Compare commits

..

12 commits

22 changed files with 2249 additions and 1 deletions

1
.gitignore vendored Normal file
View file

@ -0,0 +1 @@
zcp-7.?.*.tar.gz

View file

@ -1 +0,0 @@
Package is retired

1
sources Normal file
View file

@ -0,0 +1 @@
4744f5c09ca082ea23cd28ea1d10941f zcp-7.1.12.tar.gz

View file

@ -0,0 +1,19 @@
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa <= 7.1.10 which fixes the RFC-
violating reply of the Zarafa IMAP gateway in response to a failed SEARCH CHARSET request.
This is documented at http://tools.ietf.org/html/rfc3501#page-64: "BADCHARSET: Optionally
followed by a parenthesized list of charsets. [...]". This patch adds missing parenthesis.
Proposed to upstream via e-mail on Sun, 27 Jul 2014 23:58:01 +0200, patch was put into the
upstream ticket https://jira.zarafa.com/browse/ZCP-12504.
--- zarafa-7.1.10/gateway/IMAP.cpp 2014-05-23 15:56:37.000000000 +0200
+++ zarafa-7.1.10/gateway/IMAP.cpp.imap-badcharset 2014-07-27 23:42:30.000000000 +0200
@@ -2409,7 +2409,7 @@
if (lstSearchCriteria[1] != "WINDOWS-1252") {
iconv = new ECIConv("windows-1252", lstSearchCriteria[1]);
if (!iconv->canConvert()) {
- hr2 = HrResponse(RESP_TAGGED_NO, strTag, "[BADCHARSET WINDOWS-1252] "+strMode+"SEARCH charset not supported");
+ hr2 = HrResponse(RESP_TAGGED_NO, strTag, "[BADCHARSET (WINDOWS-1252)] "+strMode+"SEARCH charset not supported");
hr = MAPI_E_CALL_FAILED;
goto exit;
}

View file

@ -0,0 +1,93 @@
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa <= 7.1.10 which fixes the RFC-
violating reply of the Zarafa IMAP gateway in response to a body fetch request. This is
documented at http://tools.ietf.org/html/rfc3501#page-55. Additionally this has been also
compared with the Dovecot IMAP server as a nearly (or even de facto) IMAP server reference
implementation. Please note that this is NOT a duplicate of ZCP-11590/ZCP-11739/ZCP-12365!
Wrong behaviour of Zarafa <= 7.1.10rc1-44973 (without this patch):
> A4 FETCH 1 (BODY.PEEK[HEADER.FIELDS (FROM FROM)])
< * 1 FETCH (BODY[HEADER.FIELDS (FROM FROM)] {66}
From: User1 <user1@domain.org>
From: User1 <user1@domain.org>
)
< A4 OK FETCH completed
Comparison with IMAP server Dovecot 2.2.13:
> A4 FETCH 1 (BODY.PEEK[HEADER.FIELDS (FROM FROM)])
< * 1 FETCH (BODY[HEADER.FIELDS (FROM FROM)] {34}
From: User1 <user1@domain.org>
)
< A4 OK Fetch completed.
Correct behaviour of Zarafa (after having this patch applied):
> A4 FETCH 1 (BODY.PEEK[HEADER.FIELDS (FROM FROM)])
< * 1 FETCH (BODY[HEADER.FIELDS (FROM FROM)] {34}
From: User1 <user1@domain.org>
)
< A4 OK FETCH completed
Testing: Full IMAP dialog example from the client perspective (after this patch applied):
< * OK [CAPABILITY IMAP4rev1 LITERAL+ AUTH=PLAIN] Zarafa IMAP gateway ready
> A0 LOGIN robert robert
< A0 OK [CAPABILITY IMAP4rev1 LITERAL+ CHILDREN XAOL-OPTION NAMESPACE QUOTA IDLE] LOGIN completed
> A1 LIST "" INBOX
< * LIST (\HasNoChildren) "/" "INBOX"
< A1 OK LIST completed
> A2 SELECT INBOX
< * 2 EXISTS
< * 0 RECENT
< * FLAGS (\Seen \Draft \Deleted \Flagged \Answered $Forwarded)
< * OK [PERMANENTFLAGS (\Seen \Draft \Deleted \Flagged \Answered $Forwarded)] Permanent flags
< * OK [UIDNEXT 4343] Predicted next UID
< * OK [UNSEEN 1] First unseen message
< * OK [UIDVALIDITY 9313] UIDVALIDITY value
< A2 OK [READ-WRITE] SELECT completed
> A3 SEARCH UNSEEN ALL
< * SEARCH 1 2
< A3 OK SEARCH completed
> A4 FETCH 1 (BODY.PEEK[HEADER.FIELDS (FROM FROM)])
< * 1 FETCH (BODY[HEADER.FIELDS (FROM FROM)] {34}
From: User1 <user1@domain.org>
)
< A4 OK FETCH completed
> A5 CLOSE
< A5 OK CLOSE completed
> A6 LOGOUT
< * BYE Zarafa server logging out
< A6 OK LOGOUT completed
IMPORTANT: This patch has been very carefully and extensively tested but it might not be
perfect nevertheless as I am not really a C/C++ developer. There should be a code review
by an experienced C/C++ developer before merging into Zarafa core.
Proposed to upstream via e-mail on Thu, 29 May 2014 01:55:35 +0200, patch was put into the
upstream ticket https://jira.zarafa.com/browse/ZCP-12398.
--- zarafa-7.1.10/gateway/IMAP.cpp 2014-05-12 12:06:03.000000000 +0200
+++ zarafa-7.1.10/gateway/IMAP.cpp.imap-fetch-body 2014-05-29 00:49:29.000000000 +0200
@@ -5253,10 +5253,21 @@
} else {
vector<string> lstReqFields;
vector<string>::iterator iterReqField;
+ vector<string>::iterator r, w;
+ set<string> tmpset;
// Get fields as vector
lstReqFields = tokenize(strFields, " ");
+ // Make elements of vector unique
+ for(r = lstReqFields.begin(), w = lstReqFields.begin(); r != lstReqFields.end(); ++r) {
+ if(tmpset.insert(*r).second) {
+ *w++ = *r;
+ }
+ }
+
+ lstReqFields.erase(w, lstReqFields.end());
+
// Output headers specified, in order of field set
for(iterReqField = lstReqFields.begin(); iterReqField != lstReqFields.end(); iterReqField++) {
for(iterField = lstFields.begin(); iterField != lstFields.end(); iterField++) {

