--- /dev/null
+# path to git projects (<project>.git)
+$projectroot = "/data/vcs/git";
+
+# directory to use for temp files
+$git_temp = "/tmp";
+
+# target of the home link on top of all pages
+#$home_link = $my_uri || "/";
+
+# html text to include at home page
+$home_text = "indextext.html";
+
+# file with project list; by default, simply scan the projectroot dir.
+$projects_list = $projectroot;
+
+# stylesheet to use
+$stylesheet = "/gitweb.css";
+
+# logo to use
+$logo = "/git-logo.png";
+
+# the 'favicon'
+$favicon = "/git-favicon.png";
+
+@git_base_url_list = (
+ "http://git.stderr.nl",
+ "ssh://git.stderr.nl"
+)
--- /dev/null
+[collections]
+/ = /data/vcs/hg
--- /dev/null
+www.drsnuggles.stderr.nl
--- /dev/null
+#!/usr/bin/python
+import os
+import re
+import pwd
+import grp
+import shutil
+import stat
+
+ROOT_DIR="/data/www"
+
+# SITES = [(sitename, application_list)]
+# application_list = [application_name, (application_name, command, ...)]
+# Here, sitename is the name of the site. This folder name should exist below ROOT_DIR and
+# is also used below SOCKET_DIR. The site name is also translated to a user and
+# group name by replacing dots by dashes and prepending USER_PREFIX and
+# GROUP_PREFIX.
+#
+# application_list specifies the applications to start for this site. These can
+# be generic (when only application_name is given), in which case the command
+# is looked up in APPLICATIONS using the application_name. For a site-specific
+# application, command is the command that should be run. It will be prefixed
+# with the site's root dir, if is not an absolute path.
+
+
+SITES=[
+ ('stderr.nl', ['php', ('trac', 'applications/trac/trac.fcgi')]),
+# ('stdin.nl', ['php']),
+ ('stdout.nl', ['php']),
+ ('ninniach.nl', ['php']),
+ ('evolution-events.nl', ['php']), #, ('xerxes', 'applications/xerxes/manage.py runfcgi'), ('wipi', 'applications/wipi/wipi.fcgi')]),
+# ('stdio.flexvps.nl', ['php']),
+# ('foresightsecurity.nl', ['php']),
+]
+
+# Generic applications that can be run for any site
+# Maps application_name to application_command. application_command will be
+# prefixed with the site's root dir, if it is not an absolute path.
+APPLICATIONS={"php": "/usr/bin/php-cgi"}
+
+# Kill these procs before starting new ones. Only processes of these names that
+# are run by the sites in SITES are killed. This is a bit hackish, we should
+# really be using pidfiles...
+KILL_PROCS=['php-cgi', 'manage.py']
+
+## ABSOLUTE path to the spawn-fcgi binary
+SPAWNFCGI="/usr/bin/spawn-fcgi"
+
+## Dir in which to create the UNIX sockets to listen on
+SOCKET_DIR="%s/var/fcgi" % (ROOT_DIR)
+
+## number of PHP children to spawn
+PHP_FCGI_CHILDREN=2
+
+## maximum number of requests a single PHP process can serve before it is restarted
+PHP_FCGI_MAX_REQUESTS=1000
+
+# The user to run as, will be prefixed to the sitename
+USER_PREFIX="httpd-"
+# The group to run as.
+SCRIPT_GROUP="httpd-users"
+# The group that should be able to use the sockets created
+HTTPD_GROUP="www-data"
+
+# Will be postfixed to the site's root and exported in the PHPRC variable.
+PHPRC_DIR="conf"
+
+#### END OF CONFIG ####
+
+for (site, apps) in SITES:
+ site_name = re.sub('\.', '-', site)
+
+ ## switch to the following user / group
+ user_id = "%s%s" % (USER_PREFIX, site_name)
+
+ # Find the site dir
+ site_dir = os.path.join(ROOT_DIR, site)
+ socket_dir = os.path.join(SOCKET_DIR, site_name)
+
+ # Pass the site dir to all fastcgi processes
+ os.environ['SITE_DIR'] = site_dir
+
+ if not site_dir:
+ raise Exception("Site dir does not exist: %s" % (site_dir))
+
+
+ # Kill existing processes first
+ for procname in KILL_PROCS:
+ os.system('killall --user %s %s' % (user_id, procname))
+
+ # Remove old sockets
+ if os.path.exists(socket_dir):
+ shutil.rmtree(socket_dir)
+
+ # Create dir for sockets. Make owning group root and set group write
+ # permissions, so the mask field in the acl will not block out anything.
+ os.makedirs(socket_dir)
+ os.chown(socket_dir, pwd.getpwnam(user_id)[2], grp.getgrnam(HTTPD_GROUP)[2])
+ #os.chmod(socket_dir, stat.S_IRWXU)
+
+ for app in apps:
+ # Unpack app tuple or lookup app command in APPLICATIONS
+ if isinstance(app, tuple):
+ if len(app) == 2:
+ (app_name, app_command) = app
+ else:
+ raise Exception("Wrong number of elements in site tuple: %s", app)
+ else:
+ app_name = app
+ app_command = APPLICATIONS[app_name]
+
+ # Prefix with site dir if not an absolute path
+ if not os.path.isabs(app_command):
+ app_command = os.path.join(site_dir, app_command)
+
+ # Create socket filename
+ socket = os.path.join(socket_dir, app_name)
+
+ # Build the command
+ # TODO: Wrap this in env to clear up the environment
+ spawnfcgi = '%s -s "%s" -u "%s" -g "%s"' % (SPAWNFCGI, socket, user_id, SCRIPT_GROUP)
+ fcgiapp = ' -- %s' % (app_command)
+
+ if app_name == 'php':
+ os.environ['PHP_FCGI_MAX_REQUESTS'] = str(PHP_FCGI_MAX_REQUESTS)
+ phprc = os.path.join(site_dir, PHPRC_DIR, 'php.ini')
+ if os.path.exists(phprc):
+ #os.environ['PHPRC'] = phprc
+ fcgiapp += ' -c %s' % (phprc)
+ spawnfcgi += ' -C %s' % (PHP_FCGI_CHILDREN)
+
+
+ print spawnfcgi + fcgiapp
+ os.system(spawnfcgi + fcgiapp)
+
+ # Ensure www-data can write to the socket :-S
+ # Spawn-fcgi explicitely chmods the socket after creation, very
+ # annoying
+ os.chmod(socket, stat.S_IRWXU | stat.S_IRWXG)
--- /dev/null
+# Debian lighttpd configuration file
+#
+
+# Chroot into our root-dir
+#server.chroot = "/data/www"
+
+#var.root-dir = ""
+var.root-dir = "/data/www"
+var.conf-dir = "/etc/lighttpd"
+var.fcgi-dir = var.root-dir + "/var/fcgi"
+
+## modules to load
+server.modules = (
+ "mod_auth",
+ "mod_access",
+ "mod_alias",
+ "mod_accesslog",
+ "mod_rewrite",
+ "mod_redirect",
+ "mod_evhost",
+ "mod_cgi",
+ "mod_fastcgi",
+ "mod_setenv",
+)
+
+# Set a default catch-all document root, which should never be used.
+server.document-root = var.root-dir + "/default/htdocs"
+
+## where to upload files to, purged daily.
+server.upload-dirs = ( "/var/cache/lighttpd/uploads" )
+
+## where to send error-messages to
+server.errorlog = var.root-dir + "/default/logs/error.log"
+
+## files to check for if .../ is requested
+index-file.names = ( "index.php", "index.html" )
+
+#### accesslog module
+accesslog.filename = var.root-dir + "/default/logs/access.log"
+
+## deny access the file-extensions
+#
+# ~ is for backupfiles from vi, emacs, joe, ...
+# .inc is often used for code includes which should in general not be part
+# of the document-root
+url.access-deny = ( "~", ".inc" )
+
+##
+# which extensions should not be handle via static-file transfer
+#
+# .php, .pl, .fcgi are most often handled by mod_fastcgi or mod_cgi
+static-file.exclude-extensions = ( ".php", ".pl", ".fcgi" )
+
+## Use ipv6 only if available.
+server.use-ipv6 = "disable"
+
+## to help the rc.scripts
+server.pid-file = "/var/run/lighttpd.pid"
+
+## virtual directory listings
+dir-listing.encoding = "utf-8"
+# Disable dir-listing by default
+server.dir-listing = "disable"
+
+# Don't run as root
+server.username = "www-data"
+server.groupname = "www-data"
+
+# Make mysqll frontend available in all domains
+alias.url += ("/mysql" => "/usr/share/phpmyadmin")
+
+#### external configuration files
+## mimetype mapping
+include_shell var.conf-dir + "/scripts/create-mime.assign.pl"
+
+## load vhosts
+include_shell var.conf-dir + "/scripts/include-vhosts.pl"
--- /dev/null
+#!/usr/bin/perl -w
+
+# This script is based on /usr/share/lighttpd/create-mime-assign.pl. This
+# script is changed to include a charset for text types.
+
+use strict;
+open MIMETYPES, "/etc/mime.types" or exit;
+print "mimetype.assign = (\n";
+my %extensions;
+while(<MIMETYPES>) {
+ chomp;
+ s/\#.*//;
+ next if /^\w*$/;
+ if(/^([a-z0-9\/+-.]+)\s+((?:[a-z0-9.+-]+[ ]?)+)$/) {
+ my $mime = $1; my $exts = $2;
+ # Append encoding for text formats
+ if ($mime =~ /^text\//) {
+ $mime .= "; charset=iso-8859-1";
+ }
+ foreach(split / /, $exts) {
+ # mime.types can have same extension for different
+ # mime types
+ next if $extensions{$_};
+ $extensions{$_} = 1;
+
+ print "\".$_\" => \"$mime\",\n";
+ }
+ }
+}
+print ")\n";
--- /dev/null
+#!/usr/bin/perl -wl
+
+# This script is based on /usr/share/lighttpd/include-conf-enabled.pl but
+# changed to read the vhosts directory instead of the conf-enabled directory.
