标签: saslauthd

POSTFIX 致命:没有 SASL 身份验证机制

我在上面的错误中挣扎了 5 个多小时。我曾尝试完全删除 Postfix,并按照下一个手册和SASL 手册的说明重新安装它。

当我尝试使用 telnet 登录时,服务器阻止了登录,我得到了这个:(使用 smtpd -v 更详细):

postfix/smtpd[26301]:xsasl_cyrus_server_create:SASL 服务=smtp,领域=(空)  
postfix/smtpd[26301]: name_mask: noanonymous  
postfix/smtpd[26301]:警告:xsasl_cyrus_server_get_mechanism_list:没有适用的 SASL 机制  
postfix/smtpd[26301]:致命:没有 SASL 身份验证机制  

以下是结果postconf -n:

alias_database = hash:/etc/aliases
alias_maps = hash:/etc/aliases
allow_percent_hack = 否
append_dot_mydomain = 否
比夫 = 否
broken_sasl_auth_clients = 是
config_directory = /etc/postfix
home_mailbox = Maildir/
inet_interfaces = 全部
邮箱命令 = /usr/bin/procmail-wrapper -o -a $DOMAIN -d $LOGNAME
邮箱大小限制 = 0
mydestination = theflipapp.com, localhost.com, , localhost
myhostname = theflipapp.com
我的网络 = 127.0.0.0/8 …

postfix saslauthd smtp-auth sasl

30
推荐指数
3
解决办法
8万
查看次数

如何让 SASL 身份验证与 DIGEST-MD5 一起用于 OpenLDAP?

我正在slapdUbuntu 14.04 Trusty Tahr 上设置 OpenLDAP 。我希望某些不是用户的实例(复制等)能够通过SASL使用DIGEST-MD5机制登录。

与用户不同,他们不应该在目录树中具有相应的 DN(以及密码)。相反,他们的凭据应该存储在外部,因此SASL.

我现在正在使用saslauthd(例如,如果可以直接访问 sasldb,这不是硬性要求)并且它使用机制工作正常PLAIN,LOGIN而使用机制DIGEST-MD5和CRAM-MD5.

我错过了什么或做错了什么?我怎样才能让它工作DIGEST-MD5?


OpenLDAP的配置为SASL在/etc/ldap/sasl2/slapd.conf这样的:

mech_list: EXTERNAL DIGEST-MD5 CRAM-MD5 PLAIN LOGIN
pwcheck_method: saslauthd
saslauthd_path: /var/run/saslauthd/mux
Run Code Online (Sandbox Code Playgroud)


有趣的(改变的)选项/etc/default/saslauthd是:

START=yes
MECHANISMS="sasldb"
Run Code Online (Sandbox Code Playgroud)

它们导致saslauthd像这样启动:

/usr/sbin/saslauthd -a sasldb -c -m /var/run/saslauthd -n 5
Run Code Online (Sandbox Code Playgroud)


我用DIGEST-MD5这样的方式重现失败的案例:

# ldapsearch -U replication -ZZ -Y DIGEST-MD5 -H ldap://ldap-master.example.com/ -b "dc=example,dc=com" "(objectClass=*)" …
Run Code Online (Sandbox Code Playgroud)

openldap ldap saslauthd sasl

10
推荐指数
1
解决办法
1万
查看次数

CentOS 7 上的 Postfix 无法针对 cyrus saslauthd 进行身份验证

Postfix 无法对 cyrus saslauthd 进行身份验证。但是,saslauthd 本身愿意进行身份验证。我错过了什么?

从系统日志mail设施:

Aug  5 14:47:26 centos7-msa-test postfix/postfix-script[20286]: starting the Postfix mail system
Aug  5 14:47:26 centos7-msa-test postfix/master[20288]: daemon started -- version 2.10.1, configuration /etc/postfix
Aug  5 14:47:34 centos7-msa-test postfix/submission/smtpd[20291]: connect from client.example.com[192.0.2.2]
Aug  5 14:47:34 centos7-msa-test postfix/submission/smtpd[20291]: Anonymous TLS connection established from client.example.com[192.0.2.2]: TLSv1 with cipher ECDHE-RSA-AES128-SHA (128/128 bits
Aug  5 14:47:34 centos7-msa-test postfix/submission/smtpd[20291]: warning: SASL authentication failure: Internal Error -4 in server.c near line 1757
Aug  5 14:47:34 centos7-msa-test postfix/submission/smtpd[20291]: warning: SASL …
Run Code Online (Sandbox Code Playgroud)

postfix centos saslauthd

9
推荐指数
1
解决办法
1万
查看次数

Postfix + sasl 方法 rimap 从用户那里剥离域名

我正在使用 Postfix 和 Courier-IMAP 设置邮件服务器。我想使用 rimap 进行 SMTP 身份验证,这样我就不必维护两个用户数据库。我遇到的问题是,用户名后缀传递的域名被剥离了。它应该是“john@domain.com”,然后变成“john”。

登录 IMAP 服务器有效,testsaslauthd -u john@domain.com -p password.

