Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

integration with samba AD DC for user authentication - SASL Authentication? #121

Open
ezplanet opened this issue May 21, 2021 · 5 comments

Comments

@ezplanet
Copy link
Contributor

ezplanet commented May 21, 2021

Has anyone managed to configure dbmail to authenticate users through samba AD DC, either kerberos or LDAP? This is because I can have users authenticated via SASL integration with samba AD for postfix/SMTP (sending emails), but the password must be manually synchronised for IMAP access.
It would be a lot better if we could authenticate dbmail users via samba AD too.

@alan-hicks
Copy link
Member

alan-hicks commented May 21, 2021 via email

@ezplanet
Copy link
Contributor Author

Thanks Alan, I followed that example for openLDAP, but it does not work with Samba AD.
We would need dbmail to support SASL authentication, like postfix does.

@ezplanet ezplanet changed the title integration with samba AD DC for user authentication integration with samba AD DC for user authentication - SASL Authentication? May 22, 2021
@CozC
Copy link
Member

CozC commented May 25, 2021 via email

@alan-hicks
Copy link
Member

alan-hicks commented May 25, 2021 via email

@ezplanet
Copy link
Contributor Author

ezplanet commented May 25, 2021

I think it would be great if SASL authentication could be added to dbmail. It will deliver a fully integrated Single Sign On solution with Samba/Microsoft AD. I use Postfix as MTA which already supports SASL. All users would benefit greatly if also dbmail supported it.

I would not aim to a full Samba 4 / Kerberos solution however since this can require lots of work.
As a minimum viable solution I would just implement SASL for authenticating database users (NO LDAP required), using their AD password. Users would have to be created in dbmail with the same name as their AD CN. A DB attribute could select SASL authentication against the default domain.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants