D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] imap servers and selective access

 

Robin Cornelius wrote:
> 
> I currently have dovecot setup for pop3 and imap, i would like to
> restrict user access to the imap server based on username and ip
> address, eg i only want user joe to access the imap server from a
> connection out side my LAN. Is this possible?

All things are possible...

The dovecot mailing list suggests that "rhost" is set for PAM, so if you
are using PAM authentication and your rules are relatively straight
forward, that might be a way to go (i.e. pam_rhost say).

Although do make sure if you use the existing modules it is in addition
to passwords, and not instead, if you use basic rhost files.

I'd say be more specific on the requirements, and ask on the dovecot
list -- someone will probably have a better answer than "pam rhosts".

> I only want to allow ssl imap connections from limited users all other
> users are local access only, currently any user can ssl imap in and
> this is definatly not wanted.

Any particular reason, do you users suddenly get less trustworthy as
they walk out the door in the evening? Only thing we do is block
password guessing IP addresses using fail2ban, but then ours are all
virtual users....

-- 
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/linux_adm/list-faq.html