root / pykota / trunk / conf / pykota.conf.sample @ 1357

Revision 1357, 16.9 kB (checked in by jalet, 20 years ago)

ldapcache directive marked as experimental

  • Property svn:eol-style set to native
  • Property svn:keywords set to Author Date Id Revision
Line 
1# PyKota sample configuration file
2#
3# Copy this file into the /etc/pykota/ directory
4# under the name /etc/pykota/pykota.conf
5#
6# PyKota - Print Quotas for CUPS and LPRng
7#
8# (c) 2003-2004 Jerome Alet <alet@librelogiciel.com>
9# This program is free software; you can redistribute it and/or modify
10# it under the terms of the GNU General Public License as published by
11# the Free Software Foundation; either version 2 of the License, or
12# (at your option) any later version.
13#
14# This program is distributed in the hope that it will be useful,
15# but WITHOUT ANY WARRANTY; without even the implied warranty of
16# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
17# GNU General Public License for more details.
18#
19# You should have received a copy of the GNU General Public License
20# along with this program; if not, write to the Free Software
21# Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307, USA.
22#
23# $Id$
24#
25
26[global]
27# Storage backend for quotas
28# only PGStorage (PostgreSQL) and LDAPStorage (OpenLDAP) are supported.
29# MySQL and BerkeleyDB are planned.
30
31# the 'postgresql' value is deprecated, use 'pgstorage' instead.
32storagebackend: pgstorage
33
34# Quota Storage Server hostname (and optional port)
35# e.g. db.example.com:5432
36storageserver: localhost
37
38#
39# name of the Quota Storage Database
40storagename: pykota
41
42#
43# Quota Storage normal user's name and password
44# These two fields contain a username and optional password
45# which may give readonly access to your print quota database.
46#
47# PLEASE ENSURE THAT THIS USER CAN'T WRITE TO YOUR PRINT QUOTA
48# DATABASE, OTHERWISE ANY USER WHO COULD READ THIS CONFIGURATION
49# FILE COULD CHANGE HIS PRINT QUOTA.
50#
51storageuser: pykotauser
52# storageuserpw: Comment out if unused, or set to Quota Storage user password
53
54# Should the database caching mechanism be enabled or not ?
55# If unset, caching is disabled. Possible values Y/N/YES/NO
56# caching mechanism works with both PostgreSQL and OpenLDAP backends
57# but may be really interesting only with OpenLDAP.
58#
59# ACTIVATING CACHE MAY CAUSE PRECISION PROBLEMS IN PRINT ACCOUNTING
60# IF AN USER PRINTS ON SEVERAL PRINTERS AT THE SAME TIME.
61# YOU MAY FIND IT INTERESTING ANYWAY, ESPECIALLY FOR LDAP.
62#
63# FYI, I ALWAYS SET IT TO YES !
64#
65storagecaching: No
66
67# Should full job history be disabled ?
68# If unset or set to No, full job history is kept in the database.
69# This will be useful in the future when the report generator
70# will be written.
71# Disabling the job history can be useful with heavily loaded
72# LDAP servers, to not make the LDAP tree grow out of control.
73# Disabling the job history with the PostgreSQL backend works too
74# but it's probably less useful than with LDAP.
75disablehistory: No
76
77# LDAP example, uncomment and adapt it to your own configuration :
78#storagebackend: ldapstorage
79#storageserver: ldap://ldap.librelogiciel.com:389
80#storagename: dc=librelogiciel,dc=com
81#storageuser: cn=notadmin,dc=librelogiciel,dc=com
82#storageuserpw: abc.123
83#
84# Here we define some helpers to know where
85# to plug into an existing LDAP directory
86#userbase: ou=People,dc=librelogiciel,dc=com
87#userrdn: uid
88#balancebase: ou=People,dc=librelogiciel,dc=com
89#balancerdn: uid
90#groupbase: ou=Groups,dc=librelogiciel,dc=com
91#grouprdn: cn
92#printerbase: ou=Printers,ou=PyKota,dc=librelogiciel,dc=com
93#printerrdn: cn
94#jobbase: ou=Jobs,ou=PyKota,dc=librelogiciel,dc=com
95#userquotabase: ou=UQuotas,ou=PyKota,dc=librelogiciel,dc=com
96#groupquotabase: ou=GQuotas,ou=PyKota,dc=librelogiciel,dc=com
97#lastjobbase: ou=LastJobs,ou=PyKota,dc=librelogiciel,dc=com
98#
99# How to create new accounts and groups
100# authorized values are "below" and "attach(objectclass name)"
101#
102# "below" creates the new accounts/groups as standalone entries
103# below the above defined 'userbase' ou
104#
105# attach(objectclass name) tries to find some existing user/group
106# using the above defined 'userrdn' or 'grouprdn' and 'userbase'
107# 'groupbase', and attach the PyKota specific entries to it.