+
+use strict;
+use File::Glob ':glob';
+
+my $confdir = "/etc/lighttpd/";
+my $enabled = "vhosts/*";
+
+chdir($confdir);
+my @files = bsd_glob($enabled);
+
+for my $file (@files)
+{
+ print "include \"$file\"";
+}
--- /dev/null
+$HTTP["host"] =~ "^(evolution-events.nl)$" {
+ url.redirect = (".*" => "http://www.%1/")
+}
+
+$HTTP["host"] =~ ".evolution-events.nl$" {
+ var.site-dir = var.root-dir + "/evolution-events.nl"
+ var.site-fcgi-dir = var.fcgi-dir + "/evolution-events-nl"
+
+ evhost.path-pattern = var.site-dir + "/htdocs/%3/"
+ accesslog.filename = var.site-dir + "/logs/access.log"
+
+ fastcgi.server = (
+ ".php" =>
+ ((
+ "socket" => var.site-fcgi-dir + "/php",
+ "broken-scriptfilename" => "enable",
+ )),
+ "/wipi" =>
+ ((
+ "socket" => var.site-fcgi-dir + "/wipi",
+ "check-local" => "disable",
+ "broken-scriptfilename" => "enable",
+ )),
+ )
+ alias.url = (
+ # Don't name this /wipistatic, since that will be caught by fastcgi above
+ "/staticwipi" => var.site-dir + "/applications/wipi/static/",
+ )
+
+ url.rewrite-once = (
+ "^/wipi/static/(.*)$" => "/staticwipi/$1",
+ "^(/.*)$" => "$1",
+ )
+
+ $HTTP["host"] =~ "^orga.evolution-events.nl$" {
+ auth.backend = "plain"
+ auth.backend.plain.userfile = var.site-dir + "/conf/simple.user"
+
+ auth.require = ( "/private" =>
+ (
+ "method" => "digest",
+ "realm" => "Evolution Events",
+ "require" => "user=admin"
+ )
+ )
+
+
+ url.rewrite-once = (
+ "^/forum/(.+)$" => "/forum/",
+ )
+ }
+
+ $HTTP["host"] =~ "^xerxes.evolution-events.nl$" {
+ fastcgi.server = (
+ "/blaa" =>
+ ((
+ "socket" => var.site-fcgi-dir + "/xerxes",
+ "check-local" => "disable",
+ )),
+ )
+
+ alias.url = (
+ "/media/" => "/home/matthijs/django/contrib/admin/media/",
+ "/static/" => var.site-dir + "/applications/xerxes/static/",
+ )
+
+ url.rewrite-once = (
+ "^(/media.*)$" => "$1",
+ "^(/static.*)$" => "$1",
+ "^/favicon\.ico$" => "/media/favicon.ico",
+ "^(/.*)$" => "/blaa$1",
+ )
+ }
+}
--- /dev/null
+$HTTP["host"] =~ ".foresightsecurity.nl$" {
+ var.site-dir = var.root-dir + "/foresightsecurity.nl"
+ var.site-fcgi-dir = var.fcgi-dir + "/evolution-events-nl"
+
+ evhost.path-pattern = var.site-dir + "/htdocs/%3/"
+ accesslog.filename = var.site-dir + "/logs/access.log"
+
+ fastcgi.server = (
+ ".php" =>
+ ((
+ "socket" => var.site-fcgi-dir + "/php",
+ "broken-scriptfilename" => "enable",
+ ))
+ )
+
+ cgi.assign = ( "cgi" => "" )
+}
--- /dev/null
+$HTTP["host"] =~ ".ninniach.nl$" {
+ var.site-dir = var.root-dir + "/ninniach.nl"
+ var.site-fcgi-dir = var.fcgi-dir + "/ninniach-nl"
+
+ evhost.path-pattern = var.site-dir + "/htdocs/%3/"
+ accesslog.filename = var.site-dir + "/logs/access.log"
+
+ fastcgi.server = (
+ ".php" =>
+ ((
+ "socket" => var.site-fcgi-dir + "/php",
+ "broken-scriptfilename" => "enable",
+ ))
+ )
+
+ $HTTP["host"] == "weblog.ninniach.nl" {
+ $HTTP["url"] !~ "^/images" {
+ cgi.assign += ( "blosxom.cgi" => "/usr/local/bin/aclperl" )
+ alias.url += ( "" => var.site-dir + "/applications/blosxom/blosxom.cgi" )
+ setenv.add-environment += (
+ "BLOSXOM_CONFIG_FILE" => var.site-dir + "/conf/blosxom.conf",
+ "BLOSXOM_DATA_BASE" => var.site-dir + "/data/blosxom",
+ "BLOSXOM_CODE_BASE" => var.site-dir + "/applications/blosxom",
+ "BLOSXOM_HTDOCS_URL" => "",
+ )
+ }
+ }
+}
--- /dev/null
+$HTTP["host"] =~ ".stderr.nl$" {
+ var.site-dir = var.root-dir + "/stderr.nl"
+ var.site-fcgi-dir = var.fcgi-dir + "/stderr-nl"
+
+ evhost.path-pattern = var.site-dir + "/htdocs/%3/"
+ accesslog.filename = var.site-dir + "/logs/access.log"
+
+ fastcgi.server = (
+ ".php" =>
+ ((
+ "socket" => var.site-fcgi-dir + "/php",
+ "broken-scriptfilename" => "enable",
+ ))
+ )
+
+ $HTTP["host"] =~ "git.stderr.nl$" {
+ cgi.assign += ( "gitweb.cgi" => "" )
+ # Put this alias in a url conditional, so urls like /gitweb.css won't get alias'd
+ $HTTP["url"] =~ "^/gitweb(/.*)?$" {
+ alias.url += ( "/gitweb" => "/usr/lib/cgi-bin/gitweb.cgi" )
+ }
+ $HTTP["url"] =~ ".git/" {
+ alias.url += ( "/" => "/data/vcs/git/" )
+ }
+ }
+
+ $HTTP["host"] =~ "blues.stderr.nl$" {
+ auth.backend = "htpasswd"
+ auth.backend.htpasswd.userfile = var.site-dir + "/conf/pandora2009.user"
+
+ auth.require = (
+ "/" => (
+ "method" => "basic",
+ "realm" => "Blues Brothers",
+ "require" => "valid-user"
+ )
+ )
+ # Only publish the pandora trac repos here
+ url.redirect += ("^/trac/?$" => "/trac/pandora")
+ fastcgi.server += (
+ "/trac" =>
+ ((
+ "socket" => var.site-fcgi-dir + "/trac",
+ "check-local" => "disable",
+ ))
+ )
+ }
+
+ $HTTP["host"] =~ "^drsnuggles.stderr.nl$" {
+ alias.url += ("/ldap" => "/usr/share/phpldapadmin-patched/htdocs")
+ }
+
+ $HTTP["host"] =~ "^www.stderr.nl$" {
+ $HTTP["url"] =~ "^/blosxom" {
+ cgi.assign += ( "blosxom.cgi" => "/usr/local/bin/aclperl" )
+ alias.url += ( "/blosxom" => var.site-dir + "/applications/blosxom/blosxom.cgi" )
+ setenv.add-environment += (
+ "BLOSXOM_CONFIG_FILE" => var.site-dir + "/conf/blosxom.conf",
+ "BLOSXOM_DATA_BASE" => var.site-dir + "/data/blosxom",
+ "BLOSXOM_CODE_BASE" => var.site-dir + "/applications/blosxom",
+ "BLOSXOM_HTDOCS_URL" => "/blog/",
+ )
+ }
+ # Disabled for now, since the only working trac is the pandora trac
+ #fastcgi.server += (
+ # "/trac" =>
+ # ((
+ # "socket" => var.site-fcgi-dir + "/trac",
+ # "check-local" => "disable",
+ # ))
+ #)
+ }
+}
--- /dev/null
+$HTTP["host"] =~ ".stdin.nl$" {
+ var.site-dir = var.root-dir + "/stdin.nl"
+ var.site-fcgi-dir = var.fcgi-dir + "/stdin-nl"
+
+ evhost.path-pattern = var.site-dir + "/htdocs/%3/"
+ accesslog.filename = var.site-dir + "/logs/access.log"
+
+ fastcgi.server = ( ".php" =>
+ ((
+ "socket" => var.site-fcgi-dir + "/php",
+ "broken-scriptfilename" => "enable",
+ ))
+ )
+}
--- /dev/null
+$HTTP["host"] =~ "stdio.flexvps.nl$" {
+ var.site-dir = var.root-dir + "/stdio.flexvps.nl"
+ var.site-fcgi-dir = var.fcgi-dir + "/stdio-flexvps-nl"
+
+ server.document-root = var.site-dir + "/htdocs"
+ accesslog.filename = var.site-dir + "/logs/access.log"
+
+ fastcgi.server = (
+ ".php" =>
+ ((
+ "socket" => var.site-fcgi-dir + "/php",
+ "broken-scriptfilename" => "enable",
+ ))
+ )
+}
--- /dev/null
+$HTTP["host"] =~ ".stdout.nl$" {
+ var.site-dir = var.root-dir + "/stdout.nl"
+ var.site-fcgi-dir = var.fcgi-dir + "/stdout-nl"
+
+ evhost.path-pattern = var.site-dir + "/htdocs/%3/"
+ accesslog.filename = var.site-dir + "/logs/access.log"
+
+ fastcgi.server = ( ".php" =>
+ ((
+ "socket" => var.site-fcgi-dir + "/php",
+ ))
+ )
+}
--- /dev/null
+www.drsnuggles.stderr.nl
--- /dev/null
+# This file contains local changes, so we can leave php5.ini to the Debian
+# default. It is not directly used by PHP, but the update-php.ini script
+# ensures it is put into the php.ini for each different domain.
+
+# Put errors in the logfile
+log_errors = On
+
+# Don't display errors to the client
+display_errors = Off
+
+# vim: set filetype=dosini:
--- /dev/null
+# Define /phpldapadmin alias, this is the default
+<IfModule mod_alias.c>
+ Alias /phpldapadmin /usr/share/phpldapadmin/htdocs
+</IfModule>
+
+# You can also use phpLDAPadmin as a VirtualHost
+# <VirtualHost *:*>
+# ServerName ldap.example.com
+# ServerAdmin root@example.com
+# DocumentRoot /usr/share/phpldapadmin
+# ErrorLog logs/ldap.example.com-error.log
+# CustomLog logs/ldap.example.com-access.log common
+# </VirtualHost>
+
+<Directory /usr/share/phpldapadmin/htdocs/>
+
+ DirectoryIndex index.php
+ Options +FollowSymLinks
+ AllowOverride None
+
+ Order allow,deny
+ Allow from all
+
+ <IfModule mod_mime.c>
+
+ <IfModule mod_php5.c>
+ AddType application/x-httpd-php .php
+
+ php_flag magic_quotes_gpc Off
+ php_flag track_vars On
+ php_flag register_globals On
+ php_value include_path .
+ </IfModule>
+
+ <IfModule !mod_php5.c>
+ <IfModule mod_actions.c>
+ <IfModule mod_cgi.c>
+ AddType application/x-httpd-php .php
+ Action application/x-httpd-php /cgi-bin/php5
+ </IfModule>
+ <IfModule mod_cgid.c>
+ AddType application/x-httpd-php .php
+ Action application/x-httpd-php /cgi-bin/php5
+ </IfModule>
+ </IfModule>
+ </IfModule>
+
+ </IfModule>
+
+</Directory>
+
--- /dev/null
+<?php
+/** NOTE **
+ ** Make sure that <?php is the FIRST line of this file!
+ ** IE: There should NOT be any blank lines or spaces BEFORE <?php
+ **/
+
+/**
+ * The phpLDAPadmin config file
+ *
+ * This is where you can customise some of the phpLDAPadmin defaults
+ * that are defined in config_default.php.
+ *
+ * To override a default, use the $config->custom variable to do so.
+ * For example, the default for defining the language in config_default.php
+ *
+ * $this->default->appearance['lang'] = array(
+ * 'desc'=>'Language',
+ * 'default'=>'auto');
+ *
+ * to override this, use $config->custom->appearance['lang'] = 'en';
+ *
+ * This file is also used to configure your LDAP server connections.
+ *
+ * You must specify at least one LDAP server there. You may add
+ * as many as you like. You can also specify your language, and
+ * many other options.
+ *
+ * NOTE: Commented out values in this file prefixed by //, represent the
+ * defaults that have been defined in config_default.php.
+ * Commented out values prefixed by #, dont reflect their default value, you can
+ * check config_default.php if you want to see what the default is.
+ *
+ * DONT change config_default.php, you changes will be lost by the next release
+ * of PLA. Instead change this file - as it will NOT be replaced by a new
+ * version of phpLDAPadmin.
+ */
+
+/*********************************************/
+/* Useful important configuration overrides */
+/*********************************************/
+
+/* If you are asked to put pla in debug mode, this is how you do it: */
+# $config->custom->debug['level'] = 255;
+# $config->custom->debug['syslog'] = true;
+# $config->custom->debug['file'] = '/tmp/pla_debug.log';
+
+/* phpLDAPadmin can encrypt the content of sensitive cookies if you set this
+ to a big random string. */
+// $config->custom->session['blowfish'] = null;
+
+/* The language setting. If you set this to 'auto', phpLDAPadmin will attempt
+ to determine your language automatically. Otherwise, available lanaguages
+ are: 'ct', 'de', 'en', 'es', 'fr', 'it', 'nl', and 'ru'
+ Localization is not complete yet, but most strings have been translated.
+ Please help by writing language files. See lang/en.php for an example. */
+// $config->custom->appearance['language'] = 'auto';
+
+/* The temporary storage directory where we will put jpegPhoto data
+ This directory must be readable and writable by your web server. */
+// $config->custom->jpeg['tmpdir'] = "/tmp"; // Example for Unix systems
+# $config->custom->jpeg['tmpdir'] = "c:\\temp"; // Example for Windows systems
+
+/* Set this to (bool)true if you do NOT want a random salt used when
+ calling crypt(). Instead, use the first two letters of the user's
+ password. This is insecure but unfortunately needed for some older
+ environments. */
+# $config->custom->password['no_random_crypt_salt'] = true;
+
+/* PHP script timeout control. If php runs longer than this many seconds then
+ PHP will stop with an Maximum Execution time error. Increase this value from
+ the default if queries to your LDAP server are slow. The default is either
+ 30 seconds or the setting of max_exection_time if this is null. */
+// $config->custom->session['timelimit'] = 30;
+
+/*********************************************/
+/* Commands */
+/*********************************************/
+
+/* Command availability ; if you don't authorize a command the command
+ links will not be shown and the command action will not be permitted.
+ For better security, set also ACL in your ldap directory. */
+
+/*
+$config->custom->commands['all'] = array(
+ 'home' => true,
+ 'external_links' => array('feature' => true,
+ 'bug' => true,
+ 'donation' => true,
+ 'help' => true,
+ 'credits' => true),
+ 'purge' => true,
+ 'schema' => true,
+ 'import' => true,
+ 'export' => true,
+ 'logout' => true,
+ 'search' => array('simple_search' => true,
+ 'predefined_search' => true,
+ 'advanced_search' => true),
+ 'server_refresh' => true,
+ 'server_info' => true,
+ 'entry_refresh' => true,
+ 'entry_move' => true,
+ 'entry_internal_attributes_show' => true,
+ 'entry_delete' => array('simple_delete' => true,
+ 'mass_delete' => false),
+ 'entry_rename' => true,
+ 'entry_compare' => true,
+ 'entry_create' => true,
+ 'attribute_add' => true,
+ 'attribute_add_value' => true,
+ 'attribute_delete' => true,
+ 'attribute_delete_value' => true);
+*/
+
+/*********************************************/
+/* Appearance */
+/*********************************************/
+
+// Use the displayName in the tree view, when available.
+$config->custom->appearance['tree_display_formats'] = array("%displayName", "%rdnValue");
+
+/* If you want to choose the appearance of the tree, specify a class name which
+ inherits from the Tree class. */
+// $config->custom->appearance['tree'] = "AJAXTree";
+# $config->custom->appearance['tree'] = "HTMLTree";
+
+/* If you want to customise the entry view/edition, specify your factory name which
+ inherits from the EntryFactory class.
+ The 'DefaultEntryFactory' draws all the attributes of an entry according this
+ config file and the ldap schema definition ; the 'TemplateEntryFactory' draws
+ an entry according to the template whose regexp matches with the dn. */
+# $config->custom->appearance['entry_factory'] = "DefaultEntryFactory";
+// $config->custom->appearance['entry_factory'] = "TemplateEntryFactory";
+
+/* If you want to customise an attribute view/edition, specify your factory name which
+ inherits from the AttributeFactory class.
+ An AttributeFactory defines which class to use to represent a given attribute */
+// $config->custom->appearance['attribute_factory'] = "AttributeFactory";
+
+/* Configure what objects are shown in left hand tree */
+// $config->custom->appearance['tree_filter'] = '(objectclass=*)';
+
+/* The height and width of the tree. If these values are not set, then
+ no tree scroll bars are provided.
+// $config->custom->appearance['tree_height'] = null;
+# $config->custom->appearance['tree_height'] = 600;
+// $config->custom->appearance['tree_width'] = null;
+# $config->custom->appearance['tree_width'] = 250;
+
+/*********************************************/
+/* Define your LDAP servers in this section */
+/*********************************************/
+
+$i=0;
+$ldapservers = new LDAPServers;
+
+/* A convenient name that will appear in the tree viewer and throughout
+ phpLDAPadmin to identify this LDAP server to users. */
+$ldapservers->SetValue($i,'server','name','My LDAP Server');
+
+/* Examples:
+ 'ldap.example.com',
+ 'ldaps://ldap.example.com/',
+ 'ldapi://%2fusr%local%2fvar%2frun%2fldapi'
+ (Unix socket at /usr/local/var/run/ldap) */
+$ldapservers->SetValue($i,'server','host','ldap.drsnuggles.stderr.nl');
+
+/* The port your LDAP server listens on (no quotes). 389 is standard. */
+// $ldapservers->SetValue($i,'server','port','389');
+
+/* Array of base DNs of your LDAP server. Leave this blank to have phpLDAPadmin
+ auto-detect it for you. */
+$ldapservers->SetValue($i,'server','base',array('dc=drsnuggles,dc=stderr,dc=nl'));
+
+/* Four options for auth_type:
+ 1. 'cookie': you will login via a web form, and a client-side cookie will
+ store your login dn and password.
