我在上面的错误中挣扎了 5 个多小时。我曾尝试完全删除 Postfix,并按照下一个手册和SASL 手册的说明重新安装它。
当我尝试使用 telnet 登录时,服务器阻止了登录,我得到了这个:(使用 smtpd -v 更详细):
postfix/smtpd[26301]:xsasl_cyrus_server_create:SASL 服务=smtp,领域=(空) postfix/smtpd[26301]: name_mask: noanonymous postfix/smtpd[26301]:警告:xsasl_cyrus_server_get_mechanism_list:没有适用的 SASL 机制 postfix/smtpd[26301]:致命:没有 SASL 身份验证机制
以下是结果postconf -n:
alias_database = hash:/etc/aliases alias_maps = hash:/etc/aliases allow_percent_hack = 否 append_dot_mydomain = 否 比夫 = 否 broken_sasl_auth_clients = 是 config_directory = /etc/postfix home_mailbox = Maildir/ inet_interfaces = 全部 邮箱命令 = /usr/bin/procmail-wrapper -o -a $DOMAIN -d $LOGNAME 邮箱大小限制 = 0 mydestination = theflipapp.com, localhost.com, , localhost myhostname = theflipapp.com 我的网络 = 127.0.0.0/8 …
我正在slapdUbuntu 14.04 Trusty Tahr 上设置 OpenLDAP 。我希望某些不是用户的实例(复制等)能够通过SASL使用DIGEST-MD5机制登录。
与用户不同,他们不应该在目录树中具有相应的 DN(以及密码)。相反,他们的凭据应该存储在外部,因此SASL.
我现在正在使用saslauthd(例如,如果可以直接访问 sasldb,这不是硬性要求)并且它使用机制工作正常PLAIN,LOGIN而使用机制DIGEST-MD5和CRAM-MD5.
我错过了什么或做错了什么?我怎样才能让它工作DIGEST-MD5?
OpenLDAP的配置为SASL在/etc/ldap/sasl2/slapd.conf这样的:
mech_list: EXTERNAL DIGEST-MD5 CRAM-MD5 PLAIN LOGIN
pwcheck_method: saslauthd
saslauthd_path: /var/run/saslauthd/mux
Run Code Online (Sandbox Code Playgroud)
有趣的(改变的)选项/etc/default/saslauthd是:
START=yes
MECHANISMS="sasldb"
Run Code Online (Sandbox Code Playgroud)
它们导致saslauthd像这样启动:
/usr/sbin/saslauthd -a sasldb -c -m /var/run/saslauthd -n 5
Run Code Online (Sandbox Code Playgroud)
我用DIGEST-MD5这样的方式重现失败的案例:
# ldapsearch -U replication -ZZ -Y DIGEST-MD5 -H ldap://ldap-master.example.com/ -b "dc=example,dc=com" "(objectClass=*)" …Run Code Online (Sandbox Code Playgroud) Postfix 无法对 cyrus saslauthd 进行身份验证。但是,saslauthd 本身愿意进行身份验证。我错过了什么?
从系统日志mail设施:
Aug 5 14:47:26 centos7-msa-test postfix/postfix-script[20286]: starting the Postfix mail system
Aug 5 14:47:26 centos7-msa-test postfix/master[20288]: daemon started -- version 2.10.1, configuration /etc/postfix
Aug 5 14:47:34 centos7-msa-test postfix/submission/smtpd[20291]: connect from client.example.com[192.0.2.2]
Aug 5 14:47:34 centos7-msa-test postfix/submission/smtpd[20291]: Anonymous TLS connection established from client.example.com[192.0.2.2]: TLSv1 with cipher ECDHE-RSA-AES128-SHA (128/128 bits
Aug 5 14:47:34 centos7-msa-test postfix/submission/smtpd[20291]: warning: SASL authentication failure: Internal Error -4 in server.c near line 1757
Aug 5 14:47:34 centos7-msa-test postfix/submission/smtpd[20291]: warning: SASL …Run Code Online (Sandbox Code Playgroud) 我正在使用 Postfix 和 Courier-IMAP 设置邮件服务器。我想使用 rimap 进行 SMTP 身份验证,这样我就不必维护两个用户数据库。我遇到的问题是,用户名后缀传递的域名被剥离了。它应该是“john@domain.com”,然后变成“john”。
登录 IMAP 服务器有效,testsaslauthd -u john@domain.com -p password.