108#
109# a possible value:  newuser: attach(posixAccount)
110#newuser : below
111#newgroup : below
112#
113# LDAP attribute which stores the user's email address
114#usermail : mail
115
116#
117# Choose what attribute contains the list of group members
118# common values are : memberUid, uniqueMember, member
119#groupmembers: memberUid
120
121# Activate low-level LDAP cache yes/no
122# Nothing to do with "storagecaching" which is higher level
123# and database independant.
124# This saves some search queries and may help with heavily
125# loaded LDAP servers.
126# This is EXPERIMENTAL.
127ldapcache: no
128
129# Where to log ?
130# supported values : stderr, system (system means syslog, but don't use 'syslog' here)
131# if the value is not set then the default SYSTEM applies.
132logger: system
133
134# Enable debugging ? Put YES or NO there.
135# From now on, YES is the default in this sample
136# configuration file, so that debugging is activated
137# when configuring PyKota. After all works, just
138# put NO instead to save some disk space in your
139# logs.
140# Actually only database queries are logged.
141debug : Yes
142
143# Mail server to use to warn users
144# If the value is not set then localhost is used.
145smtpserver: localhost
146
147# Email domain
148# If the value is not set, and the mail attribute for the user
149# is not set in the PyKota storage, be it LDAP (see usermail directive
150# above) or PostgreSQL, then email messages are sent to
151# username@smtpserver
152#
153# If the value is set, then email messages are sent to
154# username@maildomain using the SMTP server defined above
155#
156# Set the appropriate value below, example.com set as per RFC2606.
157maildomain: example.com
158
159# Should we force usernames to be all lowercase when printing ?
160# Default is No.
161# This is a global option only.
162# Some people reported that WinXP sends mixed case usernames
163# setting 'utolower: Yes' solves the problem.
164# Of course you have to user lowercase only when adding
165# users with edpykota, because ALL database accesses are
166# still case sensitive.
167#
168# If utolower is Yes, the usernames received from the printing
169# system is converted to lowercase at the start of the cupspykota
170# backend or of the pykota filter.
171#
172# If utolower is No, which is the default, strict case checking
173# is done, this means that users 'Jerome' and 'jerome' are
174# different. Printer and groups names are ALWAYS case sensitive.
175utolower: No
176
177# What is the accounting backend to use
178#
179# supported values :
180#
181#    - querying : asks the printer for its lifetime page counter
182#                 via either SNMP, AppleTalk, or any external
183#                 command. This method is the method used by
184#                 default in PyKota since its beginning.
185#
186#    - external : delegates the job's size computation to any
187#                 external command of your choice. A stupid and
188#                 completely unreliable example, but which
189#                 shows what this command may be is :
190#
191#                   accounter: external(/bin/grep -c showpage)
192#
193#                 Another one, which should work with all DSC
194#                 compliant Postscript files :
195#
196#                   accounter: external(/bin/grep -c "%%Page:")
197#
198#    - stupid : counts the occurences of the 'showpage' postscript
199#               statement in the document to be printed.
200#               THIS IS NOT RELIABLE. This is just to serve as
201#               an example on how to implement your own accounting
202#               method.
203#
204# This value can be set either globally or on a per printer basis
205# If both are defined, the printer option has priority.
206# if not set it defaults to 'querying'.
207#
208# A script which seems to be accurate, copy it from the
209# untested/postscript directory to another place.
210# accounter: external(/usr/local/bin/pagecount.sh)
211# WARNING : it may not work when multiple copies are asked.
212#           this breaks ghostscript, I don't know why yet.
213#
214# default value
215accounter: querying
216
217# Print Quota administrator
218# These values can be set either globally or per printer or both.
219# If both are defined, the printer option has priority.
220# If these values are not set, the default admin root
221# and the default adminmail root@localhost are used.
222admin: John Doe
223adminmail: root@localhost
224
225#
226# Who should we send an email to in case a quota is reached ?
227# possible values are : DevNull, User, Admin, Both, External(some command)
228# The Both value means that the User and the Admin will receive
229# an email message.
230# The DevNull value means no email message will be sent.
231# This value can be set either globally or per printer or both.
232# If both are defined, the printer option has priority.
