Compare commits
21 commits
| Author | SHA1 | Date | |
|---|---|---|---|
| a5a8366ccf | |||
| 47cc873ba6 | |||
| 8f5d117f89 | |||
| ac3cd50389 | |||
| e225a36f01 | |||
| a56a8a43af | |||
| 4e07fdc3d5 | |||
| 8735de08ac | |||
| 55f9cedbfc | |||
| f800d1c727 | |||
| 17841d83c9 | |||
| c7ecef187e | |||
| 384c0c36e1 | |||
| 423e99d9b3 | |||
| 860fae1250 | |||
| ce0e01723f | |||
|
|
7e34c68abe | ||
| 09deb48f90 | |||
| 6485eb28e2 | |||
| 1b451fb6f4 | |||
| 4a32efa8ec |
24 changed files with 3784 additions and 485 deletions
2
sources
2
sources
|
|
@ -1 +1 @@
|
|||
7317dd7889303abbbd30e39f04771f10 zcp-7.1.11.tar.gz
|
||||
SHA512 (zcp-7.1.14.tar.gz) = 594ad30145b4a5db4f777ccf137b19296c1ef7250ab8731cbae102e1a466d0c33641056c0334bcd3d098d4e9d32d9c7e3730de72cf84251d6413bab70360ad1a
|
||||
|
|
|
|||
19
zarafa-7.1.10-imap-badcharset.patch
Normal file
19
zarafa-7.1.10-imap-badcharset.patch
Normal file
|
|
@ -0,0 +1,19 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa <= 7.1.10 which fixes the RFC-
|
||||
violating reply of the Zarafa IMAP gateway in response to a failed SEARCH CHARSET request.
|
||||
This is documented at http://tools.ietf.org/html/rfc3501#page-64: "BADCHARSET: Optionally
|
||||
followed by a parenthesized list of charsets. [...]". This patch adds missing parenthesis.
|
||||
|
||||
Proposed to upstream via e-mail on Sun, 27 Jul 2014 23:58:01 +0200, patch was put into the
|
||||
upstream ticket https://jira.zarafa.com/browse/ZCP-12504.
|
||||
|
||||
--- zarafa-7.1.10/gateway/IMAP.cpp 2014-05-23 15:56:37.000000000 +0200
|
||||
+++ zarafa-7.1.10/gateway/IMAP.cpp.imap-badcharset 2014-07-27 23:42:30.000000000 +0200
|
||||
@@ -2409,7 +2409,7 @@
|
||||
if (lstSearchCriteria[1] != "WINDOWS-1252") {
|
||||
iconv = new ECIConv("windows-1252", lstSearchCriteria[1]);
|
||||
if (!iconv->canConvert()) {
|
||||
- hr2 = HrResponse(RESP_TAGGED_NO, strTag, "[BADCHARSET WINDOWS-1252] "+strMode+"SEARCH charset not supported");
|
||||
+ hr2 = HrResponse(RESP_TAGGED_NO, strTag, "[BADCHARSET (WINDOWS-1252)] "+strMode+"SEARCH charset not supported");
|
||||
hr = MAPI_E_CALL_FAILED;
|
||||
goto exit;
|
||||
}
|
||||
93
zarafa-7.1.10-imap-fetch-body.patch
Normal file
93
zarafa-7.1.10-imap-fetch-body.patch
Normal file
|
|
@ -0,0 +1,93 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa <= 7.1.10 which fixes the RFC-
|
||||
violating reply of the Zarafa IMAP gateway in response to a body fetch request. This is
|
||||
documented at http://tools.ietf.org/html/rfc3501#page-55. Additionally this has been also
|
||||
compared with the Dovecot IMAP server as a nearly (or even de facto) IMAP server reference
|
||||
implementation. Please note that this is NOT a duplicate of ZCP-11590/ZCP-11739/ZCP-12365!
|
||||
|
||||
Wrong behaviour of Zarafa <= 7.1.10rc1-44973 (without this patch):
|
||||
> A4 FETCH 1 (BODY.PEEK[HEADER.FIELDS (FROM FROM)])
|
||||
< * 1 FETCH (BODY[HEADER.FIELDS (FROM FROM)] {66}
|
||||
From: User1 <user1@domain.org>
|
||||
From: User1 <user1@domain.org>
|
||||
|
||||
)
|
||||
< A4 OK FETCH completed
|
||||
|
||||
Comparison with IMAP server Dovecot 2.2.13:
|
||||
> A4 FETCH 1 (BODY.PEEK[HEADER.FIELDS (FROM FROM)])
|
||||
< * 1 FETCH (BODY[HEADER.FIELDS (FROM FROM)] {34}
|
||||
From: User1 <user1@domain.org>
|
||||
|
||||
)
|
||||
< A4 OK Fetch completed.
|
||||
|
||||
Correct behaviour of Zarafa (after having this patch applied):
|
||||
> A4 FETCH 1 (BODY.PEEK[HEADER.FIELDS (FROM FROM)])
|
||||
< * 1 FETCH (BODY[HEADER.FIELDS (FROM FROM)] {34}
|
||||
From: User1 <user1@domain.org>
|
||||
|
||||
)
|
||||
< A4 OK FETCH completed
|
||||
|
||||
Testing: Full IMAP dialog example from the client perspective (after this patch applied):
|
||||
< * OK [CAPABILITY IMAP4rev1 LITERAL+ AUTH=PLAIN] Zarafa IMAP gateway ready
|
||||
> A0 LOGIN robert robert
|
||||
< A0 OK [CAPABILITY IMAP4rev1 LITERAL+ CHILDREN XAOL-OPTION NAMESPACE QUOTA IDLE] LOGIN completed
|
||||
> A1 LIST "" INBOX
|
||||
< * LIST (\HasNoChildren) "/" "INBOX"
|
||||
< A1 OK LIST completed
|
||||
> A2 SELECT INBOX
|
||||
< * 2 EXISTS
|
||||
< * 0 RECENT
|
||||
< * FLAGS (\Seen \Draft \Deleted \Flagged \Answered $Forwarded)
|
||||
< * OK [PERMANENTFLAGS (\Seen \Draft \Deleted \Flagged \Answered $Forwarded)] Permanent flags
|
||||
< * OK [UIDNEXT 4343] Predicted next UID
|
||||
< * OK [UNSEEN 1] First unseen message
|
||||
< * OK [UIDVALIDITY 9313] UIDVALIDITY value
|
||||
< A2 OK [READ-WRITE] SELECT completed
|
||||
> A3 SEARCH UNSEEN ALL
|
||||
< * SEARCH 1 2
|
||||
< A3 OK SEARCH completed
|
||||
> A4 FETCH 1 (BODY.PEEK[HEADER.FIELDS (FROM FROM)])
|
||||
< * 1 FETCH (BODY[HEADER.FIELDS (FROM FROM)] {34}
|
||||
From: User1 <user1@domain.org>
|
||||
|
||||
)
|
||||
< A4 OK FETCH completed
|
||||
> A5 CLOSE
|
||||
< A5 OK CLOSE completed
|
||||
> A6 LOGOUT
|
||||
< * BYE Zarafa server logging out
|
||||
< A6 OK LOGOUT completed
|
||||
|
||||
IMPORTANT: This patch has been very carefully and extensively tested but it might not be
|
||||
perfect nevertheless as I am not really a C/C++ developer. There should be a code review
|
||||
by an experienced C/C++ developer before merging into Zarafa core.
|
||||
|
||||
Proposed to upstream via e-mail on Thu, 29 May 2014 01:55:35 +0200, patch was put into the
|
||||
upstream ticket https://jira.zarafa.com/browse/ZCP-12398.
|
||||
|
||||
--- zarafa-7.1.10/gateway/IMAP.cpp 2014-05-12 12:06:03.000000000 +0200
|
||||
+++ zarafa-7.1.10/gateway/IMAP.cpp.imap-fetch-body 2014-05-29 00:49:29.000000000 +0200
|
||||
@@ -5253,10 +5253,21 @@
|
||||
} else {
|
||||
vector<string> lstReqFields;
|
||||
vector<string>::iterator iterReqField;
|
||||
+ vector<string>::iterator r, w;
|
||||
+ set<string> tmpset;
|
||||
|
||||
// Get fields as vector
|
||||
lstReqFields = tokenize(strFields, " ");
|
||||
|
||||
+ // Make elements of vector unique
|
||||
+ for(r = lstReqFields.begin(), w = lstReqFields.begin(); r != lstReqFields.end(); ++r) {
|
||||
+ if(tmpset.insert(*r).second) {
|
||||
+ *w++ = *r;
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ lstReqFields.erase(w, lstReqFields.end());
|
||||
+
|
||||
// Output headers specified, in order of field set
|
||||
for(iterReqField = lstReqFields.begin(); iterReqField != lstReqFields.end(); iterReqField++) {
|
||||
for(iterField = lstFields.begin(); iterField != lstFields.end(); iterField++) {
|
||||
|
|
@ -4,6 +4,9 @@ broken on the given system and/or architecture. Interestingly that patch is not
|
|||
in 2012 the first time, proposed them as a patch to Zarafa and got merged. With a recent Zarafa release it
|
||||
seems they silently removed it again...
|
||||
|
||||
Proposed to upstream via e-mail on Fri, 11 Jul 2014 01:03:43 +0200, patch was put into the upstream ticket
|
||||
https://jira.zarafa.com/browse/ZCP-12463.
|
||||
|
||||
--- zarafa-7.1.10/ECtools/zarafa-search/Makefile.am 2014-05-23 15:03:49.000000000 +0200
|
||||
+++ zarafa-7.1.10/ECtools/zarafa-search/Makefile.am.kyotocabinet 2014-07-10 21:48:42.000000000 +0200
|
||||
@@ -1,4 +1,8 @@
|
||||
|
|
|
|||
|
|
@ -1,446 +0,0 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa <= 7.1.10 which implements much more
|
||||
fine granulated configuration settings for SSL/TLS protocol and cipher enabling and disabling. The
|
||||
currently available "ssl_enable_v2" setting allows either to disable SSLv2 (and enables SSLv3 only
|
||||
instead) or to enable all, thus SSLv2, SSLv3, TLSv1, TLSv1.1 and TLSv1.2 (TLSv1.1 and TLSv1.2 only
|
||||
if Zarafa was linked against OpenSSL 1.0.1 or later). Since SSLv2 has known protocol weaknesses it
|
||||
never should be enabled - but for Zarafa it currently must be enabled to support TLSv1 and better.
|
||||
|
||||
This patch introduces the new setting "ssl_protocols" which replaces "ssl_enable_v2". The default
|
||||
is "!SSLv2" to simply disable SSLv2 by default. The setting can be filled either with SSL protocols
|
||||
that shall be enabled and/or disabled, e.g. "SSLv3 TLSv1" or "!SSLv2 !SSLv3". However only the more
|
||||
usual disable/exclude option should be used as this does not exclude future protocols by default.
|
||||
|
||||
Further this patch introduces the completely new setting "ssl_ciphers". This one allows to set SSL
|
||||
cipher suites. Right now, all SSL ciphers are accepted which is just weak or might Zarafa even make
|
||||
even vulnerable to known SSL attacks. The German Federal Office for Information Security (BSI) says
|
||||
that RC4 should not be used anymore - but Zarafa does it by default. And without this patch there
|
||||
is also no way for Zarafa administrators to avoid that. Indeed this setting has the risk to get the
|
||||
administrators ending up in a cipher mismatch between different systems but this new setting still
|
||||
could be declared as officially unsupported and only for the brave ones who know what they do. Thus
|
||||
the default is already set to something less weak than before but still below BSI recommendations.
|
||||
|
||||
Finally this patch introduces the also new setting "ssl_prefer_server_ciphers". It does what it is
|
||||
named after: When choosing a cipher during an SSL/TLS handshake, normally the client's preference
|
||||
is used. If this setting is enabled, the server's preference will be used instead. This comes handy
|
||||
to administrators for strange cipher orderings required for special configurations and clients - or
|
||||
new weaknesses where workarounds are required for the time being.
|
||||
|
||||
Testing: Configure zarafa-gateway, zarafa-ical and zarafa-server for cleartext and SSL as usual.
|
||||
Try to login via POP3S, IMAPS, CalDAV-SSL and MAPI in SOAP over HTTPS. Change SSL protocols and the
|
||||
ciphers to something more weak ("SSLv2" and "LOW") or to something more strong ("TLSv1.2" and e.g.
|
||||
"HIGH"). During all my tests I did not figure out any newly introduced issue or Zarafa breakage.
|
||||
|
||||
Important: The technical implementation of this patch might be not perfect as I am not really a C/
|
||||
C++ developer. The logic and the implementation is heavily based on Dovecot, Postfix and hints from
|
||||
https://docs.fedoraproject.org/en-US/Fedora_Security_Team/html/Defensive_Coding/. There should be
|
||||
a code review and code clean up by an experienced C/C++ developer before merging into Zarafa core.
|
||||
|
||||
This patch should be only applied in conjuction with the POP3 RESP-CODES and AUTH-RESP-CODE patch,
|
||||
the POP3 CAPA (CAPABILITIES) patch as well as the POP3 STLS (STARTTLS) patch applied before.
|
||||
|
||||
--- zarafa-7.1.10/caldav/CalDAV.cpp 2014-05-23 15:56:36.000000000 +0200
|
||||
+++ zarafa-7.1.10/caldav/CalDAV.cpp.rsc 2014-08-12 19:45:04.000000000 +0200
|
||||
@@ -220,7 +220,9 @@
|
||||
{ "log_timestamp", "1" },
|
||||
{ "ssl_private_key_file", "/etc/zarafa/ical/privkey.pem" },
|
||||
{ "ssl_certificate_file", "/etc/zarafa/ical/cert.pem" },
|
||||
- { "ssl_enable_v2", "no" },
|
||||
+ { "ssl_protocols", "!SSLv2" },
|
||||
+ { "ssl_ciphers", "ALL:!LOW:!SSLv2:!EXP:!aNULL" },
|
||||
+ { "ssl_prefer_server_ciphers", "no" },
|
||||
{ "ssl_verify_client", "no" },
|
||||
{ "ssl_verify_file", "" },
|
||||
{ "ssl_verify_path", "" },
|
||||
--- zarafa-7.1.10/common/ECChannel.cpp 2014-05-23 15:56:36.000000000 +0200
|
||||
+++ zarafa-7.1.10/common/ECChannel.cpp.rsc 2014-08-12 19:48:00.000000000 +0200
|
||||
@@ -92,6 +92,11 @@
|
||||
HRESULT hr = hrSuccess;
|
||||
char *szFile = NULL;
|
||||
char *szPath = NULL;
|
||||
+ char *ssl_protocols = strdup(lpConfig->GetSetting("ssl_protocols"));
|
||||
+ char *ssl_ciphers = lpConfig->GetSetting("ssl_ciphers");
|
||||
+ char *ssl_name;
|
||||
+ int ssl_proto, ssl_op = 0, ssl_include = 0, ssl_exclude = 0;
|
||||
+ bool ssl_neg;
|
||||
|
||||
if (lpConfig == NULL) {
|
||||
hr = MAPI_E_CALL_FAILED;
|
||||
@@ -107,11 +112,79 @@
|
||||
SSL_load_error_strings();
|
||||
lpCTX = SSL_CTX_new(SSLv23_server_method());
|
||||
SSL_CTX_set_options(lpCTX, SSL_OP_ALL);
|
||||
- SSL_CTX_set_default_verify_paths(lpCTX);
|
||||
|
||||
- // disable SSLv2 support
|
||||
- if (!parseBool(lpConfig->GetSetting("ssl_enable_v2", "", "no")))
|
||||
- SSL_CTX_set_options(lpCTX, SSL_OP_NO_SSLv2);
|
||||
+ ssl_name = strtok(ssl_protocols, " ");
|
||||
+ while(ssl_name != NULL) {
|
||||
+ if (*ssl_name != '!')
|
||||
+ ssl_neg = FALSE;
|
||||
+ else {
|
||||
+ ssl_name++;
|
||||
+ ssl_neg = TRUE;
|
||||
+ }
|
||||
+
|
||||
+ if (strcasecmp(ssl_name, SSL_TXT_SSLV2) == 0)
|
||||
+ ssl_proto = 0x01;
|
||||
+ else if (strcasecmp(ssl_name, SSL_TXT_SSLV3) == 0)
|
||||
+ ssl_proto = 0x02;
|
||||
+ else if (strcasecmp(ssl_name, SSL_TXT_TLSV1) == 0)
|
||||
+ ssl_proto = 0x04;
|
||||
+#ifdef SSL_TXT_TLSV1_1
|
||||
+ else if (strcasecmp(ssl_name, SSL_TXT_TLSV1_1) == 0)
|
||||
+ ssl_proto = 0x08;
|
||||
+#endif
|
||||
+#ifdef SSL_TXT_TLSV1_2
|
||||
+ else if (strcasecmp(ssl_name, SSL_TXT_TLSV1_2) == 0)
|
||||
+ ssl_proto = 0x10;
|
||||
+#endif
|
||||
+ else {
|
||||
+ lpLogger->Log(EC_LOGLEVEL_ERROR, "Unknown protocol '%s' in ssl_protocols setting", ssl_name);
|
||||
+ hr = MAPI_E_CALL_FAILED;
|
||||
+ goto exit;
|
||||
+ }
|
||||
+
|
||||
+ if (ssl_neg)
|
||||
+ ssl_exclude |= ssl_proto;
|
||||
+ else
|
||||
+ ssl_include |= ssl_proto;
|
||||
+
|
||||
+ ssl_name = strtok(NULL, " ");
|
||||
+ }
|
||||
+
|
||||
+ if (ssl_include != 0) {
|
||||
+ // Exclude everything, except those that are included (and let excludes still override those)
|
||||
+ ssl_exclude |= 0x1f & ~ssl_include;
|
||||
+ }
|
||||
+
|
||||
+ if ((ssl_exclude & 0x01) != 0)
|
||||
+ ssl_op |= SSL_OP_NO_SSLv2;
|
||||
+ if ((ssl_exclude & 0x02) != 0)
|
||||
+ ssl_op |= SSL_OP_NO_SSLv3;
|
||||
+ if ((ssl_exclude & 0x04) != 0)
|
||||
+ ssl_op |= SSL_OP_NO_TLSv1;
|
||||
+#ifdef SSL_OP_NO_TLSv1_1
|
||||
+ if ((ssl_exclude & 0x08) != 0)
|
||||
+ ssl_op |= SSL_OP_NO_TLSv1_1;
|
||||
+#endif
|
||||
+#ifdef SSL_OP_NO_TLSv1_2
|
||||
+ if ((ssl_exclude & 0x10) != 0)
|
||||
+ ssl_op |= SSL_OP_NO_TLSv1_2;
|
||||
+#endif
|
||||
+
|
||||
+ if (ssl_protocols) {
|
||||
+ SSL_CTX_set_options(lpCTX, ssl_op);
|
||||
+ }
|
||||
+
|
||||
+ if (ssl_ciphers && SSL_CTX_set_cipher_list(lpCTX, ssl_ciphers) != 1) {
|
||||
+ lpLogger->Log(EC_LOGLEVEL_ERROR, "Can not set SSL cipher list to '%s': %s", ssl_ciphers, ERR_error_string(ERR_get_error(), 0));
|
||||
+ hr = MAPI_E_CALL_FAILED;
|
||||
+ goto exit;
|
||||
+ }
|
||||
+
|
||||
+ if (parseBool(lpConfig->GetSetting("ssl_prefer_server_ciphers"))) {
|
||||
+ SSL_CTX_set_options(lpCTX, SSL_OP_CIPHER_SERVER_PREFERENCE);
|
||||
+ }
|
||||
+
|
||||
+ SSL_CTX_set_default_verify_paths(lpCTX);
|
||||
|
||||
if (SSL_CTX_use_certificate_chain_file(lpCTX, lpConfig->GetSetting("ssl_certificate_file")) != 1) {
|
||||
lpLogger->Log(EC_LOGLEVEL_ERROR, "SSL CTX certificate file error: %s", ERR_error_string(ERR_get_error(), 0));
|
||||
--- zarafa-7.1.10/doc/manual.xml 2014-05-23 15:01:13.000000000 +0200
|
||||
+++ zarafa-7.1.10/doc/manual.xml.rsc 2014-08-12 19:45:04.000000000 +0200
|
||||
@@ -4226,11 +4226,33 @@
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
- <term><option>server_ssl_enable_v2</option></term>
|
||||
+ <term><option>server_ssl_protocols</option></term>
|
||||
<listitem>
|
||||
- <para>Incoming SSL connections normally are v3.</para>
|
||||
- <para>Default: <replaceable>no</replaceable>
|
||||
- </para>
|
||||
+ <para>Disabled or enabled protocol names. Supported protocol names
|
||||
+ are <replaceable>SSLv2</replaceable>, <replaceable>SSLv3</replaceable>
|
||||
+ and <replaceable>TLSv1</replaceable>. If Zarafa was linked against
|
||||
+ OpenSSL 1.0.1 or later there is additional support for the new protocols
|
||||
+ <replaceable>TLSv1.1</replaceable> and <replaceable>TLSv1.2</replaceable>.
