.\" Automatically generated by Pod::Man v1.37, Pod::Parser v1.32 .\" .\" Standard preamble: .\" ======================================================================== .de Sh \" Subsection heading .br .if t .Sp .ne 5 .PP \fB\\$1\fR .PP .. .de Sp \" Vertical space (when we can't use .PP) .if t .sp .5v .if n .sp .. .de Vb \" Begin verbatim text .ft CW .nf .ne \\$1 .. .de Ve \" End verbatim text .ft R .fi .. .\" Set up some character translations and predefined strings. \*(-- will .\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left .\" double quote, and \*(R" will give a right double quote. \*(C+ will .\" give a nicer C++. Capital omega is used to do unbreakable dashes and .\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, .\" nothing in troff, for use with C<>. .tr \(*W- .ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' .ie n \{\ . ds -- \(*W- . ds PI pi . if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch . if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch . ds L" "" . ds R" "" . ds C` "" . ds C' "" 'br\} .el\{\ . ds -- \|\(em\| . ds PI \(*p . ds L" `` . ds R" '' 'br\} .\" .\" If the F register is turned on, we'll generate index entries on stderr for .\" titles (.TH), headers (.SH), subsections (.Sh), items (.Ip), and index .\" entries marked with X<> in POD. Of course, you'll have to process the .\" output yourself in some meaningful fashion. .if \nF \{\ . de IX . tm Index:\\$1\t\\n%\t"\\$2" .. . nr % 0 . rr F .\} .\" .\" For nroff, turn off justification. Always turn off hyphenation; it makes .\" way too many mistakes in technical documents. .hy 0 .if n .na .\" .\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). .\" Fear. Run. Save yourself. No user-serviceable parts. . \" fudge factors for nroff and troff .if n \{\ . ds #H 0 . ds #V .8m . ds #F .3m . ds #[ \f1 . ds #] \fP .\} .if t \{\ . ds #H ((1u-(\\\\n(.fu%2u))*.13m) . ds #V .6m . ds #F 0 . ds #[ \& . ds #] \& .\} . \" simple accents for nroff and troff .if n \{\ . ds ' \& . ds ` \& . ds ^ \& . ds , \& . ds ~ ~ . ds / .\} .if t \{\ . ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" . ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' . ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' . ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' . ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' . ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' .\} . \" troff and (daisy-wheel) nroff accents .ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' .ds 8 \h'\*(#H'\(*b\h'-\*(#H' .ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] .ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' .ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' .ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] .ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] .ds ae a\h'-(\w'a'u*4/10)'e .ds Ae A\h'-(\w'A'u*4/10)'E . \" corrections for vroff .if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' .if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' . \" for low resolution devices (crt and lpr) .if \n(.H>23 .if \n(.V>19 \ \{\ . ds : e . ds 8 ss . ds o a . ds d- d\h'-1'\(ga . ds D- D\h'-1'\(hy . ds th \o'bp' . ds Th \o'LP' . ds ae ae . ds Ae AE .\} .rm #[ #] #H #V #F C .\" ======================================================================== .\" .IX Title "NNRPD 8" .TH NNRPD 8 "2008-04-06" "INN 2.4.5" "InterNetNews Documentation" .SH "NAME" nnrpd \- NNTP server for reader clients .SH "SYNOPSIS" .IX Header "SYNOPSIS" \&\fBnnrpd\fR [\fB\-DfnoSt\fR] [\fB\-b\fR \fIaddress\fR] [\fB\-c\fR \fIconfigfile\fR] [\fB\-g\fR \fIshadowgroup\fR>] [\fB\-i\fR \fIinitial\fR] [\fB\-I\fR \fIinstance\fR] [\fB\-p\fR \fIport\fR] [\fB\-P\fR \fIprefork\fR] [\fB\-r\fR \fIreason\fR] [\fB\-s\fR \fIpadding\fR] .SH "DESCRIPTION" .IX Header "DESCRIPTION" \&\fBnnrpd\fR is an \s-1NNTP\s0 server for newsreaders. It accepts commands on its standard input and responds on its standard output. It is normally invoked by \fIinnd\fR\|(8) with those descriptors attached to a remote client connection. \fBnnrpd\fR also supports running as a standalone daemon. .PP Unlike \fIinnd\fR\|(8) \fBnnrpd\fR supports all \s-1NNTP\s0 commands