233# If the value is not set, then the default BOTH applies.
234#
235#   Format of the external syntax :
236#
237#       mailto: external(/usr/bin/mycommand >/dev/null)
238#
239#   You can use :
240#
241#       '%(action)s'            will contain either WARN or DENY
242#       '%(username)s'          will contain the user's name
243#       '%(printername)s'       will contain the printer's name
244#       '%(email)s'             will contain the user's email address
245#       '%(message)s'           will contain the message if you want
246#                               to use it.
247#
248#   On your command line, to pass arguments to your command.
249#   Example :
250#
251#       mailto: external(/usr/bin/callpager %(username)s "Quota problem on %(printername)s" >/dev/null)
252#
253#   To automatically send a WinPopup message (this may only work with a PDC,
254#   here the same machine does Samba as PDC + CUPS) :
255#
256#       mailto: external(echo "%(message)s"  | /usr/bin/iconv --to-code utf-8 --from-code iso-8859-15 | /usr/bin/smbclient -M "%(username)s" 2>&1 >/dev/null)
257#
258#   NB : I use ISO-8859-15, but Windows expects UTF-8, so we pipe the message
259#        into iconv before sending it to the Windows user.
260#
261# or more simply :
262#
263#       mailto: external(/usr/share/pykota/mailandpopup.sh %(username)s %(printername)s "%(email)s" "%(message)s" 2>&1 >/dev/null)
264#
265#   NB : The mailandpopup.sh shell script is now included in PyKota
266#
267#   NB : in ANY case, don't forget to redirect your command's standard output
268#        somewhere (e.g. >/dev/null) so that there's no perturbation to the
269#        underlying layer (filter or backend)
270#
271mailto: both
272
273#
274# Grace delay in days
275# This value can be set either globally or per printer or both.
276# If both are defined, the printer option has priority.
277# If the value is not set then the default seven (7) days applies.
278gracedelay: 7
279
280#
281# Poor man's threshold
282# If account balance reaches below this amount,
283# a warning message is sent by email
284#
285# If unset, default poor man's threshold is 1.0.
286# This option can only appear in the global section
287poorman: 2.0
288
289# Poor man's warning message
290# The warning message that is sent if the "poorman" value is reached
291# Again this must appear in the global section
292poorwarn: Your Print Quota account balance is low.
293 Soon you'll not be allowed to print anymore.
294
295# Soft limit reached warning message
296# The warning message that is sent if the soft quota limit is reached
297# May appear either globally or on a per-printer basis
298softwarn: Your Print Quota Soft Limit is reached.
299 This means that you may still be allowed to print for some
300 time, but you must contact your administrator to purchase
301 more print quota.
302 
303# Hard limit reached error message
304# The error message that is sent if the hard quota limit is reached
305# May appear either globally or on a per-printer basis
306hardwarn: Your Print Quota Hard Limit is reached.
307 This means that you are not allowed to print anymore.
308 Please contact your administrator at root@localhost
309 as soon as possible to solve the problem.
310
311# one section per printer, or no other section at all if all options
312# are defined globally.
313# Each section's name must be the same as the printer's queue name as defined
314# in your printing system, be it CUPS or LPRng.
315# If you don't want any special printer section, just comment out
316# the line below so that following options are global.
317[hpmarketing]
318
319# How to query the hpmarketing printer for its page counter.
320# THIS IS ONLY USED IF YOU HAVE SET 'accounter' TO 'querying'
321# JUST COMMENT IT OUT IF YOU USE ANY OTHER ACCOUNTING METHOD.
322# (it would be ignored anyway)
323#
324# In the lines below "%(printer)s" is automatically replaced
325# at run time with your printer's Fully Qualified Domain Name
326# e.g. myprinter.example.com
327#
328# Only snmp(community, oid) and external(command) are supported
329#
330# Example :
331#     requester: external(/usr/bin/snmpget -v1 -c public -Ov %(printer)s mib-2.43.10.2.1.4.1.1 | cut -f 2,2 -d " ")
332# and :
333#     requester: snmp(public, mib-2.43.10.2.1.4.1.1)
334# are equivalent
335#
336#################################################
337# NB : the 'snmp()' requester is now deprecated #
338# because it has some accuracy problems.        #
339# please use 'external()' instead.              #
340#################################################
341#
342# Another untested example, using npadmin :
343#     requester: external(/usr/bin/npadmin --pagecount %(printer)s)
344#
345# Another example, for AppleTalk printers which works fine :
346# (You may need the pap CUPS backend installed, and copy the
347# pagecount.ps file from untested/netatalk into /etc or any
348# appropriate location)
349#     requester: external(/usr/share/pykota/papwaitprinter.sh "MyPrinter:LaserWriter@*" && /usr/bin/pap -p "MyPrinter:LaserWriter@*" /usr/share/pykota/pagecount.ps  2>/dev/null | /bin/grep -v status | /bin/grep -v Connect | /usr/bin/tail -1)
350#
351# An example for parallel printers like the HP Laserjet 5MP :
352#
353#     requester: external(/bin/cat /usr/share/pykota/pagecount.pjl >/dev/lp0 && /usr/bin/head -2 </dev/lp0 | /usr/bin/tail -1)
354#
355#
356# This value can be set either globally or per printer or both.
