Using a separate passdb per service

Steffen Kaiser skdovecot at smail.inf.fh-brs.de
Mon Aug 10 07:58:40 UTC 2015


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Fri, 7 Aug 2015, Gerry wrote:

> The problem is that Dovecot is operating in proxy mode, which means
> that the password_query returns NULL as the password and explicitly
> returns a field "nopasswd" containing "Y". Thus, users can not
> authenticate against the UNIX socket.

> What I think I want to do is convince Dovecot to use one passdb for the
> imap/pop3/managesieve services and different one for the "auth" service.

As far as I know, all services use the "auth" in the back.

But you have the "%s" / service variable. You should be able to craft a 
SQL query, that returns NULL & nopasswd=Y, if postfix is not querying 
Dovecot.

I don't know, which service name postfix passes to Dovecot, though,

- -- 
Steffen Kaiser
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQEVAwUBVchZsHz1H7kL/d9rAQIaLwf/WXnI9PMGuN042g7VzfDlZxbsVTvck55X
DqPdy1P+YDtMCFpEbTxQG8m9EMfI82Zcd3rzqGbcaMbFqatG7TsucBg06S5j7XSX
fs/jNX6DwAdmNIRzjrEU5a8M+Zpo6ifWohBO1IMax3sAs4Z9v+O/hEjX1wiKed24
nFA1QNFG/s2bjDUbf7WBYnU0MnFPeUmMJzy5sR+zFC9lWbaj+Y9b6ayMbdlhVvcz
8qu827/i+2McHlDiS3a2JmwuYTyGpPwfryIojjgTnYvxB1Ex4qsI/mfk8s2am6hY
SIvi0Btdlb/ZUmxMy8WKj/hko4Mb+nxO6FBpMU8V8opTJHHUuLf0UA==
=1Wip
-----END PGP SIGNATURE-----


More information about the dovecot mailing list