for user-oriented reading and posting. \fBnnrpd\fR uses the \fIreaders.conf\fR file to control who is authorized to access the Usenet database. .PP On exit, \fBnnrpd\fR will report usage statistics through \fIsyslog\fR\|(3). .PP \&\fBnnrpd\fR only reads config files (both \fIreaders.conf\fR and \fIinn.conf\fR) when it is spawned. You can therefore never change the behavior of a client that's already connected. If \fBnnrpd\fR is run from \fBinnd\fR (the default) or from \fIinetd\fR\|(8), \fIxinetd\fR\|(8), or some equivalent, a new \fBnnrpd\fR process is spawned for every connection and therefore any changes to configuration files will be immediately effective for all new connections. If you are instead running \fBnnrpd\fR with the \fB\-D\fR option, any configuration changes won't take effect until \fBnnrpd\fR is restarted. .PP The \fIinn.conf\fR setting \fInnrpdflags\fR can be used to pass any of the options below to instances of \fBnnrpd\fR that are spawned directly from \&\fBinnd\fR. Many options only make sense when \fB\-D\fR is used, so these options should not be used with \fInnrpdflags\fR. See also the discussion of \fInnrpdflags\fR in \fIinn.conf\fR\|(5). .PP When \fInnrpdloadlimit\fR in \fIinn.conf\fR is not 0, it will also reject connections if the load average is greater than that value (typically 16). \&\fBnnrpd\fR can also prevent high-volume posters from abusing your resources. See the discussion of exponential backoff in \fIinn.conf\fR\|(5). .SH "OPTIONS" .IX Header "OPTIONS" .IP "\fB\-b\fR \fIaddress\fR" 4 .IX Item "-b address" The \fB\-b\fR parameter instructs \fBnnrpd\fR to bind to the specified \s-1IP\s0 address when started as a standalone daemon using the \fB\-D\fR flag. This has to be a valid IPv4 or IPv6 address belonging to an interface of the local host. It can also be ::0 (although the default is 0.0.0.0 if unspecified). .IP "\fB\-c\fR \fIconfigfile\fR" 4 .IX Item "-c configfile" By default, \fBnnrpd\fR reads the \fIreaders.conf\fR to determine how to authenticate connections. The \fB\-c\fR flag specifies an alternate file for this purpose. If the file name isn't fully qualified, it is taken to be relative to \fIpathetc\fR in \fIinn.conf\fR (this is useful to have several instances of \fBnnrpd\fR running on different ports or \s-1IP\s0 addresses with different settings.) .IP "\fB\-D\fR" 4 .IX Item "-D" If specified, this parameter causes \fBnnrpd\fR to operate as a daemon. That is, it detaches itself and runs in the background, forking a process for every connection. By default \fBnnrpd\fR listens on the \s-1NNTP\s0 port (119), so either \fIinnd\fR\|(8) has to be started on another port or \fBnnrpd\fR \fB\-p\fR parameter. Note that with this parameter, \&\fBnnrpd\fR continues running until killed. This means that it reads \&\fIinn.conf\fR once on startup and never again until restarted. \fBnnrpd\fR should therefore be restarted if inn.conf is changed. .Sp When started in daemon mode, \fBnnrpd\fR will write its \s-1PID\s0 into a file in the \fIpathrun\fR directory. The file will be named \fInnrpd\-%d.pid\fR, where \&\f(CW%d\fR is replaced with the port that \fBnnrpd\fR is configured to listen on (119 unless the \fB\-p\fR option is given). .IP "\fB\-f\fR" 4 .IX Item "-f" If specified, \fBnnrpd\fR does not detach itself and runs in the foreground when started as a standalone daemon using the \fB\-D\fR flag. .IP "\fB\-g\fR \fIshadowgroup\fR" 4 .IX Item "-g shadowgroup" On systems that have a shadow password file, \fBnnrpd\fR tries to add the group \fIshadow\fR as a supplementary group if it is running in standalone mode. On many systems, members of that group have read permission for the shadow password file. The \fB\-g\fR parameter instructs \&\fBnnrpd\fR to try to add the named group as a supplementary group on shadow systems instead of \fIshadow\fR. This only works if \&\f(CW\*(C`HAVE_GETSPNAM\*(C'\fR in \fIinclude/config.h\fR is defined and \fBnnrpd\fR is running in standalone mode since this call only works when \fBnnrpd\fR is started as root. .IP "\fB\-i\fR \fIinitial\fR" 4 .IX Item "-i initial" Specify an initial command to \fBnnrpd\fR. When used, \fIinitial\fR is taken as