<?xml version="1.0"?>
<!DOCTYPE profile>
<profile xmlns="http://www.suse.com/1.0/yast2ns" xmlns:config="http://www.suse.com/1.0/configns">
  <add-on>
    <add_on_others config:type="list">
      <listentry>
        <alias>repo-non-oss</alias>
        <media_url><![CDATA[http://download.opensuse.org/distribution/leap/15.2/repo/non-oss/]]></media_url>
        <name>Non-OSS Repository</name>
        <priority config:type="integer">99</priority>
        <product_dir>/</product_dir>
      </listentry>
      <listentry>
        <alias>repo-update</alias>
        <media_url><![CDATA[http://download.opensuse.org/update/leap/15.2/oss/]]></media_url>
        <name>Main Update Repository</name>
        <priority config:type="integer">99</priority>
        <product_dir>/</product_dir>
      </listentry>
      <listentry>
        <alias>repo-update-non-oss</alias>
        <media_url><![CDATA[http://download.opensuse.org/update/leap/15.2/non-oss/]]></media_url>
        <name>Update Repository (Non-Oss)</name>
        <priority config:type="integer">99</priority>
        <product_dir>/</product_dir>
      </listentry>
    </add_on_others>
    <add_on_products config:type="list"/>
  </add-on>
  <bootloader>
    <global>
      <append>splash=silent resume=/dev/disk/by-id/ata-SATA_SSD_A45A079C1C8600706471-part1 quiet mitigations=auto</append>
      <cpu_mitigations>auto</cpu_mitigations>
      <gfxmode>auto</gfxmode>
      <hiddenmenu>false</hiddenmenu>
      <os_prober>true</os_prober>
      <secure_boot>false</secure_boot>
      <terminal>gfxterm</terminal>
      <timeout config:type="integer">8</timeout>
      <xen_kernel_append>vga=gfx-1024x768x16</xen_kernel_append>
    </global>
    <loader_type>grub2-efi</loader_type>
  </bootloader>
  <deploy_image>
    <image_installation config:type="boolean">false</image_installation>
  </deploy_image>
  <firewall>
    <default_zone>public</default_zone>
    <enable_firewall config:type="boolean">false</enable_firewall>
    <log_denied_packets>off</log_denied_packets>
    <start_firewall config:type="boolean">false</start_firewall>
    <zones config:type="list">
      <zone>
        <description>Unsolicited incoming network packets are rejected. Incoming packets that are related to outgoing network connections are accepted. Outgoing network connections are allowed.</description>
        <interfaces config:type="list"/>
        <masquerade config:type="boolean">false</masquerade>
        <name>block</name>
        <ports config:type="list"/>
        <protocols config:type="list"/>
        <services config:type="list"/>
        <short>Block</short>
        <target>%%REJECT%%</target>
      </zone>
      <zone>
        <description>For computers in your demilitarized zone that are publicly-accessible with limited access to your internal network. Only selected incoming connections are accepted.</description>
        <interfaces config:type="list"/>
        <masquerade config:type="boolean">false</masquerade>
        <name>dmz</name>
        <ports config:type="list"/>
        <protocols config:type="list"/>
        <services config:type="list">
          <service>ssh</service>
        </services>
        <short>DMZ</short>
        <target>default</target>
      </zone>
      <zone>
        <description>Unsolicited incoming network packets are dropped. Incoming packets that are related to outgoing network connections are accepted. Outgoing network connections are allowed.</description>
        <interfaces config:type="list"/>
        <masquerade config:type="boolean">false</masquerade>
        <name>drop</name>
        <ports config:type="list"/>
        <protocols config:type="list"/>
        <services config:type="list"/>
        <short>Drop</short>
        <target>DROP</target>
      </zone>
      <zone>
        <description>For use on external networks. You do not trust the other computers on networks to not harm your computer. Only selected incoming connections are accepted.</description>
        <interfaces config:type="list"/>
        <masquerade config:type="boolean">true</masquerade>
        <name>external</name>
        <ports config:type="list"/>
        <protocols config:type="list"/>
        <services config:type="list">
          <service>ssh</service>
        </services>
        <short>External</short>
        <target>default</target>
      </zone>
      <zone>
        <description>For use in home areas. You mostly trust the other computers on networks to not harm your computer. Only selected incoming connections are accepted.</description>
        <interfaces config:type="list"/>
        <masquerade config:type="boolean">false</masquerade>
        <name>home</name>
        <ports config:type="list"/>
        <protocols config:type="list"/>
        <services config:type="list">
          <service>ssh</service>
          <service>mdns</service>
          <service>samba-client</service>
          <service>dhcpv6-client</service>
        </services>
        <short>Home</short>
        <target>default</target>
      </zone>
      <zone>
        <description>For use on internal networks. You mostly trust the other computers on the networks to not harm your computer. Only selected incoming connections are accepted.</description>
        <interfaces config:type="list"/>
        <masquerade config:type="boolean">false</masquerade>
        <name>internal</name>
        <ports config:type="list"/>
        <protocols config:type="list"/>
        <services config:type="list">
          <service>ssh</service>
          <service>mdns</service>
          <service>samba-client</service>
          <service>dhcpv6-client</service>
        </services>
        <short>Internal</short>
        <target>default</target>
      </zone>
      <zone>
        <description>For use in public areas. You do not trust the other computers on networks to not harm your computer. Only selected incoming connections are accepted.</description>
        <interfaces config:type="list"/>
        <masquerade config:type="boolean">false</masquerade>
        <name>public</name>
        <ports config:type="list"/>
        <protocols config:type="list"/>
        <services config:type="list">
          <service>ssh</service>
          <service>dhcpv6-client</service>
          <service>tigervnc</service>
          <service>tigervnc-https</service>
        </services>
        <short>Public</short>
        <target>default</target>
      </zone>
      <zone>
        <description>All network connections are accepted.</description>
        <interfaces config:type="list"/>
        <masquerade config:type="boolean">false</masquerade>
        <name>trusted</name>
        <ports config:type="list"/>
        <protocols config:type="list"/>
        <services config:type="list"/>
        <short>Trusted</short>
