[ { type: install message: <&1 Option 3: Change the permissions on courierpasswd to set gid to the group ownership of the socket directory. Again, if the socket directory is owned by courier:courier, change the ownership and permissions of courierpasswd like so: chgrp courier courierpasswd chmod g+s courierpasswd Be aware that courierpasswd does not provide any max-failed-retry functionality so it is possible for local users to perform dictionary attacks against account passwords if courierpasswd is set up this way. The location of the authdaemon domain socket is listed in the authdaemonrc configuration file as the parameter authdaemonvar. EOM } ]