使用smtpd_sasl_local_domain(设置或取消设置)没有区别。
这个帖子好像不行。即使我尝试使用 uasdfer@asdfasdf 登录,它也会剥离域部分。
后缀 sasl:
# cat main.cf |grep -i sasl
smtpd_sasl_auth_enable = yes
smtpd_sasl_security_options = noanonymous
broken_sasl_auth_clients = yes
smtpd_recipient_restrictions = permit_mynetworks permit_sasl_authenticated reject_unauth_destination reject_rbl_client zen.spamhaus.org check_policy_service unix:private/policyd-spf
Run Code Online (Sandbox Code Playgroud)
萨尔配置:
# cat saslauthd |grep -v "#"|grep -v -E "^$"
START=yes
DESC="SASL Authentication Daemon"
NAME="saslauthd"
MECHANISMS="rimap"
MECH_OPTIONS="127.0.0.1"
THREADS=5
OPTIONS="-c -m /var/run/saslauthd"
Run Code Online (Sandbox Code Playgroud)
服务器版本:
我最近使用 iRedMail 设置了 postfix、dovecot、amavis 和一套其他工具,但我很难对我的外发邮件服务器进行身份验证。
问题是这样的:
xyz@mydomain.com 是 abc@mydomain.com 的别名。我使用 abc@mydomain.com 进行身份验证,因为那是邮箱,但我实际上是从别名发送的。
这是会话的示例:
EHLO mydomain.com
250-mx1.mymailserver.net
250-PIPELINING
250-SIZE 45728640
250-ETRN
250-STARTTLS
250-AUTH PLAIN LOGIN
250-AUTH=PLAIN LOGIN
250-ENHANCEDSTATUSCODES
250-8BITMIME
250 DSN
auth plain amlta0BhbHRlcm5hdGl2ZXJlYWxpdHkuY29tAGppbWtAY=
235 2.7.0 Authentication successful
MAIL FROM: xyz@alternativereality.com
250 2.1.0 Ok
RCPT TO: joe@gmail.com
553 5.7.1 <xyz@mydomain.com>: Sender address rejected: not owned by user abc@mydomain.com
QUIT
Run Code Online (Sandbox Code Playgroud)
这是 postfix 的 main.cf 的相关部分:
smtpd_sender_restrictions = permit_mynetworks, reject_sender_login_mismatch, permit_sasl_authenticated
Run Code Online (Sandbox Code Playgroud)
显然reject_sender_login_mismatch是问题所在。我实际上更愿意保留此功能但支持别名。
这可以做到吗,和/或有没有办法作为别名进行身份验证?
提前致谢!
今天醒来发现我的网站缓慢/无响应。向上拉,看起来大量 saslauthd 进程已经启动,每个进程使用大约 64m 的 RAM,导致机器进入交换空间。我从来没有见过这么多用在那里。
top - 16:54:13 up 85 days, 11:48, 1 user, load average: 0.32, 0.50, 0.38
Tasks: 143 total, 1 running, 142 sleeping, 0 stopped, 0 zombie
Cpu(s): 0.7%us, 0.3%sy, 0.0%ni, 97.3%id, 0.2%wa, 0.0%hi, 0.0%si, 1.4%st
Mem: 1048796k total, 1025904k used, 22892k free, 14032k buffers
Swap: 2097144k total, 332460k used, 1764684k free, 194348k cached
PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND
848 admin 20 0 263m 115m 4840 S 0 11.3 …Run Code Online (Sandbox Code Playgroud) 我正在尝试让 saslauthd 与 openldap 一起工作。
ldapsearch 和连接到 openldap 的每个服务都可以正常工作。sasldblistusers2 不起作用 - ldapwhoami 也不起作用。
getent passwd 也可以正常工作。
sasldblistusers2 生成此日志条目:
Sep 30 03:48:01 sogo sasldblistusers2: _sasl_plugin_load failed on sasl_auxprop_plug_init for plugin: ldapdb
Sep 30 03:48:01 sogo sasldblistusers2: canonuserfunc error -7