        <target>ACCEPT</target>
      </zone>
      <zone>
        <description>For use in work areas. You mostly trust the other computers on networks to not harm your computer. Only selected incoming connections are accepted.</description>
        <interfaces config:type="list"/>
        <masquerade config:type="boolean">false</masquerade>
        <name>work</name>
        <ports config:type="list"/>
        <protocols config:type="list"/>
        <services config:type="list">
          <service>ssh</service>
          <service>dhcpv6-client</service>
        </services>
        <short>Work</short>
        <target>default</target>
      </zone>
    </zones>
  </firewall>
  <general>
    <mode>
      <confirm config:type="boolean">false</confirm>
    </mode>
  </general>
  <groups config:type="list">
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>100</gid>
      <group_password>x</group_password>
      <groupname>users</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>1</gid>
      <group_password>x</group_password>
      <groupname>bin</groupname>
      <userlist>daemon</userlist>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>496</gid>
      <group_password>x</group_password>
      <groupname>polkitd</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>491</gid>
      <group_password>x</group_password>
      <groupname>utmp</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>478</gid>
      <group_password>x</group_password>
      <groupname>systemd-network</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>484</gid>
      <group_password>x</group_password>
      <groupname>lp</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>477</gid>
      <group_password>x</group_password>
      <groupname>systemd-timesync</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>468</gid>
      <group_password>x</group_password>
      <groupname>vnc</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>485</gid>
      <group_password>x</group_password>
      <groupname>kvm</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>51</gid>
      <group_password>x</group_password>
      <groupname>postfix</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>65533</gid>
      <group_password>x</group_password>
      <groupname>nogroup</groupname>
      <userlist>nobody</userlist>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>493</gid>
      <group_password>x</group_password>
      <groupname>wheel</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>488</gid>
      <group_password>x</group_password>
      <groupname>dialout</groupname>
      <userlist>elpos</userlist>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>5</gid>
      <group_password>x</group_password>
      <groupname>tty</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>65534</gid>
      <group_password>x</group_password>
      <groupname>nobody</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>2</gid>
      <group_password>x</group_password>
      <groupname>daemon</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>483</gid>
      <group_password>x</group_password>
      <groupname>tape</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>15</gid>
      <group_password>x</group_password>
      <groupname>shadow</groupname>
      <userlist>vnc</userlist>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>498</gid>
      <group_password>x</group_password>
      <groupname>mysql</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>479</gid>
      <group_password>x</group_password>
      <groupname>systemd-journal</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>475</gid>
      <group_password>x</group_password>
      <groupname>pulse</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>471</gid>
      <group_password>x</group_password>
      <groupname>sshd</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>0</gid>
      <group_password>x</group_password>
      <groupname>root</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>487</gid>
      <group_password>x</group_password>
      <groupname>disk</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>474</gid>
      <group_password>x</group_password>
      <groupname>pulse-access</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>490</gid>
      <group_password>x</group_password>
      <groupname>audio</groupname>
      <userlist>pulse</userlist>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>472</gid>
      <group_password>x</group_password>
      <groupname>nscd</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>42</gid>
      <group_password>x</group_password>
      <groupname>trusted</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>59</gid>
      <group_password>x</group_password>
      <groupname>maildrop</groupname>
      <userlist>postfix</userlist>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>495</gid>
      <group_password>!</group_password>
      <groupname>mail</groupname>
      <userlist>postfix</userlist>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>492</gid>
      <group_password>x</group_password>
      <groupname>kmem</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>469</gid>
      <group_password>x</group_password>
      <groupname>lightdm</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>467</gid>
      <group_password>x</group_password>
      <groupname>sddm</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>62</gid>
      <group_password>x</group_password>
      <groupname>man</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>497</gid>
      <group_password>x</group_password>
      <groupname>messagebus</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>480</gid>
      <group_password>x</group_password>
      <groupname>tftp</groupname>
      <userlist>dnsmasq,tftp</userlist>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>499</gid>
      <group_password>x</group_password>
      <groupname>lock</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>486</gid>
      <group_password>x</group_password>
      <groupname>input</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>473</gid>
      <group_password>x</group_password>
      <groupname>chrony</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>489</gid>
      <group_password>x</group_password>
      <groupname>cdrom</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>71</gid>
      <group_password>x</group_password>
      <groupname>ntadmin</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>482</gid>
      <group_password>x</group_password>
      <groupname>video</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>481</gid>
      <group_password>x</group_password>
      <groupname>rtkit</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>476</gid>
      <group_password>x</group_password>
