.\" A man page for default.conf .\" Copyright (C) 2011 Red Hat, Inc. .\" .\" This program is free software; you can redistribute it and/or modify .\" it under the terms of the GNU General Public License as published by .\" the Free Software Foundation, either version 3 of the License, or .\" (at your option) any later version. .\" .\" This program is distributed in the hope that it will be useful, but .\" WITHOUT ANY WARRANTY; without even the implied warranty of .\" MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU .\" General Public License for more details. .\" .\" You should have received a copy of the GNU General Public License .\" along with this program. If not, see . .\" .\" Author: Rob Crittenden .\" .TH "default.conf" "5" "Feb 21 2011" "IPA" "IPA Manual Pages" .SH "NAME" default.conf \- IPA configuration file .SH "SYNOPSIS" /etc/ipa/default.conf, ~/.ipa/default.conf, /etc/ipa/server.conf, /etc/ipa/cli.conf .SH "DESCRIPTION" The \fIdefault.conf \fRconfiguration file is used to set system\-wide defaults to be applied when running IPA clients and servers. Users may create an optional configuration file in \fI~/.ipa/default.conf\fR which will be merged into the system\-wide defaults file. The following files are read, in order: .nf ~/.ipa/default.conf /etc/ipa/.conf /etc/ipa/default.conf built\-in constants .fi The IPA server does not read ~/.ipa/default.conf. The first setting wins. .SH "SYNTAX" The configuration options are not case sensitive. The values may be case sensitive, depending on the option. Blank lines are ignored. Lines beginning with # are comments and are ignored. Valid lines consist of an option name, an equals sign and a value. Spaces surrounding equals sign are ignored. An option terminates at the end of a line. Values should not be quoted, the quotes will not be stripped. .RS L # Wrong \- don't include quotes verbose = "True" # Right \- Properly formatted options verbose = True verbose=True .RE Options must appear in the section named [global]. There are no other sections defined or used currently. Options may be defined that are not used by IPA. Be careful of misspellings, they will not be rejected. .SH "OPTIONS" The following options are relevant for the server: .TP .B basedn\fR Specifies the base DN to use when performing LDAP operations. The base must be in DN format (dc=example,dc=com). .TP .B ca_agent_port Specifies the secure CA agent port. The default is 8443. .TP .B ca_host Specifies the hostname of the dogtag CA server. The default is the hostname of the IPA server. .TP .B ca_port Specifies the insecure CA end user port. The default is 8080. .TP .B certmonger_wait_timeout The time to wait for a certmonger request to complete during installation. The default value is 300 seconds. .TP .B context Specifies the context that IPA is being executed in. IPA may operate differently depending on the context. The current defined contexts are cli and server. Additionally this value is used to load /etc/ipa/\fBcontext\fR.conf to provide context\-specific configuration. For example, if you want to always perform client requests in verbose mode but do not want to have verbose enabled on the server, add the verbose option to \fI/etc/ipa/cli.conf\fR. .TP .B debug When True provides detailed information. Specifically this set the global log level to "debug". Default is False. .TP .B dogtag_version Stores the version of Dogtag. Value 9 is assumed if not specified otherwise. .TP .B domain The domain of the IPA server e.g. example.com. .TP .B enable_ra Specifies whether the CA is acting as an RA agent, such as when dogtag is being used as the Certificate Authority. This setting only applies to the IPA server configuration. .TP .B fallback Specifies whether an IPA client should attempt to fall back and try other services if the first connection fails. .TP .B host Specifies the local system hostname. .TP .B http_timeout Timeout for HTTP blocking requests (e.g. connection). The default value is 30 seconds. .TP .B in_server Specifies whether requests should be forwarded to an IPA server or handled locally. This is used internally by IPA in a similar way as context. The same IPA framework is used by the ipa command\-line tool and the server. This setting tells the framework whether it should execute the command as if on the server or forward it via XML\-RPC to a remote server. .TP .B in_tree This is used in development and is generally a detected value. It means that the code is being executed within a source tree. .TP .B interactive Specifies whether values should be prompted for or not. The default is True. .TP .B kinit_lifetime