|
||||
+ To exclude both, SSLv2 and SSLv3 set <option>server_ssl_protocols</option>
|
||||
+ to <replaceable>!SSLv2 !SSLv3</replaceable>. SSLv2 is considered unsafe
|
||||
+ and these connections should not be accepted.</para>
|
||||
+ <para>Default: <replaceable>!SSLv2</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
+
|
||||
+ <varlistentry>
|
||||
+ <term><option>server_ssl_ciphers</option></term>
|
||||
+ <listitem>
|
||||
+ <para>SSL ciphers to use, set to <replaceable>ALL</replaceable> for backward compatibility.</para>
|
||||
+ <para>Default: <replaceable>ALL:!LOW:!SSLv2:!EXP:!aNULL</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
+
|
||||
+ <varlistentry>
|
||||
+ <term><option>server_ssl_prefer_server_ciphers</option></term>
|
||||
+ <listitem>
|
||||
+ <para>Prefer the server's order of SSL ciphers over client's.</para>
|
||||
+ <para>Default: <replaceable>no</replaceable></para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
@@ -8070,11 +8092,32 @@
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
- <term><option>ssl_enable_v2</option></term>
|
||||
+ <term><option>ssl_protocols</option></term>
|
||||
+ <listitem>
|
||||
+ <para>Disabled or enabled protocol names. Supported protocol names
|
||||
+ are <replaceable>SSLv2</replaceable>, <replaceable>SSLv3</replaceable>
|
||||
+ and <replaceable>TLSv1</replaceable>. If Zarafa was linked against
|
||||
+ OpenSSL 1.0.1 or later there is additional support for the new protocols
|
||||
+ <replaceable>TLSv1.1</replaceable> and <replaceable>TLSv1.2</replaceable>.
|
||||
+ To exclude both, SSLv2 and SSLv3 set <option>ssl_protocols</option>
|
||||
+ to <replaceable>!SSLv2 !SSLv3</replaceable>. SSLv2 is considered unsafe
|
||||
+ and these connections should not be accepted.</para>
|
||||
+ <para>Default: <replaceable>!SSLv2</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
+
|
||||
+ <varlistentry>
|
||||
+ <term><option>ssl_ciphers</option></term>
|
||||
+ <listitem>
|
||||
+ <para>SSL ciphers to use, set to <replaceable>ALL</replaceable> for backward compatibility.</para>
|
||||
+ <para>Default: <replaceable>ALL:!LOW:!SSLv2:!EXP:!aNULL</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
+
|
||||
+ <varlistentry>
|
||||
+ <term><option>ssl_prefer_server_ciphers</option></term>
|
||||
<listitem>
|
||||
- <para>Accept SSLv2 only connections. SSLv2 is considered
|
||||
- unsafe, and these connections should not be
|
||||
- accepted.</para>
|
||||
+ <para>Prefer the server's order of SSL ciphers over client's.</para>
|
||||
<para>Default: <replaceable>no</replaceable></para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
@@ -10075,11 +10118,32 @@
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
- <term><option>ssl_enable_v2</option></term>
|
||||
+ <term><option>ssl_protocols</option></term>
|
||||
+ <listitem>
|
||||
+ <para>Disabled or enabled protocol names. Supported protocol names
|
||||
+ are <replaceable>SSLv2</replaceable>, <replaceable>SSLv3</replaceable>
|
||||
+ and <replaceable>TLSv1</replaceable>. If Zarafa was linked against
|
||||
+ OpenSSL 1.0.1 or later there is additional support for the new protocols
|
||||
+ <replaceable>TLSv1.1</replaceable> and <replaceable>TLSv1.2</replaceable>.
|
||||
+ To exclude both, SSLv2 and SSLv3 set <option>ssl_protocols</option>
|
||||
+ to <replaceable>!SSLv2 !SSLv3</replaceable>. SSLv2 is considered unsafe
|
||||
+ and these connections should not be accepted.</para>
|
||||
+ <para>Default: <replaceable>!SSLv2</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
+
|
||||
+ <varlistentry>
|
||||
+ <term><option>ssl_ciphers</option></term>
|
||||
+ <listitem>
|
||||
+ <para>SSL ciphers to use, set to <replaceable>ALL</replaceable> for backward compatibility.</para>
|
||||
+ <para>Default: <replaceable>ALL:!LOW:!SSLv2:!EXP:!aNULL</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
+
|
||||
+ <varlistentry>
|
||||
+ <term><option>ssl_prefer_server_ciphers</option></term>
|
||||
<listitem>
|
||||
- <para>Accept SSLv2 only connections. SSLv2 is considered
|
||||
- unsafe, and these connections should not be
|
||||
- accepted.</para>
|
||||
+ <para>Prefer the server's order of SSL ciphers over client's.</para>
|
||||
<para>Default: <replaceable>no</replaceable></para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
--- zarafa-7.1.10/gateway/Gateway.cpp 2014-05-23 15:56:37.000000000 +0200
|
||||
+++ zarafa-7.1.10/gateway/Gateway.cpp.rsc 2014-08-12 19:45:04.000000000 +0200
|
||||
@@ -365,7 +365,9 @@
|
||||
{ "ssl_verify_client", "no" },
|
||||
{ "ssl_verify_file", "" },
|
||||
{ "ssl_verify_path", "" },
|
||||
- { "ssl_enable_v2", "no" },
|
||||
+ { "ssl_protocols", "!SSLv2" },
|
||||
+ { "ssl_ciphers", "ALL:!LOW:!SSLv2:!EXP:!aNULL" },
|
||||
+ { "ssl_prefer_server_ciphers", "no" },
|
||||
{ "log_method", "file" },
|
||||
{ "log_file", "-" },
|
||||
{ "log_level", "2", CONFIGSETTING_RELOADABLE },
|
||||
--- zarafa-7.1.10/installer/linux/gateway.cfg 2014-05-23 15:03:19.000000000 +0200
|
||||
+++ zarafa-7.1.10/installer/linux/gateway.cfg.rsc 2014-08-12 19:45:04.000000000 +0200
|
||||
@@ -84,8 +84,14 @@
|
||||
ssl_verify_file =
|
||||
ssl_verify_path =
|
||||
|
||||
-# Accept SSLv2 only incoming connections
|
||||
-ssl_enable_v2 = no
|
||||
+# SSL protocols to use, set to '!SSLv2' for 'ssl_enable_v2 = no'
|
||||
+ssl_protocols = !SSLv2
|
||||
+
|
||||
+# SSL ciphers to use, set to 'ALL' for backward compatibility
|
||||
+ssl_ciphers = ALL:!LOW:!SSLv2:!EXP:!aNULL
|
||||
+
|
||||
+# Prefer the server's order of SSL ciphers over client's
|
||||
+ssl_prefer_server_ciphers = no
|
||||
|
||||
# Process model, using pthreads (thread) or processes (fork)
|
||||
process_model = fork
|
||||
--- zarafa-7.1.10/installer/linux/ical.cfg 2014-05-23 15:03:19.000000000 +0200
|
||||
+++ zarafa-7.1.10/installer/linux/ical.cfg.rsc 2014-08-12 19:45:04.000000000 +0200
|
||||
@@ -66,8 +66,14 @@
|
||||
ssl_verify_file =
|
||||
ssl_verify_path =
|
||||
|
||||
-# Accept SSLv2 only incoming connections
|
||||
-ssl_enable_v2 = no
|
||||
+# SSL protocols to use, set to '!SSLv2' for 'ssl_enable_v2 = no'
|
||||
+ssl_protocols = !SSLv2
|
||||
+
|
||||
+# SSL ciphers to use, set to 'ALL' for backward compatibility
|
||||
+ssl_ciphers = ALL:!LOW:!SSLv2:!EXP:!aNULL
|
||||
+
|
||||
+# Prefer the server's order of SSL ciphers over client's
|
||||
+ssl_prefer_server_ciphers = no
|
||||
|
||||
##############################################################
|
||||
# OTHER ICAL SETTINGS
|
||||
--- zarafa-7.1.10/installer/linux/server.cfg 2014-05-23 15:03:19.000000000 +0200
|
||||
+++ zarafa-7.1.10/installer/linux/server.cfg.rsc 2014-08-12 19:45:04.000000000 +0200
|
||||
@@ -154,8 +154,14 @@
|
||||
# Path with CA certificates, e.g. /etc/ssl/certs
|
||||
server_ssl_ca_path =
|
||||
|
||||
-# Accept SSLv2 only connections. Normally v3 connections are used.
|
||||
-server_ssl_enable_v2 = no
|
||||
+# SSL protocols to use, set to '!SSLv2' for 'server_ssl_enable_v2 = no'
|
||||
+server_ssl_protocols = !SSLv2
|
||||
+
|
||||
+# SSL ciphers to use, set to 'ALL' for backward compatibility
|
||||
+server_ssl_ciphers = ALL:!LOW:!SSLv2:!EXP:!aNULL
|
||||
+
|
||||
+# Prefer the server's order of SSL ciphers over client's
|
||||
+server_ssl_prefer_server_ciphers = no
|
||||
|
||||
# Path of SSL Public keys of clients
|
||||
sslkeys_path = /etc/zarafa/sslkeys
|
||||
--- zarafa-7.1.10/provider/server/ECServer.cpp 2014-05-23 15:56:37.000000000 +0200
|
||||
+++ zarafa-7.1.10/provider/server/ECServer.cpp.rsc 2014-08-12 19:45:04.000000000 +0200
|
||||
@@ -919,7 +919,9 @@
|
||||
{ "server_ssl_key_pass", "server", CONFIGSETTING_EXACT },
|
||||
{ "server_ssl_ca_file", "/etc/zarafa/ssl/cacert.pem" },
|
||||
{ "server_ssl_ca_path", "" },
|
||||
- { "server_ssl_enable_v2", "no" },
|
||||
+ { "server_ssl_protocols", "!SSLv2" },
|
||||
+ { "server_ssl_ciphers", "ALL:!LOW:!SSLv2:!EXP:!aNULL" },
|
||||
+ { "server_ssl_prefer_server_ciphers", "no" },
|
||||
{ "sslkeys_path", "/etc/zarafa/sslkeys" }, // login keys
|
||||
// Database options
|
||||
{ "database_engine", "mysql" },
|
||||
--- zarafa-7.1.10/provider/server/ECSoapServerConnection.cpp 2014-05-23 15:56:37.000000000 +0200
|
||||
+++ zarafa-7.1.10/provider/server/ECSoapServerConnection.cpp.rsc 2014-08-12 19:45:04.000000000 +0200
|
||||
@@ -240,6 +240,11 @@
|
||||
ECRESULT er = erSuccess;
|
||||
int socket = SOAP_INVALID_SOCKET;
|
||||
struct soap *lpsSoap = NULL;
|
||||
+ char *server_ssl_protocols = strdup(m_lpConfig->GetSetting("server_ssl_protocols"));
|
||||
+ char *server_ssl_ciphers = m_lpConfig->GetSetting("server_ssl_ciphers");
|
||||
+ char *ssl_name;
|
||||
+ int ssl_proto, ssl_op = 0, ssl_include = 0, ssl_exclude = 0;
|
||||
+ bool ssl_neg;
|
||||
|
||||
if(lpServerName == NULL) {
|
||||
er = ZARAFA_E_INVALID_PARAMETER;
|
||||
@@ -270,10 +275,79 @@
|
||||
goto exit;
|
||||
}
|
||||
|
||||
- // disable SSLv2 support
|
||||
- if (!parseBool(m_lpConfig->GetSetting("server_ssl_enable_v2", "", "no")))
|
||||
- SSL_CTX_set_options(lpsSoap->ctx, SSL_OP_NO_SSLv2);
|
||||
-
|
||||
+ SSL_CTX_set_options(lpsSoap->ctx, SSL_OP_ALL);
|
||||
+
|
||||
+ ssl_name = strtok(server_ssl_protocols, " ");
|
||||
+ while(ssl_name != NULL) {
|
||||
+ if (*ssl_name != '!')
|
||||
+ ssl_neg = FALSE;
|
||||
+ else {
|
||||
+ ssl_name++;
|
||||
+ ssl_neg = TRUE;
|
||||
+ }
|
||||
+
|
||||
+ if (strcasecmp(ssl_name, SSL_TXT_SSLV2) == 0)
|
||||
+ ssl_proto = 0x01;
|
||||
+ else if (strcasecmp(ssl_name, SSL_TXT_SSLV3) == 0)
|
||||
+ ssl_proto = 0x02;
|
||||
+ else if (strcasecmp(ssl_name, SSL_TXT_TLSV1) == 0)
|
||||
+ ssl_proto = 0x04;
|
||||
+#ifdef SSL_TXT_TLSV1_1
|
||||
+ else if (strcasecmp(ssl_name, SSL_TXT_TLSV1_1) == 0)
|
||||
+ ssl_proto = 0x08;
|
||||
+#endif
|
||||
+#ifdef SSL_TXT_TLSV1_2
|
||||
+ else if (strcasecmp(ssl_name, SSL_TXT_TLSV1_2) == 0)
|
||||
+ ssl_proto = 0x10;
|
||||
+#endif
|
||||
+ else {
|
||||
+ m_lpLogger->Log(EC_LOGLEVEL_FATAL, "Unknown protocol '%s' in server_ssl_protocols setting", ssl_name);
|
||||
+ er = ZARAFA_E_CALL_FAILED;
|
||||
+ goto exit;
|
||||
+ }
|
||||
+
|
||||
+ if (ssl_neg)
|
||||
+ ssl_exclude |= ssl_proto;
|
||||
+ else
|
||||
+ ssl_include |= ssl_proto;
|
||||
+
|
||||
+ ssl_name = strtok(NULL, " ");
|
||||
+ }
|
||||
+
|
||||
+ if (ssl_include != 0) {
|
||||
+ // Exclude everything, except those that are included (and let excludes still override those)
|
||||
+ ssl_exclude |= 0x1f & ~ssl_include;
|
||||
+ }
|
||||
+
|
||||
+ if ((ssl_exclude & 0x01) != 0)
|
||||
+ ssl_op |= SSL_OP_NO_SSLv2;
|
||||
+ if ((ssl_exclude & 0x02) != 0)
|
||||
+ ssl_op |= SSL_OP_NO_SSLv3;
|
||||
+ if ((ssl_exclude & 0x04) != 0)
|
||||
+ ssl_op |= SSL_OP_NO_TLSv1;
|
||||
+#ifdef SSL_OP_NO_TLSv1_1
|
||||
+ if ((ssl_exclude & 0x08) != 0)
|
||||
+ ssl_op |= SSL_OP_NO_TLSv1_1;
|
||||
+#endif
|
||||
+#ifdef SSL_OP_NO_TLSv1_2
|
||||
+ if ((ssl_exclude & 0x10) != 0)
|
||||
+ ssl_op |= SSL_OP_NO_TLSv1_2;
|
||||
+#endif
|
||||
+
|
||||
+ if (server_ssl_protocols) {
|
||||
+ SSL_CTX_set_options(lpsSoap->ctx, ssl_op);
|
||||
+ }
|
||||
+
|
||||
+ if (server_ssl_ciphers && SSL_CTX_set_cipher_list(lpsSoap->ctx, server_ssl_ciphers) != 1) {
|
||||
+ m_lpLogger->Log(EC_LOGLEVEL_FATAL, "Can not set SSL cipher list to '%s': %s", server_ssl_ciphers, ERR_error_string(ERR_get_error(), 0));
|
||||
+ er = ZARAFA_E_CALL_FAILED;
|
||||
+ goto exit;
|
||||
+ }
|
||||
+
|
||||
+ if (parseBool(m_lpConfig->GetSetting("server_ssl_prefer_server_ciphers"))) {
|
||||
+ SSL_CTX_set_options(lpsSoap->ctx, SSL_OP_CIPHER_SERVER_PREFERENCE);
|
||||
+ }
|
||||
+
|
||||
// request certificate from client, is OK if not present.
|
||||
SSL_CTX_set_verify(lpsSoap->ctx, SSL_VERIFY_PEER | SSL_VERIFY_CLIENT_ONCE, NULL);
|
||||
|
||||
|
|
@ -15,6 +15,9 @@ Important: The technical implementation of this patch might be not perfect as I
|
|||
C++ developer. There should be a code review by an experienced C/C++ developer before merging into
|
||||
Zarafa core.
|
||||
|
||||
Proposed to upstream via e-mail on Thu, 16 Oct 2014 00:00:05 +0200, patch was put into the upstream
|
||||
ticket https://jira.zarafa.com/browse/ZCP-12473.
|
||||
|
||||
--- zarafa-7.1.11/gateway/IMAP.cpp 2014-09-03 10:45:06.000000000 +0200
|
||||
+++ zarafa-7.1.11/gateway/IMAP.cpp.plaintext_auth_localhost 2014-09-24 01:29:10.000000000 +0200
|
||||
@@ -757,7 +757,7 @@
|
||||
|
|
|
|||
32
zarafa-7.1.11-vacation-headers.patch
Normal file
32
zarafa-7.1.11-vacation-headers.patch
Normal file
|
|
@ -0,0 +1,32 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa >= 7.1.11 which restricts replies by
|
||||
zarafa-autorespond to automated processes and mailing lists according to RFC 5230, section 4.6. For
|
||||
further details please have a look to http://tools.ietf.org/html/rfc5230#page-8 as well.
|
||||
|
||||
Proposed to upstream via e-mail on Wed, 27 Aug 2014 23:30:31 +0200, patch was put into the upstream
|
||||
ticket https://jira.zarafa.com/browse/ZCP-12590.
