Email - dovecot-ldap.conf.devices
Email Solution · Config document · referenced from Dovecot authentication
dnpass holds the password of the service account vmail_svc in clear text; it is a placeholder here. The file must be readable by root only.The LDAP settings of Dovecot for the accounts of devices and applications, the <service-name>_mail accounts that servers and appliances send mail with. It is the users' file with another search base.
| Item | Value |
|---|---|
| Path on the server | /etc/dovecot/dovecot-ldap.conf.devices |
| Shown here | DC2-A-VCMSX001 |
| Also on | DC2-B-VCMSX001 and DC2-A-VCMSX002 |
| Searches | OU=msx_SVC,OU=Users_SVC of the site 2 directory |
| Used by | the second passdb and the second userdb of auth-ldap.conf.ext |
| Software | Dovecot 2.2 from the RHEL 7 repository; the exact package release is not recorded |
The file
# LDAP Server settings # Due to problems in LDAP clients/LDAP libraries in dual IP stacks (IPv4, IPv6) environments, this configuration (parameter "uris") contains only IPv4 addresses. # # DC2-A-VCAD001 - 10.12.16.209 # DC2-A-VCAD002 - 10.12.16.210 uris = ldaps://10.12.16.209:636 ldaps://10.12.16.210:636 base = ou=msx_svc,ou=users_svc,DC=ad-dc2,DC=example,DC=net scope = subtree deref = never ldap_version = 3 # LDAP User Binding settings auth_bind = yes dn = cn=vmail_svc,ou=Users_svc,DC=ad-dc2,DC=example,DC=net dnpass = <LDAP_BIND_PASSWORD> # LDAP Filter settings user_filter = (&(memberOf:1.2.840.113556.1.4.1941:=CN=IMAP_ACCESS,OU=APPS,OU=RBAC_ROLES,OU=RBAC,DC=ad-dc2,DC=example,DC=net)(userPrincipalName=%u)(objectClass=person)(!(userAccountControl:1.2.840.113556.1.4.803:=2))) pass_filter = (&(userPrincipalName=%u)(objectClass=person)(!(userAccountControl:1.2.840.113556.1.4.803:=2))) pass_attrs = userPassword=password default_pass_scheme = CRYPT user_attrs = =home=/data/vmail/%Ld/%Ln/Maildir/,=mail=maildir:/data/vmail/%Ld/%Ln/Maildir/
Differences from the users' file
| Line | Users | Devices |
|---|---|---|
base | ou=users_std,DC=ad-dc2,DC=example,DC=net | ou=msx_svc,ou=users_svc,DC=ad-dc2,DC=example,DC=net |
Everything else is the same, including the user_filter with IMAP_ACCESS. A device account therefore gets a mailbox and webmail access only when it is put into that group, which the design reserves for troubleshooting, on request. For what the single lines do see dovecot-ldap.conf.users.
Differences between the hosts
The live lines are the same on the three servers. On DC2-B-VCMSX001 the file lacks the empty line at the end.
Checked against Dovecot 2.4.5
The settings are those of the users' file and so is the comparison: every key has a new name in 2.4 and moves into dovecot.conf. See dovecot-ldap.conf.users.
| As built | Today |
|---|---|
| a second file for a second search base | a second named passdb ldap and userdb ldap block with its own ldap_base |
CentOS Stream 9 and 10, the upstream of RHEL 9 and 10, still carry Dovecot 2.3, so on RHEL the step from 2.2 to 2.3 comes first and the 2.4 syntax applies with upstream packages only.