diff --git a/manifests/ldap.pp b/manifests/ldap.pp index d04a7c8..5989632 100644 --- a/manifests/ldap.pp +++ b/manifests/ldap.pp @@ -2,6 +2,7 @@ # auth-ldap.conf.ext class dovecot::ldap ( $ldap_hosts = 'ldap.example.org:389', + $ldap_uris = false, $ldap_dn = 'cn=vmail,cn=users,dc=example,dc=org', $ldap_dnpass = 'NotPassword#1234!', $ldap_auth_bind_userdn = 'cn=%n,cn=users,dc=example,dc=org', @@ -9,13 +10,32 @@ $ldap_auth_bind = 'no', $ldap_scope = 'subtree', $ldap_debug_level = '-1', + $ldap_userdb_static = 'uid=vmail gid=vmail home=/srv/vmail/%n mail=maildir:~/mail', $ldap_user_filter = '(&(objectClass=user)(cn=%n))', + $ldap_user_attrs = '=home=/srv/vmail/%d/%n, =uid=vmail, =gid=vmail, =mail=maildir:~/mail', $ldap_pass_filter = '(&(objectClass=user)(cn=%n))', $ldap_pass_attrs = 'cn=user', #cn is ldap attribute name, user is dovecot field $ldap_iterate_attrs = 'cn=user', - $ldap_iterate_filter = '(objectClass=user)' + $ldap_iterate_filter = '(objectClass=user)', + $ldap_tls = 'no', + $ldap_tls_ca_cert_file = false, + $ldap_tls_ca_cert_dir = false, + $ldap_tls_cipher_suite = false, + $ldap_tls_cert_file = false, + $ldap_tls_key_file = false, + $ldap_tls_require_cert = 'demand', ) { + if $ldap_uris and $ldap_hosts { + fail('uris and hosts are mutually exclusives') + } + + package {'dovecot-ldap': + ensure => installed, + before => Exec['dovecot'], + notify => Service['dovecot'] + } + # TODO the next two files use same template, probably should be creating symlink.... file { '/etc/dovecot/dovecot-ldap.conf.ext': ensure => present, diff --git a/templates/auth-ldap.conf.ext b/templates/auth-ldap.conf.ext index 7fc5b7a..d5de265 100644 --- a/templates/auth-ldap.conf.ext +++ b/templates/auth-ldap.conf.ext @@ -25,13 +25,17 @@ passdb { # lookup by using userdb static instead of userdb ldap, for example: # #these values for home and mail override mail_home and mail_location +<%- if @ldap_userdb_static -%> userdb { driver = static - #args = uid=vmail gid=vmail home=/srv/vmail/%d/%n mail=maildir:~/mail - # not using domain in mail home b/c domain is stripped by "auth_username_format = %Ln" and - # we don't know how to look up username in ldap - args = uid=vmail gid=vmail home=/srv/vmail/%n mail=maildir:~/mail + args = <%= @ldap_userdb_static %> } +<%- else -%> +#userdb { +# driver = static +# args = +#} +<%- end -%> #userdb { # driver = prefetch #} @@ -40,4 +44,4 @@ userdb { userdb { driver = ldap args = /etc/dovecot/dovecot-ldap-userdb.conf.ext -} \ No newline at end of file +} diff --git a/templates/dovecot-ldap.conf.ext b/templates/dovecot-ldap.conf.ext index 56a5931..62869f6 100644 --- a/templates/dovecot-ldap.conf.ext +++ b/templates/dovecot-ldap.conf.ext @@ -1,150 +1,194 @@ -# This file is opened as root, so it should be owned by root and mode 0600. -# -# http://wiki2.dovecot.org/AuthDatabase/LDAP -# -# NOTE: If you're not using authentication binds, you'll need to give -# dovecot-auth read access to userPassword field in the LDAP server. -# With OpenLDAP this is done by modifying /etc/ldap/slapd.conf. There should -# already be something like this: - -# access to attribute=userPassword -# by dn="" read # add this -# by anonymous auth -# by self write -# by * none - -# Space separated list of LDAP hosts to use. host:port is allowed too. -hosts = <%= @ldap_hosts %> - -# LDAP URIs to use. You can use this instead of hosts list. Note that this -# setting isn't supported by all LDAP libraries. -#uris = - -# Distinguished Name - the username used to login to the LDAP server. -# Leave it commented out to bind anonymously (useful with auth_bind=yes). -dn = <%= @ldap_dn %> - -# Password for LDAP server, if dn is specified. -dnpass = <%= @ldap_dnpass %> - -# Use SASL binding instead of the simple binding. Note that this changes -# ldap_version automatically to be 3 if it's lower. Also note that SASL binds -# and auth_bind=yes don't work together. -#sasl_bind = no -# SASL mechanism name to use. -#sasl_mech = -# SASL realm to use. -#sasl_realm = -# SASL authorization ID, ie. the dnpass is for this "master user", but the -# dn is still the logged in user. Normally you want to keep this empty. -#sasl_authz_id = - -# Use TLS to connect to the LDAP server. -tls = no -# TLS options, currently supported only with OpenLDAP: -#tls_ca_cert_file = -#tls_ca_cert_dir = -#tls_cipher_suite = -# TLS cert/key is used only if LDAP server requires a client certificate. -#tls_cert_file = -#tls_key_file = -# Valid values: never, hard, demand, allow, try -#tls_require_cert = - -# Use the given ldaprc path. -#ldaprc_path = - -# LDAP library debug level as specified by LDAP_DEBUG_* in ldap_log.h. -# -1 = everything. You may need to recompile OpenLDAP with debugging enabled -# to get enough output. -debug_level = <%= @ldap_debug_level %> - -# Use authentication binding for verifying password's validity. This works by -# logging into LDAP server using the username and password given by client. -# The pass_filter is used to find the DN for the user. Note that the pass_attrs -# is still used, only the password field is ignored in it. Before doing any -# search, the binding is switched back to the default DN. -auth_bind = <%= @ldap_auth_bind %> - -# If authentication binding is used, you can save one LDAP request per login -# if users' DN can be specified with a common template. The template can use -# the standard %variables (see user_filter). Note that you can't -# use any pass_attrs if you use this setting. -# -# If you use this setting, it's a good idea to use a different -# dovecot-ldap.conf.ext for userdb (it can even be a symlink, just as long as -# the filename is different in userdb's args). That way one connection is used -# only for LDAP binds and another connection is used for user lookups. -# Otherwise the binding is changed to the default DN before each user lookup. -# -# For example: -# auth_bind_userdn = cn=%u,ou=people,o=org -# -<% if (not @ldap_auth_bind_userdn.empty?) then -%> -auth_bind_userdn = <%= @ldap_auth_bind_userdn %> -<% else -%> -#auth_bind_userdn = -<% end -%> - - - -# LDAP protocol version to use. Likely 2 or 3. -#ldap_version = 3 - -# LDAP base. %variables can be used here. -# For example: dc=mail, dc=example, dc=org -base = <%= @ldap_base %> - -# Dereference: never, searching, finding, always -deref = always - -# Search scope: base, onelevel, subtree -scope = <%= @ldap_scope %> - -# User attributes are given in LDAP-name=dovecot-internal-name list. The -# internal names are: -# uid - System UID -# gid - System GID -# home - Home directory -# mail - Mail location -# -# There are also other special fields which can be returned, see -# http://wiki2.dovecot.org/UserDatabase/ExtraFields -user_attrs = \ - =home=/srv/vmail/%d/%n,\ - =uid=vmail,\ - =gid=vmail,\ - =mail=maildir:~/mail - -# Filter for user lookup. Some variables can be used (see -# http://wiki2.dovecot.org/Variables for full list): -# %u - username -# %n - user part in user@domain, same as %u if there's no domain -# %d - domain part in user@domain, empty if user there's no domain -user_filter = <%= @ldap_user_filter %> - -# Password checking attributes: -# user: Virtual user name (user@domain), if you wish to change the -# user-given username to something else -# password: Password, may optionally start with {type}, eg. {crypt} -# There are also other special fields which can be returned, see -# http://wiki2.dovecot.org/PasswordDatabase/ExtraFields -pass_attrs = <%= @ldap_pass_attrs %> - -# If you wish to avoid two LDAP lookups (passdb + userdb), you can use -# userdb