|
||||
|
||||
--- zarafa-7.1.11/spooler/DAgent.cpp 2014-08-24 12:27:06.000000000 +0200
|
||||
+++ zarafa-7.1.11/spooler/DAgent.cpp.vacation-headers 2014-08-27 23:20:18.000000000 +0200
|
||||
@@ -1422,11 +1422,19 @@
|
||||
|
||||
// See if we're looping
|
||||
if (lpMessageProps[0].ulPropTag == PR_TRANSPORT_MESSAGE_HEADERS_A) {
|
||||
- if ( (strstr(lpMessageProps[0].Value.lpszA, "X-Zarafa-Vacation:") != NULL) ||
|
||||
- (strstr(lpMessageProps[0].Value.lpszA, "Auto-Submitted:") != NULL) ||
|
||||
- (strstr(lpMessageProps[0].Value.lpszA, "Precedence:") != NULL) )
|
||||
+ if ( (strstr(lpMessageProps[0].Value.lpszA, "X-Zarafa-Vacation:") != NULL) || // Zarafa
|
||||
+ (strstr(lpMessageProps[0].Value.lpszA, "Auto-Submitted:") != NULL) || // RFC 3834
|
||||
+ (strstr(lpMessageProps[0].Value.lpszA, "List-Id:") != NULL) || // RFC 2919
|
||||
+ (strstr(lpMessageProps[0].Value.lpszA, "List-Help:") != NULL) || // RFC 2369
|
||||
+ (strstr(lpMessageProps[0].Value.lpszA, "List-Subscribe:") != NULL) || // RFC 2369
|
||||
+ (strstr(lpMessageProps[0].Value.lpszA, "List-Unsubscribe:") != NULL) || // RFC 2369
|
||||
+ (strstr(lpMessageProps[0].Value.lpszA, "List-Post:") != NULL) || // RFC 2369
|
||||
+ (strstr(lpMessageProps[0].Value.lpszA, "List-Owner:") != NULL) || // RFC 2369
|
||||
+ (strstr(lpMessageProps[0].Value.lpszA, "List-Archive:") != NULL) || // RFC 2369
|
||||
+ (strstr(lpMessageProps[0].Value.lpszA, "Precedence:") != NULL) ) // RFC 3834
|
||||
// Vacation header already present, do not send vacation reply
|
||||
// Precedence: list/bulk/junk, do not reply to these mails
|
||||
+ // See also http://tools.ietf.org/html/rfc5230#page-8 for details
|
||||
goto exit;
|
||||
// save headers to a file so they can also be tested from the script we're runing
|
||||
snprintf(szTemp, PATH_MAX, "%s/autorespond-headers.XXXXXX", getenv("TEMP") == NULL ? "/tmp" : getenv("TEMP"));
|
||||
44
zarafa-7.1.11-vacation-headers2.patch
Normal file
44
zarafa-7.1.11-vacation-headers2.patch
Normal file
|
|
@ -0,0 +1,44 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa >= 7.1.11 which adds anti-loop headers
|
||||
for automatic responses by zarafa-autorespond for Microsoft Exchange and all vacation(1) compatible
|
||||
implementations.
|
||||
|
||||
For the Microsoft Exchange related part useful links are:
|
||||
- http://msdn.microsoft.com/en-us/library/ee219609(v=exchg.80).aspx
|
||||
- https://www.jitbit.com/maxblog/18-detecting-outlook-autoreplyout-of-office-emails-and-x-auto-response-suppress-header/
|
||||
|
||||
For vacation(1) compatible implementations useful links are:
|
||||
- http://www.daemon-systems.org/man/vacation.1.html
|
||||
- Book "sendmail" (written by Bryan Costales, Claus Assmann, George Jansen, Gregory Neil Shapiro), ISBN 0596555342
|
||||
|
||||
Proposed to upstream via e-mail on Wed, 27 Aug 2014 23:59:58 +0200, patch was put into the upstream
|
||||
ticket https://jira.zarafa.com/browse/ZCP-12591.
|
||||
|
||||
--- zarafa-7.1.11/spooler/DAgent.cpp 2014-08-24 12:27:06.000000000 +0200
|
||||
+++ zarafa-7.1.11/spooler/DAgent.cpp.vacation-headers2 2014-08-27 23:52:42.000000000 +0200
|
||||
@@ -1469,12 +1469,25 @@
|
||||
if (hr != hrSuccess)
|
||||
goto exit;
|
||||
|
||||
- // add anti-loop header
|
||||
+ // add anti-loop header for Zarafa
|
||||
snprintf(szHeader, PATH_MAX, "\nX-Zarafa-Vacation: autorespond");
|
||||
hr = WriteOrLogError(fd, szHeader, strlen(szHeader));
|
||||
if (hr != hrSuccess)
|
||||
goto exit;
|
||||
|
||||
+ // add anti-loop header for Exchange, see http://msdn.microsoft.com/en-us/library/ee219609(v=exchg.80).aspx
|
||||
+ snprintf(szHeader, PATH_MAX, "\nX-Auto-Response-Suppress: All");
|
||||
+ hr = WriteOrLogError(fd, szHeader, strlen(szHeader));
|
||||
+ if (hr != hrSuccess)
|
||||
+ goto exit;
|
||||
+
|
||||
+ // add anti-loop header for vacation(1) compatible implementations, see section 10.9 of book "sendmail" (written
|
||||
+ // by Bryan Costales, Claus Assmann, George Jansen, Gregory Neil Shapiro), ISBN 0596555342
|
||||
+ snprintf(szHeader, PATH_MAX, "\nPrecedence: bulk");
|
||||
+ hr = WriteOrLogError(fd, szHeader, strlen(szHeader));
|
||||
+ if (hr != hrSuccess)
|
||||
+ goto exit;
|
||||
+
|
||||
if (lpMessageProps[3].ulPropTag == PR_SUBJECT_W) {
|
||||
// convert as one string because of [] characters
|
||||
swprintf(szwHeader, PATH_MAX, L"%ls [%ls]", szSubject, lpMessageProps[3].Value.lpszW);
|
||||
21
zarafa-7.1.11-webaccess-fail2ban.patch
Normal file
21
zarafa-7.1.11-webaccess-fail2ban.patch
Normal file
|
|
@ -0,0 +1,21 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa <= 7.1.11 which logs authentication
|
||||
failures of Zarafa WebAccess into the error log of the webserver. This is basically a backport of
|
||||
https://jira.zarafa.com/browse/WA-6908 from WebApp to WebAccess. In difference to original patch
|
||||
there is no inappropriate space before a punctuation mark also known as "plenken".
|
||||
|
||||
Proposed to upstream via e-mail on Wed, 13 Aug 2014 22:56:09 +0200, initial patch was put into the
|
||||
upstream ticket https://jira.zarafa.com/browse/ZCP-12543.
|
||||
|
||||
--- zarafa-7.1.11/php-webclient-ajax/client/login.php 2014-09-03 10:45:06.000000000 +0200
|
||||
+++ zarafa-7.1.11/php-webclient-ajax/client/login.php 2015-02-18 01:08:13.000000000 +0100
|
||||
@@ -86,6 +86,10 @@
|
||||
switch($_SESSION["hresult"]){
|
||||
case MAPI_E_LOGON_FAILED:
|
||||
case MAPI_E_UNCONFIGURED:
|
||||
+ // Print error message to error_log of webserver
|
||||
+ if (!empty($_POST["username"])) {
|
||||
+ error_log('user '.$_POST["username"].': authentication failure at MAPI');
|
||||
+ }
|
||||
echo _("Logon failed, please check your name/password.");
|
||||
break;
|
||||
case MAPI_E_NETWORK_ERROR:
|
||||
2185
zarafa-7.1.12-gcc5.patch
Normal file
2185
zarafa-7.1.12-gcc5.patch
Normal file
File diff suppressed because it is too large
Load diff
38
zarafa-7.1.12-gsoap-sslv3.patch
Normal file
38
zarafa-7.1.12-gsoap-sslv3.patch
Normal file
|
|
@ -0,0 +1,38 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for zarafa >= 7.1.12 which disables weak SSLv2
|
||||
and SSLv3 protocols for encrypted SOAP connections between the Zarafa services. Until (including)
|
||||
the Zarafa 7.1.11 release the upstream default was to replace the SSLv23_method() that a pristine
|
||||
gSOAP library ships with the "safer" SSLv3_method(). With Zarafa 7.1.12 the SSLv3_method() was
|
||||
changed to SSLv23_method(). However this enables SSLv2 again (and still does not disable SSLv3).
|
||||
Thus this patch disables SSLv2 and SSLv3 as well as TLS compression explicitly; similar like the
|
||||
Zarafa Outlook Client which meanwhile only allows TLSv1.0 (and better).
|
||||
|
||||
Proposed to upstream via e-mail on Wed, 2 Apr 2014 11:35:40 +0200, initial patch was put into the
|
||||
upstream ticket Ticket#2014040210000266.
|
||||
|
||||
--- zarafa-7.1.12/provider/common/SOAPSock.cpp 2015-04-07 13:10:13.000000000 +0200
|
||||
+++ zarafa-7.1.12/provider/common/SOAPSock.cpp.gsoap-sslv3 2015-04-07 16:32:20.000000000 +0200
|
||||
@@ -157,9 +157,6 @@
|
||||
|
||||
lpCmd->endpoint = strdup(strServerPath.c_str());
|
||||
|
||||
- // default allow SSLv3, TLSv1, TLSv1.1 and TLSv1.2
|
||||
- lpCmd->soap->ctx = SSL_CTX_new(SSLv23_method());
|
||||
-
|
||||
#ifdef WITH_OPENSSL
|
||||
if (strncmp("https:", lpCmd->endpoint, 6) == 0) {
|
||||
// no need to add certificates to call, since soap also calls SSL_CTX_set_default_verify_paths()
|
||||
@@ -183,6 +180,14 @@
|
||||
lpCmd->soap->fsslverify = ssl_verify_callback_zarafa_silent;
|
||||
|
||||
SSL_CTX_set_verify(lpCmd->soap->ctx, SSL_VERIFY_PEER, lpCmd->soap->fsslverify);
|
||||
+
|
||||
+ // disable SSLv2 (according to RFC 6176) and SSLv3, leaving just TLSv1.0 (and better)
|
||||
+ SSL_CTX_set_options(lpCmd->soap->ctx, SSL_OP_NO_SSLv2 | SSL_OP_NO_SSLv3);
|
||||
+
|
||||
+#ifdef SSL_OP_NO_COMPRESSION
|
||||
+ // disable TLS compression to close the CRIME attack vector (also known as CVE-2012-4929)
|
||||
+ SSL_CTX_set_options(lpCmd->soap->ctx, SSL_OP_NO_COMPRESSION);
|
||||
+#endif
|
||||
}
|
||||
#endif
|
||||
|
||||
|
|
@ -1,4 +1,4 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa <= 7.1.9 which implements ECDHE (elliptic
|
||||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa >= 7.1.12 which implements ECDHE (elliptic
|
||||
curve diffie-hellman key exchange) support. http://en.wikipedia.org/wiki/Elliptic_curve_cryptography is
|
||||
providing more information about elliptic curves.
|
||||
|
||||
|
|
@ -22,21 +22,24 @@ by an experienced C/C++ and OpenSSL developer before merging into Zarafa core.
|
|||
This patch should be only applied after ZCP-12143 and its dependencies. However this patch might maybe
|
||||
not directly apply due to some previous merge issues as mentioned in Ticket#2014030810000131.
|
||||
|
||||
--- zarafa-7.1.9/common/ECChannel.cpp 2014-04-13 23:46:59.000000000 +0200
|
||||
+++ zarafa-7.1.9/common/ECChannel.cpp.ssl_ecdhe 2014-04-13 23:59:43.000000000 +0200
|
||||
@@ -97,6 +97,9 @@
|
||||
char *ssl_name;
|
||||
int ssl_proto, ssl_op = 0, ssl_include = 0, ssl_exclude = 0;
|
||||
bool ssl_neg;
|
||||
Proposed to upstream via e-mail on Mon, 14 Apr 2014 12:04:17 +0200, initial patch was put into upstream
|
||||
ticket https://jira.zarafa.com/browse/ZCP-12237.
|
||||
|
||||
--- zarafa-7.1.12/common/ECChannel.cpp 2015-04-07 13:10:12.000000000 +0200
|
||||
+++ zarafa-7.1.12/common/ECChannel.cpp.ssl_ecdhe 2015-04-07 17:12:15.000000000 +0200
|
||||
@@ -93,6 +93,9 @@
|
||||
char *ssl_ciphers = lpConfig->GetSetting("ssl_ciphers");
|
||||
char *ssl_name = NULL;
|
||||
int ssl_op = 0, ssl_include = 0, ssl_exclude = 0;
|
||||
+#if !defined(OPENSSL_NO_ECDH) && defined(NID_X9_62_prime256v1)
|
||||
+ EC_KEY *ecdh;
|
||||
+#endif
|
||||
|
||||
if (lpConfig == NULL) {
|
||||
hr = MAPI_E_CALL_FAILED;
|
||||
lpLogger->Log(EC_LOGLEVEL_ERROR, "ECChannel::HrSetCtx(): invalid parameters");
|
||||
@@ -113,6 +116,16 @@
|
||||
lpCTX = SSL_CTX_new(SSLv23_server_method());
|
||||
SSL_CTX_set_options(lpCTX, SSL_OP_ALL);
|
||||
|
||||
SSL_CTX_set_options(lpCTX, SSL_OP_ALL); // enable quirk and bug workarounds
|
||||
|
||||
+#if !defined(OPENSSL_NO_ECDH) && defined(NID_X9_62_prime256v1)
|
||||
+ ecdh = EC_KEY_new_by_curve_name(NID_X9_62_prime256v1);
|
||||
|
|
@ -50,20 +53,20 @@ not directly apply due to some previous merge issues as mentioned in Ticket#2014
|
|||
+
|
||||
ssl_name = strtok(ssl_protocols, " ");
|
||||
while(ssl_name != NULL) {
|
||||
if (*ssl_name != '!')
|
||||
--- zarafa-7.1.9/provider/server/ECSoapServerConnection.cpp 2014-04-13 23:46:59.000000000 +0200
|
||||
+++ zarafa-7.1.9/provider/server/ECSoapServerConnection.cpp.ssl_ecdhe 2014-04-14 00:00:54.000000000 +0200
|
||||
@@ -245,6 +245,9 @@
|
||||
char *ssl_name;
|
||||
int ssl_proto, ssl_op = 0, ssl_include = 0, ssl_exclude = 0;
|
||||
bool ssl_neg;
|
||||
int ssl_proto = 0;
|
||||
--- zarafa-7.1.12/provider/server/ECSoapServerConnection.cpp 2015-04-07 13:10:13.000000000 +0200
|
||||
+++ zarafa-7.1.12/provider/server/ECSoapServerConnection.cpp.ssl_ecdhe 2015-04-07 17:13:23.000000000 +0200
|
||||
@@ -235,6 +235,9 @@
|
||||
char *server_ssl_ciphers = m_lpConfig->GetSetting("server_ssl_ciphers");
|
||||
char *ssl_name = NULL;
|
||||
int ssl_op = 0, ssl_include = 0, ssl_exclude = 0;
|
||||
+#if !defined(OPENSSL_NO_ECDH) && defined(NID_X9_62_prime256v1)
|
||||
+ EC_KEY *ecdh;
|
||||
+#endif
|
||||
|
||||
if(lpServerName == NULL) {
|
||||
er = ZARAFA_E_INVALID_PARAMETER;
|
||||
@@ -277,6 +280,16 @@
|
||||
free(server_ssl_ciphers);
|
||||
@@ -268,6 +271,16 @@
|
||||
|
||||
SSL_CTX_set_options(lpsSoap->ctx, SSL_OP_ALL);
|
||||
|
||||
|
|
@ -79,4 +82,4 @@ not directly apply due to some previous merge issues as mentioned in Ticket#2014
|
|||
+
|
||||
ssl_name = strtok(server_ssl_protocols, " ");
|
||||
while(ssl_name != NULL) {
|
||||
if (*ssl_name != '!')
|
||||
int ssl_proto = 0;
|
||||
123
zarafa-7.1.12-ssl_protocols_ciphers.patch
Normal file
123
zarafa-7.1.12-ssl_protocols_ciphers.patch
Normal file
|
|
@ -0,0 +1,123 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa >= 7.1.12 which re-adds the whole
|
||||
documentation that was initially proposed to upstream but lost when this feature was backported
|
||||
from Zarafa 7.2 to the 7.1 series.
|
||||
|
||||
Proposed to upstream via e-mail on Sat, 8 Mar 2014 14:30:29 +0100, initial patch was put into
|
||||
the upstream ticket https://jira.zarafa.com/browse/ZCP-12143.
|
||||
|
||||
--- zarafa-7.1.12/doc/manual.xml 2015-04-07 12:03:31.000000000 +0200
|
||||
+++ zarafa-7.1.12/doc/manual.xml.ssl_protocols_ciphers 2015-04-07 17:05:47.000000000 +0200
|
||||
@@ -4226,14 +4226,35 @@
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
- <term><option>server_ssl_enable_v2</option></term>
|
||||
+ <term><option>server_ssl_protocols</option></term>
|
||||
<listitem>
|
||||
- <para>Incoming SSL connections normally are v3.</para>
|
||||
- <para>Default: <replaceable>no</replaceable>
|
||||
- </para>
|
||||
+ <para>Disabled or enabled protocol names. Supported protocol names
|
||||
+ are <replaceable>SSLv2</replaceable>, <replaceable>SSLv3</replaceable>
|
||||
+ and <replaceable>TLSv1</replaceable>. If Zarafa was linked against
|
||||
+ OpenSSL 1.0.1 or later there is additional support for the new protocols
|
||||
+ <replaceable>TLSv1.1</replaceable> and <replaceable>TLSv1.2</replaceable>.
|
||||
+ To exclude both, SSLv2 and SSLv3 set <option>server_ssl_protocols</option>
|
||||
+ to <replaceable>!SSLv2 !SSLv3</replaceable>. SSLv2 is considered unsafe
|
||||
+ and these connections should not be accepted.</para>
|
||||
+ <para>Default: <replaceable>!SSLv2</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
+
|
||||
+ <varlistentry>
|
||||
+ <term><option>server_ssl_ciphers</option></term>
|
||||
+ <listitem>
|
||||
+ <para>SSL ciphers to use, set to <replaceable>ALL</replaceable> for backward compatibility.</para>
|
||||
+ <para>Default: <replaceable>ALL:!LOW:!SSLv2:!EXP:!aNULL</replaceable></para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
+ <varlistentry>
|
||||
+ <term><option>server_ssl_prefer_server_ciphers</option></term>
|
||||
+ <listitem>
|
||||
+ <para>Prefer the server's order of SSL ciphers over client's.</para>
|
||||
+ <para>Default: <replaceable>no</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
</variablelist>
|
||||
</refsection>
|
||||
|
||||
@@ -8090,11 +8111,32 @@
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
- <term><option>ssl_enable_v2</option></term>
|
||||
+ <term><option>ssl_protocols</option></term>
|
||||
+ <listitem>
|
||||
+ <para>Disabled or enabled protocol names. Supported protocol names
|
||||
+ are <replaceable>SSLv2</replaceable>, <replaceable>SSLv3</replaceable>
|
||||
+ and <replaceable>TLSv1</replaceable>. If Zarafa was linked against
|
||||
+ OpenSSL 1.0.1 or later there is additional support for the new protocols
|
||||
+ <replaceable>TLSv1.1</replaceable> and <replaceable>TLSv1.2</replaceable>.
