Compare commits
66 commits
| Author | SHA1 | Date | |
|---|---|---|---|
| cbefa778aa | |||
| e225a36f01 | |||
| a56a8a43af | |||
| 6244133f60 | |||
| 4e07fdc3d5 | |||
| 10fc4283ed | |||
| 8735de08ac | |||
| 55f9cedbfc | |||
| c1293fe8f4 | |||
| f800d1c727 | |||
| 330b839bc0 | |||
| 17841d83c9 | |||
| c7ecef187e | |||
| 384c0c36e1 | |||
| 423e99d9b3 | |||
| 860fae1250 | |||
| ce0e01723f | |||
|
|
7e34c68abe | ||
| e45d09e2f6 | |||
| 09deb48f90 | |||
| 6c5927e0bb | |||
| 6485eb28e2 | |||
| 61af5881ff | |||
| 1b451fb6f4 | |||
| 4a32efa8ec | |||
| 2e23aecced | |||
| 2d9933259b | |||
| 9ce8cccb85 | |||
| b4883e8a2e | |||
| 14138b8550 | |||
| ed3da28ff4 | |||
| fbb3b95baf | |||
| e5dd60cfe2 | |||
| a92bdbec8c | |||
| 7a506e7ba2 | |||
| 76acd81c5f | |||
| 1581907833 | |||
| 38d6b76bcd | |||
| 02e1ad31b4 | |||
| 8bdb536827 | |||
| 630eb4f7fc | |||
| 2a88c6f82c | |||
| b7bb67eda6 | |||
| 21938df2ad | |||
| 400e3e49e0 | |||
| 8fad6da11c | |||
| 3bd957acf4 | |||
| 30174be4c1 | |||
| 3ce2c93650 | |||
| 57a2484789 | |||
| a8555d2635 | |||
| 3943a3bf54 | |||
| c159617c9f | |||
| f08aa15e82 | |||
| e501e8a061 | |||
| 313443d044 | |||
|
|
5962fec96d | ||
| a8e3bdc46e | |||
| 6b6e7ac724 | |||
|
|
ed8b9ffbb5 | ||
| 66ffd74995 | |||
| aea372d81c | |||
| e00d77bd88 | |||
| c5242c3fa3 | |||
| 51e3570083 | |||
| bdc317a1a4 |
26 changed files with 4839 additions and 1 deletions
1
.gitignore
vendored
Normal file
1
.gitignore
vendored
Normal file
|
|
@ -0,0 +1 @@
|
|||
zcp-7.?.*.tar.gz
|
||||
|
|
@ -1 +0,0 @@
|
|||
Package is retired
|
||||
1
sources
Normal file
1
sources
Normal file
|
|
@ -0,0 +1 @@
|
|||
ded12c2363c7205889b8c68519140a4b zcp-7.1.14.tar.gz
|
||||
19
zarafa-7.1.10-imap-badcharset.patch
Normal file
19
zarafa-7.1.10-imap-badcharset.patch
Normal file
|
|
@ -0,0 +1,19 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa <= 7.1.10 which fixes the RFC-
|
||||
violating reply of the Zarafa IMAP gateway in response to a failed SEARCH CHARSET request.
|
||||
This is documented at http://tools.ietf.org/html/rfc3501#page-64: "BADCHARSET: Optionally
|
||||
followed by a parenthesized list of charsets. [...]". This patch adds missing parenthesis.
|
||||
|
||||
Proposed to upstream via e-mail on Sun, 27 Jul 2014 23:58:01 +0200, patch was put into the
|
||||
upstream ticket https://jira.zarafa.com/browse/ZCP-12504.
|
||||
|
||||
--- zarafa-7.1.10/gateway/IMAP.cpp 2014-05-23 15:56:37.000000000 +0200
|
||||
+++ zarafa-7.1.10/gateway/IMAP.cpp.imap-badcharset 2014-07-27 23:42:30.000000000 +0200
|
||||
@@ -2409,7 +2409,7 @@
|
||||
if (lstSearchCriteria[1] != "WINDOWS-1252") {
|
||||
iconv = new ECIConv("windows-1252", lstSearchCriteria[1]);
|
||||
if (!iconv->canConvert()) {
|
||||
- hr2 = HrResponse(RESP_TAGGED_NO, strTag, "[BADCHARSET WINDOWS-1252] "+strMode+"SEARCH charset not supported");
|
||||
+ hr2 = HrResponse(RESP_TAGGED_NO, strTag, "[BADCHARSET (WINDOWS-1252)] "+strMode+"SEARCH charset not supported");
|
||||
hr = MAPI_E_CALL_FAILED;
|
||||
goto exit;
|
||||
}
|
||||
93
zarafa-7.1.10-imap-fetch-body.patch
Normal file
93
zarafa-7.1.10-imap-fetch-body.patch
Normal file
|
|
@ -0,0 +1,93 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa <= 7.1.10 which fixes the RFC-
|
||||
violating reply of the Zarafa IMAP gateway in response to a body fetch request. This is
|
||||
documented at http://tools.ietf.org/html/rfc3501#page-55. Additionally this has been also
|
||||
compared with the Dovecot IMAP server as a nearly (or even de facto) IMAP server reference
|
||||
implementation. Please note that this is NOT a duplicate of ZCP-11590/ZCP-11739/ZCP-12365!
|
||||
|
||||
Wrong behaviour of Zarafa <= 7.1.10rc1-44973 (without this patch):
|
||||
> A4 FETCH 1 (BODY.PEEK[HEADER.FIELDS (FROM FROM)])
|
||||
< * 1 FETCH (BODY[HEADER.FIELDS (FROM FROM)] {66}
|
||||
From: User1 <user1@domain.org>
|
||||
From: User1 <user1@domain.org>
|
||||
|
||||
)
|
||||
< A4 OK FETCH completed
|
||||
|
||||
Comparison with IMAP server Dovecot 2.2.13:
|
||||
> A4 FETCH 1 (BODY.PEEK[HEADER.FIELDS (FROM FROM)])
|
||||
< * 1 FETCH (BODY[HEADER.FIELDS (FROM FROM)] {34}
|
||||
From: User1 <user1@domain.org>
|
||||
|
||||
)
|
||||
< A4 OK Fetch completed.
|
||||
|
||||
Correct behaviour of Zarafa (after having this patch applied):
|
||||
> A4 FETCH 1 (BODY.PEEK[HEADER.FIELDS (FROM FROM)])
|
||||
< * 1 FETCH (BODY[HEADER.FIELDS (FROM FROM)] {34}
|
||||
From: User1 <user1@domain.org>
|
||||
|
||||
)
|
||||
< A4 OK FETCH completed
|
||||
|
||||
Testing: Full IMAP dialog example from the client perspective (after this patch applied):
|
||||
< * OK [CAPABILITY IMAP4rev1 LITERAL+ AUTH=PLAIN] Zarafa IMAP gateway ready
|
||||
> A0 LOGIN robert robert
|
||||
< A0 OK [CAPABILITY IMAP4rev1 LITERAL+ CHILDREN XAOL-OPTION NAMESPACE QUOTA IDLE] LOGIN completed
|
||||
> A1 LIST "" INBOX
|
||||
< * LIST (\HasNoChildren) "/" "INBOX"
|
||||
< A1 OK LIST completed
|
||||
> A2 SELECT INBOX
|
||||
< * 2 EXISTS
|
||||
< * 0 RECENT
|
||||
< * FLAGS (\Seen \Draft \Deleted \Flagged \Answered $Forwarded)
|
||||
< * OK [PERMANENTFLAGS (\Seen \Draft \Deleted \Flagged \Answered $Forwarded)] Permanent flags
|
||||
< * OK [UIDNEXT 4343] Predicted next UID
|
||||
< * OK [UNSEEN 1] First unseen message
|
||||
< * OK [UIDVALIDITY 9313] UIDVALIDITY value
|
||||
< A2 OK [READ-WRITE] SELECT completed
|
||||
> A3 SEARCH UNSEEN ALL
|
||||
< * SEARCH 1 2
|
||||
< A3 OK SEARCH completed
|
||||
> A4 FETCH 1 (BODY.PEEK[HEADER.FIELDS (FROM FROM)])
|
||||
< * 1 FETCH (BODY[HEADER.FIELDS (FROM FROM)] {34}
|
||||
From: User1 <user1@domain.org>
|
||||
|
||||
)
|
||||
< A4 OK FETCH completed
|
||||
> A5 CLOSE
|
||||
< A5 OK CLOSE completed
|
||||
> A6 LOGOUT
|
||||
< * BYE Zarafa server logging out
|
||||
< A6 OK LOGOUT completed
|
||||
|
||||
IMPORTANT: This patch has been very carefully and extensively tested but it might not be
|
||||
perfect nevertheless as I am not really a C/C++ developer. There should be a code review
|
||||
by an experienced C/C++ developer before merging into Zarafa core.
|
||||
|
||||
Proposed to upstream via e-mail on Thu, 29 May 2014 01:55:35 +0200, patch was put into the
|
||||
upstream ticket https://jira.zarafa.com/browse/ZCP-12398.
|
||||
|
||||
--- zarafa-7.1.10/gateway/IMAP.cpp 2014-05-12 12:06:03.000000000 +0200
|
||||
+++ zarafa-7.1.10/gateway/IMAP.cpp.imap-fetch-body 2014-05-29 00:49:29.000000000 +0200
|
||||
@@ -5253,10 +5253,21 @@
|
||||
} else {
|
||||
vector<string> lstReqFields;
|
||||
vector<string>::iterator iterReqField;
|
||||
+ vector<string>::iterator r, w;
|
||||
+ set<string> tmpset;
|
||||
|
||||
// Get fields as vector
|
||||
lstReqFields = tokenize(strFields, " ");
|
||||
|
||||
+ // Make elements of vector unique
|
||||
+ for(r = lstReqFields.begin(), w = lstReqFields.begin(); r != lstReqFields.end(); ++r) {
|
||||
+ if(tmpset.insert(*r).second) {
|
||||
+ *w++ = *r;
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ lstReqFields.erase(w, lstReqFields.end());
|
||||
+
|
||||
// Output headers specified, in order of field set
|
||||
for(iterReqField = lstReqFields.begin(); iterReqField != lstReqFields.end(); iterReqField++) {
|
||||
for(iterField = lstFields.begin(); iterField != lstFields.end(); iterField++) {
|
||||
31
zarafa-7.1.10-kyotocabinet.patch
Normal file
31
zarafa-7.1.10-kyotocabinet.patch
Normal file
|
|
@ -0,0 +1,31 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for zarafa >= 7.1.10 which re-adds the ability to disable
|
||||
zarafa-search during build-time. This is e.g. required if CLucene and/or Kyotocabinet is unavailable or
|
||||
broken on the given system and/or architecture. Interestingly that patch is not new, I wrote these lines
|
||||
in 2012 the first time, proposed them as a patch to Zarafa and got merged. With a recent Zarafa release it
|
||||
seems they silently removed it again...
|
||||
|
||||
Proposed to upstream via e-mail on Fri, 11 Jul 2014 01:03:43 +0200, patch was put into the upstream ticket
|
||||
https://jira.zarafa.com/browse/ZCP-12463.
|
||||
|
||||
--- zarafa-7.1.10/ECtools/zarafa-search/Makefile.am 2014-05-23 15:03:49.000000000 +0200
|
||||
+++ zarafa-7.1.10/ECtools/zarafa-search/Makefile.am.kyotocabinet 2014-07-10 21:48:42.000000000 +0200
|
||||
@@ -1,4 +1,8 @@
|
||||
+if WITH_CLUCENE
|
||||
+if WITH_KYOTOCABINET
|
||||
bin_PROGRAMS = zarafa-search
|
||||
+endif
|
||||
+endif
|
||||
|
||||
AM_CPPFLAGS = ${ZCPPFLAGS} \
|
||||
-I${top_srcdir}/mapi4linux/include \
|
||||
--- zarafa-7.1.10/ECtools/zarafa-search/Makefile.in 2014-05-23 15:04:02.000000000 +0200
|
||||
+++ zarafa-7.1.10/ECtools/zarafa-search/Makefile.in.kyotocabinet 2014-07-10 21:49:16.000000000 +0200
|
||||
@@ -34,7 +34,7 @@
|
||||
POST_UNINSTALL = :
|
||||
build_triplet = @build@
|
||||
host_triplet = @host@
|
||||
-bin_PROGRAMS = zarafa-search$(EXEEXT)
|
||||
+@WITH_CLUCENE_TRUE@@WITH_KYOTOCABINET_TRUE@bin_PROGRAMS = zarafa-search$(EXEEXT)
|
||||
subdir = ECtools/zarafa-search
|
||||
DIST_COMMON = $(srcdir)/Makefile.am $(srcdir)/Makefile.in
|
||||
ACLOCAL_M4 = $(top_srcdir)/aclocal.m4
|
||||
39
zarafa-7.1.11-php-unbundle.patch
Normal file
39
zarafa-7.1.11-php-unbundle.patch
Normal file
|
|
@ -0,0 +1,39 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for zarafa >= 7.1.11 which removes the bundled PHP PEAR files/libraries
|
||||
and replaces them by files and libraries shipped by the distribution. From file server/PEAR/JSON.php only the function
|
||||
json_decode() is used, which can be provided by the php-json RPM package. The file server/PEAR/XML/Unserializer.php can
|
||||
be provided by the php-pear-XML-Serializer RPM package. The rest of the PHP PEAR files/libraries are only dependencies of
|
||||
these two files mentioned before (which are satisfied by the two newly required RPM packages).
