Re: saslauthd in squeeze requires restart once in awhile



On Sun, Dec 5, 2010 at 10:00 PM, D G Teed <donald.teed@xxxxxxxxx> wrote:

Hello,

I'm using sasl support with postfix for TLS/SSL support.
saslauthd is set for pam authentication, and this is configured
to use winbind. It all works!

Once in awhile - twice a month I think it has been - users
report logins to SMTP is failing. When I test saslauthd,
with testsaslauthd -s smtp, it fails. If I restart only saslauthd
and run the same testsaslauthd from my command line history,
it works. The test command is run local and is using authentication
which would rely on the chain of : saslauthd-> pam -> winbind .


I was looking for errors in the maillog file, but there are actually errors
in
the authentication log: auth.log

The first error is:

Dec 4 17:32:04 myhostname saslauthd[32590]: PAM unable to
dlopen(/lib/security/pam_unix.so): /lib/security/pam_unix.so: cannot open
shared object file: Too many open files

I have a feeling this is a symptom, not the cause of the problem. SMTP with
sasl
points to pam. The config at pam.d/smtp doesn't even list pam_unix ,
but the same error is showing for multiple pam modules.

--Donald


Relevant Pages

  • FreeBSD / PostFix / Sasl / PAM
    ... Postfix / SASL2 / PAM authentification. ... It seems the saslauthd is core'dumping all the time, ... user.host.com: SASL PLAIN authentication failed ...
    (freebsd-current)
  • Re: SSH to LDAP
    ... Can't seem to get the config file right. ... login I get the following error ... PAM: authentication thread exited unexpectedly ... The PAM config should be basically the same for both (mostly ...
    (comp.security.ssh)
  • Re: saslauthd, - F16 - Broken?
    ... authentication request to saslauthd but saslauthd appears to simply sit on ... I think this means that exim is passing the query to saslauthd correctly ... but saslauthd for whatever reason isn't contacting PAM properly. ... it and started it up and PAM authentication worked. ...
    (Fedora)
  • Re: OpenSSH and pam_krb5
    ... > with GSSAPI and PAM authentication. ... this data is present in a separate process (the "authentication ... application (ie sshd). ...
    (SSH)
  • Re: PHKs MD5 might not be slow enough anymore
    ... It does not disable password authentication. ... It disables the SSH ... most people *do* need PAM. ... And, just to be safe, also turn off the challenge-response ...
    (FreeBSD-Security)