|
||||
+ To exclude both, SSLv2 and SSLv3 set <option>ssl_protocols</option>
|
||||
+ to <replaceable>!SSLv2 !SSLv3</replaceable>. SSLv2 is considered unsafe
|
||||
+ and these connections should not be accepted.</para>
|
||||
+ <para>Default: <replaceable>!SSLv2</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
+
|
||||
+ <varlistentry>
|
||||
+ <term><option>ssl_ciphers</option></term>
|
||||
<listitem>
|
||||
- <para>Accept SSLv2 only connections. SSLv2 is considered
|
||||
- unsafe, and these connections should not be
|
||||
- accepted.</para>
|
||||
+ <para>SSL ciphers to use, set to <replaceable>ALL</replaceable> for backward compatibility.</para>
|
||||
+ <para>Default: <replaceable>ALL:!LOW:!SSLv2:!EXP:!aNULL</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
+
|
||||
+ <varlistentry>
|
||||
+ <term><option>ssl_prefer_server_ciphers</option></term>
|
||||
+ <listitem>
|
||||
+ <para>Prefer the server's order of SSL ciphers over client's.</para>
|
||||
<para>Default: <replaceable>no</replaceable></para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
@@ -10091,11 +10133,32 @@
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
- <term><option>ssl_enable_v2</option></term>
|
||||
+ <term><option>ssl_protocols</option></term>
|
||||
+ <listitem>
|
||||
+ <para>Disabled or enabled protocol names. Supported protocol names
|
||||
+ are <replaceable>SSLv2</replaceable>, <replaceable>SSLv3</replaceable>
|
||||
+ and <replaceable>TLSv1</replaceable>. If Zarafa was linked against
|
||||
+ OpenSSL 1.0.1 or later there is additional support for the new protocols
|
||||
+ <replaceable>TLSv1.1</replaceable> and <replaceable>TLSv1.2</replaceable>.
|
||||
+ To exclude both, SSLv2 and SSLv3 set <option>ssl_protocols</option>
|
||||
+ to <replaceable>!SSLv2 !SSLv3</replaceable>. SSLv2 is considered unsafe
|
||||
+ and these connections should not be accepted.</para>
|
||||
+ <para>Default: <replaceable>!SSLv2</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
+
|
||||
+ <varlistentry>
|
||||
+ <term><option>ssl_ciphers</option></term>
|
||||
+ <listitem>
|
||||
+ <para>SSL ciphers to use, set to <replaceable>ALL</replaceable> for backward compatibility.</para>
|
||||
+ <para>Default: <replaceable>ALL:!LOW:!SSLv2:!EXP:!aNULL</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
+
|
||||
+ <varlistentry>
|
||||
+ <term><option>ssl_prefer_server_ciphers</option></term>
|
||||
<listitem>
|
||||
- <para>Accept SSLv2 only connections. SSLv2 is considered
|
||||
- unsafe, and these connections should not be
|
||||
- accepted.</para>
|
||||
+ <para>Prefer the server's order of SSL ciphers over client's.</para>
|
||||
<para>Default: <replaceable>no</replaceable></para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
56
zarafa-7.1.12-upgrade-lock.patch
Normal file
56
zarafa-7.1.12-upgrade-lock.patch
Normal file
|
|
@ -0,0 +1,56 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa 7.1.12 which backports the fix for
|
||||
CVE-2015-3436. Guido Günther detected and reported that replacing "/tmp/zarafa-upgrade-lock" by
|
||||
a symlink makes the zarafa-server process following that symlink and thus allows to overwrite
|
||||
arbitrary files in the filesystem (assuming zarafa-server runs as root which is not the case by
|
||||
default at Fedora, but it is the upstream default). One just needs write permissions in /tmp and
|
||||
wait until the zarafa-server is restarted. https://bugzilla.redhat.com/show_bug.cgi?id=1222151
|
||||
contains further information. The difference between this backport and the original diff is that
|
||||
the log levels were reworked from Zarafa 7.1.x to 7.2.x (which this backport takes care of).
|
||||
|
||||
--- zarafa-7.1.12/provider/server/ECServer.cpp 2015-05-08 15:09:05.000000000 +0200
|
||||
+++ zarafa-7.1.12/provider/server/ECServer.cpp.upgrade-lock 2015-05-18 23:05:00.000000000 +0200
|
||||
@@ -101,6 +101,8 @@
|
||||
// have to go with the safe value which is for 64bit.
|
||||
#define MYSQL_MIN_THREAD_STACK (256*1024)
|
||||
|
||||
+const char upgrade_lock_file[] = "/tmp/zarafa-upgrade-lock";
|
||||
+
|
||||
extern ECSessionManager* g_lpSessionManager;
|
||||
|
||||
// scheduled functions
|
||||
@@ -832,7 +834,7 @@
|
||||
// SIGSEGV backtrace support
|
||||
stack_t st = {0};
|
||||
struct sigaction act = {{0}};
|
||||
- FILE *tmplock = NULL;
|
||||
+ int tmplock = -1;
|
||||
struct stat dir = {0};
|
||||
struct passwd *runasUser = NULL;
|
||||
|
||||
@@ -1288,8 +1290,9 @@
|
||||
m_bDatabaseUpdateIgnoreSignals = true;
|
||||
|
||||
// add a lock file to disable the /etc/init.d scripts
|
||||
- tmplock = fopen("/tmp/zarafa-upgrade-lock","w");
|
||||
- if (!tmplock)
|
||||
+ tmplock = open(upgrade_lock_file, O_CREAT | O_EXCL, S_IRUSR | S_IWUSR);
|
||||
+
|
||||
+ if (tmplock == -1)
|
||||
g_lpLogger->Log(EC_LOGLEVEL_FATAL, "WARNING: Unable to place upgrade lockfile: %s", strerror(errno));
|
||||
|
||||
#ifdef EMBEDDED_MYSQL
|
||||
@@ -1314,9 +1317,11 @@
|
||||
er = lpDatabaseFactory->UpdateDatabase(m_bForceDatabaseUpdate, dbError);
|
||||
|
||||
// remove lock file
|
||||
- if (tmplock) {
|
||||
- fclose(tmplock);
|
||||
- unlink("/tmp/zarafa-upgrade-lock");
|
||||
+ if (tmplock != -1) {
|
||||
+ if (unlink(upgrade_lock_file) == -1)
|
||||
+ g_lpLogger->Log(EC_LOGLEVEL_FATAL, "WARNING: Unable to delete upgrade lockfile (%s): %s", upgrade_lock_file, strerror(errno));
|
||||
+
|
||||
+ close(tmplock);
|
||||
}
|
||||
|
||||
if(er == ZARAFA_E_INVALID_VERSION) {
|
||||
18
zarafa-7.1.12-webaccess-defaultfont.patch
Normal file
18
zarafa-7.1.12-webaccess-defaultfont.patch
Normal file
|
|
@ -0,0 +1,18 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa WebAccess >= 7.1.12 which fixes the issue that the configured
|
||||
default font from the settings (for HTML e-mails) is just not applied when creating a new e-mail. This issue is also known
|
||||
to Zarafa since at least April 2011 - but will be not fixed at upstream; see also: https://jira.zarafa.com/browse/ZCP-7492
|
||||
|
||||
This patch is is free software: You can redistribute it and/or modify it under the terms of the GNU Affero General
|
||||
Public License, version 3, as published by the Free Software Foundation.
|
||||
|
||||
--- zarafa-7.1.12/php-webclient-ajax/client/layout/dialogs/standard/createmail.php 2015-05-08 15:09:05.000000000 +0200
|
||||
+++ zarafa-7.1.12/php-webclient-ajax/client/layout/dialogs/standard/createmail.php.rsc 2015-07-12 04:26:59.000000000 +0200
|
||||
@@ -381,7 +381,7 @@
|
||||
|
||||
//set the default font-family for editorarea
|
||||
var font_family = parentWebclient.settings.get("createmail/maildefaultfont","Arial");
|
||||
- document.fckEditor.EditorDocument.body.style.fontFamily = font_family;
|
||||
+ document.fckEditor.EditorDocument.body.getElementsByTagName("p")[0].style.fontFamily = font_family;
|
||||
|
||||
// set content of body if it is passed in URL
|
||||
<? if(isset($_GET["body"])) { ?>
|
||||
58
zarafa-7.1.12-webaccess-mcrypt.patch
Normal file
58
zarafa-7.1.12-webaccess-mcrypt.patch
Normal file
|
|
@ -0,0 +1,58 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa >= 7.1.12 which fixes the fix that fixes CVE-2014-0103. Ush,
|
||||
that was complicated, so: CVE-2014-0103 exists because Zarafa WebAccess < 7.1.10 and Zarafa WebApp < 1.6 storing passwords
|
||||
in cleartext on server (in the PHP session). Zarafa solved this flaw by using openssl_encrypt() and openssl_decrypt() from
|
||||
PHP's OpenSSL bindings. However these functions are only available in PHP 5.3 or later. Without this patch suggestion, any
|
||||
older but still supported Linux distribution like Red Hat Enterprise Linux 5 or SuSE Linux Enterprise Server 10 (which are
|
||||
both shipping PHP < 5.3 by default) would still be left vulnerable.
|
||||
|
||||
Given that I am personally more a fan of OpenSSL rather mcrypt, I am not absolutely sure if this implementation is really
|
||||
correct even it works fine on my test system. So please explicitly review this code to avoid introducing another security
|
||||
flaw by trying to fix one! A thing that I generally question for myself is the usage of "des-ede3-cbc"/"MCRYPT_TRIPLEDES"
|
||||
instead of e.g. MCRYPT_RIJNDAEL_128. Given that this decision was initially made by Zarafa I am just following that here.
|
||||
|
||||
Important: To get this patch really powerful the install-time requirement needs to be adapted like this (this example is
|
||||
based on Fedora's build system so the macros %{?rhel} and %{?fedora} might not exist at Zarafa but need to be replaced by
|
||||
other macros):
|
||||
|
||||
%if 0%{?rhel}%{?fedora} < 6
|
||||
Requires: php-mcrypt
|
||||
%else
|
||||
Requires: php-openssl
|
||||
%endif
|
||||
|
||||
This requires php-openssl (provided by php-common) on RHEL 6 (and later) and php-mcrypt (separate package) before RHEL 6.
|
||||
|
||||
Proposed to upstream via e-mail on Thu, 5 Jun 2014 00:24:32 +0200, initial patch was put into the (non-disclosed) upstream
|
||||
ticket https://jira.zarafa.com/browse/ZCP-12407.
|
||||
|
||||
--- zarafa-7.1.12/php-webclient-ajax/index.php 2015-04-07 13:10:13.000000000 +0200
|
||||
+++ zarafa-7.1.12/php-webclient-ajax/index.php.webaccess-mcrypt 2015-04-07 16:22:23.000000000 +0200
|
||||
@@ -135,6 +135,8 @@
|
||||
} else {
|
||||
$_SESSION['password'] = openssl_encrypt($password,"des-ede3-cbc",PASSWORD_KEY,0,PASSWORD_IV);
|
||||
}
|
||||
+ } elseif(function_exists("mcrypt_encrypt")) {
|
||||
+ $_SESSION['password'] = base64_encode(mcrypt_encrypt(MCRYPT_TRIPLEDES, PASSWORD_KEY, $password, MCRYPT_MODE_CBC, PASSWORD_IV));
|
||||
} else {
|
||||
$_SESSION["password"] = $password;
|
||||
}
|
||||
--- zarafa-7.1.12/php-webclient-ajax/server/core/class.mapisession.php 2015-04-07 13:10:14.000000000 +0200
|
||||
+++ zarafa-7.1.12/php-webclient-ajax/server/core/class.mapisession.php.webaccess-mcrypt 2015-04-07 16:23:58.000000000 +0200
|
||||
@@ -132,6 +132,8 @@
|
||||
} else {
|
||||
$password = openssl_decrypt($password,"des-ede3-cbc",PASSWORD_KEY,0,PASSWORD_IV);
|
||||
}
|
||||
+ } elseif(function_exists("mcrypt_decrypt")) {
|
||||
+ $password = rtrim(mcrypt_decrypt(MCRYPT_TRIPLEDES, PASSWORD_KEY, base64_decode($password), MCRYPT_MODE_CBC, PASSWORD_IV), "\0");
|
||||
}
|
||||
// logon
|
||||
$this->session = mapi_logon_zarafa($username, $password, $server, $sslcert_file, $sslcert_pass);
|
||||
@@ -144,6 +146,8 @@
|
||||
} else {
|
||||
$password = openssl_encrypt($password,"des-ede3-cbc",PASSWORD_KEY,0,PASSWORD_IV);
|
||||
}
|
||||
+ } elseif(function_exists("mcrypt_encrypt")) {
|
||||
+ $password = base64_encode(mcrypt_encrypt(MCRYPT_TRIPLEDES, PASSWORD_KEY, $password, MCRYPT_MODE_CBC, PASSWORD_IV));
|
||||
}
|
||||
|
||||
if ($result == NOERROR && $this->session !== false){
|
||||
30
zarafa-7.1.12-webaccess-xss.patch
Normal file
30
zarafa-7.1.12-webaccess-xss.patch
Normal file
|
|
@ -0,0 +1,30 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa WebAccess >= 6.00 which ensures proper escaping of
|
||||
multiple user properties like fullname/realname, username and e-mail address. Without this patch a user having
|
||||
the unlikely fullname/realname '<script>alert("Hello world");</script>' (without the '') is not properly escaped
|
||||
on all places within the Zarafa WebAccess; this might be an XSS flaw.
|
||||
|
||||
This patch is is free software: You can redistribute it and/or modify it under the terms of the GNU Affero General
|
||||
Public License, version 3, as published by the Free Software Foundation.
|
||||
|
||||
--- zarafa-7.1.12/php-webclient-ajax/client/webclient.php 2015-05-08 15:09:05.000000000 +0200
|
||||
+++ zarafa-7.1.12/php-webclient-ajax/client/webclient.php.webaccess-xss 2015-07-09 23:42:35.000000000 +0200
|
||||
@@ -220,7 +220,7 @@
|
||||
dhtml.executeEvent(document.body, "ZarafaDnD:initDragMsgsToDesktop");
|
||||
}
|
||||
|
||||
- webclient.setUserInfo("<?=addslashes(windows1252_to_utf8($GLOBALS["mapisession"]->getUserName()))?>", "<?=addslashes(windows1252_to_utf8($GLOBALS["mapisession"]->getFullName()))?>", "<?=bin2hex($GLOBALS["mapisession"]->getUserEntryid())?>" , "<?=addslashes(windows1252_to_utf8($GLOBALS["mapisession"]->getEmail()))?>");
|
||||
+ webclient.setUserInfo("<?=htmlspecialchars(addslashes(windows1252_to_utf8($GLOBALS["mapisession"]->getUserName())))?>", "<?=htmlspecialchars(addslashes(windows1252_to_utf8($GLOBALS["mapisession"]->getFullName())))?>", "<?=bin2hex($GLOBALS["mapisession"]->getUserEntryid())?>" , "<?=htmlspecialchars(addslashes(windows1252_to_utf8($GLOBALS["mapisession"]->getEmail())))?>");
|
||||
|
||||
// Store current sessionid in sessionid variable
|
||||
webclient.sessionid = "<?=session_id()?>";
|
||||
--- zarafa-7.1.12/php-webclient-ajax/client/core/layoutmanager.js 2015-05-08 15:09:06.000000000 +0200
|
||||
+++ zarafa-7.1.12/php-webclient-ajax/client/core/layoutmanager.js.webaccess-xss 2015-07-09 23:43:39.000000000 +0200
|
||||
@@ -324,7 +324,7 @@
|
||||
var loggedon = dhtml.getElementById("loggedon");
|
||||
|
||||
var loggedonas = document.createElement("span");
|
||||
- loggedonas.innerHTML = _("you are logged on as") + " " + escapeHtml(webclient.fullname);
|
||||
+ loggedonas.innerHTML = _("you are logged on as") + " " + webclient.fullname;
|
||||
loggedon.appendChild(loggedonas);
|
||||
|
||||
var seperator = document.createElement("span");
|
||||
298
zarafa-7.1.13-ssl_dhe.patch
Normal file
298
zarafa-7.1.13-ssl_dhe.patch
Normal file
|
|
@ -0,0 +1,298 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa >= 7.1.13 which implements DHE aka EDH
|
||||
(diffie-hellman key exchange) support. https://en.wikipedia.org/wiki/Diffie-Hellman_key_exchange is
|
||||
providing more information about Perfect Forward Secrecy (PFS). This implementation might need some
|
||||
more resources compared to ECDHE, however not all servers and/or clients are supporting it through;
|
||||
e.g. Red Hat Enterprise Linux 5 (and derivates). The prime length of 1024, 2048, 3072, 4096, 6144
|
||||
and 8192 bits are based on the private key size to avoid any static DH parameters. Please be aware
|
||||
that this patch may cause issues with some older SSL/TLS clients, mostly Java 7 or earlier, that do
|
||||
not support primes larger than 1024 bits.
|
||||
|
||||
Suggestions for testing; run the following openssl(1) commands before and after applying this patch:
|
||||
|
||||
1. echo QUIT | openssl s_client -cipher 'kEDH:ALL' -connect <host>:110 -starttls pop3 2>&1 | grep Cipher
|
||||
2. echo QUIT | openssl s_client -cipher 'kEDH:ALL' -connect <host>:143 -starttls imap 2>&1 | grep Cipher
|
||||
3. echo QUIT | openssl s_client -cipher 'kEDH:ALL' -connect <host>:237 2>&1 | grep Cipher
|
||||
4. echo QUIT | openssl s_client -cipher 'kEDH:ALL' -connect <host>:993 2>&1 | grep Cipher
|
||||
5. echo QUIT | openssl s_client -cipher 'kEDH:ALL' -connect <host>:995 2>&1 | grep Cipher
|
||||
6. echo QUIT | openssl s_client -cipher 'kEDH:ALL' -connect <host>:8443 2>&1 | grep Cipher
|
||||
|
||||
After applying this patch the output should contain e.g. "DHE-RSA-AES256-GCM-SHA384" on a Red Hat
|
||||
Enterprise Linux 6 (and derivates). Without this patch the result is e.g. "AES256-GCM-SHA384". Note
|
||||
that ZCP-12237 is maybe having influence on the result depending on the exact test case.
|
||||
|
||||
Important: As https://www.mail-archive.com/haproxy@formilux.org/msg13274.html is the origin for this
|
||||
patch (a HAProxy patch suggestion, which itself bases on mod_ssl of Apache httpd), the licensing is
|
||||
likely a combination out of the Apache License, Version 2.0, the GNU General Public License, version
|
||||
2 (or later) and the GNU Affero General Public License, version 3 (and thus excludes dual-licensing
|
||||
situations such as at the upstream of Zarafa).
|
||||
|
||||
This patch should be only applied after ZCP-12237 and its dependencies.
