sasl authentication failure : cannot connect to saslauthd server : connection refused

Discuss your pilot or production implementation with other Zimbra admins or our engineers.
Post Reply
shriram.sampat
Posts: 38
Joined: Tue Nov 25, 2014 1:36 am

sasl authentication failure : cannot connect to saslauthd server : connection refused

Post by shriram.sampat »

Hello Everyone,
My zimbra is running in vsphere esxi 5.5 along with other servers and I had a server crash a few days ago due to a problem in vsphere.
After restart, smtp authentication from clients like thunderbird does not work anymore ! This is the entry in zimbra.log
Apr 2 10:48:39 mailserver postfix/submission/smtpd[23001]: warning: SASL authentication failure: cannot connect to saslauthd server: Connection refused
Apr 2 10:48:39 mailserver postfix/submission/smtpd[23001]: warning: SASL authentication failure: Password verification failed
Apr 2 10:48:39 mailserver postfix/submission/smtpd[23001]: warning: unknown[192.168.2.111]: SASL PLAIN authentication failed: generic failure
Apr 2 10:48:39 mailserver postfix/submission/smtpd[23001]: warning: SASL authentication failure: cannot connect to saslauthd server: Connection refused
Apr 2 10:48:39 mailserver postfix/submission/smtpd[23001]: warning: unknown[192.168.2.111]: SASL LOGIN authentication failed: generic failure
zmcontrol status shows all services running. I cannot find any saslauthd running.
Can anyone help me troubleshoot this problem please ?
Thanks in advance.

Ram
shriram.sampat
Posts: 38
Joined: Tue Nov 25, 2014 1:36 am

sasl authentication failure : cannot connect to saslauthd server : connection refused

Post by shriram.sampat »

Sorry forgot to give version info : Zimbra 8.5.1
shriram.sampat
Posts: 38
Joined: Tue Nov 25, 2014 1:36 am

sasl authentication failure : cannot connect to saslauthd server : connection refused

Post by shriram.sampat »

Hello Everyone,



Some more additional info



Thunderbird settings :



port : 587

connection security : starttls

authentication method : normal password

username : user@company.com



zimbra.log :





Apr 2 10:57:11 mailserver postfix/submission/smtpd[28607]: Anonymous TLS connection established from unknown[192.168.2.111]: TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)

Apr 2 10:57:11 mailserver postfix/submission/smtpd[28607]: warning: SASL authentication failure: cannot connect to saslauthd server: Connection refused

Apr 2 10:57:11 mailserver postfix/submission/smtpd[28607]: warning: SASL authentication failure: Password verification failed

Apr 2 10:57:11 mailserver postfix/submission/smtpd[28607]: warning: unknown[192.168.2.111]: SASL PLAIN authentication failed: generic failure

Apr 2 10:57:11 mailserver postfix/submission/smtpd[28607]: warning: SASL authentication failure: cannot connect to saslauthd server: Connection refused

Apr 2 10:57:11 mailserver postfix/submission/smtpd[28607]: warning: unknown[192.168.2.111]: SASL LOGIN authentication failed: generic failure



CMD >>> zmprov getServer mailserver.company.de | grep Auth

zimbraAuthTokenNotificationInterval: 60000

zimbraLowestSupportedAuthVersion: 2

zimbraMtaAuthEnabled: TRUE

zimbraMtaAuthHost: mailserver.company.de

zimbraMtaAuthTarget: TRUE

zimbraMtaAuthURL: https://mailserver.company.de:443/service/soap/

zimbraMtaBrokenSaslAuthClients: yes

zimbraMtaSaslAuthEnable: yes

zimbraMtaSmtpSaslAuthEnable: yes

zimbraMtaSmtpdSaslAuthenticatedHeader: no

zimbraMtaTlsAuthOnly: TRUE

zimbraShareNotificationMtaAuthRequired: FALSE



Any pointers greatly appreciated.



Thanks.



Ram
User avatar
jorgedlcruz
Zimbra Alumni
Zimbra Alumni
Posts: 2782
Joined: Thu May 22, 2014 4:47 pm

sasl authentication failure : cannot connect to saslauthd server : connection refused

Post by jorgedlcruz »

Can you please share with us a screenshot of how you have configured your SMTP part in Thunderbird?



