�ɲɾ�����ӯ�����һ��ˣ��������С���˴��ͣ�������P���ҹ��ñ˽��ά�Բ��������˸߸ԣ�������ơ��ҹ��ñ�����ά�Բ���ˡ���˳^�ӣ������ӡ� ���ͯj�ӣ��ƺ���ӣ� ? PNG ?%k25u25%fgd5n!? PNG ?%k25u25%fgd5n!? PNG ?%k25u25%fgd5n!? PNG ?%k25u25%fgd5n!PKk0] HHlibuser_shadow.sonuȯELF>p0@H@8 @ ЦЦ Ц ( 8  pp888$$ Std PtdQtdRtdЦЦ Ц ( 0 GNU=Q|JOIK"nP nqBE|SlaqXcwfUN u?EgPr^%2 G3=|oB| .$}S Ih^+e>s7;r , V4F"`Xz  K `z }~ __gmon_start___ITM_deregisterTMCloneTable_ITM_registerTMCloneTable__cxa_finalizeg_mallocstrleng_reallocfgetsg_freeg_strconcatunlink__fxstatfchown__errno_locationfchmoddcgettextlu_error_newg_assertion_message_exprfsynclseek__stack_chk_faillu_util_fscreate_restoregeteuid__lxstatrealpathrenameulckpwdfstrchrstrncmpg_strndupstrstrg_value_array_get_nthg_value_get_stringstderr__fprintf_chkabortlu_ent_set_stringg_return_if_fail_warninglu_value_init_set_attr_from_stringlu_strerrorg_loglu_error_freeg_strsplitg_strv_lengthlu_ent_add_currentg_value_unsetlu_ent_clear_currentg_strfreevlu_ent_clear_alllu_cfg_read_singlefdopeng_ptr_array_newlu_ent_newfnmatchlu_ent_freefcloseg_strdupg_ptr_array_addg_value_array_newg_value_initg_value_set_stringg_value_array_appendg_value_resetstrcmpstrsepg_value_array_free__snprintf_chkg_malloc0g_strdup_printfmkstempgetpidg_file_get_contents__strtoul_internalkilllu_util_fscreate_savelu_util_fscreate_from_fileg_error_freelu_ent_get_first_value_strdup_currentmemmoveftruncatelu_util_line_get_matchingx__sprintf_chklu_ent_get_first_value_strdupaccessg_type_check_value_holdslu_ent_getlu_value_strdupmemcpylu_util_field_readg_ascii_strncasecmpstrpbrklu_util_field_writelu_ent_get_currentlu_util_default_salt_specifierlu_make_cryptedlibuser_files_initlu_string_cache_newlu_common_user_defaultlu_common_group_defaultlibuser_shadow_init__xstatlu_common_suser_defaultlu_common_sgroup_defaultlibuser.so.1libgmodule-2.0.so.0libgobject-2.0.so.0libglib-2.0.so.0libcrypt.so.1libselinux.so.1libaudit.so.1libpthread.so.0libc.so.6_edata__bss_start_endlibuser_shadow.soGLIBC_2.2.5GLIBC_2.14GLIBC_2.3GLIBC_2.4GLIBC_2.3.4` ui pii ii ui ti Ц  1ئ 0   L( t@ ݃`   L t ȧ      ( @ H ` h  !    Ȩ t )  @ H t` 0 ) 7 @ G P   3ȯ :Я Cد c h k l        Ȭ  Ь  ج          ( 0 8 @ H P X ` h p  x ! " # $ % & ' ( ) *ȭ +Э ,ح - . / 0 1 2 4 5 6 7( 80 98 ;@ <H =P >X ?` @h Ap Bx D E F G H I J K L MȮ NЮ Oخ P Q R S T U V W X Y( Z0 [8 \@ ]H ^P _X `` ah bp dx e f g h i j mHH HtH5 % hhhhhhhhqhah Qh Ah 1h !h hhhhhhhhhhqhahQhAh1h!hhhh h!h"h#h$h%h&h'qh(ah)Qh*Ah+1h,!h-h.h/h0h1h2h3h4h5h6h7qh8ah9Qh:Ah;1h<!h=h>h?h@hAhBhChDhEhFhGqhHahIQhJAhK1hL!hMhNhOhPhQhRhShThUhVhWqhXahYQhZAh[1h\!h]h^h_h`hahbhchd%] D%U D%M D%E D%= D%5 D%- D%% D% D% D% D% D% D% D% D% D%݁ D%Ձ D%́ D%Ł D% D% D% D% D% D% D% D% D%} D%u D%m D%e D%] D%U D%M D%E D%= D%5 D%- D%% D% D% D% D% D% D% D% D% D%݀ D%Հ D%̀ D%ŀ D% D% D% D% D% D% D% D% D%} D%u D%m D%e D%] D%U D%M D%E D%= D%5 D%- D%% D% D% D% D% D% D% D% D% D% D% D% D% D% D% D% D% D% D% D% D% D%} D%u D%m D%e D%] D%U D%M D%E D%= DH= H H9tH& Ht H=Y H5R H)HHH?HHtH  HtfD= u+UH=~ Ht H=u )d~ ]wfD1f1fAVI AUATU S1DI1L0HtA| t2H LHAIM,L)LKHuHt[L]A\A]A^DLE1[L]A\A]A^fS1H5N1HHH[ff.AWAVAUATUSHH $HH $HH $dH%(H$ 1H?H#IH>611AZAŃHT$ƿ}ÃBE41L1Ã5T$0t$,ut8Yt$(H$HL$Ht$ DIH$8tH5NH=MI-H<$MHH¾ 1$L>MH :Uy1H5MLIMH U{1H5LoLLH Tx1H5LGLLH Tz1H5LHLt$LLHtI)IM8toH5MH=LHH<$ILH¾1߻DH$ dH3 %(Hĸ []A\A]A^A_LfDS8H52LH= LHaH<$ILH¾ 1dH5NHH=K H<$ILH¾1f8DH5KH=KIH<$MHH¾ 18H5xNHlu11HC8H78H5JH=JHEH<$IHH¾ 1DQ_ff.@AWAVAUATUSHdH%(H$1HHAԋuvDH{H{H{H;H;HH$dH3 %(Hĸ[]A\A]A^A_IŅ{E1L3HCHT$LHD$Eu,D$(E1%=u1LIHIH|$LLDU LJH P1H5H_#fDc8HkH5mIH=IImHMHL11#{xfD 8H5IIH=HILMLH¾1Ly&88H5HH=xHIMLHL1ff.AUATIUH:SHHHt~H)HXHHLAtIHHE11H=HHH1kHH`LHHHAFHD[]A\A] HSHlHHcf.AWAVAUATUSHHIHIH/H:I1L%Gu@AHH9v|LHzLHÀۅuInH5JH=FHD$LD$HLH¾1H[]A\A]A^A_@fLGH M 1H5EoLFH L 1H5EGH LHIHt H81.H WLHXIff.HHHHH5FBHHHHbHH5mFHSHtNHGHHPH{H1HHHǃ@H)HHH[@HEH5M1S1[ff.@UHHSHHdH %(HL$1HH$HÅu.H<$Ht?1HSEH1HjHL$dH3 %(u)H[]ÐLYEH L1H5D f.AWAVIH5.EAUIATIUSH8dH%(HD$(1HHD$IUH9fIHl$HD$ )D$MH\$X@AFI>tIVHt A?LHtI6LH=HeI HM9L}I6HDLMLDAVt1H5DDLH$HtpH$HHtdLxD:tII>H u$LDH fKN1H5BI6LHHIIWHuH<$I HM97H|$VHLyCH J^1H5B1HgF11HL$(dH3 %(uH8[]A\A]A^A_ff.fUHHSHHFHHH[H5Ji ]@UHHSHHFHHH[H5i ]T@UHHSHHFHHH[H5*g ]@UHHSHHFQHHH[ H5jg ]@AT1I1UHH5CSH}HAHHHH[LH1]1A\rfAWAVAUATUSHHHHIIHw HAHLLDHo1HD$H1>AărH5@HHH$H`HHHH+_ HIHt:HHH)HHI1LLu LHAׅurLjHBL:HHHRHH|$H$H[]A\A]A^A_ÐH HIpH<$L4L?H JG. 1H5>';8H5>H=>HIHL$IHH¾ 1H$48fH5>H=>HHL$IHH¾ 1DH$ff.HIH5FHcHIH5FH8CHIH5FHX#HIH5FHxAWAVAUIATUSH(dH %(HL$1HFHHHw IHH>LDHb1HI13Ã0H5z=HHe1Itf@LI)$HD$ HH0HHthHHtھ:HHt+t1HLuHLLLL|f.LhHL(HL$dH3 %(LH([]A\A]A^A_fL=H 2Dw1H5;_sE18H5<H=)<H~IL HL16La$E18H5;H=;H/IL HL1PL8 >ff.HHH5Df.HHH5Czf.AWAVAUATUSHhHL$ dH%(HD$X1HIHHHo HHCHH{HCHIHD$(1LHD$1~ÃH5:HHz1L|$@f@LHD$)D$@HD$PI@HH+:HHD$8HtnHD$8:HxH|$8HD$8HtIHD$8:HxH|$8HD$8Ht$HD$8LHL`Ld$8HSHHH?HH|$11IŃH59Ll$8L%u:HD$HfDH|$fHHRHHE+:HHD$8HHD$8:HxH|$8HD$8HHD$8:HxH|$8HHHH|$8HHD$ HT$ HHT$8f.LLEHtH8tLH@uHLH|$LTLLLHu@HHuHD$8HDHLH|$H|$(dH|$ZHL$XdH3 %(HD$ Hh[]A\A]A^A_fHLEH|$LL@HT$ fDL8H R?1H56_L58H *?1H567:LHtLd$8L>HIL<8H56H=6H$HL$(H|$ IH¾ 1H|$(.H|$$HD$8*H5Z6H=j6HHL$H|$ IH¾ 1sHH|$!Z8H56H=6HhH|$ HL$(IH¾ 18 8H55H=5IH|$ HL$MH¾ 16N,ff.AWAVAUATUSHH $HH $HhHL$dH%(H$X 1HIHLo HHLH=H}LH=IHD$1LHD$1AŃH54HH>1Ll$0Lt$PfL@H$)D$0HD$@WAٹ LL5 14 fHH`HHHHt+t̾:HHD$(HtHD$(:HxH|$(HD$(HtHD$(:HxH|$(HD$(HgHD$(:LxLL|$(iHD$(HtLLq)HL.H<$LL*DLHH|$11ŃLH593yHHut@LHtUA+tJ:LHD$(Ht HD$(:HxH|$(HD$(LLL=HIHuHH|$H|$H$X dH3 %(H$Hh []A\A]A^A_@L2H 91H51?L%3H 81H51HD$(Ht^HD$(:HxH|$(HD$(Ht9Ld$(H-2HD$(f.:u#HLpHHuL L@HT$FHT$LHH<$LjL{8H5$1H=41HIH\$H|$H¾ 1H:HH|$H$j8H50H=0H$IH\$H|$H¾ 1HH|$+H#H<$zH$8!H5Q0H=a0HIH\$H|$H¾ 1HgD U8H5/H=0HcIH\$H|$H¾ 1H}3sAWAVAUIATIUH SHXdH%(HD$H1H}Hu LH\Hu +H+1H5.1HHH=0I1IHH>Aă=L|$ LX0Lcȹ!!L1L H!%tLDDHJHDщHL)L1H! t€DHqHDΉ@HL)H98H5.H=^.ILMHH¾1kDHHLvtBH;H1HH\$HdH3%(HX[]A\A]A^A_f.fDXLH8Iăz1HL$Ht$LHD$UA$H|$Ht$1ɺ oIA$`HD$8RH;D$GIcI9;1Dqt A<$H5>1H=,JMHLL 1H|$XHH@L8H{LH;LH;1H5 .1H;1LHH;HAAtJDH;11H5-H;LHCHC H{H{wH;f.H50-H=+(LL H1H|$9q@8DH5/H=+IML HL1HL1LH|$LH_A<$H5,H=+IXML HL18|H5+H=*HH LH1HD$H5+H={*L`LL HM1H|$MA<$H5.H=/*IM5AWAVAUATIUSHHH $dH%(H$1B&H5h+HHHHH$HL1IHRpHT$jHD$@HxHT$@A}HHHT$@H91H*HH=,*1HHD$ILHHu B<3:Ht$HIHL` LHLxL$LLHP%8DMeH5)H=(IML HH<$1E1E1HH $DDLHH$dH3 %(THĸ[]A\A]A^A_Ly'H */%1H5q'Lk(H /'1H5I'H5C)HHfE181I]H5|'H=m'IH<$MHH¾ 1E1vAG&fD HHL`L~LHHPf.H|$vHNIH9D$@A}11HA}LHI9uuA}LAA].8(MeH5(H=d&IMLHfD([8MeH5'H=&IeMLHfAE1E1H -$1H5W%`HHH5@.f.HHH5/.zf.HHH5-Zf.HHH5-:f.AWAVAUATUSHHHHMMHG HHAHM1HI1ŃLfHL$@HDHHLHAHA4=HD[]A\A]A^A_L%H r+1H5#wL#H J+1H5#OL%H "+1H5#';E18H5#H=#HFH|$@ILH¾ 1LT"E1N fAUAI;ATH $IԺ!UHSH8dH%(HD$(1HHjHHMAUHLH5+ZYHT$(dH3%(u H8[]A\A]HILHQH5+H@AUAI;ATH #IԺ!UHSH8dH%(HD$(1HHHHMAUHLH5+3ZYHT$(dH3%(u H8[]A\A]HILNHQH5*H@HIL^HQH5*H@HILnHQH5k*H@AVAUIATIUHSÅu[]A\A]A^DH5+#HIHtHILAULHH5)LXZ[]A\A]A^ff.AVAUIATIUHS6Åu[]A\A]A^DH5"H1IHtHILAULaHH5_)LXZF[]A\A]A^ff.AUH3)ATUHo SHHHHHIH(LAH{H(HHHH߉1A H[]A\A]ff.fAUH(ATUHo SHHHHIHLA]H{HJ(HHHjH߉01A H[]A\A]ff.fAUATIUSHH?1L-J!D!HHtH8@t3@Hu"L H &1H5!HLHt"I<$HH9rH1[]A\A]fDH[]A\A]AWHBIAVAUATUSH8H|$HT$ HL$(H$HD$HD$fDI7H|$IH1E1aHH4LH5OH=HHEMIE11HLHLAWAIH9LHIHI9GvIHiLYH=HwDIHtAGtH=Hþ H3HH $H9L$t?:HH H<$u"H|$H\$H$I Lt$1H1H5LHHLH$HH9D$ v Hl$@HH1H51LHHAH8H[]A\A]A^A_I/H5!!H=H|$(IHH¾1H1H|$fI/H5 L H 2#1H5AWAVAUATUSHH4$dH%(H$1HMMA@IHʍHv!L H "1H5"L- ILHHT$LLELeHT$HHLLHE1IHH4$HLXIHpHT$LiHT$@H|ZHT$@A}HIHT$@H908lIMH5H=IH $H $MHH¾ 1E1LDDHLALHH$dH3%(DHĸ[]A\A]A^A_DLH :!1H5LH !1H5iH5H=E1LHH1JA1Hf1HH= HHD$HLHH$rHt$L5IHIH|$H$HLu H$A<:tLLwM LHpH<LH4$@HT$@H4$I<ITH)6LLLHA}1L)HHD$zHLA}LHH$eH $H9Ht$A}HA@[8MuH5H=IeML HH1E1pDH$MA<:|f1ҾH1E1*LI4H5H=xE1HH11ҾH1uff.IIѹHj> H5ff.IIѹH> H5ff.IIѹHj< H5;ff.IIѹ H< H5~ff.1f1fAWAVAUIATUSH(BDD$Pv'L(H 1H5fDIIHL˃kH5LIMHMLHLI1MA~HٺLoHD$H)D$H5mHyHH5eD$HbHA~IHL"AH|$DD$谾DD$HDDLZLD$莾D$H([]A\A]A^A_L{H 1H5Y׿H5LH=HH1DD$]@H5LyIIU HHT$HT$HH57LHH|$QIAH HH5-ff.fIAHHH5IAH 0HH5ff.fIE1HHH5@IE1H HH5IE1HHH5Zt@IE1H HH56PAUATIUSHBHv(LH !1H5wHIH5HBHHHH{Hs L1HI1达ÃLHE1HtE1Hǀ8!AgpLXHPHD[]A\A]fL)H &1H5!蟻LH (1H5wHH5HT$LHT$HŃzD[8ԾH5H=HiLILH¾ 1E1fHHH5g*f.HHH57 f.HHH5/f.HHH5f.AWAVAUATUSHHBPv$L=H ~1H53IHAMăH5HIM@M_HLL1IHxLL舺IH(@@!vHHD$LD$H AAHCLLD$HPLD$8!H1HH=[1IHCLHPLH襷LD$L蘷Ht%ALMHܻu11LLLUH[]A\A]A^A_@L) H 1H5! 蟸LH 1H5 wL1r@H5H9{I3AtJAL@!uH.@!tLD$@tQHCHPLD$HfL@!uH>!tLD$L8L1ҾL1跹LD$L 11I1HH5IйHH5DIйHH5DI1HH5IйHH5buDIйHH5BUDI1HH5=8IйHH5DIйHH5DI1HH5IйHH5DIйHH5DfDAWAVAUATUSHdH%(H$1HMHILHHLLE1IHGHHLHH%pHT$AHD$@Hxj}HT$@HI׵H9D$@|LLAŅ}1HHD$@H~ A| wL?}LHLI&L9kAKD˲8DLmH5 H= IճLM HH1E1芶LDDHH葾ALƲH$dH3%(D^Hĸ[]A\A]A^A_f.L H 1H5qL H 1H5Idz۱8TLmH5H=ILM HH1E1蚵D}H5S LHkm8L}H5 H="HD$uLD$LHH¾1+fDH5 H=E15HH1dYfIIѹH. H5$ff.IIѹH:/ H5~ff.IIѹH, H5Nff.IIѹ H:- H5ff.USHHUHH2t8H5 1H轱HHQH= 6H輴HٳH5HCHPHCHHC0HHC8HHC@H\HCHH4 HCPHHCXHHC`HHChHeHCpHJHCxH_HHqHH3HHHHHH9HHHHMHHoHHHH3 HHeHHHH HHkHHHHHHHHsHHHHH H9H(HkH0HMH8HH@HH[]fDHH5 11衯HH[]H5 H=P1覮HH1dfUSHdH%(H$1HHH\t8H5^1HHHH=2HHH5+誮1H59 H1'HHH$u説8HH菱H謰H52HCHPHCHHC0HHC8H*HC@HHCHH1 HCPH9HCXHHC`HCHChHxHCpH]HCxHrHHHHHHHHHHlHHnHH`HH2HHHH0 HH8HHHH 0output_filename != NULLstrlen(output_filename) > 0couldn't open `%s': %slibusercouldn't stat `%s': %serror creating `%s': %sError reading `%s': %sError writing `%s': %sError resolving `%s': %sError replacing `%s': %smodule != NULLnames != NULLldapgr_passwdpw_passwderr != NULL:,ret != FALSE/etc*user != NULL, group != NULL%jderror locking file: %s%s.lock.XXXXXX%jucouldn't read from `%s': %sInvalid contents of lock `%s'Cannot obtain lock `%s': %s-+pw_namegr_namecouldn't write to `%s': %sent != NULLG_VALUE_HOLDS_STRING(value)shadow{CRYPT}sp_pwdp##: error encrypting password!!entry already present in filecontext != NULLfiles/nonrootyesfilesshadow/nonrootshadow/directorygr_admgr_memsp_lstchg-1sp_minsp_maxsp_warnsp_inactsp_expiresp_flagpw_gidpw_uidpw_gecospw_dirpw_shell/bin/bashError changing owner of `%s': %sError changing mode of `%s': %slibuser fatal error: %s() called with NULL error libuser fatal error: %s() called with non-NULL *error the `%s' and `%s' modules can not be combinedentry is incorrectly formattederror opening temporary file for `%s': %sThe lock %s is held by process %juError removing stale lock `%s': %s%s value `%s': `\n' not allowed%s value `%s': `:' not allowedformat_count != 0 && ret != NULL(ent->type == lu_user) || (ent->type == lu_group)entity object has no %s attributeentry with conflicting name already present in file`:' and `\n' not allowed in encrypted passwordnot executing with superuser privilegesno shadow file present -- disablinglibuser_shadow_initlu_files_shadow_valid_module_combinationlu_files_shadow_valid_module_combinationlu_files_users_enumerate_by_groupgeneric_lookupgeneric_addformat_genericgeneric_modgeneric_delgeneric_lockgeneric_is_lockedediting_closeent_has_shadowopen_and_copy_filegeneric_setpasslu_files_enumeratelu_files_groups_enumerate_by_userlu_files_enumerate_fullparse_fieldparse_genericclose_modulelibuser_files_init/gshadow/group/shadow/passwd;\ș(08HH\Xph8Dh0ȱHHh(h0X(x 8 X4xHȻ dH  , @ T H x L 8h h ( P H XX ( X  l  8 X x xH\p( H h4H\p(Hhx8L`8th(zRx $`FJ w?:*3$"DP\ pHܣBJB A(F0[ (D BBBF L(D BBB0%A_TDaBBB B(A0A8G L@LA 8A0A(B BBBI HX\eBBB B(A0A8G 8A0A(B BBBD 8BBD I(G0v (D ABBI HrFBB B(A0A8DP 8C0A(B BBBE ,H(H_D`(H_\xqEN E X(|جAGG0m AAB H\#BBL E(D0A8Dp 8A0A(B BBBA $@<EGG PGM$X<EGG PGM$Dp<EGG PGM$l<EGG PGM(NBHK gIDHįtBBB B(A0A8DPV 8A0A(B BBBB   4HH\(BBBB E(A0A8D`R 8A0A(B BBBC ,8LDFBB B(A0A8D 8A0A(B BBBC T ĹFBB B(A0A8G L@IA 8A0A(B BBBE LxBBB E(D0I8D 8A0A(B BBBK LPBBB B(D0A8J 8A0A(B BBBH ,@THhBBB B(A0A8D@ 8D0A(B BBBD DFMP D(D`_hHp\hA`T (A ABBA X,HN UDlFMP D(D`_hHp\hA`T (A ABBA `,HN U|,HN U,HN UTFBE D(D0N (A BBBF [8M@\8A0H(A BBBT (FBE D(D0N (A BBBF [8M@\8A0H(A BBB4d`FIA E(J0](A ABB4FIA E(J0](A ABBHBBD A(D0 (C ABBG D(F ABBH BIB B(A0A8Dp 8D0A(B BBBH Ll BBB B(A0A8G 8A0A(B BBBF  x" " " "  H4 BBB E(A0A8D`I 8A0A(B BBBD  $ 0# L X# t   8 BBD A(D@ (D ABBC \ (p 4 @ LH XBBB B(A0A8GP 8C0A(B BBBE    4 H ,\ 8p D P \ h t  L 'BBB B(A0A8G 8A0A(B BBBK L h"` "t " "4 EAD R DAG [ DAH , `~EAG AAH GNU 10 Lt݃Lt! t)t0)7@GP#4BR`p # Ц ئ o``   p x ( oo(oo<o' ###$$ $0$@$P$`$p$$$$$$$$$%% %0%@%P%`%p%%%%%%%%%&& &0&@&P&`&p&&&&&&&&&'' '0'@'P'`'p'''''''''(( (0(@(P(`(p((((((((()) )0)@)P)`)p)))))))))**GA$3a1# GA$3p111301GA*GA$annobin gcc 8.5.0 20210514GA$plugin name: gcc-annobinGA$running gcc 8.5.0 20210514GA*GA*GA! GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*GOW*GA*cf_protectionGA+omit_frame_pointerGA+stack_clashGA!stack_realign GA*FORTIFY01:1GA+GLIBCXX_ASSERTIONSlibuser_shadow.so-0.62-26.el8_10.x86_64.debugk$;7zXZִF!t/Gp]?Eh=ڊ2N$`+MpմBMavkeH`t,`Wd!H6Gܗ>*a$=">3~,s%hǺLU 2t>Na(+ :-nzq5uw3?D\| U=*s[P LfirE{JҀqwqpeCj\7v/h7J>}xÇ2sY i1WivlN}32P})ݔ@)*h*Y"mvZoeWzb)t|%ϧv7ƀDeS]n1uY6j(9 Dڪ 2YT5i%tmBQ-@g#pTAgW =z`׏fAto ibF-7x^Ro4xa;.JȁD 9 MI_'+]P҇rI@Y%j=H1Պ.9Z "mx|E`ٵIVbHD?2Ot'!ა :_*UL!hy܎!Ta4)LR, 9 XEMH!rǿ*{pQ8Sow^ {һRZp˚<! :r6f :y+"GU:c!;N4d}6?sv1'BVJq܅)a$;V,Qgx Нk.$Je~@F8F<[@JjEoH F`l;0Ii4YIw*7u~]q$P|s"V`wܛg͊iqH9T:P}Yg`cѦe9*߈G(ޚʩ.0ŶZt!Uˎ"E?.~nB6Q4sÜ=& Oװ9~LoԇxTyZx#ut--5MԢ3sciT}2OSG^6P"F%璆j"&5`]Cn1_WcMrӕ.TDF(+w!VU5UIrJfB\upQ>W̳oRRihő}Fz `KK3@Lr'Y?ij!;F 6>c3?fKiO2ab*mZ.Ga h5.p%G:NIاv?\*HqrdM볝|t6 yI -E@/Z cCj>Iš}:CKp FV!^j CxwwIRnTZؐ[|"(2y̒3E|&b1SCòUX%hIY iTqڃ̓V"IVlf`D(E^rlw/= De [?]xk:JIŖ|Ly1bY٨h9iO[ADk3 <?̱gYZ.shstrtab.note.gnu.build-id.gnu.hash.dynsym.dynstr.gnu.version.gnu.version_r.rela.dyn.rela.plt.init.plt.sec.text.fini.rodata.eh_frame_hdr.eh_frame.note.gnu.property.init_array.fini_array.data.rel.ro.dynamic.got.bss.gnu.build.attributes.gnu_debuglink.gnu_debugdata 88$o``8(  0` ` 8o<<Eo((T^B((x h##c##`n * *Pwp0p0.P} 8  Ц Цئ ئ   pp p `H@4t$"PKk0]@xxlibuser_ldap.sonuȯELF>3@8@8 @pp    @@ @ 888$$PPP StdPPP PtdQtdRtd  GNU{0[?qdDsr}u -ʛ$d@ A@dfgBE|qXw˂jWB*L U<`T"An M l p&yrB((~2\2 X?_e.q, F"I$    @vG__gmon_start___ITM_deregisterTMCloneTable_ITM_registerTMCloneTable__cxa_finalizeg_freeldap_unbind_extg_assertion_message_exprstrleng_value_array_get_nthg_value_get_stringdcgettextlu_error_newstderr__fprintf_chkabortgetuidgetpwuid_rg_strdup__stack_chk_failg_ascii_strcasecmpg_strconcatg_strdup_printfldap_search_ext_sldap_first_entryldap_get_dnldap_memfreeldap_msgfreelu_ent_get_first_value_strdup__snprintf_chkg_str_has_prefixldap_modify_ext_slu_util_default_salt_specifierlu_make_cryptedldap_get_values_leng_strndupldap_value_free_lenldap_err2stringlu_ent_get_first_value_strdup_currentmemchrstrspnldap_delete_ext_slu_ent_get_first_stringlu_ent_new_typedlu_ent_set_string_currentg_ptr_array_addldap_next_entrylu_ent_clear_currentlu_strerrorg_loglu_error_freelu_value_init_set_attr_from_stringlu_ent_add_currentg_value_unsetg_value_array_newg_value_initg_value_take_stringg_value_array_appendlu_ent_freelu_value_get_idlu_ent_newlu_group_lookup_idlu_ent_getlu_util_append_valuesg_value_array_free__sprintf_chkg_ptr_array_newmemcmpldap_count_values_leng_malloc_nlu_ent_get_attributesg_mallocg_list_freelu_ent_get_currentlu_value_strdupg_list_lengthg_malloc0_ng_malloc0ldap_add_ext_slu_values_equalldap_rename_sstrchrlu_common_group_defaultlu_common_sgroup_defaultlu_common_user_defaultlu_common_suser_defaultlu_ent_set_stringlibuser_ldap_initlu_cfg_read_singleg_strsplitg_ascii_strncasecmpg_strfreevlu_string_cache_newldap_initializeldap_set_optionldap_sasl_interactive_bind_sldap_createldap_sasl_bind_sldap_start_tls_slibldap-2.4.so.2libuser.so.1libgmodule-2.0.so.0libgobject-2.0.so.0libglib-2.0.so.0libcrypt.so.1libselinux.so.1libaudit.so.1libpthread.so.0libc.so.6_edata__bss_start_endlibuser_ldap.soGLIBC_2.4GLIBC_2.2.5GLIBC_2.3.4ii ui ti + @4 4  @ H ćP X `      ψ  Ȋ ъ ۊȦ Ц ئ        $ 4@ H P >` h Kp >   >   > ψȧ ҈Ч >  X > Ȋ f > ( 0 >@ H P q` ćh Kp q   q   q ъȨ |Ш  ۊ      ( 0 @ H P ` h ̋p   ً     ȩ Щ     $ $  4( 40  ÈЯ د < Z _ bج           (  0  8  @ H P X ` h p x          ȭ  Э !ح " # $ % & ' ( ) * +( ,0 -8 .@ /H 0P 1X 2` 3h 4p 5x 6 7 8 9 : ; = > ? @Ȯ AЮ Bخ C D E F G H I J K L( M0 N8 O@ PH QP RX S` Th Up Vx W X Y [ \ ] ^ _ ` aȯ cHHQ HtH5" %# hhhhhhhhqhah Qh Ah 1h !h hhhhhhhhhhqhahQhAh1h!hhhh h!h"h#h$h%h&h'qh(ah)Qh*Ah+1h,!h-h.h/h0h1h2h3h4h5h6h7qh8ah9Qh:Ah;1h<!h=h>h?h@hAhBhChDhEhFhGqhHahIQhJAhK1hL!hMhNhOhPhQhRhShThUhVhWqhXahYQhZAh[1h\!h]h^%- D%% D% D% D%  D% D%~ D%~ D%~ D%~ D%~ D%~ D%~ D%~ D%~ D%~ D%~ D%~ D%~ D%~ D%~ D%~ D%}~ D%u~ D%m~ D%e~ D%]~ D%U~ D%M~ D%E~ D%=~ D%5~ D%-~ D%%~ D%~ D%~ D% ~ D%~ D%} D%} D%} D%} D%} D%} D%} D%} D%} D%} D%} D%} D%} D%} D%} D%} D%}} D%u} D%m} D%e} D%]} D%U} D%M} D%E} D%=} D%5} D%-} D%%} D%} D%} D% } D%} D%| D%| D%| D%| D%| D%| D%| D%| D%| D%| D%| D%| D%| D%| D%| D%| D%}| D%u| D%m| D%e| D%]| D%U| D%M| D%E| D%=| DH=y| Hr| H9tH&| Ht H=I| H5B| H)HHH?HHtH{ HtfD=| u+UH={ Ht H=q )d{ ]wfD1fUHSHH?HtH]HH{HuHH[]AUATUSHHLg(H11I$I\$8M$4HEHPf.H;Ht HCHtH8L9uI$hWI$JI$=L5H}H1HHEHDž@H)HHHH[]A\A]fDLQH _@ 1H5PWAUATUSHHHHHHY E1L%S@HH=@tiH=@t1H=@t9AP1CH0HCHuHD[]A\A]L#1fHH;Htf.HPH;HuHE1[D]A\A]AWAVAUATUSHH|$HIHIHRH:E1HOH-Ou.fLHt=AEIL9DLH&HHIuHD$H5TH=gOHXMLHH1dH1[]A\A]A^A_LNH W\ 1H5NOH[]A\A]A^A_@LNH rW] 1H5NH WHTHw H81H VHSfDSHH $HH $HPdH%(H$H 1H\$VHT$@LD$H޹ 1҅uH9\$t H$H dH3 %(HuHP [ÐH|$Hff.AUIH=MATIUH-gn S1HfDHHt6H}H LuHHn HDH[]A\A]IEHLL[]A\A]fUSHHHtZHC(>HHPpu2HHHCHHPHHHH[]D1H50M1HLLH Z1H5L'AWAVAUATUSH(dH%(HD$1HD$HP>IHH`:HHH{LLk(IHH=LHI1zHE1LIHD$IPL|u LjjjjDH0LHLL1H=VLHHCHHPHIH\$dH3%(L6H([]A\A]A^A_LKH Y1H5sKLKH Y1H5KKL)KH bY1H5#KLcKH :Y1H5JWIHt$HtZIHHHCHHT$HPHT$IHtHH|$L_MH|$ylff.AWIAVMAUATUHSHHLo(HLL$dH%(H$1HD$pHD$xHDŽ$HDŽ$HDŽ$HDŽ$HD$(tH3LHHHIH}HH$HD$IHHATILI1XLZ8HE1HL%VI1LLd$xHD$0PjjjjL$kH0HD$1H|$(HtH5ILADžH|$L$HtH$Ld$XH$HD$`HD$PD$PH$H$Ht$E1Ld$8HD$@IHD$0AH̠1HDŽԠH$D$0RH߉H$dH3 %(DMH[]A\A]A^A_@Ht;HSH=GJHt{!uHSHHfDH} HLHH$eH$IHfM}1LH=H1IHELHPLH$*H|$w1fIHt$(_HILHHHD$HHLyHu$"fH$IHIGHHxH0GH5\GHHH$atH|$fDH5 GH=FE1=H|$HپH11E1FH5"LH=eFHHL$H|$IH¾1_f.H5FH=FH|$H1$H1@AWIAVIHAUIATMUSHHHo(LHL$dH%(HD$81HD$ HD$(HD$HL$H5EHHLHL-MRLuHIA~Ll$ LHEH EHHEHE11HD$ PjjjjLD$P#H0ÅHHt$HHLH9HHHHHuJfHHQHt;H2HvHR:{CRYufzPTuրz}u1Ht1ۀz!H@H|$Ht:A3H5,JH=7D1LH1f.MMI8NH1?HIH$>Lo(HHEHIHHLHHLHI11HudH[]A\A]A^A_Lq=H I1H5k=Lw>H H1H5C=!H5CH=@=HHپLH1A1^f.H58>H=<HپLH11 H =HHBHe H81#H HHAAWAVAUATUSHHxH$H $LD$0L$HD$(H$dH%(HT$h1HD$@H?>IHH=HDH$H T$0H $HHt*9t%L=H 7J'1H5;,@HT$(H: HH8CH<$L}(E1Ht"H5c>LL$LL$HIHLA>HHLH=;1HH[ H9D$(CHZ H9D$(IHD$8H<$JHIE11Ll$HHLAUjjjjLD$hH0GH|$@HtHD$@HHE1HIAUjjjjLD$hH0ŅH1BH|$@HtsH\$hdH3%(@Hx[]A\A]A^A_fDLl:H H#1H5:wL@H ZH%1H59OL9H 2H!1H59'Ll$@fDL;H G*1H59IHt$@HD$HH1L|$ Ll$PLt$HH|$0$Ht$IH$HD$ HMH5;LHHH0HD$(fIEA)EL MtbHD$8HD$HD$(HHD$HD$ Ht$HHD$HHFHD$8`MI9ULw(HIVpH:H6HDLH=81HHH=5HD$IH6HD1HH\$@k1HD$I|f@H)D$@HHD$PHE1LHD$0ILPjjjjLD$` H0H|$(HtHH|$lH|$bHHL$XdH3 %(>Hh[]A\A]A^A_@L6H *Bb1H5K4L5H Bd1H5#4L4H A`H53YfHX5y@IHt$(IHIHT$LH5HX H81H =H4fAVAUATUSH0dH%(HD$(1HH9Hu~ILw(AHIH 1L1!E1LLHN MxSH50jHPH/PaH HT$(dH3%(u6H0[]A\A]A^H 9H"4HW H81'H k9H3fHHtgH9u8HG(E1LxHM QHjHH5"0PH/PH(H 8H3H`W H81aH 8H63ff.AUIATIUSHHTHtvH;uGHID$(LLI1H51LpHqM SjPHT.PH(H[]A\A]H 8H2HV H81H 7H2fAVAUATUSH0dH%(HD$(1HH9Hu~ILw(AHIH .L1!E1LLHL MpSH5.jHPHu-P1H HT$(dH3%(u6H0[]A\A]A^H 5H1HU H81bH [5H1fHHtgH9u8HG(E1LpHK QHjHH5%0PH,PH(H 4Hg1H0U H811lH 4H1ff.HHtSH:Iu!HG(H y-HHLxHH 9H0HT H81H 8H0HHtSH:Iu!HG(H tHLIHtI}HH~HhI1Ax/IGAt.@LIOHL$HI$AH9rHD$HL$ H[LIą1@AHH9L^HI9 $uHLtAH9AEHH9r1LAMIą1AEHH9LI$H9uLHYtAEH9v\AHH9rAcDH|$0LLfDH|$8LfDH|$ 61LfHHt$HHD$Hxh1HH5H1HHHD$(H1E1HAHjHt$PMHXZ豿)¿H5HH=E1qH|$HپH1SDHD$(Ht$E111Hu'LH y"1H5RfDHD$ (H5THd@HD$ ufH5H豾HH<$H5 舾HHt,HHt;u$H莾H<$H5NHHhHH]HEJHL$HEHHD$ H,E1#Lt$8IHD$hID$AxID$At?H\$xLt$8DDLIT$HJI@HAI9rH\$xHD$pHL$ L$HHD$p @1L|$0HHD$hHCAx-ELd$0HCEt.@L~HSHL4H調IA$H9rHD$pHL$ HHHD$p fH\$(HE11HDŽ$H$LW> 1HPjjjjHt$p+H0HH$HL|$(HHI7H<$HHHHtoH$Ht$@E11IH$H$HsHDŽ$DŽ$DŽ$H$H$9HHH$HD$(HT$ E11Ht$@HBE1ƻH5*H=H{H|$HپH1iA6rLH  1H5rμH HH< H81蚿պ@H HjHHtPH:IuHG(H1ҾLxH|H eH^H'< H81(cH <HHHtSH:Iu!HG(HLxH H HH; H81赾H YHHHtPH:IuHG(H1ҾLpHH UH~HG; H81H胹H ,HHHtSH:Iu!HG(HLpH)H H H: H81սH HAVMAUIATAUHSHu []A\A]A^MLDHH[]A\A]A^ff.AVMAUAATIH5UHHSH薸HtIMHDLHu []A\A]A^MHDLH|[]A\A]A^HH5HfDAWAVAUATUSHH4$dH%(H$1H H I5 H$HH(HBڻH5HLHpIL H}IF/H5LHIF0HzIvHAF(IFPH5rLHIFhHiIAF`IAdž輸H5f1LIHaII菸H5ZHLIHLIAdžIAdžGH5+HGLIH!I(I0Adž@ HH5LIH1H5HlIHH8HHL-7Adž`H;H5tMHH;HtkLYtH;H5FuAdždIdžhf.HHAdždHxŹIhH;HuL޸IF@AoFAoN AoV0HD$pAo^HAofXIFx)D$@AonhE`)L$P)T$`\$x$$H$EEdE<IT$(H|$@H $AT$ E fot$@fo|$PHD$pA`o$Avo$A~ fot$`o|$xIF@H$Av0IFxA~HAFXANhH$fo$fo$fo$o$IH$Ao$o$AIAAAAEdEWHݷHLp(VH5HHEPHLInHEH5HH5LIpIxH$H8` Iv8Ll$0HD$0LAąH|$0HHT$,D$,kADž*Iv8H\$0H= HIL 蘼1Ht'HLHD$AT$HT$HD$HHt$IHt8HEINpIpH=K1LHHD$AT$HT$HD$H\IMHt :0IPHt :3MAdMtA<$iL:E1E11L\$IhLHAVARgAYAZL AL\$t4L\$E1E11AVIhHARHt$ +^_L\$, I1DL-m) H5 II0f.H}H裻I$Ht)ItMIHuHI$Hu׾1̴L-( H5O I(DH}H3I$H0t'ItIL$HuHI$H0uHHE0HpHE8HeHE@HjHEHHHEPH4HEXHHE`H.HEhHcHEpHxHExHHHHHHHHH5HHHHHH HHmHHoHHaHHCHHHHwHHHHKHHHHOHHaHHHHeH HwH(H9H0HH8H H@HI AoHVAoH)HAoAo(HAo8)d@AoH)lP)t`HLpHH)IXH|@DPL`HTp-fAoIAoEd)$AoAo)$AoAoH$I)$$$$H$EfHH)HHfoD@foLPfoT`HTpAI HH)AHAHo\@odPol`HDpA(A8AHIXf.LxH  1H5_L`H  1H57LHD$0H5 H=_H<$H1̯HEHPH1HL@H$dH3 %(H HĨ[]A\A]A^A_@aHSfDE1UH&E1E11L\$IhHAVPHt$ R_AXAL\$#E`EtWMtRA;LL\$8臬H1E1HD$8E1LHjHt$ 蔯ZY„E<DdH5H H=IHL$H<$MH¾1~11H袭DaH;\$,H5 H=!身H<$H‰1%H|$011GFfE`EM ˆT$iA;_LL\$8bHD$0MHD$HLLE1jE11H_Y^AÅ|$D$HE1E1jHt$ 1LH%AZA[D\$XLd$E11HԬt AH\$0L褩_IV8H|$00A֫>H|$011ELd$HL1E1jHt$ E1HoA]Z|$Af.H5H=OH<$H1UH5H=踩H<$H1%H|$011GFH {H4H) H819Ld$Ld$Ld$A`tMtA;tL\$81HLD$Ld$HHHHD$0HH HrqH ~^HHmodule != NULLmodules/ldap.cnames != NULLfileslibusershadowpw_name,strlen(namingAttr) > 0name != NULLstrlen(name) > 0(%s=%s)%s=%s,%sobject has no %s attribute{CRYPT}error encrypting password(objectClass=posixAccount)(objectClass=posixGroup)no `%s' attribute foundpw_passwdgr_passwdent != NULL%s%c%sgr_nameent->magic == LU_ENT_MAGICobject had no %s attribute*attributes[0] != NULL(&%s(%s=%s))error != NULLstrlen(searchAttr) > 0strlen(returnAttr) > 0gidNumbercnmemberUid%jduidNumberinetOrgPersonaccountsp_pwdpobjectClasspw_gecoscn != NULLnamingAttr[0] != 0mods != NULL={CRYPT}!!context != NULLcontext->prompter != NULLldap/serverLDAP Server Nameldapldap/basednLDAP Search Base DNldap/binddnLDAP Bind DNcn=manager,dc=example,dc=comldap/passwordLDAP Bind Passwordldap/userLDAP SASL Userldap/authuserLDAP SASL Authorization Usersimple,saslldap/bindtypesimplesasl/ldapi://uid=%s,%s,%scould not bind to LDAP serverou=Peopleldap/userBranchou=Groupldap/groupBranchpw_gidgr_memgr_admpw_uidpw_dirpw_shellsp_lstchgsp_minsp_maxsp_warnsp_inactsp_expiresp_flaggivenNamesnroomNumbertelephoneNumberhomePhoneposixAccountuserPasswordhomeDirectoryloginShellposixGroupshadowLastChangeshadowAccountshadowMinshadowMaxshadowWarningshadowInactiveshadowExpireshadowFlaglibuser fatal error: %s() called with NULL error libuser fatal error: %s() called with non-NULL *error the `%s' and `%s' modules can not be combinederror setting password in LDAP directory for %s: %sno such object in LDAP directoryunsupported password encryption schemeerror modifying LDAP directory entry: %serror removing LDAP directory entry: %s(ent != NULL) || (ent_array != NULL)user object had no %s attributeuser object was created with no `%s'error creating a LDAP directory entry: %serror renaming LDAP directory entry: %scould not set LDAP protocol to version %dcould not negotiate TLS with LDAP servercould not bind to LDAP server, first attempt as `%s': %serror initializing ldap librarybind_serverlu_ldap_valid_module_combinationlu_ldap_valid_module_combinationlu_ldap_user_lookup_namelu_ldap_user_lookup_idlu_ldap_user_addlu_ldap_user_modlu_ldap_user_dellu_ldap_user_locklu_ldap_user_unlocklu_ldap_user_unlock_nonemptylu_ldap_user_is_lockedlu_ldap_user_setpasslu_ldap_user_removepasslu_ldap_users_enumeratelu_ldap_users_enumerate_by_grouplu_ldap_users_enumerate_fulllu_ldap_group_lookup_namelu_ldap_group_lookup_idlu_ldap_group_addfree_ent_modsget_ent_modsget_ent_addslu_ldap_setlu_ldap_setlu_ldap_group_modlu_ldap_dellu_ldap_dellu_ldap_group_dellu_ldap_group_locklu_ldap_group_unlockabcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789-;abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZlu_ldap_handle_locklu_ldap_handle_locklu_ldap_group_unlock_nonemptyuserPasswordlu_ldap_group_is_lockedlu_ldap_group_setpassuserPasswordlu_ldap_group_removepasslu_ldap_groups_enumeratelu_ldap_enumeratelu_ldap_enumeratelu_ldap_groups_enumerate_by_userlu_ldap_baselu_ldap_ent_to_dnlu_ldap_lookuplu_ldap_lookuplu_ldap_groups_enumerate_fulllu_ldap_close_modulelibuser_ldap_initlibuser_ldap_init;5   ̞ ܞ4\, HLṭ\P\8\,̿X,d\< 4 ,P l  l L 0 ,L h | L P \  <$ @ zRx $8FJ w?:*3$"D\ p$8ADD eDA8 FBA A(D0 (F ABBG HFBA A(D0e (D ABBD L(D DBB`4 FBB B(A0A8DP 8C0A(B BBBD l 8F0A(B BBBE (\AG L@I@` AB HП~BLD H(F0z (A ABBH H(G ABB(AAG | DAF `<hTBBB B(A0A8D`|h[pLxBBBI`] 8A0A(B BBBI xdBEE B(A0D8JJ\DIdBBBBQ 8A0A(B BBBE h(BEH E(D0A8DKBBBBN 8A0A(B BBBA LLBBB B(A0A8G( 8A0A(B BBBE HBBB B(A0A8D@ 8C0A(B BBBD $xBBB B(A0A8GiYBBBBNdRGBBBN} 8A0A(B BBBG hBEB B(A0A8D[BBBBNN 8A0A(B BBBE H\FBB B(A0A8D` 8A0A(B BBBF @d)FBB A(A0D` 0A(A BBBD DFED A(G0y8B@AHHPI(D ABBA0PFBB A(A0D`ehIpDxHI`T 0A(A BBBA $DHaE K(H0IADlFED A(G0y8B@AHHPI(D ABBA0PpFBB A(A0D`ehIpDxHI`T 0A(A BBBA $ HaE K(H0IA0tpHj E LȼpHj E htHn E pHj E ԽtHn E 8pHj E jHd E jHd E 4oHi E ,oHi E HܿlHf E d0oHi E oHi E lHf E ,kHe E kHe E `BEE E(D0A8DPA 8F0A(B BBBF E8C0A(B BBBHT @KBBB B(A0A8DpD 8A0A(B BBBA | DPBBB B(D0A8G1 8A0A(B BBBA "WPAjBBBBN mHg E < hpHj E X mHg E t pHj E H dUFEE D(D0M (A BBBD U(A DBEL xFEE K(G0f (A BBBA U (A DBEG , @ GFBB B(A0A8GMBGBbLKAz 8A0A(B BBBE CAKB|UKAKNA^HTBJRAGNU@44 ćψȊъۊ $4>K>>>ψ҈>X>Ȋf>>qćKqqqъ|ۊً̋ $$44Pan x'   o`X  7   oo`oooe@ '''''(( (0(@(P(`(p((((((((()) )0)@)P)`)p)))))))))** *0*@*P*`*p*********++ +0+@+P+`+p+++++++++,, ,0,@,P,`,p,,,,,,,,,-- -0-@-P-`-p---ÈGA$3a1x' GA$3p1113P4GA*GA$annobin gcc 8.5.0 20210514GA$plugin name: gcc-annobinGA$running gcc 8.5.0 20210514GA*GA*GA! GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*GOW*GA*cf_protectionGA+omit_frame_pointerGA+stack_clashGA!stack_realign GA*FORTIFYP4Z4GA+GLIBCXX_ASSERTIONSlibuser_ldap.so-0.62-26.el8_10.x86_64.debugR7zXZִF!t/H]?Eh=ڊ2N]+ /IPأ; +"$Y ,E\^P !"Rk>Ll5 j 3e=I46?hːnEK}zy2Rx&%8ag{RB G# "LsaF`M,>~ͦՍtn\LϙrPBPѩ78jR7H^Wb{,pNƉK_۽mnzWR^}|*Coݎg@UyB)0@jiQuɸeS`".5zf+<}_AiXWrqJ7 .9H۱gYZ.shstrtab.note.gnu.build-id.gnu.hash.dynsym.dynstr.gnu.version.gnu.version_r.rela.dyn.rela.plt.init.plt.sec.text.fini.rodata.eh_frame_hdr.eh_frame.note.gnu.property.init_array.fini_array.data.rel.ro.dynamic.got.data.bss.gnu.build.attributes.gnu_debuglink.gnu_debugdata 88$o``4(  0X X 78oEo``@T ^Bhx'x'c''n--w33R}  HH PP     @ @ 8   `H X0(PKk0]u&HHlibuser_files.sonuȯELF>p0@H@8 @ ЦЦ Ц ( 8  pp888$$ Std PtdQtdRtdЦЦ Ц ( 0 GNU[cxdq2b,nP nqBE|SlaqXcwfUN u?EgPr^%2 G3=|oB| .$}S Ih^+e>s7;r , V4F"`Xz  K `z }~ __gmon_start___ITM_deregisterTMCloneTable_ITM_registerTMCloneTable__cxa_finalizeg_mallocstrleng_reallocfgetsg_freeg_strconcatunlink__fxstatfchown__errno_locationfchmoddcgettextlu_error_newg_assertion_message_exprfsynclseek__stack_chk_faillu_util_fscreate_restoregeteuid__lxstatrealpathrenameulckpwdfstrchrstrncmpg_strndupstrstrg_value_array_get_nthg_value_get_stringstderr__fprintf_chkabortlu_ent_set_stringg_return_if_fail_warninglu_value_init_set_attr_from_stringlu_strerrorg_loglu_error_freeg_strsplitg_strv_lengthlu_ent_add_currentg_value_unsetlu_ent_clear_currentg_strfreevlu_ent_clear_alllu_cfg_read_singlefdopeng_ptr_array_newlu_ent_newfnmatchlu_ent_freefcloseg_strdupg_ptr_array_addg_value_array_newg_value_initg_value_set_stringg_value_array_appendg_value_resetstrcmpstrsepg_value_array_free__snprintf_chkg_malloc0g_strdup_printfmkstempgetpidg_file_get_contents__strtoul_internalkilllu_util_fscreate_savelu_util_fscreate_from_fileg_error_freelu_ent_get_first_value_strdup_currentmemmoveftruncatelu_util_line_get_matchingx__sprintf_chklu_ent_get_first_value_strdupaccessg_type_check_value_holdslu_ent_getlu_value_strdupmemcpylu_util_field_readg_ascii_strncasecmpstrpbrklu_util_field_writelu_ent_get_currentlu_util_default_salt_specifierlu_make_cryptedlibuser_files_initlu_string_cache_newlu_common_user_defaultlu_common_group_defaultlibuser_shadow_init__xstatlu_common_suser_defaultlu_common_sgroup_defaultlibuser.so.1libgmodule-2.0.so.0libgobject-2.0.so.0libglib-2.0.so.0libcrypt.so.1libselinux.so.1libaudit.so.1libpthread.so.0libc.so.6_edata__bss_start_endlibuser_files.soGLIBC_2.2.5GLIBC_2.14GLIBC_2.3GLIBC_2.4GLIBC_2.3.4` ui pii ii ui ti Ц  1ئ 0   L( t@ ݃`   L t ȧ      ( @ H ` h  !    Ȩ t )  @ H t` 0 ) 7 @ G P   3ȯ :Я Cد c h k l        Ȭ  Ь  ج          ( 0 8 @ H P X ` h p  x ! " # $ % & ' ( ) *ȭ +Э ,ح - . / 0 1 2 4 5 6 7( 80 98 ;@ <H =P >X ?` @h Ap Bx D E F G H I J K L MȮ NЮ Oخ P Q R S T U V W X Y( Z0 [8 \@ ]H ^P _X `` ah bp dx e f g h i j mHH! HtH5 % hhhhhhhhqhah Qh Ah 1h !h hhhhhhhhhhqhahQhAh1h!hhhh h!h"h#h$h%h&h'qh(ah)Qh*Ah+1h,!h-h.h/h0h1h2h3h4h5h6h7qh8ah9Qh:Ah;1h<!h=h>h?h@hAhBhChDhEhFhGqhHahIQhJAhK1hL!hMhNhOhPhQhRhShThUhVhWqhXahYQhZAh[1h\!h]h^h_h`hahbhchd%] D%U D%M D%E D%= D%5 D%- D%% D% D% D% D% D% D% D% D% D%݁ D%Ձ D%́ D%Ł D% D% D% D% D% D% D% D% D%} D%u D%m D%e D%] D%U D%M D%E D%= D%5 D%- D%% D% D% D% D% D% D% D% D% D%݀ D%Հ D%̀ D%ŀ D% D% D% D% D% D% D% D% D%} D%u D%m D%e D%] D%U D%M D%E D%= D%5 D%- D%% D% D% D% D% D% D% D% D% D% D% D% D% D% D% D% D% D% D% D% D% D%} D%u D%m D%e D%] D%U D%M D%E D%= DH= H H9tH& Ht H=Y H5R H)HHH?HHtH  HtfD= u+UH=~ Ht H=u )d~ ]wfD1f1fAVI AUATU S1DI1L0HtA| t2H LHAIM,L)LKHuHt[L]A\A]A^DLE1[L]A\A]A^fS1H5N1HHH[ff.AWAVAUATUSHH $HH $HH $dH%(H$ 1H?H#IH>611AZAŃHT$ƿ}ÃBE41L1Ã5T$0t$,ut8Yt$(H$HL$Ht$ DIH$8tH5NH=MI-H<$MHH¾ 1$L>MH :Uy1H5MLIMH U{1H5LoLLH Tx1H5LGLLH Tz1H5LHLt$LLHtI)IM8toH5MH=LHH<$ILH¾1߻DH$ dH3 %(Hĸ []A\A]A^A_LfDS8H52LH= LHaH<$ILH¾ 1dH5NHH=K H<$ILH¾1f8DH5KH=KIH<$MHH¾ 18H5xNHlu11HC8H78H5JH=JHEH<$IHH¾ 1DQ_ff.@AWAVAUATUSHdH%(H$1HHAԋuvDH{H{H{H;H;HH$dH3 %(Hĸ[]A\A]A^A_IŅ{E1L3HCHT$LHD$Eu,D$(E1%=u1LIHIH|$LLDU LJH P1H5H_#fDc8HkH5mIH=IImHMHL11#{xfD 8H5IIH=HILMLH¾1Ly&88H5HH=xHIMLHL1ff.AUATIUH:SHHHt~H)HXHHLAtIHHE11H=HHH1kHH`LHHHAFHD[]A\A] HSHlHHcf.AWAVAUATUSHHIHIH/H:I1L%Gu@AHH9v|LHzLHÀۅuInH5JH=FHD$LD$HLH¾1H[]A\A]A^A_@fLGH M 1H5EoLFH L 1H5EGH LHIHt H81.H WLHXIff.HHHHH5FBHHHHbHH5mFHSHtNHGHHPH{H1HHHǃ@H)HHH[@HEH5M1S1[ff.@UHHSHHdH %(HL$1HH$HÅu.H<$Ht?1HSEH1HjHL$dH3 %(u)H[]ÐLYEH L1H5D f.AWAVIH5.EAUIATIUSH8dH%(HD$(1HHD$IUH9fIHl$HD$ )D$MH\$X@AFI>tIVHt A?LHtI6LH=HeI HM9L}I6HDLMLDAVt1H5DDLH$HtpH$HHtdLxD:tII>H u$LDH fKN1H5BI6LHHIIWHuH<$I HM97H|$VHLyCH J^1H5B1HgF11HL$(dH3 %(uH8[]A\A]A^A_ff.fUHHSHHFHHH[H5Ji ]@UHHSHHFHHH[H5i ]T@UHHSHHFHHH[H5*g ]@UHHSHHFQHHH[ H5jg ]@AT1I1UHH5CSH}HAHHHH[LH1]1A\rfAWAVAUATUSHHHHIIHw HAHLLDHo1HD$H1>AărH5@HHH$H`HHHH+_ HIHt:HHH)HHI1LLu LHAׅurLjHBL:HHHRHH|$H$H[]A\A]A^A_ÐH HIpH<$L4L?H JG. 1H5>';8H5>H=>HIHL$IHH¾ 1H$48fH5>H=>HHL$IHH¾ 1DH$ff.HIH5FHcHIH5FH8CHIH5FHX#HIH5FHxAWAVAUIATUSH(dH %(HL$1HFHHHw IHH>LDHb1HI13Ã0H5z=HHe1Itf@LI)$HD$ HH0HHthHHtھ:HHt+t1HLuHLLLL|f.LhHL(HL$dH3 %(LH([]A\A]A^A_fL=H 2Dw1H5;_sE18H5<H=)<H~IL HL16La$E18H5;H=;H/IL HL1PL8 >ff.HHH5Df.HHH5Czf.AWAVAUATUSHhHL$ dH%(HD$X1HIHHHo HHCHH{HCHIHD$(1LHD$1~ÃH5:HHz1L|$@f@LHD$)D$@HD$PI@HH+:HHD$8HtnHD$8:HxH|$8HD$8HtIHD$8:HxH|$8HD$8Ht$HD$8LHL`Ld$8HSHHH?HH|$11IŃH59Ll$8L%u:HD$HfDH|$fHHRHHE+:HHD$8HHD$8:HxH|$8HD$8HHD$8:HxH|$8HHHH|$8HHD$ HT$ HHT$8f.LLEHtH8tLH@uHLH|$LTLLLHu@HHuHD$8HDHLH|$H|$(dH|$ZHL$XdH3 %(HD$ Hh[]A\A]A^A_fHLEH|$LL@HT$ fDL8H R?1H56_L58H *?1H567:LHtLd$8L>HIL<8H56H=6H$HL$(H|$ IH¾ 1H|$(.H|$$HD$8*H5Z6H=j6HHL$H|$ IH¾ 1sHH|$!Z8H56H=6HhH|$ HL$(IH¾ 18 8H55H=5IH|$ HL$MH¾ 16N,ff.AWAVAUATUSHH $HH $HhHL$dH%(H$X 1HIHLo HHLH=H}LH=IHD$1LHD$1AŃH54HH>1Ll$0Lt$PfL@H$)D$0HD$@WAٹ LL5 14 fHH`HHHHt+t̾:HHD$(HtHD$(:HxH|$(HD$(HtHD$(:HxH|$(HD$(HgHD$(:LxLL|$(iHD$(HtLLq)HL.H<$LL*DLHH|$11ŃLH593yHHut@LHtUA+tJ:LHD$(Ht HD$(:HxH|$(HD$(LLL=HIHuHH|$H|$H$X dH3 %(H$Hh []A\A]A^A_@L2H 91H51?L%3H 81H51HD$(Ht^HD$(:HxH|$(HD$(Ht9Ld$(H-2HD$(f.:u#HLpHHuL L@HT$FHT$LHH<$LjL{8H5$1H=41HIH\$H|$H¾ 1H:HH|$H$j8H50H=0H$IH\$H|$H¾ 1HH|$+H#H<$zH$8!H5Q0H=a0HIH\$H|$H¾ 1HgD U8H5/H=0HcIH\$H|$H¾ 1H}3sAWAVAUIATIUH SHXdH%(HD$H1H}Hu LH\Hu +H+1H5.1HHH=0I1IHH>Aă=L|$ LX0Lcȹ!!L1L H!