|
||||
|
||||
--- zarafa-7.1.13/common/ECChannel.cpp 2015-07-30 01:01:07.212313822 +0200
|
||||
+++ zarafa-7.1.13/common/ECChannel.cpp.ssl_dhe 2015-07-30 02:05:36.045747555 +0200
|
||||
@@ -85,6 +85,119 @@
|
||||
// because of statics
|
||||
SSL_CTX* ECChannel::lpCTX = NULL;
|
||||
|
||||
+#if !defined(OPENSSL_NO_DH)
|
||||
+static DH *ssl_get_dh_1024(void) {
|
||||
+ DH *dh = DH_new();
|
||||
+ if (dh) {
|
||||
+ dh->p = get_rfc2409_prime_1024(NULL);
|
||||
+ // See RFC 2409, Section 6 "Oakley Groups" for the reason why we use 2 as a generator
|
||||
+ BN_dec2bn(&dh->g, "2");
|
||||
+ if (!dh->p || !dh->g) {
|
||||
+ DH_free(dh);
|
||||
+ dh = NULL;
|
||||
+ }
|
||||
+ }
|
||||
+ return dh;
|
||||
+}
|
||||
+
|
||||
+static DH *ssl_get_dh_2048(void) {
|
||||
+ DH *dh = DH_new();
|
||||
+ if (dh) {
|
||||
+ dh->p = get_rfc3526_prime_2048(NULL);
|
||||
+ // See RFC 3526, Section 3 "2048-bit MODP Group" for the reason why we use 2 as a generator
|
||||
+ BN_dec2bn(&dh->g, "2");
|
||||
+ if (!dh->p || !dh->g) {
|
||||
+ DH_free(dh);
|
||||
+ dh = NULL;
|
||||
+ }
|
||||
+ }
|
||||
+ return dh;
|
||||
+}
|
||||
+
|
||||
+static DH *ssl_get_dh_3072(void) {
|
||||
+ DH *dh = DH_new();
|
||||
+ if (dh) {
|
||||
+ dh->p = get_rfc3526_prime_3072(NULL);
|
||||
+ // See RFC 3526, Section 4 "3072-bit MODP Group" for the reason why we use 2 as a generator
|
||||
+ BN_dec2bn(&dh->g, "2");
|
||||
+ if (!dh->p || !dh->g) {
|
||||
+ DH_free(dh);
|
||||
+ dh = NULL;
|
||||
+ }
|
||||
+ }
|
||||
+ return dh;
|
||||
+}
|
||||
+
|
||||
+static DH *ssl_get_dh_4096(void) {
|
||||
+ DH *dh = DH_new();
|
||||
+ if (dh) {
|
||||
+ dh->p = get_rfc3526_prime_4096(NULL);
|
||||
+ // See RFC 3526, Section 5 "4096-bit MODP Group" for the reason why we use 2 as a generator
|
||||
+ BN_dec2bn(&dh->g, "2");
|
||||
+ if (!dh->p || !dh->g) {
|
||||
+ DH_free(dh);
|
||||
+ dh = NULL;
|
||||
+ }
|
||||
+ }
|
||||
+ return dh;
|
||||
+}
|
||||
+
|
||||
+static DH *ssl_get_dh_6144(void) {
|
||||
+ DH *dh = DH_new();
|
||||
+ if (dh) {
|
||||
+ dh->p = get_rfc3526_prime_6144(NULL);
|
||||
+ // See RFC 3526, Section 6 "6144-bit MODP Group" for the reason why we use 2 as a generator
|
||||
+ BN_dec2bn(&dh->g, "2");
|
||||
+ if (!dh->p || !dh->g) {
|
||||
+ DH_free(dh);
|
||||
+ dh = NULL;
|
||||
+ }
|
||||
+ }
|
||||
+ return dh;
|
||||
+}
|
||||
+
|
||||
+static DH *ssl_get_dh_8192(void) {
|
||||
+ DH *dh = DH_new();
|
||||
+ if (dh) {
|
||||
+ dh->p = get_rfc3526_prime_8192(NULL);
|
||||
+ // See RFC 3526, Section 7 "8192-bit MODP Group" for the reason why we use 2 as a generator
|
||||
+ BN_dec2bn(&dh->g, "2");
|
||||
+ if (!dh->p || !dh->g) {
|
||||
+ DH_free(dh);
|
||||
+ dh = NULL;
|
||||
+ }
|
||||
+ }
|
||||
+ return dh;
|
||||
+}
|
||||
+
|
||||
+// Returns Diffie-Hellman parameters matching the private key length
|
||||
+static DH *ssl_get_tmp_dh(SSL *ssl, int exporting, int keylen) {
|
||||
+ DH *dh = NULL;
|
||||
+ EVP_PKEY *pkey = SSL_get_privatekey(ssl);
|
||||
+ int type = pkey ? EVP_PKEY_type(pkey->type) : EVP_PKEY_NONE;
|
||||
+
|
||||
+ if (type == EVP_PKEY_RSA || type == EVP_PKEY_DSA) {
|
||||
+ keylen = EVP_PKEY_bits(pkey);
|
||||
+ }
|
||||
+
|
||||
+ if (keylen >= 8192) {
|
||||
+ dh = ssl_get_dh_8192();
|
||||
+ } else if (keylen >= 6144) {
|
||||
+ dh = ssl_get_dh_6144();
|
||||
+ } else if (keylen >= 4096) {
|
||||
+ dh = ssl_get_dh_4096();
|
||||
+ } else if (keylen >= 3072) {
|
||||
+ dh = ssl_get_dh_3072();
|
||||
+ } else if (keylen >= 2048) {
|
||||
+ dh = ssl_get_dh_2048();
|
||||
+ } else {
|
||||
+ dh = ssl_get_dh_1024();
|
||||
+ }
|
||||
+
|
||||
+ return dh;
|
||||
+}
|
||||
+#endif
|
||||
+
|
||||
HRESULT ECChannel::HrSetCtx(ECConfig *lpConfig, ECLogger *lpLogger) {
|
||||
HRESULT hr = hrSuccess;
|
||||
char *szFile = NULL;
|
||||
@@ -116,6 +229,11 @@
|
||||
|
||||
SSL_CTX_set_options(lpCTX, SSL_OP_ALL); // enable quirk and bug workarounds
|
||||
|
||||
+#if !defined(OPENSSL_NO_DH)
|
||||
+ SSL_CTX_set_options(lpCTX, SSL_OP_SINGLE_DH_USE);
|
||||
+ SSL_CTX_set_tmp_dh_callback(lpCTX, ssl_get_tmp_dh);
|
||||
+#endif
|
||||
+
|
||||
#if !defined(OPENSSL_NO_ECDH) && defined(NID_X9_62_prime256v1)
|
||||
ecdh = EC_KEY_new_by_curve_name(NID_X9_62_prime256v1);
|
||||
|
||||
--- zarafa-7.1.13/provider/server/ECSoapServerConnection.cpp 2015-07-30 01:01:07.212313822 +0200
|
||||
+++ zarafa-7.1.13/provider/server/ECSoapServerConnection.cpp.ssl_dhe 2015-07-30 02:05:54.658626465 +0200
|
||||
@@ -165,6 +165,119 @@
|
||||
return nRet;
|
||||
}
|
||||
|
||||
+#if !defined(OPENSSL_NO_DH)
|
||||
+static DH *ssl_get_dh_1024(void) {
|
||||
+ DH *dh = DH_new();
|
||||
+ if (dh) {
|
||||
+ dh->p = get_rfc2409_prime_1024(NULL);
|
||||
+ // See RFC 2409, Section 6 "Oakley Groups" for the reason why we use 2 as a generator
|
||||
+ BN_dec2bn(&dh->g, "2");
|
||||
+ if (!dh->p || !dh->g) {
|
||||
+ DH_free(dh);
|
||||
+ dh = NULL;
|
||||
+ }
|
||||
+ }
|
||||
+ return dh;
|
||||
+}
|
||||
+
|
||||
+static DH *ssl_get_dh_2048(void) {
|
||||
+ DH *dh = DH_new();
|
||||
+ if (dh) {
|
||||
+ dh->p = get_rfc3526_prime_2048(NULL);
|
||||
+ // See RFC 3526, Section 3 "2048-bit MODP Group" for the reason why we use 2 as a generator
|
||||
+ BN_dec2bn(&dh->g, "2");
|
||||
+ if (!dh->p || !dh->g) {
|
||||
+ DH_free(dh);
|
||||
+ dh = NULL;
|
||||
+ }
|
||||
+ }
|
||||
+ return dh;
|
||||
+}
|
||||
+
|
||||
+static DH *ssl_get_dh_3072(void) {
|
||||
+ DH *dh = DH_new();
|
||||
+ if (dh) {
|
||||
+ dh->p = get_rfc3526_prime_3072(NULL);
|
||||
+ // See RFC 3526, Section 4 "3072-bit MODP Group" for the reason why we use 2 as a generator
|
||||
+ BN_dec2bn(&dh->g, "2");
|
||||
+ if (!dh->p || !dh->g) {
|
||||
+ DH_free(dh);
|
||||
+ dh = NULL;
|
||||
+ }
|
||||
+ }
|
||||
+ return dh;
|
||||
+}
|
||||
+
|
||||
+static DH *ssl_get_dh_4096(void) {
|
||||
+ DH *dh = DH_new();
|
||||
+ if (dh) {
|
||||
+ dh->p = get_rfc3526_prime_4096(NULL);
|
||||
+ // See RFC 3526, Section 5 "4096-bit MODP Group" for the reason why we use 2 as a generator
|
||||
+ BN_dec2bn(&dh->g, "2");
|
||||
+ if (!dh->p || !dh->g) {
|
||||
+ DH_free(dh);
|
||||
+ dh = NULL;
|
||||
+ }
|
||||
+ }
|
||||
+ return dh;
|
||||
+}
|
||||
+
|
||||
+static DH *ssl_get_dh_6144(void) {
|
||||
+ DH *dh = DH_new();
|
||||
+ if (dh) {
|
||||
+ dh->p = get_rfc3526_prime_6144(NULL);
|
||||
+ // See RFC 3526, Section 6 "6144-bit MODP Group" for the reason why we use 2 as a generator
|
||||
+ BN_dec2bn(&dh->g, "2");
|
||||
+ if (!dh->p || !dh->g) {
|
||||
+ DH_free(dh);
|
||||
+ dh = NULL;
|
||||
+ }
|
||||
+ }
|
||||
+ return dh;
|
||||
+}
|
||||
+
|
||||
+static DH *ssl_get_dh_8192(void) {
|
||||
+ DH *dh = DH_new();
|
||||
+ if (dh) {
|
||||
+ dh->p = get_rfc3526_prime_8192(NULL);
|
||||
+ // See RFC 3526, Section 7 "8192-bit MODP Group" for the reason why we use 2 as a generator
|
||||
+ BN_dec2bn(&dh->g, "2");
|
||||
+ if (!dh->p || !dh->g) {
|
||||
+ DH_free(dh);
|
||||
+ dh = NULL;
|
||||
+ }
|
||||
+ }
|
||||
+ return dh;
|
||||
+}
|
||||
+
|
||||
+// Returns Diffie-Hellman parameters matching the private key length
|
||||
+static DH *ssl_get_tmp_dh(SSL *ssl, int exporting, int keylen) {
|
||||
+ DH *dh = NULL;
|
||||
+ EVP_PKEY *pkey = SSL_get_privatekey(ssl);
|
||||
+ int type = pkey ? EVP_PKEY_type(pkey->type) : EVP_PKEY_NONE;
|
||||
+
|
||||
+ if (type == EVP_PKEY_RSA || type == EVP_PKEY_DSA) {
|
||||
+ keylen = EVP_PKEY_bits(pkey);
|
||||
+ }
|
||||
+
|
||||
+ if (keylen >= 8192) {
|
||||
+ dh = ssl_get_dh_8192();
|
||||
+ } else if (keylen >= 6144) {
|
||||
+ dh = ssl_get_dh_6144();
|
||||
+ } else if (keylen >= 4096) {
|
||||
+ dh = ssl_get_dh_4096();
|
||||
+ } else if (keylen >= 3072) {
|
||||
+ dh = ssl_get_dh_3072();
|
||||
+ } else if (keylen >= 2048) {
|
||||
+ dh = ssl_get_dh_2048();
|
||||
+ } else {
|
||||
+ dh = ssl_get_dh_1024();
|
||||
+ }
|
||||
+
|
||||
+ return dh;
|
||||
+}
|
||||
+#endif
|
||||
+
|
||||
ECSoapServerConnection::ECSoapServerConnection(ECConfig* lpConfig, ECLogger* lpLogger)
|
||||
{
|
||||
m_lpConfig = lpConfig;
|
||||
@@ -271,6 +384,11 @@
|
||||
|
||||
SSL_CTX_set_options(lpsSoap->ctx, SSL_OP_ALL);
|
||||
|
||||
+#if !defined(OPENSSL_NO_DH)
|
||||
+ SSL_CTX_set_options(lpsSoap->ctx, SSL_OP_SINGLE_DH_USE);
|
||||
+ SSL_CTX_set_tmp_dh_callback(lpsSoap->ctx, ssl_get_tmp_dh);
|
||||
+#endif
|
||||
+
|
||||
#if !defined(OPENSSL_NO_ECDH) && defined(NID_X9_62_prime256v1)
|
||||
ecdh = EC_KEY_new_by_curve_name(NID_X9_62_prime256v1);
|
||||
|
||||
36
zarafa-7.1.14-ical-remote-dos.patch
Normal file
36
zarafa-7.1.14-ical-remote-dos.patch
Normal file
|
|
@ -0,0 +1,36 @@
|
|||
Backport of upstream patch from Git commit 512457466b87039c6a8d25887fdaca6173619546 to fix
|
||||
remote DoS by memory exhaustion in the zarafa-ical daemon of Zarafa 7.1.14 (MITRE assigned
|
||||
CVE-2021-28994). See also:
|
||||
|
||||
- https://seclists.org/oss-sec/2021/q1/244
|
||||
- https://seclists.org/oss-sec/2021/q1/256
|
||||
- https://github.com/Kopano-dev/kopano-core/commit/512457466b87039c6a8d25887fdaca6173619546
|
||||
- https://bugzilla.redhat.com/show_bug.cgi?id=1942773
|
||||
- https://seclists.org/oss-sec/2021/q2/0
|
||||
|
||||
Reproducer (replace 'localhost' accordingly): perl -e 'print "GET / HTTP/1.0\nHost: \n"; \
|
||||
while(1) { print " " . "A" x 65000 . "\n"; }' | socat - tcp-connect:localhost:8080
|
||||
|
||||
--- zarafa-7.1.14/caldav/Http.cpp 2015-10-20 11:13:41.000000000 +0200
|
||||
+++ zarafa-7.1.14/caldav/Http.cpp.ical-remote-dos 2021-03-24 16:17:51.417866211 +0100
|
||||
@@ -180,6 +180,8 @@
|
||||
std::string strBuffer;
|
||||
ULONG n = 0;
|
||||
std::map<std::string, std::string>::iterator iHeader = mapHeaders.end();
|
||||
+ static constexpr std::size_t MAX_HEADER_LENGTH = 65536;
|
||||
+ std::size_t numOfBytesRead = 0;
|
||||
|
||||
m_lpLogger->Log(EC_LOGLEVEL_DEBUG, "Receiving headers:");
|
||||
do
|
||||
@@ -191,6 +193,11 @@
|
||||
if (strBuffer.empty())
|
||||
break;
|
||||
|
||||
+ numOfBytesRead += strBuffer.size();
|
||||
+ if(numOfBytesRead > MAX_HEADER_LENGTH) {
|
||||
+ return MAPI_E_TOO_BIG;
|
||||
+ }
|
||||
+
|
||||
if (n == 0) {
|
||||
m_strAction = strBuffer;
|
||||
} else {
|
||||
57
zarafa-7.1.14-ical-remote-dos2.patch
Normal file
57
zarafa-7.1.14-ical-remote-dos2.patch
Normal file
|
|
@ -0,0 +1,57 @@
|
|||
Backport of upstream patch from Git commit 5fca684b79841ee285e59279d36c17eb2b8499b0 to fix
|
||||
remote DoS with out-of-bounds access in the zarafa-ical daemon of Zarafa 7.1.14. See also:
|
||||
|
||||
- https://seclists.org/oss-sec/2021/q2/1
|
||||
- https://github.com/Kopano-dev/kopano-core/commit/5fca684b79841ee285e59279d36c17eb2b8499b0
|
||||
- https://bugzilla.redhat.com/show_bug.cgi?id=1953242
|
||||
- https://seclists.org/oss-sec/2021/q2/75
|
||||
|
||||
Reproducer (replace 'localhost' accordingly): perl -e 'print "GET / HTTP/1.0\nFoo:\n"' | \
|
||||
socat - tcp-connect:localhost:8080
|
||||
|
||||
--- zarafa-7.1.14/caldav/Http.cpp 2021-04-25 02:08:00.210346882 +0200
|
||||
+++ zarafa-7.1.14/caldav/Http.cpp.ical-remote-dos2 2021-04-25 02:14:34.734819443 +0200
|
||||
@@ -201,19 +201,36 @@
|
||||
if (n == 0) {
|
||||
m_strAction = strBuffer;
|
||||
} else {
|
||||
- std::string::size_type pos = strBuffer.find(':');
|
||||
- std::string::size_type start = 0;
|
||||
- std::pair<std::map<std::string, std::string>::iterator, bool> r;
|
||||
+ std::string::size_type keyPos = strBuffer.find(':');
|
||||
+ std::size_t start = 0;
|
||||
|
||||
+ // Multi-line header
|
||||
if (strBuffer[0] == ' ' || strBuffer[0] == '\t') {
|
||||
if (iHeader == mapHeaders.end())
|
||||
continue;
|
||||
- // continue header
|
||||
- while (strBuffer[start] == ' ' || strBuffer[start] == '\t') start++;
|
||||
+
|
||||
+ // Continue header
|
||||
+ while (strBuffer[start] == ' ' || strBuffer[start] == '\t')
|
||||
+ ++start;
|
||||
iHeader->second += strBuffer.substr(start);
|
||||
+ } else if (keyPos == std::string::npos) {
|
||||
+ // If we were not in a multi-line header and
|
||||
+ // didn't find a colon, ignore this header.
|
||||
+ continue;
|
||||
} else {
|
||||
- // new header
|
||||
- r = mapHeaders.insert(make_pair<string,string>(strBuffer.substr(0,pos), strBuffer.substr(pos+2)));
|
||||
+ // Skip initial spaces in value.
|
||||
+ auto valuePos = keyPos;
|
||||
+ ++valuePos; // skip colon
|
||||
+ while (valuePos < strBuffer.size() && strBuffer[valuePos] == ' ') {
|
||||
+ ++valuePos;
|
||||
+ }
|
||||
+
|
||||
+ // If there's no valid value just ignore it and continue
|
||||
+ if (valuePos >= strBuffer.size()) {
|
||||
+ continue;
|
||||
+ }
|
||||
+
|
||||
+ auto r = mapHeaders.emplace(strBuffer.substr(0, keyPos), strBuffer.substr(valuePos));
|
||||
iHeader = r.first;
|
||||
}
|
||||
}
|
||||
363
zarafa-7.1.14-libical3.patch
Normal file
363
zarafa-7.1.14-libical3.patch
Normal file
|
|
@ -0,0 +1,363 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa <= 7.1.14 which backports the support for
|
||||
libical 3.0.x from Kopano Core 8.x. This patch only exists, because Red Hat decided (by bumping libical
|
||||
from 1.0.1 to 3.0.3) to silently break the API of libical in Red Hat Enterprise Linux 7. It was silent,
|
||||
because the rebase is not mentioned in any release notes for Red Hat Enterprise Linux 7.x. Unfortunately,
|
||||
the compat-libical1 RPM package provides only a run-time compatibility library, but not a build-time one.
|
||||
|
||||
And finally, the backports from Kopano Core 8.x introduce a dependency on C++11 due to "nullptr", which
|
||||
requires some more source code changes to make Zarafa compiling using the -std=c++11 option. The last two
|
||||
parts of this patch just avoid running autoconf and are generated results.
