Set-PveAccessDomains
Update authentication server settings.
API: PUT /access/domains/{realm}, Proxmox VE API viewer
Syntax
Section titled “Syntax”Set-PveAccessDomains [-PveTicket <PveTicket>] [-AcrValues <string>] [-Audiences <string>] [-Autocreate <bool>] [-BaseDn <string>] [-BindDn <string>] [-Capath <string>] [-CaseSensitive <bool>] [-Cert <string>] [-Certkey <string>] [-CheckConnection <bool>] [-ClientId <string>] [-ClientKey <string>] [-Comment <string>] [-Default <bool>] [-Delete <string>] [-Digest <string>] [-Domain <string>] [-Filter <string>] [-GroupClasses <string>] [-GroupDn <string>] [-GroupFilter <string>] [-GroupNameAttr <string>] [-GroupsAutocreate <bool>] [-GroupsClaim <string>] [-GroupsOverwrite <bool>] [-IssuerUrl <string>] [-Mode <string>] [-Password <SecureString>] [-Port <int>] [-Prompt <string>] [-QueryUserinfo <bool>] -Realm <string> [-Scopes <string>] [-Secure <bool>] [-Server1 <string>] [-Server2 <string>] [-Sslversion <string>] [-SyncDefaultsOptions <string>] [-SyncAttributes <string>] [-Tfa <string>] [-UserAttr <string>] [-UserClasses <string>] [-Verify <bool>] [<CommonParameters>]Parameters
Section titled “Parameters”| Parameter | Type | Required | Description |
|---|---|---|---|
-PveTicket |
PveTicket |
No | Ticket data connection. |
-AcrValues |
string |
No | Specifies the Authentication Context Class Reference values that theAuthorization Server is being requested to use for the Auth Request. |
-Audiences |
string |
No | A list of audiences that the OpenID Issuer may include that are accepted in addition to ‘client-id’. |
-Autocreate |
bool |
No | Automatically create users if they do not exist. |
-BaseDn |
string |
No | LDAP base domain name. |
-BindDn |
string |
No | LDAP bind domain name. |
-Capath |
string |
No | Path to the CA certificate store. |
-CaseSensitive |
bool |
No | username is case-sensitive. |
-Cert |
string |
No | Path to the client certificate. |
-Certkey |
string |
No | Path to the client certificate key. |
-CheckConnection |
bool |
No | Check bind connection to the server. |
-ClientId |
string |
No | OpenID Client ID. |
-ClientKey |
string |
No | OpenID Client Key. |
-Comment |
string |
No | Description. |
-Default |
bool |
No | Use this as default realm. |
-Delete |
string |
No | A list of settings you want to delete. |
-Digest |
string |
No | Prevent changes if current configuration file has a different digest. This can be used to prevent concurrent modifications. |
-Domain |
string |
No | AD domain name. |
-Filter |
string |
No | LDAP filter for user sync. |
-GroupClasses |
string |
No | The objectclasses for groups. |
-GroupDn |
string |
No | LDAP base domain name for group sync. If not set, the base_dn will be used. |
-GroupFilter |
string |
No | LDAP filter for group sync. |
-GroupNameAttr |
string |
No | LDAP attribute representing a groups name. If not set or found, the first value of the DN will be used as name. |
-GroupsAutocreate |
bool |
No | Automatically create groups if they do not exist. |
-GroupsClaim |
string |
No | OpenID claim used to retrieve groups with. |
-GroupsOverwrite |
bool |
No | All groups will be overwritten for the user on login. |
-IssuerUrl |
string |
No | OpenID Issuer Url. |
-Mode |
string |
No | LDAP protocol mode. Values: ldap, ldaps, ldap+starttls. |
-Password |
SecureString |
No | LDAP bind password. Will be stored in ‘/etc/pve/priv/realm/<REALM>.pw’. |
-Port |
int |
No | Server port. |
-Prompt |
string |
No | Specifies whether the Authorization Server prompts the End-User for reauthentication and consent. |
-QueryUserinfo |
bool |
No | Enables querying the userinfo endpoint for claims values. |
-Realm |
string |
Yes | Authentication domain ID. |
-Scopes |
string |
No | Specifies the scopes (user details) that should be authorized and returned, for example ‘email’ or ‘profile’. |
-Secure |
bool |
No | Use secure LDAPS protocol. DEPRECATED: use ‘mode’ instead. |
-Server1 |
string |
No | Server IP address (or DNS name) |
-Server2 |
string |
No | Fallback Server IP address (or DNS name) |
-Sslversion |
string |
No | LDAPS TLS/SSL version. It’s not recommended to use version older than 1.2! Values: tlsv1, tlsv1_1, tlsv1_2, tlsv1_3. |
-SyncDefaultsOptions |
string |
No | The default options for behavior of synchronizations. |
-SyncAttributes |
string |
No | Comma separated list of key=value pairs for specifying which LDAP attributes map to which PVE user field. For example, to map the LDAP attribute ‘mail’ to PVEs ‘email’, write ‘email=mail’. By default, each PVE user field is represented by an LDAP attribute of the same name. |
-Tfa |
string |
No | Use Two-factor authentication. |
-UserAttr |
string |
No | LDAP user attribute name. |
-UserClasses |
string |
No | The objectclasses for users. |
-Verify |
bool |
No | Verify the server’s SSL certificate. |
Every parameter also binds by property name from the pipeline, so an object with node and vmid properties (the output of Get-PveGuest, for one) fills -Node and -Vmid. Without -PveTicket the cmdlet uses the last connection, see Connection.
Output
Section titled “Output”A PveResponse: the data returned by Proxmox VE is in .Response.data, the outcome in .IsSuccessStatusCode. See Results and Errors.