Compare commits
1 commit
| Author | SHA1 | Date | |
|---|---|---|---|
| edecf3addf |
13 changed files with 1 additions and 2056 deletions
1
.gitignore
vendored
1
.gitignore
vendored
|
|
@ -1 +0,0 @@
|
|||
zcp-7.?.*.tar.gz
|
||||
1
dead.package
Normal file
1
dead.package
Normal file
|
|
@ -0,0 +1 @@
|
|||
Package is retired
|
||||
1
sources
1
sources
|
|
@ -1 +0,0 @@
|
|||
7317dd7889303abbbd30e39f04771f10 zcp-7.1.11.tar.gz
|
||||
|
|
@ -1,28 +0,0 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for zarafa >= 7.1.10 which re-adds the ability to disable
|
||||
zarafa-search during build-time. This is e.g. required if CLucene and/or Kyotocabinet is unavailable or
|
||||
broken on the given system and/or architecture. Interestingly that patch is not new, I wrote these lines
|
||||
in 2012 the first time, proposed them as a patch to Zarafa and got merged. With a recent Zarafa release it
|
||||
seems they silently removed it again...
|
||||
|
||||
--- zarafa-7.1.10/ECtools/zarafa-search/Makefile.am 2014-05-23 15:03:49.000000000 +0200
|
||||
+++ zarafa-7.1.10/ECtools/zarafa-search/Makefile.am.kyotocabinet 2014-07-10 21:48:42.000000000 +0200
|
||||
@@ -1,4 +1,8 @@
|
||||
+if WITH_CLUCENE
|
||||
+if WITH_KYOTOCABINET
|
||||
bin_PROGRAMS = zarafa-search
|
||||
+endif
|
||||
+endif
|
||||
|
||||
AM_CPPFLAGS = ${ZCPPFLAGS} \
|
||||
-I${top_srcdir}/mapi4linux/include \
|
||||
--- zarafa-7.1.10/ECtools/zarafa-search/Makefile.in 2014-05-23 15:04:02.000000000 +0200
|
||||
+++ zarafa-7.1.10/ECtools/zarafa-search/Makefile.in.kyotocabinet 2014-07-10 21:49:16.000000000 +0200
|
||||
@@ -34,7 +34,7 @@
|
||||
POST_UNINSTALL = :
|
||||
build_triplet = @build@
|
||||
host_triplet = @host@
|
||||
-bin_PROGRAMS = zarafa-search$(EXEEXT)
|
||||
+@WITH_CLUCENE_TRUE@@WITH_KYOTOCABINET_TRUE@bin_PROGRAMS = zarafa-search$(EXEEXT)
|
||||
subdir = ECtools/zarafa-search
|
||||
DIST_COMMON = $(srcdir)/Makefile.am $(srcdir)/Makefile.in
|
||||
ACLOCAL_M4 = $(top_srcdir)/aclocal.m4
|
||||
|
|
@ -1,446 +0,0 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa <= 7.1.10 which implements much more
|
||||
fine granulated configuration settings for SSL/TLS protocol and cipher enabling and disabling. The
|
||||
currently available "ssl_enable_v2" setting allows either to disable SSLv2 (and enables SSLv3 only
|
||||
instead) or to enable all, thus SSLv2, SSLv3, TLSv1, TLSv1.1 and TLSv1.2 (TLSv1.1 and TLSv1.2 only
|
||||
if Zarafa was linked against OpenSSL 1.0.1 or later). Since SSLv2 has known protocol weaknesses it
|
||||
never should be enabled - but for Zarafa it currently must be enabled to support TLSv1 and better.
|
||||
|
||||
This patch introduces the new setting "ssl_protocols" which replaces "ssl_enable_v2". The default
|
||||
is "!SSLv2" to simply disable SSLv2 by default. The setting can be filled either with SSL protocols
|
||||
that shall be enabled and/or disabled, e.g. "SSLv3 TLSv1" or "!SSLv2 !SSLv3". However only the more
|
||||
usual disable/exclude option should be used as this does not exclude future protocols by default.
|
||||
|
||||
Further this patch introduces the completely new setting "ssl_ciphers". This one allows to set SSL
|
||||
cipher suites. Right now, all SSL ciphers are accepted which is just weak or might Zarafa even make
|
||||
even vulnerable to known SSL attacks. The German Federal Office for Information Security (BSI) says
|
||||
that RC4 should not be used anymore - but Zarafa does it by default. And without this patch there
|
||||
is also no way for Zarafa administrators to avoid that. Indeed this setting has the risk to get the
|
||||
administrators ending up in a cipher mismatch between different systems but this new setting still
|
||||
could be declared as officially unsupported and only for the brave ones who know what they do. Thus
|
||||
the default is already set to something less weak than before but still below BSI recommendations.
|
||||
|
||||
Finally this patch introduces the also new setting "ssl_prefer_server_ciphers". It does what it is
|
||||
named after: When choosing a cipher during an SSL/TLS handshake, normally the client's preference
|
||||
is used. If this setting is enabled, the server's preference will be used instead. This comes handy
|
||||
to administrators for strange cipher orderings required for special configurations and clients - or
|
||||
new weaknesses where workarounds are required for the time being.
|
||||
|
||||
Testing: Configure zarafa-gateway, zarafa-ical and zarafa-server for cleartext and SSL as usual.
|
||||
Try to login via POP3S, IMAPS, CalDAV-SSL and MAPI in SOAP over HTTPS. Change SSL protocols and the
|
||||
ciphers to something more weak ("SSLv2" and "LOW") or to something more strong ("TLSv1.2" and e.g.
|
||||
"HIGH"). During all my tests I did not figure out any newly introduced issue or Zarafa breakage.
|
||||
|
||||
Important: The technical implementation of this patch might be not perfect as I am not really a C/
|
||||
C++ developer. The logic and the implementation is heavily based on Dovecot, Postfix and hints from
|
||||
https://docs.fedoraproject.org/en-US/Fedora_Security_Team/html/Defensive_Coding/. There should be
|
||||
a code review and code clean up by an experienced C/C++ developer before merging into Zarafa core.
|
||||
|
||||
This patch should be only applied in conjuction with the POP3 RESP-CODES and AUTH-RESP-CODE patch,
|
||||
the POP3 CAPA (CAPABILITIES) patch as well as the POP3 STLS (STARTTLS) patch applied before.
