LINUXOR.SK ... open source notes ...

Email - dovecot-ldap.conf.users

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

Email Solution · Config document · referenced from Dovecot authentication

notednpass holds the password of the service account vmail_svc in clear text; it is a placeholder here. The file must be readable by root only.

The LDAP settings of Dovecot for the accounts of people: where the domain controllers are, with which account to search, and the filters that decide who may log in and who has a mailbox.

ItemValue
Path on the server/etc/dovecot/dovecot-ldap.conf.users
Shown hereDC2-A-VCMSX001
Also onDC2-B-VCMSX001 and DC2-A-VCMSX002
SearchesOU=Users_STD of the site 2 directory
Used bythe first passdb and the first userdb of auth-ldap.conf.ext
SoftwareDovecot 2.2 from the RHEL 7 repository; the exact package release is not recorded

The file

ini
# LDAP Server settings
# Due to problems in LDAP clients/LDAP libraries in dual IP stacks (IPv4, IPv6) environments, this configuration (parameter "uris") contains only IPv4 addresses.
#
# DC2-A-VCAD001 - 10.12.16.209
# DC2-A-VCAD002 - 10.12.16.210
uris            = ldaps://10.12.16.209:636 ldaps://10.12.16.210:636
base            = ou=users_std,DC=ad-dc2,DC=example,DC=net
scope           = subtree
deref           = never
ldap_version    = 3

# LDAP User Binding settings
auth_bind       = yes
dn              = cn=vmail_svc,ou=Users_svc,DC=ad-dc2,DC=example,DC=net
dnpass          = <LDAP_BIND_PASSWORD>

# LDAP Filter settings
user_filter     = (&(memberOf:1.2.840.113556.1.4.1941:=CN=IMAP_ACCESS,OU=APPS,OU=RBAC_ROLES,OU=RBAC,DC=ad-dc2,DC=example,DC=net)(userPrincipalName=%u)(objectClass=person)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))
pass_filter     = (&(userPrincipalName=%u)(objectClass=person)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))
pass_attrs      = userPassword=password
default_pass_scheme = CRYPT
user_attrs      = =home=/data/vmail/%Ld/%Ln/Maildir/,=mail=maildir:/data/vmail/%Ld/%Ln/Maildir/

Reading it

Differences between the hosts

The live lines are the same on the three servers. On DC2-B-VCMSX001 the file lacks the empty line at the end; diff shows nothing else.

Checked against Dovecot 2.4.5

As builtToday
urisldap_uris
dn, dnpassldap_auth_dn, ldap_auth_dn_password
base, scope, deref, ldap_version = 3ldap_base, ldap_scope, ldap_deref, ldap_version; version 3 is now the default
auth_bind = yespassdb_ldap_bind = yes
pass_filter, user_filterpassdb_ldap_filter, userdb_ldap_filter; since 2.4.3 variables in LDAP settings need the safe filter
pass_attrs, user_attrspassdb_fields, userdb_fields with %{ldap:attribute}
default_pass_scheme = CRYPTpassdb_default_password_scheme; irrelevant with authentication binds
no tls_* settingLDAP uses the common ssl_client_* settings; ssl_client_require_valid_cert defaults to yes, the CA comes from ssl_client_ca_file or ssl_client_ca_dir

The separate file is gone: in 2.4 these are regular settings in dovecot.conf. The last row is the one that matters for this build, which set no CA anywhere: a 2.4 server verifies the certificate of the domain controller unless told otherwise. On the directory side nothing changed that would break the file: simple binds over LDAPS keep working when Active Directory requires signing, and both matching-rule OIDs in the filters are still documented. CentOS Stream 9 and 10, the upstream of RHEL 9 and 10, still carry Dovecot 2.3, so on RHEL the step from 2.2 to 2.3 comes first and the 2.4 syntax applies with upstream packages only.

← solutionz