View file

@ -0,0 +1,31 @@
Patch by Robert Scheck <robert@fedoraproject.org> for zarafa >= 7.1.10 which re-adds the ability to disable
zarafa-search during build-time. This is e.g. required if CLucene and/or Kyotocabinet is unavailable or
broken on the given system and/or architecture. Interestingly that patch is not new, I wrote these lines
in 2012 the first time, proposed them as a patch to Zarafa and got merged. With a recent Zarafa release it
seems they silently removed it again...
Proposed to upstream via e-mail on Fri, 11 Jul 2014 01:03:43 +0200, patch was put into the upstream ticket
https://jira.zarafa.com/browse/ZCP-12463.
--- zarafa-7.1.10/ECtools/zarafa-search/Makefile.am 2014-05-23 15:03:49.000000000 +0200
+++ zarafa-7.1.10/ECtools/zarafa-search/Makefile.am.kyotocabinet 2014-07-10 21:48:42.000000000 +0200
@@ -1,4 +1,8 @@
+if WITH_CLUCENE
+if WITH_KYOTOCABINET
bin_PROGRAMS = zarafa-search
+endif
+endif
AM_CPPFLAGS = ${ZCPPFLAGS} \
-I${top_srcdir}/mapi4linux/include \
--- zarafa-7.1.10/ECtools/zarafa-search/Makefile.in 2014-05-23 15:04:02.000000000 +0200
+++ zarafa-7.1.10/ECtools/zarafa-search/Makefile.in.kyotocabinet 2014-07-10 21:49:16.000000000 +0200
@@ -34,7 +34,7 @@
POST_UNINSTALL = :
build_triplet = @build@
host_triplet = @host@
-bin_PROGRAMS = zarafa-search$(EXEEXT)
+@WITH_CLUCENE_TRUE@@WITH_KYOTOCABINET_TRUE@bin_PROGRAMS = zarafa-search$(EXEEXT)
subdir = ECtools/zarafa-search
DIST_COMMON = $(srcdir)/Makefile.am $(srcdir)/Makefile.in
ACLOCAL_M4 = $(top_srcdir)/aclocal.m4

View file

@ -0,0 +1,39 @@
Patch by Robert Scheck <robert@fedoraproject.org> for zarafa >= 7.1.11 which removes the bundled PHP PEAR files/libraries
and replaces them by files and libraries shipped by the distribution. From file server/PEAR/JSON.php only the function
json_decode() is used, which can be provided by the php-json RPM package. The file server/PEAR/XML/Unserializer.php can
be provided by the php-pear-XML-Serializer RPM package. The rest of the PHP PEAR files/libraries are only dependencies of
these two files mentioned before (which are satisfied by the two newly required RPM packages).
--- zarafa-7.1.11.rsc/php-webclient-ajax/config.php.dist 2014-09-03 09:56:49.000000000 +0200
+++ zarafa-7.1.11.rsc/php-webclient-ajax/config.php.dist.php-unbundle 2014-09-07 18:24:28.000000000 +0200
@@ -56,7 +56,7 @@
// Define the server paths
set_include_path(BASE_PATH. PATH_SEPARATOR .
- BASE_PATH."server/PEAR/" . PATH_SEPARATOR .
+ "/usr/share/pear/" . PATH_SEPARATOR .
"/usr/share/php/");
// Define the relative URL for dialogs, this string is appended with HTTP GET arguments
--- zarafa-7.1.11.rsc/php-webclient-ajax/zarafa.php 2014-09-03 10:45:06.000000000 +0200
+++ zarafa-7.1.11.rsc/php-webclient-ajax/zarafa.php.php-unbundle 2014-09-07 18:21:36.000000000 +0200
@@ -59,7 +59,7 @@
include("config.php");
include("defaults.php");
include("server/util.php");
- require("server/PEAR/JSON.php");
+ @include("server/PEAR/JSON.php");
require("mapi/mapi.util.php");
require("mapi/mapicode.php");
--- zarafa-7.1.11.rsc/php-webclient-ajax/server/core/class.xmlparser.php 2014-09-03 10:45:06.000000000 +0200
+++ zarafa-7.1.11.rsc/php-webclient-ajax/server/core/class.xmlparser.php.php-unbundle 2014-09-07 18:22:40.000000000 +0200
@@ -50,7 +50,7 @@
?>
<?php
- require_once("server/PEAR/XML/Unserializer.php");
+ require_once("XML/Unserializer.php");
/**
* XML Parser

View file

@ -0,0 +1,91 @@
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa <= 7.1.11 which enhances my earlier
this year implemented "disable_plaintext_auth" feature (new option in Zarafa >= 7.1.10 to disable
all plaintext authentications unless SSL/TLS is used), https://jira.zarafa.com/browse/ZCP-12142
contains the initial implementation and a more verbose feature description.
Given that there are unfortunately still Zarafa systems around using saslauthd without pam_mapi
but rimap instead the "disable_plaintext_auth" feature prevents them from enabling this option as
rimap doesn't support SSL/TLS; https://jira.zarafa.com/browse/ZCP-12473 contains an example report
by a Zarafa customer. Thus this patch adds an exception if the source IPv4 address is "127.0.0.1"
and allows even if "disable_plaintext_auth" is enabled a cleartext authentication. It was a design
decision to check only for 127.0.0.1/32 rather 127.0.0.0/8 because there seem to be systems where
the loopback network except 127.0.0.1/32 is routable?!
Important: The technical implementation of this patch might be not perfect as I am not really a C/
C++ developer. There should be a code review by an experienced C/C++ developer before merging into
Zarafa core.
Proposed to upstream via e-mail on Thu, 16 Oct 2014 00:00:05 +0200, patch was put into the upstream
ticket https://jira.zarafa.com/browse/ZCP-12473.
--- zarafa-7.1.11/gateway/IMAP.cpp 2014-09-03 10:45:06.000000000 +0200
+++ zarafa-7.1.11/gateway/IMAP.cpp.plaintext_auth_localhost 2014-09-24 01:29:10.000000000 +0200
@@ -757,7 +757,7 @@
if (!lpChannel->UsingSsl() && lpChannel->sslctx())
strCapabilities += " STARTTLS";
- if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0)
+ if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0)
strCapabilities += " LOGINDISABLED";
else
strCapabilities += " AUTH=PLAIN";
@@ -923,7 +923,7 @@
char *plain = lpConfig->GetSetting("disable_plaintext_auth");
// If plaintext authentication was disabled any authentication attempt must be refused very soon
- if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0) {
+ if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0) {
hr2 = HrResponse(RESP_TAGGED_NO, strTag, "[PRIVACYREQUIRED] Plaintext authentication disallowed on non-secure "
"(SSL/TLS) connections.");
if (hr2 != hrSuccess)
@@ -1002,7 +1002,7 @@
}
// If plaintext authentication was disabled any login attempt must be refused very soon
- if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0) {
+ if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0) {
hr2 = HrResponse(RESP_UNTAGGED, "BAD [ALERT] Plaintext authentication not allowed without SSL/TLS, but your client "
"did it anyway. If anyone was listening, the password was exposed.");
if (hr2 != hrSuccess)
--- zarafa-7.1.11/gateway/POP3.cpp 2014-09-03 10:45:06.000000000 +0200
+++ zarafa-7.1.11/gateway/POP3.cpp.plaintext_auth_localhost 2014-09-24 01:30:41.000000000 +0200
@@ -320,7 +320,7 @@
if (!lpChannel->UsingSsl() && lpChannel->sslctx())
strCapabilities += "STLS\r\n";
- if (!(!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0))
+ if (!(!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0))
strCapabilities += "USER\r\n";
}
@@ -402,7 +402,7 @@
HRESULT hr = hrSuccess;
char *plain = lpConfig->GetSetting("disable_plaintext_auth");
- if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0) {
+ if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0) {
hr = HrResponse(POP3_RESP_AUTH_ERROR, "Plaintext authentication disallowed on non-secure (SSL/TLS) connections");
lpLogger->Log(EC_LOGLEVEL_ERROR, "Aborted login from %s with username \"%s\" (tried to use disallowed plaintext auth)",
lpChannel->GetIPAddress().c_str(), strUser.c_str());
@@ -431,7 +431,7 @@
HRESULT hr = hrSuccess;
char *plain = lpConfig->GetSetting("disable_plaintext_auth");
- if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0) {
+ if (!lpChannel->UsingSsl() && lpChannel->sslctx() && plain && strcmp(plain, "yes") == 0 && strcmp(lpChannel->GetIPAddress().c_str(), "127.0.0.1") != 0) {
hr = HrResponse(POP3_RESP_AUTH_ERROR, "Plaintext authentication disallowed on non-secure (SSL/TLS) connections");
if(szUser.empty())
lpLogger->Log(EC_LOGLEVEL_ERROR, "Aborted login from %s without username (tried to use disallowed "
--- zarafa-7.1.11/doc/manual.xml 2014-09-03 09:56:28.000000000 +0200
+++ zarafa-7.1.11/doc/manual.xml.plaintext_auth_localhost 2014-10-15 01:22:14.000000000 +0200
@@ -8024,7 +8024,9 @@
<term><option>disable_plaintext_auth</option></term>
<listitem>
<para>Disable all plaintext POP3 and IMAP authentications unless
- SSL/TLS is used. Obviously this requires at least
+ SSL/TLS is used (except for connections originating from
+ <replaceable>127.0.0.1</replaceable> to allow saslauthd with rimap).
+ Obviously enabling this configuration option requires at least
<replaceable>ssl_private_key_file</replaceable> and
<replaceable>ssl_certificate_file</replaceable> to take effect.</para>
<para>Default: <replaceable>no</replaceable></para>