+ 2. 'session': same as cookie but your login dn and password are stored on the
+ web server in a persistent session variable.
+ 3. 'http': same as session but your login dn and password are retrieved via
+ HTTP authentication.
+ 4. 'config': specify your login dn and password here in this config file. No
+ login will be required to use phpLDAPadmin for this server.
+
+ Choose wisely to protect your authentication information appropriately for
+ your situation. If you choose 'cookie', your cookie contents will be
+ encrypted using blowfish and the secret your specify above as
+ session['blowfish']. */
+$ldapservers->SetValue($i,'server','auth_type','session');
+
+/* The DN of the user for phpLDAPadmin to bind with. For anonymous binds or
+ 'cookie' or 'session' auth_types, LEAVE THE LOGIN_DN AND LOGIN_PASS BLANK. If
+ you specify a login_attr in conjunction with a cookie or session auth_type,
+ then you can also specify the login_dn/login_pass here for searching the
+ directory for users (ie, if your LDAP server does not allow anonymous binds. */
+// $ldapservers->SetValue($i,'login','dn','');
+ $ldapservers->SetValue($i,'login','dn','cn=admin,dc=drsnuggles,dc=stderr,dc=nl');
+
+/* Your LDAP password. If you specified an empty login_dn above, this MUST also
+ be blank. */
+// $ldapservers->SetValue($i,'login','pass','');
+ $ldapservers->SetValue($i,'login','pass','');
+
+// Make sure that uniqueNumber doesn't start counting at 1000. The uidNumbers
+// will still work correctly, since they start counting at whatever minimal
+// value is in the directory already.
+ $ldapservers->SetValue($i,'auto_number','min',0);
+
+/* Use TLS (Transport Layer Security) to connect to the LDAP server. */
+// $ldapservers->SetValue($i,'server','tls',false);
+
+/************************************
+ * SASL Authentication *
+ ************************************/
+
+/* Enable SASL authentication LDAP SASL authentication requires PHP 5.x
+ configured with --with-ldap-sasl=DIR. If this option is disabled (ie, set to
+ false), then all other sasl options are ignored. */
+// $ldapservers->SetValue($i,'server','sasl_auth',false);
+
+/* SASL auth mechanism */
+// $ldapservers->SetValue($i,'server','sasl_mech','PLAIN');
+
+/* SASL authentication realm name */
+// $ldapservers->SetValue($i,'server','sasl_realm','');
+# $ldapservers->SetValue($i,'server','sasl_realm',"example.com");
+
+/* SASL authorization ID name
+ If this option is undefined, authorization id will be computed from bind DN,
+ using sasl_authz_id_regex and sasl_authz_id_replacement. */
+// $ldapservers->SetValue($i,'server','sasl_authz_id', null);
+
+/* SASL authorization id regex and replacement
+ When sasl_authz_id property is not set (default), phpLDAPAdmin will try to
+ figure out authorization id by itself from bind distinguished name (DN).
+
+ This procedure is done by calling preg_replace() php function in the
+ following way:
+
+ $authz_id = preg_replace($sasl_authz_id_regex,$sasl_authz_id_replacement,
+ $bind_dn);
+
+ For info about pcre regexes, see:
+ - pcre(3), perlre(3)
+ - http://www.php.net/preg_replace */
+// $ldapservers->SetValue($i,'server','sasl_authz_id_regex',null);
+// $ldapservers->SetValue($i,'server','sasl_authz_id_replacement',null);
+# $ldapservers->SetValue($i,'server','sasl_authz_id_regex','/^uid=([^,]+)(.+)/i');
+# $ldapservers->SetValue($i,'server','sasl_authz_id_replacement','$1');
+
+/* SASL auth security props.
+ See http://beepcore-tcl.sourceforge.net/tclsasl.html#anchor5 for explanation.
+*/
+// $ldapservers->SetValue($i,'server','sasl_props',null);
+
+/* If the link between your web server and this LDAP server is slow, it is
+ recommended that you set 'low_bandwidth' to true. This will enable
+ phpLDAPadmin to forego some "fancy" features to conserve bandwidth. */
+// $ldapservers->SetValue($i,'server','low_bandwidth',false);
+
+/* Default password hashing algorithm. One of md5, ssha, sha, md5crpyt, smd5,
+ blowfish, crypt or leave blank for now default algorithm. */
+// $ldapservers->SetValue($i,'appearance','password_hash','md5');
+
+/* If you specified 'cookie' or 'session' as the auth_type above, you can
+ optionally specify here an attribute to use when logging in. If you enter
+ 'uid' and login as 'dsmith', phpLDAPadmin will search for (uid=dsmith)
+ and log in as that user.
+ Leave blank or specify 'dn' to use full DN for logging in. Note also that if
+ your LDAP server requires you to login to perform searches, you can enter the
+ DN to use when searching in 'login_dn' and 'login_pass' above. You may also
+ specify 'string', in which case you can provide a string to use for logging
+ users in. See 'login_string' directly below. */
+// $ldapservers->SetValue($i,'login','attr','dn');
+
+/* If you specified something different from 'dn', for example 'uid', as the
+ login_attr above, you can optionally specify here to fall back to
+ authentication with dn.
+ This is useful, when users should be able to log in with their uid, but
+ the ldap administrator wants to log in with his root-dn, that does not
+ necessarily have the uid attribute. */
+// $ldapservers->SetValue($i,'login','fallback_dn',false);
+
+/* If you specified 'cookie' or 'session' as the auth_type above, and you
+ specified 'string' for 'login_attr' above, you must provide a string here for
+ logging users in. If, for example, I have a lot of user entries with DNs like
+ "uid=dsmith,ou=People,dc=example,dc=com", then I can specify a string
+ "uid=<username>,ou=People,dc=example,dc=com" and my users can login with
+ their user names alone, ie: "dsmith" in this case. */
+# $ldapservers->SetValue($i,'login','string','uid=<username>,ou=People,dc=example,dc=com');
+
+/* If 'login_attr' is used above such that phpLDAPadmin will search for your DN
+ at login, you may restrict the search to a specific objectClass. EG, set this
+ to 'posixAccount' or 'inetOrgPerson', depending upon your setup. */
+// $ldapservers->SetValue($i,'login','class',null);
+
+/* Specify true If you want phpLDAPadmin to not display or permit any
+ modification to the LDAP server. */
+// $ldapservers->SetValue($i,'server','read_only',false);
+
+/* Specify false if you do not want phpLDAPadmin to draw the 'Create new' links
+ in the tree viewer. */
+// $ldapservers->SetValue($i,'appearance','show_create',true);
+
+/* This feature allows phpLDAPadmin to automatically determine the next
+ available uidNumber for a new entry. */
+// $ldapservers->SetValue($i,'auto_number','enable',true);
+
+/* The mechanism to use when finding the next available uidNumber. Two possible
+ values: 'uidpool' or 'search'.
+ The 'uidpool' mechanism uses an existing uidPool entry in your LDAP server to
+ blindly lookup the next available uidNumber. The 'search' mechanism searches
+ for entries with a uidNumber value and finds the first available uidNumber
+ (slower). */
+// $ldapservers->SetValue($i,'auto_number','mechanism','search');
+
+/* The DN of the search base when the 'search' mechanism is used above. */
+# $ldapservers->SetValue($i,'auto_number','search_base','ou=People,dc=example,dc=com');
+
+/* The minimum number to use when searching for the next available UID number
+ (only when 'search' is used for auto_uid_number_mechanism' */
+// $ldapservers->SetValue($i,'auto_number','min','1000');
+
+/* The DN of the uidPool entry when 'uidpool' mechanism is used above. */
+# $servers[$i]['auto_uid_number_uid_pool_dn'] = 'cn=uidPool,dc=example,dc=com';
+
+/* If you set this, then phpldapadmin will bind to LDAP with this user ID when
+ searching for the uidnumber. The idea is, this user id would have full
+ (readonly) access to uidnumber in your ldap directory (the logged in user
+ may not), so that you can be guaranteed to get a unique uidnumber for your
+ directory. */
+// $ldapservers->SetValue($i,'auto_number','dn',null);
+
+/* The password for the dn above. */
+// $ldapservers->SetValue($i,'auto_number','pass',null);
+
+/* Enable anonymous bind login. */
+// $ldapservers->SetValue($i,'login','anon_bind',true);
+
+/* Use customized page with prefix when available. */
+# $ldapservers->SetValue($i,'custom','pages_prefix','custom_');
+
+/* If you set this, then phpldapadmin will bind to LDAP with this user when
+ testing for unique attributes (as set in unique_attrs array). If you want to
+ enforce unique attributes, than this id should have full (readonly) access
+ to the attributes in question (the logged in user may not have enough access)
+*/
+// $ldapservers->SetValue($i,'unique_attrs','dn',null);
+
+/* The password for the dn above */
+// $ldapservers->SetValue($i,'unique_attrs','pass',null);
+
+/* If you set this, then only these DNs are allowed to log in. This array can
+ contain individual users, groups or ldap search filter(s). Keep in mind that
+ the user has not authenticated yet, so this will be an anonymous search to
+ the LDAP server, so make your ACLs allow these searches to return results! */
+# $ldapservers->SetValue($i,'login','allowed_dns',array(
+# 'uid=stran,ou=People,dc=example,dc=com',
+# '(&(gidNumber=811)(objectClass=groupOfNames))',
+# '(|(uidNumber=200)(uidNumber=201))',
+# 'cn=callcenter,ou=Group,dc=example,dc=com'));
+
+/* Set this if you dont want this LDAP server to show in the tree */
+// $ldapservers->SetValue($i,'appearance','visible',true);
+
+/* This is the time out value in minutes for the server. After as many minutes
+ of inactivity you will be automatically logged out. If not set, the default
+ value will be ( session_cache_expire()-1 ) */
+# $ldapservers->SetValue($i,'login','timeout',30);
+
+/* Set this if you want phpldapadmin to perform rename operation on entry which
+ has children. Certain servers are known to allow it, certain are not */
+// $ldapservers->SetValue($i,'server','branch_rename',false);
+
+/**************************************************************************
+ * If you want to configure additional LDAP servers, do so below. *
+ * Remove the commented lines and use this section as a template for all *
+ * your other LDAP servers. *
+ **************************************************************************/
+
+/*
+$i++;
+$ldapservers->SetValue($i,'server','name','LDAP Server');
+$ldapservers->SetValue($i,'server','host','127.0.0.1');
+$ldapservers->SetValue($i,'server','port','389');
+$ldapservers->SetValue($i,'server','base',array(''));
+$ldapservers->SetValue($i,'server','auth_type','cookie');
+$ldapservers->SetValue($i,'login','dn','');
+$ldapservers->SetValue($i,'login','pass','');
+$ldapservers->SetValue($i,'server','tls',false);
+$ldapservers->SetValue($i,'server','low_bandwidth',false);
+$ldapservers->SetValue($i,'appearance','password_hash','md5');
+$ldapservers->SetValue($i,'login','attr','dn');
+$ldapservers->SetValue($i,'login','string',null);
+$ldapservers->SetValue($i,'login','class',null);
+$ldapservers->SetValue($i,'server','read_only',false);
+$ldapservers->SetValue($i,'appearance','show_create',true);
+$ldapservers->SetValue($i,'auto_number','enable',true);
+$ldapservers->SetValue($i,'auto_number','mechanism','search');
+$ldapservers->SetValue($i,'auto_number','search_base',null);
+$ldapservers->SetValue($i,'auto_number','min','1000');
+$ldapservers->SetValue($i,'auto_number','dn',null);
+$ldapservers->SetValue($i,'auto_number','pass',null);
+$ldapservers->SetValue($i,'login','anon_bind',true);
+$ldapservers->SetValue($i,'custom','pages_prefix','custom_');
+$ldapservers->SetValue($i,'unique_attrs','dn',null);
+$ldapservers->SetValue($i,'unique_attrs','pass',null);
+
+# SASL auth
+$ldapservers->SetValue($i,'server','sasl_auth',true);
+$ldapservers->SetValue($i,'server','sasl_mech','PLAIN');
+$ldapservers->SetValue($i,'server','sasl_realm','EXAMPLE.COM');
+$ldapservers->SetValue($i,'server','sasl_authz_id',null);
+$ldapservers->SetValue($i,'server','sasl_authz_id_regex','/^uid=([^,]+)(.+)/i');
+$ldapservers->SetValue($i,'server','sasl_authz_id_replacement','$1');
+$ldapservers->SetValue($i,'server','sasl_props',null);
+*/
+
+/*********************************************/
+/* User-friendly attribute translation */
+/*********************************************/
+
+/* Use this array to map attribute names to user friendly names. For example, if
+ you don't want to see "facsimileTelephoneNumber" but rather "Fax". */
+$friendly_attrs = array();
+
+$friendly_attrs['facsimileTelephoneNumber'] = 'Fax';
+$friendly_attrs['telephoneNumber'] = 'Phone';
+$friendly_attrs['uid'] = 'User Name';
+
+/*********************************************/
+/* Support for attrs display order */
+/*********************************************/
+
+/* Use this array if you want to have your attributes displayed in a specific
+ order. You can use default attribute names or their fridenly names.