Best regards
Jorge de la Cruz https://jorgedelacruz.es
Systems Engineer at Veeam Software https://www.veeam.com/
User avatar
jorgedlcruz
Zimbra Alumni
Zimbra Alumni
Posts: 2782
Joined: Thu May 22, 2014 4:47 pm

sasl authentication failure : cannot connect to saslauthd server : connection refused

Post by jorgedlcruz »

Can you try like root user
/opt/zimbra/libexec/zmfixperms -extended
And then like Zimbra user
zmcontrol restart
And let us know?
Jorge de la Cruz https://jorgedelacruz.es
Systems Engineer at Veeam Software https://www.veeam.com/
shriram.sampat
Posts: 38
Joined: Tue Nov 25, 2014 1:36 am

sasl authentication failure : cannot connect to saslauthd server : connection refused

Post by shriram.sampat »

Thanks a lot Jorge de la Cruz,



This worked :)



Ram
User avatar
jorgedlcruz
Zimbra Alumni
Zimbra Alumni
Posts: 2782
Joined: Thu May 22, 2014 4:47 pm

sasl authentication failure : cannot connect to saslauthd server : connection refused

Post by jorgedlcruz »

Glad to hear Shriram,



Best regards
Jorge de la Cruz https://jorgedelacruz.es
Systems Engineer at Veeam Software https://www.veeam.com/
lamei
Posts: 1
Joined: Tue May 25, 2021 5:45 pm

Re: sasl authentication failure : cannot connect to saslauthd server : connection refused

Post by lamei »

same problem:

SASL authentication failure: cannot connect to saslauthd server: Permission denied (per zimbra log)

zimbra 8.8.12

Just moved from Ubuntu 14.04 to 16.04 (yeah I know we need to move it to 20, but one at a time) worked well on 14.04

Many things didn't work initially on 16 but now working.

Server won't send Mail is remaining issue::

names (ips, encoded anything) have been changed to protect the guilty

Looking for any thoughts or suggestions (zmfixperms didin't solve). It's gotta be simple. I already feel stupid.

zmprov

zimbraAuthTokenNotificationInterval: 60000
zimbraLowestSupportedAuthVersion: 2
zimbraMtaAuthEnabled: TRUE
zimbraMtaAuthHost: smtp.waccado.net
zimbraMtaAuthPort: 7073
zimbraMtaAuthTarget: TRUE
zimbraMtaBrokenSaslAuthClients: yes
zimbraMtaSaslAuthEnable: yes
zimbraMtaSmtpSaslAuthEnable: yes
zimbraMtaSmtpdClientAuthRateLimit: 0
zimbraMtaSmtpdSaslAuthenticatedHeader: no
zimbraMtaTlsAuthOnly: TRUE
zimbraShareNotificationMtaAuthRequired: FALSE

relavant zimbra.log (single instance)

