from small one page howto to huge articles all in one place

search text in:




Other .linuxhowtos.org sites:gentoo.linuxhowtos.org



Last additions:
using iotop to find disk usage hogs

using iotop to find disk usage hogs

words:

887

views:

210219

userrating:


May 25th. 2007:
Words

486

Views

259180

why adblockers are bad


Workaround and fixes for the current Core Dump Handling vulnerability affected kernels

Workaround and fixes for the current Core Dump Handling vulnerability affected kernels

words:

161

views:

150551

userrating:


April, 26th. 2006:

Druckversion
You are here: manpages





DOVEAD-AUTH

Section: Dovecot (1)
Updated: February 2026
Index Return to Main Contents
 

NAME

dovead-auth- Flush/lookup/test authentication data  

SYNOPSIS

doveadm [lB]GLOBAL OPTIONS[rB] auth command [lB]OPTIONS[rB] [lB]ARGUMENTS[rB]  

DESCRIPTION

The doveadm auth COMMANDS can be used to perform various authentication related actions.  

GLOBAL OPTIONS

Global doveadm(1) -D
Enables verbosity and debug messages.

-O

Do not read any config file, just use defaults. The dovecot_storage_version setting defaults to the latest version, but can be overridden with

-k

Preserve entire environment for doveadm, not just import_environment setting.

-v

Enables verbosity, including progress counter.

-i instanc-name

If using multiple Dovecot instances, choose the config file based on this instance name. See instance_name setting for more information.

-c confi-file

Read configuration from the given confi-file. By default it first reads config socket, and then falls back to /etc/dovecot/dovecot.conf. You can also point this to config socket of some instance running compatible version.

-o setting=value

Overrides the configuration setting from /etc/dovecot/dovecot.conf and from the userdb with the given value. In order to override multiple settings, the -o option may be specified multiple times.

-f formatter

Specifies the formatter for formatting the output. Supported formatters are: flow
prints each line with key=value pairs.

json

prints a JSON array of JSON objects.

pager

prints each key: value pair on its own line and separates records with form feed character (^L).

tab

prints a table header followed by tab separated value lines.

table

prints a table header followed by adjusted value lines.

 

OPTIONS

-x auth_info
auth_info specifies additional conditions for the user command. The auth_info option string has to be given as name = value pair. For multiple conditions the -x option could be supplied multiple times. Possible names for the auth_info are: service
The service for which the userdb lookup should be tested. The value may be the name of a service, commonly used with Dovecot. For example: imap, pop3 or smtp.

session

Session identifier.

lip

The local IP address (server) for the test.

rip

The remote IP address (client) for the test.

lport

The local port, e.g. 143

rport

The remote port, e.g. 24567

real_lip

The local IP to which the client connected on this host.

real_rip

The remote IP where client connected from to this host.

real_lport

The local port to which client connected to to this host.

real_rport

The remote port from where the client connected from to this host.

forward_<field>

Field to forward as %{forward:field} to auth process.

 

ARGUMENTS

user
The user's login name. Depending on the configuration, the login name may be for example jane or john@example.com.

password

Optionally the user's password. doveadm(1) will prompt for the password, if none was given.

 

COMMANDS

 

auth cache flush

doveadm [lB]GLOBAL OPTIONS[rB] auth cache flush [lB]-a master_socket_path[rB] [lB]use-mask ...[rB] Flush the authentication cache. By default the cache is flushed for all the users (which can also be done by sending SIGHUP to the auth process). You can also flush the cache for one or more users by providing a use-mask matching their usernames. -a master_socket_path
This option is used to specify an absolute path to an alternative UNIX domain socket. By default doveadm(1) will use the socket

-x auth_info

auth_info specifies additional conditions for the user command. The auth_info option string has to be given as name = value pair. For multiple conditions the -x option could be supplied multiple times. Possible names for the auth_info are: service
The service for which the userdb lookup should be tested. The value may be the name of a service, commonly used with Dovecot. For example: imap, pop3 or smtp.

session

Session identifier.

lip

The local IP address (server) for the test.

rip

The remote IP address (client) for the test.

lport

The local port, e.g. 143

rport

The remote port, e.g. 24567

real_lip

The local IP to which the client connected on this host.

real_rip

The remote IP where client connected from to this host.

real_lport

The local port to which client connected to to this host.

real_rport

The remote port from where the client connected from to this host.

forward_<field>

Field to forward as %{forward:field} to auth process.

 

auth lookup

doveadm [lB]GLOBAL OPTIONS[rB] auth lookup [lB]-a userdb_socket_path[rB] [lB]-x auth_info[rB] [lB]-f field[rB] user [lB]...[rB] Similar to dovead-user(1) command, except it performs a -a userdb_socket_path
This option is used to specify an absolute path to an alternative UNIX domain socket. By default doveadm(1) will use the socket

-f field

When this option and the name of a userdb field is given, doveadm(1) will show only the value of the specified field.

