Recent Posts

Pages: 1 2 3 [4] 5 6 ... 10
31
Backup / Re: NEW Backup (beta) / Restore Account -> Does not list accounts to restore
« Last post by DA_MAN on September 27, 2026, 10:02:26 PM »
CWP 1.15 and this still hasn't been addressed. When can we expect for the S3 restore to be fixed? Ever???
32
E-Mail / Alma8/CWP8 – Amavis 2.13.1 + SpamAssassin 3.4.6 logging and admin notifications
« Last post by Wonder on September 24, 2026, 12:12:47 PM »
Hello,

I am reviewing and tuning the spam/malware filtering configuration on a production CWP server running AlmaLinux 8.10.

Before describing the two issues I am currently trying to solve, I would like to give some context about the current mail setup, because we have already checked most of the SpamAssassin/Amavis chain.

The current inbound mail flow is:

Postfix → Amavis → SpamAssassin / ClamAV → Postfix reinjection → Dovecot LMTP

Postfix sends incoming SMTP mail to Amavis on:

127.0.0.1:10024

and Amavis reinjects it into Postfix on:

127.0.0.1:10025

We have verified this flow using real incoming messages and Postfix Queue-IDs.

The active Amavis configuration is:

/etc/amavisd/amavisd.conf

The server is currently running:

AlmaLinux 8.10

CWP

Amavis 2.13.1

SpamAssassin 3.4.6

Postfix

Dovecot/LMTP

ClamAV

SpamAssassin is being used through Amavis. An older direct Postfix → SpamAssassin pipe that existed previously is no longer used.

Additional SpamAssassin components

We have also reviewed the additional SpamAssassin components.

Razor2

I found this CWP forum thread:

“Install Razor2 for Postfix/Dovecot Spam Filtering along with SpamAssassin”

and particularly the June 2026 AlmaLinux 8/9 update.

Razor is installed and initialized for the user under which Amavis runs. razor-admin -discover completes successfully and TCP outbound port 2703 is allowed in CSF.

Pyzor

Pyzor 1.1.1 is installed.

The SpamAssassin Pyzor plugin was already enabled. We also found that Pyzor required outbound UDP/24441 on this server, so UDP port 24441 was added to CSF outbound rules.

Running Pyzor as the Amavis user now returns:

public.pyzor.org:24441 (200, 'OK')

Bayes

The Bayes database used by the Amavis account exists under:

/var/spool/amavisd/.spamassassin/

and it is active. The HAM count is increasing with real mail. At the moment the SPAM learned count is still zero, which we are monitoring before changing any autolearn thresholds.

DNSBL / URIBL

We discovered that the server's default DNS resolvers were being blocked specifically by URIBL.

Rather than changing the system DNS configuration, dedicated DNS resolvers were configured only for SpamAssassin using the dns_server directives in local.cf.

We have successfully tested queries against:

URIBL

SURBL

Spamhaus ZEN

Spamhaus DBL

DNSWL

The system DNS configuration itself was left unchanged.

Archive decoders

We also checked the archive/attachment decoders used by Amavis. Missing support for RAR/LZ4/Zstandard/7z was installed and the corresponding Amavis startup warnings disappeared.

ClamAV

Amavis has clamdscan available as its primary ClamAV scanner, with clamscan available as a secondary scanner.

Spam filtering itself is working

The current Amavis SpamAssassin thresholds are:

sa_tag_level_deflt = 2.0

sa_tag2_level_deflt = 5.0

sa_kill_level_deflt = 10.0

Messages scoring above the spam threshold but below the kill threshold are delivered with the expected X-Spam-* headers and ***SPAM*** subject prefix.

Messages reaching the kill threshold are discarded according to the current Amavis configuration.

We also performed a GTUBE test through the normal external SMTP → Postfix → Amavis path. It was correctly identified as spam and Amavis returned:

250 2.7.0 Ok, discarded ... - spam

So the actual SpamAssassin filtering through Amavis is working.