if it were the first command received by \fBnnrpd\fR. .IP "\fB\-I\fR \fIinstance\fR" 4 .IX Item "-I instance" If specified \fIinstance\fR is used as an additional static portion within MessageIDs generated by \fBnnrpd\fR; typically this option would be used where a cluster of machines exist with the same virtual hostname and must be disambiguated during posts. .IP "\fB\-n\fR" 4 .IX Item "-n" The \fB\-n\fR flag turns off resolution of \s-1IP\s0 addresses to names. If you only use IP-based restrictions in \fIreaders.conf\fR and can handle \s-1IP\s0 addresses in your logs, using this flag may result in some additional speed. .IP "\fB\-o\fR" 4 .IX Item "-o" The \fB\-o\fR flag causes all articles to be spooled instead of sending them to \fIinnd\fR\|(8). \fBrnews\fR with the \fB\-U\fR flag should be invoked from cron on a regular basis to take care of these articles. This flag is useful if \fIinnd\fR\|(8) in accepting articles and \fBnnrpd\fR is started standalone or using \fIinetd\fR\|(8). .IP "\fB\-p\fR \fIport\fR" 4 .IX Item "-p port" The \fB\-p\fR parameter instructs \fBnnrpd\fR to listen on \fIport\fR when started as a standalone daemon using the \fB\-D\fR flag. .IP "\fB\-P\fR \fIprefork\fR" 4 .IX Item "-P prefork" The \fB\-P\fR parameter instructs \fBnnrpd\fR to prefork \fIprefork\fR children awaiting connections when started as a standalone daemon using the \&\fB\-D\fR flag. .IP "\fB\-r\fR \fIreason\fR" 4 .IX Item "-r reason" If the \fB\-r\fR flag is used, then \fBnnrpd\fR will reject the incoming connection giving \fIreason\fR as the text. This flag is used by \fIinnd\fR\|(8) when it is paused or throttled. .IP "\fB\-s\fR \fIpadding\fR" 4 .IX Item "-s padding" As each command is received, \fBnnrpd\fR tries to change its \f(CW\*(C`argv\*(C'\fR array so that \fIps\fR\|(1) will print out the command being executed. To get a full display, the \fB\-s\fR flag may be used with a long string as its argument, which will be overwritten when the program changes its title. .IP "\fB\-S\fR" 4 .IX Item "-S" If specified, \fBnnrpd\fR will start a negotiation for \s-1SSL\s0 session as soon as connected. To use this flag, \f(CW\*(C`\-\-with\-openssl\*(C'\fR must have been specified at \f(CW\*(C`configure\*(C'\fR time. .IP "\fB\-t\fR" 4 .IX Item "-t" If the \fB\-t\fR flag is used then all client commands and initial responses will be traced by reporting them in syslog. This flag is set by \fIinnd\fR\|(8) under the control of the \fIctlinnd\fR\|(8) \f(CW\*(C`trace\*(C'\fR command, and is toggled upon receipt of a \f(CW\*(C`SIGHUP\*(C'\fR; see \fIsignal\fR\|(2). .SH "SSL SUPPORT" .IX Header "SSL SUPPORT" If \s-1INN\s0 is built with \f(CW\*(C`\-\-with\-openssl\*(C'\fR, \fBnnrpd\fR will support news reading over \s-1TLS\s0 (also known as \s-1SSL\s0). For clients that use the \s-1STARTTLS\s0 command, no special configuration is needed beyond creating a \s-1TLS/SSL\s0 certificate for the server. You should do this in exactly the same way that you would generate a certificate for a web server. .PP If you're happy with a self-signed certificate (which will generate warnings with some news reader clients), you can create and install one in the default path by running \f(CW\*(C`make cert\*(C'\fR after \f(CW\*(C`make install\*(C'\fR when installing \s-1INN\s0, or by running the following commands: .PP .Vb 6 \& openssl req \-new \-x509 \-nodes \-out /usr/local/news/lib/cert.pem \e \& \-days 366 \-keyout /usr/local/news/lib/key.pem \& chown news:news /usr/local/news/lib/cert.pem \& chmod 640 /usr/local/news/lib/cert.pem \& chown news:news /usr/local/news/lib/key.pem \& chmod 600 /usr/local/news/lib/key.pem .Ve .PP Replace the paths with something appropriate to your \s-1INN\s0 installation. This will create a self-signed certificate that will expire in a year. The \fBopenssl\fR program will ask you a variety of questions about your organization. Enter the fully qualified domain name of the server as the name the certificate is for. .PP Most news clients currently do not use the \s-1STARTTLS\s0 command, however, and instead expect to connect to a separate port (563) and start an \s-1SSL\s0 negotiation immediately. \fBinnd\fR does