auth against LDAP

Michael Plate plate at bibliothek.uni-kassel.de
Fri Oct 29 05:37:26 EDT 2004


Hi,

bnies at bluewin.ch wrote:
[...]
> The disadvantage of using PAM is that the mail users get system accounts.

Are you really sure ? I don't know PAM on solaris, but if  you only 
allow imap, sieve and possibly pop3 in e.g. /etc/pam.d/ user can't get 
an interactive account.

/etc/pam.d/imap (with access for ldap and winbind) :

auth       sufficient   /lib/security/pam_ldap.so
account    sufficient   /lib/security/pam_ldap.so
auth       required     /lib/security/pam_winbind.so use_first_pass
account    required     /lib/security/pam_winbind.so

works for some users not on windos via a local ldap and AD (using smb, 
not ldap)

CU

Michael




---
Cyrus Home Page: http://asg.web.cmu.edu/cyrus
Cyrus Wiki/FAQ: http://cyruswiki.andrew.cmu.edu
List Archives/Info: http://asg.web.cmu.edu/cyrus/mailing-list.html




More information about the Info-cyrus mailing list