[imp] Re: AD group restrictions give "Too many login failures"

Tom Lisjac netdxr at gmail.com
Mon Mar 14 15:44:46 PST 2005


On Mon, 14 Mar 2005 11:41:15 +0100, Jan Schneider <jan at horde.org> wrote:
> Zitat von Tom Lisjac <netdxr at gmail.com>:
> 
> > I'm using the FRAMEWORK_3 cvs version of imp from last week with
> > cyrus-imap and saslauthd->pam->winbind/Active Directory for
> > authentication .  Everything was working fine... any domain user could
> > log in and I could administer the imap mailboxes with
> > Administration->Users.
> >
> > A final production step was to restrict domain logins to members of
> > the AD group "webmail"... so I added the following line to the imap
> > service in /etc/pam.d:
> >
> > account required /lib/security/$ISA/pam_succeed_if.so user ingroup webmail
> >
> > This worked and restricted the logins... but now Administration->Users
> > throws the following error:
> >
> > A fatal error has occurred
> > Too many login failures
> > [line 236 of /var/www/html/webmail/admin/user.php]
> 
> Did you add the user that you configured in config/servers.php in the admin
> section to the webmail group?

That fixed it! Thanks very much, Jan!

Our prototype system is now functionally complete and, after three
weeks of testing, appears to be working perfectly. We were planning to
release it for the next school year... but everyone that sees a demo
wants to start using it NOW! Our administrators are amazed that
feature rich and easy to use software of this quality is free and open
source. Congratulations and thanks to everyone who had a part in
creating this outstanding framework and suite of applications!

-Tom Lisjac


More information about the imp mailing list