Compare commits
12 commits
| Author | SHA1 | Date | |
|---|---|---|---|
| f800d1c727 | |||
| 17841d83c9 | |||
| c7ecef187e | |||
| 384c0c36e1 | |||
| 423e99d9b3 | |||
| 860fae1250 | |||
| ce0e01723f | |||
|
|
7e34c68abe | ||
| 09deb48f90 | |||
| 6485eb28e2 | |||
| 1b451fb6f4 | |||
| 4a32efa8ec |
22 changed files with 2249 additions and 1 deletions
1
.gitignore
vendored
Normal file
1
.gitignore
vendored
Normal file
|
|
@ -0,0 +1 @@
|
|||
zcp-7.?.*.tar.gz
|
||||
|
|
@ -1 +0,0 @@
|
|||
Package is retired
|
||||
1
sources
Normal file
1
sources
Normal file
|
|
@ -0,0 +1 @@
|
|||
4744f5c09ca082ea23cd28ea1d10941f zcp-7.1.12.tar.gz
|
||||
19
zarafa-7.1.10-imap-badcharset.patch
Normal file
19
zarafa-7.1.10-imap-badcharset.patch
Normal file
|
|
@ -0,0 +1,19 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa <= 7.1.10 which fixes the RFC-
|
||||
violating reply of the Zarafa IMAP gateway in response to a failed SEARCH CHARSET request.
|
||||
This is documented at http://tools.ietf.org/html/rfc3501#page-64: "BADCHARSET: Optionally
|
||||
followed by a parenthesized list of charsets. [...]". This patch adds missing parenthesis.
|
||||
|
||||
Proposed to upstream via e-mail on Sun, 27 Jul 2014 23:58:01 +0200, patch was put into the
|
||||
upstream ticket https://jira.zarafa.com/browse/ZCP-12504.
|
||||
|
||||
--- zarafa-7.1.10/gateway/IMAP.cpp 2014-05-23 15:56:37.000000000 +0200
|
||||
+++ zarafa-7.1.10/gateway/IMAP.cpp.imap-badcharset 2014-07-27 23:42:30.000000000 +0200
|
||||
@@ -2409,7 +2409,7 @@
|
||||
if (lstSearchCriteria[1] != "WINDOWS-1252") {
|
||||
iconv = new ECIConv("windows-1252", lstSearchCriteria[1]);
|
||||
if (!iconv->canConvert()) {
|
||||
- hr2 = HrResponse(RESP_TAGGED_NO, strTag, "[BADCHARSET WINDOWS-1252] "+strMode+"SEARCH charset not supported");
|
||||
+ hr2 = HrResponse(RESP_TAGGED_NO, strTag, "[BADCHARSET (WINDOWS-1252)] "+strMode+"SEARCH charset not supported");
|
||||
hr = MAPI_E_CALL_FAILED;
|
||||
goto exit;
|
||||
}
|
||||
93
zarafa-7.1.10-imap-fetch-body.patch
Normal file
93
zarafa-7.1.10-imap-fetch-body.patch
Normal file
|
|
@ -0,0 +1,93 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa <= 7.1.10 which fixes the RFC-
|
||||
violating reply of the Zarafa IMAP gateway in response to a body fetch request. This is
|
||||
documented at http://tools.ietf.org/html/rfc3501#page-55. Additionally this has been also
|
||||
compared with the Dovecot IMAP server as a nearly (or even de facto) IMAP server reference
|
||||
implementation. Please note that this is NOT a duplicate of ZCP-11590/ZCP-11739/ZCP-12365!
|
||||
|
||||
Wrong behaviour of Zarafa <= 7.1.10rc1-44973 (without this patch):
|
||||
> A4 FETCH 1 (BODY.PEEK[HEADER.FIELDS (FROM FROM)])
|
||||
< * 1 FETCH (BODY[HEADER.FIELDS (FROM FROM)] {66}
|
||||
From: User1 <user1@domain.org>
|
||||
From: User1 <user1@domain.org>
|
||||
|
||||
)
|
||||
< A4 OK FETCH completed
|
||||
|
||||
Comparison with IMAP server Dovecot 2.2.13:
|
||||
> A4 FETCH 1 (BODY.PEEK[HEADER.FIELDS (FROM FROM)])
|
||||
< * 1 FETCH (BODY[HEADER.FIELDS (FROM FROM)] {34}
|
||||
From: User1 <user1@domain.org>
|
||||
|
||||
)
|
||||
< A4 OK Fetch completed.
|
||||
|
||||
Correct behaviour of Zarafa (after having this patch applied):
|
||||
> A4 FETCH 1 (BODY.PEEK[HEADER.FIELDS (FROM FROM)])
|
||||
< * 1 FETCH (BODY[HEADER.FIELDS (FROM FROM)] {34}
|
||||
From: User1 <user1@domain.org>
|
||||
|
||||
)
|
||||
< A4 OK FETCH completed
|
||||
|
||||
Testing: Full IMAP dialog example from the client perspective (after this patch applied):
|
||||
< * OK [CAPABILITY IMAP4rev1 LITERAL+ AUTH=PLAIN] Zarafa IMAP gateway ready
|
||||
> A0 LOGIN robert robert
|
||||
< A0 OK [CAPABILITY IMAP4rev1 LITERAL+ CHILDREN XAOL-OPTION NAMESPACE QUOTA IDLE] LOGIN completed
|
||||
> A1 LIST "" INBOX
|
||||
< * LIST (\HasNoChildren) "/" "INBOX"
|
||||
< A1 OK LIST completed
|
||||
> A2 SELECT INBOX
|
||||
< * 2 EXISTS
|
||||
< * 0 RECENT
|
||||
< * FLAGS (\Seen \Draft \Deleted \Flagged \Answered $Forwarded)
|
||||
< * OK [PERMANENTFLAGS (\Seen \Draft \Deleted \Flagged \Answered $Forwarded)] Permanent flags
|
||||
< * OK [UIDNEXT 4343] Predicted next UID
|
||||
< * OK [UNSEEN 1] First unseen message
|
||||
< * OK [UIDVALIDITY 9313] UIDVALIDITY value
|
||||
< A2 OK [READ-WRITE] SELECT completed
|
||||
> A3 SEARCH UNSEEN ALL
|
||||
< * SEARCH 1 2
|
||||
< A3 OK SEARCH completed
|
||||
> A4 FETCH 1 (BODY.PEEK[HEADER.FIELDS (FROM FROM)])
|
||||
< * 1 FETCH (BODY[HEADER.FIELDS (FROM FROM)] {34}
|
||||
From: User1 <user1@domain.org>
|
||||
|
||||
)
|
||||
< A4 OK FETCH completed
|
||||
> A5 CLOSE
|
||||
< A5 OK CLOSE completed
|
||||
> A6 LOGOUT
|
||||
< * BYE Zarafa server logging out
|
||||
< A6 OK LOGOUT completed
|
||||
|
||||
IMPORTANT: This patch has been very carefully and extensively tested but it might not be
|
||||
perfect nevertheless as I am not really a C/C++ developer. There should be a code review
|
||||
by an experienced C/C++ developer before merging into Zarafa core.
|
||||
|
||||
Proposed to upstream via e-mail on Thu, 29 May 2014 01:55:35 +0200, patch was put into the
|
||||
upstream ticket https://jira.zarafa.com/browse/ZCP-12398.
|
||||
|
||||
--- zarafa-7.1.10/gateway/IMAP.cpp 2014-05-12 12:06:03.000000000 +0200
|
||||
+++ zarafa-7.1.10/gateway/IMAP.cpp.imap-fetch-body 2014-05-29 00:49:29.000000000 +0200
|
||||
@@ -5253,10 +5253,21 @@
|
||||
} else {
|
||||
vector<string> lstReqFields;
|
||||
vector<string>::iterator iterReqField;
|
||||
+ vector<string>::iterator r, w;
|
||||
+ set<string> tmpset;
|
||||
|
||||
// Get fields as vector
|
||||
lstReqFields = tokenize(strFields, " ");
|
||||
|
||||
+ // Make elements of vector unique
|
||||
+ for(r = lstReqFields.begin(), w = lstReqFields.begin(); r != lstReqFields.end(); ++r) {
|
||||
+ if(tmpset.insert(*r).second) {
|
||||
+ *w++ = *r;
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ lstReqFields.erase(w, lstReqFields.end());
|
||||
+
|
||||
// Output headers specified, in order of field set
|
||||
for(iterReqField = lstReqFields.begin(); iterReqField != lstReqFields.end(); iterReqField++) {
|
||||
for(iterField = lstFields.begin(); iterField != lstFields.end(); iterField++) {
|
||||
31
zarafa-7.1.10-kyotocabinet.patch
Normal file
31
zarafa-7.1.10-kyotocabinet.patch
Normal file
|
|
@ -0,0 +1,31 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for zarafa >= 7.1.10 which re-adds the ability to disable
|
||||
zarafa-search during build-time. This is e.g. required if CLucene and/or Kyotocabinet is unavailable or
|
||||
broken on the given system and/or architecture. Interestingly that patch is not new, I wrote these lines
|
||||
in 2012 the first time, proposed them as a patch to Zarafa and got merged. With a recent Zarafa release it
|
||||
seems they silently removed it again...
