Admin Account authentication now honors zimbraAuthFallbackToLocal when using external/custom authentication

Zimbra supports various authentication sources for authenticating users. Examples include external LDAP, Active Directory and custom authentication plugins.

Prior to Zimbra 10.0.8 the setting of zimbraAuthFallbackToLocal had no effect on administrative accounts. Meaning you could use the username and password from Zimbra LDAP for signing on to an admin account. Even if the admin account is non-existing in the external authentication source or you entered a password that does not match the external authentication source.

In some cases people installing Zimbra would use a simple password when installing Zimbra, then set-up external authentication and did not realize the original simple password was still working. In addition someone could set an admin password on the Zimbra LDAP to create something that could be seen as a back door, as this effectively bypasses external authentication.

To improve Zimbra security and adhere to more modern auditing requirements, from Zimbra 10.0.8 onwards the setting of zimbraAuthFallbackToLocal will be honored for administrative accounts as well as regular accounts. The recommended setting when using external authentication is:

zmprov md example.com zimbraAuthFallbackToLocal FALSE

 

If you are unable to add your admin account to your external authentication source, you are recommended to follow the steps here:

https://wiki.zimbra.com/wiki/How_To_Create_an_Admin_Account#How_to_regain_access_to_admin_account_if_using_external_LDAP_or_Active_Directory_authentication

 

This blog post also applies on Zimbra 9.0 P40 which has reached End of General Support.

,

2 Responses to Admin Account authentication now honors zimbraAuthFallbackToLocal when using external/custom authentication

  1. Michael Hart April 26, 2024 at 1:33 PM #

    “This blog post also applies on Zimbra 9.0 P40 which has reached End of General Support.”

    Zimbra 9.0 General Support was extended and ends on 12/31/2024.

    • Avatar photo
      Barry de Graaff May 1, 2024 at 2:16 AM #

      It is only extended for existing customers.

Leave a Reply

Copyright © 2022 Zimbra, Inc. All rights reserved.

All information contained in this blog is intended for informational purposes only. Synacor, Inc. is not responsible or liable in any manner for the use or misuse of any technical content provided herein. No specific or implied warranty is provided in association with the information or application of the information provided herein, including, but not limited to, use, misuse or distribution of such information by any user. The user assumes any and all risk pertaining to the use or distribution in any form of any subject matter contained in this blog.

Legal Information | Privacy Policy | Do Not Sell My Personal Information | CCPA Disclosures