Re: Log authentication attempts
25 Jan
2017
25 Jan
'17
12:24 a.m.
On 24.01.2017 00:06, rej ex wrote:
SMTP? Wouldn't that be handled by your MTA, not Dovecot?
AKi Tuomi wrote:
Since 2.2.27 we've had auth policy server support which can do this properly.
As I read the docs, the auth policy server would only get the hashed password, and wouldn't be able to record the plaintext password.
Maybe use the checkpassword hook?
http://wiki.dovecot.org/AuthDatabase/CheckPassword
Joseph Tam <jtam.home@gmail.com>
25 Jan
25 Jan
7:17 a.m.
New subject: Log authentication attempts
So it would seem if you don't read it carefully.
auth_policy_request_attributes: Request attributes specification (see attributes section below) Default: auth_policy_request_attributes = login=%{orig_username} pwhash=%{hashed_password} remote=%{real_rip}
I invite you to consider what would happen if you were to replace %{hashed_password} with %{password}?
Aki
2991
Age (days ago)
2992
Last active (days ago)
1 comments
2 participants
participants (2)
-
Aki Tuomi
-
Joseph Tam