使用smtpd_sasl_local_domain(设置或取消设置)没有区别。

这个帖子好像不行。即使我尝试使用 uasdfer@asdfasdf 登录,它也会剥离域部分。

后缀 sasl:

# cat main.cf |grep -i sasl
smtpd_sasl_auth_enable = yes
smtpd_sasl_security_options = noanonymous
broken_sasl_auth_clients = yes
smtpd_recipient_restrictions = permit_mynetworks permit_sasl_authenticated reject_unauth_destination reject_rbl_client zen.spamhaus.org check_policy_service unix:private/policyd-spf
Run Code Online (Sandbox Code Playgroud)

萨尔配置:

# cat saslauthd |grep -v "#"|grep -v -E "^$"
START=yes
DESC="SASL Authentication Daemon"
NAME="saslauthd"
MECHANISMS="rimap"
MECH_OPTIONS="127.0.0.1"
THREADS=5
OPTIONS="-c -m /var/run/saslauthd"
Run Code Online (Sandbox Code Playgroud)

服务器版本:

  • Debian 6.0.7
  • Postfix 2.7.1-1+squeeze1
  • 快递 4.8.0-3

postfix saslauthd sasl

8
推荐指数
1
解决办法
3681
查看次数

如何配置我的 postfix 服务器,以便 reject_sender_login_mismatch 不会阻止主帐户的别名?

我最近使用 iRedMail 设置了 postfix、dovecot、amavis 和一套其他工具,但我很难对我的外发邮件服务器进行身份验证。

问题是这样的:

xyz@mydomain.com 是 abc@mydomain.com 的别名。我使用 abc@mydomain.com 进行身份验证,因为那是邮箱,但我实际上是从别名发送的。

这是会话的示例:

EHLO mydomain.com
250-mx1.mymailserver.net
250-PIPELINING
250-SIZE 45728640
250-ETRN
250-STARTTLS
250-AUTH PLAIN LOGIN
250-AUTH=PLAIN LOGIN
250-ENHANCEDSTATUSCODES
250-8BITMIME
250 DSN
auth plain amlta0BhbHRlcm5hdGl2ZXJlYWxpdHkuY29tAGppbWtAY=
235 2.7.0 Authentication successful
MAIL FROM: xyz@alternativereality.com
250 2.1.0 Ok
RCPT TO: joe@gmail.com
553 5.7.1 <xyz@mydomain.com>: Sender address rejected: not owned by user abc@mydomain.com
QUIT
Run Code Online (Sandbox Code Playgroud)

这是 postfix 的 main.cf 的相关部分:

smtpd_sender_restrictions = permit_mynetworks, reject_sender_login_mismatch, permit_sasl_authenticated
Run Code Online (Sandbox Code Playgroud)

显然reject_sender_login_mismatch是问题所在。我实际上更愿意保留此功能但支持别名。

这可以做到吗,和/或有没有办法作为别名进行身份验证?

提前致谢!

smtp postfix authentication saslauthd

6
推荐指数
1
解决办法
8964
查看次数

saslauthd 使用太多内存

今天醒来发现我的网站缓慢/无响应。向上拉,看起来大量 saslauthd 进程已经启动,每个进程使用大约 64m 的 RAM,导致机器进入交换空间。我从来没有见过这么多用在那里。

top - 16:54:13 up 85 days, 11:48,  1 user,  load average: 0.32, 0.50, 0.38
Tasks: 143 total,   1 running, 142 sleeping,   0 stopped,   0 zombie
Cpu(s):  0.7%us,  0.3%sy,  0.0%ni, 97.3%id,  0.2%wa,  0.0%hi,  0.0%si,  1.4%st
Mem:   1048796k total,  1025904k used,    22892k free,    14032k buffers
Swap:  2097144k total,   332460k used,  1764684k free,   194348k cached

  PID USER      PR  NI  VIRT  RES  SHR S %CPU %MEM    TIME+  COMMAND                                                                                  
  848 admin     20   0  263m 115m 4840 S    0 11.3 …
Run Code Online (Sandbox Code Playgroud)

email-server postfix saslauthd

6
推荐指数
2
解决办法
4551
查看次数

在 debian 上使用 ldapdb 的 Saslauth

我正在尝试让 saslauthd 与 openldap 一起工作。

ldapsearch 和连接到 openldap 的每个服务都可以正常工作。sasldblistusers2 不起作用 - ldapwhoami 也不起作用。

getent passwd 也可以正常工作。

sasldblistusers2 生成此日志条目:

Sep 30 03:48:01 sogo sasldblistusers2: _sasl_plugin_load failed on sasl_auxprop_plug_init for plugin: ldapdb
Sep 30 03:48:01 sogo sasldblistusers2: canonuserfunc error -7
Sep 30 03:48:01 sogo sasldblistusers2: _sasl_plugin_load failed on sasl_canonuser_init for plugin: ldapdb
Sep 30 03:48:01 sogo sasldblistusers2: DIGEST-MD5 common mech free
Run Code Online (Sandbox Code Playgroud)

ldapwhoami 结果:

root@sogo:/root# ldapwhoami
SASL/DIGEST-MD5 authentication started
Please enter your password:
ldap_sasl_interactive_bind_s: Invalid credentials (49)
        additional info: SASL(-13): user not found: …
Run Code Online (Sandbox Code Playgroud)

openldap saslauthd sasl

6
推荐指数
1
解决办法
6077
查看次数

saslauthd 身份验证错误

我的服务器出现了预期问题,我无法从邮件客户端进行连接。

我查看了服务器日志,唯一可以确定问题的是以下事件:

Nov 23 18:32:43 hig3 dovecot: imap-login: Login: user=, method=PLAIN, rip=xxxxxxxx, lip=xxxxxxxx, TLS Nov 23 18:32:55 hig3 postfix/smtpd[11653]: connect from xxxxxxx .co.uk[xxxxxxx] Nov 23 18:32:55 hig3 postfix/smtpd[11653]:警告:SASL 认证失败:无法连接到 saslauthd 服务器:没有这样的文件或目录 11 月 23 日 18:32:55 hig3 postfix/smtpd [11653]:警告:xxxxxxx.co.uk[xxxxxxxx]:SASL LOGIN 身份验证失败:通用失败 11 月 23 日 18:32:56 hig3 postfix/smtpd[11653]:来自 xxxxxxx.co.uk[xxxxxxx] 的 AUTH 后失去连接11 月 23 日 18:32:56 hig3 postfix/smtpd[11653]:与 xxxxxxx.co.uk[xxxxxxxx] 断开连接

这个问题很不寻常,因为就在半小时前在我的办公室,我的邮件客户端没有提示我输入正确的用户名和密码。我没有对服务器进行任何更改,因此我无法理解会发生什么导致此错误发生。

搜索错误消息会产生各种结果,其中包含我不确定的“修复”(显然不想让它变得更糟或修复未损坏的东西)。

当我跑

测试aslauthd -u xxxxx -p xxxxxx

我也得到以下结果:

connect() : 没有那个文件或目录

但是当我跑

testaslauthd -u xxxxx -p xxxxxx -f /var/spool/postfix/var/run/saslauthd/mux …

email postfix saslauthd sasl ubuntu-10.04

6
推荐指数
2
解决办法
2万
查看次数

后缀:SASL 身份验证失败:无法连接到 saslauthd 服务器:权限被拒绝

我有一个 Postfix/Dovecot 服务器并运行了大约一周,直到我不得不重新启动它。当我这样做时,事情就停止了。我已经搜索了几个小时但毫无结果。

IMAP 成功验证(尽管 dovecot 被配置为搭载 postfix 验证)。Postfix 不会,而是失败并出现以下错误:SASL authentication failure: cannot connect to saslauthd server: Permission denied

我尝试将 postfix 用户添加到 saslauth 组(不是 sasl,根据几个谷歌结果。)这并没有改变任何东西。Postfix 似乎根本没有/var/spool/postfix/var/目录(它没有/var/,/etc/或任何东西),因此/var/run/saslauthd无法修改任何权限。但是,它在重新启动之前就可以工作,所以我认为这不是问题所在。

我已在调试模式下启动 saslauthd,但它不输出任何内容。我到处搜索并尝试了我能找到的所有解决方案,但似乎没有一个有帮助。

Postfix 配置为PLAINauthLOGIN机制。saslauthd配置为使用 PAM 身份验证(更改为影子没有帮助)。

如果措辞有些不好,我深表歉意,现在是午夜 12 点,我从晚上 9:45 左右就开始处理这个问题。

鸽子会议-n:

# 2.2.13: /etc/dovecot/dovecot.conf
# OS: Linux 3.14.5-200.fc20.x86_64 x86_64 Fedora release 20 (Heisenbug)
auth_mechanisms = plain login
mail_location = maildir:~/Maildir
mbox_write_locks = fcntl
namespace inbox {
  inbox = …
Run Code Online (Sandbox Code Playgroud)

postfix saslauthd dovecot sasl

6
推荐指数
2
解决办法
2万
查看次数

当 SASL 身份验证失败时,在邮件日志中记录用户名

我有一个带有 postfix 和cyrus-sasl. 当身份验证失败时,它会在maillog下面一行中报告。

postfix/smtpd[27669]: warning: unknown[185.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Run Code Online (Sandbox Code Playgroud)

我怎样才能做到这一点,以便它也能在日志文件中报告失败的用户名(如SASL LOGIN authentication failed: authentication failure for bob)?

postfix saslauthd

5
推荐指数
1
解决办法
5793
查看次数