Login aborted: Connection closed (disconnected during TLS handshake)
We're starting to see lots of the following errors during IMAP and POP3 collections from the Dovecot mail server.
Jan 23 14:35:19 ouserver dovecot[3460161]: imap-login: Login aborted: Connection closed (disconnected during TLS handshake) (tls_handshake_not_finished): user=<>, rip=XXXXXXX, lip=xxx.xxx.xxx.xxx, TLS handshaking: Connection closed, session=<qLwV1QVJBs54lnWH>
This started today.
Users are reporting mail server is not responding on various devices.
It appears to affect random accounts and users are unable to collect email. I have email accounts on the same server and as at the time of writing I am unaffected.
CloudLinux v8.10.0 STANDARD standard
cPanel Version
132.0.21
Anyone else experiencing this issue and any advice.
Thank you.
-
Hey there! I can't say I've had any similar reports of this behavior over the last few days.
When checking the log file, do you see that it is frequently the same IP address trying to connect, or trying to access the same email address? If so, there could be an attack happening against your server or a particular email account.
0 -
Okay thank cPRex,
We're still seeing this across a number of accounts reported in our nightly Logwatch run.
The IP addresses are different and are IPs for our geographic region. The accounts affected earlier appear to have resolved themselves but other accounts are now reporting the error.
When this happens clients are unable to collect their email. Delivery is unaffected. I receive phone calls from clients reporting that they are unable to collect mail.
dovecot[1826080]: pop3-login: Login aborted: Inactivity (disconnected during TLS handshake) (tls_handshake_not_finished): user=<>, rip=x.xx.xx.xxx lip=xx.xx.xxx.xxx, TLS handshaking, session=<96RJPO9I804BmB9l>: 1 Time(s)
Both POP and IMAP affected.
We have not changed anything ourselves on the server.
We would open a ticket with you to investigate, been a while since our last ticket and now the message received is that our license is through our server provider and so we must apparently, go through them. Assuming wildly that there is no longer an option for a direct investigation by way of yourselves?
Thank you.
0 -
Thanks for the additional details. Your are correct that support should be directed to the license provider, and then they would escalate the ticket to us if necessary.
Is it possible that you just have too many email users connecting at once and you need to bump the values in WHM >> Mailserver Configuration? Or do you think this is not legitimate traffic?
0
Please sign in to leave a comment.
Comments
3 comments