Re: possible doveadm expunge bug

2023-09-23 Thread Noel Butler via dovecot
On 18/09/2023 16:17, Aki Tuomi via dovecot wrote: Aki, any ideas? Or have I have hit a ridiculously low 1000D hard coded limit? ...and I know some troll will comment, so let me say yes I know I can and will likely have to use nix's "find" to actually cull them, but if doveadm has an expunge op

Dovecot OIDC question

2023-09-23 Thread dovecot--- via dovecot
Exploring the possible use of SSO using OIDC with Dovecot. Trying to understand the functionality of OIDC as it pertains to e-mail clients like Thunderbird, Outlook etc... My OIDC provider will authenticate a user by intercepting the connection attempt to the resource, present a login screen an

Re: 2.3.21 broke XOAUTH authentication against Keycloak

2023-09-23 Thread Aki Tuomi via dovecot
> On 23/09/2023 12:55 EEST t...@interseclab.org wrote: > > > I have Roundcube and Dovecot2 setup to authenticate against Keycloak > using the XOAUTH2 method, as follows: > > introspection_url = > https://[...]/realms/[...]/protocol/openid-connect/token/introspect > introspection_mode = post

2.3.21 broke XOAUTH authentication against Keycloak

2023-09-23 Thread tj
I have Roundcube and Dovecot2 setup to authenticate against Keycloak using the XOAUTH2 method, as follows: introspection_url = https://[...]/realms/[...]/protocol/openid-connect/token/introspect introspection_mode = post username_attribute = email client_id = [...] client_secret = [...] tls_ca

is dovecot 2.3.20 compatible with YESCRYPT?

2023-09-23 Thread Andrew Hoff via dovecot
To Whom It May Concern, Fedora 38 uses YESCRYPT by default to create the passwords stored in "shadow". The prefix is "$y$".  Ref:  https://doc.dovecot.org/configuration_manual/authentication/password_schemes/#authentication-password-schemes The nearest supported password scheme is blowfish.  Ca

Re: dovecot username with domain

2023-09-23 Thread Tom Hendrikx via dovecot
On 19-09-2023 22:36, Dave McGuire wrote: On 9/19/23 16:34, Michael Grant wrote: Thanks, I was hoping for something less complicated.  I found    auth_username_format %n which drops the domain if supplied.  Unfortunately my imap username isn't 'mgrant'.  Probably i could make this work if there

Re: How to use http api doveadm to manage acl permissions

2023-09-23 Thread cyril . leclerc
Yes off course i ve done that but not found, moreover it should be available in the api documentation ? this is the content off the get call is there a command for acl with maybe not ACL word inside ? [ { "command": "mailboxMutf7", "parameters": [ {