However, I have two Amavis/CWP questions which I have not been able to resolve cleanly.

1. Amavis per-recipient logging / Hits

The normal CWP Amavis configuration currently contains:

$log_level = 0;

$log_recip_templ = undef;

$do_syslog = 1;

$syslog_facility = 'mail';

Normally we do not see Amavis per-message entries such as:

Passed CLEAN ... Hits: ...

in /var/log/maillog.

The Postfix logs clearly show the same messages going to 127.0.0.1:10024, being accepted by Amavis and being reinjected through 127.0.0.1:10025, so Amavis is definitely processing them.

Interestingly, at least one Passed CLEAN {RelayedInbound} ... Hits: ... entry did appear previously in maillog.

For testing, we temporarily removed/commented:

$log_recip_templ = undef;

The installed Amavis source contains the standard default log_recip_templ, including the Passed, Blocked, CLEAN, SPAMMY, SPAM, BANNED, INFECTED, Hits, tag/tag2/kill information, etc.

amavisd -c /etc/amavisd/amavisd.conf test-config completed successfully and Amavis was restarted. We even rebooted the server during testing.

However, the expected per-recipient Passed/Blocked/Hits entries still did not appear in /var/log/maillog.

The temporary test has now been completely reverted and the production configuration is back to:

$log_recip_templ = undef;

Is there any CWP-specific configuration, Amavis packaging change, syslog configuration or additional option required to enable these normal per-recipient Amavis log entries?

2. Administrative notifications for VIRUS / BANNED / UNCHECKED

I have created a dedicated local mailbox:

mailsecurity@skytime.es

I would like Amavis to notify this mailbox only for important security events initially:

VIRUS

BANNED

UNCHECKED

I do not want administrative email notifications for every ordinary spam message or every clean message.

The current CWP Amavis configuration contains:

$virus_admin = undef;

Looking at the installed Amavis 2.13.1 Conf.pm, VIRUS and UNCHECKED appear to use virus_admin_maps, while banned_admin_maps also appears to fall back to the virus administrator configuration.

As a controlled test I tried:

$virus_admin = "mailsecurity\@$mydomain";

but test-config rejected this configuration with:

Can't use string ("skytime.es") as an ARRAY ref while "strict refs" in use at /etc/amavisd/amavisd.conf line 125.

Amavis was not restarted with that invalid configuration. The change was immediately reverted and test-config is successful again.

What is the correct/recommended syntax in the current CWP + Amavis 2.13.1 configuration to send administrator notifications for VIRUS, BANNED and UNCHECKED to this local mailbox, without enabling notifications for normal spam?

I would prefer to use the configuration expected by CWP rather than continue experimenting directly on a production mail server.

Thanks in advance.
33
Thank you, this is very useful.

Actually when I checked the PHP-FPM slow logs (which I had not thought to do previously) I quickly discovered a site with a simple hack. It was hanging on the homepage due to a hack on the index.php executing various encrypted commands with curl.

Cleaning up the hack immediately improved performance to what I would expect!
34
The fact that you still get the timeout with Cloudflare disabled is useful because it largely removes Cloudflare from the equation. I also wouldn’t increase MaxRequestWorkers or PHP-FPM children any further until you identify which layer is actually saturating.

When the timeout happens, I’d capture the state at that exact moment rather than looking only at overall CPU/RAM. Check the affected account’s PHP-FPM processes, its CWP process/package limits (nproc, apache_nproc, nofile), Apache scoreboard, and the corresponding PHP-FPM slow/error log. Also compare pm.max_children against the number of active/queued requests for that pool.

One particularly useful test would be to run several simultaneous requests directly against the origin while watching the affected PHP-FPM pool. If requests begin queueing while the machine still has free CPU/RAM, you’ve found a concurrency/limit bottleneck rather than a server-capacity problem.

