More on my IMAP problem...
Before I elaborate, if anyone has IMAP working with userdb, would you mind posting or sending me a copy of your etc/imapd config file? I've also attached my etc/imapd config file to this message in case someone can spot the problem. Anyway... As I mentioned previously, POP3 and Webmail are working fine, so the general Courier configuration seems to be ok. The environment is 100% Courier; no Qmail/Exim/etc. I'm using userdb with systempw defined, and running authdaemon.plain. An example userdb entry looks like this: [EMAIL PROTECTED] uid=10001|gid=10001|home=/mail/karmak.org/alli|systempw=XXX For this example, a Maildir has been created under /mail/karmak.org/alli. I have not created any other directories or files here, although several have been created by the system after logging in via Webmail. Courier runs under UID/GID=10001/10001. The following configure options were used in building Courier: --with-db=gdbm --with-mailuser=courier --with-mailgroup=courier --disable-changepass --with-ispell=[/path/to/ispell] --disable-https --with-cacheowner=courier --enable-workarounds-for-imap-client-bugs --enable-mimetypes=[courier-dir]/etc/mimetypes The IMAP server starts up both from the command line and from the Webadmin interface. Neither report any problems. The server is definitely running, as I can telnet to port 143. The SSL server also running, and the certificate is transferred when connecting to port 993 with a client. However, after the username and password are sent, the server mysteriously breaks the connection. If I telnet to port 143, I can manually type CAPABILITY and get the following: -------------------------------- * OK Courier-IMAP ready. Copyright 1998-2001 Double Precision, Inc. See COPYING for distribution information. CAPABILITY * CAPABILITY IMAP4rev1 NAMESPACE AUTH=CRAM-MD5 CHILDREN SORT THREAD=ORDEREDSUBJECT THREAD=REFERENCES CAPABILITY OK CAPABILITY completed -------------------------------- If I type LOGIN with a username and password, the connection is immediately terminated. The output is: -------------------------------- * OK Courier-IMAP ready. Copyright 1998-2001 Double Precision, Inc. See COPYING for distribution information. a001 LOGIN [EMAIL PROTECTED] [plain-text-password] Connection closed by foreign host. -------------------------------- I'm not very familiar with the IMAP protocol, but based on a cursory reading of RFC2060, it looks like the LOGIN command should have been accepted. I've also tried turning on 'AUTH=PLAIN' for non-TLS connections, but this did not work. (I'm not really sure if that's relevant here, as it looks like AUTHENTICATE is optional). That's all I have for now. Could someone who is familiar with the IMAP protocol verify whether or not the LOGIN command should have worked as I've used it above? If not, is there any way I can tell manually pass commands to the server to find out where exactly things are breaking? Unfortunately none of the clients I've used (Mutt, Outlook Express, and Mozilla) give any indication of what the problem is. Thanks, m.
