Re: Best way to auth cyrus 3.x to an AD domain setup
Lars Schimmer <[email protected]>
| Newsgroups | gmane.mail.imap.cyrus |
|---|---|
| Organization | TU Graz CGV |
| Message-ID | <[email protected]> |
On 2/25/19 3:17 PM, Dan White wrote: > On 02/25/19 11:45 +0100, Lars Schimmer wrote: >> Ok, after sasldb2 file is not good anymore, I want to ask user passwords >> from our AD Domain setup. >> >> I had a short search and I did find several methosd to let cyrus3 ask >> for users/pwasswords from a AD server, but all are kinda old. >> >> E.g. using krb5 service principle in win server 2008, or just using LDAp >> against the server. >> >> What is the preferred, easy to use method nowadays, any docs available? >> >> Or how do I use sasl to save passwords encrypted with hash on local >> harddrive? > > https://www.openldap.org/lists/openldap-technical/201106/msg00198.html > > In imapd.conf: > > sasl_pwcheck_method: saslauthd Tried, but passwd check bad. With ldapsearch I get a positiv feedback, but on imap login I get: SASL(-13): authentication failure: checkpass failed And no simple way to debug :-( MfG, Lars Schimmer -- ------------------------------------------------------------- TU Graz, Institut für ComputerGraphik & WissensVisualisierung Tel: +43 316 873-5405 E-Mail: [email protected] Fax: +43 316 873-5402 PGP-Key-ID: 0x4A9B1723 ---- Cyrus Home Page: http://www.cyrusimap.org/ List Archives/Info: http://lists.andrew.cmu.edu/pipermail/info-cyrus/ To Unsubscribe: https://lists.andrew.cmu.edu/mailman/listinfo/info-cyrus
signature.asc
(application/pgp-signature, 195 B)
-----BEGIN PGP SIGNATURE----- iF0EARECAB0WIQR0wxkJRmamY9krY7GZaG4TSpsXIwUCXHUWagAKCRCZaG4TSpsX IxomAJ42Fogr9uDnOIUjEifHijLmzBhb+ACgl+3+W++tRaMKqixdBbegcEY/CTE= =FkWL -----END PGP SIGNATURE-----