%tLDDHJHDщHL)L1H! t€DHqHDΉ@HL)H98H5.H=^.ILMHH¾1kDHHLvtBH;H1HH\$HdH3%(HX[]A\A]A^A_f.fDXLH8Iăz1HL$Ht$LHD$UA$H|$Ht$1ɺ oIA$`HD$8RH;D$GIcI9;1Dqt A<$H5>1H=,JMHLL 1H|$XHH@L8H{LH;LH;1H5 .1H;1LHH;HAAtJDH;11H5-H;LHCHC H{H{wH;f.H50-H=+(LL H1H|$9q@8DH5/H=+IML HL1HL1LH|$LH_A<$H5,H=+IXML HL18|H5+H=*HH LH1HD$H5+H={*L`LL HM1H|$MA<$H5.H=/*IM5AWAVAUATIUSHHH $dH%(H$1B&H5h+HHHHH$HL1IHRpHT$jHD$@HxHT$@A}HHHT$@H91H*HH=,*1HHD$ILHHu B<3:Ht$HIHL` LHLxL$LLHP%8DMeH5)H=(IML HH<$1E1E1HH $DDLHH$dH3 %(THĸ[]A\A]A^A_Ly'H */%1H5q'Lk(H /'1H5I'H5C)HHfE181I]H5|'H=m'IH<$MHH¾ 1E1vAG&fD HHL`L~LHHPf.H|$vHNIH9D$@A}11HA}LHI9uuA}LAA].8(MeH5(H=d&IMLHfD([8MeH5'H=&IeMLHfAE1E1H -$1H5W%`HHH5@.f.HHH5/.zf.HHH5-Zf.HHH5-:f.AWAVAUATUSHHHHMMHG HHAHM1HI1ŃLfHL$@HDHHLHAHA4=HD[]A\A]A^A_L%H r+1H5#wL#H J+1H5#OL%H "+1H5#';E18H5#H=#HFH|$@ILH¾ 1LT"E1N fAUAI;ATH $IԺ!UHSH8dH%(HD$(1HHjHHMAUHLH5+ZYHT$(dH3%(u H8[]A\A]HILHQH5+H@AUAI;ATH #IԺ!UHSH8dH%(HD$(1HHHHMAUHLH5+3ZYHT$(dH3%(u H8[]A\A]HILNHQH5*H@HIL^HQH5*H@HILnHQH5k*H@AVAUIATIUHSÅu[]A\A]A^DH5+#HIHtHILAULHH5)LXZ[]A\A]A^ff.AVAUIATIUHS6Åu[]A\A]A^DH5"H1IHtHILAULaHH5_)LXZF[]A\A]A^ff.AUH3)ATUHo SHHHHHIH(LAH{H(HHHH߉1A H[]A\A]ff.fAUH(ATUHo SHHHHIHLA]H{HJ(HHHjH߉01A H[]A\A]ff.fAUATIUSHH?1L-J!D!HHtH8@t3@Hu"L H &1H5!HLHt"I<$HH9rH1[]A\A]fDH[]A\A]AWHBIAVAUATUSH8H|$HT$ HL$(H$HD$HD$fDI7H|$IH1E1aHH4LH5OH=HHEMIE11HLHLAWAIH9LHIHI9GvIHiLYH=HwDIHtAGtH=Hþ H3HH $H9L$t?:HH H<$u"H|$H\$H$I Lt$1H1H5LHHLH$HH9D$ v Hl$@HH1H51LHHAH8H[]A\A]A^A_I/H5!!H=H|$(IHH¾1H1H|$fI/H5 L H 2#1H5AWAVAUATUSHH4$dH%(H$1HMMA@IHʍHv!L H "1H5"L- ILHHT$LLELeHT$HHLLHE1IHH4$HLXIHpHT$LiHT$@H|ZHT$@A}HIHT$@H908lIMH5H=IH $H $MHH¾ 1E1LDDHLALHH$dH3%(DHĸ[]A\A]A^A_DLH :!1H5LH !1H5iH5H=E1LHH1JA1Hf1HH= HHD$HLHH$rHt$L5IHIH|$H$HLu H$A<:tLLwM LHpH<LH4$@HT$@H4$I<ITH)6LLLHA}1L)HHD$zHLA}LHH$eH $H9Ht$A}HA@[8MuH5H=IeML HH1E1pDH$MA<:|f1ҾH1E1*LI4H5H=xE1HH11ҾH1uff.IIѹHj> H5ff.IIѹH> H5ff.IIѹHj< H5;ff.IIѹ H< H5~ff.1f1fAWAVAUIATUSH(BDD$Pv'L(H 1H5fDIIHL˃kH5LIMHMLHLI1MA~HٺLoHD$H)D$H5mHyHH5eD$HbHA~IHL"AH|$DD$谾DD$HDDLZLD$莾D$H([]A\A]A^A_L{H 1H5Y׿H5LH=HH1DD$]@H5LyIIU HHT$HT$HH57LHH|$QIAH HH5-ff.fIAHHH5IAH 0HH5ff.fIE1HHH5@IE1H HH5IE1HHH5Zt@IE1H HH56PAUATIUSHBHv(LH !1H5wHIH5HBHHHH{Hs L1HI1达ÃLHE1HtE1Hǀ8!AgpLXHPHD[]A\A]fL)H &1H5!蟻LH (1H5wHH5HT$LHT$HŃzD[8ԾH5H=HiLILH¾ 1E1fHHH5g*f.HHH57 f.HHH5/f.HHH5f.AWAVAUATUSHHBPv$L=H ~1H53IHAMăH5HIM@M_HLL1IHxLL舺IH(@@!vHHD$LD$H AAHCLLD$HPLD$8!H1HH=[1IHCLHPLH襷LD$L蘷Ht%ALMHܻu11LLLUH[]A\A]A^A_@L) H 1H5! 蟸LH 1H5 wL1r@H5H9{I3AtJAL@!uH.@!tLD$@tQHCHPLD$HfL@!uH>!tLD$L8L1ҾL1跹LD$L 11I1HH5IйHH5DIйHH5DI1HH5IйHH5buDIйHH5BUDI1HH5=8IйHH5DIйHH5DI1HH5IйHH5DIйHH5DfDAWAVAUATUSHdH%(H$1HMHILHHLLE1IHGHHLHH%pHT$AHD$@Hxj}HT$@HI׵H9D$@|LLAŅ}1HHD$@H~ A| wL?}LHLI&L9kAKD˲8DLmH5 H= IճLM HH1E1芶LDDHH葾ALƲH$dH3%(D^Hĸ[]A\A]A^A_f.L H 1H5qL H 1H5Idz۱8TLmH5H=ILM HH1E1蚵D}H5S LHkm8L}H5 H="HD$uLD$LHH¾1+fDH5 H=E15HH1dYfIIѹH. H5$ff.IIѹH:/ H5~ff.IIѹH, H5Nff.IIѹ H:- H5ff.USHHUHH2t8H5 1H轱HHQH= 6H輴HٳH5HCHPHCHHC0HHC8HHC@H\HCHH4 HCPHHCXHHC`HHChHeHCpHJHCxH_HHqHH3HHHHHH9HHHHMHHoHHHH3 HHeHHHH HHkHHHHHHHHsHHHHH H9H(HkH0HMH8HH@HH[]fDHH5 11衯HH[]H5 H=P1覮HH1dfUSHdH%(H$1HHH\t8H5^1HHHH=2HHH5+誮1H59 H1'HHH$u説8HH菱H謰H52HCHPHCHHC0HHC8H*HC@HHCHH1 HCPH9HCXHHC`HCHChHxHCpH]HCxHrHHHHHHHHHHlHHnHH`HH2HHHH0 HH8HHHH 0output_filename != NULLstrlen(output_filename) > 0couldn't open `%s': %slibusercouldn't stat `%s': %serror creating `%s': %sError reading `%s': %sError writing `%s': %sError resolving `%s': %sError replacing `%s': %smodule != NULLnames != NULLldapgr_passwdpw_passwderr != NULL:,ret != FALSE/etc*user != NULL, group != NULL%jderror locking file: %s%s.lock.XXXXXX%jucouldn't read from `%s': %sInvalid contents of lock `%s'Cannot obtain lock `%s': %s-+pw_namegr_namecouldn't write to `%s': %sent != NULLG_VALUE_HOLDS_STRING(value)shadow{CRYPT}sp_pwdp##: error encrypting password!!entry already present in filecontext != NULLfiles/nonrootyesfilesshadow/nonrootshadow/directorygr_admgr_memsp_lstchg-1sp_minsp_maxsp_warnsp_inactsp_expiresp_flagpw_gidpw_uidpw_gecospw_dirpw_shell/bin/bashError changing owner of `%s': %sError changing mode of `%s': %slibuser fatal error: %s() called with NULL error libuser fatal error: %s() called with non-NULL *error the `%s' and `%s' modules can not be combinedentry is incorrectly formattederror opening temporary file for `%s': %sThe lock %s is held by process %juError removing stale lock `%s': %s%s value `%s': `\n' not allowed%s value `%s': `:' not allowedformat_count != 0 && ret != NULL(ent->type == lu_user) || (ent->type == lu_group)entity object has no %s attributeentry with conflicting name already present in file`:' and `\n' not allowed in encrypted passwordnot executing with superuser privilegesno shadow file present -- disablinglibuser_shadow_initlu_files_shadow_valid_module_combinationlu_files_shadow_valid_module_combinationlu_files_users_enumerate_by_groupgeneric_lookupgeneric_addformat_genericgeneric_modgeneric_delgeneric_lockgeneric_is_lockedediting_closeent_has_shadowopen_and_copy_filegeneric_setpasslu_files_enumeratelu_files_groups_enumerate_by_userlu_files_enumerate_fullparse_fieldparse_genericclose_modulelibuser_files_init/gshadow/group/shadow/passwd;\ș(08HH\Xph8Dh0ȱHHh(h0X(x 8 X4xHȻ dH  , @ T H x L 8h h ( P H XX ( X  l  8 X x xH\p( H h4H\p(Hhx8L`8th(zRx $`FJ w?:*3$"DP\ pHܣBJB A(F0[ (D BBBF L(D BBB0%A_TDaBBB B(A0A8G L@LA 8A0A(B BBBI HX\eBBB B(A0A8G 8A0A(B BBBD 8BBD I(G0v (D ABBI HrFBB B(A0A8DP 8C0A(B BBBE ,H(H_D`(H_\xqEN E X(|جAGG0m AAB H\#BBL E(D0A8Dp 8A0A(B BBBA $@<EGG PGM$X<EGG PGM$Dp<EGG PGM$l<EGG PGM(NBHK gIDHįtBBB B(A0A8DPV 8A0A(B BBBB   4HH\(BBBB E(A0A8D`R 8A0A(B BBBC ,8LDFBB B(A0A8D 8A0A(B BBBC T ĹFBB B(A0A8G L@IA 8A0A(B BBBE LxBBB E(D0I8D 8A0A(B BBBK LPBBB B(D0A8J 8A0A(B BBBH ,@THhBBB B(A0A8D@ 8D0A(B BBBD DFMP D(D`_hHp\hA`T (A ABBA X,HN UDlFMP D(D`_hHp\hA`T (A ABBA `,HN U|,HN U,HN UTFBE D(D0N (A BBBF [8M@\8A0H(A BBBT (FBE D(D0N (A BBBF [8M@\8A0H(A BBB4d`FIA E(J0](A ABB4FIA E(J0](A ABBHBBD A(D0 (C ABBG D(F ABBH BIB B(A0A8Dp 8D0A(B BBBH Ll BBB B(A0A8G 8A0A(B BBBF  x" " " "  H4 BBB E(A0A8D`I 8A0A(B BBBD  $ 0# L X# t   8 BBD A(D@ (D ABBC \ (p 4 @ LH XBBB B(A0A8GP 8C0A(B BBBE    4 H ,\ 8p D P \ h t  L 'BBB B(A0A8G 8A0A(B BBBK L h"` "t " "4 EAD R DAG [ DAH , `~EAG AAH GNU 10 Lt݃Lt! t)t0)7@GP#4BR`p # Ц ئ o``   p x   oo oo:o' ###$$ $0$@$P$`$p$$$$$$$$$%% %0%@%P%`%p%%%%%%%%%&& &0&@&P&`&p&&&&&&&&&'' '0'@'P'`'p'''''''''(( (0(@(P(`(p((((((((()) )0)@)P)`)p)))))))))**GA$3a1# GA$3p111301GA*GA$annobin gcc 8.5.0 20210514GA$plugin name: gcc-annobinGA$running gcc 8.5.0 20210514GA*GA*GA! GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*GOW*GA*cf_protectionGA+omit_frame_pointerGA+stack_clashGA!stack_realign GA*FORTIFY01:1GA+GLIBCXX_ASSERTIONSlibuser_files.so-0.62-26.el8_10.x86_64.debug7zXZִF!t/Go]?Eh=ڊ2N$`+MpմBMavkeH`t,`Wd!H6Gܗ>*a$=">3~,s%hǺLU 2t>Na(+ :-j^mSomvD4CQ'CfZ-eZ¤>)+/Xк/0K0' 9AKVr52Hl^iV9|Yî;>MT]|7VJfm /_2ڍo" Šxi `N,c&&5.]w$;uieDG]8)c(n_0Fu ?KDmhX&~HjKwLŕmYo9rItb)r ˅5dA +r@KK_tme4jb$F9J#rጷ|evp \F:.aN- ,gm~5)#+tI^R4 w[(SXK̛8RէbT8n%VW^f!S̠.0!J*:y 8žLPcTQ9\ՀKyu?O@/&CѺ )#%wMX=^ F~ZV޹Yԏ3t~C)GM s"TAZy߁x+=mk1D*0ӽ\8kQ*MU(,% O a"t)Z@O_w M (=8FIcJ,KO!DourxUF問k*Ǘ}dCZomy(BPǛIiK Le'XMWB#pL1D9S=]| hQ+{)*Fxҿrb~+q{"J ^{- A`Ud4~) bCkAӮ yXh/xrNkcozjQróqEsX3PgWܔ]s!jIIEC>ia/yio#Ir;Riw)t*p-7,nji,9H"j-v,C ԗ#َNg"\7Ƃ1rj[;$ xMu*A vl8$6HvcŖHCb=kǃ0TX g z#zrczLc˗Z!#cwԈ"N?|YKrT"GZDh3!oŅyU6qQooי=F:˨JDRrξ._ڔڀ{tu50,"㉳bԣNFlbJ,)ONQ:#'Q SJ5(D\9R\ݞJMw׳ sr|>ؼl; tS!'Z$A6w A_gX<HWo/Cڬ_?͔FA?cѓo \;YVM5}xHJn̘YN <j.:ѱgYZ.shstrtab.note.gnu.build-id.gnu.hash.dynsym.dynstr.gnu.version.gnu.version_r.rela.dyn.rela.plt.init.plt.sec.text.fini.rodata.eh_frame_hdr.eh_frame.note.gnu.property.init_array.fini_array.data.rel.ro.dynamic.got.bss.gnu.build.attributes.gnu_debuglink.gnu_debugdata 88$o``8(  0` ` 8o::Eo  T^B  x h##c##`n * *Pwp0p0.P} 8  Ц Цئ ئ   pp p `H@4t$"PK1]:##AUTHORSnu[Nalin Dahyabhai PK1]%attributes.txtnu[Users: objectclass = posixAccount (files) uid userPassword uidNumber gidNumber gecos homeDirectory loginShell objectclass = shadowAccount (shadow) uid shadowLastChange shadowMin shadowMax shadowWarning shadowInactive shadowExpire shadowFlag Groups: objectclass = posixGroup (files) cn gidNumber memberUid objectclass = shadowGroup (shadow) cn userPassword administratorUid memberUid PK1]췈88READMEnu[About ===== The libuser library implements a standardized interface for manipulating and administering user and group accounts. The library uses pluggable back-ends to interface to its data sources. Sample applications modeled after those included with the shadow password suite are included. New releases will be available at https://fedorahosted.org/libuser/ . Bugs ==== Please consider reporting the bug to your distribution's bug tracking system. Otherwise, report bugs at https://fedorahosted.org/libuser/ . Bug reports with patches are especially welcome. PK1]tY>~  TODOnu[Easy: * Workalikes for various apps on other OSs: http://docs.sun.com/ab2/coll.40.6/REFMAN1/@Ab2PageView/169291 http://docs.sun.com/ab2/coll.40.6/REFMAN1/@Ab2PageView/64438 http://docs.sun.com/ab2/coll.40.6/REFMAN1/@Ab2PageView/64530 http://www.uwsg.iu.edu/usail/man/solaris/logins.1.html Medium: * Add the -o option to luseradd/lusermod/lgroupadd/lgroupmod (bad idea?) * Create variants of the apps that are hard-coded to use files only, for use in batch environments like post-package-install, or maybe add a --local flag, which will be interpreted as "shadow files"/"files".... * Add a shadowGroup schema file if RFC 2307bis doesn't include one, or ask Luke about adding one, and document what we expect an LDAP directory to have in order for the ldap module to not get confused (for now, that's the RFC 2307 schema + inetOrgPerson + TLS). * Make the LDAP module check the server schema for allowed object classes and attributes for new user additions and so on; right now it's kind of a crap shoot to see if the server will reject an operation due to a schema error. Hard: * Figure out how to reconcile lckpwdf() and fcntl() locking when the files being locked may not even be the system's main files. * Write a RADIUS back-end. * Write an NIS or NIS+ back-end using yppasswd.x in glibc, or maybe using the routines declared in /usr/include/rpcsvc/libnis.h * Write a libdbi or ODBC back-end. * Write a hesiod back-end. * Implement an lgpasswd command for local group administration by the group's administrators. PK1]b]]NEWSnu[0.62: * Fixed security vulnerabilities: * \n characters were allowed in files/shadow fields (CVE-2015-3245) * Non-atomic file updates in files/shadow module (CVE-2015-3246) Thanks to Qualys for reporting these issues. * The files and shadow modules now use a shadow-utils compatible scheme (primarily lckpwdf()). 0.61: * Python 3 is now supported. Consistent with the Python 3 C API and its prevailing usage, only UTF-8 locales work. Note that importing libuser in non-UTF-8 locales will fail in Python 3. * The Python extension now requires Python 2.7. * Translations are now maintained in https://fedora.zanata.org/ . * tests/fs_test can be edited to truly perform operations as root, without fakeroot. * sgml2txt is no longer required for building from the released tarball. * Miscellaneous bug fixes and cleanups, primarily in the Python extension. 0.60: * New functions lu_homedir_remove_for_user() and lu_homedir_remove_for_user_if_owned(). * libuser's pkg-config file no longer refers to internally-used libraries. glib-2.0 and gobject-2.0 are still included because they are required to use the API anyway. * When setting dates in shadow fields, avoid the special value 0 if the clock is incorrect. * Miscellaneous cleanups. 0.59: * Fixed security vulnerabilities: * Race conditions in copying and removing home directories (CVE-2012-5630) * Information disclosure when moving users' home directory (CVE-2012-5644) Related changes: - INCOMPATIBLE API CHANGES: lu_homedir_move() and lu_homedir_populate() will refuse to use a pre-existing directory as a destination. - setuid/setgid bits are now preserved when copying regular files in home directories (from /etc/skel or when moving a home directory) * Empty fields in /etc/shadow are now treated as "missing", like libc does. * Specific values of the attributes can be used to represent "missing data". * lchage(1) now handles missing fields on both input and output. * Refuse to build when secure_getenv() is not available. * Miscellaneous bug fixes and cleanups. 0.58 * API enhancements: * New helpers for attribute access replace 4-5 function calls with 1: lu_ent_get_first_{string,id,value_strdup}(), lu_ent_set_{string,id,long}() * New header , providing lu_homedir_{populate,move,remove}, lu_nscd_flush_cache(), and lu_mail_spool_{create,remove}. * lu_users_enumerate_by_group_full() and lu_groups_enumerate_by_user_full() are now fully supported. * New module-private function lu_util_append_values(). * Documented that LU_*PASSWORD should not be manipulated directly. * deleteUser in Python bindings now removes the mail spool instead of creating it. * New warning in libuser.conf.5 about storing a LDAP password in system-wide configuration. * Module interface ABI has changed. * Miscellaneous bug fixes and cleanups, quite a few memory leaks fixed. 0.57.7 * lu_users_enumerate_by_group_full() added, implemented ONLY for LDAP for now. Related functions and functionality in other modules will be added later. Applications are advised to NOT USE these functions yet. * group/user list by name of a user/group now returns an error if the user/group was not found. The Python bindings enumerateUsersFull and enumerateGroupsFull no longer crash in this situation. * Updated translations. 0.57.6 * Make it possible to use ldapi: URLs by not trying to use TLS (based on a patch by ). * Hopefully fix races in test suite, causing failures on slower computers. * Mark --help messages for translation and improve them a bit. * Update translations. 0.57.5 * Update translations. 0.57.4 * Don't crash when a database file size is a multiple of page size. * Miscellaneous bug fixes and cleanups. 0.57.3 * Don't assume user/group IDs start at 500 in Python getFirstUnusedGid and getFirstUnusedUid. * Preserve S_ISGID and other bits when copying directories from /etc/skel. * Deprecate lu_*_t typedefs: use {struct,enum} lu_* instead. * Update to build with recent gtk-doc. 0.57.2 * Fix adding LDAP users with empty gecos. * Correctly preserve algorithm used to hash an LDAP password when changing it. * Don't hard-code ports used in the test suite (to allow parallel development and builds). * Miscellaneous bug fixes. 0.57.1 * Fix a crash when a module refuses to load with a warning (e.g. the "shadow" module when /etc/shadow is not present) 0.57 * Resolve an ambiguity about "password" value format that could cause setting a known plaintext password in LDAP accounts: the "files"/"shadow" and LDAP modules may not be used together any more, and the module interface ABI has changed to support this. * Don't authenticate the user (in lchfn, lchsh, lpasswd) if the application is not set*id and it does not need elevated privileges. In particular, this allows the above programs to be used for LDAP administration by unprivileged users. * Change default crypt_style to sha512. * Don't abort on invalid ID values. * Miscellaneous bug fixes. 0.56.18 * Update translations. 