<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//OASIS//DTD DocBook XML V4.1.2//EN" "http://www.oasis-open.org/docbook/xml/4.1.2/docbookx.dtd" [
<!ENTITY legal SYSTEM "legal.xml">
<!ENTITY version "2.26.0">
<!ENTITY date "02/10/2009">
<!ENTITY mdash "&#8212;">
<!ENTITY percnt "&#x0025;">
]>
<article id="index" lang="hr">
  <articleinfo>
    <title>GNOME priručnik upravitelja zaslona</title>

    <revhistory>
      <revision><revnumber>0.0</revnumber> <date>2008-09</date></revision>
    </revhistory>

    <abstract role="description">
      <para>GDM je GNOME Upravitelj zaslonom, grafički program za prijavu.</para>
    </abstract>

    <authorgroup>
      <author><firstname>Martin</firstname><othername>K.</othername> <surname>Petersen</surname> <affiliation> <address><email>mkp@mkp.net</email></address> </affiliation></author>
      <author><firstname>George</firstname><surname>Lebl</surname> <affiliation> <address><email>jirka@5z.com</email></address> </affiliation></author>
      <author><firstname>Jon</firstname><surname>McCann</surname> <affiliation> <address><email>mccann@jhu.edu</email></address> </affiliation></author>
      <author><firstname>Ray</firstname><surname>Strode</surname> <affiliation> <address><email>rstrode@redhat.com</email></address> </affiliation></author>
      <author role="maintainer"><firstname>Brian</firstname><surname>Cameron</surname> <affiliation> <address><email>Brian.Cameron@Oracle.COM</email></address> </affiliation></author>
    </authorgroup>
    <copyright><year>1998</year> <year>1999</year> <holder>Martin K. Petersen</holder></copyright>
    <copyright><year>2001</year> <year>2003</year> <year>2004</year> <holder>George Lebl</holder></copyright>
    <copyright><year>2003</year> <year>2007</year> <year>2008</year> <holder>Red Hat, Inc.</holder></copyright>
    <copyright><year>2003</year> <year>2011</year> <holder>Oracle i/ili njegove podružnice. Sva prava pridržana.</holder></copyright>

    

    <releaseinfo>Ovaj priručnik opisuje 2.26.0 GNOME Upravitelja zaslona. Posljednji puta je nadopunjen 02/10/2009.</releaseinfo>  
  </articleinfo>

  <!-- ============= Preface ================================== -->

  <sect1 id="preface">
    <title>Izrazi i sporazumi korišteni u ovome priručniku</title>

    <para>Ovaj priručnik opisuje 2.26.0 GNOME Upravitelja zaslona. Posljednji puta je nadopunjen 02/10/2009.</para>  

    <para>Odabiratelj - Program koji se koristi za odabir udaljenog računala i udaljeno upravljanje zaslonom na priključenom zaslonu (<command>gdm-host-chooser</command>).</para>

    <para>FreeDesktop - Organizacija koja pruža standarde za radne površine, poput Specifikacije unosa radne površine (Desktop Entry Specification) koju koristi GDM. <ulink type="http" url="http://www.freedesktop.org/"> http://www.freedesktop.org</ulink>.</para>
    <para>GDM - GNOME Upravitelj zaslonima. Koristi se za opisivanje softverskog paketa u cjelini.</para>

    <para>Dobrodošlica - grafički prozor prijave (pružan od strane <command>gnome-shell</command>).</para>

    <para>PAM - Priključiv mehanizamm ovjere</para>

    <para>XDMCP - X Protokol upravljanja zaslonom</para>

    <para>X poslužitelj - Implementacija X Window sustava. Primjerice, Xorg X poslužitelj koji osigurava X.org zaklada <ulink type="http" url="http://www.x.org/">http://www.x.org</ulink>.</para>

    <para>Putanje koje počinju riječju u izlomljenim zagradama relativne su prema instalacijskom prefiksu. tj. <filename>&lt;share&gt;/pixmaps/</filename> odnosi se na <filename>/usr/share/pixmaps</filename> ako je GDM podešen s <command>--prefix=/usr</command>.</para>
  </sect1>

  <!-- ============= Overview ================================= -->

  <sect1 id="overview">
    <title>Pregled</title>

    <sect2 id="introduction">
      <title>Uvod</title>

      <para>GNOME Upravitelj zaslona (GDM) je upravitelj zaslona koji implementira sve bitne značajke potrebne za upravljanje priključenim i udaljenim zaslonima. GDM je napisan iz početka i ne sadrži XDM ili X Consortium kôd.</para>

      <para>Zapamtite da je GDM moguće podešavati, a mnoge postavke podešavanja utječu na sigurnost. Problemi kojih treba biti svjestan istaknuti su u ovom dokumentu.</para> 

      <para>Zapamtite da pojedini operativni sustavi podešavaju GDM tako da se ponaša drugačije od zadanih vrijednosti kako je opisano u ovom dokumentu. Ako se GDM ne ponaša kao što je dokumentirano, tada provjerite razlikuje li se neko povezano podešavanje od ovdje opisanog.</para>

      <para>Za dodatne GDM informacije, posjetite web stranicu projekta na <ulink type="http" url="http://wiki.gnome.org/Projects/GDM/"> http://wiki.gnome.org/Projects/ GDM</ulink>.</para>

      <para>Za raspravu ili upite o GDM-u, pogledajte popis adrese e-pošte <address><email>gdm-list@gnome.org</email></address> Ovaj popis je arhiviran i dobar je izvor za provjeru traženog odgovora na uobičajena pitanja. Ovaj popis je arhiviran na <ulink type="http" url="http://mail.gnome.org/archives/gdm-list/"> http://mail.gnome.org/archives/gdm-list/</ulink> i ima mogućnost pretrage poruka po ključnim riječima.</para>

      <para>Pošaljite sve izvještaje grešaka ili zahtjeve za poboljšanjem u "gdm" kategoriju na <ulink type="http" url="http://bugzilla.gnome.org/"> http://bugzilla.gnome.org</ulink> .</para>
    </sect2>

    <sect2 id="stability">
      <title>Stabilnost sučelja</title>

      <para>GDM 2.20 i starija izdanja podržavaju stabilna sučelja podešavanja. Ipak, baza kôda u potpunosti je ponovno napisana za GDM 2.22 i nije potpuno kompatibilna sa starijim izdanjima. To je dijelom zato što stvari funkcioniraju drugačije, stoga neke mogućnosti jednostavno nemaju smisla, dijelom zato što neke mogućnosti nikad nisu imale smisla, a dijelom zato što neke funkcije još nisu ponovno implementirane.</para>

      <para>Sučelja koja su i dalje podržana na stabilan način uključuju Init, PreSession, PostSession, PostLogin i Xsession skripte. Pojedine mogućnosti podešavanja pozadinskog programa u <filename>&lt;etc&gt;/gdm/custom.conf</filename> datoteci i dalje su podržane. Podržani su i dalje <filename>~/.dmrc</filename> i lokacije slika preglednika lica.</para>

      <para>GDM 2.20 i starija izdanja podržavali su mogućnost upravljanja višestrukim zaslonima s odvojenim grafičkim karticama, poput onih koje se koriste u okruženjima terminalskih poslužitelja, prijavu u prozor putem programa kao što su Xnest ili Xephyr, gdmsetup program, XML temeljene teme dobrodošlice i mogućnost pokretanja XDMCP odabirtatelja sa zaslona prijave. Ove značajke nisu dodane tijekom ponovnog pisanja 2.22 izdanja.</para>

    </sect2>

    <sect2 id="functionaldesc">
      <title>Funkcionalni opis</title>

<!--
<para>
        TODO - Would be good to discuss D-Bus, perhaps the new GObject model,
               and to explain the reasons why the rewrite made GDM better.
               From a high-level overview perspective, rather than the
               technical aspects.
</para>
-->

      <para>GDM je odgovoran za upravljanje zaslonima u sustavu. To uključuje ovjeru korisnika, pokretanje korisničke sesije i prekid korisničke sesije. GDM je moguće podesiti, a načini na koji se može podesiti opisani su u odlomku "GDM podešavanje" ovog dokumenta. GDM je dostupan i korisnicima s invaliditetom.</para>

      <para>GDM pruža mogućnost upravljanja zaslonom glavne konzole i zaslonima pokrenutim putem VT-a. Integriran je s drugim programima, kao što je Fast User Switch Applet (FUSA) i gnome-screensaver za upravljanje višestrukim zaslonima na konzoli putem sučelja Virtualni Terminal X poslužitelja (VT). Može upravljati i XDMCP zaslonima.</para>

      <para>Neovisno o vrsti zaslona, GDM će učiniti sljedeće kada upravlja zaslonom. Pokrenut će proces X poslužitelja, zatim pokrenuti <filename>Init</filename> skriptu kao korijenski korisnik i pokrenuti program dobrodošlice na zaslonu.</para>

      <para>Program dobrodošlice pokreće se kao nepovlašteni "gdm" korisnik/grupa. Ovaj korisnik i grupa opisani su u odjeljku "Sigurnost" ovog dokumenta. Glavne funkcije programa dobrodošlice su pružanje mehanizma za odabir računa prijave i pokretanje dijaloga između korisnika i sustava pri ovjeri tog računa. Proces ovjere pokreću Pluggable Authentication Modules (PAM). PAM moduli određuju koji se upiti (ako postoje) prikazuju korisniku za ovjeru prijave. U prosječnom sustavu, program dobrodošlice tražit će korisničko ime i lozinku za ovjeru prijave. Ipak, pojedini sustavi mogu biti podešeni za korištenje dodatnih mehanizama poput čitača otisaka prstiju ili pametnih kartica. GDM se može podesiti da podržava ove alternativne prijave paralelno s proširenjima prijave programa dobrodošlice i mogućnosti <command>--enable-split-authentication</command> <filename>./configure</filename>, ili jedne po jedne putem PAM sustava podešavanja.</para>

      <para>Proširenje pametne kartice može se omogućiti ili onemogućiti putem <filename>org.gnome.display-manager.extensions.smartcard.active</filename> ključa postavki.</para>

      <para>Isto tako, proširenje otiska prsta može se omogućiti ili onemogućiti putem <filename>org.gnome.display-manager.extensions.fingerprint.active</filename> gsettings ključa.</para>

