Re: Authentication and authorization with OpenLDAP; hashed passwords

Howard Chu <[email protected]>
Newsgroups gmane.mail.imap.cyrus
Message-ID <[email protected]>
Niels Dettenbach via Info wrote:
> Am Sonntag, 25. Juni 2023, 13:19:05 CEST schrieb PFiver via Info:
>> I would like to use cyrus-imap as a relaying and forwarding SMTP MTA, IMAP
>> mail and Cal/Card*DAV server for personal use. It will run in a small VM
>> that serves no more than  10 user.
> Just a side note (simplified):
> 
> cyrus-imapd is not a SMTP MTA. For this purpose, soem SMTP MTA solution like 
> exim, postfix, sendmail etc. is typically used "together" with cyrus-imapd. 
> cyrus speak lmtp ("local" mail transfer) with them to get fed with incoming 
> emails.
> 
> For User authentication in Cyrus, i would expect to use 
> Cyrus -> PAM -.> LDAP or ponetially
> Cyrus -> SASL -> GSSAPI -> LDAP

Unless your KDC is using OpenLDAP as its backend, typically SASL -> GSSAPI doesn't involve LDAP at all.

A more typical example would be using SASL/DIGEST-MD5 or SASL/SCRAM etc...

> as a typical solution (but never did it byself yet).
> 
> look at i.e.:
> https://www.cyrusimap.org/sasl/sasl/faqs/openldap-sasl-gssapi.html
> 
> 
> hth,
> 
> 
> niels.
> 
> 
> 


-- 
  -- Howard Chu
  CTO, Symas Corp.           http://www.symas.com
  Director, Highland Sun     http://highlandsun.com/hyc/
  Chief Architect, OpenLDAP  http://www.openldap.org/project/

------------------------------------------
Cyrus: Info
Permalink: https://cyrus.topicbox.com/groups/info/T48b6e9b6846822f7-Mc2c9cb8c6bcf2eeaa4830899
Delivery options: https://cyrus.topicbox.com/groups/info/subscription
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.