May 25 15:58:42 server postfix/smtp[22977]: smtp_stream_setup: maxtime=300 enable_deadline=0
May 25 15:58:42 server postfix/smtp[22977]: vstream_buf_get_ready: fd 16 got 39
May 25 15:58:42 server postfix/smtp[22977]: < smtp.waccado.net[170.21.75.4]:587: 220 server.wackado.net ESMTP Postfix
May 25 15:58:42 server postfix/smtp[22977]: > smtp.waccado.net[170.21.75.4]:587: EHLO server.wackado.net
May 25 15:58:42 server postfix/smtp[22977]: vstream_fflush_some: fd 16 flush 26
May 25 15:58:42 server postfix/smtp[22977]: vstream_buf_get_ready: fd 16 got 142
May 25 15:58:42 server postfix/smtp[22977]: < smtp.waccado.net[170.21.75.4]:587: 250-server.wackado.net
May 25 15:58:42 server postfix/smtp[22977]: < smtp.waccado.net[170.21.75.4]:587: 250-PIPELINING
May 25 15:58:42 server postfix/smtp[22977]: < smtp.waccado.net[170.21.75.4]:587: 250-SIZE 50000000
May 25 15:58:42 server postfix/smtp[22977]: < smtp.waccado.net[170.21.75.4]:587: 250-VRFY
May 25 15:58:42 server postfix/smtp[22977]: < smtp.waccado.net[170.21.75.4]:587: 250-ETRN
May 25 15:58:42 server postfix/smtp[22977]: < smtp.waccado.net[170.21.75.4]:587: 250-STARTTLS
May 25 15:58:42 server postfix/smtp[22977]: < smtp.waccado.net[170.21.75.4]:587: 250-ENHANCEDSTATUSCODES
May 25 15:58:42 server postfix/smtp[22977]: < smtp.waccado.net[170.21.75.4]:587: 250-8BITMIME
May 25 15:58:42 server postfix/smtp[22977]: < smtp.waccado.net[170.21.75.4]:587: 250 DSN
May 25 15:58:42 server postfix/smtp[22977]: server features: 0x901f size 50000000
May 25 15:58:42 server postfix/smtp[22977]: Using ESMTP PIPELINING, TCP send buffer size is 2626560, PIPELINING buffer size is 4096
May 25 15:58:42 server postfix/smtp[22977]: smtp_stream_setup: maxtime=300 enable_deadline=0
May 25 15:58:42 server postfix/smtp[22977]: > smtp.waccado.net[170.21.75.4]:587: STARTTLS
May 25 15:58:42 server postfix/smtp[22977]: vstream_fflush_some: fd 16 flush 10
May 25 15:58:42 server postfix/smtp[22977]: vstream_buf_get_ready: fd 16 got 30
May 25 15:58:42 server postfix/smtp[22977]: < smtp.waccado.net[170.21.75.4]:587: 220 2.0.0 Ready to start TLS
May 25 15:58:42 server postfix/smtp[22977]: event_request_timer: reset 0x43ba50 0x15e6890 5
May 25 15:58:42 server postfix/smtp[22977]: send attr request = seed
May 25 15:58:42 server postfix/smtp[22977]: send attr size = 32
May 25 15:58:42 server postfix/smtp[22977]: vstream_fflush_some: fd 10 flush 22
May 25 15:58:42 server postfix/smtp[22977]: vstream_buf_get_ready: fd 10 got 60
May 25 15:58:42 server postfix/smtp[22977]: private/tlsmgr: wanted attribute: status
May 25 15:58:42 server postfix/smtp[22977]: input attribute name: status
May 25 15:58:42 server postfix/smtp[22977]: input attribute value: 0
May 25 15:58:42 server postfix/smtp[22977]: private/tlsmgr: wanted attribute: seed
May 25 15:58:42 server postfix/smtp[22977]: input attribute name: seed
May 25 15:58:42 server postfix/smtp[22977]: input attribute value: lHRBrk4Q6mLz+2CpgAXlMWwDxy+XVBxOmPbCRDWoXYk=
May 25 15:58:42 server postfix/smtp[22977]: private/tlsmgr: wanted attribute: (list terminator)
May 25 15:58:42 server postfix/smtp[22977]: input attribute name: (end)
May 25 15:58:42 server postfix/smtp[22977]: smtp_stream_setup: maxtime=300 enable_deadline=0
May 25 15:58:42 server postfix/smtp[22977]: > smtp.waccado.net[170.21.75.4]:587: EHLO server.wackado.net
