Re: Authentication and authorization with OpenLDAP; hashed passwords

"Patrick Pfeifer via Info" <[email protected]>
Newsgroups gmane.mail.imap.cyrus
Message-ID <[email protected]>
On 26.06.23 09:35, Niels Dettenbach via Info wrote:
> Just a side note (simplified):
>
> cyrus-imapd is not a SMTP MTA.
Noted. All right. Thank you for the info.
> For User authentication in Cyrus, i would expect to use
> Cyrus -> PAM -.> LDAP or ponetially
PAM ? All right. That sounds good actually! I remember fiddling with 
those config files in /etc/pam.d (25ish years ago) and as I recall it 
was working well. This sounds like a good option. But Google does again 
not seem to have any interest in any kind friendship when I ask it for 
cyrus-imap pam authentication 
<https://www.google.com/search?hl=de&q=cyrus-imap pam 
authentication>.There are two 
<https://www.cyrusimap.org/imap/concepts/features.html#security-and-authentication> 
links 
<https://www.cyrusimap.org/imap/concepts/features.html#security-and-authentication> 
to the cyrusimap.org Documentation, where there is basically no info on 
it and the 3rd hit, a link to tldp.org, with a PDF HowTo, speaks right 
from my heart when it says: "Chapter 4.3 - PAM: Not enough info to 
document. Email me if you have some."
> Cyrus -> SASL -> GSSAPI -> LDAP
> as a typical solution (but never did it byself yet).
Ok, well. I'd rather not do Kerberos. That doesn't seem to make sense 
for my tiny setup.


On 26.06.23 11:43, Howard Chu wrote:
> A more typical example would be using SASL/DIGEST-MD5 or SASL/SCRAM etc...
Thanks, but if my understanding is correct, these only work as long as 
you store the plain text passwords on the server -- which I am not doing.

------------------------------------------
Cyrus: Info
Permalink: https://cyrus.topicbox.com/groups/info/T48b6e9b6846822f7-M70db158bf484b34e65c7329a
Delivery options: https://cyrus.topicbox.com/groups/info/subscription
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.