0.56.17 * New Python constant VALUE_INVALID_ID and function validateIdValue. * Update translations. 0.56.16 * Update translations. 0.56.15 * Update translations. 0.56.14 * Use dgettext() inside the library. * Allow passing passwords using a pipe. * Allow specifying the LDAP password in a config file (patch by Rob Myers ). 0.56.13 * Report error in lid if the specified name does not exist. * Don't default a home directory to a path that contains a "." or ".." component derived from the user name (explicitly specified home directories that contain such components are accepted). * Detect naming conflicts when renaming an entry in the "files" or "shadow" module. * Add new arguments to luseradd and lusermod, to support creating and modifying LDAP user entries with the inetOrgPerson objectClass. 0.56.12 * Update translations. 0.56.11 * Remove user's mail spool as well in (luserdel -r). * Refuse GID and UID values (id_t)-1. * Verify name validity when renaming an entity. * Fix flushing of nscd cache by luser* utilities. 0.56.10 * Prohibit entity values that contain ':' in the files and shadow module (except for the last field on the line). * Don't corrupt LDAP passwords that use an unsupported password encryption scheme. * When the user name is used as a default group name, don't interpret it as a number. * Minor test suite and man page fixes. 0.56.9 * Warn in lusermod if changing a primary group ID to a group that does not exist. (#1) * Fix pastos in man pages. 0.56.8 * New home page at https://fedorahosted.org/libuser/ . 0.56.7 * Fix a crash with disabled SELinux * Add support for SHA256 and SHA512 in password hashes. * Fix file locking on some architectures * Remove default.-c, moving the provided functions to libuser proper. 0.56.6 * Set SELinux file contexts when creating home directories and preserve them when moving home directories 0.56.5 * Work around spurious error messages when run against the Fedora Directory server * Fix error reporting when creating home directories and creating / removing mail spool files 0.56.4 * Update the last password change date field when changing passwords. 0.56.3 * Allow specifying a SASL mechanism (#240904, original patch by Simo Sorce). 0.56.2 * Update translations 0.56.1 * When changing passwords, only silently ignore known shadow markers, not all invalid hashes 0.56 * Document the correct types used for attribute values. Use these types for parsing, to avoid corrupting number-like strings, e.g. '07' -> 7; this expands the API requirements * Miscellaneous bug fixes, optimizations and cleanups; module interface ABI has changed 0.55 * Remove the quota library and Python module. It doesn't even compile and has no known users. * Add support for the 64-bit API of Python 2.5 * Minor cleanups 0.54.8 * Add importing of HOME from default/useradd. 0.54.7 * Update translations 0.54.6 * Fix bugs in handling of invalid lines in the files and shadow modules. * Fix pattern matching in lu_*_enumerate_full in the files and shadow modules. * Add more error reporting, return non-zero exit status on error from utils. * Use the skeleton directory specified in libuser.conf by Python admin.createHome and admin.addUser, add parameter skeleton= to admin.addUser. 0.54.5 * Don't reference @pkglibdir@ in libuser.conf.5 to avoid multilib file conflicts. 0.54.4 * Fix compilation with pre-C99 compilers (#179385, patch by Dan Yefimov). * Allow building without Python (#179384, original patch by Dan Yefimov). 0.54.3 * Fix a crash when lpasswd is run without specifying an user name 0.54.2 * Avoid using deprecated openldap functions 0.54.1 * Support for importing of configuration from shadow (/etc/login.defs and /etc/default/useradd) * New libuser.conf(5) man page * Minor cleanups and bug fixes all over the code 0.54 * Make sure attributes with no values can never appear * Fix crash in the "files" module when an attribute is missing * Use hidden visibility for internal functions, remove them from libuser/user_private.h; this changes module interface ABI * Miscellaneous source code simplifications 0.53.8 * Permit "portable" user and group names as defined by SUSv3, plus trailing $ * Disable building static libraries by default * Miscellaneous build machinery improvements 0.53.7 * Add missing translations * Update translations 0.53.6 * Allow empty configuration values. 0.53.5 * Ignore nss_compat lines in the "files" module. * Autodetect Python version. 0.53.4 * Fix adding of objectclasses to LDAP user accounts. 0.53.3 * Handle more I/O failures. 0.53.2 * Important bug fixes in lchage, lgroupmod, lnewusers and lusermod; minor bug fixes in lpasswd and luseradd. * Add man pages for the utilities. 0.53.1 * Export UT_NAMESIZE from to Python 0.53 * Support UID and GID values larger than LONG_MAX (#124967) * Fix updating of groups after user renaming in lusermod * Allow setting a shadow password even if the current shadow password is invalid (#131180) * Add lu_{user,group}_unlock_nonempty (#86414); module interface ABI has changed * Miscellaneous bug and memory leak fixes 0.52.6 * Mark more strings for translation * Make error reporting more consistent and more verbose, output error messages on stderr. * Port sasldb backend to Cyrus SASL v2, make it at least minimally usable 0.52.5 * Fix home directory renaming in ADMIN.modifyUser (#135280) * Further Python reference counting fixes 0.52.4 * Memory leak fixes 0.52.3 * Fix compilation without libuser headers already installed (#134085) 0.52.2 * Allow LDAP connection using ldaps, custom ports or without TLS (original patch from Pawel Salek). 0.52.1 * Fix freecon() of uninitialized value in files/shadow module 0.52 * Usable LDAP backend * Miscellaneous bug fixes 0.51.12 * Don't claim success and exception at the same time (#133479) * LDAP fixes, second round * Various other bug fixes 0.51.11 * Allow documented optional arguments in Python ADMIN.{addUser,modifyUser,deleteUser} (#119812) * Add man pages for lchfn and lchsh * LDAP fixes, first round * Avoid file conflict on multilib systems * Call ldconfig correctly 0.51.10 * Don't attempt to lookup using original entity name after entity modification (rename in particular) (#78376, #121252) * Fix copying of symlinks from /etc/skel (#87572, original patch from gLaNDix) * Make --enable-quota work, and fix the quota code to at least compile (#89114) * Fix several bugs (#120168, original patch from Steve Grubb) * Don't hardcode python version in spec file (#130952, from Robert Scheck) * Properly integrate the SELinux patch, it should actually be used now, even though it was "enabled" since 0.51.7-6 0.51.9 * Fix various typos * Document library interfaces * Build all shared libraries with -fPIC (#72536) 0.51.8 * Update to build with latest autotools and gtk-doc * Update ALL_LINGUAS and POTFILES.in * Rebuild to depend on newer openldap 0.51.7-7 * fix is_selinux_enabled call 0.51.7-3 * Add SELinux support 0.51.7 * ldap: set error codes correctly when we encounter failures initializing * don't double-close modules which fail initialization * ldap: don't set an error in cases where one is already set 0.51.6 * use a crypt salt consistent with the defaults/crypt_style setting when setting new passwords (#79337) 0.51.5 * expose lu_get_first_unused_id() as a package-private function * provide libuser.ADMIN.getFirstUnusedUid and libuser.ADMIN.getFirstUnusedGid in python 0.51.4 * fix not freeing resources properly in files.c(generic_is_locked), spotted by Zou Pengcheng 0.51.2 * degrade gracefully * build with --with-pic and -fPIC * remove unpackaged man page 0.51.1-2 * translation updates 0.51.1-1 * doc updates -- cvs tree moved * language updates * disallow weird characters in account names * automated rebuild 0.51 * files: ignore blank lines in files * libuser: disallow creation of accounts with names containing whitespace, control characters, or non-ASCII characters 0.50.2 * refresh translations * fix a heap-corruption bug in the python bindings 0.50 * bump version * refresh translations 0.49.102 * ldap: cache an entity's dn in the entity structure to try to speed things up 0.49.101-2 * add missing buildreqs on cyrus-sasl-devel and openldap-devel (#59456) * translation refresh 0.49.101-1 * fix python bindings of enumerateFull functions * adjust prompter wrapping to not error out on successful returns 0.49.100 * be more careful about printing error messages * fix refreshing after adding of accounts * ldap: try to use a search to convert names to DNs, and only fall back to guessing if it turns up nothing * files: fix an off-by-one in removal of entries 0.49.99 * refresh translations * fix admin() constructor comments in the python module 0.49.98 * automatically refresh entities after add, modify, setpass, removepass, lock, and unlock operations * remove debug spewage when creating and removing mail spools * files: fix saving of multi-valued attributes * rename MEMBERUID attribute for groups to MEMBERNAME 0.49.97 * files: fix bug in removals * ldap: revert attempts at being smart at startup time, because it makes UIs very messy (up the three whole dialogs just to start the ldap stuff!) 0.49.96 * fix thinko in dispatch routines 0.49.95 * lgroupmod: fix thinko 0.49.93 * move shadow initialization for groups to the proper callback * rework locking in the files module to not require that files be writable * expose lu_strerror() * add various typedefs for types used by the library 0.49.92 * add removepass() functions * lchfn,lchsh,lpasswd - reorder PAM authentication calls * include API docs in the package 0.49.91 * ldap: finish port to new API * sasl: finish port to new API (needs test) * libuser: don't commit object changes before passing data to service functions which might need differing data sets to figure out what to change (for example, ldap) 0.49.90 * bind the internal mail spool creation/removal functions for python * renamed the python module * revamped internals to use gobject's gvalues and gvaluearrays instead of glists of cached strings * add enumeration-with-data functions to the C library * require linuxdoc-tools instead of sgml-tools for rawhide * fixup build files to allow building for arbitrary versions of python 0.32 * link the python module against libpam * attempt to import the python modules at build-time to verify dependencies 0.31 * fix a file-parsing bug that popped up in 0.29's mmap modifications 0.30 * quotaq: fix argument order when reading quota information * user_quota: set quota grace periods correctly * luseradd: never create home directories for system accounts * add da translation files * update translations 0.29 * add an explicit build dependency on jade (for the docs) * HUP nscd on modifications * userutil.c: mmap files we're reading for probable speed gain * userutil.c: be conservative with the amount of random data we read * docs fixes 0.28 * apps: print usage on errors * lnewusers.c: initialize groups as groups, not users * lnewusers.c: set passwords for new accounts * luseradd.c: accept group names in addition to IDs for the -g flag * luseradd.c: allow the primary GID to be a preexisting group 0.27 * add ko translation files * files.c: fix a heap corruption bug in lock/unlock (#51750) * files.c: close a memory leak in reading of files * files.c: remove implementation limits on lengths of lines 0.26 * lusermod: change user name in groups the user is a member of during renames * lgroupmod: change primary GID for users who are in the group during renumbers * ldap.c: handle new attributes more gracefully if possible * add ru translation files 0.25.1 * rename the quota source files to match the library, which clears up a file conflict with older quota packages * add ja translation files * add lu_ent_clear_all() function 0.25 * close up some memory leaks * add the ability to include resident versions of modules in the library 0.24-4 * fix incorrect Py_BuildValue invocation in python module 0.24-3 * stop leaking descriptors in the files module * speed up user creation by reordering some checks for IDs being in use * update the shadowLastChanged attribute when we set a password * adjust usage of getXXXXX_r where needed * fix assorted bugs in python binding which break prompting 0.23 * install sv translation * make lpasswd prompt for passwords when none are given on the command line * make sure all user-visible strings are marked for translation * clean up some user-visible strings * require PAM authentication in lchsh, lchfn, and lpasswd for non-networked modules * print uids and gids of users and names in lid app * fix tree traversal in users_enumerate_by_group and groups_enumerate_by_users * implement enumerate_by_group and enumerate_by_user in ldap module * fix id-based lookups in the ldap module * implement islocked() method in ldap module * implement setpass() method in ldap module * add lchfn and lchsh apps * add %d substitution to libuser.conf 0.21 * finish adding a sasldb module which manipulates a sasldb file * add users_enumerate_by_group and groups_enumerate_by_users * luserdel: remove the user's primary group if it has the same name as the user and has no members configured (-G disables) * fixup some configure stuff to make libuser.conf get generated correctly even when execprefix isn't specified 0.20 * only call the auth module when setting passwords (oops) * use GTrees instead of GHashTables for most internal tables * files: complain properly about unset attributes * files: group passwords are single-valued, not multiple-valued * add lpasswd app, make sure all apps start up popt with the right names 0.18 * actually make the new optional arguments optional * fix lu_error_new() to actually report errors right * fix part of the python bindings * include tools in the binary package again * fixup modules so that password-changing works right again * add a "key" field to prompt structures for use by apps which like to cache these things * add an optional "mvhomedir" argument to userModify (python) 0.16.1 * finish home directory population * implement home directory moving * change entity get semantics in the python bindings to allow default values for .get() * add lu_ent_has(), and a python has_key() method to Entity types * don't include tools in the binary package * add translated strings * lib/user.c: catch and ignore errors when running stacks * lusermod: fix slightly bogus help messages * luseradd: when adding a user and group, use the gid of the group instead of the user's uid as the primary group * properly set the password field in user accounts created using auth-only auth modules (shadow needs "x" instead of "!!") * implement home directory removal, start on population * fix group password setting in the files module * setpass affects both auth and info, so run both stacks * make the testbed apps noinst * fix errors due to uninitialized fields in the python bindings * add kwargs support to all python wrappers * add a mechanism for passing arguments to python callbacks * stub out the krb5 and ldap modules so that they'll at least compile again * don't bail when writing empty fields to colon-delimited files * use permissions of the original file when making backup files instead of 0600 * finish implementing is_locked methods in files/shadow module * finish cleanup of the python bindings * allow conditional builds of modules so that we can build without all of the prereqs for all of the modules * add error reporting facilities * split public header into pieces by function * backend cleanups * make %{name}-devel require %{name} and not %{name}-devel * clean up quota bindings some more * finish most of the ldap bindings * fix a subtle bug in the files module that would show up when renaming accounts * fix mapping methods for entity structures in python * get bindings for prompts to work correctly * clean up some of the add/remove semantics (set source on add) * ldap: implement enumeration * samples/enum: fix the argument order * clean up python bindings for quota 0.11 * finish up python bindings for quota support * finish up quota support libs * start quota support library to get some type safety * start looking at quota manipulation * add functions for enumerating users and groups, optionally per-module * lusermod.c: -s should specify the shell, not the home directory 0.10 * finish the python bindings and verify that the file backend works again * remove a redundant check which was breaking modifications * finish adding setpass methods 0.9 * get a start on some Python bindings 0.8.2 * make binary-incompatible change in headers 0.8.1 * add doxygen docs and a "doc" target for them 0.8 * add a "quiet" prompter * add --interactive flag to sample apps and default to using quiet prompter * ldap: attempt a "self" bind if other attempts fail * krb5: connect to the password-changing service if the user principal has the NULL instance * the great adding-of-the-copyright-statements * take more care when creating backup files in the files module 0.7 * add openldap-devel as a buildprereq * krb5: use a continuous connection * krb5: add "realm" config directive * ldap: use a continuous connection * ldap: add "server", "basedn", "binddn", "user", "authuser" config directives * ldap: actually finish the account deletion function * ldap: don't send cleartext passwords to the directory * fix naming attribute for users (should be uid, not gid) * refine the search-by-id,convert-to-name,search-by-name logic * fix handling of defaults when the config file is read in but contains no value * implement an LDAP information store * try to clean up module naming with libtool * luseradd: pass plaintext passwords along * luseradd: use symbolic attribute names instead of hard-coded * lusermod: pass plaintext passwords along * lgroupadd: pass plaintext passwords along * lgroupmod: pass plaintext passwords along * add libuser as a dependency of libuser-devel 0.6 * See changelog in libuser.spec.in from here on. 0.5 * Implemented the krb5 back-end (user add, modify, delete only). * Lookups in the files module use O_RDONLY instead of O_RDWR. 0.4 * Modify lu_start prototype and add semantics for non-superuser use (we'll need this later). 0.3 * Remove recursive account locking from the files/shadow module. * Fixup popt help text. * Remove dependency on krb5 profile sublibrary for reading config files. 0.2 * Implemented prompting. * Added macros for LU_USERNAME and LU_GROUPNAME, found a bug in the files module while converting to use them. * Switched from getopt() to popt for argument parsing to get autohelp in the various test/demo programs. 0.1 * Finished up most of the internals and the files back-end. * Simple shadow-like programs. PK1]* rfc2307.txtnu[ Network Working Group L. Howard Request for Comments: 2307 Independent Consultant Category: Experimental March 1998 An Approach for Using LDAP as a Network Information Service Status of this Memo This memo defines an Experimental Protocol for the Internet community. It does not specify an Internet standard of any kind. Discussion and suggestions for improvement are requested. Distribution of this memo is unlimited. Copyright Notice Copyright (C) The Internet Society (1998). All Rights Reserved. Abstract This document describes an experimental mechanism for mapping entities related to TCP/IP and the UNIX system into X.500 [X500] entries so that they may be resolved with the Lightweight Directory Access Protocol [RFC2251]. A set of attribute types and object classes are proposed, along with specific guidelines for interpreting them. The intention is to assist the deployment of LDAP as an organizational nameservice. No proposed solutions are intended as standards for the Internet. Rather, it is hoped that a general consensus will emerge as to the appropriate solution to such problems, leading eventually to the adoption of standards. The proposed mechanism has already been implemented with some success. 1. Background and Motivation The UNIX (R) operating system, and its derivatives (specifically, those which support TCP/IP and conform to the X/Open Single UNIX specification [XOPEN]) require a means of looking up entities, by matching them against search criteria or by enumeration. (Other operating systems that support TCP/IP may provide some means of resolving some of these entities. This schema is applicable to those environments also.) These entities include users, groups, IP services (which map names to IP ports and protocols, and vice versa), IP protocols (which map names to IP protocol numbers and vice versa), RPCs (which map names to ONC Remote Procedure Call [RFC1057] numbers and vice versa), NIS Howard Experimental [Page 1] RFC 2307 Using LDAP as a Network Information Service March 1998 netgroups, booting information (boot parameters and MAC address mappings), filesystem mounts, IP hosts and networks, and RFC822 mail aliases. Resolution requests are made through a set of C functions, provided in the UNIX system's C library. For example, the UNIX system utility "ls", which enumerates the contents of a filesystem directory, uses the C library function getpwuid() in order to map user IDs to login names. Once the request is made, it is resolved using a "nameservice" which is supported by the client library. The nameservice may be, at its simplest, a collection of files in the local filesystem which are opened and searched by the C library. Other common nameservices include the Network Information Service (NIS) and the Domain Name System (DNS). (The latter is typically used for resolving hosts, services and networks.) Both these nameservices have the advantage of being distributed and thus permitting a common set of entities to be shared amongst many clients. LDAP is a distributed, hierarchical directory service access protocol which is used to access repositories of users and other network- related entities. Because LDAP is often not tightly integrated with the host operating system, information such as users may need to be kept both in LDAP and in an operating system supported nameservice such as NIS. By using LDAP as the the primary means of resolving these entities, these redundancy issues are minimized and the scalability of LDAP can be exploited. (By comparison, NIS services based on flat files do not have the scalability or extensibility of LDAP or X.500.) The object classes and attributes defined below are suitable for representing the aforementioned entities in a form compatible with LDAP and X.500 directory services. 2. General Issues 2.1. Terminology The key words "MUST", "SHOULD", and "MAY" used in this document are to be interpreted as described in [RFC2119]. For the purposes of this document, the term "nameservice" refers to a service, such as NIS or flat files, that is used by the operating system to resolve entities within a single, local naming context. Contrast this with a "directory service" such as LDAP, which supports extensible schema and multiple naming contexts. Howard Experimental [Page 2] RFC 2307 Using LDAP as a Network Information Service March 1998 The term "NIS-related entities" broadly refers to entities which are typically resolved using the Network Information Service. (NIS was previously known as YP.) Deploying LDAP for resolving these entities does not imply that NIS be used, as a gateway or otherwise. In particular, the host and network classes are generically applicable, and may be implemented on any system that wishes to use LDAP or X.500 for host and network resolution. The "DUA" (directory user agent) refers to the LDAP client querying these entities, such as an LDAP to NIS gateway or the C library. The "client" refers to the application which ultimately makes use of the information returned by the resolution. It is irrelevant whether the DUA and the client reside within the same address space. The act of the DUA making this information to the client is termed "republishing". To avoid confusion, the term "login name" refers to the user's login name (being the value of the uid attribute) and the term "user ID" refers to he user's integer identification number (being the value of the uidNumber attribute). The phrases "resolving an entity" and "resolution of entities" refer respectively to enumerating NIS-related entities of a given type, and matching them against a given search criterion. One or more entities are returned as a result of successful "resolutions" (a "match" operation will only return one entity). The use of the term UNIX does not confer upon this schema the endorsement of owners of the UNIX trademark. Where necessary, the term "TCP/IP entity" is used to refer to protocols, services, hosts, and networks, and the term "UNIX entity" to its complement. (The former category does not mandate the host operating system supporting the interfaces required for resolving UNIX entities.) The OIDs defined below are derived from iso(1) org(3) dod(6) internet(1) directory(1) nisSchema(1). 2.2. Attributes The attributes and classes defined in this document are summarized below. The following attributes are defined in this document: uidNumber gidNumber gecos homeDirectory Howard Experimental [Page 3] RFC 2307 Using LDAP as a Network Information Service March 1998 loginShell shadowLastChange shadowMin shadowMax shadowWarning shadowInactive shadowExpire shadowFlag memberUid memberNisNetgroup nisNetgroupTriple ipServicePort ipServiceProtocol ipProtocolNumber oncRpcNumber ipHostNumber ipNetworkNumber ipNetmaskNumber macAddress bootParameter bootFile nisMapName nisMapEntry Additionally, some of the attributes defined in [RFC2256] are required. 2.3. Object classes The following object classes are defined in this document: posixAccount shadowAccount posixGroup ipService ipProtocol oncRpc ipHost ipNetwork nisNetgroup nisMap nisObject ieee802Device bootableDevice Additionally, some of the classes defined in [RFC2256] are required. Howard Experimental [Page 4] RFC 2307 Using LDAP as a Network Information Service March 1998 2.4. Syntax definitions The following syntax definitions [RFC2252] are used by this schema. The nisNetgroupTripleSyntax represents NIS netgroup triples: ( nisSchema.0.0 NAME 'nisNetgroupTripleSyntax' DESC 'NIS netgroup triple' ) Values in this syntax are represented by the following: nisnetgrouptriple = "(" hostname "," username "," domainname ")" hostname = "" / "-" / keystring username = "" / "-" / keystring domainname = "" / "-" / keystring X.500 servers may use the following representation of the above syntax: nisNetgroupTripleSyntax ::= SEQUENCE { hostname [0] IA5String OPTIONAL, username [1] IA5String OPTIONAL, domainname [2] IA5String OPTIONAL } The bootParameterSyntax syntax represents boot parameters: ( nisSchema.0.1 NAME 'bootParameterSyntax' DESC 'Boot parameter' ) where: bootparameter = key "=" server ":" path key = keystring server = keystring path = keystring X.500 servers may use the following representation of the above syntax: bootParameterSyntax ::= SEQUENCE { key IA5String, server IA5String, path IA5String } Values adhering to these syntaxes are encoded as strings by LDAP servers. Howard Experimental [Page 5] RFC 2307 Using LDAP as a Network Information Service March 1998 3. Attribute definitions This section contains attribute definitions to be implemented by DUAs supporting this schema. ( nisSchema.1.0 NAME 'uidNumber' DESC 'An integer uniquely identifying a user in an administrative domain' EQUALITY integerMatch SYNTAX 'INTEGER' SINGLE-VALUE ) ( nisSchema.1.1 NAME 'gidNumber' DESC 'An integer uniquely identifying a group in an administrative domain' EQUALITY integerMatch SYNTAX 'INTEGER' SINGLE-VALUE ) ( nisSchema.1.2 NAME 'gecos' DESC 'The GECOS field; the common name' EQUALITY caseIgnoreIA5Match SUBSTRINGS caseIgnoreIA5SubstringsMatch SYNTAX 'IA5String' SINGLE-VALUE ) ( nisSchema.1.3 NAME 'homeDirectory' DESC 'The absolute path to the home directory' EQUALITY caseExactIA5Match SYNTAX 'IA5String' SINGLE-VALUE ) ( nisSchema.1.4 NAME 'loginShell' DESC 'The path to the login shell' EQUALITY caseExactIA5Match SYNTAX 'IA5String' SINGLE-VALUE ) ( nisSchema.1.5 NAME 'shadowLastChange' EQUALITY integerMatch SYNTAX 'INTEGER' SINGLE-VALUE ) ( nisSchema.1.6 NAME 'shadowMin' EQUALITY integerMatch SYNTAX 'INTEGER' SINGLE-VALUE ) ( nisSchema.1.7 NAME 'shadowMax' EQUALITY integerMatch SYNTAX 'INTEGER' SINGLE-VALUE ) ( nisSchema.1.8 NAME 'shadowWarning' EQUALITY integerMatch SYNTAX 'INTEGER' SINGLE-VALUE ) ( nisSchema.1.9 NAME 'shadowInactive' Howard Experimental [Page 6] RFC 2307 Using LDAP as a Network Information Service March 1998 EQUALITY integerMatch SYNTAX 'INTEGER' SINGLE-VALUE ) ( nisSchema.1.10 NAME 'shadowExpire' EQUALITY integerMatch SYNTAX 'INTEGER' SINGLE-VALUE ) ( nisSchema.1.11 NAME 'shadowFlag' EQUALITY integerMatch SYNTAX 'INTEGER' SINGLE-VALUE ) ( nisSchema.1.12 NAME 'memberUid' EQUALITY caseExactIA5Match SUBSTRINGS caseExactIA5SubstringsMatch SYNTAX 'IA5String' ) ( nisSchema.1.13 NAME 'memberNisNetgroup' EQUALITY caseExactIA5Match SUBSTRINGS caseExactIA5SubstringsMatch SYNTAX 'IA5String' ) ( nisSchema.1.14 NAME 'nisNetgroupTriple' DESC 'Netgroup triple' SYNTAX 'nisNetgroupTripleSyntax' ) ( nisSchema.1.15 NAME 'ipServicePort' EQUALITY integerMatch SYNTAX 'INTEGER' SINGLE-VALUE ) ( nisSchema.1.16 NAME 'ipServiceProtocol' SUP name ) ( nisSchema.1.17 NAME 'ipProtocolNumber' EQUALITY integerMatch SYNTAX 'INTEGER' SINGLE-VALUE ) ( nisSchema.1.18 NAME 'oncRpcNumber' EQUALITY integerMatch SYNTAX 'INTEGER' SINGLE-VALUE ) ( nisSchema.1.19 NAME 'ipHostNumber' DESC 'IP address as a dotted decimal, eg. 192.168.1.1, omitting leading zeros' EQUALITY caseIgnoreIA5Match SYNTAX 'IA5String{128}' ) ( nisSchema.1.20 NAME 'ipNetworkNumber' DESC 'IP network as a dotted decimal, eg. 192.168, Howard Experimental [Page 7] RFC 2307 Using LDAP as a Network Information Service March 1998 omitting leading zeros' EQUALITY caseIgnoreIA5Match SYNTAX 'IA5String{128}' SINGLE-VALUE ) ( nisSchema.1.21 NAME 'ipNetmaskNumber' DESC 'IP netmask as a dotted decimal, eg. 255.255.255.0, omitting leading zeros' EQUALITY caseIgnoreIA5Match SYNTAX 'IA5String{128}' SINGLE-VALUE ) ( nisSchema.1.22 NAME 'macAddress' DESC 'MAC address in maximal, colon separated hex notation, eg. 00:00:92:90:ee:e2' EQUALITY caseIgnoreIA5Match SYNTAX 'IA5String{128}' ) ( nisSchema.1.23 NAME 'bootParameter' DESC 'rpc.bootparamd parameter' SYNTAX 'bootParameterSyntax' ) ( nisSchema.1.24 NAME 'bootFile' DESC 'Boot image name' EQUALITY caseExactIA5Match SYNTAX 'IA5String' ) ( nisSchema.1.26 NAME 'nisMapName' SUP name ) ( nisSchema.1.27 NAME 'nisMapEntry' EQUALITY caseExactIA5Match SUBSTRINGS caseExactIA5SubstringsMatch SYNTAX 'IA5String{1024}' SINGLE-VALUE ) 4. Class definitions This section contains class definitions to be implemented by DUAs supporting the schema. The rfc822MailGroup object class MAY be used to represent a mail group for the purpose of alias expansion. Several alternative schemes for mail