|
||||
|
||||
--- zarafa-7.1.10/caldav/CalDAV.cpp 2014-05-23 15:56:36.000000000 +0200
|
||||
+++ zarafa-7.1.10/caldav/CalDAV.cpp.rsc 2014-08-12 19:45:04.000000000 +0200
|
||||
@@ -220,7 +220,9 @@
|
||||
{ "log_timestamp", "1" },
|
||||
{ "ssl_private_key_file", "/etc/zarafa/ical/privkey.pem" },
|
||||
{ "ssl_certificate_file", "/etc/zarafa/ical/cert.pem" },
|
||||
- { "ssl_enable_v2", "no" },
|
||||
+ { "ssl_protocols", "!SSLv2" },
|
||||
+ { "ssl_ciphers", "ALL:!LOW:!SSLv2:!EXP:!aNULL" },
|
||||
+ { "ssl_prefer_server_ciphers", "no" },
|
||||
{ "ssl_verify_client", "no" },
|
||||
{ "ssl_verify_file", "" },
|
||||
{ "ssl_verify_path", "" },
|
||||
--- zarafa-7.1.10/common/ECChannel.cpp 2014-05-23 15:56:36.000000000 +0200
|
||||
+++ zarafa-7.1.10/common/ECChannel.cpp.rsc 2014-08-12 19:48:00.000000000 +0200
|
||||
@@ -92,6 +92,11 @@
|
||||
HRESULT hr = hrSuccess;
|
||||
char *szFile = NULL;
|
||||
char *szPath = NULL;
|
||||
+ char *ssl_protocols = strdup(lpConfig->GetSetting("ssl_protocols"));
|
||||
+ char *ssl_ciphers = lpConfig->GetSetting("ssl_ciphers");
|
||||
+ char *ssl_name;
|
||||
+ int ssl_proto, ssl_op = 0, ssl_include = 0, ssl_exclude = 0;
|
||||
+ bool ssl_neg;
|
||||
|
||||
if (lpConfig == NULL) {
|
||||
hr = MAPI_E_CALL_FAILED;
|
||||
@@ -107,11 +112,79 @@
|
||||
SSL_load_error_strings();
|
||||
lpCTX = SSL_CTX_new(SSLv23_server_method());
|
||||
SSL_CTX_set_options(lpCTX, SSL_OP_ALL);
|
||||
- SSL_CTX_set_default_verify_paths(lpCTX);
|
||||
|
||||
- // disable SSLv2 support
|
||||
- if (!parseBool(lpConfig->GetSetting("ssl_enable_v2", "", "no")))
|
||||
- SSL_CTX_set_options(lpCTX, SSL_OP_NO_SSLv2);
|
||||
+ ssl_name = strtok(ssl_protocols, " ");
|
||||
+ while(ssl_name != NULL) {
|
||||
+ if (*ssl_name != '!')
|
||||
+ ssl_neg = FALSE;
|
||||
+ else {
|
||||
+ ssl_name++;
|
||||
+ ssl_neg = TRUE;
|
||||
+ }
|
||||
+
|
||||
+ if (strcasecmp(ssl_name, SSL_TXT_SSLV2) == 0)
|
||||
+ ssl_proto = 0x01;
|
||||
+ else if (strcasecmp(ssl_name, SSL_TXT_SSLV3) == 0)
|
||||
+ ssl_proto = 0x02;
|
||||
+ else if (strcasecmp(ssl_name, SSL_TXT_TLSV1) == 0)
|
||||
+ ssl_proto = 0x04;
|
||||
+#ifdef SSL_TXT_TLSV1_1
|
||||
+ else if (strcasecmp(ssl_name, SSL_TXT_TLSV1_1) == 0)
|
||||
+ ssl_proto = 0x08;
|
||||
+#endif
|
||||
+#ifdef SSL_TXT_TLSV1_2
|
||||
+ else if (strcasecmp(ssl_name, SSL_TXT_TLSV1_2) == 0)
|
||||
+ ssl_proto = 0x10;
|
||||
+#endif
|
||||
+ else {
|
||||
+ lpLogger->Log(EC_LOGLEVEL_ERROR, "Unknown protocol '%s' in ssl_protocols setting", ssl_name);
|
||||
+ hr = MAPI_E_CALL_FAILED;
|
||||
+ goto exit;
|
||||
+ }
|
||||
+
|
||||
+ if (ssl_neg)
|
||||
+ ssl_exclude |= ssl_proto;
|
||||
+ else
|
||||
+ ssl_include |= ssl_proto;
|
||||
+
|
||||
+ ssl_name = strtok(NULL, " ");
|
||||
+ }
|
||||
+
|
||||
+ if (ssl_include != 0) {
|
||||
+ // Exclude everything, except those that are included (and let excludes still override those)
|
||||
+ ssl_exclude |= 0x1f & ~ssl_include;
|
||||
+ }
|
||||
+
|
||||
+ if ((ssl_exclude & 0x01) != 0)
|
||||
+ ssl_op |= SSL_OP_NO_SSLv2;
|
||||
+ if ((ssl_exclude & 0x02) != 0)
|
||||
+ ssl_op |= SSL_OP_NO_SSLv3;
|
||||
+ if ((ssl_exclude & 0x04) != 0)
|
||||
+ ssl_op |= SSL_OP_NO_TLSv1;
|
||||
+#ifdef SSL_OP_NO_TLSv1_1
|
||||
+ if ((ssl_exclude & 0x08) != 0)
|
||||
+ ssl_op |= SSL_OP_NO_TLSv1_1;
|
||||
+#endif
|
||||
+#ifdef SSL_OP_NO_TLSv1_2
|
||||
+ if ((ssl_exclude & 0x10) != 0)
|
||||
+ ssl_op |= SSL_OP_NO_TLSv1_2;
|
||||
+#endif
|
||||
+
|
||||
+ if (ssl_protocols) {
|
||||
+ SSL_CTX_set_options(lpCTX, ssl_op);
|
||||
+ }
|
||||
+
|
||||
+ if (ssl_ciphers && SSL_CTX_set_cipher_list(lpCTX, ssl_ciphers) != 1) {
|
||||
+ lpLogger->Log(EC_LOGLEVEL_ERROR, "Can not set SSL cipher list to '%s': %s", ssl_ciphers, ERR_error_string(ERR_get_error(), 0));
|
||||
+ hr = MAPI_E_CALL_FAILED;
|
||||
+ goto exit;
|
||||
+ }
|
||||
+
|
||||
+ if (parseBool(lpConfig->GetSetting("ssl_prefer_server_ciphers"))) {
|
||||
+ SSL_CTX_set_options(lpCTX, SSL_OP_CIPHER_SERVER_PREFERENCE);
|
||||
+ }
|
||||
+
|
||||
+ SSL_CTX_set_default_verify_paths(lpCTX);
|
||||
|
||||
if (SSL_CTX_use_certificate_chain_file(lpCTX, lpConfig->GetSetting("ssl_certificate_file")) != 1) {
|
||||
lpLogger->Log(EC_LOGLEVEL_ERROR, "SSL CTX certificate file error: %s", ERR_error_string(ERR_get_error(), 0));
|
||||
--- zarafa-7.1.10/doc/manual.xml 2014-05-23 15:01:13.000000000 +0200
|
||||
+++ zarafa-7.1.10/doc/manual.xml.rsc 2014-08-12 19:45:04.000000000 +0200
|
||||
@@ -4226,11 +4226,33 @@
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
- <term><option>server_ssl_enable_v2</option></term>
|
||||
+ <term><option>server_ssl_protocols</option></term>
|
||||
<listitem>
|
||||
- <para>Incoming SSL connections normally are v3.</para>
|
||||
- <para>Default: <replaceable>no</replaceable>
|
||||
- </para>
|
||||
+ <para>Disabled or enabled protocol names. Supported protocol names
|
||||
+ are <replaceable>SSLv2</replaceable>, <replaceable>SSLv3</replaceable>
|
||||
+ and <replaceable>TLSv1</replaceable>. If Zarafa was linked against
|
||||
+ OpenSSL 1.0.1 or later there is additional support for the new protocols
|
||||
+ <replaceable>TLSv1.1</replaceable> and <replaceable>TLSv1.2</replaceable>.
