Adding official email accounts and aliases in LDAP

August 15, 2016

Reading time ~1 minute


This post will touch on what objectClass and attributes I used specifically for OpenLDAP mail user records. I like the idea of keeping things well organized and with this simple structure I'm keeping the People and Mail containers separate. As a result, user records in the Mail organizational unit will have mail specific attributes not found in People user records.

For the attributes to work I needed to have postfix-book.schema loaded into LDAP.

Import Mail Account

dn: uid=jdoe,ou=Mail,dc=domain1,dc=net
objectClass: top
objectClass: person
objectClass: organizationalPerson
objectClass: inetOrgPerson
objectClass: PostfixBookMailAccount
uid: jdoe
cn: John Doe
sn: Doe
mailEnabled: TRUE
mailUidNumber: 5000
mailGidNumber: 5000
description: John Doe's mail account
userPassword: {SSHA}lFXu8SajJaj+vEk99SvsBa+sRLmLfiRV
mailHomeDirectory: /home/vmail/
mailStorageDirectory: maildir:/home/vmail/

Once this mail record is imported into LDAP, the primary mail account including additional mail aliases defined by the mailAlias attribute can be verified using the postmap command.

$ postmap -q ldap:/etc/postfix/ldap/

$ postmap -q ldap:/etc/postfix/ldap/

We know LDAP can find our alias because the primary mail account that owns the alias was returned.

comments powered by Disqus

Monitoring a remote Nagios instance

Intro I wanted a quick way to monitor a remote Nagios host from a secondary Linux server in the event the primary Nagios instance became una…… Continue reading

Splunk Enterprise (Free) LDAP auth in Apache

Published on August 03, 2017

Setup Cyrus SASL with LDAP

Published on August 09, 2016