|
||||
|
||||
Technically, this patch is inspired by the following patches from Kopano Core 8.x:
|
||||
|
||||
- https://github.com/Kopano-dev/kopano-core/commit/e90693bfd57644297cc2f52277101d935b242921
|
||||
- https://github.com/Kopano-dev/kopano-core/commit/0768d5d5a0496a91004ea3559281f41421f468dc
|
||||
- https://github.com/Kopano-dev/kopano-core/commit/00d3efa21ce8c063f11f9d3b92be75e8147d3faa
|
||||
- https://github.com/Kopano-dev/kopano-core/commit/d9dc1cb404959846979f50aef9d3fece5865781d
|
||||
|
||||
This patch is is free software: You can redistribute it and/or modify it under the terms of the GNU Affero
|
||||
General Public License, version 3, as published by the Free Software Foundation.
|
||||
|
||||
--- zarafa-7.1.14/common/ECLogger.h 2015-10-20 11:13:43.000000000 +0200
|
||||
+++ zarafa-7.1.14/common/ECLogger.h.libical3 2021-03-24 21:56:23.232044349 +0100
|
||||
@@ -81,8 +81,8 @@
|
||||
#define _LOG_BUFSIZE 10240
|
||||
#define _LOG_TSSIZE 64
|
||||
|
||||
-#define LOG_DEBUG(_plog,_msg,...) if ((_plog)->Log(EC_LOGLEVEL_DEBUG)) (_plog)->Log(EC_LOGLEVEL_DEBUG, _msg, ##__VA_ARGS__)
|
||||
-#define LOG_AUDIT(_plog,_msg,...) if ((_plog)) (_plog)->Log(EC_LOGLEVEL_FATAL, _msg, ##__VA_ARGS__)
|
||||
+#define LOG_DEBUG(_plog,msg,...) if ((_plog)->Log(EC_LOGLEVEL_DEBUG)) (_plog)->Log(EC_LOGLEVEL_DEBUG, msg, ##__VA_ARGS__)
|
||||
+#define LOG_AUDIT(_plog,msg,...) if ((_plog)) (_plog)->Log(EC_LOGLEVEL_FATAL, msg, ##__VA_ARGS__)
|
||||
|
||||
#ifdef UNICODE
|
||||
#define TSTRING_PRINTF "%ls"
|
||||
--- zarafa-7.1.14/common/rtfutil.cpp 2015-10-20 11:13:44.000000000 +0200
|
||||
+++ zarafa-7.1.14/common/rtfutil.cpp.libical3 2021-03-24 21:34:41.350262220 +0100
|
||||
@@ -286,7 +286,7 @@
|
||||
sState[ulState].szCharset = szANSICharset;
|
||||
} else if(strcmp(szCommand,"fcharset") == 0) {
|
||||
if(sState[ulState].bInFontTbl) {
|
||||
- mapFontToCharset.insert(make_pair<int,int>(sState[ulState].ulFont, lArg));
|
||||
+ mapFontToCharset.insert(make_pair(sState[ulState].ulFont, lArg));
|
||||
}
|
||||
} else if(strcmp(szCommand,"htmltag") == 0) {
|
||||
} else if(strcmp(szCommand,"mhtmltag") == 0) {
|
||||
@@ -538,7 +538,7 @@
|
||||
sState[ulState].szCharset = szANSICharset;
|
||||
} else if(strcmp(szCommand,"fcharset") == 0) {
|
||||
if(sState[ulState].bInFontTbl) {
|
||||
- mapFontToCharset.insert(make_pair<int,int>(sState[ulState].ulFont, lArg));
|
||||
+ mapFontToCharset.insert(make_pair(sState[ulState].ulFont, lArg));
|
||||
}
|
||||
} else if(strcmp(szCommand,"htmltag") == 0) {
|
||||
} else if(strcmp(szCommand,"mhtmltag") == 0) {
|
||||
@@ -847,7 +847,7 @@
|
||||
sState[ulState].szCharset = szANSICharset;
|
||||
} else if(strcmp(szCommand,"fcharset") == 0) {
|
||||
if(sState[ulState].bInFontTbl) {
|
||||
- mapFontToCharset.insert(make_pair<int,int>(sState[ulState].ulFont, lArg));
|
||||
+ mapFontToCharset.insert(make_pair(sState[ulState].ulFont, lArg));
|
||||
}
|
||||
} else if(strcmp(szCommand,"htmltag") == 0) {
|
||||
} else if(strcmp(szCommand,"latentstyles") == 0) {
|
||||
@@ -1191,7 +1191,7 @@
|
||||
sState[ulState].szCharset = szANSICharset;
|
||||
} else if(strcmp(szCommand,"fcharset") == 0) {
|
||||
if(sState[ulState].bInFontTbl) {
|
||||
- mapFontToCharset.insert(make_pair<int,int>(sState[ulState].ulFont, lArg));
|
||||
+ mapFontToCharset.insert(make_pair(sState[ulState].ulFont, lArg));
|
||||
}
|
||||
} else if(strcmp(szCommand,"htmltag") == 0) {
|
||||
} else if(strcmp(szCommand,"mhtmltag") == 0) {
|
||||
--- zarafa-7.1.14/configure.ac 2015-10-20 10:35:08.000000000 +0200
|
||||
+++ zarafa-7.1.14/configure.ac.libical3 2021-03-24 21:04:19.288964999 +0100
|
||||
@@ -93,6 +93,15 @@
|
||||
LFS_CFLAGS=`getconf LFS_CFLAGS`
|
||||
ZCPPFLAGS="$ZCPPFLAGS $LFS_CFLAGS"
|
||||
|
||||
+# Backport of libical 3.0.x support from Kopano needs at least C++11
|
||||
+AC_MSG_CHECKING([whether C++ compiler understands -std=c++11 option])
|
||||
+AC_LANG_PUSH([C++])
|
||||
+CXXFLAGS="$ZCXXFLAGS -std=c++11"
|
||||
+AC_COMPILE_IFELSE([AC_LANG_SOURCE([])], [AC_MSG_RESULT([yes])], [AC_MSG_ERROR([at least C++11 is needed])])
|
||||
+CXXFLAGS="$ZCXXFLAGS"
|
||||
+ZCXXFLAGS="$ZCXXFLAGS -std=c++11"
|
||||
+AC_LANG_POP([C++])
|
||||
+
|
||||
# disable variadic-macros: too much warning: anonymous variadic macros were introduced in C99, only on new compilers
|
||||
AC_MSG_CHECKING([whether C++ compiler understands -Wno-variadic-macros option])
|
||||
if ( echo 'int main() {}' | $CXX -Wno-variadic-macros -E - >/dev/null 2>&1 ); then
|
||||
--- zarafa-7.1.14/ECtools/zarafa-search/ECServerIndexer.cpp 2015-10-20 11:13:42.000000000 +0200
|
||||
+++ zarafa-7.1.14/ECtools/zarafa-search/ECServerIndexer.cpp.libical3 2021-03-24 22:09:21.447493538 +0100
|
||||
@@ -1113,7 +1113,7 @@
|
||||
goto exit;
|
||||
}
|
||||
|
||||
- m_listRebuildStores.push_back(make_pair<std::string, std::string>(strServerGuid, strStoreGuid));
|
||||
+ m_listRebuildStores.push_back(make_pair(strServerGuid, strStoreGuid));
|
||||
pthread_cond_signal(&m_condRebuild);
|
||||
|
||||
exit:
|
||||
--- zarafa-7.1.14/libicalmapi/icalcompat.h 1970-01-01 01:00:00.000000000 +0100
|
||||
+++ zarafa-7.1.14/libicalmapi/icalcompat.h.libical3 2021-03-24 20:08:34.242068922 +0100
|
||||
@@ -0,0 +1,15 @@
|
||||
+#ifndef ICALMAPI_ICALCOMPAT_H
|
||||
+#define ICALMAPI_ICALCOMPAT_H 1
|
||||
+
|
||||
+#include <libical/ical.h>
|
||||
+
|
||||
+template<typename T> static inline void ical_utc(T &r, bool utc)
|
||||
+{
|
||||
+#if defined(ICAL_MAJOR_VERSION) && ICAL_MAJOR_VERSION < 3
|
||||
+ r.is_utc = utc;
|
||||
+#else
|
||||
+ r.zone = utc ? icaltimezone_get_utc_timezone() : nullptr;
|
||||
+#endif
|
||||
+}
|
||||
+
|
||||
+#endif
|
||||
--- zarafa-7.1.14/libicalmapi/icalrecurrence.cpp 2015-10-20 11:13:41.000000000 +0200
|
||||
+++ zarafa-7.1.14/libicalmapi/icalrecurrence.cpp.libical3 2021-03-24 20:09:40.783647592 +0100
|
||||
@@ -54,6 +54,7 @@
|
||||
#include <math.h>
|
||||
#include <algorithm>
|
||||
#include "freebusy.h"
|
||||
+#include "icalcompat.h"
|
||||
|
||||
bool operator ==(SPropValue spv, ULONG ulPropTag) {
|
||||
return spv.ulPropTag == ulPropTag;
|
||||
@@ -863,12 +864,12 @@
|
||||
for (iException = lstExceptions.begin(); iException != lstExceptions.end(); iException++) {
|
||||
if(bIsAllDay)
|
||||
{
|
||||
- ittExDate = icaltime_from_timet(LocalToUTC(*iException, sTZgmt), bIsAllDay);
|
||||
+ ittExDate = icaltime_from_timet_with_zone(LocalToUTC(*iException, sTZgmt), bIsAllDay, nullptr);
|
||||
}
|
||||
else
|
||||
- ittExDate = icaltime_from_timet(LocalToUTC(*iException, sTimeZone), 0);
|
||||
+ ittExDate = icaltime_from_timet_with_zone(LocalToUTC(*iException, sTimeZone), 0, nullptr);
|
||||
|
||||
- ittExDate.is_utc = 1;
|
||||
+ ical_utc(ittExDate, true);
|
||||
|
||||
icalcomponent_add_property(lpicEvent, icalproperty_new_exdate(ittExDate));
|
||||
}
|
||||
@@ -987,8 +988,8 @@
|
||||
*/
|
||||
icRec.count = 0;
|
||||
// if untiltime is saved as UTC it breaks last occurrence.
|
||||
- icRec.until = icaltime_from_timet(lpRecurrence->getEndDate() + lpRecurrence->getStartTimeOffset(), bIsAllday);
|
||||
- icRec.until.is_utc = 0;
|
||||
+ icRec.until = icaltime_from_timet_with_zone(lpRecurrence->getEndDate() + lpRecurrence->getStartTimeOffset(), bIsAllday, nullptr);
|
||||
+ ical_utc(icRec.until, false);
|
||||
break;
|
||||
case recurrence::NUMBER:
|
||||
icRec.count = lpRecurrence->getCount();
|
||||
--- zarafa-7.1.14/libicalmapi/Makefile.am 2015-10-20 10:35:03.000000000 +0200
|
||||
+++ zarafa-7.1.14/libicalmapi/Makefile.am.libical3 2021-03-24 20:05:15.554338238 +0100
|
||||
@@ -16,7 +16,7 @@
|
||||
|
||||
libicalmapidir = $(includedir)/icalmapi
|
||||
libicalmapi_HEADERS = icalitem.h nameids.h icaluid.h \
|
||||
- MAPIToICal.h ICalToMAPI.h \
|
||||
+ MAPIToICal.h ICalToMAPI.h icalcompat.h \
|
||||
vtimezone.h valarm.h vconverter.h vevent.h vtodo.h \
|
||||
icalrecurrence.h icalmapi.h vfreebusy.h
|
||||
|
||||
--- zarafa-7.1.14/libicalmapi/valarm.cpp 2015-10-20 11:13:41.000000000 +0200
|
||||
+++ zarafa-7.1.14/libicalmapi/valarm.cpp.libical3 2021-03-24 20:10:25.009031936 +0100
|
||||
@@ -57,6 +57,7 @@
|
||||
#include "CommonUtil.h"
|
||||
#include "Util.h"
|
||||
#include "stringutil.h"
|
||||
+#include "icalcompat.h"
|
||||
|
||||
#ifdef _DEBUG
|
||||
#define new DEBUG_NEW
|
||||
@@ -92,8 +93,8 @@
|
||||
memset((void *) &sittTrigger, 0, sizeof(icaltriggertype));
|
||||
|
||||
if (ttReminderTime && bTask) {
|
||||
- sittTrigger.time = icaltime_from_timet(ttReminderTime, false); // given in UTC
|
||||
- sittTrigger.time.is_utc = 1;
|
||||
+ sittTrigger.time = icaltime_from_timet_with_zone(ttReminderTime, false, nullptr); // given in UTC
|
||||
+ ical_utc(sittTrigger.time, true);
|
||||
} else
|
||||
sittTrigger.duration = icaldurationtype_from_int(-1 * lRemindBefore * 60); // set seconds
|
||||
|
||||
--- zarafa-7.1.14/libicalmapi/vconverter.cpp 2015-10-20 11:13:41.000000000 +0200
|
||||
+++ zarafa-7.1.14/libicalmapi/vconverter.cpp.libical3 2021-03-24 22:01:11.431379616 +0100
|
||||
@@ -59,6 +59,7 @@
|
||||
#include "mapi_ptr.h"
|
||||
#include "namedprops.h"
|
||||
#include "base64.h"
|
||||
+#include "icalcompat.h"
|
||||
|
||||
using namespace std;
|
||||
|
||||
@@ -639,7 +640,7 @@
|
||||
|
||||
strUid = bin2hex(lpsProp->Value.bin.cb, lpsProp->Value.bin.lpb);
|
||||
|
||||
- icTime = icaltime_from_timet(ICalTimeTypeToUTC(lpiEvent, icProp), 0);
|
||||
+ icTime = icaltime_from_timet_with_zone(ICalTimeTypeToUTC(lpiEvent, icProp), 0, nullptr);
|
||||
sprintf(strHexDate,"%04x%02x%02x", icTime.year, icTime.month, icTime.day);
|
||||
|
||||
// Exception date is stored in GlobalObjectId
|
||||
@@ -2148,8 +2149,8 @@
|
||||
// Set creation time / CREATED
|
||||
lpPropVal = PpropFindProp(lpMsgProps, ulMsgProps, PR_CREATION_TIME);
|
||||
if (lpPropVal) {
|
||||
- ittICalTime = icaltime_from_timet(FileTimeToUnixTime(lpPropVal->Value.ft.dwHighDateTime, lpPropVal->Value.ft.dwLowDateTime), 0);
|
||||
- ittICalTime.is_utc = 1;
|
||||
+ ittICalTime = icaltime_from_timet_with_zone(FileTimeToUnixTime(lpPropVal->Value.ft.dwHighDateTime, lpPropVal->Value.ft.dwLowDateTime), 0, nullptr);
|
||||
+ ical_utc(ittICalTime, true);
|
||||
|
||||
lpProp = icalproperty_new_created(ittICalTime);
|
||||
icalcomponent_add_property(lpEvent, lpProp);
|
||||
@@ -2169,8 +2170,8 @@
|
||||
// Set modification time / LAST-MODIFIED + DTSTAMP
|
||||
lpPropVal = PpropFindProp(lpMsgProps, ulMsgProps, PR_LAST_MODIFICATION_TIME);
|
||||
if (lpPropVal) {
|
||||
- ittICalTime = icaltime_from_timet(FileTimeToUnixTime(lpPropVal->Value.ft.dwHighDateTime, lpPropVal->Value.ft.dwLowDateTime), 0);
|
||||
- ittICalTime.is_utc = 1;
|
||||
+ ittICalTime = icaltime_from_timet_with_zone(FileTimeToUnixTime(lpPropVal->Value.ft.dwHighDateTime, lpPropVal->Value.ft.dwLowDateTime), 0, nullptr);
|
||||
+ ical_utc(ittICalTime, true);
|
||||
|
||||
lpProp = icalproperty_new_lastmodified(ittICalTime);
|
||||
icalcomponent_add_property(lpEvent,lpProp);
|
||||
--- zarafa-7.1.14/libicalmapi/vtimezone.cpp 2015-10-20 11:13:41.000000000 +0200
|
||||
+++ zarafa-7.1.14/libicalmapi/vtimezone.cpp.libical3 2021-03-24 20:14:19.824069285 +0100
|
||||
@@ -49,6 +49,7 @@
|
||||
#include <stdlib.h>
|
||||
#include <math.h>
|
||||
#include <time.h>
|
||||
+#include "icalcompat.h"
|
||||
|
||||
using namespace std;
|
||||
|
||||
@@ -192,7 +193,7 @@
|
||||
}
|
||||
|
||||
icTime = icalcomponent_get_dtstart(icComp);
|
||||
- icTime.is_utc = 1;
|
||||
+ ical_utc(icTime, true);
|
||||
|
||||
if (kind == ICAL_XSTANDARD_COMPONENT) {
|
||||
// this is set when we request the STD timezone part.