85
zarafa-7.1.11-rpath.patch Normal file
View file

@ -0,0 +1,85 @@
Patch by Robert Scheck <robert@fedoraproject.org> for zarafa >= 7.1.11, which works
around the broken libtool of Debian. Multilib/multiarch systems like Fedora or Red
Hat Enterprise Linux are using /usr/lib64 for 64 bit libraries and /usr/lib is used
for 32 bit libraries. That allows to run 32 bit software on 64 bit systems. Debian
systems only use /usr/lib which contains only 32 or 64 bit systems depending on the
architecture.
Libtool hardcodes the runtime search path in a library (rpath), if the library that
is used for linking is not within the default system library path. The result is,
that if aclocal.m4/configure files are generated by a Debian system, but used on a
Fedora or Red Hat Enterprise Linux 64 bit system for compiling, "-rpath /usr/lib64"
makes it into the binary.
Fedora and EPEL (for Red Hat Enterprise Linux) do not allow binaries with rpath, as
the Linux dynamic linker is usually smarter than the hardcoded path.
The fix for this issue is to add the optional /lib64 and /usr/lib64 directories at/
within libtool in front of the regular /lib and /usr/lib directories at the system
library path. These libtool information are hold in aclocal.m4, which is generated
by running aclocal. As the content of aclocal.m4 is included into configure during
a run of autoconf, aclocal.m4 needs to be modified within the upstream build system
each time after a aclocal run - until Debian's libtool is fixed at Debian upstream.
Applying the fix is either possible by using the first hunk of the patch (second
hunk is runtime-only if configure file has been already generated) or by running
the following sed command after each aclocal run within the upstream build system:
sed -e 's@\(# Append ld.so.conf contents to the search path\)@# Add ABI-specific directories to the system library path.\n sys_lib_dlsearch_path_spec="/lib64 /usr/lib64 /lib /usr/lib"\n\n \1@' \
-e 's@/lib /usr/lib $lt_ld_extra@$sys_lib_dlsearch_path_spec $lt_ld_extra@' -i zarafa-7.1.11/aclocal.m4
More information regarding this topic can be found for example at:
- http://osdir.com/ml/bug-libtool-gnu/2009-12/msg00034.html
- http://lists.gnu.org/archive/html/libtool/2009-01/msg00039.html
- http://thread.gmane.org/gmane.comp.gnu.libtool.general/8339/focus=8345
--- zarafa-7.1.11/aclocal.m4 2014-09-03 09:56:52.000000000 +0200
+++ zarafa-7.1.11/aclocal.m4.rpath 2014-09-07 17:20:37.000000000 +0200
@@ -2672,10 +2672,13 @@
# before this can be enabled.
hardcode_into_libs=yes
+ # Add ABI-specific directories to the system library path.
+ sys_lib_dlsearch_path_spec="/lib64 /usr/lib64 /lib /usr/lib"
+
# Append ld.so.conf contents to the search path
if test -f /etc/ld.so.conf; then
lt_ld_extra=`awk '/^include / { system(sprintf("cd /etc; cat %s 2>/dev/null", \[$]2)); skip = 1; } { if (!skip) print \[$]0; skip = 0; }' < /etc/ld.so.conf | $SED -e 's/#.*//;/^[ ]*hwcap[ ]/d;s/[:, ]/ /g;s/=[^=]*$//;s/=[^= ]* / /g;s/"//g;/^$/d' | tr '\n' ' '`
- sys_lib_dlsearch_path_spec="/lib /usr/lib $lt_ld_extra"
+ sys_lib_dlsearch_path_spec="$sys_lib_dlsearch_path_spec $lt_ld_extra"
fi
# We used to test for /lib/ld.so.1 and disable shared libraries on
--- zarafa-7.1.11/configure 2014-09-03 09:56:53.000000000 +0200
+++ zarafa-7.1.11/configure.rpath 2014-09-07 17:28:07.000000000 +0200
@@ -10983,10 +10983,13 @@
# before this can be enabled.
hardcode_into_libs=yes
+ # Add ABI-specific directories to the system library path.
+ sys_lib_dlsearch_path_spec="/lib64 /usr/lib64 /lib /usr/lib"
+
# Append ld.so.conf contents to the search path
if test -f /etc/ld.so.conf; then
lt_ld_extra=`awk '/^include / { system(sprintf("cd /etc; cat %s 2>/dev/null", \$2)); skip = 1; } { if (!skip) print \$0; skip = 0; }' < /etc/ld.so.conf | $SED -e 's/#.*//;/^[ ]*hwcap[ ]/d;s/[:, ]/ /g;s/=[^=]*$//;s/=[^= ]* / /g;s/"//g;/^$/d' | tr '\n' ' '`
- sys_lib_dlsearch_path_spec="/lib /usr/lib $lt_ld_extra"
+ sys_lib_dlsearch_path_spec="$sys_lib_dlsearch_path_spec $lt_ld_extra"
fi
# We used to test for /lib/ld.so.1 and disable shared libraries on
@@ -16025,10 +16028,13 @@
# before this can be enabled.
hardcode_into_libs=yes
+ # Add ABI-specific directories to the system library path.
+ sys_lib_dlsearch_path_spec="/lib64 /usr/lib64 /lib /usr/lib"
+
# Append ld.so.conf contents to the search path
if test -f /etc/ld.so.conf; then
lt_ld_extra=`awk '/^include / { system(sprintf("cd /etc; cat %s 2>/dev/null", \$2)); skip = 1; } { if (!skip) print \$0; skip = 0; }' < /etc/ld.so.conf | $SED -e 's/#.*//;/^[ ]*hwcap[ ]/d;s/[:, ]/ /g;s/=[^=]*$//;s/=[^= ]* / /g;s/"//g;/^$/d' | tr '\n' ' '`
- sys_lib_dlsearch_path_spec="/lib /usr/lib $lt_ld_extra"
+ sys_lib_dlsearch_path_spec="$sys_lib_dlsearch_path_spec $lt_ld_extra"
fi
# We used to test for /lib/ld.so.1 and disable shared libraries on

