<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom"><title>Yaal Coop - linux</title><link href="https://yaal.coop/en/" rel="alternate"/><link href="https://yaal.coop/en/blog/feeds/tag-linux.atom.xml" rel="self"/><id>https://yaal.coop/en/</id><updated>2022-06-02T00:00:00+02:00</updated><entry><title>Purism Librem 5 software review : our list to Santa</title><link href="https://yaal.coop/en/blog/purism-librem5-software-santas-list" rel="alternate"/><published>2022-06-02T00:00:00+02:00</published><updated>2022-06-02T00:00:00+02:00</updated><author><name>Éloi Rivard &lt;eloi@yaal.coop&gt;</name></author><id>tag:yaal.coop,2022-06-02:/en/blog/purism-librem5-software-santas-list</id><summary type="html">&lt;p&gt;We tested the Purism Librem5 phone with fresh eyes, and listed what is missing before we can use the phone as a daily driver.&lt;/p&gt;</summary><content type="html">&lt;p&gt;After several years of waiting, we just received our &lt;a href="https://puri.sm/products/librem-5/"&gt;Librem 5 phone&lt;/a&gt; from Purism.
The Librem 5 phone is a privacy-oriented phone which notable features are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;it uses &lt;a href="https://pureos.net"&gt;PureOS&lt;/a&gt;, a GNU/Linux distribution based on Debian, instead of Android or iOS;&lt;/li&gt;
&lt;li&gt;the interface is based on &lt;a href="https://gnome.org"&gt;GNOME&lt;/a&gt; with a few modifications;&lt;/li&gt;
&lt;li&gt;it has kill switches to physically disable wifi, bluetooth, cellular data, camera and microphone.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Running a Linux on a cellular phone enables new uses, especially for tech savvy, but it comes with its lot of drawbacks.
The main notable ones is that Linux phones is a brand new field, and a lot of apps are simply 'not ready'.
Either because their UI is not adaptive, because they have not been adapted to mobile user interactions (swiping and other gestures), or just because they have not been tested enough by users, so some actions feels convoluted.&lt;/p&gt;
&lt;p&gt;FOSS developers do their best, and a whole lot of great work has been done so far.
However we are not yet at a point where Linux phones can be put in the hands of a larger audience.
With our fresh eyes of new Linux mobile users, we want to list here the main things that we felt were really missing to provide a good user experience (at least for our biased geeky use).
We focused on &lt;a href="https://apps.gnome.org/"&gt;GNOME Core and Circle apps&lt;/a&gt;, and mobile/Librem5 specific apps developed by Purism.
What we expect from a phone is to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;place calls&lt;/li&gt;
&lt;li&gt;receive and send SMS&lt;/li&gt;
&lt;li&gt;receive and send emails&lt;/li&gt;
&lt;li&gt;be used as an alarm clock&lt;/li&gt;
&lt;li&gt;manage contacts&lt;/li&gt;
&lt;li&gt;manage tasks&lt;/li&gt;
&lt;li&gt;be used as a geolocation navigation device&lt;/li&gt;
&lt;li&gt;browse the internet&lt;/li&gt;
&lt;li&gt;play music&lt;/li&gt;
&lt;li&gt;take photos&lt;/li&gt;
&lt;li&gt;take notes&lt;/li&gt;
&lt;li&gt;display documents&lt;/li&gt;
&lt;li&gt;share internet connection&lt;/li&gt;
&lt;li&gt;be used as a torchlight&lt;/li&gt;
&lt;li&gt;discuss with people&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;As patching has even more value than reporting, this list could be used by us (or you?) as a to-do list for some day if we get bored.&lt;/p&gt;
&lt;p&gt;We have tested the phone running &lt;a href="https://pureos.net/"&gt;PureOS byzantium&lt;/a&gt;, and we updated all the apps through &lt;a href="https://flathub.org"&gt;Flatpak&lt;/a&gt; when possible so we could get the latest GNOME 42 fixes.&lt;/p&gt;
&lt;h1&gt;Blockers&lt;/h1&gt;
&lt;p&gt;In this category we put the issues we feel are very discouraging for a daily use.
This mainly concerns UX friction and stress, and missing or broken features.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/World/Phosh/squeekboard/"&gt;Squeekboard&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/World/Phosh/squeekboard/-/issues/93"&gt;Alternate characters popovers&lt;/a&gt;: We Europeans use a lot of diacritics, the keyboard should offer us a way easily write any common accentuated character.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://source.puri.sm/Librem5/OS-issues/"&gt;Librem5&lt;/a&gt; - &lt;a href="https://source.puri.sm/Librem5/OS-issues/-/issues/84"&gt;Translation have to be forced&lt;/a&gt;: At first launch, the welcome panel asks the user for their language, but this action is uneffective and the system is displayed in English after that. This is easy to fix with a command-line, but surprising for a first-launch.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/gnome-clocks"&gt;Clocks&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/gnome-clocks/-/issues/1"&gt;Alarms should ring even when the application is not launched&lt;/a&gt;: If an alarm has been set, it should ring on time, no matter what. Having to launch the application to get the alarm ring is unexpected.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/gnome-clocks"&gt;Clocks&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/gnome-clocks/-/issues/100"&gt;Alarms should wake the system up&lt;/a&gt;: If an alarm has been set, it should ring on time, no matter what. Alarms should wake the system up if needed.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/gnome-clocks"&gt;Clocks&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/gnome-clocks/-/issues/10"&gt;Custom alarm sound&lt;/a&gt;: At the moment, the only alarm sound is the default one.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/gnome-clocks"&gt;Clocks&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/gnome-clocks/-/issues/160"&gt;Interact with an alarm from the lock screen&lt;/a&gt;: Currently it is needed to enter the PIN code before we can stop the alarms. When you wake up, this is harsh.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/World/Phosh/squeekboard/"&gt;Squeekboard&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/World/Phosh/squeekboard/-/issues/282"&gt;Input indicator&lt;/a&gt;: When a key is tapped, users should have a visual indication of which key is actually pressed.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://source.puri.sm/Librem5/linux"&gt;Librem5&lt;/a&gt; - &lt;a href="https://source.puri.sm/Librem5/linux/-/issues/387"&gt;Night light support&lt;/a&gt;: GNOME provide a night light feature that reddish the screen automatically depending on the hour. It seems there are some kernel thing to do to enable this. Without this, watching to the screen at night just kill your eyes.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/calls/"&gt;Calls&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/calls/-/issues/456"&gt;Alphabet side bar&lt;/a&gt;: The application lacks an alphabet side bar to quickly jump to some letters in the contact list. With thousands of contacts this would become more than useful.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/gnome-contacts"&gt;Contacts&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/gnome-contacts/-/issues/246"&gt;Alphabet side bar&lt;/a&gt;: The application lacks an alphabet side bar to quickly jump to some letters in the contact list. With thousands of contacts this would become more than useful.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/gnome-todo/"&gt;To-Do&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/gnome-todo/-/issues/274"&gt;Adaptive UI&lt;/a&gt;: The UI is not adaptive at the moment, so To-Do is not usable.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/gnome-weather/"&gt;Weather&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/gnome-weather/-/issues/236"&gt;Adaptive UI&lt;/a&gt;: The application is not adapted to mobile UI.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/fractal/"&gt;Fractal&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/fractal/-/issues/717"&gt;End-to-end encryption&lt;/a&gt;: At Yaal Coop we encrypt our conversations, so E2EE in Fractal is a blocker to us.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/gnome-maps/"&gt;Maps&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/gnome-maps/-/issues/264"&gt;Adaptive UI&lt;/a&gt;: The side-menu is not usable on a Librem 5 at this point.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/gnome-maps/"&gt;Maps&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/gnome-maps/-/issues/335"&gt;Navigation view&lt;/a&gt;: The application can calculate itineraries, but do not provide anything to follow the itineraries. Is is not usable in a car yet.