Index: [Article Count Order] [Thread]

Date:  Thu, 01 Mar 2007 08:39:14 +1100
From:  Greg Kuhnert <greg.kuhnert (at mark) theanchoragesylvania.com>
Subject:  [coba-e:08962] Re: Dovecot problems
To:  coba-e (at mark) bluequartz.org
Message-Id:  <45E5F682.5010103 (at mark) theanchoragesylvania.com>
In-Reply-To:  <45C07915.20909 (at mark) enavn.com>
References:  <054101c69921$4ad0b480$0301a8c0 (at mark) Jerrycp>	 <04a101c6992b$b33c8850$0e00a8c0 (at mark) office.swiftinter.net>	 <455ADFDB.8020803 (at mark) enavn.com> <45BF3255.1080803 (at mark) enavn.com> <b0dc50f60701300706g361a6fcs6aec1302fa7e2ec1 (at mark) mail.gmail.com> <45C07915.20909 (at mark) enavn.com>
X-Mail-Count: 08962

What is more concerning than your customers downloading email during the 
normal course of events, is someone doing a dictionary attack against 
your pop/imap server. Over the last few weeks, I have had my server 
brought to its knees a few times. I am currently running the script 
recently posted here to restart dovecot when the number of spawned 
processes gets too high. It works, but it's ugly.

 From what I can see, the bottleneck is not in dovecot, but im PAM or in 
CODB. I started playing around and tried to login to the admin web page 
using a normal user account. This failed. I then shutdown dovecot to get 
the load and memory usage down. When it reached a reasonable level, I 
tried to re-start codb. This failed. Not sure if it was a codb bug, or 
just something still locked from pam etc.

Has anyone else started to dig into the code for the PAM module for 
codb? I tried turning on debug log messages in syslog, but didnt get 
very far.... Hints anyone?

Jes Kasper Klittum wrote:
> Marcelo Caparroz wrote:
>
>> Dovecot and qpopper go mad when there are many people downloading your
>> emails. If the CPU load is high, the problem is worse. But the basic 
>> issue
>> here is the authentification process. Looks like the BQ canīt handle 
>> many
>> pop3 connection.
>
> So are you saying it is the pam package that has a problem?
>
> Jes
>
>
>
>


-- 
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.