      <groupname>systemd-coredump</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>470</gid>
      <group_password>x</group_password>
      <groupname>avahi</groupname>
      <userlist/>
    </group>
    <group>
      <encrypted config:type="boolean">true</encrypted>
      <gid>494</gid>
      <group_password>!</group_password>
      <groupname>ftp</groupname>
      <userlist/>
    </group>
  </groups>
  <host>
    <hosts config:type="list">
      <hosts_entry>
        <host_address>127.0.0.1</host_address>
        <names config:type="list">
          <name>localhost amora-mia</name>
        </names>
      </hosts_entry>
      <hosts_entry>
        <host_address>192.168.1.1</host_address>
        <names config:type="list">
          <name>amora-mia</name>
        </names>
      </hosts_entry>
      <hosts_entry>
        <host_address>::1</host_address>
        <names config:type="list">
          <name>localhost ipv6-localhost ipv6-loopback</name>
        </names>
      </hosts_entry>
      <hosts_entry>
        <host_address>fe00::0</host_address>
        <names config:type="list">
          <name>ipv6-localnet</name>
        </names>
      </hosts_entry>
      <hosts_entry>
        <host_address>ff00::0</host_address>
        <names config:type="list">
          <name>ipv6-mcastprefix</name>
        </names>
      </hosts_entry>
      <hosts_entry>
        <host_address>ff02::1</host_address>
        <names config:type="list">
          <name>ipv6-allnodes</name>
        </names>
      </hosts_entry>
      <hosts_entry>
        <host_address>ff02::2</host_address>
        <names config:type="list">
          <name>ipv6-allrouters</name>
        </names>
      </hosts_entry>
      <hosts_entry>
        <host_address>ff02::3</host_address>
        <names config:type="list">
          <name>ipv6-allhosts</name>
        </names>
      </hosts_entry>
    </hosts>
  </host>
  <keyboard>
    <keymap>english-us</keymap>
  </keyboard>
  <language>
    <language>en_US</language>
    <languages>he_IL,en_US</languages>
  </language>
  <login_settings>
    <autologin_user>elpos</autologin_user>
    <password_less_login config:type="boolean">true</password_less_login>
  </login_settings>
  <networking>
    <dhcp_options>
      <dhclient_client_id/>
      <dhclient_hostname_option>AUTO</dhclient_hostname_option>
    </dhcp_options>
    <dns>
      <dhcp_hostname config:type="boolean">true</dhcp_hostname>
      <hostname>posadmin</hostname>
      <resolv_conf_policy>auto</resolv_conf_policy>
    </dns>
    <interfaces config:type="list">
      <interface>
        <bootproto>dhcp</bootproto>
        <name>eth0</name>
        <startmode>auto</startmode>
      </interface>
      <interface>
        <bootproto>dhcp</bootproto>
        <mtu>0</mtu>
        <name>eth1</name>
        <startmode>auto</startmode>
      </interface>
      <interface>
        <bootproto>dhcp</bootproto>
        <name>p8p1</name>
        <startmode>auto</startmode>
      </interface>
    </interfaces>
    <ipv6 config:type="boolean">false</ipv6>
    <keep_install_network config:type="boolean">true</keep_install_network>
    <managed config:type="boolean">true</managed>
    <routing>
      <ipv4_forward config:type="boolean">false</ipv4_forward>
      <ipv6_forward config:type="boolean">false</ipv6_forward>
    </routing>
  </networking>
  <nis>
    <netconfig_policy>auto</netconfig_policy>
    <nis_broadcast config:type="boolean">false</nis_broadcast>
    <nis_broken_server config:type="boolean">false</nis_broken_server>
    <nis_domain/>
    <nis_local_only config:type="boolean">false</nis_local_only>
  </nis>
  <ntp-client>
    <ntp_policy><![CDATA[auto]]></ntp_policy>
    <ntp_servers config:type="list">
      <ntp_server>
        <address>0.opensuse.pool.ntp.org</address>
        <iburst config:type="boolean">true</iburst>
        <offline config:type="boolean">false</offline>
      </ntp_server>
      <ntp_server>
        <address>1.opensuse.pool.ntp.org</address>
        <iburst config:type="boolean">true</iburst>
        <offline config:type="boolean">false</offline>
      </ntp_server>
      <ntp_server>
        <address>2.opensuse.pool.ntp.org</address>
        <iburst config:type="boolean">true</iburst>
        <offline config:type="boolean">false</offline>
      </ntp_server>
      <ntp_server>
        <address>3.opensuse.pool.ntp.org</address>
        <iburst config:type="boolean">true</iburst>
        <offline config:type="boolean">false</offline>
      </ntp_server>
    </ntp_servers>
    <ntp_sync>systemd</ntp_sync>
  </ntp-client>
  <partitioning config:type="list">
    <drive>
      <device>/dev/sda</device>
      <disklabel>msdos</disklabel>
      <enable_snapshots config:type="boolean">false</enable_snapshots>
      <initialize config:type="boolean">false</initialize>
      <partitions config:type="list">
        <partition>
          <create config:type="boolean">true</create>
          <filesystem config:type="symbol">swap</filesystem>
          <format config:type="boolean">true</format>
          <mount>swap</mount>
          <mountby config:type="symbol">uuid</mountby>
          <partition_id config:type="integer">253</partition_id>
          <partition_nr config:type="integer">1</partition_nr>
          <partition_type>primary</partition_type>
          <resize config:type="boolean">false</resize>
          <size>4198498304</size>
        </partition>
        <partition>
          <create config:type="boolean">true</create>
          <filesystem config:type="symbol">ext4</filesystem>
          <format config:type="boolean">true</format>
          <mount>/</mount>
          <mountby config:type="symbol">uuid</mountby>
          <partition_id config:type="integer">131</partition_id>
          <partition_nr config:type="integer">2</partition_nr>
          <partition_type>primary</partition_type>
          <resize config:type="boolean">false</resize>
          <size>68719476736</size>
        </partition>
        <partition>
          <create config:type="boolean">true</create>
          <filesystem config:type="symbol">vfat</filesystem>
          <format config:type="boolean">true</format>
          <mount>/boot/efi</mount>
          <mountby config:type="symbol">uuid</mountby>
          <partition_id config:type="integer">131</partition_id>
          <partition_nr config:type="integer">3</partition_nr>
          <partition_type>primary</partition_type>
          <resize config:type="boolean">false</resize>
          <size>524288000</size>
        </partition>
      </partitions>
      <type config:type="symbol">CT_DISK</type>
      <use>all</use>
    </drive>
  </partitioning>
  <printer>
    <client_conf_content>
      <file_contents><![CDATA[# CUPS client configuration file (optional).

