Email - dovecot-ldap.conf.users
Email Solution · Config document · referenced from Dovecot authentication
dnpass holds the password of the service account vmail_svc in clear text; it is a placeholder here. The file must be readable by root only.The LDAP settings of Dovecot for the accounts of people: where the domain controllers are, with which account to search, and the filters that decide who may log in and who has a mailbox.
| Item | Value |
|---|---|
| Path on the server | /etc/dovecot/dovecot-ldap.conf.users |
| Shown here | DC2-A-VCMSX001 |
| Also on | DC2-B-VCMSX001 and DC2-A-VCMSX002 |
| Searches | OU=Users_STD of the site 2 directory |
| Used by | the first passdb and the first userdb of auth-ldap.conf.ext |
| Software | Dovecot 2.2 from the RHEL 7 repository; the exact package release is not recorded |
The file
# LDAP Server settings # Due to problems in LDAP clients/LDAP libraries in dual IP stacks (IPv4, IPv6) environments, this configuration (parameter "uris") contains only IPv4 addresses. # # DC2-A-VCAD001 - 10.12.16.209 # DC2-A-VCAD002 - 10.12.16.210 uris = ldaps://10.12.16.209:636 ldaps://10.12.16.210:636 base = ou=users_std,DC=ad-dc2,DC=example,DC=net scope = subtree deref = never ldap_version = 3 # LDAP User Binding settings auth_bind = yes dn = cn=vmail_svc,ou=Users_svc,DC=ad-dc2,DC=example,DC=net dnpass = <LDAP_BIND_PASSWORD> # LDAP Filter settings user_filter = (&(memberOf:1.2.840.113556.1.4.1941:=CN=IMAP_ACCESS,OU=APPS,OU=RBAC_ROLES,OU=RBAC,DC=ad-dc2,DC=example,DC=net)(userPrincipalName=%u)(objectClass=person)(!(userAccountControl:1.2.840.113556.1.4.803:=2))) pass_filter = (&(userPrincipalName=%u)(objectClass=person)(!(userAccountControl:1.2.840.113556.1.4.803:=2))) pass_attrs = userPassword=password default_pass_scheme = CRYPT user_attrs = =home=/data/vmail/%Ld/%Ln/Maildir/,=mail=maildir:/data/vmail/%Ld/%Ln/Maildir/
Reading it
urisnames the two domain controllers of site 2 by IPv4 address and withldaps://, TLS from the first byte on port 636.dnanddnpassare the service account that searches the directory.auth_bind = yesthen verifies the password by binding as the account that was found.pass_filterfinds the account at login: the login name must equaluserPrincipalName, and the account must not be disabled (bit 2 ofuserAccountControl).user_filteris used for user lookups, that is for IMAP logins and for mail delivery. It asks in addition for membership ofIMAP_ACCESS, directly or through nested groups (the matching rule1.2.840.113556.1.4.1941).pass_attrsanddefault_pass_schemebelong to the other way of working, where Dovecot reads a password hash from the directory and compares it itself. Active Directory does not hand outuserPassword, and withauth_bind = yesthese two lines are not used.
Differences between the hosts
The live lines are the same on the three servers. On DC2-B-VCMSX001 the file lacks the empty line at the end; diff shows nothing else.
Checked against Dovecot 2.4.5
| As built | Today |
|---|---|
uris | ldap_uris |
dn, dnpass | ldap_auth_dn, ldap_auth_dn_password |
base, scope, deref, ldap_version = 3 | ldap_base, ldap_scope, ldap_deref, ldap_version; version 3 is now the default |
auth_bind = yes | passdb_ldap_bind = yes |
pass_filter, user_filter | passdb_ldap_filter, userdb_ldap_filter; since 2.4.3 variables in LDAP settings need the safe filter |
pass_attrs, user_attrs | passdb_fields, userdb_fields with %{ldap:attribute} |
default_pass_scheme = CRYPT | passdb_default_password_scheme; irrelevant with authentication binds |
no tls_* setting | LDAP uses the common ssl_client_* settings; ssl_client_require_valid_cert defaults to yes, the CA comes from ssl_client_ca_file or ssl_client_ca_dir |
The separate file is gone: in 2.4 these are regular settings in dovecot.conf. The last row is the one that matters for this build, which set no CA anywhere: a 2.4 server verifies the certificate of the domain controller unless told otherwise. On the directory side nothing changed that would break the file: simple binds over LDAPS keep working when Active Directory requires signing, and both matching-rule OIDs in the filters are still documented. CentOS Stream 9 and 10, the upstream of RHEL 9 and 10, still carry Dovecot 2.3, so on RHEL the step from 2.2 to 2.3 comes first and the 2.4 syntax applies with upstream packages only.