|
||||
|
||||
--- zarafa-7.1.11.rsc/php-webclient-ajax/config.php.dist 2014-09-03 09:56:49.000000000 +0200
|
||||
+++ zarafa-7.1.11.rsc/php-webclient-ajax/config.php.dist.php-unbundle 2014-09-07 18:24:28.000000000 +0200
|
||||
@@ -56,7 +56,7 @@
|
||||
|
||||
// Define the server paths
|
||||
set_include_path(BASE_PATH. PATH_SEPARATOR .
|
||||
- BASE_PATH."server/PEAR/" . PATH_SEPARATOR .
|
||||
+ "/usr/share/pear/" . PATH_SEPARATOR .
|
||||
"/usr/share/php/");
|
||||
|
||||
// Define the relative URL for dialogs, this string is appended with HTTP GET arguments
|
||||
--- zarafa-7.1.11.rsc/php-webclient-ajax/zarafa.php 2014-09-03 10:45:06.000000000 +0200
|
||||
+++ zarafa-7.1.11.rsc/php-webclient-ajax/zarafa.php.php-unbundle 2014-09-07 18:21:36.000000000 +0200
|
||||
@@ -59,7 +59,7 @@
|
||||
include("config.php");
|
||||
include("defaults.php");
|
||||
include("server/util.php");
|
||||
- require("server/PEAR/JSON.php");
|
||||
+ @include("server/PEAR/JSON.php");
|
||||
|
||||
require("mapi/mapi.util.php");
|
||||
require("mapi/mapicode.php");
|
||||
--- zarafa-7.1.11.rsc/php-webclient-ajax/server/core/class.xmlparser.php 2014-09-03 10:45:06.000000000 +0200
|
||||
+++ zarafa-7.1.11.rsc/php-webclient-ajax/server/core/class.xmlparser.php.php-unbundle 2014-09-07 18:22:40.000000000 +0200
|
||||
@@ -50,7 +50,7 @@
|
||||
|
||||
?>
|
||||
<?php
|
||||
- require_once("server/PEAR/XML/Unserializer.php");
|
||||
+ require_once("XML/Unserializer.php");
|
||||
|
||||
/**
|
||||
* XML Parser
|
||||
91
zarafa-7.1.11-plaintext_auth_localhost.patch
Normal file
91
zarafa-7.1.11-plaintext_auth_localhost.patch
Normal file
|
|
@ -0,0 +1,91 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa <= 7.1.11 which enhances my earlier
|
||||
this year implemented "disable_plaintext_auth" feature (new option in Zarafa >= 7.1.10 to disable
|
||||
all plaintext authentications unless SSL/TLS is used), https://jira.zarafa.com/browse/ZCP-12142
|
||||
contains the initial implementation and a more verbose feature description.
|
||||
|
||||
Given that there are unfortunately still Zarafa systems around using saslauthd without pam_mapi
|
||||
but rimap instead the "disable_plaintext_auth" feature prevents them from enabling this option as
|
||||
rimap doesn't support SSL/TLS; https://jira.zarafa.com/browse/ZCP-12473 contains an example report
|
||||
by a Zarafa customer. Thus this patch adds an exception if the source IPv4 address is "127.0.0.1"
|
||||
and allows even if "disable_plaintext_auth" is enabled a cleartext authentication. It was a design
|
||||
decision to check only for 127.0.0.1/32 rather 127.0.0.0/8 because there seem to be systems where
|
||||
the loopback network except 127.0.0.1/32 is routable?!
|
||||
|
||||
Important: The technical implementation of this patch might be not perfect as I am not really a C/
|
||||
C++ developer. There should be a code review by an experienced C/C++ developer before merging into
|
||||
Zarafa core.
|
||||
|
||||
Proposed to upstream via e-mail on Thu, 16 Oct 2014 00:00:05 +0200, patch was put into the upstream
|
||||
ticket https://jira.zarafa.com/browse/ZCP-12473.
|
||||
|
||||
--- zarafa-7.1.11/gateway/IMAP.cpp 2014-09-03 10:45:06.000000000 +0200
|
||||
+++ zarafa-7.1.11/gateway/IMAP.cpp.plaintext_auth_localhost 2014-09-24 01:29:10.000000000 +0200
|
||||
@@ -757,7 +757,7 @@
|
||||
if (!lpChannel->UsingSsl() && lpChannel->sslctx())
|
||||
strCapabilities += " STARTTLS";
|
||||
|
||||
- if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0)
|
||||
+ if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0)
|
||||
strCapabilities += " LOGINDISABLED";
|
||||
else
|
||||
strCapabilities += " AUTH=PLAIN";
|
||||
@@ -923,7 +923,7 @@
|
||||
char *plain = lpConfig->GetSetting("disable_plaintext_auth");
|
||||
|
||||
// If plaintext authentication was disabled any authentication attempt must be refused very soon
|
||||
- if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0) {
|
||||
+ if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0) {
|
||||
hr2 = HrResponse(RESP_TAGGED_NO, strTag, "[PRIVACYREQUIRED] Plaintext authentication disallowed on non-secure "
|
||||
"(SSL/TLS) connections.");
|
||||
if (hr2 != hrSuccess)
|
||||
@@ -1002,7 +1002,7 @@
|
||||
}
|
||||
|
||||
// If plaintext authentication was disabled any login attempt must be refused very soon
|
||||
- if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0) {
|
||||
+ if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0) {
|
||||
hr2 = HrResponse(RESP_UNTAGGED, "BAD [ALERT] Plaintext authentication not allowed without SSL/TLS, but your client "
|
||||
"did it anyway. If anyone was listening, the password was exposed.");
|
||||
if (hr2 != hrSuccess)
|
||||
--- zarafa-7.1.11/gateway/POP3.cpp 2014-09-03 10:45:06.000000000 +0200
|
||||
+++ zarafa-7.1.11/gateway/POP3.cpp.plaintext_auth_localhost 2014-09-24 01:30:41.000000000 +0200
|
||||
@@ -320,7 +320,7 @@
|
||||
if (!lpChannel->UsingSsl() && lpChannel->sslctx())
|
||||
strCapabilities += "STLS\r\n";
|
||||
|
||||
- if (!(!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0))
|
||||
+ if (!(!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0))
|
||||
strCapabilities += "USER\r\n";
|
||||
}
|
||||
|
||||
@@ -402,7 +402,7 @@
|
||||
HRESULT hr = hrSuccess;
|
||||
char *plain = lpConfig->GetSetting("disable_plaintext_auth");
|
||||
|
||||
- if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0) {
|
||||
+ if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0) {
|
||||
hr = HrResponse(POP3_RESP_AUTH_ERROR, "Plaintext authentication disallowed on non-secure (SSL/TLS) connections");
|
||||
lpLogger->Log(EC_LOGLEVEL_ERROR, "Aborted login from %s with username \"%s\" (tried to use disallowed plaintext auth)",
|
||||
lpChannel->GetIPAddress().c_str(), strUser.c_str());
|
||||
@@ -431,7 +431,7 @@
|
||||
HRESULT hr = hrSuccess;
|
||||
char *plain = lpConfig->GetSetting("disable_plaintext_auth");
|
||||
|
||||
- if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0) {
|
||||
+ if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0) {
|
||||
hr = HrResponse(POP3_RESP_AUTH_ERROR, "Plaintext authentication disallowed on non-secure (SSL/TLS) connections");
|
||||
if(szUser.empty())
|
||||
lpLogger->Log(EC_LOGLEVEL_ERROR, "Aborted login from %s without username (tried to use disallowed "
|
||||
--- zarafa-7.1.11/doc/manual.xml 2014-09-03 09:56:28.000000000 +0200
|
||||
+++ zarafa-7.1.11/doc/manual.xml.plaintext_auth_localhost 2014-10-15 01:22:14.000000000 +0200
|
||||
@@ -8024,7 +8024,9 @@
|
||||
<term><option>disable_plaintext_auth</option></term>
|
||||
<listitem>
|
||||
<para>Disable all plaintext POP3 and IMAP authentications unless
|
||||
- SSL/TLS is used. Obviously this requires at least
|
||||
+ SSL/TLS is used (except for connections originating from
|
||||
+ <replaceable>127.0.0.1</replaceable> to allow saslauthd with rimap).
|
||||
+ Obviously enabling this configuration option requires at least
|
||||
<replaceable>ssl_private_key_file</replaceable> and
|
||||
<replaceable>ssl_certificate_file</replaceable> to take effect.</para>
|
||||
<para>Default: <replaceable>no</replaceable></para>
|
||||
85
zarafa-7.1.11-rpath.patch
Normal file
85
zarafa-7.1.11-rpath.patch
Normal file
|
|
@ -0,0 +1,85 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for zarafa >= 7.1.11, which works
|
||||
around the broken libtool of Debian. Multilib/multiarch systems like Fedora or Red
|
||||
Hat Enterprise Linux are using /usr/lib64 for 64 bit libraries and /usr/lib is used
|
||||
for 32 bit libraries. That allows to run 32 bit software on 64 bit systems. Debian
|
||||
systems only use /usr/lib which contains only 32 or 64 bit systems depending on the
|
||||
architecture.
|
||||
|
||||
Libtool hardcodes the runtime search path in a library (rpath), if the library that
|
||||
is used for linking is not within the default system library path. The result is,
|
||||
that if aclocal.m4/configure files are generated by a Debian system, but used on a
|
||||
Fedora or Red Hat Enterprise Linux 64 bit system for compiling, "-rpath /usr/lib64"
|
||||
makes it into the binary.
|
||||
|
||||
Fedora and EPEL (for Red Hat Enterprise Linux) do not allow binaries with rpath, as
|
||||
the Linux dynamic linker is usually smarter than the hardcoded path.
|
||||
|
||||
The fix for this issue is to add the optional /lib64 and /usr/lib64 directories at/
|
||||
within libtool in front of the regular /lib and /usr/lib directories at the system
|
||||
library path. These libtool information are hold in aclocal.m4, which is generated
|
||||
by running aclocal. As the content of aclocal.m4 is included into configure during
|
||||
a run of autoconf, aclocal.m4 needs to be modified within the upstream build system
|
||||
each time after a aclocal run - until Debian's libtool is fixed at Debian upstream.
|
||||
|
||||
Applying the fix is either possible by using the first hunk of the patch (second
|
||||
hunk is runtime-only if configure file has been already generated) or by running
|
||||
the following sed command after each aclocal run within the upstream build system:
|
||||
|
||||
sed -e 's@\(# Append ld.so.conf contents to the search path\)@# Add ABI-specific directories to the system library path.\n sys_lib_dlsearch_path_spec="/lib64 /usr/lib64 /lib /usr/lib"\n\n \1@' \
|
||||
-e 's@/lib /usr/lib $lt_ld_extra@$sys_lib_dlsearch_path_spec $lt_ld_extra@' -i zarafa-7.1.11/aclocal.m4
|
||||
|
||||
More information regarding this topic can be found for example at:
|
||||
|
||||
- http://osdir.com/ml/bug-libtool-gnu/2009-12/msg00034.html
|
||||
- http://lists.gnu.org/archive/html/libtool/2009-01/msg00039.html
|
||||
- http://thread.gmane.org/gmane.comp.gnu.libtool.general/8339/focus=8345
|
||||
|
||||
--- zarafa-7.1.11/aclocal.m4 2014-09-03 09:56:52.000000000 +0200
|
||||
+++ zarafa-7.1.11/aclocal.m4.rpath 2014-09-07 17:20:37.000000000 +0200
|
||||
@@ -2672,10 +2672,13 @@
|
||||
# before this can be enabled.
|
||||
hardcode_into_libs=yes
|
||||
|
||||
+ # Add ABI-specific directories to the system library path.
