X-Git-Url: http://git.openafs.org/?p=openafs.git;a=blobdiff_plain;f=doc%2Fman-pages%2Fpod8%2Fbackup.pod;h=0900fe6edecc1e706b5dd96e4ae4102953618d70;hp=4cb65af1d6eb6265afacbdaa62d140711e1688bc;hb=345ee34236c08a0a2fb3fff016edfa18c7af4b0a;hpb=04fa499ac9285f51fdbc2ff724c2a1bd7f0e5d58 diff --git a/doc/man-pages/pod8/backup.pod b/doc/man-pages/pod8/backup.pod index 4cb65af..0900fe6 100644 --- a/doc/man-pages/pod8/backup.pod +++ b/doc/man-pages/pod8/backup.pod @@ -72,6 +72,10 @@ Commands to obtain help: L|backup_apropos(8)> and L|backup_help(8)>. +=item * + +A command to display the OpenAFS command suite version: B. + =back The backup command interpreter interacts with two other processes: @@ -162,13 +166,15 @@ prints the help message. =item B<-localauth> Constructs a server ticket using the server encryption key with the -highest key version number in the local F file. The +highest key version number in the local F +or F file. The B command interpreter presents the ticket, which never expires, to the Backup Server, Volume Server and Volume Location (VL) Server during mutual authentication. Use this flag only when issuing a command on a server machine; client -machines do not usually have a F file. The issuer +machines do not usually have a F or +F file. The issuer of a command that includes this flag must be logged on to the server machine as the local superuser C. The flag is useful for commands invoked by an unattended application program, such as a process controlled @@ -188,6 +194,18 @@ interactive mode. The local identity and AFS tokens with which the B command interpreter enters interactive mode apply to all commands issued during the interactive session. +=item B<-nobutcauth> + +Prior to the fix for OPENAFS-SA-2018-001, B did not allow incoming +connections to be authenticated. As part of that fix, B was modified +to authenticate to the B services when possible, but a B utility +with the security fix will not interoperate with a B that lacks the fix +unless this option is passed, which forces the use of unauthenticated +connections to the B. Use of this option is strongly disrecommended, +and it is provided only for backwards compatibility in environments where +B and B communicate over a secure network environment that denies +access to untrusted parties. + =item B<-portoffset> > Specifies the port offset number of the Tape Coordinator that is to @@ -260,7 +278,7 @@ on every Backup Server machine, every Volume Location (VL) Server machine, and every file server machine that houses affected volumes. By convention, a common F file is distributed to all database server and file server machines in the cell. See the chapter on privileged users in the -I for more information on this type of +I for more information on this type of privilege. If the B<-localauth> flag is included, the user must instead be logged on @@ -272,6 +290,7 @@ command is issued. L, L, L, +L, L, L, L,