ldap auxprop plugin on centos4/rhel4?

Nikola Milutinovic alokin1 at yahoo.com
Thu Mar 9 04:06:53 EST 2006

--- Simon Matter <simon.matter at ch.sauter-bc.com> wrote:

> > I'm currently using saslauthd configured to use LDAP.  Trying to switch
> > to ldap auxprop plugin.  Went through the man pages, and Googled
> > around, and all examples I found don't seem to work.  The Cyrus simply
> > doesn't talk to my LDAP server (not even attempting, as witnessed by
> > tcpdump).  Do I need any additional RPM package for CentOS4 or RHEL4 to
> > make this work?  Do I need to recompile cyrus-sasl with any special
> > options (looks the one distributed with CentOS4 and RHEL4 is compiled
> > with '--with-ldap')?
> On an old RedHat 7.2 test box with my own cyrus-sasl rpm I was using this
> config:
> /etc/imapd.conf:
> sasl_pwcheck_method: saslauthd
> sasl_mech_list: PLAIN
> /etc/sysconfig/saslauthd:
> MECH=ldap
> /etc/saslauthd.conf:
> ldap_servers: ldap://localhost/
> ldap_search_base: dc=invoca,dc=ch
> #ldap_bind_dn: <none>
> #ldap_bind_pw: <none>
> Is this what you tried?
> Simon

No Simon.

I believe Aleksandar is talking about AuxProp: LDAP-DB. AFAIK, AuxProp can have
3 backends: SASL-DB, SQL (MySQL and PgSQL) and LDAP-DB. He is trying to cut out
SASLAuthD from the picture.

This is basically a good move, since it will enable even CRAM-MD5 and
DIGEST-MD5 against MS Active Directory. Is that what you're after, Alex? We
will be introducing an IMAP4 server into our intranet, soon. Of course, GSSAPI
will be on the top of my list, but even (PLAIN+SSL) or CRAM-MD5 -> AuxProp ->
LDAP -> ADS sounds fine.