|
||||
|
||||
Proposed to upstream via e-mail on Fri, 11 Jul 2014 01:03:43 +0200, patch was put into the upstream ticket
|
||||
https://jira.zarafa.com/browse/ZCP-12463.
|
||||
|
||||
--- zarafa-7.1.10/ECtools/zarafa-search/Makefile.am 2014-05-23 15:03:49.000000000 +0200
|
||||
+++ zarafa-7.1.10/ECtools/zarafa-search/Makefile.am.kyotocabinet 2014-07-10 21:48:42.000000000 +0200
|
||||
@@ -1,4 +1,8 @@
|
||||
+if WITH_CLUCENE
|
||||
+if WITH_KYOTOCABINET
|
||||
bin_PROGRAMS = zarafa-search
|
||||
+endif
|
||||
+endif
|
||||
|
||||
AM_CPPFLAGS = ${ZCPPFLAGS} \
|
||||
-I${top_srcdir}/mapi4linux/include \
|
||||
--- zarafa-7.1.10/ECtools/zarafa-search/Makefile.in 2014-05-23 15:04:02.000000000 +0200
|
||||
+++ zarafa-7.1.10/ECtools/zarafa-search/Makefile.in.kyotocabinet 2014-07-10 21:49:16.000000000 +0200
|
||||
@@ -34,7 +34,7 @@
|
||||
POST_UNINSTALL = :
|
||||
build_triplet = @build@
|
||||
host_triplet = @host@
|
||||
-bin_PROGRAMS = zarafa-search$(EXEEXT)
|
||||
+@WITH_CLUCENE_TRUE@@WITH_KYOTOCABINET_TRUE@bin_PROGRAMS = zarafa-search$(EXEEXT)
|
||||
subdir = ECtools/zarafa-search
|
||||
DIST_COMMON = $(srcdir)/Makefile.am $(srcdir)/Makefile.in
|
||||
ACLOCAL_M4 = $(top_srcdir)/aclocal.m4
|
||||
39
zarafa-7.1.11-php-unbundle.patch
Normal file
39
zarafa-7.1.11-php-unbundle.patch
Normal file
|
|
@ -0,0 +1,39 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for zarafa >= 7.1.11 which removes the bundled PHP PEAR files/libraries
|
||||
and replaces them by files and libraries shipped by the distribution. From file server/PEAR/JSON.php only the function
|
||||
json_decode() is used, which can be provided by the php-json RPM package. The file server/PEAR/XML/Unserializer.php can
|
||||
be provided by the php-pear-XML-Serializer RPM package. The rest of the PHP PEAR files/libraries are only dependencies of
|
||||
these two files mentioned before (which are satisfied by the two newly required RPM packages).
|
||||
|
||||
--- zarafa-7.1.11.rsc/php-webclient-ajax/config.php.dist 2014-09-03 09:56:49.000000000 +0200
|
||||
+++ zarafa-7.1.11.rsc/php-webclient-ajax/config.php.dist.php-unbundle 2014-09-07 18:24:28.000000000 +0200
|
||||
@@ -56,7 +56,7 @@
|
||||
|
||||
// Define the server paths
|
||||
set_include_path(BASE_PATH. PATH_SEPARATOR .
|
||||
- BASE_PATH."server/PEAR/" . PATH_SEPARATOR .
|
||||
+ "/usr/share/pear/" . PATH_SEPARATOR .
|
||||
"/usr/share/php/");
|
||||
|
||||
// Define the relative URL for dialogs, this string is appended with HTTP GET arguments
|
||||
--- zarafa-7.1.11.rsc/php-webclient-ajax/zarafa.php 2014-09-03 10:45:06.000000000 +0200
|
||||
+++ zarafa-7.1.11.rsc/php-webclient-ajax/zarafa.php.php-unbundle 2014-09-07 18:21:36.000000000 +0200
|
||||
@@ -59,7 +59,7 @@
|
||||
include("config.php");
|
||||
include("defaults.php");
|
||||
include("server/util.php");
|
||||
- require("server/PEAR/JSON.php");
|
||||
+ @include("server/PEAR/JSON.php");
|
||||
|
||||
require("mapi/mapi.util.php");
|
||||
require("mapi/mapicode.php");
|
||||
--- zarafa-7.1.11.rsc/php-webclient-ajax/server/core/class.xmlparser.php 2014-09-03 10:45:06.000000000 +0200
|
||||
+++ zarafa-7.1.11.rsc/php-webclient-ajax/server/core/class.xmlparser.php.php-unbundle 2014-09-07 18:22:40.000000000 +0200
|
||||
@@ -50,7 +50,7 @@
|
||||
|
||||
?>
|
||||
<?php
|
||||
- require_once("server/PEAR/XML/Unserializer.php");
|
||||
+ require_once("XML/Unserializer.php");
|
||||
|
||||
/**
|
||||
* XML Parser
|
||||
91
zarafa-7.1.11-plaintext_auth_localhost.patch
Normal file
91
zarafa-7.1.11-plaintext_auth_localhost.patch
Normal file
|
|
@ -0,0 +1,91 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa <= 7.1.11 which enhances my earlier
|
||||
this year implemented "disable_plaintext_auth" feature (new option in Zarafa >= 7.1.10 to disable
|
||||
all plaintext authentications unless SSL/TLS is used), https://jira.zarafa.com/browse/ZCP-12142
|
||||
contains the initial implementation and a more verbose feature description.
|
||||
|
||||
Given that there are unfortunately still Zarafa systems around using saslauthd without pam_mapi
|
||||
but rimap instead the "disable_plaintext_auth" feature prevents them from enabling this option as
|
||||
rimap doesn't support SSL/TLS; https://jira.zarafa.com/browse/ZCP-12473 contains an example report
|
||||
by a Zarafa customer. Thus this patch adds an exception if the source IPv4 address is "127.0.0.1"
|
||||
and allows even if "disable_plaintext_auth" is enabled a cleartext authentication. It was a design
|
||||
decision to check only for 127.0.0.1/32 rather 127.0.0.0/8 because there seem to be systems where
|
||||
the loopback network except 127.0.0.1/32 is routable?!
|
||||
|
||||
Important: The technical implementation of this patch might be not perfect as I am not really a C/
|
||||
C++ developer. There should be a code review by an experienced C/C++ developer before merging into
|
||||
Zarafa core.
|
||||
|
||||
Proposed to upstream via e-mail on Thu, 16 Oct 2014 00:00:05 +0200, patch was put into the upstream
|
||||
ticket https://jira.zarafa.com/browse/ZCP-12473.
|
||||
|
||||
--- zarafa-7.1.11/gateway/IMAP.cpp 2014-09-03 10:45:06.000000000 +0200
|
||||
+++ zarafa-7.1.11/gateway/IMAP.cpp.plaintext_auth_localhost 2014-09-24 01:29:10.000000000 +0200
|
||||
@@ -757,7 +757,7 @@
|
||||
if (!lpChannel->UsingSsl() && lpChannel->sslctx())
|
||||
strCapabilities += " STARTTLS";
|
||||
|
||||
- if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0)
|
||||
+ if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0)
|
||||
strCapabilities += " LOGINDISABLED";
|
||||
else
|
||||
strCapabilities += " AUTH=PLAIN";
|
||||
@@ -923,7 +923,7 @@
|
||||
char *plain = lpConfig->GetSetting("disable_plaintext_auth");
|
||||
|
||||
// If plaintext authentication was disabled any authentication attempt must be refused very soon
|
||||
- if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0) {
|
||||
+ if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0) {
|
||||
hr2 = HrResponse(RESP_TAGGED_NO, strTag, "[PRIVACYREQUIRED] Plaintext authentication disallowed on non-secure "
|
||||
"(SSL/TLS) connections.");
|
||||
if (hr2 != hrSuccess)
|
||||
@@ -1002,7 +1002,7 @@
|
||||
}
|
||||
|
||||
// If plaintext authentication was disabled any login attempt must be refused very soon
|
||||
- if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0) {
|
||||
+ if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0) {
|
||||
hr2 = HrResponse(RESP_UNTAGGED, "BAD [ALERT] Plaintext authentication not allowed without SSL/TLS, but your client "
|
||||
"did it anyway. If anyone was listening, the password was exposed.");
|
||||
if (hr2 != hrSuccess)
|
||||
--- zarafa-7.1.11/gateway/POP3.cpp 2014-09-03 10:45:06.000000000 +0200
|
||||
+++ zarafa-7.1.11/gateway/POP3.cpp.plaintext_auth_localhost 2014-09-24 01:30:41.000000000 +0200
|
||||
@@ -320,7 +320,7 @@
|
||||
if (!lpChannel->UsingSsl() && lpChannel->sslctx())
|
||||
strCapabilities += "STLS\r\n";
|
||||
|
||||
- if (!(!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0))
|
||||
+ if (!(!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0))
|
||||
strCapabilities += "USER\r\n";
|
||||
}
|
||||
|
||||
@@ -402,7 +402,7 @@
|
||||
HRESULT hr = hrSuccess;
|
||||
char *plain = lpConfig->GetSetting("disable_plaintext_auth");
|
||||
|
||||
- if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0) {
|
||||
+ if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0) {
|
||||
hr = HrResponse(POP3_RESP_AUTH_ERROR, "Plaintext authentication disallowed on non-secure (SSL/TLS) connections");
|
||||
lpLogger->Log(EC_LOGLEVEL_ERROR, "Aborted login from %s with username \"%s\" (tried to use disallowed plaintext auth)",
|
||||
lpChannel->GetIPAddress().c_str(), strUser.c_str());
|
||||
@@ -431,7 +431,7 @@
|
||||
HRESULT hr = hrSuccess;
|
||||
char *plain = lpConfig->GetSetting("disable_plaintext_auth");
|
||||
|
||||
- if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0) {
|
||||
+ if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0) {
|
||||
hr = HrResponse(POP3_RESP_AUTH_ERROR, "Plaintext authentication disallowed on non-secure (SSL/TLS) connections");
|
||||
if(szUser.empty())
|
||||
lpLogger->Log(EC_LOGLEVEL_ERROR, "Aborted login from %s without username (tried to use disallowed "
|
||||
--- zarafa-7.1.11/doc/manual.xml 2014-09-03 09:56:28.000000000 +0200
|
||||
+++ zarafa-7.1.11/doc/manual.xml.plaintext_auth_localhost 2014-10-15 01:22:14.000000000 +0200
|
||||
@@ -8024,7 +8024,9 @@
|
||||
<term><option>disable_plaintext_auth</option></term>
|
||||
<listitem>
|
||||
<para>Disable all plaintext POP3 and IMAP authentications unless
|
||||
- SSL/TLS is used. Obviously this requires at least
|
||||
+ SSL/TLS is used (except for connections originating from
|
||||
+ <replaceable>127.0.0.1</replaceable> to allow saslauthd with rimap).
|
||||
+ Obviously enabling this configuration option requires at least
|
||||
<replaceable>ssl_private_key_file</replaceable> and
|
||||
<replaceable>ssl_certificate_file</replaceable> to take effect.</para>
|
||||
<para>Default: <replaceable>no</replaceable></para>
|
||||
85
zarafa-7.1.11-rpath.patch
Normal file
85
zarafa-7.1.11-rpath.patch
Normal file
|
|
@ -0,0 +1,85 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for zarafa >= 7.1.11, which works
|
||||
around the broken libtool of Debian. Multilib/multiarch systems like Fedora or Red
|
||||
Hat Enterprise Linux are using /usr/lib64 for 64 bit libraries and /usr/lib is used
|
||||
for 32 bit libraries. That allows to run 32 bit software on 64 bit systems. Debian
|
||||
systems only use /usr/lib which contains only 32 or 64 bit systems depending on the
|
||||
architecture.
|
||||
|
||||
Libtool hardcodes the runtime search path in a library (rpath), if the library that
|
||||
is used for linking is not within the default system library path. The result is,
|
||||
that if aclocal.m4/configure files are generated by a Debian system, but used on a
|
||||
Fedora or Red Hat Enterprise Linux 64 bit system for compiling, "-rpath /usr/lib64"
|
||||
makes it into the binary.
|
||||
|
||||
Fedora and EPEL (for Red Hat Enterprise Linux) do not allow binaries with rpath, as
|
||||
the Linux dynamic linker is usually smarter than the hardcoded path.
|
||||
|
||||
The fix for this issue is to add the optional /lib64 and /usr/lib64 directories at/
|
||||
within libtool in front of the regular /lib and /usr/lib directories at the system
|
||||
library path. These libtool information are hold in aclocal.m4, which is generated
|
||||
by running aclocal. As the content of aclocal.m4 is included into configure during
|
||||
a run of autoconf, aclocal.m4 needs to be modified within the upstream build system
|
||||
each time after a aclocal run - until Debian's libtool is fixed at Debian upstream.
|
||||
|
||||
Applying the fix is either possible by using the first hunk of the patch (second
|
||||
hunk is runtime-only if configure file has been already generated) or by running
|
||||
the following sed command after each aclocal run within the upstream build system:
|
||||
|
||||
sed -e 's@\(# Append ld.so.conf contents to the search path\)@# Add ABI-specific directories to the system library path.\n sys_lib_dlsearch_path_spec="/lib64 /usr/lib64 /lib /usr/lib"\n\n \1@' \
|
||||
-e 's@/lib /usr/lib $lt_ld_extra@$sys_lib_dlsearch_path_spec $lt_ld_extra@' -i zarafa-7.1.11/aclocal.m4
|
||||
|
||||
More information regarding this topic can be found for example at:
|
||||
|
||||
- http://osdir.com/ml/bug-libtool-gnu/2009-12/msg00034.html
|
||||
- http://lists.gnu.org/archive/html/libtool/2009-01/msg00039.html
|
||||
- http://thread.gmane.org/gmane.comp.gnu.libtool.general/8339/focus=8345
|
||||
|
||||
--- zarafa-7.1.11/aclocal.m4 2014-09-03 09:56:52.000000000 +0200
|
||||
+++ zarafa-7.1.11/aclocal.m4.rpath 2014-09-07 17:20:37.000000000 +0200
|
||||
@@ -2672,10 +2672,13 @@
|
||||
# before this can be enabled.
|
||||
hardcode_into_libs=yes
|
||||
|
||||
+ # Add ABI-specific directories to the system library path.
|
||||
+ sys_lib_dlsearch_path_spec="/lib64 /usr/lib64 /lib /usr/lib"
|
||||
+
|
||||
# Append ld.so.conf contents to the search path
|
||||
if test -f /etc/ld.so.conf; then
|
||||
lt_ld_extra=`awk '/^include / { system(sprintf("cd /etc; cat %s 2>/dev/null", \[$]2)); skip = 1; } { if (!skip) print \[$]0; skip = 0; }' < /etc/ld.so.conf | $SED -e 's/#.*//;/^[ ]*hwcap[ ]/d;s/[:, ]/ /g;s/=[^=]*$//;s/=[^= ]* / /g;s/"//g;/^$/d' | tr '\n' ' '`
|
||||
- sys_lib_dlsearch_path_spec="/lib /usr/lib $lt_ld_extra"
|
||||
+ sys_lib_dlsearch_path_spec="$sys_lib_dlsearch_path_spec $lt_ld_extra"
|
||||
fi
|
||||
|
||||
# We used to test for /lib/ld.so.1 and disable shared libraries on
|
||||
--- zarafa-7.1.11/configure 2014-09-03 09:56:53.000000000 +0200
|
||||
+++ zarafa-7.1.11/configure.rpath 2014-09-07 17:28:07.000000000 +0200
|
||||
@@ -10983,10 +10983,13 @@
|
||||
# before this can be enabled.
|
||||
hardcode_into_libs=yes
|
||||
|
||||
+ # Add ABI-specific directories to the system library path.
|
||||
+ sys_lib_dlsearch_path_spec="/lib64 /usr/lib64 /lib /usr/lib"
|
||||
+
|
||||
# Append ld.so.conf contents to the search path
|
||||
if test -f /etc/ld.so.conf; then
|
||||
lt_ld_extra=`awk '/^include / { system(sprintf("cd /etc; cat %s 2>/dev/null", \$2)); skip = 1; } { if (!skip) print \$0; skip = 0; }' < /etc/ld.so.conf | $SED -e 's/#.*//;/^[ ]*hwcap[ ]/d;s/[:, ]/ /g;s/=[^=]*$//;s/=[^= ]* / /g;s/"//g;/^$/d' | tr '\n' ' '`
|
||||
- sys_lib_dlsearch_path_spec="/lib /usr/lib $lt_ld_extra"
|
||||
+ sys_lib_dlsearch_path_spec="$sys_lib_dlsearch_path_spec $lt_ld_extra"
|
||||
fi
|
||||
|
||||
# We used to test for /lib/ld.so.1 and disable shared libraries on
|
||||
@@ -16025,10 +16028,13 @@
|
||||
# before this can be enabled.
|
||||
hardcode_into_libs=yes
|
||||
|
||||
+ # Add ABI-specific directories to the system library path.
|
||||
+ sys_lib_dlsearch_path_spec="/lib64 /usr/lib64 /lib /usr/lib"
|
||||
+
|
||||
# Append ld.so.conf contents to the search path
|
||||
if test -f /etc/ld.so.conf; then
|
||||
lt_ld_extra=`awk '/^include / { system(sprintf("cd /etc; cat %s 2>/dev/null", \$2)); skip = 1; } { if (!skip) print \$0; skip = 0; }' < /etc/ld.so.conf | $SED -e 's/#.*//;/^[ ]*hwcap[ ]/d;s/[:, ]/ /g;s/=[^=]*$//;s/=[^= ]* / /g;s/"//g;/^$/d' | tr '\n' ' '`
|
||||
- sys_lib_dlsearch_path_spec="/lib /usr/lib $lt_ld_extra"
|
||||
+ sys_lib_dlsearch_path_spec="$sys_lib_dlsearch_path_spec $lt_ld_extra"
|
||||
fi
|
||||
|
||||
# We used to test for /lib/ld.so.1 and disable shared libraries on
|
||||
32
zarafa-7.1.11-vacation-headers.patch
Normal file
32
zarafa-7.1.11-vacation-headers.patch
Normal file
|
|
@ -0,0 +1,32 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa >= 7.1.11 which restricts replies by
|
||||
zarafa-autorespond to automated processes and mailing lists according to RFC 5230, section 4.6. For
|
||||
further details please have a look to http://tools.ietf.org/html/rfc5230#page-8 as well.