+ For example, "sn" will be displayed right after "givenName". All the other
+ attributes that are not specified in this array will be displayed after in
+ alphabetical order. */
+# $attrs_display_order = array(
+# 'givenName',
+# 'sn',
+# 'cn',
+# 'displayName',
+# 'uid',
+# 'uidNumber',
+# 'gidNumber',
+# 'homeDirectory',
+# 'mail',
+# 'userPassword'
+# );
+
+/*********************************************/
+/* Hidden attributes */
+/*********************************************/
+
+/* You may want to hide certain attributes from being displayed in the editor
+ screen. Do this by adding the desired attributes to this list (and uncomment
+ it). This only affects the editor screen. Attributes will still be visible in
+ the schema browser and elsewhere. An example is provided below:
+ NOTE: The user must be able to read the hidden_except_dn entry to be
+ excluded. */
+# $hidden_attrs = array( 'jpegPhoto', 'objectClass' );
+# $hidden_except_dn = "cn=PLA UnHide,ou=Groups,c=AU";
+
+/* Hidden attributes in read-only mode. If undefined, it will be equal to
+ $hidden_attrs. */
+# $hidden_attrs_ro = array(
+# 'objectClass','shadowWarning', 'shadowLastChange', 'shadowMax',
+# 'shadowFlag', 'shadowInactive', 'shadowMin', 'shadowExpire');
+
+/** **/
+/** Read-only attributes **/
+/** **/
+
+/* You may want to phpLDAPadmin to display certain attributes as read only,
+ meaning that users will not be presented a form for modifying those
+ attributes, and they will not be allowed to be modified on the "back-end"
+ either. You may configure this list here:
+ NOTE: The user must be able to read the read_only_except_dn entry to be
+ excluded. */
+# $read_only_attrs = array( 'objectClass' );
+# $read_only_except_dn = "cn=PLA ReadWrite,ou=Groups,c=AU";
+
+/* An example of how to specify multiple read-only attributes: */
+# $read_only_attrs = array( 'jpegPhoto', 'objectClass', 'someAttribute' );
+
+/*********************************************/
+/* Unique attributes */
+/*********************************************/
+
+/* You may want phpLDAPadmin to enforce some attributes to have unique values
+ (ie: not belong to other entries in your tree. This (together with
+ unique_attrs['dn'] and unique_attrs['pass'] option will not let updates to
+ occur with other attributes have the same value.
+ NOTE: Currently the unique_attrs is NOT enforced when copying a dn. (Need to
+ present a user with the option of changing the unique attributes. */
+# $unique_attrs = array('uid','uidNumber','mail');
+
+/*********************************************/
+/* Group attributes */
+/*********************************************/
+
+/* Add "modify group members" link to the attribute. */
+// $config->custom->modify_member['groupattr'] = array('member','uniqueMember','memberUid')
+
+/* Configure filter for member search. This only applies to "modify group members" feature */
+// $config->custom->modify_member['filter'] = '(objectclass=Person)';
+
+/* Attribute that is added to the group member attribute. */
+// $config->custom->modify_member['attr'] = 'dn';
+
+/*********************************************/
+/* Predefined Queries (canned views) */
+/*********************************************/
+
+/* To make searching easier, you may setup predefined queries below: */
+$q=0;
+$queries = array();
+
+/* The name that will appear in the simple search form */
+$queries[$q]['name'] = 'User List';
+
+/* The base to search on */
+$queries[$q]['base'] = 'dc=example,dc=com';
+
+/* The search scope (sub, base, one) */
+$queries[$q]['scope'] = 'sub';
+
+/* The LDAP filter to use */
+$queries[$q]['filter'] = '(&(objectClass=posixAccount)(uid=*))';
+
+/* The attributes to return */
+$queries[$q]['attributes'] = 'cn, uid, homeDirectory, telephonenumber, jpegphoto';
+
+/* If you want to configure more pre-defined queries, copy and paste the above (including the "$q++;") */
+$q++;
+$queries[$q]['name'] = 'Samba Users';
+$queries[$q]['base'] = 'dc=example,dc=com';
+$queries[$q]['scope'] = 'sub';
+$queries[$q]['filter'] = '(&(|(objectClass=sambaAccount)(objectClass=sambaSamAccount))(objectClass=posixAccount)(!(uid=*$)))';
+$queries[$q]['attributes'] = 'uid, smbHome, uidNumber';
+
+$q++;
+$queries[$q]['name'] = 'Samba Computers';
+$queries[$q]['base'] = 'dc=example,dc=com';
+$queries[$q]['scope'] = 'sub';
+$queries[$q]['filter'] = '(&(objectClass=sambaAccount)(uid=*$))';
+$queries[$q]['attributes'] = 'uid, homeDirectory';
+?>
--- /dev/null
+<?xml version="1.0" encoding="UTF-8" standalone="no"?>
+<!DOCTYPE template SYSTEM "template.dtd">
+<template>
+<title>Posix Group - SUSE</title>
+<!-- <regexp>^ou=.*,</regexp> -->
+<icon>images/ou.png</icon>
+<description>Posix Group - SUSE</description>
+<askcontainer>1</askcontainer>
+<rdn>cn</rdn>
+<visible>1</visible>
+
+<objectClasses>
+<objectClass id="posixGroup"></objectClass>
+<objectClass id="namedObject"></objectClass>
+</objectClasses>
+
+<attributes>
+<attribute id="cn">
+ <display>Group</display>
+ <order>1</order>
+ <page>1</page>
+</attribute>
+<attribute id="gidNumber">
+ <display>GID Number</display>
+ <hint>Automatically determined</hint>
+ <value>=php.GetNextNumber(/,gid)</value>
+ <readonly>1</readonly>
+ <order>2</order>
+ <page>1</page>
+ <spacer>1</spacer>
+</attribute>
+<attribute id="memberUid">
+ <maxvalnb>10</maxvalnb>
+ <display>Users</display>
+ <type>Dn</type>
+ <hidden>0</hidden>
+ <order>3</order>
+ <page>1</page>
+</attribute>
+</attributes>
+</template>
--- /dev/null
+<?xml version="1.0" encoding="UTF-8" standalone="no"?>
+<!DOCTYPE template SYSTEM "template.dtd">
+<template>
+<title>Samba3 Group Mapping - SUSE</title>
+<!-- <regexp>^ou=.*,</regexp> -->
+<icon>images/ou.png</icon>
+<description>New Samba3 Group Mapping</description>
+<askcontainer>1</askcontainer>
+<rdn>cn</rdn>
+<visible>1</visible>
+
+<objectClasses>
+<objectClass id="posixGroup"></objectClass>
+<objectClass id="namedObject"></objectClass>
+<objectClass id="sambaGroupMapping"></objectClass>
+</objectClasses>
+
+<attributes>
+<attribute id="cn">
+ <display>Group</display>
+ <order>1</order>
+ <page>1</page>
+</attribute>
+<attribute id="displayName">
+ <display>Windows Name</display>
+ <order>2</order>
+ <page>1</page>
+</attribute>
+<attribute id="gidNumber">
+ <display>GID Number</display>
+ <hint>Automatically determined</hint>
+ <value>=php.GetNextNumber(/,gid)</value>
+ <readonly>1</readonly>
+ <order>3</order>
+ <page>1</page>
+ <spacer>1</spacer>
+</attribute>
+<attribute id="sambaSID">
+ <display>Samba SID</display>
+ <option>=php.PickList(/,(objectClass=sambaDomain),sambaSID,%sambaSID% (%sambaDomainName%))</option>
+ <helper>
+ <id>sidsuffix</id>
+ <value></value>
+ </helper>
+ <post>=php.Join(-,(%sambaSID%,%sidsuffix%))</post>
+ <order>4</order>
+ <page>1</page>
+</attribute>
+<attribute id="sambaGroupType">
+ <display>Samba Group Type</display>
+ <option id="2">Domain Group</option>
+ <option id="4">Local Group</option>
+ <option id="5">Well-known Group</option>
+ <value>2</value>
+ <order>5</order>
+ <page>1</page>
+ <spacer>1</spacer>
+</attribute>
+<attribute id="memberUid">
+ <maxvalnb>10</maxvalnb>
+ <display>Users</display>
+ <type>Dn</type>
+ <hidden>0</hidden>
+ <order>10</order>
+ <page>1</page>
+</attribute>
+</attributes>
+</template>
--- /dev/null
+<?xml version="1.0" encoding="UTF-8" standalone="no"?>
+<!DOCTYPE template SYSTEM "template.dtd">
+<!--This template doesnt work needs modification to the Engine.-->
+<template>
+<title>LDAP Alias</title>
+<!--<regexp>^ou=People,o=.*,</regexp>-->
+<icon>images/mail_alias.png</icon>
+<description>New LDAP Alias</description>
+<askcontainer>1</askcontainer>
+<rdn>aliasedObjectName</rdn>
+<visible>1</visible>
+<invalid>1</invalid>
+
+<objectClasses>
+<objectClass id="alias"></objectClass>
+<objectClass id="extensibleObject"></objectClass>
+</objectClasses>
+
+<attributes>
+<attribute id="aliasedObjectName">
+ <display>Alias To</display>
+ <order>1</order>
+ <page>1</page>
+</attribute>
+</attributes>
+</template>
--- /dev/null
+<?xml version="1.0" encoding="UTF-8" standalone="no"?>
+<!DOCTYPE template SYSTEM "template.dtd">
+<template>
+<title>Courier Mail Account</title>
+<!--<regexp>^ou=People,o=.*,</regexp>-->
+<icon>images/mail_account.png</icon>
+<description>New Courier Mail Account</description>
+<askcontainer>1</askcontainer>
+<rdn>cn</rdn>
+<visible>1</visible>
+<invalid>0</invalid>
+
+<objectClasses>
+<objectClass id="inetOrgPerson"></objectClass>
+<objectClass id="courierMailAccount"></objectClass>
+</objectClasses>
+
+<attributes>
+<attribute id="givenName">
+ <display>Given Name</display>
+ <onchange>autoFill:cn,%givenName% %sn%</onchange>
+ <onchange>autoFill:uid,%gidNumber|0-0/T%-%givenName|0-1/l%%sn/l%</onchange>
+ <order>1</order>
+ <page>1</page>
+</attribute>
+<attribute id="sn">
+ <display>Last name</display>
+ <onchange>autoFill:cn,%givenName% %sn%</onchange>
+ <onchange>autoFill:uid,%gidNumber|0-0/T%-%givenName|0-1/l%%sn/l%</onchange>
+ <order>2</order>
+ <page>1</page>
+</attribute>
+<attribute id="cn">
+ <display>Common Name</display>
+ <order>3</order>
+ <page>1</page>
+ <spacer>1</spacer>
+</attribute>
+<attribute id="uid">
+ <display>User ID</display>
+ <icon>images/uid.png</icon>
+ <!--<onchange>autoFill:homeDirectory,/home/users/%uid%</onchange>-->
+ <onchange>autoFill:homeDirectory,/home/users/%gidNumber|0-0/T%/%uid|3-%</onchange>
+ <order>4</order>
+ <page>1</page>
+</attribute>
+<attribute id="uidNumber">
+ <display>UID Number</display>
+ <hint>Automatically determined</hint>
+ <icon>images/terminal.png</icon>
+ <value>=php.GetNextNumber(/,uid)</value>
+ <readonly>1</readonly>
+ <order>6</order>
+ <page>1</page>
+</attribute>
+<attribute id="gidNumber">
+ <display>GID Number</display>
+ <onchange>autoFill:uid,%gidNumber|0-0/T%-%givenName|0-1/l%%sn/l%</onchange>
+ <onchange>autoFill:homeDirectory,/home/users/%gidNumber|0-0/T%/%uid|3-%</onchange>
+ <option>=php.PickList(/,(objectClass=posixGroup),gidNumber,%cn%)</option>
+ <order>7</order>
+ <page>1</page>
+ <spacer>1</spacer>
+</attribute>
+<attribute id="homeDirectory">
+ <display>Home Directory</display>
+ <order>8</order>
+ <page>1</page>
+</attribute>
+<attribute id="mail">
+ <display>Email</display>
+ <icon>images/mail.png</icon>
+ <order>9</order>
+ <page>1</page>
+</attribute>
+<attribute id="mailbox">
+ <display>Mailbox</display>
+ <order>10</order>
+ <page>1</page>
+</attribute>
+<attribute id="userPassword">
+ <display>Password</display>
+ <icon>images/lock.png</icon>
+ <type>password</type>
+ <verify>1</verify>
+ <helper>
+ <display>Encryption</display>
+ <id>enc</id>
+ <option>blowfish</option>
+ <option>clear</option>
+ <option>crypt</option>
+ <option>ext_des</option>
+ <option>md5</option>
+ <option>md5crypt</option>
+ <option>sha</option>
+ <option>smd5</option>
+ <option>ssha</option>
+ <value>md5</value>
+ </helper>
+ <post>=php.Password(%enc%,%userPassword%)</post>
+ <order>11</order>
+ <page>1</page>
+</attribute>
+</attributes>
+</template>
--- /dev/null
+<?xml version="1.0" encoding="UTF-8" standalone="no"?>
+<!DOCTYPE template SYSTEM "template.dtd">
+<template>
+<title>Courier Mail Alias</title>
+<!--<regexp>^ou=People,o=.*,</regexp>-->
+<icon>images/mail_alias.png</icon>
+<description>New Courier Mail Alias</description>
+<askcontainer>1</askcontainer>
+<rdn>cn</rdn>
+<visible>1</visible>
+<invalid>0</invalid>
+
+<objectClasses>
+<objectClass id="inetOrgPerson"></objectClass>
+<objectClass id="courierMailAlias"></objectClass>
+</objectClasses>
+
+<attributes>
+<attribute id="cn">
+ <display>Common Name</display>
+ <order>1</order>
+ <page>1</page>
+</attribute>
+<attribute id="sn">
+ <display>Last name</display>
+ <order>2</order>
+ <page>1</page>
+</attribute>
+<attribute id="mail">
+ <display>Email</display>
+ <order>3</order>
+ <page>1</page>
+</attribute>
+<attribute id="maildrop">
+ <display>Maildrop</display>
+ <order>4</order>
+ <page>1</page>
+</attribute>
+</attributes>
+</template>
--- /dev/null
