OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: Prevent specific user to authenticate in SASL/LDAP

From: Alain Spineux (aspineuxgmail.com)
Date: Fri Jul 20 2007 - 16:34:15 CDT


This is not related to postfix but to SASL.
Anyway You have two solution, you create a group and you make this
user member of the group, or you add an attribute to a special value.

Then in your saslauthd.conf, you customize the ldap_filter option to check if
the user has the attribute or is in the group.

Regards

On 7/19/07, Steve Scanavarro <steve.scanavarrogmail.com> wrote:
> Hello everyone.
> I have a system that works as follows:
> Machine 1 ( Linux MAILSERVER): Running Postfix + Cyrus + SASL Authentication
> through PAM+LDAP.
> Machine 2 : This is the machine that is running MS Active Directory (ie.
> LDAP), where the Machine 1 sends the request for authentication.
> Machine 3: Squid + LDAP (active directory) authentication
>
> Well, what I need is to block an UNIQUE and SPECIFIC user account from using
> the E-Mail, specially Authenticating (SASL->LDAP), but I cannot
> erase/disabled that account in Active Directory, because it's been used by
> Machine 3 for LDAP authentication in the Proxy (Squid).
>
> Thanks for any help!
>
>

--
--
Alain Spineux
aspineux gmail com
May the sources be with you