|
||||
|
||||
Proposed to upstream via e-mail on Wed, 27 Aug 2014 23:30:31 +0200, patch was put into the upstream
|
||||
ticket https://jira.zarafa.com/browse/ZCP-12590.
|
||||
|
||||
--- zarafa-7.1.11/spooler/DAgent.cpp 2014-08-24 12:27:06.000000000 +0200
|
||||
+++ zarafa-7.1.11/spooler/DAgent.cpp.vacation-headers 2014-08-27 23:20:18.000000000 +0200
|
||||
@@ -1422,11 +1422,19 @@
|
||||
|
||||
// See if we're looping
|
||||
if (lpMessageProps[0].ulPropTag == PR_TRANSPORT_MESSAGE_HEADERS_A) {
|
||||
- if ( (strstr(lpMessageProps[0].Value.lpszA, "X-Zarafa-Vacation:") != NULL) ||
|
||||
- (strstr(lpMessageProps[0].Value.lpszA, "Auto-Submitted:") != NULL) ||
|
||||
- (strstr(lpMessageProps[0].Value.lpszA, "Precedence:") != NULL) )
|
||||
+ if ( (strstr(lpMessageProps[0].Value.lpszA, "X-Zarafa-Vacation:") != NULL) || // Zarafa
|
||||
+ (strstr(lpMessageProps[0].Value.lpszA, "Auto-Submitted:") != NULL) || // RFC 3834
|
||||
+ (strstr(lpMessageProps[0].Value.lpszA, "List-Id:") != NULL) || // RFC 2919
|
||||
+ (strstr(lpMessageProps[0].Value.lpszA, "List-Help:") != NULL) || // RFC 2369
|
||||
+ (strstr(lpMessageProps[0].Value.lpszA, "List-Subscribe:") != NULL) || // RFC 2369
|
||||
+ (strstr(lpMessageProps[0].Value.lpszA, "List-Unsubscribe:") != NULL) || // RFC 2369
|
||||
+ (strstr(lpMessageProps[0].Value.lpszA, "List-Post:") != NULL) || // RFC 2369
|
||||
+ (strstr(lpMessageProps[0].Value.lpszA, "List-Owner:") != NULL) || // RFC 2369
|
||||
+ (strstr(lpMessageProps[0].Value.lpszA, "List-Archive:") != NULL) || // RFC 2369
|
||||
+ (strstr(lpMessageProps[0].Value.lpszA, "Precedence:") != NULL) ) // RFC 3834
|
||||
// Vacation header already present, do not send vacation reply
|
||||
// Precedence: list/bulk/junk, do not reply to these mails
|
||||
+ // See also http://tools.ietf.org/html/rfc5230#page-8 for details
|
||||
goto exit;
|
||||
// save headers to a file so they can also be tested from the script we're runing
|
||||
snprintf(szTemp, PATH_MAX, "%s/autorespond-headers.XXXXXX", getenv("TEMP") == NULL ? "/tmp" : getenv("TEMP"));
|
||||
44
zarafa-7.1.11-vacation-headers2.patch
Normal file
44
zarafa-7.1.11-vacation-headers2.patch
Normal file
|
|
@ -0,0 +1,44 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa >= 7.1.11 which adds anti-loop headers
|
||||
for automatic responses by zarafa-autorespond for Microsoft Exchange and all vacation(1) compatible
|
||||
implementations.
|
||||
|
||||
For the Microsoft Exchange related part useful links are:
|
||||
- http://msdn.microsoft.com/en-us/library/ee219609(v=exchg.80).aspx
|
||||
- https://www.jitbit.com/maxblog/18-detecting-outlook-autoreplyout-of-office-emails-and-x-auto-response-suppress-header/
|
||||
|
||||
For vacation(1) compatible implementations useful links are:
|
||||
- http://www.daemon-systems.org/man/vacation.1.html
|
||||
- Book "sendmail" (written by Bryan Costales, Claus Assmann, George Jansen, Gregory Neil Shapiro), ISBN 0596555342
|
||||
|
||||
Proposed to upstream via e-mail on Wed, 27 Aug 2014 23:59:58 +0200, patch was put into the upstream
|
||||
ticket https://jira.zarafa.com/browse/ZCP-12591.
|
||||
|
||||
--- zarafa-7.1.11/spooler/DAgent.cpp 2014-08-24 12:27:06.000000000 +0200
|
||||
+++ zarafa-7.1.11/spooler/DAgent.cpp.vacation-headers2 2014-08-27 23:52:42.000000000 +0200
|
||||
@@ -1469,12 +1469,25 @@
|
||||
if (hr != hrSuccess)
|
||||
goto exit;
|
||||
|
||||
- // add anti-loop header
|
||||
+ // add anti-loop header for Zarafa
|
||||
snprintf(szHeader, PATH_MAX, "\nX-Zarafa-Vacation: autorespond");
|
||||
hr = WriteOrLogError(fd, szHeader, strlen(szHeader));
|
||||
if (hr != hrSuccess)
|
||||
goto exit;
|
||||
|
||||
+ // add anti-loop header for Exchange, see http://msdn.microsoft.com/en-us/library/ee219609(v=exchg.80).aspx
|
||||
+ snprintf(szHeader, PATH_MAX, "\nX-Auto-Response-Suppress: All");
|
||||
+ hr = WriteOrLogError(fd, szHeader, strlen(szHeader));
|
||||
+ if (hr != hrSuccess)
|
||||
+ goto exit;
|
||||
+
|
||||
+ // add anti-loop header for vacation(1) compatible implementations, see section 10.9 of book "sendmail" (written
|
||||
+ // by Bryan Costales, Claus Assmann, George Jansen, Gregory Neil Shapiro), ISBN 0596555342
|
||||
+ snprintf(szHeader, PATH_MAX, "\nPrecedence: bulk");
|
||||
+ hr = WriteOrLogError(fd, szHeader, strlen(szHeader));
|
||||
+ if (hr != hrSuccess)
|
||||
+ goto exit;
|
||||
+
|
||||
if (lpMessageProps[3].ulPropTag == PR_SUBJECT_W) {
|
||||
// convert as one string because of [] characters
|
||||
swprintf(szwHeader, PATH_MAX, L"%ls [%ls]", szSubject, lpMessageProps[3].Value.lpszW);
|
||||
21
zarafa-7.1.11-webaccess-fail2ban.patch
Normal file
21
zarafa-7.1.11-webaccess-fail2ban.patch
Normal file
|
|
@ -0,0 +1,21 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa <= 7.1.11 which logs authentication
|
||||
failures of Zarafa WebAccess into the error log of the webserver. This is basically a backport of
|
||||
https://jira.zarafa.com/browse/WA-6908 from WebApp to WebAccess. In difference to original patch
|
||||
there is no inappropriate space before a punctuation mark also known as "plenken".
|
||||
|
||||
Proposed to upstream via e-mail on Wed, 13 Aug 2014 22:56:09 +0200, initial patch was put into the
|
||||
upstream ticket https://jira.zarafa.com/browse/ZCP-12543.
|
||||
|
||||
--- zarafa-7.1.11/php-webclient-ajax/client/login.php 2014-09-03 10:45:06.000000000 +0200
|
||||
+++ zarafa-7.1.11/php-webclient-ajax/client/login.php 2015-02-18 01:08:13.000000000 +0100
|
||||
@@ -86,6 +86,10 @@
|
||||
switch($_SESSION["hresult"]){
|
||||
case MAPI_E_LOGON_FAILED:
|
||||
case MAPI_E_UNCONFIGURED:
|
||||
+ // Print error message to error_log of webserver
|
||||
+ if (!empty($_POST["username"])) {
|
||||
+ error_log('user '.$_POST["username"].': authentication failure at MAPI');
|
||||
+ }
|
||||
echo _("Logon failed, please check your name/password.");
|
||||
break;
|
||||
case MAPI_E_NETWORK_ERROR:
|
||||
38
zarafa-7.1.12-gsoap-sslv3.patch
Normal file
38
zarafa-7.1.12-gsoap-sslv3.patch
Normal file
|
|
@ -0,0 +1,38 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for zarafa >= 7.1.12 which disables weak SSLv2
|
||||
and SSLv3 protocols for encrypted SOAP connections between the Zarafa services. Until (including)
|
||||
the Zarafa 7.1.11 release the upstream default was to replace the SSLv23_method() that a pristine
|
||||
gSOAP library ships with the "safer" SSLv3_method(). With Zarafa 7.1.12 the SSLv3_method() was
|
||||
changed to SSLv23_method(). However this enables SSLv2 again (and still does not disable SSLv3).
|
||||
Thus this patch disables SSLv2 and SSLv3 as well as TLS compression explicitly; similar like the
|
||||
Zarafa Outlook Client which meanwhile only allows TLSv1.0 (and better).
|
||||
|
||||
Proposed to upstream via e-mail on Wed, 2 Apr 2014 11:35:40 +0200, initial patch was put into the
|
||||
upstream ticket Ticket#2014040210000266.
