3 pts_createuser - Creates a user or machine entry in the Protection Database
10 B<pts createuser> S<<< B<-name> <I<user name>>+ >>> S<<< [B<-id> <I<user id>>+] >>>
11 S<<< [B<-cell> <I<cell name>>] >>> [B<-noauth>] [B<-localauth>] [B<-force>]
14 B<pts createu> S<<< B<-na> <I<user name>>+ >>> S<<< [B<-i> <I<user id>>+] >>>
15 S<<< [B<-c> <I<cell name>>] >>> [B<-no>] [B<-l>] [B<-f>] [B<-h>]
17 B<pts cu> S<<< B<-na> <I<user name>>+ >>> S<<< [B<-i> <I<user id>>+] >>>
18 S<<< [B<-c> <I<cell name>>] >>> [B<-no>] [B<-l>] [B<-f>] [B<-h>]
25 The B<pts createuser> command creates an entry in the Protection Database
26 for each user or machine specified by the B<-name> argument. A user entry
27 name becomes the user's AFS username (the one to provide when
28 authenticating with the AFS Authentication Server). A machine entry's
29 name is the machine's IP address or a wildcard notation that represents a
30 range of consecutive IP addresses (a group of machines on the same
31 network). It is not possible to authenticate as a machine, but a group to
32 which a machine entry belongs can appear on a directory's access control
33 list (ACL), thereby granting the indicated permissions to any user logged
36 AFS user IDs (AFS UIDs) are positive integers and by default the
37 Protection Server assigns an AFS UID that is one greater than the current
38 value of the C<max user id> counter in the Protection Database,
39 incrementing the counter by one for each user. To assign a specific AFS
40 UID, use the B<-id> argument. If any of the specified AFS UIDs is greater
41 than the current value of the C<max user id> counter, the counter is reset
42 to that value. It is acceptable to specify an AFS UID smaller than the
43 current value of the counter, but the creation operation fails if an
44 existing user or machine entry already has it. To display or set the value
45 of the C<max user id> counter, use the B<pts listmax> or B<pts setmax>
46 command, respectively.
48 The issuer of the B<pts createuser> command is recorded as the entry's
49 creator and the group system:administrators as its owner.
53 The Protection Server reserves AFS UID 0 (zero) and returns an error if
54 the B<-id> argument has that value.
60 =item B<-name> <I<user name>>+
62 Specifies either a username for a user entry, or an IP address (complete
63 or wildcarded) for a machine entry:
69 A username can include up to 63 numbers and lowercase letters, but it is
70 best to make it shorter than eight characters, because many application
71 programs cannot handle longer names. Also, it is best not to include shell
72 metacharacters or other punctuation marks. In particular, the colon (C<:>)
73 and at-sign (C<@>) characters are not acceptable. The period is generally
74 used only in special administrative names, to separate the username and an
75 I<instance>, as in the example C<pat.admin>.
79 A machine identifier is its IP address in dotted decimal notation (for
80 example, 192.12.108.240), or a wildcard notation that represents a set of
81 IP addresses (a group of machines on the same network). The following are
82 acceptable wildcard formats. The letters C<W>, C<X>, C<Y> and C<Z> each
83 represent an actual number from the range 1 through 255.
89 W.X.Y.Z represents a single machine, for example C<192.12.108.240>.
93 W.X.Y.0 matches all machines whose IP addresses start with the first three
94 numbers. For example, C<192.12.108.0> matches both C<192.12.108.119> and
95 C<192.12.108.120>, but does not match C<192.12.105.144>.
99 W.X.0.0 matches all machines whose IP addresses start with the first two
100 numbers. For example, the address C<192.12.0.0> matches both
101 C<192.12.106.23> and C<192.12.108.120>, but does not match C<192.5.30.95>.
105 W.0.0.0 matches all machines whose IP addresses start with the first
106 number in the specified address. For example, the address C<192.0.0.0>
107 matches both C<192.5.30.95> and C<192.12.108.120>, but does not match
112 Do not define a machine entry with the name C<0.0.0.0> to match every
113 machine. The system:anyuser group is equivalent.
117 =item B<-id> <I<user id>>+
119 Specifies an AFS UID for each user or machine entry, rather than allowing
120 the Protection Server to assign it. Provide a positive integer.
122 If this argument is used and the B<-name> argument names multiple new
123 entries, it is best to provide an equivalent number of AFS UIDs. The
124 first UID is assigned to the first entry, the second to the second entry,
125 and so on. If there are fewer UIDs than entries, the Protection Server
126 assigns UIDs to the unmatched entries based on the C<max user id>
127 counter. If there are more UIDs than entries, the excess UIDs are
128 ignored. If any of the UIDs is greater than the current value of the C<max
129 user id> counter, the counter is reset to that value.
131 =include fragments/pts-common.pod
137 The command generates the following string to confirm creation of each
140 User <name> has id <id>
144 The following example creates a Protection Database entry for the user
147 % pts createuser -name johnson
149 The following example creates three wildcarded machine entries in the ABC
150 Corporation cell. The three entries encompass all of the machines on the
151 company's networks without including machines on other networks:
153 % pts createuser -name 138.255.0.0 192.12.105.0 192.12.106.0
155 =head1 PRIVILEGE REQUIRED
157 The issuer must belong to the system:administrators group.
167 IBM Corporation 2000. <http://www.ibm.com/> All Rights Reserved.
169 This documentation is covered by the IBM Public License Version 1.0. It was
170 converted from HTML to POD by software written by Chas Williams and Russ
171 Allbery, based on work by Alf Wachsmann and Elizabeth Cassell.