+<?xml version="1.0" encoding="UTF-8" standalone="no"?>
+<!DOCTYPE template SYSTEM "template.dtd">
+<template>
+<title>DNS Entry</title>
+<!--<regexp>^ou=People,o=.*,</regexp>-->
+<icon>images/dc.png</icon>
+<description>New DNS Entry</description>
+<askcontainer>1</askcontainer>
+<rdn>dc</rdn>
+<visible>1</visible>
+
+<objectClasses>
+<objectClass id="dnsDomain"></objectClass>
+<objectClass id="domainRelatedObject"></objectClass>
+</objectClasses>
+
+<attributes>
+<attribute id="domainComponent">
+ <description>Domain Component</description>
+ <display>DC Name</display>
+ <order>1</order>
+ <page>1</page>
+</attribute>
+<attribute id="associatedDomain">
+ <display>Associated Domain</display>
+ <order>2</order>
+ <page>1</page>
+</attribute>
+</attributes>
+</template>
--- /dev/null
+<?xml version="1.0" encoding="UTF-8" standalone="no"?>
+<!DOCTYPE template SYSTEM "template.dtd">
+<template>
+<title>Example entry</title>
+<regexp>^$</regexp>
+<icon>images/star.png</icon>
+<description>This is the description</description>
+<rdn>o</rdn>
+<visible>0</visible>
+
+<objectClasses>
+<objectClass id="organization"></objectClass>
+</objectClasses>
+
+<attributes>
+<attribute id="attribute1">
+ <description>This is the attribute description</description>
+ <display>Attribute 1</display>
+ <hint>This is an example</hint>
+ <icon>images/user.png</icon>
+ <order>1</order>
+ <page>1</page>
+</attribute>
+<attribute id="attribute2">
+ <description>This is the attribute description</description>
+ <display>Attribute 2</display>
+ <order>2</order>
+ <page>2</page>
+</attribute>
+<attribute id="attribute3">
+ <description>This is the attribute description</description>
+ <display>Attribute 3</display>
+ <order>1</order>
+ <page>2</page>
+</attribute>
+</attributes>
+</template>
--- /dev/null
+<?xml version="1.0" encoding="UTF-8" standalone="no"?>
+<!DOCTYPE template SYSTEM "template.dtd">
+<template>
+<title>Address Book Entry</title>
+<!--<regexp>^ou=People,o=.*,</regexp>-->
+<icon>images/user.png</icon>
+<description>New Address Book Entry</description>
+<askcontainer>1</askcontainer>
+<rdn>cn</rdn>
+<visible>1</visible>
+
+<objectClasses>
+<objectClass id="inetOrgPerson"></objectClass>
+</objectClasses>
+
+<attributes>
+<attribute id="givenName">
+ <display>First name</display>
+ <icon>images/uid.png</icon>
+ <onchange>autoFill:cn,%givenName% %sn%</onchange>
+ <order>1</order>
+ <page>1</page>
+</attribute>
+<attribute id="sn">
+ <display>Last name</display>
+ <onchange>autoFill:cn,%givenName% %sn%</onchange>
+ <order>2</order>
+ <page>1</page>
+</attribute>
+<attribute id="cn">
+ <display>Common Name</display>
+ <order>3</order>
+ <page>1</page>
+ <spacer>1</spacer>
+</attribute>
+<attribute id="o">
+ <display>Organisation</display>
+ <order>4</order>
+ <page>1</page>
+</attribute>
+<attribute id="street">
+ <display>Street</display>
+ <icon>images/mail.png</icon>
+ <type>textarea</type>
+ <cols>50</cols>
+ <rows>4</rows>
+ <order>4</order>
+ <page>1</page>
+</attribute>
+<attribute id="l">
+ <display>City</display>
+ <order>5</order>
+ <page>1</page>
+</attribute>
+<attribute id="st">
+ <display>State</display>
+ <order>6</order>
+ <page>1</page>
+</attribute>
+<attribute id="postalCode">
+ <display>Postal code</display>
+ <order>7</order>
+ <page>1</page>
+ <spacer>1</spacer>
+</attribute>
+<attribute id="telephoneNumber">
+ <display>Work phone</display>
+ <icon>images/phone.png</icon>
+ <order>8</order>
+ <page>1</page>
+</attribute>
+<attribute id="facsimileTelephoneNumber">
+ <display>Fax</display>
+ <order>9</order>
+ <page>1</page>
+</attribute>
+<attribute id="mobile">
+ <display>Mobile</display>
+ <order>9</order>
+ <page>1</page>
+</attribute>
+<attribute id="mail">
+ <display>Email</display>
+ <order>10</order>
+ <page>1</page>
+</attribute>
+</attributes>
+</template>
--- /dev/null
+<?xml version="1.0" encoding="UTF-8" standalone="no"?>
+<!DOCTYPE template SYSTEM "template.dtd">
+<template>
+<title>Kolab User Entry</title>
+<!--<regexp>^ou=People,o=.*,</regexp>-->
+<icon>images/user.png</icon>
+<description>New Address Book Entry</description>
+<askcontainer>1</askcontainer>
+<rdn>cn</rdn>
+<visible>1</visible>
+<invalid>1</invalid>
+
+<objectClasses>
+<objectClass id="inetOrgPerson"></objectClass>
+</objectClasses>
+
+<attributes>
+<attribute id="givenName">
+ <display>First name</display>
+ <icon>images/uid.png</icon>
+ <onchange>autoFill:cn,%givenName% %sn%</onchange>
+ <order>1</order>
+</attribute>
+<attribute id="sn">
+ <display>Last name</display>
+ <onchange>autoFill:cn,%givenName% %sn%</onchange>
+ <order>2</order>
+</attribute>
+<attribute id="cn">
+ <display>Common Name</display>
+ <order>3</order>
+</attribute>
+<attribute id="mail">
+ <display>Email</display>
+ <order>4</order>
+</attribute>
+<attribute id="userPassword">
+ <display>Password</display>
+ <icon>images/lock.png</icon>
+ <type>password</type>
+ <verify>1</verify>
+ <helper>
+ <display>Encryption</display>
+ <id>enc</id>
+ <option>blowfish</option>
+ <option>clear</option>
+ <option>crypt</option>
+ <option>ext_des</option>
+ <option>md5</option>
+ <option>md5crypt</option>
+ <option>sha</option>
+ <option>smd5</option>
+ <option>ssha</option>
+ <value>md5</value>
+ </helper>
+ <post>=php.Password(%enc%,%userPassword%)</post>
+ <order>5</order>
+ <spacer>1</spacer>
+</attribute>
+
+<attribute id="title">
+ <display>Title</display>
+ <icon>images/ou.png</icon>
+ <order>6</order>
+</attribute>
+<attribute id="alias">
+ <display>Alias</display>
+ <order>7</order>
+</attribute>
+<attribute id="o">
+ <display>Organisation</display>
+ <order>8</order>
+</attribute>
+<attribute id="ou">
+ <display>Organisational unit</display>
+ <order>9</order>
+</attribute>
+<attribute id="roomNumber">
+ <display>Room Number</display>
+ <order>10</order>
+ <spacer>1</spacer>
+</attribute>
+
+<attribute id="street">
+ <display>Address</display>
+ <icon>images/mail.png</icon>
+ <order>11</order>
+</attribute>
+<attribute id="postOfficeBox">
+ <display>Post box</display>
+ <order>12</order>
+</attribute>
+<attribute id="l">
+ <display>City</display>
+ <order>13</order>
+</attribute>
+<attribute id="st">
+ <display>State</display>
+ <order>14</order>
+</attribute>
+<attribute id="postalCode">
+ <display>Postal code</display>
+ <order>15</order>
+</attribute>
+<attribute id="c">
+ <display>Country</display>
+ <order>16</order>
+ <spacer>1</spacer>
+</attribute>
+<attribute id="telephoneNumber">
+ <display>Work phone</display>
+ <icon>images/phone.png</icon>
+ <order>17</order>
+</attribute>
+<attribute id="facsimileTelephoneNumber">
+ <display>Fax</display>
+ <order>18</order>
+</attribute>
+<attribute id="mobile">
+ <display>Mobile</display>
+ <order>19</order>
+</attribute>
+</attributes>
+</template>
--- /dev/null
+<?xml version="1.0" encoding="UTF-8" standalone="no"?>
+<!DOCTYPE template SYSTEM "template.dtd">
+<template>
+<title>Address Book Entry (mozillaOrgPerson)</title>
+<!--<regexp>^ou=People,o=.*,</regexp>-->
+<icon>images/user.png</icon>
+<description>New Address Book Entry</description>
+<askcontainer>1</askcontainer>
+<rdn>cn</rdn>
+<visible>1</visible>
+
+<objectClasses>
+<objectClass id="inetOrgPerson"></objectClass>
+<objectClass id="mozillaAddressBookEntry"></objectClass>
+</objectClasses>
+
+<attributes>
+<attribute id="givenName">
+ <display>First Name</display>
+ <icon>images/uid.png</icon>
+ <onchange>autoFill:cn,%sn% %givenName%</onchange>
+ <order>1</order>
+</attribute>
+<attribute id="sn">
+ <display>Last Name</display>
+ <onchange>autoFill:cn,%sn% %givenName%</onchange>
+ <order>2</order>
+</attribute>
+<attribute id="cn">
+ <display>Common Name</display>
+ <order>3</order>
+</attribute>
+<attribute id="mozillaNickName">
+ <display>Nickname</display>
+ <order>4</order>
+ <spacer>1</spacer>
+</attribute>
+<attribute id="mail">
+ <display>t_email</display>
+ <order>5</order>
+</attribute>
+<attribute id="mozillaSecondEmail">
+ <display>Additional email</display>
+ <order>6</order>
+ <spacer>1</spacer>
+</attribute>
+<attribute id="telephoneNumber">
+ <display>Work Phone</display>
+ <icon>images/phone.png</icon>
+ <order>7</order>
+</attribute>
+<attribute id="homePhone">
+ <display>Home Phone</display>
+ <order>8</order>
+</attribute>
+<attribute id="facsimileTelephoneNumber">
+ <display>Fax</display>
+ <order>9</order>
+</attribute>
+<attribute id="pager">
+ <display>Page</display>
+ <order>10</order>
+</attribute>
+<attribute id="mobile">
+ <display>Mobile</display>
+ <order>11</order>
+ <spacer>1</spacer>
+</attribute>
+<attribute id="homePostalAddress">
+ <display>Home Address</display>
+ <order>12</order>
+</attribute>
+<attribute id="mozillaHomePostalAddress2">
+ <display>Home Address 2</display>
+ <order>13</order>
+</attribute>
+<attribute id="mozillaHomeLocalityName">
+ <display>Home City</display>
+ <order>14</order>
+</attribute>
+<attribute id="mozillaHomeState">
+ <display>Home State</display>
+ <order>15</order>
+</attribute>
+<attribute id="mozillaHomePostalCode">
+ <display>Home ZIP/Postal Code</display>
+ <order>16</order>
+</attribute>
+<attribute id="mozillaHomeCountryName">
+ <display>Home Country</display>
+ <order>17</order>
+</attribute>
+<attribute id="mozillaHomeUrl">
+ <display>Home Web page</display>
+ <order>18</order>
+ <spacer>1</spacer>
+</attribute>
+<attribute id="title">
+ <display>Work Title</display>
+ <order>19</order>
+</attribute>
+<attribute id="ou">
+ <display>Work Department</display>
+ <order>20</order>
+</attribute>
+<attribute id="o">
+ <display>Work Organization</display>
+ <order>21</order>
+</attribute>
+<attribute id="street">
+ <display>Work Address</display>
+ <order>22</order>
+</attribute>
+<attribute id="mozillaWorkStreet2">
+ <display>Work Address 2</display>
+ <order>23</order>
+</attribute>
+<attribute id="l">
+ <display>Work City</display>
+ <order>24</order>
+</attribute>
+<attribute id="st">
+ <display>Work State/Province</display>
+ <order>25</order>
+</attribute>
+<attribute id="postalCode">
+ <display>Work ZIP/Postal Code</display>
+ <order>26</order>
+</attribute>
+<attribute id="c">
+ <display>Work Country</display>
+ <order>27</order>
+</attribute>
+<attribute id="mozillaWorkUrl">
+ <display>Work Web page</display>
+ <order>28</order>
+</attribute>
+</attributes>
+</template>
--- /dev/null
+<?xml version="1.0" encoding="UTF-8" standalone="no"?>
+<!DOCTYPE template SYSTEM "template.dtd">
+<template>
+<title>Organisational Role</title>
+<!--<regexp>^ou=People,o=.*,</regexp>-->
+<icon>images/o.png</icon>
+<description>New Organisational Role</description>
+<askcontainer>1</askcontainer>
+<rdn>cn</rdn>
+<visible>1</visible>
+
+<objectClasses>
+<objectClass id="organizationalRole"></objectClass>
+</objectClasses>
+
+<attributes>
+<attribute id="cn">
+ <display>Role CN</display>
+ <order>1</order>
+ <spacer>1</spacer>
+</attribute>
+<attribute id="telephoneNumber">
+ <display>Work phone</display>
+ <icon>images/phone.png</icon>
+ <order>2</order>
+</attribute>
+<attribute id="facsimileTelephoneNumber">
+ <display>Fax</display>
+ <order>3</order>
+ <spacer>1</spacer>
+</attribute>
+
+<attribute id="description">
+ <display>Comments</display>
+ <icon>images/light.png</icon>
+ <order>4</order>
+ <spacer>1</spacer>
+</attribute>
+
+<attribute id="roleOccupant">
+ <display>Occupant</display>
+ <icon>images/object.png</icon>
+ <order>5</order>
+ <spacer>1</spacer>
+</attribute>
+
+<attribute id="street">
+ <display>Street Address</display>
+ <icon>images/mail.png</icon>
+ <order>6</order>
+</attribute>
+<attribute id="l">
+ <display>City</display>
+ <order>7</order>
+</attribute>
+<attribute id="st">
+ <display>State</display>
+ <order>8</order>
+</attribute>
+<attribute id="postalCode">
+ <display>Postal code</display>
+ <order>9</order>
+ <spacer>1</spacer>
+</attribute>
+
+<attribute id="postalAddress">
+ <display>Postal Address</display>
+ <icon>images/mail.png</icon>
+ <order>10</order>
+ <spacer>1</spacer>
+</attribute>
+<attribute id="registeredAddress">