|
||||
+ sys_lib_dlsearch_path_spec="/lib64 /usr/lib64 /lib /usr/lib"
|
||||
+
|
||||
# Append ld.so.conf contents to the search path
|
||||
if test -f /etc/ld.so.conf; then
|
||||
lt_ld_extra=`awk '/^include / { system(sprintf("cd /etc; cat %s 2>/dev/null", \[$]2)); skip = 1; } { if (!skip) print \[$]0; skip = 0; }' < /etc/ld.so.conf | $SED -e 's/#.*//;/^[ ]*hwcap[ ]/d;s/[:, ]/ /g;s/=[^=]*$//;s/=[^= ]* / /g;s/"//g;/^$/d' | tr '\n' ' '`
|
||||
- sys_lib_dlsearch_path_spec="/lib /usr/lib $lt_ld_extra"
|
||||
+ sys_lib_dlsearch_path_spec="$sys_lib_dlsearch_path_spec $lt_ld_extra"
|
||||
fi
|
||||
|
||||
# We used to test for /lib/ld.so.1 and disable shared libraries on
|
||||
--- zarafa-7.1.11/configure 2014-09-03 09:56:53.000000000 +0200
|
||||
+++ zarafa-7.1.11/configure.rpath 2014-09-07 17:28:07.000000000 +0200
|
||||
@@ -10983,10 +10983,13 @@
|
||||
# before this can be enabled.
|
||||
hardcode_into_libs=yes
|
||||
|
||||
+ # Add ABI-specific directories to the system library path.
|
||||
+ sys_lib_dlsearch_path_spec="/lib64 /usr/lib64 /lib /usr/lib"
|
||||
+
|
||||
# Append ld.so.conf contents to the search path
|
||||
if test -f /etc/ld.so.conf; then
|
||||
lt_ld_extra=`awk '/^include / { system(sprintf("cd /etc; cat %s 2>/dev/null", \$2)); skip = 1; } { if (!skip) print \$0; skip = 0; }' < /etc/ld.so.conf | $SED -e 's/#.*//;/^[ ]*hwcap[ ]/d;s/[:, ]/ /g;s/=[^=]*$//;s/=[^= ]* / /g;s/"//g;/^$/d' | tr '\n' ' '`
|
||||
- sys_lib_dlsearch_path_spec="/lib /usr/lib $lt_ld_extra"
|
||||
+ sys_lib_dlsearch_path_spec="$sys_lib_dlsearch_path_spec $lt_ld_extra"
|
||||
fi
|
||||
|
||||
# We used to test for /lib/ld.so.1 and disable shared libraries on
|
||||
@@ -16025,10 +16028,13 @@
|
||||
# before this can be enabled.
|
||||
hardcode_into_libs=yes
|
||||
|
||||
+ # Add ABI-specific directories to the system library path.
|
||||
+ sys_lib_dlsearch_path_spec="/lib64 /usr/lib64 /lib /usr/lib"
|
||||
+
|
||||
# Append ld.so.conf contents to the search path
|
||||
if test -f /etc/ld.so.conf; then
|
||||
lt_ld_extra=`awk '/^include / { system(sprintf("cd /etc; cat %s 2>/dev/null", \$2)); skip = 1; } { if (!skip) print \$0; skip = 0; }' < /etc/ld.so.conf | $SED -e 's/#.*//;/^[ ]*hwcap[ ]/d;s/[:, ]/ /g;s/=[^=]*$//;s/=[^= ]* / /g;s/"//g;/^$/d' | tr '\n' ' '`
|
||||
- sys_lib_dlsearch_path_spec="/lib /usr/lib $lt_ld_extra"
|
||||
+ sys_lib_dlsearch_path_spec="$sys_lib_dlsearch_path_spec $lt_ld_extra"
|
||||
fi
|
||||
|
||||
# We used to test for /lib/ld.so.1 and disable shared libraries on
|
||||
32
zarafa-7.1.11-vacation-headers.patch
Normal file
32
zarafa-7.1.11-vacation-headers.patch
Normal file
|
|
@ -0,0 +1,32 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa >= 7.1.11 which restricts replies by
|
||||
zarafa-autorespond to automated processes and mailing lists according to RFC 5230, section 4.6. For
|
||||
further details please have a look to http://tools.ietf.org/html/rfc5230#page-8 as well.
|
||||
|
||||
Proposed to upstream via e-mail on Wed, 27 Aug 2014 23:30:31 +0200, patch was put into the upstream
|
||||
ticket https://jira.zarafa.com/browse/ZCP-12590.
|
||||
|
||||
--- zarafa-7.1.11/spooler/DAgent.cpp 2014-08-24 12:27:06.000000000 +0200
|
||||
+++ zarafa-7.1.11/spooler/DAgent.cpp.vacation-headers 2014-08-27 23:20:18.000000000 +0200
|
||||
@@ -1422,11 +1422,19 @@
|
||||
|
||||
// See if we're looping
|
||||
if (lpMessageProps[0].ulPropTag == PR_TRANSPORT_MESSAGE_HEADERS_A) {
|
||||
- if ( (strstr(lpMessageProps[0].Value.lpszA, "X-Zarafa-Vacation:") != NULL) ||
|
||||
- (strstr(lpMessageProps[0].Value.lpszA, "Auto-Submitted:") != NULL) ||
|
||||
- (strstr(lpMessageProps[0].Value.lpszA, "Precedence:") != NULL) )
|
||||
+ if ( (strstr(lpMessageProps[0].Value.lpszA, "X-Zarafa-Vacation:") != NULL) || // Zarafa
|
||||
+ (strstr(lpMessageProps[0].Value.lpszA, "Auto-Submitted:") != NULL) || // RFC 3834
|
||||
+ (strstr(lpMessageProps[0].Value.lpszA, "List-Id:") != NULL) || // RFC 2919
|
||||
+ (strstr(lpMessageProps[0].Value.lpszA, "List-Help:") != NULL) || // RFC 2369
|
||||
+ (strstr(lpMessageProps[0].Value.lpszA, "List-Subscribe:") != NULL) || // RFC 2369
|
||||
+ (strstr(lpMessageProps[0].Value.lpszA, "List-Unsubscribe:") != NULL) || // RFC 2369
|
||||
+ (strstr(lpMessageProps[0].Value.lpszA, "List-Post:") != NULL) || // RFC 2369
|
||||
+ (strstr(lpMessageProps[0].Value.lpszA, "List-Owner:") != NULL) || // RFC 2369
|
||||
+ (strstr(lpMessageProps[0].Value.lpszA, "List-Archive:") != NULL) || // RFC 2369
|
||||
+ (strstr(lpMessageProps[0].Value.lpszA, "Precedence:") != NULL) ) // RFC 3834
|
||||
// Vacation header already present, do not send vacation reply
|
||||
// Precedence: list/bulk/junk, do not reply to these mails
|
||||
+ // See also http://tools.ietf.org/html/rfc5230#page-8 for details
|
||||
goto exit;
|
||||
// save headers to a file so they can also be tested from the script we're runing
|
||||
snprintf(szTemp, PATH_MAX, "%s/autorespond-headers.XXXXXX", getenv("TEMP") == NULL ? "/tmp" : getenv("TEMP"));
|
||||
44
zarafa-7.1.11-vacation-headers2.patch
Normal file
44
zarafa-7.1.11-vacation-headers2.patch
Normal file
|
|
@ -0,0 +1,44 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa >= 7.1.11 which adds anti-loop headers
|
||||
for automatic responses by zarafa-autorespond for Microsoft Exchange and all vacation(1) compatible
|
||||
implementations.
|
||||
|
||||
For the Microsoft Exchange related part useful links are:
|
||||
- http://msdn.microsoft.com/en-us/library/ee219609(v=exchg.80).aspx
|
||||
- https://www.jitbit.com/maxblog/18-detecting-outlook-autoreplyout-of-office-emails-and-x-auto-response-suppress-header/
|
||||
|
||||
For vacation(1) compatible implementations useful links are:
|
||||
- http://www.daemon-systems.org/man/vacation.1.html
|
||||
- Book "sendmail" (written by Bryan Costales, Claus Assmann, George Jansen, Gregory Neil Shapiro), ISBN 0596555342
|
||||
|
||||
Proposed to upstream via e-mail on Wed, 27 Aug 2014 23:59:58 +0200, patch was put into the upstream
|
||||
ticket https://jira.zarafa.com/browse/ZCP-12591.
|
||||
|
||||
--- zarafa-7.1.11/spooler/DAgent.cpp 2014-08-24 12:27:06.000000000 +0200
|
||||
+++ zarafa-7.1.11/spooler/DAgent.cpp.vacation-headers2 2014-08-27 23:52:42.000000000 +0200
|
||||
@@ -1469,12 +1469,25 @@
|
||||
if (hr != hrSuccess)
|
||||
goto exit;
|
||||
|
||||
- // add anti-loop header
|
||||
+ // add anti-loop header for Zarafa
|
||||
snprintf(szHeader, PATH_MAX, "\nX-Zarafa-Vacation: autorespond");
|
||||
hr = WriteOrLogError(fd, szHeader, strlen(szHeader));
|
||||
if (hr != hrSuccess)
|
||||
goto exit;
|
||||
|
||||
+ // add anti-loop header for Exchange, see http://msdn.microsoft.com/en-us/library/ee219609(v=exchg.80).aspx
|
||||
+ snprintf(szHeader, PATH_MAX, "\nX-Auto-Response-Suppress: All");
|
||||
+ hr = WriteOrLogError(fd, szHeader, strlen(szHeader));
|
||||
+ if (hr != hrSuccess)
|
||||
+ goto exit;
|
||||
+
|
||||
+ // add anti-loop header for vacation(1) compatible implementations, see section 10.9 of book "sendmail" (written
|
||||
+ // by Bryan Costales, Claus Assmann, George Jansen, Gregory Neil Shapiro), ISBN 0596555342
|
||||
+ snprintf(szHeader, PATH_MAX, "\nPrecedence: bulk");
|
||||
+ hr = WriteOrLogError(fd, szHeader, strlen(szHeader));
|
||||
+ if (hr != hrSuccess)
|
||||
+ goto exit;
|
||||
+
|
||||
if (lpMessageProps[3].ulPropTag == PR_SUBJECT_W) {
|
||||
// convert as one string because of [] characters
|
||||
swprintf(szwHeader, PATH_MAX, L"%ls [%ls]", szSubject, lpMessageProps[3].Value.lpszW);
|
||||
21
zarafa-7.1.11-webaccess-fail2ban.patch
Normal file
21
zarafa-7.1.11-webaccess-fail2ban.patch
Normal file
|
|
@ -0,0 +1,21 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa <= 7.1.11 which logs authentication
|
||||
failures of Zarafa WebAccess into the error log of the webserver. This is basically a backport of
|
||||
https://jira.zarafa.com/browse/WA-6908 from WebApp to WebAccess. In difference to original patch
|
||||
there is no inappropriate space before a punctuation mark also known as "plenken".
|
||||
|
||||
Proposed to upstream via e-mail on Wed, 13 Aug 2014 22:56:09 +0200, initial patch was put into the
|
||||
upstream ticket https://jira.zarafa.com/browse/ZCP-12543.
|
||||
|
||||
--- zarafa-7.1.11/php-webclient-ajax/client/login.php 2014-09-03 10:45:06.000000000 +0200
|
||||
+++ zarafa-7.1.11/php-webclient-ajax/client/login.php 2015-02-18 01:08:13.000000000 +0100
|
||||
@@ -86,6 +86,10 @@
|
||||
switch($_SESSION["hresult"]){
|
||||
case MAPI_E_LOGON_FAILED:
|
||||
case MAPI_E_UNCONFIGURED:
|
||||
+ // Print error message to error_log of webserver
|
||||
+ if (!empty($_POST["username"])) {
|
||||
+ error_log('user '.$_POST["username"].': authentication failure at MAPI');
|
||||
+ }
|
||||
echo _("Logon failed, please check your name/password.");
|
||||
break;
|
||||
case MAPI_E_NETWORK_ERROR:
|
||||
2185
zarafa-7.1.12-gcc5.patch
Normal file
2185
zarafa-7.1.12-gcc5.patch
Normal file
File diff suppressed because it is too large
Load diff
38
zarafa-7.1.12-gsoap-sslv3.patch
Normal file
38
zarafa-7.1.12-gsoap-sslv3.patch
Normal file
|
|
@ -0,0 +1,38 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for zarafa >= 7.1.12 which disables weak SSLv2
|
||||
and SSLv3 protocols for encrypted SOAP connections between the Zarafa services. Until (including)
|
||||
the Zarafa 7.1.11 release the upstream default was to replace the SSLv23_method() that a pristine
|
||||
gSOAP library ships with the "safer" SSLv3_method(). With Zarafa 7.1.12 the SSLv3_method() was
|
||||
changed to SSLv23_method(). However this enables SSLv2 again (and still does not disable SSLv3).
