Compare commits

...
Sign in to create a new pull request.

1 commit

Author SHA1 Message Date
edecf3addf Package is retired 2014-12-07 19:58:25 +01:00
13 changed files with 1 additions and 2056 deletions

1
.gitignore vendored
View file

@ -1 +0,0 @@
zcp-7.?.*.tar.gz

1
dead.package Normal file
View file

@ -0,0 +1 @@
Package is retired

View file

@ -1 +0,0 @@
7317dd7889303abbbd30e39f04771f10 zcp-7.1.11.tar.gz

View file

@ -1,28 +0,0 @@
Patch by Robert Scheck <robert@fedoraproject.org> for zarafa >= 7.1.10 which re-adds the ability to disable
zarafa-search during build-time. This is e.g. required if CLucene and/or Kyotocabinet is unavailable or
broken on the given system and/or architecture. Interestingly that patch is not new, I wrote these lines
in 2012 the first time, proposed them as a patch to Zarafa and got merged. With a recent Zarafa release it
seems they silently removed it again...
--- zarafa-7.1.10/ECtools/zarafa-search/Makefile.am 2014-05-23 15:03:49.000000000 +0200
+++ zarafa-7.1.10/ECtools/zarafa-search/Makefile.am.kyotocabinet 2014-07-10 21:48:42.000000000 +0200
@@ -1,4 +1,8 @@
+if WITH_CLUCENE
+if WITH_KYOTOCABINET
bin_PROGRAMS = zarafa-search
+endif
+endif
AM_CPPFLAGS = ${ZCPPFLAGS} \
-I${top_srcdir}/mapi4linux/include \
--- zarafa-7.1.10/ECtools/zarafa-search/Makefile.in 2014-05-23 15:04:02.000000000 +0200
+++ zarafa-7.1.10/ECtools/zarafa-search/Makefile.in.kyotocabinet 2014-07-10 21:49:16.000000000 +0200
@@ -34,7 +34,7 @@
POST_UNINSTALL = :
build_triplet = @build@
host_triplet = @host@
-bin_PROGRAMS = zarafa-search$(EXEEXT)
+@WITH_CLUCENE_TRUE@@WITH_KYOTOCABINET_TRUE@bin_PROGRAMS = zarafa-search$(EXEEXT)
subdir = ECtools/zarafa-search
DIST_COMMON = $(srcdir)/Makefile.am $(srcdir)/Makefile.in
ACLOCAL_M4 = $(top_srcdir)/aclocal.m4

