Hi there
I'm having difficulties in getting dovecot to run under daemontools. Also, from a sysadmin perspective, so far, I find dovecot's config rather complex - I suppose that's what happens when one attempts to appease all authentication methods... anyway, I digress.
System details, to set the scene:
OS: Slackware Linux
Linux Kernel: 2.4.29
GCC: 3.2.2
Dovecot version: 1.0.rc6
Dovecot configure options:
./configure --prefix=/usr --sysconfdir=/etc --localstatedir=/var --with-checkpassword --without-passwd --without-passwd-file --without-shadow --without-pam --without-bsdauth --without-gssapi --without-ldap --without-vpopmail --with-prefetch-userdb --without-sql --without-pgsql --without-mysql --with-ssl=openssl --without-pop3d --with-storages=maildir --without-deliver
MTA: qmail
Storage: Maildirs under a single virtual user (vmail)
Checkpassword: /var/qmail/bin/qmail-vpoplogin (modified cdb checkpassword)
User DB: /var/qmail/users/vpasswd.cdb
/etc/dovecot.conf
base_dir = /var/run/dovecot
protocols = imap
listen = 127.0.0.1
ssl_disable = yes
shutdown_clients = yes
log_path = /var/log/dovecot
login_dir = /var/run/dovecot/login
maildir_copy_with_hardlinks = yes
protocol imap {
# only require access from webmail on same host
listen = 127.0.0.1:143
}
auth default {
passdb checkpassword {
args = /var/qmail/bin/qmail-vpoplogin
}
userdb prefetch {
}
# user who can access user/passwd db
user = auth
}
Firstly, I cannot run dovecot as an unprivileged user, as the OS moans that the user doesn't have permission to write to /dev/stderr. I've had a similar issue running Clamav, but a patch to Clamav resolved this? This seems to be related to referencing /dev/stderr directly. Any ideas?
Should I be running dovecot as the virtual mailbox user vmail?
Before I ramble on about what I've tried, could someone explain to me what dovecot actually does, in terms of privilege separation? The online docs are somewhat convoluted. This would help shed light on the solution.
I also noticed the posts re daemontools some time ago, yet they do not include any setup solutions etc - I'd appreciate details from those of you who've succeeded in this regard.
Thanks
Dale