LINUXOR.SK ... open source notes ...

Email - dovecot-ldap.conf.devices

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

Email Solution · Config document · referenced from Dovecot authentication

notednpass holds the password of the service account vmail_svc in clear text; it is a placeholder here. The file must be readable by root only.

The LDAP settings of Dovecot for the accounts of devices and applications, the <service-name>_mail accounts that servers and appliances send mail with. It is the users' file with another search base.

ItemValue
Path on the server/etc/dovecot/dovecot-ldap.conf.devices
Shown hereDC2-A-VCMSX001
Also onDC2-B-VCMSX001 and DC2-A-VCMSX002
SearchesOU=msx_SVC,OU=Users_SVC of the site 2 directory
Used bythe second passdb and the second userdb of auth-ldap.conf.ext
SoftwareDovecot 2.2 from the RHEL 7 repository; the exact package release is not recorded

The file

ini
# LDAP Server settings
# Due to problems in LDAP clients/LDAP libraries in dual IP stacks (IPv4, IPv6) environments, this configuration (parameter "uris") contains only IPv4 addresses.
#
# DC2-A-VCAD001 - 10.12.16.209
# DC2-A-VCAD002 - 10.12.16.210
uris            = ldaps://10.12.16.209:636 ldaps://10.12.16.210:636
base            = ou=msx_svc,ou=users_svc,DC=ad-dc2,DC=example,DC=net
scope           = subtree
deref           = never
ldap_version    = 3

# LDAP User Binding settings
auth_bind       = yes
dn              = cn=vmail_svc,ou=Users_svc,DC=ad-dc2,DC=example,DC=net
dnpass          = <LDAP_BIND_PASSWORD>

# LDAP Filter settings
user_filter     = (&(memberOf:1.2.840.113556.1.4.1941:=CN=IMAP_ACCESS,OU=APPS,OU=RBAC_ROLES,OU=RBAC,DC=ad-dc2,DC=example,DC=net)(userPrincipalName=%u)(objectClass=person)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))
pass_filter     = (&(userPrincipalName=%u)(objectClass=person)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))
pass_attrs      = userPassword=password
default_pass_scheme = CRYPT
user_attrs      = =home=/data/vmail/%Ld/%Ln/Maildir/,=mail=maildir:/data/vmail/%Ld/%Ln/Maildir/

Differences from the users' file

LineUsersDevices
baseou=users_std,DC=ad-dc2,DC=example,DC=netou=msx_svc,ou=users_svc,DC=ad-dc2,DC=example,DC=net

Everything else is the same, including the user_filter with IMAP_ACCESS. A device account therefore gets a mailbox and webmail access only when it is put into that group, which the design reserves for troubleshooting, on request. For what the single lines do see dovecot-ldap.conf.users.

Differences between the hosts

The live lines are the same on the three servers. On DC2-B-VCMSX001 the file lacks the empty line at the end.

Checked against Dovecot 2.4.5

The settings are those of the users' file and so is the comparison: every key has a new name in 2.4 and moves into dovecot.conf. See dovecot-ldap.conf.users.

As builtToday
a second file for a second search basea second named passdb ldap and userdb ldap block with its own ldap_base

CentOS Stream 9 and 10, the upstream of RHEL 9 and 10, still carry Dovecot 2.3, so on RHEL the step from 2.2 to 2.3 comes first and the 2.4 syntax applies with upstream packages only.

← solutionz