Re: adding caldav/carddav next to dovecot

2022-10-16 Thread dovecot . pkoch
Hi, we are using Sabre DAV. Very stable and its performance depends on the performance of your webserver. We are using Apache-MPM prefork. If your webserver can handle HTTP-requests for 10k users, it will handle CARDDAV/CALDAV-requests for that amount of users as well. If you are familiar with

SSL Client authentication with trustcenter-certificate

2014-11-03 Thread dovecot . pkoch
Dear reader, we are using dovecot 2.2.7 and like it very much. Authentication is done via a checkpassword program that does two things: 1) check wether the client has connected via SSL using a client certificate 2) check wether the client is using a one time password generator Most of our users

Thunderbird ignores some folders

2014-10-03 Thread dovecot . pkoch
Dear readers we are using Dovecot 2.2.7 and all of our users are using Thunderbird as their mail client. Some of them additionally use their iPad/iPhone and a very few an Android Mail-Client. Now one user noticed that two of his mail folders disappeared. He first believed that he accidentally

[Dovecot] %{orig_user} missing in checkpassword-Script

2014-05-03 Thread dovecot . pkoch
Dear dovecot maintainers: I'm using SSL client certificates together with a checkpassword scripts to authenticate our users. My problem is: In the checkpassword script the AUTH_USER environment variable will either contain the username that was configured in the mailclient (if

[Dovecot] %{orig_user} missing in checkpassword-Script

2014-03-27 Thread dovecot . pkoch
Hi everybody, I'm using SSL client certificates or checkpassword scripts to authenticate our users. If a user sent a client certificate from his smartcard my checkpasswort will ignore the password, if he does not sent a client certificate but uses his OTP-token then my checkwassword script will

[Dovecot] AUTH_USER variable has invalid value in checkpassword Script

2014-02-25 Thread dovecot . pkoch
Dear dovecot experts: We are using client certificates to authenthicate against a Dovecot server. Our certificates contain a x500UniqueIdentifier. I'm absolutely sure that the value of the x500UniqueIdentifier was stored into the AUTH_USER when I tested my setup last year. This has somehow

Re: [Dovecot] AUTH_USER variable has invalid value in checkpassword Script

2014-02-25 Thread dovecot . pkoch
answering my own questions: This has somehow changed and now AUTH_USER always contains the username. This has fatal consequences as no every owner of a valid certificate can logon as any user. I now use auth_ssl_username_from_cert = yes and this temporarily fixes my problem. Now if user A

[Dovecot] ssl_require_crl does not work as expected

2013-04-07 Thread dovecot . pkoch
Hi I'm trying to use dovecot with client certificates. We produce our certificates with our on CA and we do NOT use certificate revocation lists. So I put ssl_require_crl = no into 10-ssl.conf. I did not find a solution neither in the wiki nor somewhere else, so I finally started to read the

[Dovecot] checkpassword protocol

2013-04-07 Thread dovecot . pkoch
Hi, I'm writing a checkpassword script in order to support our OTP token as a fallback for client certificate authentication. Here are two questions: 1) It seems to me that the username and the password will be delivered to my script both on file descriptor 3 and via the environment variables

[Dovecot] Logon with Client Certificate and OTP fallback

2013-03-10 Thread dovecot . pkoch
Dear Dovecot experts, we have unusual authentication requirements, namely: - almost all of our user are using a smartcard to connect with our mailserver. Thunderbird is our friend here as it will use the smartcard as an additional certificate store and Thunderbird will do client certificate

Re: [Dovecot] Logon with Client Certificate and OTP fallback (dovecot: message 4 of 20)

2013-03-10 Thread dovecot . pkoch
Hi Robert 2013/3/10 Robert Schetterer - r...@sys4.de dovecot.pkoch.74fa2fe130.rs#sys4...@ob.0sg.net try read http://wiki2.dovecot.org/PasswordDatabase/PAM ... This can be useful with e.g. pam_opie to find out which one time password you're supposed to give: 1 LOGIN username otp 1 NO