|
||||
|
||||
--- zarafa-7.1.12/provider/common/SOAPSock.cpp 2015-04-07 13:10:13.000000000 +0200
|
||||
+++ zarafa-7.1.12/provider/common/SOAPSock.cpp.gsoap-sslv3 2015-04-07 16:32:20.000000000 +0200
|
||||
@@ -157,9 +157,6 @@
|
||||
|
||||
lpCmd->endpoint = strdup(strServerPath.c_str());
|
||||
|
||||
- // default allow SSLv3, TLSv1, TLSv1.1 and TLSv1.2
|
||||
- lpCmd->soap->ctx = SSL_CTX_new(SSLv23_method());
|
||||
-
|
||||
#ifdef WITH_OPENSSL
|
||||
if (strncmp("https:", lpCmd->endpoint, 6) == 0) {
|
||||
// no need to add certificates to call, since soap also calls SSL_CTX_set_default_verify_paths()
|
||||
@@ -183,6 +180,14 @@
|
||||
lpCmd->soap->fsslverify = ssl_verify_callback_zarafa_silent;
|
||||
|
||||
SSL_CTX_set_verify(lpCmd->soap->ctx, SSL_VERIFY_PEER, lpCmd->soap->fsslverify);
|
||||
+
|
||||
+ // disable SSLv2 (according to RFC 6176) and SSLv3, leaving just TLSv1.0 (and better)
|
||||
+ SSL_CTX_set_options(lpCmd->soap->ctx, SSL_OP_NO_SSLv2 | SSL_OP_NO_SSLv3);
|
||||
+
|
||||
+#ifdef SSL_OP_NO_COMPRESSION
|
||||
+ // disable TLS compression to close the CRIME attack vector (also known as CVE-2012-4929)
|
||||
+ SSL_CTX_set_options(lpCmd->soap->ctx, SSL_OP_NO_COMPRESSION);
|
||||
+#endif
|
||||
}
|
||||
#endif
|
||||
|
||||
117
zarafa-7.1.12-licensed-archiver.patch
Normal file
117
zarafa-7.1.12-licensed-archiver.patch
Normal file
|
|
@ -0,0 +1,117 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa >= 7.1.12 which removes a wrongly introduced dependency to the
|
||||
proprietary zarafa-licensed. From Zarafa 7.1.11 to 7.1.12 there were some changes to the ValidateArchiverLicense() method;
|
||||
due to these changes rebuilding fails with "ArchiverSession.cpp:53:23: fatal error: ECLicense.h: No such file or directory"
|
||||
now. The patch just reverts the changes that were introduced from 7.1.11 to 7.1.12 to get the code building again.
|
||||
|
||||
--- zarafa-7.1.12/ECtools/zarafa-archiver/ArchiverSession.cpp 2015-04-07 13:10:12.000000000 +0200
|
||||
+++ zarafa-7.1.12/ECtools/zarafa-archiver/ArchiverSession.cpp.licensed-archiver 2015-04-07 15:55:07.000000000 +0200
|
||||
@@ -50,8 +50,6 @@
|
||||
#include "mapiext.h"
|
||||
#include "userutil.h"
|
||||
#include "ECMsgStore.h"
|
||||
-#include "ECLicense.h"
|
||||
-#include "ECMAPILicense.h"
|
||||
|
||||
typedef mapi_memory_ptr<ECSERVERLIST> ECServerListPtr;
|
||||
|
||||
@@ -879,38 +877,7 @@
|
||||
typedef mapi_object_ptr<ECMsgStore, IID_ECMsgStore> ECMsgStorePtr;
|
||||
|
||||
HRESULT ArchiverSession::ValidateArchiverLicense(bool attachnewuser /* = false*/) const {
|
||||
- IMsgStore *lpMsgStore = NULL;
|
||||
- IMsgStore *lpProxedMsgStore = NULL;
|
||||
- UnknownPtr ptrUnknown;
|
||||
- ECMsgStorePtr ptrOnlineStore;
|
||||
-
|
||||
- HRESULT hr = HrOpenDefaultStore(GetMAPISession(), MDB_WRITE | MDB_NO_DIALOG | MDB_NO_MAIL | MDB_TEMPORARY, &lpMsgStore);
|
||||
- if (hr != hrSuccess)
|
||||
- goto exit;
|
||||
-
|
||||
- hr = GetProxyStoreObject(lpMsgStore, &lpProxedMsgStore);
|
||||
- if (hr != hrSuccess)
|
||||
- goto exit;
|
||||
-
|
||||
- hr = lpProxedMsgStore->QueryInterface(IID_ECMsgStoreOnline, &ptrUnknown);
|
||||
- if (hr != hrSuccess)
|
||||
- goto exit;
|
||||
-
|
||||
- hr = ptrUnknown->QueryInterface(IID_ECMsgStore, &ptrOnlineStore);
|
||||
- if (hr != hrSuccess) {
|
||||
- m_lpLogger->Log(EC_LOGLEVEL_FATAL, "Unable to validate archived user count. Please check the archiver and licensed log for errors.");
|
||||
- hr = MAPI_E_NO_SUPPORT;
|
||||
- goto exit;
|
||||
- }
|
||||
-
|
||||
- hr = HrCheckLicense(&ptrOnlineStore->m_xMsgStore, SERVICE_TYPE_ARCHIVE, ZARAFA_ARCHIVE_DEFAULT);
|
||||
- if (hr != hrSuccess)
|
||||
- {
|
||||
- m_lpLogger->Log(EC_LOGLEVEL_FATAL, "No archiver license found.");
|
||||
- hr = MAPI_E_NO_SUPPORT;
|
||||
- }
|
||||
- else
|
||||
- {
|
||||
+ HRESULT hr;
|
||||
unsigned int ulArchivedUsers = 0;
|
||||
unsigned int ulMaxUsers = 0;
|
||||
|
||||
@@ -931,7 +898,6 @@
|
||||
} else if (ulArchivedUsers + 5 >= ulMaxUsers) { //@todo which warning limit?
|
||||
m_lpLogger->Log(EC_LOGLEVEL_FATAL, "You almost reached the archived user limit. Archived users %d of %d", ulArchivedUsers, ulMaxUsers);
|
||||
}
|
||||
- }
|
||||
|
||||
exit:
|
||||
return hr;
|
||||
--- zarafa-7.1.12/ECtools/zarafa-archiver/Makefile.am 2015-04-07 12:00:49.000000000 +0200
|
||||
+++ zarafa-7.1.12/ECtools/zarafa-archiver/Makefile.am.licensed-archiver 2015-04-07 15:59:42.000000000 +0200
|
||||
@@ -9,7 +9,6 @@
|
||||
-I${top_srcdir}/provider/client \
|
||||
-I${top_srcdir}/provider/include \
|
||||
-I${top_srcdir}/provider/soap \
|
||||
- -I${top_srcdir}/liblicense \
|
||||
-I${top_builddir}/provider/soap \
|
||||
$(GSOAP_CFLAGS) \
|
||||
-I${top_srcdir}/common \
|
||||
@@ -17,9 +16,7 @@
|
||||
|
||||
libarchiver_la_LIBADD = ${top_builddir}/mapi4linux/src/libmapi.la \
|
||||
${top_builddir}/common/libcommon_mapi.la \
|
||||
- ${top_builddir}/common/libcommon_util.la \
|
||||
- ${top_builddir}/liblicense/liblicense.la \
|
||||
- ${top_builddir}/liblicense/liblicense_mapi.la
|
||||
+ ${top_builddir}/common/libcommon_util.la
|
||||
|
||||
libarchiver_la_SOURCES = \
|
||||
ArchiverSession.cpp ArchiverSession.h ArchiverSessionPtr.h \
|
||||
--- zarafa-7.1.12/ECtools/zarafa-archiver/Makefile.in 2015-04-07 12:03:40.000000000 +0200
|
||||
+++ zarafa-7.1.12/ECtools/zarafa-archiver/Makefile.in.licensed-archiver 2015-04-07 16:00:15.000000000 +0200
|
||||
@@ -112,9 +112,7 @@
|
||||
libarchiver_la_DEPENDENCIES = \
|
||||
${top_builddir}/mapi4linux/src/libmapi.la \
|
||||
${top_builddir}/common/libcommon_mapi.la \
|
||||
- ${top_builddir}/common/libcommon_util.la \
|
||||
- ${top_builddir}/liblicense/liblicense.la \
|
||||
- ${top_builddir}/liblicense/liblicense_mapi.la
|
||||
+ ${top_builddir}/common/libcommon_util.la
|
||||
am_libarchiver_la_OBJECTS = ArchiverSession.lo archiver-common.lo \
|
||||
ArchiveManageImpl.lo ArchiveStateCollector.lo \
|
||||
ArchiveStateUpdater.lo ArchiveHelper.lo StoreHelper.lo \
|
||||
@@ -395,7 +393,6 @@
|
||||
-I${top_srcdir}/provider/client \
|
||||
-I${top_srcdir}/provider/include \
|
||||
-I${top_srcdir}/provider/soap \
|
||||
- -I${top_srcdir}/liblicense \
|
||||
-I${top_builddir}/provider/soap \
|
||||
$(GSOAP_CFLAGS) \
|
||||
-I${top_srcdir}/common \
|
||||
@@ -403,9 +400,7 @@
|
||||
|
||||
libarchiver_la_LIBADD = ${top_builddir}/mapi4linux/src/libmapi.la \
|
||||
${top_builddir}/common/libcommon_mapi.la \
|
||||
- ${top_builddir}/common/libcommon_util.la \
|
||||
- ${top_builddir}/liblicense/liblicense.la \
|
||||
- ${top_builddir}/liblicense/liblicense_mapi.la
|
||||
+ ${top_builddir}/common/libcommon_util.la
|
||||
|
||||
libarchiver_la_SOURCES = \
|
||||
ArchiverSession.cpp ArchiverSession.h ArchiverSessionPtr.h \
|
||||
85
zarafa-7.1.12-ssl_ecdhe.patch
Normal file
85
zarafa-7.1.12-ssl_ecdhe.patch
Normal file
|
|
@ -0,0 +1,85 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa >= 7.1.12 which implements ECDHE (elliptic
|
||||
curve diffie-hellman key exchange) support. http://en.wikipedia.org/wiki/Elliptic_curve_cryptography is
|
||||
providing more information about elliptic curves.
