Skip to content

Set-PveAccessDomains

Update authentication server settings.

API: PUT /access/domains/{realm}, Proxmox VE API viewer

Set-PveAccessDomains
[-PveTicket <PveTicket>]
[-AcrValues <string>]
[-Audiences <string>]
[-Autocreate <bool>]
[-BaseDn <string>]
[-BindDn <string>]
[-Capath <string>]
[-CaseSensitive <bool>]
[-Cert <string>]
[-Certkey <string>]
[-CheckConnection <bool>]
[-ClientId <string>]
[-ClientKey <string>]
[-Comment <string>]
[-Default <bool>]
[-Delete <string>]
[-Digest <string>]
[-Domain <string>]
[-Filter <string>]
[-GroupClasses <string>]
[-GroupDn <string>]
[-GroupFilter <string>]
[-GroupNameAttr <string>]
[-GroupsAutocreate <bool>]
[-GroupsClaim <string>]
[-GroupsOverwrite <bool>]
[-IssuerUrl <string>]
[-Mode <string>]
[-Password <SecureString>]
[-Port <int>]
[-Prompt <string>]
[-QueryUserinfo <bool>]
-Realm <string>
[-Scopes <string>]
[-Secure <bool>]
[-Server1 <string>]
[-Server2 <string>]
[-Sslversion <string>]
[-SyncDefaultsOptions <string>]
[-SyncAttributes <string>]
[-Tfa <string>]
[-UserAttr <string>]
[-UserClasses <string>]
[-Verify <bool>]
[<CommonParameters>]
Parameter Type Required Description
-PveTicket PveTicket No Ticket data connection.
-AcrValues string No Specifies the Authentication Context Class Reference values that theAuthorization Server is being requested to use for the Auth Request.
-Audiences string No A list of audiences that the OpenID Issuer may include that are accepted in addition to ‘client-id’.
-Autocreate bool No Automatically create users if they do not exist.
-BaseDn string No LDAP base domain name.
-BindDn string No LDAP bind domain name.
-Capath string No Path to the CA certificate store.
-CaseSensitive bool No username is case-sensitive.
-Cert string No Path to the client certificate.
-Certkey string No Path to the client certificate key.
-CheckConnection bool No Check bind connection to the server.
-ClientId string No OpenID Client ID.
-ClientKey string No OpenID Client Key.
-Comment string No Description.
-Default bool No Use this as default realm.
-Delete string No A list of settings you want to delete.
-Digest string No Prevent changes if current configuration file has a different digest. This can be used to prevent concurrent modifications.
-Domain string No AD domain name.
-Filter string No LDAP filter for user sync.
-GroupClasses string No The objectclasses for groups.
-GroupDn string No LDAP base domain name for group sync. If not set, the base_dn will be used.
-GroupFilter string No LDAP filter for group sync.
-GroupNameAttr string No LDAP attribute representing a groups name. If not set or found, the first value of the DN will be used as name.
-GroupsAutocreate bool No Automatically create groups if they do not exist.
-GroupsClaim string No OpenID claim used to retrieve groups with.
-GroupsOverwrite bool No All groups will be overwritten for the user on login.
-IssuerUrl string No OpenID Issuer Url.
-Mode string No LDAP protocol mode. Values: ldap, ldaps, ldap+starttls.
-Password SecureString No LDAP bind password. Will be stored in ‘/etc/pve/priv/realm/<REALM>.pw’.
-Port int No Server port.
-Prompt string No Specifies whether the Authorization Server prompts the End-User for reauthentication and consent.
-QueryUserinfo bool No Enables querying the userinfo endpoint for claims values.
-Realm string Yes Authentication domain ID.
-Scopes string No Specifies the scopes (user details) that should be authorized and returned, for example ‘email’ or ‘profile’.
-Secure bool No Use secure LDAPS protocol. DEPRECATED: use ‘mode’ instead.
-Server1 string No Server IP address (or DNS name)
-Server2 string No Fallback Server IP address (or DNS name)
-Sslversion string No LDAPS TLS/SSL version. It’s not recommended to use version older than 1.2! Values: tlsv1, tlsv1_1, tlsv1_2, tlsv1_3.
-SyncDefaultsOptions string No The default options for behavior of synchronizations.
-SyncAttributes string No Comma separated list of key=value pairs for specifying which LDAP attributes map to which PVE user field. For example, to map the LDAP attribute ‘mail’ to PVEs ‘email’, write ‘email=mail’. By default, each PVE user field is represented by an LDAP attribute of the same name.
-Tfa string No Use Two-factor authentication.
-UserAttr string No LDAP user attribute name.
-UserClasses string No The objectclasses for users.
-Verify bool No Verify the server’s SSL certificate.

Every parameter also binds by property name from the pipeline, so an object with node and vmid properties (the output of Get-PveGuest, for one) fills -Node and -Vmid. Without -PveTicket the cmdlet uses the last connection, see Connection.

A PveResponse: the data returned by Proxmox VE is in .Response.data, the outcome in .IsSuccessStatusCode. See Results and Errors.