|
||||
+ To exclude both, SSLv2 and SSLv3 set <option>server_ssl_protocols</option>
|
||||
+ to <replaceable>!SSLv2 !SSLv3</replaceable>. SSLv2 is considered unsafe
|
||||
+ and these connections should not be accepted.</para>
|
||||
+ <para>Default: <replaceable>!SSLv2</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
+
|
||||
+ <varlistentry>
|
||||
+ <term><option>server_ssl_ciphers</option></term>
|
||||
+ <listitem>
|
||||
+ <para>SSL ciphers to use, set to <replaceable>ALL</replaceable> for backward compatibility.</para>
|
||||
+ <para>Default: <replaceable>ALL:!LOW:!SSLv2:!EXP:!aNULL</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
+
|
||||
+ <varlistentry>
|
||||
+ <term><option>server_ssl_prefer_server_ciphers</option></term>
|
||||
+ <listitem>
|
||||
+ <para>Prefer the server's order of SSL ciphers over client's.</para>
|
||||
+ <para>Default: <replaceable>no</replaceable></para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
@@ -8070,11 +8092,32 @@
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
- <term><option>ssl_enable_v2</option></term>
|
||||
+ <term><option>ssl_protocols</option></term>
|
||||
+ <listitem>
|
||||
+ <para>Disabled or enabled protocol names. Supported protocol names
|
||||
+ are <replaceable>SSLv2</replaceable>, <replaceable>SSLv3</replaceable>
|
||||
+ and <replaceable>TLSv1</replaceable>. If Zarafa was linked against
|
||||
+ OpenSSL 1.0.1 or later there is additional support for the new protocols
|
||||
+ <replaceable>TLSv1.1</replaceable> and <replaceable>TLSv1.2</replaceable>.
|
||||
+ To exclude both, SSLv2 and SSLv3 set <option>ssl_protocols</option>
|
||||
+ to <replaceable>!SSLv2 !SSLv3</replaceable>. SSLv2 is considered unsafe
|
||||
+ and these connections should not be accepted.</para>
|
||||
+ <para>Default: <replaceable>!SSLv2</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
+
|
||||
+ <varlistentry>
|
||||
+ <term><option>ssl_ciphers</option></term>
|
||||
+ <listitem>
|
||||
+ <para>SSL ciphers to use, set to <replaceable>ALL</replaceable> for backward compatibility.</para>
|
||||
+ <para>Default: <replaceable>ALL:!LOW:!SSLv2:!EXP:!aNULL</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
+
|
||||
+ <varlistentry>
|
||||
+ <term><option>ssl_prefer_server_ciphers</option></term>
|
||||
<listitem>
|
||||
- <para>Accept SSLv2 only connections. SSLv2 is considered
|
||||
- unsafe, and these connections should not be
|
||||
- accepted.</para>
|
||||
+ <para>Prefer the server's order of SSL ciphers over client's.</para>
|
||||
<para>Default: <replaceable>no</replaceable></para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
@@ -10075,11 +10118,32 @@
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
- <term><option>ssl_enable_v2</option></term>
|
||||
+ <term><option>ssl_protocols</option></term>
|
||||
+ <listitem>
|
||||
+ <para>Disabled or enabled protocol names. Supported protocol names
|
||||
+ are <replaceable>SSLv2</replaceable>, <replaceable>SSLv3</replaceable>
|
||||
+ and <replaceable>TLSv1</replaceable>. If Zarafa was linked against
|
||||
+ OpenSSL 1.0.1 or later there is additional support for the new protocols
|
||||
+ <replaceable>TLSv1.1</replaceable> and <replaceable>TLSv1.2</replaceable>.
|
||||
+ To exclude both, SSLv2 and SSLv3 set <option>ssl_protocols</option>
|
||||
+ to <replaceable>!SSLv2 !SSLv3</replaceable>. SSLv2 is considered unsafe
|
||||
+ and these connections should not be accepted.</para>
|
||||
+ <para>Default: <replaceable>!SSLv2</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
+
|
||||
+ <varlistentry>
|
||||
+ <term><option>ssl_ciphers</option></term>
|
||||
+ <listitem>
|
||||
+ <para>SSL ciphers to use, set to <replaceable>ALL</replaceable> for backward compatibility.</para>
|
||||
+ <para>Default: <replaceable>ALL:!LOW:!SSLv2:!EXP:!aNULL</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
+
|
||||
+ <varlistentry>
|
||||
+ <term><option>ssl_prefer_server_ciphers</option></term>
|
||||
<listitem>
|
||||
- <para>Accept SSLv2 only connections. SSLv2 is considered
|
||||
- unsafe, and these connections should not be
|
||||
- accepted.</para>
|
||||
+ <para>Prefer the server's order of SSL ciphers over client's.</para>
|
||||
<para>Default: <replaceable>no</replaceable></para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
--- zarafa-7.1.10/gateway/Gateway.cpp 2014-05-23 15:56:37.000000000 +0200
|
||||
+++ zarafa-7.1.10/gateway/Gateway.cpp.rsc 2014-08-12 19:45:04.000000000 +0200
|
||||
@@ -365,7 +365,9 @@
|
||||
{ "ssl_verify_client", "no" },
|
||||
{ "ssl_verify_file", "" },
|
||||
{ "ssl_verify_path", "" },
|
||||
- { "ssl_enable_v2", "no" },
|
||||
+ { "ssl_protocols", "!SSLv2" },
|
||||
+ { "ssl_ciphers", "ALL:!LOW:!SSLv2:!EXP:!aNULL" },
|
||||
+ { "ssl_prefer_server_ciphers", "no" },
|
||||
{ "log_method", "file" },
|
||||
{ "log_file", "-" },
|
||||
{ "log_level", "2", CONFIGSETTING_RELOADABLE },
|
||||
--- zarafa-7.1.10/installer/linux/gateway.cfg 2014-05-23 15:03:19.000000000 +0200
|
||||
+++ zarafa-7.1.10/installer/linux/gateway.cfg.rsc 2014-08-12 19:45:04.000000000 +0200
|
||||
@@ -84,8 +84,14 @@
|
||||
ssl_verify_file =
|
||||
ssl_verify_path =
|
||||
|
||||
-# Accept SSLv2 only incoming connections
|
||||
-ssl_enable_v2 = no
|
||||
+# SSL protocols to use, set to '!SSLv2' for 'ssl_enable_v2 = no'
|
||||
+ssl_protocols = !SSLv2
|
||||
+
|
||||
+# SSL ciphers to use, set to 'ALL' for backward compatibility
|
||||
+ssl_ciphers = ALL:!LOW:!SSLv2:!EXP:!aNULL
|
||||
+
|
||||
+# Prefer the server's order of SSL ciphers over client's
|
||||
+ssl_prefer_server_ciphers = no
|
||||
|
||||
# Process model, using pthreads (thread) or processes (fork)
|
||||
process_model = fork
|
||||
--- zarafa-7.1.10/installer/linux/ical.cfg 2014-05-23 15:03:19.000000000 +0200
|
||||
+++ zarafa-7.1.10/installer/linux/ical.cfg.rsc 2014-08-12 19:45:04.000000000 +0200
|
||||
@@ -66,8 +66,14 @@
|
||||
ssl_verify_file =
|
||||
ssl_verify_path =
|
||||
|
||||
-# Accept SSLv2 only incoming connections
|
||||
-ssl_enable_v2 = no
|
||||
+# SSL protocols to use, set to '!SSLv2' for 'ssl_enable_v2 = no'
|
||||
+ssl_protocols = !SSLv2
|
||||
+
|
||||
+# SSL ciphers to use, set to 'ALL' for backward compatibility
|
||||
+ssl_ciphers = ALL:!LOW:!SSLv2:!EXP:!aNULL
|
||||
+
|
||||
+# Prefer the server's order of SSL ciphers over client's
|
||||
+ssl_prefer_server_ciphers = no
|
||||
|
||||
##############################################################
|
||||
# OTHER ICAL SETTINGS
|
||||
--- zarafa-7.1.10/installer/linux/server.cfg 2014-05-23 15:03:19.000000000 +0200
|
||||
+++ zarafa-7.1.10/installer/linux/server.cfg.rsc 2014-08-12 19:45:04.000000000 +0200
|
||||
@@ -154,8 +154,14 @@
|
||||
# Path with CA certificates, e.g. /etc/ssl/certs
|
||||
server_ssl_ca_path =
|
||||
|
||||
-# Accept SSLv2 only connections. Normally v3 connections are used.
|
||||
-server_ssl_enable_v2 = no
|
||||
+# SSL protocols to use, set to '!SSLv2' for 'server_ssl_enable_v2 = no'
|
||||
+server_ssl_protocols = !SSLv2
|
||||
+
|
||||
+# SSL ciphers to use, set to 'ALL' for backward compatibility
|
||||
+server_ssl_ciphers = ALL:!LOW:!SSLv2:!EXP:!aNULL
|
||||
+
|
||||
+# Prefer the server's order of SSL ciphers over client's
|
||||
+server_ssl_prefer_server_ciphers = no
|
||||
|
||||
# Path of SSL Public keys of clients
|
||||
sslkeys_path = /etc/zarafa/sslkeys
|
||||
--- zarafa-7.1.10/provider/server/ECServer.cpp 2014-05-23 15:56:37.000000000 +0200
|
||||
+++ zarafa-7.1.10/provider/server/ECServer.cpp.rsc 2014-08-12 19:45:04.000000000 +0200
|
||||
@@ -919,7 +919,9 @@
|
||||
{ "server_ssl_key_pass", "server", CONFIGSETTING_EXACT },
|
||||
{ "server_ssl_ca_file", "/etc/zarafa/ssl/cacert.pem" },
|
||||
{ "server_ssl_ca_path", "" },
|
||||
- { "server_ssl_enable_v2", "no" },
|
||||
+ { "server_ssl_protocols", "!SSLv2" },
|
||||
+ { "server_ssl_ciphers", "ALL:!LOW:!SSLv2:!EXP:!aNULL" },
|
||||
+ { "server_ssl_prefer_server_ciphers", "no" },
|
||||
{ "sslkeys_path", "/etc/zarafa/sslkeys" }, // login keys
|
||||
// Database options
|
||||
{ "database_engine", "mysql" },
|
||||
--- zarafa-7.1.10/provider/server/ECSoapServerConnection.cpp 2014-05-23 15:56:37.000000000 +0200
|
||||
+++ zarafa-7.1.10/provider/server/ECSoapServerConnection.cpp.rsc 2014-08-12 19:45:04.000000000 +0200
|
||||
@@ -240,6 +240,11 @@
|
||||
ECRESULT er = erSuccess;
|
||||
int socket = SOAP_INVALID_SOCKET;
|
||||
struct soap *lpsSoap = NULL;
|
||||
+ char *server_ssl_protocols = strdup(m_lpConfig->GetSetting("server_ssl_protocols"));
|
||||
+ char *server_ssl_ciphers = m_lpConfig->GetSetting("server_ssl_ciphers");
|
||||
+ char *ssl_name;
|
||||
+ int ssl_proto, ssl_op = 0, ssl_include = 0, ssl_exclude = 0;
|
||||
+ bool ssl_neg;
|
||||
|
||||
if(lpServerName == NULL) {
|
||||
er = ZARAFA_E_INVALID_PARAMETER;
|
||||
@@ -270,10 +275,79 @@
|
||||
goto exit;
|
||||
}
|
||||
|
||||
- // disable SSLv2 support
|
||||
- if (!parseBool(m_lpConfig->GetSetting("server_ssl_enable_v2", "", "no")))
|
||||
- SSL_CTX_set_options(lpsSoap->ctx, SSL_OP_NO_SSLv2);
|
||||
-
|
||||
+ SSL_CTX_set_options(lpsSoap->ctx, SSL_OP_ALL);
|
||||
+
|
||||
+ ssl_name = strtok(server_ssl_protocols, " ");
|
||||
+ while(ssl_name != NULL) {
|
||||
+ if (*ssl_name != '!')
|
||||
+ ssl_neg = FALSE;
|
||||
+ else {
|
||||
+ ssl_name++;
|
||||
+ ssl_neg = TRUE;
|
||||
+ }
|
||||
+
|
||||
+ if (strcasecmp(ssl_name, SSL_TXT_SSLV2) == 0)
|
||||
+ ssl_proto = 0x01;
|
||||
+ else if (strcasecmp(ssl_name, SSL_TXT_SSLV3) == 0)
|
||||
+ ssl_proto = 0x02;
|
||||
+ else if (strcasecmp(ssl_name, SSL_TXT_TLSV1) == 0)
|
||||
+ ssl_proto = 0x04;
|
||||
+#ifdef SSL_TXT_TLSV1_1
|
||||
+ else if (strcasecmp(ssl_name, SSL_TXT_TLSV1_1) == 0)
|
||||
+ ssl_proto = 0x08;
|
||||
+#endif
|
||||
+#ifdef SSL_TXT_TLSV1_2
|
||||
+ else if (strcasecmp(ssl_name, SSL_TXT_TLSV1_2) == 0)
|
||||
+ ssl_proto = 0x10;
|
||||
+#endif
|
||||
+ else {
|
||||
+ m_lpLogger->Log(EC_LOGLEVEL_FATAL, "Unknown protocol '%s' in server_ssl_protocols setting", ssl_name);
|
||||
+ er = ZARAFA_E_CALL_FAILED;
|
||||
+ goto exit;
|
||||
+ }
|
||||
+
|
||||
+ if (ssl_neg)
|
||||
+ ssl_exclude |= ssl_proto;
|
||||
+ else
|
||||
+ ssl_include |= ssl_proto;
|
||||
+
|
||||
+ ssl_name = strtok(NULL, " ");
|
||||
+ }
|
||||
+
|
||||
+ if (ssl_include != 0) {
|
||||
+ // Exclude everything, except those that are included (and let excludes still override those)
|
||||
+ ssl_exclude |= 0x1f & ~ssl_include;
|
||||
+ }
|
||||
+
|
||||
+ if ((ssl_exclude & 0x01) != 0)
|
||||
+ ssl_op |= SSL_OP_NO_SSLv2;
|
||||
+ if ((ssl_exclude & 0x02) != 0)
|
||||
+ ssl_op |= SSL_OP_NO_SSLv3;
|
||||
+ if ((ssl_exclude & 0x04) != 0)
|
||||
+ ssl_op |= SSL_OP_NO_TLSv1;
|
||||
+#ifdef SSL_OP_NO_TLSv1_1
|
||||
+ if ((ssl_exclude & 0x08) != 0)
|
||||
+ ssl_op |= SSL_OP_NO_TLSv1_1;
|
||||
+#endif
|
||||
+#ifdef SSL_OP_NO_TLSv1_2
|
||||
+ if ((ssl_exclude & 0x10) != 0)
|
||||
+ ssl_op |= SSL_OP_NO_TLSv1_2;
|
||||
+#endif
|
||||
+
|
||||
+ if (server_ssl_protocols) {
|
||||
+ SSL_CTX_set_options(lpsSoap->ctx, ssl_op);
|
||||
+ }
|
||||
+
|
||||
+ if (server_ssl_ciphers && SSL_CTX_set_cipher_list(lpsSoap->ctx, server_ssl_ciphers) != 1) {
|
||||
+ m_lpLogger->Log(EC_LOGLEVEL_FATAL, "Can not set SSL cipher list to '%s': %s", server_ssl_ciphers, ERR_error_string(ERR_get_error(), 0));
|
||||
+ er = ZARAFA_E_CALL_FAILED;
|
||||
+ goto exit;
|
||||
+ }
|
||||
+
|
||||
+ if (parseBool(m_lpConfig->GetSetting("server_ssl_prefer_server_ciphers"))) {
|
||||
+ SSL_CTX_set_options(lpsSoap->ctx, SSL_OP_CIPHER_SERVER_PREFERENCE);
|
||||
+ }
|
||||
+
|
||||
// request certificate from client, is OK if not present.
