Issues with plain authentication mode with qmail-ldap 20120221
André Alexandre Gaio <[email protected]> Sat, 18 May 2013 22:51:07 -0300
| Newsgroups | gmane.mail.qmail.ldap |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format.
--------------020902040105070708060802
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 8bit
Hello Guys,
I'm having a problem since I started using the patch 20120221, about 1
year ago, I had not noticed yet.
The problem is as follows:
If I use the LOGIN authentication mode, everything happens normally.
This is how I configure my email clients by default.
If I set any email client PLAIN authentication mode, the login process
usually happens when the user enters the correct password, and send
email normally follows too.
But when the user misses the password at login, the qmail-smtpd process
falls with a segfault, but he usually responds well:
535 authentication failure
or
501 failed authentication exchange
It ends the session normally.
I noticed this strange behavior when a user configured mode PLAIN by
mistake in your email client instead of LOGIN so that is what standardized.
Appears in the log with LOGLEVEL=255 and DEBUGLEVEL=3:
@400000005197d6e333ee9034 tcpserver: pid 27959 from XXX.XXX.45.10
@400000005197d6e333f575d4 tcpserver: ok 27959
correio.domaindst.com.br:172.16.1.2:587
correio01.domainorig.com.br:XXX.XXX.45.10::60720
@400000005197d6e3341050d4 qmail-smtpd 27959: connection from
XXX.XXX.45.10 (correio01.domainorig.com.br) to correio.domaindst.com.br
@400000005197d6e33410c9ec qmail-smtpd 27959: enabled options: max msg
size: 55000000 starttls sanitycheck blockrelayprobe rcptcheck ldapsoftok
smtp-auth authrequired smtp550disconnect qmailqueue
/var/qmail/bin/simscan-msa
@400000005197d6ea2407f9e4 qmail-smtpd 27959: remote ehlo: domainorig.com.br
@400000005197d6f235249f34 qmail-smtpd 27959: auth plain
@400000005197d6f2353df77c init_ldap: control/ldapserver: '127.0.0.1'
@400000005197d6f2353e64dc init_ldap: control/ldapbasedn:
dc=domaindst,dc=com,dc=br
@400000005197d6f2353e68c4 init_ldap: control/ldapobjectclass: qmailUser
@400000005197d6f2353e68c4 init_ldap: control/ldaptimeout: 30
@400000005197d6f2353e6cac init_ldap: control/ldaprebind: 1
@400000005197d6f2353e6cac init_ldap: control/ldapuid: 777
@400000005197d6f2353e6cac init_ldap: control/ldapgid: 777
@400000005197d6f2353e7094 init_ldap: control/ldapmessagestore: /vmail/
@400000005197d6f2353e8bec init_ldap: control/ldapdefaultdotmode: both
@400000005197d6f2353ea35c init_ldap: control/defaultquotasize: 1024000000
@400000005197d6f2353ea35c init_ldap: control/defaultquotacount: 5000
@400000005197d6f23544d164 qldap_open: init successful
@400000005197d6f23544ecbc qldap_set_option: set referrals successful
@400000005197d6f2354d31ec qldap_bind: successful
@400000005197d6f23552044c qldap_lookup: search for
(&(objectClass=qmailUser)(uid=suporte)) succeeded
@400000005197d6f235526dc4 qldap_get_attr(accountStatus): active
@400000005197d6f23553f07c qldap_open: init successful
@400000005197d6f2355413a4 qldap_set_option: set referrals successful
@400000005197d6f2355ad61c qldap_bind: failed (Invalid credentials)
@400000005197d6f2355ada04 check_ldap: password compare was not successful
@400000005197d6f2355b919c warning: auth_fail: user suporte failed
@400000005197d6f33636c2e4 tcpserver: end 27959 status 139
This behavior does not happen with the previous patch 20060201.
Has anyone had noticed this? Or just happen to me?
My server is a Dell with Xeon E5430 2.66GHz processor with 16GB RAM and
SAS disks, the distro is a linux CentOS 6.4 with kernel default
2.6.32-358.6.1.el6.x86_64 #1 SMP.
This happens too in a small Atom D525 with 4GB RAM and Ubuntu 12.04.2
LTS with 3.2.0-32-generic x86_64 SMP kernel.
Thanks in advice and sorry by the long mail and by my bad english. :-)
--
André Alexandre Gaio
Engenheiro de redes e Suporte
RedHat RHCE - LPIC - Novell SCLA - HE IPv6 Sage
Linwork Informática Ltda
"...o que o SENHOR pede de ti: que pratiques a justiça, e ames a misericórdia, e andes humildemente com o teu Deus." Mq. 6:8
--------------020902040105070708060802
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=ISO-8859-1">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<meta http-equiv="content-type" content="text/html;
charset=ISO-8859-1">
<span id="result_box" class="" lang="en"><span class="hps">Hello</span>
<span class="hps">Guys,</span><br>
<br>
<span class="hps">I'm</span> <span class="hps">having a problem</span>
<span class="hps">since I</span> <span class="hps">started using</span>
<span class="hps">the patch</span> <span class="hps">20120221</span><span>,</span>
<span class="hps">about 1 year</span> <span class="hps">ago</span><span>,
I</span> <span class="hps">had not noticed</span> <span
class="hps">yet.</span><br>
<br>
<span class="hps">The problem</span> <span class="hps">is as
follows:</span><br>
<br>
<span class="hps">If I</span> <span class="hps">use the</span> <span
class="hps">LOGIN</span> <span class="hps">authentication</span>
<span class="hps">mode</span><span>,</span> <span class="hps">everything
happens</span> <span class="hps">normally.</span> <span
class="hps">This</span> <span class="hps">is</span> <span
class="hps">how</span> <span class="hps">I configure</span> <span
class="hps">my</span> <span class="hps">email clients</span> <span
class="hps">by default</span><span>.</span><br>
<br>
<span class="hps">If I set</span> <span class="hps">any</span> <span
class="hps">email client</span> <span class="hps">PLAIN</span>
<span class="hps">authentication mode</span><span>,</span> <span
class="hps">the login process</span> <span class="hps">usually
happens when</span> <span class="hps">the user enters</span> <span
class="hps">the correct</span> <span class="hps">password, and</span>
<span class="hps">send</span> <span class="hps">email</span> <span
class="hps">normally follows</span> <span class="hps">too.</span><br>
<br>
<span class="hps">But when</span> <span class="hps">the user</span>
<span class="hps">misses</span> <span class="hps">the password</span>
<span class="hps">at login</span><span>,</span> <span class="hps">the</span>
<span class="hps">qmail</span><span class="atn">-</span><span>smtpd</span>
<span class="hps">process</span> <span class="hps">falls</span> <span
class="hps">with a</span> <span class="hps">segfault</span><span>,</span>
<span class="hps">but he</span> <span class="hps">usually</span>
<span class="hps">responds</span> <span class="hps">well</span><span>:</span><br>
<br>
<span class="hps">535</span> <span class="hps">authentication</span>
<span class="hps">failure</span><br>
<span class="hps">or</span><br>
<span class="hps">501</span> <span class="hps">failed</span> <span
class="hps">authentication</span> <span class="hps">exchange</span><br>
<br>
<span class="hps">It ends</span> <span class="hps">the session</span>
<span class="hps">normally.</span><br>
<br>
<span class="hps">I noticed</span> <span class="hps">this</span>
<span class="hps">strange behavior</span> <span class="hps">when
a user</span> <span class="hps">configured</span> <span
class="hps">mode</span> <span class="hps">PLAIN</span> <span
class="hps">by mistake</span> <span class="hps">in</span> <span
class="hps">your email client</span> <span class="hps">instead
of</span> <span class="hps">LOGIN</span> <span class="hps">so</span>
<span class="hps">that</span> <span class="hps">is what</span> <span
class="hps">standardized</span><span>.</span><br>
<br>
<span class="hps">Appears</span> <span class="hps">in the log
with LOGLEVEL=255 and DEBUGLEVEL=3</span><span>:</span></span><br>
<br>
@400000005197d6e333ee9034 tcpserver: pid 27959 from XXX.XXX.45.10<br>
@400000005197d6e333f575d4 tcpserver: ok 27959
correio.domaindst.com.br:172.16.1.2:587
correio01.domainorig.com.br:XXX.XXX.45.10::60720<br>
@400000005197d6e3341050d4 qmail-smtpd 27959: connection from
XXX.XXX.45.10 (correio01.domainorig.com.br) to
correio.domaindst.com.br<br>
@400000005197d6e33410c9ec qmail-smtpd 27959: enabled options: max
msg size: 55000000 starttls sanitycheck blockrelayprobe rcptcheck
ldapsoftok smtp-auth authrequired smtp550disconnect qmailqueue
/var/qmail/bin/simscan-msa<br>
@400000005197d6ea2407f9e4 qmail-smtpd 27959: remote ehlo:
domainorig.com.br<br>
@400000005197d6f235249f34 qmail-smtpd 27959: auth plain<br>
@400000005197d6f2353df77c init_ldap: control/ldapserver: '127.0.0.1'<br>
@400000005197d6f2353e64dc init_ldap: control/ldapbasedn:
dc=domaindst,dc=com,dc=br<br>
@400000005197d6f2353e68c4 init_ldap: control/ldapobjectclass:
qmailUser<br>
@400000005197d6f2353e68c4 init_ldap: control/ldaptimeout: 30<br>
@400000005197d6f2353e6cac init_ldap: control/ldaprebind: 1<br>
@400000005197d6f2353e6cac init_ldap: control/ldapuid: 777<br>
@400000005197d6f2353e6cac init_ldap: control/ldapgid: 777<br>
@400000005197d6f2353e7094 init_ldap: control/ldapmessagestore:
/vmail/<br>
@400000005197d6f2353e8bec init_ldap: control/ldapdefaultdotmode:
both<br>
@400000005197d6f2353ea35c init_ldap: control/defaultquotasize:
1024000000<br>
@400000005197d6f2353ea35c init_ldap: control/defaultquotacount: 5000<br>
@400000005197d6f23544d164 qldap_open: init successful<br>
@400000005197d6f23544ecbc qldap_set_option: set referrals successful<br>
@400000005197d6f2354d31ec qldap_bind: successful<br>
@400000005197d6f23552044c qldap_lookup: search for
(&(objectClass=qmailUser)(uid=suporte)) succeeded<br>
@400000005197d6f235526dc4 qldap_get_attr(accountStatus): active<br>
@400000005197d6f23553f07c qldap_open: init successful<br>
@400000005197d6f2355413a4 qldap_set_option: set referrals successful<br>
@400000005197d6f2355ad61c qldap_bind: failed (Invalid credentials)<br>
@400000005197d6f2355ada04 check_ldap: password compare was not
successful<br>
@400000005197d6f2355b919c warning: auth_fail: user suporte failed<br>
@400000005197d6f33636c2e4 tcpserver: end 27959 status 139<br>
<span id="result_box" class="" lang="en"><br>
<span class="hps">This behavior</span> <span class="hps">does not
happen</span> <span class="hps">with the</span> <span
class="hps">previous patch</span> <span class="hps">20060201</span><span>.</span><br>
<br>
<span class="hps">Has anyone</span> <span class="hps">had noticed</span>
<span class="hps">this?</span> <span class="hps">Or</span> <span
class="hps">just happen</span> <span class="hps">to me?</span></span><br>
<br>
My server is a Dell with Xeon E5430 2.66GHz processor with 16GB RAM
and SAS disks, the distro is a linux CentOS 6.4 with kernel default
2.6.32-358.6.1.el6.x86_64 #1 SMP. <br>
This happens too in a small Atom D525 with 4GB RAM and Ubuntu
12.04.2 LTS with 3.2.0-32-generic x86_64 SMP kernel.<br>
<br>
Thanks in advice and sorry by the long mail and by my bad english.
:-)<br>
<br>
<pre class="moz-signature" cols="72">--
André Alexandre Gaio
Engenheiro de redes e Suporte
RedHat RHCE - LPIC - Novell SCLA - HE IPv6 Sage
Linwork Informática Ltda
"...o que o SENHOR pede de ti: que pratiques a justiça, e ames a misericórdia, e andes humildemente com o teu Deus." Mq. 6:8 </pre>
</body>
</html>
--------------020902040105070708060802--