Re: Authentication and authorization with OpenLDAP; hashed passwords
"Patrick Pfeifer via Info" <[email protected]>
| Newsgroups | gmane.mail.imap.cyrus |
|---|---|
| Message-ID | <[email protected]> |
On 26.06.23 09:35, Niels Dettenbach via Info wrote: > Just a side note (simplified): > > cyrus-imapd is not a SMTP MTA. Noted. All right. Thank you for the info. > For User authentication in Cyrus, i would expect to use > Cyrus -> PAM -.> LDAP or ponetially PAM ? All right. That sounds good actually! I remember fiddling with those config files in /etc/pam.d (25ish years ago) and as I recall it was working well. This sounds like a good option. But Google does again not seem to have any interest in any kind friendship when I ask it for cyrus-imap pam authentication <https://www.google.com/search?hl=de&q=cyrus-imap pam authentication>.There are two <https://www.cyrusimap.org/imap/concepts/features.html#security-and-authentication> links <https://www.cyrusimap.org/imap/concepts/features.html#security-and-authentication> to the cyrusimap.org Documentation, where there is basically no info on it and the 3rd hit, a link to tldp.org, with a PDF HowTo, speaks right from my heart when it says: "Chapter 4.3 - PAM: Not enough info to document. Email me if you have some." > Cyrus -> SASL -> GSSAPI -> LDAP > as a typical solution (but never did it byself yet). Ok, well. I'd rather not do Kerberos. That doesn't seem to make sense for my tiny setup. On 26.06.23 11:43, Howard Chu wrote: > A more typical example would be using SASL/DIGEST-MD5 or SASL/SCRAM etc... Thanks, but if my understanding is correct, these only work as long as you store the plain text passwords on the server -- which I am not doing. ------------------------------------------ Cyrus: Info Permalink: https://cyrus.topicbox.com/groups/info/T48b6e9b6846822f7-M70db158bf484b34e65c7329a Delivery options: https://cyrus.topicbox.com/groups/info/subscription