      <para>GDM i PAM mogu se podesiti da ne zahtijevaju nikakav unos, što će uzrokovati da se GDM automatski prijavi i jednostavno pokrene sesiju, što može biti korisno za pojedina okruženja, poput sustava s jednim korisnikom ili kioscima.</para>

      <para>Kao dodatak ovjeri prijave, program dobrodošlice omogućuje korisniku odabir sesije i jezika koji će koristiti. Sesije su određene datotekama koje završavaju .desktop sufiksom, a više informacija o tim datotekama možete pronaći u odlomku "GDM korisnička sesija i podešavanje jezika" u ovom dokumentu. Po zadanome, GDM je podešen za prikaz preglednika lica tako da korisnik može odabrati svoj korisnički račun klikom na sliku umjesto upisivanja svog korisničkog imena. GDM prati korisnikovu zadanu sesiju i jezik u korisnikovoj <filename>~/.dmrc</filename> datoteci i koristit će te zadane postavke ako korisnik nije odabrao sesiju ili jezik u korisničkom sučelju za prijavu.</para>

      <para>Nakon ovjere korisnika, pozadinski program pokreće <filename>PostLogin</filename> skriptu kao korijenski korisnik, zatim pokreće <filename>PreSession</filename> skriptu kao korijenski korisnik. Nakon pokretanja ovih skripti, pokreće se korisnička sesija. Kada korisnik izađe iz svoje sesije, <filename>PostSession</filename> skripta se pokreće kao korijenski korisnik. Ove se skripte ponašaju kao spojnice za distribucije i krajnje korisnike u svrhu prilagodbe upravljanja sesijama. Primjerice, korištenjem ovih spojnica možete postaviti sustav koji stvara korisnički $HOME direktorij u hodu i briše ga nakon odjave. Razlika između <filename>PostLogin</filename> i <filename>PreSession</filename> skripti je u tome što se <filename>PostLogin</filename> pokreće prije poziva pam_open_session stoga je ona pravo mjesto za prilagodbu svega potrebnog za pokretanje prije pokretanja korisničke sesije. Skripta <filename>PreSession</filename> poziva se nakon pokretanja sesije.</para>
    </sect2>

    <sect2 id="greeterpanel">
      <title>Panel dobrodošlice</title>
      <para>Program GDM dobrodošlice prikazuje panel pričvršćen na dnu zaslona koji pruža dodatnu funkcionalnost. Kada je korisnik odabran, panel mu omogućuje odabir sesije, jezika i rasporeda tipkovnice koji će koristiti nakon prijave. Izbornik rasporeda tipkovnice još mijenja i raspored tipkovnice koji se koristi pri upisivanju lozinke. Panel sadrži područje usluge prijave za napuštanje ikona stanja. Pojedini primjeri ikona stanja uključuju ikonu baterije trenutnu potrošnje baterije i ikonu omogućavanja značajki pristupačnosti. Program dobrodošlice isto nudi tipke koje korisniku omogućuju isključivanje ili ponovno pokretanje sustava, moguće je podesiti GDM da ne prikazuje te tipke, po potrebi. GDM se može podesiti putem PolicyKita (ili putem RBAC-a na Oracle Solarisu) da od korisnika zahtijeva odgovarajuću ovjeru prije pokretanja isključivanja ili ponovnog pokretanja.</para>

      <para>Zapamtite da su značajke rasporeda tipkovnice dostupne samo na sustavima koji podržavaju libxklavier.</para>
    </sect2>

    <sect2 id="accessibility">
      <title>Pristupačnost</title>

        <para>GDM podržava "Pristupačnu prijavu", omogućujući korisnicima prijavu na svoju radnu površinu čak i ako ne mogu jednostavno koristiti zaslon, miš ili tipkovnicu na uobičajeni način. Tehnologija pristupačnosti (AT) ima značajke poput zaslonske tipkovnice, čitača zaslona, povećala zaslona i Xserver AccessX pristupačnost tipkovnice. Po potrebi, moguće je omogućiti ikone i upravljanja velikim tekstom i visokim kontrastom. Pogledajte odlomak "Podešavanje pristupačnosti" u dokumentu za više informacija o tome kako se različite značajke pristupačnosti mogu podesiti.</para>

        <para>Na pojedinim operativnim sustavima, potrebno je osigurati da GDM korisnik bude član "audio" grupe za AT programe koji zahtijevaju zvučni izlaz (poput tekst-u-govor) kako bi bio funkcionalan.</para>
    </sect2>

    <sect2 id="facebrowser">
      <title>GDM preglednik lica</title>

      <para>Preglednik lica je sučelje koje korisnicima omogućuje odabir korisničkog imena klikom na sliku. Ova se značajka može omogućiti ili onemogućiti putem GSettings org.gnome.login-screen disable-user-list ključa i uključena je po zadanome. Kada je onemogućena, korisnici moraju ručno upisati svoje puno korisničko ime. Kada je omogućena, prikazuje sve lokalne korisnike koji su dostupni za prijavu na sustav (svi korisnički računi određeni u /etc/passwd datoteci koji imaju valjanu ljusku i dovoljno visok UID) i udaljene korisnike koji su se nedavno prijavili. Preglednik lica u GDM 2.20 i starijim izdanjima pokušao bi prikazati sve udaljene korisnike, što je uzrokovalo probleme s performansama u velikim, poslovnim implementacijama.</para>

      <para>Preglednik lica podešen je da prikaže korisnike koji se najčešće prijavljuju na vrhu popisa. Ovo pomaže osigurati korisnicima koji se često prijavljuju brži pronalazak svoje sliku za prijavu.</para>

      <para>Preglednik lica podržava "pretragu unaprijed" koja dinamički pomiče odabir lica dok korisnik tipka odgovarajuće korisničko ime na popisu. To znači da će korisnik s dugim korisničkim imenom morati upisati samo prvih nekoliko znakova korisničkog imena prije nego što se odabere ispravna stavka na popisu.</para>

      <para>Ikone koje koristi GDM, administrator sustava može instalirati globalno ili se mogu nalaziti u korisničkim osobnim direktorijima. Ako su instalirane globalno, trebale bi biti u <filename>&lt;share&gt;/pixmaps/faces/</filename> direktoriju, a naziv datoteke trebao bi biti ime korisnika. Datoteke sa slikom lica trebale bi biti standardne slike koje GTK+ može čitati, poput PNG ili JPEG formata. Ikone lica smještene u globalnom direktoriju lica moraju biti čitljive GDM korisniku.</para>

<!--
<para>
        TODO - In the old GDM the ~/gnome2/gdm file is used, but the new code
               seems to use ~/.gnome/gdm.  Error?
</para>
-->
      <para>Ako nema globalne ikone za korisnika, GDM će datoteku slike tražiti u korisnikovom $HOME direktoriju. GDM će prvo potražiti sliku lica korisnika u <filename>~/.face</filename>. Ako se ne pronađe, pokušat će <filename>~/.face.icon</filename>. Ako i dalje nije pronađena, koristit će vrijednost određenu za "face/picture=" u <filename>~/.gnome2/gdm</filename> datoteci.</para>

      <para>Ako korisnik nema određenu sliku lica, GDM će koristiti ikonu "stock_person" određenu u trenutnoj GTK+ temi. Ako takva slika nije određena, vratit će se na generičku sliku lica.</para>

      <para>Zapamtite da učitavanje i promjena veličine ikona lica smještenih u osobnim direktorijima udaljenih korisnika može biti dugotrajan zadatak. Budući da nije praktično učitavati slike preko NIS-a ili NFS-a, GDM ne pokušava učitati slike lica iz udaljenih osobnih direktorija.</para>

      <para>Kada je preglednik uključen, valjana korisnička imena na računalu su svima dostupna. Ako je XDMCP omogućen, tada su korisnička imena dostupna i udaljenim korisnicima. Ovo, naravno, donekle ograničava sigurnost budući da zlonamjerni korisnik ne mora pogađati valjana korisnička imena. U pojedinim vrlo restriktivnim okruženjima preglednik lica možda neće biti prikladan.</para>

    </sect2>

    <sect2 id="xdmcp">
      <title>XDMCP</title>

<!--
<para>
        TODO - What XDMCP features actually work?   I know that the
               chooser is missing.
</para>
-->

      <para>GDM pozadinski program se može podesiti da osluškuje i upravlja zahtjevima Protokola upravljanja X zaslona (XDMCP) s udaljenih zaslona. Po zadanome XDMCP podrška je isključena, ali se po potrebi može omogućiti. Ako je GDM izgrađen s podrškom za TCP Wrapper, tada će pozadinski program odobriti pristup samo poslužiteljima navedenim u odjeljku GDM usluge u TCP Wrappers datoteci podešavanja.</para>

      <para>GDM uključuje nekoliko mjera koje ga čine otpornijim na napade uskraćivanjem usluge na XDMCP pozadinskom programu. Mnoštvo parametara protokola, čekanja rukovanja itd. mogu se precizno prilagoditi. Zadano podešavanje trebalo bi razumno raditi na većini sustava.</para>

      <para>GDM po zadanome osluškuje XDMCP zahtjeve na normalnom UDP ulazu koji se koristi za XDMCP, ulaz 177 i odgovorit će na QUERY i BROADCAST_QUERY zahtjeve slanjem WILLING paketa pokretaču.</para>

      <para>GDM se može podesiti da poštuje INDIREKTNE zahtjeve i predstavlja biratelja poslužitelja udaljenog zaslona. GDM će zapamtiti izbor korisnika i proslijediti sljedeće zahtjeve odabranom upravitelju. GDM još podržava i proširenje protokola koje će zaboraviti preusmjeravanje nakon što korisnikovo povezivanje uspije. Ovo proširenje je podržano samo ako su oba pozadinska programa GDM. Transparentan je i zanemarit će ga XDM ili drugi pozadinski programi koji implementiraju XDMCP.</para>

      <para>Ako se čini da XDMCP ne radi, provjerite jesu li svi poslužitelji navedeni u <filename>/etc/hosts</filename> datoteci.</para>

      <para>Pogledajte odlomak "Sigurnost" za informacije o sigurnosnim problemima kada se koristi XDMCP.</para>
    </sect2>

    <sect2 id="logging">
      <title>Zapisivanje</title>

      <para>GDM koristi syslog za zapisivanje grešaka i stanja. Može zapisivati i informacije otklanjanja grešaka, što može biti korisno za pronalaženje problema ako GDM ne radi ispravno. Zapisivanje otklanjanja grešaka može se omogućiti postavljanjem debug/Enable ključa na "istina" u <filename>&lt;etc&gt;/gdm/custom.conf</filename> datoteci.</para>