+ <display>Registered Address</display>
+ <icon>images/mail.png</icon>
+ <order>11</order>
+</attribute>
+
+</attributes>
+</template>
--- /dev/null
+<?xml version="1.0" encoding="UTF-8" standalone="no"?>
+<!DOCTYPE template SYSTEM "template.dtd">
+<template>
+<title>Organisational Unit</title>
+<!-- <regexp>^o=.*,</regexp> -->
+<icon>images/ou.png</icon>
+<description>New Organisational Unit</description>
+<askcontainer>1</askcontainer>
+<rdn>ou</rdn>
+<visible>1</visible>
+
+<objectClasses>
+<objectClass id="organizationalUnit"></objectClass>
+</objectClasses>
+
+<attributes>
+<attribute id="ou">
+ <description>Organisational Unit</description>
+ <display>Organisational Unit</display>
+ <hint>don't include "ou="</hint>
+ <order>1</order>
+ <page>1</page>
+</attribute>
+</attributes>
+</template>
--- /dev/null
+<?xml version="1.0" encoding="UTF-8" standalone="no"?>
+<!DOCTYPE template SYSTEM "template.dtd">
+<template>
+<title>User Account</title>
+<!--<regexp>^ou=People,o=.*,</regexp>-->
+<icon>images/user.png</icon>
+<description>New User Account</description>
+<askcontainer>1</askcontainer>
+<rdn>cn</rdn>
+<visible>1</visible>
+
+<objectClasses>
+<objectClass id="inetOrgPerson"></objectClass>
+<objectClass id="posixAccount"></objectClass>
+<objectClass id="hostObject"></objectClass>
+</objectClasses>
+
+<attributes>
+<attribute id="givenName">
+ <display>First name</display>
+ <icon>images/uid.png</icon>
+ <onchange>autoFill:cn,%givenName% %sn%</onchange>
+ <onchange>autoFill:uid,%givenName|0-1/l%%sn/l%</onchange>
+ <order>1</order>
+ <page>1</page>
+</attribute>
+<attribute id="sn">
+ <display>Last name</display>
+ <onchange>autoFill:cn,%givenName% %sn%</onchange>
+ <onchange>autoFill:uid,%givenName|0-1/l%%sn/l%</onchange>
+ <!-- <onchange>autoFill:homeDirectory,/home/users/%uid|0-1/l%/%uid%</onchange> -->
+ <order>2</order>
+ <page>1</page>
+</attribute>
+<attribute id="cn">
+ <display>Common Name</display>
+ <order>3</order>
+ <page>1</page>
+</attribute>
+<attribute id="uid">
+ <display>User ID</display>
+ <onchange>autoFill:homeDirectory,/home/%uid%</onchange>
+ <order>4</order>
+ <page>1</page>
+ <spacer>1</spacer>
+</attribute>
+<attribute id="homeDirectory">
+ <display>Home directory</display>
+ <!-- <onchange>autoFill:homeDirectory,/home/users/%gidNumber|0-0/T%/%uid|3-%</onchange> -->
+ <order>8</order>
+ <page>1</page>
+</attribute>
+<attribute id="uidNumber">
+ <display>UID Number</display>
+ <hint>Automatically determined</hint>
+ <icon>images/terminal.png</icon>
+ <order>6</order>
+ <page>1</page>
+ <value>=php.GetNextNumber(/,uid)</value>
+ <readonly>1</readonly>
+</attribute>
+<attribute id="gidNumber">
+ <display>GID Number</display>
+ <!-- <onchange>autoFill:homeDirectory,/home/users/%gidNumber|0-0/T%/%uid|3-%</onchange> -->
+ <order>7</order>
+ <page>1</page>
+ <option>=php.PickList(/,(objectClass=posixGroup),gidNumber,%cn%)</option>
+</attribute>
+<attribute id="loginShell">
+ <display>Login shell</display>
+ <order>9</order>
+ <page>1</page>
+ <!-- <option>=php.PickList(/,(objectClass=posixAccount),loginShell,%loginShell%)</option> -->
+ <option>/bin/sh</option>
+ <option>/bin/bash</option>
+</attribute>
+<attribute id="userPassword">
+ <display>Password</display>
+ <icon>images/lock.png</icon>
+ <type>password</type>
+ <verify>1</verify>
+ <helper>
+ <display>Encryption</display>
+ <id>enc</id>
+ <option>blowfish</option>
+ <option>clear</option>
+ <option>crypt</option>
+ <option>ext_des</option>
+ <option>md5</option>
+ <option>md5crypt</option>
+ <option>sha</option>
+ <option>smd5</option>
+ <option>ssha</option>
+ <value>ssha</value>
+ </helper>
+ <post>=php.Password(%enc%,%userPassword%)</post>
+ <order>5</order>
+ <page>1</page>
+ <spacer>1</spacer>
+</attribute>
+<attribute id="host">
+ <display>Accessable hosts</display>
+ <hidden>0</hidden>
+ <order>3</order>
+ <page>1</page>
+</attribute>
+</attributes>
+</template>
--- /dev/null
+<?xml version="1.0" encoding="UTF-8" standalone="no"?>
+<!DOCTYPE template SYSTEM "template.dtd">
+<template>
+<title>Posix Group</title>
+<!-- <regexp>^ou=.*,</regexp> -->
+<icon>images/ou.png</icon>
+<description>New Posix Group</description>
+<askcontainer>1</askcontainer>
+<rdn>cn</rdn>
+<visible>1</visible>
+
+<objectClasses>
+<objectClass id="posixGroup"></objectClass>
+</objectClasses>
+
+<attributes>
+<attribute id="cn">
+ <display>Group</display>
+ <order>1</order>
+ <page>1</page>
+</attribute>
+<attribute id="gidNumber">
+ <display>GID Number</display>
+ <hint>Automatically determined</hint>
+ <order>2</order>
+ <page>1</page>
+ <value>=php.GetNextNumber(/,gid)</value>
+ <readonly>1</readonly>
+ <spacer>1</spacer>
+ <!-- <option>=php.GetNextNumber(/,gid,false,(&(objectClass=posixGroup)),*2;+1000)</option> -->
+</attribute>
+<attribute id="memberUid">
+ <display>Users</display>
+ <!-- <option>=php.MultiList(/,(objectClass=posixAccount),uid,%cn% (%uid|-4%))</option> -->
+ <hidden>0</hidden>
+ <order>3</order>
+ <page>1</page>
+</attribute>
+</attributes>
+</template>
--- /dev/null
+<?xml version="1.0" encoding="UTF-8" standalone="no"?>
+<!DOCTYPE template SYSTEM "template.dtd">
+<template>
+<title>Samba Domain</title>
+<!--<regexp>^ou=People,o=.*,</regexp>-->
+<icon>images/dc.png</icon>
+<description>New Samba Domain</description>
+<askcontainer>1</askcontainer>
+<rdn>sambaDomainName</rdn>
+<visible>1</visible>
+
+<objectClasses>
+<objectClass id="sambaDomain"></objectClass>
+</objectClasses>
+
+<attributes>
+<attribute id="sambaDomainName">
+ <display>Samba Domain Name</display>
+ <order>1</order>
+ <page>1</page>
+</attribute>
+<attribute id="sambaSID">
+ <display>Samba SID</display>
+ <hint>Samba SID is in the format S-1-5-21-x-y-z</hint>
+ <value>S-1-5-21-</value>
+ <order>2</order>
+ <page>1</page>
+</attribute>
+</attributes>
+</template>
--- /dev/null
+<?xml version="1.0" encoding="UTF-8" standalone="no"?>
+<!DOCTYPE template SYSTEM "template.dtd">
+<template>
+<title>Samba3 Group Mapping</title>
+<!-- <regexp>^ou=.*,</regexp> -->
+<icon>images/ou.png</icon>
+<description>New Samba3 Group Mapping</description>
+<askcontainer>1</askcontainer>
+<rdn>cn</rdn>
+<visible>1</visible>
+
+<objectClasses>
+<objectClass id="posixGroup"></objectClass>
+<objectClass id="sambaGroupMapping"></objectClass>
+</objectClasses>
+
+<attributes>
+<attribute id="cn">
+ <display>Group</display>
+ <order>1</order>
+ <page>1</page>
+</attribute>
+<attribute id="displayName">
+ <display>Windows Name</display>
+ <order>2</order>
+ <page>1</page>
+</attribute>
+<attribute id="gidNumber">
+ <display>GID Number</display>
+ <hint>Automatically determined</hint>
+ <value>=php.GetNextNumber(/,gid,true,(&(objectClass=sambaDomain)(sambaDomainName=mysambadomain))</value>
+ <readonly>1</readonly>
+ <order>3</order>
+ <page>1</page>
+ <spacer>1</spacer>
+</attribute>
+<attribute id="sambaSID">
+ <display>Samba SID</display>
+ <option>=php.PickList(/,(objectClass=sambaDomain),sambaSID,%sambaSID% (%sambaDomainName%))</option>
+ <helper>
+ <id>sidsuffix</id>
+ <option>=php.GetNextNumber(/,gid,false,(&(objectClass=sambaDomain)(sambaDomainName=mysambadomain)),*2;+1000)</option>
+ </helper>
+ <post>=php.Join(-,(%sambaSID%,%sidsuffix%))</post>
+ <order>4</order>
+ <page>1</page>
+</attribute>
+<attribute id="sambaGroupType">
+ <display>Samba Group Type</display>
+ <option id="2">Domain Group</option>
+ <option id="4">Local Group</option>
+ <option id="5">Well-known Group</option>
+ <value>2</value>
+ <order>5</order>
+ <page>1</page>
+ <spacer>1</spacer>
+</attribute>
+<attribute id="memberUid">
+ <display>Users</display>
+ <type>multiselect</type>
+ <option>=php.MultiList(/,(objectClass=posixAccount),uid,%cn% %uid|-4/U%,memberUid,dmdName=users:::dc=localdomain,root => cn=root; nobody => cn=nobody,cn,,,)</option>
+ <value>=php.MultiList(/,(&(objectClass=posixAccount)(gidNumber=29999)),uid)</value>
+ <size>10</size>
+ <hidden>0</hidden>
+ <order>10</order>
+ <page>1</page>
+</attribute>
+</attributes>
+</template>
--- /dev/null
+<?xml version="1.0" encoding="UTF-8" standalone="no"?>
+<!DOCTYPE template SYSTEM "template.dtd">
+<template>
+<title>Samba3 Machine</title>
+<!--<regexp>^ou=People,o=.*,</regexp>-->
+<icon>images/server.png</icon>
+<description>New Samba3 Machine</description>
+<askcontainer>1</askcontainer>
+<rdn>uid</rdn>
+<visible>1</visible>
+
+<objectClasses>
+<objectClass id="sambaSAMAccount"></objectClass>
+<objectClass id="posixAccount"></objectClass>
+<objectClass id="account"></objectClass>
+</objectClasses>
+
+<attributes>
+<attribute id="uid">
+ <display>Machine Name</display>
+ <hint>The machine name should end with a $</hint>
+ <icon>images/terminal.png</icon>
+ <onchange>autoFill:cn,%uid%</onchange>
+ <order>1</order>
+ <page>1</page>
+</attribute>
+<attribute id="uidNumber">
+ <display>UID Number</display>
+ <hint>Automatically determined</hint>
+ <value>=php.GetNextNumber(/,uid)</value>
+ <readonly>1</readonly>
+ <order>2</order>
+ <page>1</page>
+</attribute>
+<attribute id="gidNumber">
+ <display>GID Number</display>
+ <option>=php.PickList(/,(objectClass=posixGroup),gidNumber,%cn%)</option>
+ <order>3</order>
+ <page>1</page>
+</attribute>
+<attribute id="sambaSID">
+ <display>Samba SID</display>
+ <option>=php.PickList(/,(objectClass=sambaDomain),sambaSID,%sambaSID% (%sambaDomainName%))</option>
+ <helper>
+ <id>sidsuffix</id>
+ <value></value>
+ </helper>
+ <post>=php.Join(-,(%sambaSID%,%sidsuffix%))</post>
+ <order>2</order>
+ <page>1</page>
+</attribute>
+<attribute id="sambaAcctFlags">
+ <value>[W]</value>
+ <hidden>1</hidden>
+</attribute>
+<attribute id="homeDirectory">
+ <value>/dev/null</value>
+ <hidden>1</hidden>
+</attribute>
+<attribute id="cn">
+ <value></value>
+ <hidden>1</hidden>
+</attribute>
+</attributes>
+</template>
--- /dev/null
+<?xml version="1.0" encoding="UTF-8" standalone="no"?>
+<!DOCTYPE template SYSTEM "template.dtd">
+<template>
+<title>Samba3 Account</title>
+<!--<regexp>^ou=People,o=.*,</regexp>-->
+<icon>images/user.png</icon>
+<description>New Samba3 Account</description>
+<askcontainer>1</askcontainer>
+<rdn>cn</rdn>
+<visible>1</visible>
+
+<objectClasses>
+<objectClass id="inetOrgPerson"></objectClass>
+<objectClass id="sambaSAMAccount"></objectClass>
+<objectClass id="posixAccount"></objectClass>
+</objectClasses>
+
+<attributes>
+<attribute id="givenName">
+ <display>First name</display>
+ <icon>images/uid.png</icon>
+ <onchange>autoFill:cn,%givenName% %sn%</onchange>
+ <order>1</order>
+ <page>1</page>
+</attribute>
+<attribute id="sn">
+ <display>Last name</display>
+ <onchange>autoFill:cn,%givenName% %sn%</onchange>
+ <onchange>autoFill:uid,%gidNumber|0-0/T%-%givenName|0-1/l%%sn/l%</onchange>
+ <order>2</order>
+ <page>1</page>
+</attribute>
+<attribute id="cn">
+ <display>Common Name</display>
+ <order>3</order>
+ <page>1</page>
+ <spacer>1</spacer>
+</attribute>
+<attribute id="uid">
+ <display>User ID</display>
+ <onchange>autoFill:homeDirectory,/home/users/%gidNumber|0-0/T%/%uid|3-%</onchange>
+ <order>4</order>
+ <page>1</page>
+ <spacer>1</spacer>
+</attribute>
+<attribute id="uidNumber">
+ <display>UID Number</display>
+ <hint>Automatically determined</hint>
+ <value>=php.GetNextNumber(/,uid)</value>
+ <order>5</order>
+ <page>1</page>
+ <readonly>1</readonly>
+</attribute>
+<attribute id="sambaSID">
+ <display>Samba SID</display>
+ <option>=php.PickList(/,(objectClass=sambaDomain),sambaSID,%sambaSID% (%sambaDomainName%))</option>
+ <helper>
+ <id>sidsuffix</id>
+ <option>=php.GetNextNumber(/,uid,false,,*2;+1000)</option>
+ </helper>
+ <post>=php.Join(-,(%sambaSID%,%sidsuffix%))</post>
+ <order>6</order>
+ <page>1</page>
+ <spacer>1</spacer>
+</attribute>
+<attribute id="userPassword">
+ <display>Password</display>
+ <icon>images/lock.png</icon>
+ <onchange>autoFill:sambaLMPassword,%userPassword%</onchange>
+ <onchange>autoFill:sambaNTPassword,%userPassword%</onchange>
+ <type>password</type>
+ <verify>1</verify>
+ <helper>
+ <display>Encryption</display>
+ <id>enc</id>
+ <option>blowfish</option>
+ <option>clear</option>
+ <option>crypt</option>
+ <option>ext_des</option>
+ <option>md5</option>
+ <option>md5crypt</option>
+ <option>sha</option>
+ <option>smd5</option>
+ <option>ssha</option>
+ <value>md5</value>
+ </helper>
+ <post>=php.Password(%enc%,%userPassword%)</post>
+ <order>7</order>
+ <page>1</page>
+</attribute>
+<attribute id="sambaLMPassword">
+ <display>LM Password</display>
+ <type>password</type>
+ <post>=php.SambaPassword(LM,%sambaLMPassword%)</post>
+ <order>8</order>
+ <page>1</page>
+</attribute>
+<attribute id="sambaNTPassword">
+ <display>NT Password</display>
+ <type>password</type>
+ <post>=php.SambaPassword(NT,%sambaNTPassword%)</post>
+ <order>9</order>
+ <page>1</page>
+ <spacer>1</spacer>
+</attribute>
+<attribute id="loginShell">
+ <display>Login shell</display>
+ <icon>images/terminal.png</icon>
+ <!-- <option>=php.PickList(/,(objectClass=posixAccount),loginShell,%loginShell%)</option> -->
+ <option>/bin/sh</option>
+ <option>/bin/tsh</option>
+ <option>/bin/csh</option>
+ <order>10</order>
+ <page>1</page>
+</attribute>
+<attribute id="gidNumber">
+ <display>GID Number</display>
+ <onchange>autoFill:homeDirectory,/home/users/%gidNumber|0-0/T%/%uid|3-%</onchange>
+ <option>=php.PickList(/,(objectClass=posixGroup),gidNumber,%cn%)</option>
+ <order>11</order>
+ <page>1</page>
+</attribute>
+<attribute id="sambaPrimaryGroupSID">
+ <display>Primary Group ID</display>
+ <option>=php.PickList(/,(objectClass=sambaGroupMapping),sambaSID,%sambaSID% (%cn%),sambaPrimaryGroupSID)</option>
+ <helper>
+ <id>sidpgsuffix</id>
+ <value></value>
+ </helper>
+ <post>=php.Join(-,(%sambaPrimaryGroupSID%,%sidpgsuffix%))</post>
+ <order>13</order>
+ <page>1</page>
+ <spacer>1</spacer>
+</attribute>
+<attribute id="homeDirectory">
+ <display>Home directory</display>
+ <order>14</order>
+ <page>1</page>
+</attribute>
+<attribute id="sambaAcctFlags">
+ <value>[U]</value>
+ <hidden>1</hidden>
+</attribute>
+</attributes>
+</template>
--- /dev/null
+<?xml version="1.0" encoding="UTF-8" standalone="no"?>
+<!DOCTYPE template SYSTEM "template.dtd">
+<template>
+<title>Sendmail Alias</title>
+<!--<regexp>^ou=People,o=.*,</regexp>-->
+<icon>images/mail.png</icon>
+<description>New Sendmail Alias</description>
+<askcontainer>1</askcontainer>
+<rdn>sendmailMTACluster</rdn>
+<visible>1</visible>
+<invalid>1</invalid>
+
+<objectClasses>
+<objectClass id="sendmailMTAAliasObject"></objectClass>
+</objectClasses>
+
+<attributes>
+<attribute id="sendmailMTACluster">
+ <display>Sendmail Cluster Name</display>
+ <icon>images/object.png</icon>
+ <order>1</order>
+ <page>1</page>
+</attribute>
+<attribute id="sendmailMTAHost">
+ <display>Sendmail Hostname</display>
+ <hint>Leave Blank</hint>
+ <order>2</order>
+ <page>1</page>
+</attribute>
+<attribute id="sendmailMTAKey">
+ <display>Email alias</display>
+ <order>3</order>
+ <page>1</page>
+</attribute>
+<attribute id="sendmailMTAAliasValue">
+ <display>Recipient Addresses</display>
+ <type>textarea</type>
+ <order>4</order>
+ <page>1</page>
+</attribute>
+<attribute id="sendmailMTAAliasGrouping">
+ <value>aliases</value>
+ <hidden>1</hidden>
+</attribute>
+</attributes>
+</template>
--- /dev/null
+<?xml version="1.0" encoding="UTF-8" standalone="no"?>
+<!DOCTYPE template SYSTEM "template.dtd">
+<template>
+<title>Sendmail Domain</title>
+<!--<regexp>^ou=People,o=.*,</regexp>-->
+<icon>images/mail.png</icon>
+<description>New Sendmail Domain</description>
+<askcontainer>1</askcontainer>
+<rdn>sendmailMTACluster</rdn>
+<visible>1</visible>
+
+<objectClasses>
+<objectClass id="sendmailMTAClass"></objectClass>
+</objectClasses>
+
+<attributes>
+<attribute id="sendmailMTACluster">
+ <display>Sendmail Cluster Name</display>
+ <icon>images/object.png</icon>
+ <order>1</order>
+ <page>1</page>
+</attribute>
+<attribute id="sendmailMTAHost">
+ <display>Sendmail Hostname</display>
+ <hint>Leave Blank</hint>
+ <order>2</order>
+ <page>1</page>
+</attribute>
+<attribute id="sendmailMTAClassValue">
+ <display>Email domain</display>
+ <order>3</order>
+ <page>1</page>
+</attribute>
+<attribute id="sendmailMTAClassName">
+ <value>w</value>
+ <hidden>1</hidden>
+</attribute>
+</attributes>
+</template>
--- /dev/null
+<?xml version="1.0" encoding="UTF-8" standalone="no"?>
+<!DOCTYPE template SYSTEM "template.dtd">
+<template>
+<title>Sendmail Cluster</title>
+<!--<regexp>^ou=People,o=.*,</regexp>-->
+<icon>images/mail.png</icon>
+<description>New Sendmail Cluster</description>
+<askcontainer>1</askcontainer>
+<rdn>sendmailMTACluster</rdn>
+<visible>1</visible>
+
+<objectClasses>
+<objectClass id="sendmailMTA"></objectClass>
+</objectClasses>
+
+<attributes>
+<attribute id="sendmailMTACluster">
+ <display>Alias To</display>
+ <order>1</order>
+ <page>1</page>
+</attribute>
+</attributes>
+</template>
--- /dev/null
+<?xml version="1.0" encoding="UTF-8" standalone="no"?>
+<!DOCTYPE template SYSTEM "template.dtd">
+<!--This template doesnt work needs modification to the Engine.-->
+<template>
+<title>Sendmail Relays</title>
+<!--<regexp>^ou=People,o=.*,</regexp>-->
+<icon>images/mail.png</icon>
+<description>New Sendmail Relays</description>
+<askcontainer>1</askcontainer>
+<rdn>sendmailMTACluster</rdn>
+<visible>1</visible>
+
+<objectClasses>
+<objectClass id="sendmailMTAClass"></objectClass>
+</objectClasses>
+
+<attributes>
+<attribute id="sendmailMTACluster">
+ <display>Sendmail Cluster Name</display>
+ <icon>images/object.png</icon>
+ <order>1</order>
+ <page>1</page>
+</attribute>
+<attribute id="sendmailMTAHost">
+ <display>Sendmail Hostname</display>
+ <hint>Leave Blank</hint>
+ <order>2</order>
+ <page>1</page>
+</attribute>
+<attribute id="sendmailMTAKey">
+ <display>Host/Network/Address</display>
+ <option>RELAY: Allow host/network/address to relay</option>
+ <option>OK: Accept local mail but disallow relay</option>
+ <option>REJECT: Reject messages</option>
+ <option>DISCARD: Discard messages</option>
+ <option>SKIP: Apply default action to messages</option>
+ <option>ERROR: Reject message with custom error</option>
+ <order>3</order>
+ <page>1</page>
+</attribute>
+<attribute id="sendmailMTAMapName">
+ <value>access</value>
+ <hidden>1</hidden>
+</attribute>
+</attributes>
+</template>
--- /dev/null
+<?xml version="1.0" encoding="UTF-8" standalone="no"?>
+<!DOCTYPE template SYSTEM "template.dtd">
+<template>
+<title>Sendmail Virtual Domain</title>
+<!--<regexp>^ou=People,o=.*,</regexp>-->
+<icon>images/mail.png</icon>
+<description>New Sendmail Domain</description>
+<askcontainer>1</askcontainer>
+<rdn>sendmailMTACluster</rdn>
+<visible>1</visible>
+
+<objectClasses>
+<objectClass id="sendmailMTAClass"></objectClass>
+</objectClasses>
+
+<attributes>
+<attribute id="sendmailMTACluster">
+ <display>Sendmail Cluster Name</display>
+ <icon>images/object.png</icon>
+ <order>1</order>
+ <page>1</page>
+</attribute>
+<attribute id="sendmailMTAHost">
+ <display>Sendmail Hostname</display>
+ <hint>Leave Blank</hint>
+ <order>2</order>
+ <page>1</page>
+</attribute>
+<attribute id="sendmailMTAClassValue">
+ <display>Email domain</display>
+ <order>3</order>
+ <page>1</page>
+</attribute>
+<attribute id="sendmailMTAClassName">
+ <value>VirtHost</value>
+ <hidden>1</hidden>
+</attribute>
+</attributes>
+</template>
--- /dev/null
+<?xml version="1.0" encoding="UTF-8" standalone="no"?>
+<!DOCTYPE template SYSTEM "template.dtd">
+<template>
+<title>Sendmail Virtual Users</title>
+<!--<regexp>^ou=People,o=.*,</regexp>-->
+<icon>images/mail.png</icon>
+<description>New Sendmail Virtual User</description>
+<askcontainer>1</askcontainer>
+<rdn>sendmailMTAMapObject</rdn>
+<visible>1</visible>
+<invalid>1</invalid>
+
+<objectClasses>
+<objectClass id="sendmailMTAMapObject"></objectClass>
+</objectClasses>
+
+<attributes>
+<attribute id="sendmailMTACluster">
+ <display>Sendmail Cluster Name</display>
+ <icon>images/object.png</icon>
+ <order>1</order>
+ <page>1</page>
+</attribute>
+<attribute id="sendmailMTAHost">
+ <display>Sendmail Hostname</display>
+ <hint>Leave Blank</hint>
+ <order>2</order>
+ <page>1</page>
+</attribute>
+<attribute id="sendmailMTAKey">
+ <display>Email alias</display>
+ <hint>use @example.com to map entire domain</hint>
+ <order>3</order>
+ <page>1</page>
+</attribute>
+<attribute id="sendmailMTAMapValue">
+ <display>Recipient Addresses</display>
+ <hint>use %1 to map user name port of address</hint>
+ <type>textarea</type>
+ <order>4</order>
+ <page>1</page>
+</attribute>
+<attribute id="sendmailMTAMapName">
+ <value>virtuser</value>
+ <hidden>1</hidden>
+</attribute>
+</attributes>
+</template>
--- /dev/null
+<?xml version="1.0" encoding="UTF-8" standalone="no"?>
+<!DOCTYPE template SYSTEM "template.dtd">
+<template>
+<title>Simple Security Object</title>
+<!--<regexp>^ou=People,o=.*,</regexp>-->
+<icon>images/user.png</icon>
+<description>New Simple Security Object</description>
+<askcontainer>1</askcontainer>
+<rdn>userid</rdn>
+<visible>1</visible>
+
+<objectClasses>
+<objectClass id="account"></objectClass>
+<objectClass id="simpleSecurityObject"></objectClass>
+</objectClasses>
+
+<attributes>
+<attribute id="userid">
+ <display>User Name</display>
+ <icon>images/uid.png</icon>
+ <order>1</order>
+ <page>1</page>
+ <spacer>1</spacer>
+</attribute>
+<attribute id="userPassword">
+ <display>Password</display>
+ <icon>images/lock.png</icon>
+ <type>password</type>
+ <verify>1</verify>
+ <helper>
+ <display>Encryption</display>
+ <id>enc</id>
+ <option>blowfish</option>
+ <option>clear</option>
+ <option>crypt</option>
+ <option>ext_des</option>
+ <option>md5</option>
+ <option>md5crypt</option>
+ <option>sha</option>
+ <option>smd5</option>
+ <option>ssha</option>
+ <value>md5</value>
+ </helper>
+ <post>=php.Password(%enc%,%userPassword%)</post>
+ <order>5</order>
+ <page>1</page>
+</attribute>
+</attributes>
+</template>
--- /dev/null
+<?xml version="1.0" encoding="UTF-8" standalone="no"?>
+<!DOCTYPE template SYSTEM "template.dtd">
+<template>
+<title>Address Book Entry</title>
+<regexp>^uid=.*,</regexp>
+<icon>images/user.png</icon>
+<visible>0</visible>
+<rdn>uid</rdn>
+
+<objectClasses>
+<objectClass id="inetOrgPerson"></objectClass>
+<objectClass id="top"></objectClass>
+</objectClasses>
+
+<attributes>
+<attribute id="givenName">
+ <display>First name</display>
+ <icon>images/uid.png</icon>
+ <onchange>autoFill:cn,%givenName% %sn%</onchange>
+ <order>1</order>
+</attribute>
+<attribute id="sn">
+ <display>Last name</display>
+ <onchange>autoFill:cn,%givenName% %sn%</onchange>
+ <order>2</order>
+</attribute>
+<attribute id="cn">
+ <display>Common Name</display>
+ <readonly>1</readonly>
+ <order>3</order>
+ <spacer>1</spacer>
+</attribute>
+<attribute id="o">
+ <display>Organisation</display>
+ <order>4</order>
+</attribute>
+<attribute id="street">
+ <display>Street</display>
+ <icon>images/mail.png</icon>
+ <type>textarea</type>
+ <cols>50</cols>
+ <rows>4</rows>
+ <order>5</order>
+</attribute>
+<attribute id="l">
+ <display>City</display>
+ <option>Berlin</option>
+ <option>London</option>
+ <option>Paris</option>
+ <option>Washington</option>
+ <option>Other</option>
+ <order>6</order>
+</attribute>
+<attribute id="st">
+ <display>State</display>
+ <order>7</order>
+</attribute>
+<attribute id="postalCode">
+ <display>Postal code</display>
+ <maxlength>5</maxlength>
+ <order>8</order>
+ <spacer>1</spacer>
+</attribute>
+<attribute id="telephoneNumber">
+ <display>Work phone</display>
+ <icon>images/phone.png</icon>
+ <order>9</order>
+</attribute>
+<attribute id="facsimileTelephoneNumber">
+ <display>Fax</display>
+ <order>10</order>
+</attribute>
+<attribute id="mobile">
+ <display>Mobile</display>
+ <order>11</order>
+</attribute>
+<attribute id="mail">
+ <display>Email</display>
+ <order>12</order>
+</attribute>
+</attributes>
+</template>
--- /dev/null
+<!-- ==========================================================================
+ This is the DTD for phpLDAPAdmin Templates (draft).
