When configuring Cyrus SASL (saslauthd) to authenticate SMTP users in Postfix on CentOS / RHEL with Virtualmin, you may encounter persistent user/password authentication failures even when credentials are valid.
Environment: CentOS 6.x / RHEL • Virtualmin • Postfix • Cyrus SASL (saslauthd)
1. Identifying the Symptom: /var/log/maillog
Checking /var/log/maillog often reveals that Postfix cannot communicate with the SASL authentication daemon:
warning: SASL authentication failure: cannot connect to saslauthd server: No such file or directory
2. The Chroot Trap and Secondary SMTP Failures
A common workaround suggested in forums is moving or binding the saslauthd socket into the Postfix spool directory (e.g. /var/spool/postfix/var/run/saslauthd). While that may resolve socket visibility, running Postfix processes inside a chroot jail introduces a severe secondary failure: outbound emails will fail to send entirely.
You will see delivery attempts stall in the active queue with errors like:
postfix/qmgr: from=<root@domain.com>, size=421, nrcpt=1 (queue active)
postfix/smtp: fatal: unknown service: smtp/tcp
postfix/qmgr: warning: private/smtp socket: malformed response
postfix/qmgr: warning: transport smtp failure -- see a previous warning/fatal/panic logfile record for the problem description
postfix/master: warning: process /usr/libexec/postfix/smtp pid 29443 exit status 1
postfix/master: warning: /usr/libexec/postfix/smtp: bad command startup -- throttling
postfix/error: to=<user@example.com>, relay=none, delay=1.1, delays=0.1/1/0/0.03, dsn=4.3.0, status=deferred (unknown mail transport error)
Root Cause: When the Postfix smtp client daemon runs chrooted, it cannot access /etc/services to resolve the network port name smtp/tcp, causing the transport to abort and defer all outgoing mail.
3. The Permanent Solution: Disable Chroot for SMTP
To resolve both the SASL socket communication and the transport errors cleanly, configure the Postfix smtp process to run unchrooted.
Step 1: Edit master.cf
Open /etc/postfix/master.cf in your text editor:
nano /etc/postfix/master.cf
Locate the smtp service definition:
# ==========================================================================
# service type private unpriv chroot wakeup maxproc command + args
# (yes) (yes) (yes) (never) (100)
# ==========================================================================
smtp unix - - - - - smtp
The 5th column controls chroot. A hyphen (-) defaults to enabled (yes). Change the 5th column from - (or y) to n:
smtp unix - - n - - smtp
Step 2: Restart Services
Restart both saslauthd and postfix so the configuration changes take effect:
service saslauthd restart
service postfix restart
4. Verification
Once services are restarted, monitor the mail log while sending a test message or authenticating a mail client:
tail -f /var/log/maillog
SASL authentication will succeed immediately without socket connection errors, and the mail queue will flush smoothly without transport or chroot exceptions.