<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title><![CDATA[iRedMail — integration with Windows Domain]]></title>
		<link>http://www.iredmail.org/forum/topic3165-integration-with-windows-domain.html</link>
		<atom:link href="http://www.iredmail.org/forum/feed-rss-topic3165.xml" rel="self" type="application/rss+xml" />
		<description><![CDATA[The most recent posts in integration with Windows Domain.]]></description>
		<lastBuildDate>Mon, 18 Mar 2013 13:30:59 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[Re: integration with Windows Domain]]></title>
			<link>http://www.iredmail.org/forum/post20909.html#p20909</link>
			<description><![CDATA[<p>Hi Frankstar,<br />If you use AD, please use it&#039;s default &quot;group&quot; as mail list.</p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Mon, 18 Mar 2013 13:30:59 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post20909.html#p20909</guid>
		</item>
		<item>
			<title><![CDATA[Re: integration with Windows Domain]]></title>
			<link>http://www.iredmail.org/forum/post20904.html#p20904</link>
			<description><![CDATA[<p>i tought, that doesnt work if i use full Microsoft AD integration ?</p>]]></description>
			<author><![CDATA[null@example.com (Frankstar)]]></author>
			<pubDate>Mon, 18 Mar 2013 13:21:43 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post20904.html#p20904</guid>
		</item>
		<item>
			<title><![CDATA[Re: integration with Windows Domain]]></title>
			<link>http://www.iredmail.org/forum/post20903.html#p20903</link>
			<description><![CDATA[<div class="quotebox"><cite>Frankstar wrote:</cite><blockquote><p>how did u guys add alias adresses ?</p></blockquote></div><p>You can add alias addresses manually, or with iRedAdmin-Pro (<a href="http://www.iredmail.org/admin_panel.html">http://www.iredmail.org/admin_panel.html</a>).</p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Mon, 18 Mar 2013 13:19:53 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post20903.html#p20903</guid>
		</item>
		<item>
			<title><![CDATA[Re: integration with Windows Domain]]></title>
			<link>http://www.iredmail.org/forum/post20902.html#p20902</link>
			<description><![CDATA[<p>other question,</p><p>how did u guys add alias adresses ?</p>]]></description>
			<author><![CDATA[null@example.com (Frankstar)]]></author>
			<pubDate>Mon, 18 Mar 2013 13:18:43 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post20902.html#p20902</guid>
		</item>
		<item>
			<title><![CDATA[Re: integration with Windows Domain]]></title>
			<link>http://www.iredmail.org/forum/post20357.html#p20357</link>
			<description><![CDATA[<p>Here&#039;s my configs. It does work, in either this format or with %s.&nbsp; This allows me to choose any domain name which is not to desirable but at least it works.&nbsp; I fail to understand what I should put in the &#039;domains&#039; OU in active directory.&nbsp; Do I put in specific OU&#039;s?&nbsp; Do i place the users in the OU&#039;s? (ie. ou=Domains\ou=domain.ca\%users%).&nbsp; Your help is appreciated and thanks!</p><p>Dovecot<br /></p><div class="codebox"><pre><code>hosts           = ad.domain.lan:389
ldap_version    = 3
auth_bind       = yes
dn              = vmail
dnpass          = Password
base            = ou=DomainUsers,dc=domain,dc=lan
scope           = subtree
deref           = never
user_filter     = (&amp;(userPrincipalName=%n@domain.lan)(objectClass=person)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))
pass_filter     = (&amp;(userPrincipalName=%n@domain.lan)(objectClass=person)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))
pass_attrs      = userPassword=password
default_pass_scheme = CRYPT
user_attrs      = =home=/var/vmail/vmail1/%Ld/%Ln/Maildir/,=mail=maildir:/var/vmail/vmail1/%Ld/%Ln/Maildir/ </code></pre></div><p>Postfix<br /></p><div class="codebox"><pre><code>server_host     = ad.domain.lan
server_port     = 389
version         = 3
bind            = yes
start_tls       = no
bind_dn         = vmail
bind_pw         = Password
search_base     = ou=DomainUsers,dc=domain,dc=lan
scope           = sub
query_filter    = (&amp;(userPrincipalName=%u@domain.lan)(objectClass=person)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))
result_attribute= userPrincipalName
debuglevel      = 0</code></pre></div>]]></description>
			<author><![CDATA[null@example.com (opiateESP)]]></author>
			<pubDate>Fri, 15 Feb 2013 21:22:27 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post20357.html#p20357</guid>
		</item>
		<item>
			<title><![CDATA[Re: integration with Windows Domain]]></title>
			<link>http://www.iredmail.org/forum/post20325.html#p20325</link>
