Hi, I have Dovecot on a FreeIPA client configured to authenticate users with PAM/SSSD (like this: https://wiki.archlinux.org/title/Dovecot#PAM_Authentication_with_SSSD). Everything works fine, but now I would like to have password+OTP for everything except mail. There, the password should suffice.
If the user has password and password+OTP selected as possible authentication types, then the second factor is optional when logging in directly (there's the "Second factor (optional)" prompt) or through SSH via Kerberos, but this doesn't help with Dovecot. Is there some way to explicitly turn off the second factor for this host? Thanks for any pointers! Ryan -- _______________________________________________ FreeIPA-users mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/[email protected] Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