View file

@ -1,446 +0,0 @@
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa <= 7.1.10 which implements much more
fine granulated configuration settings for SSL/TLS protocol and cipher enabling and disabling. The
currently available "ssl_enable_v2" setting allows either to disable SSLv2 (and enables SSLv3 only
instead) or to enable all, thus SSLv2, SSLv3, TLSv1, TLSv1.1 and TLSv1.2 (TLSv1.1 and TLSv1.2 only
if Zarafa was linked against OpenSSL 1.0.1 or later). Since SSLv2 has known protocol weaknesses it
never should be enabled - but for Zarafa it currently must be enabled to support TLSv1 and better.
This patch introduces the new setting "ssl_protocols" which replaces "ssl_enable_v2". The default
is "!SSLv2" to simply disable SSLv2 by default. The setting can be filled either with SSL protocols
that shall be enabled and/or disabled, e.g. "SSLv3 TLSv1" or "!SSLv2 !SSLv3". However only the more
usual disable/exclude option should be used as this does not exclude future protocols by default.
Further this patch introduces the completely new setting "ssl_ciphers". This one allows to set SSL
cipher suites. Right now, all SSL ciphers are accepted which is just weak or might Zarafa even make
even vulnerable to known SSL attacks. The German Federal Office for Information Security (BSI) says
that RC4 should not be used anymore - but Zarafa does it by default. And without this patch there
is also no way for Zarafa administrators to avoid that. Indeed this setting has the risk to get the
administrators ending up in a cipher mismatch between different systems but this new setting still
could be declared as officially unsupported and only for the brave ones who know what they do. Thus
the default is already set to something less weak than before but still below BSI recommendations.
Finally this patch introduces the also new setting "ssl_prefer_server_ciphers". It does what it is
named after: When choosing a cipher during an SSL/TLS handshake, normally the client's preference
is used. If this setting is enabled, the server's preference will be used instead. This comes handy
to administrators for strange cipher orderings required for special configurations and clients - or
new weaknesses where workarounds are required for the time being.
Testing: Configure zarafa-gateway, zarafa-ical and zarafa-server for cleartext and SSL as usual.
Try to login via POP3S, IMAPS, CalDAV-SSL and MAPI in SOAP over HTTPS. Change SSL protocols and the
ciphers to something more weak ("SSLv2" and "LOW") or to something more strong ("TLSv1.2" and e.g.
"HIGH"). During all my tests I did not figure out any newly introduced issue or Zarafa breakage.
Important: The technical implementation of this patch might be not perfect as I am not really a C/
C++ developer. The logic and the implementation is heavily based on Dovecot, Postfix and hints from
https://docs.fedoraproject.org/en-US/Fedora_Security_Team/html/Defensive_Coding/. There should be
a code review and code clean up by an experienced C/C++ developer before merging into Zarafa core.
This patch should be only applied in conjuction with the POP3 RESP-CODES and AUTH-RESP-CODE patch,
the POP3 CAPA (CAPABILITIES) patch as well as the POP3 STLS (STARTTLS) patch applied before.
--- zarafa-7.1.10/caldav/CalDAV.cpp 2014-05-23 15:56:36.000000000 +0200
+++ zarafa-7.1.10/caldav/CalDAV.cpp.rsc 2014-08-12 19:45:04.000000000 +0200
@@ -220,7 +220,9 @@
{ "log_timestamp", "1" },
{ "ssl_private_key_file", "/etc/zarafa/ical/privkey.pem" },
{ "ssl_certificate_file", "/etc/zarafa/ical/cert.pem" },
- { "ssl_enable_v2", "no" },
+ { "ssl_protocols", "!SSLv2" },
+ { "ssl_ciphers", "ALL:!LOW:!SSLv2:!EXP:!aNULL" },
+ { "ssl_prefer_server_ciphers", "no" },
{ "ssl_verify_client", "no" },
{ "ssl_verify_file", "" },
{ "ssl_verify_path", "" },
--- zarafa-7.1.10/common/ECChannel.cpp 2014-05-23 15:56:36.000000000 +0200
+++ zarafa-7.1.10/common/ECChannel.cpp.rsc 2014-08-12 19:48:00.000000000 +0200
@@ -92,6 +92,11 @@
HRESULT hr = hrSuccess;
char *szFile = NULL;
char *szPath = NULL;
+ char *ssl_protocols = strdup(lpConfig->GetSetting("ssl_protocols"));
+ char *ssl_ciphers = lpConfig->GetSetting("ssl_ciphers");
+ char *ssl_name;
+ int ssl_proto, ssl_op = 0, ssl_include = 0, ssl_exclude = 0;
+ bool ssl_neg;
if (lpConfig == NULL) {
hr = MAPI_E_CALL_FAILED;
@@ -107,11 +112,79 @@
SSL_load_error_strings();
lpCTX = SSL_CTX_new(SSLv23_server_method());
SSL_CTX_set_options(lpCTX, SSL_OP_ALL);
- SSL_CTX_set_default_verify_paths(lpCTX);
- // disable SSLv2 support
- if (!parseBool(lpConfig->GetSetting("ssl_enable_v2", "", "no")))
- SSL_CTX_set_options(lpCTX, SSL_OP_NO_SSLv2);
+ ssl_name = strtok(ssl_protocols, " ");
+ while(ssl_name != NULL) {
+ if (*ssl_name != '!')
+ ssl_neg = FALSE;
+ else {
+ ssl_name++;
+ ssl_neg = TRUE;
+ }
+
+ if (strcasecmp(ssl_name, SSL_TXT_SSLV2) == 0)
+ ssl_proto = 0x01;
+ else if (strcasecmp(ssl_name, SSL_TXT_SSLV3) == 0)
+ ssl_proto = 0x02;
+ else if (strcasecmp(ssl_name, SSL_TXT_TLSV1) == 0)
+ ssl_proto = 0x04;
+#ifdef SSL_TXT_TLSV1_1
+ else if (strcasecmp(ssl_name, SSL_TXT_TLSV1_1) == 0)
+ ssl_proto = 0x08;
+#endif
+#ifdef SSL_TXT_TLSV1_2
+ else if (strcasecmp(ssl_name, SSL_TXT_TLSV1_2) == 0)
+ ssl_proto = 0x10;
+#endif
+ else {
+ lpLogger->Log(EC_LOGLEVEL_ERROR, "Unknown protocol '%s' in ssl_protocols setting", ssl_name);
+ hr = MAPI_E_CALL_FAILED;
+ goto exit;
+ }
+
+ if (ssl_neg)
+ ssl_exclude |= ssl_proto;
+ else
+ ssl_include |= ssl_proto;
+
+ ssl_name = strtok(NULL, " ");
+ }
+
+ if (ssl_include != 0) {
+ // Exclude everything, except those that are included (and let excludes still override those)
+ ssl_exclude |= 0x1f & ~ssl_include;
+ }
+
+ if ((ssl_exclude & 0x01) != 0)
+ ssl_op |= SSL_OP_NO_SSLv2;
+ if ((ssl_exclude & 0x02) != 0)
+ ssl_op |= SSL_OP_NO_SSLv3;
+ if ((ssl_exclude & 0x04) != 0)
