Pam-Mysql“无法初始化线程:错误 11”

Pam-Mysql“无法初始化线程:错误 11”

在 Debian OpenVZ 容器内,我有 2 个 OpenVPN 服务器(端口 53 上的 udp 和端口 443 上的 tcp)。

身份验证基于Pam-Mysql。

在我的里面OpenVPN 配置文件我有:

[...]
plugin /etc/openvpn/openvpn-auth-pam.so openvpn
[...]

在某个时间,通常是早上,当连接的用户很少时,UDP OpenVPN 服务器(永远不会是 TCP 服务器)的身份验证会停止工作。

OpenVPN日志:

Thu Jun 19 10:11:11 2014 us=331224 109.190.XXX.XXX:50611 TLS: Initial packet from [AF_INET]109.190.XXX.XXX:50611, sid=bd8b4b95 0bf1eb05
AUTH-PAM: BACKGROUND: received command code: 0
AUTH-PAM: BACKGROUND: USER: pierrejeanbergeron
Can't initialize threads: error 11
AUTH-PAM: BACKGROUND: user 'pierrejeanbergeron' failed to authenticate: Permission denied
Thu Jun 19 10:11:12 2014 us=705970 109.190.XXX.XXX:50611 PLUGIN_CALL: POST /etc/openvpn/openvpn-auth-pam.so/PLUGIN_AUTH_USER_PASS_VERIFY status=1
Thu Jun 19 10:11:12 2014 us=705983 109.190.XXX.XXX:50611 PLUGIN_CALL: plugin function PLUGIN_AUTH_USER_PASS_VERIFY failed with status 1: /etc/openvpn/openvpn-auth-pam.so
Thu Jun 19 10:11:12 2014 us=706002 109.190.XXX.XXX:50611 TLS Auth Error: Auth Username/Password verification failed for peer
Thu Jun 19 10:11:12 2014 us=857039 109.190.XXX.XXX:50611 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA
Thu Jun 19 10:11:12 2014 us=857064 109.190.XXX.XXX:50611 [] Peer Connection Initiated with [AF_INET]109.190.XXX.XXX:50611
Thu Jun 19 10:11:15 2014 us=33310 109.190.XXX.XXX:50611 PUSH: Received control message: 'PUSH_REQUEST'
Thu Jun 19 10:11:15 2014 us=33335 109.190.XXX.XXX:50611 Delayed exit in 5 seconds
Thu Jun 19 10:11:15 2014 us=33364 109.190.XXX.XXX:50611 SENT CONTROL [UNDEF]: 'AUTH_FAILED' (status=1)
Thu Jun 19 10:11:15 2014 us=107955 109.190.XXX.XXX:50611 Connection reset, restarting [0]
Thu Jun 19 10:11:15 2014 us=107974 109.190.XXX.XXX:50611 SIGUSR1[soft,connection-reset] received, client-instance restarting
Thu Jun 19 10:11:15 2014 us=108016 TCP/UDP: Closing socket

然后我重新启动 OpenVPN,一切又恢复正常。

请注意我已经设置THREADS=0/etc/default/saslauthd

答案1

这个错误似乎与 OpenVZ 对 VE 线程数的限制有关。请检查文件 /proc/user_beancounters 中“numproc”行上的“failcnt”列。

相关内容