This blog is about something that is not a Zimbra feature, yes you read it correctly, usually on the blog we highlight new or existing features. But this blog is a little different. Every now and then people write in the Zimbra forums or comment on blog posts saying they run Zimbra with SELinux in […]
Archive | PowerTips – Admins
Zimbra not affected by critical OpenSSL issue
The OpenSSL project is releasing a critical fix for OpenSSL version 3.x. Zimbra is using OpenSSL version 1.1.1q which is an older still supported version of OpenSSL. The version in Zimbra is not affected by the fix, which means no patches are needed for Zimbra. You should install operating system security updates and other 3rd […]
Did you know? Basic Authentication will be disabled in Exchange Online
Did you know that as of this month Microsoft will randomly select customers and disable Basic Authentication on their Exchange Online services? While from a pure security perspective username and password authentication is outdated, you may still have issues with devices that can only support username and password authentication. For example legacy business applications, multifunction […]
Zimbra installation integrity check
The script in this article allows Zimbra administrators to create checksums of all the files in a Zimbra installation. The output of the script can be used to identify unintended changes and newly created files. Such changes can for example be caused by hackers. You can use this script pro-actively by scheduling it in a […]
Security Update – make sure to install pax/spax
All Zimbra administrators should make sure the pax package is installed on their Zimbra server. Pax is needed by Amavis to extract the contents of compressed attachments for virus scanning. If the pax package is not installed, Amavis will fall-back to using cpio, unfortunately the fall-back is implemented poorly (by Amavis) and will allow an […]
Proxy the Admin Console via Zimbra Proxy increase TLS security
The Admin Console web-ui is the go-to place for managing your Zimbra installation. Historically the Zimbra Admin Console was accessed directly without Zimbra Proxy. However there is no longer a need to access the Admin Console without using Zimbra Proxy. And to make sure the Admin Console uses the best TLS security you need to […]