Collax Business Server

Release Notes Version 3.0.8

Release date: 03/29/2006

Overview

Update Instructions

To install this update please follow these steps:

Procedure

Contents

Installation

New in this Release

Problems Fixed in this Release

Notes and Restrictions


Installation 3.0.8

Update from Release 1.X

If your Collax Business Server version is below 2.0.0 please make sure that you do a backup of the intermediate Version 1.18b. To upgrade to the current version a further intermediate step to version 2.5.2 will be accomplished.

exchange4linux-3

If the version of your Collax Business Server is lower than 1.1.6a or 2.0.24, please contact the support hotline for upgrading to the latest version.

New in Release 3.0.8

Mail: "No Rewrite" for Retrieving Mail

Normally, when retrieving mail the RFC-822 headers (To, From, Cc, Bcc, and Reply-To) are rewritten in such a way that local mail IDs are resolved to complete mail address. The new option, which you can find under the settings for the individual external mailboxes, disables this rewriting. Do not enable this option unless you experience difficulties with rejected e-mail.

Hardware: Support of Additional Hard-Disk Controllers

This update supports additional device drivers for the following hard-disk controllers: LSI Logic SAS1064A, LSI Logic SAS1064E, LSI Logic SAS1066, LSI Logic SAS1066E, LSI Logic SAS1068, LSI Logic SAS1068E, LSI Logic SAS1078, LSI Logic FC939X Fibre Channel Adapter, and LSI Logic FC949X Fibre Channel Adapter.

Add-on Software: Update Status of the Collax Virus Protection

From this version, you can determine whether or not the administrator entered under "Virus Scanner -> General -> Anti-Virus Administrator" is to be informed by e-mail about the update status of the Collax Virus Protection. By default, no notification is sent.

Problems Fixed in Release 3.0.8

SEC: Linux Kernel

Apart from expanded hardware support, the kernel features improvements of the Open Source community against buffer overflows and DoS attacks. The patch for version 2.4.32 makes the subroutines getsockname() and getpeername() for IPv4, the Orinoco driver (PCMCIA WLAN), and a function of the e1000 driver more secure. For detailed information about the content of the patch, refer to the following page: http://linux.exosec.net/kernel/2.4-hf/2.4.31/2.4.31-hf32.3/CHANGELOG

SEC: ImageMagick

ImageMagick is a free software suite for creating and editing bitmap images. This update fixes two format-string errors in the application. For more information, refer to the following page: http://lwn.net/Vulnerabilities/168990/

File: Activating the Web Server

After the activation, the web server was not started correctly, but only after going through the entire system configuration. With this update, the web server is started correctly after going through the entire configuration or the different configuration.

Proxy: Web-Proxy Wizard

Using the web-proxy wizard, the use of the web-proxy service can be made vailable for the entire network with a few steps. The automatic adaptation of the firewall rules now also takes existing rules into consideration.

Backup: LDAP Error Message During Restore

The error message "Error: Command to unpack...#LDAPTAG returned bad status 247." used to be displayed even after a successful LDAP restore. With this update, this message no longer appears.

Add-on Software: Collax Virus Protection for File Shares

Collax Virus Protection enables regular virus scanning of files in file shares. So far, this function could only be configured under the file-share settings. From this update on, the file shares to scan can also be configured under the Collax Virus Protection settings.

Add-on Software: Parallel Operation of TrendMicro Virus Scanner and Collax Virus Protection Mail

When using the TrendMicro virus scanner alongside the Collax Virus Protection e-mail filter, the TrendMicro virus scanner did not pass on the the e-mail to the following filter of the Collax Virus Protection, but forwarded them to the internal mail server for delivery. With this update, all e-mail is passed through all activated filters.

Notes and Restrictions

File: FTP and virtual hosts

Exporting virtual hosts via FTP is only possible with IP-based virtual hosts. Name-based virtual hosting with FTP is not possible due to limitations in the FTP protocol itself.

Mail: Sender rewriting and multiple mail domains

The setting "Canonicalize sender address" can be used to rewrite internal email addresses to addresses that can be reached externally.

If you create multiple mail domains, the address is always rewritten to the first matching rewrite address. The order in which mail domains within the LDAP directory are considered for matches can change, though, and is more or less random.

You can work around this problem by configuring the email clients such that the external address is always used for outgoing e-mail.

Mail: Internal User mailadmin with non-local User Database

When the authentication of users is made against a non-local database, e. g. ADS/PDC, please be aware that the user "mailadmin" does not exist on the ADS/PD, because this user is used internally in CBS. Otherwise problems will occur, e. g. during the creation of local mailboxes.