|
||||
@@ -342,7 +343,7 @@
|
||||
|
||||
// STD
|
||||
icComp = icalcomponent_new_xstandard();
|
||||
- icTime = icaltime_from_timet(SystemTimeToUnixTime(tsTimeZone.stStdDate), 0);
|
||||
+ icTime = icaltime_from_timet_with_zone(SystemTimeToUnixTime(tsTimeZone.stStdDate), 0, nullptr);
|
||||
icalcomponent_add_property(icComp, icalproperty_new_dtstart(icTime));
|
||||
if (tsTimeZone.lStdBias == tsTimeZone.lDstBias || tsTimeZone.stStdDate.wMonth == 0 || tsTimeZone.stDstDate.wMonth == 0) {
|
||||
// std == dst
|
||||
@@ -373,7 +374,7 @@
|
||||
// DST, optional
|
||||
if (tsTimeZone.lStdBias != tsTimeZone.lDstBias && tsTimeZone.stStdDate.wMonth != 0 && tsTimeZone.stDstDate.wMonth != 0) {
|
||||
icComp = icalcomponent_new_xdaylight();
|
||||
- icTime = icaltime_from_timet(SystemTimeToUnixTime(tsTimeZone.stDstDate), 0);
|
||||
+ icTime = icaltime_from_timet_with_zone(SystemTimeToUnixTime(tsTimeZone.stDstDate), 0, nullptr);
|
||||
icalcomponent_add_property(icComp, icalproperty_new_dtstart(icTime));
|
||||
|
||||
icalcomponent_add_property(icComp, icalproperty_new_tzoffsetfrom(-tsTimeZone.lBias *60));
|
||||
--- zarafa-7.1.14/provider/libserver/ECCacheManager.cpp 2015-10-20 11:13:46.000000000 +0200
|
||||
+++ zarafa-7.1.14/provider/libserver/ECCacheManager.cpp.libical3 2021-03-24 21:48:06.169046380 +0100
|
||||
@@ -68,9 +68,9 @@
|
||||
|
||||
#include <algorithm>
|
||||
|
||||
-#define LOG_CACHE_DEBUG(_msg, ...) if (m_lpLogger->Log(EC_LOGLEVEL_DEBUG|EC_LOGLEVEL_CACHE)) { m_lpLogger->Log(EC_LOGLEVEL_DEBUG|EC_LOGLEVEL_CACHE, "cache: "_msg, ##__VA_ARGS__); }
|
||||
-#define LOG_USERCACHE_DEBUG(_msg, ...) if (m_lpLogger->Log(EC_LOGLEVEL_DEBUG|EC_LOGLEVEL_USERCACHE)) { m_lpLogger->Log(EC_LOGLEVEL_DEBUG|EC_LOGLEVEL_USERCACHE, "usercache: "_msg, ##__VA_ARGS__); }
|
||||
-#define LOG_CELLCACHE_DEBUG(_msg, ...) if (m_lpLogger->Log(EC_LOGLEVEL_DEBUG|EC_LOGLEVEL_CACHE)) { m_lpLogger->Log(EC_LOGLEVEL_DEBUG|EC_LOGLEVEL_CACHE, "cellcache: "_msg, ##__VA_ARGS__); }
|
||||
+#define LOG_CACHE_DEBUG(msg, ...) if (m_lpLogger->Log(EC_LOGLEVEL_DEBUG|EC_LOGLEVEL_CACHE)) { m_lpLogger->Log(EC_LOGLEVEL_DEBUG|EC_LOGLEVEL_CACHE, "cache: " msg, ##__VA_ARGS__); }
|
||||
+#define LOG_USERCACHE_DEBUG(msg, ...) if (m_lpLogger->Log(EC_LOGLEVEL_DEBUG|EC_LOGLEVEL_USERCACHE)) { m_lpLogger->Log(EC_LOGLEVEL_DEBUG|EC_LOGLEVEL_USERCACHE, "usercache: " msg, ##__VA_ARGS__); }
|
||||
+#define LOG_CELLCACHE_DEBUG(msg, ...) if (m_lpLogger->Log(EC_LOGLEVEL_DEBUG|EC_LOGLEVEL_CACHE)) { m_lpLogger->Log(EC_LOGLEVEL_DEBUG|EC_LOGLEVEL_CACHE, "cellcache: " msg, ##__VA_ARGS__); }
|
||||
|
||||
// Specialization for ECsACL
|
||||
template<>
|
||||
--- zarafa-7.1.14/provider/libserver/ECDatabaseMySQL.cpp 2015-10-20 11:13:45.000000000 +0200
|
||||
+++ zarafa-7.1.14/provider/libserver/ECDatabaseMySQL.cpp.libical3 2021-03-24 21:55:47.974759496 +0100
|
||||
@@ -81,7 +81,7 @@
|
||||
#define DEBUG_TRANSACTION 0
|
||||
#endif
|
||||
|
||||
-#define LOG_SQL_DEBUG(_plog, _msg, ...) if ((_plog)->Log(EC_LOGLEVEL_DEBUG|EC_LOGLEVEL_SQL)) (_plog)->Log(EC_LOGLEVEL_DEBUG|EC_LOGLEVEL_SQL, _msg, ##__VA_ARGS__)
|
||||
+#define LOG_SQL_DEBUG(_plog, msg, ...) if ((_plog)->Log(EC_LOGLEVEL_DEBUG|EC_LOGLEVEL_SQL)) (_plog)->Log(EC_LOGLEVEL_DEBUG|EC_LOGLEVEL_SQL, msg, ##__VA_ARGS__)
|
||||
|
||||
// The maximum packet size. This is automatically also the maximum
|
||||
// size of a single entry in the database. This means that PR_BODY, PR_COMPRESSED_RTF
|
||||
--- zarafa-7.1.14/provider/libserver/ZarafaCmd.cpp 2015-10-20 11:13:45.000000000 +0200
|
||||
+++ zarafa-7.1.14/provider/libserver/ZarafaCmd.cpp.libical3 2021-03-24 21:55:31.623627454 +0100
|
||||
@@ -118,7 +118,7 @@
|
||||
#define STROUT_FIX(s) (bSupportUnicode ? (s) : ECStringCompat::UTF8_to_WTF1252(soap, (s)))
|
||||
#define STROUT_FIX_CPY(s) (bSupportUnicode ? s_strcpy(soap, (s)) : ECStringCompat::UTF8_to_WTF1252(soap, (s)))
|
||||
|
||||
-#define LOG_SOAP_DEBUG(logger, _msg, ...) if (logger->Log(EC_LOGLEVEL_DEBUG|EC_LOGLEVEL_SOAP)) { logger->Log(EC_LOGLEVEL_DEBUG|EC_LOGLEVEL_SOAP, "soap: "_msg, ##__VA_ARGS__); }
|
||||
+#define LOG_SOAP_DEBUG(logger, msg, ...) if (logger->Log(EC_LOGLEVEL_DEBUG|EC_LOGLEVEL_SOAP)) { logger->Log(EC_LOGLEVEL_DEBUG|EC_LOGLEVEL_SOAP, "soap: " msg, ##__VA_ARGS__); }
|
||||
|
||||
#ifdef _DEBUG
|
||||
#define new DEBUG_NEW
|
||||
--- zarafa-7.1.14/provider/plugins/plugin.h 2015-10-20 11:13:45.000000000 +0200
|
||||
+++ zarafa-7.1.14/provider/plugins/plugin.h.libical3 2021-03-24 21:56:42.074196656 +0100
|
||||
@@ -70,7 +70,7 @@
|
||||
|
||||
using namespace std;
|
||||
|
||||
-#define LOG_PLUGIN_DEBUG(_msg, ...) if (m_logger->Log(EC_LOGLEVEL_DEBUG|EC_LOGLEVEL_PLUGIN)) { m_logger->Log(EC_LOGLEVEL_DEBUG|EC_LOGLEVEL_PLUGIN, "plugin: "_msg, ##__VA_ARGS__); }
|
||||
+#define LOG_PLUGIN_DEBUG(msg, ...) if (m_logger->Log(EC_LOGLEVEL_DEBUG|EC_LOGLEVEL_PLUGIN)) { m_logger->Log(EC_LOGLEVEL_DEBUG|EC_LOGLEVEL_PLUGIN, "plugin: " msg, ##__VA_ARGS__); }
|
||||
|
||||
/**
|
||||
* The objectsignature combines the object id with the
|
||||
--- zarafa-7.1.14/configure 2021-03-24 22:32:26.083216071 +0100
|
||||
+++ zarafa-7.1.14/configure.libical3 2021-03-24 22:40:08.332400705 +0100
|
||||
@@ -16844,6 +16844,36 @@
|
||||
LFS_CFLAGS=`getconf LFS_CFLAGS`
|
||||
ZCPPFLAGS="$ZCPPFLAGS $LFS_CFLAGS"
|
||||
|
||||
+# Backport of libical 3.0.x support from Kopano needs at least C++11
|
||||
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether C++ compiler understands -std=c++11 option" >&5
|
||||
+$as_echo_n "checking whether C++ compiler understands -std=c++11... " >&6; }
|
||||
+ac_ext=cpp
|
||||
+ac_cpp='$CXXCPP $CPPFLAGS'
|
||||
+ac_compile='$CXX -c $CXXFLAGS $CPPFLAGS conftest.$ac_ext >&5'
|
||||
+ac_link='$CXX -o conftest$ac_exeext $CXXFLAGS $CPPFLAGS $LDFLAGS conftest.$ac_ext $LIBS >&5'
|
||||
+ac_compiler_gnu=$ac_cv_cxx_compiler_gnu
|
||||
+
|
||||
+CXXFLAGS="$ZCXXFLAGS -std=c++11"
|
||||
+cat confdefs.h - <<_ACEOF >conftest.$ac_ext
|
||||
+/* end confdefs.h. */
|
||||
+
|
||||
+_ACEOF
|
||||
+if ac_fn_cxx_try_compile "$LINENO"; then :
|
||||
+ { $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
|
||||
+$as_echo "yes" >&6; }
|
||||
+else
|
||||
+ as_fn_error $? "at least C++11 is needed" "$LINENO" 5
|
||||
+fi
|
||||
+rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
|
||||
+CXXFLAGS="$ZCXXFLAGS"
|
||||
+ZCXXFLAGS="$ZCXXFLAGS -std=c++11"
|
||||
+ac_ext=cpp
|
||||
+ac_cpp='$CXXCPP $CPPFLAGS'
|
||||
+ac_compile='$CXX -c $CXXFLAGS $CPPFLAGS conftest.$ac_ext >&5'
|
||||
+ac_link='$CXX -o conftest$ac_exeext $CXXFLAGS $CPPFLAGS $LDFLAGS conftest.$ac_ext $LIBS >&5'
|
||||
+ac_compiler_gnu=$ac_cv_cxx_compiler_gnu
|
||||
+
|
||||
+
|
||||
# disable variadic-macros: too much warning: anonymous variadic macros were introduced in C99, only on new compilers
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether C++ compiler understands -Wno-variadic-macros option" >&5
|
||||
$as_echo_n "checking whether C++ compiler understands -Wno-variadic-macros option... " >&6; }
|
||||
--- zarafa-7.1.14/libicalmapi/Makefile.in 2015-10-20 10:35:13.000000000 +0200
|
||||
+++ zarafa-7.1.14/libicalmapi/Makefile.in.libical3 2021-03-24 20:15:45.459810942 +0100
|
||||
@@ -370,7 +370,7 @@
|
||||
|
||||
libicalmapidir = $(includedir)/icalmapi
|
||||
libicalmapi_HEADERS = icalitem.h nameids.h icaluid.h \
|
||||
- MAPIToICal.h ICalToMAPI.h \
|
||||
+ MAPIToICal.h ICalToMAPI.h icalcompat.h \
|
||||
vtimezone.h valarm.h vconverter.h vevent.h vtodo.h \
|
||||
icalrecurrence.h icalmapi.h vfreebusy.h
|
||||
|
||||
41
zarafa-7.1.14-pam_acct_mgmt.patch
Normal file
41
zarafa-7.1.14-pam_acct_mgmt.patch
Normal file
|
|
@ -0,0 +1,41 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa <= 7.1.14 which backports the security fix
|
||||
by Andreas Rönnquist <gusnan@librem.one> for Kopano Core <= 11.0.2.51 (for Debian). It fixes a security
|
||||
issue which allows attackers to authenticate even if the user account or password is expired. See also:
|
||||
|
||||
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26562
|
||||
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1016973
|
||||
- https://jira.kopano.io/browse/KC-2021
|
||||
- https://github.com/Kopano-dev/kopano-core/blob/master/provider/libserver/ECKrbAuth.cpp#L137
|
||||
- https://bugzilla.redhat.com/show_bug.cgi?id=2192126
|
||||
|
||||
The security flaw was introduced between Zarafa 6.30.0 RC 1e (Subversion Revision 14802) and 6.30.8 Final
|
||||
(Subversion Revision 18345) in provider/libserver/ECPamAuth.cpp and also affects Kopano Core <= 11.0.2.51
|
||||
in provider/libserver/ECKrbAuth.cpp.
|
||||
|
||||
--- zarafa-7.1.14/provider/libserver/ECPamAuth.cpp 2015-10-20 11:13:45.000000000 +0200
|
||||
+++ zarafa-7.1.14/provider/libserver/ECPamAuth.cpp.pam_acct_mgmt 2023-02-09 19:53:11.843375272 +0200
|
||||
@@ -111,14 +111,21 @@
|
||||
}
|
||||
|
||||
res = pam_authenticate(pamh, PAM_SILENT);
|
||||
-
|
||||
- pam_end(pamh, res);
|
||||
-
|
||||
if (res != PAM_SUCCESS) {
|
||||
*lpstrError = pam_strerror(NULL, res);
|
||||
+ pam_end(pamh, res);
|
||||
er = ZARAFA_E_LOGON_FAILED;
|
||||
}
|
||||
|
||||
+ res = pam_acct_mgmt(pamh, PAM_SILENT);
|
||||
+ if (res != PAM_SUCCESS) {
|
||||
+ *lpstrError = pam_strerror(NULL, res);
|
||||
+ pam_end(pamh, res);
|
||||
+ er = ZARAFA_E_LOGON_FAILED;
|
||||
+ }
|
||||
+
|
||||
+ pam_end(pamh, res);
|
||||
+
|
||||
exit:
|
||||
pthread_mutex_unlock(&cPAMLock.m_mPAMAuthLock);
|
||||
|
||||
147
zarafa-7.1.14-spooler-expand_groups.patch
Normal file
147
zarafa-7.1.14-spooler-expand_groups.patch
Normal file
|
|
@ -0,0 +1,147 @@
|
|||
Backport of upstream patch from subversion revision 50583 to fix https://jira.zarafa.com/browse/ZCP-12148
|
||||
|
||||
--- zarafa-7.1.14/inetmapi/ECVMIMEUtils.cpp 2015-10-20 11:13:43.000000000 +0200
|
||||
+++ zarafa-7.1.14/inetmapi/ECVMIMEUtils.cpp.spooler-expand_groups 2016-11-28 22:46:59.000000000 +0100
|
||||
@@ -112,7 +112,7 @@
|
||||
* This function takes a MAPI table, reads all items from it, expands any groups and adds all expanded recipients into the passed
|
||||
* recipient table. Group expansion is recursive.
|
||||
*/
|
||||
-HRESULT ECVMIMESender::HrAddRecipsFromTable(LPADRBOOK lpAdrBook, IMAPITable *lpTable, vmime::mailboxList &recipients, std::set<std::wstring> &setGroups, std::set<std::wstring> &setRecips, bool bAllowEveryone)
|
||||
+HRESULT ECVMIMESender::HrAddRecipsFromTable(LPADRBOOK lpAdrBook, IMAPITable *lpTable, vmime::mailboxList &recipients, std::set<std::wstring> &setGroups, std::set<std::wstring> &setRecips, bool bAllowEveryone, bool bAlwaysExpandDistrList)
|
||||
{
|
||||
HRESULT hr = hrSuccess;
|
||||
LPSRowSet lpRowSet = NULL;
|
||||
@@ -125,14 +125,10 @@
|
||||
// Get all recipients from the group
|
||||
for (ULONG i = 0; i < lpRowSet->cRows; i++) {
|
||||
LPSPropValue lpPropObjectType = PpropFindProp( lpRowSet->aRow[i].lpProps, lpRowSet->aRow[i].cValues, PR_OBJECT_TYPE);
|
||||
+ bool bAddrFetchSuccess = HrGetAddress(lpAdrBook, lpRowSet->aRow[i].lpProps, lpRowSet->aRow[i].cValues, PR_ENTRYID, PR_DISPLAY_NAME_W, PR_ADDRTYPE_W, PR_EMAIL_ADDRESS_W, strName, strType, strEmail) == hrSuccess;
|
||||
|
||||
- if(lpPropObjectType == NULL || lpPropObjectType->Value.ul == MAPI_MAILUSER) {
|
||||
- // Normal recipient
|
||||
- if (HrGetAddress(lpAdrBook, lpRowSet->aRow[i].lpProps, lpRowSet->aRow[i].cValues,
|
||||
- PR_ENTRYID, PR_DISPLAY_NAME_W, PR_ADDRTYPE_W, PR_EMAIL_ADDRESS_W,
|
||||
- strName, strType, strEmail) == hrSuccess)
|
||||
- {
|
||||
-
|
||||
+ if (bAddrFetchSuccess && (lpPropObjectType == NULL || lpPropObjectType->Value.ul == MAPI_MAILUSER || (lpPropObjectType->Value.ul == MAPI_DISTLIST && !bAlwaysExpandDistrList))) {
|
||||
+ if (bAddrFetchSuccess) {
|
||||
if(!strEmail.empty() && setRecips.find(strEmail) == setRecips.end()) {
|
||||
recipients.appendMailbox(vmime::create<vmime::mailbox>(convert_to<string>(strEmail)));
|
||||
setRecips.insert(strEmail);
|
||||
@@ -263,7 +259,7 @@
|
||||
if(hr != hrSuccess)
|
||||
goto exit;
|
||||
|
||||
- hr = HrAddRecipsFromTable(lpAdrBook, lpTable, recipients, setGroups, setRecips, bAllowEveryone);
|
||||
+ hr = HrAddRecipsFromTable(lpAdrBook, lpTable, recipients, setGroups, setRecips, bAllowEveryone, true);
|
||||
if(hr != hrSuccess)
|
||||
goto exit;
|
||||
|
||||
@@ -283,7 +279,7 @@
|
||||
return hr;
|
||||
}
|
||||
|
||||
-HRESULT ECVMIMESender::HrMakeRecipientsList(LPADRBOOK lpAdrBook, LPMESSAGE lpMessage, vmime::ref<vmime::message> vmMessage, vmime::mailboxList &recipients, bool bAllowEveryone)
|
||||
+HRESULT ECVMIMESender::HrMakeRecipientsList(LPADRBOOK lpAdrBook, LPMESSAGE lpMessage, vmime::ref<vmime::message> vmMessage, vmime::mailboxList &recipients, bool bAllowEveryone, bool bAlwaysExpandDistrList)
|
||||
{
|
||||
HRESULT hr = hrSuccess;
|
||||
SRestriction sRestriction;
|
||||
@@ -320,7 +316,7 @@
|
||||
goto exit;
|
||||
}
|
||||
|
||||
- hr = HrAddRecipsFromTable(lpAdrBook, lpRTable, recipients, setGroups, setRecips, bAllowEveryone);
|
||||
+ hr = HrAddRecipsFromTable(lpAdrBook, lpRTable, recipients, setGroups, setRecips, bAllowEveryone, true);
|
||||
if (hr != hrSuccess)
|
||||
goto exit;
|
||||
|
||||
@@ -338,7 +334,7 @@
|
||||
// This function does not catch the vmime exception
|
||||
// it should be handled by the calling party.
