# MonkeySphere server configuration file.
-# GPG home directory for server
-#GNUPGHOME=/etc/monkeysphere/gnupg
+# This is an sh-style shell configuration file. Variable names should
+# be separated from their assignements by a single '=' and no spaces.
+# Environement variables with the same names as these variables but
+# prefeced by "MONKEYSPHERE_" will take precedence over the values
+# specified here.
-# GPG keyserver to search for keys
+# GPG keyserver to search for keys.
#KEYSERVER=subkeys.pgp.net
-# Required key capabilities
-# Must be quoted, lowercase, space-seperated list of the following:
-# e = encrypt
-# s = sign
-# c = certify
-# a = authentication
-#REQUIRED_KEY_CAPABILITY="e a"
+# Path to authorized_user_ids file to process to create
+# authorized_keys file. '%h' will be replaced by the home directory
+# of the user, and %u will be replaced by the username of the user.
+# For purely admin-controlled authorized_user_ids, you might put them
+# in /etc/monkeysphere/authorized_user_ids/%u
+#AUTHORIZED_USER_IDS="%h/.config/monkeysphere/authorized_user_ids"
# Whether to add user controlled authorized_keys file to
# monkeysphere-generated authorized_keys file. Should be path to file
-# where '%h' will be substituted for the user's home directory.
-#USER_CONTROLLED_AUTHORIZED_KEYS=%h/.ssh/authorized_keys
+# where '%h' will be replaced by the home directory of the user or
+# '%u' by the username. To not add any user-controlled file, put "-"
+# FIXME: this usage of "-" contravenes the normal convention where "-"
+# means standard in/out. Why not use "none" or "" instead?
+#RAW_AUTHORIZED_KEYS="%h/.ssh/authorized_keys"
+
+# User who controls the monkeysphere authentication keyring.
+#MONKEYSPHERE_USER=monkeysphere