			<description><![CDATA[<p>Can you post your confs files...?</p><p>With the method I&#039;ve mentionned before, it cannot login using a domain wich isn&#039;t in the specified OU... Therefore, I can&#039;t help you if you don&#039;t use this trick, because I only know this one.</p>]]></description>
			<author><![CDATA[null@example.com (nicolasfo)]]></author>
			<pubDate>Thu, 14 Feb 2013 08:29:44 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post20325.html#p20325</guid>
		</item>
		<item>
			<title><![CDATA[Re: integration with Windows Domain]]></title>
			<link>http://www.iredmail.org/forum/post20316.html#p20316</link>
			<description><![CDATA[<p>Ok, so I have it accepting logins now but the problem is it will accept ANY login so long as the username is from AD.&nbsp; I have entered the OpenLDAP query&#039;s as:</p><p><strong>%u@domain.lan</strong> for postfix and <strong>%n@domain.lan</strong> for dovecot.&nbsp; This allows <strong>user@ANYNAME.COM</strong> to login successfully.&nbsp; I guess this is a semi-victory as I can now use my desired domain.&nbsp; Now I just need to restrict this to only allow the domain that I wish to use.</p><p>Any thoughts?</p>]]></description>
			<author><![CDATA[null@example.com (opiateESP)]]></author>
			<pubDate>Wed, 13 Feb 2013 18:20:38 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post20316.html#p20316</guid>
		</item>
		<item>
			<title><![CDATA[Re: integration with Windows Domain]]></title>
			<link>http://www.iredmail.org/forum/post20307.html#p20307</link>
			<description><![CDATA[<p>What is you /var/log/mail.log ?</p><p>What isn&#039;t working as expected ? Did you try tests commands as mentionned in the howto ?</p>]]></description>
			<author><![CDATA[null@example.com (nicolasfo)]]></author>
			<pubDate>Wed, 13 Feb 2013 15:35:18 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post20307.html#p20307</guid>
		</item>
		<item>
			<title><![CDATA[Re: integration with Windows Domain]]></title>
			<link>http://www.iredmail.org/forum/post20297.html#p20297</link>
			<description><![CDATA[<p>That didn&#039;t work for me. I know I must be missing something.</p>]]></description>
			<author><![CDATA[null@example.com (opiateESP)]]></author>
			<pubDate>Tue, 12 Feb 2013 18:57:37 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post20297.html#p20297</guid>
		</item>
		<item>
			<title><![CDATA[Re: integration with Windows Domain]]></title>
			<link>http://www.iredmail.org/forum/post20252.html#p20252</link>
			<description><![CDATA[<p>Hello,</p><p>In my case, my AD domain is called &quot;domain.lan&quot; and my externals domains are called &quot;domain2.fr&quot;, &quot;domain3.com&quot;, &quot;domain4.biz&quot;</p><p>So, I&#039;ve made an OU called &quot;domains&quot; at the root of my AD tree (under &quot;domain.lan&quot;) and I&#039;ve made others OU under &quot;domains&quot;, one for each domains I&#039;m supposed to manage.</p><p>After this, in Dovecot :</p><p>/etc/dovecot/dovecot-ldap.conf :<br /></p><div class="codebox"><pre><code>hosts           = dc.domain.lan:389
ldap_version    = 3
auth_bind       = yes
dn              = vmail@domain.lan
dnpass          = password_of_vmail
base            = ou=domains,dc=domain,dc=lan
scope           = subtree
deref           = never
user_filter     = (&amp;(userPrincipalName=%u)(objectClass=person)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))
pass_filter     = (&amp;(userPrincipalName=%u)(objectClass=person)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))
pass_attrs      = userPassword=password
default_pass_scheme = CRYPT
user_attrs      = =home=/path_to_your_storage/%Ld/%Ln/Maildir/,=mail=maildir:/path_to_your_storage/mail/%Ld/%Ln/Maildir/</code></pre></div><p>With this config, users must authenticate with, as username, the full email address.</p><p>Use the same config in Postfix, but beware to add the line &quot;result_attribute= userPrincipalName&quot; in each 3 files *_maps.cf&quot; (I&#039;ve modified only those files), beacause you&#039;ll had duplicates results with the tests commands mentionned in the howto.</p><p>Had I answered to your problem ?</p><p>Nicolas</p>]]></description>
			<author><![CDATA[null@example.com (nicolasfo)]]></author>
			<pubDate>Fri, 08 Feb 2013 10:44:55 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post20252.html#p20252</guid>
		</item>
		<item>
			<title><![CDATA[Re: integration with Windows Domain]]></title>
			<link>http://www.iredmail.org/forum/post20239.html#p20239</link>
