• [^] # Re: Configuration ?

    Posté par . En réponse au message Installation Dovecot Postfix. Évalué à 1.

    Fichier de config: slapd.conf:
    # Features to permit
    #allow bind_v2
    # Schema and objectClass definitions
    include /etc/ldap/schema/core.schema
    include /etc/ldap/schema/cosine.schema
    include /etc/ldap/schema/nis.schema
    include /etc/ldap/schema/inetorgperson.schema
    include /etc/ldap/schema/mmc.schema 
    include /etc/ldap/schema/mail.schema
    # Where the pid file is put. The init.d script
    # will not stop the server if you change this.
    pidfile /var/run/slapd/slapd.pid
    # List of arguments that were passed to the server
    argsfile /var/run/slapd/slapd.args
    # Read slapd.conf(5) for possible values
    loglevel 256
    # Where the dynamically loaded modules are stored
    modulepath	/usr/lib/ldap
    moduleload	back_bdb
    # The maximum number of entries that is returned for a search operation
    sizelimit 500
    # The tool-threads parameter sets the actual amount of cpu's that is used
    # for indexing.
    tool-threads 1
    #######################################################################
    # Specific Backend Directives for bdb:
    # Backend specific directives apply to this backend until another
    # 'backend' directive occurs
    backend		bdb
    #######################################################################
    # Specific Backend Directives for 'other':
    # Backend specific directives apply to this backend until another
    # 'backend' directive occurs
    #backend		
    #######################################################################
    # Specific Directives for database #1, of type bdb:
    # Database specific directives apply to this databasse until another
    # 'database' directive occurs
    database bdb
    # The base of your directory in database #1
    suffix "dc=flo-debian,dc=gescom"
    # rootdn directive for specifying a superuser on the database. This is needed
    # for syncrepl.
    rootdn "cn=admin,dc=flo-debian,dc=gescom"
    rootpw gescom
    # Where the database file are physically stored for database #1
    directory "/var/lib/ldap"
    # The dbconfig settings are used to generate a DB_CONFIG file the first
    # time slapd starts. They do NOT override existing an existing DB_CONFIG
    # file. You should therefore change these settings in DB_CONFIG directly
    # or remove DB_CONFIG and restart slapd for changes to take effect.
    # For the Debian package we use 2MB as default but be sure to update this
    # value if you have plenty of RAM
    dbconfig set_cachesize 0 2097152 0
    # Sven Hartge reported that he had to set this value incredibly high
    # to get slapd running at all. See http://bugs.debian.org/303057 for more
    # information.
    # Number of objects that can be locked at the same time.
    dbconfig set_lk_max_objects 1500
    # Number of locks (both requested and granted)
    dbconfig set_lk_max_locks 1500
    # Number of lockers
    dbconfig set_lk_max_lockers 1500
    # Indexing options for database #1
    index objectClass eq
    index cn,sn pres,eq,sub,subany
    # Save the time that the entry gets modified, for database #1
    lastmod on
    # Checkpoint the BerkeleyDB database periodically in case of system
    # failure and to speed slapd shutdown.
    checkpoint 512 30
    # Where to store the replica logs for database #1
    # replogfile	/var/lib/ldap/replog
    # The userPassword by default can be changed
    # by the entry owning it if they are authenticated.
    # Others should not be able to see it, except the
    # admin entry below
    # These access lines apply to database #1 only
    access to attrs=userPassword,shadowLastChange
     by dn="cn=admin,dc=flo-debian,dc=gescom" write
     by anonymous auth
     by self write
     by * none
    # Ensure read access to the base for things like
    # supportedSASLMechanisms. Without this you may
    # have problems with SASL not knowing what
    # mechanisms are available and the like.
    # Note that this is covered by the 'access to *'
    # ACL below too but if you change that as people
    # are wont to do you'll still need this if you
    # want SASL (and possible other things) to work 
    # happily.
    access to dn.base="" by * read
    # The admin dn has full write access, everyone else
    # can read everything.
    access to *
     by dn="cn=admin,dc=flo-debian,dc=gescom" write
     by * none
    	by * read
    # For Netscape Roaming support, each user gets a roaming
    # profile for which they have write access to
    #access to dn=".*,ou=Roaming,o=morsnet"
    # by dn="cn=admin,dc=flo-debian,dc=gescom" write
    # by dnattr=owner write
    #######################################################################
    # Specific Directives for database #2, of type 'other' (can be bdb too):
    # Database specific directives apply to this databasse until another
    # 'database' directive occurs
    #database 
    # The base of your directory for database #2
    #suffix		"dc=debian,dc=org"
    
    - ldap.conf:
    # LDAP Defaults
    # See ldap.conf(5) for details
    # This file should be world readable but not world writable.
    host localhost
    base dc=flo-debian,dc=gescom
    #SIZELIMIT	12
    #TIMELIMIT	15
    #DEREF		never
    