357# If both are defined, the printer option has priority.
358#
359# NB : The SNMP oid mib-2.43.10.2.1.4.1.1 works on HP Laserjet Printers, but it may
360#      be different with other brands, refer to your printer's documentation
361#      for details. Also you may have to specify -v2c or -v3 depending on your
362#      printer's support for different versions of the SNMP specification.
363#
364#
365# Some examples and comments provided by Bob Martel from csuohio.edu
366#
367# For several printers I could not get the page count using snmpget.  I
368# resorted to snmpwalk:
369#
370# requester: external(/opt/local/net-snmp/bin/snmpwalk -v 1 -Cc -c public %(printer)s | grep mib-2.43.10.2.1.4.1.1 | cut -d " " -f4)
371#
372# The last example is still more ugly, some of the printers only provided
373# their counters without names, but at least always on the same line:
374#
375# requester: external(/opt/local/net-snmp/bin/snmpwalk -v 1 -Cc -c public -Ov %(printer)s | grep Counter32 | tail -2 | head -1 | cut -d " " -f2)
376#
377#
378# An example using netcat and a preformatted PJL job which you can find
379# in the untested/pjl directory, which is sent to a JetDirect print
380# server on port 9100 :
381#
382# requester: external(/bin/nc -w 2 %(printer)s 9100 </usr/share/pykota/pagecount.pjl | /usr/bin/tail -2)
383#
384#
385# An example using the contributed pagecount.pl script which does
386# the same as above, but should work on more printers :
387#
388# requester: external(/usr/share/pykota/pagecount.pl %(printer)s 9100)
389#
390#
391# WARNING : In any case, when using an external requester, please test the command line outside
392#           of PyKota before. This will save you some headaches in case it doesn't work as expected.
393#
394# The waitprinter.sh is there to wait until the printer is idle again.
395# This should prevent a job to be sent to the printer while another one is
396# not yet finished (not all pages are printed, but the complete job is in
397# the printer)
398requester: external(/usr/share/pykota/waitprinter.sh %(printer)s && /usr/bin/snmpget -v1 -c public -Ov %(printer)s mib-2.43.10.2.1.4.1.1 | cut -f 2,2 -d " ")
399
400# Default policy for inexistant users (e.g. root)
401# either allow or deny or external(some command here)
402# This value can be set either globally or per printer or both.
403# If both are defined, the printer option has priority.
404# If the value is not set then the default policy DENY applies.
405# ATTENTION :
406#     Before 1.04 the default value was ALLOW, but unknown users
407#     allowed to print causes accuracy problems : their jobs are
408#     charged to the next person who prints on the same printer.
409# There's no policy wrt inexistant groups, they are ignored.
410#
411# external policy can be used to launch any external command of your choice,
412# for example to automatically add the user to the quota storage
413# if he is unknown. Example :
414#
415#       policy: external(/usr/bin/edpykota --add --printer %(printername)s --softlimit 50 --hardlimit 60 %(username)s >/dev/null)
416#
417# Of course you can launch any command of your choice with this, e.g. :
418#
419#       policy: external(/usr/local/bin/myadminscript.sh %(username)s >/dev/null)
420
421# You can use :
422#
423#       '%(username)s'          will contain the user's name
424#       '%(printername)s'       will contain the printer's name
425#
426#   On your command line, to pass arguments to your command.
427#
428#   NB : Don't forget to redirect your command's standard output somewhere
429#        (e.g. >/dev/null) so that there's no perturbation to the underlying
430#        layer (filter or backend)
431#
432# If the user still doesn't exist after external policy command was
433# launched (the external command didn't add it), or if an error occured
434# during the execution of the external policy command, the job is rejected.
435#
436policy: deny
Note: See TracBrowser for help on using the browser.