			<description><![CDATA[<p>Hey all,</p><p>I have been trying to implement this with no luck at all... the only login that is working is my AD FQD ending in &quot;.lan&quot;</p><p>Here&#039;s how I&#039;ve adjusted the config for a separate domain.&nbsp; I&#039;ve repeated this in the 3 ad_*.cf</p><p>query_filter&nbsp; &nbsp; = (&amp;(userPrincipalName=<strong>%u@domain.ca</strong>)(objectClass=person)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))</p><p>This is the Dovecot config</p><p>user_filter&nbsp; &nbsp; &nbsp;= (&amp;(userPrincipalName=<strong>%n@domain.ca</strong>)(objectClass=person)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))<br />pass_filter&nbsp; &nbsp; &nbsp;= (&amp;(userPrincipalName=<strong>%n@domain.ca</strong>)(objectClass=person)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))</p>]]></description>
			<author><![CDATA[null@example.com (opiateESP)]]></author>
			<pubDate>Thu, 07 Feb 2013 17:50:45 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post20239.html#p20239</guid>
		</item>
		<item>
			<title><![CDATA[Re: integration with Windows Domain]]></title>
			<link>http://www.iredmail.org/forum/post14767.html#p14767</link>
			<description><![CDATA[<p>Hello all,</p><p>I&#039;m in the same case.</p><p>I want to totally finish the &quot;local integration&quot; (tests, tests, and tests) to spent time on this &quot;problem&quot;.</p><p>It seems, as usual, ZhangHuangbin had the solution, or can help us : you&#039;re the best <img src="http://www.iredmail.org/forum/img/smilies/smile.png" width="15" height="15" alt="smile" /></p><p>I&#039;m gonna follow this thread and bring my bricks to the wall, if I can help.</p><p>Thanks guys <img src="http://www.iredmail.org/forum/img/smilies/smile.png" width="15" height="15" alt="smile" /></p>]]></description>
			<author><![CDATA[null@example.com (nicolasfo)]]></author>
			<pubDate>Wed, 28 Mar 2012 08:57:28 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post14767.html#p14767</guid>
		</item>
		<item>
			<title><![CDATA[Re: integration with Windows Domain]]></title>
			<link>http://www.iredmail.org/forum/post14734.html#p14734</link>
			<description><![CDATA[<div class="quotebox"><cite>aaddiikk wrote:</cite><blockquote><p>What should I change or take into consideration, if my windows domain is: mydomain.local and the mail domain is: myotherdomain.com?</p></blockquote></div><p>You have to modify LDAP query files of Postfix (/etc/postfix/ad_*.cf) and Dovecot (/etc/dovecot-ldap.conf).<br />For example, in Postfix LDAP query file:<br />- &#039;%s&#039; will be substituted by full email address<br />- &#039;%u&#039; is local&nbsp; part of the email address<br />- &#039;%d&#039; is domain part of the email address</p><p>So, to use (and hard-code) a different mail domain name, please replace &#039;%s&#039; in Postfix LDAP query files by &#039;%u@myotherdomain.com&#039;.</p><p>Reference:<br />- Postfix manual page, ldap_table(5): <a href="http://www.postfix.org/ldap_table.5.html">http://www.postfix.org/ldap_table.5.html</a><br />- Dovecot Variables: <a href="http://wiki.dovecot.org/Variables">http://wiki.dovecot.org/Variables</a> (It&#039;s %u, %n (the same as %u in Postfix), %d).</p><div class="quotebox"><cite>aaddiikk wrote:</cite><blockquote><p>What if I have two mail domains and all users should be able to recieve emails from both domains?</p></blockquote></div><p>I didn&#039;t test it before, you can give it a try. But i think you have to use &#039;%s&#039; in Postfix to query full email address instead of &#039;%u@myotherdomain.com&#039; to avoid hard-coded domain name.</p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Tue, 27 Mar 2012 04:06:50 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post14734.html#p14734</guid>
		</item>
		<item>
			<title><![CDATA[integration with Windows Domain]]></title>
			<link>http://www.iredmail.org/forum/post14732.html#p14732</link>
			<description><![CDATA[<p>Hi there,</p><p>First of all. This is my first post here! Welcome you guys! Ive been using iredmail for the last 2 years and Im still impressed how easy and smooth it is. I dont know how I was able to set up mail server before without it!</p><p>The question: For the first time, I would like to integrate iredmail with Windows Active Directory. It will be used to authenticate mail users against windows domain. Ive red the document regarding the integration located here: <a href="http://www.iredmail.org/wiki/index.php?title=Integration/Active.Directory.iRedMail">http://www.iredmail.org/wiki/index.php? … y.iRedMail</a> but I still dont get one thing. The document assumes that the windows domain and mail domain is the same (example.com). What should I change or take into consideration, if my windows domain is: mydomain.local and the mail domain is: myotherdomain.com? What if I have two mail domains and all users should be able to recieve emails from both domains?</p><p>regards,<br />Adrian</p>]]></description>
			<author><![CDATA[null@example.com (aaddiikk)]]></author>
			<pubDate>Mon, 26 Mar 2012 19:24:42 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post14732.html#p14732</guid>
		</item>
	</channel>
</rss>