      <para>Zapis iz raznih X poslužitelja pohranjuje se u GDM direktorij zapisa, koji je uobičajeno <filename>&lt;var&gt;/log/gdm/</filename>. Sve poruke X poslužitelja spremaju se u datoteku pridruženu vrijednosti zaslona, <filename>&lt;display&gt;.log</filename>.</para>

      <para>Izlaz sesije prenosi se kroz GDM pozadinski program u <filename>~/<replaceable>$XDG_CACHE_HOME</replaceable>/gdm/session.log</filename> datoteku koja se uobičajeno proširuje na <filename>~/.cache/gdm/ session.log</filename>. Datoteka se prebriše pri svakoj prijavi, tako da će odjava i ponovna prijava istog korisnika putem GDM-a uzrokovati gubitak svih poruka iz prijašnje sesije.</para>

      <para>Zapamtite da ako GDM iz nekog razloga ne može stvoriti ovu datoteku, stvorit će se pričuvna datoteka naziva <filename>~/<replaceable>$XDG_CACHE_HOME</replaceable>/gdm/session.log.XXXXXXXX</filename> gdje su <filename>XXXXXXXX</filename> neki naizmjenično odabrani znakovi.</para>
    </sect2>

    <sect2 id="fusa">
      <title>Brza zamjena korisnika</title>

      <para>GDM omogućuje istovremenu prijavu više korisnika. Nakon što je jedan korisnik prijavljen, drugi se korisnici mogu prijaviti putem zamjenjivača korisnika na GNOME panelu ili pomoću "Zamijeni korisnika" tipke u dijalogu zaključanog zaslona GNOME čuvara zaslona. Aktivna sesija može se mijenjati naprijed i natrag koristeći isti mehanizam. Zapamtite da pojedine distribucije možda neće dodati zamjenu korisnika zadanom podešavanju panela. Zamjena korisnika može se dodati pomoću sadržajnog izbornika panela.</para>
      <para>Zapamtite da je ova značajka dostupna na sustavima koji podržavaju virtualne terminale. Ova značajka neće funkcionirati ako virtualni terminali nisu dostupni.</para>
    </sect2>
  </sect1>

  <!-- ============= Security ================================= -->

  <sect1 id="security">
    <title>Sigurnost</title>

    <sect2 id="gdmuser">
      <title>GDM korisnik i grupe</title>

      <para>Iz sigurnosnih razloga preporuča se namjenski ID korisnika i grupe za pravilan rad. Ovaj korisnik i grupa uobičajeno su "gdm" na većini sustava, ali se mogu podesiti za bilo kojeg korisnika ili grupu. Svi GDM GUI programi pokreću se kao ovaj korisnik, tako da se programi koji komuniciraju s korisnikom pokreću u sigurnom okruženju. Ovaj korisnik i grupa trebaju imati ograničene dozvole.</para>

      <para>Jedina posebna dozvola koju "gdm" korisnik zahtijeva je mogućnost čitanja i pisanja Xauth datoteka u <filename>&lt;var&gt;/run/gdm</filename> direktorij. Direktorij <filename>&lt;var&gt;/run/gdm</filename> trebao bi imati root:gdm vlasništvo i 1777 dozvole.</para>

      <para>Ni pod kojim okolnostima ne bi trebali podesiti GDM korisnika/grupu na korisnika kojem korisnik može lako pristupiti, poput korisnik <filename>nobody</filename>. Svaki korisnik koji dobije pristup Xauth ključu može njuškati i upravljati pokrenutim GUI programima koji su pokrenuti u pridruženoj sesiji ili izvršiti napad uskraćivanjem usluge. Bitno je osigurati pravilno podešen sustav tako da samo "gdm" korisnik ima pristup ovim datotekama i da se nije lako prijaviti na ovaj račun. Primjerice, račun bi trebao biti postavljen tako da nema lozinku ili da dopušta nekorijenskim korisnicima prijavu na račun.</para>

      <para>Podešavanje GDM dobrodošlice pohranjeno je u GConf. Kako bi GDM korisnik mogao pisati podešavanje, potrebno je da "gdm" korisnik ima $HOME direktorij s dozvolom pisanja. Korisnici mogu podesiti zadano GConf podešavanje po potrebi kako bi izbjegli da "gdm" korisniku daju $HOME direktorij s dozvolom pisanja. Ipak, pojedine GDM značajke mogu biti onemogućene ako se ne mogu zapisivati podaci o stanju u GConf podešavanju.</para>
    </sect2>

    <sect2 id="PAM">
      <title>PAM</title>

      <para>GDM koristi PAM za ovjeru prijave. PAM je kratica za Pluggable Authentication Module, a koristi ga većina programa koji zahtijevaju ovjeru na vašem računalu. Omogućuje administratoru podešavanje specifičnog ponašanja ovjere za različite programe prijave (kao što su ssh, GUI za prijavu, čuvar zaslona itd.)</para>

      <para>PAM je složen i vrlo podesiv, a ova dokumentacija nema namjeru to opširno objašnjavati. Umjesto toga, namjera je dati pregled kako je PAM podešavanje povezano s GDM-om, kako se PAM uobičajeno podešava s GDM-om i koji su poznati problemi. Očekivano je da osoba koja ima potrebu podesiti PAM mora dodatno pročitati PAM dokumentaciju kako bi razumjela PAM podešavanje i pojmove koji se koriste u ovom odlomku.</para>
        
      <para>PAM podešavanje ima različito, ali slično sučelje na raznim operativnim sustavima, stoga provjerite <ulink type="help" url="man:pam.d">pam.d</ulink> ili <ulink type="help" url="man:pam.conf">pam.conf</ulink> stranice priručnika za pojedinosti. Obavezno pročitajte PAM dokumentaciju i upoznajte se sa sigurnosnim implikacijama bilo kakvih promjena koje namjeravate napraviti u svome podešavanju.</para>

      <para>Zapamtite da GDM po zadanome koristi PAM "gdm" naziv usluge za normalnu prijavu i PAM "gdm-autologin" naziv usluge za automatsku prijavu. Ove usluge možda nisu određene u vašoj pam.d ili pam.conf datoteci podešavanja. Ako nema unosa, GDM će koristiti zadano PAM ponašanje. Na većini sustava ovo bi trebalo dobro funkcionirati. Ipak, značajka automatske prijave možda neće raditi ako usluga gdm-autologin nije određena.</para>

      <para>Skripta <filename>PostLogin</filename> pokreće se prije pam_open_session poziva , a skripta <filename>PreSession</filename> se poziva nakon. Ovo omogućuje administratoru sustava dodavanje bilo koje skripte procesu prijave prije ili nakon što PAM pokrene sesiju.</para>

      <para>Ako želite učiniti da GDM radi s drugim vrstama mehanizama ovjere (poput čitača otiska prsta ili pametne kartice), tada bi to trebali implementirati korištenjem servisnog modula PAM za željenu vrstu ovjere, umjesto pokušajem izravne izmjene GDM kôda. Pogledajte PAM dokumentaciju na vašem sustavu. O tome kako to učiniti često se raspravlja na<address><email>gdm-list@gnome.org</email></address> mailing listi, tako da možete pogledati arhive popisa za više informacija.</para>

      <para>PAM ima određena ograničenja u pogledu mogućnosti rada s više vrsta ovjere istovremeno, poput podrške mogućnosti prihvaćanja pametne kartice i mogućnosti upisivanja korisničkog imena i lozinke u program prijave. Postoje tehnike koje se koriste da bi ovo funkcioniralo, a najbolje je istražiti kako se ovaj problem uobičajeno rješava prilikom postavljanja takvog podešavanja.</para>

      <para>Ako automatska prijava ne radi na sustavu, provjerite je li "gdm-autologin" PAM određen u PAM podešavanju. Kako bi ovo funkcioniralo, potrebno je koristiti PAM modul koji jednostavno ne vrši ovjeru ili koji jednostavno vraća PAM_SUCCESS sa svih svojih javnih sučelja. Pod pretpostavkom da vaš sustav ima pam_allow.so PAM modul koji to radi, PAM podešavanje za omogućavanje "gdm-autologin" izgledao bi ovako:</para>

<screen>
       gdm-autologin auth  required    pam_unix_cred.so.1
       gdm-autologin auth  sufficient  pam_allow.so.1
       gdm-autologin account  sufficient  pam_allow.so.1
       gdm-autologin session  sufficient  pam_allow.so.1
       gdm-autologin password  sufficient  pam_allow.so.1
</screen>

      <para>Gornja postavka neće uzrokovati stvaranje unosa posljednje prijave. Ako želite unos posljednje prijave, tada koristite sljedeće za sesiju:</para>

<screen>
       gdm-autologin session required pam_unix_session.so.1
</screen>

      <para>Ako računalo koristi više ljudi, što automatsku prijavu čini neprikladnom, možete dopustiti pojedinim korisnicima prijavu bez upisa svojih lozinki. Ova se značajka može omogućiti kao mogućnost po korisniku u user-admin alatu iz gnome-system-tools; to se postiže provjerom je li korisnik član Unix grupe pod nazivom "nopasswdlogin" prije nego što se zatraži lozinka. Kako bi ovo radilo, PAM datoteka podešavanja za uslugu "gdm" mora sadržavati redak kao što je:</para>

<screen>
      gdm auth  sufficient  pam_succeed_if.so  user ingroup nopasswdlogin
</screen>

    </sect2>

    <sect2 id="utmpwtmp">
      <title>utmp i wtmp</title>

      <para>GDM stvara utmp i wtmp unose baze podataka korisničkih računa nakon prijave i odjave u sesiju. Baza podataka utmp sadrži informacije o korisničkom pristupu i informacije računa kojima se pristupa naredbama poput <command>finger</command>, <command>last</command>, <command>login</command> i <command>who</command>. Baza podataka wtmp sadrži povijest pristupa korisnika i informacija računa za bazu podataka utmp. Pogledajte <ulink type="help" url="man:utmp">utmp</ulink> i <ulink type="help" url="man:wtmp">wtmp</ulink> stranice priručnika na vašem sustavu za više informacija.</para>
    </sect2>