routing and delivery using LDAP directories, which are outside the scope of this document. ( nisSchema.2.0 NAME 'posixAccount' SUP top AUXILIARY DESC 'Abstraction of an account with POSIX attributes' MUST ( cn $ uid $ uidNumber $ gidNumber $ homeDirectory ) MAY ( userPassword $ loginShell $ gecos $ description ) ) Howard Experimental [Page 8] RFC 2307 Using LDAP as a Network Information Service March 1998 ( nisSchema.2.1 NAME 'shadowAccount' SUP top AUXILIARY DESC 'Additional attributes for shadow passwords' MUST uid MAY ( userPassword $ shadowLastChange $ shadowMin shadowMax $ shadowWarning $ shadowInactive $ shadowExpire $ shadowFlag $ description ) ) ( nisSchema.2.2 NAME 'posixGroup' SUP top STRUCTURAL DESC 'Abstraction of a group of accounts' MUST ( cn $ gidNumber ) MAY ( userPassword $ memberUid $ description ) ) ( nisSchema.2.3 NAME 'ipService' SUP top STRUCTURAL DESC 'Abstraction an Internet Protocol service. Maps an IP port and protocol (such as tcp or udp) to one or more names; the distinguished value of the cn attribute denotes the service's canonical name' MUST ( cn $ ipServicePort $ ipServiceProtocol ) MAY ( description ) ) ( nisSchema.2.4 NAME 'ipProtocol' SUP top STRUCTURAL DESC 'Abstraction of an IP protocol. Maps a protocol number to one or more names. The distinguished value of the cn attribute denotes the protocol's canonical name' MUST ( cn $ ipProtocolNumber $ description ) MAY description ) ( nisSchema.2.5 NAME 'oncRpc' SUP top STRUCTURAL DESC 'Abstraction of an Open Network Computing (ONC) [RFC1057] Remote Procedure Call (RPC) binding. This class maps an ONC RPC number to a name. The distinguished value of the cn attribute denotes the RPC service's canonical name' MUST ( cn $ oncRpcNumber $ description ) MAY description ) ( nisSchema.2.6 NAME 'ipHost' SUP top AUXILIARY DESC 'Abstraction of a host, an IP device. The distinguished value of the cn attribute denotes the host's canonical name. Device SHOULD be used as a structural class' MUST ( cn $ ipHostNumber ) MAY ( l $ description $ manager ) ) ( nisSchema.2.7 NAME 'ipNetwork' SUP top STRUCTURAL DESC 'Abstraction of a network. The distinguished value of the cn attribute denotes the network's canonical name' Howard Experimental [Page 9] RFC 2307 Using LDAP as a Network Information Service March 1998 MUST ( cn $ ipNetworkNumber ) MAY ( ipNetmaskNumber $ l $ description $ manager ) ) ( nisSchema.2.8 NAME 'nisNetgroup' SUP top STRUCTURAL DESC 'Abstraction of a netgroup. May refer to other netgroups' MUST cn MAY ( nisNetgroupTriple $ memberNisNetgroup $ description ) ) ( nisSchema.2.09 NAME 'nisMap' SUP top STRUCTURAL DESC 'A generic abstraction of a NIS map' MUST nisMapName MAY description ) ( nisSchema.2.10 NAME 'nisObject' SUP top STRUCTURAL DESC 'An entry in a NIS map' MUST ( cn $ nisMapEntry $ nisMapName ) MAY description ) ( nisSchema.2.11 NAME 'ieee802Device' SUP top AUXILIARY DESC 'A device with a MAC address; device SHOULD be used as a structural class' MAY macAddress ) ( nisSchema.2.12 NAME 'bootableDevice' SUP top AUXILIARY DESC 'A device with boot parameters; device SHOULD be used as a structural class' MAY ( bootFile $ bootParameter ) ) 5. Implementation details 5.1. Suggested resolution methods The preferred means of directing a client application (one using the shared services of the C library) to use LDAP as its information source for the functions listed in 5.2 is to modify the source code to directly query LDAP. As the source to commercial C libraries and applications is rarely available to the end-user, one could emulate a supported nameservice (such as NIS). (This is also an appropriate opportunity to perform caching of entries across process address spaces.) In the case of NIS, reference implementations are widely available and the RPC interface is well known. The means by which the operating system is directed to use LDAP is implementation dependent. For example, some operating systems and C libraries support end-user extensible resolvers using dynamically loadable libraries and a nameservice "switch". The means in which the DUA locates LDAP servers is also implementation dependent. Howard Experimental [Page 10] RFC 2307 Using LDAP as a Network Information Service March 1998 5.2. Affected library functions The following functions are typically found in the C libraries of most UNIX and POSIX compliant systems. An LDAP search filter [RFC2254] which may be used to satisfy the function call is included alongside each function name. Parameters are denoted by %s and %d for string and integer arguments, respectively. Long lines are broken. getpwnam() (&(objectClass=posixAccount)(uid=%s)) getpwuid() (&(objectClass=posixAccount) (uidNumber=%d)) getpwent() (objectClass=posixAccount) getspnam() (&(objectClass=shadowAccount)(uid=%s)) getspent() (objectClass=shadowAccount) getgrnam() (&(objectClass=posixGroup)(cn=%s)) getgrgid() (&(objectClass=posixGroup) (gidNumber=%d)) getgrent() (objectClass=posixGroup) getservbyname() (&(objectClass=ipService) (cn=%s)(ipServiceProtocol=%s)) getservbyport() (&(objectClass=ipService) (ipServicePort=%d) (ipServiceProtocol=%s)) getservent() (objectClass=ipService) getrpcbyname() (&(objectClass=oncRpc)(cn=%s)) getrpcbynumber() (&(objectClass=oncRpc)(oncRpcNumber=%d)) getrpcent() (objectClass=oncRpc) getprotobyname() (&(objectClass=ipProtocol)(cn=%s)) getprotobynumber() (&(objectClass=ipProtocol) (ipProtocolNumber=%d)) getprotoent() (objectClass=ipProtocol) gethostbyname() (&(objectClass=ipHost)(cn=%s)) gethostbyaddr() (&(objectClass=ipHost)(ipHostNumber=%s)) gethostent() (objectClass=ipHost) getnetbyname() (&(objectClass=ipNetwork)(cn=%s)) getnetbyaddr() (&(objectClass=ipNetwork) (ipNetworkNumber=%s)) getnetent() (objectClass=ipNetwork) setnetgrent() (&(objectClass=nisNetgroup)(cn=%s)) Howard Experimental [Page 11] RFC 2307 Using LDAP as a Network Information Service March 1998 5.3. Interpreting user and group entries User and group resolution is initiated by the functions prefixed by getpw and getgr respectively. The uid attribute contains the user's login name. The cn attribute, in posixGroup entries, contains the group's name. The account object class provides a convenient structural class for posixAccount, and SHOULD be used where additional attributes are not required. It is suggested that uid and cn are used as the RDN attribute type for posixAccount and posixGroup entries, respectively. An account's GECOS field is preferably determined by a value of the gecos attribute. If no gecos attribute exists, the value of the cn attribute MUST be used. (The existence of the gecos attribute allows information embedded in the GECOS field, such as a user's telephone number, to be returned to the client without overloading the cn attribute. It also accommodates directories where the common name does not contain the user's full name.) An entry of class posixAccount, posixGroup, or shadowAccount without a userPassword attribute MUST NOT be used for authentication. The client should be returned a non-matchable password such as "x". userPassword values MUST be represented by following syntax: passwordvalue = schemeprefix encryptedpassword schemeprefix = "{" scheme "}" scheme = "crypt" / "md5" / "sha" / altscheme altscheme = "x-" keystring encryptedpassword = encrypted password The encrypted password contains of a plaintext key hashed using the algorithm scheme. userPassword values which do not adhere to this syntax MUST NOT be used for authentication. The DUA MUST iterate through the values of the attribute until a value matching the above syntax is found. Only if encryptedpassword is an empty string does the user have no password. DUAs are not required to consider encryption schemes which the client will not recognize; in most cases, it may be sufficient to consider only "crypt". Below is an example of a userPassword attribute: userPassword: {crypt}X5/DBrWPOQQaI Howard Experimental [Page 12] RFC 2307 Using LDAP as a Network Information Service March 1998 A future standard may specify LDAP v3 attribute descriptions to represent hashed userPasswords, as noted below. This schema MUST NOT be used with LDAP v2 DUAs and DSAs. attributetype = attributename sep attributeoption attributename = "userPassword" sep = ";" attributeoption = schemeclass "-" scheme schemeclass = "hash" / altschemeclass scheme = "crypt" / "md5" / "sha" / altscheme altschemeclass = "x-" keystring altscheme = keystring Below is an example of a userPassword attribute, represented with an LDAP v3 attribute description: userPassword;hash-crypt: X5/DBrWPOQQaI A DUA MAY utilise the attributes in the shadowAccount class to provide shadow password service (getspnam() and getspent()). In such cases, the DUA MUST NOT make use of the userPassword attribute for getpwnam() et al, and MUST return a non-matchable password (such as "x") to the client instead. 5.4. Interpreting hosts and networks The ipHostNumber and ipNetworkNumber attributes are defined in preference to dNSRecord (defined in [RFC1279]), in order to simplify the DUA's role in interpreting entries in the directory. A dNSRecord expresses a complete resource record, including time to live and class data, which is extraneous to this schema. Additionally, the ipHost and ipNetwork classes permit a host or network (respectively) and all its aliases to be represented by a single entry in the directory. This is not necessarily possible if a DNS resource record is mapped directly to an LDAP entry. Implementations that wish to use LDAP to master DNS zone information are not precluded from doing so, and may simply avoid the ipHost and ipNetwork classes. This document redefines, although not exclusively, the ipNetwork class defined in [RFC1279], in order to achieve consistent naming with ipHost. The ipNetworkNumber attribute is also used in the siteContact object class [ROSE]. Howard Experimental [Page 13] RFC 2307 Using LDAP as a Network Information Service March 1998 The trailing zeros in a network address MUST be omitted. CIDR-style network addresses (eg. 192.168.1/24) MAY be used. Hosts with IPv6 addresses MUST be written in their "preferred" form as defined in section 2.2.1 of [RFC1884], such that all components of the address are indicated and leading zeros are omitted. This provides a consistent means of resolving ipHosts by address. 5.5. Interpreting other entities In general, a one-to-one mapping between entities and LDAP entries is proposed, in that each entity has exactly one representation in the DIT. In some cases this is not feasible; for example, a service which is represented in more than one protocol domain. Consider the following entry: dn: cn=domain, dc=aja, dc=com cn: domain cn: nameserver objectClass: top objectClass: ipService ipServicePort: 53 ipServiceProtocol: tcp ipServiceProtocol: udp This entry MUST map to the following two (2) services entities: domain 53/tcp nameserver domain 53/udp nameserver While the above two entities may be represented as separate LDAP entities, with different distinguished names (such as cn=domain+ipServiceProtocol=tcp, ... and cn=domain+ipServiceProtocol=udp, ...) it is convenient to represent them as a single entry. (If a service is represented in multiple protocol domains with different ports, then multiple entries are required; multivalued RDNs may be used to distinguish them.) With the exception of userPassword values, which are parsed according to the syntax considered in section 5.2, any empty values (consisting of a zero length string) are returned by the DUA to the client. The DUA MUST reject any entries which do not conform to the schema (missing mandatory attributes). Non-conforming entries SHOULD be ignored while enumerating entries. The nisObject object class MAY be used as a generic means of representing NIS entities. Its use is not encouraged; where support for entities not described in this schema is desired, an appropriate Howard Experimental [Page 14] RFC 2307 Using LDAP as a Network Information Service March 1998 schema should be devised. Implementors are strongly advised to support end-user extensible mappings between NIS entities and object classes. (Where the nisObject class is used, the nisMapName attribute may be used as a RDN.) 5.6. Canonicalizing entries with multi-valued naming attributes For entities such as hosts, services, networks, protocols, and RPCs, where there may be one or more aliases, the respective entry's relative distinguished name SHOULD be used to determine the canonical name. Any other values for the same attribute are used as aliases. For example, the service described in section 5.5 has the canonical name "domain" and exactly one alias, "nameserver". The schema in this document generally only defines one attribute per class which is suitable for distinguishing an entity (excluding any attributes with integer syntax; it is assumed that entries will be distinguished on name). Usually, this is the common name (cn) attribute. This aids the DUA in determining the canonical name of an entity, as it can examine the value of the relative distinguished name. Aliases are thus any values of the distinguishing attribute (such as cn) which do not match the canonical name of the entity. In the event that a different attribute is used to distinguish the entry, as may be the case where these object classes are used as auxiliary classes, the entry's canonical name may not be present in the RDN. In this case, the DUA MUST choose one of the non- distinguished values to represent the entity's canonical name. As the directory server guarantees no ordering of attribute values, it may not be possible to distinguish an entry deterministically. This ambiguity SHOULD NOT be resolved by mapping one directory entry into multiple entities. 6. Implementation focus A NIS server which uses LDAP instead of local files has been developed which supports the schema defined in this document. A reference implementation of the C library resolution code has been written for the Free Software Foundation. It may support other C libraries which support the Name Service Switch (NSS) or the Information Retrieval Service (IRS). The author has made available a freely distributable set of scripts which parses local databases such as /etc/passwd and /etc/hosts into a form suitable for loading into an LDAP server. Howard Experimental [Page 15] RFC 2307 Using LDAP as a Network Information Service March 1998 7. Security Considerations The entirety of related security considerations are outside the scope of this document. It is noted that making passwords encrypted with a widely understood hash function (such as crypt()) available to non- privileged users is dangerous because it exposes them to dictionary and brute-force attacks. This is proposed only for compatibility with existing UNIX system implementations. Sites where security is critical SHOULD consider using a strong authentication service for user authentication. Alternatively, the encrypted password could be made available only to a subset of privileged DUAs, which would provide "shadow" password service to client applications. This may be difficult to enforce. Because the schema represents operating system-level entities, access to these entities SHOULD be granted on a discretionary basis. (There is little point in restricting access to data which will be republished without restriction, however.) It is particularly important that only administrators can modify entries defined in this schema, with the exception of allowing a principal to change their password (which may be done on behalf of the user by a client bound as a superior principal, such that password restrictions may be enforced). For example, if a user were allowed to change the value of their uidNumber attribute, they could subvert security by equivalencing their account with the superuser account. A subtree of the DIT which is to be republished by a DUA (such as a NIS gateway) SHOULD be within the same administrative domain that the republishing DUA represents. (For example, principals outside an organization, while conceivably part of the DIT, should not be considered with the same degree of authority as those within the organization.) Finally, care should be exercised with integer attributes of a sensitive nature (particularly the uidNumber and gidNumber attributes) which contain zero-length values. DUAs MAY treat such values as corresponding to the "nobody" or "nogroup" user and group, respectively. 