View file

@ -0,0 +1,32 @@
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa >= 7.1.11 which restricts replies by
zarafa-autorespond to automated processes and mailing lists according to RFC 5230, section 4.6. For
further details please have a look to http://tools.ietf.org/html/rfc5230#page-8 as well.
Proposed to upstream via e-mail on Wed, 27 Aug 2014 23:30:31 +0200, patch was put into the upstream
ticket https://jira.zarafa.com/browse/ZCP-12590.
--- zarafa-7.1.11/spooler/DAgent.cpp 2014-08-24 12:27:06.000000000 +0200
+++ zarafa-7.1.11/spooler/DAgent.cpp.vacation-headers 2014-08-27 23:20:18.000000000 +0200
@@ -1422,11 +1422,19 @@
// See if we're looping
if (lpMessageProps[0].ulPropTag == PR_TRANSPORT_MESSAGE_HEADERS_A) {
- if ( (strstr(lpMessageProps[0].Value.lpszA, "X-Zarafa-Vacation:") != NULL) ||
- (strstr(lpMessageProps[0].Value.lpszA, "Auto-Submitted:") != NULL) ||
- (strstr(lpMessageProps[0].Value.lpszA, "Precedence:") != NULL) )
+ if ( (strstr(lpMessageProps[0].Value.lpszA, "X-Zarafa-Vacation:") != NULL) || // Zarafa
+ (strstr(lpMessageProps[0].Value.lpszA, "Auto-Submitted:") != NULL) || // RFC 3834
+ (strstr(lpMessageProps[0].Value.lpszA, "List-Id:") != NULL) || // RFC 2919
+ (strstr(lpMessageProps[0].Value.lpszA, "List-Help:") != NULL) || // RFC 2369
+ (strstr(lpMessageProps[0].Value.lpszA, "List-Subscribe:") != NULL) || // RFC 2369
+ (strstr(lpMessageProps[0].Value.lpszA, "List-Unsubscribe:") != NULL) || // RFC 2369
+ (strstr(lpMessageProps[0].Value.lpszA, "List-Post:") != NULL) || // RFC 2369
+ (strstr(lpMessageProps[0].Value.lpszA, "List-Owner:") != NULL) || // RFC 2369
+ (strstr(lpMessageProps[0].Value.lpszA, "List-Archive:") != NULL) || // RFC 2369
+ (strstr(lpMessageProps[0].Value.lpszA, "Precedence:") != NULL) ) // RFC 3834
// Vacation header already present, do not send vacation reply
// Precedence: list/bulk/junk, do not reply to these mails
+ // See also http://tools.ietf.org/html/rfc5230#page-8 for details
goto exit;
// save headers to a file so they can also be tested from the script we're runing
snprintf(szTemp, PATH_MAX, "%s/autorespond-headers.XXXXXX", getenv("TEMP") == NULL ? "/tmp" : getenv("TEMP"));

View file

@ -0,0 +1,44 @@
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa >= 7.1.11 which adds anti-loop headers
for automatic responses by zarafa-autorespond for Microsoft Exchange and all vacation(1) compatible
implementations.
For the Microsoft Exchange related part useful links are:
- http://msdn.microsoft.com/en-us/library/ee219609(v=exchg.80).aspx
- https://www.jitbit.com/maxblog/18-detecting-outlook-autoreplyout-of-office-emails-and-x-auto-response-suppress-header/
For vacation(1) compatible implementations useful links are:
- http://www.daemon-systems.org/man/vacation.1.html
- Book "sendmail" (written by Bryan Costales, Claus Assmann, George Jansen, Gregory Neil Shapiro), ISBN 0596555342
Proposed to upstream via e-mail on Wed, 27 Aug 2014 23:59:58 +0200, patch was put into the upstream
ticket https://jira.zarafa.com/browse/ZCP-12591.
--- zarafa-7.1.11/spooler/DAgent.cpp 2014-08-24 12:27:06.000000000 +0200
+++ zarafa-7.1.11/spooler/DAgent.cpp.vacation-headers2 2014-08-27 23:52:42.000000000 +0200
@@ -1469,12 +1469,25 @@
if (hr != hrSuccess)
goto exit;
- // add anti-loop header
+ // add anti-loop header for Zarafa
snprintf(szHeader, PATH_MAX, "\nX-Zarafa-Vacation: autorespond");
hr = WriteOrLogError(fd, szHeader, strlen(szHeader));
if (hr != hrSuccess)
goto exit;
+ // add anti-loop header for Exchange, see http://msdn.microsoft.com/en-us/library/ee219609(v=exchg.80).aspx
+ snprintf(szHeader, PATH_MAX, "\nX-Auto-Response-Suppress: All");
+ hr = WriteOrLogError(fd, szHeader, strlen(szHeader));
+ if (hr != hrSuccess)
+ goto exit;
+
+ // add anti-loop header for vacation(1) compatible implementations, see section 10.9 of book "sendmail" (written
+ // by Bryan Costales, Claus Assmann, George Jansen, Gregory Neil Shapiro), ISBN 0596555342
+ snprintf(szHeader, PATH_MAX, "\nPrecedence: bulk");
+ hr = WriteOrLogError(fd, szHeader, strlen(szHeader));
+ if (hr != hrSuccess)
+ goto exit;
+
if (lpMessageProps[3].ulPropTag == PR_SUBJECT_W) {
// convert as one string because of [] characters
swprintf(szwHeader, PATH_MAX, L"%ls [%ls]", szSubject, lpMessageProps[3].Value.lpszW);

View file

@ -0,0 +1,21 @@
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa <= 7.1.11 which logs authentication
failures of Zarafa WebAccess into the error log of the webserver. This is basically a backport of
https://jira.zarafa.com/browse/WA-6908 from WebApp to WebAccess. In difference to original patch
there is no inappropriate space before a punctuation mark also known as "plenken".
Proposed to upstream via e-mail on Wed, 13 Aug 2014 22:56:09 +0200, initial patch was put into the
upstream ticket https://jira.zarafa.com/browse/ZCP-12543.
--- zarafa-7.1.11/php-webclient-ajax/client/login.php 2014-09-03 10:45:06.000000000 +0200
+++ zarafa-7.1.11/php-webclient-ajax/client/login.php 2015-02-18 01:08:13.000000000 +0100
@@ -86,6 +86,10 @@
switch($_SESSION["hresult"]){
case MAPI_E_LOGON_FAILED:
case MAPI_E_UNCONFIGURED:
+ // Print error message to error_log of webserver
+ if (!empty($_POST["username"])) {
+ error_log('user '.$_POST["username"].': authentication failure at MAPI');
+ }
echo _("Logon failed, please check your name/password.");
break;
case MAPI_E_NETWORK_ERROR:

View file

@ -0,0 +1,38 @@
Patch by Robert Scheck <robert@fedoraproject.org> for zarafa >= 7.1.12 which disables weak SSLv2
and SSLv3 protocols for encrypted SOAP connections between the Zarafa services. Until (including)
the Zarafa 7.1.11 release the upstream default was to replace the SSLv23_method() that a pristine
gSOAP library ships with the "safer" SSLv3_method(). With Zarafa 7.1.12 the SSLv3_method() was
changed to SSLv23_method(). However this enables SSLv2 again (and still does not disable SSLv3).
Thus this patch disables SSLv2 and SSLv3 as well as TLS compression explicitly; similar like the
Zarafa Outlook Client which meanwhile only allows TLSv1.0 (and better).
Proposed to upstream via e-mail on Wed, 2 Apr 2014 11:35:40 +0200, initial patch was put into the
upstream ticket Ticket#2014040210000266.
--- zarafa-7.1.12/provider/common/SOAPSock.cpp 2015-04-07 13:10:13.000000000 +0200
+++ zarafa-7.1.12/provider/common/SOAPSock.cpp.gsoap-sslv3 2015-04-07 16:32:20.000000000 +0200
@@ -157,9 +157,6 @@
lpCmd->endpoint = strdup(strServerPath.c_str());
- // default allow SSLv3, TLSv1, TLSv1.1 and TLSv1.2
- lpCmd->soap->ctx = SSL_CTX_new(SSLv23_method());
-
#ifdef WITH_OPENSSL
if (strncmp("https:", lpCmd->endpoint, 6) == 0) {
// no need to add certificates to call, since soap also calls SSL_CTX_set_default_verify_paths()
@@ -183,6 +180,14 @@
lpCmd->soap->fsslverify = ssl_verify_callback_zarafa_silent;
SSL_CTX_set_verify(lpCmd->soap->ctx, SSL_VERIFY_PEER, lpCmd->soap->fsslverify);
+
+ // disable SSLv2 (according to RFC 6176) and SSLv3, leaving just TLSv1.0 (and better)
+ SSL_CTX_set_options(lpCmd->soap->ctx, SSL_OP_NO_SSLv2 | SSL_OP_NO_SSLv3);
+
+#ifdef SSL_OP_NO_COMPRESSION
+ // disable TLS compression to close the CRIME attack vector (also known as CVE-2012-4929)
+ SSL_CTX_set_options(lpCmd->soap->ctx, SSL_OP_NO_COMPRESSION);
+#endif
}
#endif

View file

@ -0,0 +1,117 @@
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa >= 7.1.12 which removes a wrongly introduced dependency to the
proprietary zarafa-licensed. From Zarafa 7.1.11 to 7.1.12 there were some changes to the ValidateArchiverLicense() method;
due to these changes rebuilding fails with "ArchiverSession.cpp:53:23: fatal error: ECLicense.h: No such file or directory"
now. The patch just reverts the changes that were introduced from 7.1.11 to 7.1.12 to get the code building again.
--- zarafa-7.1.12/ECtools/zarafa-archiver/ArchiverSession.cpp 2015-04-07 13:10:12.000000000 +0200
+++ zarafa-7.1.12/ECtools/zarafa-archiver/ArchiverSession.cpp.licensed-archiver 2015-04-07 15:55:07.000000000 +0200
@@ -50,8 +50,6 @@
#include "mapiext.h"
#include "userutil.h"
#include "ECMsgStore.h"
-#include "ECLicense.h"
-#include "ECMAPILicense.h"
typedef mapi_memory_ptr<ECSERVERLIST> ECServerListPtr;
@@ -879,38 +877,7 @@
typedef mapi_object_ptr<ECMsgStore, IID_ECMsgStore> ECMsgStorePtr;
HRESULT ArchiverSession::ValidateArchiverLicense(bool attachnewuser /* = false*/) const {
- IMsgStore *lpMsgStore = NULL;
- IMsgStore *lpProxedMsgStore = NULL;
- UnknownPtr ptrUnknown;
- ECMsgStorePtr ptrOnlineStore;
-
- HRESULT hr = HrOpenDefaultStore(GetMAPISession(), MDB_WRITE | MDB_NO_DIALOG | MDB_NO_MAIL | MDB_TEMPORARY, &lpMsgStore);
- if (hr != hrSuccess)
- goto exit;
-
- hr = GetProxyStoreObject(lpMsgStore, &lpProxedMsgStore);
- if (hr != hrSuccess)
- goto exit;
-
- hr = lpProxedMsgStore->QueryInterface(IID_ECMsgStoreOnline, &ptrUnknown);
- if (hr != hrSuccess)
- goto exit;
-
- hr = ptrUnknown->QueryInterface(IID_ECMsgStore, &ptrOnlineStore);
- if (hr != hrSuccess) {
- m_lpLogger->Log(EC_LOGLEVEL_FATAL, "Unable to validate archived user count. Please check the archiver and licensed log for errors.");
- hr = MAPI_E_NO_SUPPORT;
- goto exit;
- }
-
- hr = HrCheckLicense(&ptrOnlineStore->m_xMsgStore, SERVICE_TYPE_ARCHIVE, ZARAFA_ARCHIVE_DEFAULT);
- if (hr != hrSuccess)
- {
- m_lpLogger->Log(EC_LOGLEVEL_FATAL, "No archiver license found.");
- hr = MAPI_E_NO_SUPPORT;
- }
- else
- {
+ HRESULT hr;
unsigned int ulArchivedUsers = 0;
unsigned int ulMaxUsers = 0;
@@ -931,7 +898,6 @@
} else if (ulArchivedUsers + 5 >= ulMaxUsers) { //@todo which warning limit?
m_lpLogger->Log(EC_LOGLEVEL_FATAL, "You almost reached the archived user limit. Archived users %d of %d", ulArchivedUsers, ulMaxUsers);
}
- }
exit:
return hr;
--- zarafa-7.1.12/ECtools/zarafa-archiver/Makefile.am 2015-04-07 12:00:49.000000000 +0200
+++ zarafa-7.1.12/ECtools/zarafa-archiver/Makefile.am.licensed-archiver 2015-04-07 15:59:42.000000000 +0200
@@ -9,7 +9,6 @@
-I${top_srcdir}/provider/client \
-I${top_srcdir}/provider/include \
-I${top_srcdir}/provider/soap \
- -I${top_srcdir}/liblicense \
-I${top_builddir}/provider/soap \
$(GSOAP_CFLAGS) \
-I${top_srcdir}/common \
@@ -17,9 +16,7 @@
libarchiver_la_LIBADD = ${top_builddir}/mapi4linux/src/libmapi.la \
${top_builddir}/common/libcommon_mapi.la \
- ${top_builddir}/common/libcommon_util.la \
- ${top_builddir}/liblicense/liblicense.la \
- ${top_builddir}/liblicense/liblicense_mapi.la
+ ${top_builddir}/common/libcommon_util.la
libarchiver_la_SOURCES = \
ArchiverSession.cpp ArchiverSession.h ArchiverSessionPtr.h \
--- zarafa-7.1.12/ECtools/zarafa-archiver/Makefile.in 2015-04-07 12:03:40.000000000 +0200
+++ zarafa-7.1.12/ECtools/zarafa-archiver/Makefile.in.licensed-archiver 2015-04-07 16:00:15.000000000 +0200
@@ -112,9 +112,7 @@
libarchiver_la_DEPENDENCIES = \
${top_builddir}/mapi4linux/src/libmapi.la \
${top_builddir}/common/libcommon_mapi.la \
- ${top_builddir}/common/libcommon_util.la \
- ${top_builddir}/liblicense/liblicense.la \
- ${top_builddir}/liblicense/liblicense_mapi.la
+ ${top_builddir}/common/libcommon_util.la
am_libarchiver_la_OBJECTS = ArchiverSession.lo archiver-common.lo \
ArchiveManageImpl.lo ArchiveStateCollector.lo \
ArchiveStateUpdater.lo ArchiveHelper.lo StoreHelper.lo \
@@ -395,7 +393,6 @@
-I${top_srcdir}/provider/client \
-I${top_srcdir}/provider/include \
-I${top_srcdir}/provider/soap \
- -I${top_srcdir}/liblicense \
-I${top_builddir}/provider/soap \
$(GSOAP_CFLAGS) \
-I${top_srcdir}/common \
@@ -403,9 +400,7 @@
libarchiver_la_LIBADD = ${top_builddir}/mapi4linux/src/libmapi.la \
${top_builddir}/common/libcommon_mapi.la \
- ${top_builddir}/common/libcommon_util.la \
- ${top_builddir}/liblicense/liblicense.la \
- ${top_builddir}/liblicense/liblicense_mapi.la
+ ${top_builddir}/common/libcommon_util.la
libarchiver_la_SOURCES = \
ArchiverSession.cpp ArchiverSession.h ArchiverSessionPtr.h \