|
||||
|
||||
Suggestions for testing; run the following openssl(1) commands before and after applying this patch:
|
||||
|
||||
1. echo QUIT | openssl s_client -connect <host>:110 -starttls pop3 2>&1 | grep Cipher
|
||||
2. echo QUIT | openssl s_client -connect <host>:143 -starttls imap 2>&1 | grep Cipher
|
||||
3. echo QUIT | openssl s_client -connect <host>:237 2>&1 | grep Cipher
|
||||
4. echo QUIT | openssl s_client -connect <host>:993 2>&1 | grep Cipher
|
||||
5. echo QUIT | openssl s_client -connect <host>:995 2>&1 | grep Cipher
|
||||
6. echo QUIT | openssl s_client -connect <host>:8443 2>&1 | grep Cipher
|
||||
|
||||
After applying this patch the output should contain e.g. "ECDHE-RSA-AES256-GCM-SHA384" on a Red Hat
|
||||
Enterprise Linux 6.5 (only RHEL >= 6.5 has support for elliptic curve). Without this patch the result
|
||||
is e.g. "AES256-GCM-SHA384".
|
||||
|
||||
Important: The technical implementation of this patch might be not perfect as I am not really a C/C++
|
||||
developer. The logic and the implementation is heavily based on Sendmail. There should be a code review
|
||||
by an experienced C/C++ and OpenSSL developer before merging into Zarafa core.
|
||||
|
||||
This patch should be only applied after ZCP-12143 and its dependencies. However this patch might maybe
|
||||
not directly apply due to some previous merge issues as mentioned in Ticket#2014030810000131.
|
||||
|
||||
Proposed to upstream via e-mail on Mon, 14 Apr 2014 12:04:17 +0200, initial patch was put into upstream
|
||||
ticket https://jira.zarafa.com/browse/ZCP-12237.
|
||||
|
||||
--- zarafa-7.1.12/common/ECChannel.cpp 2015-04-07 13:10:12.000000000 +0200
|
||||
+++ zarafa-7.1.12/common/ECChannel.cpp.ssl_ecdhe 2015-04-07 17:12:15.000000000 +0200
|
||||
@@ -93,6 +93,9 @@
|
||||
char *ssl_ciphers = lpConfig->GetSetting("ssl_ciphers");
|
||||
char *ssl_name = NULL;
|
||||
int ssl_op = 0, ssl_include = 0, ssl_exclude = 0;
|
||||
+#if !defined(OPENSSL_NO_ECDH) && defined(NID_X9_62_prime256v1)
|
||||
+ EC_KEY *ecdh;
|
||||
+#endif
|
||||
|
||||
if (lpConfig == NULL) {
|
||||
lpLogger->Log(EC_LOGLEVEL_ERROR, "ECChannel::HrSetCtx(): invalid parameters");
|
||||
@@ -113,6 +116,16 @@
|
||||
|
||||
SSL_CTX_set_options(lpCTX, SSL_OP_ALL); // enable quirk and bug workarounds
|
||||
|
||||
+#if !defined(OPENSSL_NO_ECDH) && defined(NID_X9_62_prime256v1)
|
||||
+ ecdh = EC_KEY_new_by_curve_name(NID_X9_62_prime256v1);
|
||||
+
|
||||
+ if (ecdh != NULL) {
|
||||
+ SSL_CTX_set_options(lpCTX, SSL_OP_SINGLE_ECDH_USE);
|
||||
+ SSL_CTX_set_tmp_ecdh(lpCTX, ecdh);
|
||||
+ EC_KEY_free(ecdh);
|
||||
+ }
|
||||
+#endif
|
||||
+
|
||||
ssl_name = strtok(ssl_protocols, " ");
|
||||
while(ssl_name != NULL) {
|
||||
int ssl_proto = 0;
|
||||
--- zarafa-7.1.12/provider/server/ECSoapServerConnection.cpp 2015-04-07 13:10:13.000000000 +0200
|
||||
+++ zarafa-7.1.12/provider/server/ECSoapServerConnection.cpp.ssl_ecdhe 2015-04-07 17:13:23.000000000 +0200
|
||||
@@ -235,6 +235,9 @@
|
||||
char *server_ssl_ciphers = m_lpConfig->GetSetting("server_ssl_ciphers");
|
||||
char *ssl_name = NULL;
|
||||
int ssl_op = 0, ssl_include = 0, ssl_exclude = 0;
|
||||
+#if !defined(OPENSSL_NO_ECDH) && defined(NID_X9_62_prime256v1)
|
||||
+ EC_KEY *ecdh;
|
||||
+#endif
|
||||
|
||||
if(lpServerName == NULL) {
|
||||
free(server_ssl_ciphers);
|
||||
@@ -268,6 +271,16 @@
|
||||
|
||||
SSL_CTX_set_options(lpsSoap->ctx, SSL_OP_ALL);
|
||||
|
||||
+#if !defined(OPENSSL_NO_ECDH) && defined(NID_X9_62_prime256v1)
|
||||
+ ecdh = EC_KEY_new_by_curve_name(NID_X9_62_prime256v1);
|
||||
+
|
||||
+ if (ecdh != NULL) {
|
||||
+ SSL_CTX_set_options(lpsSoap->ctx, SSL_OP_SINGLE_ECDH_USE);
|
||||
+ SSL_CTX_set_tmp_ecdh(lpsSoap->ctx, ecdh);
|
||||
+ EC_KEY_free(ecdh);
|
||||
+ }
|
||||
+#endif
|
||||
+
|
||||
ssl_name = strtok(server_ssl_protocols, " ");
|
||||
while(ssl_name != NULL) {
|
||||
int ssl_proto = 0;
|
||||
123
zarafa-7.1.12-ssl_protocols_ciphers.patch
Normal file
123
zarafa-7.1.12-ssl_protocols_ciphers.patch
Normal file
|
|
@ -0,0 +1,123 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa >= 7.1.12 which re-adds the whole
|
||||
documentation that was initially proposed to upstream but lost when this feature was backported
|
||||
from Zarafa 7.2 to the 7.1 series.
|
||||
|
||||
Proposed to upstream via e-mail on Sat, 8 Mar 2014 14:30:29 +0100, initial patch was put into
|
||||
the upstream ticket https://jira.zarafa.com/browse/ZCP-12143.
|
||||
|
||||
--- zarafa-7.1.12/doc/manual.xml 2015-04-07 12:03:31.000000000 +0200
|
||||
+++ zarafa-7.1.12/doc/manual.xml.ssl_protocols_ciphers 2015-04-07 17:05:47.000000000 +0200
|
||||
@@ -4226,14 +4226,35 @@
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
- <term><option>server_ssl_enable_v2</option></term>
|
||||
+ <term><option>server_ssl_protocols</option></term>
|
||||
<listitem>
|
||||
- <para>Incoming SSL connections normally are v3.</para>
|
||||
- <para>Default: <replaceable>no</replaceable>
|
||||
- </para>
|
||||
+ <para>Disabled or enabled protocol names. Supported protocol names
|
||||
+ are <replaceable>SSLv2</replaceable>, <replaceable>SSLv3</replaceable>
|
||||
+ and <replaceable>TLSv1</replaceable>. If Zarafa was linked against
|
||||
+ OpenSSL 1.0.1 or later there is additional support for the new protocols
|
||||
+ <replaceable>TLSv1.1</replaceable> and <replaceable>TLSv1.2</replaceable>.
