<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title><![CDATA[iRedMail — LDAP-based group ACL (SOGo, and other external services)]]></title>
		<link>https://forum.iredmail.org/topic18594-ldapbased-group-acl-sogo-and-other-external-services.html</link>
		<atom:link href="https://forum.iredmail.org/feed-rss-topic18594.xml" rel="self" type="application/rss+xml" />
		<description><![CDATA[The most recent posts in LDAP-based group ACL (SOGo, and other external services).]]></description>
		<lastBuildDate>Thu, 23 Dec 2021 12:45:28 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[Re: LDAP-based group ACL (SOGo, and other external services)]]></title>
			<link>https://forum.iredmail.org/post81654.html#p81654</link>
			<description><![CDATA[<p>There is already functionality in Pro to manage access to external services (ADDITIONAL_ENABLED_USER_SERVICES), so that is great. For me, those group memberships will not change very often, and i have a graphical interface via phpLDAPadmin. That gives me flexibility to e.g. adapt to the requirements for Group ACLs of other services (SOGo can be configured to use mailList, but maybe another service is not so flexible).</p><p>I just started to use iRedmail (we have yet to migrate), and I think the one functionality I miss are app passwords, and TOTP for the iredadmin interface. About app passwords please find my reply here: <a href="https://forum.iredmail.org/topic17646-multiple-passwords-add-app-password.html">https://forum.iredmail.org/topic17646-m … sword.html</a></p><p>not sure if this is easy to achieve that for dovecot, postfix, and SOGo? From my research, there is no mailclient which would support more than a simple password for all of the different required protocols (imap, smtp, caldav, carddav). </p><p>I thought about 2 users sharing each mailbox/calendar/address book, but this is too complicated, because in dovecot you can only share a folder, but not a whole mailbox. sorry to be off-topic.</p>]]></description>
			<author><![CDATA[null@example.com (it-3414)]]></author>
			<pubDate>Thu, 23 Dec 2021 12:45:28 +0000</pubDate>
			<guid>https://forum.iredmail.org/post81654.html#p81654</guid>
		</item>
		<item>
			<title><![CDATA[Re: LDAP-based group ACL (SOGo, and other external services)]]></title>
			<link>https://forum.iredmail.org/post81652.html#p81652</link>
			<description><![CDATA[<div class="quotebox"><cite>it-3414 wrote:</cite><blockquote><p>so if I cannot handle Group ACLs via maillists, is it safe to store the groupOfNames objects inside ou=Groups?</p></blockquote></div><p>It&#039;s ok to store it.</p><p>But maybe we can improve (or &quot;fix&quot;) iRedAdmin-Pro to achieve what you need, this way might be the best. Your opinion?</p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Thu, 23 Dec 2021 11:56:08 +0000</pubDate>
			<guid>https://forum.iredmail.org/post81652.html#p81652</guid>
		</item>
		<item>
			<title><![CDATA[Re: LDAP-based group ACL (SOGo, and other external services)]]></title>
			<link>https://forum.iredmail.org/post81645.html#p81645</link>
			<description><![CDATA[<p>so if I cannot handle Group ACLs via maillists, is it safe to store the groupOfNames objects inside ou=Groups?</p>]]></description>
			<author><![CDATA[null@example.com (it-3414)]]></author>
			<pubDate>Thu, 23 Dec 2021 11:33:43 +0000</pubDate>
			<guid>https://forum.iredmail.org/post81645.html#p81645</guid>
		</item>
		<item>
			<title><![CDATA[Re: LDAP-based group ACL (SOGo, and other external services)]]></title>
			<link>https://forum.iredmail.org/post81644.html#p81644</link>
			<description><![CDATA[<p>Hello ZhangHuan,</p><p>the problem is that the mailing list are of objectClass &quot;mailList&quot;, which is not used by SOGo. I could configure SOGo to use this objectclass instead of e.g. groupOfNames (e.g. GroupObjectClasses = (mailList);</p><p>However, the problem is that members of mailLists are not added to the OpenLDAP entry of a mailList. I also don&#039;t see this information in the user LDAP entry, so I guess this is handled/stored somewhere else?</p><p>E.g. on my (fresh 1.4.2 iRedmail), a mailing list with 2 members (just tested and working), the OpenLDAP entry for this mailList is this:</p><p># Entry 1: mail=group-ml-3@MYDOMAIN.net,ou=Groups,domainNa...