Re: pam + ldap smtp authentication

"Keith T. Garner" <[email protected]>
Newsgroups gmane.mail.jamm.user
Message-ID <[email protected]>
On Fri, Apr 02, 2004 at 11:49:59, Nadeem Bitar said:
> This is from the redhat posstfix-sasl readme
> /usr/share/doc/postfix/README-Postfix-SASL-RedHat.txt
> 
> "  Is SASL appending a realm or domain to a username? PAM
>    authentication requires a bare username and password, other
>    authentication methods require the username to be qualified with a
>    realm. Typically the username will be rewritten as user@realm
>    (e.g. [email protected]) PAM does not understand a username with
>    "@realm" appended to it and will fail the authentication with the
>    message that the user is unknown. If the log files shows saslauthd
>    usernames with "@realm" appended to it then the
>    smtpd_sasl_local_domain configuration parameter is likely set in
>    /etc/postfix/main.cf file, make sure its either not set or set it
>    to an empty string. Restart postfix and test authtentication again,
>    the log file should show only a bare username.
> "
> 
> I might have other misconfiguration. I would go over everything and
> might have to recompile.

As far as pam is concerned the username is "user@host."  What you have
posted above is if you have SASL misconfigured for talking to pam for
the normal unix user database, where username doesn't contain "@host."

keith

-- 
  Keith T. Garner                                         [email protected]
   The whole problem with the world is that fools and fanatics are always so
 certain of themselves, and wiser people so full of doubts. --Bertrand Russell


-------------------------------------------------------
This SF.Net email is sponsored by: IBM Linux Tutorials
Free Linux tutorial presented by Daniel Robbins, President and CEO of
GenToo technologies. Learn everything from fundamentals to system
administration.http://ads.osdn.com/?ad_id=1470&alloc_id=3638&op=click
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.