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/gnome-maps/"&gt;Maps&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/gnome-maps/-/issues/2"&gt;Long-press to open the contextual menu&lt;/a&gt;: Some actions are only accessible via right click on desktop, so on mobile they just cannot be done. A long press on the map should have the same effect as a right click.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/gnome-online-accounts/"&gt;Online Accounts&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/gnome-online-accounts/-/issues/1"&gt;CarDAV &amp;amp; CalDAV provider support&lt;/a&gt;: This would allow to plug any contact, calendar and todo list provider to the system.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/mobile-broadband-provider-info"&gt;mobile-broadband-provider-info&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/mobile-broadband-provider-info/-/merge_requests/38"&gt;TeleCoop support&lt;/a&gt;: This allows to use data with &lt;a href="https://telecoop.fr/"&gt;TeleCoop&lt;/a&gt;. The patch is applied but not yet deployed.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/gnome-software"&gt;Software&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/gnome-software/-/issues/1472"&gt;UI is sluggish&lt;/a&gt;: When Flatpak in enabled, any actions takes decades to achieve, to the point that it is sometimes needed to restart the app.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.com/kop316/vvmplayer"&gt;Voicemail&lt;/a&gt; - &lt;a href="https://source.puri.sm/Librem5/OS-issues/-/issues/267"&gt;There is no working voicemail app at the moment&lt;/a&gt;: Having the ability to easily listen to voicemails is a must-have on a 2022 phone.&lt;/li&gt;
&lt;/ul&gt;
&lt;h1&gt;Comfort&lt;/h1&gt;
&lt;p&gt;In this category we put the issues that would improve our comfort.
This mainly concern mobile UX improvements.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/World/Phosh/phosh/"&gt;Phosh&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/World/Phosh/phosh/-/issues/9"&gt;Automatic light and dark theme switch&lt;/a&gt;: Along with the screen warmness adaptation, switching from a light to a dark theme when the night comes is a bliss for the eyes. This is achievable with GNOME Shell with the &lt;a href="https://extensions.gnome.org/extension/2236/night-theme-switcher/"&gt;Night Theme Switcher&lt;/a&gt; extension for instance.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/World/Phosh/phosh/"&gt;Phosh&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/World/Phosh/phosh/-/merge_requests/934"&gt;Swipe to open and close the menu&lt;/a&gt;: As of today, the application menu and the top menu can only be opened by tapping. However swiping to open the menu feels more natural on mobile. This have been implemented but not yet deployed.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/World/Phosh/phosh/"&gt;Phosh&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/World/Phosh/phosh/-/issues/397"&gt;Automatically unlock the keyring&lt;/a&gt;: When opening a new session with a PIN, it is then asked a second time to unlock the GNOME keyring. This feels redundant.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/World/Phosh/phosh/"&gt;Phosh&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/World/Phosh/phosh/-/issues/525"&gt;Hold the volume buttons to change volume&lt;/a&gt;: Currently, we have to press the buttons multiple times in order to change the volume.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://source.puri.sm/Librem5/OS-issues"&gt;Librem5&lt;/a&gt; - &lt;a href="https://source.puri.sm/Librem5/OS-issues/-/issues/265"&gt;Ask the encryption passphrase at first boot&lt;/a&gt;: At first boot, a (default) passphrase is asked to decrypt the disk, in English, with a qwerty keyboard. It would be friendlier to not ask it a the first boot and let the user choose it.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://source.puri.sm/Librem5/OS-issues"&gt;Librem5&lt;/a&gt; - &lt;a href="https://source.puri.sm/Librem5/OS-issues/-/issues/265"&gt;Disk decryption screen l10n&lt;/a&gt;: The disk decryption screen is in English, with a qwerty keyboard, so it is not adapted to other languages.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/World/Phosh/phosh/"&gt;Phosh&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/World/Phosh/phosh/-/issues/784"&gt;Keep the time displayed when the top menu is opened&lt;/a&gt;: The time is hidden when the top menu is opened. Time is still an interesting information to display when the menu is opened, and without this the top bar appears strangely empty. This seems to be fixed but not yet deployed.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/World/Phosh/phosh/"&gt;Phosh&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/World/Phosh/phosh/-/issues/783"&gt;Toggle geolocation from the top menu&lt;/a&gt;: In the top menu there are button to toggle wifi or bluetooth, but not to toggle geolocation.&lt;/li&gt;
&lt;/ul&gt;
&lt;h1&gt;Sparkles&lt;/h1&gt;
&lt;p&gt;In this category we put everything else that we met during our test, from nice-to-have features to slight mobile UX improvements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://source.puri.sm/Librem5/chatty/"&gt;Chatty&lt;/a&gt; - &lt;a href="https://source.puri.sm/Librem5/chatty/-/issues/698"&gt;Swipe to return to the message list&lt;/a&gt;: When a message is displayed, there is an arrow button that allows to go back to the message list, but the more natural action on mobile would be to swipe left.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/geary/"&gt;Geary&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/geary/-/issues/1377"&gt;Swipe to return to the message list&lt;/a&gt;: When a message is displayed, there is an arrow button that allows to go back to the message list, but the more natural action on mobile would be to swipe left.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/gnome-calendar"&gt;Calendar&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/gnome-calendar/-/issues/702"&gt;Swipe to navigate between weeks or months&lt;/a&gt;: Swipe would be more adapted to mobile screens than the current arrows.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/gnome-calendar"&gt;Calendar&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/gnome-calendar/-/issues/838"&gt;Selection visual indicator&lt;/a&gt;: During a selection on touchscreen, users have no feedback until their finger is released.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/gnome-calendar"&gt;Calendar&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/gnome-calendar/-/issues/670"&gt;Adaptive UI&lt;/a&gt;: Calendar displays good enough on mobile, but some details are missing. For instance, the tooltips can be larger than the screen.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/gnome-clocks"&gt;Clocks&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/gnome-clocks/-/issues/238"&gt;Analog watch widget&lt;/a&gt;: Tapping multiple times on the screen to select hours and minutes is cumbersome. An analog watch widget could achieve the action in on two taps.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/gnome-disk-utility"&gt;Disks&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/gnome-disk-utility/-/issues/251"&gt;Adaptive UI&lt;/a&gt;: The encryption menu is not adaptive, but this is still usable.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/dialect-app/dialect/"&gt;Dialect&lt;/a&gt; - &lt;a href="https://github.com/dialect-app/dialect/issues/254"&gt;Slow performances at startup&lt;/a&gt;: The applications takes several seconds to start.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/dialect-app/dialect/"&gt;Dialect&lt;/a&gt; - &lt;a href="https://github.com/dialect-app/dialect/issues/255"&gt;Cannot close the preferences dialog&lt;/a&gt;: It has a close button on GNOME Shell, but not on phosh.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/dialect-app/dialect/"&gt;Dialect&lt;/a&gt; - &lt;a href="https://github.com/dialect-app/dialect/issues/211"&gt;Offline translations&lt;/a&gt;: Because we are not always connected.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/gnome-maps/"&gt;Maps&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/gnome-maps/-/issues/1"&gt;Offline maps&lt;/a&gt;: To save mobile data, it would be better to pre-download maps and routes on a Wifi connection for instance.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/gnome-dictionary"&gt;Dictionary&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/gnome-dictionary/-/issues/15"&gt;Offline dictionary&lt;/a&gt;: Currently, an internet connection is needed to use the app.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/evince/"&gt;Evince&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/evince/-/issues/1256"&gt;Automatically switch to night mode&lt;/a&gt;: Evince allows to manually invert the background color at night. This should be done automatically depending on the system dark mode.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/gnome-maps"&gt;Maps&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/gnome-maps/-/issues/452"&gt;Double-tap to zoom&lt;/a&gt;: On desktop double-clicking zooms, as should do double-tapping on touchscreen.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/World/Phosh/squeekboard"&gt;Squeekboard&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/World/Phosh/squeekboard/-/merge_requests/552"&gt;Bépo support&lt;/a&gt;: This one does only concerns a few nerds, but bépo (a French dvorak layout) support would be awesome.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/geary"&gt;Geary&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/geary/-/issues/1196"&gt;Image banner is not adaptive&lt;/a&gt;: The image display banner does not display well on mobile.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/epiphany"&gt;Web&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/epiphany/-/issues/1801"&gt;Password banner is not adaptive&lt;/a&gt;: The password banner does not display well on mobile.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/World/deja-dup"&gt;Backups&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/World/deja-dup/-/issues/310"&gt;Adaptive UI&lt;/a&gt;: The home screen does not display well on mobile.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://source.puri.sm/Librem5/OS-issues"&gt;Librem5&lt;/a&gt; - &lt;a href="https://source.puri.sm/Librem5/OS-issues/-/issues/138"&gt;Mobile data traffic counter&lt;/a&gt;: This would be a useful utility when data is limited.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/lakoliu/Furtherance"&gt;Furtherance&lt;/a&gt; - &lt;a href="https://github.com/lakoliu/Furtherance/issues/52"&gt;Home screen is not adaptive enough&lt;/a&gt;: The French translation of the application provokes UX adaptivity issues.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/gnome-notes/"&gt;Notes&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/gnome-notes/-/issues/134"&gt;Adaptive UI&lt;/a&gt;: Notes is not yet adaptive.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.gnome.org/GNOME/gnome-control-center"&gt;Settings&lt;/a&gt; - &lt;a href="https://gitlab.gnome.org/GNOME/gnome-control-center/-/issues/231#note_1469421"&gt;Bluetooth screen is not adaptive enough&lt;/a&gt;: As usual, some French content makes the panel too large.&lt;/li&gt;
&lt;/ul&gt;</content><category term="FOSS"/><category term="FOSS"/><category term="gnome"/><category term="linux"/><category term="purism"/><category term="librem5"/></entry><entry><title>How to plug OpenSMTPD with OpenLDAP on Debian Buster</title><link href="https://yaal.coop/en/blog/how-to-plug-opensmtpd-with-openldap-on-debian-buster" rel="alternate"/><published>2019-12-27T00:00:00+01:00</published><updated>2019-12-27T00:00:00+01:00</updated><author><name>Éloi Rivard &lt;eloi@yaal.coop&gt;</name></author><id>tag:yaal.coop,2019-12-27:/en/blog/how-to-plug-opensmtpd-with-openldap-on-debian-buster</id><summary type="html">&lt;p&gt;This should be easy to do; it is not.&lt;/p&gt;</summary><content type="html">&lt;p&gt;So you want to host your own mail server with opensmtpd, but you don't have
time to understand everything going on? Here is an expeditious guide for doing
just that.&lt;/p&gt;
&lt;p&gt;In this guide I used OpenSMTPD 6.6.1 on Debian Buster.&lt;/p&gt;
&lt;p&gt;Lets start by blindly copy-pasting this snippet to install the dependencies we
will need:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;sudo&lt;span class="w"&gt; &lt;/span&gt;apt&lt;span class="w"&gt; &lt;/span&gt;install&lt;span class="w"&gt; &lt;/span&gt;opensmtpd&lt;span class="w"&gt; &lt;/span&gt;libpam-ldap&lt;span class="w"&gt; &lt;/span&gt;libnss-ldap
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;h1&gt;OpenSMTPD&lt;/h1&gt;
&lt;p&gt;OpenSMTPD has some LDAP support with the &lt;code&gt;opensmtpd-extras&lt;/code&gt; package, but not
enough for LDAP authentication. Someone opened a &lt;a href="https://github.com/OpenSMTPD/OpenSMTPD/issues/812"&gt;bug
report&lt;/a&gt; stating that you can
request some fields from the LDAP server, giving you access to the hashed user
password, but that's it. You do not know which hash algorithm was used, and
even if you did, OpenSMTPD will only use the one provided by
&lt;a href="http://man7.org/linux/man-pages/man3/crypt.3.html"&gt;crypt&lt;/a&gt;, so there is a good
chance that comparing hashed passwords won't work. Later, an OpenSMTPD
developer
&lt;a href="https://github.com/OpenSMTPD/OpenSMTPD/issues/812#issuecomment-458482184"&gt;confirmed&lt;/a&gt;
that there was no such thing as LDAP authentication in OpenSMTPD, but that one
should rely on standard authentication mechanisms such as PAM or bsd_auth:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;[...] OpenSMTPD authenticate using crypt(3) by default, which indeed will
require credentials to be adapted for that function, but it does so through
bsd_auth(3) on OpenBSD and may be configured to use pam(3) on other systems,
so you may just delegate authentication to an ldap layer if you actually
don't want the system's auth to take place.&lt;/p&gt;
&lt;p&gt;This seems like the right approach to tackle this issue to me, if I were to
authenticate against ldap, I'd use an ldap authenticator for bsd_auth(3) or
pam(3).&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Here is an example of a &lt;code&gt;/etc/smtpd.conf&lt;/code&gt; file.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="n"&gt;pki&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;mail&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;mydomain&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;tld&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;cert&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;/path/to/fullchain.pem&amp;quot;&lt;/span&gt;
&lt;span class="n"&gt;pki&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;mail&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;mydomain&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;tld&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;key&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;/path/to/privkey.pem&amp;quot;&lt;/span&gt;
&lt;span class="n"&gt;pki&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;mail&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;mydomain&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;tld&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;dhe&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;auto&lt;/span&gt;

&lt;span class="n"&gt;public_addr&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;xxx.xxx.xxx.xxx&amp;quot;&lt;/span&gt;
&lt;span class="n"&gt;listen&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;on&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;$&lt;/span&gt;&lt;span class="n"&gt;public_addr&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;port&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;465&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;smtps&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;pki&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;mail&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;mydomain&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;tld&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;auth&lt;/span&gt;
&lt;span class="n"&gt;listen&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;on&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;$&lt;/span&gt;&lt;span class="n"&gt;public_addr&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;port&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;587&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;tls&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="n"&gt;require&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;pki&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;mail&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;mydomain&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;tld&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;auth&lt;/span&gt;

&lt;span class="n"&gt;table&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;ldap&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;ldap&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;etc&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;mail&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;ldap&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;conf&lt;/span&gt;

&lt;span class="n"&gt;action&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;dovecot&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;lmtp&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;/var/run/dovecot/lmtp&amp;quot;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;userbase&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;ldap&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="n"&gt;action&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;relay&amp;quot;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;relay&lt;/span&gt;

&lt;span class="k"&gt;match&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;any&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;for&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;domain&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;mydomain.tld&amp;quot;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;action&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;dovecot&amp;quot;&lt;/span&gt;
&lt;span class="k"&gt;match&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;any&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;action&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;relay&amp;quot;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Note that the &lt;code&gt;userbase&lt;/code&gt; parameter is not directly linked with user authentication.
It actually defines the list of available recipients. Here is an example of
&lt;code&gt;/etc/mail/ldap.conf&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;url                     ldap://ldap.mydomain.tld
username                cn=admin,dc=mydomain,dc=tld
password                MyAmazingPassword
basedn                  ou=Users,dc=mydomain,dc=tld

userinfo_filter         (&amp;amp;(objectClass=posixAccount)(uid=%s))
userinfo_attributes     uidNumber,gidNumber,homeDirectory
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Without further configuration, the &lt;code&gt;auth&lt;/code&gt; keyword in &lt;code&gt;smtpd.conf&lt;/code&gt; tells OpenSMTPD
