summaryrefslogtreecommitdiffstats
path: root/doc/wiki/PasswordDatabase.Shadow.txt
blob: f103260b7dc6b4158a3d6842570aa308cef5ddcf (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
Shadow
======

Works at least with Linux and Solaris, but nowadays <PAM>
[PasswordDatabase.PAM.txt] is usually preferred to this.

This uses auth-worker processes:

---%<-------------------------------------------------------------------------
passdb {
  driver = shadow
}
---%<-------------------------------------------------------------------------

By default the auth-worker processes are run as "dovecot" user though, which
normally doesn't have access to '/etc/shadow'. If this is a problem, you can
fix it with:

---%<-------------------------------------------------------------------------
service auth-worker {
  # This should be enough:
  group = shadow
  # If not, just give full root permissions:
  #user = root
}
---%<-------------------------------------------------------------------------

If there are only a few users and you're using '/etc/shadow' file, there's
really no need to use auth-workers. You can disable them with:

---%<-------------------------------------------------------------------------
passdb {
  driver = shadow
  args = blocking=no
}
---%<-------------------------------------------------------------------------

(This file was created from the wiki on 2019-06-19 12:42)