##VERSION: $Id: imapd.dist.in,v 1.11 2001/11/13 13:35:27 mrsam Exp $ # # imapd created from imapd.dist by sysconftool # # Do not alter lines that begin with ##, they are used when upgrading # this configuration. # # Copyright 1998 - 2001 Double Precision, Inc. See COPYING for # distribution information. # # This configuration file sets various options for the Courier-IMAP server # when used with the couriertcpd server. # A lot of the stuff here is documented in the manual page for couriertcpd. # # NOTE - do not use \ to split long variable contents on multiple lines. # This will break the default imapd.rc script, which parses this file. # ##NAME: ADDRESS:0 # # Address to listen on, can be set to a single IP address. # # ADDRESS=127.0.0.1 ADDRESS=0 ##NAME: PORT:1 # # Port numbers that connections are accepted on. The default is 143, # the standard IMAP port. # # Multiple port numbers can be separated by commas. When multiple port # numbers are used it is possible to select a specific IP address for a # given port as "ip.port". For example, "127.0.0.1.900,192.68.0.1.900" # accepts connections on port 900 on IP addresses 127.0.0.1 and 192.68.0.1 # The previous ADDRESS setting is a default for ports that do not have # a specified IP address. PORT=143 ##NAME: MAXDAEMONS:0 # # Maximum number of IMAP servers started # MAXDAEMONS="40" ##NAME: MAXPERIP:0 # # Maximum number of connections to accept from the same IP address MAXPERIP="4" ##NAME: PIDFILE:0 # # File where couriertcpd will save its process ID # PIDFILE=/pkg/courier/0.36.1/var/run/tmp/imapd.pid ##NAME: TCPDOPTS:0 # # Miscellaneous couriertcpd options that shouldn't be changed. # TCPDOPTS="-nodnslookup -noidentlookup" ##NAME: AUTHMODULES:0 # # Authentication modules. Here's the default list: # # authdaemon # # The default is set during the initial configuration. # AUTHMODULES="authdaemon" ##NAME: AUTHMODULES_ORIG:0 # # For use by webadmin AUTHMODULES_ORIG="authdaemon" ##NAME: IMAP_CAPABILITY:0 # # IMAP_CAPABILITY specifies what most of the response should be to the # CAPABILITY command. # # If you have properly configured Courier to use CRAM-MD5 or CRAM-SHA1 # authentication (see INSTALL), set IMAP_CAPABILITY as follows: # # IMAP_CAPABILITY="IMAP4rev1 CHILDREN NAMESPACE THREAD=ORDEREDSUBJECT THREAD=REFERENCES SORT AUTH=CRAM-MD5 AUTH=CRAM-SHA1" # # Otherwise, leave it set to the default value. The IDLE keyword can also # be added, in experimental mode. # # NOTE: CRAM-SHA1 is considered experimental at this time. # # NOTE: If you use maildirquotas (see maildir/README.maildirquota), partial # support for the QUOTA extension can be added. IMAP_CAPABILITY="IMAP4rev1 NAMESPACE AUTH=CRAM-MD5 CHILDREN SORT THREAD=ORDEREDSUBJECT THREAD=REFERENCES" ##NAME: IMAP_CAPABILITY_ORIG:0 # # For use by webadmin IMAP_CAPABILITY_ORIG="IMAP4rev1 CHILDREN NAMESPACE THREAD=ORDEREDSUBJECT THREAD=REFERENCES SORT AUTH=CRAM-MD5 AUTH=CRAM-SHA1 IDLE" ##NAME: IMAP_IDLE_TIMEOUT:0 # # If you want to try out the IDLE extension, this setting controls how often # the server polls for changes to the folder, in IDLE mode (in seconds). IMAP_IDLE_TIMEOUT="60" ##NAME: IMAP_CAPABILITY_TLS:0 # # The following setting will advertise SASL PLAIN authentication after # STARTTLS is established. If you want to allow SASL PLAIN authentication # with or without TLS then just comment this out, and add AUTH=PLAIN to # IMAP_CAPABILITY IMAP_CAPABILITY_TLS="IMAP4rev1 NAMESPACE AUTH=CRAM-MD5 AUTH=PLAIN CHILDREN SORT THREAD=ORDEREDSUBJECT THREAD=REFERENCES" ##NAME: IMAP_TLS_ORIG:0 # # For use by webadmin IMAP_CAPABILITY_TLS_ORIG="$IMAP_CAPABILITY_ORIG AUTH=PLAIN" ##NAME: IMAP_DISABLETHREADSORT:0 # # Set IMAP_DISABLETHREADSORT to disable the THREAD and SORT commands - # server side sorting and threading. # # Those capabilities will still be advertised, but the server will reject # them. Set this option if you want to disable all the extra load from # server-side threading and sorting. Not advertising those capabilities # will simply result in the