+ ssl_op |= SSL_OP_NO_TLSv1;
+#ifdef SSL_OP_NO_TLSv1_1
+ if ((ssl_exclude & 0x08) != 0)
+ ssl_op |= SSL_OP_NO_TLSv1_1;
+#endif
+#ifdef SSL_OP_NO_TLSv1_2
+ if ((ssl_exclude & 0x10) != 0)
+ ssl_op |= SSL_OP_NO_TLSv1_2;
+#endif
+
+ if (ssl_protocols) {
+ SSL_CTX_set_options(lpCTX, ssl_op);
+ }
+
+ if (ssl_ciphers && SSL_CTX_set_cipher_list(lpCTX, ssl_ciphers) != 1) {
+ lpLogger->Log(EC_LOGLEVEL_ERROR, "Can not set SSL cipher list to '%s': %s", ssl_ciphers, ERR_error_string(ERR_get_error(), 0));
+ hr = MAPI_E_CALL_FAILED;
+ goto exit;
+ }
+
+ if (parseBool(lpConfig->GetSetting("ssl_prefer_server_ciphers"))) {
+ SSL_CTX_set_options(lpCTX, SSL_OP_CIPHER_SERVER_PREFERENCE);
+ }
+
+ SSL_CTX_set_default_verify_paths(lpCTX);
if (SSL_CTX_use_certificate_chain_file(lpCTX, lpConfig->GetSetting("ssl_certificate_file")) != 1) {
lpLogger->Log(EC_LOGLEVEL_ERROR, "SSL CTX certificate file error: %s", ERR_error_string(ERR_get_error(), 0));
--- zarafa-7.1.10/doc/manual.xml 2014-05-23 15:01:13.000000000 +0200
+++ zarafa-7.1.10/doc/manual.xml.rsc 2014-08-12 19:45:04.000000000 +0200
@@ -4226,11 +4226,33 @@
</varlistentry>
<varlistentry>
- <term><option>server_ssl_enable_v2</option></term>
+ <term><option>server_ssl_protocols</option></term>
<listitem>
- <para>Incoming SSL connections normally are v3.</para>
- <para>Default: <replaceable>no</replaceable>
- </para>
+ <para>Disabled or enabled protocol names. Supported protocol names
+ are <replaceable>SSLv2</replaceable>, <replaceable>SSLv3</replaceable>
+ and <replaceable>TLSv1</replaceable>. If Zarafa was linked against
+ OpenSSL 1.0.1 or later there is additional support for the new protocols
+ <replaceable>TLSv1.1</replaceable> and <replaceable>TLSv1.2</replaceable>.
+ To exclude both, SSLv2 and SSLv3 set <option>server_ssl_protocols</option>
+ to <replaceable>!SSLv2 !SSLv3</replaceable>. SSLv2 is considered unsafe
+ and these connections should not be accepted.</para>
+ <para>Default: <replaceable>!SSLv2</replaceable></para>
+ </listitem>
+ </varlistentry>
+
+ <varlistentry>
+ <term><option>server_ssl_ciphers</option></term>
+ <listitem>
+ <para>SSL ciphers to use, set to <replaceable>ALL</replaceable> for backward compatibility.</para>
+ <para>Default: <replaceable>ALL:!LOW:!SSLv2:!EXP:!aNULL</replaceable></para>
+ </listitem>
+ </varlistentry>
+
+ <varlistentry>
+ <term><option>server_ssl_prefer_server_ciphers</option></term>
+ <listitem>
+ <para>Prefer the server's order of SSL ciphers over client's.</para>
+ <para>Default: <replaceable>no</replaceable></para>
</listitem>
</varlistentry>
@@ -8070,11 +8092,32 @@
</varlistentry>
<varlistentry>
- <term><option>ssl_enable_v2</option></term>
+ <term><option>ssl_protocols</option></term>
+ <listitem>
+ <para>Disabled or enabled protocol names. Supported protocol names
+ are <replaceable>SSLv2</replaceable>, <replaceable>SSLv3</replaceable>
+ and <replaceable>TLSv1</replaceable>. If Zarafa was linked against
+ OpenSSL 1.0.1 or later there is additional support for the new protocols
+ <replaceable>TLSv1.1</replaceable> and <replaceable>TLSv1.2</replaceable>.
+ To exclude both, SSLv2 and SSLv3 set <option>ssl_protocols</option>
+ to <replaceable>!SSLv2 !SSLv3</replaceable>. SSLv2 is considered unsafe
+ and these connections should not be accepted.</para>
+ <para>Default: <replaceable>!SSLv2</replaceable></para>
+ </listitem>
+ </varlistentry>
+
+ <varlistentry>
+ <term><option>ssl_ciphers</option></term>
+ <listitem>
+ <para>SSL ciphers to use, set to <replaceable>ALL</replaceable> for backward compatibility.</para>
+ <para>Default: <replaceable>ALL:!LOW:!SSLv2:!EXP:!aNULL</replaceable></para>
+ </listitem>
+ </varlistentry>
+
+ <varlistentry>
+ <term><option>ssl_prefer_server_ciphers</option></term>
<listitem>
- <para>Accept SSLv2 only connections. SSLv2 is considered
- unsafe, and these connections should not be
- accepted.</para>
+ <para>Prefer the server's order of SSL ciphers over client's.</para>
<para>Default: <replaceable>no</replaceable></para>
</listitem>
</varlistentry>
@@ -10075,11 +10118,32 @@
</varlistentry>
<varlistentry>
- <term><option>ssl_enable_v2</option></term>
+ <term><option>ssl_protocols</option></term>
+ <listitem>
+ <para>Disabled or enabled protocol names. Supported protocol names
+ are <replaceable>SSLv2</replaceable>, <replaceable>SSLv3</replaceable>
+ and <replaceable>TLSv1</replaceable>. If Zarafa was linked against
+ OpenSSL 1.0.1 or later there is additional support for the new protocols
+ <replaceable>TLSv1.1</replaceable> and <replaceable>TLSv1.2</replaceable>.
+ To exclude both, SSLv2 and SSLv3 set <option>ssl_protocols</option>
+ to <replaceable>!SSLv2 !SSLv3</replaceable>. SSLv2 is considered unsafe
+ and these connections should not be accepted.</para>
+ <para>Default: <replaceable>!SSLv2</replaceable></para>
+ </listitem>
+ </varlistentry>
+
+ <varlistentry>
+ <term><option>ssl_ciphers</option></term>
+ <listitem>
+ <para>SSL ciphers to use, set to <replaceable>ALL</replaceable> for backward compatibility.</para>
+ <para>Default: <replaceable>ALL:!LOW:!SSLv2:!EXP:!aNULL</replaceable></para>
+ </listitem>
+ </varlistentry>
+
+ <varlistentry>
+ <term><option>ssl_prefer_server_ciphers</option></term>
<listitem>
- <para>Accept SSLv2 only connections. SSLv2 is considered
- unsafe, and these connections should not be
- accepted.</para>
+ <para>Prefer the server's order of SSL ciphers over client's.</para>
<para>Default: <replaceable>no</replaceable></para>
</listitem>
</varlistentry>
--- zarafa-7.1.10/gateway/Gateway.cpp 2014-05-23 15:56:37.000000000 +0200
+++ zarafa-7.1.10/gateway/Gateway.cpp.rsc 2014-08-12 19:45:04.000000000 +0200
@@ -365,7 +365,9 @@
{ "ssl_verify_client", "no" },
{ "ssl_verify_file", "" },
{ "ssl_verify_path", "" },
- { "ssl_enable_v2", "no" },
+ { "ssl_protocols", "!SSLv2" },
