Email - Dovecot 10-auth.conf
Email Solution · Config document · referenced from Dovecot authentication
The authentication settings of Dovecot: which SASL mechanisms are offered, whether they are allowed without TLS, and which password and user databases are used. Stock comments are left out; three settings differ from the distribution's file.
| Item | Value |
|---|---|
| Path on the server | /etc/dovecot/conf.d/10-auth.conf |
| Shown here | DC2-A-VCMSX001 |
| Also on | DC2-B-VCMSX001 and DC2-A-VCMSX002, identical |
| Includes | auth-ldap.conf.ext |
| Software | Dovecot 2.2 from the RHEL 7 repository; the exact package release is not recorded |
The file
# Allow plaintext mechanisms on connections that Dovecot does not see as # encrypted. Dovecot itself runs without TLS here (10-ssl.conf); the # encryption is done by Postfix in front of it. # CFG-ON -> disable_plaintext_auth = no disable_plaintext_auth = no # Mechanisms offered to Postfix and to IMAP clients. Stock is "plain" only. # CFG-OFF -> auth_mechanisms = plain # CFG-ON -> auth_mechanisms = plain login auth_mechanisms = plain login # The system accounts (PAM, /etc/passwd) are switched off as a source ... # CFG-OFF -> !include auth-system.conf.ext # ... and Active Directory over LDAP is the only one. # CFG-ON -> !include auth-ldap.conf.ext !include auth-ldap.conf.ext
Differences between the hosts
None. The file is the same on the three internal servers.
Checked against Dovecot 2.4.5
| As built | Today |
|---|---|
disable_plaintext_auth = no | replaced by auth_allow_cleartext; the equivalent of this build is auth_allow_cleartext = yes, the default refuses cleartext logins on unsecured connections |
auth_mechanisms = plain login | still valid, default plain |
!include auth-ldap.conf.ext | the external files are replaced by regular settings in named passdb and userdb blocks |
CentOS Stream 9 and 10, the upstream of RHEL 9 and 10, still carry Dovecot 2.3, so on RHEL the step from 2.2 to 2.3 comes first and the 2.4 syntax applies with upstream packages only.