clients reading the entire folder, and sorting # it on the client side. That will still put some load on the server. # advertising these capabilities, but rejecting the commands, will stop this # silliness. # IMAP_DISABLETHREADSORT="0" ##NAME: IMAP_CHECK_ALL_FOLDERS:0 # # Set IMAP_CHECK_ALL_FOLDERS to 1 if you want the server to check for new # mail in every folder. Not all IMAP clients use an IMAP's server new mail # indicator, but some do, and normally new mail is checked only in INBOX, # because it is a comparatively time consuming operation, and it would be # a complete waste of time unless mail filters are used to deliver new # mail directly to folders. # # When IMAP clients are used which support new mail indication, and when # mail filters are used to sort incoming mail into folders, setting # IMAP_CHECK_ALL_FOLDERS to 1 will allow IMAP clients to announce new # mail in folders. Note that this will result in slightly more load on the # server. # IMAP_CHECK_ALL_FOLDERS="0" ##NAME: IMAP_OBSOLETE_CLIENT:0 # # Set IMAP_OBSOLETE_CLIENT if your IMAP client expects \\NoInferiors to mean # what \\HasNoChildren really means. IMAP_OBSOLETE_CLIENT="0" ##NAME: IMAP_ULIMITD:0 # # IMAP_ULIMITD sets the maximum size of the data segment of the server # process. The value of IMAP_ULIMITD is simply passed to the "ulimit -d" # command. The argument to ulimit -d sets the upper limit on the size # of the data segment of the server process, in kilobytes. The default # value of 65536 sets a very generous limit of 64 megabytes, which should # be more than plenty for anyone. # # This feature is used as an additional safety check that should stop # any potential denial-of-service attacks that exploit any kind of # a memory leak to exhaust all the available memory on the server. # It is theoretically possible that obscenely huge folders will also # result in the server running out of memory when doing server-side # sorting (by my calculations you have to have at least 100,000 messages # in a single folder, for that to happen). IMAP_ULIMITD="65536" ##NAME: IMAP_USELOCKS:0 # # Set IMAP_USELOCKS to 1 if you experience weird problems when using IMAP # clients that open multiple connections to the server. I would hope that # most IMAP clients are sane enough not to issue commands to multiple IMAP # channels which conflict with each other. # IMAP_USELOCKS="0" ##NAME: IMAP_EMPTYTRASH:0 # # The following setting is optional, and causes messages from the given # folder to be automatically deleted after the given number of days. # IMAP_EMPTYTRASH is a comma-separated list of folder:days. The default # setting, below, purges 7 day old messages from the Trash folder. # Another useful setting would be: # # IMAP_EMPTYTRASH=Trash:7,Sent:30 # # This would also delete messages from the Sent folder (presumably copies # of sent mail) after 30 days. This is a global setting that is applied to # every mail account, and is probably useful in a controlled, corporate # environment. # # You might want to disable this setting in certain situations - it results # in a stat() of every file in each folder, at login and logout. # IMAP_EMPTYTRASH="Trash:7" ##NAME: IMAP_MOVE_EXPUNGE_TO_TRASH:0 # # Set IMAP_MOVE_EXPUNGE_TO_TRASH to move expunged messages to Trash. This # effectively allows an undo of message deletion by fishing the deleted # mail from trash. Trash can be manually expunged as usually, and mail # will get automatically expunged from Trash according to IMAP_EMPTYTRASH. # # NOTE: shared folders are still expunged as usual. Shared folders are # not affected. # IMAP_MOVE_EXPUNGE_TO_TRASH="0" ##NAME: IMAPDSTART:0 # # IMAPDSTART is not used directly. Rather, this is a convenient flag to # be read by your system startup script in /etc/rc.d, like this: # # . /pkg/courier/0.36.1/libexec/imapd.config # # case x$IMAPDSTART in # x[yY]*) # /pkg/courier/0.36.1/libexec/imapd.rc start # ;; # esac # # The default setting is going to be NO, so you'll have to manually flip # it to yes. IMAPDSTART="YES"