+ { "ssl_ciphers", "ALL:!LOW:!SSLv2:!EXP:!aNULL" },
+ { "ssl_prefer_server_ciphers", "no" },
{ "log_method", "file" },
{ "log_file", "-" },
{ "log_level", "2", CONFIGSETTING_RELOADABLE },
--- zarafa-7.1.10/installer/linux/gateway.cfg 2014-05-23 15:03:19.000000000 +0200
+++ zarafa-7.1.10/installer/linux/gateway.cfg.rsc 2014-08-12 19:45:04.000000000 +0200
@@ -84,8 +84,14 @@
ssl_verify_file =
ssl_verify_path =
-# Accept SSLv2 only incoming connections
-ssl_enable_v2 = no
+# SSL protocols to use, set to '!SSLv2' for 'ssl_enable_v2 = no'
+ssl_protocols = !SSLv2
+
+# SSL ciphers to use, set to 'ALL' for backward compatibility
+ssl_ciphers = ALL:!LOW:!SSLv2:!EXP:!aNULL
+
+# Prefer the server's order of SSL ciphers over client's
+ssl_prefer_server_ciphers = no
# Process model, using pthreads (thread) or processes (fork)
process_model = fork
--- zarafa-7.1.10/installer/linux/ical.cfg 2014-05-23 15:03:19.000000000 +0200
+++ zarafa-7.1.10/installer/linux/ical.cfg.rsc 2014-08-12 19:45:04.000000000 +0200
@@ -66,8 +66,14 @@
ssl_verify_file =
ssl_verify_path =
-# Accept SSLv2 only incoming connections
-ssl_enable_v2 = no
+# SSL protocols to use, set to '!SSLv2' for 'ssl_enable_v2 = no'
+ssl_protocols = !SSLv2
+
+# SSL ciphers to use, set to 'ALL' for backward compatibility
+ssl_ciphers = ALL:!LOW:!SSLv2:!EXP:!aNULL
+
+# Prefer the server's order of SSL ciphers over client's
+ssl_prefer_server_ciphers = no
##############################################################
# OTHER ICAL SETTINGS
--- zarafa-7.1.10/installer/linux/server.cfg 2014-05-23 15:03:19.000000000 +0200
+++ zarafa-7.1.10/installer/linux/server.cfg.rsc 2014-08-12 19:45:04.000000000 +0200
@@ -154,8 +154,14 @@
# Path with CA certificates, e.g. /etc/ssl/certs
server_ssl_ca_path =
-# Accept SSLv2 only connections. Normally v3 connections are used.
-server_ssl_enable_v2 = no
+# SSL protocols to use, set to '!SSLv2' for 'server_ssl_enable_v2 = no'
+server_ssl_protocols = !SSLv2
+
+# SSL ciphers to use, set to 'ALL' for backward compatibility
+server_ssl_ciphers = ALL:!LOW:!SSLv2:!EXP:!aNULL
+
+# Prefer the server's order of SSL ciphers over client's
+server_ssl_prefer_server_ciphers = no
# Path of SSL Public keys of clients
sslkeys_path = /etc/zarafa/sslkeys
--- zarafa-7.1.10/provider/server/ECServer.cpp 2014-05-23 15:56:37.000000000 +0200
+++ zarafa-7.1.10/provider/server/ECServer.cpp.rsc 2014-08-12 19:45:04.000000000 +0200
@@ -919,7 +919,9 @@
{ "server_ssl_key_pass", "server", CONFIGSETTING_EXACT },
{ "server_ssl_ca_file", "/etc/zarafa/ssl/cacert.pem" },
{ "server_ssl_ca_path", "" },
- { "server_ssl_enable_v2", "no" },
+ { "server_ssl_protocols", "!SSLv2" },
+ { "server_ssl_ciphers", "ALL:!LOW:!SSLv2:!EXP:!aNULL" },
+ { "server_ssl_prefer_server_ciphers", "no" },
{ "sslkeys_path", "/etc/zarafa/sslkeys" }, // login keys
// Database options
{ "database_engine", "mysql" },
--- zarafa-7.1.10/provider/server/ECSoapServerConnection.cpp 2014-05-23 15:56:37.000000000 +0200
+++ zarafa-7.1.10/provider/server/ECSoapServerConnection.cpp.rsc 2014-08-12 19:45:04.000000000 +0200
@@ -240,6 +240,11 @@
ECRESULT er = erSuccess;
int socket = SOAP_INVALID_SOCKET;
struct soap *lpsSoap = NULL;
+ char *server_ssl_protocols = strdup(m_lpConfig->GetSetting("server_ssl_protocols"));
+ char *server_ssl_ciphers = m_lpConfig->GetSetting("server_ssl_ciphers");
+ char *ssl_name;
+ int ssl_proto, ssl_op = 0, ssl_include = 0, ssl_exclude = 0;
+ bool ssl_neg;
if(lpServerName == NULL) {
er = ZARAFA_E_INVALID_PARAMETER;
@@ -270,10 +275,79 @@
goto exit;
}
- // disable SSLv2 support
- if (!parseBool(m_lpConfig->GetSetting("server_ssl_enable_v2", "", "no")))
- SSL_CTX_set_options(lpsSoap->ctx, SSL_OP_NO_SSLv2);
-
+ SSL_CTX_set_options(lpsSoap->ctx, SSL_OP_ALL);
+
+ ssl_name = strtok(server_ssl_protocols, " ");
+ while(ssl_name != NULL) {
+ if (*ssl_name != '!')
+ ssl_neg = FALSE;
+ else {
+ ssl_name++;
+ ssl_neg = TRUE;
+ }
+
+ if (strcasecmp(ssl_name, SSL_TXT_SSLV2) == 0)
+ ssl_proto = 0x01;
+ else if (strcasecmp(ssl_name, SSL_TXT_SSLV3) == 0)
+ ssl_proto = 0x02;
+ else if (strcasecmp(ssl_name, SSL_TXT_TLSV1) == 0)
+ ssl_proto = 0x04;
+#ifdef SSL_TXT_TLSV1_1
+ else if (strcasecmp(ssl_name, SSL_TXT_TLSV1_1) == 0)
+ ssl_proto = 0x08;
+#endif
+#ifdef SSL_TXT_TLSV1_2
+ else if (strcasecmp(ssl_name, SSL_TXT_TLSV1_2) == 0)
+ ssl_proto = 0x10;
+#endif
+ else {
+ m_lpLogger->Log(EC_LOGLEVEL_FATAL, "Unknown protocol '%s' in server_ssl_protocols setting", ssl_name);
+ er = ZARAFA_E_CALL_FAILED;
+ goto exit;
+ }
+
+ if (ssl_neg)
+ ssl_exclude |= ssl_proto;
+ else
+ ssl_include |= ssl_proto;
+
+ ssl_name = strtok(NULL, " ");
+ }
+
+ if (ssl_include != 0) {
+ // Exclude everything, except those that are included (and let excludes still override those)
+ ssl_exclude |= 0x1f & ~ssl_include;
+ }
+
+ if ((ssl_exclude & 0x01) != 0)
+ ssl_op |= SSL_OP_NO_SSLv2;
+ if ((ssl_exclude & 0x02) != 0)
+ ssl_op |= SSL_OP_NO_SSLv3;
+ if ((ssl_exclude & 0x04) != 0)
+ ssl_op |= SSL_OP_NO_TLSv1;
+#ifdef SSL_OP_NO_TLSv1_1
+ if ((ssl_exclude & 0x08) != 0)
+ ssl_op |= SSL_OP_NO_TLSv1_1;
+#endif
+#ifdef SSL_OP_NO_TLSv1_2
+ if ((ssl_exclude & 0x10) != 0)
+ ssl_op |= SSL_OP_NO_TLSv1_2;
+#endif
+
+ if (server_ssl_protocols) {
+ SSL_CTX_set_options(lpsSoap->ctx, ssl_op);
+ }
+
+ if (server_ssl_ciphers && SSL_CTX_set_cipher_list(lpsSoap->ctx, server_ssl_ciphers) != 1) {
+ m_lpLogger->Log(EC_LOGLEVEL_FATAL, "Can not set SSL cipher list to '%s': %s", server_ssl_ciphers, ERR_error_string(ERR_get_error(), 0));
+ er = ZARAFA_E_CALL_FAILED;
+ goto exit;
+ }
+
+ if (parseBool(m_lpConfig->GetSetting("server_ssl_prefer_server_ciphers"))) {
+ SSL_CTX_set_options(lpsSoap->ctx, SSL_OP_CIPHER_SERVER_PREFERENCE);
+ }
+
// request certificate from client, is OK if not present.
SSL_CTX_set_verify(lpsSoap->ctx, SSL_VERIFY_PEER | SSL_VERIFY_CLIENT_ONCE, NULL);