|
||||
Thus this patch disables SSLv2 and SSLv3 as well as TLS compression explicitly; similar like the
|
||||
Zarafa Outlook Client which meanwhile only allows TLSv1.0 (and better).
|
||||
|
||||
Proposed to upstream via e-mail on Wed, 2 Apr 2014 11:35:40 +0200, initial patch was put into the
|
||||
upstream ticket Ticket#2014040210000266.
|
||||
|
||||
--- zarafa-7.1.12/provider/common/SOAPSock.cpp 2015-04-07 13:10:13.000000000 +0200
|
||||
+++ zarafa-7.1.12/provider/common/SOAPSock.cpp.gsoap-sslv3 2015-04-07 16:32:20.000000000 +0200
|
||||
@@ -157,9 +157,6 @@
|
||||
|
||||
lpCmd->endpoint = strdup(strServerPath.c_str());
|
||||
|
||||
- // default allow SSLv3, TLSv1, TLSv1.1 and TLSv1.2
|
||||
- lpCmd->soap->ctx = SSL_CTX_new(SSLv23_method());
|
||||
-
|
||||
#ifdef WITH_OPENSSL
|
||||
if (strncmp("https:", lpCmd->endpoint, 6) == 0) {
|
||||
// no need to add certificates to call, since soap also calls SSL_CTX_set_default_verify_paths()
|
||||
@@ -183,6 +180,14 @@
|
||||
lpCmd->soap->fsslverify = ssl_verify_callback_zarafa_silent;
|
||||
|
||||
SSL_CTX_set_verify(lpCmd->soap->ctx, SSL_VERIFY_PEER, lpCmd->soap->fsslverify);
|
||||
+
|
||||
+ // disable SSLv2 (according to RFC 6176) and SSLv3, leaving just TLSv1.0 (and better)
|
||||
+ SSL_CTX_set_options(lpCmd->soap->ctx, SSL_OP_NO_SSLv2 | SSL_OP_NO_SSLv3);
|
||||
+
|
||||
+#ifdef SSL_OP_NO_COMPRESSION
|
||||
+ // disable TLS compression to close the CRIME attack vector (also known as CVE-2012-4929)
|
||||
+ SSL_CTX_set_options(lpCmd->soap->ctx, SSL_OP_NO_COMPRESSION);
|
||||
+#endif
|
||||
}
|
||||
#endif
|
||||
|
||||
85
zarafa-7.1.12-ssl_ecdhe.patch
Normal file
85
zarafa-7.1.12-ssl_ecdhe.patch
Normal file
|
|
@ -0,0 +1,85 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa >= 7.1.12 which implements ECDHE (elliptic
|
||||
curve diffie-hellman key exchange) support. http://en.wikipedia.org/wiki/Elliptic_curve_cryptography is
|
||||
providing more information about elliptic curves.
|
||||
|
||||
Suggestions for testing; run the following openssl(1) commands before and after applying this patch:
|
||||
|
||||
1. echo QUIT | openssl s_client -connect <host>:110 -starttls pop3 2>&1 | grep Cipher
|
||||
2. echo QUIT | openssl s_client -connect <host>:143 -starttls imap 2>&1 | grep Cipher
|
||||
3. echo QUIT | openssl s_client -connect <host>:237 2>&1 | grep Cipher
|
||||
4. echo QUIT | openssl s_client -connect <host>:993 2>&1 | grep Cipher
|
||||
5. echo QUIT | openssl s_client -connect <host>:995 2>&1 | grep Cipher
|
||||
6. echo QUIT | openssl s_client -connect <host>:8443 2>&1 | grep Cipher
|
||||
|
||||
After applying this patch the output should contain e.g. "ECDHE-RSA-AES256-GCM-SHA384" on a Red Hat
|
||||
Enterprise Linux 6.5 (only RHEL >= 6.5 has support for elliptic curve). Without this patch the result
|
||||
is e.g. "AES256-GCM-SHA384".
|
||||
|
||||
Important: The technical implementation of this patch might be not perfect as I am not really a C/C++
|
||||
developer. The logic and the implementation is heavily based on Sendmail. There should be a code review
|
||||
by an experienced C/C++ and OpenSSL developer before merging into Zarafa core.
|
||||
|
||||
This patch should be only applied after ZCP-12143 and its dependencies. However this patch might maybe
|
||||
not directly apply due to some previous merge issues as mentioned in Ticket#2014030810000131.
|
||||
|
||||
Proposed to upstream via e-mail on Mon, 14 Apr 2014 12:04:17 +0200, initial patch was put into upstream
|
||||
ticket https://jira.zarafa.com/browse/ZCP-12237.
|
||||
|
||||
--- zarafa-7.1.12/common/ECChannel.cpp 2015-04-07 13:10:12.000000000 +0200
|
||||
+++ zarafa-7.1.12/common/ECChannel.cpp.ssl_ecdhe 2015-04-07 17:12:15.000000000 +0200
|
||||
@@ -93,6 +93,9 @@
|
||||
char *ssl_ciphers = lpConfig->GetSetting("ssl_ciphers");
|
||||
char *ssl_name = NULL;
|
||||
int ssl_op = 0, ssl_include = 0, ssl_exclude = 0;
|
||||
+#if !defined(OPENSSL_NO_ECDH) && defined(NID_X9_62_prime256v1)
|
||||
+ EC_KEY *ecdh;
|
||||
+#endif
|
||||
|
||||
if (lpConfig == NULL) {
|
||||
lpLogger->Log(EC_LOGLEVEL_ERROR, "ECChannel::HrSetCtx(): invalid parameters");
|
||||
@@ -113,6 +116,16 @@
|
||||
|
||||
SSL_CTX_set_options(lpCTX, SSL_OP_ALL); // enable quirk and bug workarounds
|
||||
|
||||
+#if !defined(OPENSSL_NO_ECDH) && defined(NID_X9_62_prime256v1)
|
||||
+ ecdh = EC_KEY_new_by_curve_name(NID_X9_62_prime256v1);
|
||||
+
|
||||
+ if (ecdh != NULL) {
|
||||
+ SSL_CTX_set_options(lpCTX, SSL_OP_SINGLE_ECDH_USE);
|
||||
+ SSL_CTX_set_tmp_ecdh(lpCTX, ecdh);
|
||||
+ EC_KEY_free(ecdh);
|
||||
+ }
|
||||
+#endif
|
||||
+
|
||||
ssl_name = strtok(ssl_protocols, " ");
|
||||
while(ssl_name != NULL) {
|
||||
int ssl_proto = 0;
|
||||
--- zarafa-7.1.12/provider/server/ECSoapServerConnection.cpp 2015-04-07 13:10:13.000000000 +0200
|
||||
+++ zarafa-7.1.12/provider/server/ECSoapServerConnection.cpp.ssl_ecdhe 2015-04-07 17:13:23.000000000 +0200
|
||||
@@ -235,6 +235,9 @@
|
||||
char *server_ssl_ciphers = m_lpConfig->GetSetting("server_ssl_ciphers");
|
||||
char *ssl_name = NULL;
|
||||
int ssl_op = 0, ssl_include = 0, ssl_exclude = 0;
|
||||
+#if !defined(OPENSSL_NO_ECDH) && defined(NID_X9_62_prime256v1)
|
||||
+ EC_KEY *ecdh;
|
||||
+#endif
|
||||
|
||||
if(lpServerName == NULL) {
|
||||
free(server_ssl_ciphers);
|
||||
@@ -268,6 +271,16 @@
|
||||
|
||||
SSL_CTX_set_options(lpsSoap->ctx, SSL_OP_ALL);
|
||||
|
||||
+#if !defined(OPENSSL_NO_ECDH) && defined(NID_X9_62_prime256v1)
|
||||
+ ecdh = EC_KEY_new_by_curve_name(NID_X9_62_prime256v1);
|
||||
+
|
||||
+ if (ecdh != NULL) {
|
||||
+ SSL_CTX_set_options(lpsSoap->ctx, SSL_OP_SINGLE_ECDH_USE);
|
||||
+ SSL_CTX_set_tmp_ecdh(lpsSoap->ctx, ecdh);
|
||||
+ EC_KEY_free(ecdh);
|
||||
+ }
|
||||
+#endif
|
||||
+
|
||||
ssl_name = strtok(server_ssl_protocols, " ");
|
||||
while(ssl_name != NULL) {
|
||||
int ssl_proto = 0;
|
||||
123
zarafa-7.1.12-ssl_protocols_ciphers.patch
Normal file
123
zarafa-7.1.12-ssl_protocols_ciphers.patch
Normal file
|
|
@ -0,0 +1,123 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa >= 7.1.12 which re-adds the whole
|
||||
documentation that was initially proposed to upstream but lost when this feature was backported
|
||||
from Zarafa 7.2 to the 7.1 series.
|
||||
|
||||
Proposed to upstream via e-mail on Sat, 8 Mar 2014 14:30:29 +0100, initial patch was put into
|
||||
the upstream ticket https://jira.zarafa.com/browse/ZCP-12143.
|
||||
|
||||
--- zarafa-7.1.12/doc/manual.xml 2015-04-07 12:03:31.000000000 +0200
|
||||
+++ zarafa-7.1.12/doc/manual.xml.ssl_protocols_ciphers 2015-04-07 17:05:47.000000000 +0200
|
||||
@@ -4226,14 +4226,35 @@
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
- <term><option>server_ssl_enable_v2</option></term>
|
||||
+ <term><option>server_ssl_protocols</option></term>
|
||||
<listitem>
|
||||
- <para>Incoming SSL connections normally are v3.</para>
|
||||
- <para>Default: <replaceable>no</replaceable>
|
||||
- </para>
|
||||
+ <para>Disabled or enabled protocol names. Supported protocol names
|
||||
+ are <replaceable>SSLv2</replaceable>, <replaceable>SSLv3</replaceable>
|
||||
+ and <replaceable>TLSv1</replaceable>. If Zarafa was linked against
|
||||
+ OpenSSL 1.0.1 or later there is additional support for the new protocols
|
||||
+ <replaceable>TLSv1.1</replaceable> and <replaceable>TLSv1.2</replaceable>.
|
||||
+ To exclude both, SSLv2 and SSLv3 set <option>server_ssl_protocols</option>
|
||||
+ to <replaceable>!SSLv2 !SSLv3</replaceable>. SSLv2 is considered unsafe
|
||||
+ and these connections should not be accepted.</para>
|
||||
+ <para>Default: <replaceable>!SSLv2</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
+
|
||||
+ <varlistentry>
|
||||
+ <term><option>server_ssl_ciphers</option></term>
|
||||
+ <listitem>
|
||||
+ <para>SSL ciphers to use, set to <replaceable>ALL</replaceable> for backward compatibility.</para>
|
||||
+ <para>Default: <replaceable>ALL:!LOW:!SSLv2:!EXP:!aNULL</replaceable></para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
+ <varlistentry>
|
||||
+ <term><option>server_ssl_prefer_server_ciphers</option></term>
|
||||
+ <listitem>
|
||||
+ <para>Prefer the server's order of SSL ciphers over client's.</para>
|
||||
+ <para>Default: <replaceable>no</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
</variablelist>
|
||||
</refsection>
|
||||
|
||||
@@ -8090,11 +8111,32 @@
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
- <term><option>ssl_enable_v2</option></term>
|
||||
+ <term><option>ssl_protocols</option></term>
|
||||
+ <listitem>
|
||||
+ <para>Disabled or enabled protocol names. Supported protocol names
|
||||
+ are <replaceable>SSLv2</replaceable>, <replaceable>SSLv3</replaceable>
|
||||
+ and <replaceable>TLSv1</replaceable>. If Zarafa was linked against
|
||||
+ OpenSSL 1.0.1 or later there is additional support for the new protocols
|
||||
+ <replaceable>TLSv1.1</replaceable> and <replaceable>TLSv1.2</replaceable>.
|
||||
+ To exclude both, SSLv2 and SSLv3 set <option>ssl_protocols</option>
|
||||
+ to <replaceable>!SSLv2 !SSLv3</replaceable>. SSLv2 is considered unsafe
|
||||
+ and these connections should not be accepted.</para>
|
||||
+ <para>Default: <replaceable>!SSLv2</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
+
|
||||
+ <varlistentry>
|
||||
+ <term><option>ssl_ciphers</option></term>
|
||||
<listitem>
|
||||
- <para>Accept SSLv2 only connections. SSLv2 is considered
|
||||
- unsafe, and these connections should not be
|
||||
- accepted.</para>
|
||||
+ <para>SSL ciphers to use, set to <replaceable>ALL</replaceable> for backward compatibility.</para>
|
||||
+ <para>Default: <replaceable>ALL:!LOW:!SSLv2:!EXP:!aNULL</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
+
|
||||
+ <varlistentry>
|
||||
+ <term><option>ssl_prefer_server_ciphers</option></term>
|
||||
+ <listitem>
|
||||
+ <para>Prefer the server's order of SSL ciphers over client's.</para>
|
||||
<para>Default: <replaceable>no</replaceable></para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
@@ -10091,11 +10133,32 @@
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
- <term><option>ssl_enable_v2</option></term>
|
||||
+ <term><option>ssl_protocols</option></term>
|
||||
+ <listitem>
|
||||
+ <para>Disabled or enabled protocol names. Supported protocol names
|
||||
+ are <replaceable>SSLv2</replaceable>, <replaceable>SSLv3</replaceable>
|
||||
+ and <replaceable>TLSv1</replaceable>. If Zarafa was linked against
|
||||
+ OpenSSL 1.0.1 or later there is additional support for the new protocols
|
||||
+ <replaceable>TLSv1.1</replaceable> and <replaceable>TLSv1.2</replaceable>.
|
||||
+ To exclude both, SSLv2 and SSLv3 set <option>ssl_protocols</option>
|
||||
+ to <replaceable>!SSLv2 !SSLv3</replaceable>. SSLv2 is considered unsafe
|
||||
+ and these connections should not be accepted.</para>
|
||||
+ <para>Default: <replaceable>!SSLv2</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
+
|
||||
+ <varlistentry>
|
||||
+ <term><option>ssl_ciphers</option></term>
|
||||
+ <listitem>
|
||||
+ <para>SSL ciphers to use, set to <replaceable>ALL</replaceable> for backward compatibility.</para>
|
||||
+ <para>Default: <replaceable>ALL:!LOW:!SSLv2:!EXP:!aNULL</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
+
|
||||
+ <varlistentry>
|
||||
+ <term><option>ssl_prefer_server_ciphers</option></term>
|
||||
<listitem>
|
||||
- <para>Accept SSLv2 only connections. SSLv2 is considered
|
||||
- unsafe, and these connections should not be
|
||||
- accepted.</para>
|
||||
+ <para>Prefer the server's order of SSL ciphers over client's.</para>
|
||||
<para>Default: <replaceable>no</replaceable></para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
56
zarafa-7.1.12-upgrade-lock.patch
Normal file
56
zarafa-7.1.12-upgrade-lock.patch
Normal file
|
|
@ -0,0 +1,56 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa 7.1.12 which backports the fix for
|
||||
CVE-2015-3436. Guido Günther detected and reported that replacing "/tmp/zarafa-upgrade-lock" by
|
||||
a symlink makes the zarafa-server process following that symlink and thus allows to overwrite
|
||||
arbitrary files in the filesystem (assuming zarafa-server runs as root which is not the case by
|
||||
default at Fedora, but it is the upstream default). One just needs write permissions in /tmp and
|
||||
wait until the zarafa-server is restarted. https://bugzilla.redhat.com/show_bug.cgi?id=1222151
|
||||
contains further information. The difference between this backport and the original diff is that
|
||||
the log levels were reworked from Zarafa 7.1.x to 7.2.x (which this backport takes care of).
|
||||
|
||||
--- zarafa-7.1.12/provider/server/ECServer.cpp 2015-05-08 15:09:05.000000000 +0200
|
||||
+++ zarafa-7.1.12/provider/server/ECServer.cpp.upgrade-lock 2015-05-18 23:05:00.000000000 +0200
|
||||
@@ -101,6 +101,8 @@
|
||||
// have to go with the safe value which is for 64bit.
|
||||
#define MYSQL_MIN_THREAD_STACK (256*1024)
|
||||
|
||||
+const char upgrade_lock_file[] = "/tmp/zarafa-upgrade-lock";
|
||||
+
|
||||
extern ECSessionManager* g_lpSessionManager;
|
||||
|
||||
// scheduled functions
|
||||
@@ -832,7 +834,7 @@
|
||||
// SIGSEGV backtrace support
|
||||
stack_t st = {0};
|
||||
struct sigaction act = {{0}};
|
||||
- FILE *tmplock = NULL;
|
||||
+ int tmplock = -1;
|
||||
struct stat dir = {0};
|
||||
struct passwd *runasUser = NULL;
|
||||
|
||||
@@ -1288,8 +1290,9 @@
|
||||
m_bDatabaseUpdateIgnoreSignals = true;
|
||||
|
||||
// add a lock file to disable the /etc/init.d scripts
|
||||
- tmplock = fopen("/tmp/zarafa-upgrade-lock","w");
|
||||
- if (!tmplock)
|
||||
+ tmplock = open(upgrade_lock_file, O_CREAT | O_EXCL, S_IRUSR | S_IWUSR);
|
||||
+
|
||||
+ if (tmplock == -1)
|
||||
g_lpLogger->Log(EC_LOGLEVEL_FATAL, "WARNING: Unable to place upgrade lockfile: %s", strerror(errno));
|
||||
|
||||
#ifdef EMBEDDED_MYSQL
|
||||
@@ -1314,9 +1317,11 @@
|
||||
er = lpDatabaseFactory->UpdateDatabase(m_bForceDatabaseUpdate, dbError);
|
||||
|
||||
// remove lock file
|
||||
- if (tmplock) {
|
||||
- fclose(tmplock);
|
||||
- unlink("/tmp/zarafa-upgrade-lock");
|
||||
+ if (tmplock != -1) {
|
||||
+ if (unlink(upgrade_lock_file) == -1)
|
||||
+ g_lpLogger->Log(EC_LOGLEVEL_FATAL, "WARNING: Unable to delete upgrade lockfile (%s): %s", upgrade_lock_file, strerror(errno));
|
||||
+
|
||||
+ close(tmplock);
|
||||
}
|
||||
|
||||
if(er == ZARAFA_E_INVALID_VERSION) {
|
||||
18
zarafa-7.1.12-webaccess-defaultfont.patch
Normal file
18
zarafa-7.1.12-webaccess-defaultfont.patch
Normal file
|
|
@ -0,0 +1,18 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa WebAccess >= 7.1.12 which fixes the issue that the configured
|
||||
default font from the settings (for HTML e-mails) is just not applied when creating a new e-mail. This issue is also known
|
||||
to Zarafa since at least April 2011 - but will be not fixed at upstream; see also: https://jira.zarafa.com/browse/ZCP-7492
|
||||
|
||||
This patch is is free software: You can redistribute it and/or modify it under the terms of the GNU Affero General
|
||||
Public License, version 3, as published by the Free Software Foundation.
|
||||
|
||||
--- zarafa-7.1.12/php-webclient-ajax/client/layout/dialogs/standard/createmail.php 2015-05-08 15:09:05.000000000 +0200
|
||||
+++ zarafa-7.1.12/php-webclient-ajax/client/layout/dialogs/standard/createmail.php.rsc 2015-07-12 04:26:59.000000000 +0200
|
||||
@@ -381,7 +381,7 @@
|
||||
|
||||
//set the default font-family for editorarea
|
||||
var font_family = parentWebclient.settings.get("createmail/maildefaultfont","Arial");
|
||||
- document.fckEditor.EditorDocument.body.style.fontFamily = font_family;
|
||||
+ document.fckEditor.EditorDocument.body.getElementsByTagName("p")[0].style.fontFamily = font_family;
|
||||
|
||||
// set content of body if it is passed in URL
|
||||
<? if(isset($_GET["body"])) { ?>
|
||||
58
zarafa-7.1.12-webaccess-mcrypt.patch
Normal file
58
zarafa-7.1.12-webaccess-mcrypt.patch
Normal file
|
|
@ -0,0 +1,58 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa >= 7.1.12 which fixes the fix that fixes CVE-2014-0103. Ush,
|
||||
that was complicated, so: CVE-2014-0103 exists because Zarafa WebAccess < 7.1.10 and Zarafa WebApp < 1.6 storing passwords
|
||||
in cleartext on server (in the PHP session). Zarafa solved this flaw by using openssl_encrypt() and openssl_decrypt() from
|
||||
PHP's OpenSSL bindings. However these functions are only available in PHP 5.3 or later. Without this patch suggestion, any
|
||||
older but still supported Linux distribution like Red Hat Enterprise Linux 5 or SuSE Linux Enterprise Server 10 (which are
|
||||
both shipping PHP < 5.3 by default) would still be left vulnerable.
|
||||
|
||||
Given that I am personally more a fan of OpenSSL rather mcrypt, I am not absolutely sure if this implementation is really
|
||||
correct even it works fine on my test system. So please explicitly review this code to avoid introducing another security
|
||||
flaw by trying to fix one! A thing that I generally question for myself is the usage of "des-ede3-cbc"/"MCRYPT_TRIPLEDES"
|
||||
instead of e.g. MCRYPT_RIJNDAEL_128. Given that this decision was initially made by Zarafa I am just following that here.
|
||||
|
||||
Important: To get this patch really powerful the install-time requirement needs to be adapted like this (this example is
|
||||
based on Fedora's build system so the macros %{?rhel} and %{?fedora} might not exist at Zarafa but need to be replaced by
|
||||
other macros):
|
||||
|
||||
%if 0%{?rhel}%{?fedora} < 6
|
||||
Requires: php-mcrypt
|
||||
%else
|
||||
Requires: php-openssl
|
||||
%endif
|
||||
|
||||
This requires php-openssl (provided by php-common) on RHEL 6 (and later) and php-mcrypt (separate package) before RHEL 6.
|
||||
|
||||
Proposed to upstream via e-mail on Thu, 5 Jun 2014 00:24:32 +0200, initial patch was put into the (non-disclosed) upstream
|
||||
ticket https://jira.zarafa.com/browse/ZCP-12407.
|
||||
|
||||
--- zarafa-7.1.12/php-webclient-ajax/index.php 2015-04-07 13:10:13.000000000 +0200
|
||||
+++ zarafa-7.1.12/php-webclient-ajax/index.php.webaccess-mcrypt 2015-04-07 16:22:23.000000000 +0200
|
||||
@@ -135,6 +135,8 @@
|
||||
} else {
|
||||
$_SESSION['password'] = openssl_encrypt($password,"des-ede3-cbc",PASSWORD_KEY,0,PASSWORD_IV);
|
||||
}
|
||||
+ } elseif(function_exists("mcrypt_encrypt")) {
|
||||
+ $_SESSION['password'] = base64_encode(mcrypt_encrypt(MCRYPT_TRIPLEDES, PASSWORD_KEY, $password, MCRYPT_MODE_CBC, PASSWORD_IV));
|
||||
} else {
|
||||
$_SESSION["password"] = $password;
|
||||
}
|
||||
--- zarafa-7.1.12/php-webclient-ajax/server/core/class.mapisession.php 2015-04-07 13:10:14.000000000 +0200
|
||||
+++ zarafa-7.1.12/php-webclient-ajax/server/core/class.mapisession.php.webaccess-mcrypt 2015-04-07 16:23:58.000000000 +0200
|
||||
@@ -132,6 +132,8 @@
|
||||
} else {
|
||||
$password = openssl_decrypt($password,"des-ede3-cbc",PASSWORD_KEY,0,PASSWORD_IV);
|
||||
}
|
||||
+ } elseif(function_exists("mcrypt_decrypt")) {
|
||||
+ $password = rtrim(mcrypt_decrypt(MCRYPT_TRIPLEDES, PASSWORD_KEY, base64_decode($password), MCRYPT_MODE_CBC, PASSWORD_IV), "\0");
|
||||
}
|
||||
// logon
|
||||
$this->session = mapi_logon_zarafa($username, $password, $server, $sslcert_file, $sslcert_pass);
|
||||
@@ -144,6 +146,8 @@
|
||||
} else {
|
||||
$password = openssl_encrypt($password,"des-ede3-cbc",PASSWORD_KEY,0,PASSWORD_IV);
|
||||
}
|
||||
+ } elseif(function_exists("mcrypt_encrypt")) {
|
||||
+ $password = base64_encode(mcrypt_encrypt(MCRYPT_TRIPLEDES, PASSWORD_KEY, $password, MCRYPT_MODE_CBC, PASSWORD_IV));
|
||||
}
|
||||
|
||||
if ($result == NOERROR && $this->session !== false){
|
||||
30
zarafa-7.1.12-webaccess-xss.patch
Normal file
30
zarafa-7.1.12-webaccess-xss.patch
Normal file
|
|
@ -0,0 +1,30 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa WebAccess >= 6.00 which ensures proper escaping of
|
||||
multiple user properties like fullname/realname, username and e-mail address. Without this patch a user having
|
||||
the unlikely fullname/realname '<script>alert("Hello world");</script>' (without the '') is not properly escaped
|
||||
on all places within the Zarafa WebAccess; this might be an XSS flaw.
