Applicable to:
- Plesk for Linux
Symptoms
-
Plesk was recently updated to versions 18.0.73, Dovecot updated to version 2.4:
# plesk -v
Product version: Plesk Obsidian 18.0.73.0
OS version: AlmaLinux 9.6 x86_64
Build date: 2025/10/02 10:00# dovecot --version
2.4.1-4 (7d8c0e5759) - Mail Clients, such as Thunderbird, receive the following error when attempting to log into a mailbox using "Encrypted Password" option:
-
When checking IMAP/SMTP server capabilities, no MD5 auth methods are advertised:
# openssl s_client -connect 203.0.113.2:993
.
OK [CAPABILITY IMAP4rev1 LOGIN-REFERRALS ID ENABLE IDLE SASL-IR LITERAL+ AUTH=PLAIN AUTH=LOGIN] Dovecot ready.
# openssl s_client -connect 203.1.113.2:465 -crlf
250-AUTH PLAIN LOGIN -
Non-descriptive lines are being logged in
/var/log/maillog, even with Dovecot Debug enabled:# dovecot[24549]: auth: Debug: Loading modules from directory: /usr/libexec/dovecot/modules/auth
dovecot[24549]: auth: Debug: Loading modules from directory: /usr/libexec/dovecot/modules/auth
dovecot[24549]: auth: Debug: Module loaded: /usr/libexec/dovecot/modules/auth/libauthdb_plesk.so dovecot[24549]: auth: Debug: Read auth token secret from /var/run/dovecot/auth-token-secret.dat
dovecot[24549]: auth: Warning: Weak password schemes are allowed
dovecot[24549]: auth: Debug: conn unix:login (pid=24580,uid=991) [1]: Server accepted connection (fd=18)
dovecot[24549]: auth: Debug: conn unix:login (pid=24580,uid=991) [1]: auth client connected (pid=24580)
dovecot[24549]: imap-login: Login aborted: Connection closed (no auth attempts in 0 secs (no_auth_attempts): user=<>, rip=203.0.113.3, lip=203.0.113.2, TLS, session=<94tUujpAK88KQzTS> auth: Debug: conn unix:login (pid=24580,uid=991) [1]: Disconnected: Connection closed (fd=18)
Cause
Product issue:
- PPPM-15147: "After updating to Plesk Obsidian 18.0.73, Thunderbird could not send or receive emails when “Encrypted Password” was selected in the email client settings"
Fixed in:
- Plesk Obsidian 18.0.73 Update 2 6 October 2025
Note: DIGEST-MD5 and CRAM-MD5 are deprecated and fail unconditionally on Dovecot 2.4 due to a Dovecot/libsasl2 compatibility issue (PPP-67617). Re-enabling them does not restore working authentication, and can instead cause repeated Fail2Ban bans.
Resolution
Update Plesk to the latest version:
Warning: Do not re-enable DIGEST-MD5 or CRAM-MD5. They cannot authenticate on Dovecot 2.4 (see Cause), so this will not restore working "Encrypted Password" authentication, and repeated failed attempts can trigger Fail2Ban bans on plesk-dovecot and recidive, blocking the client's IP address for every mailbox using it (PPP-67617).
If updating Plesk is not possible, switch the affected mail client's authentication setting from "Encrypted Password" (or "Encrypted authentication") to Normal Password, keeping the connection secured over SSL/TLS. This uses the PLAIN or LOGIN mechanism, which is supported and unaffected.
If a server was already configured with the old workaround above and is now seeing repeated authentication failures or Fail2Ban bans, remove it:
- Connect to the server via SSH.
-
Back up the current Dovecot configuration:
# cp -a /etc/dovecot /etc/dovecot.bak-$(date +%Y%m%d)
-
Create or edit /etc/dovecot/conf.d/99_custom_auth.conf:
CONFIG_TEXT: auth_allow_weak_schemes = no
auth_mechanisms = plain login apop -
Restart Dovecot service:
# systemctl restart dovecot
Note: Any mail client set to "Encrypted Password" must be switched to Normal Password over SSL/TLS after this change, since DIGEST-MD5 and CRAM-MD5 are no longer available.
Comments
Please sign in to leave a comment.