Skip to content

Commit d8fc3ec

Browse files
committed
Enforce minimum membership of mailusers to send/receive(IMAP) mail
1 parent 878ba82 commit d8fc3ec

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

ansible/roles/dovecot/templates/configs/auth-ldap.conf.ext.j2

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -81,7 +81,7 @@ passdb ldap {
8181
}
8282
bind = yes
8383

84-
filter = (&(objectClass=posixAccount)(uid=%{user | username}))
84+
filter = (&(objectClass=posixAccount)(memberof=cn=mailusers,cn=groups,cn=accounts,dc=box,dc=pydis,dc=wtf)(uid=%{user | username}))
8585
driver = ldap
8686
ldap_connection_group = passdb
8787
}
@@ -93,7 +93,7 @@ userdb ldap {
9393
sieve = %{home}/main.sieve
9494
sieve_user_log_path = %{home}/sieve.log
9595
}
96-
filter = (&(objectClass=posixAccount)(uid=%{user | username}))
96+
filter = (&(objectClass=posixAccount)(memberof=cn=mailusers,cn=groups,cn=accounts,dc=box,dc=pydis,dc=wtf)(uid=%{user | username}))
9797
driver = ldap
9898
ldap_connection_group = userdb
9999
}

0 commit comments

Comments
 (0)