    <sect2 id="xauth">
      <title>Shema ovjere X poslužitelja</title>

      <para>Datoteke ovjere X poslužitelja pohranjuju se u novostvorenom poddirektoriju <filename>&lt;var&gt;/run/gdm</filename> pri pokretanju. Ove se datoteke koriste za pohranjivanje i dijeljenje "lozinke" između X klijenta i X poslužitelja. Ova "lozinka" je jedinstvena za svaku prijavljenu sesiju, stoga korisnici iz jedne sesije ne mogu njuškati korisnike iz druge.</para>

      <para>GDM podržava samo MIT-MAGIC-COOKIE-1 shemu ovjere X poslužitelja. Ubičajeno malo se dobiva od drugih shema i do sada nije uložen nikakav trud da se one implementiraju. Budite posebno oprezni pri XDMCP korištenju jer kolačić ovjere X poslužitelja ide preko žice kao običan tekst. Ako je njuškanje moguće, napadač bi mogao jednostavno njuškati vašu lozinku ovjere dok se prijavljujete, bez obzira koja se shema ovjere koristi. Ako je njuškanje moguće i nepoželjno, tada bi trebali koristiti ssh za tuneliranje X povezivanja umjesto XDMCP-a. Možete zamisliti XDMCP kao neku vrstu grafičkog telneta, koji ima iste sigurnosne probleme. U većini slučajeva, ssh -Y treba imati prednost nad GDM-ovim XDMCP značajkama.</para>

    </sect2>

    <sect2 id="xdmcpsecurity">
      <title>XDMCP sigurnost</title>

      <para>Iako je vaš zaslon zaštićen kolačićima, XEvents i pritisci tipki upisani pri upisu lozinki, i dalje će ići preko žice u običnom tekstu. Jednostavno ih je presresti.</para>

      <para>XDMCP je prvenstveno koristan za pokretanje malih klijenta poput terminal laboratorija. Ti mali klijenti trebat će mrežu samo za pristup poslužitelju, stoga je najbolje sigurnosno pravilo imati te male klijente na zasebnoj mreži kojoj se ne može pristupiti izvana i mogu se povezati samo s poslužiteljem. Jedina točka s koje trebate pristup izvana je poslužitelj. Ova vrsta postavljanja nikada ne bi trebala koristiti neupravljano čvorište ili drugu mrežu koja se može njuškati.</para>

    </sect2>

    <sect2 id="xdmcpaccess">
      <title>XDMCP upravljanje pristupom</title>

      <para>XDMCP upravljanje pristupom vrši se pomoću TCP wrappera. Moguće je kompilirati GDM bez podrške za TCP wrapper, tako da ova značajka možda nije podržana na pojedinim operativnim sustavima.</para>

      <para>Trebali bi koristiti naziv pozadinskog programa <command>gdm</command> u <filename>&lt;etc&gt;/hosts.allow</filename> i <filename>&lt;etc&gt;/hosts.deny</filename> datotekama. Primjerice, za zabranu prijave računala sa <filename>.zla.domena</filename>, dodajte</para>
<screen>
gdm: .zla.domena
</screen>
      <para>u <filename>&lt;etc&gt;/hosts.deny</filename>. Još možete dodati</para>
<screen>
gdm: .vaša.domena
</screen>
      <para>u <filename>&lt;etc&gt;/hosts.allow</filename> ako inače zabranjujete sve usluge sa svih poslužitelja. Pogledajte <ulink type="help" url="man:hosts.allow">hosts.allow(5)</ulink> stranicu priručnika za pojedinosti.</para>
    </sect2>

    <sect2 id="firewall">
      <title>Sigurnost vatrozida</title>

      <para>Iako GDM pokušava nadmudriti potencijalne napadače koji pokušavaju iskoristiti XDMCP, ipak se savjetuje da blokirate XDMCP ulaz (uobičajeno UDP ulaz 177) na vatrozidu osim ako je stvarno potreban. GDM štiti od napada uskraćivanjem usluge, ali X protokol je još uvijek inherentno nesiguran i trebao bi se koristiti samo u kontroliranim okruženjima. Svako udaljeno povezivanje zauzima mnogo resursa, tako da je mnogo lakše izvršiti napad uskraćivanjem usluge putem XDMCP-a nego napadati web poslužitelj.</para>

      <para>Pametno je blokirati sve ulaze X poslužitelja. To su TCP ulazi 6000+ (jedan za svaki broj prikaza) u vatrozidu. Zapamtite da će GDM koristiti brojeve prikaza 20 i više za prilagodljive poslužitelje na zahtjev.</para>

      <para>X nije baš siguran protokol kada se koristi preko Interneta, a XDMCP je još manje siguran.</para>
    </sect2>

    <sect2 id="policykit">
      <title>PolicyKit</title>

<!--
<para>
        TODO - Should we say more?
</para>
-->

      <para>GDM se može podesiti da koristi PolicyKit kako bi administratoru sustava dopustio upravljanje omogućavanjem tipki isključivanja i ponovnog pokretanja u zaslonu prijave na zaslonu dobrodošlice.</para>

      <para>Tim tipkama se upravlja radnjama <filename>org.freedesktop.consolekit.system.stop-multiple-users</filename> i <filename>org.freedesktop.consolekit.system.restart-multiple-users</filename>. Pravila za ove radnje mogu se postaviti pomoću polkit-gnome-authorization alata ili polkit-auth pragrama naredbenog retka.</para>
 
    </sect2>

    <sect2 id="rbac">
      <title>RBAC (Upravljanje pristupom temeljenom na ulogama)</title>

      <para>GDM se može podesiti da koristi RBAC umjesto PolicyKita. U ovom se slučaju RBAC podešavanje koristi za upravljanje omogućavanjem tipki isključivanja i ponovnog pokretanja u zaslonu prijave na zaslonu dobrodošlice.</para>

      <para>Primjerice, na Oracle Solarisu, "solaris.system.shutdown" ovjera se koristi za upravljanje ovim. Jednostavno promijenite <filename>/etc/user_attr</filename> datoteku tako da "gdm" korisnik ima ovu ovlast.</para>
    </sect2>

  </sect1>

  <!-- ============= ConsoleKit ================================ -->

  <sect1 id="consolekit">
    <title>Podrška za ConsoleKit</title>

<!--
<para>
    TODO - Should we update these docs?  Probably should mention any 
           configuration that users may want to do for using it with GDM?
           If so, perhaps this section should be moved to a subsection of
           the "Configure" section?
</para>
-->

    <para>GDM uključuje podršku za objavljivanje podataka prijave korisnika s radnim okvirom korisnika i sesijom prijave poznatim kao ConsoleKit. ConsoleKit može pratiti sve trenutno prijavljene korisnike. U tom smislu, može se koristiti kao zamjena za utmp ili utmpx datoteke koje su dostupne na većini Unixoidnih operativnih sustava.</para>

    <para>Kada GDM treba stvoriti novi proces prijave korisnika, pozvat će povlašteni način ConsoleKita kako bi otvorio novu sesiju za korisnika. U ovom trenutku GDM isto pruža ConsoleKit informacije o ovoj korisničkoj sesiji poput: ID korisnika, X11 naziva zaslona koji će biti povezan sa sesijom, naziv poslužitelja s kojeg sesija potječe (korisno u slučaju XDMCP sesije ), je li ova sesija priključena ili nije, itd. Kao entitet koji pokreće korisnički proces, GDM je u jedinstvenom položaju da zna sve o korisničkoj sesiji i da mu se vjeruje da će pružiti ove informacije. Korištenje ovog povlaštenog načina ograničeno je korištenjem sigurnosnih pravila sabirnice poruka D-Bus sustava.</para>

    <para>U slučaju da se korisnik s postojećom sesijom ovjeri na GDM i zatraži nastavak te postojeće sesije, GDM poziva povlašteni način ConsoleKita za otključavanje dotične sesije. Točne pojedinosti o tome što se događa kada sesija primi ovaj signal za otključavanje nisu određene i specifične su za sesiju. Ipak, većina sesija će kao odgovor otključati čuvar zaslona.</para>

    <para>Kada se korisnik odluči odjaviti ili ako se GDM ili sesija neočekivano prekinu, korisnička sesija bit će poništena s ConsoleKita.</para>
  </sect1>

  <!-- ============= Configuration ============================= -->

  <sect1 id="configuration">
    <title>Podešavanje</title>

    <para lang="en">
      GDM has a number of configuration interfaces.  These include scripting
      integration points, daemon configuration, greeter configuration, 
      general session settings, integration with gnome-settings-daemon
      configuration, and session configuration.  These types of integration are
      described in detail below.
    </para>

    <sect2 id="scripting">
      <title lang="en">Scripting Integration Points</title>
      
      <para lang="en">
        The GDM script integration points can be found in the
        <filename>&lt;etc&gt;/gdm/</filename> directory:
      </para>

<screen lang="en">
Xsession
Init/
PostLogin/
PreSession/
PostSession/
</screen>

      <para lang="en">
        The <filename>Init</filename>, <filename>PostLogin</filename>,
        <filename>PreSession</filename>, and <filename>PostSession</filename>
        scripts all work as described below.
      </para>

      <para lang="en">
        For each type of script, the default one which will be executed is
        called "Default" and is stored in a directory associated with
        the script type.  So the default <filename>Init</filename> script is 
        <filename>&lt;etc&gt;/gdm/Init/Default</filename>.  A per-display
        script can be provided, and if it exists it will be run instead of the 
        default script.  Such scripts are stored in the same directory as the
        default script and have the same name as the Xserver DISPLAY value for
        that display.  For example, if the <filename>&lt;Init&gt;/:0</filename>
        script exists, it will be run for DISPLAY ":0".
     </para>

     <para lang="en">
        All of these scripts are run with root privilege and return 0 if run
        successfully, and a non-zero return code if there was any failure that
        should cause the login session to be aborted.  Also note that GDM will
        block until the scripts finish, so if any of these scripts hang, this
        will cause the login process to also hang.
      </para>

      <para lang="en">
        When the Xserver for the login GUI has been successfully started, but
        before the login GUI is actually displayed, GDM will run the
        <filename>Init</filename> script.  This script is useful for starting
        programs that should be run while the login screen is showing, or for
        doing any special initialization if required.
      </para>

      <para lang="en">
        After the user has been successfully authenticated GDM will run the
        <filename>PostLogin</filename> script.  This is done before any session
        setup has been done, including before the pam_open_session call.  This
        script is useful for doing any session initialization that needs to
        happen before the session starts.  For example, you might setup the
        user's $HOME directory if needed.
      </para>

      <para lang="en">
        After the user session has been initialized, GDM will run the
        <filename>PreSession</filename> script.  This script is useful for
        doing any session initialization that needs to happen after the 
        session has been initialized.  It can be used for session management or
        accounting, for example.
      </para>

      <para lang="en"> 
        When a user terminates their session, GDM will run the
        <filename>PostSession</filename> script.  Note that the Xserver will
        have been stopped by the time this script is run, so it should not be
        accessed.  
      </para>

      <para lang="en">
        Note that the <filename>PostSession</filename> script will be run
        even when the display fails to respond due to an I/O error or
        similar. Thus, there is no guarantee that X applications will work
        during script execution.
      </para>

      <para lang="en">
        All of the above scripts will set the
        <filename>$RUNNING_UNDER_GDM</filename> environment variable to
        <filename>yes</filename>.  If the scripts are also shared with other
        display managers, this allows you to identify when GDM is calling these
        scripts, so you can run specific code when GDM is used.
      </para>
    </sect2>

    <sect2 id="autostart">
      <title>Podešavanje automatskog pokretanja</title>
      
      <para lang="en">
        The <filename>&lt;share&gt;/gdm/autostart/LoginWindow</filename>
        directory contains files in the format specified by the
        "FreeDesktop.org Desktop Application Autostart
        Specification".  Standard features in the specification may be
        used to specify programs that should auto-restart or only be launched
        if a GConf configuration value is set, etc.
      </para>

      <para lang="en">
        Any <filename>.desktop</filename> files in this directory will cause
        the associated program to automatically start with the login GUI
        greeter.  By default, GDM is shipped with files which will autostart
        the gdm-simple-greeter login GUI greeter itself, the
        gnome-power-manager application, the gnome-settings-daemon, and the
        metacity window manager.  These programs are needed for the greeter
        program to work.  In addition, desktop files are provided for starting
        various AT programs if the configuration values specified in the
        Accessibility Configuration section below are set.
      </para>
    </sect2>

    <sect2 id="xsessionscript">
      <title>Xsession skripta</title>

      <para lang="en">
        There is also an <filename>Xsession</filename> script located at
        <filename>&lt;etc&gt;/gdm/Xsession</filename> which is called between
        the <filename>PreSession</filename> and the
        <filename>PostSession</filename> scripts.  This script does not
        support per-display like the other scripts.  This script is used for
        actually starting the user session.  This script is run as the user,
        and it will run whatever session was specified by the Desktop session
        file the user selected to start. 
      </para>
    </sect2>

    <sect2 id="daemonconfig">
      <title>Podešavanje pozadinskog programa</title>

      <para lang="en">
        The GDM daemon is configured using the
        <filename>&lt;etc&gt;/gdm/custom.conf</filename> file.  Default
        values are stored in GConf in the <filename>gdm.schemas</filename>
        file.  It is recommended that end-users modify the
        <filename>&lt;etc&gt;/gdm/custom.conf</filename> file because the
        schemas file may be overwritten when the user updates their system to
        have a newer version of GDM.
      </para>

      <para lang="en">
        Note that older versions of GDM supported additional configuration
        options which are no longer supported in the latest versions of GDM.
      </para>

      <para lang="en">
        The <filename>&lt;etc&gt;/gdm/custom.conf</filename> file is in the
        <filename>keyfile</filename> format.  Keywords in brackets
        define group sections, strings before an equal sign (=) are keys and
        the data after equal sign represents their value.  Empty lines or
        lines starting with the hash mark (#) are ignored.  
      </para>

      <para lang="en">
        The file <filename>&lt;etc&gt;/gdm/custom.conf</filename> supports the
        "[daemon]", "[security]", and "[xdmcp]"
        group sections.  Within each group, there are particular key/value
        pairs that can be specified to modify how GDM behaves.  For example,
        to enable timed login and specify the timed login user to be a user
        named "you", you would modify the file so it contains the
        following lines:
      </para>
     
<screen lang="en">
[daemon]
TimedLoginEnable=true
TimedLogin=you
</screen>

      <para lang="en">
        A full list of supported configuration keys follow:
      </para>

      <sect3 id="choosersection">
        <title lang="en">[chooser]</title>
        <variablelist>

          <varlistentry>
            <term lang="en">Multicast</term>
            <listitem>
              <synopsis lang="en">Multicast=false</synopsis>
              <para lang="en">
                If true and IPv6 is enabled, the chooser will send a multicast
                query to the local network and collect responses from the hosts
                who have joined multicast group.
              </para>
            </listitem>
          </varlistentry>
         
          <varlistentry>
            <term lang="en">MulticastAddr</term>
            <listitem>
              <synopsis lang="en">MulticastAddr=ff02::1</synopsis>
              <para lang="en">
                This is the Link-local multicast address.
              </para>
            </listitem>
          </varlistentry>
        </variablelist>
      </sect3>

      <sect3 id="daemonsection">
        <title lang="en">[daemon]</title>
        <variablelist>
          <varlistentry>
            <term lang="en">TimedLoginEnable</term>
            <listitem>
              <synopsis lang="en">TimedLoginEnable=false</synopsis>
              <para lang="en">
                 If the user given in <filename>TimedLogin</filename> should be
                logged in after a number of seconds (set with
                <filename>TimedLoginDelay</filename>) of inactivity on the
                login screen.  This is useful for public access terminals or
                perhaps even home use.  If the user uses the keyboard or
                browses the menus, the timeout will be reset to 
                <filename>TimedLoginDelay</filename> or 30 seconds, whichever 
                is higher.   If the user does not enter a username but just
                hits the ENTER key while the login program is requesting the
                username, then GDM will assume the user wants to login
                immediately as the timed user.  Note that no password will be
                asked for this user so you should be careful, although if using
                PAM it can be configured to require password entry before
                allowing login.  Refer to the "Security-&gt;PAM"
                section of the manual for more information, or for help if this
                feature does not seem to work.
              </para>
            </listitem>
          </varlistentry>

          <varlistentry>
            <term lang="en">TimedLogin</term>
            <listitem>
              <synopsis lang="en">TimedLogin=</synopsis>
              <para lang="en">
                This is the user that should be logged in after a specified
                number of seconds of inactivity.
              </para>
              <para lang="en">
                If the value ends with a vertical bar | (the pipe symbol),
                then GDM will execute the program specified and use whatever
                value is returned on standard out from the program as the user.
                The program is run with the DISPLAY environment variable set so
                that it is possible to specify the user in a per-display
                fashion.  For example if the value is "/usr/bin/getloginuser|",
                then the program "/usr/bin/getloginuser" will be run to get the
                user value.
              </para>
            </listitem>
          </varlistentry>

          <varlistentry>
            <term lang="en">TimedLoginDelay</term>
            <listitem>
              <synopsis lang="en">TimedLoginDelay=30</synopsis>
              <para lang="en">
                Delay in seconds before the <filename>TimedLogin</filename>
                user will be logged in.
              </para>
            </listitem>
          </varlistentry>

          <varlistentry>
            <term lang="en">AutomaticLoginEnable</term>
            <listitem>
              <synopsis lang="en">AutomaticLoginEnable=false</synopsis>
              <para lang="en">
                If true, the user given in <filename>AutomaticLogin</filename>
                should be logged in immediately. This feature is like timed
                login with a delay of 0 seconds.
              </para>
            </listitem>
          </varlistentry>

          <varlistentry>
            <term lang="en">AutomaticLogin</term>
            <listitem>
              <synopsis lang="en">AutomaticLogin=</synopsis>
              <para lang="en">
                This is the user that should be logged in immediately if
                <filename>AutomaticLoginEnable</filename> is true.
              </para>
              <para lang="en">
                If the value ends with a vertical bar | (the pipe symbol),
                then GDM will execute the program specified and use whatever
                value is returned on standard out from the program as the user.
                The program is run with the DISPLAY environment variable set so
                that it is possible to specify the user in a per-display
                fashion.  For example if the value is "/usr/bin/getloginuser|",
                then the program "/usr/bin/getloginuser" will be run to get the
                user value.
              </para>
            </listitem>
          </varlistentry>

          <varlistentry>
            <term>Korisnik</term>
            <listitem>
              <synopsis>User=gdm</synopsis>
              <para lang="en">
                The username under which the greeter and other GUI programs
                are run.  Refer to the <filename>Group</filename>
                configuration key and to the "Security-&gt;GDM User And
                Group" section of this document for more information.
              </para>
            </listitem>
          </varlistentry>

          <varlistentry>
            <term>Group</term>
            <listitem>
              <synopsis>Group=gdm</synopsis>
              <para lang="en">
                The group name under which the greeter and other GUI programs
                are run.  Refer to the <filename>User</filename>
                configuration key and to the "Security-&gt;GDM User And
                Group" section of this document for more information.
              </para>
            </listitem>
          </varlistentry>
        </variablelist>
      </sect3>

      <sect3 id="debugsection">
        <title>Mogućnosti otklanjanja grešaka</title>
      
        <variablelist>
          <title lang="en">[debug]</title>
          
          <varlistentry>
            <term lang="en">Enable</term>
            <listitem>
              <synopsis lang="en">Enable=false</synopsis>
              <para lang="en">
                To enable debugging, set the debug/Enable key to
                "true" in the
                <filename>&lt;etc&gt;/gdm/custom.conf</filename>
                file and restart GDM.  Then debug output will be sent to the
                system log file (<filename>&lt;var&gt;/log/messages</filename>
                or <filename>&lt;var&gt;/adm/messages</filename> depending on
                your Operating System).
              </para>
            </listitem>
          </varlistentry>
        </variablelist>
      </sect3>

      <sect3 id="greetersection">
        <title>Greeter mogućnosti</title>
      
        <variablelist>
          <title lang="en">[greeter]</title>
          
          <varlistentry>
            <term lang="en">IncludeAll</term>
            <listitem>
              <synopsis lang="en">IncludeAll=true</synopsis>
              <para lang="en">
                If true, then the face browser will show all users on the local
                machine.  If false, the face browser will only show users who
                have recently logged in.
              </para>

              <para lang="en">
                When this key is true, GDM will call fgetpwent() to get a list
                of local users on the system.  Any users with a user id less
                than 500 (or 100 if running on Oracle Solaris) are filtered
                out.  The Face Browser also will display any users that have
                previously logged in on the system  (for example NIS/LDAP
                users).  It gets this list via calling the
                <command>ck-history</command> ConsoleKit interface.  It will
                also filter out any users which do not have a valid shell
                (valid shells are any shell that getusershell() returns -
                /sbin/nologin or /bin/false are considered invalid shells even
                if getusershell() returns them).
              </para>