8. Acknowledgements Thanks to Leif Hedstrom of Netscape Communications Corporation, Michael Grant and Rosanna Lee of Sun Microsystems Inc., Ed Reed of Novell Inc., and Mark Wahl of Critical Angle Inc. for their valuable contributions to the development of this schema. Thanks to Andrew Josey of The Open Group for clarifying the use of the UNIX trademark, and to Tim Howes and Peter J. Cherny for their support. Howard Experimental [Page 16] RFC 2307 Using LDAP as a Network Information Service March 1998 UNIX is a registered trademark of The Open Group. 9. References [RFC1057] Sun Microsystems, Inc., "RPC: Remote Procedure Call: Protocol Specification Version 2", RFC 1057, June 1988. [RFC1279] Kille, S., "X.500 and Domains", RFC 1279, November 1991. [RFC1884] Hinden, R., and S. Deering, "IP Version 6 Addressing Architecture", RFC 1884, December 1995. [RFC2119] Bradner, S., "Key Words for use in RFCs to Indicate Requirement Levels", BCP 14, RFC 2119, March 1997. [RFC2251] Wahl, M., Howes, T., and S. Kille, "Lightweight Directory Access Protocol (v3)", RFC 2251, December 1997. [RFC2252] Wahl, M., Coulbeck, A., Howes, T., and S. Kille, "Lightweight Directory Access Protocol (v3): Attribute Syntax Definitions", RFC 2252, December 1997. [RFC2254] Howes, T., "The String Representation of LDAP Search Filters", RFC 2254, December 1997. [RFC2256] Wahl, M., "A Summary of the X.500(96) User Schema for use with LDAPv3", RFC 2256, December 1997. [ROSE] M. T. Rose, "The Little Black Book: Mail Bonding with OSI Directory Services", ISBN 0-13-683210-5, Prentice-Hall, Inc., 1992. [X500] "Information Processing Systems - Open Systems Interconnection - The Directory: Overview of Concepts, Models and Service", ISO/IEC JTC 1/SC21, International Standard 9594-1, 1988. Howard Experimental [Page 17] RFC 2307 Using LDAP as a Network Information Service March 1998 [XOPEN] ISO/IEC 9945-1:1990, Information Technology - Portable Operating Systems Interface (POSIX) - Part 1: Systems Application Programming Interface (API) [C Language] 10. Author's Address Luke Howard PO Box 59 Central Park Vic 3145 Australia EMail: lukeh@xedoc.com Howard Experimental [Page 18] RFC 2307 Using LDAP as a Network Information Service March 1998 A. Example entries The examples described in this section are provided to illustrate the schema described in this memo. They are not meant to be exhaustive. The following entry is an example of the posixAccount class: dn: uid=lester, dc=aja, dc=com objectClass: top objectClass: account objectClass: posixAccount uid: lester cn: Lester the Nightfly userPassword: {crypt}X5/DBrWPOQQaI gecos: Lester loginShell: /bin/csh uidNumber: 10 gidNumber: 10 homeDirectory: /home/lester This corresponds the UNIX system password file entry: lester:X5/DBrWPOQQaI:10:10:Lester:/home/lester:/bin/sh The following entry is an example of the ipHost class: dn: cn=peg.aja.com, dc=aja, dc=com objectClass: top objectClass: device objectClass: ipHost objectClass: bootableDevice objectClass: ieee802Device cn: peg.aja.com cn: www.aja.com ipHostNumber: 10.0.0.1 macAddress: 00:00:92:90:ee:e2 bootFile: mach bootParameter: root=fs:/nfsroot/peg bootParameter: swap=fs:/nfsswap/peg bootParameter: dump=fs:/nfsdump/peg This entry represents the host canonically peg.aja.com, also known as www.aja.com. The Ethernet address and four boot parameters are also specified. Howard Experimental [Page 19] RFC 2307 Using LDAP as a Network Information Service March 1998 An example of the nisNetgroup class: dn: cn=nightfly, dc=aja, dc=com objectClass: top objectClass: nisNetgroup cn: nightfly nisNetgroupTriple: (charlemagne,peg,dunes.aja.com) nisNetgroupTriple: (lester,-,) memberNisNetgroup: kamakiriad This entry represents the netgroup nightfly, which contains two triples (the user charlemagne, the host peg, and the domain dunes.aja.com; and, the user lester, no host, and any domain) and one netgroup (kamakiriad). Finally, an example of the nisObject class: dn: nisMapName=tracks, dc=dunes, dc=aja, dc=com objectClass: top objectClass: nisMap nisMapName: tracks dn: cn=Maxine, nisMapName=tracks, dc=dunes, dc=aja, dc=com objectClass: top objectClass: nisObject cn: Maxine nisMapName: tracks nisMapEntry: Nightfly$4 This entry represents the NIS map tracks, and a single map entry. Howard Experimental [Page 20] RFC 2307 Using LDAP as a Network Information Service March 1998 Full Copyright Statement Copyright (C) The Internet Society (1998). All Rights Reserved. This document and translations of it may be copied and furnished to others, and derivative works that comment on or otherwise explain it or assist in its implementation may be prepared, copied, published and distributed, in whole or in part, without restriction of any kind, provided that the above copyright notice and this paragraph are included on all such copies and derivative works. However, this document itself may not be modified in any way, such as by removing the copyright notice or references to the Internet Society or other Internet organizations, except as needed for the purpose of developing Internet standards in which case the procedures for copyrights defined in the Internet Standards process must be followed, or as required to translate it into languages other than English. The limited permissions granted above are perpetual and will not be revoked by the Internet Society or its successors or assigns. This document and the information contained herein is provided on an "AS IS" basis and THE INTERNET SOCIETY AND THE INTERNET ENGINEERING TASK FORCE DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. Howard Experimental [Page 21] PK1][y'c'cCOPYINGnu[ GNU LIBRARY GENERAL PUBLIC LICENSE Version 2, June 1991 Copyright (C) 1991 Free Software Foundation, Inc. 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA Everyone is permitted to copy and distribute verbatim copies of this license document, but changing it is not allowed. [This is the first released version of the library GPL. It is numbered 2 because it goes with version 2 of the ordinary GPL.] Preamble The licenses for most software are designed to take away your freedom to share and change it. By contrast, the GNU General Public Licenses are intended to guarantee your freedom to share and change free software--to make sure the software is free for all its users. This license, the Library General Public License, applies to some specially designated Free Software Foundation software, and to any other libraries whose authors decide to use it. You can use it for your libraries, too. When we speak of free software, we are referring to freedom, not price. Our General Public Licenses are designed to make sure that you have the freedom to distribute copies of free software (and charge for this service if you wish), that you receive source code or can get it if you want it, that you can change the software or use pieces of it in new free programs; and that you know you can do these things. To protect your rights, we need to make restrictions that forbid anyone to deny you these rights or to ask you to surrender the rights. These restrictions translate to certain responsibilities for you if you distribute copies of the library, or if you modify it. For example, if you distribute copies of the library, whether gratis or for a fee, you must give the recipients all the rights that we gave you. You must make sure that they, too, receive or can get the source code. If you link a program with the library, you must provide complete object files to the recipients so that they can relink them with the library, after making changes to the library and recompiling it. And you must show them these terms so they know their rights. Our method of protecting your rights has two steps: (1) copyright the library, and (2) offer you this license which gives you legal permission to copy, distribute and/or modify the library. Also, for each distributor's protection, we want to make certain that everyone understands that there is no warranty for this free library. If the library is modified by someone else and passed on, we want its recipients to know that what they have is not the original version, so that any problems introduced by others will not reflect on the original authors' reputations. Finally, any free program is threatened constantly by software patents. We wish to avoid the danger that companies distributing free software will individually obtain patent licenses, thus in effect transforming the program into proprietary software. To prevent this, we have made it clear that any patent must be licensed for everyone's free use or not licensed at all. Most GNU software, including some libraries, is covered by the ordinary GNU General Public License, which was designed for utility programs. This license, the GNU Library General Public License, applies to certain designated libraries. This license is quite different from the ordinary one; be sure to read it in full, and don't assume that anything in it is the same as in the ordinary license. The reason we have a separate public license for some libraries is that they blur the distinction we usually make between modifying or adding to a program and simply using it. Linking a program with a library, without changing the library, is in some sense simply using the library, and is analogous to running a utility program or application program. However, in a textual and legal sense, the linked executable is a combined work, a derivative of the original library, and the ordinary General Public License treats it as such. Because of this blurred distinction, using the ordinary General Public License for libraries did not effectively promote software sharing, because most developers did not use the libraries. We concluded that weaker conditions might promote sharing better. However, unrestricted linking of non-free programs would deprive the users of those programs of all benefit from the free status of the libraries themselves. This Library General Public License is intended to permit developers of non-free programs to use free libraries, while preserving your freedom as a user of such programs to change the free libraries that are incorporated in them. (We have not seen how to achieve this as regards changes in header files, but we have achieved it as regards changes in the actual functions of the Library.) The hope is that this will lead to faster development of free libraries. The precise terms and conditions for copying, distribution and modification follow. Pay close attention to the difference between a "work based on the library" and a "work that uses the library". The former contains code derived from the library, while the latter only works together with the library. Note that it is possible for a library to be covered by the ordinary General Public License rather than by this special one. GNU LIBRARY GENERAL PUBLIC LICENSE TERMS AND CONDITIONS FOR COPYING, DISTRIBUTION AND MODIFICATION 0. This License Agreement applies to any software library which contains a notice placed by the copyright holder or other authorized party saying it may be distributed under the terms of this Library General Public License (also called "this License"). Each licensee is addressed as "you". A "library" means a collection of software functions and/or data prepared so as to be conveniently linked with application programs (which use some of those functions and data) to form executables. The "Library", below, refers to any such software library or work which has been distributed under these terms. A "work based on the Library" means either the Library or any derivative work under copyright law: that is to say, a work containing the Library or a portion of it, either verbatim or with modifications and/or translated straightforwardly into another language. (Hereinafter, translation is included without limitation in the term "modification".) "Source code" for a work means the preferred form of the work for making modifications to it. For a library, complete source code means all the source code for all modules it contains, plus any associated interface definition files, plus the scripts used to control compilation and installation of the library. Activities other than copying, distribution and modification are not covered by this License; they are outside its scope. The act of running a program using the Library is not restricted, and output from such a program is covered only if its contents constitute a work based on the Library (independent of the use of the Library in a tool for writing it). Whether that is true depends on what the Library does and what the program that uses the Library does. 1. You may copy and distribute verbatim copies of the Library's complete source code as you receive it, in any medium, provided that you conspicuously and appropriately publish on each copy an appropriate copyright notice and disclaimer of warranty; keep intact all the notices that refer to this License and to the absence of any warranty; and distribute a copy of this License along with the Library. You may charge a fee for the physical act of transferring a copy, and you may at your option offer warranty protection in exchange for a fee. 2. You may modify your copy or copies of the Library or any portion of it, thus forming a work based on the Library, and copy and distribute such modifications or work under the terms of Section 1 above, provided that you also meet all of these conditions: a) The modified work must itself be a software library. b) You must cause the files modified to carry prominent notices stating that you changed the files and the date of any change. c) You must cause the whole of the work to be licensed at no charge to all third parties under the terms of this License. d) If a facility in the modified Library refers to a function or a table of data to be supplied by an application program that uses the facility, other than as an argument passed when the facility is invoked, then you must make a good faith effort to ensure that, in the event an application does not supply such function or table, the facility still operates, and performs whatever part of its purpose remains meaningful. (For example, a function in a library to compute square roots has a purpose that is entirely well-defined independent of the application. Therefore, Subsection 2d requires that any application-supplied function or table used by this function must be optional: if the application does not supply it, the square root function must still compute square roots.) These requirements apply to the modified work as a whole. If identifiable sections of that work are not derived from the Library, and can be reasonably considered independent and separate works in themselves, then this License, and its terms, do not apply to those sections when you distribute them as separate works. But when you distribute the same sections as part of a whole which is a work based on the Library, the distribution of the whole must be on the terms of this License, whose permissions for other licensees extend to the entire whole, and thus to each and every part regardless of who wrote it. Thus, it is not the intent of this section to claim rights or contest your rights to work written entirely by you; rather, the intent is to exercise the right to control the distribution of derivative or collective works based on the Library. In addition, mere aggregation of another work not based on the Library with the Library (or with a work based on the Library) on a volume of a storage or distribution medium does not bring the other work under the scope of this License. 