prefetch instead of userdb ldap in dovecot.conf. In that case you'll -# also have to include user_attrs in pass_attrs field prefixed with "userdb_" -# string. For example: -#pass_attrs = uid=user,userPassword=password,\ -# homeDirectory=userdb_home,uidNumber=userdb_uid,gidNumber=userdb_gid - -# Filter for password lookups -pass_filter = <%= @ldap_pass_filter %> - -# Attributes and filter to get a list of all users -iterate_attrs = <%= @ldap_iterate_attrs %> -iterate_filter = <%= @ldap_iterate_filter %> - -# Default password scheme. "{scheme}" before password overrides this. -# List of supported schemes is in: http://wiki2.dovecot.org/Authentication -#default_pass_scheme = CRYPT \ No newline at end of file +# This file is opened as root, so it should be owned by root and mode 0600. +# +# http://wiki2.dovecot.org/AuthDatabase/LDAP +# +# NOTE: If you're not using authentication binds, you'll need to give +# dovecot-auth read access to userPassword field in the LDAP server. +# With OpenLDAP this is done by modifying /etc/ldap/slapd.conf. There should +# already be something like this: + +# access to attribute=userPassword +# by dn="" read # add this +# by anonymous auth +# by self write +# by * none + +# Space separated list of LDAP hosts to use. host:port is allowed too. +<%- if @ldap_hosts -%> +hosts = <%= @ldap_hosts %> +<%- else -%> +#hosts = +<%- end -%> + +# LDAP URIs to use. You can use this instead of hosts list. Note that this +# setting isn't supported by all LDAP libraries. +<%- if @ldap_uris -%> +uris = <%= @ldap_uris %> +<%- else -%> +#uris = +<%- end -%> + +# Distinguished Name - the username used to login to the LDAP server. +# Leave it commented out to bind anonymously (useful with auth_bind=yes). +dn = <%= @ldap_dn %> + +# Password for LDAP server, if dn is specified. +dnpass = <%= @ldap_dnpass %> + +# Use SASL binding instead of the simple binding. Note that this changes +# ldap_version automatically to be 3 if it's lower. Also note that SASL binds +# and auth_bind=yes don't work together. +#sasl_bind = no +# SASL mechanism name to use. +#sasl_mech = +# SASL realm to use. +#sasl_realm = +# SASL authorization ID, ie. the dnpass is for this "master user", but the +# dn is still the logged in user. Normally you want to keep this empty. +#sasl_authz_id = + +# Use TLS to connect to the LDAP server. +<%- if @ldap_tls and @ldap_host -%> +tls = <%= @ldap_tls %> +<%- else -%> +#Deactivate tls when using uris = ldaps:// +#tls = +<%- end -%> +# TLS options, currently supported only with OpenLDAP: +<%- if @ldap_tls == 'yes' -%> + <%- if @ldap_tls_ca_cert_file %>tls_ca_cert_file = <%= @ldap_tls_ca_cert_file %><% end %> + <%- if @ldap_tls_ca_cert_dir %>tls_ca_cert_dir = <%= @ldap_tls_ca_cert_dir %><% end %> + <%- if @ldap_tls_cipher_suite %>tls_cipher_suite = <%= @ldap_tls_cipher_suite %><% end %> +# TLS cert/key is used only if LDAP server requires a client certificate. + <%- if @ldap_tls_cert_file %>tls_cert_file = <%= @ldap_tls_cert_file %><% end %> + <%- if @ldap_tls_key_file %>tls_key_file = <%= @ldap_tls_key_file %><% end %> +# Valid values: never, hard, demand, allow, try +tls_require_cert = <%= @ldap_tls_require_cert %> +<% else -%> +#tls_ca_cert_file = +#tls_ca_cert_dir = +#tls_cipher_suite = +# TLS cert/key is used only if LDAP server requires a client certificate. +#tls_cert_file = +#tls_key_file = +# Valid values: never, hard, demand, allow, try +#tls_require_cert = +<% end -%> + +# Use the given ldaprc path. +#ldaprc_path = + +# LDAP library debug level as specified by LDAP_DEBUG_* in ldap_log.h. +# -1 = everything. You may need to recompile OpenLDAP with debugging enabled +# to get enough output. +debug_level = <%= @ldap_debug_level %> + +# Use authentication binding for verifying password's