View file

@ -1,39 +0,0 @@
Patch by Robert Scheck <robert@fedoraproject.org> for zarafa >= 7.1.11 which removes the bundled PHP PEAR files/libraries
and replaces them by files and libraries shipped by the distribution. From file server/PEAR/JSON.php only the function
json_decode() is used, which can be provided by the php-json RPM package. The file server/PEAR/XML/Unserializer.php can
be provided by the php-pear-XML-Serializer RPM package. The rest of the PHP PEAR files/libraries are only dependencies of
these two files mentioned before (which are satisfied by the two newly required RPM packages).
--- zarafa-7.1.11.rsc/php-webclient-ajax/config.php.dist 2014-09-03 09:56:49.000000000 +0200
+++ zarafa-7.1.11.rsc/php-webclient-ajax/config.php.dist.php-unbundle 2014-09-07 18:24:28.000000000 +0200
@@ -56,7 +56,7 @@
// Define the server paths
set_include_path(BASE_PATH. PATH_SEPARATOR .
- BASE_PATH."server/PEAR/" . PATH_SEPARATOR .
+ "/usr/share/pear/" . PATH_SEPARATOR .
"/usr/share/php/");
// Define the relative URL for dialogs, this string is appended with HTTP GET arguments
--- zarafa-7.1.11.rsc/php-webclient-ajax/zarafa.php 2014-09-03 10:45:06.000000000 +0200
+++ zarafa-7.1.11.rsc/php-webclient-ajax/zarafa.php.php-unbundle 2014-09-07 18:21:36.000000000 +0200
@@ -59,7 +59,7 @@
include("config.php");
include("defaults.php");
include("server/util.php");
- require("server/PEAR/JSON.php");
+ @include("server/PEAR/JSON.php");
require("mapi/mapi.util.php");
require("mapi/mapicode.php");
--- zarafa-7.1.11.rsc/php-webclient-ajax/server/core/class.xmlparser.php 2014-09-03 10:45:06.000000000 +0200
+++ zarafa-7.1.11.rsc/php-webclient-ajax/server/core/class.xmlparser.php.php-unbundle 2014-09-07 18:22:40.000000000 +0200
@@ -50,7 +50,7 @@
?>
<?php
- require_once("server/PEAR/XML/Unserializer.php");
+ require_once("XML/Unserializer.php");
/**
* XML Parser

View file

@ -1,88 +0,0 @@
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa <= 7.1.11 which enhances my earlier
this year implemented "disable_plaintext_auth" feature (new option in Zarafa >= 7.1.10 to disable
all plaintext authentications unless SSL/TLS is used), https://jira.zarafa.com/browse/ZCP-12142
contains the initial implementation and a more verbose feature description.
Given that there are unfortunately still Zarafa systems around using saslauthd without pam_mapi
but rimap instead the "disable_plaintext_auth" feature prevents them from enabling this option as
rimap doesn't support SSL/TLS; https://jira.zarafa.com/browse/ZCP-12473 contains an example report
by a Zarafa customer. Thus this patch adds an exception if the source IPv4 address is "127.0.0.1"
and allows even if "disable_plaintext_auth" is enabled a cleartext authentication. It was a design
decision to check only for 127.0.0.1/32 rather 127.0.0.0/8 because there seem to be systems where
the loopback network except 127.0.0.1/32 is routable?!
Important: The technical implementation of this patch might be not perfect as I am not really a C/
C++ developer. There should be a code review by an experienced C/C++ developer before merging into
Zarafa core.
--- zarafa-7.1.11/gateway/IMAP.cpp 2014-09-03 10:45:06.000000000 +0200
+++ zarafa-7.1.11/gateway/IMAP.cpp.plaintext_auth_localhost 2014-09-24 01:29:10.000000000 +0200
@@ -757,7 +757,7 @@
if (!lpChannel->UsingSsl() && lpChannel->sslctx())
strCapabilities += " STARTTLS";
- if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0)
+ if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0)
strCapabilities += " LOGINDISABLED";
else
strCapabilities += " AUTH=PLAIN";
@@ -923,7 +923,7 @@
char *plain = lpConfig->GetSetting("disable_plaintext_auth");
// If plaintext authentication was disabled any authentication attempt must be refused very soon
- if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0) {
+ if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0) {
hr2 = HrResponse(RESP_TAGGED_NO, strTag, "[PRIVACYREQUIRED] Plaintext authentication disallowed on non-secure "
"(SSL/TLS) connections.");
if (hr2 != hrSuccess)
@@ -1002,7 +1002,7 @@
}
// If plaintext authentication was disabled any login attempt must be refused very soon
- if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0) {
+ if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0) {
hr2 = HrResponse(RESP_UNTAGGED, "BAD [ALERT] Plaintext authentication not allowed without SSL/TLS, but your client "
"did it anyway. If anyone was listening, the password was exposed.");
if (hr2 != hrSuccess)
--- zarafa-7.1.11/gateway/POP3.cpp 2014-09-03 10:45:06.000000000 +0200
+++ zarafa-7.1.11/gateway/POP3.cpp.plaintext_auth_localhost 2014-09-24 01:30:41.000000000 +0200
@@ -320,7 +320,7 @@
if (!lpChannel->UsingSsl() && lpChannel->sslctx())
strCapabilities += "STLS\r\n";
- if (!(!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0))
+ if (!(!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0))
strCapabilities += "USER\r\n";
}
@@ -402,7 +402,7 @@
HRESULT hr = hrSuccess;
char *plain = lpConfig->GetSetting("disable_plaintext_auth");
- if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0) {
+ if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0) {
hr = HrResponse(POP3_RESP_AUTH_ERROR, "Plaintext authentication disallowed on non-secure (SSL/TLS) connections");
lpLogger->Log(EC_LOGLEVEL_ERROR, "Aborted login from %s with username \"%s\" (tried to use disallowed plaintext auth)",
lpChannel->GetIPAddress().c_str(), strUser.c_str());
@@ -431,7 +431,7 @@
HRESULT hr = hrSuccess;
char *plain = lpConfig->GetSetting("disable_plaintext_auth");
- if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0) {
+ if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0) {
hr = HrResponse(POP3_RESP_AUTH_ERROR, "Plaintext authentication disallowed on non-secure (SSL/TLS) connections");
if(szUser.empty())
lpLogger->Log(EC_LOGLEVEL_ERROR, "Aborted login from %s without username (tried to use disallowed "
--- zarafa-7.1.11/doc/manual.xml 2014-09-03 09:56:28.000000000 +0200
+++ zarafa-7.1.11/doc/manual.xml.plaintext_auth_localhost 2014-10-15 01:22:14.000000000 +0200
@@ -8024,7 +8024,9 @@
<term><option>disable_plaintext_auth</option></term>
<listitem>
<para>Disable all plaintext POP3 and IMAP authentications unless
- SSL/TLS is used. Obviously this requires at least
+ SSL/TLS is used (except for connections originating from
+ <replaceable>127.0.0.1</replaceable> to allow saslauthd with rimap).
+ Obviously enabling this configuration option requires at least
<replaceable>ssl_private_key_file</replaceable> and
<replaceable>ssl_certificate_file</replaceable> to take effect.</para>
<para>Default: <replaceable>no</replaceable></para>

View file

@ -1,85 +0,0 @@
Patch by Robert Scheck <robert@fedoraproject.org> for zarafa >= 7.1.11, which works
around the broken libtool of Debian. Multilib/multiarch systems like Fedora or Red
Hat Enterprise Linux are using /usr/lib64 for 64 bit libraries and /usr/lib is used
for 32 bit libraries. That allows to run 32 bit software on 64 bit systems. Debian
systems only use /usr/lib which contains only 32 or 64 bit systems depending on the
architecture.
Libtool hardcodes the runtime search path in a library (rpath), if the library that
is used for linking is not within the default system library path. The result is,
that if aclocal.m4/configure files are generated by a Debian system, but used on a
Fedora or Red Hat Enterprise Linux 64 bit system for compiling, "-rpath /usr/lib64"
makes it into the binary.
Fedora and EPEL (for Red Hat Enterprise Linux) do not allow binaries with rpath, as
the Linux dynamic linker is usually smarter than the hardcoded path.
The fix for this issue is to add the optional /lib64 and /usr/lib64 directories at/
within libtool in front of the regular /lib and /usr/lib directories at the system
library path. These libtool information are hold in aclocal.m4, which is generated
by running aclocal. As the content of aclocal.m4 is included into configure during
a run of autoconf, aclocal.m4 needs to be modified within the upstream build system
each time after a aclocal run - until Debian's libtool is fixed at Debian upstream.
Applying the fix is either possible by using the first hunk of the patch (second
hunk is runtime-only if configure file has been already generated) or by running
the following sed command after each aclocal run within the upstream build system:
sed -e 's@\(# Append ld.so.conf contents to the search path\)@# Add ABI-specific directories to the system library path.\n sys_lib_dlsearch_path_spec="/lib64 /usr/lib64 /lib /usr/lib"\n\n \1@' \
-e 's@/lib /usr/lib $lt_ld_extra@$sys_lib_dlsearch_path_spec $lt_ld_extra@' -i zarafa-7.1.11/aclocal.m4
More information regarding this topic can be found for example at:
- http://osdir.com/ml/bug-libtool-gnu/2009-12/msg00034.html
- http://lists.gnu.org/archive/html/libtool/2009-01/msg00039.html
- http://thread.gmane.org/gmane.comp.gnu.libtool.general/8339/focus=8345
--- zarafa-7.1.11/aclocal.m4 2014-09-03 09:56:52.000000000 +0200
+++ zarafa-7.1.11/aclocal.m4.rpath 2014-09-07 17:20:37.000000000 +0200
@@ -2672,10 +2672,13 @@
# before this can be enabled.
hardcode_into_libs=yes
+ # Add ABI-specific directories to the system library path.
+ sys_lib_dlsearch_path_spec="/lib64 /usr/lib64 /lib /usr/lib"
+
# Append ld.so.conf contents to the search path
if test -f /etc/ld.so.conf; then
lt_ld_extra=`awk '/^include / { system(sprintf("cd /etc; cat %s 2>/dev/null", \[$]2)); skip = 1; } { if (!skip) print \[$]0; skip = 0; }' < /etc/ld.so.conf | $SED -e 's/#.*//;/^[ ]*hwcap[ ]/d;s/[:, ]/ /g;s/=[^=]*$//;s/=[^= ]* / /g;s/"//g;/^$/d' | tr '\n' ' '`
- sys_lib_dlsearch_path_spec="/lib /usr/lib $lt_ld_extra"
+ sys_lib_dlsearch_path_spec="$sys_lib_dlsearch_path_spec $lt_ld_extra"
fi
# We used to test for /lib/ld.so.1 and disable shared libraries on
--- zarafa-7.1.11/configure 2014-09-03 09:56:53.000000000 +0200
+++ zarafa-7.1.11/configure.rpath 2014-09-07 17:28:07.000000000 +0200
@@ -10983,10 +10983,13 @@
# before this can be enabled.
hardcode_into_libs=yes
+ # Add ABI-specific directories to the system library path.
+ sys_lib_dlsearch_path_spec="/lib64 /usr/lib64 /lib /usr/lib"
+
# Append ld.so.conf contents to the search path
if test -f /etc/ld.so.conf; then
lt_ld_extra=`awk '/^include / { system(sprintf("cd /etc; cat %s 2>/dev/null", \$2)); skip = 1; } { if (!skip) print \$0; skip = 0; }' < /etc/ld.so.conf | $SED -e 's/#.*//;/^[ ]*hwcap[ ]/d;s/[:, ]/ /g;s/=[^=]*$//;s/=[^= ]* / /g;s/"//g;/^$/d' | tr '\n' ' '`
- sys_lib_dlsearch_path_spec="/lib /usr/lib $lt_ld_extra"
+ sys_lib_dlsearch_path_spec="$sys_lib_dlsearch_path_spec $lt_ld_extra"
fi
# We used to test for /lib/ld.so.1 and disable shared libraries on
@@ -16025,10 +16028,13 @@
# before this can be enabled.
hardcode_into_libs=yes
+ # Add ABI-specific directories to the system library path.
+ sys_lib_dlsearch_path_spec="/lib64 /usr/lib64 /lib /usr/lib"
+
# Append ld.so.conf contents to the search path
if test -f /etc/ld.so.conf; then
lt_ld_extra=`awk '/^include / { system(sprintf("cd /etc; cat %s 2>/dev/null", \$2)); skip = 1; } { if (!skip) print \$0; skip = 0; }' < /etc/ld.so.conf | $SED -e 's/#.*//;/^[ ]*hwcap[ ]/d;s/[:, ]/ /g;s/=[^=]*$//;s/=[^= ]* / /g;s/"//g;/^$/d' | tr '\n' ' '`
- sys_lib_dlsearch_path_spec="/lib /usr/lib $lt_ld_extra"
+ sys_lib_dlsearch_path_spec="$sys_lib_dlsearch_path_spec $lt_ld_extra"
fi
# We used to test for /lib/ld.so.1 and disable shared libraries on

View file

@ -1,82 +0,0 @@
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa <= 7.1.9 which implements ECDHE (elliptic
curve diffie-hellman key exchange) support. http://en.wikipedia.org/wiki/Elliptic_curve_cryptography is
providing more information about elliptic curves.
Suggestions for testing; run the following openssl(1) commands before and after applying this patch:
1. echo QUIT | openssl s_client -connect <host>:110 -starttls pop3 2>&1 | grep Cipher
2. echo QUIT | openssl s_client -connect <host>:143 -starttls imap 2>&1 | grep Cipher
3. echo QUIT | openssl s_client -connect <host>:237 2>&1 | grep Cipher
4. echo QUIT | openssl s_client -connect <host>:993 2>&1 | grep Cipher
5. echo QUIT | openssl s_client -connect <host>:995 2>&1 | grep Cipher
6. echo QUIT | openssl s_client -connect <host>:8443 2>&1 | grep Cipher
After applying this patch the output should contain e.g. "ECDHE-RSA-AES256-GCM-SHA384" on a Red Hat
Enterprise Linux 6.5 (only RHEL >= 6.5 has support for elliptic curve). Without this patch the result
is e.g. "AES256-GCM-SHA384".
Important: The technical implementation of this patch might be not perfect as I am not really a C/C++
developer. The logic and the implementation is heavily based on Sendmail. There should be a code review
by an experienced C/C++ and OpenSSL developer before merging into Zarafa core.
This patch should be only applied after ZCP-12143 and its dependencies. However this patch might maybe
not directly apply due to some previous merge issues as mentioned in Ticket#2014030810000131.
--- zarafa-7.1.9/common/ECChannel.cpp 2014-04-13 23:46:59.000000000 +0200
+++ zarafa-7.1.9/common/ECChannel.cpp.ssl_ecdhe 2014-04-13 23:59:43.000000000 +0200
@@ -97,6 +97,9 @@
char *ssl_name;
int ssl_proto, ssl_op = 0, ssl_include = 0, ssl_exclude = 0;
bool ssl_neg;
+#if !defined(OPENSSL_NO_ECDH) && defined(NID_X9_62_prime256v1)
+ EC_KEY *ecdh;
+#endif
if (lpConfig == NULL) {
hr = MAPI_E_CALL_FAILED;
@@ -113,6 +116,16 @@
lpCTX = SSL_CTX_new(SSLv23_server_method());
SSL_CTX_set_options(lpCTX, SSL_OP_ALL);
+#if !defined(OPENSSL_NO_ECDH) && defined(NID_X9_62_prime256v1)
+ ecdh = EC_KEY_new_by_curve_name(NID_X9_62_prime256v1);
+
+ if (ecdh != NULL) {
+ SSL_CTX_set_options(lpCTX, SSL_OP_SINGLE_ECDH_USE);
+ SSL_CTX_set_tmp_ecdh(lpCTX, ecdh);
+ EC_KEY_free(ecdh);
+ }
+#endif
+
ssl_name = strtok(ssl_protocols, " ");
while(ssl_name != NULL) {
if (*ssl_name != '!')
--- zarafa-7.1.9/provider/server/ECSoapServerConnection.cpp 2014-04-13 23:46:59.000000000 +0200
+++ zarafa-7.1.9/provider/server/ECSoapServerConnection.cpp.ssl_ecdhe 2014-04-14 00:00:54.000000000 +0200
@@ -245,6 +245,9 @@
char *ssl_name;
int ssl_proto, ssl_op = 0, ssl_include = 0, ssl_exclude = 0;
bool ssl_neg;
+#if !defined(OPENSSL_NO_ECDH) && defined(NID_X9_62_prime256v1)
+ EC_KEY *ecdh;
+#endif
if(lpServerName == NULL) {
er = ZARAFA_E_INVALID_PARAMETER;
@@ -277,6 +280,16 @@
SSL_CTX_set_options(lpsSoap->ctx, SSL_OP_ALL);
+#if !defined(OPENSSL_NO_ECDH) && defined(NID_X9_62_prime256v1)
+ ecdh = EC_KEY_new_by_curve_name(NID_X9_62_prime256v1);
+
+ if (ecdh != NULL) {
+ SSL_CTX_set_options(lpsSoap->ctx, SSL_OP_SINGLE_ECDH_USE);
+ SSL_CTX_set_tmp_ecdh(lpsSoap->ctx, ecdh);
+ EC_KEY_free(ecdh);
+ }
+#endif
+
ssl_name = strtok(server_ssl_protocols, " ");
while(ssl_name != NULL) {
if (*ssl_name != '!')

View file

@ -1,48 +0,0 @@
#
# Zarafa Webaccess featuring a 'Look & Feel' similar to Outlook
#
Alias /webaccess /usr/share/zarafa-webaccess/
# Following Apache and PHP settings need to be set to work correct
#
<Directory /usr/share/zarafa-webaccess/>
# Some apache settings
DirectoryIndex index.php
Options -Indexes +FollowSymLinks
<IfModule mod_authz_core.c>
# Apache 2.4
Require all granted
</IfModule>
<IfModule !mod_authz_core.c>
# Apache 2.2
Order allow,deny
Allow from all
</IfModule>
# Register globals must be off
php_flag register_globals off
# Magic quotes must be off
php_flag magic_quotes_gpc off
php_flag magic_quotes_runtime off
# The maximum POST limit. To upload large files, this value must
# be larger than upload_max_filesize.
php_value post_max_size 31M
php_value upload_max_filesize 30M
# Short open tags must be on
php_flag short_open_tag on
# Uncomment to enhance security of WebAccess by restricting cookies
# to only be provided over HTTPS connections
# php_flag session.cookie_secure on
# php_flag session.cookie_httponly on
# Uncomment for debugging purposes only. Make sure Apache/PHP can
# write to this file or no errors will be logged!
# php_flag log_errors on
# php_value error_log /var/lib/zarafa-webaccess/error_log
</Directory>

View file

@ -1,2 +0,0 @@
; Enable Zarafa mapi extension module
extension=mapi.so

View file

@ -1,100 +0,0 @@
/var/log/zarafa/archiver.log {
weekly
missingok
rotate 52
compress
delaycompress
notifempty
create 0644 zarafa zarafa
}
/var/log/zarafa/dagent.log {
weekly
missingok
rotate 52
compress
delaycompress
notifempty
postrotate
killall -HUP zarafa-dagent 2> /dev/null || true
endscript
create 0644 zarafa zarafa
}
/var/log/zarafa/gateway.log {
weekly
missingok
rotate 52
compress
delaycompress
notifempty
postrotate
killall -HUP zarafa-gateway 2> /dev/null || true
endscript
create 0644 zarafa zarafa
}
/var/log/zarafa/ical.log {
weekly
missingok
rotate 52
compress
delaycompress
notifempty
postrotate
killall -HUP zarafa-ical 2> /dev/null || true
endscript
create 0644 zarafa zarafa
}
/var/log/zarafa/indexer.log {
weekly
missingok
rotate 52
compress
delaycompress
notifempty
postrotate
killall -HUP zarafa-indexer 2> /dev/null || true
endscript
create 0644 zarafa zarafa
}
/var/log/zarafa/monitor.log {
weekly
missingok
rotate 52
compress
delaycompress
notifempty
postrotate
killall -HUP zarafa-monitor 2> /dev/null || true
endscript
create 0644 zarafa zarafa
}
/var/log/zarafa/server.log /var/log/zarafa/audit.log {
weekly
missingok
rotate 52
compress
delaycompress
notifempty
postrotate
killall -HUP zarafa-server 2> /dev/null || true
endscript
create 0644 zarafa zarafa
}
/var/log/zarafa/spooler.log {
weekly
missingok
rotate 52
compress
delaycompress
notifempty
postrotate
killall -HUP zarafa-spooler 2> /dev/null || true
endscript
create 0644 zarafa zarafa
}

File diff suppressed because it is too large Load diff