May 25 15:58:42 server postfix/smtp[22977]: vstream_fflush_some: fd 16 flush 26
May 25 15:58:42 server postfix/smtp[22977]: vstream_buf_get_ready: fd 16 got 160
May 25 15:58:42 server postfix/smtp[22977]: < smtp.waccado.net[170.21.75.4]:587: 250-server.wackado.net
May 25 15:58:42 server postfix/smtp[22977]: < smtp.waccado.net[170.21.75.4]:587: 250-PIPELINING
May 25 15:58:42 server postfix/smtp[22977]: < smtp.waccado.net[170.21.75.4]:587: 250-SIZE 50000000
May 25 15:58:42 server postfix/smtp[22977]: < smtp.waccado.net[170.21.75.4]:587: 250-VRFY
May 25 15:58:42 server postfix/smtp[22977]: < smtp.waccado.net[170.21.75.4]:587: 250-ETRN
May 25 15:58:42 server postfix/smtp[22977]: < smtp.waccado.net[170.21.75.4]:587: 250-AUTH LOGIN
May 25 15:58:42 server postfix/smtp[22977]: < smtp.waccado.net[170.21.75.4]:587: 250-AUTH=LOGIN
May 25 15:58:42 server postfix/smtp[22977]: < smtp.waccado.net[170.21.75.4]:587: 250-ENHANCEDSTATUSCODES
May 25 15:58:42 server postfix/smtp[22977]: < smtp.waccado.net[170.21.75.4]:587: 250-8BITMIME
May 25 15:58:42 server postfix/smtp[22977]: < smtp.waccado.net[170.21.75.4]:587: 250 DSN
May 25 15:58:42 server postfix/smtp[22977]: server features: 0x902f size 50000000
May 25 15:58:42 server postfix/smtp[22977]: Using ESMTP PIPELINING, TCP send buffer size is 2626560, PIPELINING buffer size is 4096
May 25 15:58:42 server postfix/smtp[22977]: maps_find: smtp_sasl_password_maps: lmdb:/opt/zimbra/conf/relay_password(0,lock|fold_fix|utf8_request): smtp.waccado.net = wackado@wackado.net:2SDr72SDr7
May 25 15:58:42 server postfix/smtp[22977]: smtp_sasl_passwd_lookup: host `smtp.waccado.net' user `wackado@wackado.net' pass `password'
May 25 15:58:42 server postfix/smtp[22977]: starting new SASL client
May 25 15:58:42 server postfix/smtp[22977]: name_mask: noanonymous
May 25 15:58:42 server postfix/smtp[22977]: smtp_sasl_authenticate: smtp.waccado.net[170.21.75.4]:587: SASL mechanisms LOGIN
May 25 15:58:42 server postfix/smtp[22977]: > smtp.waccado.net[170.21.75.4]:587: AUTH LOGIN
May 25 15:58:42 server postfix/smtp[22977]: vstream_fflush_some: fd 16 flush 12
May 25 15:58:42 server postfix/smtp[22977]: vstream_buf_get_ready: fd 16 got 18
May 25 15:58:42 server postfix/smtp[22977]: < smtp.waccado.net[170.21.75.4]:587: 334 VXNlcm5hbWU6
May 25 15:58:42 server postfix/smtp[22977]: xsasl_cyrus_client_next: decoded challenge: Username:
May 25 15:58:42 server postfix/smtp[22977]: xsasl_cyrus_client_get_user: waccado@wackado.net
May 25 15:58:42 server postfix/smtp[22977]: xsasl_cyrus_client_get_passwd: 2SDr72SDr7
May 25 15:58:42 server postfix/smtp[22977]: xsasl_cyrus_client_next: uncoded client response waccado@wackado.net
May 25 15:58:42 server postfix/smtp[22977]: > smtp.waccado.net[170.21.75.4]:587: dmlzdGF1e1eHgubmV0
May 25 15:58:42 server postfix/smtp[22977]: vstream_fflush_some: fd 16 flush 30
May 25 15:58:42 server postfix/smtp[22977]: vstream_buf_get_ready: fd 16 got 18
May 25 15:58:42 server postfix/smtp[22977]: < smtp.waccado.net[170.21.75.4]:587: 334 UGFzc3cmQ6
May 25 15:58:42 server postfix/smtp[22977]: xsasl_cyrus_client_next: decoded challenge: Password:
May 25 15:58:42 server postfix/smtp[22977]: xsasl_cyrus_client_next: uncoded client response password
May 25 15:58:42 server postfix/smtp[22977]: > smtp.waccado.net[170.21.75.4]:587: MlNEcjcyU0RyNw==
