Skip to content

Commit

Permalink
Use permission for all services
Browse files Browse the repository at this point in the history
  • Loading branch information
Josue-T committed Nov 25, 2018
1 parent f8f0482 commit 6514b2c
Show file tree
Hide file tree
Showing 5 changed files with 9 additions and 7 deletions.
4 changes: 2 additions & 2 deletions data/templates/dovecot/dovecot-ldap.conf
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ auth_bind = yes
ldap_version = 3
base = ou=users,dc=yunohost,dc=org
user_attrs = uidNumber=500,gidNumber=8,mailuserquota=quota_rule=*:bytes=%$
user_filter = (&(objectClass=inetOrgPerson)(uid=%n))
pass_filter = (&(objectClass=inetOrgPerson)(uid=%n))
user_filter = (&(objectClass=inetOrgPerson)(uid=%n)(permission=cn=main.mail,ou=permission,dc=yunohost,dc=org))
pass_filter = (&(objectClass=inetOrgPerson)(uid=%n)(permission=cn=main.mail,ou=permission,dc=yunohost,dc=org))
default_pass_scheme = SSHA

2 changes: 1 addition & 1 deletion data/templates/metronome/domain.tpl.cfg.lua
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ VirtualHost "{{ domain }}"
hostname = "localhost",
user = {
basedn = "ou=users,dc=yunohost,dc=org",
filter = "(&(objectClass=posixAccount)(mail=*@{{ domain }}))",
filter = "(&(objectClass=posixAccount)(mail=*@{{ domain }})(permission=cn=main.metronome,ou=permission,dc=yunohost,dc=org))",
usernamefield = "mail",
namefield = "cn",
},
Expand Down
2 changes: 1 addition & 1 deletion data/templates/postfix/plain/ldap-accounts.cf
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
server_host = localhost
server_port = 389
search_base = dc=yunohost,dc=org
query_filter = (&(objectClass=mailAccount)(mail=%s))
query_filter = (&(objectClass=mailAccount)(mail=%s)(permission=cn=main.mail,ou=permission,dc=yunohost,dc=org))
result_attribute = uid
2 changes: 1 addition & 1 deletion data/templates/postfix/plain/ldap-aliases.cf
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
server_host = localhost
server_port = 389
search_base = dc=yunohost,dc=org
query_filter = (&(objectClass=mailAccount)(mail=%s))
query_filter = (&(objectClass=mailAccount)(mail=%s)(permission=cn=main.mail,ou=permission,dc=yunohost,dc=org))
result_attribute = maildrop
6 changes: 4 additions & 2 deletions data/templates/ssh/sshd_config
Original file line number Diff line number Diff line change
Expand Up @@ -88,9 +88,11 @@ Subsystem sftp internal-sftp
# and ChallengeResponseAuthentication to 'no'.
UsePAM yes

Match User sftpusers
AllowGroups main.sftp admins root

Match Group main.sftp
ForceCommand internal-sftp
ChrootDirectory /home/%u
ChrootDirectory /home
AllowTcpForwarding no
GatewayPorts no
X11Forwarding no

0 comments on commit 6514b2c

Please sign in to comment.