validity. This works by +# logging into LDAP server using the username and password given by client. +# The pass_filter is used to find the DN for the user. Note that the pass_attrs +# is still used, only the password field is ignored in it. Before doing any +# search, the binding is switched back to the default DN. +auth_bind = <%= @ldap_auth_bind %> + +# If authentication binding is used, you can save one LDAP request per login +# if users' DN can be specified with a common template. The template can use +# the standard %variables (see user_filter). Note that you can't +# use any pass_attrs if you use this setting. +# +# If you use this setting, it's a good idea to use a different +# dovecot-ldap.conf.ext for userdb (it can even be a symlink, just as long as +# the filename is different in userdb's args). That way one connection is used +# only for LDAP binds and another connection is used for user lookups. +# Otherwise the binding is changed to the default DN before each user lookup. +# +# For example: +# auth_bind_userdn = cn=%u,ou=people,o=org +# +<% if (not @ldap_auth_bind_userdn.empty?) then -%> +auth_bind_userdn = <%= @ldap_auth_bind_userdn %> +<% else -%> +#auth_bind_userdn = +<% end -%> + + + +# LDAP protocol version to use. Likely 2 or 3. +#ldap_version = 3 + +# LDAP base. %variables can be used here. +# For example: dc=mail, dc=example, dc=org +base = <%= @ldap_base %> + +# Dereference: never, searching, finding, always +deref = always + +# Search scope: base, onelevel, subtree +scope = <%= @ldap_scope %> + +# User attributes are given in LDAP-name=dovecot-internal-name list. The +# internal names are: +# uid - System UID +# gid - System GID +# home - Home directory +# mail - Mail location +# +# There are also other special fields which can be returned, see +# http://wiki2.dovecot.org/UserDatabase/ExtraFields +<%- if @ldap_user_attrs -%> +user_attrs = <%= @ldap_user_attrs %> +<%- else -%> +#user_attrs = +<%- end -%> + +# Filter for user lookup. Some variables can be used (see +# http://wiki2.dovecot.org/Variables for full list): +# %u - username +# %n - user part in user@domain, same as %u if there's no domain +# %d - domain part in user@domain, empty if user there's no domain +<%- if @ldap_user_filter -%> +user_filter = <%= @ldap_user_filter %> +<%- else -%> +#user_filter = +<%- end -%> + +# Password checking attributes: +# user: Virtual user name (user@domain), if you wish to change the +# user-given username to something else +# password: Password, may optionally start with {type}, eg. {crypt} +# There are also other special fields which can be returned, see +# http://wiki2.dovecot.org/PasswordDatabase/ExtraFields +<%- if @ldap_pass_attrs -%> +pass_attrs = <%= @ldap_pass_attrs %> +<%- else -%> +#pass_attrs = +<%- end -%> + +# If you wish to avoid two LDAP lookups (passdb + userdb), you can use +# userdb prefetch instead of userdb ldap in dovecot.conf. In that case you'll +# also have to include user_attrs in pass_attrs field prefixed with "userdb_" +# string. For example: +#pass_attrs = uid=user,userPassword=password,\ +# homeDirectory=userdb_home,uidNumber=userdb_uid,gidNumber=userdb_gid + +# Filter for password lookups +<%- if @ldap_pass_filter -%> +pass_filter = <%= @ldap_pass_filter %> +<%- else -%> +#pass_filter = +<%- end -%> + +# Attributes and filter to get a list of all users +<%- if @ldap_iterate_attrs -%> +iterate_attrs = <%= @ldap_iterate_attrs %> +<%- else -%> +#iterate_attrs = +<%- end -%> +<%- if @ldap_iterate_filter -%> +iterate_filter = <%= @ldap_iterate_filter %> +<%- else -%> +#iterate_filter = +<%- end -%> + +# Default password scheme. "{scheme}" before password overrides this. +# List of supported schemes is in: http://wiki2.dovecot.org/Authentication +#default_pass_scheme = CRYPT