Skip to content

scheduler: Raise auth failure log level from DEBUG to WARN for fail2ban compatibility#1561

Open
abubakarsabir924-cell wants to merge 1 commit intoOpenPrinting:masterfrom
abubakarsabir924-cell:fix/auth-failure-log-level
Open

scheduler: Raise auth failure log level from DEBUG to WARN for fail2ban compatibility#1561
abubakarsabir924-cell wants to merge 1 commit intoOpenPrinting:masterfrom
abubakarsabir924-cell:fix/auth-failure-log-level

Conversation

@abubakarsabir924-cell
Copy link
Copy Markdown

Fixes #1553

When LogLevel is set to "error" in cupsd.conf, authentication
failure messages were logged at CUPSD_LOG_DEBUG level and never
appeared in logs. This prevented fail2ban from detecting failed
login attempts and blocked brute force protection.

This change raises the log level from CUPSD_LOG_DEBUG to
CUPSD_LOG_WARN for the "User not in group(s)" message in
scheduler/auth.c, ensuring it appears in logs regardless of
the configured LogLevel.

@abubakarsabir924-cell
Copy link
Copy Markdown
Author

Hi @michaelrsweet Sir, I have submitted PR #[PR 1561] for this issue. I changed the log level from CUPSD_LOG_DEBUG to CUPSD_LOG_WARN in scheduler/auth.c line 2084, where the 'User not in group(s)' message is logged before returning HTTP_STATUS_UNAUTHORIZED. This ensures authentication failures are visible when LogLevel is set to error, enabling fail2ban to work correctly with CUPS. Please review and let me know if any changes are needed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Change authentication failure logging priority to error or warning

1 participant