+
+ Copyright (c) 2005 <adezorzi AT rhx DOT it>
+
+ temporary URI for the DTD: http://www.phamm.org/DTD/pla-template-strict.dtd
+ Validate your templates here: http://www.stg.brown.edu/service/xmlvalid/
+========================================================================== -->
+
+<!-- Unused -->
+<!ENTITY % Boolean "(0 | 1)">
+
+<!-- ================================================================ -->
+
+<!-- Template Definition -->
+<!ELEMENT template (title,regexp?,icon?,description?,askcontainer?,rdn?,
+ destinationcontainer?,action?,leaf?,
+ visible?,invalid?,objectClasses,attributes)>
+
+<!-- ObjectClasses Definition -->
+<!ELEMENT objectClasses (objectClass+)>
+<!ELEMENT objectClass EMPTY>
+<!ATTLIST objectClass id CDATA #REQUIRED>
+
+<!-- Attributes Definition -->
+<!ELEMENT attributes (attribute*)>
+<!ELEMENT attribute (array?, value*, cols?, description?, display?, helper?, hidden?, readonly?, hint?,
+ icon?, onchange*, order?, override?, page?, post?,minvalnb?,maxvalnb?,
+ presubmit?, rows?, spacer*, type?, option*, verify?)>
+<!ATTLIST attribute id CDATA #REQUIRED>
+
+<!-- helper -->
+<!ELEMENT helper (value*,display?,hint?,id?,location?,option*)>
+
+<!-- ================================================================ -->
+
+<!-- Common Parameters -->
+<!ELEMENT icon (#PCDATA)>
+<!ELEMENT hint (#PCDATA)>
+<!ELEMENT description (#PCDATA)>
+<!ELEMENT display (#PCDATA)>
+
+<!-- Header Parameters -->
+<!ELEMENT title (#PCDATA)>
+<!ELEMENT regexp (#PCDATA)>
+<!ELEMENT askcontainer (#PCDATA)>
+<!ELEMENT rdn (#PCDATA)>
+<!ELEMENT visible (#PCDATA)>
+<!ELEMENT invalid (#PCDATA)>
+<!ELEMENT destinationcontainer (#PCDATA)>
+<!ELEMENT action (#PCDATA)>
+<!ELEMENT leaf (#PCDATA)>
+
+<!-- Attribute Parameters -->
+<!ELEMENT array (#PCDATA)>
+<!ELEMENT minvalnb (#PCDATA)>
+<!ELEMENT maxvalnb (#PCDATA)>
+<!ELEMENT cols (#PCDATA)>
+<!ELEMENT value (#PCDATA)>
+<!ELEMENT hidden (#PCDATA)>
+<!ELEMENT readonly (#PCDATA)>
+<!ELEMENT onchange (#PCDATA)>
+<!ELEMENT order (#PCDATA)>
+<!ELEMENT override (#PCDATA)>
+<!ELEMENT page (#PCDATA)>
+<!ELEMENT post (#PCDATA)>
+<!ELEMENT presubmit (#PCDATA)>
+<!ELEMENT rows (#PCDATA)>
+<!ELEMENT spacer (#PCDATA)>
+<!ELEMENT type (#PCDATA)>
+<!ELEMENT verify (#PCDATA)>
+
+<!-- Helper Parameters -->
+<!ELEMENT id (#PCDATA)>
+<!ELEMENT location (#PCDATA)>
+<!ELEMENT option (#PCDATA)>
--- /dev/null
+#!/bin/sh
+exec perl -mfiletest=access $@
--- /dev/null
+#!/bin/sh
+
+if [ "$1" = "-h" -o "$1" = "--help" -o $# -ne 1 ]; then
+ echo "Usage $0 <dirname>"
+ echo "<dirname> is the full path to the site, such as /var/www/example.nl"
+ echo "which is created if it does not exist yet. If it exists, it's"
+ echo "permissions are reset".
+ exit 0
+fi
+
+HTTPD_USER=www-data
+# The primary group of the created user
+HTTPD_USERS_GID=1002
+# The template to copy
+TEMPLATE_DIR=/data/www/template
+# The bases to create users under
+USERBASE="ou=Httpd Users,ou=Users,dc=drsnuggles,dc=stderr,dc=nl"
+GROUPBASE="ou=Domain Groups,ou=Groups,dc=drsnuggles,dc=stderr,dc=nl"
+# PHP config to change the error_log setting in
+PHP_CONFIG=conf/php.ini.override
+# PHP error logfile to set error_log to
+PHP_ERRORLOG=logs/php.log
+
+# Get dir
+DIR="$1"
+
+if [ -e "$DIR" ]; then
+ if [ ! -d "$DIR" ]; then
+ echo "$DIR" must be a directory, or not exist yet.
+ exit 1;
+ fi
+ echo "Skipping creation of $DIR, it already exists";
+else
+ # Create $DIR from $TEMPLATE_DIR, if it does not exist yet
+ echo "Creating $DIR from $TEMPLATE_DIR"
+ cp -R "$TEMPLATE_DIR" "$DIR"
+fi
+
+# Make $DIR absolute
+cd "$DIR"
+DIR=`pwd`
+
+# Strip prefix
+SITE=`basename $DIR`
+
+# replace . with -
+GROUP=`echo $SITE | sed s/\\\\./-/g`
+SCRIPT_USER="httpd-$GROUP"
+
+if getent passwd | grep $SCRIPT_USER &> /dev/null && getent group | grep $GROUP &> /dev/null; then
+ echo "$SCRIPT_USER and/or $GROUP already exists, skipping account creation"
+else
+ # find a uid
+ ID=2000
+ while getent passwd | cut -f 3 -d: | grep "^$ID\$" &>/dev/null && getent group | cut -f 3 -d: | grep "^$ID\$" &> /dev/null; do
+ ((ID++))
+ done;
+
+ echo Found uid/gid $ID for $SCRIPT_USER/$GROUP
+
+ # Create a user for scripts to run as, and a group to give write permissions to
+ # files.
+ ldapvi --profile bind --add --in --ldapvi <<EOF || exit
+add cn=$GROUP,$GROUPBASE
+cn: $GROUP
+gidNumber: $ID
+objectClass: posixGroup
+objectClass: top
+
+add cn=$SITE,$USERBASE
+cn: $SITE
+uidNumber: $ID
+gidNumber: $HTTPD_USERS_GID
+homeDirectory: $DIR
+objectClass: posixAccount
+objectClass: account
+objectClass: top
+uid: $SCRIPT_USER
+EOF
+fi
+
+if getent passwd | grep $SCRIPT_USER &> /dev/null && getent group | grep $GROUP &> /dev/null; then
+ echo "$SCRIPT_USER and $GROUP created succesfully"
+else
+ echo "User or group creation failed"
+ exit 1
+fi
+
+echo "Setting up permissions"
+# Set up permissions
+sudo chown -R 0:$GROUP "$DIR"
+
+# By default, let the owner have write access, the group have read access
+sudo setfacl -R --set d:u::rwX,d:g::rX,d:o::-,u::rwX,g::rX,o::- "$DIR"
+
+# Give the group write access to htdocs, applications, conf and data
+sudo setfacl -R -m g::rwX,d:g::rwX "$DIR/htdocs" "$DIR/applications" "$DIR/conf" "$DIR/data"
+
+# Give lighttpd read access to the dir itself
+sudo setfacl -m u:$HTTPD_USER:rx "$DIR"
+
+# Allow lighttpd to read anything in htdocs, applications, conf and data
+sudo setfacl -R -m d:u:$HTTPD_USER:rX,u:$HTTPD_USER:rX "$DIR/htdocs" "$DIR/applications" "$DIR/conf" "$DIR/data"
+
+# Allow lighttpd to write new files in logs (but not touch existing or those created by lighttpd)
+sudo setfacl -m u:$HTTPD_USER:rwX "$DIR/logs"
+
+# Give scripts read access to the dir itself
+sudo setfacl -m u:$SCRIPT_USER:rx "$DIR"
+
+# Allow scripts to read anything in applications, htdocs and conf
+sudo setfacl -R -m d:u:$SCRIPT_USER:rX,u:$SCRIPT_USER:rX "$DIR/applications" "$DIR/htdocs" "$DIR/conf"
+
+# Allow scripts to create new files in logs and data (but not touch existing or those created by lighttpd)
+sudo setfacl -m u:$SCRIPT_USER:rwX "$DIR/logs" "$DIR/data"
+
+# Temp, chown existing log files
+sudo sh -c "chown -R $SCRIPT_USER \"$DIR\"/logs/php.log* \"$DIR\"/logs/wipi.log*"
+sudo sh -c "chown -R $HTTPD_USER \"$DIR\"/logs/access.log*"
+
+# Now, set the error_log setting in php.ini. This ensures each domein will have
+# a separate logfile for errors, since lighttpd only supports a single error
+# log (When error_log is not set, error messages will go to lighttpd's log
+# automatically).
+
+echo Updating `basename $PHP_CONFIG`
+sudo sed -i "s#^error_log *=.*#error_log = $DIR/$PHP_ERRORLOG#" "$DIR/$PHP_CONFIG"
+sudo update-php.ini
+
+
+# Done!
+echo "Done!"
+echo "Now add human users to $GROUP."
+echo "Also add this site to /usr/local/sbin/spawn-fcgi.sh and enable"
+echo "fcgi in lighttpd if dynamic content is required."
--- /dev/null
+#!/bin/sh
+
+# This script will merge the main php.ini with local and site specific
+# additions into a site specific php.ini.
+
+BASE=/etc/php5/cgi/php.ini
+LOCAL=/etc/php5/cgi/php.ini.local
+SITES=/data/www/*
+CONFIN=conf/php.ini.override
+CONFOUT=conf/php.ini
+
+for SITE in $SITES; do
+ IN=$SITE/$CONFIN
+ OUT=$SITE/$CONFOUT
+ if [ \! -r $IN ]; then
+ continue;
+ fi
+ echo "Updating $OUT"
+
+ cat > $OUT <<EOF
+;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
+;
+; This file is autogenerated by $0
+;
+; Do NOT edit this file directly.
+;
+; You should instead edit $IN (for site-specific config) or $LOCAL (for global
+; config) and run $0 afterwards.
+;
+;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
+
+
+;;; Begin included $BASE (this is the default config from php) ;;;
+
+EOF
+
+ cat $BASE >> $OUT
+ echo -e "\n;;; End included $BASE ;;;\n" >> $OUT
+ echo -e "\n;;; Begin included $LOCAL (these are global config changes) ;;;\n" >> $OUT
+ cat $LOCAL >> $OUT
+ echo -e "\n;;; End included $LOCAL ;;;\n" >> $OUT
+ echo -e "\n;;; Begin included $IN (these are config changes specific to this site) ;;;\n" >> $OUT
+ cat $IN >> $OUT
+ echo -e "\n;;; End included $IN ;;;\n" >> $OUT
+done
--- /dev/null
+#!/usr/bin/env python
+#
+# An example CGI script to export multiple hgweb repos, edit as necessary
+
+# adjust python path if not a system-wide install:
+#import sys
+#sys.path.insert(0, "/path/to/python/lib")
+
+# enable importing on demand to reduce startup time
+from mercurial import demandimport; demandimport.enable()
+
+# Uncomment to send python tracebacks to the browser if an error occurs:
+#import cgitb
+#cgitb.enable()
+
+# If you'd like to serve pages with UTF-8 instead of your default
+# locale charset, you can do so by uncommenting the following lines.
+# Note that this will cause your .hgrc files to be interpreted in
+# UTF-8 and all your repo files to be displayed using UTF-8.
+#
+#import os
+#os.environ["HGENCODING"] = "UTF-8"
+
+from mercurial.hgweb.hgwebdir_mod import hgwebdir
+import mercurial.hgweb.wsgicgi as wsgicgi
+
+# The config file looks like this. You can have paths to individual
+# repos, collections of repos in a directory tree, or both.
+#
+# [paths]
+# virtual/path = /real/path
+# virtual/path = /real/path
+#
+# [collections]
+# /prefix/to/strip/off = /root/of/tree/full/of/repos
+#
+# collections example: say directory tree /foo contains repos /foo/bar,
+# /foo/quux/baz. Give this config section:
+# [collections]
+# /foo = /foo
+# Then repos will list as bar and quux/baz.
+#
+# Alternatively you can pass a list of ('virtual/path', '/real/path') tuples
+# or use a dictionary with entries like 'virtual/path': '/real/path'
+
+application = hgwebdir('/etc/hgweb.conf')
+wsgicgi.launch(application)