Package: dovecot
Version: 0.99.13-3
Followup-For: Bug #273361

My /etc/pam.d/common-* looks like this:

account [success=1 default=ignore] pam_unix.so
account required pam_ldap.so use_first_pass
account required pam_permit.so
auth    [success=1 default=ignore] pam_unix.so
auth    required pam_ldap.so use_first_pass
auth    required pam_permit.so
session [success=1 default=ignore] pam_unix.so
session required pam_ldap.so use_first_pass
session required pam_mkhomedir.so skel=/etc/skel umask=0002
session required pam_permit.so

When many LDAP users login, /var/log/auth.log shows many (expected) error like:
Feb  3 18:16:15 eta dovecot-auth: (pam_unix) authentication failure; logname= 
uid=0 euid=0 tty= ruser= rhost=127.0.0.1
Feb  3 18:16:19 eta dovecot-auth: (pam_unix) check pass; user unknown

After recent upgrades, these lines begin to appear.
Feb  3 16:31:00 eta dovecot-auth: Login process has too old (123s) requests, 
killing it.
Feb  3 16:31:00 eta dovecot-auth: Login process has too old (124s) requests, 
killing it.

And some more like this:
Feb  3 16:45:23 eta dovecot-auth: I/O leak: 0x8054940 (13)
Feb  3 16:45:23 eta dovecot-auth: I/O leak: 0x8054940 (14)
Feb  3 16:45:23 eta dovecot-auth: I/O leak: 0x8054940 (15)

However, the problem is solved by changing /etc/pam.d/dovecot to:
auth    required pam_ldap.so
account required pam_ldap.so
session required pam_mkhomedir.so skel=/etc/skel umask=0002
session required pam_ldap.so

I think dovecot has some problem dealing with the pam_unix + pam_ldap
configuration. I don't know if it really happens between 0.99.10 to
0.99.11. Shall we report it upstream?


-- System Information:
Debian Release: 3.1
  APT prefers testing
  APT policy: (500, 'testing'), (400, 'unstable')
Architecture: i386 (i686)
Kernel: Linux 2.6.8-mppe
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)

Versions of packages dovecot depends on:
ii  dovecot-imapd                 0.99.13-3  A secure IMAP server that supports
ii  dovecot-pop3d                 0.99.13-3  A secure POP3 server that supports

-- no debconf information


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to