I’d also temporarily correlate the timeout timestamps with ModSecurity audit entries. That should help distinguish PHP-FPM saturation, account limits, Apache worker exhaustion and request filtering instead of changing several limits at once.

I develop CWP7 Turbo Manager, specifically around diagnosing and tuning this sort of CWP web-stack performance problem. Full disclosure: I’m the developer. It may be relevant here, but I’d first capture the PHP-FPM/account state during one of the 522 events—the numbers from that moment should tell us which direction to go.
35
1. Check how many processes are running under the user account of the problematic website when the error occurs.

2. Make sure the number of processes is not close to the Process Limit specified for the account in the CWP admin panel (check the account properties).

3. Check the package limits assigned to the problematic account. Pay particular attention to nproc, apache_nproc, and nofile.

Thanks - this is a great tip that had not occurred to me. I have increased all those limits now, will monitor and see if it improves things.

Quote
4. Is mod_security enabled ?

Yes

Quote
5. Do you use a VPS or a dedicated server? If it’s a VPS, what type of virtualization is used?

It's a VPS, running on Hetzner Cloud (KVM)
36
1. Check how many processes are running under the user account of the problematic website when the error occurs.

2. Make sure the number of processes is not close to the Process Limit specified for the account in the CWP admin panel (check the account properties).

3. Check the package limits assigned to the problematic account. Pay particular attention to nproc, apache_nproc, and nofile.

4. Is mod_security enabled ?

5. Do you use a VPS or a dedicated server? If it’s a VPS, what type of virtualization is used?
37
Updates / Re: Unable to load dynamic library 'intl'
« Last post by cyberspace on September 23, 2026, 11:16:16 PM »
Follow the instructions provided right under the words:

(Has been modified if your server shows PHP 7.4.33 on AlmaLinux 9.8)
38
Mine was already disabled.

39
Information / Re: New WordPress vulnerability - CVE-2026-87902
« Last post by Starburst on September 23, 2026, 04:29:28 PM »
Thank You
40
I have a CWP Pro virtual server running AlmaLinux 8.10 and CWP 1.14

The server is never under any appreciable load - max 33% of processor capacity and 4GB of RAM from 16GB total. Checking the Apache Server Status via the CWP control panel, everything looks sane - 12 spawned servers, utilises 1.5GB RAM, 272 tasks.

All sites on the server use PHP-FPM, some stuck on legacy PHP7.4 but most running PHP8.3

Cloudflare returns a timeout error of 522 on some sites, seemingly at random but rather often. If I disable Cloudflare, I get the same timeouts but with a vanilla error message in the browser. So Cloudflare is not at fault here.

I have tried various tactics to prevent this:

a) Apache was reporting it had run out of RequestWorker processes, so I included the following snippet via conf/extra/httpd-mpm.conf (Apache runs with the MPM Evnt mod on my server).

Code: [Select]
<IfModule mpm_event_module>
    StartServers            25
    ServerLimit             32
    MinSpareThreads         75
    MaxSpareThreads        250
    ThreadsPerChild         25
    MaxRequestWorkers    800
    MaxConnectionsPerChild   0
</IfModule>

b) When that didn't solve the problem, I also increased the number of max PHP-FPM processes in the default template and for individual sites. I increased from the default of MaxChildProcceses 4 to 25.

c) I enabled KeepAlive which I don't think is enabled by default, via self-authored snippet included in conf/extra/httpd-keepalive.conf

Code: [Select]
KeepAlive On
MaxKeepAliveRequests 100
KeepAliveTimeout 5

None of the above has resolved the problem. I am at a loss. Furthermore, some of the sites show extremely poor performance. Yet the server has loads of spare capacity.

Anyone got any insight here?

I have checked if disabling the firewall made any difference (in case it was blocking Cloudflare IP addresses). It did not and it is not.
Pages: 1 2 3 [4] 5 6 ... 10