|
||||
SSL_CTX_set_verify(lpsSoap->ctx, SSL_VERIFY_PEER | SSL_VERIFY_CLIENT_ONCE, NULL);
|
||||
|
||||
|
|
@ -1,39 +0,0 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for zarafa >= 7.1.11 which removes the bundled PHP PEAR files/libraries
|
||||
and replaces them by files and libraries shipped by the distribution. From file server/PEAR/JSON.php only the function
|
||||
json_decode() is used, which can be provided by the php-json RPM package. The file server/PEAR/XML/Unserializer.php can
|
||||
be provided by the php-pear-XML-Serializer RPM package. The rest of the PHP PEAR files/libraries are only dependencies of
|
||||
these two files mentioned before (which are satisfied by the two newly required RPM packages).
|
||||
|
||||
--- zarafa-7.1.11.rsc/php-webclient-ajax/config.php.dist 2014-09-03 09:56:49.000000000 +0200
|
||||
+++ zarafa-7.1.11.rsc/php-webclient-ajax/config.php.dist.php-unbundle 2014-09-07 18:24:28.000000000 +0200
|
||||
@@ -56,7 +56,7 @@
|
||||
|
||||
// Define the server paths
|
||||
set_include_path(BASE_PATH. PATH_SEPARATOR .
|
||||
- BASE_PATH."server/PEAR/" . PATH_SEPARATOR .
|
||||
+ "/usr/share/pear/" . PATH_SEPARATOR .
|
||||
"/usr/share/php/");
|
||||
|
||||
// Define the relative URL for dialogs, this string is appended with HTTP GET arguments
|
||||
--- zarafa-7.1.11.rsc/php-webclient-ajax/zarafa.php 2014-09-03 10:45:06.000000000 +0200
|
||||
+++ zarafa-7.1.11.rsc/php-webclient-ajax/zarafa.php.php-unbundle 2014-09-07 18:21:36.000000000 +0200
|
||||
@@ -59,7 +59,7 @@
|
||||
include("config.php");
|
||||
include("defaults.php");
|
||||
include("server/util.php");
|
||||
- require("server/PEAR/JSON.php");
|
||||
+ @include("server/PEAR/JSON.php");
|
||||
|
||||
require("mapi/mapi.util.php");
|
||||
require("mapi/mapicode.php");
|
||||
--- zarafa-7.1.11.rsc/php-webclient-ajax/server/core/class.xmlparser.php 2014-09-03 10:45:06.000000000 +0200
|
||||
+++ zarafa-7.1.11.rsc/php-webclient-ajax/server/core/class.xmlparser.php.php-unbundle 2014-09-07 18:22:40.000000000 +0200
|
||||
@@ -50,7 +50,7 @@
|
||||
|
||||
?>
|
||||
<?php
|
||||
- require_once("server/PEAR/XML/Unserializer.php");
|
||||
+ require_once("XML/Unserializer.php");
|
||||
|
||||
/**
|
||||
* XML Parser
|
||||
|
|
@ -1,88 +0,0 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa <= 7.1.11 which enhances my earlier
|
||||
this year implemented "disable_plaintext_auth" feature (new option in Zarafa >= 7.1.10 to disable
|
||||
all plaintext authentications unless SSL/TLS is used), https://jira.zarafa.com/browse/ZCP-12142
|
||||
contains the initial implementation and a more verbose feature description.
|
||||
|
||||
Given that there are unfortunately still Zarafa systems around using saslauthd without pam_mapi
|
||||
but rimap instead the "disable_plaintext_auth" feature prevents them from enabling this option as
|
||||
rimap doesn't support SSL/TLS; https://jira.zarafa.com/browse/ZCP-12473 contains an example report
|
||||
by a Zarafa customer. Thus this patch adds an exception if the source IPv4 address is "127.0.0.1"
|
||||
and allows even if "disable_plaintext_auth" is enabled a cleartext authentication. It was a design
|
||||
decision to check only for 127.0.0.1/32 rather 127.0.0.0/8 because there seem to be systems where
|
||||
the loopback network except 127.0.0.1/32 is routable?!
|
||||
|
||||
Important: The technical implementation of this patch might be not perfect as I am not really a C/
|
||||
C++ developer. There should be a code review by an experienced C/C++ developer before merging into
|
||||
Zarafa core.