|
||||
|
||||
This patch is is free software: You can redistribute it and/or modify it under the terms of the GNU Affero General
|
||||
Public License, version 3, as published by the Free Software Foundation.
|
||||
|
||||
--- zarafa-7.1.12/php-webclient-ajax/client/webclient.php 2015-05-08 15:09:05.000000000 +0200
|
||||
+++ zarafa-7.1.12/php-webclient-ajax/client/webclient.php.webaccess-xss 2015-07-09 23:42:35.000000000 +0200
|
||||
@@ -220,7 +220,7 @@
|
||||
dhtml.executeEvent(document.body, "ZarafaDnD:initDragMsgsToDesktop");
|
||||
}
|
||||
|
||||
- webclient.setUserInfo("<?=addslashes(windows1252_to_utf8($GLOBALS["mapisession"]->getUserName()))?>", "<?=addslashes(windows1252_to_utf8($GLOBALS["mapisession"]->getFullName()))?>", "<?=bin2hex($GLOBALS["mapisession"]->getUserEntryid())?>" , "<?=addslashes(windows1252_to_utf8($GLOBALS["mapisession"]->getEmail()))?>");
|
||||
+ webclient.setUserInfo("<?=htmlspecialchars(addslashes(windows1252_to_utf8($GLOBALS["mapisession"]->getUserName())))?>", "<?=htmlspecialchars(addslashes(windows1252_to_utf8($GLOBALS["mapisession"]->getFullName())))?>", "<?=bin2hex($GLOBALS["mapisession"]->getUserEntryid())?>" , "<?=htmlspecialchars(addslashes(windows1252_to_utf8($GLOBALS["mapisession"]->getEmail())))?>");
|
||||
|
||||
// Store current sessionid in sessionid variable
|
||||
webclient.sessionid = "<?=session_id()?>";
|
||||
--- zarafa-7.1.12/php-webclient-ajax/client/core/layoutmanager.js 2015-05-08 15:09:06.000000000 +0200
|
||||
+++ zarafa-7.1.12/php-webclient-ajax/client/core/layoutmanager.js.webaccess-xss 2015-07-09 23:43:39.000000000 +0200
|
||||
@@ -324,7 +324,7 @@
|
||||
var loggedon = dhtml.getElementById("loggedon");
|
||||
|
||||
var loggedonas = document.createElement("span");
|
||||
- loggedonas.innerHTML = _("you are logged on as") + " " + escapeHtml(webclient.fullname);
|
||||
+ loggedonas.innerHTML = _("you are logged on as") + " " + webclient.fullname;
|
||||
loggedon.appendChild(loggedonas);
|
||||
|
||||
var seperator = document.createElement("span");
|
||||
298
zarafa-7.1.13-ssl_dhe.patch
Normal file
298
zarafa-7.1.13-ssl_dhe.patch
Normal file
|
|
@ -0,0 +1,298 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa >= 7.1.13 which implements DHE aka EDH
|
||||
(diffie-hellman key exchange) support. https://en.wikipedia.org/wiki/Diffie-Hellman_key_exchange is
|
||||
providing more information about Perfect Forward Secrecy (PFS). This implementation might need some
|
||||
more resources compared to ECDHE, however not all servers and/or clients are supporting it through;
|
||||
e.g. Red Hat Enterprise Linux 5 (and derivates). The prime length of 1024, 2048, 3072, 4096, 6144
|
||||
and 8192 bits are based on the private key size to avoid any static DH parameters. Please be aware
|
||||
that this patch may cause issues with some older SSL/TLS clients, mostly Java 7 or earlier, that do
|
||||
not support primes larger than 1024 bits.
|
||||
|
||||
Suggestions for testing; run the following openssl(1) commands before and after applying this patch:
|
||||
|
||||
1. echo QUIT | openssl s_client -cipher 'kEDH:ALL' -connect <host>:110 -starttls pop3 2>&1 | grep Cipher
|
||||
2. echo QUIT | openssl s_client -cipher 'kEDH:ALL' -connect <host>:143 -starttls imap 2>&1 | grep Cipher
|
||||
3. echo QUIT | openssl s_client -cipher 'kEDH:ALL' -connect <host>:237 2>&1 | grep Cipher
|
||||
4. echo QUIT | openssl s_client -cipher 'kEDH:ALL' -connect <host>:993 2>&1 | grep Cipher
|
||||
5. echo QUIT | openssl s_client -cipher 'kEDH:ALL' -connect <host>:995 2>&1 | grep Cipher
|
||||
6. echo QUIT | openssl s_client -cipher 'kEDH:ALL' -connect <host>:8443 2>&1 | grep Cipher
|
||||
|
||||
After applying this patch the output should contain e.g. "DHE-RSA-AES256-GCM-SHA384" on a Red Hat
|
||||
Enterprise Linux 6 (and derivates). Without this patch the result is e.g. "AES256-GCM-SHA384". Note
|
||||
that ZCP-12237 is maybe having influence on the result depending on the exact test case.
|
||||
|
||||
Important: As https://www.mail-archive.com/haproxy@formilux.org/msg13274.html is the origin for this
|
||||
patch (a HAProxy patch suggestion, which itself bases on mod_ssl of Apache httpd), the licensing is
|
||||
likely a combination out of the Apache License, Version 2.0, the GNU General Public License, version
|
||||
2 (or later) and the GNU Affero General Public License, version 3 (and thus excludes dual-licensing
|
||||
situations such as at the upstream of Zarafa).
|
||||
|
||||
This patch should be only applied after ZCP-12237 and its dependencies.
|
||||
|
||||
--- zarafa-7.1.13/common/ECChannel.cpp 2015-07-30 01:01:07.212313822 +0200
|
||||
+++ zarafa-7.1.13/common/ECChannel.cpp.ssl_dhe 2015-07-30 02:05:36.045747555 +0200
|
||||
@@ -85,6 +85,119 @@
|
||||
// because of statics
|
||||
SSL_CTX* ECChannel::lpCTX = NULL;
|
||||
|
||||
+#if !defined(OPENSSL_NO_DH)
|
||||
+static DH *ssl_get_dh_1024(void) {
|
||||
+ DH *dh = DH_new();
|
||||
+ if (dh) {
|
||||
+ dh->p = get_rfc2409_prime_1024(NULL);
|
||||
+ // See RFC 2409, Section 6 "Oakley Groups" for the reason why we use 2 as a generator
|
||||
+ BN_dec2bn(&dh->g, "2");
|
||||
+ if (!dh->p || !dh->g) {
|
||||
+ DH_free(dh);
|
||||
+ dh = NULL;
|
||||
+ }
|
||||
+ }
|
||||
+ return dh;
|
||||
+}
|
||||
+
|
||||
+static DH *ssl_get_dh_2048(void) {
|
||||
+ DH *dh = DH_new();
|
||||
+ if (dh) {
|
||||
+ dh->p = get_rfc3526_prime_2048(NULL);
|
||||
+ // See RFC 3526, Section 3 "2048-bit MODP Group" for the reason why we use 2 as a generator
|
||||
+ BN_dec2bn(&dh->g, "2");
|
||||
+ if (!dh->p || !dh->g) {
|
||||
+ DH_free(dh);
|
||||
+ dh = NULL;
|
||||
+ }
|
||||
+ }
|
||||
+ return dh;
|
||||
+}
|
||||
+
|
||||
+static DH *ssl_get_dh_3072(void) {
|
||||
+ DH *dh = DH_new();
|
||||
+ if (dh) {
|
||||
+ dh->p = get_rfc3526_prime_3072(NULL);
|
||||
+ // See RFC 3526, Section 4 "3072-bit MODP Group" for the reason why we use 2 as a generator
|
||||
+ BN_dec2bn(&dh->g, "2");
|
||||
+ if (!dh->p || !dh->g) {
|
||||
+ DH_free(dh);
|
||||
+ dh = NULL;
|
||||
+ }
|
||||
+ }
|
||||
+ return dh;
|
||||
+}
|
||||
+
|
||||
+static DH *ssl_get_dh_4096(void) {
|
||||
+ DH *dh = DH_new();
|
||||
+ if (dh) {
|
||||
+ dh->p = get_rfc3526_prime_4096(NULL);
|
||||
+ // See RFC 3526, Section 5 "4096-bit MODP Group" for the reason why we use 2 as a generator
|
||||
+ BN_dec2bn(&dh->g, "2");
|
||||
+ if (!dh->p || !dh->g) {
|
||||
+ DH_free(dh);
|
||||
+ dh = NULL;
|
||||
+ }
|
||||
+ }
|
||||
+ return dh;
|
||||
+}
|
||||
+
|
||||
+static DH *ssl_get_dh_6144(void) {
|
||||
+ DH *dh = DH_new();
|
||||
+ if (dh) {
|
||||
+ dh->p = get_rfc3526_prime_6144(NULL);
|
||||
+ // See RFC 3526, Section 6 "6144-bit MODP Group" for the reason why we use 2 as a generator
|
||||
+ BN_dec2bn(&dh->g, "2");
|
||||
+ if (!dh->p || !dh->g) {
|
||||
+ DH_free(dh);
|
||||
+ dh = NULL;
|
||||
+ }
|
||||
+ }
|
||||
+ return dh;
|
||||
+}
|
||||
+
|
||||
+static DH *ssl_get_dh_8192(void) {
|
||||
+ DH *dh = DH_new();
|
||||
+ if (dh) {
|
||||
+ dh->p = get_rfc3526_prime_8192(NULL);
|
||||
+ // See RFC 3526, Section 7 "8192-bit MODP Group" for the reason why we use 2 as a generator
|
||||
+ BN_dec2bn(&dh->g, "2");
|
||||
+ if (!dh->p || !dh->g) {
|
||||
+ DH_free(dh);
|
||||
+ dh = NULL;
|
||||
+ }
|
||||
+ }
|
||||
+ return dh;
|
||||
+}
|
||||
+
|
||||
+// Returns Diffie-Hellman parameters matching the private key length
|
||||
+static DH *ssl_get_tmp_dh(SSL *ssl, int exporting, int keylen) {
|
||||
+ DH *dh = NULL;
|
||||
+ EVP_PKEY *pkey = SSL_get_privatekey(ssl);
|
||||
+ int type = pkey ? EVP_PKEY_type(pkey->type) : EVP_PKEY_NONE;
|
||||
+
|
||||
+ if (type == EVP_PKEY_RSA || type == EVP_PKEY_DSA) {
|
||||
+ keylen = EVP_PKEY_bits(pkey);
|
||||
+ }
|
||||
+
|
||||
+ if (keylen >= 8192) {
|
||||
+ dh = ssl_get_dh_8192();
|
||||
+ } else if (keylen >= 6144) {
|
||||
+ dh = ssl_get_dh_6144();
|
||||
+ } else if (keylen >= 4096) {
|
||||
+ dh = ssl_get_dh_4096();
|
||||
+ } else if (keylen >= 3072) {
|
||||
+ dh = ssl_get_dh_3072();
|
||||
+ } else if (keylen >= 2048) {
|
||||
+ dh = ssl_get_dh_2048();
|
||||
+ } else {
|
||||
+ dh = ssl_get_dh_1024();
|
||||
+ }
|
||||
+
|
||||
+ return dh;
|
||||
+}
|
||||
+#endif
|
||||
+
|
||||
HRESULT ECChannel::HrSetCtx(ECConfig *lpConfig, ECLogger *lpLogger) {
|
||||
HRESULT hr = hrSuccess;
|
||||
char *szFile = NULL;
|
||||
@@ -116,6 +229,11 @@
|
||||
|
||||
