Jacek Kowalski
2012-Mar-27 11:20 UTC
[Dovecot] Problem with DOVECOT - long authentication time
Hi all,
I want to start new server with Postfix (I still have qmail ) and I
think I have a problem with authentication in dovecot - it takes 3
seconds. Is this normal time?
My configuration:
Usernames: from MySQL
Passwords: from Active Directory
dovecot -n
# 1.1.20: /etc/dovecot.conf
# OS: Linux 2.6.18-274.7.1.el5 i686 CentOS release 5.7 (Final) ext3
log_path: /var/log/dovecot.log
protocols: pop3 pop3s imap imaps
listen: *
ssl_cert_file: /etc/pki/tls/certs/iRedMail_CA.pem
ssl_key_file: /etc/pki/tls/private/iRedMail.key
login_dir: /var/run/dovecot/login
login_executable(default): /usr/libexec/dovecot/imap-login
login_executable(imap): /usr/libexec/dovecot/imap-login
login_executable(pop3): /usr/libexec/dovecot/pop3-login
mail_uid: 500
mail_gid: 500
mail_location: maildir:/xxx/%u:INDEX=/xxx/%u
mail_executable(default): /usr/libexec/dovecot/imap
mail_executable(imap): /usr/libexec/dovecot/imap
mail_executable(pop3): /usr/libexec/dovecot/pop3
mail_plugins(default): quota imap_quota zlib
mail_plugins(imap): quota imap_quota zlib
mail_plugins(pop3): quota zlib
mail_plugin_dir(default): /usr/lib/dovecot/imap
mail_plugin_dir(imap): /usr/lib/dovecot/imap
mail_plugin_dir(pop3): /usr/lib/dovecot/pop3
lda:
postmaster_address: postmaster at domain.com
mail_plugins: cmusieve quota
log_path: /var/log/sieve.log
auth default:
mechanisms: plain login
default_realm: infor.pl
username_format: %Lu
debug: yes
debug_passwords: yes
passdb:
driver: pam
passdb:
driver: sql
args: /etc/dovecot-ldap.conf
userdb:
driver: sql
args: /etc/dovecot-mysql.conf
socket:
type: listen
client:
path: /var/spool/postfix/dovecot-auth
mode: 438
user: postfix
group: postfix
master:
path: /var/run/dovecot/auth-master
mode: 438
user: vmail
group: vmail
plugin:
quota_warning: storage=85%% /usr/local/bin/dovecot-quota-warning.sh 85
quota_warning2: storage=90%% /usr/local/bin/dovecot-quota-warning.sh 90
quota_warning3: storage=95%% /usr/local/bin/dovecot-quota-warning.sh 95
quota: maildir
quota_rule: *:storage=300M
quota_rule2: *:messages=0
expire: Trash 7 Trash/* 7 Junk 30
expire_dict: proxy::expire
auth_socket_path: /var/run/dovecot/auth-master
sieve: /xxx/sieve/%Ld/%Ln/dovecot.sieve
dict:
expire: db:/xxx/expire.db
grep -v '^ *\(#.*\)\?$' dovecot-mysql.conf
driver = mysql
default_pass_scheme = CRYPT
connect = host=localhost dbname=xxx user=xxx password=xxx
#password_query = SELECT password FROM mailbox WHERE username='%u' AND
active='1'
user_query = SELECT CONCAT(storagebasedirectory, '/', storagenode,
'/',
maildir) AS home, CONCAT('*:bytes=', quota*1048576) AS quota_rule FROM
mailbox WHERE username='%u' AND active='1' AND
enable%Ls%Lc='1'
postfix: postfix-2.5.9-5.ired
dovecot: dovecot-1.1.20-1_98.el5
mysql: mysql-server-5.0.77-4.el5_6.6
This is not a TCP connection problem, because i have results from
tcpdump and wireshark. There is a information that Active directory is
answering with password in 0,2 second.
