fail2ban has been deaf for 8 days #114
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fixes"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
fail2banhas been reading zero journal entries since it started:python3Packages.systemd-pythonlinkssystemdLibs, which inheritssystemdMinimal'swithCompression = false- no zstd, so it hard-refuses every journal file (all of them writtenCOMPRESSED-ZSTD) and polls an empty directory forever without ever erroring.modules/packages.nixoverlaysfail2banonto apython3whosesystemd-pythonbuilds againstsystemdLibs.override { withCompression = true; }. no module change needed -services.fail2ban.packagealready defaults topkgs.fail2ban.Total failed: 0.Aborted login (auth failed...), dovecot now emitsLogin aborted: Connection closed (...) (auth_failed): user=....dovecot.localfilter appended viaenvironment.etc(module exposes nofiltersoption), keyed on the new parenthesised tags rather than the prose ahead of them.auth_failed+ aggressive-modeno_auth_attempts; deliberately leavestls_handshake_not_finishedandprocess_fullalone (client-side TLS failures / our own login-process cap, not attacker signal).left for later: bans aren't retroactive, fail2ban seeks to now on start - verify post-deploy with
fail2ban-client status dovecot,Total failedshould climb off 0 (~380/day inbound).libsystemdcannot read a compressed journal 2db43c6613dovecot2.4 renamed every disconnect line out from under the f2b filter