|
||||
+ To exclude both, SSLv2 and SSLv3 set <option>server_ssl_protocols</option>
|
||||
+ to <replaceable>!SSLv2 !SSLv3</replaceable>. SSLv2 is considered unsafe
|
||||
+ and these connections should not be accepted.</para>
|
||||
+ <para>Default: <replaceable>!SSLv2</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
+
|
||||
+ <varlistentry>
|
||||
+ <term><option>server_ssl_ciphers</option></term>
|
||||
+ <listitem>
|
||||
+ <para>SSL ciphers to use, set to <replaceable>ALL</replaceable> for backward compatibility.</para>
|
||||
+ <para>Default: <replaceable>ALL:!LOW:!SSLv2:!EXP:!aNULL</replaceable></para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
+ <varlistentry>
|
||||
+ <term><option>server_ssl_prefer_server_ciphers</option></term>
|
||||
+ <listitem>
|
||||
+ <para>Prefer the server's order of SSL ciphers over client's.</para>
|
||||
+ <para>Default: <replaceable>no</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
</variablelist>
|
||||
</refsection>
|
||||
|
||||
@@ -8090,11 +8111,32 @@
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
- <term><option>ssl_enable_v2</option></term>
|
||||
+ <term><option>ssl_protocols</option></term>
|
||||
+ <listitem>
|
||||
+ <para>Disabled or enabled protocol names. Supported protocol names
|
||||
+ are <replaceable>SSLv2</replaceable>, <replaceable>SSLv3</replaceable>
|
||||
+ and <replaceable>TLSv1</replaceable>. If Zarafa was linked against
|
||||
+ OpenSSL 1.0.1 or later there is additional support for the new protocols
|
||||
+ <replaceable>TLSv1.1</replaceable> and <replaceable>TLSv1.2</replaceable>.
|
||||
+ To exclude both, SSLv2 and SSLv3 set <option>ssl_protocols</option>
|
||||
+ to <replaceable>!SSLv2 !SSLv3</replaceable>. SSLv2 is considered unsafe
|
||||
+ and these connections should not be accepted.</para>
|
||||
+ <para>Default: <replaceable>!SSLv2</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
+
|
||||
+ <varlistentry>
|
||||
+ <term><option>ssl_ciphers</option></term>
|
||||
<listitem>
|
||||
- <para>Accept SSLv2 only connections. SSLv2 is considered
|
||||
- unsafe, and these connections should not be
|
||||
- accepted.</para>
|
||||
+ <para>SSL ciphers to use, set to <replaceable>ALL</replaceable> for backward compatibility.</para>
|
||||
+ <para>Default: <replaceable>ALL:!LOW:!SSLv2:!EXP:!aNULL</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
+
|
||||
+ <varlistentry>
|
||||
+ <term><option>ssl_prefer_server_ciphers</option></term>
|
||||
+ <listitem>
|
||||
+ <para>Prefer the server's order of SSL ciphers over client's.</para>
|
||||
<para>Default: <replaceable>no</replaceable></para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
@@ -10091,11 +10133,32 @@
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
- <term><option>ssl_enable_v2</option></term>
|
||||
+ <term><option>ssl_protocols</option></term>
|
||||
+ <listitem>
|
||||
+ <para>Disabled or enabled protocol names. Supported protocol names
|
||||
+ are <replaceable>SSLv2</replaceable>, <replaceable>SSLv3</replaceable>
|
||||
+ and <replaceable>TLSv1</replaceable>. If Zarafa was linked against
|
||||
+ OpenSSL 1.0.1 or later there is additional support for the new protocols
|
||||
+ <replaceable>TLSv1.1</replaceable> and <replaceable>TLSv1.2</replaceable>.
|
||||
+ To exclude both, SSLv2 and SSLv3 set <option>ssl_protocols</option>
|
||||
+ to <replaceable>!SSLv2 !SSLv3</replaceable>. SSLv2 is considered unsafe
|
||||
+ and these connections should not be accepted.</para>
|
||||
+ <para>Default: <replaceable>!SSLv2</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
+
|
||||
+ <varlistentry>
|
||||
+ <term><option>ssl_ciphers</option></term>
|
||||
+ <listitem>
|
||||
+ <para>SSL ciphers to use, set to <replaceable>ALL</replaceable> for backward compatibility.</para>
|
||||
+ <para>Default: <replaceable>ALL:!LOW:!SSLv2:!EXP:!aNULL</replaceable></para>
|
||||
+ </listitem>
|
||||
+ </varlistentry>
|
||||
+
|
||||
+ <varlistentry>
|
||||
+ <term><option>ssl_prefer_server_ciphers</option></term>
|
||||
<listitem>
|
||||
- <para>Accept SSLv2 only connections. SSLv2 is considered
|
||||
- unsafe, and these connections should not be
|
||||
- accepted.</para>
|
||||
+ <para>Prefer the server's order of SSL ciphers over client's.</para>
|
||||
<para>Default: <replaceable>no</replaceable></para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
56
zarafa-7.1.12-upgrade-lock.patch
Normal file
56
zarafa-7.1.12-upgrade-lock.patch
Normal file
|
|
@ -0,0 +1,56 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa 7.1.12 which backports the fix for
|
||||
CVE-2015-3436. Guido Günther detected and reported that replacing "/tmp/zarafa-upgrade-lock" by
|
||||
a symlink makes the zarafa-server process following that symlink and thus allows to overwrite
|
||||
arbitrary files in the filesystem (assuming zarafa-server runs as root which is not the case by
|
||||
default at Fedora, but it is the upstream default). One just needs write permissions in /tmp and
|
||||
wait until the zarafa-server is restarted. https://bugzilla.redhat.com/show_bug.cgi?id=1222151
|
||||
contains further information. The difference between this backport and the original diff is that
|
||||
the log levels were reworked from Zarafa 7.1.x to 7.2.x (which this backport takes care of).
|
||||
|
||||
--- zarafa-7.1.12/provider/server/ECServer.cpp 2015-05-08 15:09:05.000000000 +0200
|
||||
+++ zarafa-7.1.12/provider/server/ECServer.cpp.upgrade-lock 2015-05-18 23:05:00.000000000 +0200
|
||||
@@ -101,6 +101,8 @@
|
||||
// have to go with the safe value which is for 64bit.
|
||||
#define MYSQL_MIN_THREAD_STACK (256*1024)
|
||||
|
||||
+const char upgrade_lock_file[] = "/tmp/zarafa-upgrade-lock";
|
||||
+
|
||||
extern ECSessionManager* g_lpSessionManager;
|
||||
|
||||
// scheduled functions
|
||||
@@ -832,7 +834,7 @@
|
||||
// SIGSEGV backtrace support
|
||||
stack_t st = {0};
|
||||
struct sigaction act = {{0}};
|
||||
- FILE *tmplock = NULL;
|
||||
+ int tmplock = -1;
|
||||
struct stat dir = {0};
|
||||
struct passwd *runasUser = NULL;
|
||||
|
||||
@@ -1288,8 +1290,9 @@
|
||||
m_bDatabaseUpdateIgnoreSignals = true;
|
||||
|
||||
// add a lock file to disable the /etc/init.d scripts
|
||||
- tmplock = fopen("/tmp/zarafa-upgrade-lock","w");
|
||||
- if (!tmplock)
|
||||
+ tmplock = open(upgrade_lock_file, O_CREAT | O_EXCL, S_IRUSR | S_IWUSR);
|
||||
+
|
||||
+ if (tmplock == -1)
|
||||
g_lpLogger->Log(EC_LOGLEVEL_FATAL, "WARNING: Unable to place upgrade lockfile: %s", strerror(errno));
|
||||
|
||||
#ifdef EMBEDDED_MYSQL
|
||||
@@ -1314,9 +1317,11 @@
|
||||
er = lpDatabaseFactory->UpdateDatabase(m_bForceDatabaseUpdate, dbError);
|
||||
|
||||
// remove lock file
|
||||
- if (tmplock) {
|
||||
- fclose(tmplock);
|
||||
- unlink("/tmp/zarafa-upgrade-lock");
|
||||
+ if (tmplock != -1) {
|
||||
+ if (unlink(upgrade_lock_file) == -1)
|
||||
+ g_lpLogger->Log(EC_LOGLEVEL_FATAL, "WARNING: Unable to delete upgrade lockfile (%s): %s", upgrade_lock_file, strerror(errno));
|
||||
+
|
||||
+ close(tmplock);
|
||||
}
|
||||
|
||||
if(er == ZARAFA_E_INVALID_VERSION) {
|
||||
58
zarafa-7.1.12-webaccess-mcrypt.patch
Normal file
58
zarafa-7.1.12-webaccess-mcrypt.patch
Normal file
|
|
@ -0,0 +1,58 @@
|
|||
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa >= 7.1.12 which fixes the fix that fixes CVE-2014-0103. Ush,
|
||||
that was complicated, so: CVE-2014-0103 exists because Zarafa WebAccess < 7.1.10 and Zarafa WebApp < 1.6 storing passwords
|
||||
in cleartext on server (in the PHP session). Zarafa solved this flaw by using openssl_encrypt() and openssl_decrypt() from
|
||||
PHP's OpenSSL bindings. However these functions are only available in PHP 5.3 or later. Without this patch suggestion, any
|
||||
older but still supported Linux distribution like Red Hat Enterprise Linux 5 or SuSE Linux Enterprise Server 10 (which are
|
||||
both shipping PHP < 5.3 by default) would still be left vulnerable.
|
||||
|
||||
Given that I am personally more a fan of OpenSSL rather mcrypt, I am not absolutely sure if this implementation is really
|
||||
correct even it works fine on my test system. So please explicitly review this code to avoid introducing another security
|
||||
flaw by trying to fix one! A thing that I generally question for myself is the usage of "des-ede3-cbc"/"MCRYPT_TRIPLEDES"
|
||||
instead of e.g. MCRYPT_RIJNDAEL_128. Given that this decision was initially made by Zarafa I am just following that here.