|
||||
|
||||
--- zarafa-7.1.11/gateway/IMAP.cpp 2014-09-03 10:45:06.000000000 +0200
|
||||
+++ zarafa-7.1.11/gateway/IMAP.cpp.plaintext_auth_localhost 2014-09-24 01:29:10.000000000 +0200
|
||||
@@ -757,7 +757,7 @@
|
||||
if (!lpChannel->UsingSsl() && lpChannel->sslctx())
|
||||
strCapabilities += " STARTTLS";
|
||||
|
||||
- if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0)
|
||||
+ if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0)
|
||||
strCapabilities += " LOGINDISABLED";
|
||||
else
|
||||
strCapabilities += " AUTH=PLAIN";
|
||||
@@ -923,7 +923,7 @@
|
||||
char *plain = lpConfig->GetSetting("disable_plaintext_auth");
|
||||
|
||||
// If plaintext authentication was disabled any authentication attempt must be refused very soon
|
||||
- if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0) {
|
||||
+ if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0) {
|
||||
hr2 = HrResponse(RESP_TAGGED_NO, strTag, "[PRIVACYREQUIRED] Plaintext authentication disallowed on non-secure "
|
||||
"(SSL/TLS) connections.");
|
||||
if (hr2 != hrSuccess)
|
||||
@@ -1002,7 +1002,7 @@
|
||||
}
|
||||
|
||||
// If plaintext authentication was disabled any login attempt must be refused very soon
|
||||
- if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0) {
|
||||
+ if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0) {
|
||||
hr2 = HrResponse(RESP_UNTAGGED, "BAD [ALERT] Plaintext authentication not allowed without SSL/TLS, but your client "
|
||||
"did it anyway. If anyone was listening, the password was exposed.");
|
||||
if (hr2 != hrSuccess)
|
||||
--- zarafa-7.1.11/gateway/POP3.cpp 2014-09-03 10:45:06.000000000 +0200
|
||||
+++ zarafa-7.1.11/gateway/POP3.cpp.plaintext_auth_localhost 2014-09-24 01:30:41.000000000 +0200
|
||||
@@ -320,7 +320,7 @@
|
||||
if (!lpChannel->UsingSsl() && lpChannel->sslctx())
|
||||
strCapabilities += "STLS\r\n";
|
||||
|
||||
- if (!(!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0))
|
||||
+ if (!(!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0))
|
||||
strCapabilities += "USER\r\n";
|
||||
}
|
||||
|
||||
@@ -402,7 +402,7 @@
|
||||
HRESULT hr = hrSuccess;
|
||||
char *plain = lpConfig->GetSetting("disable_plaintext_auth");
|
||||
|
||||
- if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0) {
|
||||
+ if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0) {
|
||||
hr = HrResponse(POP3_RESP_AUTH_ERROR, "Plaintext authentication disallowed on non-secure (SSL/TLS) connections");
|
||||
lpLogger->Log(EC_LOGLEVEL_ERROR, "Aborted login from %s with username \"%s\" (tried to use disallowed plaintext auth)",
|
||||
lpChannel->GetIPAddress().c_str(), strUser.c_str());
|
||||
@@ -431,7 +431,7 @@
|
||||
HRESULT hr = hrSuccess;
|
||||
char *plain = lpConfig->GetSetting("disable_plaintext_auth");
|
||||
|
||||
- if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0) {
|
||||
+ if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0) {
|
||||
hr = HrResponse(POP3_RESP_AUTH_ERROR, "Plaintext authentication disallowed on non-secure (SSL/TLS) connections");
|
||||
if(szUser.empty())
|
||||
lpLogger->Log(EC_LOGLEVEL_ERROR, "Aborted login from %s without username (tried to use disallowed "
|
||||
--- zarafa-7.1.11/doc/manual.xml 2014-09-03 09:56:28.000000000 +0200
|
||||
+++ zarafa-7.1.11/doc/manual.xml.plaintext_auth_localhost 2014-10-15 01:22:14.000000000 +0200
|
||||
@@ -8024,7 +8024,9 @@
|
||||
<term><option>disable_plaintext_auth</option></term>
|
||||
<listitem>
|
||||
<para>Disable all plaintext POP3 and IMAP authentications unless
|
||||
- SSL/TLS is used. Obviously this requires at least
|
||||
+ SSL/TLS is used (except for connections originating from
|
||||
+ <replaceable>127.0.0.1</replaceable> to allow saslauthd with rimap).
|
||||
+ Obviously enabling this configuration option requires at least
|
||||
<replaceable>ssl_private_key_file</replaceable> and
|
||||
<replaceable>ssl_certificate_file</replaceable> to take effect.</para>
|
||||
<para>Default: <replaceable>no</replaceable></para>
|
||||
|
|
@ -1,85 +0,0 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for zarafa >= 7.1.11, which works
|
||||
around the broken libtool of Debian. Multilib/multiarch systems like Fedora or Red
|
||||
Hat Enterprise Linux are using /usr/lib64 for 64 bit libraries and /usr/lib is used
|
||||
for 32 bit libraries. That allows to run 32 bit software on 64 bit systems. Debian
|
||||
systems only use /usr/lib which contains only 32 or 64 bit systems depending on the
|
||||
architecture.
|
||||
|
||||
Libtool hardcodes the runtime search path in a library (rpath), if the library that
|
||||
is used for linking is not within the default system library path. The result is,
|
||||
that if aclocal.m4/configure files are generated by a Debian system, but used on a
|
||||
Fedora or Red Hat Enterprise Linux 64 bit system for compiling, "-rpath /usr/lib64"
|
||||
makes it into the binary.
|
||||
|
||||
Fedora and EPEL (for Red Hat Enterprise Linux) do not allow binaries with rpath, as
|
||||
the Linux dynamic linker is usually smarter than the hardcoded path.
|
||||
|
||||
The fix for this issue is to add the optional /lib64 and /usr/lib64 directories at/
|
||||
within libtool in front of the regular /lib and /usr/lib directories at the system
|
||||
library path. These libtool information are hold in aclocal.m4, which is generated
|
||||
by running aclocal. As the content of aclocal.m4 is included into configure during
|
||||
a run of autoconf, aclocal.m4 needs to be modified within the upstream build system
|
||||
each time after a aclocal run - until Debian's libtool is fixed at Debian upstream.
|
||||
|
||||
Applying the fix is either possible by using the first hunk of the patch (second
|
||||
hunk is runtime-only if configure file has been already generated) or by running
|
||||
the following sed command after each aclocal run within the upstream build system:
|
||||
|
||||
sed -e 's@\(# Append ld.so.conf contents to the search path\)@# Add ABI-specific directories to the system library path.\n sys_lib_dlsearch_path_spec="/lib64 /usr/lib64 /lib /usr/lib"\n\n \1@' \
|
||||
-e 's@/lib /usr/lib $lt_ld_extra@$sys_lib_dlsearch_path_spec $lt_ld_extra@' -i zarafa-7.1.11/aclocal.m4
|
||||
|
||||
More information regarding this topic can be found for example at:
|
||||
|
||||
- http://osdir.com/ml/bug-libtool-gnu/2009-12/msg00034.html
|
||||
- http://lists.gnu.org/archive/html/libtool/2009-01/msg00039.html
|
||||
- http://thread.gmane.org/gmane.comp.gnu.libtool.general/8339/focus=8345
|
||||
|
||||
--- zarafa-7.1.11/aclocal.m4 2014-09-03 09:56:52.000000000 +0200
|
||||
+++ zarafa-7.1.11/aclocal.m4.rpath 2014-09-07 17:20:37.000000000 +0200
|
||||
@@ -2672,10 +2672,13 @@
|
||||
# before this can be enabled.
|
||||
hardcode_into_libs=yes
|
||||
|
||||
+ # Add ABI-specific directories to the system library path.
|
||||
+ sys_lib_dlsearch_path_spec="/lib64 /usr/lib64 /lib /usr/lib"
|
||||
+
|
||||
# Append ld.so.conf contents to the search path
|
||||
if test -f /etc/ld.so.conf; then
|
||||
lt_ld_extra=`awk '/^include / { system(sprintf("cd /etc; cat %s 2>/dev/null", \[$]2)); skip = 1; } { if (!skip) print \[$]0; skip = 0; }' < /etc/ld.so.conf | $SED -e 's/#.*//;/^[ ]*hwcap[ ]/d;s/[:, ]/ /g;s/=[^=]*$//;s/=[^= ]* / /g;s/"//g;/^$/d' | tr '\n' ' '`
|
||||
- sys_lib_dlsearch_path_spec="/lib /usr/lib $lt_ld_extra"
|
||||
+ sys_lib_dlsearch_path_spec="$sys_lib_dlsearch_path_spec $lt_ld_extra"
|
||||
fi
|
||||
|
||||
# We used to test for /lib/ld.so.1 and disable shared libraries on
|
||||
--- zarafa-7.1.11/configure 2014-09-03 09:56:53.000000000 +0200
|
||||
+++ zarafa-7.1.11/configure.rpath 2014-09-07 17:28:07.000000000 +0200
|
||||
@@ -10983,10 +10983,13 @@
|
||||
# before this can be enabled.
|
||||
hardcode_into_libs=yes
|
||||
|
||||
+ # Add ABI-specific directories to the system library path.
|
||||
+ sys_lib_dlsearch_path_spec="/lib64 /usr/lib64 /lib /usr/lib"
|
||||
+
|
||||
# Append ld.so.conf contents to the search path
|
||||
if test -f /etc/ld.so.conf; then
|
||||
lt_ld_extra=`awk '/^include / { system(sprintf("cd /etc; cat %s 2>/dev/null", \$2)); skip = 1; } { if (!skip) print \$0; skip = 0; }' < /etc/ld.so.conf | $SED -e 's/#.*//;/^[ ]*hwcap[ ]/d;s/[:, ]/ /g;s/=[^=]*$//;s/=[^= ]* / /g;s/"//g;/^$/d' | tr '\n' ' '`
|
||||
- sys_lib_dlsearch_path_spec="/lib /usr/lib $lt_ld_extra"
|
||||
+ sys_lib_dlsearch_path_spec="$sys_lib_dlsearch_path_spec $lt_ld_extra"
|
||||
fi
|
||||
|
||||
# We used to test for /lib/ld.so.1 and disable shared libraries on
|
||||
@@ -16025,10 +16028,13 @@
|
||||
# before this can be enabled.
|
||||
hardcode_into_libs=yes
|
||||
|
||||
+ # Add ABI-specific directories to the system library path.
|
||||
+ sys_lib_dlsearch_path_spec="/lib64 /usr/lib64 /lib /usr/lib"
|
||||
+
|
||||
# Append ld.so.conf contents to the search path
|
||||
if test -f /etc/ld.so.conf; then
|
||||
lt_ld_extra=`awk '/^include / { system(sprintf("cd /etc; cat %s 2>/dev/null", \$2)); skip = 1; } { if (!skip) print \$0; skip = 0; }' < /etc/ld.so.conf | $SED -e 's/#.*//;/^[ ]*hwcap[ ]/d;s/[:, ]/ /g;s/=[^=]*$//;s/=[^= ]* / /g;s/"//g;/^$/d' | tr '\n' ' '`
|
||||
- sys_lib_dlsearch_path_spec="/lib /usr/lib $lt_ld_extra"
|
||||
+ sys_lib_dlsearch_path_spec="$sys_lib_dlsearch_path_spec $lt_ld_extra"
|
||||
fi
|
||||
|
||||
# We used to test for /lib/ld.so.1 and disable shared libraries on
|
||||
|
|
@ -1,82 +0,0 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa <= 7.1.9 which implements ECDHE (elliptic
|
||||
curve diffie-hellman key exchange) support. http://en.wikipedia.org/wiki/Elliptic_curve_cryptography is
|
||||
providing more information about elliptic curves.
|
||||
|
||||
Suggestions for testing; run the following openssl(1) commands before and after applying this patch:
|
||||
|
||||
1. echo QUIT | openssl s_client -connect <host>:110 -starttls pop3 2>&1 | grep Cipher
|
||||
2. echo QUIT | openssl s_client -connect <host>:143 -starttls imap 2>&1 | grep Cipher
|
||||
3. echo QUIT | openssl s_client -connect <host>:237 2>&1 | grep Cipher
|
||||
4. echo QUIT | openssl s_client -connect <host>:993 2>&1 | grep Cipher
|
||||
5. echo QUIT | openssl s_client -connect <host>:995 2>&1 | grep Cipher
|
||||
6. echo QUIT | openssl s_client -connect <host>:8443 2>&1 | grep Cipher
|
||||
|
||||
After applying this patch the output should contain e.g. "ECDHE-RSA-AES256-GCM-SHA384" on a Red Hat
|
||||
Enterprise Linux 6.5 (only RHEL >= 6.5 has support for elliptic curve). Without this patch the result
|
||||
is e.g. "AES256-GCM-SHA384".
|
||||
|
||||
Important: The technical implementation of this patch might be not perfect as I am not really a C/C++
|
||||
developer. The logic and the implementation is heavily based on Sendmail. There should be a code review
|
||||
by an experienced C/C++ and OpenSSL developer before merging into Zarafa core.
|
||||
|
||||
This patch should be only applied after ZCP-12143 and its dependencies. However this patch might maybe
|
||||
not directly apply due to some previous merge issues as mentioned in Ticket#2014030810000131.
|
||||
|
||||
--- zarafa-7.1.9/common/ECChannel.cpp 2014-04-13 23:46:59.000000000 +0200
|
||||
+++ zarafa-7.1.9/common/ECChannel.cpp.ssl_ecdhe 2014-04-13 23:59:43.000000000 +0200
|
||||
@@ -97,6 +97,9 @@
|
||||
char *ssl_name;
|
||||
int ssl_proto, ssl_op = 0, ssl_include = 0, ssl_exclude = 0;
|
||||
bool ssl_neg;
|
||||
+#if !defined(OPENSSL_NO_ECDH) && defined(NID_X9_62_prime256v1)
|
||||
+ EC_KEY *ecdh;
|
||||
+#endif
|
||||
|
||||
if (lpConfig == NULL) {
|
||||
hr = MAPI_E_CALL_FAILED;
|
||||
@@ -113,6 +116,16 @@
|
||||
lpCTX = SSL_CTX_new(SSLv23_server_method());
|
||||
SSL_CTX_set_options(lpCTX, SSL_OP_ALL);
|
||||
|
||||
+#if !defined(OPENSSL_NO_ECDH) && defined(NID_X9_62_prime256v1)
|
||||
+ ecdh = EC_KEY_new_by_curve_name(NID_X9_62_prime256v1);
|
||||
+
|
||||
+ if (ecdh != NULL) {
|
||||
+ SSL_CTX_set_options(lpCTX, SSL_OP_SINGLE_ECDH_USE);
|
||||
+ SSL_CTX_set_tmp_ecdh(lpCTX, ecdh);
|
||||
+ EC_KEY_free(ecdh);
|
||||
+ }
|
||||
+#endif
|
||||
+
|
||||
ssl_name = strtok(ssl_protocols, " ");
|
||||
while(ssl_name != NULL) {
|
||||
if (*ssl_name != '!')
|
||||
--- zarafa-7.1.9/provider/server/ECSoapServerConnection.cpp 2014-04-13 23:46:59.000000000 +0200
|
||||
+++ zarafa-7.1.9/provider/server/ECSoapServerConnection.cpp.ssl_ecdhe 2014-04-14 00:00:54.000000000 +0200
|
||||
@@ -245,6 +245,9 @@
|
||||
char *ssl_name;
|
||||
int ssl_proto, ssl_op = 0, ssl_include = 0, ssl_exclude = 0;
|
||||
bool ssl_neg;
|
||||
+#if !defined(OPENSSL_NO_ECDH) && defined(NID_X9_62_prime256v1)
|
||||
+ EC_KEY *ecdh;
|
||||
+#endif
|
||||
|
||||
if(lpServerName == NULL) {
|
||||
er = ZARAFA_E_INVALID_PARAMETER;
|
||||
@@ -277,6 +280,16 @@
|
||||
|
||||
SSL_CTX_set_options(lpsSoap->ctx, SSL_OP_ALL);
|
||||
|
||||
+#if !defined(OPENSSL_NO_ECDH) && defined(NID_X9_62_prime256v1)
|
||||
+ ecdh = EC_KEY_new_by_curve_name(NID_X9_62_prime256v1);
|
||||
+
|
||||
+ if (ecdh != NULL) {
|
||||
+ SSL_CTX_set_options(lpsSoap->ctx, SSL_OP_SINGLE_ECDH_USE);
|
||||
+ SSL_CTX_set_tmp_ecdh(lpsSoap->ctx, ecdh);
|
||||
+ EC_KEY_free(ecdh);
|
||||
+ }
|
||||
+#endif
|
||||
+
|
||||
ssl_name = strtok(server_ssl_protocols, " ");
|
||||
while(ssl_name != NULL) {
|
||||
if (*ssl_name != '!')
|
||||
|
|
@ -1,48 +0,0 @@
|
|||
#
|
||||
# Zarafa Webaccess featuring a 'Look & Feel' similar to Outlook
|
||||
#
|
||||
|
||||
Alias /webaccess /usr/share/zarafa-webaccess/
|
||||
|
||||
# Following Apache and PHP settings need to be set to work correct
|
||||
#
|
||||
<Directory /usr/share/zarafa-webaccess/>
|
||||
# Some apache settings
|
||||
DirectoryIndex index.php
|
||||
Options -Indexes +FollowSymLinks
|
||||
|
||||
<IfModule mod_authz_core.c>
|
||||
# Apache 2.4
|
||||
Require all granted
|
||||
</IfModule>
|
||||
<IfModule !mod_authz_core.c>
|
||||
# Apache 2.2
|
||||
Order allow,deny
|
||||
Allow from all
|
||||
</IfModule>
|
||||
|
||||
# Register globals must be off
|
||||
php_flag register_globals off
|
||||
|
||||
# Magic quotes must be off
|
||||
php_flag magic_quotes_gpc off
|
||||
php_flag magic_quotes_runtime off
|
||||
|
||||
# The maximum POST limit. To upload large files, this value must
|
||||
# be larger than upload_max_filesize.
|
||||
php_value post_max_size 31M
|
||||
php_value upload_max_filesize 30M
|
||||
|
||||
# Short open tags must be on
|
||||
php_flag short_open_tag on
|
||||
|
||||
# Uncomment to enhance security of WebAccess by restricting cookies
|
||||
# to only be provided over HTTPS connections
|
||||
# php_flag session.cookie_secure on
|
||||
# php_flag session.cookie_httponly on
|
||||
|
||||
# Uncomment for debugging purposes only. Make sure Apache/PHP can
|
||||
# write to this file or no errors will be logged!
|
||||
# php_flag log_errors on
|
||||
# php_value error_log /var/lib/zarafa-webaccess/error_log
|
||||
</Directory>
|
||||
|
|
@ -1,2 +0,0 @@
|
|||
; Enable Zarafa mapi extension module
|
||||
extension=mapi.so
|
||||
100
zarafa.logrotate
100
zarafa.logrotate
|
|
@ -1,100 +0,0 @@
|
|||
/var/log/zarafa/archiver.log {
|
||||
weekly
|
||||
missingok
|
||||
rotate 52
|
||||
compress
|
||||
delaycompress
|
||||
notifempty
|
||||
create 0644 zarafa zarafa
|
||||
}
|
||||
|
||||
/var/log/zarafa/dagent.log {
|
||||
weekly
|
||||
missingok
|
||||
rotate 52
|
||||
compress
|
||||
delaycompress
|
||||
notifempty
|
||||
postrotate
|
||||
killall -HUP zarafa-dagent 2> /dev/null || true
|
||||
endscript
|
||||
create 0644 zarafa zarafa
|
||||
}
|
||||
|
||||
/var/log/zarafa/gateway.log {
|
||||
weekly
|
||||
missingok
|
||||
rotate 52
|
||||
compress
|
||||
delaycompress
|
||||
notifempty
|
||||
postrotate
|
||||
killall -HUP zarafa-gateway 2> /dev/null || true
|
||||
endscript
|
||||
create 0644 zarafa zarafa
|
||||
}
|
||||
|
||||
/var/log/zarafa/ical.log {
|
||||
weekly
|
||||
missingok
|
||||
rotate 52
|
||||
compress
|
||||
delaycompress
|
||||
notifempty
|
||||
postrotate
|
||||
killall -HUP zarafa-ical 2> /dev/null || true
|
||||
endscript
|
||||
create 0644 zarafa zarafa
|
||||
}
|
||||
|
||||
/var/log/zarafa/indexer.log {
|
||||
weekly
|
||||
missingok
|
||||
rotate 52
|
||||
compress
|
||||
delaycompress
|
||||
notifempty
|
||||
postrotate
|
||||
killall -HUP zarafa-indexer 2> /dev/null || true
|
||||
endscript
|
||||
create 0644 zarafa zarafa
|
||||
}
|
||||
|
||||
/var/log/zarafa/monitor.log {
|
||||
weekly
|
||||
missingok
|
||||
rotate 52
|
||||
compress
|
||||
delaycompress
|
||||
notifempty
|
||||
postrotate
|
||||
killall -HUP zarafa-monitor 2> /dev/null || true
|
||||
endscript
|
||||
create 0644 zarafa zarafa
|
||||
}
|
||||
|
||||
/var/log/zarafa/server.log /var/log/zarafa/audit.log {
|
||||
weekly
|
||||
missingok
|
||||
rotate 52
|
||||
compress
|
||||
delaycompress
|
||||
notifempty
|
||||
postrotate
|
||||
killall -HUP zarafa-server 2> /dev/null || true
|
||||
endscript
|
||||
create 0644 zarafa zarafa
|
||||
}
|
||||
|
||||
/var/log/zarafa/spooler.log {
|
||||
weekly
|
||||
missingok
|
||||
rotate 52
|
||||
compress
|
||||
delaycompress
|
||||
notifempty
|
||||
postrotate
|
||||
killall -HUP zarafa-spooler 2> /dev/null || true
|
||||
endscript
|
||||
create 0644 zarafa zarafa
|
||||
}
|
||||
1136
zarafa.spec
1136
zarafa.spec
File diff suppressed because it is too large
Load diff
Loading…
Add table
Add a link
Reference in a new issue