Symptoms

cPanel monitoring may report that Dovecot and Exim are down because service check cannot authenticate. 

 

Description

We noticed that some CURRENT/EDGE servers may report services down because of failed authentication. 
Looking at the journal logs journalctl -p err --no-pager shows lots of the following:

Dec 18 08:20:50 SERVER auth[1255525]: pam_imunify(dovecot_imunify:auth): Unknown response command from cpdoveauthd

 

We've opened an internal case for our development team to investigate this further. For reference, the case number is CPANEL-50784. Follow this article to receive an email notification when a solution is published in the product.  We have also notified the Imunify 360 team, and they are aware of this. The issue is in the dovecot-pam module and they currently recommend to go to the dovecot-native mode.

 

Workaround

Log onto WHM and go to Imunify 360, Click on the Settings (gear symbol at the top-right) and scroll down to the PAM section.  If Exim+Dovecot brute-force attack protection is enabled, disable it and save.

The services should then recover.