summaryrefslogtreecommitdiffstats
path: root/doc/wiki/Plugins.VarExpandCrypt.txt
diff options
context:
space:
mode:
authorDaniel Baumann <daniel.baumann@progress-linux.org>2024-04-28 09:51:24 +0000
committerDaniel Baumann <daniel.baumann@progress-linux.org>2024-04-28 09:51:24 +0000
commitf7548d6d28c313cf80e6f3ef89aed16a19815df1 (patch)
treea3f6f2a3f247293bee59ecd28e8cd8ceb6ca064a /doc/wiki/Plugins.VarExpandCrypt.txt
parentInitial commit. (diff)
downloaddovecot-upstream.tar.xz
dovecot-upstream.zip
Adding upstream version 1:2.3.19.1+dfsg1.upstream/1%2.3.19.1+dfsg1upstream
Signed-off-by: Daniel Baumann <daniel.baumann@progress-linux.org>
Diffstat (limited to 'doc/wiki/Plugins.VarExpandCrypt.txt')
-rw-r--r--doc/wiki/Plugins.VarExpandCrypt.txt45
1 files changed, 45 insertions, 0 deletions
diff --git a/doc/wiki/Plugins.VarExpandCrypt.txt b/doc/wiki/Plugins.VarExpandCrypt.txt
new file mode 100644
index 0000000..4bf43d9
--- /dev/null
+++ b/doc/wiki/Plugins.VarExpandCrypt.txt
@@ -0,0 +1,45 @@
+var_expand_crypt plugin
+=======================
+
+This plugins provides generic encrypt/decrypt facility for var_expand. It
+requires functional lib-dcrypt backend. For dovecot-auth process this plugin is
+automatically usable.
+
+Syntax
+------
+
+---%<-------------------------------------------------------------------------
+args=encrypted_value=%{encrypt;key=value,iv=value,noiv=yes,algo=algorithm,format=base64|hex:field}
+args=decrypted_value=%{decrypt;key=value,iv=value,noiv=yes,algo=algorithm,format=base64|hex:field}
+---%<-------------------------------------------------------------------------
+
+ * key - hex-encoded value
+ * iv - hex-encoded value
+ * noiv - whether iv is included in return value
+ * algo - algorithm name (defaults to aes-256-cbc)
+ * format - return format
+
+decrypt expects input in base64 or hex format.
+
+NOTE: It is usually best to leave iv management to dovecot, and not use iv and
+noiv options at all.
+
+Return formats
+--------------
+
+Without noiv encrypt returns iv$encrypted$. With noiv, just encrypted data is
+returned. Field(s) are encoded using format.
+
+key and iv must be the length required by the given algorithm.
+
+Example
+-------
+
+---%<-------------------------------------------------------------------------
+%{encrypt;key=f1f2f3f4f5f6f7f8f1f2f3f4f5f6f7f8f1f2f3f4f5f6f7f8f1f2f3f4f5f6f7f8:password}
+= 93736a0f910df27f89210e096e1d639a$966c2b4f3e7487f6acdb836f8d1dc3e0$
+%{decrypt;key=f1f2f3f4f5f6f7f8f1f2f3f4f5f6f7f8f1f2f3f4f5f6f7f8f1f2f3f4f5f6f7f8:encrypted}
+= pass
+---%<-------------------------------------------------------------------------
+
+(This file was created from the wiki on 2019-06-19 12:42)