SSL_CTX_set_options(lpCTX, SSL_OP_ALL); // enable quirk and bug workarounds
|
||||
|
||||
+#if !defined(OPENSSL_NO_DH)
|
||||
+ SSL_CTX_set_options(lpCTX, SSL_OP_SINGLE_DH_USE);
|
||||
+ SSL_CTX_set_tmp_dh_callback(lpCTX, ssl_get_tmp_dh);
|
||||
+#endif
|
||||
+
|
||||
#if !defined(OPENSSL_NO_ECDH) && defined(NID_X9_62_prime256v1)
|
||||
ecdh = EC_KEY_new_by_curve_name(NID_X9_62_prime256v1);
|
||||
|
||||
--- zarafa-7.1.13/provider/server/ECSoapServerConnection.cpp 2015-07-30 01:01:07.212313822 +0200
|
||||
+++ zarafa-7.1.13/provider/server/ECSoapServerConnection.cpp.ssl_dhe 2015-07-30 02:05:54.658626465 +0200
|
||||
@@ -165,6 +165,119 @@
|
||||
return nRet;
|
||||
}
|
||||
|
||||
+#if !defined(OPENSSL_NO_DH)
|
||||
+static DH *ssl_get_dh_1024(void) {
|
||||
+ DH *dh = DH_new();
|
||||
+ if (dh) {
|
||||
+ dh->p = get_rfc2409_prime_1024(NULL);
|
||||
+ // See RFC 2409, Section 6 "Oakley Groups" for the reason why we use 2 as a generator
|
||||
+ BN_dec2bn(&dh->g, "2");
|
||||
+ if (!dh->p || !dh->g) {
|
||||
+ DH_free(dh);
|
||||
+ dh = NULL;
|
||||
+ }
|
||||
+ }
|
||||
+ return dh;
|
||||
+}
|
||||
+
|
||||
+static DH *ssl_get_dh_2048(void) {
|
||||
+ DH *dh = DH_new();
|
||||
+ if (dh) {
|
||||
+ dh->p = get_rfc3526_prime_2048(NULL);
|
||||
+ // See RFC 3526, Section 3 "2048-bit MODP Group" for the reason why we use 2 as a generator
|
||||
+ BN_dec2bn(&dh->g, "2");
|
||||
+ if (!dh->p || !dh->g) {
|
||||
+ DH_free(dh);
|
||||
+ dh = NULL;
|
||||
+ }
|
||||
+ }
|
||||
+ return dh;
|
||||
+}
|
||||
+
|
||||
+static DH *ssl_get_dh_3072(void) {
|
||||
+ DH *dh = DH_new();
|
||||
+ if (dh) {
|
||||
+ dh->p = get_rfc3526_prime_3072(NULL);
|
||||
+ // See RFC 3526, Section 4 "3072-bit MODP Group" for the reason why we use 2 as a generator
|
||||
+ BN_dec2bn(&dh->g, "2");
|
||||
+ if (!dh->p || !dh->g) {
|
||||
+ DH_free(dh);
|
||||
+ dh = NULL;
|
||||
+ }
|
||||
+ }
|
||||
+ return dh;
|
||||
+}
|
||||
+
|
||||
+static DH *ssl_get_dh_4096(void) {
|
||||
+ DH *dh = DH_new();
|
||||
+ if (dh) {
|
||||
+ dh->p = get_rfc3526_prime_4096(NULL);
|
||||
+ // See RFC 3526, Section 5 "4096-bit MODP Group" for the reason why we use 2 as a generator
|
||||
+ BN_dec2bn(&dh->g, "2");
|
||||
+ if (!dh->p || !dh->g) {
|
||||
+ DH_free(dh);
|
||||
+ dh = NULL;
|
||||
+ }
|
||||
+ }
|
||||
+ return dh;
|
||||
+}
|
||||
+
|
||||
+static DH *ssl_get_dh_6144(void) {
|
||||
+ DH *dh = DH_new();
|
||||
+ if (dh) {
|
||||
+ dh->p = get_rfc3526_prime_6144(NULL);
|
||||
+ // See RFC 3526, Section 6 "6144-bit MODP Group" for the reason why we use 2 as a generator
|
||||
+ BN_dec2bn(&dh->g, "2");
|
||||
+ if (!dh->p || !dh->g) {
|
||||
+ DH_free(dh);
|
||||
+ dh = NULL;
|
||||
+ }
|
||||
+ }
|
||||
+ return dh;
|
||||
+}
|
||||
+
|
||||
+static DH *ssl_get_dh_8192(void) {
|
||||
+ DH *dh = DH_new();
|
||||
+ if (dh) {
|
||||
+ dh->p = get_rfc3526_prime_8192(NULL);
|
||||
+ // See RFC 3526, Section 7 "8192-bit MODP Group" for the reason why we use 2 as a generator
|
||||
+ BN_dec2bn(&dh->g, "2");
|
||||
+ if (!dh->p || !dh->g) {
|
||||
+ DH_free(dh);
|
||||
+ dh = NULL;
|
||||
+ }
|
||||
+ }
|
||||
+ return dh;
|
||||
+}
|
||||
+
|
||||
+// Returns Diffie-Hellman parameters matching the private key length
|
||||
+static DH *ssl_get_tmp_dh(SSL *ssl, int exporting, int keylen) {
|
||||
+ DH *dh = NULL;
|
||||
+ EVP_PKEY *pkey = SSL_get_privatekey(ssl);
|
||||
+ int type = pkey ? EVP_PKEY_type(pkey->type) : EVP_PKEY_NONE;
|
||||
+
|
||||
+ if (type == EVP_PKEY_RSA || type == EVP_PKEY_DSA) {
|
||||
+ keylen = EVP_PKEY_bits(pkey);
|
||||
+ }
|
||||
+
|
||||
+ if (keylen >= 8192) {
|
||||
+ dh = ssl_get_dh_8192();
|
||||
+ } else if (keylen >= 6144) {
|
||||
+ dh = ssl_get_dh_6144();
|
||||
+ } else if (keylen >= 4096) {
|
||||
+ dh = ssl_get_dh_4096();
|
||||
+ } else if (keylen >= 3072) {
|
||||
+ dh = ssl_get_dh_3072();
|
||||
+ } else if (keylen >= 2048) {
|
||||
+ dh = ssl_get_dh_2048();
|
||||
+ } else {
|
||||
+ dh = ssl_get_dh_1024();
|
||||
+ }
|
||||
+
|
||||
+ return dh;
|
||||
+}
|
||||
+#endif
|
||||
+
|
||||
ECSoapServerConnection::ECSoapServerConnection(ECConfig* lpConfig, ECLogger* lpLogger)
|
||||
{
|
||||
m_lpConfig = lpConfig;
|
||||
@@ -271,6 +384,11 @@
|
||||
|
||||
SSL_CTX_set_options(lpsSoap->ctx, SSL_OP_ALL);
|
||||
|
||||
+#if !defined(OPENSSL_NO_DH)
|
||||
+ SSL_CTX_set_options(lpsSoap->ctx, SSL_OP_SINGLE_DH_USE);
|
||||
+ SSL_CTX_set_tmp_dh_callback(lpsSoap->ctx, ssl_get_tmp_dh);
|
||||
+#endif
|
||||
+
|
||||
#if !defined(OPENSSL_NO_ECDH) && defined(NID_X9_62_prime256v1)
|
||||
ecdh = EC_KEY_new_by_curve_name(NID_X9_62_prime256v1);
|
||||
|
||||
147
zarafa-7.1.14-spooler-expand_groups.patch
Normal file
147
zarafa-7.1.14-spooler-expand_groups.patch
Normal file
|
|
@ -0,0 +1,147 @@
|
|||
Backport of upstream patch from subversion revision 50583 to fix https://jira.zarafa.com/browse/ZCP-12148
|
||||
|
||||
--- zarafa-7.1.14/inetmapi/ECVMIMEUtils.cpp 2015-10-20 11:13:43.000000000 +0200
|
||||
+++ zarafa-7.1.14/inetmapi/ECVMIMEUtils.cpp.spooler-expand_groups 2016-11-28 22:46:59.000000000 +0100
|
||||
@@ -112,7 +112,7 @@
|
||||
* This function takes a MAPI table, reads all items from it, expands any groups and adds all expanded recipients into the passed
|
||||
* recipient table. Group expansion is recursive.
|
||||
*/
|
||||
-HRESULT ECVMIMESender::HrAddRecipsFromTable(LPADRBOOK lpAdrBook, IMAPITable *lpTable, vmime::mailboxList &recipients, std::set<std::wstring> &setGroups, std::set<std::wstring> &setRecips, bool bAllowEveryone)
|
||||
+HRESULT ECVMIMESender::HrAddRecipsFromTable(LPADRBOOK lpAdrBook, IMAPITable *lpTable, vmime::mailboxList &recipients, std::set<std::wstring> &setGroups, std::set<std::wstring> &setRecips, bool bAllowEveryone, bool bAlwaysExpandDistrList)
|
||||
{
|
||||
HRESULT hr = hrSuccess;
|
||||
LPSRowSet lpRowSet = NULL;
|
||||
@@ -125,14 +125,10 @@
|
||||
// Get all recipients from the group
|
||||
for (ULONG i = 0; i < lpRowSet->cRows; i++) {
|
||||
LPSPropValue lpPropObjectType = PpropFindProp( lpRowSet->aRow[i].lpProps, lpRowSet->aRow[i].cValues, PR_OBJECT_TYPE);
|
||||
+ bool bAddrFetchSuccess = HrGetAddress(lpAdrBook, lpRowSet->aRow[i].lpProps, lpRowSet->aRow[i].cValues, PR_ENTRYID, PR_DISPLAY_NAME_W, PR_ADDRTYPE_W, PR_EMAIL_ADDRESS_W, strName, strType, strEmail) == hrSuccess;
|
||||
|
||||
- if(lpPropObjectType == NULL || lpPropObjectType->Value.ul == MAPI_MAILUSER) {
|
||||
- // Normal recipient
|
||||
- if (HrGetAddress(lpAdrBook, lpRowSet->aRow[i].lpProps, lpRowSet->aRow[i].cValues,
|
||||
- PR_ENTRYID, PR_DISPLAY_NAME_W, PR_ADDRTYPE_W, PR_EMAIL_ADDRESS_W,
|
||||
- strName, strType, strEmail) == hrSuccess)
|
||||
- {
|
||||
-
|
||||
+ if (bAddrFetchSuccess && (lpPropObjectType == NULL || lpPropObjectType->Value.ul == MAPI_MAILUSER || (lpPropObjectType->Value.ul == MAPI_DISTLIST && !bAlwaysExpandDistrList))) {
|
||||
+ if (bAddrFetchSuccess) {
|
||||
if(!strEmail.empty() && setRecips.find(strEmail) == setRecips.end()) {
|
||||
recipients.appendMailbox(vmime::create<vmime::mailbox>(convert_to<string>(strEmail)));
|
||||
setRecips.insert(strEmail);
|
||||
@@ -263,7 +259,7 @@
|
||||
if(hr != hrSuccess)
|
||||
goto exit;
|
||||
|
||||
- hr = HrAddRecipsFromTable(lpAdrBook, lpTable, recipients, setGroups, setRecips, bAllowEveryone);
|
||||
+ hr = HrAddRecipsFromTable(lpAdrBook, lpTable, recipients, setGroups, setRecips, bAllowEveryone, true);
|
||||
if(hr != hrSuccess)
|
||||
goto exit;
|
||||
|
||||
@@ -283,7 +279,7 @@
|
||||
return hr;
|
||||
}
|
||||
|
||||
-HRESULT ECVMIMESender::HrMakeRecipientsList(LPADRBOOK lpAdrBook, LPMESSAGE lpMessage, vmime::ref<vmime::message> vmMessage, vmime::mailboxList &recipients, bool bAllowEveryone)
|
||||
+HRESULT ECVMIMESender::HrMakeRecipientsList(LPADRBOOK lpAdrBook, LPMESSAGE lpMessage, vmime::ref<vmime::message> vmMessage, vmime::mailboxList &recipients, bool bAllowEveryone, bool bAlwaysExpandDistrList)
|
||||
{
|
||||
HRESULT hr = hrSuccess;
|
||||
SRestriction sRestriction;
|
||||
@@ -320,7 +316,7 @@
|
||||
goto exit;
|
||||
}
|
||||
|
||||
- hr = HrAddRecipsFromTable(lpAdrBook, lpRTable, recipients, setGroups, setRecips, bAllowEveryone);
|
||||
+ hr = HrAddRecipsFromTable(lpAdrBook, lpRTable, recipients, setGroups, setRecips, bAllowEveryone, true);
|
||||
if (hr != hrSuccess)
|
||||
goto exit;
|
||||
|
||||
@@ -338,7 +334,7 @@
|
||||
// This function does not catch the vmime exception
|
||||
// it should be handled by the calling party.
