Re: [Dovecot] Broken IMAPS Connects Create Lingering imap-login Processes

2014-05-14 Thread Jochen Bern
On 06.05.2014 19:06, Jochen Bern wrote: > On 06.05.2014 14:14, Timo Sirainen wrote: >> There was bug where a broken handshake could have caused 100% CPU >> usage. Maybe the same problem could happen in a slightly different >> way and also not cause CPU usage. >> http://hg.dovecot.org/dovecot-2.2/re

Re: [Dovecot] Broken IMAPS Connects Create Lingering imap-login Processes

2014-05-06 Thread Jochen Bern
On 06.05.2014 14:14, Timo Sirainen wrote: > On 5.5.2014, at 23.13, Jochen Bern wrote: >> The problem I'ld like to ask for help with here is that dovecot's >> imap-login process doesn't terminate when the FIN is received, or when >> the IMAP protocol's inactivity timeout is reached, it takes *more

Re: [Dovecot] Broken IMAPS Connects Create Lingering imap-login Processes

2014-05-06 Thread Timo Sirainen
On 5.5.2014, at 23.13, Jochen Bern wrote: > we are running a central server (CentOS 6.5, dovecot-2.0.9-7.el6 with a > small patch to disable the IMAP CREATE command, and > openssl-1.0.1e-16.el6_5.7) and distribute standard client software to > customer( site)s. > > One of the customers has a maj

Re: [Dovecot] Broken IMAPS Connects Create Lingering imap-login Processes

2014-05-05 Thread Jochen Bern
On -10.01.-28163 20:59, Reindl Harald wrote: > Am 05.05.2014 22:13, schrieb Jochen Bern: >> One of the customers has a major networking problem that hasn't been >> fully analyzed yet. Sniffing his IMAPS connects on the server side, I >> see [...] > > ask that user to restart his network-devices >

[Dovecot] Broken IMAPS Connects Create Lingering imap-login Processes

2014-05-05 Thread Jochen Bern
Hello everyone, we are running a central server (CentOS 6.5, dovecot-2.0.9-7.el6 with a small patch to disable the IMAP CREATE command, and openssl-1.0.1e-16.el6_5.7) and distribute standard client software to customer( site)s. The clients do IMAPS connects in regular intervals (no IDLE, no linge

Re: [Dovecot] Broken IMAPS Connects Create Lingering imap-login Processes

2014-05-05 Thread Reindl Harald
Am 05.05.2014 22:13, schrieb Jochen Bern: > One of the customers has a major networking problem that hasn't been > fully analyzed yet. Sniffing his IMAPS connects on the server side, I > see no (necessarily fragmented) TLSv1 Client Cert + Key Exchange happen; > instead, after ~60s, we receive a s