Sep 30 03:48:01 sogo sasldblistusers2: _sasl_plugin_load failed on sasl_canonuser_init for plugin: ldapdb
Sep 30 03:48:01 sogo sasldblistusers2: DIGEST-MD5 common mech free
Run Code Online (Sandbox Code Playgroud)
ldapwhoami 结果:
root@sogo:/root# ldapwhoami
SASL/DIGEST-MD5 authentication started
Please enter your password:
ldap_sasl_interactive_bind_s: Invalid credentials (49)
additional info: SASL(-13): user not found: …Run Code Online (Sandbox Code Playgroud) 我的服务器出现了预期问题,我无法从邮件客户端进行连接。
我查看了服务器日志,唯一可以确定问题的是以下事件:
Nov 23 18:32:43 hig3 dovecot: imap-login: Login: user=, method=PLAIN, rip=xxxxxxxx, lip=xxxxxxxx, TLS Nov 23 18:32:55 hig3 postfix/smtpd[11653]: connect from xxxxxxx .co.uk[xxxxxxx] Nov 23 18:32:55 hig3 postfix/smtpd[11653]:警告:SASL 认证失败:无法连接到 saslauthd 服务器:没有这样的文件或目录 11 月 23 日 18:32:55 hig3 postfix/smtpd [11653]:警告:xxxxxxx.co.uk[xxxxxxxx]:SASL LOGIN 身份验证失败:通用失败 11 月 23 日 18:32:56 hig3 postfix/smtpd[11653]:来自 xxxxxxx.co.uk[xxxxxxx] 的 AUTH 后失去连接11 月 23 日 18:32:56 hig3 postfix/smtpd[11653]:与 xxxxxxx.co.uk[xxxxxxxx] 断开连接
这个问题很不寻常,因为就在半小时前在我的办公室,我的邮件客户端没有提示我输入正确的用户名和密码。我没有对服务器进行任何更改,因此我无法理解会发生什么导致此错误发生。
搜索错误消息会产生各种结果,其中包含我不确定的“修复”(显然不想让它变得更糟或修复未损坏的东西)。
当我跑
测试aslauthd -u xxxxx -p xxxxxx
我也得到以下结果:
connect() : 没有那个文件或目录
但是当我跑
testaslauthd -u xxxxx -p xxxxxx -f /var/spool/postfix/var/run/saslauthd/mux …
我有一个 Postfix/Dovecot 服务器并运行了大约一周,直到我不得不重新启动它。当我这样做时,事情就停止了。我已经搜索了几个小时但毫无结果。
IMAP 成功验证(尽管 dovecot 被配置为搭载 postfix 验证)。Postfix 不会,而是失败并出现以下错误:SASL authentication failure: cannot connect to saslauthd server: Permission denied
我尝试将 postfix 用户添加到 saslauth 组(不是 sasl,根据几个谷歌结果。)这并没有改变任何东西。Postfix 似乎根本没有/var/spool/postfix/var/目录(它没有/var/,/etc/或任何东西),因此/var/run/saslauthd无法修改任何权限。但是,它在重新启动之前就可以工作,所以我认为这不是问题所在。
我已在调试模式下启动 saslauthd,但它不输出任何内容。我到处搜索并尝试了我能找到的所有解决方案,但似乎没有一个有帮助。
Postfix 配置为PLAINauthLOGIN机制。saslauthd配置为使用 PAM 身份验证(更改为影子没有帮助)。
如果措辞有些不好,我深表歉意,现在是午夜 12 点,我从晚上 9:45 左右就开始处理这个问题。
鸽子会议-n:
# 2.2.13: /etc/dovecot/dovecot.conf
# OS: Linux 3.14.5-200.fc20.x86_64 x86_64 Fedora release 20 (Heisenbug)
auth_mechanisms = plain login
mail_location = maildir:~/Maildir
mbox_write_locks = fcntl
namespace inbox {
inbox = …Run Code Online (Sandbox Code Playgroud) 我有一个带有 postfix 和cyrus-sasl. 当身份验证失败时,它会在maillog下面一行中报告。
postfix/smtpd[27669]: warning: unknown[185.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Run Code Online (Sandbox Code Playgroud)
我怎样才能做到这一点,以便它也能在日志文件中报告失败的用户名(如SASL LOGIN authentication failed: authentication failure for bob)?