-x auth_info

auth_info specifies additional conditions for the user command. The auth_info option string has to be given as name = value pair. For multiple conditions the -x option could be supplied multiple times. Possible names for the auth_info are: service
The service for which the userdb lookup should be tested. The value may be the name of a service, commonly used with Dovecot. For example: imap, pop3 or smtp.

session

Session identifier.

lip

The local IP address (server) for the test.

rip

The remote IP address (client) for the test.

lport

The local port, e.g. 143

rport

The remote port, e.g. 24567

real_lip

The local IP to which the client connected on this host.

real_rip

The remote IP where client connected from to this host.

real_lport

The local port to which client connected to to this host.

real_rport

The remote port from where the client connected from to this host.

forward_<field>

Field to forward as %{forward:field} to auth process.

 

auth test

doveadm [lB]GLOBAL OPTIONS[rB] auth test [lB]-a auth_socket_path[rB] [lB]-A sasl_mech[rB] [lB]-x auth_info[rB] user [lB]password[rB] Test authentication for the given user. -a auth_socket_path
This option is used to specify an absolute path to an alternative UNIX domain socket. By default doveadm(1) will use the socket

-A sasl_mech

The SASL mechanism used for the authentication. By default PLAIN is used.

-x auth_info

auth_info specifies additional conditions for the user command. The auth_info option string has to be given as name = value pair. For multiple conditions the -x option could be supplied multiple times. Possible names for the auth_info are: service
The service for which the userdb lookup should be tested. The value may be the name of a service, commonly used with Dovecot. For example: imap, pop3 or smtp.

session

Session identifier.

lip

The local IP address (server) for the test.

rip

The remote IP address (client) for the test.

lport

The local port, e.g. 143

rport

The remote port, e.g. 24567

real_lip

The local IP to which the client connected on this host.

real_rip

The remote IP where client connected from to this host.

real_lport

The local port to which client connected to to this host.

real_rport

The remote port from where the client connected from to this host.

forward_<field>

Field to forward as %{forward:field} to auth process.

 

auth login

doveadm [lB]GLOBAL OPTIONS[rB] auth login [lB]-a auth_socket_path[rB] [lB]-m auth_master_socket_path[rB] [lB]-A sasl_mech[rB] [lB]-x auth_info[rB] user [lB]password[rB] Test full login for the given user; i.e. performing both passdb lookup (authentication) and userdb lookup (login). -a auth_socket_path
This option is used to specify an absolute path to an alternative UNIX domain socket. By default doveadm(1) will use the socket

-m auth_master_socket_path

This option is used to specify an absolute path to an alternative UNIX domain socket for the master socket. By default doveadm(1) will use the socket

-A sasl_mech

The SASL mechanism used for the authentication. By default PLAIN is used.

-x auth_info

auth_info specifies additional conditions for the user command. The auth_info option string has to be given as name = value pair. For multiple conditions the -x option could be supplied multiple times. Possible names for the auth_info are: service
The service for which the userdb lookup should be tested. The value may be the name of a service, commonly used with Dovecot. For example: imap, pop3 or smtp.

session

Session identifier.

lip

The local IP address (server) for the test.

rip

The remote IP address (client) for the test.

lport

The local port, e.g. 143

rport

The remote port, e.g. 24567

real_lip

The local IP to which the client connected on this host.

real_rip

The remote IP where client connected from to this host.

real_lport

The local port to which client connected to to this host.

real_rport

The remote port from where the client connected from to this host.

forward_<field>

Field to forward as %{forward:field} to auth process.

 

EXAMPLE

This example demonstrates an imap authentication test for user john, assuming the user is connected from the host with the IP address 192.0.2.143.
doveadm auth test-x service=imap-x rip=192.0.2.143 john
Password:
passdb: john auth succeeded
extra fields:
  user=john
 

REPORTING BUGS

Report bugs, including doveconf-n output, to the Dovecot Mailing List ladovecot@dovecot.orgra. Information about reporting bugs is available at: https://dovecot.org/bugreport.html  

SEE ALSO

doveadm(1)


 

Index

NAME
SYNOPSIS
DESCRIPTION
GLOBAL OPTIONS
OPTIONS
ARGUMENTS
COMMANDS
auth cache flush
auth lookup
auth test
auth login
EXAMPLE
REPORTING BUGS
SEE ALSO





Support us on Content Nation
rdf newsfeed | rss newsfeed | Atom newsfeed
- Powered by LeopardCMS - Running on Gentoo -
Copyright 2004-2025 Sascha Nitsch Unternehmensberatung GmbH
Valid XHTML1.1 : Valid CSS
- Level Triple-A Conformance to Web Content Accessibility Guidelines 1.0 -
- Copyright and legal notices -
Time to create this page: 12.2 ms