On 2016-04-22 13:32, Christian Boltz wrote:
> Hello,
> 
> Am Freitag, 22. April 2016, 12:27:44 CEST schrieb Carlos E. R.:
>> <2.2> 2016-04-22 12:14:59 Telcontar dovecot - - -  master: Fatal:
>> setrlimit(RLIMIT_DATA, 268435456): Permission denied 
> ...
>> Telcontar:~ # aa-logprof
>> Reading log entries from /var/log/audit/audit.log.
>> Updating AppArmor profiles in /etc/apparmor.d.
>> Enforce-mode changes:
>>
>> Profile:    /usr/sbin/dovecot
>> Capability: sys_resource
>> Severity:   8
>>
>> (A)llow / [(D)eny] / Audi(t) / Abo(r)t / (F)inish
>> Adding capability sys_resource to profile.
> 
> That's surprising in more than one way ;-)
> 
> First, the dovecot profile wasn't touched in this update. (Nevertheless, 
> check for *.rpmnew or *.rpmsave files in /etc/apparmor.d just to be on 
> the safe side.)

I already did, none there.

 
> Now the question is why dovecot wants to do this. Did you change any 
> settings in dovecot or rlimit settings on your system? Do you set 
> vsz_limit somewhere in your dovecot config?

Not in months. Time ago, yes, I had to do it, or some thing ate all the RAM - I 
remember now asking about it some time ago, maybe a year:

/etc/dovecot/local.conf


default_vsz_limit = 256M
# It is ignored, not applied to services. The real limit applied is  
18446744073709551615 B.

#login_trusted_networks = 192.168.1.0/24, 127.0.0.1/8
login_trusted_networks = 192.168.1.14/31,  127.0.0.1/8
# 192.168.1.129/31,

# Space separated list of wanted authentication mechanisms:
#   plain login digest-md5 cram-md5 ntlm rpa apop anonymous gssapi otp skey
#   gss-spnego
# NOTE: See also disable_plaintext_auth setting.
auth_mechanisms = plain login

# <2.2> 2014-08-19 23:47:06 Telcontar dovecot - - -  auth: Fatal: CRAM-MD5 
mechanism can't be supported with given passdbs
# <2.2> 2014-08-19 23:49:37 Telcontar dovecot - - -  auth: Fatal: DIGEST-MD5 
mechanism can't be supported with given passdbs


disable_plaintext_auth = yes
ssl = yes
mail_location = mbox:~/Mail:INBOX=/var/mail/%u
mail_debug = yes

#verbose_ssl = no
#CER - testing - nope, unknown setting #verbose_lda = no



# For use with delivery agent, /usr/lib/dovecot/dovecot-lda
lda_mailbox_autocreate = yes
lda_mailbox_autosubscribe = yes


#mail_max_userip_connections = 15  en 20-imap.conf
#CER - el Thunderbird puede necesitar más (15 o 30).
#No se si esto funcionaría:
protocol imap {
  mail_max_userip_connections = 20
}

service imap {
  # Most of the memory goes to mmap()ing files. You may need to increase this
  # limit if you have huge mailboxes.
  #vsz_limit = $default_vsz_limit
  # this results in vsz_limit = 18446744073709551615 B
  vsz_limit = 512 M

  # Max. number of IMAP processes (connections)
  #process_limit = 1024
}



ssl_cert = </etc/ssl/certs/dovecot.pem
ssl_key = </etc/ssl/private/dovecot.pem

listen = *, ::


mail_plugins = $mail_plugins fts fts_lucene

plugin {
  fts = lucene
  # Lucene-specific settings, good ones are:
  fts_lucene = whitespace_chars=@.
}





-- 
Cheers / Saludos,

                Carlos E. R.
                (from 13.1 x86_64 "Bottle" at Telcontar)

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
Evergreen mailing list
Evergreen@lists.rosenauer.org
http://lists.rosenauer.org/mailman/listinfo/evergreen

Reply via email to