Re: Getting horde to authenticate against dovecot DB
Michael J Rubinsky <[email protected]> Sat, 17 Aug 2019 14:21:48 +0000
| Newsgroups | gmane.comp.horde.user |
|---|---|
| Message-ID | <20190817142148.Horde.8Tyjh1qaNNRvo01Q3vLZj2H@tarn.theupstairsroom.com> |
Quoting Coy Hile <[email protected]>: > Hi all, > > I'm currently trying to get Horde to authenticate against my Dovecot > virtual user database, as I want the ActiveSync functionality that > is missing from other solutions. However, I'm having a hard time > getting the passwords in a form that both Horde and Dovecot > understand. > > In the dovecot DB, I have: > > username | domain | > password > ---------------+----------+-------------------------------------------------------------------------------------------------------------------------- > [email protected] | test.com | > {SHA512-CRYPT}$6$8CK0YWwoEjEvhEwf$58UUMSvPL8fE1p50bfTjHqivp3iwmfk/2sbv9igUT0FhwRc548UaKDWBYCvgrOyDfT81u9dLEJ7ulHLFbvbSq/ > > > conf.php contains (in relevant part): > > $conf['auth']['params']['query_auth'] = 'SELECT * FROM users WHERE > username=\L AND password=\P'; > $conf['auth']['params']['encryption'] = 'crypt-sha512'; > $conf['auth']['params']['show_encryption'] = false; > $conf['auth']['driver'] = 'customsql'; > > In syslog, one sees: > > Aug 16 21:39:23 8616546e-fcab-e37b-a25a-c746648411f7 HORDE: [horde] > SQL (0.0014s) #012#011SELECT * FROM users WHERE > username='[email protected]' AND#012#011 > password='$6$jCCF2GRqLkldtA6u$NMZosKqif68Ro0HjRTGy7Y/tqUuGEMYq.oZ5OqcX#012#011 NAC3PW7jMhsL.ZzdE67vjw6Bx6gIgoQh.d.3syBdYUC4j0' [pid 2321 on line 241 of > "/usr/share/php/Horde/Db/Adapter/Pdo/Base.php"] > Aug 16 21:39:23 8616546e-fcab-e37b-a25a-c746648411f7 HORDE: [horde] > FAILED LOGIN for [email protected] to horde (10.100.9.20) [pid 2321 on > line 198 of "/usr/share/horde/login.php"] > > So, that brings up some questions: > (1) Is the data in the log actually correct? Why are there what > appear to be "#012#011 " in the middle of the query? > (2) Am I completely taking the wrong approach here? Is there a > better way to get these two things to play nice, or do I have to > finesse something in the SQL queries to make this work? > > I'll probably only use this as a front end to activesync, which will > talk to the same Dovecot instance eventually. You are probably missing the 'query_getpw' query. You need a query that will load the password first, in order to get the salt before we can verify the user provided password. Something like 'SELECT password FROM you_table WHERE username = \L' See towards the end of the following post for more info: https://theupstairsroom.com/116 > Thanks, > -c > > -- > Coy Hile > [email protected] > -- > Horde mailing list > Frequently Asked Questions: http://horde.org/faq/ > To unsubscribe, mail: [email protected] -- mike The Horde Project http://www.horde.org https://www.facebook.com/hordeproject https://www.twitter.com/hordeproject -- Horde mailing list Frequently Asked Questions: http://horde.org/faq/ To unsubscribe, mail: [email protected]
(unnamed)
(application/pgp-keys, 9.1 KB) - not displayed
signature.asc
(application/pgp-signature, 821 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4 iQIcBAABAgAGBQJdWA18AAoJEJGSgkbRsxbbEVQP/3VzBAtjprqp1UHubGDkwmTl ZLYDvLp5IYFfvt6mCJJ0SfKvrSuc+YwuvmL/wqan+mqAWk3ITVvBGwE4UtAadhqt 39ZjHuCfZ2NGLhH27HgshhvXjt1Izm/EbUELP7dlhvWH7yFuWl9AkHo4C+MgO/ze S3KxD9Xj+UOMc/26o4vamiggDKJ91cHvrtrMzdpJkg9XqlE8DwvgyhNogUCi7xd1 YE/SILqyZdGTyTtWGTG7cvl1WYClnlsMUPHWUDYSRs/l/wwrrZy11l+9hq2pDGVy 34pIGpKbpdjjuUzTq9IFgx7LdPn2+K66KoCYQFIIgjs9TFJGJ+DO7PziJKnoCRUp hEVgSQsuqodPhwb/WNXsDclRUqLxmrHM/qgG2r8cZhQfkqGQlJHMXf8pQAxzv4Cz Av2P+JBo4XazwB4Gu848QWqC+EMZjWOst79bZP0ZFTwietES8CJjVvlISTyDy+Js Sxh4hJt4DPseVSriU6AjfX5n5ZLst1KhrFPZ2Qwwo7pNIuI2mNc/ThuaE0kIq6SH en/KaOD9X53z3ZhulfEa7WNGPqAyWM617IL0orStFBVunOZ+1gQdpVRNCpGzomxj 6Idad1lAN5W+j8426s7Uev3zFjRZtm4X2ompNVH7GjDoIgzfsEIhyd2yeY5WjybG Z7aNDaeV+mV9BlXndZ2A =GDL1 -----END PGP SIGNATURE-----