|
||||
|
||||
-HRESULT ECVMIMESender::sendMail(LPADRBOOK lpAdrBook, LPMESSAGE lpMessage, vmime::ref<vmime::message> vmMessage, bool bAllowEveryone)
|
||||
+HRESULT ECVMIMESender::sendMail(LPADRBOOK lpAdrBook, LPMESSAGE lpMessage, vmime::ref<vmime::message> vmMessage, bool bAllowEveryone, bool bAlwaysExpandDistrList)
|
||||
{
|
||||
HRESULT hr = hrSuccess;
|
||||
vmime::mailbox expeditor;
|
||||
@@ -386,7 +382,7 @@
|
||||
goto exit;
|
||||
}
|
||||
|
||||
- hr = HrMakeRecipientsList(lpAdrBook, lpMessage, vmMessage, recipients, bAllowEveryone);
|
||||
+ hr = HrMakeRecipientsList(lpAdrBook, lpMessage, vmMessage, recipients, bAllowEveryone, bAlwaysExpandDistrList);
|
||||
if (hr != hrSuccess)
|
||||
goto exit;
|
||||
|
||||
--- zarafa-7.1.14/inetmapi/ECVMIMEUtils.h 2015-10-20 11:13:43.000000000 +0200
|
||||
+++ zarafa-7.1.14/inetmapi/ECVMIMEUtils.h.spooler-expand_groups 2016-11-28 22:51:24.000000000 +0100
|
||||
@@ -55,15 +55,15 @@
|
||||
{
|
||||
private:
|
||||
|
||||
- HRESULT HrMakeRecipientsList(LPADRBOOK lpAdrBook, LPMESSAGE lpMessage, vmime::ref<vmime::message> vmMessage, vmime::mailboxList &recipients, bool bAllowEveryone);
|
||||
+ HRESULT HrMakeRecipientsList(LPADRBOOK lpAdrBook, LPMESSAGE lpMessage, vmime::ref<vmime::message> vmMessage, vmime::mailboxList &recipients, bool bAllowEveryone, bool bAlwaysExpandDistrList);
|
||||
HRESULT HrExpandGroup(LPADRBOOK lpAdrBook, LPSPropValue lpGroupName, LPSPropValue lpGroupEntryID, vmime::mailboxList &recipients, std::set<std::wstring> &setGroups, std::set<std::wstring> &setRecips, bool bAllowEveryone);
|
||||
- HRESULT HrAddRecipsFromTable(LPADRBOOK lpAdrBook, IMAPITable *lpTable, vmime::mailboxList &recipients, std::set<std::wstring> &setGroups, std::set<std::wstring> &setRecips, bool bAllowEveryone);
|
||||
+ HRESULT HrAddRecipsFromTable(LPADRBOOK lpAdrBook, IMAPITable *lpTable, vmime::mailboxList &recipients, std::set<std::wstring> &setGroups, std::set<std::wstring> &setRecips, bool bAllowEveryone, bool bAlwaysExpandDistrList);
|
||||
|
||||
public:
|
||||
ECVMIMESender(ECLogger *newlpLogger, std::string strSMTPHost, int port);
|
||||
virtual ~ECVMIMESender();
|
||||
|
||||
- HRESULT sendMail(LPADRBOOK lpAdrBook, LPMESSAGE lpMessage, vmime::ref<vmime::message> vmMessage, bool bAllowEveryone);
|
||||
+ HRESULT sendMail(LPADRBOOK lpAdrBook, LPMESSAGE lpMessage, vmime::ref<vmime::message> vmMessage, bool bAllowEveryone, bool bAlwaysExpandDistrList);
|
||||
};
|
||||
|
||||
#endif
|
||||
--- zarafa-7.1.14/inetmapi/inetmapi.cpp 2015-10-20 11:13:43.000000000 +0200
|
||||
+++ zarafa-7.1.14/inetmapi/inetmapi.cpp.spooler-expand_groups 2016-11-28 22:50:04.000000000 +0100
|
||||
@@ -331,7 +331,7 @@
|
||||
goto exit;
|
||||
}
|
||||
|
||||
- hr = mailer->sendMail(lpAddrBook, lpMessage, vmMessage, sopt.allow_send_to_everyone);
|
||||
+ hr = mailer->sendMail(lpAddrBook, lpMessage, vmMessage, sopt.allow_send_to_everyone, sopt.always_expand_distr_list);
|
||||
|
||||
exit:
|
||||
delete mToVM;
|
||||
--- zarafa-7.1.14/inetmapi/options.h 2015-10-20 11:13:43.000000000 +0200
|
||||
+++ zarafa-7.1.14/inetmapi/options.h.spooler-expand_groups 2016-11-28 22:55:44.000000000 +0100
|
||||
@@ -68,6 +68,7 @@
|
||||
char *charset_upgrade;
|
||||
bool allow_send_to_everyone;
|
||||
bool enable_dsn; /**< Enable SMTP Delivery Status Notifications */
|
||||
+ bool always_expand_distr_list;
|
||||
} sending_options;
|
||||
|
||||
void INETMAPI_API imopt_default_delivery_options(delivery_options *dopt);
|
||||
--- zarafa-7.1.14/spooler/mailer.cpp 2015-10-20 11:13:43.000000000 +0200
|
||||
+++ zarafa-7.1.14/spooler/mailer.cpp.spooler-expand_groups 2016-11-28 22:54:38.000000000 +0100
|
||||
@@ -2178,6 +2178,8 @@
|
||||
// Enable SMTP Delivery Status Notifications
|
||||
sopt.enable_dsn = parseBool(g_lpConfig->GetSetting("enable_dsn"));
|
||||
|
||||
+ sopt.always_expand_distr_list = parseBool(g_lpConfig->GetSetting("expand_groups"));
|
||||
+
|
||||
// Init plugin system
|
||||
hr = pyMapiPluginFactory.Init(g_lpConfig, g_lpLogger);
|
||||
if (hr != hrSuccess) {
|
||||
@@ -2427,7 +2429,7 @@
|
||||
*/
|
||||
}
|
||||
|
||||
- if(parseBool(g_lpConfig->GetSetting("expand_groups"))) {
|
||||
+ if (sopt.always_expand_distr_list) {
|
||||
// Expand recipients with ADDRTYPE=ZARAFA to multiple ADDRTYPE=SMTP recipients
|
||||
hr = ExpandRecipients(lpAddrBook, lpMessage);
|
||||
if(hr != hrSuccess)
|
||||
@@ -2438,7 +2440,7 @@
|
||||
if (hr != hrSuccess)
|
||||
g_lpLogger->Log(EC_LOGLEVEL_WARNING, "Unable to rewrite recipients");
|
||||
|
||||
- if(parseBool(g_lpConfig->GetSetting("expand_groups"))) {
|
||||
+ if (sopt.always_expand_distr_list) {
|
||||
// Only touch recips if we're expanding groups; the rationale is here that the user
|
||||
// has typed a recipient twice if we have duplicates and expand_groups = no, so that's
|
||||
// what the user wanted apparently. What's more, duplicate recips are filtered for RCPT TO
|
||||
113
zarafa.spec
113
zarafa.spec
|
|
@ -1,6 +1,6 @@
|
|||
%global beta_or_rc 0
|
||||
%global actual_release 2
|
||||
%global svnrevision 46050
|
||||
%global actual_release 6
|
||||
%global svnrevision 51822
|
||||
%global with_search 1
|
||||
%global with_ldap 1
|
||||
%global with_xmlto 1
|
||||
|
|
@ -31,7 +31,7 @@
|
|||
|
||||
Summary: Open Source Edition of the Zarafa Collaboration Platform
|
||||
Name: zarafa
|
||||
Version: 7.1.11
|
||||
Version: 7.1.14
|
||||
%if %{beta_or_rc}
|
||||
Release: 0.%{actual_release}.svn%{svnrevision}%{?dist}
|
||||
%else
|
||||
|
|
@ -54,15 +54,33 @@ Source1: %{name}.ini
|
|||
Source2: %{name}.logrotate
|
||||
Source3: %{name}-webaccess.conf
|
||||
|
||||
Patch0: zarafa-7.1.11-rpath.patch
|
||||
Patch1: zarafa-7.1.11-php-unbundle.patch
|
||||
Patch2: zarafa-7.1.10-kyotocabinet.patch
|
||||
Patch3: zarafa-7.1.10-ssl_protocols_ciphers.patch
|
||||
Patch4: zarafa-7.1.9-ssl_ecdhe.patch
|
||||
Patch5: zarafa-7.1.11-plaintext_auth_localhost.patch
|
||||
Patch0: https://raw.githubusercontent.com/robert-scheck/zarafa-patches/main/zarafa-7.1.11-rpath.patch
|
||||
Patch1: https://raw.githubusercontent.com/robert-scheck/zarafa-patches/main/zarafa-7.1.11-php-unbundle.patch
|
||||
Patch2: https://raw.githubusercontent.com/robert-scheck/zarafa-patches/main/zarafa-7.1.10-kyotocabinet.patch
|
||||
Patch3: https://raw.githubusercontent.com/robert-scheck/zarafa-patches/main/zarafa-7.1.12-ssl_protocols_ciphers.patch
|
||||
Patch4: https://raw.githubusercontent.com/robert-scheck/zarafa-patches/main/zarafa-7.1.12-ssl_ecdhe.patch
|
||||
Patch5: https://raw.githubusercontent.com/robert-scheck/zarafa-patches/main/zarafa-7.1.11-plaintext_auth_localhost.patch
|
||||
Patch6: https://raw.githubusercontent.com/robert-scheck/zarafa-patches/main/zarafa-7.1.10-imap-badcharset.patch
|
||||
Patch7: https://raw.githubusercontent.com/robert-scheck/zarafa-patches/main/zarafa-7.1.10-imap-fetch-body.patch
|
||||
Patch8: https://raw.githubusercontent.com/robert-scheck/zarafa-patches/main/zarafa-7.1.11-vacation-headers.patch
|
||||
Patch9: https://raw.githubusercontent.com/robert-scheck/zarafa-patches/main/zarafa-7.1.11-vacation-headers2.patch
|
||||
Patch10: https://raw.githubusercontent.com/robert-scheck/zarafa-patches/main/zarafa-7.1.11-webaccess-fail2ban.patch
|
||||
Patch11: https://raw.githubusercontent.com/robert-scheck/zarafa-patches/main/zarafa-7.1.12-webaccess-mcrypt.patch
|
||||
Patch12: https://raw.githubusercontent.com/robert-scheck/zarafa-patches/main/zarafa-7.1.12-gsoap-sslv3.patch
|
||||
Patch14: https://raw.githubusercontent.com/robert-scheck/zarafa-patches/main/zarafa-7.1.12-upgrade-lock.patch
|
||||
Patch15: https://raw.githubusercontent.com/robert-scheck/zarafa-patches/main/zarafa-7.1.12-gcc5.patch
|
||||
Patch16: https://raw.githubusercontent.com/robert-scheck/zarafa-patches/main/zarafa-7.1.12-webaccess-xss.patch
|
||||
Patch17: https://raw.githubusercontent.com/robert-scheck/zarafa-patches/main/zarafa-7.1.12-webaccess-defaultfont.patch
|
||||
Patch18: https://raw.githubusercontent.com/robert-scheck/zarafa-patches/main/zarafa-7.1.13-ssl_dhe.patch
|
||||
Patch19: https://raw.githubusercontent.com/robert-scheck/zarafa-patches/main/zarafa-7.1.14-spooler-expand_groups.patch
|
||||
Patch20: https://raw.githubusercontent.com/robert-scheck/zarafa-patches/main/zarafa-7.1.14-libical3.patch
|
||||
Patch21: https://raw.githubusercontent.com/robert-scheck/zarafa-patches/main/zarafa-7.1.14-ical-remote-dos.patch
|
||||
Patch22: https://raw.githubusercontent.com/robert-scheck/zarafa-patches/main/zarafa-7.1.14-ical-remote-dos2.patch
|
||||
Patch23: https://raw.githubusercontent.com/robert-scheck/zarafa-patches/main/zarafa-7.1.14-pam_acct_mgmt.patch
|
||||
|
||||
BuildRequires: bison
|
||||
BuildRequires: gcc-c++
|
||||
BuildRequires: make
|
||||
BuildRequires: byacc
|
||||
BuildRequires: flex
|
||||
BuildRequires: gettext
|
||||
|
|
@ -315,7 +333,7 @@ Group: Applications/Productivity
|
|||
Requires: httpd, php-mapi = %{version}-%{release}
|
||||
# Bug: php53 from RHEL 5 does not provide php (#717158)
|
||||
%if 0%{?rhel} == 5
|
||||
Requires: mod_php >= 4.3
|
||||
Requires: mod_php >= 4.3, php-mcrypt
|
||||
%else
|
||||
Requires: php >= 4.3, php-openssl
|
||||
%endif
|
||||
|
|
@ -373,6 +391,8 @@ PHP projects, using the MAPI functions like a normal MAPI program.
|
|||
%package -n python-MAPI
|
||||
Summary: The Python MAPI extension by Zarafa
|
||||
Group: Development/Languages
|
||||
Provides: python-mapi = %{version}-%{release}
|
||||
Provides: python-mapi%{?_isa} = %{version}-%{release}
|
||||
|
||||
%description -n python-MAPI
|
||||
The python-MAPI package contains the Python MAPI extension to provide the
|
||||
|
|
@ -391,6 +411,25 @@ touch -c -r aclocal.m4.rpath aclocal.m4
|
|||
%patch3 -p1 -b .ssl_protocols_ciphers
|
||||
%patch4 -p1 -b .ssl_ecdhe
|
||||
%patch5 -p1 -b .disable_plaintext_auth-localhost
|
||||
%patch6 -p1 -b .imap-badcharset
|
||||
%patch7 -p1 -b .imap-fetch-body
|
||||
%patch8 -p1 -b .vacation-headers
|
||||
%patch9 -p1 -b .vacation-headers2
|
||||
%patch10 -p1 -b .webaccess-fail2ban
|
||||
%patch11 -p1 -b .webaccess-mcrypt
|
||||
%patch12 -p1 -b .gsoap-sslv3
|
||||
%patch14 -p1 -b .upgrade-lock
|
||||
%patch15 -p1 -b .gcc5
|
||||
touch -c -r autoconf/boost.m4.gcc5 autoconf/boost.m4
|
||||
%patch16 -p1 -b .webaccess-xss
|
||||
%patch17 -p1 -b .webaccess-defaultfont
|
||||
rm -f php-webclient-ajax/{.,*,*/*,*/*/*/*}/*.webaccess-*
|
||||
%patch18 -p1 -b .ssl_dhe
|
||||
%patch19 -p1 -b .spooler-expand_groups
|
||||
%patch20 -p1 -b .libical3
|
||||
%patch21 -p1 -b .ical-remote-dos
|
||||
%patch22 -p1 -b .ical-remote-dos2
|
||||
%patch23 -p1 -b .pam_acct_mgmt
|
||||
|
||||
%build
|
||||
%if 0%{?rhel}%{?fedora} < 6
|
||||
|
|
@ -473,6 +512,10 @@ done
|
|||
|
||||
# Move the logrotate configuration file to its correct place
|
||||
install -p -m 644 %{SOURCE2} $RPM_BUILD_ROOT%{_sysconfdir}/logrotate.d/%{name}
|
||||
%if 0%{?fedora} >= 16 || 0%{?rhel} >= 7
|
||||
sed -e 's/}/\tsu root root\n}/' -i $RPM_BUILD_ROOT%{_sysconfdir}/logrotate.d/%{name}
|
||||
touch -c -r %{SOURCE2} $RPM_BUILD_ROOT%{_sysconfdir}/logrotate.d/%{name}
|
||||
%endif
|
||||
|
||||
# Move the userscripts to their correct place and symlink them
|
||||
mkdir -p $RPM_BUILD_ROOT%{_datadir}/%{name}/userscripts/
|
||||
|
|
@ -534,7 +577,7 @@ mkdir -p $RPM_BUILD_ROOT%{_datadir}/%{name}-webaccess/plugins/
|
|||
|
||||
# Remove unwanted language connectors and webaccess files
|
||||
rm -f $RPM_BUILD_ROOT%{_datadir}/%{name}-webaccess/client/widgets/fckeditor/editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.{cfm,pl}
|
||||
rm -f $RPM_BUILD_ROOT%{_datadir}/%{name}-webaccess/{.htaccess,%{name}-webaccess.conf,senddocument.php}
|
||||
rm -f $RPM_BUILD_ROOT%{_datadir}/%{name}-webaccess/{.htaccess,%{name}-webaccess.conf}
|
||||
|
||||
# Remove flash-based multi-attachment upload (missing source)
|
||||
%if %{no_multiupload}
|
||||
|
|
@ -725,7 +768,8 @@ fi
|
|||
|
||||
%files common
|
||||
%defattr(-,root,root,-)
|
||||
%doc installer/licenseagreement/AGPL-3
|
||||
%{!?_licensedir:%global license %%doc}
|
||||
%license installer/licenseagreement/AGPL-3
|
||||
%dir %{_sysconfdir}/%{name}/
|
||||
%config(noreplace) %{_sysconfdir}/logrotate.d/%{name}
|
||||
%config(noreplace) %{_sysconfdir}/sysconfig/%{name}
|
||||
|
|
@ -762,8 +806,6 @@ fi
|
|||
%{_libdir}/libicalmapi.so
|
||||
%{_libdir}/libinetmapi.so
|
||||
%{_libdir}/libmapi.so
|
||||
%{_libdir}/libmapicalendar.so
|
||||
%{_libdir}/libmapitimezone.so
|
||||
%{_libdir}/libcommon_mapi.a
|
||||
%{_libdir}/libcommon_service.a
|
||||
%{_libdir}/libcommon_ssl.a
|
||||
|
|
@ -772,10 +814,8 @@ fi
|
|||
%{_libdir}/libzarafasync.so
|
||||
%{_includedir}/icalmapi/
|
||||
%{_includedir}/inetmapi/
|
||||
%{_includedir}/mapitimezone/
|
||||
%{_includedir}/mapi4linux/
|
||||
%{_includedir}/libfreebusy/
|
||||
%{_includedir}/libmapicalendar/
|
||||
%{_includedir}/libzarafasync/
|
||||
%{_includedir}/%{name}/
|
||||
%{_libdir}/pkgconfig/%{name}.pc
|
||||
|
|
@ -920,12 +960,11 @@ fi
|
|||
%{_libdir}/libicalmapi.so.*
|
||||
%{_libdir}/libinetmapi.so.*
|
||||
%{_libdir}/libmapi.so.*
|
||||
%{_libdir}/libmapicalendar.so.*
|
||||
%{_libdir}/libmapitimezone.so.*
|
||||
|
||||
%files -n php-mapi
|
||||
%defattr(-,root,root,-)
|
||||
%config(noreplace) %{_sysconfdir}/php.d/%{ini_name}
|
||||
%config(noreplace) %{_sysconfdir}/%{name}/php-mapi.cfg
|
||||
%{_datadir}/php/mapi/
|
||||
%{_libdir}/php/modules/mapi.so
|
||||
|
||||
|
|
@ -934,6 +973,44 @@ fi
|
|||
%{python_sitearch}/*
|
||||
|
||||
%changelog
|
||||
* Sun Apr 30 2023 Robert Scheck <robert@fedoraproject.org> 7.1.14-6
|
||||
- Backported patch from Debian to fix CVE-2022-26562 (#2192126)
|
||||
|
||||
* Sun Apr 25 2021 Robert Scheck <robert@fedoraproject.org> 7.1.14-5
|
||||
- Added upstream patch to fix remote DoS in zarafa-ical (#1953242)
|
||||
|
||||
* Thu Mar 25 2021 Robert Scheck <robert@fedoraproject.org> 7.1.14-4
|
||||
- Added patch to allow building against libical 3.0.x
|
||||
- Added upstream patch to fix remote DoS in zarafa-ical (#1942773)
|
||||
|
||||
* Mon Nov 28 2016 Robert Scheck <robert@fedoraproject.org> 7.1.14-3
|
||||
- Added upstream patch to fix broken group expansion (ZCP-12148)
|
||||
|
||||
* Wed Dec 23 2015 Robert Scheck <robert@fedoraproject.org> 7.1.14-2
|
||||
- Rebuild for libical soname bump (#1288284)
|
||||
|
||||
* Tue Nov 10 2015 Robert Scheck <robert@fedoraproject.org> 7.1.14-1
|
||||
- Upgrade to 7.1.14 (#1263006)
|
||||
|
||||
* Wed Aug 05 2015 Robert Scheck <robert@fedoraproject.org> 7.1.13-1
|
||||
- Upgrade to 7.1.13
|
||||
- Added patch to fix a possible XSS situation in WebAccess
|
||||
- Added patch to avoid non-working default font in WebAccess
|
||||
- Added patch to implement DHE/EDH support (aside of ECDHE)
|
||||
|
||||
* Wed Jul 01 2015 Robert Scheck <robert@fedoraproject.org> 7.1.12-3
|
||||
- Added patch to build using GCC 5.x
|
||||
|
||||
* Mon May 18 2015 Robert Scheck <robert@fedoraproject.org> 7.1.12-2
|
||||
- Upgrade to 7.1.12 (re-released)
|
||||
- Backported patch from Zarafa 7.2 to fix CVE-2015-3436 (#1222151)
|
||||
|
||||
* Tue Apr 07 2015 Robert Scheck <robert@fedoraproject.org> 7.1.12-1
|
||||
- Upgrade to 7.1.12
|
||||
- Added multiple minor enhancement and bugfix patches
|
||||
- Added patch to fix CVE-2014-0103 for PHP < 5.3 (#1073618)
|
||||
- Handle "su" option in logrotate >= 3.8.0 to avoid errors
|
||||
|
||||
* Sat Oct 25 2014 Kevin Kofler <Kevin@tigcc.ticalc.org> 7.1.11-2
|
||||
- Rebuild for reference-counting-enabled clucene09
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue