in curly braces as in " +"xref:Viewing_and_Managing_Log_Files.adoc#ex-expression-based_filters[Expression-based " +"Filters]. The script allows you to use *facility/priority-based* filters " +"inside the expression. On the other hand, *property-based* filters are not " +"recommended here. RainerScript supports regular expressions with specialized " +"functions `re_match()` and `re_extract()`." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:170 +#, no-wrap +msgid "Expression-based Filters" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:174 +msgid "" +"The following expression contains two nested conditions. The log files " +"created by a program called *prog1* are split into two files based on the " +"presence of the \"`test`\" string in the message." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:185 +#, no-wrap +msgid "" +"if $programname == 'prog1' then {\n" +" action(type=\"omfile\" file=\"/var/log/prog1.log\")\n" +" if $msg contains 'test' then\n" +" action(type=\"omfile\" file=\"/var/log/prog1test.log\")\n" +" else\n" +" action(type=\"omfile\" file=\"/var/log/prog1notest.log\")\n" +"}\n" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:191 +msgid "" +"See " +"xref:Viewing_and_Managing_Log_Files.adoc#brid-Log_Files-Resources-Online[Online " +"Documentation] for more examples of various expression-based " +"filters. RainerScript is the basis for " +"[application]*rsyslog*pass:attributes[{blank}]'s new configuration format, " +"see " +"xref:Viewing_and_Managing_Log_Files.adoc#sec-using_the_new_configuration_format[Using " +"the New Configuration Format]" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:193 +#, no-wrap +msgid "Actions" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:196 +msgid "" +"indexterm:[rsyslog,actions] Actions specify what is to be done with the " +"messages filtered out by an already-defined selector. The following are some " +"of the actions you can define in your rule:" +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:197 +#, no-wrap +msgid "Saving syslog messages to log files" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:198 +msgid "" +"The majority of actions specify to which log file a syslog message is " +"saved. This is done by specifying a file path after your already-defined " +"selector:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:202 +#, no-wrap +msgid "_FILTER_ _PATH_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:205 +msgid "" +"where _FILTER_ stands for user-specified selector and _PATH_ is a path of a " +"target file." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:207 +msgid "" +"For instance, the following rule is comprised of a selector that selects all " +"[application]*cron* syslog messages and an action that saves them into the " +"`/var/log/cron.log` log file:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:210 +#, no-wrap +msgid "cron.* /var/log/cron.log\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:213 +msgid "" +"By default, the log file is synchronized every time a syslog message is " +"generated. Use a dash mark (`-`) as a prefix of the file path you specified " +"to omit syncing:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:217 +#, no-wrap +msgid "_FILTER_ -_PATH_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:220 +msgid "" +"Note that you might lose information if the system terminates right after a " +"write attempt. However, this setting can improve performance, especially if " +"you run programs that produce very verbose log messages." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:222 +msgid "" +"Your specified file path can be either *static* or *dynamic*. Static files " +"are represented by a fixed file path as shown in the example above. Dynamic " +"file paths can differ according to the received message. Dynamic file paths " +"are represented by a template and a question mark (`?`) prefix:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:226 +#, no-wrap +msgid "_FILTER_ ?_DynamicFile_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:229 +msgid "" +"where _DynamicFile_ is a name of a predefined template that modifies output " +"paths. You can use the dash prefix (`-`) to disable syncing, also you can " +"use multiple templates separated by a colon (`;`). For more information on " +"templates, see " +"xref:Viewing_and_Managing_Log_Files.adoc#brid-generating-dynamic-fnames[Generating " +"Dynamic File Names]." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:231 +msgid "" +"If the file you specified is an existing [application]*terminal* or " +"`/dev/console` device, syslog messages are sent to standard output (using " +"special [application]*terminal*-handling) or your console (using special " +"`/dev/console`-handling) when using the X Window System, respectively." +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:232 +#, no-wrap +msgid "Sending syslog messages over the network" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:233 +msgid "" +"[application]*rsyslog* allows you to send and receive syslog messages over " +"the network. This feature allows you to administer syslog messages of " +"multiple hosts on one machine. To forward syslog messages to a remote " +"machine, use the following syntax:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:237 +#, no-wrap +msgid "@([command]#zpass:attributes[{blank}]_NUMBER_pass:attributes[{blank}]#)_HOST_:pass:attributes[{blank}]_PORT_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:243 +msgid "" +"The at sign (`@`) indicates that the syslog messages are forwarded to a host " +"using the `UDP` protocol. To use the `TCP` protocol, use two at signs with " +"no space between them (`@@`)." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:245 +msgid "" +"The optional " +"[command]#zpass:attributes[{blank}]_NUMBER_pass:attributes[{blank}]# setting " +"enables [application]*zlib* compression for syslog messages. The _NUMBER_ " +"attribute specifies the level of compression (from 1 – lowest to 9 " +"– maximum). Compression gain is automatically checked by `rsyslogd`, " +"messages are compressed only if there is any compression gain and messages " +"below 60 bytes are never compressed." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:247 +msgid "" +"The _HOST_ attribute specifies the host which receives the selected syslog " +"messages." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:249 +msgid "The _PORT_ attribute specifies the host machine's port." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:251 +msgid "" +"When specifying an `IPv6` address as the host, enclose the address in square " +"brackets (`[`, `]`)." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:253 +#, no-wrap +msgid "Sending syslog Messages over the Network" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:257 +msgid "" +"The following are some examples of actions that forward syslog messages over " +"the network (note that all actions are preceded with a selector that selects " +"all messages with any priority). To forward messages to `192.168.0.1` via " +"the `UDP` protocol, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:261 +#, no-wrap +msgid "*.* @192.168.0.1\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:265 +msgid "" +"To forward messages to \"`example.com`\" using port 18 and the `TCP` " +"protocol, use:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:269 +#, no-wrap +msgid "*.* @@example.com:18\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:273 +msgid "" +"The following compresses messages with [application]*zlib* (level 9 " +"compression) and forwards them to `2001:db8::1` using the `UDP` protocol" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:277 +#, no-wrap +msgid "*.* @(z9)[2001:db8::1]\n" +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:282 +#, no-wrap +msgid "Output channels" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:283 +msgid "" +"Output channels are primarily used to specify the maximum size a log file " +"can grow to. This is very useful for log file rotation (for more information " +"see xref:Viewing_and_Managing_Log_Files.adoc#s2-log_rotation[Log " +"Rotation]). An output channel is basically a collection of information about " +"the output action. Output channels are defined by the `$outchannel` " +"directive. To define an output channel in `/etc/rsyslog.conf`, use the " +"following syntax:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:287 +#, no-wrap +msgid "" +"$outchannel pass:quotes[_NAME_], pass:quotes[_FILE_NAME_], " +"pass:quotes[_MAX_SIZE_], pass:quotes[_ACTION_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:292 +msgid "The _NAME_ attribute specifies the name of the output channel." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:294 +msgid "" +"The _FILE_NAME_ attribute specifies the name of the output file. Output " +"channels can write only into files, not pipes, terminal, or other kind of " +"output." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:296 +msgid "" +"The _MAX_SIZE_ attribute represents the maximum size the specified file (in " +"_FILE_NAME_) can grow to. This value is specified in *bytes*." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:298 +msgid "" +"The _ACTION_ attribute specifies the action that is taken when the maximum " +"size, defined in _MAX_SIZE_, is hit." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:300 +msgid "To use the defined output channel as an action inside a rule, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:304 +#, no-wrap +msgid "_FILTER_ :omfile:$pass:attributes[{blank}]_NAME_\n" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:307 +#, no-wrap +msgid "Output channel log rotation" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:311 +msgid "" +"The following output shows a simple log rotation through the use of an " +"output channel. First, the output channel is defined via the `$outchannel` " +"directive:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:315 +#, no-wrap +msgid "" +" $outchannel log_rotation, /var/log/test_log.log, 104857600, " +"/home/joe/log_rotation_script\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:319 +msgid "" +"and then it is used in a rule that selects every syslog message with any " +"priority and executes the previously-defined output channel on the acquired " +"syslog messages:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:323 +#, no-wrap +msgid "*.* :omfile:$log_rotation\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:327 +msgid "" +"Once the limit (in the example 100{nbsp}MB) is hit, the " +"`/home/joe/log_rotation_script` is executed. This script can contain " +"anything from moving the file into a different folder, editing specific " +"content out of it, or simply removing it." +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:330 +#, no-wrap +msgid "Sending syslog messages to specific users" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:331 +msgid "" +"[application]*rsyslog* can send syslog messages to specific users by " +"specifying a user name of the user you want to send the messages to (as in " +"xref:Viewing_and_Managing_Log_Files.adoc#ex-multiple_actions[Specifying " +"Multiple Actions]). To specify more than one user, separate each user name " +"with a comma (`,`). To send messages to every user that is currently logged " +"on, use an asterisk (`*`)." +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:332 +#, no-wrap +msgid "Executing a program" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:333 +msgid "" +"[application]*rsyslog* lets you execute a program for selected syslog " +"messages and uses the `system()` call to execute the program in shell. To " +"specify a program to be executed, prefix it with a caret character " +"(`^`). Consequently, specify a template that formats the received message " +"and passes it to the specified executable as a one line parameter (for more " +"information on templates, see " +"xref:Viewing_and_Managing_Log_Files.adoc#s2-Templates[Templates])." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:337 +#, no-wrap +msgid "pass:quotes[_FILTER_] ^pass:quotes[_EXECUTABLE_]; pass:quotes[_TEMPLATE_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:340 +msgid "" +"Here an output of the _FILTER_ condition is processed by a program " +"represented by _EXECUTABLE_. This program can be any valid " +"executable. Replace _TEMPLATE_ with the name of the formatting template." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:342 +#, no-wrap +msgid "Executing a Program" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:346 +msgid "" +"In the following example, any syslog message with any priority is selected, " +"formatted with the `template` template and passed as a parameter to the " +"[application]*test-program* program, which is then executed with the " +"provided parameter:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:349 +#, no-wrap +msgid "*.* ^test-program;template\n" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:353 +#, no-wrap +msgid "Be careful when using the shell execute action" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:358 +msgid "" +"When accepting messages from any host, and using the shell execute action, " +"you may be vulnerable to command injection. An attacker may try to inject " +"and execute commands in the program you specified to be executed in your " +"action. To avoid any possible security threats, thoroughly consider the use " +"of the shell execute action." +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:361 +#, no-wrap +msgid "Storing syslog messages in a database" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:362 +msgid "" +"Selected syslog messages can be directly written into a database table using " +"the *database writer* action. The database writer uses the following syntax:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:366 +#, no-wrap +msgid ":pass:quotes[_PLUGIN_]:pass:quotes[_DB_HOST_],pass:quotes[_DB_NAME_],pass:quotes[_DB_USER_],pass:quotes[_DB_PASSWORD_];pass:quotes[_TEMPLATE_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:371 +msgid "" +"The _PLUGIN_ calls the specified plug-in that handles the database writing " +"(for example, the `ommysql` plug-in)." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:373 +msgid "The _DB_HOST_ attribute specifies the database host name." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:375 +msgid "The _DB_NAME_ attribute specifies the name of the database." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:377 +msgid "The _DB_USER_ attribute specifies the database user." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:379 +msgid "" +"The _DB_PASSWORD_ attribute specifies the password used with the " +"aforementioned database user." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:381 +msgid "" +"The _TEMPLATE_ attribute specifies an optional use of a template that " +"modifies the syslog message. For more information on templates, see " +"xref:Viewing_and_Managing_Log_Files.adoc#s2-Templates[Templates]." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:382 +#, no-wrap +msgid "Using MySQL and PostgreSQL" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:388 +msgid "" +"Currently, [application]*rsyslog* provides support for `MySQL` and " +"`PostgreSQL` databases only. In order to use the `MySQL` and `PostgreSQL` " +"database writer functionality, install the [package]*rsyslog-mysql* and " +"[package]*rsyslog-pgsql* packages, respectively. Also, make sure you load " +"the appropriate modules in your `/etc/rsyslog.conf` configuration file:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:393 +#, no-wrap +msgid "" +"$ModLoad ommysql # Output module for MySQL support\n" +"$ModLoad ompgsql # Output module for PostgreSQL support\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:397 +msgid "" +"For more information on [application]*rsyslog* modules, see " +"xref:Viewing_and_Managing_Log_Files.adoc#s1-using_rsyslog_modules[Using " +"Rsyslog Modules]." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:399 +msgid "" +"Alternatively, you may use a generic database interface provided by the " +"`omlibdb` module (supports: Firebird/Interbase, MS SQL, Sybase, SQLLite, " +"Ingres, Oracle, mSQL)." +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:402 +#, no-wrap +msgid "Discarding syslog messages" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:403 +msgid "To discard your selected messages, use the tilde character (`~`)." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:407 +#, no-wrap +msgid "_FILTER_ ~\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:410 +msgid "" +"The discard action is mostly used to filter out messages before carrying on " +"any further processing. It can be effective if you want to omit some " +"repeating messages that would otherwise fill the log files. The results of " +"discard action depend on where in the configuration file it is specified, " +"for the best results place these actions on top of the actions list. Please " +"note that once a message has been discarded there is no way to retrieve it " +"in later configuration file lines." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:412 +msgid "For instance, the following rule discards any cron syslog messages:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:415 +#, no-wrap +msgid "cron.* ~\n" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:417 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:432 +#, no-wrap +msgid "Specifying Multiple Actions" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:419 +msgid "" +"For each selector, you are allowed to specify multiple actions. To specify " +"multiple actions for one selector, write each action on a separate line and " +"precede it with an ampersand (&) character:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:426 +#, no-wrap +msgid "" +"_FILTER_ _ACTION_\n" +"& _ACTION_\n" +"& _ACTION_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:430 +msgid "" +"Specifying multiple actions improves the overall performance of the desired " +"outcome since the specified selector has to be evaluated only once." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:436 +msgid "" +"In the following example, all kernel syslog messages with the critical " +"priority (`crit`) are sent to user `user1`, processed by the template `temp` " +"and passed on to the `test-program` executable, and forwarded to " +"`192.168.0.1` via the `UDP` protocol." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:442 +#, no-wrap +msgid "" +"kern.=crit user1\n" +"& ^test-program;temp\n" +"& @192.168.0.1\n" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:448 +msgid "" +"Any action can be followed by a template that formats the message. To " +"specify a template, suffix an action with a semicolon (`;`) and specify the " +"name of the template. For more information on templates, see " +"xref:Viewing_and_Managing_Log_Files.adoc#s2-Templates[Templates]." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:449 +#, no-wrap +msgid "Using templates" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:454 +msgid "" +"A template must be defined before it is used in an action, otherwise it is " +"ignored. In other words, template definitions should always precede rule " +"definitions in `/etc/rsyslog.conf`." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:458 +#, no-wrap +msgid "Templates" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:461 +msgid "" +"indexterm:[rsyslog,templates] Any output that is generated by " +"[application]*rsyslog* can be modified and formatted according to your needs " +"with the use of *templates*. To create a template use the following syntax " +"in `/etc/rsyslog.conf`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:465 +#, no-wrap +msgid "" +"$template pass:quotes[_TEMPLATE_NAME_],\"pass:quotes[_text %PROPERTY% more " +"text_]\", pass:quotes[_OPTION_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:470 +msgid "" +"`$template` is the template directive that indicates that the text following " +"it, defines a template." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:472 +msgid "" +"`TEMPLATE_NAME` is the name of the template. Use this name to refer to the " +"template." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:474 +msgid "" +"Anything between the two quotation marks " +"(`\"`pass:attributes[{blank}]…pass:attributes[{blank}]`\"`) is the " +"actual template text. Within this text, special characters, such as `\\n` " +"for new line or `\\r` for carriage return, can be used. Other characters, " +"such as `%` or `\"`, have to be escaped if you want to use those characters " +"literally." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:476 +msgid "" +"The text specified between two percent signs (`%`) specifies a _property_ " +"that allows you to access specific contents of a syslog message. For more " +"information on properties, see " +"xref:Viewing_and_Managing_Log_Files.adoc#brid-properties[Properties]." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:478 +msgid "" +"The `OPTION` attribute specifies any options that modify the template " +"functionality. The currently supported template options are `sql` and " +"`stdsql`, which are used for formatting the text as an SQL query." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:479 +#, no-wrap +msgid "The sql and stdsql options" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:484 +msgid "" +"Note that the database writer checks whether the `sql` or `stdsql` options " +"are specified in the template. If they are not, the database writer does not " +"perform any action. This is to prevent any possible security threats, such " +"as SQL injection." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:486 +msgid "" +"See section [citetitle]_Storing syslog messages in a database_ in " +"xref:Viewing_and_Managing_Log_Files.adoc#s2-Actions[Actions] for more " +"information." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:490 +#, no-wrap +msgid "Generating Dynamic File Names" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:493 +msgid "" +"Templates can be used to generate dynamic file names. By specifying a " +"property as a part of the file path, a new file will be created for each " +"unique property, which is a convenient way to classify syslog messages." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:495 +msgid "" +"For example, use the `timegenerated` property, which extracts a time stamp " +"from the message, to generate a unique file name for each syslog message:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:498 +#, no-wrap +msgid "$template DynamicFile,\"/var/log/test_logs/%timegenerated%-test.log\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:501 +msgid "" +"Keep in mind that the `$template` directive only specifies the template. You " +"must use it inside a rule for it to take effect. In `/etc/rsyslog.conf`, use " +"the question mark (`?`) in an action definition to mark the dynamic file " +"name template:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:504 +#, no-wrap +msgid "*.* ?DynamicFile\n" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:507 +#, no-wrap +msgid "Properties" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:509 +msgid "" +"Properties defined inside a template (between two percent signs (`%`)) " +"enable access various contents of a syslog message through the use of a " +"_property replacer_. To define a property inside a template (between the two " +"quotation marks " +"(`\"`pass:attributes[{blank}]…pass:attributes[{blank}]`\"`)), use the " +"following syntax:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:513 +#, no-wrap +msgid "%pass:quotes[_PROPERTY_NAME_]:pass:quotes[_FROM_CHAR_]:pass:quotes[_TO_CHAR_]:pass:quotes[_OPTION_]%\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:518 +msgid "" +"The _PROPERTY_NAME_ attribute specifies the name of a property. A list of " +"all available properties and their detailed description can be found in the " +"`rsyslog.conf(5)` manual page under the section *Available Properties*." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:520 +msgid "" +"_FROM_CHAR_ and _TO_CHAR_ attributes denote a range of characters that the " +"specified property will act upon. Alternatively, regular expressions can be " +"used to specify a range of characters. To do so, set the letter `R` as the " +"_FROM_CHAR_ attribute and specify your desired regular expression as the " +"_TO_CHAR_ attribute." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:522 +msgid "" +"The _OPTION_ attribute specifies any property options, such as the " +"[option]`lowercase` option to convert the input to lowercase. A list of all " +"available property options and their detailed description can be found in " +"the `rsyslog.conf(5)` manual page under the section *Property Options*." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:524 +msgid "The following are some examples of simple properties:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:526 +msgid "The following property obtains the whole message text of a syslog message:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:530 +#, no-wrap +msgid "%msg%\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:533 +msgid "" +"The following property obtains the first two characters of the message text " +"of a syslog message:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:537 +#, no-wrap +msgid "%msg:1:2%\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:540 +msgid "" +"The following property obtains the whole message text of a syslog message " +"and drops its last line feed character:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:544 +#, no-wrap +msgid "%msg:::drop-last-lf%\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:547 +msgid "" +"The following property obtains the first 10 characters of the time stamp " +"that is generated when the syslog message is received and formats it " +"according to the " +"[citetitle]_link:++https://www.rfc-editor.org/info/rfc3339++[RFC 3339]_ date " +"standard." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:551 +#, no-wrap +msgid "%timegenerated:1:10:date-rfc3339%\n" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:553 +#, no-wrap +msgid "Template Examples" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:555 +msgid "This section presents a few examples of [application]*rsyslog* templates." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:557 +msgid "" +"xref:Viewing_and_Managing_Log_Files.adoc#example-temp1[A verbose syslog " +"message template] shows a template that formats a syslog message so that it " +"outputs the message's severity, facility, the time stamp of when the message " +"was received, the host name, the message tag, the message text, and ends " +"with a new line." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:559 +#, no-wrap +msgid "A verbose syslog message template" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:565 +#, no-wrap +msgid "" +"$template verbose, \"%syslogseverity%, %syslogfacility%, %timegenerated%, " +"%HOSTNAME%, %syslogtag%, %msg%\\n\"\n" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:570 +msgid "" +"xref:Viewing_and_Managing_Log_Files.adoc#example-temp2[A wall message " +"template] shows a template that resembles a traditional wall message (a " +"message that is send to every user that is logged in and has their `mesg(1)` " +"permission set to `yes`). This template outputs the message text, along with " +"a host name, message tag and a time stamp, on a new line (using `\\r` and " +"`\\n`) and rings the bell (using `\\7`)." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:572 +#, no-wrap +msgid "A wall message template" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:578 +#, no-wrap +msgid "" +"$template wallmsg,\"\\r\\n\\7Message from syslogd@%HOSTNAME% at " +"%timegenerated% ...\\r\\n %syslogtag% %msg%\\n\\r\"\n" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:583 +msgid "" +"xref:Viewing_and_Managing_Log_Files.adoc#example-temp3[A database formatted " +"message template] shows a template that formats a syslog message so that it " +"can be used as a database query. Notice the use of the `sql` option at the " +"end of the template specified as the template option. It tells the database " +"writer to format the message as an MySQL `SQL` query." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:585 +#, no-wrap +msgid "A database formatted message template" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:591 +#, no-wrap +msgid "" +"$template dbFormat,\"insert into SystemEvents (Message, Facility, FromHost, " +"Priority, DeviceReportedTime, ReceivedAt, InfoUnitID, SysLogTag) values " +"('%msg%', %syslogfacility%, '%HOSTNAME%', %syslogpriority%, " +"'%timereported:::date-mysql%', '%timegenerated:::date-mysql%', %iut%, " +"'%syslogtag%')\", sql\n" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:596 +msgid "" +"[application]*rsyslog* also contains a set of predefined templates " +"identified by the `RSYSLOG_` prefix. These are reserved for the syslog's use " +"and it is advisable to not create a template using this prefix to avoid " +"conflicts. The following list shows these predefined templates along with " +"their definitions." +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:597 +#, no-wrap +msgid "`RSYSLOG_DebugFormat`" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:598 +msgid "A special format used for troubleshooting property problems." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:602 +#, no-wrap +msgid "" +"\"Debug line with all properties:\\nFROMHOST: '%FROMHOST%', fromhost-ip: " +"'%fromhost-ip%', HOSTNAME: '%HOSTNAME%', PRI: %PRI%,\\nsyslogtag " +"'%syslogtag%', programname: '%programname%', APP-NAME: '%APP-NAME%', PROCID: " +"'%PROCID%', MSGID: '%MSGID%',\\nTIMESTAMP: '%TIMESTAMP%', STRUCTURED-DATA: " +"'%STRUCTURED-DATA%',\\nmsg: '%msg%'\\nescaped msg: " +"'%msg:::drop-cc%'\\nrawmsg: '%rawmsg%'\\n\\n\\\"\n" +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:604 +#, no-wrap +msgid "`RSYSLOG_SyslogProtocol23Format`" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:605 +msgid "" +"The format specified in IETF's internet-draft ietf-syslog-protocol-23, which " +"is assumed to become the new syslog standard RFC." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:609 +#, no-wrap +msgid "" +"\"%PRI%1 %TIMESTAMP:::date-rfc3339% %HOSTNAME% %APP-NAME% %PROCID% %MSGID% " +"%STRUCTURED-DATA% %msg%\\n\\\"\n" +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:611 +#, no-wrap +msgid "`RSYSLOG_FileFormat`" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:612 +msgid "" +"A modern-style logfile format similar to TraditionalFileFormat, but with " +"high-precision time stamps and time zone information." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:616 +#, no-wrap +msgid "" +"\"%TIMESTAMP:::date-rfc3339% %HOSTNAME% " +"%syslogtag%%msg:::sp-if-no-1st-sp%%msg:::drop-last-lf%\\n\\\"\n" +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:618 +#, no-wrap +msgid "`RSYSLOG_TraditionalFileFormat`" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:619 +msgid "The older default log file format with low-precision time stamps." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:623 +#, no-wrap +msgid "" +"\"%TIMESTAMP% %HOSTNAME% " +"%syslogtag%%msg:::sp-if-no-1st-sp%%msg:::drop-last-lf%\\n\\\"\n" +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:625 +#, no-wrap +msgid "`RSYSLOG_ForwardFormat`" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:626 +msgid "" +"A forwarding format with high-precision time stamps and time zone " +"information." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:630 +#, no-wrap +msgid "" +"\"%PRI%%TIMESTAMP:::date-rfc3339% %HOSTNAME% " +"%syslogtag:1:32%%msg:::sp-if-no-1st-sp%%msg%\\\"\n" +msgstr "" + +#. type: Labeled list +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:632 +#, no-wrap +msgid "`RSYSLOG_TraditionalForwardFormat`" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:633 +msgid "The traditional forwarding format with low-precision time stamps." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:637 +#, no-wrap +msgid "" +"\"%PRI%%TIMESTAMP% %HOSTNAME% " +"%syslogtag:1:32%%msg:::sp-if-no-1st-sp%%msg%\\\"\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:640 +#, no-wrap +msgid "Global Directives" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:643 +msgid "" +"indexterm:[rsyslog,global directives] Global directives are configuration " +"options that apply to the `rsyslogd` daemon. They usually specify a value " +"for a specific predefined variable that affects the behavior of the " +"`rsyslogd` daemon or a rule that follows. All of the global directives must " +"start with a dollar sign (`$`). Only one directive can be specified per " +"line. The following is an example of a global directive that specifies the " +"maximum size of the syslog message queue:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:648 +#, no-wrap +msgid "$MainMsgQueueSize 50000\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:652 +msgid "" +"The default size defined for this directive (10,000 messages) can be " +"overridden by specifying a different value (as shown in the example above)." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:654 +msgid "" +"You can define multiple directives in your `/etc/rsyslog.conf` configuration " +"file. A directive affects the behavior of all configuration options until " +"another occurrence of that same directive is detected. Global directives can " +"be used to configure actions, queues and for debugging. A comprehensive list " +"of all available configuration directives can be found in " +"xref:Viewing_and_Managing_Log_Files.adoc#brid-Log_Files-Resources-Online[Online " +"Documentation]. Currently, a new configuration format has been developed " +"that replaces the $-based syntax (see " +"xref:Viewing_and_Managing_Log_Files.adoc#sec-using_the_new_configuration_format[Using " +"the New Configuration Format]). However, classic global directives remain " +"supported as a legacy format." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:656 +#, no-wrap +msgid "Log Rotation" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:659 +msgid "" +"indexterm:[rsyslog,log rotation] The following is a sample " +"`/etc/logrotate.conf` configuration file:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:668 +#, no-wrap +msgid "" +"# rotate log files weekly\n" +"weekly\n" +"# keep 4 weeks worth of backlogs\n" +"rotate 4\n" +"# uncomment this if you want your log files compressed\n" +"compress\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:672 +msgid "" +"All of the lines in the sample configuration file define global options that " +"apply to every log file. In our example, log files are rotated weekly, " +"rotated log files are kept for four weeks, and all rotated log files are " +"compressed by [application]*gzip* into the `.gz` format. Any lines that " +"begin with a hash sign (#) are comments and are not processed." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:674 +msgid "" +"You may define configuration options for a specific log file and place it " +"under the global options. However, it is advisable to create a separate " +"configuration file for any specific log file in the `/etc/logrotate.d/` " +"directory and define any configuration options there." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:676 +msgid "" +"The following is an example of a configuration file placed in the " +"`/etc/logrotate.d/` directory:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:687 +#, no-wrap +msgid "" +"/var/log/messages {\n" +" rotate 5\n" +" weekly\n" +" postrotate\n" +" /usr/bin/killall -HUP syslogd\n" +" endscript\n" +"}\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:691 +msgid "" +"The configuration options in this file are specific for the " +"`/var/log/messages` log file only. The settings specified here override the " +"global settings where possible. Thus the rotated `/var/log/messages` log " +"file will be kept for five weeks instead of four weeks as was defined in the " +"global options." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:693 +msgid "" +"The following is a list of some of the directives you can specify in your " +"[application]*logrotate* configuration file:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:695 +msgid "" +"`weekly` — Specifies the rotation of log files to be done weekly. Similar " +"directives include:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:697 +msgid "`daily`" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:699 +msgid "`monthly`" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:701 +msgid "`yearly`" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:703 +msgid "" +"`compress` — Enables compression of rotated log files. Similar directives " +"include:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:705 +msgid "`nocompress`" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:707 +msgid "`compresscmd` — Specifies the command to be used for compressing." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:709 +msgid "`uncompresscmd`" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:711 +msgid "`compressext` — Specifies what extension is to be used for compressing." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:713 +msgid "" +"`compressoptions` — Specifies any options to be passed to the compression " +"program used." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:715 +msgid "" +"`delaycompress` — Postpones the compression of log files to the next " +"rotation of log files." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:717 +msgid "" +"`rotate _INTEGER_pass:attributes[{blank}]` — Specifies the number of " +"rotations a log file undergoes before it is removed or mailed to a specific " +"address. If the value 0 is specified, old log files are removed instead of " +"rotated." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:719 +msgid "" +"`mail _ADDRESS_pass:attributes[{blank}]` — This option enables mailing of " +"log files that have been rotated as many times as is defined by the `rotate` " +"directive to the specified address. Similar directives include:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:721 +msgid "`nomail`" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:723 +msgid "" +"`mailfirst` — Specifies that the just-rotated log files are to be mailed, " +"instead of the about-to-expire log files." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:725 +msgid "" +"`maillast` — Specifies that the about-to-expire log files are to be mailed, " +"instead of the just-rotated log files. This is the default option when " +"`mail` is enabled." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:727 +msgid "" +"For the full list of directives and various configuration options, see the " +"`logrotate(8)` manual page." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:729 +#, no-wrap +msgid "Using the New Configuration Format" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:732 +msgid "" +"indexterm:[rsyslog,new configuration format] In [application]*rsyslog* " +"version 6, a new configuration syntax was introduced. This new configuration " +"format aims to be more powerful, more intuitive, and to prevent common " +"mistakes by not permitting certain invalid constructs. The syntax " +"enhancement is enabled by the new configuration processor that relies on " +"RainerScript. The legacy format is still fully supported and it is used by " +"default in the `/etc/rsyslog.conf` configuration file." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:734 +msgid "" +"RainerScript is a scripting language designed for processing network events " +"and configuring event processors such as " +"[application]*rsyslog*. RainerScript was first used to define " +"expression-based filters, see " +"xref:Viewing_and_Managing_Log_Files.adoc#ex-expression-based_filters[Expression-based " +"Filters]. The version of RainerScript in rsyslog version 7 implemented the " +"`input()` and `ruleset()` statements, which permit the `/etc/rsyslog.conf` " +"configuration file to be written in the new syntax. The new syntax differs " +"mainly in that it is much more structured; parameters are passed as " +"arguments to statements, such as input, action, template, and module " +"load. The scope of options is limited by blocks. This enhances readability " +"and reduces the number of bugs caused by misconfiguration. There is also a " +"significant performance gain. Some functionality is exposed in both " +"syntaxes, some only in the new one." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:736 +msgid "Compare the configuration written with legacy-style parameters:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:744 +#, no-wrap +msgid "" +"$InputFileName /tmp/inputfile\n" +"$InputFileTag tag1:\n" +"$InputFileStateFile inputfile-state\n" +"$InputRunFileMonitor\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:748 +msgid "and the same configuration with the use of the new format statement:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:753 +#, no-wrap +msgid "" +"input(type=\"imfile\" file=\"/tmp/inputfile\" tag=\"tag1:\" " +"statefile=\"inputfile-state\")\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:757 +msgid "" +"This significantly reduces the number of parameters used in configuration, " +"improves readability, and also provides higher execution speed. For more " +"information on RainerScript statements and parameters see " +"xref:Viewing_and_Managing_Log_Files.adoc#brid-Log_Files-Resources-Online[Online " +"Documentation]." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:759 +#, no-wrap +msgid "Rulesets" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:762 +msgid "" +"indexterm:[rsyslog,rulesets] Leaving special directives aside, " +"[application]*rsyslog* handles messages as defined by *rules* that consist " +"of a filter condition and an action to be performed if the condition is " +"true. With a traditionally written `/etc/rsyslog.conf` file, all rules are " +"evaluated in order of appearance for every input message. This process " +"starts with the first rule and continues until all rules have been processed " +"or until the message is discarded by one of the rules." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:764 +msgid "" +"However, rules can be grouped into sequences called _rulesets_. With " +"rulesets, you can limit the effect of certain rules only to selected inputs " +"or enhance the performance of [application]*rsyslog* by defining a distinct " +"set of actions bound to a specific input. In other words, filter conditions " +"that will be inevitably evaluated as false for certain types of messages can " +"be skipped. The legacy ruleset definition in `/etc/rsyslog.conf` can look as " +"follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:771 +#, no-wrap +msgid "" +"$RuleSet _rulesetname_\n" +"_rule_\n" +"_rule2_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:774 +msgid "" +"The rule ends when another rule is defined, or the default ruleset is called " +"as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:777 +#, no-wrap +msgid "$RuleSet RSYSLOG_DefaultRuleset\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:780 +msgid "" +"With the new configuration format in rsyslog 7, the `input()` and " +"`ruleset()` statements are reserved for this operation. The new format " +"ruleset definition in `/etc/rsyslog.conf` can look as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:790 +#, no-wrap +msgid "" +"ruleset(name=\"pass:attributes[{blank}]_rulesetname_pass:attributes[{blank}]\") " +"{\n" +" _rule_\n" +" _rule2_\n" +" call _rulesetname2_\n" +" …\n" +"}\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:794 +msgid "" +"Replace _rulesetname_ with an identifier for your ruleset. The ruleset name " +"cannot start with `RSYSLOG_` since this namespace is reserved for use by " +"[application]*rsyslog*. `RSYSLOG_DefaultRuleset` then defines the default " +"set of rules to be performed if the message has no other ruleset " +"assigned. With _rule_ and _rule2_ you can define rules in filter-action " +"format mentioned above. With the `call` parameter, you can nest rulesets by " +"calling them from inside other ruleset blocks." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:796 +msgid "After creating a ruleset, you need to specify what input it will apply to:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:800 +#, no-wrap +msgid "" +"input(type=\"pass:quotes[_input_type_]\" port=\"pass:quotes[_port_num_]\" " +"ruleset=\"pass:quotes[_rulesetname_]\");\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:803 +msgid "" +"Here you can identify an input message by _input_type_, which is an input " +"module that gathered the message, or by _port_num_ – the port " +"number. Other parameters such as *file* or *tag* can be specified for " +"`input()`. Replace _rulesetname_ with a name of the ruleset to be evaluated " +"against the message. In case an input message is not explicitly bound to a " +"ruleset, the default ruleset is triggered." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:805 +msgid "" +"You can also use the legacy format to define rulesets, for more information " +"see " +"xref:Viewing_and_Managing_Log_Files.adoc#brid-Log_Files-Resources-Online[Online " +"Documentation]." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:807 +#, no-wrap +msgid "Using rulesets" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:811 +msgid "" +"The following rulesets ensure different handling of remote messages coming " +"from different ports. Add the following into `/etc/rsyslog.conf`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:817 +#, no-wrap +msgid "" +"ruleset(name=\"remote-10514\") {\n" +" action(type=\"omfile\" file=\"/var/log/remote-10514\")\n" +"}\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:822 +#, no-wrap +msgid "" +"ruleset(name=\"remote-10515\") {\n" +" cron.* action(type=\"omfile\" file=\"/var/log/remote-10515-cron\")\n" +" mail.* action(type=\"omfile\" file=\"/var/log/remote-10515-mail\")\n" +"}\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:825 +#, no-wrap +msgid "" +"input(type=\"imtcp\" port=\"10514\" ruleset=\"remote-10514\");\n" +"input(type=\"imtcp\" port=\"10515\" ruleset=\"remote-10515\");\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:829 +msgid "" +"Rulesets shown in the above example define log destinations for the remote " +"input from two ports, in case of 10515, messages are sorted according to the " +"facility. Then, the TCP input is enabled and bound to rulesets. Note that " +"you must load the required modules (imtcp) for this configuration to work." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:833 +#, no-wrap +msgid "Compatibility with syslogd" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:836 +msgid "" +"From [application]*rsyslog* version 6, compatibility mode specified via the " +"[option]`-c` option has been removed. Also, the syslogd-style command-line " +"options are deprecated and configuring [application]*rsyslog* through these " +"command-line options should be avoided. However, you can use several " +"templates and directives to configure `rsyslogd` to emulate syslogd-like " +"behavior." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:838 +msgid "" +"For more information on various `rsyslogd` options, see the " +"`rsyslogd(8)`pass:attributes[{blank}]manual page." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:840 +#, no-wrap +msgid "Working with Queues in Rsyslog" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:843 +msgid "" +"indexterm:[rsyslog,queues] Queues are used to pass content, mostly syslog " +"messages, between components of [application]*rsyslog*. With queues, rsyslog " +"is capable of processing multiple messages simultaneously and to apply " +"several actions to a single message at once. The data flow inside " +"[application]*rsyslog* can be illustrated as follows:" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:845 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:847 +#, no-wrap +msgid "Message Flow in Rsyslog" +msgstr "" + +#. type: Target for macro image +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:847 +#, no-wrap +msgid "rsyslog_message_flow.png" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:850 +msgid "" +"Whenever [application]*rsyslog* receives a message, it passes this message " +"to the preprocessor and then places it into the _main message " +"queue_. Messages wait there to be dequeued and passed to the _rule " +"processor_." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:852 +msgid "" +"The *rule processor* is a parsing and filtering engine. Here, the rules " +"defined in `/etc/rsyslog.conf` are applied. Based on these rules, the rule " +"processor evaluates which actions are to be performed. Each action has its " +"own action queue. Messages are passed through this queue to the respective " +"action processor which creates the final output. Note that at this point, " +"several actions can run simultaneously on one message. For this purpose, a " +"message is duplicated and passed to multiple action processors." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:854 +msgid "" +"Only one queue per action is possible. Depending on configuration, the " +"messages can be sent right to the action processor without action " +"queuing. This is the behavior of *direct queues* (see below). In case the " +"output action fails, the action processor notifies the action queue, which " +"then takes an unprocessed element back and after some time interval, the " +"action is attempted again." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:856 +msgid "" +"To sum up, there are two positions where queues stand in " +"[application]*rsyslog*: either in front of the rule processor as a single " +"*main message queue* or in front of various types of output actions as " +"*action queues*. Queues provide two main advantages that both lead to " +"increased performance of message processing:" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:858 +msgid "" +"they serve as buffers that *decouple* producers and consumers in the " +"structure of [application]*rsyslog*" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:860 +msgid "they allow for *parallelization* of actions performed on messages" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:862 +msgid "" +"Apart from this, queues can be configured with several directives to provide " +"optimal performance for your system. These configuration options are covered " +"in the following sections." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:867 +msgid "" +"If an output plug-in is unable to deliver a message, it is stored in the " +"preceding message queue. If the queue fills, the inputs block until it is no " +"longer full. This will prevent new messages from being logged via the " +"blocked queue. In the absence of separate action queues this can have severe " +"consequences, such as preventing `SSH` logging, which in turn can prevent " +"`SSH` access. Therefore it is advised to use dedicated action queues for " +"outputs which are forwarded over a network or to a database." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:871 +#, no-wrap +msgid "Defining Queues" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:874 +msgid "" +"Based on where the messages are stored, there are several types of queues: " +"*direct*, *in-memory*, *disk*, and *disk-assisted in-memory* queues that are " +"most widely used. You can choose one of these types for the main message " +"queue and also for action queues. Add the following into " +"`/etc/rsyslog.conf`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:878 +#, no-wrap +msgid "$pass:quotes[_object_]QueueType pass:quotes[_queue_type_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:881 +msgid "" +"Here, you can apply the setting for the main message queue (replace _object_ " +"with [option]`MainMsg`) or for an action queue (replace _object_ with " +"[option]`Action`). Replace _queue_type_ with one of `direct`, `linkedlist` " +"or `fixedarray` (which are in-memory queues), or `disk`." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:883 +msgid "" +"The default setting for a main message queue is the FixedArray queue with a " +"limit of 10,000 messages. Action queues are by default set as Direct queues." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:884 +#, no-wrap +msgid "Direct Queues" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:886 +msgid "" +"For many simple operations, such as when writing output to a local file, " +"building a queue in front of an action is not needed. To avoid queuing, use:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:890 +#, no-wrap +msgid "$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueType Direct\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:893 +msgid "" +"Replace _object_ with [option]`MainMsg` or with [option]`Action` to use this " +"option to the main message queue or for an action queue respectively. With " +"direct queue, messages are passed directly and immediately from the producer " +"to the consumer." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:894 +#, no-wrap +msgid "Disk Queues" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:896 +msgid "" +"Disk queues store messages strictly on a hard drive, which makes them highly " +"reliable but also the slowest of all possible queuing modes. This mode can " +"be used to prevent the loss of highly important log data. However, disk " +"queues are not recommended in most use cases. To set a disk queue, type the " +"following into `/etc/rsyslog.conf`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:900 +#, no-wrap +msgid "$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueType Disk\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:903 +msgid "" +"Replace _object_ with [option]`MainMsg` or with [option]`Action` to use this " +"option to the main message queue or for an action queue respectively. Disk " +"queues are written in parts, with a default size 10 Mb. This default size " +"can be modified with the following configuration directive:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:907 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueMaxFileSize " +"_size_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:910 +msgid "" +"where _size_ represents the specified size of disk queue part. The defined " +"size limit is not restrictive, [application]*rsyslog* always writes one " +"complete queue entry, even if it violates the size limit. Each part of a " +"disk queue matches with an individual file. The naming directive for these " +"files looks as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:914 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueFilename " +"_name_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:917 +msgid "" +"This sets a _name_ prefix for the file followed by a 7-digit number starting " +"at one and incremented for each file." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:918 +#, no-wrap +msgid "In-memory Queues" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:920 +msgid "" +"With in-memory queue, the enqueued messages are held in memory which makes " +"the process very fast. The queued data is lost if the computer is power " +"cycled or shut down. However, you can use the " +"[option]`$ActionQueueSaveOnShutdown` setting to save the data before " +"shutdown. There are two types of in-memory queues:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:922 +#, no-wrap +msgid "" +"*FixedArray* queue — the default mode for the main message queue, with " +"a limit of 10,000 elements. This type of queue uses a fixed, pre-allocated " +"array that holds pointers to queue elements. Due to these pointers, even if " +"the queue is empty a certain amount of memory is consumed. However, " +"FixedArray offers the best run time performance and is optimal when you " +"expect a relatively low number of queued messages and high performance.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:924 +#, no-wrap +msgid "" +"*LinkedList* queue — here, all structures are dynamically allocated in " +"a linked list, thus the memory is allocated only when needed. LinkedList " +"queues handle occasional message bursts very well.\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:926 +msgid "" +"In general, use LinkedList queues when in doubt. Compared to FixedArray, it " +"consumes less memory and lowers the processing overhead." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:928 +msgid "Use the following syntax to configure in-memory queues:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:932 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueType " +"LinkedList\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:937 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueType " +"FixedArray\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:940 +msgid "" +"Replace _object_ with [option]`MainMsg` or with [option]`Action` to use this " +"option to the main message queue or for an action queue respectively." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:941 +#, no-wrap +msgid "Disk-Assisted In-memory Queues" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:943 +msgid "" +"Both disk and in-memory queues have their advantages and " +"[application]*rsyslog* lets you combine them in *disk-assisted in-memory " +"queues*. To do so, configure a normal in-memory queue and then add the " +"[option]`$objectQueueFileName` directive to define a file name for disk " +"assistance. This queue then becomes *disk-assisted*, which means it couples " +"an in-memory queue with a disk queue to work in tandem." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:945 +msgid "" +"The disk queue is activated if the in-memory queue is full or needs to " +"persist after shutdown. With a disk-assisted queue, you can set both " +"disk-specific and in-memory specific configuration parameters. This type of " +"queue is probably the most commonly used, it is especially useful for " +"potentially long-running and unreliable actions." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:947 +msgid "" +"To specify the functioning of a disk-assisted in-memory queue, use the " +"so-called *watermarks*:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:951 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1047 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueHighWatermark " +"_number_\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:956 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueLowWatermark " +"_number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:959 +msgid "" +"Replace _object_ with [option]`MainMsg` or with [option]`Action` to use this " +"option to the main message queue or for an action queue " +"respectively. Replace _number_ with a number of enqueued messages. When an " +"in-memory queue reaches the number defined by the high watermark, it starts " +"writing messages to disk and continues until the in-memory queue size drops " +"to the number defined with the low watermark. Correctly set watermarks " +"minimize unnecessary disk writes, but also leave memory space for message " +"bursts since writing to disk files is rather lengthy. Therefore, the high " +"watermark must be lower than the whole queue capacity set with " +"*$objectQueueSize*. The difference between the high watermark and the " +"overall queue size is a spare memory buffer reserved for message bursts. On " +"the other hand, setting the high watermark too low will turn on disk " +"assistance unnecessarily often." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:961 +#, no-wrap +msgid "Reliable Forwarding of Log Messages to a Server" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:965 +msgid "" +"Rsyslog is often used to maintain a centralized logging system, where log " +"messages are forwarded to a server over the network. To avoid message loss " +"when the server is not available, it is advisable to configure an action " +"queue for the forwarding action. This way, messages that failed to be sent " +"are stored locally until the server is reachable again. Note that such " +"queues are not configurable for connections using the `UDP` protocol. To " +"establish a fully reliable connection, for example when your logging server " +"is outside of your private network, consider using the RELP protocol " +"described in xref:Viewing_and_Managing_Log_Files.adoc#s2-using_RELP[Using " +"RELP]." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:967 +#, no-wrap +msgid "Forwarding To a Single Server" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:969 +msgid "" +"Suppose the task is to forward log messages from the system to a server with " +"host name *example.com*, and to configure an action queue to buffer the " +"messages in case of a server outage. To do so, perform the following steps:" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:971 +msgid "Create a working directory to store the queue files. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:975 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1014 +#, no-wrap +msgid "~]#{nbsp}mkdir pass:quotes[`/rsyslog/work/`]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:978 +msgid "" +"Use the following configuration in `/etc/rsyslog.conf` or create a file with " +"the following content in the `/etc/rsyslog.d/` directory:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:981 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1020 +#, no-wrap +msgid "$WorkDirectory /rsyslog/work\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:987 +#, no-wrap +msgid "" +"$ActionQueueType LinkedList\n" +"$ActionQueueFileName example_fwd\n" +"$ActionResumeRetryCount -1\n" +"$ActionQueueSaveOnShutdown on\n" +"*.* @@example.com:18\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:990 +msgid "Where:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:992 +msgid "" +"the `/rsyslog/work/` directory created in the previous step is marked as a " +"working directory," +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:994 +msgid "[option]`$ActionQueueType` enables a LinkedList in-memory queue," +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:996 +msgid "" +"[option]`$ActionFileName` defines a disk storage, in this case the backup " +"files are created in the `/rsyslog/work/` directory with the *example_fwd* " +"prefix," +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:998 +msgid "" +"the [option]`$ActionResumeRetryCount -1` setting prevents rsyslog form " +"dropping messages when retrying to connect if server is not responding," +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1000 +msgid "" +"enabled [option]`$ActionQueueSaveOnShutdown` saves in-memory data if rsyslog " +"shuts down," +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1002 +msgid "" +"the last line forwards all received messages to the logging server, port " +"specification is optional." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1004 +msgid "" +"With the above configuration, rsyslog keeps messages in memory if the remote " +"server is not reachable. A file on disk is created only if rsyslog runs out " +"of the configured memory queue space or needs to shut down, which benefits " +"the system performance." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1006 +#, no-wrap +msgid "Forwarding To Multiple Servers" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1008 +msgid "" +"The process of forwarding log messages to multiple servers is similar to the " +"previous procedure:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1010 +msgid "" +"Create a working directory for rsyslog to store the queue files. For " +"example:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1017 +msgid "" +"Each destination server requires a separate forwarding rule, action queue " +"specification, and backup file on disk. For example, use the following " +"configuration in `/etc/rsyslog.conf` or create a file with the following " +"content in the `/etc/rsyslog.d/` directory:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1026 +#, no-wrap +msgid "" +"$ActionQueueType LinkedList\n" +"$ActionQueueFileName example_fwd1\n" +"$ActionResumeRetryCount -1\n" +"$ActionQueueSaveOnShutdown on\n" +"*.* @@example1.com\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1032 +#, no-wrap +msgid "" +"$ActionQueueType LinkedList\n" +"$ActionQueueFileName example_fwd2\n" +"$ActionResumeRetryCount -1\n" +"$ActionQueueSaveOnShutdown on\n" +"*.* @@example2.com\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1037 +#, no-wrap +msgid "Managing Queues" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1040 +msgid "" +"All types of queues can be further configured to match your " +"requirements. You can use several directives to modify both action queues " +"and the main message queue. Currently, there are more than 20 queue " +"parameters available, see " +"xref:Viewing_and_Managing_Log_Files.adoc#brid-Log_Files-Resources-Online[Online " +"Documentation]. Some of these settings are used commonly, others, such as " +"worker thread management, provide closer control over the queue behavior and " +"are reserved for advanced users. With advanced settings, you can optimize " +"[application]*rsyslog*pass:attributes[{blank}]'s performance, schedule " +"queuing, or modify the behavior of a queue on system shutdown." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1041 +#, no-wrap +msgid "Limiting Queue Size" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1043 +msgid "" +"You can limit the number of messages that queue can contain with the " +"following setting:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1050 +msgid "" +"Replace _object_ with [option]`MainMsg` or with [option]`Action` to use this " +"option to the main message queue or for an action queue " +"respectively. Replace _number_ with a number of enqueued messages. You can " +"set the queue size only as the number of messages, not as their actual " +"memory size. The default queue size is 10,000 messages for the main message " +"queue and ruleset queues, and 1000 for action queues." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1052 +msgid "" +"Disk assisted queues are unlimited by default and can not be restricted with " +"this directive, but you can reserve them physical disk space in bytes with " +"the following settings:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1056 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueMaxDiscSpace " +"_number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1059 +msgid "" +"Replace _object_ with [option]`MainMsg` or with [option]`Action`. When the " +"size limit specified by _number_ is hit, messages are discarded until " +"sufficient amount of space is freed by dequeued messages." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1060 +#, no-wrap +msgid "Discarding Messages" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1062 +msgid "" +"When a queue reaches a certain number of messages, you can discard less " +"important messages in order to save space in the queue for entries of higher " +"priority. The threshold that launches the discarding process can be set with " +"the so-called *discard mark*:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1066 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueDiscardMark " +"_number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1069 +msgid "" +"Replace _object_ with [option]`MainMsg` or with [option]`Action` to use this " +"option to the main message queue or for an action queue respectively. Here, " +"_number_ stands for a number of messages that have to be in the queue to " +"start the discarding process. To define which messages to discard, use:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1073 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueDiscardSeverity " +"_priority_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1076 +msgid "" +"Replace _priority_ with one of the following keywords (or with a number): " +"[command]#debug# (7), [command]#info# (6), [command]#notice# (5), " +"[command]#warning# (4), [command]#err# (3), [command]#crit# (2), " +"[command]#alert# (1), and [command]#emerg# (0). With this setting, both " +"newly incoming and already queued messages with lower than defined priority " +"are erased from the queue immediately after the discard mark is reached." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1077 +#, no-wrap +msgid "Using Timeframes" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1079 +msgid "" +"You can configure [application]*rsyslog* to process queues during a specific " +"time period. With this option you can, for example, transfer some processing " +"into off-peak hours. To define a time frame, use the following syntax:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1083 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueDequeueTimeBegin " +"_hour_\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1088 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueDequeueTimeEnd " +"_hour_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1091 +msgid "" +"With _hour_ you can specify hours that bound your time frame. Use the " +"24-hour format without minutes." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1092 +#, no-wrap +msgid "Configuring Worker Threads" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1094 +msgid "" +"A _worker thread_ performs a specified action on the enqueued message. For " +"example, in the main message queue, a worker task is to apply filter logic " +"to each incoming message and enqueue them to the relevant action " +"queues. When a message arrives, a worker thread is started " +"automatically. When the number of messages reaches a certain number, another " +"worker thread is turned on. To specify this number, use:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1098 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueWorkerThreadMinimumMessages " +"_number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1101 +msgid "" +"Replace _number_ with a number of messages that will trigger a supplemental " +"worker thread. For example, with _number_ set to 100, a new worker thread is " +"started when more than 100 messages arrive. When more than 200 messages " +"arrive, the third worker thread starts and so on. However, too many working " +"threads running in parallel becomes ineffective, so you can limit the " +"maximum number of them by using:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1105 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueWorkerThreads " +"_number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1108 +msgid "" +"where _number_ stands for a maximum number of working threads that can run " +"in parallel. For the main message queue, the default limit is 1 thread. Once " +"a working thread has been started, it keeps running until an inactivity " +"timeout appears. To set the length of timeout, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1112 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueWorkerTimeoutThreadShutdown " +"_time_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1115 +msgid "" +"Replace _time_ with the duration set in milliseconds. Without this setting, " +"a zero timeout is applied and a worker thread is terminated immediately when " +"it runs out of messages. If you specify _time_ as `-1`, no thread will be " +"closed." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1116 +#, no-wrap +msgid "Batch Dequeuing" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1118 +msgid "" +"To increase performance, you can configure [application]*rsyslog* to dequeue " +"multiple messages at once. To set the upper limit for such dequeueing, use:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1122 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueDequeueBatchSize " +"_number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1125 +msgid "" +"Replace _number_ with the maximum number of messages that can be dequeued at " +"once. Note that a higher setting combined with a higher number of permitted " +"working threads results in greater memory consumption." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1126 +#, no-wrap +msgid "Terminating Queues" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1128 +msgid "" +"When terminating a queue that still contains messages, you can try to " +"minimize the data loss by specifying a time interval for worker threads to " +"finish the queue processing:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1132 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueTimeoutShutdown " +"_time_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1135 +msgid "" +"Specify _time_ in milliseconds. If after that period there are still some " +"enqueued messages, workers finish the current data element and then " +"terminate. Unprocessed messages are therefore lost. Another time interval " +"can be set for workers to finish the final element:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1139 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueTimeoutActionCompletion " +"_time_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1142 +msgid "" +"In case this timeout expires, any remaining workers are shut down. To save " +"data at shutdown, use:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1146 +#, no-wrap +msgid "" +"$pass:attributes[{blank}]_object_pass:attributes[{blank}]QueueTimeoutSaveOnShutdown " +"_time_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1149 +msgid "" +"If set, all queue elements are saved to disk before [application]*rsyslog* " +"terminates." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1151 +#, no-wrap +msgid "Configuring rsyslog on a Logging Server" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1154 +msgid "" +"The `rsyslog` service provides facilities both for running a logging server " +"and for configuring individual systems to send their log files to the " +"logging server. See " +"xref:Viewing_and_Managing_Log_Files.adoc#ex-net_forwarding_with_queue[Reliable " +"Forwarding of Log Messages to a Server] for information on client rsyslog " +"configuration." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1156 +msgid "" +"The `rsyslog` service must be installed on the system that you intend to use " +"as a logging server and all systems that will be configured to send logs to " +"it. Rsyslog is installed by default in {MAJOROSVER}. If required, to ensure " +"that it is, enter the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1160 +#, no-wrap +msgid "~]#{nbsp}dnf install rsyslog\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1163 +msgid "" +"The steps in this procedure must be followed on the system that you intend " +"to use as your logging server. All steps in this procedure must be made as " +"the `root` user:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1165 +msgid "Configure the firewall to allow `rsyslog` `TCP` traffic." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1167 +msgid "" +"The default port for `rsyslog` `TCP` traffic is `514`. To allow `TCP` " +"traffic on this port, enter a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1172 +#, no-wrap +msgid "" +"~]#{nbsp}firewall-cmd --zone=zone --add-port=514/tcp\n" +"success\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1175 +msgid "Where _zone_ is the zone of the interface to use." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1177 +msgid "Open the `/etc/rsyslog.conf` file in a text editor and proceed as follows:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1179 +msgid "" +"Add these lines below the modules section but above the `Provides UDP syslog " +"reception` section:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1182 +#, no-wrap +msgid "# Define templates before the rules that use them\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1186 +#, no-wrap +msgid "" +"### Per-Host Templates for Remote Systems ###\n" +"$template TmplAuthpriv, " +"\"/var/log/remote/auth/%HOSTNAME%/%PROGRAMNAME:::secpath-replace%.log\"\n" +"$template TmplMsg, " +"\"/var/log/remote/msg/%HOSTNAME%/%PROGRAMNAME:::secpath-replace%.log\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1189 +msgid "" +"Replace the default `Provides TCP syslog reception` section with the " +"following:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1200 +#, no-wrap +msgid "" +"# Provides TCP syslog reception\n" +"$ModLoad imtcp\n" +"# Adding this ruleset to process remote messages\n" +"$RuleSet remote1\n" +"authpriv.* ?TmplAuthpriv\n" +"*.info;mail.none;authpriv.none;cron.none ?TmplMsg\n" +"$RuleSet RSYSLOG_DefaultRuleset #End the rule set by switching back to the " +"default rule set\n" +"$InputTCPServerBindRuleset remote1 #Define a new input and bind it to the " +"\"remote1\" rule set\n" +"$InputTCPServerRun 514\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1203 +msgid "Save the changes to the `/etc/rsyslog.conf` file." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1205 +msgid "" +"The `rsyslog` service must be running on both the logging server and the " +"systems attempting to log to it." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1207 +msgid "Use the [command]#systemctl# command to start the `rsyslog` service." +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1211 +#, no-wrap +msgid "~]#{nbsp}pass:quotes[`systemctl start rsyslog`]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1214 +msgid "" +"To ensure the `rsyslog` service starts automatically in future, enter the " +"following command as root:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1218 +#, no-wrap +msgid "~]#{nbsp}pass:quotes[`systemctl enable rsyslog`]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1221 +msgid "" +"Your log server is now configured to receive and store log files from the " +"other systems in your environment." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1223 +#, no-wrap +msgid "Using The New Template Syntax on a Logging Server" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1226 +msgid "" +"Rsyslog 7 has a number of different templates styles. The string template " +"most closely resembles the legacy format. Reproducing the templates from the " +"example above using the string format would look as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1232 +#, no-wrap +msgid "" +"template(name=\"TmplAuthpriv\" type=\"string\"\n" +" " +"string=\"/var/log/remote/auth/%HOSTNAME%/%PROGRAMNAME:::secpath-replace%.log\"\n" +" )\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1236 +#, no-wrap +msgid "" +"template(name=\"TmplMsg\" type=\"string\"\n" +" " +"string=\"/var/log/remote/msg/%HOSTNAME%/%PROGRAMNAME:::secpath-replace%.log\"\n" +" )\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1240 +msgid "These templates can also be written in the list format as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1251 +#, no-wrap +msgid "" +"template(name=\"TmplAuthpriv\" type=\"list\") {\n" +" constant(value=\"/var/log/remote/auth/\")\n" +" property(name=\"hostname\")\n" +" constant(value=\"/\")\n" +" property(name=\"programname\" SecurePath=\"replace\")\n" +" constant(value=\".log\")\n" +" }\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1262 +#, no-wrap +msgid "" +"template(name=\"TmplMsg\" type=\"list\") {\n" +" constant(value=\"/var/log/remote/msg/\")\n" +" property(name=\"hostname\")\n" +" constant(value=\"/\")\n" +" property(name=\"programname\" SecurePath=\"replace\")\n" +" constant(value=\".log\")\n" +" }\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1265 +msgid "" +"This template text format might be easier to read for those new to rsyslog " +"and therefore can be easier to adapt as requirements change." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1267 +msgid "" +"To complete the change to the new syntax, we need to reproduce the module " +"load command, add a rule set, and then bind the rule set to the protocol, " +"port, and ruleset:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1271 +#, no-wrap +msgid "module(load=\"imtcp\")\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1276 +#, no-wrap +msgid "" +"ruleset(name=\"remote1\"){\n" +" authpriv.* action(type=\"omfile\" DynaFile=\"TmplAuthpriv\")\n" +" *.info;mail.none;authpriv.none;cron.none action(type=\"omfile\" " +"DynaFile=\"TmplMsg\")\n" +"}\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1278 +#, no-wrap +msgid "input(type=\"imtcp\" port=\"514\" ruleset=\"remote1\")\n" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1281 +#, no-wrap +msgid "Using Rsyslog Modules" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1284 +msgid "" +"indexterm:[rsyslog,modules] Due to its modular design, " +"[application]*rsyslog* offers a variety of _modules_ which provide " +"additional functionality. Note that modules can be written by third " +"parties. Most modules provide additional inputs (see *Input Modules* below) " +"or outputs (see *Output Modules* below). Other modules provide special " +"functionality specific to each module. The modules may provide additional " +"configuration directives that become available after a module is loaded. To " +"load a module, use the following syntax:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1289 +#, no-wrap +msgid "$ModLoad _MODULE_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1293 +msgid "" +"where [option]`$ModLoad` is the global directive that loads the specified " +"module and _MODULE_ represents your desired module. For example, if you want " +"to load the Text File Input Module ([command]#imfile#) that enables " +"[application]*rsyslog* to convert any standard text files into syslog " +"messages, specify the following line in the `/etc/rsyslog.conf` " +"configuration file:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1298 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1379 +#, no-wrap +msgid "$ModLoad imfile\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1302 +msgid "" +"[application]*rsyslog* offers a number of modules which are split into the " +"following main categories:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1304 +msgid "" +"Input Modules — Input modules gather messages from various sources. The name " +"of an input module always starts with the `im` prefix, such as " +"[command]#imfile# and [command]#imjournal#." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1306 +msgid "" +"Output Modules — Output modules provide a facility to issue message to " +"various targets such as sending across a network, storing in a database, or " +"encrypting. The name of an output module always starts with the `om` prefix, " +"such as [command]#omsnmp#, [command]#omrelp#, and so on." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1308 +msgid "" +"Parser Modules — These modules are useful in creating custom parsing rules " +"or to parse malformed messages. With moderate knowledge of the C programming " +"language, you can create your own message parser. The name of a parser " +"module always starts with the `pm` prefix, such as [command]#pmrfc5424#, " +"[command]#pmrfc3164#, and so on." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1310 +msgid "" +"Message Modification Modules — Message modification modules change content " +"of syslog messages. Names of these modules start with the `mm` " +"prefix. Message Modification Modules such as [command]#mmanon#, " +"[command]#mmnormalize#, or [command]#mmjsonparse# are used for anonymization " +"or normalization of messages." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1312 +msgid "" +"String Generator Modules — String generator modules generate strings based " +"on the message content and strongly cooperate with the template feature " +"provided by [application]*rsyslog*. For more information on templates, see " +"xref:Viewing_and_Managing_Log_Files.adoc#s2-Templates[Templates]. The name " +"of a string generator module always starts with the `sm` prefix, such as " +"[command]#smfile# or [command]#smtradfile#." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1314 +msgid "" +"Library Modules — Library modules provide functionality for other loadable " +"modules. These modules are loaded automatically by [application]*rsyslog* " +"when needed and cannot be configured by the user." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1316 +msgid "" +"A comprehensive list of all available modules and their detailed description " +"can be found at " +"link:++https://www.rsyslog.com/doc/rsyslog_conf_modules.html/++[https://www.rsyslog.com/doc/rsyslog_conf_modules.html]." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1321 +msgid "" +"Note that when [application]*rsyslog* loads any modules, it provides them " +"with access to some of its functions and data. This poses a possible " +"security threat. To minimize security risks, use trustworthy modules only." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1325 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1371 +#, no-wrap +msgid "Importing Text Files" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1328 +msgid "" +"The Text File Input Module, abbreviated as [command]#imfile#, enables " +"[application]*rsyslog* to convert any text file into a stream of syslog " +"messages. You can use [command]#imfile# to import log messages from " +"applications that create their own text file logs. To load " +"[command]#imfile#, add the following into `/etc/rsyslog.conf`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1334 +#, no-wrap +msgid "" +"$ModLoad imfile\n" +"$InputFilePollInterval _int_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1338 +msgid "" +"It is sufficient to load [command]#imfile# once, even when importing " +"multiple files. The *$InputFilePollInterval* global directive specifies how " +"often [application]*rsyslog* checks for changes in connected text files. The " +"default interval is 10 seconds, to change it, replace _int_ with a time " +"interval specified in seconds." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1340 +msgid "" +"To identify the text files to import, use the following syntax in " +"`/etc/rsyslog.conf`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1351 +#, no-wrap +msgid "" +"# File 1\n" +"$InputFileName pass:quotes[_path_to_file_]\n" +"$InputFileTag pass:quotes[_tag:_]\n" +"$InputFileStateFile pass:quotes[_state_file_name_]\n" +"$InputFileSeverity pass:quotes[_severity_]\n" +"$InputFileFacility pass:quotes[_facility_]\n" +"$InputRunFileMonitor\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1355 +#, no-wrap +msgid "" +"# File 2\n" +"$InputFileName pass:quotes[_path_to_file2_]\n" +"...\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1359 +msgid "Four settings are required to specify an input text file:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1361 +msgid "replace _path_to_file_ with a path to the text file." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1363 +msgid "replace _tag:_ with a tag name for this message." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1365 +msgid "" +"replace _state_file_name_ with a unique name for the *state file*. *State " +"files*, which are stored in the rsyslog working directory, keep cursors for " +"the monitored files, marking what partition has already been processed. If " +"you delete them, whole files will be read in again. Make sure that you " +"specify a name that does not already exist." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1367 +msgid "" +"add the *$InputRunFileMonitor* directive that enables the file " +"monitoring. Without this setting, the text file will be ignored." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1369 +msgid "" +"Apart from the required directives, there are several other settings that " +"can be applied on the text input. Set the severity of imported messages by " +"replacing _severity_ with an appropriate keyword. Replace _facility_ with a " +"keyword to define the subsystem that produced the message. The keywords for " +"severity and facility are the same as those used in facility/priority-based " +"filters, see xref:Viewing_and_Managing_Log_Files.adoc#s2-Filters[Filters]." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1375 +msgid "" +"The Apache HTTP server creates log files in text format. To apply the " +"processing capabilities of [application]*rsyslog* to apache error messages, " +"first use the [command]#imfile# module to import the messages. Add the " +"following into `/etc/rsyslog.conf`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1384 +#, no-wrap +msgid "" +"$InputFileName /var/log/httpd/error_log\n" +"$InputFileTag apache-error:\n" +"$InputFileStateFile state-apache-error\n" +"$InputRunFileMonitor\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1390 +#, no-wrap +msgid "Exporting Messages to a Database" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1393 +msgid "" +"Processing of log data can be faster and more convenient when performed in a " +"database rather than with text files. Based on the type of DBMS used, choose " +"from various output modules such as [command]#ommysql#, [command]#ompgsql#, " +"[command]#omoracle#, or [command]#ommongodb#. As an alternative, use the " +"generic [command]#omlibdbi# output module that relies on the `libdbi` " +"library. The [command]#omlibdbi# module supports database systems " +"Firebird/Interbase, MS SQL, Sybase, SQLite, Ingres, Oracle, mSQL, MySQL, and " +"PostgreSQL." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1395 +#, no-wrap +msgid "Exporting Rsyslog Messages to a Database" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1399 +msgid "" +"To store the rsyslog messages in a MySQL database, add the following into " +"`/etc/rsyslog.conf`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1403 +#, no-wrap +msgid "$ModLoad ommysql\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1406 +#, no-wrap +msgid "" +"$ActionOmmysqlServerPort 1234\n" +"*.* " +":ommysql:database-server,database-name,database-userid,database-password\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1410 +msgid "" +"First, the output module is loaded, then the communication port is " +"specified. Additional information, such as name of the server and the " +"database, and authentication data, is specified on the last line of the " +"above example." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1414 +#, no-wrap +msgid "Enabling Encrypted Transport" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1417 +msgid "" +"Confidentiality and integrity in network transmissions can be provided by " +"either the *TLS* or *GSSAPI* encryption protocol." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1419 +#, no-wrap +msgid "" +"*Transport Layer Security* (TLS) is a cryptographic protocol designed to " +"provide communication security over the network. When using TLS, rsyslog " +"messages are encrypted before sending, and mutual authentication exists " +"between the sender and receiver.\n" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1421 +#, no-wrap +msgid "" +"*Generic Security Service API* (GSSAPI) is an application programming " +"interface for programs to access security services. To use it in connection " +"with [application]*rsyslog* you must have a functioning " +"[application]*Kerberos* environment.\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1423 +#, no-wrap +msgid "Using RELP" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1426 +#, no-wrap +msgid "" +"*Reliable Event Logging Protocol* (RELP) is a networking protocol for data " +"logging in computer networks. It is designed to provide reliable delivery of " +"event messages, which makes it useful in environments where message loss is " +"not acceptable.\n" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1428 +#, no-wrap +msgid "Interaction of Rsyslog and Journal" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1431 +msgid "" +"As mentioned above, [application]*Rsyslog* and [application]*Journal*, the " +"two logging applications present on your system, have several distinctive " +"features that make them suitable for specific use cases. In many situations " +"it is useful to combine their capabilities, for example to create structured " +"messages and store them in a file database (see " +"xref:Viewing_and_Managing_Log_Files.adoc#s1-structured_logging_with_rsyslog[Structured " +"Logging with Rsyslog]). A communication interface needed for this " +"cooperation is provided by input and output modules on the side of " +"[application]*Rsyslog* and by the " +"[application]*Journal*pass:attributes[{blank}]'s communication socket." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1433 +msgid "" +"By default, `rsyslogd` uses the `imjournal` module as a default input mode " +"for journal files. With this module, you import not only the messages but " +"also the structured data provided by `journald`. Also, older data can be " +"imported from `journald` (unless forbidden with the " +"[option]`$ImjournalIgnorePreviousMessages` directive). See " +"xref:Viewing_and_Managing_Log_Files.adoc#s2-importing_data_from_journal[Importing " +"Data from Journal] for basic configuration of `imjournal`." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1435 +msgid "" +"As an alternative, configure `rsyslogd` to read from the socket provided by " +"`journal` as an output for syslog-based applications. The path to the socket " +"is `/run/systemd/journal/syslog`. Use this option when you want to maintain " +"plain rsyslog messages. Compared to `imjournal` the socket input currently " +"offers more features, such as ruleset binding or filtering. To import " +"[application]*Journal* data through the socket, use the following " +"configuration in `/etc/rsyslog.conf`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1441 +#, no-wrap +msgid "" +"$ModLoad imuxsock\n" +"$OmitLocalLogging off\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1445 +msgid "" +"The above syntax loads the `imuxsock` module and turns off the " +"[option]`$OmitLocalLogging` directive, which enables the import through the " +"system socket. The path to this socket is specified separately in " +"`/etc/rsyslog.d/listen.conf` as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1450 +#, no-wrap +msgid "$SystemLogSocketName /run/systemd/journal/syslog\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1454 +msgid "" +"You can also output messages from [application]*Rsyslog* to " +"[application]*Journal* with the `omjournal` module. Configure the output in " +"`/etc/rsyslog.conf` as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1458 +#, no-wrap +msgid "$ModLoad omjournal\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1460 +#, no-wrap +msgid "*.* :omjournal:\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1464 +msgid "" +"For instance, the following configuration forwards all received messages on " +"tcp port 10514 to the Journal:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1469 +#, no-wrap +msgid "" +"$ModLoad imtcp\n" +"$ModLoad omjournal\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1472 +#, no-wrap +msgid "" +"$RuleSet remote\n" +"*.* :omjournal:\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1475 +#, no-wrap +msgid "" +"$InputTCPServerBindRuleset remote\n" +"$InputTCPServerRun 10514\n" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1479 +#, no-wrap +msgid "Structured Logging with Rsyslog" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1482 +msgid "" +"On systems that produce large amounts of log data, it can be convenient to " +"maintain log messages in a *structured format*. With structured messages, it " +"is easier to search for particular information, to produce statistics and to " +"cope with changes and inconsistencies in message " +"structure. [application]*Rsyslog* uses the *JSON* (JavaScript Object " +"Notation) format to provide structure for log messages." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1484 +msgid "Compare the following unstructured log message:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1488 +#, no-wrap +msgid "" +"Oct 25 10:20:37 localhost anacron[1395]: Jobs will be executed " +"sequentially\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1491 +msgid "with a structured one:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1495 +#, no-wrap +msgid "" +"{\"timestamp\":\"2013-10-25T10:20:37\", \"host\":\"localhost\", " +"\"program\":\"anacron\", \"pid\":\"1395\", \"msg\":\"Jobs will be executed " +"sequentially\"}\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1498 +msgid "" +"Searching structured data with use of key-value pairs is faster and more " +"precise than searching text files with regular expressions. The structure " +"also lets you to search for the same entry in messages produced by various " +"applications. Also, JSON files can be stored in a document database such as " +"MongoDB, which provides additional performance and analysis capabilities. On " +"the other hand, a structured message requires more disk space than the " +"unstructured one." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1500 +msgid "" +"In [application]*rsyslog*, log messages with meta data are pulled from " +"[application]*Journal* with use of the `imjournal` module. With the " +"`mmjsonparse` module, you can parse data imported from " +"[application]*Journal* and from other sources and process them further, for " +"example as a database output. For parsing to be successful, `mmjsonparse` " +"requires input messages to be structured in a way that is defined by the " +"*Lumberjack* project." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1502 +msgid "" +"The *Lumberjack* project aims to add structured logging to " +"[application]*rsyslog* in a backward-compatible way. To identify a " +"structured message, *Lumberjack* specifies the *@cee:* string that prepends " +"the actual JSON structure. Also, *Lumberjack* defines the list of standard " +"field names that should be used for entities in the JSON string. For more " +"information on *Lumberjack*, see " +"xref:Viewing_and_Managing_Log_Files.adoc#brid-Log_Files-Resources-Online[Online " +"Documentation]." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1504 +msgid "The following is an example of a lumberjack-formatted message:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1509 +#, no-wrap +msgid "" +" @cee: {\"pid\":17055, \"uid\":1000, \"gid\":1000, " +"\"appname\":\"logger\", \"msg\":\"Message text.\"}\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1513 +msgid "" +"To build this structure inside [application]*Rsyslog*, a template is used, " +"see " +"xref:Viewing_and_Managing_Log_Files.adoc#s2-filtering_structured_messages[Filtering " +"Structured Messages]. Applications and servers can employ the `libumberlog` " +"library to generate messages in the lumberjack-compliant form. For more " +"information on `libumberlog`, see " +"xref:Viewing_and_Managing_Log_Files.adoc#brid-Log_Files-Resources-Online[Online " +"Documentation]." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1515 +#, no-wrap +msgid "Importing Data from Journal" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1518 +msgid "" +"The [command]#imjournal# module is " +"[application]*Rsyslog*pass:attributes[{blank}]'s input module to natively " +"read the journal files (see " +"xref:Viewing_and_Managing_Log_Files.adoc#s1-interaction_of_rsyslog_and_journal[Interaction " +"of Rsyslog and Journal]). Journal messages are then logged in text format as " +"other rsyslog messages. However, with further processing, it is possible to " +"translate meta data provided by [application]*Journal* into a structured " +"message." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1520 +msgid "" +"To import data from [application]*Journal* to [application]*Rsyslog*, use " +"the following configuration in `/etc/rsyslog.conf`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1525 +#, no-wrap +msgid "$ModLoad imjournal\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1531 +#, no-wrap +msgid "" +"$imjournalPersistStateInterval pass:quotes[_number_of_messages_]\n" +"$imjournalStateFile pass:quotes[_path_]\n" +"$imjournalRatelimitInterval pass:quotes[_seconds_]\n" +"$imjournalRatelimitBurst pass:quotes[_burst_number_]\n" +"$ImjournalIgnorePreviousMessages pass:quotes[_off/on_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1535 +msgid "" +"With _number_of_messages_, you can specify how often the journal data must " +"be saved. This will happen each time the specified number of messages is " +"reached." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1537 +msgid "" +"Replace _path_ with a path to the state file. This file tracks the journal " +"entry that was the last one processed." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1539 +msgid "" +"With _seconds_, you set the length of the rate limit interval. The number of " +"messages processed during this interval can not exceed the value specified " +"in _burst_number_. The default setting is 20,000 messages per 600 " +"seconds. Rsyslog discards messages that come after the maximum burst within " +"the time frame specified." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1541 +msgid "" +"With [option]`$ImjournalIgnorePreviousMessages` you can ignore messages that " +"are currently in Journal and import only new messages, which is used when " +"there is no state file specified. The default setting is `off`. Please note " +"that if this setting is off and there is no state file, all messages in the " +"Journal are processed, even if they were already processed in a previous " +"rsyslog session." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1546 +msgid "" +"You can use `imjournal` simultaneously with `imuxsock` module that is the " +"traditional system log input. However, to avoid message duplication, you " +"must prevent `imuxsock` from reading the Journal's system socket. To do so, " +"use the [option]`$OmitLocalLogging` directive:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1552 +#, no-wrap +msgid "" +"$ModLoad imuxsock\n" +"$ModLoad imjournal\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1555 +#, no-wrap +msgid "" +"$OmitLocalLogging on\n" +"$AddUnixListenSocket /run/systemd/journal/syslog\n" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1561 +msgid "" +"You can translate all data and meta data stored by [application]*Journal* " +"into structured messages. Some of these meta data entries are listed in " +"xref:Viewing_and_Managing_Log_Files.adoc#ex-verbose_journalctl_output[Verbose " +"journalctl Output], for a complete list of journal fields see the " +"`systemd.journal-fields(7)` manual page. For example, it is possible to " +"focus on *kernel journal fields*, that are used by messages originating in " +"the kernel." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1563 +#, no-wrap +msgid "Filtering Structured Messages" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1566 +msgid "" +"To create a lumberjack-formatted message that is required by " +"[application]*rsyslog*pass:attributes[{blank}]'s parsing module, use the " +"following template:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1571 +#, no-wrap +msgid "" +"template(name=\"CEETemplate\" type=\"string\" string=\"%TIMESTAMP% " +"%HOSTNAME% %syslogtag% @cee: %$!all-json%\\n\")\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1575 +msgid "" +"This template prepends the `@cee:` string to the JSON string and can be " +"applied, for example, when creating an output file with `omfile` module. To " +"access JSON field names, use the *$!* prefix. For example, the following " +"filter condition searches for messages with specific *hostname* and *UID*:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1580 +#, no-wrap +msgid "" +"($!hostname == " +"\"pass:attributes[{blank}]_hostname_pass:attributes[{blank}]\" && $!UID== " +"\"pass:attributes[{blank}]_UID_pass:attributes[{blank}]\")\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1584 +#, no-wrap +msgid "Parsing JSON" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1587 +msgid "The `mmjsonparse` module is used for parsing structured messages." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1589 +msgid "" +"These messages can come from [application]*Journal* or from other input " +"sources, and must be formatted in a way defined by the *Lumberjack* " +"project. These messages are identified by the presence of the *@cee:* " +"string. Then, `mmjsonparse` checks if the JSON structure is valid and then " +"the message is parsed." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1591 +msgid "" +"To parse lumberjack-formatted JSON messages with `mmjsonparse`, use the " +"following configuration in the `/etc/rsyslog.conf`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1595 +#, no-wrap +msgid "$ModLoad mmjsonparse\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1597 +#, no-wrap +msgid "*.* :mmjsonparse:\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1601 +msgid "" +"In this example, the `mmjsonparse` module is loaded on the first line, then " +"all messages are forwarded to it. Currently, there are no configuration " +"parameters available for `mmjsonparse`." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1603 +#, no-wrap +msgid "Storing Messages in the MongoDB" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1606 +msgid "" +"[application]*Rsyslog* supports storing JSON logs in the MongoDB document " +"database through the *ommongodb* output module." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1608 +msgid "" +"To forward log messages into MongoDB, use the following syntax in the " +"`/etc/rsyslog.conf` (configuration parameters for *ommongodb* are available " +"only in the new configuration format; see " +"xref:Viewing_and_Managing_Log_Files.adoc#sec-using_the_new_configuration_format[Using " +"the New Configuration Format]):" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1613 +#, no-wrap +msgid "$ModLoad ommongodb\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1615 +#, no-wrap +msgid "" +"*.* action(type=\"ommongodb\" server=\"pass:quotes[_DB_server_]\" " +"serverport=\"pass:quotes[_port_]\" db=\"pass:quotes[_DB_name_]\" " +"collection=\"pass:quotes[_collection_name_]\" uid=\"pass:quotes[_UID_]\" " +"pwd=\"pass:quotes[_password_]\")\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1619 +msgid "" +"Replace _DB_server_ with the name or address of the MongoDB server. Specify " +"_port_ to select a non-standard port from the MongoDB server. The default " +"_port_ value is `0` and usually there is no need to change this parameter." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1621 +msgid "" +"With _DB_name_, you identify to which database on the MongoDB server you " +"want to direct the output. Replace _collection_name_ with the name of a " +"collection in this database. In MongoDB, collection is a group of documents, " +"the equivalent of an RDBMS table." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1623 +msgid "You can set your login details by replacing _UID_ and _password_." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1625 +msgid "" +"You can shape the form of the final database output with use of " +"templates. By default, [application]*rsyslog* uses a template based on " +"standard [application]*lumberjack* field names." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1627 +#, no-wrap +msgid "Debugging Rsyslog" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1630 +msgid "" +"indexterm:[rsyslog,debugging] To run `rsyslogd` in debugging mode, use the " +"following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1634 +#, no-wrap +msgid "`rsyslogd` [option]`-dn`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1637 +msgid "" +"With this command, `rsyslogd` produces debugging information and prints it " +"to the standard output. The [option]`-n` stands for \"`no fork`\". You can " +"modify debugging with environmental variables, for example, you can store " +"the debug output in a log file. Before starting `rsyslogd`, type the " +"following on the command line:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1643 +#, no-wrap +msgid "" +"export RSYSLOG_DEBUGLOG=\"pass:quotes[_path_]\"\n" +"export RSYSLOG_DEBUG=\"Debug\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1647 +msgid "" +"Replace _path_ with a desired location for the file where the debugging " +"information will be logged. For a complete list of options available for the " +"RSYSLOG_DEBUG variable, see the related section in the `rsyslogd(8)` manual " +"page." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1649 +msgid "To check if syntax used in the `/etc/rsyslog.conf` file is valid use:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1653 +#, no-wrap +msgid "`rsyslogd` [option]`-N` `1`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1656 +msgid "" +"Where `1` represents level of verbosity of the output message. This is a " +"forward compatibility option because currently, only one level is " +"provided. However, you must add this argument to run the validation." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1658 +#, no-wrap +msgid "Troubleshooting Logging to a Server" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1661 +msgid "" +"Ensure the time is correctly set on the systems generating the log messages " +"as well as on any logging servers. See " +"xref:basic-system-configuration/Configuring_the_Date_and_Time.adoc#ch-Configuring_the_Date_and_Time[Configuring " +"the Date and Time] for information on checking and setting the time. See " +"xref:servers/Configuring_NTP_Using_ntpd.adoc#ch-Configuring_NTP_Using_ntpd[Configuring " +"NTP Using ntpd] and " +"xref:servers/Configuring_NTP_Using_the_chrony_Suite.adoc#ch-Configuring_NTP_Using_the_chrony_Suite[Configuring " +"NTP Using the chrony Suite] for information on using `NTP` to keep the " +"system clock accurately set." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1663 +msgid "" +"On a logging server, check that the firewall has the appropriate ports open " +"to allow ingress of either `UDP` or `TCP`, depending on what traffic and " +"port the sending systems are configured to use. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1667 +#, no-wrap +msgid "~]#{nbsp}firewall-cmd --zone=public --list-ports\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1670 +msgid "" +"For more information on opening and closing ports in `firewalld`, see the " +"link:++https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Security_Guide/++[Red{nbsp}Hat " +"Enterprise{nbsp}Linux{nbsp}7 Security Guide]. Review the configuration of " +"the logging server to ensure it is listening on the same port the sending " +"systems are configured to send on, and all are set to use the same protocol." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1672 +msgid "" +"Use the [command]#logger# command to generate test log messages. For " +"example:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1677 +#, no-wrap +msgid "" +"~]$ [command]#logger -p authpriv.info \"Test Secret\"#\n" +"~]$ [command]#logger -p auth.info \"Test Info\"#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1680 +msgid "" +"See the `logger(1)` manual page for more information on the " +"[command]#logger# command." +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1682 +#, no-wrap +msgid "Using the Journal" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1685 +msgid "" +"The Journal is a component of [application]*systemd* that is responsible for " +"viewing and management of log files. It can be used in parallel, or in place " +"of a traditional syslog daemon, such as `rsyslogd`. The Journal was " +"developed to address problems connected with traditional logging. It is " +"closely integrated with the rest of the system, supports various logging " +"technologies and access management for the log files." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1687 +msgid "" +"Logging data is collected, stored, and processed by the Journal's `journald` " +"service. It creates and maintains binary files called *journals* based on " +"logging information that is received from the kernel, from user processes, " +"from standard output, and standard error output of system services or via " +"its native API. These journals are structured and indexed, which provides " +"relatively fast seek times. Journal entries can carry a unique " +"identifier. The `journald` service collects numerous meta data fields for " +"each log message. The actual journal files are secured, and therefore cannot " +"be manually edited." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1689 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2000 +#, no-wrap +msgid "Viewing Log Files" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1692 +msgid "" +"To access the journal logs, use the [application]*journalctl* tool. For a " +"basic view of the logs type as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1696 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1899 +#, no-wrap +msgid "[command]#journalctl#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1699 +msgid "" +"An output of this command is a list of all log files generated on the system " +"including messages generated by system components and by users. The " +"structure of this output is similar to one used in `/var/log/messages/` but " +"with certain improvements:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1701 +msgid "" +"the priority of entries is marked visually. Lines of error priority and " +"higher are highlighted with red color and a bold font is used for lines with " +"notice and warning priority" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1703 +msgid "the time stamps are converted for the local time zone of your system" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1705 +msgid "all logged data is shown, including rotated logs" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1707 +msgid "the beginning of a boot is tagged with a special line" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1709 +#, no-wrap +msgid "Example Output of journalctl" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1713 +msgid "" +"The following is an example output provided by the [application]*journalctl* " +"tool. When called without parameters, the listed entries begin with a time " +"stamp, then the host name and application that performed the operation is " +"mentioned followed by the actual message. This example shows the first three " +"entries in the journal log:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1721 +#, no-wrap +msgid "" +"# journalctl\n" +"-- Logs begin at Thu 2013-08-01 15:42:12 CEST, end at Thu 2013-08-01 " +"15:48:48 CEST. --\n" +"Aug 01 15:42:12 localhost systemd-journal[54]: Allowing runtime journal " +"files to grow to 49.7M.\n" +"Aug 01 15:42:12 localhost kernel: Initializing cgroup subsys cpuset\n" +"Aug 01 15:42:12 localhost kernel: Initializing cgroup subsys cpu\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1723 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1779 +#, no-wrap +msgid "[...]\n" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1729 +msgid "" +"In many cases, only the latest entries in the journal log are relevant. The " +"simplest way to reduce [command]#journalctl# output is to use the " +"[option]`-n` option that lists only the specified number of most recent log " +"entries:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1733 +#, no-wrap +msgid "[command]#journalctl# [option]`-n` _Number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1736 +msgid "" +"Replace _Number_ with the number of lines to be shown. When no number is " +"specified, [command]#journalctl# displays the ten most recent entries." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1738 +msgid "" +"The [command]#journalctl# command allows controlling the form of the output " +"with the following syntax:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1742 +#, no-wrap +msgid "[command]#journalctl# [option]`-o` _form_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1745 +msgid "" +"Replace _form_ with a keyword specifying a desired form of output. There are " +"several options, such as [option]`verbose`, which returns full-structured " +"entry items with all fields, [option]`export`, which creates a binary stream " +"suitable for backups and network transfer, and [option]`json`, which formats " +"entries as JSON data structures. For the full list of keywords, see the " +"`journalctl(1)` manual page." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1747 +#, no-wrap +msgid "Verbose journalctl Output" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1751 +msgid "To view full meta data about all entries, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1756 +#, no-wrap +msgid "" +"# journalctl -o verbose\n" +"[...]\n" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1777 +#, no-wrap +msgid "" +"Fri 2013-08-02 14:41:22 CEST " +"[s=e1021ca1b81e4fc688fad6a3ea21d35b;i=55c;b=78c81449c920439da57da7bd5c56a770;m=27cc\n" +" _BOOT_ID=78c81449c920439da57da7bd5c56a770\n" +" PRIORITY=5\n" +" SYSLOG_FACILITY=3\n" +" _TRANSPORT=syslog\n" +" _MACHINE_ID=69d27b356a94476da859461d3a3bc6fd\n" +" _HOSTNAME=localhost.localdomain\n" +" _PID=562\n" +" _COMM=dbus-daemon\n" +" _EXE=/usr/bin/dbus-daemon\n" +" _CMDLINE=/bin/dbus-daemon --system --address=systemd: --nofork " +"--nopidfile --systemd-activation\n" +" _SYSTEMD_CGROUP=/system/dbus.service\n" +" _SYSTEMD_UNIT=dbus.service\n" +" SYSLOG_IDENTIFIER=dbus\n" +" SYSLOG_PID=562\n" +" _UID=81\n" +" _GID=81\n" +" _SELINUX_CONTEXT=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023\n" +" MESSAGE=[system] Successfully activated service " +"'net.reactivated.Fprint'\n" +" _SOURCE_REALTIME_TIMESTAMP=1375447282839181\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1783 +msgid "" +"This example lists fields that identify a single log entry. These meta data " +"can be used for message filtering as shown in " +"xref:Viewing_and_Managing_Log_Files.adoc#advanced_filtering[Advanced " +"Filtering]. For a complete description of all possible fields see the " +"`systemd.journal-fields(7)` manual page." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1787 +#, no-wrap +msgid "Access Control" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1790 +msgid "" +"By default, [application]*Journal* users without `root` privileges can only " +"see log files generated by them. The system administrator can add selected " +"users to the *adm* group, which grants them access to complete log files. To " +"do so, type as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1794 +#, no-wrap +msgid "[command]#usermod# [option]`-a` [option]`-G` *adm* _username_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1797 +msgid "" +"Here, replace _username_ with a name of the user to be added to the *adm* " +"group. This user then receives the same output of the [command]#journalctl# " +"command as the root user. Note that access control only works when " +"persistent storage is enabled for [application]*Journal*." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1799 +#, no-wrap +msgid "Using The Live View" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1802 +msgid "" +"When called without parameters, [command]#journalctl# shows the full list of " +"entries, starting with the oldest entry collected. With the live view, you " +"can supervise the log messages in real time as new entries are continuously " +"printed as they appear. To start [application]*journalctl* in live view " +"mode, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1806 +#, no-wrap +msgid "[command]#journalctl# [option]`-f`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1809 +msgid "" +"This command returns a list of the ten most current log lines. The " +"[application]*journalctl* utility then stays running and waits for new " +"changes to show them immediately." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1811 +#, no-wrap +msgid "Filtering Messages" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1814 +msgid "" +"The output of the [command]#journalctl# command executed without parameters " +"is often extensive, therefore you can use various filtering methods to " +"extract information to meet your needs." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1815 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1826 +#, no-wrap +msgid "Filtering by Priority" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1817 +msgid "" +"Log messages are often used to track erroneous behavior on the system. To " +"view only entries with a selected or higher priority, use the following " +"syntax:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1821 +#, no-wrap +msgid "[command]#journalctl# [option]`-p` _priority_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1824 +msgid "" +"Here, replace _priority_ with one of the following keywords (or with a " +"number): [command]#debug# (7), [command]#info# (6), [command]#notice# (5), " +"[command]#warning# (4), [command]#err# (3), [command]#crit# (2), " +"[command]#alert# (1), and [command]#emerg# (0)." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1830 +msgid "To view only entries with *error* or higher priority, use:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1834 +#, no-wrap +msgid "[command]#journalctl# [option]`-p err`\n" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1838 +#, no-wrap +msgid "Filtering by Time" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1840 +msgid "To view log entries only from the current boot, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1844 +#, no-wrap +msgid "[command]#journalctl# [option]`-b`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1847 +msgid "" +"If you reboot your system just occasionally, the [option]`-b` will not " +"significantly reduce the output of [command]#journalctl#. In such cases, " +"time-based filtering is more helpful:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1851 +#, no-wrap +msgid "" +"[command]#journalctl# " +"[option]`--since`pass:attributes[{blank}]=pass:attributes[{blank}]_value_ " +"[option]`--until`pass:attributes[{blank}]=pass:attributes[{blank}]_value_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1854 +msgid "" +"With [option]`--since` and [option]`--until`, you can view only log messages " +"created within a specified time range. You can pass _values_ to these " +"options in form of date or time or both as shown in the following example." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1856 +#, no-wrap +msgid "Filtering by Time and Priority" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1860 +msgid "" +"Filtering options can be combined to reduce the set of results according to " +"specific requests. For example, to view the *warning* or higher priority " +"messages from a certain point in time, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1864 +#, no-wrap +msgid "" +"[command]#journalctl# [option]`-p warning` [option]`--since=\"2013-3-16 " +"23:59:59\"`\n" +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1869 +#, no-wrap +msgid "Advanced Filtering" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1871 +msgid "" +"xref:Viewing_and_Managing_Log_Files.adoc#ex-verbose_journalctl_output[Verbose " +"journalctl Output] lists a set of fields that specify a log entry and can " +"all be used for filtering. For a complete description of meta data that " +"`systemd` can store, see the `systemd.journal-fields(7)` manual page. This " +"meta data is collected for each log message, without user " +"intervention. Values are usually text-based, but can take binary and large " +"values; fields can have multiple values assigned though it is not very " +"common." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1873 +msgid "" +"To view a list of unique values that occur in a specified field, use the " +"following syntax:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1877 +#, no-wrap +msgid "[command]#journalctl# [option]`-F` _fieldname_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1880 +msgid "Replace _fieldname_ with a name of a field you are interested in." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1882 +msgid "" +"To show only log entries that fit a specific condition, use the following " +"syntax:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1886 +#, no-wrap +msgid "" +"[command]#journalctl# " +"_fieldname_pass:attributes[{blank}]=pass:attributes[{blank}]_value_\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1889 +msgid "" +"Replace _fieldname_ with a name of a field and _value_ with a specific value " +"contained in that field. As a result, only lines that match this condition " +"are returned." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1890 +#, no-wrap +msgid "kbd:[Tab] Completion on Field Names" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1895 +msgid "" +"As the number of meta data fields stored by `systemd` is quite large, it is " +"easy to forget the exact name of the field of interest. When unsure, type:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1902 +msgid "" +"and press the kbd:[Tab] key two times. This shows a list of available field " +"names. kbd:[Tab] completion based on context works on field names, so you " +"can type a distinctive set of letters from a field name and then press " +"kbd:[Tab] to complete the name automatically. Similarly, you can list unique " +"values from a field. Type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1906 +#, no-wrap +msgid "[command]#journalctl# _fieldname_pass:attributes[{blank}]=\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1909 +msgid "" +"and press kbd:[Tab] two times. This serves as an alternative to " +"[command]#journalctl# [option]`-F` _fieldname_." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1913 +msgid "You can specify multiple values for one field:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1917 +#, no-wrap +msgid "" +"[command]#journalctl# " +"_fieldname_pass:attributes[{blank}]=pass:attributes[{blank}]_value1_ " +"_fieldname_pass:attributes[{blank}]=pass:attributes[{blank}]_value2_ ...\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1920 +msgid "" +"Specifying two matches for the same field results in a logical `OR` " +"combination of the matches. Entries matching _value1_ or _value2_ are " +"displayed." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1922 +msgid "" +"Also, you can specify multiple field-value pairs to further reduce the " +"output set:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1926 +#, no-wrap +msgid "" +"[command]#journalctl# " +"_fieldname1_pass:attributes[{blank}]=pass:attributes[{blank}]_value_ " +"_fieldname2_pass:attributes[{blank}]=pass:attributes[{blank}]_value_ ...\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1929 +msgid "" +"If two matches for different field names are specified, they will be " +"combined with a logical `AND`. Entries have to match both conditions to be " +"shown." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1931 +msgid "" +"With use of the *+* symbol, you can set a logical `OR` combination of " +"matches for multiple fields:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1935 +#, no-wrap +msgid "" +"journalctl pass:quotes[_fieldname1_]=pass:quotes[_value_] + " +"pass:quotes[_fieldname2_]=pass:quotes[_value_] ...\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1938 +msgid "" +"This command returns entries that match at least one of the conditions, not " +"only those that match both of them." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1940 +#, no-wrap +msgid "Advanced filtering" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1944 +msgid "" +"To display entries created by `avahi-daemon.service` or `crond.service` " +"under user with UID 70, use the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1948 +#, no-wrap +msgid "" +"journalctl pass:quotes[`_UID=70`] " +"pass:quotes[`_SYSTEMD_UNIT=avahi-daemon.service`] " +"pass:quotes[`_SYSTEMD_UNIT=crond.service`]\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1951 +msgid "" +"Since there are two values set for the `_SYSTEMD_UNIT` field, both results " +"will be displayed, but only when matching the `_UID=70` condition. This can " +"be expressed simply as: (UID=70 and (avahi or cron))." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1955 +msgid "" +"You can apply the aforementioned filtering also in the live-view mode to " +"keep track of the latest changes in the selected group of log entries:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1959 +#, no-wrap +msgid "" +"[command]#journalctl# [option]`-f` " +"_fieldname_pass:attributes[{blank}]=pass:attributes[{blank}]_value_ ...\n" +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1962 +#, no-wrap +msgid "Enabling Persistent Storage" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1965 +msgid "" +"By default, [application]*Journal* stores log files only in memory or a " +"small ring-buffer in the `/run/log/journal/` directory. This is sufficient " +"to show recent log history with [command]#journalctl#. This directory is " +"volatile, log data is not saved permanently. With the default configuration, " +"syslog reads the journal logs and stores them in the `/var/log/` " +"directory. With persistent logging enabled, journal files are stored in " +"`/var/log/journal` which means they persist after reboot. Journal can then " +"replace [application]*rsyslog* for some users (but see the chapter " +"introduction)." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1967 +msgid "Enabled persistent storage has the following advantages" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1969 +msgid "Richer data is recorded for troubleshooting in a longer period of time" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1971 +msgid "For immediate troubleshooting, richer data is available after a reboot" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1973 +msgid "Server console currently reads data from journal, not log files" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1975 +msgid "Persistent storage has also certain disadvantages:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1977 +msgid "" +"Even with persistent storage the amount of data stored depends on free " +"memory, there is no guarantee to cover a specific time span" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1979 +msgid "More disk space is needed for logs" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1981 +msgid "" +"To enable persistent storage for Journal, create the journal directory " +"manually as shown in the following example. As `root` type:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1985 +#, no-wrap +msgid "[command]#mkdir# [option]`-p` `/var/log/journal`\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1988 +msgid "Then, restart `journald` to apply the change:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1992 +#, no-wrap +msgid "[command]#systemctl# [option]`restart` `systemd-journald`\n" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1995 +#, no-wrap +msgid "Managing Log Files in a Graphical Environment" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:1998 +msgid "" +"As an alternative to the aforementioned command-line utilities, Red{nbsp}Hat " +"Enterprise{nbsp}Linux{nbsp}7 provides an accessible GUI for managing log " +"messages." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2005 +msgid "" +"indexterm:[log files,viewing] Most log files are stored in plain text " +"format. You can view them with any text editor such as [command]#Vi# or " +"[application]*Emacs*. Some log files are readable by all users on the " +"system; however, root privileges are required to read most log files. " +"indexterm:[gnome-system-log,System Log] To view system log files in an " +"interactive, real-time application, use the [application]*System Log*." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2006 +#, no-wrap +msgid "Installing the gnome-system-log package" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2011 +msgid "" +"In order to use the [application]*System Log*, first ensure the " +"[package]*gnome-system-log* package is installed on your system by running, " +"as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2015 +#, no-wrap +msgid "~]#{nbsp}dnf install gnome-system-log\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2019 +msgid "" +"For more information on installing packages with DNF, see " +"xref:package-management/DNF.adoc#sec-Installing[Installing Packages]." +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2023 +msgid "" +"After you have installed the [package]*gnome-system-log* package, open the " +"[application]*System Log* by clicking " +"menu:Applications[pass:attributes[{blank}]`System Tools` > `System " +"Log`pass:attributes[{blank}]], or type the following command at a shell " +"prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2027 +#, no-wrap +msgid "~]${nbsp}pass:attributes[{blank}][command]#gnome-system-log#\n" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2032 +msgid "" +"The application only displays log files that exist; thus, the list might " +"differ from the one shown in " +"xref:Viewing_and_Managing_Log_Files.adoc#fig-redhat-logviewer[System Log]. " +"indexterm:[System Log,searching]indexterm:[System Log,filtering]" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2034 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2036 +#, no-wrap +msgid "System Log" +msgstr "" + +#. type: Target for macro image +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2036 +#, no-wrap +msgid "redhat-logviewer.png" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2039 +msgid "" +"indexterm:[System Log,refresh rate] The [application]*System Log* " +"application lets you filter any existing log file. Click on the button " +"marked with the gear symbol to view the menu, select " +"menu:[pass:attributes[{blank}]`Filters` > > `Manage " +"Filters`pass:attributes[{blank}]] to define or edit the desired filter." +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2041 +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2043 +#, no-wrap +msgid "System Log - Filters" +msgstr "" + +#. type: Target for macro image +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2043 +#, no-wrap +msgid "redhat-filters.png" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2046 +msgid "" +"Adding or editing a filter lets you define its parameters as is shown in " +"xref:Viewing_and_Managing_Log_Files.adoc#fig-redhat-filter-sample[System Log " +"- defining a filter]." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2048 +#, no-wrap +msgid "System Log - defining a filter" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2050 +#, no-wrap +msgid "System Log - Defining a Filter" +msgstr "" + +#. type: Target for macro image +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2050 +#, no-wrap +msgid "redhat-filter-sample.png" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2053 +msgid "When defining a filter, the following parameters can be edited:" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2055 +msgid "`Name` — Specifies the name of the filter." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2057 +msgid "" +"`Regular Expression` — Specifies the regular expression that will be applied " +"to the log file and will attempt to match any possible strings of text in " +"it." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2059 +msgid "`Effect`" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2061 +msgid "" +"`Highlight` — If checked, the found results will be highlighted with the " +"selected color. You may select whether to highlight the background or the " +"foreground of the text." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2063 +msgid "" +"`Hide` — If checked, the found results will be hidden from the log file you " +"are viewing." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2065 +msgid "" +"When you have at least one filter defined, it can be selected from the " +"`Filters` menu and it will automatically search for the strings you have " +"defined in the filter and highlight or hide every successful match in the " +"log file you are currently viewing." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2067 +#, no-wrap +msgid "System Log - enabling a filter" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2069 +#, no-wrap +msgid "System Log - Enabling a Filter" +msgstr "" + +#. type: Target for macro image +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2069 +#, no-wrap +msgid "redhat-filter-enable.png" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2072 +msgid "" +"When you select the `Show matches only` option, only the matched strings " +"will be shown in the log file you are currently viewing." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2074 +#, no-wrap +msgid "Adding a Log File" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2081 +msgid "" +"To add a log file you want to view in the list, select menu:File[> `Open` " +">]. This will display the `Open Log` window where you can select the " +"directory and file name of the log file you want to view. " +"xref:Viewing_and_Managing_Log_Files.adoc#fig-redhat-logviewer-add[System Log " +"- adding a log file] illustrates the Open Log window." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2083 +#, no-wrap +msgid "System Log - adding a log file" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2085 +#, no-wrap +msgid "System Log - Adding a Log File" +msgstr "" + +#. type: Target for macro image +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2085 +#, no-wrap +msgid "redhat-logviewer-add.png" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2088 +msgid "" +"Click on the btn:[Open] button to open the file. The file is immediately " +"added to the viewing list where you can select it and view its contents." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2089 +#, no-wrap +msgid "Reading zipped log files" +msgstr "" + +#. type: delimited block = +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2094 +msgid "" +"The [application]*System Log* also allows you to open log files zipped in " +"the `.gz` format." +msgstr "" + +#. type: Title === +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2098 +#, no-wrap +msgid "Monitoring Log Files" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2101 +msgid "" +"indexterm:[log files,monitoring]indexterm:[System Log,monitoring] " +"[application]*System Log* monitors all opened logs by default. If a new line " +"is added to a monitored log file, the log name appears in bold in the log " +"list. If the log file is selected or displayed, the new lines appear in bold " +"at the bottom of the log " +"file. " +"xref:Viewing_and_Managing_Log_Files.adoc#fig-redhat-logviewer-monitoring[System " +"Log - new log alert] illustrates a new alert in the `cron` log file and in " +"the `messages` log file. Clicking on the `messages` log file displays the " +"logs in the file with the new lines in bold." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2103 +#, no-wrap +msgid "System Log - new log alert" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2105 +#, no-wrap +msgid "System Log - New Log Alert" +msgstr "" + +#. type: Target for macro image +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2105 +#, no-wrap +msgid "redhat-logviewer-monitoring.png" +msgstr "" + +#. type: Title == +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2108 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2111 +msgid "" +"For more information on how to configure the `rsyslog` daemon and how to " +"locate, view, and monitor log files, see the resources listed below." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2112 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2115 +msgid "" +"`rsyslogd`(8) — The manual page for the `rsyslogd` daemon documents its " +"usage." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2117 +msgid "" +"`rsyslog.conf`(5) — The manual page named `rsyslog.conf` documents available " +"configuration options." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2119 +msgid "" +"`logrotate`(8) — The manual page for the [application]*logrotate* utility " +"explains in greater detail how to configure and use it." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2121 +msgid "" +"`journalctl`(1) — The manual page for the [command]#journalctl# daemon " +"documents its usage." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2123 +msgid "" +"`journald.conf`(5) — This manual page documents available configuration " +"options." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2125 +msgid "" +"`systemd.journal-fields`(7) — This manual page lists special " +"[application]*Journal* fields." +msgstr "" + +#. type: Block title +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2127 +#, no-wrap +msgid "Online Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2130 +msgid "" +"link:++https://www.rsyslog.com/++[rsyslog Home Page] — The " +"[application]*rsyslog* home page offers a thorough technical breakdown of " +"its features, documentation, configuration examples, and video tutorials." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2132 +msgid "" +"link:++https://www.rsyslog.com/doc/rainerscript.html++[pass:attributes[{blank}]*RainerScript* " +"documentation on the rsyslog Home Page] — Commented summary of data types, " +"expressions, and functions available in *RainerScript*." +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/Viewing_and_Managing_Log_Files.adoc:2133 +msgid "" +"link:++https://www.rsyslog.com/doc/queues.html++[Description of *queues* on " +"the rsyslog Home Page] — General information on various types of message " +"queues and their usage." +msgstr "" diff --git a/pot/rawhide/pages/monitoring-and-automation/intro-monitoring-and-automation.pot b/pot/rawhide/pages/monitoring-and-automation/intro-monitoring-and-automation.pot new file mode 100644 index 00000000000..ba1303ae45c --- /dev/null +++ b/pot/rawhide/pages/monitoring-and-automation/intro-monitoring-and-automation.pot @@ -0,0 +1,30 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/monitoring-and-automation/intro-monitoring-and-automation.adoc:1 +#, no-wrap +msgid "Monitoring and Automation" +msgstr "" + +#. type: Plain text +#: ./pages/monitoring-and-automation/intro-monitoring-and-automation.adoc:3 +msgid "" +"This part describes various tools that allow system administrators to " +"monitor system performance, automate system tasks, and report bugs." +msgstr "" diff --git a/pot/rawhide/pages/package-management/DNF.pot b/pot/rawhide/pages/package-management/DNF.pot new file mode 100644 index 00000000000..1826686f358 --- /dev/null +++ b/pot/rawhide/pages/package-management/DNF.pot @@ -0,0 +1,2229 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/package-management/DNF.adoc:5 +#, no-wrap +msgid "DNF" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:8 +msgid "" +"[application]*DNF* is the {OSORG} package manager that is able to query for " +"information about packages, fetch packages from repositories, install and " +"uninstall packages using automatic dependency resolution, and update an " +"entire system to the latest available packages. DNF performs automatic " +"dependency resolution on packages you are updating, installing or removing, " +"and thus is able to automatically determine, fetch and install all available " +"dependent packages. DNF can be configured with new, additional repositories, " +"or _package sources_, and also provides many plug-ins which enhance and " +"extend its capabilities. DNF is able to perform many of the same tasks that " +"[application]*RPM* can; additionally, many of the command line options are " +"similar. DNF enables easy and simple package management on a single machine " +"or on groups of them." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:10 +#, no-wrap +msgid "Secure package management with GPG-signed packages" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:15 +msgid "" +"DNF provides secure package management by enabling GPG (Gnu Privacy Guard; " +"also known as GnuPG) signature verification on GPG-signed packages to be " +"turned on for all package repositories (package sources), or for individual " +"repositories. When signature verification is enabled, DNF will refuse to " +"install any packages not GPG-signed with the correct key for that " +"repository. This means that you can trust that the [application]*RPM* " +"packages you download and install on your system are from a trusted source, " +"such as {OSORG}, and were not modified during transfer. See " +"xref:DNF.adoc#sec-Configuring_DNF_and_DNF_Repositories[Configuring DNF and " +"DNF Repositories] for details on enabling signature-checking with DNF, or " +"xref:RPM.adoc#s1-check-rpm-sig[Checking Package Signatures] for information " +"on working with and verifying GPG-signed [application]*RPM* packages in " +"general." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:19 +msgid "" +"DNF also enables you to easily set up your own repositories of " +"[application]*RPM* packages for download and installation on other machines." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:21 +msgid "" +"Learning DNF is a worthwhile investment because it is often the fastest way " +"to perform system administration tasks, and it provides capabilities beyond " +"those provided by the [application]*PackageKit* graphical package management " +"tools." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:23 +#, no-wrap +msgid "DNF and superuser privileges" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:28 +msgid "" +"You must have superuser privileges in order to use the [command]#dnf# " +"command to install, update or remove packages on your system. All examples " +"in this chapter assume that you have already obtained superuser privileges " +"by using either the [command]#su# or [command]#sudo# command." +msgstr "" + +#. type: Title == +#: ./pages/package-management/DNF.adoc:32 +#, no-wrap +msgid "Checking For and Updating Packages" +msgstr "" + +#. type: Title === +#: ./pages/package-management/DNF.adoc:35 +#, no-wrap +msgid "Checking For Updates" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:38 +msgid "" +"indexterm:[DNF Updates,checking for updates] The quickest way to check for " +"updates is to attempt to install any available updates by using the " +"[command]#dnf upgrade# command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:45 +#, no-wrap +msgid "" +"~]# dnf upgrade\n" +"Last metadata expiration check performed 1:24:32 ago on Thu May 14 23:23:51 " +"2015.\n" +"Dependencies resolved.\n" +"Nothing to do.\n" +"Complete!\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:48 +msgid "" +"Note that [command]#dnf upgrade# installs only those updates that can be " +"installed. If a package cannot be updated, because of dependency problems " +"for example, it is skipped." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:50 +msgid "" +"The [command]#dnf check-update# command can be used see which installed " +"packages on your system have new versions available, however it does not " +"mean that they can be successfully installed. This command is therefore " +"mostly useful in scripts and for checking for updated packages that were not " +"installed after running [command]#dnf upgrade#." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:52 +msgid "For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:56 +#, no-wrap +msgid "" +"~]# dnf check-update\n" +"Using metadata from Mon Apr 20 16:34:10 2015 (2:42:10 hours old)\n" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:60 +#, no-wrap +msgid "" +"python.x86_64 2.7.9-6.fc22 updates\n" +"python-cryptography.x86_64 0.8.2-1.fc22 updates\n" +"python-libs.x86_64 2.7.9-6.fc22 updates\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:63 +msgid "" +"The packages in the above output are listed as having updated versions. The " +"line in the example output tells us:" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:65 +msgid "`python` — the name of the package," +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:67 +msgid "`x86_64` — the CPU architecture the package was built for," +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:69 +msgid "`2.7.9` — the version of the updated package," +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:71 +msgid "`6.fc22` — the release of the updated package," +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:73 +msgid "`updates-testing` — the repository in which the updated package is located." +msgstr "" + +#. type: Title === +#: ./pages/package-management/DNF.adoc:75 +#, no-wrap +msgid "Updating Packages" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:78 +msgid "" +"indexterm:[DNF Updates,updating packages] You can choose to update a single " +"package, multiple packages, or all packages at once. If any dependencies of " +"the package, or packages, you update have updates available themselves, then " +"they are updated too." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:79 +#, no-wrap +msgid "Updating a Single Packageindexterm:[DNF Updates,updating a single package]" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:81 +msgid "To update a single package, run the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:85 +#, no-wrap +msgid "dnf upgrade pass:quotes[_package_name_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:88 +msgid "For example, to update the [package]*python* package, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:99 +#, no-wrap +msgid "" +"~]# dnf upgrade python\n" +"Using metadata from Mon Apr 20 16:38:16 2015 (2:42:14 hours old)\n" +"Dependencies resolved.\n" +"==================================================================\n" +" Package Arch Version Repository Size\n" +"==================================================================\n" +"Upgrading:\n" +" python x86_64 2.7.9-6.fc22 updates 92 k\n" +" python-libs x86_64 2.7.9-6.fc22 updates 5.8 M\n" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:103 +#, no-wrap +msgid "" +"Transaction Summary\n" +"==================================================================\n" +"Upgrade 2 Packages\n" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:106 +#, no-wrap +msgid "" +"Total download size: 5.9 M\n" +"Is this ok [y/N]:\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:109 +msgid "This output contains:" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:111 +msgid "" +"`python.x86_64` — you can download and install new [package]*python* " +"package." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:113 +msgid "" +"`python-libs.x86_64` — DNF has resolved that the " +"[package]*python-libs-2.7.9-6.fc22.x86_64* package is a required dependency " +"of the [package]*python* package." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:115 +msgid "" +"DNF presents the update information and then prompts you as to whether you " +"want it to perform the update; DNF runs interactively by default. If you " +"already know which transactions DNF plans to perform, you can use the " +"[option]`-y` option to automatically answer [command]#yes# to any questions " +"DNF may ask (in which case it runs non-interactively). However, you should " +"always examine which changes DNF plans to make to the system so that you can " +"easily troubleshoot any problems that might arise." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:117 +msgid "" +"If a transaction does go awry, you can view DNF's transaction history by " +"using the [command]#dnf history# command as described in " +"xref:DNF.adoc#sec-DNF-Transaction_History[Working with Transaction History]." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:119 +#, no-wrap +msgid "Updating and installing kernels with DNF" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:124 +msgid "" +"DNF always *installs* a new kernel in the same sense that [application]*RPM* " +"installs a new kernel when you use the command [command]#rpm -i " +"kernel#. Therefore, you do not need to worry about the distinction between " +"*installing* and *upgrading* a kernel package when you use the " +"[command]#dnf# command: it will do the right thing, regardless of whether " +"you are using the [command]#dnf upgrade# or [command]#dnf install# command." +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:126 +msgid "" +"When using [application]*RPM*, on the other hand, it is important to use the " +"[command]#rpm -i kernel# command (which installs a new kernel) instead of " +"[command]#rpm -u kernel# (which *replaces* the current kernel). See " +"xref:RPM.adoc#sec-Installing_and_Upgrading[Installing and Upgrading " +"Packages] for more information on installing and updating kernels with " +"[application]*RPM*." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:129 +#, no-wrap +msgid "" +"Updating All Packages and Their Dependenciesindexterm:[DNF Updates,updating " +"all packages and dependencies]" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:131 +msgid "" +"To update all packages and their dependencies, enter [command]#dnf upgrade# " +"without any arguments:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:135 +#, no-wrap +msgid "[command]#dnf upgrade#\n" +msgstr "" + +#. type: Title === +#: ./pages/package-management/DNF.adoc:138 +#, no-wrap +msgid "Preserving Configuration File Changes" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:141 +msgid "" +"indexterm:[Configuration File Changes] You will inevitably make changes to " +"the configuration files installed by packages as you use your {MAJOROS} " +"system. [application]*RPM*, which DNF uses to perform changes to the system, " +"provides a mechanism for ensuring their integrity. See " +"xref:RPM.adoc#sec-Installing_and_Upgrading[Installing and Upgrading " +"Packages] for details on how to manage changes to configuration files across " +"package upgrades." +msgstr "" + +#. type: Title == +#: ./pages/package-management/DNF.adoc:143 +#, no-wrap +msgid "Packages and Package Groups" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:145 +msgid "" +"indexterm:[packages,packages and package groups]indexterm:[DNF,packages and " +"package groups]" +msgstr "" + +#. type: Title === +#: ./pages/package-management/DNF.adoc:147 +#, no-wrap +msgid "Searching Packages" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:150 +msgid "" +"indexterm:[packages,searching packages with DNF,dnf " +"search]indexterm:[DNF,searching packages with DNF,dnf search] You can search " +"all *RPM* package names and summaries by using the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:154 +#, no-wrap +msgid "[command]#dnf# [option]`search` _term_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:157 +msgid "Add the [option]`all` to match against descriptions and URLs." +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:161 +#, no-wrap +msgid "[command]#dnf# [option]`search all` _term_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:164 +msgid "" +"This command displays the list of matches for each term. For example, to " +"list all packages that match \"`meld`\" or \"`kompare`\", type:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:171 +#, no-wrap +msgid "" +"~]# dnf search meld kompare\n" +"Loaded plugins: langpacks, presto, refresh-packagekit\n" +"============================ N/S Matched: meld " +"===============================\n" +"meld.noarch : Visual diff and merge tool\n" +"python-meld3.x86_64 : HTML/XML templating system for Python\n" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:174 +#, no-wrap +msgid "" +"=========================== N/S Matched: kompare " +"=============================\n" +"komparator.x86_64 : Kompare and merge two folders\n" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:176 +#, no-wrap +msgid " Name and summary matches only, use \"search all\" for everything.\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:178 +msgid "" +"indexterm:[packages,searching for packages with DNF,dnf " +"search]indexterm:[DNF,searching for packages with DNF,dnf search]" +msgstr "" + +#. type: Title === +#: ./pages/package-management/DNF.adoc:180 +#, no-wrap +msgid "Listing Packages" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:183 +msgid "" +"indexterm:[packages,listing packages with DNF,dnf " +"search]indexterm:[DNF,listing packages with DNF,dnf list] [command]#dnf " +"list# and related commands provide information about packages, package " +"groups, and repositories." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:185 +msgid "" +"All of DNF's list commands allow you to filter the results by appending one " +"or more _glob expressions_ as arguments. Glob expressions are normal strings " +"of characters which contain one or more of the wildcard characters " +"[command]#*# (which expands to match any character multiple times) and " +"[command]#?# (which expands to match any one character)." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:187 +#, no-wrap +msgid "Filtering results with glob expressions" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:192 +msgid "" +"indexterm:[packages,listing packages with DNF,Glob " +"expressions]indexterm:[DNF,listing packages with DNF,Glob expressions] Be " +"careful to escape the glob expressions when passing them as arguments to a " +"[command]#dnf# command, otherwise the Bash shell will interpret these " +"expressions as _pathname expansions_, and potentially pass all files in the " +"current directory that match the globs to DNF. To make sure the glob " +"expressions are passed to DNF as intended, either:" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:194 +msgid "" +"escape the wildcard characters by preceding them with a backslash character; " +"or," +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:196 +msgid "double-quote or single-quote the entire glob expression." +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:198 +msgid "" +"DNF searches only package names when using glob expressions. To search for a " +"version of a package, include a dash and part of the version number as " +"follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:208 +#, no-wrap +msgid "" +"~]# dnf list kernel*-4*\n" +"Last metadata expiration check performed 2:46:09 ago on Thu May 14 23:23:51 " +"2015.\n" +"Installed Packages\n" +"kernel.x86_64 4.0.0-1.fc22 " +"@System\n" +"kernel.x86_64 4.0.2-300.fc22 " +"@System\n" +"kernel-core.x86_64 4.0.0-1.fc22 " +"@System\n" +"kernel-core.x86_64 4.0.2-300.fc22 " +"@System\n" +"[output truncated]\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:211 +msgid "" +"See " +"xref:DNF.adoc#ex-Listing_all_ABRT_addons_and_plugins_using_glob_expressions[Listing " +"all ABRT addons and plug-ins using glob expressions] and " +"xref:DNF.adoc#ex-Listing_available_packages_using_a_single_glob_expression_with_escaped_wildcards[Listing " +"available packages using a single glob expression with escaped wildcard " +"characters] for an example usage of both these methods." +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:214 +#, no-wrap +msgid "[command]#dnf list _glob_expression_pass:attributes[{blank}]…#" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:215 +msgid "" +"Lists information on installed and available packages matching all glob " +"expressions." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:217 +#, no-wrap +msgid "Listing all ABRT addons and plug-ins using glob expressions" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:221 +msgid "" +"Packages with various ABRT addons and plug-ins either begin with " +"\"`abrt-addon-`\", or \"`abrt-plugin-`\". To list these packages, type the " +"following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:237 +#, no-wrap +msgid "" +"~]# dnf list abrt-addon\\* abrt-plugin\\*\n" +"Last metadata expiration check performed 0:14:36 ago on Mon May 25 23:38:13 " +"2015.\n" +"Installed Packages\n" +"abrt-addon-ccpp.x86_64 2.5.1-2.fc22 @System\n" +"abrt-addon-coredump-helper.x86_64 2.5.1-2.fc22 @System\n" +"abrt-addon-kerneloops.x86_64 2.5.1-2.fc22 @System\n" +"abrt-addon-pstoreoops.x86_64 2.5.1-2.fc22 @System\n" +"abrt-addon-python.x86_64 2.5.1-2.fc22 @System\n" +"abrt-addon-python3.x86_64 2.5.1-2.fc22 @System\n" +"abrt-addon-vmcore.x86_64 2.5.1-2.fc22 @System\n" +"abrt-addon-xorg.x86_64 2.5.1-2.fc22 @System\n" +"abrt-plugin-bodhi.x86_64 2.5.1-2.fc22 @System\n" +"Available Packages\n" +"abrt-addon-upload-watch.x86_64 2.5.1-2.fc22 fedora\n" +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:241 +#, no-wrap +msgid "" +"indexterm:[packages,listing packages with DNF,dnf list all] " +"indexterm:[DNF,listing packages with DNF,dnf list all] " +"[command]#dnf list all#" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:242 +msgid "Lists all installed *and* available packages." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:244 +#, no-wrap +msgid "Listing all installed and available packages" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:258 +#, no-wrap +msgid "" +"~]# dnf list all\n" +"Last metadata expiration check performed 0:21:11 ago on Mon May 25 23:38:13 " +"2015.\n" +"Installed Packages\n" +"NetworkManager.x86_64 1:1.0.2-1.fc22 @System\n" +"NetworkManager-libnm.x86_64 1:1.0.2-1.fc22 @System\n" +"PackageKit.x86_64 1.0.6-4.fc22 @System\n" +"PackageKit-glib.x86_64 1.0.6-4.fc22 @System\n" +"aajohan-comfortaa-fonts.noarch 2.004-4.fc22 @System\n" +"abrt.x86_64 2.5.1-2.fc22 @System\n" +"[output truncated]\n" +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:262 +#, no-wrap +msgid "" +"indexterm:[packages,listing packages with DNF,dnf list installed] " +"indexterm:[DNF,listing packages with DNF,dnf list installed] " +"[command]#dnf list installed#" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:263 +msgid "" +"Lists all packages installed on your system. The rightmost column in the " +"output lists the repository from which the package was retrieved." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:265 +#, no-wrap +msgid "Listing installed packages using a double-quoted glob expression" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:269 +msgid "" +"To list all installed packages that begin with \"`krb`\" followed by exactly " +"one character and a hyphen, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:276 +#, no-wrap +msgid "" +"~]# dnf list installed \"krb?-*\"\n" +"Last metadata expiration check performed 0:34:45 ago on Mon May 25 23:38:13 " +"2015.\n" +"Installed Packages\n" +"krb5-libs.x86_64 1.13.1-3.fc22 @System\n" +"krb5-workstation.x86_64 1.13.1-3.fc22 @System\n" +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:280 +#, no-wrap +msgid "" +"indexterm:[packages,listing packages with DNF,dnf list available] " +"indexterm:[DNF,listing packages with DNF,dnf list available] " +"[command]#dnf list available#" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:281 +msgid "Lists all available packages in all enabled repositories." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:283 +#, no-wrap +msgid "" +"Listing available packages using a single glob expression with escaped " +"wildcard characters" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:287 +msgid "" +"To list all available packages with names that contain \"`gstreamer`\" and " +"then \"`plugin`\", run the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:299 +#, no-wrap +msgid "" +"~]# dnf list available gstreamer\\*plugin\\*\n" +"Last metadata expiration check performed 0:42:15 ago on Mon May 25 23:38:13 " +"2015.\n" +"Available Packages\n" +"gstreamer-plugin-crystalhd.i686 3.10.0-8.fc22 fedora\n" +"gstreamer-plugin-crystalhd.x86_64 3.10.0-8.fc22 fedora\n" +"gstreamer-plugins-bad-free.i686 0.10.23-24.fc22 fedora\n" +"gstreamer-plugins-bad-free.x86_64 0.10.23-24.fc22 fedora\n" +"gstreamer-plugins-bad-free-devel.i686 0.10.23-24.fc22 fedora\n" +"gstreamer-plugins-bad-free-devel.x86_64 0.10.23-24.fc22 fedora\n" +" [output truncated]\n" +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:303 +#, no-wrap +msgid "" +"indexterm:[packages,listing packages with DNF,dnf group list] " +"indexterm:[DNF,listing packages with DNF,dnf group list] " +"[command]#dnf group list#" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:304 +msgid "Lists all package groups." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:306 +#, no-wrap +msgid "Listing all package groups" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:320 +#, no-wrap +msgid "" +"~]# dnf group list\n" +"Loaded plugins: langpacks, presto, refresh-packagekit\n" +"Setting up Group Process\n" +"Installed Groups:\n" +" Administration Tools\n" +" Design Suite\n" +" Dial-up Networking Support\n" +" Fonts\n" +" GNOME Desktop Environment\n" +"[output truncated]\n" +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:324 +#, no-wrap +msgid "" +"indexterm:[packages,listing packages with DNF,dnf repolist] " +"indexterm:[DNF,listing packages with DNF,dnf repolist] " +"[command]#dnf repolist#" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:325 +msgid "" +"Lists the repository ID, name, and number of packages it provides for each " +"*enabled* repository." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:327 +#, no-wrap +msgid "Listing enabled repositories" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:336 +#, no-wrap +msgid "" +"~]# dnf repolist\n" +"Last metadata expiration check performed 0:48:29 ago on Mon May 25 23:38:13 " +"2015.\n" +"repo id repo name " +"status\n" +"*fedora Fedora 22 - x86_64 " +"44,762\n" +"*updates Fedora 22 - x86_64 - Updates " +"0\n" +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:340 +#, no-wrap +msgid "" +"indexterm:[packages,listing packages from a single repository with DNF,dnf " +"repository-packages] indexterm:[DNF,listing packages from a " +"single repository with DNF,dnf repository-packages] [command]#dnf " +"repository-packages _repo_id_ list#" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:341 +msgid "Lists the packages from the specified repository." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:343 +#, no-wrap +msgid "Listing packages from a single repository" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:354 +#, no-wrap +msgid "" +"~]# dnf repository-packages fedora list [option]\n" +"Last metadata expiration check performed 1:38:25 ago on Wed May 20 22:16:16 " +"2015.\n" +"Installed Packages\n" +"PackageKit.x86_64 1.0.6-3.fc22 " +"@System\n" +"PackageKit-glib.x86_64 1.0.6-3.fc22 " +"@System\n" +"aajohan-comfortaa-fonts.noarch 2.004-4.fc22 " +"@System\n" +"[output truncated]\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:357 +msgid "" +"The default action is to list all packages available and installed from the " +"repository specified. Add the [option]`available` or [option]`installed` " +"option to list only those packages available or installed from the specified " +"repository." +msgstr "" + +#. type: Title === +#: ./pages/package-management/DNF.adoc:361 +#, no-wrap +msgid "Displaying Package Information" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:364 +msgid "" +"indexterm:[packages,displaying packages with DNF,dnf " +"info]indexterm:[DNF,displaying packages with DNF,dnf info] To display " +"information about one or more packages, use a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:368 +#, no-wrap +msgid "dnf info pass:quotes[_package_name_]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:371 +#: ./pages/package-management/DNF.adoc:402 +msgid "For example, to display information about the [package]*abrt* package, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:390 +#, no-wrap +msgid "" +"~]# dnf info abrt\n" +"Last metadata expiration check: 1:09:44 ago on Tue May 31 06:51:51 2016.\n" +"Installed Packages\n" +"Name : abrt\n" +"Arch : x86_64\n" +"Epoch : 0\n" +"Version : 2.8.1\n" +"Release : 1.fc24\n" +"Size : 2.2 M\n" +"Repo : @System\n" +"From repo : updates-testing\n" +"Summary : Automatic bug detection and reporting tool\n" +"URL : https://abrt.readthedocs.org/\n" +"License : GPLv2+\n" +"Description : abrt is a tool to help users to detect defects in applications " +"and\n" +" : to create a bug report with all information needed by " +"maintainer to fix it.\n" +" : It uses plugin system to extend its functionality.\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:393 +msgid "" +"indexterm:[packages,displaying packages,dnf info]indexterm:[DNF,displaying " +"packages,dnf info] The [command]#dnf info " +"_package_name_pass:attributes[{blank}]# command is similar to the " +"[command]#rpm -q --info _package_name_pass:attributes[{blank}]# command, but " +"provides as additional information the name of the DNF repository the RPM " +"package was installed from (look for the `From repo:` line in the " +"output). The [command]#dnf info# command shows only the newest available " +"package if there is a newer version available than the one installed. The " +"[command]#dnf repoquery# command can show *all* installed and available " +"packages." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:395 +msgid "" +"To display information about all available packages, both installed and " +"available from a repository, use a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:399 +#, no-wrap +msgid "dnf repoquery pass:quotes[_package_name_] --info\n" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:421 +#, no-wrap +msgid "" +"~]# dnf repoquery abrt --info\n" +"Last metadata expiration check: 1:01:44 ago on Tue May 31 06:51:51 2016.\n" +"Name : abrt\n" +"Version : 2.8.1\n" +"Release : 1.fc24\n" +"Architecture: x86_64\n" +"Size : 2318452\n" +"License : GPLv2+\n" +"Source RPM : abrt-2.8.1-1.fc24.src.rpm\n" +"Build Date : 2016-05-25 08:54\n" +"Packager : Fedora Project\n" +"URL : https://abrt.readthedocs.org/\n" +"Summary : Automatic bug detection and reporting tool\n" +"Description :\n" +"abrt is a tool to help users to detect defects in applications and\n" +"to create a bug report with all information needed by maintainer to fix " +"it.\n" +"It uses plugin system to extend its functionality.\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:424 +msgid "See the [command]#dnf repoquery# usage statement for more options:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:430 +#, no-wrap +msgid "" +"~]$ [command]#dnf repoquery -h#\n" +"usage: dnf [options] COMMAND\n" +"_output truncated_\n" +msgstr "" + +#. type: Title === +#: ./pages/package-management/DNF.adoc:433 +#, no-wrap +msgid "Installing Packages" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:436 +msgid "" +"indexterm:[packages,installing with DNF]indexterm:[DNF,installing with DNF] " +"DNF allows you to install both a single package and multiple packages, as " +"well as a package group of your choice." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:437 +#, no-wrap +msgid "Installing Individual Packages" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:439 +msgid "" +"To install a single package and all of its non-installed dependencies, enter " +"a command in the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:443 +#, no-wrap +msgid "dnf install pass:quotes[_package_name_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:446 +msgid "" +"You can also install multiple packages simultaneously by appending their " +"names as arguments:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:450 +#, no-wrap +msgid "dnf install pass:quotes[_package_name_] pass:quotes[_package_name_]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:453 +msgid "" +"If you are installing packages on a _multilib_ system, such as an AMD64 or " +"Intel64 machine, you can specify the architecture of the package, as long as " +"it is available in an enabled repository, by appending _.arch_ to the " +"package name. For example, to install the [package]*sqlite2* package for " +"`i586`, type:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:456 +#, no-wrap +msgid "~]# dnf install sqlite2.i586\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:459 +msgid "" +"You can use glob expressions to quickly install multiple similarly-named " +"packages:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:462 +#, no-wrap +msgid "~]# dnf install audacious-plugins-\\*\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:465 +msgid "" +"In addition to package names and glob expressions, you can also provide file " +"names to [command]#dnf install#. If you know the name of the binary you want " +"to install, but not its package name, you can give [command]#dnf install# " +"the path name:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:468 +#, no-wrap +msgid "~]# dnf install /usr/sbin/named\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:471 +msgid "" +"[command]#dnf# then searches through its package lists, finds the package " +"which provides `/usr/sbin/named`, if any, and prompts you as to whether you " +"want to install it." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:473 +#, no-wrap +msgid "Finding which package owns a file" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:478 +msgid "" +"If you know you want to install the package that contains the `named` " +"binary, but you do not know in which `/usr/bin` or `/usr/sbin` directory the " +"file is installed, use the [command]#dnf provides# command with a glob " +"expression:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:484 +#, no-wrap +msgid "" +"~]# dnf provides \"*bin/named\"\n" +"Using metadata from Thu Apr 16 13:41:45 2015 (4:23:50 hours old)\n" +"bind-32:9.10.2-1.fc22.x86_64 : The Berkeley Internet Name Domain (BIND) DNS " +"(Domain Name System) server\n" +"Repo : @System\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:487 +msgid "" +"[command]#dnf provides " +"\"*/pass:attributes[{blank}]_file_name_pass:attributes[{blank}]\"# will find " +"all the packages that contain _file_name_." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:490 +#, no-wrap +msgid "" +"Installing a Package Groupindexterm:[packages,installing a package group " +"with DNF]indexterm:[DNF,installing a package group with DNF]" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:492 +msgid "" +"A package group is similar to a package: it is not useful by itself, but " +"installing one pulls a group of dependent packages that serve a common " +"purpose. A package group has a name and a _groupid_ (*GID*). The " +"[command]#dnf group list -v# command lists the names of all package groups, " +"and, next to each of them, their groupid in parentheses. The groupid is " +"always the term in the last pair of parentheses, such as " +"`kde-desktop-environment` in the following example:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:508 +#, no-wrap +msgid "" +"~]# dnf -v group list kde\\*\n" +"cachedir: /var/cache/dnf/x86_64/22\n" +"Loaded plugins: builddep, config-manager, copr, playground, " +"debuginfo-install, download, generate_completion_cache, kickstart, " +"needs-restarting, noroot, protected_packages, Query, reposync, langpacks\n" +"initialized Langpacks plugin\n" +"DNF version: 0.6.5\n" +"repo: using cache for: fedora\n" +"not found deltainfo for: Fedora 22 - x86_64\n" +"not found updateinfo for: Fedora 22 - x86_64\n" +"repo: using cache for: updates-testing\n" +"repo: using cache for: updates\n" +"not found updateinfo for: Fedora 22 - x86_64 - Updates\n" +"Using metadata from Thu Apr 16 13:41:45 2015 (4:37:51 hours old)\n" +"Available environment groups:\n" +" KDE Plasma Workspaces (kde-desktop-environment)\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:511 +msgid "" +"You can install a package group by passing its full group name (without the " +"groupid part) to [command]#group install#:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:515 +#, no-wrap +msgid "dnf group install pass:quotes[_group_name_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:518 +msgid "Multi-word names must be quoted." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:520 +msgid "You can also install by groupid:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:524 +#, no-wrap +msgid "[command]#dnf# [option]`group install` _groupid_\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:527 +msgid "" +"You can even pass the groupid, or quoted name, to the [command]#install# " +"command if you prepend it with an @-symbol (which tells [command]#dnf# that " +"you want to perform a [command]#group install#):" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:531 +#, no-wrap +msgid "[command]#dnf# [option]`install` @pass:attributes[{blank}]_group_\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:534 +msgid "" +"For example, the following are alternative but equivalent ways of installing " +"the `KDE Plasma Workspaces` group:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:539 +#, no-wrap +msgid "" +"~]# dnf group install \"KDE Plasma Workspaces\"\n" +"~]# dnf group install kde-desktop-environment\n" +"~]# dnf install @kde-desktop-environment\n" +msgstr "" + +#. type: Title === +#: ./pages/package-management/DNF.adoc:542 +#, no-wrap +msgid "Removing Packages" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:545 +msgid "" +"indexterm:[packages,uninstalling packages with " +"DNF]indexterm:[DNF,uninstalling packages with DNF] Similarly to package " +"installation, DNF allows you to uninstall (remove in [application]*RPM* and " +"DNF terminology) both individual packages and a package group." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:546 +#, no-wrap +msgid "" +"Removing Individual Packagesindexterm:[packages,uninstalling packages with " +"DNF,dnf remove package_name]indexterm:[DNF,uninstalling packages with " +"DNF,dnf remove package_name]" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:548 +msgid "" +"To uninstall a particular package, as well as any packages that depend on " +"it, run the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:552 +#, no-wrap +msgid "dnf remove pass:quotes[_package_name_]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:555 +msgid "" +"As when you install multiple packages, you can remove several at once by " +"adding more package names to the command. For example, to remove " +"[package]*totem*, [package]*rhythmbox*, and [package]*sound-juicer*, type " +"the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:558 +#, no-wrap +msgid "~]# dnf remove totem rhythmbox sound-juicer\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:561 +msgid "Similar to [command]#install#, [command]#remove# can take these arguments:" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:563 +msgid "package names" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:565 +msgid "glob expressions" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:567 +msgid "file lists" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:569 +msgid "package provides" +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:571 +#, no-wrap +msgid "Removing a package when other packages depend on it" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:576 +msgid "" +"DNF is not able to remove a package without also removing packages which " +"depend on it. This type of operation can only be performed by " +"[application]*RPM*, is not advised, and can potentially leave your system in " +"a non-functioning state or cause applications to misbehave and terminate " +"unexpectedly. For further information, refer to " +"xref:RPM.adoc#s2-rpm-uninstalling[Uninstalling Packages] in the " +"[application]*RPM* chapter." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:579 +#, no-wrap +msgid "Removing a Package Group" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:581 +msgid "" +"You can remove a package group using syntax congruent with the " +"[command]#install# syntax:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:585 +#, no-wrap +msgid "[command]#dnf# [option]`group remove` _group_\n" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:590 +#, no-wrap +msgid "[command]#dnf# [option]`remove` @pass:attributes[{blank}]_group_\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:593 +msgid "" +"The following are alternative but equivalent ways of removing the `KDE " +"Plasma Workspaces` group:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:598 +#, no-wrap +msgid "" +"~]# dnf group remove \"KDE Plasma Workspaces\"\n" +"~]# dnf group remove kde-desktop-environment\n" +"~]# dnf remove @kde-desktop-environment\n" +msgstr "" + +#. type: Title === +#: ./pages/package-management/DNF.adoc:601 +#, no-wrap +msgid "Working with Transaction History" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:604 +msgid "" +"The [command]#dnf history# command allows users to review information about " +"a timeline of DNF transactions, the dates and times on when they occurred, " +"the number of packages affected, whether transactions succeeded or were " +"aborted, and if the RPM database was changed between " +"transactions. Additionally, this command can be used to undo or redo certain " +"transactions." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:605 +#, no-wrap +msgid "Listing Transactions" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:607 +msgid "" +"To display a list of all transactions, as `root`, either run [command]#dnf " +"history# with no additional arguments, or enter the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:611 +#, no-wrap +msgid "[command]#dnf# [option]`history` [option]`list`\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:614 +msgid "" +"To display only transactions in a given range, use the command in the " +"following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:618 +#, no-wrap +msgid "dnf history list pass:quotes[_start_id_]..pass:quotes[_end_id_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:621 +msgid "" +"You can also list only transactions regarding a particular package or " +"packages. To do so, use the command with a package name or a glob " +"expression:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:625 +#, no-wrap +msgid "dnf history list pass:quotes[_glob_expression_]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:628 +msgid "For example, the list of first five transactions may look as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:633 +#, no-wrap +msgid "" +"~]# dnf history list 1..4\n" +"Using metadata from Thu Apr 16 13:41:45 2015 (5:47:31 hours old)\n" +"ID | Login user | Date a | Action | Altere\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:638 +#, no-wrap +msgid "" +" 4 | root | 2015-04-16 18:35 | Erase | " +"1\n" +" 3 | root | 2015-04-16 18:34 | Install | " +"1\n" +" 2 | root | 2015-04-16 17:53 | Install | " +"1\n" +" 1 | System | 2015-04-16 14:14 | Install | 668 " +"E\n" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:641 +#, no-wrap +msgid "" +"The [command]#dnf history list# command produces tabular output with each " +"row consisting of the following columns:\n" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:643 +#, no-wrap +msgid "* `ID` — an integer value that identifies a particular transaction.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:645 +#, no-wrap +msgid "" +"* `Login user` — the name of the user whose login session was used to " +"initiate a transaction. This information is typically presented in the " +"`pass:attributes[{blank}]_Full Name_ " +"_pass:attributes[{blank}]` form, however " +"sometimes the command used to perform the transaction is displayed. For " +"transactions that were not issued by a user (such as an automatic system " +"update), `System ` is used instead.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:647 +#, no-wrap +msgid "* `Date and time` — the date and time when a transaction was issued.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:649 +#, no-wrap +msgid "" +"* `Action(s)` — a list of actions that were performed during a " +"transaction as described in " +"xref:DNF.adoc#tabl-DNF-Transaction_History-Actions[Possible values of the " +"Action(s) field].\n" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:651 +#, no-wrap +msgid "" +"* `Altered` — the number of packages that were affected by a " +"transaction, possibly followed by additional information.\n" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:654 +#, no-wrap +msgid "" +"[[tabl-DNF-Transaction_History-Actions]]\n" +".Possible values of the Action(s) field\n" +msgstr "" + +#. type: Table +#: ./pages/package-management/DNF.adoc:664 +#, no-wrap +msgid "" +"[options=\"header\"]\n" +"|Action|Abbreviation|Description\n" +"|`Downgrade`|`D`|At least one package has been downgraded to an older " +"version.\n" +"|`Erase`|`E`|At least one package has been removed.\n" +"|`Install`|`I`|At least one new package has been installed.\n" +"|`Obsoleting`|`O`|At least one package has been marked as obsolete.\n" +"|`Reinstall`|`R`|At least one package has been reinstalled.\n" +"|`Update`|`U`|At least one package has been updated to a newer version.\n" +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:666 +#, no-wrap +msgid "Reverting and Repeating Transactions" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:668 +msgid "" +"Apart from reviewing the transaction history, the [command]#dnf history# " +"command provides means to revert or repeat a selected transaction. To revert " +"a transaction, type the following at a shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:672 +#, no-wrap +msgid "[command]#dnf# [option]`history` [option]`undo` _id_\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:675 +msgid "To repeat a particular transaction, as `root`, run the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:679 +#, no-wrap +msgid "[command]#dnf# [option]`history` [option]`redo` _id_\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:682 +msgid "" +"Both commands also accept the `last` keyword to undo or repeat the latest " +"transaction." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:684 +msgid "" +"Note that both [command]#dnf history undo# and [command]#dnf history redo# " +"commands merely revert or repeat the steps that were performed during a " +"transaction, and will fail if the required packages are not available. For " +"example, if the transaction installed a new package, the [command]#dnf " +"history undo# command will uninstall it and also attempt to downgrade all " +"updated packages to their previous version, but the command will fail if the " +"required packages are not available." +msgstr "" + +#. type: Title == +#: ./pages/package-management/DNF.adoc:686 +#, no-wrap +msgid "Configuring DNF and DNF Repositories" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:689 +msgid "" +"indexterm:[DNF,configuring DNF and DNF repositories]indexterm:[DNF,DNF " +"repositories,configuring DNF and DNF repositories] The configuration file " +"for DNF and related utilities is located at `/etc/dnf/dnf.conf`. This file " +"contains one mandatory `[main]` section, which allows you to set DNF options " +"that have global effect, and may also contain one or more " +"`[pass:attributes[{blank}]_repository_pass:attributes[{blank}]]` sections, " +"which allow you to set repository-specific options. However, it is " +"recommended to define individual repositories in new or existing `.repo` " +"files in the `/etc/yum.repos.d/` directory. The values you define in " +"individual `[pass:attributes[{blank}]_repository_pass:attributes[{blank}]]` " +"sections of the `/etc/dnf/dnf.conf` file override values set in the `[main]` " +"section." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:691 +msgid "This section shows you how to:" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:693 +msgid "" +"set global DNF options by editing the `[main]` section of the " +"`/etc/dnf/dnf.conf` configuration file;" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:695 +msgid "" +"set options for individual repositories by editing the " +"`[pass:attributes[{blank}]_repository_pass:attributes[{blank}]]` sections in " +"`/etc/dnf/dnf.conf` and `.repo` files in the `/etc/yum.repos.d/` directory;" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:697 +msgid "" +"use DNF variables in `/etc/dnf/dnf.conf` and files in the " +"`/etc/yum.repos.d/` directory so that dynamic version and architecture " +"values are handled correctly;" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:699 +msgid "add, enable, and disable DNF repositories on the command line; and," +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:701 +msgid "set up your own custom DNF repository." +msgstr "" + +#. type: Title === +#: ./pages/package-management/DNF.adoc:703 +#, no-wrap +msgid "Setting [main] Options" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:706 +msgid "" +"indexterm:[DNF,setting [main] options] The `/etc/dnf/dnf.conf` configuration " +"file contains exactly one `[main]` section, and while some of the key-value " +"pairs in this section affect how [command]#dnf# operates, others affect how " +"DNF treats repositories." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:708 +msgid "" +"You can add many additional options under the `[main]` section heading in " +"`/etc/dnf/dnf.conf`." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:710 +msgid "A sample `/etc/dnf/dnf.conf` configuration file can look like this:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:716 +#, no-wrap +msgid "" +"[main]\n" +"gpgcheck=1\n" +"installonly_limit=3\n" +"clean_requirements_on_remove=true\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:719 +msgid "The following are the most commonly-used options in the `[main]` section:" +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:720 +#, no-wrap +msgid "[option]`debuglevel`pass:attributes[{blank}]=pass:attributes[{blank}]_value_" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:721 +#: ./pages/package-management/DNF.adoc:727 +#: ./pages/package-management/DNF.adoc:744 +#: ./pages/package-management/DNF.adoc:750 +#: ./pages/package-management/DNF.adoc:776 +#: ./pages/package-management/DNF.adoc:780 +#: ./pages/package-management/DNF.adoc:805 +msgid "{blank}" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:723 +msgid "" +"…where _value_ is an integer between `0` and `10`. Setting a higher " +"[option]`debuglevel` value causes [command]#dnf# to display more detailed " +"debugging output. [option]`debuglevel=0` disables debugging output, and " +"[option]`debuglevel=2` is the default." +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:724 +#, no-wrap +msgid "[option]`exclude`pass:attributes[{blank}]=pass:attributes[{blank}]_package_name_pass:attributes[{blank}] pass:attributes[{blank}]_more_package_names_" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:725 +msgid "" +"This option allows you to exclude packages by keyword during installation " +"and updates. Listing multiple packages for exclusion can be accomplished by " +"quoting a space-delimited list of packages. Shell globs using wildcards (for " +"example, `*` and `?`) are allowed." +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:726 +#, no-wrap +msgid "[option]`gpgcheck`pass:attributes[{blank}]=pass:attributes[{blank}]_value_" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:729 +#: ./pages/package-management/DNF.adoc:752 +#: ./pages/package-management/DNF.adoc:807 +msgid "…where _value_ is one of:" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:731 +msgid "" +"`0` — Disable GPG signature-checking on packages in all repositories, " +"including local package installation." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:733 +msgid "" +"`1` — Enable GPG signature-checking on all packages in all repositories, " +"including local package installation. [option]`gpgcheck=1` is the default, " +"and thus all packages' signatures are checked." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:735 +msgid "" +"If this option is set in the `[main]` section of the `/etc/dnf/dnf.conf` " +"file, it sets the GPG-checking rule for all repositories. However, you can " +"also set " +"[option]`gpgcheck=pass:attributes[{blank}]_value_pass:attributes[{blank}]` " +"for individual repositories instead; you can enable GPG-checking on one " +"repository while disabling it on another. Setting " +"[option]`gpgcheck=pass:attributes[{blank}]_value_pass:attributes[{blank}]` " +"for an individual repository in its corresponding `.repo` file overrides the " +"default if it is present in `/etc/dnf/dnf.conf`." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:737 +msgid "" +"For more information on GPG signature-checking, refer to " +"xref:RPM.adoc#s1-check-rpm-sig[Checking Package Signatures]." +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:738 +#, no-wrap +msgid "[option]`installonlypkgs`pass:attributes[{blank}]=pass:attributes[{blank}]_space_pass:attributes[{blank}] pass:attributes[{blank}]_separated_pass:attributes[{blank}] pass:attributes[{blank}]_list_pass:attributes[{blank}] pass:attributes[{blank}]_of_pass:attributes[{blank}] pass:attributes[{blank}]_packages_" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:739 +msgid "" +"Here you can provide a space-separated list of packages which [command]#dnf# " +"can *install*, but will never *update*. See the *dnf.conf*(5) manual page " +"for the list of packages which are install-only by default." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:741 +msgid "" +"If you add the [option]`installonlypkgs` directive to `/etc/dnf/dnf.conf`, " +"you should ensure that you list *all* of the packages that should be " +"install-only, including any of those listed under the `installonlypkgs` " +"section of *dnf.conf*(5). In particular, kernel packages should always be " +"listed in [option]`installonlypkgs` (as they are by default), and " +"[option]`installonly_limit` should always be set to a value greater than `2` " +"so that a backup kernel is always available in case the default one fails to " +"boot." +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:743 +#, no-wrap +msgid "[option]`installonly_limit`pass:attributes[{blank}]=pass:attributes[{blank}]_value_" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:746 +msgid "" +"…where _value_ is an integer representing the maximum number of versions " +"that can be installed simultaneously for any single package listed in the " +"[option]`installonlypkgs` directive." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:748 +msgid "" +"The defaults for the [option]`installonlypkgs` directive include several " +"different kernel packages, so be aware that changing the value of " +"[option]`installonly_limit` will also affect the maximum number of installed " +"versions of any single kernel package. The default value listed in " +"`/etc/dnf/dnf.conf` is [option]`installonly_limit=3`, and it is not " +"recommended to decrease this value, particularly below `2`." +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:749 +#, no-wrap +msgid "[option]`keepcache`pass:attributes[{blank}]=pass:attributes[{blank}]_value_" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:754 +msgid "" +"`0` — Do not retain the cache of headers and packages after a successful " +"installation. This is the default." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:756 +msgid "`1` — Retain the cache after a successful installation." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:758 +msgid "" +"For a complete list of available `[main]` options, refer to the `[MAIN] " +"OPTIONS` section of the *dnf.conf*(5) manual page." +msgstr "" + +#. type: Title === +#: ./pages/package-management/DNF.adoc:760 +#, no-wrap +msgid "Setting [repository] Options" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:763 +msgid "" +"indexterm:[DNF,setting [repository] options] The " +"`[pass:attributes[{blank}]_repository_pass:attributes[{blank}]]` sections, " +"where _repository_ is a unique repository ID such as `my_personal_repo` " +"(spaces are not permitted), allow you to define individual DNF repositories." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:765 +msgid "" +"The following is a bare-minimum example of the form a " +"`[pass:attributes[{blank}]_repository_pass:attributes[{blank}]]` section " +"takes:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:771 +#, no-wrap +msgid "" +"[pass:quotes[_repository_]]\n" +"name=pass:quotes[_repository_name_]\n" +"baseurl=pass:quotes[_repository_url_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:774 +msgid "" +"Every `[pass:attributes[{blank}]_repository_pass:attributes[{blank}]]` " +"section must contain the following directives:" +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:775 +#, no-wrap +msgid "[option]`name`pass:attributes[{blank}]=pass:attributes[{blank}]_repository_name_" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:778 +msgid "" +"…where _repository_name_ is a human-readable string describing the " +"repository." +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:779 +#, no-wrap +msgid "_parameter_pass:attributes[{blank}]=pass:attributes[{blank}]_repository_url_" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:782 +msgid "" +"…where _parameter_ is one of the following: [option]`baseurl`, " +"[option]`metalink`, or [option]`mirrorlist`pass:attributes[{blank}];" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:784 +msgid "" +"…where _repository_url_ is a URL to a directory containing a `repodata` " +"directory of a repository, a metalink file, or a mirror list file." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:786 +msgid "If the repository is available over HTTP, use: `http://path/to/repo`" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:788 +msgid "If the repository is available over FTP, use: `ftp://path/to/repo`" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:790 +msgid "If the repository is local to the machine, use: `file:///path/to/local/repo`" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:792 +msgid "" +"If a specific online repository requires basic HTTP authentication, you can " +"specify your user name and password by prepending it to the URL as " +"[option]`pass:attributes[{blank}]_username_:pass:attributes[{blank}]_password_pass:attributes[{blank}]@pass:attributes[{blank}]_link_pass:attributes[{blank}]`. " +"For example, if a repository on http://www.example.com/repo/ requires a " +"username of \"`user`\" and a password of \"`password`\", then the " +"[option]`baseurl` link could be specified as " +"[option]`http://user:password@www.example.com/repo/`." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:794 +msgid "Usually this URL is an HTTP link, such as:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:798 +#, no-wrap +msgid "baseurl=http://path/to/repo/releases/$releasever/server/$basearch/os/\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:801 +msgid "" +"Note that DNF always expands the `$releasever`, `$arch`, and `$basearch` " +"variables in URLs. For more information about DNF variables, refer to " +"xref:DNF.adoc#sec-Using_DNF_Variables[Using DNF Variables]." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:803 +msgid "" +"To configure the default set of repositories, use the [option]`enabled` " +"option as follows:" +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:804 +#, no-wrap +msgid "[option]`enabled`pass:attributes[{blank}]=pass:attributes[{blank}]_value_" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:809 +msgid "" +"`0` — Do not include this repository as a package source when performing " +"updates and installs." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:811 +msgid "`1` — Include this repository as a package source." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:813 +msgid "" +"Turning repositories on and off can also be performed by passing either the " +"[option]`--set-enabled _repo_name_pass:attributes[{blank}]` or " +"[option]`--set-disabled _repo_name_pass:attributes[{blank}]` option to the " +"[command]#dnf# command, or through the `Add/Remove Software` window of the " +"[application]*PackageKit* utility." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:815 +msgid "" +"Many more `[pass:attributes[{blank}]_repository_pass:attributes[{blank}]]` " +"options exist. For a complete list, refer to the `[repository] OPTIONS` " +"section of the *dnf.conf*(5) manual page." +msgstr "" + +#. type: Title === +#: ./pages/package-management/DNF.adoc:817 +#, no-wrap +msgid "Using DNF Variables" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:820 +msgid "" +"indexterm:[DNF,variables] Variables can be used only in the appropriate " +"sections of the DNF configuration files, namely the `/etc/dnf/dnf.conf` file " +"and all `.repo` files in the `/etc/yum.repos.d/` directory. Repository " +"variables include:" +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:821 +#, no-wrap +msgid "`$releasever`" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:822 +msgid "" +"Refers to the release version of operating system which DNF derives from " +"information available in RPMDB." +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:823 +#, no-wrap +msgid "`$arch`" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:824 +msgid "" +"Refers to the system’s CPU architecture. Valid values for `$arch` include: " +"`i586`, `i686` and `x86_64`." +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:825 +#, no-wrap +msgid "`$basearch`" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:826 +msgid "" +"Refers to the base architecture of the system. For example, i686 and i586 " +"machines both have a base architecture of `i386`, and AMD64 and Intel64 " +"machines have a base architecture of `x86_64`." +msgstr "" + +#. type: Title == +#: ./pages/package-management/DNF.adoc:828 +#, no-wrap +msgid "Viewing the Current Configuration" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:831 +msgid "" +"To list all configuration options and their corresponding values, and the " +"repositories, execute the [command]#dnf config-manager# command with the " +"[option]`--dump` option:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:845 +#, no-wrap +msgid "" +"~]${nbsp}dnf config-manager --dump\n" +"============================= main ======================================\n" +"[main]\n" +"alwaysprompt = True\n" +"assumeno = False\n" +"assumeyes = False\n" +"bandwidth = 0\n" +"best = False\n" +"bugtracker_url = " +"https://bugzilla.redhat.com/enter_bug.cgi?product=Fedora&component=dnf\n" +"cachedir = /var/cache/dnf/x86_64/22\n" +"[output truncated]\n" +msgstr "" + +#. type: Title == +#: ./pages/package-management/DNF.adoc:848 +#, no-wrap +msgid "Adding, Enabling, and Disabling a DNF Repository" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:851 +msgid "" +"indexterm:[DNF,repository] " +"xref:DNF.adoc#sec-Setting_repository_Options[Setting [repository] Options] " +"describes various options you can use to define a DNF repository. This " +"section explains how to add, enable, and disable a repository by using the " +"[command]#dnf config-manager# command." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:852 +#, no-wrap +msgid "Adding a DNF Repository" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:854 +msgid "" +"To define a new repository, you can either add a " +"`[pass:attributes[{blank}]_repository_pass:attributes[{blank}]]` section to " +"the `/etc/dnf/dnf.conf` file, or to a `.repo` file in the " +"`/etc/yum.repos.d/` directory. All files with the `.repo` file extension in " +"this directory are read by DNF, and it is recommended to define your " +"repositories here instead of in `/etc/dnf/dnf.conf`." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:856 +msgid "" +"DNF repositories commonly provide their own `.repo` file. To add such a " +"repository to your system and enable it, run the following command as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:860 +#, no-wrap +msgid "dnf config-manager --add-repo pass:quotes[_repository_url_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:863 +msgid "…where _repository_url_ is a link to the `.repo` file." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:865 +#, no-wrap +msgid "Adding example.repo" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:869 +msgid "" +"To add a repository located at http://www.example.com/example.repo, type the " +"following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:874 +#, no-wrap +msgid "" +"~]#{nbsp}dnf config-manager --add-repo http://www.example.com/example.repo\n" +"adding repo from: http://www.example.com/example.repo\n" +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:878 +#, no-wrap +msgid "Enabling a DNF Repository" +msgstr "" + +#. type: delimited block = +#: ./pages/package-management/DNF.adoc:880 +msgid "" +"To enable a particular repository or repositories, type the following at a " +"shell prompt as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:884 +#, no-wrap +msgid "" +"[command]#dnf config-manager# [option]`--set-enabled` " +"_repository_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:887 +#: ./pages/package-management/DNF.adoc:897 +msgid "" +"…where _repository_ is the unique repository ID. To display the " +"current configuration, add the [option]`--dump` option." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:888 +#, no-wrap +msgid "Disabling a DNF Repository" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:890 +msgid "To disable a DNF repository, run the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/package-management/DNF.adoc:894 +#, no-wrap +msgid "" +"[command]#dnf config-manager# [option]`--set-disabled` " +"_repository_pass:attributes[{blank}]…\n" +msgstr "" + +#. type: Title == +#: ./pages/package-management/DNF.adoc:899 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:901 +msgid "indexterm:[DNF,Additional Resources]" +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:901 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:904 +msgid "`dnf(8)` — The DNF command reference manual page." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:906 +msgid "`dnf.conf(8)` — DNF Configuration Reference manual page." +msgstr "" + +#. type: Block title +#: ./pages/package-management/DNF.adoc:907 +#, no-wrap +msgid "Online Documentation" +msgstr "" + +#. type: Labeled list +#: ./pages/package-management/DNF.adoc:909 +#, no-wrap +msgid "link:++https://dnf.readthedocs.org/en/latest/index.html++[]" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/DNF.adoc:909 +msgid "The DNF wiki contains more documentation." +msgstr "" diff --git a/pot/rawhide/pages/package-management/intro-package-management.pot b/pot/rawhide/pages/package-management/intro-package-management.pot new file mode 100644 index 00000000000..62e3f862652 --- /dev/null +++ b/pot/rawhide/pages/package-management/intro-package-management.pot @@ -0,0 +1,71 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/package-management/intro-package-management.adoc:3 +#, no-wrap +msgid "Package Management" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/intro-package-management.adoc:6 +msgid "" +"There are two types of {MAJOROS} system; \"`traditional`\", which use DNF, " +"and \"`image-based`\" which use rpm-ostree." +msgstr "" + +#. type: Title == +#: ./pages/package-management/intro-package-management.adoc:7 +#, no-wrap +msgid "Traditional package management" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/intro-package-management.adoc:11 +msgid "" +"On a traditional {MAJOROS} system, software is divided into RPM packages, " +"which can be managed via [application]*DNF*." +msgstr "" + +#. type: Title == +#: ./pages/package-management/intro-package-management.adoc:12 +#, no-wrap +msgid "Hybrid image/package management" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/intro-package-management.adoc:19 +msgid "" +"The \"`Atomic`\" variant of {MAJOROS} uses [application]*rpm-ostree* to " +"update the host. `rpm-ostree` is a hybrid image/package system. By default, " +"installations are in \"`image`\" mode using OSTree, but additional packages " +"can be installed. It also supports overrides, rebases, and many other " +"features. For more information, see " +"link:++https://www.projectatomic.io/docs/os-updates/++[its online " +"documentation]." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/intro-package-management.adoc:22 +msgid "" +"Additionally, the `atomic` CLI supports installation of system containers, " +"which are Docker/OCI images distinct from the host user space. For more " +"information, see " +"link:++https://www.projectatomic.io/docs/usr-bin-atomic/++[its online " +"documentation]." +msgstr "" diff --git a/pot/rawhide/pages/package-management/rpm-ostree.pot b/pot/rawhide/pages/package-management/rpm-ostree.pot new file mode 100644 index 00000000000..f140c5fc1f5 --- /dev/null +++ b/pot/rawhide/pages/package-management/rpm-ostree.pot @@ -0,0 +1,38 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/package-management/rpm-ostree.adoc:5 +#, no-wrap +msgid "rpm-ostree" +msgstr "" + +#. type: Plain text +#: ./pages/package-management/rpm-ostree.adoc:10 +msgid "" +"[application]*rpm-ostree* is a hybrid image/package system for {OSORG}. One " +"of the most important things to understand is that available RPMs come from " +"the same `/etc/yum.repos.d` sources." +msgstr "" + +#. type: Plain text +#: ./pages/package-management/rpm-ostree.adoc:11 +msgid "" +"For more information, see the " +"link:https://coreos.github.io/rpm-ostree/[upstream documentation]." +msgstr "" diff --git a/pot/rawhide/pages/pam_userdb.pot b/pot/rawhide/pages/pam_userdb.pot new file mode 100644 index 00000000000..b012c09210a --- /dev/null +++ b/pot/rawhide/pages/pam_userdb.pot @@ -0,0 +1,94 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/pam_userdb.adoc:5 +#, no-wrap +msgid "pam_userdb" +msgstr "" + +#. type: Plain text +#: ./pages/pam_userdb.adoc:8 +msgid "" +"pam_userdb is a PAM module to authenticate against a db database. It is used " +"to verify a username/password pair against values stored in a key/data pairs " +"style database (i.e. Berkeley DB, GDBM). The database is indexed by the " +"username, and the data fields corresponding to the username keys are the " +"passwords. This module is most notably used in vsftpd environments." +msgstr "" + +#. type: Plain text +#: ./pages/pam_userdb.adoc:10 +msgid "" +"Recently, pam_userdb switched its database provider from Berkeley DB to " +"GDBM. If your system uses this module to authenticate users you need to " +"convert the database to the new format." +msgstr "" + +#. type: Title == +#: ./pages/pam_userdb.adoc:11 +#, no-wrap +msgid "Determining whether you are using pam_userdb" +msgstr "" + +#. type: Plain text +#: ./pages/pam_userdb.adoc:13 +msgid "The way to determine if you are using pam_userdb, is to check the PAM stack:" +msgstr "" + +#. type: delimited block - +#: ./pages/pam_userdb.adoc:18 +#, no-wrap +msgid "" +"$ grep -r pam_userdb /etc/pam.d/\n" +"/etc/pam.d/vsftpd:auth sufficient pam_userdb.so " +"db=/etc/vsftpd/login\n" +msgstr "" + +#. type: Plain text +#: ./pages/pam_userdb.adoc:21 +msgid "" +"If you are not using pam_userdb, then the search will return no values and " +"you don't have to do anything." +msgstr "" + +#. type: Title == +#: ./pages/pam_userdb.adoc:22 +#, no-wrap +msgid "Converting the database" +msgstr "" + +#. type: Plain text +#: ./pages/pam_userdb.adoc:25 +msgid "" +"libdb package contains a binary that will handle the conversion for you. You " +"only need to run it by providing the source and destination database " +"files:. Example:" +msgstr "" + +#. type: delimited block - +#: ./pages/pam_userdb.adoc:29 +#, no-wrap +msgid "$ db_converter --src /etc/vsftpd/login.db --dest /etc/vsftpd/login.gdbm\n" +msgstr "" + +#. type: Title == +#: ./pages/pam_userdb.adoc:31 +#, no-wrap +msgid "Additional Resources" +msgstr "" diff --git a/pot/rawhide/pages/servers/Configuring_NTP_Using_ntpd.pot b/pot/rawhide/pages/servers/Configuring_NTP_Using_ntpd.pot new file mode 100644 index 00000000000..79fca86d666 --- /dev/null +++ b/pot/rawhide/pages/servers/Configuring_NTP_Using_ntpd.pot @@ -0,0 +1,2071 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:6 +#, no-wrap +msgid "Configuring NTP Using ntpd" +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:9 +#, no-wrap +msgid "Introduction to NTP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:12 +msgid "" +"The _Network Time Protocol_ (*NTP*) enables the accurate dissemination of " +"time and date information in order to keep the time clocks on networked " +"computer systems synchronized to a common reference over the network or the " +"Internet. Many standards bodies around the world have atomic clocks which " +"may be made available as a reference. The satellites that make up the Global " +"Position System contain more than one atomic clock, making their time " +"signals potentially very accurate. Their signals can be deliberately " +"degraded for military reasons. An ideal situation would be where each site " +"has a server, with its own reference clock attached, to act as a site-wide " +"time server. Many devices which obtain the time and date via low frequency " +"radio transmissions or the Global Position System (GPS) exist. However for " +"most situations, a range of publicly accessible time servers connected to " +"the Internet at geographically dispersed locations can be used. These `NTP` " +"servers provide \"`pass:attributes[{blank}]_Coordinated Universal " +"Time_pass:attributes[{blank}]`\" (*UTC*). Information about these time " +"servers can found at [citetitle]_www.pool.ntp.org_." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:14 +msgid "" +"Accurate time keeping is important for a number of reasons in IT. In " +"networking for example, accurate time stamps in packets and logs are " +"required. Logs are used to investigate service and security issues and so " +"time stamps made on different systems must be made by synchronized clocks to " +"be of real value. As systems and networks become increasingly faster, there " +"is a corresponding need for clocks with greater accuracy and resolution. In " +"some countries there are legal obligations to keep accurately synchronized " +"clocks. Please see [citetitle]_www.ntp.org_ for more information. In Linux " +"systems, `NTP` is implemented by a daemon running in user space. The default " +"`NTP` user space daemon in {MAJOROSVER} is `chronyd`. It must be disabled if " +"you want to use the `ntpd` daemon. See " +"xref:servers/Configuring_NTP_Using_the_chrony_Suite.adoc#ch-Configuring_NTP_Using_the_chrony_Suite[Configuring " +"NTP Using the chrony Suite] for information on [application]*chrony*." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:16 +msgid "" +"The user space daemon updates the system clock, which is a software clock " +"running in the kernel. Linux uses a software clock as its system clock for " +"better resolution than the typical embedded hardware clock referred to as " +"the \"`pass:attributes[{blank}]_Real Time Clock_pass:attributes[{blank}]`\" " +"*(RTC)*. See the `rtc(4)` and `hwclock(8)` man pages for information on " +"hardware clocks. The system clock can keep time by using various clock " +"sources. Usually, the _Time Stamp Counter_ (*TSC*) is used. The TSC is a CPU " +"register which counts the number of cycles since it was last reset. It is " +"very fast, has a high resolution, and there are no interrupts. On system " +"start, the system clock reads the time and date from the RTC. The time kept " +"by the RTC will drift away from actual time by up to 5 minutes per month due " +"to temperature variations. Hence the need for the system clock to be " +"constantly synchronized with external time references. When the system clock " +"is being synchronized by `ntpd`, the kernel will in turn update the RTC " +"every 11 minutes automatically." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:18 +#, no-wrap +msgid "NTP Strata" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:21 +msgid "" +"`NTP` servers are classified according to their synchronization distance " +"from the atomic clocks which are the source of the time signals. The servers " +"are thought of as being arranged in layers, or strata, from 1 at the top " +"down to 15. Hence the word stratum is used when referring to a specific " +"layer. Atomic clocks are referred to as Stratum 0 as this is the source, but " +"no Stratum 0 packet is sent on the Internet, all stratum 0 atomic clocks are " +"attached to a server which is referred to as stratum 1. These servers send " +"out packets marked as Stratum 1. A server which is synchronized by means of " +"packets marked stratum `n` belongs to the next, lower, stratum and will mark " +"its packets as stratum `n+1`. Servers of the same stratum can exchange " +"packets with each other but are still designated as belonging to just the " +"one stratum, the stratum one below the best reference they are synchronized " +"to. The designation Stratum 16 is used to indicate that the server is not " +"currently synchronized to a reliable time source." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:23 +msgid "" +"Note that by default `NTP` clients act as servers for those systems in the " +"stratum below them." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:25 +msgid "Here is a summary of the `NTP` Strata:" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:26 +#, no-wrap +msgid "Stratum 0" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:27 +msgid "Atomic Clocks and their signals broadcast over Radio and GPS" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:29 +msgid "GPS (Global Positioning System)" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:31 +msgid "Mobile Phone Systems" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:34 +msgid "" +"Low Frequency Radio Broadcasts+ WWVB (Colorado, USA.), JJY-40 and JJY-60 " +"(Japan), DCF77 (Germany), and MSF (United Kingdom)" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:36 +msgid "" +"These signals can be received by dedicated devices and are usually connected " +"by RS-232 to a system used as an organizational or site-wide time server." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:37 +#, no-wrap +msgid "Stratum 1" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:38 +msgid "Computer with radio clock, GPS clock, or atomic clock attached" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:39 +#, no-wrap +msgid "Stratum 2" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:40 +msgid "Reads from stratum 1; Serves to lower strata" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:41 +#, no-wrap +msgid "Stratum 3" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:42 +msgid "Reads from stratum 2; Serves to lower strata" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:43 +#, no-wrap +msgid "Stratum _n+1_" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:44 +msgid "Reads from stratum _n_pass:attributes[{blank}]; Serves to lower strata" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:45 +#, no-wrap +msgid "Stratum 15" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:46 +msgid "Reads from stratum 14; This is the lowest stratum." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:48 +msgid "" +"This process continues down to Stratum 15 which is the lowest valid " +"stratum. The label Stratum 16 is used to indicated an unsynchronized state." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:50 +#, no-wrap +msgid "Understanding NTP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:54 +msgid "" +"The version of `NTP` used by {MAJOROS} is as described in " +"[citetitle]_link:++https://www.rfc-editor.org/info/rfc1305++[RFC 1305 " +"Network Time Protocol (Version 3) Specification, Implementation and " +"Analysis]_ and " +"[citetitle]_link:++https://www.rfc-editor.org/info/rfc5905++[RFC 5905 " +"Network Time Protocol Version 4: Protocol and Algorithms Specification]_" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:56 +msgid "" +"This implementation of `NTP` enables sub-second accuracy to be " +"achieved. Over the Internet, accuracy to 10s of milliseconds is normal. On a " +"Local Area Network (LAN), 1 ms accuracy is possible under ideal " +"conditions. This is because clock drift is now accounted and corrected for, " +"which was not done in earlier, simpler, time protocol systems. A resolution " +"of 233 picoseconds is provided by using 64-bit time stamps. The first " +"32-bits of the time stamp is used for seconds, the last 32-bits are used for " +"fractions of seconds." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:58 +msgid "" +"`NTP` represents the time as a count of the number of seconds since 00:00 " +"(midnight) 1 January, 1900 GMT. As 32-bits is used to count the seconds, " +"this means the time will \"`roll over`\" in 2036. However `NTP` works on the " +"difference between time stamps so this does not present the same level of " +"problem as other implementations of time protocols have done. If a hardware " +"clock that is within 68 years of the correct time is available at boot time " +"then `NTP` will correctly interpret the current date. The `NTP4` " +"specification provides for an \"`Era Number`\" and an \"`Era Offset`\" which " +"can be used to make software more robust when dealing with time lengths of " +"more than 68 years. Note, please do not confuse this with the Unix Year 2038 " +"problem." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:60 +msgid "" +"The `NTP` protocol provides additional information to improve accuracy. Four " +"time stamps are used to allow the calculation of round-trip time and server " +"response time. In order for a system in its role as `NTP` client to " +"synchronize with a reference time server, a packet is sent with an " +"\"`originate time stamp`\". When the packet arrives, the time server adds a " +"\"`receive time stamp`\". After processing the request for time and date " +"information and just before returning the packet, it adds a \"`transmit time " +"stamp`\". When the returning packet arrives at the `NTP` client, a " +"\"`receive time stamp`\" is generated. The client can now calculate the " +"total round trip time and by subtracting the processing time derive the " +"actual traveling time. By assuming the outgoing and return trips take equal " +"time, the single-trip delay in receiving the `NTP` data is calculated. The " +"full `NTP` algorithm is much more complex than presented here." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:62 +msgid "" +"When a packet containing time information is received it is not immediately " +"responded to, but is first subject to validation checks and then processed " +"together with several other time samples to arrive at an estimate of the " +"time. This is then compared to the system clock to determine the time " +"offset, the difference between the system clock's time and what `ntpd` has " +"determined the time should be. The system clock is adjusted slowly, at most " +"at a rate of 0.5ms per second, to reduce this offset by changing the " +"frequency of the counter being used. It will take at least 2000 seconds to " +"adjust the clock by 1 second using this method. This slow change is referred " +"to as slewing and cannot go backwards. If the time offset of the clock is " +"more than 128ms (the default setting), `ntpd` can \"`step`\" the clock " +"forwards or backwards. If the time offset at system start is greater than " +"1000 seconds then the user, or an installation script, should make a manual " +"adjustment. See " +"xref:basic-system-configuration/Configuring_the_Date_and_Time.adoc#ch-Configuring_the_Date_and_Time[Configuring " +"the Date and Time]. With the [option]`-g` option to the [command]#ntpd# " +"command (used by default), any offset at system start will be corrected, but " +"during normal operation only offsets of up to 1000 seconds will be " +"corrected." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:64 +msgid "" +"Some software may fail or produce an error if the time is changed " +"backwards. For systems that are sensitive to step changes in the time, the " +"threshold can be changed to 600s instead of 128ms using the [option]`-x` " +"option (unrelated to the [option]`-g` option). Using the [option]`-x` option " +"to increase the stepping limit from 0.128s to 600s has a drawback because a " +"different method of controlling the clock has to be used. It disables the " +"kernel clock discipline and may have a negative impact on the clock " +"accuracy. The [option]`-x` option can be added to the `/etc/sysconfig/ntpd` " +"configuration file." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:66 +#, no-wrap +msgid "Understanding the Drift File" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:69 +msgid "" +"The drift file is used to store the frequency offset between the system " +"clock running at its nominal frequency and the frequency required to remain " +"in synchronization with UTC. If present, the value contained in the drift " +"file is read at system start and used to correct the clock source. Use of " +"the drift file reduces the time required to achieve a stable and accurate " +"time. The value is calculated, and the drift file replaced, once per hour by " +"`ntpd`. The drift file is replaced, rather than just updated, and for this " +"reason the drift file must be in a directory for which the `ntpd` has write " +"permissions." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:71 +#, no-wrap +msgid "UTC, Timezones, and DST" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:74 +msgid "" +"As `NTP` is entirely in UTC (Universal Time, Coordinated), Timezones and DST " +"(Daylight Saving Time) are applied locally by the system. The file " +"`/etc/localtime` is a copy of, or symlink to, a zone information file from " +"`/usr/share/zoneinfo`. The RTC may be in localtime or in UTC, as specified " +"by the 3rd line of `/etc/adjtime`, which will be one of LOCAL or UTC to " +"indicate how the RTC clock has been set. Users can easily change this " +"setting using the checkbox `System Clock Uses UTC` in the [application]*Date " +"and Time* graphical configuration tool. See " +"xref:basic-system-configuration/Configuring_the_Date_and_Time.adoc#ch-Configuring_the_Date_and_Time[Configuring " +"the Date and Time] for information on how to use that tool. Running the RTC " +"in UTC is recommended to avoid various problems when daylight saving time is " +"changed." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:76 +msgid "" +"The operation of `ntpd` is explained in more detail in the man page " +"`ntpd(8)`. The resources section lists useful sources of information. See " +"xref:Configuring_NTP_Using_ntpd.adoc#s1-ntpd_additional-resources[Additional " +"Resources]." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:78 +#, no-wrap +msgid "Authentication Options for NTP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:81 +msgid "" +"`NTPv4` added support for the Autokey Security Architecture, which is based " +"on public asymmetric cryptography while retaining support for symmetric key " +"cryptography. The Autokey Security Architecture is described in " +"[citetitle]_link:++https://www.rfc-editor.org/info/rfc5906++[RFC 5906 " +"Network Time Protocol Version 4: Autokey Specification]_. The man page " +"`ntp_auth(5)` describes the authentication options and commands for `ntpd`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:83 +msgid "" +"An attacker on the network can attempt to disrupt a service by sending `NTP` " +"packets with incorrect time information. On systems using the public pool of " +"`NTP` servers, this risk is mitigated by having more than three `NTP` " +"servers in the list of public `NTP` servers in `/etc/ntp.conf`. If only one " +"time source is compromised or spoofed, `ntpd` will ignore that source. You " +"should conduct a risk assessment and consider the impact of incorrect time " +"on your applications and organization. If you have internal time sources you " +"should consider steps to protect the network over which the `NTP` packets " +"are distributed. If you conduct a risk assessment and conclude that the risk " +"is acceptable, and the impact to your applications minimal, then you can " +"choose not to use authentication." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:85 +msgid "" +"The broadcast and multicast modes require authentication by default. If you " +"have decided to trust the network then you can disable authentication by " +"using [command]#disable auth# directive in the `ntp.conf` " +"file. Alternatively, authentication needs to be configured by using SHA1 or " +"MD5 symmetric keys, or by public (asymmetric) key cryptography using the " +"Autokey scheme. The Autokey scheme for asymmetric cryptography is explained " +"in the `ntp_auth(8)` man page and the generation of keys is explained in " +"`ntp-keygen(8`). To implement symmetric key cryptography, see " +"xref:Configuring_NTP_Using_ntpd.adoc#s2_Configuring_Symmetric_Authentication_Using_a_Key[Configuring " +"Symmetric Authentication Using a Key] for an explanation of the " +"[option]`key` option." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:87 +#, no-wrap +msgid "Managing the Time on Virtual Machines" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:90 +msgid "" +"Virtual machines cannot access a real hardware clock and a virtual clock is " +"not stable enough as the stability is dependent on the host systems work " +"load. For this reason, para-virtualized clocks should be provided by the " +"virtualization application in use (for more information see " +"_https://docs.fedoraproject.org/en-US/Fedora/18/html/Virtualization_Administration_Guide/sect-Virtualization-Tips_and_tricks-Libvirt_Managed_Timers.html[Libvirt " +"Managed Timers]_ in the _Virtualization Administration Guide_). On {MAJOROS} " +"with [application]*KVM* the default clock source is [option]`kvm-clock`. See " +"the " +"[citetitle]_link:++https://docs.fedoraproject.org/en-US/Fedora/13/html/Virtualization_Guide/chap-Virtualization-KVM_guest_timing_management.html++[KVM " +"guest timing management]_ chapter of the [citetitle]_Virtualization Host " +"Configuration and Guest Installation Guide_." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:92 +#, no-wrap +msgid "Understanding Leap Seconds" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:95 +msgid "" +"Greenwich Mean Time (GMT) was derived by measuring the solar day, which is " +"dependent on the Earth's rotation. When atomic clocks were first made, the " +"potential for more accurate definitions of time became possible. In 1958, " +"International Atomic Time (TAI) was introduced based on the more accurate " +"and very stable atomic clocks. A more accurate astronomical time, Universal " +"Time 1 (UT1), was also introduced to replace GMT. The atomic clocks are in " +"fact far more stable than the rotation of the Earth and so the two times " +"began to drift apart. For this reason UTC was introduced as a practical " +"measure. It is kept within one second of UT1 but to avoid making many small " +"trivial adjustments it was decided to introduce the concept of a _leap " +"second_ in order to reconcile the difference in a manageable way. The " +"difference between UT1 and UTC is monitored until they drift apart by more " +"than half a second. Then only is it deemed necessary to introduce a one " +"second adjustment, forward or backward. Due to the erratic nature of the " +"Earth's rotational speed, the need for an adjustment cannot be predicted far " +"into the future. The decision as to when to make an adjustment is made by " +"the [citetitle]_link:++https://www.iers.org++[International Earth Rotation " +"and Reference Systems Service (IERS)]_. However, these announcements are " +"important only to administrators of Stratum 1 servers because `NTP` " +"transmits information about pending leap seconds and applies them " +"automatically." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:97 +#, no-wrap +msgid "Understanding the ntpd Configuration File" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:100 +msgid "" +"The daemon, `ntpd`, reads the configuration file at system start or when the " +"service is restarted. The default location for the file is `/etc/ntp.conf` " +"and you can view the file by entering the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:104 +#, no-wrap +msgid "~]${nbsp}pass:attributes[{blank}][command]#less /etc/ntp.conf#\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:107 +msgid "" +"The configuration commands are explained briefly later in this chapter, see " +"xref:Configuring_NTP_Using_ntpd.adoc#s1-Configure_NTP[Configure NTP], and " +"more verbosely in the `ntp.conf(5)` man page." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:109 +msgid "" +"Here follows a brief explanation of the contents of the default " +"configuration file:" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:110 +#, no-wrap +msgid "The driftfile entry" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:111 +msgid "A path to the drift file is specified, the default entry on {MAJOROS} is:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:115 +#, no-wrap +msgid "driftfile /var/lib/ntp/drift\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:120 +msgid "" +"If you change this be certain that the directory is writable by `ntpd`. The " +"file contains one value used to adjust the system clock frequency after " +"every system or service start. See " +"xref:Configuring_NTP_Using_ntpd.adoc#s1-Understanding_the_Drift_File[Understanding " +"the Drift File] for more information." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:121 +#, no-wrap +msgid "The access control entries" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:122 +msgid "The following line sets the default access control restriction:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:126 +#, no-wrap +msgid "restrict default nomodify notrap nopeer noquery\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:129 +msgid "The [option]`nomodify` options prevents any changes to the configuration." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:131 +msgid "The [option]`notrap` option prevents `ntpdc` control message protocol traps." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:133 +msgid "The [option]`nopeer` option prevents a peer association being formed." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:135 +msgid "" +"The [option]`noquery` option prevents `ntpq` and `ntpdc` queries, but not " +"time queries, from being answered." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:140 +msgid "" +"The `ntpq` and `ntpdc` queries can be used in amplification attacks, " +"therefore do not remove the [option]`noquery` option from the " +"[command]#restrict default# command on publicly accessible systems." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:142 +msgid "" +"See " +"[citetitle]_link:++https://access.redhat.com/security/cve/CVE-2013-5211++[CVE-2013-5211]_ " +"for more details." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:146 +msgid "" +"Addresses within the range `127.0.0.0/8` are sometimes required by various " +"processes or applications. As the \"`restrict default`\" line above prevents " +"access to everything not explicitly allowed, access to the standard loopback " +"address for `IPv4` and `IPv6` is permitted by means of the following lines:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:151 +#, no-wrap +msgid "" +"# the administrative functions.\n" +"restrict 127.0.0.1\n" +"restrict ::1\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:154 +msgid "" +"Addresses can be added underneath if specifically required by another " +"application." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:156 +msgid "" +"Hosts on the local network are not permitted because of the \"`restrict " +"default`\" line above. To change this, for example to allow hosts from the " +"`192.0.2.0/24` network to query the time and statistics but nothing more, a " +"line in the following format is required:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:160 +#, no-wrap +msgid "restrict 192.0.2.0 mask 255.255.255.0 nomodify notrap nopeer\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:163 +msgid "" +"To allow unrestricted access from a specific host, for example " +"`192.0.2.250/32`, a line in the following format is required:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:167 +#, no-wrap +msgid "restrict 192.0.2.250\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:170 +msgid "A mask of `255.255.255.255` is applied if none is specified." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:172 +msgid "The restrict commands are explained in the `ntp_acc(5)` man page." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:173 +#, no-wrap +msgid "The public servers entry" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:174 +msgid "By default, the `ntp.conf` file contains four public server entries:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:182 +#, no-wrap +msgid "" +"server 0.fedora.pool.ntp.org iburst\n" +"server 1.fedora.pool.ntp.org iburst\n" +"server 2.fedora.pool.ntp.org iburst\n" +"server 3.fedora.pool.ntp.org iburst\n" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:184 +#, no-wrap +msgid "The broadcast multicast servers entry" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:185 +msgid "" +"By default, the `ntp.conf` file contains some commented out examples. These " +"are largely self explanatory. See " +"xref:Configuring_NTP_Using_ntpd.adoc#s1-Configure_NTP[Configure NTP] for the " +"explanation of the specific commands. If required, add your commands just " +"below the examples." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:190 +msgid "" +"When the `DHCP` client program, [application]*dhclient*, receives a list of " +"`NTP` servers from the `DHCP` server, it adds them to `ntp.conf` and " +"restarts the service. To disable that feature, add [command]#PEERNTP=no# to " +"`/etc/sysconfig/network`." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:194 +#, no-wrap +msgid "Understanding the ntpd Sysconfig File" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:197 +msgid "" +"The file will be read by the `ntpd` init script on service start. The " +"default contents is as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:201 +#, no-wrap +msgid "" +"# Command line options for ntpd\n" +"OPTIONS=\"-g\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:204 +msgid "" +"The [option]`-g` option enables `ntpd` to ignore the offset limit of 1000s " +"and attempt to synchronize the time even if the offset is larger than 1000s, " +"but only on system start. Without that option [application]*ntpd* will exit " +"if the time offset is greater than 1000s. It will also exit after system " +"start if the service is restarted and the offset is greater than 1000s even " +"with the [option]`-g` option." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:206 +#, no-wrap +msgid "Disabling chrony" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:209 +msgid "" +"In order to use `ntpd` the default user space daemon, `chronyd`, must be " +"stopped and disabled. Issue the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:213 +#, no-wrap +msgid "~]#{nbsp}systemctl stop chronyd\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:216 +msgid "" +"To prevent it restarting at system start, issue the following command as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:220 +#, no-wrap +msgid "~]#{nbsp}systemctl disable chronyd\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:223 +msgid "To check the status of `chronyd`, issue the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:227 +#, no-wrap +msgid "~]${nbsp}pass:attributes[{blank}][command]#systemctl status chronyd#\n" +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:230 +#, no-wrap +msgid "Checking if the NTP Daemon is Installed" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:233 +msgid "To check if `ntpd` is installed, enter the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:237 +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:249 +#, no-wrap +msgid "~]#{nbsp}dnf install ntp\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:240 +msgid "" +"`NTP` is implemented by means of the daemon or service `ntpd`, which is " +"contained within the [package]*ntp* package." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:242 +#, no-wrap +msgid "Installing the NTP Daemon (ntpd)" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:245 +msgid "To install `ntpd`, enter the following command as `root`:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:252 +msgid "To enable `ntpd` at system start, enter the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:256 +#, no-wrap +msgid "~]#{nbsp}systemctl enable ntpd\n" +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:259 +#, no-wrap +msgid "Checking the Status of NTP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:262 +msgid "" +"To check if `ntpd` is running and configured to run at system start, issue " +"the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:266 +#, no-wrap +msgid "~]${nbsp}pass:attributes[{blank}][command]#systemctl status ntpd#\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:269 +msgid "To obtain a brief status report from `ntpd`, issue the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:276 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#ntpstat#\n" +"unsynchronised\n" +" time server re-starting\n" +" polling server every 64 s\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:284 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#ntpstat#\n" +"synchronised to NTP server (10.5.26.10) at stratum 2\n" +" time correct to within 52 ms\n" +" polling server every 1024 s\n" +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:287 +#, no-wrap +msgid "Configure the Firewall to Allow Incoming NTP Packets" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:290 +msgid "" +"The `NTP` traffic consists of `UDP` packets on port `123` and needs to be " +"permitted through network and host-based firewalls in order for `NTP` to " +"function." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:292 +msgid "" +"Check if the firewall is configured to allow incoming `NTP` traffic for " +"clients using the graphical [application]*Firewall Configuration* tool." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:294 +msgid "" +"To start the graphical [application]*firewall-config* tool, press the " +"kbd:[Super] key to enter the Activities Overview, type [command]#firewall# " +"and then press kbd:[Enter]. The `Firewall Configuration` window opens. You " +"will be prompted for your user password." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:296 +msgid "" +"To start the graphical firewall configuration tool using the command line, " +"enter the following command as `root` user:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:300 +#, no-wrap +msgid "~]#{nbsp}firewall-config\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:303 +msgid "" +"The `Firewall Configuration` window opens. Note, this command can be run as " +"normal user but you will then be prompted for the `root` password from time " +"to time." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:305 +msgid "" +"Look for the word \"`Connected`\" in the lower left corner. This indicates " +"that the [application]*firewall-config* tool is connected to the user space " +"daemon, `firewalld`." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:307 +#, no-wrap +msgid "Change the Firewall Settings" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:310 +msgid "" +"To immediately change the current firewall settings, ensure the drop-down " +"selection menu labeled `Configuration` is set to `Runtime`. Alternatively, " +"to edit the settings to be applied at the next system start, or firewall " +"reload, select `Permanent` from the drop-down list." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:315 +msgid "" +"When making changes to the firewall settings in `Runtime` mode, your " +"selection takes immediate effect when you set or clear the check box " +"associated with the service. You should keep this in mind when working on a " +"system that may be in use by other users." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:317 +msgid "" +"When making changes to the firewall settings in `Permanent` mode, your " +"selection will only take effect when you reload the firewall or the system " +"restarts. To reload the firewall, select the Options menu and select `Reload " +"Firewall`." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:321 +#, no-wrap +msgid "Open Ports in the Firewall for NTP Packets" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:324 +msgid "" +"To permit traffic through the firewall to a certain port, start the " +"[application]*firewall-config* tool and select the network zone whose " +"settings you want to change. Select the `Ports` tab and then click the " +"btn:[Add] button. The `Port and Protocol` window opens." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:326 +msgid "Enter the port number `123` and select `udp` from the drop-down list." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:328 +#, no-wrap +msgid "Configure ntpdate Servers" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:331 +msgid "" +"The purpose of the `ntpdate` service is to set the clock during system " +"boot. This was used previously to ensure that the services started after " +"`ntpdate` would have the correct time and not observe a jump in the " +"clock. The use of `ntpdate` and the list of step-tickers is considered " +"deprecated and so Fedora uses the [option]`-g` option to the [command]#ntpd# " +"command and not `ntpdate` by default." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:333 +msgid "" +"The `ntpdate` service in Fedora is mostly useful only when used alone " +"without `ntpd`. With [application]*systemd*, which starts services in " +"parallel, enabling the `ntpdate` service will not ensure that other services " +"started after it will have correct time unless they specify an ordering " +"dependency on `time-sync.target`, which is provided by the `ntpdate` " +"service. The `ntp-wait` service (in the [package]*ntp-perl* subpackage) " +"provides the `time-sync` target for the `ntpd` service. In order to ensure a " +"service starts with correct time, add `After=time-sync.target` to the " +"service and enable one of the services which provide the target (`ntpdate` " +"or [application]*sntp*, or [application]*ntp-wait* if `ntpd` is " +"enabled). Some services on Fedora have the dependency included by default ( " +"for example, `dhcpd`, `dhcpd6`, and `crond`)." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:335 +msgid "" +"To check if the `ntpdate` service is enabled to run at system start, issue " +"the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:339 +#, no-wrap +msgid "~]${nbsp}pass:attributes[{blank}][command]#systemctl status ntpdate#\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:342 +msgid "" +"To enable the service to run at system start, issue the following command as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:346 +#, no-wrap +msgid "~]#{nbsp}systemctl enable ntpdate\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:349 +msgid "" +"In Fedora the default `/etc/ntp/step-tickers` file contains " +"`0.fedora.pool.ntp.org`. To configure additional `ntpdate` servers, using a " +"text editor running as `root`, edit `/etc/ntp/step-tickers`. The number of " +"servers listed is not very important as `ntpdate` will only use this to " +"obtain the date information once when the system is starting. If you have an " +"internal time server then use that host name for the first line. An " +"additional host on the second line as a backup is sensible. The selection of " +"backup servers and whether the second host is internal or external depends " +"on your risk assessment. For example, what is the chance of any problem " +"affecting the first server also affecting the second server? Would " +"connectivity to an external server be more likely to be available than " +"connectivity to internal servers in the event of a network failure " +"disrupting access to the first server?" +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:351 +#, no-wrap +msgid "Configure NTP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:354 +msgid "" +"To change the default configuration of the `NTP` service, use a text editor " +"running as `root` user to edit the `/etc/ntp.conf` file. This file is " +"installed together with `ntpd` and is configured to use time servers from " +"the Fedora pool by default. The man page `ntp.conf(5)` describes the command " +"options that can be used in the configuration file apart from the access and " +"rate limiting commands which are explained in the `ntp_acc(5)` man page." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:356 +#, no-wrap +msgid "Configure Access Control to an NTP Service" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:359 +msgid "" +"To restrict or control access to the `NTP` service running on a system, make " +"use of the [command]#restrict# command in the `ntp.conf` file. See the " +"commented out example:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:364 +#, no-wrap +msgid "" +"# Hosts on local network are less restricted.\n" +"#restrict 192.168.1.0 mask 255.255.255.0 nomodify notrap\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:367 +msgid "The [command]#restrict# command takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:371 +#, no-wrap +msgid "[command]#restrict# _option_\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:374 +msgid "where _option_ is one or more of:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:376 +msgid "" +"[option]`ignore` — All packets will be ignored, including `ntpq` and " +"`ntpdc` queries." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:378 +msgid "" +"[option]`kod` — a \"`Kiss-o'-death`\" packet is to be sent to reduce " +"unwanted queries." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:380 +msgid "" +"[option]`limited` — do not respond to time service requests if the " +"packet violates the rate limit default values or those specified by the " +"[command]#discard# command. `ntpq` and `ntpdc` queries are not affected. For " +"more information on the [command]#discard# command and the default values, " +"see " +"xref:Configuring_NTP_Using_ntpd.adoc#s2_Configure_Rate_Limiting_Access_to_an_NTP_Service[Configure " +"Rate Limiting Access to an NTP Service]." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:382 +msgid "" +"[option]`lowpriotrap` — traps set by matching hosts to be low " +"priority." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:384 +msgid "[option]`nomodify` — prevents any changes to the configuration." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:386 +msgid "" +"[option]`noquery` — prevents `ntpq` and `ntpdc` queries, but not time " +"queries, from being answered." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:388 +msgid "[option]`nopeer` — prevents a peer association being formed." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:390 +msgid "" +"[option]`noserve` — deny all packets except `ntpq` and `ntpdc` " +"queries." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:392 +msgid "[option]`notrap` — prevents `ntpdc` control message protocol traps." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:394 +msgid "" +"[option]`notrust` — deny packets that are not cryptographically " +"authenticated." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:396 +msgid "" +"[option]`ntpport` — modify the match algorithm to only apply the " +"restriction if the source port is the standard `NTP` `UDP` port `123`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:398 +msgid "" +"[option]`version` — deny packets that do not match the current `NTP` " +"version." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:400 +msgid "" +"To configure rate limit access to not respond at all to a query, the " +"respective [command]#restrict# command has to have the [option]`limited` " +"option. If `ntpd` should reply with a `KoD` packet, the [command]#restrict# " +"command needs to have both [option]`limited` and [option]`kod` options." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:402 +msgid "" +"The `ntpq` and `ntpdc` queries can be used in amplification attacks (see " +"[citetitle]_link:++https://access.redhat.com/security/cve/CVE-2013-5211++[CVE-2013-5211]_ " +"for more details), do not remove the [option]`noquery` option from the " +"[command]#restrict default# command on publicly accessible systems." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:404 +#, no-wrap +msgid "Configure Rate Limiting Access to an NTP Service" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:407 +msgid "" +"To enable rate limiting access to the `NTP` service running on a system, add " +"the [option]`limited` option to the [command]#restrict# command as explained " +"in " +"xref:Configuring_NTP_Using_ntpd.adoc#s2-Configure_Access_Control_to_an_NTP_service[Configure " +"Access Control to an NTP Service]. If you do not want to use the default " +"discard parameters, then also use the [command]#discard# command as " +"explained here." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:409 +msgid "The [command]#discard# command takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:413 +#, no-wrap +msgid "" +"[command]#discard# [option]`average` _value_ [option]`minimum` _value_ " +"[option]`monitor` _value_\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:416 +msgid "" +"[option]`average` — specifies the minimum average packet spacing to be " +"permitted, it accepts an argument in _log2_ seconds. The default value is 3 " +"(_2pass:attributes[{blank}]^3^pass:attributes[{blank}]_ equates to 8 " +"seconds)." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:418 +msgid "" +"[option]`minimum` — specifies the minimum packet spacing to be " +"permitted, it accepts an argument in _log2_ seconds. The default value is 1 " +"(_2pass:attributes[{blank}]^1^pass:attributes[{blank}]_ equates to 2 " +"seconds)." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:420 +msgid "" +"[option]`monitor` — specifies the discard probability for packets once " +"the permitted rate limits have been exceeded. The default value is 3000 " +"seconds. This option is intended for servers that receive 1000 or more " +"requests per second." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:422 +msgid "Examples of the [command]#discard# command are as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:426 +#, no-wrap +msgid "discard average 4\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:431 +#, no-wrap +msgid "discard average 4 minimum 2\n" +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:434 +#, no-wrap +msgid "Adding a Peer Address" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:437 +msgid "" +"To add the address of a peer, that is to say, the address of a server " +"running an `NTP` service of the same stratum, make use of the " +"[command]#peer# command in the `ntp.conf` file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:439 +msgid "The [command]#peer# command takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:443 +#, no-wrap +msgid "[command]#peer# _address_\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:446 +msgid "" +"where _address_ is an `IP` unicast address or a `DNS` resolvable name. The " +"address must only be that of a system known to be a member of the same " +"stratum. Peers should have at least one time source that is different to " +"each other. Peers are normally systems under the same administrative " +"control." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:448 +#, no-wrap +msgid "Adding a Server Address" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:451 +msgid "" +"To add the address of a server, that is to say, the address of a server " +"running an `NTP` service of a higher stratum, make use of the " +"[command]#server# command in the `ntp.conf` file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:453 +msgid "The [command]#server# command takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:457 +#, no-wrap +msgid "[command]#server# _address_\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:461 +msgid "" +"where _address_ is an `IP` unicast address or a `DNS` resolvable name. The " +"address of a remote reference server or local reference clock from which " +"packets are to be received." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:463 +#, no-wrap +msgid "Adding a Broadcast or Multicast Server Address" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:466 +msgid "" +"To add a broadcast or multicast address for sending, that is to say, the " +"address to broadcast or multicast `NTP` packets to, make use of the " +"[command]#broadcast# command in the `ntp.conf` file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:468 +msgid "" +"The broadcast and multicast modes require authentication by default. See " +"xref:Configuring_NTP_Using_ntpd.adoc#s1-Authentication_Options_for_NTP[Authentication " +"Options for NTP]." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:470 +msgid "The [command]#broadcast# command takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:474 +#, no-wrap +msgid "[command]#broadcast# _address_\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:477 +msgid "" +"where _address_ is an `IP` broadcast or multicast address to which packets " +"are sent." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:479 +msgid "" +"This command configures a system to act as an `NTP` broadcast server. The " +"address used must be a broadcast or a multicast address. Broadcast address " +"implies the `IPv4` address `255.255.255.255`. By default, routers do not " +"pass broadcast messages. The multicast address can be an `IPv4` Class D " +"address, or an `IPv6` address. The IANA has assigned `IPv4` multicast " +"address `224.0.1.1` and `IPv6` address `FF05::101` (site local) to " +"`NTP`. Administratively scoped `IPv4` multicast addresses can also be used, " +"as described in " +"[citetitle]_link:++https://www.rfc-editor.org/info/rfc2365++[RFC 2365 " +"Administratively Scoped IP Multicast]_." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:481 +#, no-wrap +msgid "Adding a Manycast Client Address" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:484 +msgid "" +"To add a manycast client address, that is to say, to configure a multicast " +"address to be used for `NTP` server discovery, make use of the " +"[command]#manycastclient# command in the `ntp.conf` file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:486 +msgid "The [command]#manycastclient# command takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:490 +#, no-wrap +msgid "[command]#manycastclient# _address_\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:494 +msgid "" +"where _address_ is an `IP` multicast address from which packets are to be " +"received. The client will send a request to the address and select the best " +"servers from the responses and ignore other servers. `NTP` communication " +"then uses unicast associations, as if the discovered `NTP` servers were " +"listed in `ntp.conf`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:496 +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:512 +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:544 +msgid "" +"This command configures a system to act as an `NTP` client. Systems can be " +"both client and server at the same time." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:498 +#, no-wrap +msgid "Adding a Broadcast Client Address" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:501 +msgid "" +"To add a broadcast client address, that is to say, to configure a broadcast " +"address to be monitored for broadcast `NTP` packets, make use of the " +"[command]#broadcastclient# command in the `ntp.conf` file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:503 +msgid "The [command]#broadcastclient# command takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:507 +#, no-wrap +msgid "[command]#broadcastclient#\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:510 +msgid "" +"Enables the receiving of broadcast messages. Requires authentication by " +"default. See " +"xref:Configuring_NTP_Using_ntpd.adoc#s1-Authentication_Options_for_NTP[Authentication " +"Options for NTP]." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:514 +#, no-wrap +msgid "Adding a Manycast Server Address" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:517 +msgid "" +"To add a manycast server address, that is to say, to configure an address to " +"allow the clients to discover the server by multicasting `NTP` packets, make " +"use of the [command]#manycastserver# command in the `ntp.conf` file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:519 +msgid "The [command]#manycastserver# command takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:523 +#, no-wrap +msgid "[command]#manycastserver# _address_\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:526 +msgid "" +"Enables the sending of multicast messages. Where _address_ is the address to " +"multicast to. This should be used together with authentication to prevent " +"service disruption." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:528 +msgid "" +"This command configures a system to act as an `NTP` server. Systems can be " +"both client and server at the same time." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:530 +#, no-wrap +msgid "Adding a Multicast Client Address" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:533 +msgid "" +"To add a multicast client address, that is to say, to configure a multicast " +"address to be monitored for multicast `NTP` packets, make use of the " +"[command]#multicastclient# command in the `ntp.conf` file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:535 +msgid "The [command]#multicastclient# command takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:539 +#, no-wrap +msgid "[command]#multicastclient# _address_\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:542 +msgid "" +"Enables the receiving of multicast messages. Where _address_ is the address " +"to subscribe to. This should be used together with authentication to prevent " +"service disruption." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:546 +#, no-wrap +msgid "Configuring the Burst Option" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:549 +msgid "" +"Using the [command]#burst# option against a public server is considered " +"abuse. Do not use this option with public `NTP` servers. Use it only for " +"applications within your own organization." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:551 +msgid "" +"To increase the average quality of time offset statistics, add the following " +"option to the end of a server command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:555 +#, no-wrap +msgid "[command]#burst#\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:558 +msgid "" +"At every poll interval, when the server responds, the system will send a " +"burst of up to eight packets instead of the usual one packet. For use with " +"the [command]#server# command to improve the average quality of the " +"time-offset calculations." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:560 +#, no-wrap +msgid "Configuring the iburst Option" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:563 +msgid "" +"To improve the time taken for initial synchronization, add the following " +"option to the end of a server command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:567 +#, no-wrap +msgid "[command]#iburst#\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:570 +msgid "" +"At every poll interval, send a burst of eight packets instead of one. When " +"the server is not responding, packets are sent 16s apart. When the server " +"responds, packets are sent every 2s. For use with the [command]#server# " +"command to reduce the time taken for initial synchronization. This is now a " +"default option in the configuration file." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:572 +#, no-wrap +msgid "Configuring Symmetric Authentication Using a Key" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:575 +msgid "" +"To configure symmetric authentication using a key, add the following option " +"to the end of a server or peer command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:579 +#, no-wrap +msgid "[command]#key# _number_\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:583 +msgid "" +"where _number_ is in the range `1` to `65534` inclusive. This option " +"enables the use of a _message authentication code_ (*MAC*) in packets. This " +"option is for use with the [command]#peer#, [command]#server#, " +"[command]#broadcast#, and [command]#manycastclient# commands." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:585 +msgid "The option can be used in the `/etc/ntp.conf` file as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:591 +#, no-wrap +msgid "" +"server 192.168.1.1 key 10\n" +"broadcast 192.168.1.255 key 20\n" +"manycastclient 239.255.254.254 key 30\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:594 +msgid "" +"See also " +"xref:Configuring_NTP_Using_ntpd.adoc#s1-Authentication_Options_for_NTP[Authentication " +"Options for NTP]." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:596 +#, no-wrap +msgid "Configuring the Poll Interval" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:599 +msgid "" +"To change the default poll interval, add the following options to the end of " +"a server or peer command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:603 +#, no-wrap +msgid "[command]#minpoll# _value_ and [command]#maxpoll# _value_\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:606 +msgid "" +"Options to change the default poll interval, where the interval in seconds " +"will be calculated by raising 2 to the power of _value_, in other words, the " +"interval is expressed in _log2_ seconds. The default [option]`minpoll` value " +"is 6, _2pass:attributes[{blank}]^6^pass:attributes[{blank}]_ equates to " +"64s. The default value for [option]`maxpoll` is 10, which equates to " +"1024s. Allowed values are in the range 3 to 17 inclusive, which equates to " +"8s to 36.4h respectively. These options are for use with the [command]#peer# " +"or [command]#server#. Setting a shorter [option]`maxpoll` may improve clock " +"accuracy." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:608 +#, no-wrap +msgid "Configuring Server Preference" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:611 +msgid "" +"To specify that a particular server should be preferred above others of " +"similar statistical quality, add the following option to the end of a server " +"or peer command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:615 +#, no-wrap +msgid "[command]#prefer#\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:618 +msgid "" +"Use this server for synchronization in preference to other servers of " +"similar statistical quality. This option is for use with the [command]#peer# " +"or [command]#server# commands." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:620 +#, no-wrap +msgid "Configuring the Time-to-Live for NTP Packets" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:623 +msgid "" +"To specify that a particular _time-to-live_ (*TTL*) value should be used in " +"place of the default, add the following option to the end of a server or " +"peer command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:627 +#, no-wrap +msgid "[command]#ttl# _value_\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:630 +msgid "" +"Specify the time-to-live value to be used in packets sent by broadcast " +"servers and multicast `NTP` servers. Specify the maximum time-to-live value " +"to use for the \"`expanding ring search`\" by a manycast client. The default " +"value is `127`." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:632 +#, no-wrap +msgid "Configuring the NTP Version to Use" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:635 +msgid "" +"To specify that a particular version of `NTP` should be used in place of the " +"default, add the following option to the end of a server or peer command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:639 +#, no-wrap +msgid "[command]#version# _value_\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:642 +msgid "" +"Specify the version of `NTP` set in created `NTP` packets. The value can be " +"in the range `1` to `4`. The default is `4`." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:644 +#, no-wrap +msgid "Configuring the Hardware Clock Update" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:647 +msgid "" +"To configure the system clock to update the hardware clock, also known as " +"the real-time clock (RTC), once after executing [application]*ntpdate*, add " +"the following line to `/etc/sysconfig/ntpdate`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:650 +#, no-wrap +msgid "SYNC_HWCLOCK=yes\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:653 +msgid "" +"To update the hardware clock from the system clock, issue the following " +"command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:657 +#, no-wrap +msgid "~]#{nbsp}hwclock --systohc\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:660 +msgid "" +"When the system clock is being synchronized by `ntpd` or `chronyd`, the " +"kernel will in turn update the RTC every 11 minutes automatically." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:662 +#, no-wrap +msgid "Configuring Clock Sources" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:665 +msgid "" +"To list the available clock sources on your system, issue the following " +"commands:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:673 +#, no-wrap +msgid "" +"~]${nbsp}cd /sys/devices/system/clocksource/clocksource0/\n" +"clocksource0]$ cat available_clocksource\n" +"kvm-clock tsc hpet acpi_pm\n" +"clocksource0]$ cat current_clocksource\n" +"kvm-clock\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:676 +msgid "" +"In the above example, the kernel is using [application]*kvm-clock*. This was " +"selected at boot time as this is a virtual machine." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:678 +msgid "" +"To override the default clock source, append the [command]#clocksource# " +"directive to the GRUB_CMDLINE_LINUX line in the `/etc/default/grub` file and " +"rebuild the `grub.cfg` file. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:682 +#, no-wrap +msgid "" +"GRUB_CMDLINE_LINUX=\"rd.lvm.lv=rhel/root crashkernel=auto " +"rd.lvm.lv=rhel/swap vconsole.font=latarcyrheb-sun16 vconsole.keymap=us rhgb " +"quiet pass:quotes[*clocksource=tsc*]\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:685 +msgid "The available clock source is architecture dependent." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:687 +msgid "Rebuild the `grub.cfg` file as follows:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:689 +msgid "On BIOS-based machines, issue the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:693 +#, no-wrap +msgid "~]#{nbsp}grub2-mkconfig -o /boot/grub2/grub.cfg\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:696 +msgid "On UEFI-based machines, issue the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:700 +#, no-wrap +msgid "~]#{nbsp}grub2-mkconfig -o /boot/efi/EFI/redhat/grub.cfg\n" +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:703 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:706 +msgid "" +"The following sources of information provide additional resources regarding " +"`NTP` and `ntpd`." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:708 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:711 +msgid "" +"`ntpd(8)` man page — Describes `ntpd` in detail, including the command line " +"options." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:713 +msgid "" +"`ntp.conf(5)` man page — Contains information on how to configure " +"associations with servers and peers." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:715 +msgid "" +"`ntpq(8)` man page — Describes the `NTP` query utility for monitoring and " +"querying an `NTP` server." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:717 +msgid "" +"`ntpdc(8)` man page — Describes the `ntpd` utility for querying and changing " +"the state of `ntpd`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:719 +msgid "" +"`ntp_auth(5)` man page — Describes authentication options, commands, and key " +"management for `ntpd`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:721 +msgid "" +"`ntp_keygen(8)` man page — Describes generating public and private keys for " +"`ntpd`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:723 +msgid "" +"`ntp_acc(5)` man page — Describes access control options using the " +"[command]#restrict# command." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:725 +msgid "" +"`ntp_mon(5)` man page — Describes monitoring options for the gathering of " +"statistics." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:727 +msgid "" +"`ntp_clock(5)` man page — Describes commands for configuring reference " +"clocks." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:729 +msgid "`ntp_misc(5)` man page — Describes miscellaneous options." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:731 +msgid "" +"`ntp_decode(5)` man page — Lists the status words, event messages and error " +"codes used for `ntpd` reporting and monitoring." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:733 +msgid "" +"`ntpstat(8)` man page — Describes a utility for reporting the " +"synchronization state of the `NTP` daemon running on the local machine." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:735 +msgid "" +"`ntptime(8)` man page — Describes a utility for reading and setting kernel " +"time variables." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:737 +msgid "" +"`tickadj(8)` man page — Describes a utility for reading, and optionally " +"setting, the length of the tick." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:739 +#, no-wrap +msgid "Useful Websites" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:741 +#, no-wrap +msgid "link:++http://doc.ntp.org/++[]" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:742 +msgid "The NTP Documentation Archive" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:743 +#, no-wrap +msgid "link:++https://www.eecis.udel.edu/~mills/ntp.html++[]" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:744 +msgid "Network Time Synchronization Research Project." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:745 +#, no-wrap +msgid "link:++https://www.eecis.udel.edu/~mills/ntp/html/manyopt.html++[]" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_ntpd.adoc:745 +msgid "Information on Automatic Server Discovery in `NTPv4`." +msgstr "" diff --git a/pot/rawhide/pages/servers/Configuring_NTP_Using_the_chrony_Suite.pot b/pot/rawhide/pages/servers/Configuring_NTP_Using_the_chrony_Suite.pot new file mode 100644 index 00000000000..9cb380ce7b2 --- /dev/null +++ b/pot/rawhide/pages/servers/Configuring_NTP_Using_the_chrony_Suite.pot @@ -0,0 +1,2129 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:6 +#, no-wrap +msgid "Configuring NTP Using the chrony Suite" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:9 +msgid "" +"Accurate time keeping is important for a number of reasons in IT. In " +"networking for example, accurate time stamps in packets and logs are " +"required. In Linux systems, the `NTP` protocol is implemented by a daemon " +"running in user space." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:11 +msgid "" +"The user space daemon updates the system clock running in the kernel. The " +"system clock can keep time by using various clock sources. Usually, the " +"_Time Stamp Counter_ (*TSC*) is used. The TSC is a CPU register which counts " +"the number of cycles since it was last reset. It is very fast, has a high " +"resolution, and there are no interrupts." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:13 +msgid "" +"There is a choice between the daemons `ntpd` and `chronyd`, which are " +"available from the repositories in the [package]*ntp* and [package]*chrony* " +"packages respectively. This section describes the use of the " +"[application]*chrony* suite of utilities to update the system clock on " +"systems that do not fit into the conventional permanently networked, always " +"on, dedicated server category." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:15 +#, no-wrap +msgid "Introduction to the chrony Suite" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:18 +msgid "" +"[application]*Chrony* consists of `chronyd`, a daemon that runs in user " +"space, and [application]*chronyc*, a command line program for making " +"adjustments to `chronyd`. Systems which are not permanently connected, or " +"not permanently powered up, take a relatively long time to adjust their " +"system clocks with `ntpd`. This is because many small corrections are made " +"based on observations of the clocks drift and offset. Temperature changes, " +"which may be significant when powering up a system, affect the stability of " +"hardware clocks. Although adjustments begin within a few milliseconds of " +"booting a system, acceptable accuracy may take anything from ten seconds " +"from a warm restart to a number of hours depending on your requirements, " +"operating environment and hardware. [application]*chrony* is a different " +"implementation of the `NTP` protocol than `ntpd`, it can adjust the system " +"clock more rapidly." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:20 +#, no-wrap +msgid "Differences Between ntpd and chronyd" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:23 +msgid "" +"One of the main differences between `ntpd` and `chronyd` is in the " +"algorithms used to control the computer's clock. Things `chronyd` can do " +"better than `ntpd` are:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:25 +msgid "" +"`chronyd` can work well when external time references are only " +"intermittently accessible, whereas `ntpd` needs regular polling of time " +"reference to work well." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:27 +msgid "" +"`chronyd` can perform well even when the network is congested for longer " +"periods of time." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:29 +msgid "" +"`chronyd` can usually synchronize the clock faster and with better time " +"accuracy." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:31 +msgid "" +"`chronyd` quickly adapts to sudden changes in the rate of the clock, for " +"example, due to changes in the temperature of the crystal oscillator, " +"whereas `ntpd` may need a long time to settle down again." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:33 +msgid "" +"In the default configuration, `chronyd` never steps the time after the clock " +"has been synchronized at system start, in order not to upset other running " +"programs. `ntpd` can be configured to never step the time too, but it has to " +"use a different means of adjusting the clock, which has some disadvantages." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:35 +msgid "" +"`chronyd` can adjust the rate of the clock on a Linux system in a larger " +"range, which allows it to operate even on machines with a broken or unstable " +"clock. For example, on some virtual machines." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:37 +msgid "Things `chronyd` can do that `ntpd` cannot do:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:39 +msgid "" +"`chronyd` provides support for isolated networks where the only method of " +"time correction is manual entry. For example, by the administrator looking " +"at a clock. `chronyd` can examine the errors corrected at different updates " +"to estimate the rate at which the computer gains or loses time, and use this " +"estimate to trim the computer clock subsequently." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:41 +msgid "" +"`chronyd` provides support to work out the rate of gain or loss of the " +"real-time clock, the hardware clock, that maintains the time when the " +"computer is turned off. It can use this data when the system boots to set " +"the system time using an adjusted value of the time taken from the real-time " +"clock. This is, at time of writing, only available in Linux." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:43 +msgid "Things `ntpd` can do that `chronyd` cannot do:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:45 +msgid "" +"`ntpd` fully supports `NTP` version 4 ([citetitle]_RFC 5905_), including " +"broadcast, multicast, manycast clients and servers, and the orphan mode. It " +"also supports extra authentication schemes based on public-key cryptography " +"([citetitle]_RFC 5906_). `chronyd` uses `NTP` version 3 ([citetitle]_RFC " +"1305_), which is compatible with version 4." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:47 +msgid "" +"`ntpd` includes drivers for many reference clocks whereas `chronyd` relies " +"on other programs, for example [application]*gpsd*, to access the data from " +"the reference clocks." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:49 +#, no-wrap +msgid "Choosing Between NTP Daemons" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:52 +msgid "" +"[application]*Chrony* should be considered for all systems which are " +"frequently suspended or otherwise intermittently disconnected and " +"reconnected to a network. Mobile and virtual systems for example." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:54 +msgid "" +"The `NTP` daemon (`ntpd`) should be considered for systems which are " +"normally kept permanently on. Systems which are required to use broadcast or " +"multicast `IP`, or to perform authentication of packets with the `Autokey` " +"protocol, should consider using `ntpd`. [application]*Chrony* only supports " +"symmetric key authentication using a message authentication code (MAC) with " +"MD5, SHA1 or stronger hash functions, whereas `ntpd` also supports the " +"`Autokey` authentication protocol which can make use of the PKI " +"system. `Autokey` is described in [citetitle]_RFC 5906_." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:56 +#, no-wrap +msgid "Understanding chrony and Its Configuration" +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:59 +#, no-wrap +msgid "Understanding chronyd" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:62 +msgid "" +"The [application]*chrony* daemon, `chronyd`, running in user space, makes " +"adjustments to the system clock which is running in the kernel. It does this " +"by consulting external time sources, using the `NTP` protocol, when ever " +"network access allows it to do so. When external references are not " +"available, `chronyd` will use the last calculated drift stored in the drift " +"file. It can also be commanded manually to make corrections, by " +"[application]*chronyc*." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:64 +#, no-wrap +msgid "Understanding chronyc" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:67 +msgid "" +"The [application]*chrony* daemon, `chronyd`, can be controlled by the " +"command line utility [application]*chronyc*. This utility provides a command " +"prompt which allows entering of a number of commands to make changes to " +"`chronyd`. The default configuration is for `chronyd` to only accept " +"commands from a local instance of [application]*chronyc*, but " +"[application]*chronyc* can be used to alter the configuration so that " +"`chronyd` will allow external control. [application]*chronyc* can be run " +"remotely after first configuring `chronyd` to accept remote connections. The " +"`IP` addresses allowed to connect to `chronyd` should be tightly controlled." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:69 +#, no-wrap +msgid "Understanding the chrony Configuration Commands" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:72 +msgid "" +"The default configuration file for `chronyd` is `/etc/chrony.conf`. The " +"[option]`-f` option can be used to specify an alternate configuration file " +"path. See the `chronyd` man page for further options. For a complete list of " +"the directives that can be used see " +"[citetitle]_link:++https://chrony-project.org/doc/4.4/chrony.conf.html++[https://chrony-project.org/doc/4.4/chrony.conf.html]_. " +"Below is a selection of configuration options:" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:73 +#, no-wrap +msgid "Comments" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:74 +msgid "Comments should be preceded by #, %, ; or !" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:75 +#, no-wrap +msgid "allow" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:77 +msgid "" +"Optionally specify a host, subnet, or network from which to allow `NTP` " +"connections to a machine acting as `NTP` server. The default is not to allow " +"connections. Examples:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:78 +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:85 +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:92 +msgid "[subs=\"quotes\"]" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:80 +#, no-wrap +msgid "allow server1.example.com\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:83 +msgid "" +"Use this form to specify a particular host, by its host name, to be allowed " +"access." +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:87 +#, no-wrap +msgid "allow 192.0.2.0/24\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:90 +msgid "Use this form to specify a particular network to be allowed access." +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:94 +#, no-wrap +msgid "allow 2001:db8::/32\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:97 +msgid "Use this form to specify an `IPv6` address to be allowed access." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:98 +#, no-wrap +msgid "cmdallow" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:99 +msgid "" +"This is similar to the [command]#allow# directive (see section " +"[command]#allow#), except that it allows control access (rather than `NTP` " +"client access) to a particular subnet or host. (By \"`control access`\" is " +"meant that [application]*chronyc* can be run on those hosts and successfully " +"connect to `chronyd` on this computer.) The syntax is identical. There is " +"also a [command]#cmddeny all# directive with similar behavior to the " +"[command]#cmdallow all# directive." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:100 +#, no-wrap +msgid "dumpdir" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:101 +msgid "" +"Path to the directory to save the measurement history across restarts of " +"`chronyd` (assuming no changes are made to the system clock behavior whilst " +"it is not running). If this capability is to be used (via the " +"[command]#dumponexit# command in the configuration file, or the " +"[command]#dump# command in [application]*chronyc*), the [command]#dumpdir# " +"command should be used to define the directory where the measurement " +"histories are saved." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:102 +#, no-wrap +msgid "dumponexit" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:103 +msgid "" +"If this command is present, it indicates that `chronyd` should save the " +"measurement history for each of its time sources recorded whenever the " +"program exits. (See the [command]#dumpdir# command above)." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:104 +#, no-wrap +msgid "local" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:105 +msgid "" +"The [command]#local# keyword is used to allow `chronyd` to appear " +"synchronized to real time from the viewpoint of clients polling it, even if " +"it has no current synchronization source. This option is normally used on " +"the \"`master`\" computer in an isolated network, where several computers " +"are required to synchronize to one another, and the \"`master`\" is kept in " +"line with real time by manual input." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:107 +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:132 +msgid "An example of the command is:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:111 +#, no-wrap +msgid "local stratum 10\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:114 +msgid "" +"A large value of 10 indicates that the clock is so many hops away from a " +"reference clock that its time is unreliable. If the computer ever has access " +"to another computer which is ultimately synchronized to a reference clock, " +"it will almost certainly be at a stratum less than 10. Therefore, the choice " +"of a high value like 10 for the [command]#local# command prevents the " +"machine’s own time from ever being confused with real time, were it ever to " +"leak out to clients that have visibility of real servers." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:115 +#, no-wrap +msgid "log" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:116 +msgid "" +"The [command]#log# command indicates that certain information is to be " +"logged. It accepts the following options:" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:117 +#, no-wrap +msgid "measurements" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:118 +msgid "" +"This option logs the raw `NTP` measurements and related information to a " +"file called `measurements.log`." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:119 +#, no-wrap +msgid "statistics" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:120 +msgid "" +"This option logs information about the regression processing to a file " +"called `statistics.log`." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:121 +#, no-wrap +msgid "tracking" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:122 +msgid "" +"This option logs changes to the estimate of the system’s gain or loss rate, " +"and any slews made, to a file called `tracking.log`." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:123 +#, no-wrap +msgid "rtc" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:124 +msgid "This option logs information about the system’s real-time clock." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:125 +#, no-wrap +msgid "refclocks" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:126 +msgid "" +"This option logs the raw and filtered reference clock measurements to a file " +"called `refclocks.log`." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:127 +#, no-wrap +msgid "tempcomp" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:128 +msgid "" +"This option logs the temperature measurements and system rate compensations " +"to a file called `tempcomp.log`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:130 +msgid "" +"The log files are written to the directory specified by the " +"[command]#logdir# command." +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:136 +#, no-wrap +msgid "log measurements statistics tracking\n" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:138 +#, no-wrap +msgid "logdir" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:139 +msgid "" +"This directive allows the directory where log files are written to be " +"specified." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:141 +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:150 +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:161 +msgid "An example of the use of this directive is:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:145 +#, no-wrap +msgid "logdir /var/log/chrony\n" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:147 +#, no-wrap +msgid "makestep" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:148 +msgid "" +"Normally `chronyd` will cause the system to gradually correct any time " +"offset, by slowing down or speeding up the clock as required. In certain " +"situations, the system clock may be so far adrift that this slewing process " +"would take a very long time to correct the system clock. This directive " +"forces `chronyd` to step system clock if the adjustment is larger than a " +"threshold value, but only if there were no more clock updates since " +"`chronyd` was started than a specified limit (a negative value can be used " +"to disable the limit). This is particularly useful when using reference " +"clocks, because the [command]#initstepslew# directive only works with `NTP` " +"sources." +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:154 +#, no-wrap +msgid "makestep 1000 10\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:157 +msgid "" +"This would step the system clock if the adjustment is larger than 1000 " +"seconds, but only in the first ten clock updates." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:158 +#, no-wrap +msgid "maxchange" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:159 +msgid "" +"This directive sets the maximum allowed offset corrected on a clock " +"update. The check is performed only after the specified number of updates to " +"allow a large initial adjustment of the system clock. When an offset larger " +"than the specified maximum occurs, it will be ignored for the specified " +"number of times and then `chronyd` will give up and exit (a negative value " +"can be used to never exit). In both cases a message is sent to syslog." +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:165 +#, no-wrap +msgid "maxchange 1000 1 2\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:168 +msgid "" +"After the first clock update, `chronyd` will check the offset on every clock " +"update, it will ignore two adjustments larger than 1000 seconds and exit on " +"another one." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:169 +#, no-wrap +msgid "maxupdateskew" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:170 +msgid "" +"One of `chronyd`pass:attributes[{blank}]'s tasks is to work out how fast or " +"slow the computer’s clock runs relative to its reference sources. In " +"addition, it computes an estimate of the error bounds around the estimated " +"value." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:172 +msgid "" +"If the range of error is too large, it indicates that the measurements have " +"not settled down yet, and that the estimated gain or loss rate is not very " +"reliable." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:174 +msgid "" +"The [command]#maxupdateskew# parameter is the threshold for determining " +"whether an estimate is too unreliable to be used. By default, the threshold " +"is 1000 ppm." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:176 +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:191 +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:200 +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:211 +msgid "The format of the syntax is:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:180 +#, no-wrap +msgid "maxupdateskew _skew-in-ppm_\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:183 +msgid "" +"Typical values for _skew-in-ppm_ might be 100 for a dial-up connection to " +"servers over a telephone line, and 5 or 10 for a computer on a LAN." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:185 +msgid "" +"It should be noted that this is not the only means of protection against " +"using unreliable estimates. At all times, `chronyd` keeps track of both the " +"estimated gain or loss rate, and the error bound on the estimate. When a new " +"estimate is generated following another measurement from one of the sources, " +"a weighted combination algorithm is used to update the master estimate. So " +"if `chronyd` has an existing highly-reliable master estimate and a new " +"estimate is generated which has large error bounds, the existing master " +"estimate will dominate in the new master estimate." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:186 +#, no-wrap +msgid "noclientlog" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:187 +msgid "" +"This directive, which takes no arguments, specifies that client accesses are " +"not to be logged. Normally they are logged, allowing statistics to be " +"reported using the clients command in [application]*chronyc*." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:188 +#, no-wrap +msgid "reselectdist" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:189 +msgid "" +"When `chronyd` selects synchronization source from available sources, it " +"will prefer the one with minimum synchronization distance. However, to avoid " +"frequent reselecting when there are sources with similar distance, a fixed " +"distance is added to the distance for sources that are currently not " +"selected. This can be set with the [option]`reselectdist` option. By " +"default, the distance is 100 microseconds." +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:195 +#, no-wrap +msgid "reselectdist _dist-in-seconds_\n" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:197 +#, no-wrap +msgid "stratumweight" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:198 +msgid "" +"The [command]#stratumweight# directive sets how much distance should be " +"added per stratum to the synchronization distance when `chronyd` selects the " +"synchronization source from available sources." +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:204 +#, no-wrap +msgid "stratumweight _dist-in-seconds_\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:207 +msgid "" +"By default, _dist-in-seconds_ is 1 second. This means that sources with " +"lower stratum are usually preferred to sources with higher stratum even when " +"their distance is significantly worse. Setting [command]#stratumweight# to 0 " +"makes `chronyd` ignore stratum when selecting the source." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:208 +#, no-wrap +msgid "rtcfile" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:209 +msgid "" +"The [command]#rtcfile# directive defines the name of the file in which " +"`chronyd` can save parameters associated with tracking the accuracy of the " +"system’s real-time clock (RTC)." +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:215 +#, no-wrap +msgid "rtcfile /var/lib/chrony/rtc\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:218 +msgid "" +"`chronyd` saves information in this file when it exits and when the " +"[command]#writertc# command is issued in [application]*chronyc*. The " +"information saved is the RTC’s error at some epoch, that epoch (in seconds " +"since January 1 1970), and the rate at which the RTC gains or loses " +"time. Not all real-time clocks are supported as their code is " +"system-specific. Note that if this directive is used then the real-time " +"clock should not be manually adjusted as this would interfere with " +"[application]*chrony*pass:attributes[{blank}]'s need to measure the rate at " +"which the real-time clock drifts if it was adjusted at random intervals." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:219 +#, no-wrap +msgid "rtcsync" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:220 +msgid "" +"The [command]#rtcsync# directive is present in the `/etc/chrony.conf` file " +"by default. This will inform the kernel the system clock is kept " +"synchronized and the kernel will update the real-time clock every 11 " +"minutes." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:222 +#, no-wrap +msgid "Security with chronyc" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:225 +msgid "" +"As access to [application]*chronyc* allows changing `chronyd` just as " +"editing the configuration files would, access to [application]*chronyc* " +"should be limited. Passwords can be specified in the key file, written in " +"ASCII or HEX, to restrict the use of [application]*chronyc*. One of the " +"entries is used to restrict the use of operational commands and is referred " +"to as the command key. In the default configuration, a random command key is " +"generated automatically on start. It should not be necessary to specify or " +"alter it manually." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:227 +msgid "" +"Other entries in the key file can be used as `NTP` keys to authenticate " +"packets received from remote `NTP` servers or peers. The two sides need to " +"share a key with identical ID, hash type and password in their key " +"file. This requires manually creating the keys and copying them over a " +"secure medium, such as `SSH`. If the key ID was, for example, 10 then the " +"systems that act as clients must have a line in their configuration files in " +"the following format:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:232 +#, no-wrap +msgid "" +"server w.x.y.z key 10\n" +"peer w.x.y.z key 10\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:236 +msgid "" +"The location of the key file is specified in the `/etc/chrony.conf` " +"file. The default entry in the configuration file is:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:240 +#, no-wrap +msgid "[command]#keyfile# [option]`/etc/chrony.keys`\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:243 +msgid "" +"The command key number is specified in `/etc/chrony.conf` using the " +"[command]#commandkey# directive, it is the key `chronyd` will use for " +"authentication of user commands. The directive in the configuration file " +"takes the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:247 +#, no-wrap +msgid "commandkey 1\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:250 +msgid "" +"An example of the format of the default entry in the key file, " +"`/etc/chrony.keys`, for the command key is:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:254 +#, no-wrap +msgid "1 SHA1 HEX:A6CFC50C9C93AB6E5A19754C246242FC5471BCDF\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:257 +msgid "" +"Where `1` is the key ID, SHA1 is the hash function to use, `HEX` is the " +"format of the key, and `A6CFC50C9C93AB6E5A19754C246242FC5471BCDF` is the key " +"randomly generated when [application]*chronyd* was started for the first " +"time. The key can be given in hexadecimal or ASCII format (the default)." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:259 +msgid "" +"A manual entry in the key file, used to authenticate packets from certain " +"`NTP` servers or peers, can be as simple as the following:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:263 +#, no-wrap +msgid "20 foobar\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:266 +msgid "" +"Where `20` is the key ID and `foobar` is the secret authentication key. The " +"default hash is MD5, and ASCII is the default format for the key." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:268 +msgid "" +"By default, `chronyd` is configured to listen for commands only from " +"`localhost` (`127.0.0.1` and `::1`) on port `323`. To access `chronyd` " +"remotely with [application]*chronyc*, any [command]#bindcmdaddress# " +"directives in the `/etc/chrony.conf` file should be removed to enable " +"listening on all interfaces and the [command]#cmdallow# directive should be " +"used to allow commands from the remote `IP` address, network, or subnet. In " +"addition, port `323` has to be opened in the firewall in order to connect " +"from a remote system. Note that the [command]#allow# directive is for `NTP` " +"access whereas the [command]#cmdallow# directive is to enable the receiving " +"of remote commands. It is possible to make these changes temporarily using " +"[application]*chronyc* running locally. Edit the configuration file to make " +"persistent changes." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:270 +msgid "" +"The communication between [application]*chronyc* and [application]*chronyd* " +"is done over `UDP`, so it needs to be authorized before issuing operational " +"commands. To authorize, use the [command]#authhash# and [command]#password# " +"commands as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:276 +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:676 +#, no-wrap +msgid "" +"chronyc> [command]#authhash SHA1#\n" +"chronyc> [command]#password " +"HEX:A6CFC50C9C93AB6E5A19754C246242FC5471BCDF#\n" +"200 OK\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:279 +msgid "" +"If [application]*chronyc* is used to configure the local " +"[application]*chronyd*, the [option]`-a` option will run the " +"[command]#authhash# and [command]#password# commands automatically." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:281 +msgid "Only the following commands can be used without providing a password:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:283 +msgid "[command]#activity#" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:285 +msgid "[command]#authhash#" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:287 +msgid "[command]#dns#" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:289 +msgid "[command]#exit#" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:291 +msgid "[command]#help#" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:293 +msgid "[command]#password#" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:295 +msgid "[command]#quit#" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:297 +msgid "[command]#rtcdata#" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:299 +msgid "[command]#sources#" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:301 +msgid "[command]#sourcestats#" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:303 +msgid "[command]#tracking#" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:305 +msgid "[command]#waitsync#" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:307 +msgid "." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:309 +#, no-wrap +msgid "Using chrony" +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:312 +#, no-wrap +msgid "Installing chrony" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:315 +msgid "" +"The [application]*chrony* suite is installed by default on some versions of " +"Fedora. If required, to ensure that it is, run the following command as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:319 +#, no-wrap +msgid "~]#{nbsp}dnf install chrony\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:322 +msgid "" +"The default location for the [application]*chrony* daemon is " +"`/usr/sbin/chronyd`. The command line utility will be installed to " +"`/usr/bin/chronyc`." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:324 +#, no-wrap +msgid "Checking the Status of chronyd" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:327 +msgid "To check the status of `chronyd`, issue the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:334 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#systemctl status chronyd#\n" +"chronyd.service - NTP client/server\n" +" Loaded: loaded (/usr/lib/systemd/system/chronyd.service; enabled)\n" +" Active: active (running) since Wed 2013-06-12 22:23:16 CEST; 11h ago\n" +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:337 +#, no-wrap +msgid "Starting chronyd" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:340 +msgid "To start `chronyd`, issue the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:344 +#, no-wrap +msgid "~]#{nbsp}systemctl start chronyd\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:347 +msgid "" +"To ensure `chronyd` starts automatically at system start, issue the " +"following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:351 +#, no-wrap +msgid "~]#{nbsp}systemctl enable chronyd\n" +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:354 +#, no-wrap +msgid "Stopping chronyd" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:357 +msgid "To stop `chronyd`, issue the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:361 +#, no-wrap +msgid "~]#{nbsp}systemctl stop chronyd\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:364 +msgid "" +"To prevent `chronyd` from starting automatically at system start, issue the " +"following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:368 +#, no-wrap +msgid "~]#{nbsp}systemctl disable chronyd\n" +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:371 +#, no-wrap +msgid "Checking if chrony is Synchronized" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:374 +msgid "" +"To check if [application]*chrony* is synchronized, make use of the " +"[command]#tracking#, [command]#sources#, and [command]#sourcestats# " +"commands." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:376 +#, no-wrap +msgid "Checking chrony Tracking" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:379 +msgid "To check [application]*chrony* tracking, issue the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:396 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#chronyc tracking#\n" +"Reference ID : 1.2.3.4 (a.b.c)\n" +"Stratum : 3\n" +"Ref time (UTC) : Fri Feb 3 15:00:29 2012\n" +"System time : 0.000001501 seconds slow of NTP time\n" +"Last offset : -0.000001632 seconds\n" +"RMS offset : 0.000002360 seconds\n" +"Frequency : 331.898 ppm fast\n" +"Residual freq : 0.004 ppm\n" +"Skew : 0.154 ppm\n" +"Root delay : 0.373169 seconds\n" +"Root dispersion : 0.024780 seconds\n" +"Update interval : 64.2 seconds\n" +"Leap status : Normal\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:400 +msgid "The fields are as follows:" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:401 +#, no-wrap +msgid "Reference ID" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:402 +msgid "" +"This is the reference ID and name (or `IP` address) if available, of the " +"server to which the computer is currently synchronized. If this is " +"`127.127.1.1` it means the computer is not synchronized to any external " +"source and that you have the \"`local`\" mode operating (via the local " +"command in [application]*chronyc*, or the [command]#local# directive in the " +"`/etc/chrony.conf` file (see section [command]#local#))." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:403 +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:456 +#, no-wrap +msgid "Stratum" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:404 +msgid "" +"The stratum indicates how many hops away from a computer with an attached " +"reference clock we are. Such a computer is a stratum-1 computer, so the " +"computer in the example is two hops away (that is to say, a.b.c is a " +"stratum-2 and is synchronized from a stratum-1)." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:405 +#, no-wrap +msgid "Ref time" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:406 +msgid "" +"This is the time (UTC) at which the last measurement from the reference " +"source was processed." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:407 +#, no-wrap +msgid "System time" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:408 +msgid "" +"In normal operation, `chronyd` never steps the system clock, because any " +"jump in the timescale can have adverse consequences for certain application " +"programs. Instead, any error in the system clock is corrected by slightly " +"speeding up or slowing down the system clock until the error has been " +"removed, and then returning to the system clock’s normal speed. A " +"consequence of this is that there will be a period when the system clock (as " +"read by other programs using the `gettimeofday()` system call, or by the " +"date command in the shell) will be different from " +"`chronyd`pass:attributes[{blank}]'s estimate of the current true time (which " +"it reports to `NTP` clients when it is operating in server mode). The value " +"reported on this line is the difference due to this effect." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:409 +#, no-wrap +msgid "Last offset" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:410 +msgid "This is the estimated local offset on the last clock update." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:411 +#, no-wrap +msgid "RMS offset" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:412 +msgid "This is a long-term average of the offset value." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:413 +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:494 +#, no-wrap +msgid "Frequency" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:414 +msgid "" +"The \"`frequency`\" is the rate by which the system’s clock would be wrong " +"if `chronyd` was not correcting it. It is expressed in ppm (parts per " +"million). For example, a value of 1ppm would mean that when the system’s " +"clock thinks it has advanced 1 second, it has actually advanced by 1.000001 " +"seconds relative to true time." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:415 +#, no-wrap +msgid "Residual freq" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:416 +msgid "" +"This shows the \"`residual frequency`\" for the currently selected reference " +"source. This reflects any difference between what the measurements from the " +"reference source indicate the frequency should be and the frequency " +"currently being used." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:418 +msgid "" +"The reason this is not always zero is that a smoothing procedure is applied " +"to the frequency. Each time a measurement from the reference source is " +"obtained and a new residual frequency computed, the estimated accuracy of " +"this residual is compared with the estimated accuracy (see [option]`skew` " +"next) of the existing frequency value. A weighted average is computed for " +"the new frequency, with weights depending on these accuracies. If the " +"measurements from the reference source follow a consistent trend, the " +"residual will be driven to zero over time." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:419 +#, no-wrap +msgid "Skew" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:420 +msgid "This is the estimated error bound on the frequency." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:421 +#, no-wrap +msgid "Root delay" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:422 +msgid "" +"This is the total of the network path delays to the stratum-1 computer from " +"which the computer is ultimately synchronized." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:424 +msgid "" +"In certain extreme situations, this value can be negative. (This can arise " +"in a symmetric peer arrangement where the computers’ frequencies are not " +"tracking each other and the network delay is very short relative to the " +"turn-around time at each computer.)" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:425 +#, no-wrap +msgid "Root dispersion" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:426 +msgid "" +"This is the total dispersion accumulated through all the computers back to " +"the stratum-1 computer from which the computer is ultimately " +"synchronized. Dispersion is due to system clock resolution, statistical " +"measurement variations etc." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:427 +#, no-wrap +msgid "Leap status" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:428 +msgid "" +"This is the leap status, which can be Normal, Insert second, Delete second " +"or Not synchronized." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:430 +#, no-wrap +msgid "Checking chrony Sources" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:433 +msgid "" +"The sources command displays information about the current time sources that " +"`chronyd` is accessing." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:435 +msgid "" +"The optional argument -v can be specified, meaning verbose. In this case, " +"extra caption lines are shown as a reminder of the meanings of the columns." +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:445 +#, no-wrap +msgid "" +"~]${nbsp}chronyc sources\n" +"\t210 Number of sources = 3\n" +"MS Name/IP address Stratum Poll Reach LastRx Last sample\n" +"===============================================================================\n" +"#* GPS0 0 4 377 11 -479ns[ -621ns] +/- " +"134ns\n" +"^? a.b.c 2 6 377 23 -923us[ -924us] +/- " +"43ms\n" +"^+ d.e.f 1 6 377 21 -2629us[-2619us] +/- " +"86ms\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:448 +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:485 +msgid "The columns are as follows:" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:449 +#, no-wrap +msgid "M" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:450 +msgid "" +"This indicates the mode of the source. `^` means a server, `=` means a peer " +"and `#` indicates a locally connected reference clock." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:451 +#, no-wrap +msgid "S" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:453 +msgid "" +"This column indicates the state of the sources. \"`*`\" indicates the source " +"to which `chronyd` is currently synchronized. \"`+`\" indicates acceptable " +"sources which are combined with the selected source. \"`-`\" indicates " +"acceptable sources which are excluded by the combining algorithm. \"`?`\" " +"indicates sources to which connectivity has been lost or whose packets do " +"not pass all tests. \"`x`\" indicates a clock which `chronyd` thinks is a " +"_falseticker_ (its time is inconsistent with a majority of other " +"sources). \"`~`\" indicates a source whose time appears to have too much " +"variability. The \"`?`\" condition is also shown at start-up, until at least " +"3 samples have been gathered from it." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:454 +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:486 +#, no-wrap +msgid "Name/IP address" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:455 +msgid "" +"This shows the name or the `IP` address of the source, or reference ID for " +"reference clocks." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:457 +msgid "" +"This shows the stratum of the source, as reported in its most recently " +"received sample. Stratum 1 indicates a computer with a locally attached " +"reference clock. A computer that is synchronized to a stratum 1 computer is " +"at stratum 2. A computer that is synchronized to a stratum 2 computer is at " +"stratum 3, and so on." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:458 +#, no-wrap +msgid "Poll" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:459 +msgid "" +"This shows the rate at which the source is being polled, as a base-2 " +"logarithm of the interval in seconds. Thus, a value of 6 would indicate that " +"a measurement is being made every 64 seconds." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:461 +msgid "" +"`chronyd` automatically varies the polling rate in response to prevailing " +"conditions." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:462 +#, no-wrap +msgid "Reach" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:463 +msgid "" +"This shows the source’s reach register printed as an octal number. The " +"register has 8 bits and is updated on every received or missed packet from " +"the source. A value of 377 indicates that a valid reply was received for all " +"of the last eight transmissions." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:464 +#, no-wrap +msgid "LastRx" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:465 +msgid "" +"This column shows how long ago the last sample was received from the " +"source. This is normally in seconds. The letters `m`, `h`, `d` or `y` " +"indicate minutes, hours, days or years. A value of 10 years indicates there " +"were no samples received from this source yet." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:466 +#, no-wrap +msgid "Last sample" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:467 +msgid "" +"This column shows the offset between the local clock and the source at the " +"last measurement. The number in the square brackets shows the actual " +"measured offset. This may be suffixed by `ns` (indicating nanoseconds), `us` " +"(indicating microseconds), `ms` (indicating milliseconds), or `s` " +"(indicating seconds). The number to the left of the square brackets shows " +"the original measurement, adjusted to allow for any slews applied to the " +"local clock since. The number following the `+/-` indicator shows the margin " +"of error in the measurement. Positive offsets indicate that the local clock " +"is ahead of the source." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:469 +#, no-wrap +msgid "Checking chrony Source Statistics" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:472 +msgid "" +"The [command]#sourcestats# command displays information about the drift rate " +"and offset estimation process for each of the sources currently being " +"examined by `chronyd`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:474 +msgid "" +"The optional argument [option]`-v` can be specified, meaning verbose. In " +"this case, extra caption lines are shown as a reminder of the meanings of " +"the columns." +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:482 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#chronyc sourcestats#\n" +"210 Number of sources = 1\n" +"Name/IP Address NP NR Span Frequency Freq Skew Offset Std " +"Dev\n" +"===============================================================================\n" +"abc.def.ghi 11 5 46m -0.001 0.045 1us " +"25us\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:487 +msgid "" +"This is the name or `IP` address of the `NTP` server (or peer) or reference " +"ID of the reference clock to which the rest of the line relates." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:488 +#, no-wrap +msgid "NP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:489 +msgid "" +"This is the number of sample points currently being retained for the " +"server. The drift rate and current offset are estimated by performing a " +"linear regression through these points." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:490 +#, no-wrap +msgid "NR" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:491 +msgid "" +"This is the number of runs of residuals having the same sign following the " +"last regression. If this number starts to become too small relative to the " +"number of samples, it indicates that a straight line is no longer a good fit " +"to the data. If the number of runs is too low, `chronyd` discards older " +"samples and re-runs the regression until the number of runs becomes " +"acceptable." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:492 +#, no-wrap +msgid "Span" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:493 +msgid "" +"This is the interval between the oldest and newest samples. If no unit is " +"shown the value is in seconds. In the example, the interval is 46 minutes." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:495 +msgid "" +"This is the estimated residual frequency for the server, in parts per " +"million. In this case, the computer’s clock is estimated to be running 1 " +"part in _10pass:attributes[{blank}]^9^pass:attributes[{blank}]_ slow " +"relative to the server." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:496 +#, no-wrap +msgid "Freq Skew" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:497 +msgid "This is the estimated error bounds on Freq (again in parts per million)." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:498 +#, no-wrap +msgid "Offset" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:499 +msgid "This is the estimated offset of the source." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:500 +#, no-wrap +msgid "Std Dev" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:501 +msgid "This is the estimated sample standard deviation." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:503 +#, no-wrap +msgid "Manually Adjusting the System Clock" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:506 +msgid "" +"To update, or step, the system clock immediately, bypassing any adjustments " +"in progress by slewing the clock, issue the following commands as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:514 +#, no-wrap +msgid "" +"~]#{nbsp}chronyc\n" +" chrony> password pass:quotes[_commandkey-password_]\n" +" 200 OK\n" +" chrony> makestep\n" +" 200 OK\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:517 +msgid "" +"Where _commandkey-password_ is the command key or password stored in the key " +"file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:519 +msgid "" +"If the [command]#rtcfile# directive is used, the real-time clock should not " +"be manually adjusted. Random adjustments would interfere with " +"[application]*chrony*pass:attributes[{blank}]'s need to measure the rate at " +"which the real-time clock drifts." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:521 +msgid "" +"If [application]*chronyc* is used to configure the local " +"[application]*chronyd*, the [option]`-a` will run the [command]#authhash# " +"and [command]#password# commands automatically. This means that the " +"interactive session illustrated above can be replaced by:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:525 +#, no-wrap +msgid "chronyc -a makestep\n" +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:528 +#, no-wrap +msgid "Setting Up chrony for Different Environments" +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:531 +#, no-wrap +msgid "Setting Up chrony for a System Which is Infrequently Connected" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:534 +msgid "" +"This example is intended for systems which use dial-on-demand " +"connections. The normal configuration should be sufficient for mobile and " +"virtual devices which connect intermittently. First, review and confirm that " +"the default settings in the `/etc/chrony.conf` are similar to the following:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:540 +#, no-wrap +msgid "" +"driftfile /var/lib/chrony/drift\n" +"commandkey 1\n" +"keyfile /etc/chrony.keys\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:544 +msgid "" +"The command key ID is generated at install time and should correspond with " +"the [command]#commandkey# value in the key file, `/etc/chrony.keys`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:546 +msgid "" +"Using your editor running as `root`, add the addresses of four `NTP` servers " +"as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:553 +#, no-wrap +msgid "" +"server 0.pool.ntp.org offline\n" +"server 1.pool.ntp.org offline\n" +"server 2.pool.ntp.org offline\n" +"server 3.pool.ntp.org offline\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:556 +msgid "" +"The [option]`offline` option can be useful in preventing systems from trying " +"to activate connections. The [application]*chrony* daemon will wait for " +"[application]*chronyc* to inform it that the system is connected to the " +"network or Internet." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:558 +#, no-wrap +msgid "Setting Up chrony for a System in an Isolated Network" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:561 +msgid "" +"For a network that is never connected to the Internet, one computer is " +"selected to be the master timeserver. The other computers are either direct " +"clients of the master, or clients of clients. On the master, the drift file " +"must be manually set with the average rate of drift of the system clock. If " +"the master is rebooted it will obtain the time from surrounding systems and " +"take an average to set its system clock. Thereafter it resumes applying " +"adjustments based on the drift file. The drift file will be updated " +"automatically when the [command]#settime# command is used." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:563 +msgid "" +"On the system selected to be the master, using a text editor running as " +"`root`, edit the `/etc/chrony.conf` as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:574 +#, no-wrap +msgid "" +"driftfile /var/lib/chrony/drift\n" +"commandkey 1\n" +"keyfile /etc/chrony.keys\n" +"initstepslew 10 client1 client3 client6\n" +"local stratum 8\n" +"manual\n" +"allow 192.0.2.0\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:578 +msgid "" +"Where `192.0.2.0` is the network or subnet address from which the clients " +"are allowed to connect." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:580 +msgid "" +"On the systems selected to be direct clients of the master, using a text " +"editor running as `root`, edit the `/etc/chrony.conf` as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:592 +#, no-wrap +msgid "" +"server master\n" +"driftfile /var/lib/chrony/drift\n" +"logdir /var/log/chrony\n" +"log measurements statistics tracking\n" +"keyfile /etc/chrony.keys\n" +"commandkey 24\n" +"local stratum 10\n" +"initstepslew 20 master\n" +"allow 192.0.2.123\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:595 +msgid "" +"Where `192.0.2.123` is the address of the master, and `master` is the host " +"name of the master. Clients with this configuration will resynchronize the " +"master if it restarts." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:597 +msgid "" +"On the client systems which are not to be direct clients of the master, the " +"`/etc/chrony.conf` file should be the same except that the [option]`local` " +"and [option]`allow` directives should be omitted." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:599 +#, no-wrap +msgid "Using chronyc" +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:602 +#, no-wrap +msgid "Using chronyc to Control chronyd" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:605 +msgid "" +"To make changes to the local instance of `chronyd` using the command line " +"utility [application]*chronyc* in interactive mode, enter the following " +"command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:609 +#, no-wrap +msgid "~]#{nbsp}chronyc -a\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:612 +msgid "" +"[application]*chronyc* must run as `root` if some of the restricted commands " +"are to be used. The [option]`-a` option is for automatic authentication " +"using the local keys when configuring `chronyd` on the local system. See " +"xref:Configuring_NTP_Using_the_chrony_Suite.adoc#sect-Security_with_chronyc[Security " +"with chronyc] for more information." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:614 +msgid "The [application]*chronyc* command prompt will be displayed as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:618 +#, no-wrap +msgid "chronyc>\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:621 +msgid "You can type [command]#help# to list all of the commands." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:623 +msgid "" +"The utility can also be invoked in non-interactive command mode if called " +"together with a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:627 +#, no-wrap +msgid "[command]#chronyc _command_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:633 +msgid "" +"Changes made using [application]*chronyc* are not permanent, they will be " +"lost after a `chronyd` restart. For permanent changes, modify " +"`/etc/chrony.conf`." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:637 +#, no-wrap +msgid "Using chronyc for Remote Administration" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:640 +msgid "" +"To configure [application]*chrony* to connect to a remote instance of " +"`chronyd`, issue a command in the following format:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:644 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#chronyc -h " +"_hostname_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:647 +msgid "" +"Where _hostname_ is the host name to connect to. The default is to connect " +"to the local daemon." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:649 +msgid "" +"To configure [application]*chrony* to connect to a remote instance of " +"`chronyd` on a non-default port, issue a command in the following format:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:653 +#, no-wrap +msgid "" +"~]${nbsp}pass:attributes[{blank}][command]#chronyc -h _hostname_ -p " +"_port_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:656 +msgid "" +"Where _port_ is the port in use for controlling and monitoring by the remote " +"instance of `chronyd`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:658 +msgid "" +"Note that commands issued at the [application]*chronyc* command prompt are " +"not persistent. Only commands in the configuration file are persistent." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:660 +msgid "" +"The first command must be the [command]#password# command at the " +"[application]*chronyc* command prompt as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:665 +#, no-wrap +msgid "" +"chronyc> [command]#password _password_pass:attributes[{blank}]#\n" +"200 OK\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:668 +msgid "The password should not have any spaces." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:670 +msgid "" +"If the password is not an MD5 hash, the hashed password must be preceded by " +"the [command]#authhash# command as follows:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:679 +msgid "" +"The password or hash associated with the command key for a remote system is " +"best obtained by `SSH`. An `SSH` connection should be established to the " +"remote machine and the ID of the command key from `/etc/chrony.conf` and the " +"command key in `/etc/chrony.keys` memorized or stored securely for the " +"duration of the session." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:681 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:684 +msgid "" +"The following sources of information provide additional resources regarding " +"[application]*chrony*." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:686 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:689 +msgid "" +"`chrony(1)` man page — Introduces the [application]*chrony* daemon and the " +"command-line interface tool." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:691 +msgid "" +"`chronyc(1)` man page — Describes the [application]*chronyc* command-line " +"interface tool including commands and command options." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:693 +msgid "" +"`chronyd(1)` man page — Describes the [application]*chronyd* daemon " +"including commands and command options." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:695 +msgid "" +"`chrony.conf(5)` man page — Describes the [application]*chrony* " +"configuration file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:697 +msgid "" +"`/usr/share/doc/chrony/chrony.txt` — User guide for the " +"[application]*chrony* suite." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:699 +#, no-wrap +msgid "Online Documentation" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:701 +#, no-wrap +msgid "link:++https://chrony.tuxfamily.org/manual.html++[]" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_NTP_Using_the_chrony_Suite.adoc:701 +msgid "The online user guide for [application]*chrony*." +msgstr "" diff --git a/pot/rawhide/pages/servers/Configuring_PTP_Using_ptp4l.pot b/pot/rawhide/pages/servers/Configuring_PTP_Using_ptp4l.pot new file mode 100644 index 00000000000..d09bc238c8d --- /dev/null +++ b/pot/rawhide/pages/servers/Configuring_PTP_Using_ptp4l.pot @@ -0,0 +1,1707 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:6 +#, no-wrap +msgid "Configuring PTP Using ptp4l" +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:9 +#, no-wrap +msgid "Introduction to PTP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:12 +msgid "" +"The _Precision Time Protocol_ (*PTP*) is a protocol used to synchronize " +"clocks in a network. When used in conjunction with hardware support, `PTP` " +"is capable of sub-microsecond accuracy, which is far better than is normally " +"obtainable with `NTP`. `PTP` support is divided between the kernel and user " +"space. The kernel in Fedora includes support for `PTP` clocks, which are " +"provided by network drivers. The actual implementation of the protocol is " +"known as [application]*linuxptp*, a `PTPv2` implementation according to the " +"IEEE standard 1588 for Linux." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:14 +msgid "" +"The [package]*linuxptp* package includes the [application]*ptp4l* and " +"[application]*phc2sys* programs for clock synchronization. The " +"[application]*ptp4l* program implements the `PTP` boundary clock and " +"ordinary clock. With hardware time stamping, it is used to synchronize the " +"`PTP` hardware clock to the master clock, and with software time stamping it " +"synchronizes the system clock to the master clock. The " +"[application]*phc2sys* program is needed only with hardware time stamping, " +"for synchronizing the system clock to the `PTP` hardware clock on the " +"_network interface card_ (*NIC*)." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:16 +#, no-wrap +msgid "Understanding PTP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:19 +msgid "" +"The clocks synchronized by `PTP` are organized in a master-slave " +"hierarchy. The slaves are synchronized to their masters which may be slaves " +"to their own masters. The hierarchy is created and updated automatically by " +"the _best master clock_ (*BMC*) algorithm, which runs on every clock. When a " +"clock has only one port, it can be _master_ or _slave_, such a clock is " +"called an _ordinary clock_ (*OC*). A clock with multiple ports can be master " +"on one port and slave on another, such a clock is called a _boundary_ clock " +"(*BC*). The top-level master is called the _grandmaster clock_, which can be " +"synchronized by using a _Global Positioning System_ (*GPS*) time source. By " +"using a GPS-based time source, disparate networks can be synchronized with a " +"high-degree of accuracy." +msgstr "" + +#. type: Block title +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:21 +#, no-wrap +msgid "PTP grandmaster, boundary, and slave Clocks" +msgstr "" + +#. type: Positional ($1) AttributeList argument for macro 'image' +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:23 +#, no-wrap +msgid "An illustration showing PTP grandmaster" +msgstr "" + +#. type: Target for macro image +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:23 +#, no-wrap +msgid "ptp_grandmaster_boundary_and_slaves.png" +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:26 +#, no-wrap +msgid "Advantages of PTP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:29 +msgid "" +"One of the main advantages that `PTP` has over the _Network Time Protocol_ " +"(*NTP*) is hardware support present in various _network interface " +"controllers_ (*NIC*) and network switches. This specialized hardware allows " +"`PTP` to account for delays in message transfer, and greatly improves the " +"accuracy of time synchronization. While it is possible to use non-PTP " +"enabled hardware components within the network, this will often cause an " +"increase in jitter or introduce an asymmetry in the delay resulting in " +"synchronization inaccuracies, which add up with multiple non-PTP aware " +"components used in the communication path. To achieve the best possible " +"accuracy, it is recommended that all networking components between `PTP` " +"clocks are `PTP` hardware enabled. Time synchronization in larger networks " +"where not all of the networking hardware supports `PTP` might be better " +"suited for `NTP`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:31 +msgid "" +"With hardware `PTP` support, the NIC has its own on-board clock, which is " +"used to time stamp the received and transmitted `PTP` messages. It is this " +"on-board clock that is synchronized to the `PTP` master, and the computer's " +"system clock is synchronized to the `PTP` hardware clock on the NIC. With " +"software `PTP` support, the system clock is used to time stamp the `PTP` " +"messages and it is synchronized to the `PTP` master directly. Hardware `PTP` " +"support provides better accuracy since the NIC can time stamp the `PTP` " +"packets at the exact moment they are sent and received while software `PTP` " +"support requires additional processing of the `PTP` packets by the operating " +"system." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:33 +#, no-wrap +msgid "Using PTP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:36 +msgid "" +"In order to use `PTP`, the kernel network driver for the intended interface " +"has to support either software or hardware time stamping capabilities." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:38 +#, no-wrap +msgid "Checking for Driver and Hardware Support" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:41 +msgid "" +"In addition to hardware time stamping support being present in the driver, " +"the NIC must also be capable of supporting this functionality in the " +"physical hardware. The best way to verify the time stamping capabilities of " +"a particular driver and NIC is to use the [application]*ethtool* utility to " +"query the interface as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:60 +#, no-wrap +msgid "" +"~]#{nbsp}ethtool -T em3\n" +"Time stamping parameters for em3:\n" +"Capabilities:\n" +" hardware-transmit (SOF_TIMESTAMPING_TX_HARDWARE)\n" +" software-transmit (SOF_TIMESTAMPING_TX_SOFTWARE)\n" +" hardware-receive (SOF_TIMESTAMPING_RX_HARDWARE)\n" +" software-receive (SOF_TIMESTAMPING_RX_SOFTWARE)\n" +" software-system-clock (SOF_TIMESTAMPING_SOFTWARE)\n" +" hardware-raw-clock (SOF_TIMESTAMPING_RAW_HARDWARE)\n" +"PTP Hardware Clock: 0\n" +"Hardware Transmit Timestamp Modes:\n" +" off (HWTSTAMP_TX_OFF)\n" +" on (HWTSTAMP_TX_ON)\n" +"Hardware Receive Filter Modes:\n" +" none (HWTSTAMP_FILTER_NONE)\n" +" all (HWTSTAMP_FILTER_ALL)\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:63 +msgid "Where _em3_ is the interface you want to check." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:66 +msgid "For software time stamping support, the parameters list should include:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:68 +msgid "`SOF_TIMESTAMPING_SOFTWARE`" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:70 +msgid "`SOF_TIMESTAMPING_TX_SOFTWARE`" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:72 +msgid "`SOF_TIMESTAMPING_RX_SOFTWARE`" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:75 +msgid "For hardware time stamping support, the parameters list should include:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:77 +msgid "`SOF_TIMESTAMPING_RAW_HARDWARE`" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:79 +msgid "`SOF_TIMESTAMPING_TX_HARDWARE`" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:81 +msgid "`SOF_TIMESTAMPING_RX_HARDWARE`" +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:83 +#, no-wrap +msgid "Installing PTP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:86 +msgid "" +"The kernel in Fedora includes support for `PTP`. User space support is " +"provided by the tools in the [application]*linuxptp* package. To install " +"[application]*linuxptp*, issue the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:90 +#, no-wrap +msgid "~]#{nbsp}dnf install linuxptp\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:93 +msgid "This will install [application]*ptp4l* and [application]*phc2sys*." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:95 +msgid "" +"Do not run more than one service to set the system clock's time at the same " +"time. If you intend to serve `PTP` time using `NTP`, see " +"xref:Configuring_PTP_Using_ptp4l.adoc#sec-Serving_PTP_Time_with_NTP[Serving " +"PTP Time with NTP]." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:97 +#, no-wrap +msgid "Starting ptp4l" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:100 +msgid "" +"The [application]*ptp4l* program can be started from the command line or it " +"can be started as a service. When running as a service, options are " +"specified in the `/etc/sysconfig/ptp4l` file. Options required for use both " +"by the service and on the command line should be specified in the " +"`/etc/ptp4l.conf` file. The `/etc/sysconfig/ptp4l` file includes the " +"[command]#-f /etc/ptp4l.conf# command line option, which causes the `ptp4l` " +"program to read the `/etc/ptp4l.conf` file and process the options it " +"contains. The use of the `/etc/ptp4l.conf` is explained in " +"xref:Configuring_PTP_Using_ptp4l.adoc#sec-Specifying_a_Configuration_File[Specifying " +"a Configuration File]. More information on the different " +"[application]*ptp4l* options and the configuration file settings can be " +"found in the `ptp4l(8)` man page." +msgstr "" + +#. type: Block title +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:101 +#, no-wrap +msgid "Starting ptp4l as a Service" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:103 +msgid "" +"To start [application]*ptp4l* as a service, issue the following command as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:107 +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:145 +#, no-wrap +msgid "~]#{nbsp}systemctl start ptp4l\n" +msgstr "" + +#. type: Block title +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:109 +#, no-wrap +msgid "Using ptp4l From The Command Line" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:111 +msgid "" +"The [application]*ptp4l* program tries to use hardware time stamping by " +"default. To use [application]*ptp4l* with hardware time stamping capable " +"drivers and NICs, you must provide the network interface to use with the " +"[option]`-i` option. Enter the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:115 +#, no-wrap +msgid "~]#{nbsp}ptp4l -i em3 -m\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:118 +msgid "" +"Where _em3_ is the interface you want to configure. Below is example output " +"from [application]*ptp4l* when the `PTP` clock on the NIC is synchronized to " +"a master:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:135 +#, no-wrap +msgid "" +"~]#{nbsp}ptp4l -i em3 -m\n" +"selected em3 as PTP clock\n" +"port 1: INITIALIZING to LISTENING on INITIALIZE\n" +"port 0: INITIALIZING to LISTENING on INITIALIZE\n" +"port 1: new foreign master 00a069.fffe.0b552d-1\n" +"selected best master clock 00a069.fffe.0b552d\n" +"port 1: LISTENING to UNCALIBRATED on RS_SLAVE\n" +"master offset -23947 s0 freq +0 path delay 11350\n" +"master offset -28867 s0 freq +0 path delay 11236\n" +"master offset -32801 s0 freq +0 path delay 10841\n" +"master offset -37203 s1 freq +0 path delay 10583\n" +"master offset -7275 s2 freq -30575 path delay 10583\n" +"port 1: UNCALIBRATED to SLAVE on MASTER_CLOCK_SELECTED\n" +"master offset -4552 s2 freq -30035 path delay 10385\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:139 +msgid "" +"The master offset value is the measured offset from the master in " +"nanoseconds. The `s0`, `s1`, `s2` strings indicate the different clock servo " +"states: `s0` is unlocked, `s1` is clock step and `s2` is locked. Once the " +"servo is in the locked state (`s2`), the clock will not be stepped (only " +"slowly adjusted) unless the [option]`pi_offset_const` option is set to a " +"positive value in the configuration file (described in the `ptp4l(8)` man " +"page). The `adj` value is the frequency adjustment of the clock in parts per " +"billion (ppb). The path delay value is the estimated delay of the " +"synchronization messages sent from the master in nanoseconds. Port 0 is a " +"Unix domain socket used for local `PTP` management. Port 1 is the `em3` " +"interface (based on the example above.) INITIALIZING, LISTENING, " +"UNCALIBRATED and SLAVE are some of possible port states which change on the " +"INITIALIZE, RS_SLAVE, MASTER_CLOCK_SELECTED events. In the last state change " +"message, the port state changed from UNCALIBRATED to SLAVE indicating " +"successful synchronization with a `PTP` master clock." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:141 +msgid "" +"The [application]*ptp4l* program can also be started as a service by " +"running:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:148 +msgid "" +"When running as a service, options are specified in the " +"`/etc/sysconfig/ptp4l` file. More information on the different " +"[application]*ptp4l* options and the configuration file settings can be " +"found in the `ptp4l(8)` man page." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:150 +msgid "" +"By default, messages are sent to `/var/log/messages`. However, specifying " +"the [option]`-m` option enables logging to standard output which can be " +"useful for debugging purposes." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:152 +msgid "" +"To enable software time stamping, the [option]`-S` option needs to be used " +"as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:156 +#, no-wrap +msgid "~]#{nbsp}ptp4l -i em3 -m -S\n" +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:159 +#, no-wrap +msgid "Selecting a Delay Measurement Mechanism" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:162 +msgid "" +"There are two different delay measurement mechanisms and they can be " +"selected by means of an option added to the [command]#ptp4l# command as " +"follows:" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:163 +#, no-wrap +msgid "[option]`-P`" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:164 +msgid "" +"The [option]`-P` selects the _peer-to-peer_ (*P2P*) delay measurement " +"mechanism." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:166 +msgid "" +"The *P2P* mechanism is preferred as it reacts to changes in the network " +"topology faster, and may be more accurate in measuring the delay, than other " +"mechanisms. The *P2P* mechanism can only be used in topologies where each " +"port exchanges *PTP* messages with at most one other *P2P* port. It must be " +"supported and used by all hardware, including transparent clocks, on the " +"communication path." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:167 +#, no-wrap +msgid "[option]`-E`" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:168 +msgid "" +"The [option]`-E` selects the _end-to-end_ (*E2E*) delay measurement " +"mechanism. This is the default." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:170 +msgid "" +"The *E2E* mechanism is also referred to as the delay \"`request-response`\" " +"mechanism." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:171 +#, no-wrap +msgid "[option]`-A`" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:172 +msgid "" +"The [option]`-A` enables automatic selection of the delay measurement " +"mechanism." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:174 +msgid "" +"The automatic option starts [application]*ptp4l* in *E2E* mode. It will " +"change to *P2P* mode if a peer delay request is received." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:179 +msgid "" +"All clocks on a single `PTP` communication path must use the same mechanism " +"to measure the delay. Warnings will be printed in the following " +"circumstances:" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:181 +msgid "When a peer delay request is received on a port using the *E2E* mechanism." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:183 +msgid "When a *E2E* delay request is received on a port using the *P2P* mechanism." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:187 +#, no-wrap +msgid "Specifying a Configuration File" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:190 +msgid "" +"The command line options and other options, which cannot be set on the " +"command line, can be set in an optional configuration file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:192 +msgid "" +"No configuration file is read by default, so it needs to be specified at " +"runtime with the [option]`-f` option. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:196 +#, no-wrap +msgid "~]#{nbsp}ptp4l -f /etc/ptp4l.conf\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:199 +msgid "" +"A configuration file equivalent to the [command]#-i em3 -m -S# options shown " +"above would look as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:207 +#, no-wrap +msgid "" +"~]#{nbsp}cat /etc/ptp4l.conf\n" +"[global]\n" +"verbose 1\n" +"time_stamping software\n" +"[em3]\n" +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:211 +#, no-wrap +msgid "Using the PTP Management Client" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:214 +msgid "" +"The `PTP` management client, [application]*pmc*, can be used to obtain " +"additional information from [application]*ptp4l* as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:223 +#, no-wrap +msgid "" +"~]#{nbsp}pmc -u -b 0 'GET CURRENT_DATA_SET'\n" +"sending: GET CURRENT_DATA_SET\n" +" 90e2ba.fffe.20c7f8-0 seq 0 RESPONSE MANAGMENT CURRENT_DATA_SET\n" +" stepsRemoved 1\n" +" offsetFromMaster -142.0\n" +" meanPathDelay 9310.0\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:238 +#, no-wrap +msgid "" +"~]#{nbsp}pmc -u -b 0 'GET TIME_STATUS_NP'\n" +"sending: GET TIME_STATUS_NP\n" +" 90e2ba.fffe.20c7f8-0 seq 0 RESPONSE MANAGMENT TIME_STATUS_NP\n" +" master_offset 310\n" +" ingress_time 1361545089345029441\n" +" cumulativeScaledRateOffset +1.000000000\n" +" scaledLastGmPhaseChange 0\n" +" gmTimeBaseIndicator 0\n" +" lastGmPhaseChange 0x0000'0000000000000000.0000\n" +" gmPresent true\n" +" gmIdentity 00a069.fffe.0b552d\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:241 +msgid "" +"Setting the [option]`-b` option to `zero` limits the boundary to the locally " +"running [application]*ptp4l* instance. A larger boundary value will retrieve " +"the information also from `PTP` nodes further from the local clock. The " +"retrievable information includes:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:243 +msgid "" +"`stepsRemoved` is the number of communication paths to the grandmaster " +"clock." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:245 +msgid "" +"`offsetFromMaster` and master_offset is the last measured offset of the " +"clock from the master in nanoseconds." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:247 +msgid "" +"`meanPathDelay` is the estimated delay of the synchronization messages sent " +"from the master in nanoseconds." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:249 +msgid "" +"if `gmPresent` is true, the `PTP` clock is synchronized to a master, the " +"local clock is not the grandmaster clock." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:251 +msgid "`gmIdentity` is the grandmaster's identity." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:253 +msgid "" +"For a full list of [application]*pmc* commands, type the following as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:257 +#, no-wrap +msgid "~]#{nbsp}pmc help\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:260 +msgid "Additional information is available in the `pmc(8)` man page." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:262 +#, no-wrap +msgid "Synchronizing the Clocks" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:265 +msgid "" +"The [application]*phc2sys* program is used to synchronize the system clock " +"to the `PTP` hardware clock (*PHC*) on the NIC. The [application]*phc2sys* " +"service is configured in the `/etc/sysconfig/phc2sys` configuration " +"file. The default setting in the `/etc/sysconfig/phc2sys` file is as " +"follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:269 +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:469 +#, no-wrap +msgid "OPTIONS=\"-a -r\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:272 +msgid "" +"The [option]`-a` option causes [application]*phc2sys* to read the clocks to " +"be synchronized from the [application]*ptp4l* application. It will follow " +"changes in the `PTP` port states, adjusting the synchronization between the " +"NIC hardware clocks accordingly. The system clock is not synchronized, " +"unless the [option]`-r` option is also specified. If you want the system " +"clock to be eligible to become a time source, specify the [option]`-r` " +"option twice." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:274 +msgid "" +"After making changes to `/etc/sysconfig/phc2sys`, restart the " +"[application]*phc2sys* service from the command line by issuing a command as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:277 +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:483 +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:681 +#, no-wrap +msgid "~]# systemctl restart phc2sys\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:280 +msgid "" +"Under normal circumstances, use [command]#systemctl# commands to start, " +"stop, and restart the [application]*phc2sys* service." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:282 +msgid "" +"When you do not want to start [application]*phc2sys* as a service, you can " +"start it from the command line. For example, enter the following command as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:286 +#, no-wrap +msgid "~]#{nbsp}phc2sys -a -r\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:289 +msgid "" +"The [option]`-a` option causes [application]*phc2sys* to read the clocks to " +"be synchronized from the [application]*ptp4l* application. If you want the " +"system clock to be eligible to become a time source, specify the " +"[option]`-r` option twice." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:291 +msgid "" +"Alternately, use the [option]`-s` option to synchronize the system clock to " +"a specific interface's `PTP` hardware clock. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:295 +#, no-wrap +msgid "~]#{nbsp}phc2sys -s em3 -w\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:298 +msgid "" +"The [option]`-w` option waits for the running [application]*ptp4l* " +"application to synchronize the `PTP` clock and then retrieves the *TAI* to " +"*UTC* offset from [application]*ptp4l*." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:300 +msgid "" +"Normally, `PTP` operates in the _International Atomic Time_ (*TAI*) " +"timescale, while the system clock is kept in _Coordinated Universal Time_ " +"(*UTC*). The current offset between the TAI and UTC timescales is 35 " +"seconds. The offset changes when leap seconds are inserted or deleted, which " +"typically happens every few years. The [option]`-O` option needs to be used " +"to set this offset manually when the [option]`-w` is not used, as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:304 +#, no-wrap +msgid "~]#{nbsp}phc2sys -s em3 -O -35\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:307 +msgid "" +"Once the [application]*phc2sys* servo is in a locked state, the clock will " +"not be stepped, unless the [option]`-S` option is used. This means that the " +"[application]*phc2sys* program should be started after the " +"[application]*ptp4l* program has synchronized the `PTP` hardware " +"clock. However, with [option]`-w`, it is not necessary to start " +"[application]*phc2sys* after [application]*ptp4l* as it will wait for it to " +"synchronize the clock." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:309 +msgid "" +"The [application]*phc2sys* program can also be started as a service by " +"running:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:313 +#, no-wrap +msgid "~]#{nbsp}systemctl start phc2sys\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:316 +msgid "" +"When running as a service, options are specified in the " +"`/etc/sysconfig/phc2sys` file. More information on the different " +"[application]*phc2sys* options can be found in the `phc2sys(8)` man page." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:318 +msgid "" +"Note that the examples in this section assume the command is run on a slave " +"system or slave port." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:320 +#, no-wrap +msgid "Verifying Time Synchronization" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:323 +msgid "" +"When `PTP` time synchronization is working properly, new messages with " +"offsets and frequency adjustments will be printed periodically to the " +"[application]*ptp4l* and [application]*phc2sys* (if hardware time stamping " +"is used) outputs. These values will eventually converge after a short period " +"of time. These messages can be seen in `/var/log/messages` file. An example " +"of the output follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:347 +#, no-wrap +msgid "" +"ptp4l[352.359]: selected /dev/ptp0 as PTP clock\n" +"ptp4l[352.361]: port 1: INITIALIZING to LISTENING on INITIALIZE\n" +"ptp4l[352.361]: port 0: INITIALIZING to LISTENING on INITIALIZE\n" +"ptp4l[353.210]: port 1: new foreign master 00a069.fffe.0b552d-1\n" +"ptp4l[357.214]: selected best master clock 00a069.fffe.0b552d\n" +"ptp4l[357.214]: port 1: LISTENING to UNCALIBRATED on RS_SLAVE\n" +"ptp4l[359.224]: master offset 3304 s0 freq +0 path delay " +"9202\n" +"ptp4l[360.224]: master offset 3708 s1 freq -29492 path delay " +"9202\n" +"ptp4l[361.224]: master offset -3145 s2 freq -32637 path delay " +"9202\n" +"ptp4l[361.224]: port 1: UNCALIBRATED to SLAVE on MASTER_CLOCK_SELECTED\n" +"ptp4l[362.223]: master offset -145 s2 freq -30580 path delay " +"9202\n" +"ptp4l[363.223]: master offset 1043 s2 freq -29436 path delay " +"8972\n" +"ptp4l[364.223]: master offset 266 s2 freq -29900 path delay " +"9153\n" +"ptp4l[365.223]: master offset 430 s2 freq -29656 path delay " +"9153\n" +"ptp4l[366.223]: master offset 615 s2 freq -29342 path delay " +"9169\n" +"ptp4l[367.222]: master offset -191 s2 freq -29964 path delay " +"9169\n" +"ptp4l[368.223]: master offset 466 s2 freq -29364 path delay " +"9170\n" +"ptp4l[369.235]: master offset 24 s2 freq -29666 path delay " +"9196\n" +"ptp4l[370.235]: master offset -375 s2 freq -30058 path delay " +"9238\n" +"ptp4l[371.235]: master offset 285 s2 freq -29511 path delay " +"9199\n" +"ptp4l[372.235]: master offset -78 s2 freq -29788 path delay " +"9204\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:351 +msgid "An example of the [application]*phc2sys* output follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:375 +#, no-wrap +msgid "" +"phc2sys[526.527]: Waiting for ptp4l...\n" +"phc2sys[527.528]: Waiting for ptp4l...\n" +"phc2sys[528.528]: phc offset 55341 s0 freq +0 delay 2729\n" +"phc2sys[529.528]: phc offset 54658 s1 freq -37690 delay 2725\n" +"phc2sys[530.528]: phc offset 888 s2 freq -36802 delay 2756\n" +"phc2sys[531.528]: phc offset 1156 s2 freq -36268 delay 2766\n" +"phc2sys[532.528]: phc offset 411 s2 freq -36666 delay 2738\n" +"phc2sys[533.528]: phc offset -73 s2 freq -37026 delay 2764\n" +"phc2sys[534.528]: phc offset 39 s2 freq -36936 delay 2746\n" +"phc2sys[535.529]: phc offset 95 s2 freq -36869 delay 2733\n" +"phc2sys[536.529]: phc offset -359 s2 freq -37294 delay 2738\n" +"phc2sys[537.529]: phc offset -257 s2 freq -37300 delay 2753\n" +"phc2sys[538.529]: phc offset 119 s2 freq -37001 delay 2745\n" +"phc2sys[539.529]: phc offset 288 s2 freq -36796 delay 2766\n" +"phc2sys[540.529]: phc offset -149 s2 freq -37147 delay 2760\n" +"phc2sys[541.529]: phc offset -352 s2 freq -37395 delay 2771\n" +"phc2sys[542.529]: phc offset 166 s2 freq -36982 delay 2748\n" +"phc2sys[543.529]: phc offset 50 s2 freq -37048 delay 2756\n" +"phc2sys[544.530]: phc offset -31 s2 freq -37114 delay 2748\n" +"phc2sys[545.530]: phc offset -333 s2 freq -37426 delay 2747\n" +"phc2sys[546.530]: phc offset 194 s2 freq -36999 delay 2749\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:378 +msgid "" +"For [application]*ptp4l* there is also a directive, " +"[option]`summary_interval`, to reduce the output and print only statistics, " +"as normally it will print a message every second or so. For example, to " +"reduce the output to every `1024` seconds, add the following line to the " +"`/etc/ptp4l.conf` file:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:381 +#, no-wrap +msgid "summary_interval 10\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:384 +msgid "" +"An example of the [application]*ptp4l* output, with " +"[option]`summary_interval 6`, follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:403 +#, no-wrap +msgid "" +"ptp4l: [615.253] selected /dev/ptp0 as PTP clock\n" +"ptp4l: [615.255] port 1: INITIALIZING to LISTENING on INITIALIZE\n" +"ptp4l: [615.255] port 0: INITIALIZING to LISTENING on INITIALIZE\n" +"ptp4l: [615.564] port 1: new foreign master 00a069.fffe.0b552d-1\n" +"ptp4l: [619.574] selected best master clock 00a069.fffe.0b552d\n" +"ptp4l: [619.574] port 1: LISTENING to UNCALIBRATED on RS_SLAVE\n" +"ptp4l: [623.573] port 1: UNCALIBRATED to SLAVE on MASTER_CLOCK_SELECTED\n" +"ptp4l: [684.649] rms 669 max 3691 freq -29383 ± 3735 delay 9232 ± 122\n" +"ptp4l: [748.724] rms 253 max 588 freq -29787 ± 221 delay 9219 ± 158\n" +"ptp4l: [812.793] rms 287 max 673 freq -29802 ± 248 delay 9211 ± 183\n" +"ptp4l: [876.853] rms 226 max 534 freq -29795 ± 197 delay 9221 ± 138\n" +"ptp4l: [940.925] rms 250 max 562 freq -29801 ± 218 delay 9199 ± 148\n" +"ptp4l: [1004.988] rms 226 max 525 freq -29802 ± 196 delay 9228 ± 143\n" +"ptp4l: [1069.065] rms 300 max 646 freq -29802 ± 259 delay 9214 ± 176\n" +"ptp4l: [1133.125] rms 226 max 505 freq -29792 ± 197 delay 9225 ± 159\n" +"ptp4l: [1197.185] rms 244 max 688 freq -29790 ± 211 delay 9201 ± 162\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:407 +msgid "" +"To reduce the output from the [application]*phc2sys*, it can be called it " +"with the [option]`-u` option as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:411 +#, no-wrap +msgid "~]#{nbsp}phc2sys -u summary-updates\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:414 +msgid "" +"Where _summary-updates_ is the number of clock updates to include in summary " +"statistics. An example follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:426 +#, no-wrap +msgid "" +"~]#{nbsp}phc2sys -s em3 -w -m -u 60\n" +"phc2sys[700.948]: rms 1837 max 10123 freq -36474 ± 4752 delay 2752 ± 16\n" +"phc2sys[760.954]: rms 194 max 457 freq -37084 ± 174 delay 2753 ± 12\n" +"phc2sys[820.963]: rms 211 max 487 freq -37085 ± 185 delay 2750 ± 19\n" +"phc2sys[880.968]: rms 183 max 440 freq -37102 ± 164 delay 2734 ± 91\n" +"phc2sys[940.973]: rms 244 max 584 freq -37095 ± 216 delay 2748 ± 16\n" +"phc2sys[1000.979]: rms 220 max 573 freq -36666 ± 182 delay 2747 ± 43\n" +"phc2sys[1060.984]: rms 266 max 675 freq -36759 ± 234 delay 2753 ± 17\n" +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:430 +#, no-wrap +msgid "Serving PTP Time with NTP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:433 +msgid "" +"The `ntpd` daemon can be configured to distribute the time from the system " +"clock synchronized by [application]*ptp4l* or [application]*phc2sys* by " +"using the LOCAL reference clock driver. To prevent `ntpd` from adjusting the " +"system clock, the `ntp.conf` file must not specify any `NTP` servers. The " +"following is a minimal example of `ntp.conf`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:440 +#, no-wrap +msgid "" +"~]#{nbsp}cat /etc/ntp.conf\n" +"server 127.127.1.0\n" +"fudge 127.127.1.0 stratum 0\n" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:446 +msgid "" +"When the `DHCP` client program, [application]*dhclient*, receives a list of " +"`NTP` servers from the `DHCP` server, it adds them to `ntp.conf` and " +"restarts the service. To disable that feature, add [command]#PEERNTP=no# to " +"`/etc/sysconfig/network`." +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:450 +#, no-wrap +msgid "Serving NTP Time with PTP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:453 +msgid "" +"`NTP` to `PTP` synchronization in the opposite direction is also " +"possible. When `ntpd` is used to synchronize the system clock, " +"[application]*ptp4l* can be configured with the [option]`priority1` option " +"(or other clock options included in the best master clock algorithm) to be " +"the grandmaster clock and distribute the time from the system clock via " +"`PTP`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:461 +#, no-wrap +msgid "" +"~]#{nbsp}cat /etc/ptp4l.conf\n" +"[global]\n" +"priority1 127\n" +"[em3]\n" +"# ptp4l -f /etc/ptp4l.conf\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:465 +msgid "" +"With hardware time stamping, [application]*phc2sys* needs to be used to " +"synchronize the `PTP` hardware clock to the system clock. If running " +"[application]*phc2sys* as a service, edit the `/etc/sysconfig/phc2sys` " +"configuration file. The default setting in the `/etc/sysconfig/phc2sys` file " +"is as follows:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:472 +msgid "As `root`, edit that line as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:476 +#, no-wrap +msgid "" +"~]# vi /etc/sysconfig/phc2sys\n" +"OPTIONS=\"-a -r -r\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:480 +msgid "" +"The [option]`-r` option is used twice here to allow synchronization of the " +"`PTP` hardware clock on the NIC from the system clock. Restart the " +"[application]*phc2sys* service for the changes to take effect:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:486 +msgid "" +"To prevent quick changes in the `PTP` clock's frequency, the synchronization " +"to the system clock can be loosened by using smaller [option]`P` " +"(proportional) and [option]`I` (integral) constants for the PI servo:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:490 +#, no-wrap +msgid "~]#{nbsp}phc2sys -a -r -r -P 0.01 -I 0.0001\n" +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:493 +#, no-wrap +msgid "Synchronize to PTP or NTP Time Using timemaster" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:496 +msgid "" +"When there are multiple `PTP` domains available on the network, or fallback " +"to `NTP` is needed, the [application]*timemaster* program can be used to " +"synchronize the system clock to all available time sources. The `PTP` time " +"is provided by [application]*phc2sys* and [application]*ptp4l* via _shared " +"memory driver_ (*SHM* reference clocks to `chronyd` or `ntpd` (depending on " +"the `NTP` daemon that has been configured on the system). The `NTP` daemon " +"can then compare all time sources, both `PTP` and `NTP`, and use the best " +"sources to synchronize the system clock." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:498 +msgid "" +"On start, [application]*timemaster* reads a configuration file that " +"specifies the `NTP` and `PTP` time sources, checks which network interfaces " +"have their own or share a `PTP` hardware clock (PHC), generates " +"configuration files for [application]*ptp4l* and `chronyd` or `ntpd`, and " +"starts the [application]*ptp4l*, [application]*phc2sys*, and `chronyd` or " +"`ntpd` processes as needed. It will remove the generated configuration files " +"on exit. It writes configuration files for `chronyd`, `ntpd`, and " +"[application]*ptp4l* to `/var/run/timemaster/`." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:500 +#, no-wrap +msgid "Starting timemaster as a Service" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:503 +msgid "" +"To start [application]*timemaster* as a service, issue the following command " +"as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:507 +#, no-wrap +msgid "~]#{nbsp}systemctl start timemaster\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:510 +msgid "This will read the options in `/etc/timemaster.conf`." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:512 +#, no-wrap +msgid "Understanding the timemaster Configuration File" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:515 +msgid "" +"{MAJOROS} provides a default `/etc/timemaster.conf` file with a number of " +"sections containing default options. The section headings are enclosed in " +"brackets." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:517 +msgid "To view the default configuration, issue a command as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:521 +#, no-wrap +msgid "" +"~]$ less /etc/timemaster.conf\n" +"# Configuration file for timemaster\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:525 +#, no-wrap +msgid "" +"#[ntp_server ntp-server.local]\n" +"#minpoll 4\n" +"#maxpoll 4\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:528 +#, no-wrap +msgid "" +"#[ptp_domain 0]\n" +"#interfaces eth0\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:531 +#, no-wrap +msgid "" +"[timemaster]\n" +"ntp_program chronyd\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:534 +#, no-wrap +msgid "" +"[chrony.conf]\n" +"include /etc/chrony.conf\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:537 +#, no-wrap +msgid "" +"[ntp.conf]\n" +"includefile /etc/ntp.conf\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:539 +#, no-wrap +msgid "[ptp4l.conf]\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:543 +#, no-wrap +msgid "" +"[chronyd]\n" +"path /usr/sbin/chronyd\n" +"options -u chrony\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:547 +#, no-wrap +msgid "" +"[ntpd]\n" +"path /usr/sbin/ntpd\n" +"options -u ntp:ntp -g\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:550 +#, no-wrap +msgid "" +"[phc2sys]\n" +"path /usr/sbin/phc2sys\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:553 +#, no-wrap +msgid "" +"[ptp4l]\n" +"path /usr/sbin/ptp4l\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:556 +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:565 +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:576 +msgid "Notice the section named as follows:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:560 +#, no-wrap +msgid "[ntp_server pass:quotes[_address_]]\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:563 +msgid "" +"This is an example of an `NTP` server section, \"`ntp-server.local`\" is an " +"example of a host name for an `NTP` server on the local LAN. Add more " +"sections as required using a host name or `IP` address as part of the " +"section name. Note that the short polling values in that example section are " +"not suitable for a public server, see " +"xref:servers/Configuring_NTP_Using_ntpd.adoc#ch-Configuring_NTP_Using_ntpd[Configuring " +"NTP Using ntpd] for an explanation of suitable [option]`minpoll` and " +"[option]`maxpoll` values." +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:569 +#, no-wrap +msgid "[ptp_domain pass:quotes[_number_]]\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:572 +msgid "" +"A \"`PTP domain`\" is a group of one or more `PTP` clocks that synchronize " +"to each other. They may or may not be synchronized to clocks in another " +"domain. Clocks that are configured with the same domain number make up the " +"domain. This includes a `PTP` grandmaster clock. The domain number in each " +"\"`PTP domain`\" section needs to correspond to one of the `PTP` domains " +"configured on the network." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:574 +msgid "" +"An instance of [application]*ptp4l* is started for every interface which has " +"its own `PTP` clock and hardware time stamping is enabled " +"automatically. Interfaces that support hardware time stamping have a `PTP` " +"clock (PHC) attached, however it is possible for a group of interfaces on a " +"NIC to share a PHC. A separate [application]*ptp4l* instance will be started " +"for each group of interfaces sharing the same PHC and for each interface " +"that supports only software time stamping. All [application]*ptp4l* " +"instances are configured to run as a slave. If an interface with hardware " +"time stamping is specified in more than one `PTP` domain, then only the " +"first [application]*ptp4l* instance created will have hardware time stamping " +"enabled." +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:580 +#, no-wrap +msgid "[timemaster]\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:583 +msgid "" +"The default [application]*timemaster* configuration includes the system " +"`ntpd` and chrony configuration (`/etc/ntp.conf` or `/etc/chronyd.conf`) in " +"order to include the configuration of access restrictions and authentication " +"keys. That means any `NTP` servers specified there will be used with " +"[application]*timemaster* too." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:585 +msgid "The section headings are as follows:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:587 +msgid "" +"[option]`[ntp_server ntp-server.local]` — Specify polling intervals for this " +"server. Create additional sections as required. Include the host name or " +"`IP` address in the section heading." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:589 +msgid "" +"[option]`[ptp_domain 0]` — Specify interfaces that have `PTP` clocks " +"configured for this domain. Create additional sections with, the appropriate " +"domain number, as required." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:591 +msgid "" +"[option]`[timemaster]` — Specify the `NTP` daemon to be used. Possible " +"values are `chronyd` and `ntpd`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:593 +msgid "" +"[option]`[chrony.conf]` — Specify any additional settings to be copied to " +"the configuration file generated for `chronyd`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:595 +msgid "" +"[option]`[ntp.conf]` — Specify any additional settings to be copied to the " +"configuration file generated for `ntpd`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:597 +msgid "" +"[option]`[ptp4l.conf]` — Specify options to be copied to the configuration " +"file generated for [application]*ptp4l*." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:599 +msgid "" +"[option]`[chronyd]` — Specify any additional settings to be passed on the " +"command line to `chronyd`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:601 +msgid "" +"[option]`[ntpd]` — Specify any additional settings to be passed on the " +"command line to `ntpd`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:603 +msgid "" +"[option]`[phc2sys]` — Specify any additional settings to be passed on the " +"command line to [application]*phc2sys*." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:605 +msgid "" +"[option]`[ptp4l]` — Specify any additional settings to be passed on the " +"command line to all instances of [application]*ptp4l*." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:607 +msgid "" +"The section headings and there contents are explained in detail in the " +"`timemaster(8)` manual page." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:609 +#, no-wrap +msgid "Configuring timemaster Options" +msgstr "" + +#. type: Block title +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:612 +#, no-wrap +msgid "Editing the timemaster Configuration File" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:614 +msgid "" +"To change the default configuration, open the `/etc/timemaster.conf` file " +"for editing as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:617 +#, no-wrap +msgid "~]# vi /etc/timemaster.conf\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:620 +msgid "" +"For each `NTP` server you want to control using [application]*timemaster*, " +"create `[ntp_server _address_pass:attributes[{blank}]]` sections . Note that " +"the short polling values in the example section are not suitable for a " +"public server, see " +"xref:servers/Configuring_NTP_Using_ntpd.adoc#ch-Configuring_NTP_Using_ntpd[Configuring " +"NTP Using ntpd] for an explanation of suitable [option]`minpoll` and " +"[option]`maxpoll` values." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:622 +msgid "" +"To add interfaces that should be used in a domain, edit the `#[ptp_domain " +"0]` section and add the interfaces. Create additional domains as " +"required. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:626 +#, no-wrap +msgid "" +"[ptp_domain 0]\n" +" interfaces eth0\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:629 +#, no-wrap +msgid "" +" [ptp_domain 1]\n" +" interfaces eth1\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:632 +msgid "" +"If required to use `ntpd` as the `NTP` daemon on this system, change the " +"default entry in the `[timemaster]` section from `chronyd` to `ntpd`. See " +"xref:servers/Configuring_NTP_Using_the_chrony_Suite.adoc#ch-Configuring_NTP_Using_the_chrony_Suite[Configuring " +"NTP Using the chrony Suite] for information on the differences between ntpd " +"and chronyd." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:634 +msgid "" +"If using `chronyd` as the `NTP` server on this system, add any additional " +"options below the default [option]`include /etc/chrony.conf` entry in the " +"`[chrony.conf]` section. Edit the default [option]`include` entry if the " +"path to `/etc/chrony.conf` is known to have changed." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:636 +msgid "" +"If using `ntpd` as the `NTP` server on this system, add any additional " +"options below the default [option]`include /etc/ntp.conf` entry in the " +"`[ntp.conf]` section. Edit the default [option]`include` entry if the path " +"to `/etc/ntp.conf` is known to have changed." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:638 +msgid "" +"In the `[ptp4l.conf]` section, add any options to be copied to the " +"configuration file generated for [application]*ptp4l*. This chapter " +"documents common options and more information is available in the `ptp4l(8)` " +"manual page." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:640 +msgid "" +"In the `[chronyd]` section, add any command line options to be passed to " +"`chronyd` when called by [application]*timemaster*. See " +"xref:servers/Configuring_NTP_Using_the_chrony_Suite.adoc#ch-Configuring_NTP_Using_the_chrony_Suite[Configuring " +"NTP Using the chrony Suite] for information on using `chronyd`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:642 +msgid "" +"In the `[ntpd]` section, add any command line options to be passed to `ntpd` " +"when called by [application]*timemaster*. See " +"xref:servers/Configuring_NTP_Using_ntpd.adoc#ch-Configuring_NTP_Using_ntpd[Configuring " +"NTP Using ntpd] for information on using `ntpd`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:644 +msgid "" +"In the `[phc2sys]` section, add any command line options to be passed to " +"[application]*phc2sys* when called by [application]*timemaster*. This " +"chapter documents common options and more information is available in the " +"`phy2sys(8)` manual page." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:646 +msgid "" +"In the `[ptp4l]` section, add any command line options to be passed to " +"[application]*ptp4l* when called by [application]*timemaster*. This chapter " +"documents common options and more information is available in the `ptp4l(8)` " +"manual page." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:648 +msgid "" +"Save the configuration file and restart [application]*timemaster* by issuing " +"the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:651 +#, no-wrap +msgid "~]# systemctl restart timemaster\n" +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:654 +#, no-wrap +msgid "Improving Accuracy" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:657 +msgid "" +"Previously, test results indicated that disabling the tickless kernel " +"capability could significantly improve the stability of the system clock, " +"and thus improve the `PTP` synchronization accuracy (at the cost of " +"increased power consumption). The kernel tickless mode can be disabled by " +"adding [option]`nohz=off` to the kernel boot option parameters. However, " +"recent improvements applied to `kernel-3.10.0-197.fc21` have greatly " +"improved the stability of the system clock and the difference in stability " +"of the clock with and without [option]`nohz=off` should be much smaller now " +"for most users." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:659 +msgid "" +"The [application]*ptp4l* and [application]*phc2sys* applications can be " +"configured to use a new adaptive servo. The advantage over the PI servo is " +"that it does not require configuration of the PI constants to perform " +"well. To make use of this for [application]*ptp4l*, add the following line " +"to the `/etc/ptp4l.conf` file:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:662 +#, no-wrap +msgid "clock_servo linreg\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:665 +msgid "" +"After making changes to `/etc/ptp4l.conf`, restart the [application]*ptp4l* " +"service from the command line by issuing the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:668 +#, no-wrap +msgid "~]# systemctl restart ptp4l\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:671 +msgid "" +"To make use of this for [application]*phc2sys*, add the following line to " +"the `/etc/sysconfig/phc2sys` file:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:675 +#, no-wrap +msgid "-E linreg\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:678 +msgid "" +"After making changes to `/etc/sysconfig/phc2sys`, restart the " +"[application]*phc2sys* service from the command line by issuing the " +"following command as `root`:" +msgstr "" + +#. type: Title == +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:684 +#, no-wrap +msgid "Additional Resources" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:687 +msgid "" +"The following sources of information provide additional resources regarding " +"`PTP` and the [application]*ptp4l* tools." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:689 +#, no-wrap +msgid "Installed Documentation" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:692 +msgid "" +"`ptp4l(8)` man page — Describes [application]*ptp4l* options including the " +"format of the configuration file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:694 +msgid "" +"`pmc(8)` man page — Describes the `PTP` management client and its command " +"options." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:696 +msgid "" +"`phc2sys(8)` man page — Describes a tool for synchronizing the system clock " +"to a `PTP` hardware clock (PHC)." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:698 +msgid "" +"`timemaster(8)` man page — Describes a program that uses " +"[application]*ptp4l* and [application]*phc2sys* to synchronize the system " +"clock using `chronyd` or `ntpd`." +msgstr "" + +#. type: Title === +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:700 +#, no-wrap +msgid "Useful Websites" +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:702 +#, no-wrap +msgid "link:++http://linuxptp.sourceforge.net/++[]" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:703 +msgid "The Linux PTP project." +msgstr "" + +#. type: Labeled list +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:704 +#, no-wrap +msgid "link:++https://www.nist.gov/el/isd/ieee/ieee1588.cfm++[]" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Configuring_PTP_Using_ptp4l.adoc:704 +msgid "The IEEE 1588 Standard." +msgstr "" diff --git a/pot/rawhide/pages/servers/Directory_Servers.pot b/pot/rawhide/pages/servers/Directory_Servers.pot new file mode 100644 index 00000000000..68c322f05a5 --- /dev/null +++ b/pot/rawhide/pages/servers/Directory_Servers.pot @@ -0,0 +1,23 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/servers/Directory_Servers.adoc:6 +#, no-wrap +msgid "Directory Servers" +msgstr "" diff --git a/pot/rawhide/pages/servers/File_and_Print_Servers.pot b/pot/rawhide/pages/servers/File_and_Print_Servers.pot new file mode 100644 index 00000000000..fca6aa978c4 --- /dev/null +++ b/pot/rawhide/pages/servers/File_and_Print_Servers.pot @@ -0,0 +1,34 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/servers/File_and_Print_Servers.adoc:6 +#, no-wrap +msgid "File and Print Servers" +msgstr "" + +#. type: Plain text +#: ./pages/servers/File_and_Print_Servers.adoc:9 +msgid "" +"This chapter guides you through the installation and configuration of " +"[application]*Samba*, an open source implementation of the _Server Message " +"Block_ (*SMB*) and _common Internet file system_ (`CIFS`) protocol, and " +"[application]*vsftpd*, the primary FTP server shipped with " +"{MAJOROS}. Additionally, it explains how to use the [application]*Printer* " +"tool to configure printers." +msgstr "" diff --git a/pot/rawhide/pages/servers/Mail_Servers.pot b/pot/rawhide/pages/servers/Mail_Servers.pot new file mode 100644 index 00000000000..20f9350deb4 --- /dev/null +++ b/pot/rawhide/pages/servers/Mail_Servers.pot @@ -0,0 +1,3359 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/servers/Mail_Servers.adoc:6 +#, no-wrap +msgid "Mail Servers" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:9 +msgid "" +"{MAJOROS} offers many advanced applications to serve and access email. This " +"chapter describes modern email protocols in use today, and some of the " +"programs designed to send and receive email." +msgstr "" + +#. type: Title == +#: ./pages/servers/Mail_Servers.adoc:11 +#, no-wrap +msgid "Email Protocols" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:14 +msgid "" +"indexterm:[email,protocols] Today, email is delivered using a client/server " +"architecture. An email message is created using a mail client program. This " +"program then sends the message to a server. The server then forwards the " +"message to the recipient's email server, where the message is then supplied " +"to the recipient's email client." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:16 +msgid "" +"To enable this process, a variety of standard network protocols allow " +"different machines, often running different operating systems and using " +"different email programs, to send and receive email." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:18 +msgid "" +"The following protocols discussed are the most commonly used in the transfer " +"of email." +msgstr "" + +#. type: Title === +#: ./pages/servers/Mail_Servers.adoc:20 +#, no-wrap +msgid "Mail Transport Protocols" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:23 +msgid "" +"Mail delivery from a client application to the server, and from an " +"originating server to the destination server, is handled by the _Simple Mail " +"Transfer Protocol_ (_SMTP_)." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:25 +#, no-wrap +msgid "SMTP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:28 +msgid "" +"indexterm:[email,protocols,SMTP] The primary purpose of SMTP is to transfer " +"email between mail servers. However, it is critical for email clients as " +"well. To send email, the client sends the message to an outgoing mail " +"server, which in turn contacts the destination mail server for delivery. For " +"this reason, it is necessary to specify an SMTP server when configuring an " +"email client." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:30 +msgid "" +"Under {MAJOROS}, a user can configure an SMTP server on the local machine to " +"handle mail delivery. However, it is also possible to configure remote SMTP " +"servers for outgoing mail." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:32 +msgid "" +"One important point to make about the SMTP protocol is that it does not " +"require authentication. This allows anyone on the Internet to send email to " +"anyone else or even to large groups of people. It is this characteristic of " +"SMTP that makes junk email or _spam_ possible. Imposing relay restrictions " +"limits random users on the Internet from sending email through your SMTP " +"server, to other servers on the internet. Servers that do not impose such " +"restrictions are called _open relay_ servers." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:34 +msgid "{MAJOROS} provides the Postfix and Sendmail SMTP programs." +msgstr "" + +#. type: Title === +#: ./pages/servers/Mail_Servers.adoc:36 +#, no-wrap +msgid "Mail Access Protocols" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:39 +msgid "" +"There are two primary protocols used by email client applications to " +"retrieve email from mail servers: the _Post Office Protocol_ (_POP_) and the " +"_Internet Message Access Protocol_ (_IMAP_)." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:41 +#, no-wrap +msgid "POP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:44 +msgid "" +"indexterm:[email,protocols,POP] The default POP server under {MAJOROS} is " +"[application]*Dovecot* and is provided by the [package]*dovecot* package." +msgstr "" + +#. type: Block title +#: ./pages/servers/Mail_Servers.adoc:45 +#, no-wrap +msgid "Installing the dovecot package" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:50 +msgid "" +"In order to use [application]*Dovecot*, first ensure the [package]*dovecot* " +"package is installed on your system by running, as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:54 +#, no-wrap +msgid "~]#{nbsp}dnf install dovecot\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:57 ./pages/servers/Mail_Servers.adoc:343 +#: ./pages/servers/Mail_Servers.adoc:565 ./pages/servers/Mail_Servers.adoc:951 +#: ./pages/servers/Mail_Servers.adoc:1076 +msgid "" +"For more information on installing packages with DNF, see " +"xref:package-management/DNF.adoc#sec-Installing[Installing Packages]." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:61 +msgid "" +"When using a `POP` server, email messages are downloaded by email client " +"applications. By default, most `POP` email clients are automatically " +"configured to delete the message on the email server after it has been " +"successfully transferred, however this setting usually can be changed." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:63 +msgid "" +"`POP` is fully compatible with important Internet messaging standards, such " +"as _Multipurpose Internet Mail Extensions_ (_MIME_), which allow for email " +"attachments." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:65 +msgid "" +"`POP` works best for users who have one system on which to read email. It " +"also works well for users who do not have a persistent connection to the " +"Internet or the network containing the mail server. Unfortunately for those " +"with slow network connections, `POP` requires client programs upon " +"authentication to download the entire content of each message. This can take " +"a long time if any messages have large attachments." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:67 +msgid "The most current version of the standard `POP` protocol is `POP3`." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:69 +msgid "There are, however, a variety of lesser-used `POP` protocol variants:" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:71 +#, no-wrap +msgid "" +"*APOP* — `POP3` with `MD5` authentication. An encoded hash of the user's " +"password is sent from the email client to the server rather than sending an " +"unencrypted password.\n" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:73 +#, no-wrap +msgid "*KPOP* — `POP3` with Kerberos authentication.\n" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:75 +#, no-wrap +msgid "" +"*RPOP* — `POP3` with `RPOP` authentication. This uses a per-user ID, similar " +"to a password, to authenticate POP requests. However, this ID is not " +"encrypted, so `RPOP` is no more secure than standard `POP`.\n" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:77 +msgid "" +"For added security, it is possible to use _Secure Socket Layer_ (_SSL_) " +"encryption for client authentication and data transfer sessions. This can be " +"enabled by using the [command]#pop3s# service, or by using the " +"[command]#stunnel# application. For more information on securing email " +"communication, see xref:Mail_Servers.adoc#s2-email-security[Securing " +"Communication]." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:79 +#, no-wrap +msgid "IMAP" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:82 +msgid "" +"indexterm:[email,protocols,IMAP] The default `IMAP` server under {MAJOROS} " +"is [application]*Dovecot* and is provided by the [package]*dovecot* " +"package. See xref:Mail_Servers.adoc#s3-email-protocols-pop[POP] for " +"information on how to install [application]*Dovecot*." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:84 +msgid "" +"When using an `IMAP` mail server, email messages remain on the server where " +"users can read or delete them. `IMAP` also allows client applications to " +"create, rename, or delete mail directories on the server to organize and " +"store email." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:86 +msgid "" +"`IMAP` is particularly useful for users who access their email using " +"multiple machines. The protocol is also convenient for users connecting to " +"the mail server via a slow connection, because only the email header " +"information is downloaded for messages until opened, saving bandwidth. The " +"user also has the ability to delete messages without viewing or downloading " +"them." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:88 +msgid "" +"For convenience, `IMAP` client applications are capable of caching copies of " +"messages locally, so the user can browse previously read messages when not " +"directly connected to the `IMAP` server." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:90 +msgid "" +"`IMAP`, like `POP`, is fully compatible with important Internet messaging " +"standards, such as MIME, which allow for email attachments." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:92 +msgid "" +"For added security, it is possible to use `SSL` encryption for client " +"authentication and data transfer sessions. This can be enabled by using the " +"[command]#imaps# service, or by using the [command]#stunnel# program. For " +"more information on securing email communication, see " +"xref:Mail_Servers.adoc#s2-email-security[Securing Communication]." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:94 +msgid "" +"Other free, as well as commercial, IMAP clients and servers are available, " +"many of which extend the IMAP protocol and provide additional functionality." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:96 +#, no-wrap +msgid "Dovecot" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:99 +msgid "" +"indexterm:[email,mail server,Dovecot] The [command]#imap-login# and " +"[command]#pop3-login# processes which implement the `IMAP` and `POP3` " +"protocols are spawned by the master `dovecot` daemon included in the " +"[package]*dovecot* package. The use of `IMAP` and `POP` is configured " +"through the `/etc/dovecot/dovecot.conf` configuration file; by default " +"[command]#dovecot# runs `IMAP` and `POP3` together with their secure " +"versions using `SSL`. To configure [command]#dovecot# to use `POP`, complete " +"the following steps:" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:101 +msgid "" +"Edit the `/etc/dovecot/dovecot.conf` configuration file to make sure the " +"`protocols` variable is uncommented (remove the hash sign (`#`) at the " +"beginning of the line) and contains the `pop3` argument. For example:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:105 +#, no-wrap +msgid "protocols = imap pop3 lmtp\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:108 +msgid "" +"When the `protocols` variable is left commented out, [command]#dovecot# will " +"use the default values as described above." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:110 +msgid "" +"Make the change operational for the current session by running the following " +"command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:114 ./pages/servers/Mail_Servers.adoc:145 +#: ./pages/servers/Mail_Servers.adoc:1058 +#, no-wrap +msgid "~]#{nbsp}systemctl restart dovecot\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:117 +msgid "Make the change operational after the next reboot by running the command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:122 +#, no-wrap +msgid "" +"~]#{nbsp}systemctl enable dovecot\n" +"ln -s '/usr/lib/systemd/system/dovecot' " +"'/etc/systemd/system/multi-user.target.wants/dovecot'\n" +msgstr "" + +#. type: Block title +#: ./pages/servers/Mail_Servers.adoc:124 +#, no-wrap +msgid "The dovecot service starts the POP3 server" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:129 +msgid "" +"Please note that [command]#dovecot# only reports that it started the `IMAP` " +"server, but also starts the `POP3` server." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:133 +msgid "" +"Unlike `SMTP`, both `IMAP` and `POP3` require connecting clients to " +"authenticate using a user name and password. By default, passwords for both " +"protocols are passed over the network unencrypted." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:135 +msgid "To configure `SSL` on [command]#dovecot#:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:137 +msgid "" +"Edit the `/etc/pki/dovecot/dovecot-openssl.cnf` configuration file as you " +"prefer. However, in a typical installation, this file does not require " +"modification." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:139 +msgid "" +"Rename, move or delete the files `/etc/pki/dovecot/certs/dovecot.pem` and " +"`/etc/pki/dovecot/private/dovecot.pem`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:141 +msgid "" +"Execute the `/usr/libexec/dovecot/mkcert.sh` script which creates the " +"[command]#dovecot# self signed certificates. These certificates are copied " +"in the `/etc/pki/dovecot/certs` and `/etc/pki/dovecot/private` " +"directories. To implement the changes, restart [command]#dovecot# by issuing " +"the following command as `root`:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:148 +msgid "" +"More details on [command]#dovecot# can be found online at " +"link:++https://www.dovecot.org++[https://www.dovecot.org]." +msgstr "" + +#. type: Title == +#: ./pages/servers/Mail_Servers.adoc:150 +#, no-wrap +msgid "Email Program Classifications" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:153 +msgid "" +"indexterm:[email,program classifications] In general, all email applications " +"fall into at least one of three classifications. Each classification plays a " +"specific role in the process of moving and managing email messages. While " +"most users are only aware of the specific email program they use to receive " +"and send messages, each one is important for ensuring that email arrives at " +"the correct destination." +msgstr "" + +#. type: Title === +#: ./pages/servers/Mail_Servers.adoc:155 +#, no-wrap +msgid "Mail Transport Agent" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:158 +msgid "" +"indexterm:[email,types,Mail Transport Agent]indexterm:[Mail Transport " +"Agent,email]indexterm:[MTA,Mail Transport Agent] A _Mail Transport Agent_ " +"(_MTA_) transports email messages between hosts using `SMTP`. A message may " +"involve several MTAs as it moves to its intended destination." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:160 +msgid "" +"While the delivery of messages between machines may seem rather " +"straightforward, the entire process of deciding if a particular MTA can or " +"should accept a message for delivery is quite complicated. In addition, due " +"to problems from spam, use of a particular MTA is usually restricted by the " +"MTA's configuration or the access configuration for the network on which the " +"MTA resides." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:162 +msgid "" +"Many modern email client programs can act as an MTA when sending " +"email. However, this action should not be confused with the role of a true " +"MTA. The sole reason email client programs are capable of sending email like " +"an MTA is because the host running the application does not have its own " +"MTA. This is particularly true for email client programs on non-UNIX-based " +"operating systems. However, these client programs only send outbound " +"messages to an MTA they are authorized to use and do not directly deliver " +"the message to the intended recipient's email server." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:164 +msgid "" +"Since {MAJOROS} offers two MTAs, _Postfix_ and _Sendmail_, email client " +"programs are often not required to act as an MTA. {MAJOROS} also includes a " +"special purpose MTA called _Fetchmail_." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:166 +msgid "" +"For more information on Postfix, Sendmail, and Fetchmail, see " +"xref:Mail_Servers.adoc#s1-email-mta[Mail Transport Agents]." +msgstr "" + +#. type: Title === +#: ./pages/servers/Mail_Servers.adoc:168 +#, no-wrap +msgid "Mail Delivery Agent" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:171 +msgid "" +"indexterm:[email,types,Mail Delivery Agent]indexterm:[Mail Delivery " +"Agent,email]indexterm:[MDA,Mail Delivery Agent] A _Mail Delivery Agent_ " +"(_MDA_) is invoked by the MTA to file incoming email in the proper user's " +"mailbox. In many cases, the MDA is actually a _Local Delivery Agent_ " +"(_LDA_), such as [command]#mail# or Procmail." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:173 +msgid "" +"Any program that actually handles a message for delivery to the point where " +"it can be read by an email client application can be considered an MDA. For " +"this reason, some MTAs (such as Sendmail and Postfix) can fill the role of " +"an MDA when they append new email messages to a local user's mail spool " +"file. In general, MDAs do not transport messages between systems nor do they " +"provide a user interface; MDAs distribute and sort messages on the local " +"machine for an email client application to access." +msgstr "" + +#. type: Title === +#: ./pages/servers/Mail_Servers.adoc:175 +#, no-wrap +msgid "Mail User Agent" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:178 +msgid "" +"indexterm:[email,types,Mail User Agent]indexterm:[Mail User " +"Agent,email]indexterm:[MUA,Mail User Agent] A _Mail User Agent_ (_MUA_) is " +"synonymous with an email client application. An MUA is a program that, at a " +"minimum, allows a user to read and compose email messages. Many MUAs are " +"capable of retrieving messages via the `POP` or `IMAP` protocols, setting up " +"mailboxes to store messages, and sending outbound messages to an MTA." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:180 +msgid "" +"MUAs may be graphical, such as [application]*Evolution*, or have simple " +"text-based interfaces, such as [application]*Mutt*." +msgstr "" + +#. type: Title == +#: ./pages/servers/Mail_Servers.adoc:182 +#, no-wrap +msgid "Mail Transport Agents" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:185 +msgid "" +"{MAJOROS} offers two primary MTAs: Postfix and Sendmail. Postfix is " +"configured as the default MTA and Sendmail is considered deprecated. If " +"required to switch the default MTA to Sendmail, you can either uninstall " +"Postfix or use the following command as `root` to switch to Sendmail:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:189 +#, no-wrap +msgid "~]#{nbsp}alternatives --config mta\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:192 +msgid "You can also use the following command to enable the desired service:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:196 +#, no-wrap +msgid "~]#{nbsp}systemctl enable service\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:199 +msgid "Similarly, to disable the service, type the following at a shell prompt:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:203 +#, no-wrap +msgid "~]#{nbsp}systemctl disable service\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:206 +msgid "" +"For more information on how to manage system services in {MAJOROSVER}, see " +"xref:infrastructure-services/Services_and_Daemons.adoc#ch-Services_and_Daemons[Services " +"and Daemons]." +msgstr "" + +#. type: Title === +#: ./pages/servers/Mail_Servers.adoc:208 +#, no-wrap +msgid "Postfix" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:211 +msgid "" +"indexterm:[email,Postfix]indexterm:[Postfix] Originally developed at IBM by " +"security expert and programmer Wietse Venema, Postfix is a " +"Sendmail-compatible MTA that is designed to be secure, fast, and easy to " +"configure." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:213 +msgid "" +"To improve security, Postfix uses a modular design, where small processes " +"with limited privileges are launched by a _master_ daemon. The smaller, less " +"privileged processes perform very specific tasks related to the various " +"stages of mail delivery and run in a changed root environment to limit the " +"effects of attacks." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:215 +msgid "" +"Configuring Postfix to accept network connections from hosts other than the " +"local computer takes only a few minor changes in its configuration file. Yet " +"for those with more complex needs, Postfix provides a variety of " +"configuration options, as well as third party add-ons that make it a very " +"versatile and full-featured MTA." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:217 +msgid "" +"The configuration files for Postfix are human readable and support upward of " +"250 directives. Unlike Sendmail, no macro processing is required for changes " +"to take effect and the majority of the most commonly used options are " +"described in the heavily commented files." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:219 +#, no-wrap +msgid "The Default Postfix Installation" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:222 +msgid "" +"indexterm:[Postfix,default installation] The Postfix executable is " +"`postfix`. This daemon launches all related processes needed to handle mail " +"delivery." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:224 +msgid "" +"Postfix stores its configuration files in the `/etc/postfix/` directory. The " +"following is a list of the more commonly used files:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:226 +msgid "" +"`access` — Used for access control, this file specifies which hosts are " +"allowed to connect to Postfix." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:228 +msgid "" +"`main.cf` — The global Postfix configuration file. The majority of " +"configuration options are specified in this file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:230 +msgid "" +"`master.cf` — Specifies how Postfix interacts with various processes to " +"accomplish mail delivery." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:232 +msgid "`transport` — Maps email addresses to relay hosts." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:234 +msgid "" +"The `aliases` file can be found in the `/etc/` directory. This file is " +"shared between Postfix and Sendmail. It is a configurable list required by " +"the mail protocol that describes user ID aliases." +msgstr "" + +#. type: Block title +#: ./pages/servers/Mail_Servers.adoc:235 +#, no-wrap +msgid "Configuring Postfix as a server for other clients" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:240 +msgid "" +"The default `/etc/postfix/main.cf` file does not allow Postfix to accept " +"network connections from a host other than the local computer. For " +"instructions on configuring Postfix as a server for other clients, see " +"xref:Mail_Servers.adoc#s3-email-mta-postfix-conf[Basic Postfix " +"Configuration]." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:244 +msgid "" +"Restart the `postfix` service after changing any options in the " +"configuration files under the `/etc/postfix` directory in order for those " +"changes to take effect. To do so, run the following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:248 +#, no-wrap +msgid "~]#{nbsp}systemctl restart postfix\n" +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:251 +#, no-wrap +msgid "Basic Postfix Configuration" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:254 +msgid "" +"By default, Postfix does not accept network connections from any host other " +"than the local host. Perform the following steps as `root` to enable mail " +"delivery for other hosts on the network:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:256 +msgid "" +"Edit the `/etc/postfix/main.cf` file with a text editor, such as " +"[command]#vi#." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:258 +msgid "" +"Uncomment the `mydomain` line by removing the hash sign (`#`), and replace " +"_domain.tld_ with the domain the mail server is servicing, such as " +"`example.com`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:260 +msgid "Uncomment the `myorigin = $mydomain` line." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:262 +msgid "" +"Uncomment the `myhostname` line, and replace _host.domain.tld_ with the host " +"name for the machine." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:264 +msgid "Uncomment the `mydestination = $myhostname, localhost.$mydomain` line." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:266 +msgid "" +"Uncomment the `mynetworks` line, and replace _168.100.189.0/28_ with a valid " +"network setting for hosts that can connect to the server." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:268 +msgid "Uncomment the `inet_interfaces = all` line." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:270 +msgid "Comment the `inet_interfaces = localhost` line." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:272 +msgid "Restart the `postfix` service." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:274 +msgid "Once these steps are complete, the host accepts outside emails for delivery." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:276 +msgid "" +"Postfix has a large assortment of configuration options. One of the best " +"ways to learn how to configure Postfix is to read the comments within the " +"`/etc/postfix/main.cf` configuration file. Additional resources including " +"information about Postfix configuration, SpamAssassin integration, or " +"detailed descriptions of the `/etc/postfix/main.cf` parameters are available " +"online at link:++http://www.postfix.org/++[http://www.postfix.org/]." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:278 +#, no-wrap +msgid "Using Postfix with LDAP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:281 +msgid "" +"Postfix can use an `LDAP` directory as a source for various lookup tables " +"(e.g.: `aliases`, `virtual`, `canonical`, etc.). This allows `LDAP` to store " +"hierarchical user information and Postfix to only be given the result of " +"`LDAP` queries when needed. By not storing this information locally, " +"administrators can easily maintain it." +msgstr "" + +#. type: Block title +#: ./pages/servers/Mail_Servers.adoc:283 +#, no-wrap +msgid "The /etc/aliases lookup example" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:286 +msgid "" +"The following is a basic example for using `LDAP` to look up the " +"`/etc/aliases` file. Make sure your `/etc/postfix/main.cf` file contains the " +"following:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:289 +#, no-wrap +msgid "alias_maps = hash:/etc/aliases, ldap:/etc/postfix/ldap-aliases.cf\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:292 +msgid "" +"Create a `/etc/postfix/ldap-aliases.cf` file if you do not have one already " +"and make sure it contains the following:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:297 +#, no-wrap +msgid "" +"server_host = pass:quotes[_ldap.example.com_]\n" +"search_base = dc=pass:quotes[_example_], dc=pass:quotes[_com_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:300 +msgid "" +"where `ldap.example.com`, `example`, and `com` are parameters that need to " +"be replaced with specification of an existing available `LDAP` server." +msgstr "" + +#. type: Block title +#: ./pages/servers/Mail_Servers.adoc:301 +#, no-wrap +msgid "The /etc/postfix/ldap-aliases.cf file" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:306 +msgid "" +"The `/etc/postfix/ldap-aliases.cf` file can specify various parameters, " +"including parameters that enable `LDAP` `SSL` and `STARTTLS`. For more " +"information, see the `ldap_table(5)` man page." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:310 ./pages/servers/Mail_Servers.adoc:547 +msgid "" +"For more information on `LDAP`, see " +"xref:servers/Directory_Servers.adoc#s1-OpenLDAP[OpenLDAP]." +msgstr "" + +#. type: Title === +#: ./pages/servers/Mail_Servers.adoc:312 +#, no-wrap +msgid "Sendmail" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:315 +msgid "" +"indexterm:[email,Sendmail]indexterm:[Sendmail] Sendmail's core purpose, like " +"other MTAs, is to safely transfer email among hosts, usually using the " +"`SMTP` protocol. Note that Sendmail is considered deprecated and users are " +"encouraged to use Postfix when possible. See " +"xref:Mail_Servers.adoc#s2-email-mta-postfix[Postfix] for more information." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:317 +#, no-wrap +msgid "Purpose and Limitations" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:320 +msgid "" +"indexterm:[Sendmail,purpose]indexterm:[Sendmail,limitations] It is important " +"to be aware of what Sendmail is and what it can do, as opposed to what it is " +"not. In these days of monolithic applications that fulfill multiple roles, " +"Sendmail may seem like the only application needed to run an email server " +"within an organization. Technically, this is true, as Sendmail can spool " +"mail to each users' directory and deliver outbound mail for users. However, " +"most users actually require much more than simple email delivery. Users " +"usually want to interact with their email using an MUA, that uses `POP` or " +"`IMAP`, to download their messages to their local machine. Or, they may " +"prefer a Web interface to gain access to their mailbox. These other " +"applications can work in conjunction with Sendmail, but they actually exist " +"for different reasons and can operate separately from one another." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:322 +msgid "" +"It is beyond the scope of this section to go into all that Sendmail should " +"or could be configured to do. With literally hundreds of different options " +"and rule sets, entire volumes have been dedicated to helping explain " +"everything that can be done and how to fix things that go wrong. See the " +"xref:Mail_Servers.adoc#s1-email-additional-resources[Additional Resources] " +"for a list of Sendmail resources." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:324 +msgid "" +"This section reviews the files installed with Sendmail by default and " +"reviews basic configuration changes, including how to stop unwanted email " +"(spam) and how to extend Sendmail with the _Lightweight Directory Access " +"Protocol (LDAP)_." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:326 +#, no-wrap +msgid "The Default Sendmail Installation" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:329 +msgid "" +"indexterm:[Sendmail,default installation] In order to use Sendmail, first " +"ensure the [package]*sendmail* package is installed on your system by " +"running, as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:333 +#, no-wrap +msgid "~]#{nbsp}dnf install sendmail\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:336 +msgid "" +"In order to configure Sendmail, ensure the [package]*sendmail-cf* package is " +"installed on your system by running, as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:340 +#, no-wrap +msgid "~]#{nbsp}dnf install sendmail-cf\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:345 +msgid "" +"Before using Sendmail, the default MTA has to be switched from Postfix. For " +"more information how to switch the default MTA refer to " +"xref:Mail_Servers.adoc#s1-email-mta[Mail Transport Agents]." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:347 +msgid "The Sendmail executable is `sendmail`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:349 +msgid "" +"Sendmail's lengthy and detailed configuration file is " +"`/etc/mail/sendmail.cf`. Avoid editing the `sendmail.cf` file directly. To " +"make configuration changes to Sendmail, edit the `/etc/mail/sendmail.mc` " +"file, back up the original `/etc/mail/sendmail.cf` file, and use the " +"following alternatives to generate a new configuration file:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:351 +msgid "" +"Use the included makefile in `/etc/mail/` to create a new " +"`/etc/mail/sendmail.cf` configuration file:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:355 +#, no-wrap +msgid "~]#{nbsp}make all -C /etc/mail/\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:358 +msgid "" +"All other generated files in `/etc/mail` (db files) will be regenerated if " +"needed. The old makemap commands are still usable. The make command is " +"automatically used whenever you start or restart the `sendmail` service." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:360 +msgid "" +"More information on configuring Sendmail can be found in " +"xref:Mail_Servers.adoc#s3-email-mta-sendmail-changes[Common Sendmail " +"Configuration Changes]." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:362 +msgid "" +"Various Sendmail configuration files are installed in the `/etc/mail/` " +"directory including:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:364 +msgid "`access` — Specifies which systems can use Sendmail for outbound email." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:366 +msgid "`domaintable` — Specifies domain name mapping." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:368 +msgid "`local-host-names` — Specifies aliases for the host." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:370 +msgid "" +"`mailertable` — Specifies instructions that override routing for particular " +"domains." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:372 +msgid "" +"`virtusertable` — Specifies a domain-specific form of aliasing, allowing " +"multiple virtual domains to be hosted on one machine." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:374 +msgid "" +"Several of the configuration files in the `/etc/mail/` directory, such as " +"`access`, `domaintable`, `mailertable` and `virtusertable`, must actually " +"store their information in database files before Sendmail can use any " +"configuration changes. To include any changes made to these configurations " +"in their database files, run the following commands, as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:379 +#, no-wrap +msgid "" +"~]#{nbsp}cd /etc/mail/\n" +"~]#{nbsp}make all\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:382 +msgid "" +"This will update `virtusertable.db`, `access.db`, `domaintable.db`, " +"`mailertable.db`, `sendmail.cf`, and `submit.cf`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:384 +msgid "" +"To update all the database files listed above and to update a custom " +"database file, use a command in the following format:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:388 +#, no-wrap +msgid "[command]#make _name.db_ all#\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:391 +msgid "where _name_ represents the name of the custom database file to be updated." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:393 +msgid "To update a single database, use a command in the following format:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:397 +#, no-wrap +msgid "[command]#make _name.db_pass:attributes[{blank}]#\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:400 +msgid "where _name.db_ represents the name of the database file to be updated." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:402 +msgid "" +"You may also restart the `sendmail` service for the changes to take effect " +"by running:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:406 ./pages/servers/Mail_Servers.adoc:443 +#: ./pages/servers/Mail_Servers.adoc:454 ./pages/servers/Mail_Servers.adoc:495 +#, no-wrap +msgid "~]#{nbsp}systemctl restart sendmail\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:409 +msgid "" +"For example, to have all emails addressed to the `example.com` domain " +"delivered to `bob@other-example.com`, add the following line to the " +"`virtusertable` file:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:414 +#, no-wrap +msgid "[command]#@example.com bob@other-example.com#\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:417 +msgid "To finalize the change, the `virtusertable.db` file must be updated:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:421 +#, no-wrap +msgid "~]#{nbsp}make virtusertable.db all\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:424 +msgid "" +"Using the [option]`all` option will result in the `virtusertable.db` and " +"`access.db` being updated at the same time." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:426 +#, no-wrap +msgid "Common Sendmail Configuration Changes" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:429 +msgid "" +"indexterm:[Sendmail,common configuration changes]indexterm:[Sendmail,with " +"UUCP] When altering the Sendmail configuration file, it is best not to edit " +"an existing file, but to generate an entirely new `/etc/mail/sendmail.cf` " +"file." +msgstr "" + +#. type: Block title +#: ./pages/servers/Mail_Servers.adoc:430 +#, no-wrap +msgid "Backup the sendmail.cf file before changing its content" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:435 +msgid "" +"Before replacing or making any changes to the `sendmail.cf` file, create a " +"backup copy." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:439 +msgid "" +"To add the desired functionality to Sendmail, edit the " +"`/etc/mail/sendmail.mc` file as `root`. Once you are finished, restart the " +"`sendmail` service and, if the [package]*m4* package is installed, the " +"[command]#m4# macro processor will automatically generate a new " +"`sendmail.cf` configuration file:" +msgstr "" + +#. type: Block title +#: ./pages/servers/Mail_Servers.adoc:445 +#, no-wrap +msgid "Configuring Sendmail as a server for other clients" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:450 +msgid "" +"The default `sendmail.cf` file does not allow Sendmail to accept network " +"connections from any host other than the local computer. To configure " +"Sendmail as a server for other clients, edit the `/etc/mail/sendmail.mc` " +"file, and either change the address specified in the [command]#Addr=# option " +"of the [command]#DAEMON_OPTIONS# directive from [command]#127.0.0.1# to the " +"IP address of an active network device or comment out the " +"[command]#DAEMON_OPTIONS# directive all together by placing [command]#dnl# " +"at the beginning of the line. When finished, regenerate " +"`/etc/mail/sendmail.cf` by restarting the service:" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:459 +msgid "" +"The default configuration in {MAJOROS} works for most `SMTP`-only " +"sites. However, it does not work for _UUCP_ (_UNIX-to-UNIX Copy Protocol_) " +"sites. If using UUCP mail transfers, the `/etc/mail/sendmail.mc` file must " +"be reconfigured and a new `/etc/mail/sendmail.cf` file must be generated." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:461 +msgid "" +"Consult the `/usr/share/sendmail-cf/README` file before editing any files in " +"the directories under the `/usr/share/sendmail-cf/` directory, as they can " +"affect the future configuration of the `/etc/mail/sendmail.cf` file." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:463 +#, no-wrap +msgid "Masquerading" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:466 +msgid "" +"indexterm:[Sendmail,aliases]indexterm:[Sendmail,masquerading] One common " +"Sendmail configuration is to have a single machine act as a mail gateway for " +"all machines on the network. For example, a company may want to have a " +"machine called `mail.example.com` that handles all of their email and " +"assigns a consistent return address to all outgoing mail." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:468 +msgid "" +"In this situation, the Sendmail server must masquerade the machine names on " +"the company network so that their return address is `user@example.com` " +"instead of `user@host.example.com`." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:470 +msgid "To do this, add the following lines to `/etc/mail/sendmail.mc`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:479 +#, no-wrap +msgid "" +"FEATURE(always_add_domain)dnl\n" +"FEATURE(`masquerade_entire_domain')dnl\n" +"FEATURE(`masquerade_envelope')dnl\n" +"FEATURE(`allmasquerade')dnl\n" +"MASQUERADE_AS(`example.com.')dnl\n" +"MASQUERADE_DOMAIN(`example.com.')dnl\n" +"MASQUERADE_AS(example.com)dnl\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:482 +msgid "" +"After generating a new `sendmail.cf` file using the [command]#m4# macro " +"processor, this configuration makes all mail from inside the network appear " +"as if it were sent from `example.com`." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:484 +#, no-wrap +msgid "Stopping Spam" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:487 +msgid "" +"indexterm:[Sendmail,spam] Email spam can be defined as unnecessary and " +"unwanted email received by a user who never requested the communication. It " +"is a disruptive, costly, and widespread abuse of Internet communication " +"standards." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:489 +msgid "" +"Sendmail makes it relatively easy to block new spamming techniques being " +"employed to send junk email. It even blocks many of the more usual spamming " +"methods by default. Main anti-spam features available in sendmail are " +"_header checks_, _relaying denial_ (default from version 8.9), _access " +"database and sender information checks_." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:491 +msgid "" +"For example, forwarding of `SMTP` messages, also called relaying, has been " +"disabled by default since Sendmail version 8.9. Before this change occurred, " +"Sendmail directed the mail host (`x.edu`) to accept messages from one party " +"(`y.com`) and sent them to a different party (`z.net`). Now, however, " +"Sendmail must be configured to permit any domain to relay mail through the " +"server. To configure relay domains, edit the `/etc/mail/relay-domains` file " +"and restart Sendmail" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:498 +msgid "" +"However users can also be sent spam from from servers on the Internet. In " +"these instances, Sendmail's access control features available through the " +"`/etc/mail/access` file can be used to prevent connections from unwanted " +"hosts. The following example illustrates how this file can be used to both " +"block and specifically allow access to the Sendmail server:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:502 +#, no-wrap +msgid "" +"badspammer.com ERROR:550 \"Go away and do not spam us anymore\" " +"tux.badspammer.com OK 10.0 RELAY\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:505 +msgid "" +"This example shows that any email sent from `badspammer.com` is blocked with " +"a 550 RFC-821 compliant error code, with a message sent back. Email sent " +"from the `tux.badspammer.com` sub-domain, is accepted. The last line shows " +"that any email sent from the 10.0.*.* network can be relayed through the " +"mail server." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:507 +msgid "" +"Because the `/etc/mail/access.db` file is a database, use the " +"[command]#makemap# command to update any changes. Do this using the " +"following command as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:511 +#, no-wrap +msgid "~]#{nbsp}makemap hash /etc/mail/access < /etc/mail/access\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:514 +msgid "" +"Message header analysis allows you to reject mail based on header " +"contents. `SMTP` servers store information about an email's journey in the " +"message header. As the message travels from one MTA to another, each puts in " +"a `Received` header above all the other `Received` headers. It is important " +"to note that this information may be altered by spammers." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:516 +msgid "" +"The above examples only represent a small part of what Sendmail can do in " +"terms of allowing or blocking access. See the " +"`/usr/share/sendmail-cf/README` file for more information and examples." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:518 +msgid "" +"Since Sendmail calls the Procmail MDA when delivering mail, it is also " +"possible to use a spam filtering program, such as SpamAssassin, to identify " +"and file spam for users. See xref:Mail_Servers.adoc#s3-email-mda-spam[Spam " +"Filters] for more information about using SpamAssassin." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:520 +#, no-wrap +msgid "Using Sendmail with LDAP" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:523 +msgid "" +"indexterm:[Sendmail,LDAP and] Using `LDAP` is a very quick and powerful way " +"to find specific information about a particular user from a much larger " +"group. For example, an `LDAP` server can be used to look up a particular " +"email address from a common corporate directory by the user's last name. In " +"this kind of implementation, `LDAP` is largely separate from Sendmail, with " +"`LDAP` storing the hierarchical user information and Sendmail only being " +"given the result of `LDAP` queries in pre-addressed email messages." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:525 +msgid "" +"However, Sendmail supports a much greater integration with `LDAP`, where it " +"uses `LDAP` to replace separately maintained files, such as `/etc/aliases` " +"and `/etc/mail/virtusertables`, on different mail servers that work together " +"to support a medium- to enterprise-level organization. In short, `LDAP` " +"abstracts the mail routing level from Sendmail and its separate " +"configuration files to a powerful `LDAP` cluster that can be leveraged by " +"many different applications." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:527 +msgid "" +"The current version of Sendmail contains support for `LDAP`. To extend the " +"Sendmail server using `LDAP`, first get an `LDAP` server, such as " +"[application]*OpenLDAP*, running and properly configured. Then edit the " +"`/etc/mail/sendmail.mc` to include the following:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:532 +#, no-wrap +msgid "" +"LDAPROUTE_DOMAIN('pass:quotes[_yourdomain.com_]')dnl\n" +"FEATURE('ldap_routing')dnl\n" +msgstr "" + +#. type: Block title +#: ./pages/servers/Mail_Servers.adoc:534 +#, no-wrap +msgid "Advanced configuration" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:539 +msgid "" +"This is only for a very basic configuration of Sendmail with `LDAP`. The " +"configuration can differ greatly from this depending on the implementation " +"of `LDAP`, especially when configuring several Sendmail machines to use a " +"common `LDAP` server." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:541 +msgid "" +"Consult `/usr/share/sendmail-cf/README` for detailed `LDAP` routing " +"configuration instructions and examples." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:545 +msgid "" +"Next, recreate the `/etc/mail/sendmail.cf` file by running the [command]#m4# " +"macro processor and again restarting Sendmail. See " +"xref:Mail_Servers.adoc#s3-email-mta-sendmail-changes[Common Sendmail " +"Configuration Changes] for instructions." +msgstr "" + +#. type: Title === +#: ./pages/servers/Mail_Servers.adoc:549 +#, no-wrap +msgid "Fetchmail" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:552 +msgid "" +"indexterm:[email,Fetchmail]indexterm:[Fetchmail] Fetchmail is an MTA which " +"retrieves email from remote servers and delivers it to the local MTA. Many " +"users appreciate the ability to separate the process of downloading their " +"messages located on a remote server from the process of reading and " +"organizing their email in an MUA. Designed with the needs of dial-up users " +"in mind, Fetchmail connects and quickly downloads all of the email messages " +"to the mail spool file using any number of protocols, including `POP3` and " +"`IMAP`. It can even forward email messages to an `SMTP` server, if " +"necessary." +msgstr "" + +#. type: Block title +#: ./pages/servers/Mail_Servers.adoc:553 +#, no-wrap +msgid "Installing the fetchmail package" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:558 +msgid "" +"In order to use [application]*Fetchmail*, first ensure the " +"[package]*fetchmail* package is installed on your system by running, as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:562 +#, no-wrap +msgid "~]#{nbsp}dnf install fetchmail\n" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:569 +msgid "" +"Fetchmail is configured for each user through the use of a `.fetchmailrc` " +"file in the user's home directory. If it does not already exist, create the " +"`.fetchmailrc` file in your home directory" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:571 +msgid "" +"Using preferences in the `.fetchmailrc` file, Fetchmail checks for email on " +"a remote server and downloads it. It then delivers it to port 25 on the " +"local machine, using the local MTA to place the email in the correct user's " +"spool file. If Procmail is available, it is launched to filter the email and " +"place it in a mailbox so that it can be read by an MUA." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:573 +#, no-wrap +msgid "Fetchmail Configuration Options" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:576 +msgid "" +"indexterm:[Fetchmail,configuration options]indexterm:[.fetchmailrc] Although " +"it is possible to pass all necessary options on the command line to check " +"for email on a remote server when executing Fetchmail, using a " +"`.fetchmailrc` file is much easier. Place any desired configuration options " +"in the `.fetchmailrc` file for those options to be used each time the " +"[command]#fetchmail# command is issued. It is possible to override these at " +"the time Fetchmail is run by specifying that option on the command line." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:578 +msgid "" +"A user's `.fetchmailrc` file contains three classes of configuration " +"options:" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:580 +#, no-wrap +msgid "" +"*global options* — Gives Fetchmail instructions that control the operation " +"of the program or provide settings for every connection that checks for " +"email.\n" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:582 +#, no-wrap +msgid "" +"*server options* — Specifies necessary information about the server being " +"polled, such as the host name, as well as preferences for specific email " +"servers, such as the port to check or number of seconds to wait before " +"timing out. These options affect every user using that server.\n" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:584 +#, no-wrap +msgid "" +"*user options* — Contains information, such as user name and password, " +"necessary to authenticate and check for email using a specified email " +"server.\n" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:586 +msgid "" +"Global options appear at the top of the `.fetchmailrc` file, followed by one " +"or more server options, each of which designate a different email server " +"that Fetchmail should check. User options follow server options for each " +"user account checking that email server. Like server options, multiple user " +"options may be specified for use with a particular server as well as to " +"check multiple email accounts on the same server." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:588 +msgid "" +"Server options are called into service in the `.fetchmailrc` file by the use " +"of a special option verb, [command]#poll# or [command]#skip#, that precedes " +"any of the server information. The [command]#poll# action tells Fetchmail to " +"use this server option when it is run, which checks for email using the " +"specified user options. Any server options after a [command]#skip# action, " +"however, are not checked unless this server's host name is specified when " +"Fetchmail is invoked. The [command]#skip# option is useful when testing " +"configurations in the `.fetchmailrc` file because it only checks skipped " +"servers when specifically invoked, and does not affect any currently working " +"configurations." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:590 +msgid "The following is an example of a `.fetchmailrc` file:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:595 +#, no-wrap +msgid "" +"set postmaster \"user1\"\n" +"set bouncemail\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:598 +#, no-wrap +msgid "" +"poll pop.domain.com proto pop3\n" +" user 'user1' there with password 'secret' is user1 here\n" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:602 +#, no-wrap +msgid "" +"poll mail.domain2.com\n" +" user 'user5' there with password 'secret2' is user1 here\n" +" user 'user7' there with password 'secret3' is user1 here\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:605 +msgid "" +"In this example, the global options specify that the user is sent email as a " +"last resort ([command]#postmaster# option) and all email errors are sent to " +"the postmaster instead of the sender ([command]#bouncemail# option). The " +"[command]#set# action tells Fetchmail that this line contains a global " +"option. Then, two email servers are specified, one set to check using " +"`POP3`, the other for trying various protocols to find one that works. Two " +"users are checked using the second server option, but all email found for " +"any user is sent to [command]#user1#pass:attributes[{blank}]'s mail " +"spool. This allows multiple mailboxes to be checked on multiple servers, " +"while appearing in a single MUA inbox. Each user's specific information " +"begins with the [command]#user# action." +msgstr "" + +#. type: Block title +#: ./pages/servers/Mail_Servers.adoc:606 +#, no-wrap +msgid "Omitting the password from the configuration" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:611 +msgid "" +"Users are not required to place their password in the `.fetchmailrc` " +"file. Omitting the [command]#with password " +"'pass:attributes[{blank}]_password_pass:attributes[{blank}]'# section causes " +"Fetchmail to ask for a password when it is launched." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:615 +msgid "" +"Fetchmail has numerous global, server, and local options. Many of these " +"options are rarely used or only apply to very specific situations. The " +"`fetchmail` man page explains each option in detail, but the most common " +"ones are listed in the following three sections." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:617 +#, no-wrap +msgid "Global Options" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:620 +msgid "" +"indexterm:[Fetchmail,configuration options,global " +"options]indexterm:[ch-email .fetchmailrc,global options] Each global option " +"should be placed on a single line after a [command]#set# action." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:622 +msgid "" +"[command]#daemon _seconds_pass:attributes[{blank}]# — Specifies daemon-mode, " +"where Fetchmail stays in the background. Replace _seconds_ with the number " +"of seconds Fetchmail is to wait before polling the server." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:624 +msgid "" +"[command]#postmaster# — Specifies a local user to send mail to in case of " +"delivery problems." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:626 +msgid "" +"[command]#syslog# — Specifies the log file for errors and status " +"messages. By default, this is `/var/log/maillog`." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:628 +#, no-wrap +msgid "Server Options" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:631 +msgid "" +"indexterm:[Fetchmail,configuration options,server " +"options]indexterm:[.fetchmailrc,server options] Server options must be " +"placed on their own line in `.fetchmailrc` after a [command]#poll# or " +"[command]#skip# action." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:633 +msgid "" +"[command]#auth _auth-type_pass:attributes[{blank}]# — Replace _auth-type_ " +"with the type of authentication to be used. By default, [command]#password# " +"authentication is used, but some protocols support other types of " +"authentication, including [command]#kerberos_v5#, [command]#kerberos_v4#, " +"and [command]#ssh#. If the [command]#any# authentication type is used, " +"Fetchmail first tries methods that do not require a password, then methods " +"that mask the password, and finally attempts to send the password " +"unencrypted to authenticate to the server." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:635 +msgid "" +"[command]#interval _number_pass:attributes[{blank}]# — Polls the specified " +"server every " +"[command]#pass:attributes[{blank}]_number_pass:attributes[{blank}]# of times " +"that it checks for email on all configured servers. This option is generally " +"used for email servers where the user rarely receives messages." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:637 +msgid "" +"[command]#port _port-number_pass:attributes[{blank}]# — Replace " +"_port-number_ with the port number. This value overrides the default port " +"number for the specified protocol." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:639 +msgid "" +"[command]#proto _protocol_pass:attributes[{blank}]# — Replace _protocol_ " +"with the protocol, such as [command]#pop3# or [command]#imap#, to use when " +"checking for messages on the server." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:641 +msgid "" +"[command]#timeout _seconds_pass:attributes[{blank}]# — Replace _seconds_ " +"with the number of seconds of server inactivity after which Fetchmail gives " +"up on a connection attempt. If this value is not set, a default of " +"[command]#300# seconds is used." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:643 +#, no-wrap +msgid "User Options" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:646 +msgid "" +"indexterm:[Fetchmail,configuration options,user " +"options]indexterm:[.fetchmailrc,user options] User options may be placed on " +"their own lines beneath a server option or on the same line as the server " +"option. In either case, the defined options must follow the [command]#user# " +"option (defined below)." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:648 +msgid "" +"[command]#fetchall# — Orders Fetchmail to download all messages in the " +"queue, including messages that have already been viewed. By default, " +"Fetchmail only pulls down new messages." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:650 +msgid "" +"[command]#fetchlimit _number_pass:attributes[{blank}]# — Replace _number_ " +"with the number of messages to be retrieved before stopping." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:652 +msgid "" +"[command]#flush# — Deletes all previously viewed messages in the queue " +"before retrieving new messages." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:654 +msgid "" +"[command]#limit _max-number-bytes_pass:attributes[{blank}]# — Replace " +"_max-number-bytes_ with the maximum size in bytes that messages are allowed " +"to be when retrieved by Fetchmail. This option is useful with slow network " +"links, when a large message takes too long to download." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:656 +msgid "" +"[command]#password " +"'pass:attributes[{blank}]_password_pass:attributes[{blank}]'# — Replace " +"_password_ with the user's password." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:658 +msgid "" +"[command]#preconnect " +"\"pass:attributes[{blank}]_command_pass:attributes[{blank}]\"# — Replace " +"_command_ with a command to be executed before retrieving messages for the " +"user." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:660 +msgid "" +"[command]#postconnect " +"\"pass:attributes[{blank}]_command_pass:attributes[{blank}]\"# — Replace " +"_command_ with a command to be executed after retrieving messages for the " +"user." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:662 +msgid "[command]#ssl# — Activates SSL encryption." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:664 +msgid "" +"[command]#user " +"\"pass:attributes[{blank}]_username_pass:attributes[{blank}]\"# — Replace " +"_username_ with the username used by Fetchmail to retrieve messages. *This " +"option must precede all other user options.*" +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:666 +#, no-wrap +msgid "Fetchmail Command Options" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:669 +msgid "" +"indexterm:[Fetchmail,command options] Most Fetchmail options used on the " +"command line when executing the [command]#fetchmail# command mirror the " +"`.fetchmailrc` configuration options. In this way, Fetchmail may be used " +"with or without a configuration file. These options are not used on the " +"command line by most users because it is easier to leave them in the " +"`.fetchmailrc` file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:671 +msgid "" +"There may be times when it is desirable to run the [command]#fetchmail# " +"command with other options for a particular purpose. It is possible to issue " +"command options to temporarily override a `.fetchmailrc` setting that is " +"causing an error, as any options specified at the command line override " +"configuration file options." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:673 +#, no-wrap +msgid "Informational or Debugging Options" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:676 +msgid "" +"indexterm:[Fetchmail,command options,informational] Certain options used " +"after the [command]#fetchmail# command can supply important information." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:678 +msgid "" +"[command]#--configdump# — Displays every possible option based on " +"information from `.fetchmailrc` and Fetchmail defaults. No email is " +"retrieved for any users when using this option." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:680 +msgid "" +"[command]#-s# — Executes Fetchmail in silent mode, preventing any messages, " +"other than errors, from appearing after the [command]#fetchmail# command." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:682 +msgid "" +"[command]#-v# — Executes Fetchmail in verbose mode, displaying every " +"communication between Fetchmail and remote email servers." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:684 +msgid "" +"[command]#-V# — Displays detailed version information, lists its global " +"options, and shows settings to be used with each user, including the email " +"protocol and authentication method. No email is retrieved for any users when " +"using this option." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:686 +#, no-wrap +msgid "Special Options" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:689 +msgid "" +"indexterm:[Fetchmail,command options,special] These options are occasionally " +"useful for overriding defaults often found in the `.fetchmailrc` file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:691 +msgid "" +"[command]#-a# — Fetchmail downloads all messages from the remote email " +"server, whether new or previously viewed. By default, Fetchmail only " +"downloads new messages." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:693 +msgid "" +"[command]#-k# — Fetchmail leaves the messages on the remote email server " +"after downloading them. This option overrides the default behavior of " +"deleting messages after downloading them." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:695 +msgid "" +"[command]#-l _max-number-bytes_pass:attributes[{blank}]# — Fetchmail does " +"not download any messages over a particular size and leaves them on the " +"remote email server." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:697 +msgid "[command]#--quit# — Quits the Fetchmail daemon process." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:699 +msgid "" +"More commands and `.fetchmailrc` options can be found in the " +"[command]#fetchmail# man page." +msgstr "" + +#. type: Title === +#: ./pages/servers/Mail_Servers.adoc:701 +#, no-wrap +msgid "Mail Transport Agent (MTA) Configuration" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:704 +msgid "" +"indexterm:[Mail Transport Agent,MTA]indexterm:[MTA,setting " +"default]indexterm:[MTA,switching with Mail Transport Agent " +"Switcher]indexterm:[Mail Transport Agent Switcher]indexterm:[Mail User " +"Agent]indexterm:[MUA] A _Mail Transport Agent_ (MTA) is essential for " +"sending email. A _Mail User Agent_ (MUA) such as [application]*Evolution*, " +"[application]*Thunderbird*, and [application]*Mutt*, is used to read and " +"compose email. When a user sends an email from an MUA, the message is handed " +"off to the MTA, which sends the message through a series of MTAs until it " +"reaches its destination." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:708 +msgid "" +"Even if a user does not plan to send email from the system, some automated " +"tasks or system programs might use the [command]#mail# command to send email " +"containing log messages to the `root` user of the local system. " +"indexterm:[sendmail]indexterm:[postfix] {MAJOROSVER} provides two MTAs: " +"Postfix and Sendmail. If both are installed, Postfix is the default " +"MTA. Note that Sendmail is considered deprecated in MAJOROS;." +msgstr "" + +#. type: Title == +#: ./pages/servers/Mail_Servers.adoc:710 +#, no-wrap +msgid "Mail Delivery Agents" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:713 +msgid "" +"{MAJOROS} includes two primary MDAs, Procmail and [command]#mail#. Both of " +"the applications are considered LDAs and both move email from the MTA's " +"spool file into the user's mailbox. However, Procmail provides a robust " +"filtering system." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:717 +msgid "" +"This section details only Procmail. For information on the [command]#mail# " +"command, consult its man page ([command]#man mail#). " +"indexterm:[email,Procmail]indexterm:[Procmail] Procmail delivers and filters " +"email as it is placed in the mail spool file of the localhost. It is " +"powerful, gentle on system resources, and widely used. Procmail can play a " +"critical role in delivering email to be read by email client applications." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:719 +msgid "" +"Procmail can be invoked in several different ways. Whenever an MTA places an " +"email into the mail spool file, Procmail is launched. Procmail then filters " +"and files the email for the MUA and quits. Alternatively, the MUA can be " +"configured to execute Procmail any time a message is received so that " +"messages are moved into their correct mailboxes. By default, the presence of " +"`/etc/procmailrc` or of a `~/.procmailrc` file (also called an _rc_ file) in " +"the user's home directory invokes Procmail whenever an MTA receives a new " +"message." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:721 +msgid "" +"By default, no system-wide `rc` files exist in the `/etc/` directory and no " +"`.procmailrc` files exist in any user's home directory. Therefore, to use " +"Procmail, each user must construct a `.procmailrc` file with specific " +"environment variables and rules." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:723 +msgid "" +"Whether Procmail acts upon an email message depends upon whether the message " +"matches a specified set of conditions or _recipes_ in the `rc` file. If a " +"message matches a recipe, then the email is placed in a specified file, is " +"deleted, or is otherwise processed." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:725 +msgid "" +"When Procmail starts, it reads the email message and separates the body from " +"the header information. Next, Procmail looks for a `/etc/procmailrc` file " +"and `rc` files in the `/etc/procmailrcs` directory for default, system-wide, " +"Procmail environmental variables and recipes. Procmail then searches for a " +"`.procmailrc` file in the user's home directory. Many users also create " +"additional `rc` files for Procmail that are referred to within the " +"`.procmailrc` file in their home directory." +msgstr "" + +#. type: Title === +#: ./pages/servers/Mail_Servers.adoc:727 +#, no-wrap +msgid "Procmail Configuration" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:730 +msgid "" +"indexterm:[Procmail,configuration]indexterm:[.procmailrc] The Procmail " +"configuration file contains important environmental variables. These " +"variables specify things such as which messages to sort and what to do with " +"the messages that do not match any recipes." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:732 +msgid "" +"These environmental variables usually appear at the beginning of the " +"`~/.procmailrc` file in the following format:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:736 +#, no-wrap +msgid "_env-variable_pass:attributes[{blank}]=\"pass:attributes[{blank}]_value_pass:attributes[{blank}]\"\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:739 +msgid "" +"In this example, " +"[command]#pass:attributes[{blank}]_env-variable_pass:attributes[{blank}]# is " +"the name of the variable and " +"[command]#pass:attributes[{blank}]_value_pass:attributes[{blank}]# defines " +"the variable." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:741 +msgid "" +"There are many environment variables not used by most Procmail users and " +"many of the more important environment variables are already defined by a " +"default value. Most of the time, the following variables are used:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:743 +msgid "" +"[command]#DEFAULT# — Sets the default mailbox where messages that do not " +"match any recipes are placed." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:745 +msgid "The default [command]#DEFAULT# value is the same as [command]#$ORGMAIL#." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:747 +msgid "" +"[command]#INCLUDERC# — Specifies additional `rc` files containing more " +"recipes for messages to be checked against. This breaks up the Procmail " +"recipe lists into individual files that fulfill different roles, such as " +"blocking spam and managing email lists, that can then be turned off or on by " +"using comment characters in the user's `~/.procmailrc` file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:749 +msgid "For example, lines in a user's `~/.procmailrc` file may look like this:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:755 +#, no-wrap +msgid "" +"MAILDIR=$HOME/Msgs\n" +"INCLUDERC=$MAILDIR/lists.rc\n" +"INCLUDERC=$MAILDIR/spam.rc\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:758 +msgid "" +"To turn off Procmail filtering of email lists but leaving spam control in " +"place, comment out the first [command]#INCLUDERC# line with a hash sign " +"(`#`). Note that it uses paths relative to the current directory." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:760 +msgid "" +"[command]#LOCKSLEEP# — Sets the amount of time, in seconds, between attempts " +"by Procmail to use a particular lockfile. The default is 8 seconds." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:762 +msgid "" +"[command]#LOCKTIMEOUT# — Sets the amount of time, in seconds, that must pass " +"after a lockfile was last modified before Procmail assumes that the lockfile " +"is old and can be deleted. The default is 1024 seconds." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:764 +msgid "" +"[command]#LOGFILE# — The file to which any Procmail information or error " +"messages are written." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:766 +msgid "" +"[command]#MAILDIR# — Sets the current working directory for Procmail. If " +"set, all other Procmail paths are relative to this directory." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:768 +msgid "" +"[command]#ORGMAIL# — Specifies the original mailbox, or another place to put " +"the messages if they cannot be placed in the default or recipe-required " +"location." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:770 +msgid "By default, a value of [command]#/var/spool/mail/$LOGNAME# is used." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:772 +msgid "" +"[command]#SUSPEND# — Sets the amount of time, in seconds, that Procmail " +"pauses if a necessary resource, such as swap space, is not available." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:774 +msgid "" +"[command]#SWITCHRC# — Allows a user to specify an external file containing " +"additional Procmail recipes, much like the [command]#INCLUDERC# option, " +"except that recipe checking is actually stopped on the referring " +"configuration file and only the recipes on the [command]#SWITCHRC#-specified " +"file are used." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:776 +msgid "" +"[command]#VERBOSE# — Causes Procmail to log more information. This option is " +"useful for debugging." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:778 +msgid "" +"Other important environmental variables are pulled from the shell, such as " +"[command]#LOGNAME#, the login name; [command]#HOME#, the location of the " +"home directory; and [command]#SHELL#, the default shell." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:780 +msgid "" +"A comprehensive explanation of all environments variables, and their default " +"values, is available in the `procmailrc` man page." +msgstr "" + +#. type: Title === +#: ./pages/servers/Mail_Servers.adoc:782 +#, no-wrap +msgid "Procmail Recipes" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:785 +msgid "" +"indexterm:[Procmail,recipes] New users often find the construction of " +"recipes the most difficult part of learning to use Procmail. This difficulty " +"is often attributed to recipes matching messages by using _regular " +"expressions_ which are used to specify qualifications for string " +"matching. However, regular expressions are not very difficult to construct " +"and even less difficult to understand when read. Additionally, the " +"consistency of the way Procmail recipes are written, regardless of regular " +"expressions, makes it easy to learn by example. To see example Procmail " +"recipes, see " +"xref:Mail_Servers.adoc#s3-email-procmail-recipes-examples[Recipe Examples]." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:787 +msgid "Procmail recipes take the following form:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:796 +#, no-wrap +msgid "" +":0 pass:quotes[_flags_] : pass:quotes[_lockfile-name_]\n" +"* pass:quotes[_condition_1_special-condition-character_] " +"pass:quotes[_condition_1_regular_expression_]\n" +"* pass:quotes[_condition_2_special-condition-character_] " +"pass:quotes[_condition-2_regular_expression_]\n" +"* pass:quotes[_condition_N_special-condition-character_] " +"pass:quotes[_condition-N_regular_expression_]\n" +" pass:quotes[_special-action-character_]\n" +" pass:quotes[_action-to-perform_]\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:799 +msgid "" +"The first two characters in a Procmail recipe are a colon and a " +"zero. Various flags can be placed after the zero to control how Procmail " +"processes the recipe. A colon after the " +"[command]#pass:attributes[{blank}]_flags_pass:attributes[{blank}]# section " +"specifies that a lockfile is created for this message. If a lockfile is " +"created, the name can be specified by replacing " +"[command]#pass:attributes[{blank}]_lockfile-name_pass:attributes[{blank}]#." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:801 +msgid "" +"A recipe can contain several conditions to match against the message. If it " +"has no conditions, every message matches the recipe. Regular expressions are " +"placed in some conditions to facilitate message matching. If multiple " +"conditions are used, they must all match for the action to be " +"performed. Conditions are checked based on the flags set in the recipe's " +"first line. Optional special characters placed after the asterisk character " +"([command]#*#) can further control the condition." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:803 +msgid "" +"The " +"[command]#pass:attributes[{blank}]_action-to-perform_pass:attributes[{blank}]# " +"argument specifies the action taken when the message matches one of the " +"conditions. There can only be one action per recipe. In many cases, the name " +"of a mailbox is used here to direct matching messages into that file, " +"effectively sorting the email. Special action characters may also be used " +"before the action is specified. See " +"xref:Mail_Servers.adoc#s3-email-procmail-recipes-special[Special Conditions " +"and Actions] for more information." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:805 +#, no-wrap +msgid "Delivering vs. Non-Delivering Recipes" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:809 +msgid "" +"indexterm:[Procmail,recipes,delivering]indexterm:[Procmail,recipes,non-delivering] " +"The action used if the recipe matches a particular message determines " +"whether it is considered a _delivering_ or _non-delivering_ recipe. A " +"delivering recipe contains an action that writes the message to a file, " +"sends the message to another program, or forwards the message to another " +"email address. A non-delivering recipe covers any other actions, such as a " +"_nesting block_. A nesting block is a set of actions, contained in braces " +"[command]#{# [command]#}#, that are performed on messages which match the " +"recipe's conditions. Nesting blocks can be nested inside one another, " +"providing greater control for identifying and performing actions on " +"messages." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:811 +msgid "" +"When messages match a delivering recipe, Procmail performs the specified " +"action and stops comparing the message against any other recipes. Messages " +"that match non-delivering recipes continue to be compared against other " +"recipes." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:813 +#, no-wrap +msgid "Flags" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:816 +msgid "" +"indexterm:[Procmail,recipes,flags] Flags are essential to determine how or " +"if a recipe's conditions are compared to a message. The [application]*egrep* " +"utility is used internally for matching of the conditions. The following " +"flags are commonly used:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:818 +msgid "" +"[command]#A# — Specifies that this recipe is only used if the previous " +"recipe without an [command]#A# or [command]#a# flag also matched this " +"message." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:820 +msgid "" +"[command]#a# — Specifies that this recipe is only used if the previous " +"recipe with an [command]#A# or [command]#a# flag also matched this message " +"*and* was successfully completed." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:822 +msgid "" +"[command]#B# — Parses the body of the message and looks for matching " +"conditions." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:824 +msgid "" +"[command]#b# — Uses the body in any resulting action, such as writing the " +"message to a file or forwarding it. This is the default behavior." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:826 +msgid "" +"[command]#c# — Generates a carbon copy of the email. This is useful with " +"delivering recipes, since the required action can be performed on the " +"message and a copy of the message can continue being processed in the `rc` " +"files." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:828 +msgid "" +"[command]#D# — Makes the [command]#egrep# comparison case-sensitive. By " +"default, the comparison process is not case-sensitive." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:830 +msgid "" +"[command]#E# — While similar to the [command]#A# flag, the conditions in the " +"recipe are only compared to the message if the immediately preceding recipe " +"without an [command]#E# flag did not match. This is comparable to an `else` " +"action." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:832 +msgid "" +"[command]#e# — The recipe is compared to the message only if the action " +"specified in the immediately preceding recipe fails." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:834 +msgid "[command]#f# — Uses the pipe as a filter." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:836 +msgid "" +"[command]#H# — Parses the header of the message and looks for matching " +"conditions. This is the default behavior." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:838 +msgid "" +"[command]#h# — Uses the header in a resulting action. This is the default " +"behavior." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:840 +msgid "" +"[command]#w# — Tells Procmail to wait for the specified filter or program to " +"finish, and reports whether or not it was successful before considering the " +"message filtered." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:842 +msgid "" +"[command]#W# — Is identical to [command]#w# except that \"`Program " +"failure`\" messages are suppressed." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:844 +msgid "For a detailed list of additional flags, see the `procmailrc` man page." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:846 +#, no-wrap +msgid "Specifying a Local Lockfile" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:849 +msgid "" +"indexterm:[Procmail,recipes,local lockfiles] Lockfiles are very useful with " +"Procmail to ensure that more than one process does not try to alter a " +"message simultaneously. Specify a local lockfile by placing a colon " +"([command]#:#) after any flags on a recipe's first line. This creates a " +"local lockfile based on the destination file name plus whatever has been set " +"in the [command]#LOCKEXT# global environment variable." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:851 +msgid "" +"Alternatively, specify the name of the local lockfile to be used with this " +"recipe after the colon." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:853 +#, no-wrap +msgid "Special Conditions and Actions" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:856 +msgid "" +"indexterm:[Procmail,recipes,special " +"conditions]indexterm:[Procmail,recipes,special actions] Special characters " +"used before Procmail recipe conditions and actions change the way they are " +"interpreted." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:858 +msgid "" +"The following characters may be used after the asterisk character " +"([command]#*#) at the beginning of a recipe's condition line:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:860 +msgid "" +"[command]#!# — In the condition line, this character inverts the condition, " +"causing a match to occur only if the condition does not match the message." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:862 +msgid "[command]#<# — Checks if the message is under a specified number of bytes." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:864 +msgid "[command]#># — Checks if the message is over a specified number of bytes." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:866 +msgid "The following characters are used to perform special actions:" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:868 +msgid "" +"[command]#!# — In the action line, this character tells Procmail to forward " +"the message to the specified email addresses." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:870 +msgid "" +"[command]#$# — Refers to a variable set earlier in the `rc` file. This is " +"often used to set a common mailbox that is referred to by various recipes." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:872 +msgid "[command]#|# — Starts a specified program to process the message." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:874 +msgid "" +"[command]#{# and [command]#}# — Constructs a nesting block, used to contain " +"additional recipes to apply to matching messages." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:876 +msgid "" +"If no special character is used at the beginning of the action line, " +"Procmail assumes that the action line is specifying the mailbox in which to " +"write the message." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:878 +#, no-wrap +msgid "Recipe Examples" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:881 +msgid "" +"indexterm:[Procmail,recipes,examples] Procmail is an extremely flexible " +"program, but as a result of this flexibility, composing Procmail recipes " +"from scratch can be difficult for new users." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:883 +msgid "" +"The best way to develop the skills to build Procmail recipe conditions stems " +"from a strong understanding of regular expressions combined with looking at " +"many examples built by others. A thorough explanation of regular expressions " +"is beyond the scope of this section. The structure of Procmail recipes and " +"useful sample Procmail recipes can be found at various places on the " +"Internet. The proper use and adaptation of regular expressions can be " +"derived by viewing these recipe examples. In addition, introductory " +"information about basic regular expression rules can be found in the " +"`grep(1)` man page." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:885 +msgid "" +"The following simple examples demonstrate the basic structure of Procmail " +"recipes and can provide the foundation for more intricate constructions." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:887 +msgid "" +"A basic recipe may not even contain conditions, as is illustrated in the " +"following example:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:892 +#, no-wrap +msgid "" +":0:\n" +"new-mail.spool\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:895 +msgid "" +"The first line specifies that a local lockfile is to be created but does not " +"specify a name, so Procmail uses the destination file name and appends the " +"value specified in the [command]#LOCKEXT# environment variable. No condition " +"is specified, so every message matches this recipe and is placed in the " +"single spool file called `new-mail.spool`, located within the directory " +"specified by the [command]#MAILDIR# environment variable. An MUA can then " +"view messages in this file." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:897 +msgid "" +"A basic recipe, such as this, can be placed at the end of all `rc` files to " +"direct messages to a default location." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:899 +msgid "" +"The following example matched messages from a specific email address and " +"throws them away." +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:904 +#, no-wrap +msgid "" +":0\n" +"* ^From: spammer@domain.com\n" +"/dev/null\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:907 +msgid "" +"With this example, any messages sent by `spammer@domain.com` are sent to the " +"`/dev/null` device, deleting them." +msgstr "" + +#. type: Block title +#: ./pages/servers/Mail_Servers.adoc:908 +#, no-wrap +msgid "Sending messages to /dev/null" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:913 +msgid "" +"Be certain that rules are working as intended before sending messages to " +"`/dev/null` for permanent deletion. If a recipe inadvertently catches " +"unintended messages, and those messages disappear, it becomes difficult to " +"troubleshoot the rule." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:915 +msgid "" +"A better solution is to point the recipe's action to a special mailbox, " +"which can be checked from time to time to look for false positives. Once " +"satisfied that no messages are accidentally being matched, delete the " +"mailbox and direct the action to send the messages to `/dev/null`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:919 +msgid "" +"The following recipe grabs email sent from a particular mailing list and " +"places it in a specified folder." +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:924 +#, no-wrap +msgid "" +":0:\n" +"* ^(From|Cc|To).*tux-lug\n" +"tuxlug\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:927 +msgid "" +"Any messages sent from the `tux-lug@domain.com` mailing list are placed in " +"the `tuxlug` mailbox automatically for the MUA. Note that the condition in " +"this example matches the message if it has the mailing list's email address " +"on the `From`, `Cc`, or `To` lines." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:929 +msgid "" +"Consult the many Procmail online resources available in " +"xref:Mail_Servers.adoc#s1-email-additional-resources[Additional Resources] " +"for more detailed and powerful recipes." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:931 +#, no-wrap +msgid "Spam Filters" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:934 +msgid "" +"indexterm:[Procmail,recipes,SpamAssassin]indexterm:[SpamAssassin,using with " +"Procmail]indexterm:[email,spam,filtering out] Because it is called by " +"Sendmail, Postfix, and Fetchmail upon receiving new emails, Procmail can be " +"used as a powerful tool for combating spam." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:936 +msgid "" +"This is particularly true when Procmail is used in conjunction with " +"SpamAssassin. When used together, these two applications can quickly " +"identify spam emails, and sort or destroy them." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:938 +msgid "" +"SpamAssassin uses header analysis, text analysis, blacklists, a " +"spam-tracking database, and self-learning Bayesian spam analysis to quickly " +"and accurately identify and tag spam." +msgstr "" + +#. type: Block title +#: ./pages/servers/Mail_Servers.adoc:939 +#, no-wrap +msgid "Installing the spamassassin package" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:944 +msgid "" +"In order to use [application]*SpamAssassin*, first ensure the " +"[package]*spamassassin* package is installed on your system by running, as " +"`root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:948 +#, no-wrap +msgid "~]#{nbsp}dnf install spamassassin\n" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:955 +msgid "" +"The easiest way for a local user to use SpamAssassin is to place the " +"following line near the top of the `~/.procmailrc` file:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:959 +#, no-wrap +msgid "INCLUDERC=/etc/mail/spamassassin/spamassassin-default.rc\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:962 +msgid "" +"The `/etc/mail/spamassassin/spamassassin-default.rc` contains a simple " +"Procmail rule that activates SpamAssassin for all incoming email. If an " +"email is determined to be spam, it is tagged in the header as such and the " +"title is prepended with the following pattern:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:965 +#, no-wrap +msgid "*****SPAM*****\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:968 +msgid "" +"The message body of the email is also prepended with a running tally of what " +"elements caused it to be diagnosed as spam." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:970 +msgid "To file email tagged as spam, a rule similar to the following can be used:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:973 +#, no-wrap +msgid ":0 Hw * ^X-Spam-Status: Yes spam\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:976 +msgid "" +"This rule files all email tagged in the header as spam into a mailbox called " +"`spam`." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:978 +msgid "" +"Since SpamAssassin is a Perl script, it may be necessary on busy servers to " +"use the binary SpamAssassin daemon (`spamd`) and the client application " +"([application]*spamc*). Configuring SpamAssassin this way, however, requires " +"`root` access to the host." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:980 +msgid "To start the `spamd` daemon, type the following command:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:984 +#, no-wrap +msgid "~]#{nbsp}systemctl start spamassassin.service\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:987 +msgid "To start the SpamAssassin daemon when the system is booted, run:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:991 +#, no-wrap +msgid "[command]#systemctl enable spamassassin.service#\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:994 +msgid "" +"See " +"xref:infrastructure-services/Services_and_Daemons.adoc#ch-Services_and_Daemons[Services " +"and Daemons] for more information on how to configure services in {MAJOROS}." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:996 +msgid "" +"To configure Procmail to use the SpamAssassin client application instead of " +"the Perl script, place the following line near the top of the " +"`~/.procmailrc` file. For a system-wide configuration, place it in " +"`/etc/procmailrc`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:1000 +#, no-wrap +msgid "INCLUDERC=/etc/mail/spamassassin/spamassassin-spamc.rc\n" +msgstr "" + +#. type: Title == +#: ./pages/servers/Mail_Servers.adoc:1003 +#, no-wrap +msgid "Mail User Agents" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:1006 +msgid "" +"{MAJOROS} offers a variety of email programs, both, graphical email client " +"programs, such as [application]*Evolution*, and text-based email programs " +"such as [command]#mutt#." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:1008 +msgid "" +"The remainder of this section focuses on securing communication between a " +"client and a server." +msgstr "" + +#. type: Title === +#: ./pages/servers/Mail_Servers.adoc:1010 +#, no-wrap +msgid "Securing Communication" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:1015 +msgid "" +"Popular MUAs included with {MAJOROS}, such as [application]*Evolution* and " +"[application]*Mutt* offer SSL-encrypted email sessions. " +"indexterm:[email,security] Like any other service that flows over a network " +"unencrypted, important email information, such as user names, passwords, and " +"entire messages, may be intercepted and viewed by users on the " +"network. Additionally, since the standard `POP` and `IMAP` protocols pass " +"authentication information unencrypted, it is possible for an attacker to " +"gain access to user accounts by collecting user names and passwords as they " +"are passed over the network." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:1017 +#, no-wrap +msgid "Secure Email Clients" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:1020 +msgid "" +"indexterm:[email,security,clients] Most Linux MUAs designed to check email " +"on remote servers support SSL encryption. To use SSL when retrieving email, " +"it must be enabled on both the email client and the server." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:1022 +msgid "" +"SSL is easy to enable on the client-side, often done with the click of a " +"button in the MUA's configuration window or via an option in the MUA's " +"configuration file. Secure `IMAP` and `POP` have known port numbers (993 and " +"995, respectively) that the MUA uses to authenticate and download messages." +msgstr "" + +#. type: Title ==== +#: ./pages/servers/Mail_Servers.adoc:1024 +#, no-wrap +msgid "Securing Email Client Communications" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:1027 +msgid "" +"indexterm:[email,security,servers]indexterm:[stunnel] Offering SSL " +"encryption to `IMAP` and `POP` users on the email server is a simple matter." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:1029 +msgid "" +"First, create an SSL certificate. This can be done in two ways: by applying " +"to a _Certificate Authority_ (_CA_) for an SSL certificate or by creating a " +"self-signed certificate." +msgstr "" + +#. type: Block title +#: ./pages/servers/Mail_Servers.adoc:1030 +#, no-wrap +msgid "Avoid using self-signed certificates" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Mail_Servers.adoc:1035 +msgid "" +"Self-signed certificates should be used for testing purposes only. Any " +"server used in a production environment should use an SSL certificate signed " +"by a CA." +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:1039 +msgid "" +"To create a self-signed SSL certificate for `IMAP` or `POP`, change to the " +"`/etc/pki/dovecot/` directory, edit the certificate parameters in the " +"`/etc/pki/dovecot/dovecot-openssl.cnf` configuration file as you prefer, and " +"type the following commands, as `root`:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:1044 +#, no-wrap +msgid "" +"dovecot]#{nbsp}rm -f certs/dovecot.pem private/dovecot.pem\n" +"dovecot]#{nbsp}/usr/libexec/dovecot/mkcert.sh\n" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Mail_Servers.adoc:1047 +msgid "" +"Once finished, make sure you have the following configurations in your " +"`/etc/dovecot/conf.d/10-ssl.conf` file:" +msgstr "" + +#. type: delimited block - +#: ./pages/servers/Mail_Servers.adoc:1051 +#, no-wrap +msgid "" +"ssl_cert = , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/servers/Web_Servers.adoc:6 +#, no-wrap +msgid "Web Servers" +msgstr "" + +#. indexterm:[HTTP server,Apache HTTP Server]indexterm:[web server,Apache HTTP Server] +#. type: delimited block = +#: ./pages/servers/Web_Servers.adoc:12 +#, no-wrap +msgid "**Editor's Note** \n" +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Web_Servers.adoc:14 +msgid "" +"_This guide is deprecated!_ Large parts of it are no longer current and it " +"will not receive any updates. A series of shorter, topic-specific " +"documentation will gradually replace it." +msgstr "" + +#. type: delimited block = +#: ./pages/servers/Web_Servers.adoc:16 +msgid "" +"For additional information about Apache Webserver on Fedora see " +"https://docs.fedoraproject.org/en-US/quick-docs/getting-started-with-apache-http-server/[Getting " +"started with Apache HTTP Server]" +msgstr "" + +#. type: Plain text +#: ./pages/servers/Web_Servers.adoc:20 +msgid "" +"A _web server_ is a network service that serves content to a client over the " +"web. This typically means web pages, but any other documents can be served " +"as well. Web servers are also known as HTTP servers, as they use the " +"_hypertext transport protocol_ (*HTTP*)." +msgstr "" diff --git a/pot/rawhide/pages/servers/intro-servers.pot b/pot/rawhide/pages/servers/intro-servers.pot new file mode 100644 index 00000000000..c568da14f1b --- /dev/null +++ b/pot/rawhide/pages/servers/intro-servers.pot @@ -0,0 +1,30 @@ +# SOME DESCRIPTIVE TITLE +# Copyright (C) YEAR Free Software Foundation, Inc. +# This file is distributed under the same license as the PACKAGE package. +# FIRST AUTHOR , YEAR. +# +#, fuzzy +msgid "" +msgstr "" +"Project-Id-Version: PACKAGE VERSION\n" +"POT-Creation-Date: 2025-05-15 21:35+0000\n" +"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n" +"Last-Translator: FULL NAME \n" +"Language-Team: LANGUAGE \n" +"Language: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" + +#. type: Title = +#: ./pages/servers/intro-servers.adoc:1 +#, no-wrap +msgid "Servers" +msgstr "" + +#. type: Plain text +#: ./pages/servers/intro-servers.adoc:3 +msgid "" +"This part discusses various topics related to servers such as how to set up " +"a web server or share files and directories over a network." +msgstr ""