<br />dn: mail=group-ml-3@MYDOMAIN.net,ou=Groups,domainName=MYDOMAIN.net,o=domains,dc=MYDOMAIN,dc=net<br />accesspolicy: public<br />accountstatus: active<br />cn: maillist4<br />enabledservice: mail<br />enabledservice: deliver<br />enabledservice: mlmmj<br />mail: group-ml-3@MYDOMAIN.net<br />mailinglistid: 78911955-XXX-ID<br />member: mail=it5@MYDOMAIN.net,ou=Users,domainName=MYDOMAIN.net,o=domains,dc=MYDOMAIN,dc=net<br />mtatransport: mlmmj:MYDOMAIN.net/group-ml-3<br />objectclass: mailList</p><p>so there is only one member (I guess the first one when creating the maillist?)</p><p>At the user side, I also don&#039;t see any attribute for memberOf:</p><p># Entry 1: mail=i...@mydomain.net,ou=Users,domainName=MYDOMAIN<br />dn: mail=i...@mydomain.net,ou=Users,domainName=MYDOMAIN.net,o=domains,dc=MYDOMAIN,dc=net<br />accountstatus: active<br />amavislocal: TRUE<br />cn: IT6<br />enabledservice: sogo<br />enabledservice: imap<br />enabledservice: sievetls<br />enabledservice: sievesecured<br />enabledservice: lmtp<br />enabledservice: dsync<br />enabledservice: shadowaddress<br />enabledservice: indexer-worker<br />enabledservice: sieve<br />enabledservice: imaptls<br />enabledservice: senderbcc<br />enabledservice: managesievesecured<br />enabledservice: deliver<br />enabledservice: recipientbcc<br />enabledservice: mail<br />enabledservice: smtpsecured<br />enabledservice: lib-storage<br />enabledservice: sogoactivesync<br />enabledservice: smtp<br />enabledservice: sogowebmail<br />enabledservice: smtptls<br />enabledservice: lda<br />enabledservice: displayedInGlobalAddressBook<br />enabledservice: imapsecured<br />enabledservice: doveadm<br />enabledservice: forward<br />enabledservice: quota-status<br />enabledservice: sogocalendar<br />enabledservice: managesievetls<br />enabledservice: internal<br />enabledservice: managesieve<br />homedirectory: /var/vmail/vmail1/MYDOMAIN.net/i/t/6/it6-2021.<br /> 12.08.15.26.38/<br />mail: i...@mydomain.net<br />mailboxfolder: Maildir<br />mailboxformat: maildir<br />mailquota: 5368709120<br />objectclass: inetOrgPerson<br />objectclass: mailUser<br />objectclass: shadowAccount<br />objectclass: amavisAccount<br />preferredlanguage: en_US<br />shadowlastchange: 18969<br />sn: it6<br />uid: it6<br />userpassword: {SSHA512}XXXXX</p><br /><p>I have iRedadmin Pro, so I add new maillist members via this interface. But yet they don&#039;t show up in OpenLDAP, but the maillist still works.</p>]]></description>
			<author><![CDATA[null@example.com (it-3414)]]></author>
			<pubDate>Thu, 23 Dec 2021 11:30:08 +0000</pubDate>
			<guid>https://forum.iredmail.org/post81644.html#p81644</guid>
		</item>
		<item>
			<title><![CDATA[Re: LDAP-based group ACL (SOGo, and other external services)]]></title>
			<link>https://forum.iredmail.org/post81632.html#p81632</link>
			<description><![CDATA[<div class="quotebox"><cite>it-3414 wrote:</cite><blockquote><p>1) another SOGoUserSource to get the groups (to not interfere with the user-authentication)</p></blockquote></div><p>It&#039;s ok to add new config section in SOGoUseSource.<br /></p><div class="quotebox"><cite>it-3414 wrote:</cite><blockquote><p>2) a openldap resource for group membership (I used phpldapadmin to create it):<br /># Entry 1: cn=grpnames4@MYDOMAIN.net,ou=Groups,domainName=...<br />dn: cn=grpnames4@MYDOMAIN.net,ou=Groups,domainName=MYDOMAIN.net,o=domains,dc=MYDOMAINonal,dc=net<br />cn: <br />member: mail=it7@MYDOMAIN.net,...<br />member: mail=it5@MYDOMAIN.net,...<br />objectclass: groupOfNames<br />objectclass: top</p></blockquote></div><p>iRedAdmin-Pro already manages the &quot;member&quot; attribute for mailing lists, so i guess you don&#039;t need new entries under &quot;ou=Groups&quot;. Did you check existing group objects?</p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Thu, 23 Dec 2021 10:57:54 +0000</pubDate>
			<guid>https://forum.iredmail.org/post81632.html#p81632</guid>
		</item>
		<item>
			<title><![CDATA[LDAP-based group ACL (SOGo, and other external services)]]></title>
			<link>https://forum.iredmail.org/post81523.html#p81523</link>