to use PAM authentication. So this is what we should now configure.&lt;/p&gt;
&lt;h1&gt;PAM&lt;/h1&gt;
&lt;p&gt;According to its man page, &lt;em&gt;PAM is a system of libraries that handle the
authentication tasks of applications (services) on the system.&lt;/em&gt; In Debian, it
mainly consists of a collection of configuration files in &lt;code&gt;/etc/pam.d&lt;/code&gt; for
programs that need a generic way to handle authentication, session management,
etc. Each file is a set of rules for one program. Those rules generally use a
&lt;code&gt;pam_foobar.so&lt;/code&gt; file depending on the method used (unix, ldap etc.). The idea
is to chain rules to define an authentication policy (e.g. try to authenticate
against the unix backend, if that fails try against LDAP, then if that fails
reject the user). By default, OpenSMTPD will look into the &lt;code&gt;/etc/pam.d/smtpd&lt;/code&gt;
file for its rules, so this is where we want to write some configuration. The
&lt;code&gt;pam_ldap.so&lt;/code&gt; module we are interested in is provided by the &lt;code&gt;libpam-ldap&lt;/code&gt;
package.&lt;/p&gt;
&lt;p&gt;Here is an example of a &lt;code&gt;/etc/pam.d/smtpd&lt;/code&gt; file.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="gh"&gt;#&lt;/span&gt;%PAM-1.0

account     [default=bad success=ok user_unknown=ignore] pam_ldap.so debug

auth        sufficient      pam_ldap.so debug
auth        required        pam_deny.so
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Basically, this configuration tells PAM to rely on &lt;code&gt;pam_ldap.so&lt;/code&gt; to manage user
accounts and authentication. As you can see, there is not a lot of information
in this file. The &lt;a href="https://wiki.debian.org/LDAP/PAM"&gt;Debian documentation&lt;/a&gt;
explains that this is because &lt;code&gt;pam_ldap.so&lt;/code&gt; delegates everything to &lt;a href="https://wiki.debian.org/LDAP/NSS"&gt;Name
Service Switch&lt;/a&gt;. The &lt;code&gt;debug&lt;/code&gt; keywords are
used for verbosity, and can safely be removed.&lt;/p&gt;
&lt;h1&gt;NSS&lt;/h1&gt;
&lt;p&gt;The NSS is provided by the &lt;code&gt;libnss-ldap&lt;/code&gt; package. It is a daemon that holds the
LDAP configuration and caches the requests to the LDAP.&lt;/p&gt;
&lt;p&gt;You can configure your ldap URI, your search DN and your bind credentials in
&lt;code&gt;/etc/nslcd.conf&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;...
uri ldap://ldap.mydomain.tld

base ou=Users,dc=mydomain,dc=tld

binddn cn=admin,dc=mydomain,dc=tld
bindpw MyVerySecretPassphrase
...
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;h1&gt;SSHD&lt;/h1&gt;
&lt;p&gt;On debian Buster, enabling LDAP on it has a side effect: SSH sessions will try to authenticate against the LDAP via PAM, unless you switch &lt;code&gt;UsePAM&lt;/code&gt; to &lt;code&gt;no&lt;/code&gt; in &lt;code&gt;/etc/ssh/sshd_config&lt;/code&gt;.&lt;/p&gt;
&lt;h1&gt;Debug your installation&lt;/h1&gt;
&lt;p&gt;To debug this installation, let's launch all those services manually and make
them verbose:&lt;/p&gt;
&lt;p&gt;Check the system authentication logs:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;sudo&lt;span class="w"&gt; &lt;/span&gt;tail&lt;span class="w"&gt; &lt;/span&gt;--follow&lt;span class="w"&gt; &lt;/span&gt;/var/log/auth.log&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;|&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;grep&lt;span class="w"&gt; &lt;/span&gt;pam_ldap
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Launch opensmtpd in verbose mode:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;sudo&lt;span class="w"&gt; &lt;/span&gt;systemctl&lt;span class="w"&gt; &lt;/span&gt;stop&lt;span class="w"&gt; &lt;/span&gt;opensmtpd
sudo&lt;span class="w"&gt; &lt;/span&gt;/usr/sbin/smtpd&lt;span class="w"&gt; &lt;/span&gt;-dv
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Launch the NSS daemon in verbose mode:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;sudo&lt;span class="w"&gt; &lt;/span&gt;systemctl&lt;span class="w"&gt; &lt;/span&gt;stop&lt;span class="w"&gt; &lt;/span&gt;nslcd
sudo&lt;span class="w"&gt; &lt;/span&gt;nslcd&lt;span class="w"&gt; &lt;/span&gt;--debug
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Check what is going on with your LDAP server:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;sudo&lt;span class="w"&gt; &lt;/span&gt;tail&lt;span class="w"&gt; &lt;/span&gt;--follow&lt;span class="w"&gt; &lt;/span&gt;/var/log/syslog&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;|&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;grep&lt;span class="w"&gt; &lt;/span&gt;slapd
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;</content><category term="Mail"/><category term="OpenSMTP"/><category term="FOSS"/><category term="Debian"/><category term="Buster"/><category term="Linux"/></entry></feed>