Files
bongo/man/bongo-admin.1
T
2026-07-17 11:34:08 +02:00

115 lines
3.4 KiB
Groff

.TH BONGO-ADMIN 1 "July 2026" "Bongo 0.7.0" "Bongo administration"
.SH NAME
bongo-admin \- administer local Bongo accounts, agents and authentication caches
.SH SYNOPSIS
.B bongo-admin
.B user
.BR add | info | list | password | rename
.RI [ arguments ]
.br
.B bongo-admin
.B ldap-cache
.BR status | extend-all
.RI [ hours ]
.br
.B bongo-admin
.B agent
.BR list | info
.RI [ name ]
.br
.B bongo-admin
.B server
.BR list | info
.SH DESCRIPTION
.B bongo-admin
performs privileged administration of the local Bongo server. It must be
run as root. Commands which change credentials or account names are written
to the authentication log.
.PP
The Bongo 0.7 command intentionally does not accept a password on the command
line. Passwords are read without echo from the controlling terminal so they
do not appear in shell history or the process list.
.SH USER COMMANDS
.TP
.BI "user add " USER
Create a local account without an initial password. Set its password with
.B user password
before allowing password authentication.
.TP
.BI "user info " USER
Show the canonical account name and mailbox path. If
.I USER
is a retained login alias, show that fact as well.
.TP
.B user list
List local Bongo accounts.
.TP
.BI "user password " USER
Read and confirm a new password from the terminal. New passwords require at
least twelve characters and are stored using the configured Argon2 password
hash.
.TP
.BI "user rename " OLD_NAME " " NEW_NAME
Atomically rename an account. Active sessions are disconnected, mailbox and
per-user databases are moved, and the old name remains a login and delivery
alias. Clients using the old name are reported as user tasks so they can be
reconfigured.
.SH LDAP OFFLINE CACHE COMMANDS
.TP
.B ldap-cache status
List cached LDAP credentials, their last verification time, expiry time and
current state.
.TP
.BI "ldap-cache extend-all [" HOURS "]"
Atomically extend all existing LDAP offline credential caches. The default is
48 hours. One invocation is limited to 744 hours. This is an emergency
operation for a known directory outage, not a replacement for restoring LDAP.
.SH AGENT AND SERVER COMMANDS
.TP
.B agent list
Read the live manager configuration from the Store and list configured agents,
their enabled state and startup priority.
.TP
.BI "agent info " NAME
Show the manager configuration for one agent.
.TP
.BR "server list" , " server info"
Show the local server hostname, Bongo version, state directory and manager
status. Bongo 0.7 has one local managed server, so both forms report the same
server.
.SH COMPATIBILITY COMMANDS
The historical aliases
.BR user-add ,
.BR user-info ,
.BR user-list ,
.BR user-passwd ,
.BR agent-list ,
.BR agent-info ,
.BR server-list
and
.BR server-info
are accepted, including their two-letter aliases.
.PP
The former MDB commands
.BR import ,
.BR setup-genschema ,
.BR setup-mdb ,
.BR setup-rights ,
.BR agent-delete ,
.BR agent-modify ,
.BR user-delete
and arbitrary
.B user-modify
were tied to the removed MDB directory and are not emulated. Initial setup,
certificate generation and basic account creation are provided by
.BR bongo-config (1).
.SH SECURITY
Do not pass secrets as command arguments or redirect them from a shared file.
Use service-scoped app passwords for IMAP, POP3, SMTP and ManageSieve when
two-factor authentication is enabled. Renames and LDAP cache extensions
should be reviewed in the authentication log.
.SH SEE ALSO
.BR bongo-config (1),
.BR bongo-manager (1),
.BR bongoagents (8)