Hi,

I have Dovecot on a FreeIPA client configured to authenticate users with 
PAM/SSSD
(like this: 
https://wiki.archlinux.org/title/Dovecot#PAM_Authentication_with_SSSD).
Everything works fine, but now I would like to have password+OTP for everything 
except mail. There, the password should suffice.

If the user has password and password+OTP selected as possible authentication 
types, then the second factor is optional
when logging in directly (there's the "Second factor (optional)" prompt) or 
through SSH via Kerberos, but this doesn't help with Dovecot.
Is there some way to explicitly turn off the second factor for this host?

Thanks for any pointers!

Ryan
-- 
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to