|
||||
|
||||
Important: To get this patch really powerful the install-time requirement needs to be adapted like this (this example is
|
||||
based on Fedora's build system so the macros %{?rhel} and %{?fedora} might not exist at Zarafa but need to be replaced by
|
||||
other macros):
|
||||
|
||||
%if 0%{?rhel}%{?fedora} < 6
|
||||
Requires: php-mcrypt
|
||||
%else
|
||||
Requires: php-openssl
|
||||
%endif
|
||||
|
||||
This requires php-openssl (provided by php-common) on RHEL 6 (and later) and php-mcrypt (separate package) before RHEL 6.
|
||||
|
||||
Proposed to upstream via e-mail on Thu, 5 Jun 2014 00:24:32 +0200, initial patch was put into the (non-disclosed) upstream
|
||||
ticket https://jira.zarafa.com/browse/ZCP-12407.
|
||||
|
||||
--- zarafa-7.1.12/php-webclient-ajax/index.php 2015-04-07 13:10:13.000000000 +0200
|
||||
+++ zarafa-7.1.12/php-webclient-ajax/index.php.webaccess-mcrypt 2015-04-07 16:22:23.000000000 +0200
|
||||
@@ -135,6 +135,8 @@
|
||||
} else {
|
||||
$_SESSION['password'] = openssl_encrypt($password,"des-ede3-cbc",PASSWORD_KEY,0,PASSWORD_IV);
|
||||
}
|
||||
+ } elseif(function_exists("mcrypt_encrypt")) {
|
||||
+ $_SESSION['password'] = base64_encode(mcrypt_encrypt(MCRYPT_TRIPLEDES, PASSWORD_KEY, $password, MCRYPT_MODE_CBC, PASSWORD_IV));
|
||||
} else {
|
||||
$_SESSION["password"] = $password;
|
||||
}
|
||||
--- zarafa-7.1.12/php-webclient-ajax/server/core/class.mapisession.php 2015-04-07 13:10:14.000000000 +0200
|
||||
+++ zarafa-7.1.12/php-webclient-ajax/server/core/class.mapisession.php.webaccess-mcrypt 2015-04-07 16:23:58.000000000 +0200
|
||||
@@ -132,6 +132,8 @@
|
||||
} else {
|
||||
$password = openssl_decrypt($password,"des-ede3-cbc",PASSWORD_KEY,0,PASSWORD_IV);
|
||||
}
|
||||
+ } elseif(function_exists("mcrypt_decrypt")) {
|
||||
+ $password = rtrim(mcrypt_decrypt(MCRYPT_TRIPLEDES, PASSWORD_KEY, base64_decode($password), MCRYPT_MODE_CBC, PASSWORD_IV), "\0");
|
||||
}
|
||||
// logon
|
||||
$this->session = mapi_logon_zarafa($username, $password, $server, $sslcert_file, $sslcert_pass);
|
||||
@@ -144,6 +146,8 @@
|
||||
} else {
|
||||
$password = openssl_encrypt($password,"des-ede3-cbc",PASSWORD_KEY,0,PASSWORD_IV);
|
||||
}
|
||||
+ } elseif(function_exists("mcrypt_encrypt")) {
|
||||
+ $password = base64_encode(mcrypt_encrypt(MCRYPT_TRIPLEDES, PASSWORD_KEY, $password, MCRYPT_MODE_CBC, PASSWORD_IV));
|
||||
}
|
||||
|
||||
if ($result == NOERROR && $this->session !== false){
|
||||
48
zarafa-webaccess.conf
Normal file
48
zarafa-webaccess.conf
Normal file
|
|
@ -0,0 +1,48 @@
|
|||
#
|
||||
# Zarafa Webaccess featuring a 'Look & Feel' similar to Outlook
|
||||
#
|
||||
|
||||
Alias /webaccess /usr/share/zarafa-webaccess/
|
||||
|
||||
# Following Apache and PHP settings need to be set to work correct
|
||||
#
|
||||
<Directory /usr/share/zarafa-webaccess/>
|
||||
# Some apache settings
|
||||
DirectoryIndex index.php
|
||||
Options -Indexes +FollowSymLinks
|
||||
|
||||
<IfModule mod_authz_core.c>
|
||||
# Apache 2.4
|
||||
Require all granted
|
||||
</IfModule>
|
||||
<IfModule !mod_authz_core.c>
|
||||
# Apache 2.2
|
||||
Order allow,deny
|
||||
Allow from all
|
||||
</IfModule>
|
||||
|
||||
# Register globals must be off
|
||||
php_flag register_globals off
|
||||
|
||||
# Magic quotes must be off
|
||||
php_flag magic_quotes_gpc off
|
||||
php_flag magic_quotes_runtime off
|
||||
|
||||
# The maximum POST limit. To upload large files, this value must
|
||||
# be larger than upload_max_filesize.
|
||||
php_value post_max_size 31M
|
||||
php_value upload_max_filesize 30M
|
||||
|
||||
# Short open tags must be on
|
||||
php_flag short_open_tag on
|
||||
|
||||
# Uncomment to enhance security of WebAccess by restricting cookies
|
||||
# to only be provided over HTTPS connections
|
||||
# php_flag session.cookie_secure on
|
||||
# php_flag session.cookie_httponly on
|
||||
|
||||
# Uncomment for debugging purposes only. Make sure Apache/PHP can
|
||||
# write to this file or no errors will be logged!
|
||||
# php_flag log_errors on
|
||||
# php_value error_log /var/lib/zarafa-webaccess/error_log
|
||||
</Directory>
|
||||
2
zarafa.ini
Normal file
2
zarafa.ini
Normal file
|
|
@ -0,0 +1,2 @@
|
|||
; Enable Zarafa mapi extension module
|
||||
extension=mapi.so
|
||||
100
zarafa.logrotate
Normal file
100
zarafa.logrotate
Normal file
|
|
@ -0,0 +1,100 @@
|
|||
/var/log/zarafa/archiver.log {
|
||||
weekly
|
||||
missingok
|
||||
rotate 52
|
||||
compress
|
||||
delaycompress
|
||||
notifempty
|
||||
create 0644 zarafa zarafa
|
||||
}
|
||||
|
||||
/var/log/zarafa/dagent.log {
|
||||
weekly
|
||||
missingok
|
||||
rotate 52
|
||||
compress
|
||||
delaycompress
|
||||
notifempty
|
||||
postrotate
|
||||
killall -HUP zarafa-dagent 2> /dev/null || true
|
||||
endscript
|
||||
create 0644 zarafa zarafa
|
||||
}
|
||||
|
||||
/var/log/zarafa/gateway.log {
|
||||
weekly
|
||||
missingok
|
||||
rotate 52
|
||||
compress
|
||||
delaycompress
|
||||
notifempty
|
||||
postrotate
|
||||
killall -HUP zarafa-gateway 2> /dev/null || true
|
||||
endscript
|
||||
create 0644 zarafa zarafa
|
||||
}
|
||||
|
||||
/var/log/zarafa/ical.log {
|
||||
weekly
|
||||
missingok
|
||||
rotate 52
|
||||
compress
|
||||
delaycompress
|
||||
notifempty
|
||||
postrotate
|
||||
killall -HUP zarafa-ical 2> /dev/null || true
|
||||
endscript
|
||||
create 0644 zarafa zarafa
|
||||
}
|
||||
|
||||
/var/log/zarafa/indexer.log {
|
||||
weekly
|
||||
missingok
|
||||
rotate 52
|
||||
compress
|
||||
delaycompress
|
||||
notifempty
|
||||
postrotate
|
||||
killall -HUP zarafa-indexer 2> /dev/null || true
|
||||
endscript
|
||||
create 0644 zarafa zarafa
|
||||
}
|
||||
|
||||
/var/log/zarafa/monitor.log {
|
||||
weekly
|
||||
missingok
|
||||
rotate 52
|
||||
compress
|
||||
delaycompress
|
||||
notifempty
|
||||
postrotate
|
||||
killall -HUP zarafa-monitor 2> /dev/null || true
|
||||
endscript
|
||||
create 0644 zarafa zarafa
|
||||
}
|
||||
|
||||
/var/log/zarafa/server.log /var/log/zarafa/audit.log {
|
||||
weekly
|
||||
missingok
|
||||
rotate 52
|
||||
compress
|
||||
delaycompress
|
||||
notifempty
|
||||
postrotate
|
||||
killall -HUP zarafa-server 2> /dev/null || true
|
||||
endscript
|
||||
create 0644 zarafa zarafa
|
||||
}
|
||||
|
||||
/var/log/zarafa/spooler.log {
|
||||
weekly
|
||||
missingok
|
||||
rotate 52
|
||||
compress
|
||||
delaycompress
|
||||
notifempty
|
||||
postrotate
|
||||
killall -HUP zarafa-spooler 2> /dev/null || true
|
||||
endscript
|
||||
create 0644 zarafa zarafa
|
||||
}
|
||||
1165
zarafa.spec
Normal file
1165
zarafa.spec
Normal file
File diff suppressed because it is too large
Load diff
Loading…
Add table
Add a link
Reference in a new issue