Re: Bug report: doveadm kick does not kick proxy sessions

Timo Sirainen via dovecot <[email protected]> Sun, 5 Jul 2026 19:27:51 +0300
Newsgroups gmane.mail.imap.dovecot
Message-ID <[email protected]>
--===============1247055839783213546==
Content-Type: multipart/alternative;
	boundary="Apple-Mail=_3D32E9D2-9440-4796-8E66-E0A3FCD85115"


--Apple-Mail=_3D32E9D2-9440-4796-8E66-E0A3FCD85115
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii

On 1. Jul 2026, at 15.11, Patrick Cernko via dovecot =
<[email protected]> wrote:
>=20
> Hi Dovecot Devs,
>=20
> I'm currently setting up Dovecot 2.4 as frontend proxy to our =
backends. The frontends simply use an LDAP attribute of the user to =
connect to the assigned IMAP backend server. That works fine so far.
>=20
> According to the documentation =
<https://doc.dovecot.org/2.4.4/core/man/doveadm-kick.1.html>, I should =
be able to disconnect a user with
>=20
> doveadm kick USERNAME
>=20
> or all sessions to a specific backend with
>=20
> doveadm kick -h BACKEND_IP
>=20
> or simply ALL sessions with
>=20
> doveadm kick '*'
>=20
> However the command reports the expected amount of connections kicked =
and exitcode 0, but all sessions stay connected. I also tried 'doveadm =
proxy kick ...' but as the the corresponding documentation states, this =
is only an alias for 'doveadm kick ...' and thus shows the same =
behavior.

Looks like kicking proxied connections works only in login processes' =
"high performance mode": =
https://doc.dovecot.org/2.4.4/core/config/login_processes.html#high-perfor=
mance-mode

I'll get it fixed for the default "high security mode" as well, =
hopefully for v2.4.5 still.


--Apple-Mail=_3D32E9D2-9440-4796-8E66-E0A3FCD85115
Content-Transfer-Encoding: 7bit
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"

   On 1. Jul 2026, at 15.11, Patrick Cernko via dovecot <[email protected]>
   wrote:

     Hi Dovecot Devs,

     I'm currently setting up Dovecot 2.4 as frontend proxy to our backends.
     The frontends simply use an LDAP attribute of the user to connect to the
     assigned IMAP backend server. That works fine so far.

     According to the documentation
     <https://doc.dovecot.org/2.4.4/core/man/doveadm-kick.1.html>, I should
     be able to disconnect a user with

     doveadm kick USERNAME

     or all sessions to a specific backend with

     doveadm kick -h BACKEND_IP

     or simply ALL sessions with

     doveadm kick '*'

     However the command reports the expected amount of connections kicked
     and exitcode 0, but all sessions stay connected. I also tried 'doveadm
     proxy kick ...' but as the the corresponding documentation states, this
     is only an alias for 'doveadm kick ...' and thus shows the same
     behavior.

   Looks like kicking proxied connections works only in login processes'
   "high performance
   mode": [1]https://doc.dovecot.org/2.4.4/core/config/login_processes.html#high-performance-mode
   I'll get it fixed for the default "high security mode" as well, hopefully
   for v2.4.5 still.

References

   Visible links
   1. https://doc.dovecot.org/2.4.4/core/config/login_processes.html#high-performance-mode

--Apple-Mail=_3D32E9D2-9440-4796-8E66-E0A3FCD85115--

--===============1247055839783213546==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
dovecot mailing list -- [email protected]
To unsubscribe send an email to [email protected]

--===============1247055839783213546==--