not, however, know how to listen for connections to that port and then spawn \fBnnrpd\fR the way that it does for regular reader connections. You will therefore need to arrange for \&\fBnnrpd\fR to listen on that port through some other means. This can be done with the \fB\-D\fR flag (and \f(CW\*(C`\-P 563\*(C'\fR), but the easiest way is probably to add a line like: .PP .Vb 1 \& nntps stream tcp nowait news /usr/lib/news/bin/nnrpd nnrpd \-S .Ve .PP to \fI/etc/inetd.conf\fR or the equivalent on your system and let \fBinetd\fR run \fBnnrpd\fR. (Change the path to \fBnnrpd\fR to match your installation if needed.) You may need to replace \f(CW\*(C`nntps\*(C'\fR with \f(CW563\fR if \f(CW\*(C`nntps\*(C'\fR isn't defined in \fI/etc/services\fR on your system. .SH "PROTOCOL DIFFERENCES" .IX Header "PROTOCOL DIFFERENCES" \&\fBnnrpd\fR implements the \s-1NNTP\s0 commands defined in \s-1RFC\s0 977, with the following differences: .IP "1." 4 The \f(CW\*(C`slave\*(C'\fR command is not implemented. This command has never been fully defined. .IP "2." 4 The \f(CW\*(C`list\*(C'\fR command may be followed by the optional word \f(CW\*(C`active.times\*(C'\fR, \&\f(CW\*(C`distributions\*(C'\fR, \f(CW\*(C`distrib.pats\*(C'\fR, \f(CW\*(C`moderators\*(C'\fR, \f(CW\*(C`newsgroups\*(C'\fR, \&\f(CW\*(C`subscriptions\*(C'\fR, or \f(CW\*(C`Ioverview.fmt\*(C'\fR to get a list of when newsgroups where created, a list of valid distributions, a file specifying default distribution patterns, moderators list, a one-per-line description of the current set of newsgroups, a list of the automatic group subscriptions, or a listing of the \fIoverview.fmt\fR file. .Sp The command \f(CW\*(C`list active\*(C'\fR is equivalent to the \f(CW\*(C`list\*(C'\fR command. This is a common extension. .IP "3." 4 The \f(CW\*(C`xhdr\*(C'\fR, \f(CW\*(C`authinfo user\*(C'\fR and \f(CW\*(C`authinfo pass\*(C'\fR commands are implemented. These are based on the reference Unix implementation. See \&\s-1RFC\s0 2980. .IP "4." 4 A new command, \f(CW\*(C`xpat header range|MessageID pat [morepat...]\*(C'\fR, is provided. The first argument is the case-insensitive name of the header to be searched. The second argument is either an article range or a single Message\-ID, as specified in \s-1RFC\s0 977. The third argument is a \&\f(CW\*(C`uwildmat\*(C'\fR(3)\-style pattern; if there are additional arguments they are joined together separated by a single space to form the complete pattern. This command is similar to the \f(CW\*(C`xhdr\*(C'\fR command. It returns a \f(CW221\fR response code, followed by the text response of all article numbers that match the pattern. .IP "5." 4 The \f(CW\*(C`listgroup group\*(C'\fR command is provided. This is a comment extension. It is equivalent to the \f(CW\*(C`group\*(C'\fR command, except that the reply is a multi-line response containing the list of all article numbers in the group. .IP "6." 4 The \f(CW\*(C`xgtitle [group]\*(C'\fR command is provided. This extension is used by ANU\-News. It returns a \f(CW282\fR reply code, followed by a one-line description of all newsgroups thatmatch the pattern. The default is the current group. .IP "7." 4 The \f(CW\*(C`xover [range]\*(C'\fR command is provided. It returns a \f(CW224\fR reply code, followed by the overview data for the specified range; the default is to return the data for the current article. .IP "8." 4 The \f(CW\*(C`xpath MessageID\*(C'\fR command is provided; see \fIinnd\fR\|(8). .IP "9." 4 The \f(CW\*(C`date\*(C'\fR command is provided; this is based on the draft \s-1NNTP\s0 protocol revision (draft\-ietf\-nntpext\-imp\-04.txt). It returns a one-line response code of \f(CW111\fR followed by the \s-1GMT\s0 date and time on the server in the form \&\f(CW\*(C`YYYYMMDDhhmmss\*(C'\fR. .SH "HISTORY" .IX Header "HISTORY" Written by Rich \f(CW$alz\fR for InterNetNews. Overview support added by Rob Robertston and Rich in January, 1993. Exponential backoff (for posting) added by Dave Hayes in Febuary 1998. .PP $Id: nnrpd.8 7880 2008-06-16 20:37:13Z iulius $ .SH "SEE ALSO" .IX Header "SEE ALSO" \&\fIctlinnd\fR\|(8), \fIinnd\fR\|(8), \fIinn.conf\fR\|(5), \fIsignal\fR\|(2), \fIuwildmat\fR\|(3).