    - dovecot.conf:
    protocols = imap 
    auth default {
     # Space separated list of wanted authentication mechanisms:
     # plain login digest-md5 cram-md5 ntlm rpa apop anonymous gssapi
     # NOTE: See also disable_plaintext_auth setting.
     mechanisms = plain login
     # LDAP database <doc/wiki/AuthDatabase.LDAP.txt>
     passdb ldap {
     # Path for LDAP configuration file
     args = /etc/dovecot/dovecot-ldap.conf
     }
     userdb ldap {
     # Path for LDAP configuration file
     args = /etc/dovecot/dovecot-ldap.conf
     }
     user = root
     master {
     # Master socket provides access to userdb information. It's typically
     # used to give Dovecot's local delivery agent access to userdb so it
     # can find mailbox locations.
     path = /var/run/dovecot/auth-master
     #mode = 0600
     # Default user/group is the one who started dovecot-auth (root)
     user = vmail 
     group = mail
     }
    
    dovecot-ldap.conf:
    #
    # NOTE: If you're not using authentication binds, you'll need to give
    # dovecot-auth read access to userPassword field in the LDAP server.
    # With OpenLDAP this is done by modifying /etc/ldap/slapd.conf. There should
    # already be something like this:
    # access to attribute=userPassword
    # by dn="<dovecot's dn>" read # add this
    # by anonymous auth
    # by self write
    # by * none
    # Space separated list of LDAP hosts to use. host:port is allowed too.
    hosts = flo-debian.gescom
    # LDAP URIs to use. You can use this instead of hosts list. Note that this
    # setting isn't supported by all LDAP libraries.
    #uris = 
    # Distinguished Name - the username used to login to the LDAP server
    #dn = cn=test,ou=Users,dc=flo-debian,dc=gescom 
    # Password for LDAP server
    #dnpass = test
    # Use SASL binding instead of the simple binding. Note that this changes
    # ldap_version automatically to be 3 if it's lower. Also note that SASL binds
    # and auth_bind=yes don't work together.
    #sasl_bind = no
    # SASL mechanism name to use.
    #sasl_mech =
    # SASL realm to use.
    #sasl_realm =
    # SASL authorization ID, ie. the dnpass is for this "master user", but the
    # dn is still the logged in user. Normally you want to keep this empty.
    #sasl_authz_id =
    # Use TLS to connect to the LDAP server.
    #tls = no
    # Use authentication binding for verifying password's validity. This works by
    # logging into LDAP server using the username and password given by client.
    # The pass_filter is used to find the DN for the user. Note that the pass_attrs
    # is still used, only the password field is ignored in it. Before doing any
    # search, the binding is switched back to the default DN.
    auth_bind = yes
    #
    # If you use this setting, it's a good idea to use a different
    # dovecot-ldap.conf for userdb (it can even be a symlink, just as long as the
    # filename is different in userdb's args). That way one connection is used only
    # for LDAP binds and another connection is used for user lookups. Otherwise
    # the binding is changed to the default DN before each user lookup.
    #
    # For example:
    # auth_bind_userdn = cn=%u,ou=people,o=org
    #
    #auth_bind_userdn =
    # LDAP protocol version to use. Likely 2 or 3.
    ldap_version = 3
    # LDAP base. %variables can be used here.
    base = dc=flo-debian, dc=gescom
    # Dereference: never, searching, finding, always
    deref = never
    # Search scope: base, onelevel, subtree
    scope = subtree
    # User attributes are given in LDAP-name=dovecot-internal-name list. The
    # internal names are:
    # uid - System UID
    # gid - System GID
    # home - Home directory
    # mail - Mail location
    #
    # There are also other special fields which can be returned, see
    # http://wiki.dovecot.org/UserDatabase/ExtraFields
    user_attrs = mailbox=home
    # Filter for user lookup. Some variables can be used (see
    # http://wiki.dovecot.org/Variables for full list):
    # %u - username
    # %n - user part in user@domain, same as %u if there's no domain
    # %d - domain part in user@domain, empty if user there's no domain
    user_filter = (&(objectClass=mailAccount)(mail=%u)(mailenable=OK)) 
    # Password checking attributes:
    # user: Virtual user name (user@domain), if you wish to change the
    # user-given username to something else
    # password: Password, may optionally start with {type}, eg. {crypt}
    # There are also other special fields which can be returned, see
    # http://wiki.dovecot.org/PasswordDatabase/ExtraFields
    pass_attrs = mail=user,userPassword=password 
    # If you wish to avoid two LDAP lookups (passdb + userdb), you can use
    # userdb prefetch instead of userdb ldap in dovecot.conf. In that case you'll
    # also have to include user_attrs in pass_attrs field prefixed with "userdb_"
    # string. For example:
    #pass_attrs = uid=user,userPassword=password,homeDirectory=userdb_home,uidNumber=userdb_uid,gidNumber=userdb_gid
    # Filter for password lookups
    pass_filter = (&(objectClass=mailAccount)(mail=%u)(mailenable=OK)) 
    # Default password scheme. "{scheme}" before password overrides this.
    # List of supported schemes is in: http://wiki.dovecot.org/Authentication
    #default_pass_scheme = CRYPT
    # You can use same UID and GID for all user accounts if you really want to.
    # If the UID/GID is still found from LDAP reply, it overrides these values.
    user_global_uid = vmail 
    user_global_gid = mail
    
    Pour info, je ne cherche pas a mettre en place, dans un 1er temps en tout cas, de sécurité ssl ou autres. Voila pour les fichiers et sinon merci pour l'info telnet :)