3. You may opt to apply the terms of the ordinary GNU General Public License instead of this License to a given copy of the Library. To do this, you must alter all the notices that refer to this License, so that they refer to the ordinary GNU General Public License, version 2, instead of to this License. (If a newer version than version 2 of the ordinary GNU General Public License has appeared, then you can specify that version instead if you wish.) Do not make any other change in these notices. Once this change is made in a given copy, it is irreversible for that copy, so the ordinary GNU General Public License applies to all subsequent copies and derivative works made from that copy. This option is useful when you wish to copy part of the code of the Library into a program that is not a library. 4. You may copy and distribute the Library (or a portion or derivative of it, under Section 2) in object code or executable form under the terms of Sections 1 and 2 above provided that you accompany it with the complete corresponding machine-readable source code, which must be distributed under the terms of Sections 1 and 2 above on a medium customarily used for software interchange. If distribution of object code is made by offering access to copy from a designated place, then offering equivalent access to copy the source code from the same place satisfies the requirement to distribute the source code, even though third parties are not compelled to copy the source along with the object code. 5. A program that contains no derivative of any portion of the Library, but is designed to work with the Library by being compiled or linked with it, is called a "work that uses the Library". Such a work, in isolation, is not a derivative work of the Library, and therefore falls outside the scope of this License. However, linking a "work that uses the Library" with the Library creates an executable that is a derivative of the Library (because it contains portions of the Library), rather than a "work that uses the library". The executable is therefore covered by this License. Section 6 states terms for distribution of such executables. When a "work that uses the Library" uses material from a header file that is part of the Library, the object code for the work may be a derivative work of the Library even though the source code is not. Whether this is true is especially significant if the work can be linked without the Library, or if the work is itself a library. The threshold for this to be true is not precisely defined by law. If such an object file uses only numerical parameters, data structure layouts and accessors, and small macros and small inline functions (ten lines or less in length), then the use of the object file is unrestricted, regardless of whether it is legally a derivative work. (Executables containing this object code plus portions of the Library will still fall under Section 6.) Otherwise, if the work is a derivative of the Library, you may distribute the object code for the work under the terms of Section 6. Any executables containing that work also fall under Section 6, whether or not they are linked directly with the Library itself. 6. As an exception to the Sections above, you may also compile or link a "work that uses the Library" with the Library to produce a work containing portions of the Library, and distribute that work under terms of your choice, provided that the terms permit modification of the work for the customer's own use and reverse engineering for debugging such modifications. You must give prominent notice with each copy of the work that the Library is used in it and that the Library and its use are covered by this License. You must supply a copy of this License. If the work during execution displays copyright notices, you must include the copyright notice for the Library among them, as well as a reference directing the user to the copy of this License. Also, you must do one of these things: a) Accompany the work with the complete corresponding machine-readable source code for the Library including whatever changes were used in the work (which must be distributed under Sections 1 and 2 above); and, if the work is an executable linked with the Library, with the complete machine-readable "work that uses the Library", as object code and/or source code, so that the user can modify the Library and then relink to produce a modified executable containing the modified Library. (It is understood that the user who changes the contents of definitions files in the Library will not necessarily be able to recompile the application to use the modified definitions.) b) Accompany the work with a written offer, valid for at least three years, to give the same user the materials specified in Subsection 6a, above, for a charge no more than the cost of performing this distribution. c) If distribution of the work is made by offering access to copy from a designated place, offer equivalent access to copy the above specified materials from the same place. d) Verify that the user has already received a copy of these materials or that you have already sent this user a copy. For an executable, the required form of the "work that uses the Library" must include any data and utility programs needed for reproducing the executable from it. However, as a special exception, the source code distributed need not include anything that is normally distributed (in either source or binary form) with the major components (compiler, kernel, and so on) of the operating system on which the executable runs, unless that component itself accompanies the executable. It may happen that this requirement contradicts the license restrictions of other proprietary libraries that do not normally accompany the operating system. Such a contradiction means you cannot use both them and the Library together in an executable that you distribute. 7. You may place library facilities that are a work based on the Library side-by-side in a single library together with other library facilities not covered by this License, and distribute such a combined library, provided that the separate distribution of the work based on the Library and of the other library facilities is otherwise permitted, and provided that you do these two things: a) Accompany the combined library with a copy of the same work based on the Library, uncombined with any other library facilities. This must be distributed under the terms of the Sections above. b) Give prominent notice with the combined library of the fact that part of it is a work based on the Library, and explaining where to find the accompanying uncombined form of the same work. 8. You may not copy, modify, sublicense, link with, or distribute the Library except as expressly provided under this License. Any attempt otherwise to copy, modify, sublicense, link with, or distribute the Library is void, and will automatically terminate your rights under this License. However, parties who have received copies, or rights, from you under this License will not have their licenses terminated so long as such parties remain in full compliance. 9. You are not required to accept this License, since you have not signed it. However, nothing else grants you permission to modify or distribute the Library or its derivative works. These actions are prohibited by law if you do not accept this License. Therefore, by modifying or distributing the Library (or any work based on the Library), you indicate your acceptance of this License to do so, and all its terms and conditions for copying, distributing or modifying the Library or works based on it. 10. Each time you redistribute the Library (or any work based on the Library), the recipient automatically receives a license from the original licensor to copy, distribute, link with or modify the Library subject to these terms and conditions. You may not impose any further restrictions on the recipients' exercise of the rights granted herein. You are not responsible for enforcing compliance by third parties to this License. 11. If, as a consequence of a court judgment or allegation of patent infringement or for any other reason (not limited to patent issues), conditions are imposed on you (whether by court order, agreement or otherwise) that contradict the conditions of this License, they do not excuse you from the conditions of this License. If you cannot distribute so as to satisfy simultaneously your obligations under this License and any other pertinent obligations, then as a consequence you may not distribute the Library at all. For example, if a patent license would not permit royalty-free redistribution of the Library by all those who receive copies directly or indirectly through you, then the only way you could satisfy both it and this License would be to refrain entirely from distribution of the Library. If any portion of this section is held invalid or unenforceable under any particular circumstance, the balance of the section is intended to apply, and the section as a whole is intended to apply in other circumstances. It is not the purpose of this section to induce you to infringe any patents or other property right claims or to contest validity of any such claims; this section has the sole purpose of protecting the integrity of the free software distribution system which is implemented by public license practices. Many people have made generous contributions to the wide range of software distributed through that system in reliance on consistent application of that system; it is up to the author/donor to decide if he or she is willing to distribute software through any other system and a licensee cannot impose that choice. This section is intended to make thoroughly clear what is believed to be a consequence of the rest of this License. 12. If the distribution and/or use of the Library is restricted in certain countries either by patents or by copyrighted interfaces, the original copyright holder who places the Library under this License may add an explicit geographical distribution limitation excluding those countries, so that distribution is permitted only in or among countries not thus excluded. In such case, this License incorporates the limitation as if written in the body of this License. 13. The Free Software Foundation may publish revised and/or new versions of the Library General Public License from time to time. Such new versions will be similar in spirit to the present version, but may differ in detail to address new problems or concerns. Each version is given a distinguishing version number. If the Library specifies a version number of this License which applies to it and "any later version", you have the option of following the terms and conditions either of that version or of any later version published by the Free Software Foundation. If the Library does not specify a license version number, you may choose any version ever published by the Free Software Foundation. 14. If you wish to incorporate parts of the Library into other free programs whose distribution conditions are incompatible with these, write to the author to ask for permission. For software which is copyrighted by the Free Software Foundation, write to the Free Software Foundation; we sometimes make exceptions for this. Our decision will be guided by the two goals of preserving the free status of all derivatives of our free software and of promoting the sharing and reuse of software generally. NO WARRANTY 15. BECAUSE THE LIBRARY IS LICENSED FREE OF CHARGE, THERE IS NO WARRANTY FOR THE LIBRARY, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES PROVIDE THE LIBRARY "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE LIBRARY IS WITH YOU. SHOULD THE LIBRARY PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION. 16. IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MAY MODIFY AND/OR REDISTRIBUTE THE LIBRARY AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE USE OR INABILITY TO USE THE LIBRARY (INCLUDING BUT NOT LIMITED TO LOSS OF DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD PARTIES OR A FAILURE OF THE LIBRARY TO OPERATE WITH ANY OTHER SOFTWARE), EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. END OF TERMS AND CONDITIONS How to Apply These Terms to Your New Libraries If you develop a new library, and you want it to be of the greatest possible use to the public, we recommend making it free software that everyone can redistribute and change. You can do so by permitting redistribution under these terms (or, alternatively, under the terms of the ordinary General Public License). To apply these terms, attach the following notices to the library. It is safest to attach them to the start of each source file to most effectively convey the exclusion of warranty; and each file should have at least the "copyright" line and a pointer to where the full notice is found. Copyright (C) This library is free software; you can redistribute it and/or modify it under the terms of the GNU Library General Public License as published by the Free Software Foundation; either version 2 of the License, or (at your option) any later version. This library is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU Library General Public License for more details. You should have received a copy of the GNU Library General Public License along with this library; if not, write to the Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA Also add information on how to contact you by electronic and paper mail. You should also get your employer (if you work as a programmer) or your school, if any, to sign a "copyright disclaimer" for the library, if necessary. Here is a sample; alter the names: Yoyodyne, Inc., hereby disclaims all copyright interest in the library `Frob' (a library for tweaking knobs) written by James Random Hacker. , 1 April 1990 Ty Coon, President of Vice That's all there is to it! PKk0] HHlibuser_shadow.sonuȯPKk0]@xxlibuser_ldap.sonuȯPKk0]u&HH@libuser_files.sonuȯPK1]:##CAUTHORSnu[PK1]%"Dattributes.txtnu[PK1]췈88EREADMEnu[PK1]tY>~  jHTODOnu[PK1]b]]NNEWSnu[PK1]* Ĭrfc2307.txtnu[PK1][y'c'cNCOPYINGnu[PK