Regards
Jacek
Jacek Kowalski
2012-Mar-27 11:39 UTC
[Dovecot] Problem with DOVECOT - long authentication time [SOLVED]
W dniu 27.03.2012 13:20, Jacek Kowalski pisze:> Hi all, > > I want to start new server with Postfix (I still have qmail ) and I > think I have a problem with authentication in dovecot - it takes 3 > seconds. Is this normal time? > > My configuration: > Usernames: from MySQL > Passwords: from Active Directory > > > dovecot -n > > # 1.1.20: /etc/dovecot.conf > # OS: Linux 2.6.18-274.7.1.el5 i686 CentOS release 5.7 (Final) ext3 > log_path: /var/log/dovecot.log > protocols: pop3 pop3s imap imaps > listen: * > ssl_cert_file: /etc/pki/tls/certs/iRedMail_CA.pem > ssl_key_file: /etc/pki/tls/private/iRedMail.key > login_dir: /var/run/dovecot/login > login_executable(default): /usr/libexec/dovecot/imap-login > login_executable(imap): /usr/libexec/dovecot/imap-login > login_executable(pop3): /usr/libexec/dovecot/pop3-login > mail_uid: 500 > mail_gid: 500 > mail_location: maildir:/xxx/%u:INDEX=/xxx/%u > mail_executable(default): /usr/libexec/dovecot/imap > mail_executable(imap): /usr/libexec/dovecot/imap > mail_executable(pop3): /usr/libexec/dovecot/pop3 > mail_plugins(default): quota imap_quota zlib > mail_plugins(imap): quota imap_quota zlib > mail_plugins(pop3): quota zlib > mail_plugin_dir(default): /usr/lib/dovecot/imap > mail_plugin_dir(imap): /usr/lib/dovecot/imap > mail_plugin_dir(pop3): /usr/lib/dovecot/pop3 > lda: > postmaster_address: postmaster at domain.com > mail_plugins: cmusieve quota > log_path: /var/log/sieve.log > auth default: > mechanisms: plain login > default_realm: infor.pl > username_format: %Lu > debug: yes > debug_passwords: yes > passdb: > driver: pam > passdb: > driver: sql > args: /etc/dovecot-ldap.conf > userdb: > driver: sql > args: /etc/dovecot-mysql.conf > socket: > type: listen > client: > path: /var/spool/postfix/dovecot-auth > mode: 438 > user: postfix > group: postfix > master: > path: /var/run/dovecot/auth-master > mode: 438 > user: vmail > group: vmail > plugin: > quota_warning: storage=85%% /usr/local/bin/dovecot-quota-warning.sh 85 > quota_warning2: storage=90%% /usr/local/bin/dovecot-quota-warning.sh 90 > quota_warning3: storage=95%% /usr/local/bin/dovecot-quota-warning.sh 95 > quota: maildir > quota_rule: *:storage=300M > quota_rule2: *:messages=0 > expire: Trash 7 Trash/* 7 Junk 30 > expire_dict: proxy::expire > auth_socket_path: /var/run/dovecot/auth-master > sieve: /xxx/sieve/%Ld/%Ln/dovecot.sieve > dict: > expire: db:/xxx/expire.db > > > > grep -v '^ *\(#.*\)\?$' dovecot-mysql.conf > > driver = mysql > default_pass_scheme = CRYPT > connect = host=localhost dbname=xxx user=xxx password=xxx > #password_query = SELECT password FROM mailbox WHERE username='%u' AND > active='1' > user_query = SELECT CONCAT(storagebasedirectory, '/', storagenode, > '/', maildir) AS home, CONCAT('*:bytes=', quota*1048576) AS quota_rule > FROM mailbox WHERE username='%u' AND active='1' AND enable%Ls%Lc='1' > > > postfix: postfix-2.5.9-5.ired > dovecot: dovecot-1.1.20-1_98.el5 > mysql: mysql-server-5.0.77-4.el5_6.6 > > > > This is not a TCP connection problem, because i have results from > tcpdump and wireshark. There is a information that Active directory is > answering with password in 0,2 second. > > > Regards > > JacekOk. Problem Solved. It was "passdb pam" problem. Regards Jacek