# You may use /etc/cups/client.conf (system wide)
# or ~/.cups/client.conf (per user).
# For more information see "man 5 client.conf".

# The ServerName directive specifies the remote server
# that is to be used for all client operations. That is, it
# redirects all client requests directly to that remote server
# so that a local running cupsd is not used in this case.
# The default is to use the local server ("localhost") or domain socket.
# Only one ServerName directive may appear.
# If multiple names are present, only the last one is used.
# The default port number is 631 but can be overridden by adding
# a colon followed by the desired port number.
# The default IPP version is 2.0 but can be overridden by adding
# a slash followed by version=V where V is 1.0 or 1.1 or 2.0 or 2.1 or 2.2.
# IPP version 2.0 does do not work with CUPS 1.3 or older servers.
# If an CUPS 1.3 or older server is used, its older IPP version
# must be specified as .../version=1.1 or .../version=1.0.

# Examples:
# ServerName sever.example.com
# ServerName 192.0.2.10
# ServerName sever.example.com:8631
# ServerName older.server.example.com/version=1.1
# ServerName older.server.example.com:8631/version=1.1

]]></file_contents>
    </client_conf_content>
    <cupsd_conf_content>
      <file_contents><![CDATA[#
# Configuration file for the CUPS scheduler.  See "man cupsd.conf" for a
# complete description of this file.
#

# Log general information in error_log - change "warn" to "debug"
# for troubleshooting...
LogLevel warn
PageLogFormat

# Only listen for connections from the local machine.
Listen localhost:631
Listen /run/cups/cups.sock

# Show shared printers on the local network.
Browsing On
BrowseLocalProtocols dnssd

# Default authentication type, when authentication is required...
DefaultAuthType Basic

# Web interface setting...
WebInterface Yes

# Restrict access to the server...
<Location />
  Order allow,deny
</Location>

# Restrict access to the admin pages...
<Location /admin>
  Order allow,deny
</Location>

# Restrict access to configuration files...
<Location /admin/conf>
  AuthType Default
  Require user @SYSTEM
  Order allow,deny
</Location>

# Restrict access to log files...
<Location /admin/log>
  AuthType Default
  Require user @SYSTEM
  Order allow,deny
</Location>

# Set the default printer/job policies...
<Policy default>
  # Job/subscription privacy...
  JobPrivateAccess default
  JobPrivateValues default
  SubscriptionPrivateAccess default
  SubscriptionPrivateValues default

  # Job-related operations must be done by the owner or an administrator...
  <Limit Create-Job Print-Job Print-URI Validate-Job>
    Order deny,allow
  </Limit>

  <Limit Send-Document Send-URI Hold-Job Release-Job Restart-Job Purge-Jobs Set-Job-Attributes Create-Job-Subscription Renew-Subscription Cancel-Subscription Get-Notifications Reprocess-Job Cancel-Current-Job Suspend-Current-Job Resume-Job Cancel-My-Jobs Close-Job CUPS-Move-Job CUPS-Get-Document>
    Require user @OWNER @SYSTEM
    Order deny,allow
  </Limit>

  # All administration operations require an administrator to authenticate...
  <Limit CUPS-Add-Modify-Printer CUPS-Delete-Printer CUPS-Add-Modify-Class CUPS-Delete-Class CUPS-Set-Default CUPS-Get-Devices>
    AuthType Default
    Require user @SYSTEM
    Order deny,allow
  </Limit>

