Authentication Bypass in MailboxImportServlet vulnerability (reminder)
https://blog.zimbra.com/2022/08/authentication-bypass-in-mailboximportservlet-vulnerability/

Search found 25 matches

by chris_60
Sat Oct 08, 2022 1:00 am
Forum: Installation and Upgrade
Topic: zmmailboxdctl failing to run after most recent apt-get
Replies: 54
Views: 27485

Re: zmmailboxdctl failing to run after most recent apt-get

Just registered to inform you guys about the same problem. My system is Centos 7. And for avoiding this problem I had to downgrade some packages: Removed: zimbra-core-components.x86_64 0:3.0.12-1zimbra8.8b1.el7 zimbra-jetty-distribution.x86_64 0:9.4.46.v20220331-2.r7 zimbra-ldap-components.x86_64 0...
by chris_60
Fri Apr 29, 2022 1:03 pm
Forum: Administrators
Topic: [FIXED] Variation on the theme: invoke PKIX path building failed...
Replies: 3
Views: 1190

[FIXED] Re: Variation on the theme: invoke PKIX path building failed...

Fixed:

Code: Select all

zimbra@foomail:~$ /opt/zimbra/common/bin/keytool -import -alias foo.bar -keystore /opt/zimbra/common/etc/java/cacerts -file /etc/letsencrypt/live/foo.bar/chain.pem


I would have thought that fullchain.pem included chain.pem, but it did not.
by chris_60
Fri Apr 29, 2022 12:28 pm
Forum: Administrators
Topic: [FIXED] Variation on the theme: invoke PKIX path building failed...
Replies: 3
Views: 1190

Re: Variation on the theme: invoke PKIX path building failed...

Doing more digging: zimbra@foomail:~$ zmprov -d gcf zimbraMailTrustedIP ========== SOAP SEND ========== <soap:Envelope xmlns:soap="http://www.w3.org/2003/05/soap-envelope"> <soap:Header> <context xmlns="urn:zimbra"> <nosession/> <userAgent name="zmprov" version="9....
by chris_60
Thu Apr 28, 2022 7:25 pm
Forum: Administrators
Topic: [FIXED] Variation on the theme: invoke PKIX path building failed...
Replies: 3
Views: 1190

[FIXED] Variation on the theme: invoke PKIX path building failed...

OS: Ubuntu 18.04.6 LTS Zimbra: 9.0.0.ZEXTRAS.202007114.UBUNTU18.64 UBUNTU18_64 FOSS edition, Patch 9.0.0_P14 Yet another variation on this error: zimbra@foomail:~$ zmprov gcf zimbraMailTrustedIP ERROR: zclient.IO_ERROR (invoke PKIX path building failed: sun.security.provider.certpath.SunCertPathBuil...
by chris_60
Mon Jan 24, 2022 1:29 pm
Forum: Administrators
Topic: Rspamd: Fast, free and open-source spam filtering system
Replies: 225
Views: 3159537

Re: Rspamd: A replacement for Spamassassin & Postscreen

Thank-you mgarbin! I almost have this working now. I have put the location block into a include file as you suggested under a folder /opt/zimbra/conf/local I have added an include statement to both of the following templates: /opt/zimbra/conf/nginx/templates/nginx.conf.web.https.default.template /op...
by chris_60
Fri Jan 14, 2022 7:14 pm
Forum: Administrators
Topic: Rspamd: Fast, free and open-source spam filtering system
Replies: 225
Views: 3159537

Re: Rspamd: A replacement for Spamassassin & Postscreen

phoenix wrote:Why don't you just connect directly to your Rspamd instance?


The native client has no SSL capabilities.
by chris_60
Fri Jan 14, 2022 5:47 pm
Forum: Administrators
Topic: Rspamd: Fast, free and open-source spam filtering system
Replies: 225
Views: 3159537

Re: Rspamd: A replacement for Spamassassin & Postscreen

Good day all, I would like to add a proxy element to Zimbra's nginx configuration to proxy requests to the Rspamd web UI. Per the Rspamd docs this is what is required for nginx: location /rspamd/ { proxy_pass http://localhost:11334/; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_ad...
by chris_60
Mon Nov 15, 2021 2:29 pm
Forum: Administrators
Topic: Milter Server Not Observing IP Listening Configuration
Replies: 2
Views: 3585

Re: Milter Server Not Observing IP Listening Configuration

So it appears a workaround here is to add a FW rule restricting traffic to this port to the lo IF.

I'm assuming at this point it must be a problem unique to this installation. :?
by chris_60
Thu Nov 04, 2021 6:59 pm
Forum: Administrators
Topic: Milter Server Not Observing IP Listening Configuration
Replies: 2
Views: 3585

Re: Milter Server Not Observing IP Listening Configuration

Any thoughts on this issue would be appreciated.

Chris
by chris_60
Fri Oct 29, 2021 1:23 pm
Forum: Administrators
Topic: Milter Server Not Observing IP Listening Configuration
Replies: 2
Views: 3585

Milter Server Not Observing IP Listening Configuration

Release 9.0.0.ZEXTRAS.202007114.UBUNTU18.64 UBUNTU18_64 FOSS edition, Patch 9.0.0_P14 Milter status: zimbra@mail:~$ zmmilterctl status Milter server is running. Current configuration: zimbra@mail:~$ zmprov gs mail.foobar.com | egrep -i zimbraMilter zimbraMilterBindAddress: 127.0.0.1 zimbraMilterBind...

Go to advanced search