Symptoms
cPanel monitoring may report that Dovecot and Exim are down because service check cannot authenticate.
Description
We noticed that some CURRENT/EDGE servers may report services down because of failed authentication.
Looking at the journal logs journalctl -p err --no-pager shows lots of the following:
Dec 18 08:20:50 SERVER auth[1255525]: pam_imunify(dovecot_imunify:auth): Unknown response command from cpdoveauthd
We've opened an internal case for our development team to investigate this further. For reference, the case number is CPANEL-50784. Follow this article to receive an email notification when a solution is published in the product. We have also notified the Imunify 360 team, and they are aware of this. The issue is in the dovecot-pam module and they currently recommend to go to the dovecot-native mode.
Workaround
Log onto WHM and go to Imunify 360, Click on the Settings (gear symbol at the top-right) and scroll down to the PAM section. If Exim+Dovecot brute-force attack protection is enabled, disable it and save.
The services should then recover.