May 25 15:58:42 server postfix/smtp[22977]: vstream_fflush_some: fd 16 flush 18
May 25 15:58:42 server postfix/smtp[22977]: vstream_buf_get_ready: fd 16 got 57
May 25 15:58:42 server postfix/smtp[22977]: < smtp.waccado.net[170.21.75.4]:587: 535 5.7.8 Error: authentication failed: generic failure
May 25 15:58:42 server postfix/smtp[22977]: connect to subsystem private/defer
May 25 15:58:42 server postfix/smtp[22977]: send attr nrequest = 0
May 25 15:58:42 server postfix/smtp[22977]: send attr flags = 0
May 25 15:58:42 server postfix/smtp[22977]: send attr queue_id = 5899DDA38B3
May 25 15:58:42 server postfix/smtp[22977]: send attr original_recipient = bennie.gov
May 25 15:58:42 server postfix/smtp[22977]: send attr recipient = bennie.gov
May 25 15:58:42 server postfix/smtp[22977]: send attr offset = 645
May 25 15:58:42 server postfix/smtp[22977]: send attr dsn_orig_rcpt = rfc822;bennie.gov
May 25 15:58:42 server postfix/smtp[22977]: send attr notify_flags = 0
May 25 15:58:42 server postfix/smtp[22977]: send attr status = 4.7.8
May 25 15:58:42 server postfix/smtp[22977]: send attr diag_type = smtp
May 25 15:58:42 server postfix/smtp[22977]: send attr diag_text = 535 5.7.8 Error: authentication failed: generic failure
May 25 15:58:42 server postfix/smtp[22977]: send attr mta_type = dns
May 25 15:58:42 server postfix/smtp[22977]: send attr mta_mname = smtp.waccado.net
May 25 15:58:42 server postfix/smtp[22977]: send attr action = delayed
May 25 15:58:42 server postfix/smtp[22977]: send attr reason = SASL authentication failed; server smtp.waccado.net[170.21.75.4] said: 535 5.7.8 Error: authentication failed: generic failure
May 25 15:58:42 server postfix/smtp[22977]: vstream_fflush_some: fd 17 flush 495
May 25 15:58:42 server postfix/smtp[22977]: vstream_buf_get_ready: fd 17 got 10
May 25 15:58:42 server postfix/smtp[22977]: private/defer socket: wanted attribute: status
May 25 15:58:42 server postfix/smtp[22977]: input attribute name: status
May 25 15:58:42 server postfix/smtp[22977]: input attribute value: 0
May 25 15:58:42 server postfix/smtp[22977]: private/defer socket: wanted attribute: (list terminator)
May 25 15:58:42 server postfix/smtp[22977]: input attribute name: (end)
May 25 15:58:42 server postfix/smtp[22977]: 5899DDA38B3: to=<bennie.gov>, relay=smtp.waccado.net[170.21.75.4]:587, delay=0.04, delays=0.01/0.01/0.01/0, dsn=4.7.8, status=deferred (SASL authentication failed; server smtp.wackado.net[170.21.75.4] said: 535 5.7.8 Error: authentication failed: generic failure)
May 25 15:58:42 server postfix/smtp[22977]: flush_add: site USPTO.gov id 5899DDA38B3
May 25 15:58:42 server postfix/smtp[22977]: match_list_match: USPTO.gov: no match
May 25 15:58:42 server postfix/smtp[22977]: flush_add: site USPTO.gov id 5899DDA38B3 status 4
May 25 15:58:42 server postfix/smtp[22977]: smtp_stream_setup: maxtime=300 enable_deadline=0
May 25 15:58:42 server postfix/smtp[22977]: > smtp.waccado.net[170.21.75.4]:587: QUIT
May 25 15:58:42 server postfix/smtp[22977]: name_mask: resource
May 25 15:58:42 server postfix/smtp[22977]: name_mask: software
May 25 15:58:42 server postfix/smtp[22977]: vstream_fflush_some: fd 16 flush 6
May 25 15:58:42 server postfix/smtp[22977]: vstream_fflush_some: fd 16 flush 0
May 25 15:58:42 server postfix/smtp[22977]: disposing SASL state information
Post Reply