              <para lang="en">
                If false, then GDM more simply only displays users that have
                previously logged in on the system (local or NIS/LDAP users) by
                calling the <command>ck-history</command> ConsoleKit interface.
              </para>
            </listitem>
          </varlistentry>

          <varlistentry>
            <term lang="en">Include</term>
            <listitem>
              <synopsis lang="en">Include=</synopsis>
              <para lang="en">
                Set to a list of users to always include in the Face Browser.
                This value is set to a list of users separated by commas.  By
                default, the value is empty.
              </para>
            </listitem>
          </varlistentry>

          <varlistentry>
            <term lang="en">Exclude</term>
            <listitem>
              <synopsis lang="en">Exclude=bin,root,daemon,adm,lp,sync,shutdown,halt,mail,news,uucp,operator,nobody,nobody4,noaccess,postgres,pvm,rpm,nfsnobody,pcap</synopsis>
              <para lang="en">
                Set to a list of users to always exclude in the Face Browser.
                This value is set to a list of users separated by commas.  Note
                that the setting in the <filename>custom.conf</filename>
                overrides the default value, so if you wish to add additional
                users to the list, then you need to set the value to the
                default value with additional users appended to the list.
              </para>
            </listitem>
          </varlistentry>
        </variablelist>
      </sect3>

      <sect3 id="securitysection">
        <title>Mogućnosti sigurnosti</title>
      
        <variablelist>
          <title lang="en">[security]</title>
          
          <varlistentry>
            <term lang="en">DisallowTCP</term>
            <listitem>
              <synopsis lang="en">DisallowTCP=true</synopsis>
              <para lang="en">
                If true, then always append <filename>-nolisten tcp</filename>
                to the command line when starting attached Xservers, thus
                disallowing TCP connection.  This is a more secure
                configuration if you are not using remote connections.
              </para>
            </listitem>
          </varlistentry>
        </variablelist>
      </sect3>

      <sect3 id="xdmcpsection">
        <title lang="en">XDCMP Support</title>

        <variablelist>
          <title lang="en">[xdmcp]</title>
          
          <varlistentry>
            <term lang="en">DisplaysPerHost</term>
            <listitem>
              <synopsis lang="en">DisplaysPerHost=1</synopsis>
              <para lang="en">
                To prevent attackers from filling up the pending queue, GDM
                will only allow one connection for each remote computer.  If
                you want to provide display services to computers with more
                than one screen, you should increase this value.
              </para>

              <para lang="en">
                Note that the number of attached DISPLAYS allowed is not 
                limited.  Only remote connections via XDMCP are limited by
                this configuration option.
              </para>
            </listitem>
          </varlistentry>

          <varlistentry>
            <term lang="en">Enable</term>
            <listitem>
              <synopsis lang="en">Enable=false</synopsis>
              <para lang="en">
                Setting this to true enables XDMCP support allowing remote
                displays/X terminals to be managed by GDM.
              </para>
            
              <para lang="en">
                <filename>gdm</filename> listens for requests on UDP port 177.
                See the Port option for more information.
              </para>
              
              <para lang="en">
                If GDM is compiled to support it, access from remote displays
                can be controlled using the TCP Wrappers library. The service
                name is <filename>gdm</filename>
              </para>
            
              <para lang="en">
                You should add 
<screen lang="en">
gdm:.my.domain
</screen>
                to your <filename>&lt;etc&gt;/hosts.allow</filename>, depending
                on your TCP Wrappers configuration.  See the
                <ulink type="help" url="man:hosts.allow">hosts.allow</ulink>
                man page for details.
              </para>
              
              <para lang="en">
                Please note that XDMCP is not a particularly secure protocol
                and that it is a good idea to block UDP port 177 on your
                firewall unless you really need it.
              </para>
            </listitem>
          </varlistentry>
          
          <varlistentry>
            <term lang="en">HonorIndirect</term>
            <listitem>
              <synopsis lang="en">HonorIndirect=true</synopsis>
              <para lang="en">
                Enables XDMCP INDIRECT choosing (i.e. remote execution of
                <filename>gdmchooser</filename>) for X-terminals which do not
                supply their own display browser.
              </para>
            </listitem>
          </varlistentry>
        
          <varlistentry>
            <term lang="en">MaxPending</term>
            <listitem>
              <synopsis lang="en">MaxPending=4</synopsis>
              <para lang="en">
                To avoid denial of service attacks, GDM has fixed size queue
                of pending connections. Only MaxPending displays can start at
                the same time.
              </para>
            
              <para lang="en">
                Please note that this parameter does not limit the number of
                remote displays which can be managed. It only limits the number
                of displays initiating a connection simultaneously.
              </para>
            </listitem>
          </varlistentry>
          
          <varlistentry>
            <term lang="en">MaxSessions</term>
            <listitem>
              <synopsis lang="en">MaxSessions=16</synopsis>
              <para lang="en">
                Determines the maximum number of remote display connections
                which will be managed simultaneously. I.e. the total number of
                remote displays that can use your host.
              </para>
            </listitem>
          </varlistentry>
        
          <varlistentry>
            <term lang="en">MaxWait</term>
            <listitem>
              <synopsis lang="en">MaxWait=30</synopsis>
              <para lang="en">
                When GDM is ready to manage a display an ACCEPT packet is sent
                to it containing a unique session id which will be used in
                future XDMCP conversations.
              </para>
            
              <para lang="en">
                GDM will then place the session id in the pending queue
                waiting for the display to respond with a MANAGE request.
              </para>
            
              <para lang="en">
                If no response is received within MaxWait seconds, GDM will
                declare the display dead and erase it from the pending queue
                freeing up the slot for other displays.
              </para>
            </listitem>
          </varlistentry>
          
          <varlistentry>
            <term lang="en">MaxWaitIndirect</term>
            <listitem>
              <synopsis lang="en">MaxWaitIndirect=30</synopsis>
              <para lang="en">
                The MaxWaitIndirect parameter determines the maximum number of
                seconds between the time where a user chooses a host and the
                subsequent indirect query where the user is connected to the
                host.  When the timeout is exceeded, the information about the
                chosen host is forgotten and the indirect slot freed up for
                other displays.  The information may be forgotten earlier if
                there are more hosts trying to send indirect queries then
                <filename>MaxPendingIndirect</filename>.
              </para>
            </listitem>
          </varlistentry>
        
          <varlistentry>
            <term lang="en">PingIntervalSeconds</term>
            <listitem>
              <synopsis lang="en">PingIntervalSeconds=60</synopsis>
              <para lang="en">
                If the Xserver does not respond in the specified number of
                seconds, then the connection is stopped and the session ended.
                When this happens the daemon dies with an ALARM signal.
                Note that GDM 2.20 and earlier multiplied this setting by 2,
                so it may be necessary to increase the timeout if upgrading
                from GDM 2.20 and earlier to a newer version.
              </para>

              <para lang="en">
                Note that GDM in the past used to have a
                <filename>PingInterval</filename> configuration key which was
                also in minutes.  For most purposes you'd want this setting
                to be lower than one minute. However since in most cases where
                XDMCP would be used (such as terminal labs), a lag of more
                than 15 or so seconds would really mean that the terminal was
                turned off or restarted and you would want to end the session.
              </para>
            </listitem>
          </varlistentry>

          <varlistentry>
            <term>Ulaz</term>
            <listitem>
              <synopsis lang="en">Port=177</synopsis>
              <para lang="en">
                The UDP port number <filename>gdm</filename> should listen to
                for XDMCP requests. Do not change this unless you know what
                you are doing.
              </para>
            </listitem>
          </varlistentry>

          <varlistentry>
            <term lang="en">Willing</term>
            <listitem>
              <synopsis lang="en">Willing=&lt;etc&gt;/gdm/Xwilling</synopsis>
              <para lang="en">
                When the machine sends a WILLING packet back after a QUERY it
                sends a string that gives the current status of this server.
                The default message is the system ID, but it is possible to
                create a script that displays customized message.  If this
                script does not exist or this key is empty the default message
                is sent.  If this script succeeds and produces some output,
                the first line of it's output is sent (and only the first
                line).  It runs at most once every 3 seconds to prevent
                possible denial of service by flooding the machine with QUERY
                packets.
              </para>
            </listitem>
          </varlistentry>
        </variablelist>
      </sect3>
    </sect2>

    <sect2 id="greeterconfiguration">
        <title>Jednostavno Greeter podešavanje</title>

        <para lang="en">
          The GDM default greeter is called the simple Greeter and is
          configured via GConf.  Default values are stored in GConf in the
          <filename>gdm-simple-greeter.schemas</filename> file.  These defaults
          can be overridden if the "gdm" user has a writable $HOME
          directory to store GConf settings.  These values can be edited using
          the <command>gconftool-2</command> or <command>gconf-editor</command>
          programs.  The following configuration options are supported:
        </para>

        <variablelist>
          <title lang="en">Greeter Configuration Keys</title>

          <varlistentry>
            <term lang="en">/apps/gdm/simple-greeter/banner_message_enable</term>
            <listitem>
              <synopsis lang="en">false (boolean)</synopsis>
              <para lang="en">
                Controls whether the banner message text is displayed.
              </para>
            </listitem>
          </varlistentry>

          <varlistentry>
            <term lang="en">/apps/gdm/simple-greeter/banner_message_text</term>
            <listitem>
              <synopsis lang="en">NULL (string)</synopsis>
              <para lang="en">
                Specifies the text banner message to show on the greeter
                window.
              </para>
            </listitem>
          </varlistentry>

          <varlistentry>
            <term lang="en">/apps/gdm/simple-greeter/disable_restart_buttons</term>
            <listitem>
              <synopsis lang="en">false (boolean)</synopsis>
              <para lang="en">
                Controls whether to show the restart buttons in the login
                window.
              </para>
            </listitem>
          </varlistentry>

          <varlistentry>
            <term lang="en">/apps/gdm/simple-greeter/disable_user_list</term>
            <listitem>
              <synopsis lang="en">false (boolean)</synopsis>
              <para lang="en">
                If true, then the face browser with known users is not shown
                in the login window.
              </para>
            </listitem>
          </varlistentry>

          <varlistentry>
            <term lang="en">/apps/gdm/simple-greeter/logo_icon_name</term>
            <listitem>
              <synopsis lang="en">computer (string)</synopsis>
              <para lang="en">
                Set to the themed icon name to use for the greeter logo.
              </para>
            </listitem>
          </varlistentry>

          <varlistentry>
            <term lang="en">/apps/gdm/simple-greeter/recent-languages</term>
            <listitem>
              <synopsis lang="en">[] (string list)</synopsis>
              <para lang="en">
                Set to a list of languages to be shown by default in the login
                window.  Default value is "[]".  With the default setting only
                the system default language is shown and the option "Other..."
                which pops-up a dialog box showing a full list of available
                languages which the user can select.
              </para>

              <para lang="en">
                Users are not intended to change this setting by hand.  Instead
                GDM keeps track of any languages selected in this configuration
                key, and will show them in the language combo box along with
                the "Other..." choice.  This way, commonly selected languages
                are easier to select.
              </para>
            </listitem>
          </varlistentry>

          <varlistentry>
            <term lang="en">/apps/gdm/simple-greeter/recent-layouts</term>
            <listitem>
              <synopsis lang="en">[] (string list)</synopsis>
              <para lang="en">
                Set to a list of keyboard layouts to be shown by default in the
                login panel.  Default value is "[]".  With the default setting
                only the system default keyboard layout is shown and the option
                "Other..." which pops-up a dialog box showing a full list of
                available keyboard layouts which the user can select.
              </para>

              <para lang="en">
                Users are not intended to change this setting by hand.  Instead
                GDM keeps track of any keyboard layouts selected in this
                configuration key, and will show them in the keyboard layout
                combo box along with the "Other..." choice.  This way, commonly
                selected keyboard layouts are easier to select.
              </para>
            </listitem>
          </varlistentry>

          <varlistentry>
            <term lang="en">/apps/gdm/simple-greeter/wm_use_compiz</term>
            <listitem>
              <synopsis lang="en">false (boolean)</synopsis>
              <para lang="en">
                Controls whether compiz is used as the window manager instead
                of metacity.
              </para>
            </listitem>
          </varlistentry>
        </variablelist>
    </sect2>

    <sect2 id="accessibilityconfiguration">
     <title>Podešavanje pristupačnosti</title>

      <para lang="en">
       This section describes the accessibility configuration options available
       in GDM.
      </para>

      <sect3 id="accessibilitydialog">
        <title lang="en">GDM Accessibility Dialog And GConf Keys</title>

        <para lang="en">
         The GDM greeter panel at the login screen displays an accessibility
         icon.  Clicking on that icon opens the GDM Accessibility Dialog.  In
         the GDM Accessibility Dialog, there is a list of checkboxes, so the
         user can enable or disable the associated assistive tools.
        </para>

        <para lang="en">
         The checkboxes that correspond to the on-screen keyboard, screen
         magnifier and screen reader assistive tools act on the three GConf
         keys that are described in the next section of this document. By
         enabling or disabling these checkboxes, the associated GConf key is
         set to "true" or "false".  When the GConf key is set to true, the 
         assistive tools linked to this GConf key are launched.  When the 
         GConf key is set to "false", any running assistive tool linked to
         this GConf key are terminated.  These GConf keys are not automatically
         reset to a default state after the user has logged in.  Consequently,
         the assistive tools that were running during the last GDM login
         session will automatically be launched at the next GDM login session.
        </para>

        <para lang="en">
         The other checkboxes in the GDM Accessibility Dialog do not have
         corresponding GConf keys because no additional program is launched to
         provide the accessibility features that they offer.  These other
         options correspond to accessibility features that are provided by the
         Xserver, which is always running during the GDM session.
        </para>
      </sect3>

      <sect3 id="accessibilitygconfconfiguration">
        <title lang="en">Accessibility GConf Keys</title>

        <para lang="en">
         GDM offers the following GConf keys to control its accessibility
         features:
        </para>

        <variablelist>
          <title lang="en">GDM Configuration Keys</title>

          <varlistentry>
            <term lang="en">/desktop/gnome/interface/accessibility</term>
            <listitem>
              <synopsis lang="en">false (boolean)</synopsis>
              <para lang="en">
                Controls whether the Accessibility infrastructure will be
                started with the GDM GUI.  This is needed for many
                accessibility technology programs to work.
              </para>
            </listitem>
          </varlistentry>
          <varlistentry>
            <term lang="en">/desktop/gnome/applications/at/screen_magnifier_enabled</term>
            <listitem>
              <synopsis lang="en">false (boolean)</synopsis>
              <para lang="en">
                If set, then the assistive tools linked to this GConf key will
                be started with the GDM GUI program.  By default this is a
                screen magnifier application.
              </para>
            </listitem>
          </varlistentry>
          <varlistentry>
            <term lang="en">/desktop/gnome/applications/at/screen_keyboard_enabled</term>
            <listitem>
              <synopsis lang="en">false (boolean)</synopsis>
              <para lang="en">
                If set, then the assistive tools linked to this GConf key will
                be started with the GDM GUI program.  By default this is an
                on-screen keyboard application.
              </para>
            </listitem>
          </varlistentry>
          <varlistentry>
            <term lang="en">/desktop/gnome/applications/at/screen_reader_enabled</term>
            <listitem>
              <synopsis lang="en">false (boolean)</synopsis>
              <para lang="en">
                If set, then the assistive tools linked to this GConf key will
                be started with the GDM GUI program.  By default this is a
                screen reader application.
              </para>
            </listitem>
          </varlistentry>
        </variablelist>
      </sect3>

      <sect3 id="accessibilitytoolsconfiguration">
        <title lang="en">Linking GConf Keys to Accessibility Tools</title>

        <para lang="en">
         For the screen_magnifier_enabled, the screen_keyboard_enabled, and the
         screen_reader_enabled GConf keys, the assistive tool which gets
         launched depends on the desktop files located in the GDM autostart
         directory as described in the "Autostart Configuration" section of
         this manual.  Any desktop file in the GDM autostart directory can be
         linked to these GConf key via specifying that GConf key in the
         AutostartCondition value in the desktop file.  So the exact
         AutostartCondition line in the desktop file could be one of the
         following:
        </para>

<screen lang="en">
AutostartCondition=GNOME /desktop/gnome/applications/at/screen_keyboard_enabled
AutostartCondition=GNOME /desktop/gnome/applications/at/screen_magnifier_enabled
AutostartCondition=GNOME /desktop/gnome/applications/at/screen_reader_enabled
</screen>

        <para lang="en">
         When an accessibility key is true, then any program which is linked to
         that key in a GDM autostart desktop file will be launched (unless the
         Hidden key is set to true in that desktop file).  A single GConf key
         can even start multiple assistive tools if there are multiple desktop
         files with this AutostartCondition in the GDM autostart directory.
        </para>
      </sect3>

      <sect3 id="accessibilitytoolexample">
        <title lang="en">Example Of Modifying Accessibility Tool Configuration</title>

        <para lang="en">
         For example, if GNOME is distributed with GOK as the default on-screen
         keyboard, then this could be replaced with a different program if
         desired.  To replace GOK with the on-screen keyboard application
         "onboard" and additionally activate the assistive tool "mousetweaks"
         for dwelling support, then the following configuration is needed.
        </para>

        <para lang="en">
         Create a desktop file for onboard and a second one for mousetweaks;
         for example, onboard.desktop and mousetweaks.desktop. These files
         must be placed in the GDM autostart directory and be in the format
         as explained in the "Autostart Configuration" section of this
         document.
        </para>

        <para lang="en">
         The following is an example <filename>onboard.desktop</filename> file:
        </para>

<screen lang="en">
[Desktop Entry]
Encoding=UTF-8
Name=Onboard Onscreen Keyboard
Comment=Use an on-screen keyboard
TryExec=onboard
Exec=onboard --size 500x180 -x 20 -y 10
Terminal=false
Type=Application
StartupNotify=true
Categories=GNOME;GTK;Accessibility;
AutostartCondition=GNOME /desktop/gnome/applications/at/screen_keyboard_enabled
</screen>

        <para lang="en">
         The following is an example <filename>mousetweaks.desktop</filename>
         file:
        </para>

<screen lang="en">
[Desktop Entry]
Encoding=UTF-8
Name=Software Mouse-Clicks
Comment=Perform clicks by dwelling with the pointer
TryExec=mousetweaks
Exec=mousetweaks --enable-dwell -m window -c -x 20 -y 240 
Terminal=false
Type=Application
StartupNotify=true
Categories=GNOME;GTK;Accessibility;
AutostartCondition=GNOME /desktop/gnome/applications/at/screen_keyboard_enabled
</screen>

        <para lang="en">
         Note the line with the AutostartCondition that links both desktop
         files to the GConf key for the on-screen keyboard.
        </para>

        <para lang="en">
         To disable GOK from starting, the desktop file for the GOK on-screen
         keyboard must be removed or deactivated.  Otherwise onboard and GOK
         would simultaneously be started.  This can be done by removing the
         gok.desktop file from the GDM autostart directory, or by adding the
         "Hidden=true" key setting to the gok.desktop file.
        </para>

        <para lang="en">
         After making these changes, GOK will no longer be started when the
         user activates the on-screen keyboard in the GDM session; but onboard
         and mousetweaks will instead be launched.
        </para>
      </sect3>
    </sect2>

    <sect2 id="generalsessionconfig">
      <title>Opće postavke sesije</title>
<!--
<para>
          TODO - I think this section should be expanded upon.  What specific
                 keys are of interest, or would some users be likely to want
                 to configure?  Also, would be good to be more specific about
                 how lock down management is handled.
</para>
-->
        <para lang="en">
          The GDM Greeter uses some of the same framework that your desktop
          session will use. And so, it is influenced by a number of the same
          GConf settings. For each of these settings the Greeter will use the
          default value unless it is specifically overridden by a) GDM's
          installed mandatory policy b) system mandatory policy. GDM installs
          its own mandatory policy to lock down some settings for security.
        </para>
    </sect2>

    <sect2 id="gnomesettingsdaemon">
      <title>GNOME postavke pozadinskog programa</title>
<!--
<para>
          TODO - I think this section should be expanded upon.  What specific
                 keys are of interest, or would some users be likely to want
                 to configure?  Also, would be good to give a more complete
                 list of plugins that users might want to consider disabling.
                 Also, shouldn't we list the sound/active key in the Greeter
                 configuration setting?  Oddly I do not find this key used
                 in anything but the chooser in SVN.
</para>
-->

        <para lang="en">
          GDM enables the following gnome-settings-daemon plugins:
          a11y-keyboard, background, sound, xsettings.
        </para>

        <para lang="en">
          These are responsible for things like the background image, font and
          theme settings, sound events, etc.
        </para>

        <para lang="en">
          Plugins can also be disabled using GConf. For example, if you want to
          disable the sound plugin then unset the following key:
          <filename>/apps/gdm/simple-greeter/settings-manager-plugins/sound/active</filename>.
        </para>
    </sect2>

    <sect2 id="sessionconfig">
      <title>Podešavanje GDM sesije</title>

      <para lang="en">
        GDM sessions are specified using the FreeDesktop.org Desktop Entry
        Specification, which can be referenced at the following URL:
        <ulink url="http://www.freedesktop.org/wiki/Specifications/desktop-entry-spec">
        http://www.freedesktop.org/wiki/Specifications/desktop-entry-spec</ulink>.
      </para>

      <para lang="en">
        By default, GDM will install desktop files in the
        <filename>&lt;share&gt;/xsessions</filename> directory.  GDM will
        search the following directories in this order to find desktop files:
        <filename>&lt;etc&gt;/X11/sessions/</filename>,
        <filename>&lt;dmconfdir&gt;/Sessions</filename>, 
        <filename>&lt;share&gt;/xsessions</filename>, and
        <filename>&lt;share&gt;/gdm/BuiltInSessions</filename>.  By default the
        <filename>&lt;dmconfdir&gt;</filename> is set to
        <filename>&lt;etc&gt;/dm/</filename> unless GDM is configured to use
        a different directory via the "--with-dmconfdir" option.
      </para>

      <para lang="en">
        A session can be disabled by editing the desktop file and adding a line
        as follows: <filename>Hidden=true</filename>.
      </para>

      <para lang="en">
        GDM desktop files support a GDM-specific extension, a key named
        "X-GDM-BypassXsession".  If the key is not specified in a
        desktop file, the value defaults to "false".  If this key is
        specified to be "true" in a desktop file, then GDM will
        launch the program specified by the desktop file "Exec" key
        directly when starting the user session.  It will not run the program
        via the <filename>&lt;etc&gt;/gdm/Xsession</filename> script, which is
        the normal behavior.  Since bypassing the
        <filename>&lt;etc&gt;/gdm/Xsession</filename> script avoids setting up
        the user session with the normal system and user settings, sessions
        started this way can be useful for debugging problems in the system or
        user scripts that might be preventing a user from being able to start
        a session.
      </para>

    </sect2>

    <sect2 id="userconfig">
      <title lang="en">GDM User Session and Language Configuration</title>
      <para lang="en">
        The user's default session and language choices are stored in the
        <filename>~/.dmrc</filename> file.  When a user logs in for the first
        time, this file is created with the user's initial choices.  The user
        can change these default values by simply changing to a different value
        when logging in.  GDM will remember this change for subsequent logins.
      </para>

      <para lang="en">
        The <filename>~/.dmrc</filename> file is in the standard
        <filename>INI</filename> format.  It has one section called
        <filename>[Desktop]</filename> which has two keys:
        <filename>Session</filename> and <filename>Language</filename>.
      </para>

      <para lang="en">
        The <filename>Session</filename> key specifies the basename of the
        session <filename>.desktop</filename> file that the user wishes to
        normally use without the <filename>.desktop</filename> extension.
        The <filename>Language</filename> key specifies the language that the
        user wishes to use by default.  If either of these keys is missing, the
        system default is used.  The file would normally look as follows:
      </para>

<screen lang="en">
[Desktop]
Session=gnome
Language=cs_CZ.UTF-8
</screen>
    </sect2>

  </sect1>

  <!-- ============= GDM Commands ============================= -->

  <sect1 id="binaries">
    <title>GDM naredbe</title>

    <sect2 id="sbindir_binaries">
      <title>GDM naredbe korijenskog korisnika</title>

      <para lang="en">
        The GDM package provides the following commands in
        <filename>sbindir</filename> intended to be run by the root user:
      </para>

      <sect3 id="gdmcommandline">
        <title lang="en"><command>gdm</command> Command Line Options</title>

        <para lang="en">
          <command>gdm</command> is the main daemon which sets up
          graphical login environment and starts necessary helpers.
       </para>

        <variablelist>
          <title lang="en"><command>gdm</command> Command Line Options</title>

          <varlistentry>
            <term lang="en">-?, --help</term>
            <listitem>
              <para lang="en">
                Gives a brief overview of the command line options.
              </para>
            </listitem>
          </varlistentry>

          <varlistentry>
            <term lang="en">--fatal-warnings</term>
            <listitem>
              <para lang="en">
                Make all warnings cause GDM to exit.
              </para>
            </listitem>
          </varlistentry>

          <varlistentry>
            <term lang="en">--timed-exit</term>
            <listitem>
              <para lang="en">
                Exit after 30 seconds.  Useful for debugging.
              </para>
            </listitem>
          </varlistentry>

          <varlistentry>
            <term lang="en">--version</term>
            <listitem>
              <para lang="en">
                Print the version of the GDM daemon.
              </para>
            </listitem>
          </varlistentry>
        </variablelist>
      </sect3>

      <sect3 id="gdmrestartcommandline">
        <title lang="en"><command>gdm-restart</command> Command Line Options</title>

        <para lang="en">
          <command>gdm-restart</command> stops and restarts GDM by sending
          the GDM daemon a HUP signal.  This command will immediately terminate
          all sessions and log out users currently logged in with GDM.
        </para>
      </sect3>

      <sect3 id="gdmsaferestartcommandline">
        <title lang="en"><command>gdm-safe-restart</command> Command Line Options</title>
  
        <para lang="en">
          <command>gdm-safe-restart</command> stops and restarts GDM by
          sending the GDM daemon a USR1 signal.  GDM will be restarted as soon
          as all users log out.
        </para>
      </sect3>

      <sect3 id="gdmstopcommandline">
        <title lang="en"><command>gdm-stop</command> Command Line Options</title>

        <para lang="en">
          <command>gdm-stop</command> stops GDM by sending the GDM daemon
          a TERM signal. 
        </para>
      </sect3>
    </sect2>
  </sect1>

  <!-- ============= Troubleshooting =========================== -->

  <sect1 id="troubleshooting">
    <title>Rješavanje problema</title>
<!--
<para>
      TODO - any other tips we should add?  Might be useful to highlight any
             common D-Bus configuration issues?
</para>
-->

    <para lang="en">
      This section discusses helpful tips for getting GDM working.  In general,
      if you have a problem using GDM, you can submit a bug or send an email
      to the gdm-list mailing list.  Information about how to do this is in
      the Introduction section of the document.
    </para>

    <para lang="en">
      If GDM is failing to work properly, it is always a good idea to include
      debug information.  To enable debugging, set the debug/Enable key to
      "true" in the <filename>&lt;etc&gt;/gdm/custom.conf</filename>
      file and restart GDM.  Then use GDM to the point where it fails, and
      debug output will be sent to the system log file
      (<filename>&lt;var&gt;/log/messages</filename> or
      <filename>&lt;var&gt;/adm/messages</filename> depending on your Operating
      System).  If you share this output with the GDM community via a bug
      report or email, please only include the GDM related debug information
      and not the entire file since it can be large.  If you do not see any
      GDM syslog output, you may need to configure syslog (refer to the
      <ulink type="help" url="man:syslog">syslog</ulink> man page).
    </para>

    <sect2 id="wontstart">
      <title>GDM se neće pokrenuti</title>

      <para lang="en">
         There are a many problems that can cause GDM to fail to start, but
         this section will discuss a few common problems and how to approach
         tracking down a problem with GDM starting.   Some problems will 
         cause GDM to respond with an error message or dialog when it tries
         to start, but it can be difficult to track down problems when GDM
         fails silently.
      </para>

      <para lang="en">
         First make sure that the Xserver is configured properly.  The 
         GDM configuration file contains a command in the [server-Standard]
         section that is used for starting the Xserver.  Verify that this
         command works on your system.  Running this command from the 
         console should start the Xserver.  If it fails, then the problem
         is likely with your Xserver configuration.  Refer to your Xserver
         error log for an idea of what the problem may be.  The problem may
         also be that your Xserver requires different command-line options.
         If so, then modify the Xserver command in the GDM configuration file
         so that it is correct for your system.
      </para>

      <para lang="en">
         Also make sure that the <filename>/tmp</filename> directory has
         reasonable ownership and permissions, and that the machine's file
         system is not full.  These problems will cause GDM to fail to start.
      </para>
    </sect2>
  </sect1>

  <!-- ============= Application License ============================= -->

  <sect1 id="license">
    <title>Licenca</title>
    <para lang="en">
      This program is free software; you can redistribute it and/or
      modify it under the terms of the  <ulink type="help" url="gnome-help:gpl">
      <citetitle>GNU General Public License</citetitle></ulink> as
      published by the Free Software Foundation; 
      either version 2 of the License, or (at your option) any later
      version.
    </para>
    <para lang="en">
      This program is distributed in the hope that it will be useful, but
      WITHOUT ANY WARRANTY; without even the implied warranty of
      MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
      <citetitle>GNU General Public License</citetitle> for more details.
    </para>
    <para lang="en">
      A copy of the <citetitle>GNU General Public License</citetitle> is
      included as an appendix to the <citetitle>GNOME Users
      Guide</citetitle>.  You may also obtain a copy of the
      <citetitle>GNU General Public License</citetitle> from the Free
      Software Foundation by visiting
      <ulink type="http" url="http://www.fsf.org">their Web site</ulink> or by
      writing to
      <address lang="en">
      Free Software Foundation, Inc.
      <street>51 Franklin Street, Fifth Floor</street>
      <city>Boston</city>, <state>MA</state> <postcode>02110-1301</postcode>
      <country>USA</country>
      </address>
    </para>
  </sect1>
</article>
<!-- Keep this comment at the end of the file
Local variables:
mode: sgml
sgml-omittag:t
sgml-shorttag:t
sgml-minimize-attributes:nil
sgml-always-quote-attributes:t
sgml-indent-step:2
sgml-indent-data:t
sgml-parent-document:nil
sgml-exposed-tags:nil
sgml-local-catalogs:nil
sgml-local-ecat-files:nil
End:
-->