  # All printer operations require a printer operator to authenticate...
  <Limit Pause-Printer Resume-Printer Enable-Printer Disable-Printer Pause-Printer-After-Current-Job Hold-New-Jobs Release-Held-New-Jobs Deactivate-Printer Activate-Printer Restart-Printer Shutdown-Printer Startup-Printer Promote-Job Schedule-Job-After Cancel-Jobs CUPS-Accept-Jobs CUPS-Reject-Jobs>
    AuthType Default
    Require user @SYSTEM
    Order deny,allow
  </Limit>

  # Only the owner or an administrator can cancel or authenticate a job...
  <Limit Cancel-Job CUPS-Authenticate-Job>
    Require user @OWNER @SYSTEM
    Order deny,allow
  </Limit>

  <Limit All>
    Order deny,allow
  </Limit>
</Policy>

# Set the authenticated printer/job policies...
<Policy authenticated>
  # Job/subscription privacy...
  JobPrivateAccess default
  JobPrivateValues default
  SubscriptionPrivateAccess default
  SubscriptionPrivateValues default

  # Job-related operations must be done by the owner or an administrator...
  <Limit Create-Job Print-Job Print-URI Validate-Job>
    AuthType Default
    Order deny,allow
  </Limit>

  <Limit Send-Document Send-URI Hold-Job Release-Job Restart-Job Purge-Jobs Set-Job-Attributes Create-Job-Subscription Renew-Subscription Cancel-Subscription Get-Notifications Reprocess-Job Cancel-Current-Job Suspend-Current-Job Resume-Job Cancel-My-Jobs Close-Job CUPS-Move-Job CUPS-Get-Document>
    AuthType Default
    Require user @OWNER @SYSTEM
    Order deny,allow
  </Limit>

  # All administration operations require an administrator to authenticate...
  <Limit CUPS-Add-Modify-Printer CUPS-Delete-Printer CUPS-Add-Modify-Class CUPS-Delete-Class CUPS-Set-Default>
    AuthType Default
    Require user @SYSTEM
    Order deny,allow
  </Limit>

  # All printer operations require a printer operator to authenticate...
  <Limit Pause-Printer Resume-Printer Enable-Printer Disable-Printer Pause-Printer-After-Current-Job Hold-New-Jobs Release-Held-New-Jobs Deactivate-Printer Activate-Printer Restart-Printer Shutdown-Printer Startup-Printer Promote-Job Schedule-Job-After Cancel-Jobs CUPS-Accept-Jobs CUPS-Reject-Jobs>
    AuthType Default
    Require user @SYSTEM
    Order deny,allow
  </Limit>

  # Only the owner or an administrator can cancel or authenticate a job...
  <Limit Cancel-Job CUPS-Authenticate-Job>
    AuthType Default
    Require user @OWNER @SYSTEM
    Order deny,allow
  </Limit>

  <Limit All>
    Order deny,allow
  </Limit>
</Policy>

# Set the kerberized printer/job policies...
<Policy kerberos>
  # Job/subscription privacy...
  JobPrivateAccess default
  JobPrivateValues default
  SubscriptionPrivateAccess default
  SubscriptionPrivateValues default

  # Job-related operations must be done by the owner or an administrator...
  <Limit Create-Job Print-Job Print-URI Validate-Job>
    AuthType Negotiate
    Order deny,allow
  </Limit>

  <Limit Send-Document Send-URI Hold-Job Release-Job Restart-Job Purge-Jobs Set-Job-Attributes Create-Job-Subscription Renew-Subscription Cancel-Subscription Get-Notifications Reprocess-Job Cancel-Current-Job Suspend-Current-Job Resume-Job Cancel-My-Jobs Close-Job CUPS-Move-Job CUPS-Get-Document>
    AuthType Negotiate
    Require user @OWNER @SYSTEM
    Order deny,allow
  </Limit>

  # All administration operations require an administrator to authenticate...
  <Limit CUPS-Add-Modify-Printer CUPS-Delete-Printer CUPS-Add-Modify-Class CUPS-Delete-Class CUPS-Set-Default>
    AuthType Default
    Require user @SYSTEM
    Order deny,allow
  </Limit>

  # All printer operations require a printer operator to authenticate...
  <Limit Pause-Printer Resume-Printer Enable-Printer Disable-Printer Pause-Printer-After-Current-Job Hold-New-Jobs Release-Held-New-Jobs Deactivate-Printer Activate-Printer Restart-Printer Shutdown-Printer Startup-Printer Promote-Job Schedule-Job-After Cancel-Jobs CUPS-Accept-Jobs CUPS-Reject-Jobs>
    AuthType Default
    Require user @SYSTEM
    Order deny,allow
  </Limit>

  # Only the owner or an administrator can cancel or authenticate a job...
  <Limit Cancel-Job CUPS-Authenticate-Job>
    AuthType Negotiate
    Require user @OWNER @SYSTEM
    Order deny,allow
  </Limit>