View file

@ -0,0 +1,85 @@
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa >= 7.1.12 which implements ECDHE (elliptic
curve diffie-hellman key exchange) support. http://en.wikipedia.org/wiki/Elliptic_curve_cryptography is
providing more information about elliptic curves.
Suggestions for testing; run the following openssl(1) commands before and after applying this patch:
1. echo QUIT | openssl s_client -connect <host>:110 -starttls pop3 2>&1 | grep Cipher
2. echo QUIT | openssl s_client -connect <host>:143 -starttls imap 2>&1 | grep Cipher
3. echo QUIT | openssl s_client -connect <host>:237 2>&1 | grep Cipher
4. echo QUIT | openssl s_client -connect <host>:993 2>&1 | grep Cipher
5. echo QUIT | openssl s_client -connect <host>:995 2>&1 | grep Cipher
6. echo QUIT | openssl s_client -connect <host>:8443 2>&1 | grep Cipher
After applying this patch the output should contain e.g. "ECDHE-RSA-AES256-GCM-SHA384" on a Red Hat
Enterprise Linux 6.5 (only RHEL >= 6.5 has support for elliptic curve). Without this patch the result
is e.g. "AES256-GCM-SHA384".
Important: The technical implementation of this patch might be not perfect as I am not really a C/C++
developer. The logic and the implementation is heavily based on Sendmail. There should be a code review
by an experienced C/C++ and OpenSSL developer before merging into Zarafa core.
This patch should be only applied after ZCP-12143 and its dependencies. However this patch might maybe
not directly apply due to some previous merge issues as mentioned in Ticket#2014030810000131.
Proposed to upstream via e-mail on Mon, 14 Apr 2014 12:04:17 +0200, initial patch was put into upstream
ticket https://jira.zarafa.com/browse/ZCP-12237.
--- zarafa-7.1.12/common/ECChannel.cpp 2015-04-07 13:10:12.000000000 +0200
+++ zarafa-7.1.12/common/ECChannel.cpp.ssl_ecdhe 2015-04-07 17:12:15.000000000 +0200
@@ -93,6 +93,9 @@
char *ssl_ciphers = lpConfig->GetSetting("ssl_ciphers");
char *ssl_name = NULL;
int ssl_op = 0, ssl_include = 0, ssl_exclude = 0;
+#if !defined(OPENSSL_NO_ECDH) && defined(NID_X9_62_prime256v1)
+ EC_KEY *ecdh;
+#endif
if (lpConfig == NULL) {
lpLogger->Log(EC_LOGLEVEL_ERROR, "ECChannel::HrSetCtx(): invalid parameters");
@@ -113,6 +116,16 @@
SSL_CTX_set_options(lpCTX, SSL_OP_ALL); // enable quirk and bug workarounds
+#if !defined(OPENSSL_NO_ECDH) && defined(NID_X9_62_prime256v1)
+ ecdh = EC_KEY_new_by_curve_name(NID_X9_62_prime256v1);
+
+ if (ecdh != NULL) {
+ SSL_CTX_set_options(lpCTX, SSL_OP_SINGLE_ECDH_USE);
+ SSL_CTX_set_tmp_ecdh(lpCTX, ecdh);
+ EC_KEY_free(ecdh);
+ }
+#endif
+
ssl_name = strtok(ssl_protocols, " ");
while(ssl_name != NULL) {
int ssl_proto = 0;
--- zarafa-7.1.12/provider/server/ECSoapServerConnection.cpp 2015-04-07 13:10:13.000000000 +0200
+++ zarafa-7.1.12/provider/server/ECSoapServerConnection.cpp.ssl_ecdhe 2015-04-07 17:13:23.000000000 +0200
@@ -235,6 +235,9 @@
char *server_ssl_ciphers = m_lpConfig->GetSetting("server_ssl_ciphers");
char *ssl_name = NULL;
int ssl_op = 0, ssl_include = 0, ssl_exclude = 0;
+#if !defined(OPENSSL_NO_ECDH) && defined(NID_X9_62_prime256v1)
+ EC_KEY *ecdh;
+#endif
if(lpServerName == NULL) {
free(server_ssl_ciphers);
@@ -268,6 +271,16 @@
SSL_CTX_set_options(lpsSoap->ctx, SSL_OP_ALL);
+#if !defined(OPENSSL_NO_ECDH) && defined(NID_X9_62_prime256v1)
+ ecdh = EC_KEY_new_by_curve_name(NID_X9_62_prime256v1);
+
+ if (ecdh != NULL) {
+ SSL_CTX_set_options(lpsSoap->ctx, SSL_OP_SINGLE_ECDH_USE);
+ SSL_CTX_set_tmp_ecdh(lpsSoap->ctx, ecdh);
+ EC_KEY_free(ecdh);
+ }
+#endif
+
ssl_name = strtok(server_ssl_protocols, " ");
while(ssl_name != NULL) {
int ssl_proto = 0;

View file

@ -0,0 +1,123 @@
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa >= 7.1.12 which re-adds the whole
documentation that was initially proposed to upstream but lost when this feature was backported
from Zarafa 7.2 to the 7.1 series.
Proposed to upstream via e-mail on Sat, 8 Mar 2014 14:30:29 +0100, initial patch was put into
the upstream ticket https://jira.zarafa.com/browse/ZCP-12143.
--- zarafa-7.1.12/doc/manual.xml 2015-04-07 12:03:31.000000000 +0200
+++ zarafa-7.1.12/doc/manual.xml.ssl_protocols_ciphers 2015-04-07 17:05:47.000000000 +0200
@@ -4226,14 +4226,35 @@
</varlistentry>
<varlistentry>
- <term><option>server_ssl_enable_v2</option></term>
+ <term><option>server_ssl_protocols</option></term>
<listitem>
- <para>Incoming SSL connections normally are v3.</para>
- <para>Default: <replaceable>no</replaceable>
- </para>
+ <para>Disabled or enabled protocol names. Supported protocol names
+ are <replaceable>SSLv2</replaceable>, <replaceable>SSLv3</replaceable>
+ and <replaceable>TLSv1</replaceable>. If Zarafa was linked against
+ OpenSSL 1.0.1 or later there is additional support for the new protocols
+ <replaceable>TLSv1.1</replaceable> and <replaceable>TLSv1.2</replaceable>.
+ To exclude both, SSLv2 and SSLv3 set <option>server_ssl_protocols</option>
+ to <replaceable>!SSLv2 !SSLv3</replaceable>. SSLv2 is considered unsafe
+ and these connections should not be accepted.</para>
+ <para>Default: <replaceable>!SSLv2</replaceable></para>
+ </listitem>
+ </varlistentry>
+
+ <varlistentry>
+ <term><option>server_ssl_ciphers</option></term>
+ <listitem>
+ <para>SSL ciphers to use, set to <replaceable>ALL</replaceable> for backward compatibility.</para>
+ <para>Default: <replaceable>ALL:!LOW:!SSLv2:!EXP:!aNULL</replaceable></para>
</listitem>
</varlistentry>
+ <varlistentry>
+ <term><option>server_ssl_prefer_server_ciphers</option></term>
+ <listitem>
+ <para>Prefer the server's order of SSL ciphers over client's.</para>
+ <para>Default: <replaceable>no</replaceable></para>
+ </listitem>
+ </varlistentry>
</variablelist>
</refsection>
@@ -8090,11 +8111,32 @@
</varlistentry>
<varlistentry>
- <term><option>ssl_enable_v2</option></term>
+ <term><option>ssl_protocols</option></term>
+ <listitem>
+ <para>Disabled or enabled protocol names. Supported protocol names
+ are <replaceable>SSLv2</replaceable>, <replaceable>SSLv3</replaceable>
+ and <replaceable>TLSv1</replaceable>. If Zarafa was linked against
+ OpenSSL 1.0.1 or later there is additional support for the new protocols
+ <replaceable>TLSv1.1</replaceable> and <replaceable>TLSv1.2</replaceable>.
+ To exclude both, SSLv2 and SSLv3 set <option>ssl_protocols</option>
+ to <replaceable>!SSLv2 !SSLv3</replaceable>. SSLv2 is considered unsafe
+ and these connections should not be accepted.</para>
+ <para>Default: <replaceable>!SSLv2</replaceable></para>
+ </listitem>
+ </varlistentry>
+
+ <varlistentry>
+ <term><option>ssl_ciphers</option></term>
<listitem>
- <para>Accept SSLv2 only connections. SSLv2 is considered
- unsafe, and these connections should not be
- accepted.</para>
+ <para>SSL ciphers to use, set to <replaceable>ALL</replaceable> for backward compatibility.</para>
+ <para>Default: <replaceable>ALL:!LOW:!SSLv2:!EXP:!aNULL</replaceable></para>
+ </listitem>
+ </varlistentry>
+
+ <varlistentry>
+ <term><option>ssl_prefer_server_ciphers</option></term>
+ <listitem>
+ <para>Prefer the server's order of SSL ciphers over client's.</para>
<para>Default: <replaceable>no</replaceable></para>
</listitem>
</varlistentry>
@@ -10091,11 +10133,32 @@
</varlistentry>
<varlistentry>
- <term><option>ssl_enable_v2</option></term>
+ <term><option>ssl_protocols</option></term>
+ <listitem>
+ <para>Disabled or enabled protocol names. Supported protocol names
+ are <replaceable>SSLv2</replaceable>, <replaceable>SSLv3</replaceable>
+ and <replaceable>TLSv1</replaceable>. If Zarafa was linked against
+ OpenSSL 1.0.1 or later there is additional support for the new protocols
+ <replaceable>TLSv1.1</replaceable> and <replaceable>TLSv1.2</replaceable>.
+ To exclude both, SSLv2 and SSLv3 set <option>ssl_protocols</option>
+ to <replaceable>!SSLv2 !SSLv3</replaceable>. SSLv2 is considered unsafe
+ and these connections should not be accepted.</para>
+ <para>Default: <replaceable>!SSLv2</replaceable></para>
+ </listitem>
+ </varlistentry>
+
+ <varlistentry>
+ <term><option>ssl_ciphers</option></term>
+ <listitem>
+ <para>SSL ciphers to use, set to <replaceable>ALL</replaceable> for backward compatibility.</para>
+ <para>Default: <replaceable>ALL:!LOW:!SSLv2:!EXP:!aNULL</replaceable></para>
+ </listitem>
+ </varlistentry>
+
+ <varlistentry>
+ <term><option>ssl_prefer_server_ciphers</option></term>
<listitem>
- <para>Accept SSLv2 only connections. SSLv2 is considered
- unsafe, and these connections should not be
- accepted.</para>
+ <para>Prefer the server's order of SSL ciphers over client's.</para>
<para>Default: <replaceable>no</replaceable></para>
</listitem>
</varlistentry>

View file

@ -0,0 +1,56 @@
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa 7.1.12 which backports the fix for
CVE-2015-3436. Guido Günther detected and reported that replacing "/tmp/zarafa-upgrade-lock" by
a symlink makes the zarafa-server process following that symlink and thus allows to overwrite
arbitrary files in the filesystem (assuming zarafa-server runs as root which is not the case by
default at Fedora, but it is the upstream default). One just needs write permissions in /tmp and
wait until the zarafa-server is restarted. https://bugzilla.redhat.com/show_bug.cgi?id=1222151
contains further information. The difference between this backport and the original diff is that
the log levels were reworked from Zarafa 7.1.x to 7.2.x (which this backport takes care of).
--- zarafa-7.1.12/provider/server/ECServer.cpp 2015-05-08 15:09:05.000000000 +0200
+++ zarafa-7.1.12/provider/server/ECServer.cpp.upgrade-lock 2015-05-18 23:05:00.000000000 +0200
@@ -101,6 +101,8 @@
// have to go with the safe value which is for 64bit.
#define MYSQL_MIN_THREAD_STACK (256*1024)
+const char upgrade_lock_file[] = "/tmp/zarafa-upgrade-lock";
+
extern ECSessionManager* g_lpSessionManager;
// scheduled functions
@@ -832,7 +834,7 @@
// SIGSEGV backtrace support
stack_t st = {0};
struct sigaction act = {{0}};
- FILE *tmplock = NULL;
+ int tmplock = -1;
struct stat dir = {0};
struct passwd *runasUser = NULL;
@@ -1288,8 +1290,9 @@
m_bDatabaseUpdateIgnoreSignals = true;
// add a lock file to disable the /etc/init.d scripts
- tmplock = fopen("/tmp/zarafa-upgrade-lock","w");
- if (!tmplock)
+ tmplock = open(upgrade_lock_file, O_CREAT | O_EXCL, S_IRUSR | S_IWUSR);
+
+ if (tmplock == -1)
g_lpLogger->Log(EC_LOGLEVEL_FATAL, "WARNING: Unable to place upgrade lockfile: %s", strerror(errno));
#ifdef EMBEDDED_MYSQL
@@ -1314,9 +1317,11 @@
er = lpDatabaseFactory->UpdateDatabase(m_bForceDatabaseUpdate, dbError);
// remove lock file
- if (tmplock) {
- fclose(tmplock);
- unlink("/tmp/zarafa-upgrade-lock");
+ if (tmplock != -1) {
+ if (unlink(upgrade_lock_file) == -1)
+ g_lpLogger->Log(EC_LOGLEVEL_FATAL, "WARNING: Unable to delete upgrade lockfile (%s): %s", upgrade_lock_file, strerror(errno));
+
+ close(tmplock);
}
if(er == ZARAFA_E_INVALID_VERSION) {

View file

@ -0,0 +1,58 @@
Patch by Robert Scheck <robert@fedoraproject.org> for Zarafa >= 7.1.12 which fixes the fix that fixes CVE-2014-0103. Ush,
that was complicated, so: CVE-2014-0103 exists because Zarafa WebAccess < 7.1.10 and Zarafa WebApp < 1.6 storing passwords
in cleartext on server (in the PHP session). Zarafa solved this flaw by using openssl_encrypt() and openssl_decrypt() from
PHP's OpenSSL bindings. However these functions are only available in PHP 5.3 or later. Without this patch suggestion, any
older but still supported Linux distribution like Red Hat Enterprise Linux 5 or SuSE Linux Enterprise Server 10 (which are
both shipping PHP < 5.3 by default) would still be left vulnerable.
Given that I am personally more a fan of OpenSSL rather mcrypt, I am not absolutely sure if this implementation is really
correct even it works fine on my test system. So please explicitly review this code to avoid introducing another security
flaw by trying to fix one! A thing that I generally question for myself is the usage of "des-ede3-cbc"/"MCRYPT_TRIPLEDES"
instead of e.g. MCRYPT_RIJNDAEL_128. Given that this decision was initially made by Zarafa I am just following that here.
Important: To get this patch really powerful the install-time requirement needs to be adapted like this (this example is
based on Fedora's build system so the macros %{?rhel} and %{?fedora} might not exist at Zarafa but need to be replaced by
other macros):
%if 0%{?rhel}%{?fedora} < 6
Requires: php-mcrypt
%else
Requires: php-openssl
%endif
This requires php-openssl (provided by php-common) on RHEL 6 (and later) and php-mcrypt (separate package) before RHEL 6.
Proposed to upstream via e-mail on Thu, 5 Jun 2014 00:24:32 +0200, initial patch was put into the (non-disclosed) upstream
ticket https://jira.zarafa.com/browse/ZCP-12407.
--- zarafa-7.1.12/php-webclient-ajax/index.php 2015-04-07 13:10:13.000000000 +0200
+++ zarafa-7.1.12/php-webclient-ajax/index.php.webaccess-mcrypt 2015-04-07 16:22:23.000000000 +0200
@@ -135,6 +135,8 @@
} else {
$_SESSION['password'] = openssl_encrypt($password,"des-ede3-cbc",PASSWORD_KEY,0,PASSWORD_IV);
}
+ } elseif(function_exists("mcrypt_encrypt")) {
+ $_SESSION['password'] = base64_encode(mcrypt_encrypt(MCRYPT_TRIPLEDES, PASSWORD_KEY, $password, MCRYPT_MODE_CBC, PASSWORD_IV));
} else {
$_SESSION["password"] = $password;
}
--- zarafa-7.1.12/php-webclient-ajax/server/core/class.mapisession.php 2015-04-07 13:10:14.000000000 +0200
+++ zarafa-7.1.12/php-webclient-ajax/server/core/class.mapisession.php.webaccess-mcrypt 2015-04-07 16:23:58.000000000 +0200
@@ -132,6 +132,8 @@
} else {
$password = openssl_decrypt($password,"des-ede3-cbc",PASSWORD_KEY,0,PASSWORD_IV);
}
+ } elseif(function_exists("mcrypt_decrypt")) {
+ $password = rtrim(mcrypt_decrypt(MCRYPT_TRIPLEDES, PASSWORD_KEY, base64_decode($password), MCRYPT_MODE_CBC, PASSWORD_IV), "\0");
}
// logon
$this->session = mapi_logon_zarafa($username, $password, $server, $sslcert_file, $sslcert_pass);
@@ -144,6 +146,8 @@
} else {
$password = openssl_encrypt($password,"des-ede3-cbc",PASSWORD_KEY,0,PASSWORD_IV);
}
+ } elseif(function_exists("mcrypt_encrypt")) {
+ $password = base64_encode(mcrypt_encrypt(MCRYPT_TRIPLEDES, PASSWORD_KEY, $password, MCRYPT_MODE_CBC, PASSWORD_IV));
}
if ($result == NOERROR && $this->session !== false){

48
zarafa-webaccess.conf Normal file
View file

@ -0,0 +1,48 @@
#
# Zarafa Webaccess featuring a 'Look & Feel' similar to Outlook
#
Alias /webaccess /usr/share/zarafa-webaccess/
# Following Apache and PHP settings need to be set to work correct
#
<Directory /usr/share/zarafa-webaccess/>
# Some apache settings
DirectoryIndex index.php
Options -Indexes +FollowSymLinks
<IfModule mod_authz_core.c>
# Apache 2.4
Require all granted
</IfModule>
<IfModule !mod_authz_core.c>
# Apache 2.2
Order allow,deny
Allow from all
</IfModule>
# Register globals must be off
php_flag register_globals off
# Magic quotes must be off
php_flag magic_quotes_gpc off
php_flag magic_quotes_runtime off
# The maximum POST limit. To upload large files, this value must
# be larger than upload_max_filesize.
php_value post_max_size 31M
php_value upload_max_filesize 30M
# Short open tags must be on
php_flag short_open_tag on
# Uncomment to enhance security of WebAccess by restricting cookies
# to only be provided over HTTPS connections
# php_flag session.cookie_secure on
# php_flag session.cookie_httponly on
# Uncomment for debugging purposes only. Make sure Apache/PHP can
# write to this file or no errors will be logged!
# php_flag log_errors on
# php_value error_log /var/lib/zarafa-webaccess/error_log
</Directory>

2
zarafa.ini Normal file
View file

@ -0,0 +1,2 @@
; Enable Zarafa mapi extension module
extension=mapi.so

100
zarafa.logrotate Normal file
View file

@ -0,0 +1,100 @@
/var/log/zarafa/archiver.log {
weekly
missingok
rotate 52
compress
delaycompress
notifempty
create 0644 zarafa zarafa
}
/var/log/zarafa/dagent.log {
weekly
missingok
rotate 52
compress
delaycompress
notifempty
postrotate
killall -HUP zarafa-dagent 2> /dev/null || true
endscript
create 0644 zarafa zarafa
}
/var/log/zarafa/gateway.log {
weekly
missingok
rotate 52
compress
delaycompress
notifempty
postrotate
killall -HUP zarafa-gateway 2> /dev/null || true
endscript
create 0644 zarafa zarafa
}
/var/log/zarafa/ical.log {
weekly
missingok
rotate 52
compress
delaycompress
notifempty
postrotate
killall -HUP zarafa-ical 2> /dev/null || true
endscript
create 0644 zarafa zarafa
}
/var/log/zarafa/indexer.log {
weekly
missingok
rotate 52
compress
delaycompress
notifempty
postrotate
killall -HUP zarafa-indexer 2> /dev/null || true
endscript
create 0644 zarafa zarafa
}
/var/log/zarafa/monitor.log {
weekly
missingok
rotate 52
compress
delaycompress
notifempty
postrotate
killall -HUP zarafa-monitor 2> /dev/null || true
endscript
create 0644 zarafa zarafa
}
/var/log/zarafa/server.log /var/log/zarafa/audit.log {
weekly
missingok
rotate 52
compress
delaycompress
notifempty
postrotate
killall -HUP zarafa-server 2> /dev/null || true
endscript
create 0644 zarafa zarafa
}
/var/log/zarafa/spooler.log {
weekly
missingok
rotate 52
compress
delaycompress
notifempty
postrotate
killall -HUP zarafa-spooler 2> /dev/null || true
endscript
create 0644 zarafa zarafa
}

1165
zarafa.spec Normal file

File diff suppressed because it is too large Load diff