|
||||
|
||||
-HRESULT ECVMIMESender::sendMail(LPADRBOOK lpAdrBook, LPMESSAGE lpMessage, vmime::ref<vmime::message> vmMessage, bool bAllowEveryone)
|
||||
+HRESULT ECVMIMESender::sendMail(LPADRBOOK lpAdrBook, LPMESSAGE lpMessage, vmime::ref<vmime::message> vmMessage, bool bAllowEveryone, bool bAlwaysExpandDistrList)
|
||||
{
|
||||
HRESULT hr = hrSuccess;
|
||||
vmime::mailbox expeditor;
|
||||
@@ -386,7 +382,7 @@
|
||||
goto exit;
|
||||
}
|
||||
|
||||
- hr = HrMakeRecipientsList(lpAdrBook, lpMessage, vmMessage, recipients, bAllowEveryone);
|
||||
+ hr = HrMakeRecipientsList(lpAdrBook, lpMessage, vmMessage, recipients, bAllowEveryone, bAlwaysExpandDistrList);
|
||||
if (hr != hrSuccess)
|
||||
goto exit;
|
||||
|
||||
--- zarafa-7.1.14/inetmapi/ECVMIMEUtils.h 2015-10-20 11:13:43.000000000 +0200
|
||||
+++ zarafa-7.1.14/inetmapi/ECVMIMEUtils.h.spooler-expand_groups 2016-11-28 22:51:24.000000000 +0100
|
||||
@@ -55,15 +55,15 @@
|
||||
{
|
||||
private:
|
||||
|
||||
- HRESULT HrMakeRecipientsList(LPADRBOOK lpAdrBook, LPMESSAGE lpMessage, vmime::ref<vmime::message> vmMessage, vmime::mailboxList &recipients, bool bAllowEveryone);
|
||||
+ HRESULT HrMakeRecipientsList(LPADRBOOK lpAdrBook, LPMESSAGE lpMessage, vmime::ref<vmime::message> vmMessage, vmime::mailboxList &recipients, bool bAllowEveryone, bool bAlwaysExpandDistrList);
|
||||
HRESULT HrExpandGroup(LPADRBOOK lpAdrBook, LPSPropValue lpGroupName, LPSPropValue lpGroupEntryID, vmime::mailboxList &recipients, std::set<std::wstring> &setGroups, std::set<std::wstring> &setRecips, bool bAllowEveryone);
|
||||
- HRESULT HrAddRecipsFromTable(LPADRBOOK lpAdrBook, IMAPITable *lpTable, vmime::mailboxList &recipients, std::set<std::wstring> &setGroups, std::set<std::wstring> &setRecips, bool bAllowEveryone);
|
||||
+ HRESULT HrAddRecipsFromTable(LPADRBOOK lpAdrBook, IMAPITable *lpTable, vmime::mailboxList &recipients, std::set<std::wstring> &setGroups, std::set<std::wstring> &setRecips, bool bAllowEveryone, bool bAlwaysExpandDistrList);
|
||||
|
||||
public:
|
||||
ECVMIMESender(ECLogger *newlpLogger, std::string strSMTPHost, int port);
|
||||
virtual ~ECVMIMESender();
|
||||
|
||||
- HRESULT sendMail(LPADRBOOK lpAdrBook, LPMESSAGE lpMessage, vmime::ref<vmime::message> vmMessage, bool bAllowEveryone);
|
||||
+ HRESULT sendMail(LPADRBOOK lpAdrBook, LPMESSAGE lpMessage, vmime::ref<vmime::message> vmMessage, bool bAllowEveryone, bool bAlwaysExpandDistrList);
|
||||
};
|
||||
|
||||
#endif
|
||||
--- zarafa-7.1.14/inetmapi/inetmapi.cpp 2015-10-20 11:13:43.000000000 +0200
|
||||
+++ zarafa-7.1.14/inetmapi/inetmapi.cpp.spooler-expand_groups 2016-11-28 22:50:04.000000000 +0100
|
||||
@@ -331,7 +331,7 @@
|
||||
goto exit;
|
||||
}
|
||||
|
||||
- hr = mailer->sendMail(lpAddrBook, lpMessage, vmMessage, sopt.allow_send_to_everyone);
|
||||
+ hr = mailer->sendMail(lpAddrBook, lpMessage, vmMessage, sopt.allow_send_to_everyone, sopt.always_expand_distr_list);
|
||||
|
||||
exit:
|
||||
delete mToVM;
|
||||
--- zarafa-7.1.14/inetmapi/options.h 2015-10-20 11:13:43.000000000 +0200
|
||||
+++ zarafa-7.1.14/inetmapi/options.h.spooler-expand_groups 2016-11-28 22:55:44.000000000 +0100
|
||||
@@ -68,6 +68,7 @@
|
||||
char *charset_upgrade;
|
||||
bool allow_send_to_everyone;
|
||||
bool enable_dsn; /**< Enable SMTP Delivery Status Notifications */
|
||||
+ bool always_expand_distr_list;
|
||||
} sending_options;
|
||||
|
||||
void INETMAPI_API imopt_default_delivery_options(delivery_options *dopt);
|
||||
--- zarafa-7.1.14/spooler/mailer.cpp 2015-10-20 11:13:43.000000000 +0200
|
||||
+++ zarafa-7.1.14/spooler/mailer.cpp.spooler-expand_groups 2016-11-28 22:54:38.000000000 +0100
|
||||
@@ -2178,6 +2178,8 @@
|
||||
// Enable SMTP Delivery Status Notifications
|
||||
sopt.enable_dsn = parseBool(g_lpConfig->GetSetting("enable_dsn"));
|
||||
|
||||
+ sopt.always_expand_distr_list = parseBool(g_lpConfig->GetSetting("expand_groups"));
|
||||
+
|
||||
// Init plugin system
|
||||
hr = pyMapiPluginFactory.Init(g_lpConfig, g_lpLogger);
|
||||
if (hr != hrSuccess) {
|
||||
@@ -2427,7 +2429,7 @@
|
||||
*/
|
||||
}
|
||||
|
||||
- if(parseBool(g_lpConfig->GetSetting("expand_groups"))) {
|
||||
+ if (sopt.always_expand_distr_list) {
|
||||
// Expand recipients with ADDRTYPE=ZARAFA to multiple ADDRTYPE=SMTP recipients
|
||||
hr = ExpandRecipients(lpAddrBook, lpMessage);
|
||||
if(hr != hrSuccess)
|
||||
@@ -2438,7 +2440,7 @@
|
||||
if (hr != hrSuccess)
|
||||
g_lpLogger->Log(EC_LOGLEVEL_WARNING, "Unable to rewrite recipients");
|
||||
|
||||
- if(parseBool(g_lpConfig->GetSetting("expand_groups"))) {
|
||||
+ if (sopt.always_expand_distr_list) {
|
||||
// Only touch recips if we're expanding groups; the rationale is here that the user
|
||||
// has typed a recipient twice if we have duplicates and expand_groups = no, so that's
|
||||
// what the user wanted apparently. What's more, duplicate recips are filtered for RCPT TO
|
||||
48
zarafa-webaccess.conf
Normal file
48
zarafa-webaccess.conf
Normal file
|
|
@ -0,0 +1,48 @@
|
|||
#
|
||||
# Zarafa Webaccess featuring a 'Look & Feel' similar to Outlook
|
||||
#
|
||||
|
||||
Alias /webaccess /usr/share/zarafa-webaccess/
|
||||
|
||||
# Following Apache and PHP settings need to be set to work correct
|
||||
#
|
||||
<Directory /usr/share/zarafa-webaccess/>
|
||||
# Some apache settings
|
||||
DirectoryIndex index.php
|
||||
Options -Indexes +FollowSymLinks
|
||||
|
||||
<IfModule mod_authz_core.c>
|
||||
# Apache 2.4
|
||||
Require all granted
|
||||
</IfModule>
|
||||
<IfModule !mod_authz_core.c>
|
||||
# Apache 2.2
|
||||
Order allow,deny
|
||||
Allow from all
|
||||
</IfModule>
|
||||
|
||||
# Register globals must be off
|
||||
php_flag register_globals off
|
||||
|
||||
# Magic quotes must be off
|
||||
php_flag magic_quotes_gpc off
|
||||
php_flag magic_quotes_runtime off
|
||||
|
||||
# The maximum POST limit. To upload large files, this value must
|
||||
# be larger than upload_max_filesize.
|
||||
php_value post_max_size 31M
|
||||
php_value upload_max_filesize 30M
|
||||
|
||||
# Short open tags must be on
|
||||
php_flag short_open_tag on
|
||||
|
||||
# Uncomment to enhance security of WebAccess by restricting cookies
|
||||
# to only be provided over HTTPS connections
|
||||
# php_flag session.cookie_secure on
|
||||
# php_flag session.cookie_httponly on
|
||||
|
||||
# Uncomment for debugging purposes only. Make sure Apache/PHP can
|
||||
# write to this file or no errors will be logged!
|
||||
# php_flag log_errors on
|
||||
# php_value error_log /var/lib/zarafa-webaccess/error_log
|
||||
</Directory>
|
||||
2
zarafa.ini
Normal file
2
zarafa.ini
Normal file
|
|
@ -0,0 +1,2 @@
|
|||
; Enable Zarafa mapi extension module
|
||||
extension=mapi.so
|
||||
100
zarafa.logrotate
Normal file
100
zarafa.logrotate
Normal file
|
|
@ -0,0 +1,100 @@
|
|||
/var/log/zarafa/archiver.log {
|
||||
weekly
|
||||
missingok
|
||||
rotate 52
|
||||
compress
|
||||
delaycompress
|
||||
notifempty
|
||||
create 0644 zarafa zarafa
|
||||
}
|
||||
|
||||
/var/log/zarafa/dagent.log {
|
||||
weekly
|
||||
missingok
|
||||
rotate 52
|
||||
compress
|
||||
delaycompress
|
||||
notifempty
|
||||
postrotate
|
||||
killall -HUP zarafa-dagent 2> /dev/null || true
|
||||
endscript
|
||||
create 0644 zarafa zarafa
|
||||
}
|
||||
|
||||
/var/log/zarafa/gateway.log {
|
||||
weekly
|
||||
missingok
|
||||
rotate 52
|
||||
compress
|
||||
delaycompress
|
||||
notifempty
|
||||
postrotate
|
||||
killall -HUP zarafa-gateway 2> /dev/null || true
|
||||
endscript
|
||||
create 0644 zarafa zarafa
|
||||
}
|
||||
|
||||
/var/log/zarafa/ical.log {
|
||||
weekly
|
||||
missingok
|
||||
rotate 52
|
||||
compress
|
||||
delaycompress
|
||||
notifempty
|
||||
postrotate
|
||||
killall -HUP zarafa-ical 2> /dev/null || true
|
||||
endscript
|
||||
create 0644 zarafa zarafa
|
||||
}
|
||||
|
||||
/var/log/zarafa/indexer.log {
|
||||
weekly
|
||||
missingok
|
||||
rotate 52
|
||||
compress
|
||||
delaycompress
|
||||
notifempty
|
||||
postrotate
|
||||
killall -HUP zarafa-indexer 2> /dev/null || true
|
||||
endscript
|
||||
create 0644 zarafa zarafa
|
||||
}
|
||||
|
||||
/var/log/zarafa/monitor.log {
|
||||
weekly
|
||||
missingok
|
||||
rotate 52
|
||||
compress
|
||||
delaycompress
|
||||
notifempty
|
||||
postrotate
|
||||
killall -HUP zarafa-monitor 2> /dev/null || true
|
||||
endscript
|
||||
create 0644 zarafa zarafa
|
||||
}
|
||||
|
||||
/var/log/zarafa/server.log /var/log/zarafa/audit.log {
|
||||
weekly
|
||||
missingok
|
||||
rotate 52
|
||||
compress
|
||||
delaycompress
|
||||
notifempty
|
||||
postrotate
|
||||
killall -HUP zarafa-server 2> /dev/null || true
|
||||
endscript
|
||||
create 0644 zarafa zarafa
|
||||
}
|
||||
|
||||
/var/log/zarafa/spooler.log {
|
||||
weekly
|
||||
missingok
|
||||
rotate 52
|
||||
compress
|
||||
delaycompress
|
||||
notifempty
|
||||
postrotate
|
||||
killall -HUP zarafa-spooler 2> /dev/null || true
|
||||
endscript
|
||||
create 0644 zarafa zarafa
|
||||
}
|
||||
1194
zarafa.spec
Normal file
1194
zarafa.spec
Normal file
File diff suppressed because it is too large
Load diff
Loading…
Add table
Add a link
Reference in a new issue