  <Limit All>
    Order deny,allow
  </Limit>
</Policy>

# The policy below is added by SUSE during build of our cups package.
# The policy 'allowallforanybody' is totally open and insecure and therefore
# it can only be used within an internal network where only trused users exist
# and where the cupsd is not accessible at all from any external host, see
# http://en.opensuse.org/SDB:CUPS_and_SANE_Firewall_settings
# Have in mind that any user who is allowed to do printer admin tasks
# can change the print queues as he likes - e.g. send copies of confidental
# print jobs from an internal network to any external destination, see
# http://en.opensuse.org/SDB:CUPS_in_a_Nutshell
# For documentation regarding 'Managing Operation Policies' see
# http://www.cups.org/documentation.php/doc-1.7/policies.html
<Policy allowallforanybody>
  # Allow anybody to access job's private values:
  JobPrivateAccess all
  # Make none of the job values to be private:
  JobPrivateValues none
  # Allow anybody to access subscription's private values:
  SubscriptionPrivateAccess all
  # Make none of the subscription values to be private:
  SubscriptionPrivateValues none
  # Allow anybody to do all IPP operations:
  # Currently the IPP operations Validate-Job Cancel-Jobs Cancel-My-Jobs Close-Job CUPS-Get-Document
  # must be additionally exlicitly specified because those IPP operations are not included
  # in the "All" wildcard value - otherwise cupsd prints error messages of the form
  # "No limit for Validate-Job defined in policy allowallforanybody and no suitable template found."
  <Limit Validate-Job Cancel-Jobs Cancel-My-Jobs Close-Job CUPS-Get-Document>
    Order deny,allow
    Allow from all
  </Limit>
  # Since CUPS > 1.5.4 the "All" wildcard value must be specified separately,
  # otherwise clients like "lpstat -p" just hang up,
  # see https://bugzilla.opensuse.org/show_bug.cgi?id=936309
  # and https://www.cups.org/str.php?L4659
  <Limit All>
    Order deny,allow
    Allow from all
  </Limit>
</Policy>
# Explicitly set the CUPS 'default' policy to be used by default:
DefaultPolicy default

]]></file_contents>
    </cupsd_conf_content>
  </printer>
  <proxy>
    <enabled config:type="boolean">false</enabled>
    <ftp_proxy/>
    <http_proxy/>
    <https_proxy/>
    <no_proxy>localhost,127.0.0.1</no_proxy>
    <proxy_password/>
    <proxy_user/>
  </proxy>
  <report>
    <errors>
      <log config:type="boolean">true</log>
      <show config:type="boolean">true</show>
      <timeout config:type="integer">0</timeout>
    </errors>
    <messages>
      <log config:type="boolean">true</log>
      <show config:type="boolean">true</show>
      <timeout config:type="integer">0</timeout>
    </messages>
    <warnings>
      <log config:type="boolean">true</log>
      <show config:type="boolean">true</show>
      <timeout config:type="integer">0</timeout>
    </warnings>
    <yesno_messages>
      <log config:type="boolean">true</log>
      <show config:type="boolean">true</show>
      <timeout config:type="integer">0</timeout>
    </yesno_messages>
  </report>
  <services-manager>
    <default_target>graphical</default_target>
    <services>
      <disable config:type="list"/>
      <enable config:type="list">
        <service>ModemManager</service>
        <service>NetworkManager</service>
        <service>NetworkManager-dispatcher</service>
        <service>NetworkManager-wait-online</service>
        <service>YaST2-Firstboot</service>
        <service>YaST2-Second-Stage</service>
        <service>anydesk</service>
        <service>apparmor</service>
        <service>auditd</service>
        <service>avahi-daemon</service>
        <service>bluetooth</service>
        <service>klog</service>
        <service>chronyd</service>
        <service>cpupower</service>
        <service>cron</service>
        <service>cups</service>
        <service>display-manager</service>
        <service>getty@tty1</service>
        <service>haveged</service>
        <service>irqbalance</service>
        <service>iscsi</service>
        <service>kbdsettings</service>
        <service>lvm2-monitor</service>
        <service>mcelog</service>
        <service>msmserver</service>
        <service>nscd</service>
        <service>postfix</service>
        <service>purge-kernels</service>
        <service>rsyslog</service>
        <service>smartd</service>
        <service>sshd</service>
        <service>systemd-fsck-root</service>
        <service>systemd-timesyncd</service>
      </enable>
      <on_demand config:type="list">
        <listentry>iscsid</listentry>
      </on_demand>
    </services>
  </services-manager>
  <software>
    <image/>
    <install_recommended config:type="boolean">true</install_recommended>
    <instsource/>
    <packages config:type="list">
      <package>zip</package>
      <package>yast2-users</package>
      <package>yast2-trans-he</package>
      <package>yast2-services-manager</package>
      <package>yast2-proxy</package>
      <package>yast2-printer</package>
      <package>yast2-ntp-client</package>
      <package>yast2-nis-client</package>
      <package>yast2-network</package>
      <package>yast2-installation</package>
      <package>yast2-firewall</package>
      <package>yast2-country</package>
      <package>yast2-bootloader</package>
      <package>yast2-add-on</package>
      <package>xorg-x11-Xvnc-novnc</package>
      <package>vsftpd</package>
      <package>spectacle</package>
      <package>openssh</package>
      <package>openSUSE-release</package>
      <package>okular</package>
      <package>numactl</package>
      <package>mc</package>
      <package>libpangox-1_0-0</package>
      <package>libigdgmm11</package>
      <package>libgtkglext-x11-1_0-0</package>
      <package>konsole</package>
      <package>knotes</package>
      <package>kmail</package>
      <package>kexec-tools</package>
      <package>jq</package>
      <package>irqbalance</package>
      <package>intel-media-driver</package>
      <package>gwenview5</package>
      <package>grub2-x86_64-efi</package>
      <package>grub2</package>
      <package>glibc</package>
      <package>gcc7</package>
      <package>firewalld</package>
      <package>fetchmsttfonts</package>
      <package>eog-plugin-slideshowshuffle</package>
      <package>e2fsprogs</package>
      <package>dosfstools</package>
      <package>culmus-fonts</package>
      <package>chrony</package>
      <package>biosdevname</package>
      <package>autoyast2-installation</package>
      <package>autoyast2</package>
      <package>SPI-bin</package>
      <package>NetworkManager</package>
      <package>MozillaFirefox-branding-upstream</package>
      <package>MozillaFirefox</package>
    </packages>
    <patterns config:type="list">
      <pattern>apparmor</pattern>
      <pattern>apparmor_opt</pattern>
      <pattern>base</pattern>
      <pattern>basesystem</pattern>
      <pattern>enhanced_base</pattern>
      <pattern>enhanced_base_opt</pattern>
      <pattern>fonts</pattern>
      <pattern>fonts_opt</pattern>
      <pattern>kde_plasma</pattern>
      <pattern>kde_yast</pattern>
      <pattern>minimal_base</pattern>
      <pattern>x11</pattern>
      <pattern>x11_enhanced</pattern>
      <pattern>x11_opt</pattern>
      <pattern>x11_yast</pattern>
      <pattern>yast2_basis</pattern>
    </patterns>
    <products config:type="list">
      <product>openSUSE</product>
    </products>
  </software>
  <ssh_import>
    <copy_config config:type="boolean">false</copy_config>
    <import config:type="boolean">false</import>
  </ssh_import>
  <timezone>
    <hwclock>localtime</hwclock>
    <timezone>Asia/Jerusalem</timezone>
  </timezone>
  <user_defaults>
    <expire/>
    <group>100</group>
    <groups/>
    <home>/home</home>
    <inactive>0</inactive>
    <no_groups config:type="boolean">true</no_groups>
    <shell>/bin/bash</shell>
    <skel>/etc/skel</skel>
    <umask>022</umask>
  </user_defaults>
  <users config:type="list">
    <user>
      <authorized_keys config:type="list"/>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>gtmuser</fullname>
      <gid>100</gid>
      <home>/home/gtmuser</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/bin/bash</shell>
      <uid>1000</uid>
      <user_password>$6$JrCoSjBFEcPX$/Uoml.tUMZHpKgrLqFtaU9sBqwamdDPZuTxq0YBaShsJ5Yz9B.rSfm9/D51TxUKETCbsUCz0xxG1mM0OdyMuq0</user_password>
      <username>gtmuser</username>
    </user>
    <user>
      <authorized_keys config:type="list"/>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>elpos</fullname>
      <gid>100</gid>
      <home>/home/elpos</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/bin/bash</shell>
      <uid>1001</uid>
      <user_password>$6$OEiVNlVfftfpY3TT$T9PnKdHAqCQyeZCfFD2B84.niFjGa/IXDZ/17zHp.PvLUKCffRe2sfxlSf7B5K6Yc0XzygRDstFOXLiRhuwiV0</user_password>
      <username>elpos</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>bin</fullname>
      <gid>1</gid>
      <home>/bin</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/sbin/nologin</shell>
      <uid>1</uid>
      <user_password>!</user_password>
      <username>bin</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>User for polkitd</fullname>
      <gid>496</gid>
      <home>/var/lib/polkit</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/sbin/nologin</shell>
      <uid>498</uid>
      <user_password>!</user_password>
      <username>polkitd</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>SDDM daemon</fullname>
      <gid>467</gid>
      <home>/var/lib/sddm</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/bin/false</shell>
      <uid>464</uid>
      <user_password>!</user_password>
      <username>sddm</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>systemd Network Management</fullname>
      <gid>478</gid>
      <home>/</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/sbin/nologin</shell>
      <uid>478</uid>
      <user_password>!!</user_password>
      <username>systemd-network</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>dnsmasq</fullname>
      <gid>65533</gid>
      <home>/var/lib/empty</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/bin/false</shell>
      <uid>492</uid>
      <user_password>!</user_password>
      <username>dnsmasq</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>Printing daemon</fullname>
      <gid>484</gid>
      <home>/var/spool/lpd</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/sbin/nologin</shell>
      <uid>494</uid>
      <user_password>!</user_password>
      <username>lp</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>Postfix Daemon</fullname>
      <gid>51</gid>
      <home>/var/spool/postfix</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/bin/false</shell>
      <uid>51</uid>
      <user_password>!</user_password>
      <username>postfix</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>user for VNC</fullname>
      <gid>468</gid>
      <home>/var/lib/empty</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/sbin/nologin</shell>
      <uid>465</uid>
      <user_password>!</user_password>
      <username>vnc</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>systemd Time Synchronization</fullname>
      <gid>477</gid>
      <home>/</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/sbin/nologin</shell>
      <uid>477</uid>
      <user_password>!!</user_password>
      <username>systemd-timesync</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>Manual pages viewer</fullname>
      <gid>62</gid>
      <home>/var/lib/empty</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/sbin/nologin</shell>
      <uid>13</uid>
      <user_password>!</user_password>
      <username>man</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>User for D-Bus</fullname>
      <gid>497</gid>
      <home>/run/dbus</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/usr/bin/false</shell>
      <uid>499</uid>
      <user_password>!</user_password>
      <username>messagebus</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>nobody</fullname>
      <gid>65534</gid>
      <home>/var/lib/nobody</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/bin/bash</shell>
      <uid>65534</uid>
      <user_password>!</user_password>
      <username>nobody</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>Daemon</fullname>
      <gid>2</gid>
      <home>/sbin</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/sbin/nologin</shell>
      <uid>2</uid>
      <user_password>!</user_password>
      <username>daemon</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>TFTP account</fullname>
      <gid>480</gid>
      <home>/srv/tftpboot</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/bin/false</shell>
      <uid>493</uid>
      <user_password>!</user_password>
      <username>tftp</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>MySQL database admin</fullname>
      <gid>498</gid>
      <home>/var/lib/mysql</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/bin/false</shell>
      <uid>60</uid>
      <user_password>!</user_password>
      <username>mysql</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>Secure FTP User</fullname>
      <gid>65534</gid>
      <home>/var/lib/empty</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/bin/false</shell>
      <uid>473</uid>
      <user_password>!</user_password>
      <username>ftpsecure</username>
    </user>
    <user>
      <authorized_keys config:type="list"/>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>root</fullname>
      <gid>0</gid>
      <home>/root</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/bin/bash</shell>
      <uid>0</uid>
      <user_password>$6$j.dzp50PGoUn$xhOIjLG2kkx2uxE3IkZjT1zjBY53t2jmtHB63mzL5fQlbO5lAC2wzCTutDFqunyEm3XA/ravM5/LCWY48EMVi/</user_password>
      <username>root</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>SSH daemon</fullname>
      <gid>471</gid>
      <home>/var/lib/sshd</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/bin/false</shell>
      <uid>471</uid>
      <user_password>!</user_password>
      <username>sshd</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>PulseAudio daemon</fullname>
      <gid>475</gid>
      <home>/var/lib/pulseaudio</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/sbin/nologin</shell>
      <uid>475</uid>
      <user_password>!</user_password>
      <username>pulse</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>Chrony Daemon</fullname>
      <gid>473</gid>
      <home>/var/lib/chrony</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/bin/false</shell>
      <uid>474</uid>
      <user_password>!</user_password>
      <username>chrony</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>User for nscd</fullname>
      <gid>472</gid>
      <home>/run/nscd</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/sbin/nologin</shell>
      <uid>472</uid>
      <user_password>!</user_password>
      <username>nscd</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>RealtimeKit</fullname>
      <gid>481</gid>
      <home>/proc</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/bin/false</shell>
      <uid>495</uid>
      <user_password>!</user_password>
      <username>rtkit</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>NFS statd daemon</fullname>
      <gid>65533</gid>
      <home>/var/lib/nfs</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/sbin/nologin</shell>
      <uid>468</uid>
      <user_password>!</user_password>
      <username>statd</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>User for Avahi</fullname>
      <gid>470</gid>
      <home>/run/avahi-daemon</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/bin/false</shell>
      <uid>467</uid>
      <user_password>!</user_password>
      <username>avahi</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>systemd Core Dumper</fullname>
      <gid>476</gid>
      <home>/</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/sbin/nologin</shell>
      <uid>476</uid>
      <user_password>!!</user_password>
      <username>systemd-coredump</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>user for rpcbind</fullname>
      <gid>65534</gid>
      <home>/var/lib/empty</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/sbin/nologin</shell>
      <uid>470</uid>
      <user_password>!</user_password>
      <username>rpc</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>usbmuxd daemon</fullname>
      <gid>65533</gid>
      <home>/var/lib/usbmuxd</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/sbin/nologin</shell>
      <uid>469</uid>
      <user_password>!</user_password>
      <username>usbmux</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>Mailer daemon</fullname>
      <gid>495</gid>
      <home>/var/spool/clientmqueue</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/sbin/nologin</shell>
      <uid>497</uid>
      <user_password>!</user_password>
      <username>mail</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>FTP Account</fullname>
      <gid>494</gid>
      <home>/srv/ftp</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/sbin/nologin</shell>
      <uid>496</uid>
      <user_password>!</user_password>
      <username>ftp</username>
    </user>
    <user>
      <encrypted config:type="boolean">true</encrypted>
      <fullname>LightDM daemon</fullname>
      <gid>469</gid>
      <home>/var/lib/lightdm</home>
      <home_btrfs_subvolume config:type="boolean">false</home_btrfs_subvolume>
      <password_settings>
        <expire/>
        <flag/>
        <inact/>
        <max>99999</max>
        <min>0</min>
        <warn>7</warn>
      </password_settings>
      <shell>/bin/false</shell>
      <uid>466</uid>
      <user_password>!</user_password>
      <username>lightdm</username>
    </user>
  </users>
</profile>
