Email - Dovecot auth-ldap.conf.ext
Email Solution · Config document · referenced from Dovecot authentication
The password and user databases of Dovecot: two of each, one pair for the accounts of people and one for the accounts of devices and applications, all four against Active Directory. The file is included from 10-auth.conf. It is short and shown whole, with the two stock comments it kept.
| Item | Value |
|---|---|
| Path on the server | /etc/dovecot/conf.d/auth-ldap.conf.ext |
| Shown here | DC2-A-VCMSX002, the mailbox server |
| Also on | DC2-A-VCMSX001 and DC2-B-VCMSX001, identical |
| Reads | /etc/dovecot/dovecot-ldap.conf.users and /etc/dovecot/dovecot-ldap.conf.devices |
| Software | Dovecot 2.2 from the RHEL 7 repository; the exact package release is not recorded |
The file
# Authentication for LDAP users. Included from 10-auth.conf. # # <doc/wiki/AuthDatabase.LDAP.txt> # CFG-ON -> Password lookup for AD user accounts passdb { driver = ldap # Path for LDAP configuration file, see example-config/dovecot-ldap.conf.ext args = /etc/dovecot/dovecot-ldap.conf.users } # CFG-ON -> Password lookup for AD device accounts passdb { driver = ldap # Path for LDAP configuration file, see example-config/dovecot-ldap.conf.ext args = /etc/dovecot/dovecot-ldap.conf.devices } # CFG-ON -> User lookup for AD user accounts userdb { driver = ldap args = /etc/dovecot/dovecot-ldap.conf.users # Default fields can be used to specify defaults that LDAP may override default_fields = home=/data/vmail/%Ld/%Ln/Maildir/,=mail=maildir:/data/vmail/%Ld/%Ln/Maildir/ } # CFG-ON -> User lookup for AD device accounts userdb { driver = ldap args = /etc/dovecot/dovecot-ldap.conf.devices # Default fields can be used to specify defaults that LDAP may override default_fields = home=/data/vmail/%Ld/%Ln/Maildir/,=mail=maildir:/data/vmail/%Ld/%Ln/Maildir/ }
Reading it
- The databases are tried in the order written: a login is checked against the users' OU first and against the devices' OU second.
- The comments say "password lookup". With
auth_bind = yesin both LDAP files it is an authentication bind: Dovecot searches the account and then binds as that account with the password the client sent. %Ldand%Lnare the domain and the local part of the login name in lower case, soUser01@ad-dc2.example.netgets/data/vmail/ad-dc2.example.net/user01/Maildir/.default_fieldsand theuser_attrsline of the LDAP files say the same thing twice. Either would do.
Differences between the hosts
None. The mailbox paths are in the file on the internal pair too, where no mailbox exists.
Checked against Dovecot 2.4.5
| As built | Today |
|---|---|
passdb { driver = ldap and args = <file> } | passdb ldap { … } and userdb ldap { … } with the LDAP settings inside; a second instance needs a name of its own |
two passdb and two userdb blocks, one file each | the same four databases, each a named block; inside a named block the short setting names expand for the driver name only |
default_fields = home=…,=mail=maildir:… | there is no default_fields setting in 2.4; fields are set with userdb_fields, and mail is split into mail_driver and mail_path |
The variables changed as well: %u is %{user}, and the lower-case local part is written with filters, %{user | username | lower}. For the lower-case domain the research gives %{user | domain | lower} by analogy only; that form is not verified. The research did not establish what replaces default_fields exactly. CentOS Stream 9 and 10, the upstream of RHEL 9 and 10, still carry Dovecot 2.3, so on RHEL the step from 2.2 to 2.3 comes first and the 2.4 syntax applies with upstream packages only.