			<description><![CDATA[<p>==== REQUIRED BASIC INFO OF YOUR IREDMAIL SERVER ====<br />- iRedMail version (check /etc/iredmail-release): 1.4.2<br />- Deployed with iRedMail Easy or the downloadable installer? downloadable<br />- Linux/BSD distribution name and version: ubuntu 20.04<br />- Store mail accounts in which backend (LDAP/MySQL/PGSQL):&nbsp; LDAP<br />- Web server (Apache or Nginx):nginx<br />- Manage mail accounts with iRedAdmin-Pro? yes<br />- [IMPORTANT] Related original log or error message is required if you&#039;re experiencing an issue.<br />====</p><p>I&#039;m not sure if that has been posted already (I only found <a href="https://forum.iredmail.org/post11173.html#p11173">https://forum.iredmail.org/post11173.html#p11173</a> and <a href="https://forum.iredmail.org/topic3059-iredadminpro-and-sogo-mail-listsgroups.html)">https://forum.iredmail.org/topic3059-ir … oups.html)</a> so in case not, this is how I got LDAP-group based ACL for SOGo resources (e.g calendar) to work. Together with the authentication of external services (<a href="https://docs.iredmail.org/iredadmin-pro.custom.user.services.html">https://docs.iredmail.org/iredadmin-pro … vices.html</a>) I think OpenLDAP based iRedmail is a great authentication service for other apps which usually use group ACLs (e.g. we use Nextcloud and rely heavily on AD groups). I hope I haven&#039;t overseen anything, as I&#039;m quite new to iRedmail, and openLDAP. </p><p>Therefore, **I would also like to know if this approach is safe?** E.g. the ldap resource will not disappear/cause problems with iRedmail updates, etc?&nbsp; Maybe it is better to not use ou=Groups (where iRedmail stores mailLists), but a separate ou (e.g. ou=customgroups) to store the group ACLs? </p><p>There are 2 things needed:<br />1) another SOGoUserSource to get the groups (to not interfere with the user-authentication)<br />{<br />&nbsp; &nbsp; // Used for groups<br />&nbsp; &nbsp; type = ldap;<br />&nbsp; &nbsp; id = groups;<br />&nbsp; &nbsp; canAuthenticate = YES;<br />&nbsp; &nbsp; isAddressBook = NO;<br />&nbsp; &nbsp; displayName = &quot;LDAP Groups&quot;;</p><p>&nbsp; &nbsp; hostname = &quot;ldap://127.0.0.1:389&quot;;<br />&nbsp; &nbsp; baseDN = &quot;domainName=%d,o=domains,dc=MYDOMAIN,dc=net&quot;;<br />&nbsp; &nbsp; bindDN = &quot;cn=vmail,dc=MYDOMAIN,dc=net&quot;;<br />&nbsp; &nbsp; bindPassword = &quot;XXXXX&quot;;<br />&nbsp; &nbsp; filter = &quot;objectClass=groupOfNames&quot;; #&lt;&lt;-- NEW filter</p><p>&nbsp; &nbsp; bindAsCurrentUser = YES;</p><br /><p>&nbsp; &nbsp; // The algorithm used for password encryption when changing<br />&nbsp; &nbsp; // passwords without Password Policies enabled.<br />&nbsp; &nbsp; // Possible values are: plain, crypt, md5-crypt, ssha, ssha512.<br />&nbsp; &nbsp; userPasswordAlgorithm = ssha512;<br />&nbsp; &nbsp; GroupObjectClasses = (groupOfNames); #&lt;&lt;--- NEW (maybe not needed?)</p><p>&nbsp; &nbsp; CNFieldName = cn;<br />&nbsp; &nbsp; IDFieldName = cn;<br />&nbsp; &nbsp; // value of UIDFieldName must be unique on entire server<br />&nbsp; &nbsp; UIDFieldName = cn;<br />}</p><p>2) a openldap resource for group membership (I used phpldapadmin to create it):</p><p># Entry 1: cn=grpnames4@MYDOMAIN.net,ou=Groups,domainName=...<br />dn: cn=grpnames4@MYDOMAIN.net,ou=Groups,domainName=MYDOMAIN.net,o=domains,dc=MYDOMAINonal,dc=net<br />cn: grpnames4@MYDOMAIN.net<br />member: mail=it7@MYDOMAIN.net,ou=Users,domainName=MYDOMAIN.net,o=domains,dc=MYDOMAIN,dc=net<br />member: mail=it5@MYDOMAIN.net,ou=Users,domainName=MYDOMAIN.net,o=domains,dc=MYDOMAIN,dc=net<br />objectclass: groupOfNames<br />objectclass: top</p><br /><p>After restart of SOGo, you should be able to search for the group-name when sharing resources, and upon adding ACLs and subscribing, the group members should see the resources. </p><p>If you add another group member in openLDAP later on, you need to additionally subscribe the user (but that was the same when using AD groups, and can be done via the sogo-tool). If you remove a user, it will take a couple of minutes until the resource disappears for this user.</p><p>Regarding SOGo, and SuperUsers: does it matter which user I add in &quot;SOGoSuperUsernames&quot; ? Should it be the postmaster, or can it be any other user?</p>]]></description>
			<author><![CDATA[null@example.com (it-3414)]]></author>
			<pubDate>Fri, 10 Dec 2021 16:28:46 +0000</pubDate>
			<guid>https://forum.iredmail.org/post81523.html#p81523</guid>
		</item>
	</channel>
</rss>