Mail: Alternative Namespace and Web Mail

The initial setup of the mailboxes is in conjunction with the option "Alternative namespace". This means that you should decide which format you want to use before the mailboxes are created. When this option is enabled the folders Sent, Draft and Trash are below the folder Inbox. When this option is disabled the folders Sent, Draft and Trash are on the same level as the folder Inbox. When you change the option "Alternative namespace" after the creation of the mailboxes, the Webmailer will show up a error in the following form: "Query: CREATE "INBOX.Sent" and "Reason Given: Invalid mailbox name". The name of the folder can vary.

Proxy: Filtering with squidGuard

When using the web-content filter with own lists which contain URLS and/or domains and/or expressions, the error that the filter doesn't work properly and thus doesn't block anything might occur. In order to fix this problem please save each list and activate the configuration.

Proxy: Enabling NTLM Authentication Whenever Possible

The NTLM authentication scheme that is usually used by windows client software is now enabled when the support for windows networks has been enabled. It is no longer necessary to enable it separately.

Proxy: NTLM Authentication with Windows 2003 Server

Please note that for being able to authenticate with NTLM against a Windows 2003 Server Service Pack 1 has to be installed.

Proxy: NTLM-Authorization with imported groups

In order to accomplish NTLM-Authorization with an imported group, this group must be a global group on the AD-Server and must be the primary group of the user.

VPN: Outbound IPSec Links

Because of a limitation in the IPSec implementation (OpenSWAN), IPSec can only be used with four different network interfaces. In particular, this leads to problems involving failovers and outgoing IPSec connections.

You can (and must) select the interface that you will use to create a VPN link. For this link, select "dial-in" in the "initiate" field. Then, in the "on Link" field, choose the network link over which the IPSec data will be forwarded.

Additionally, if you wish to prevent these links from being used to establish an inbound connection to your local network, you must specify the system certificate as your own certificate as well as the receiver's certificate.

VPN: VPN and Asymmetric Routing

It is not possible to use VPN connections with asymmetric routes if the system is both a router and an IPSec gateway.

This is because IPSec accumulates a checksum of the IP header contents. With asymmetric routing, the IP addresses of the links - over which the data is transmitted and received - do not correspond.

VPN: Multiple IPSec Connections Between Two Security Gateways

It is not possible to establish multiple IPSec connections for the same networks and the same two security gateways. This is due to how OpenSWAN works internally (keyword "eroutes". Those having trouble with OpenSWAN know what is meant here; a deeper analysis would go beyond the scope of these release notes).

You can set up a GRE-tunnel over the IPSec-tunnel to bypass this problem.

VPN: VPN and Traffic Shaping

Because VPN connections are handled as network devices some limitations apply to traffic shaping inside VPN tunnels. Concrete this means classification information can be lost for data transmitted inside a VPN tunnel.

VPN: Reachable Networks and VPN Links

All networks that are reachable through a VPN link must also be specified as reachable networks in the respective dial-in link.

LDAP: Change of LDAP Base DN

The base DN of the LDAP directory cannot be changed retroactively through the GUI. The reason for this is that not all directory data can be rebuilt from the configuration.

Although data is lost, the easier way is to delete the files in the "/var/lib/openldap/openldap-data" directory, and then recreate the directory.

To achieve that, proceed as follows:

Procedure

Beware: all passwords of all users will be lost after having changed the base DN. You have to enter them again via the Admin GUI.

Fax: Hylafax Fax Spamlists

HylaFAX may reject fax messages from certain numbers. If this happens, disable the fax spam lists as follows: Go to "Mail and Messaging -> Fax and SMS -> General" and disable "Number control" . Then save and activate the configuration.

Hardware: FritzCard AVM PCMCIA

It is possible, that problems occur when a FritzCard-AVM-PCMCIA and another different PCMCIA-card are used at the same time. In this case please call the support hotline.

Hardware: Support for Class-1 Modems and Sedlbauer ISDN Cards

In some cases it was possible that faxes were not submitted correctly so that the header was cut or missing wholly.

If you experience these problems you should set the maximum receive rate to a value below 14.400 Bit/s. You can set this in the MODEM-Page on the GUI.

In order to be able to use the Sedlbauer-ISDN-Card for an analog connection to a provider, the following must be set in "Additional Hayes-Options" : "AT&FS14=10S15=0S18=1&E" followed by the MSN of the ISDN-Card.

Hardware: Support for Analog Modems

The configuration used within CBS works properly with the most commonly used modems. Nevertheless, it is possible that specific modems cannot be initialized correctly. At the moment, analog links are not used as fallback by the "Link monitoring" .

Add-on Software: AntiVir-Webgate

The AntiVir-WebGate does not yet support HTTPS which means that HTTPS-connections are not possible in combination with AntiVir-WebGate. So at the moment HTTPS-traffic bypasses this filter.

Add-on Software: Proxy Authentication with TrendMicro Interscan VirusWall

The web filter of the TrendMicro VirusWall can not authenticate against other proxies. If a remote proxy requires authentication, the web filter of the VirusWall cannot be used. Workaround: enable AntiVir WebGate additionally which is able to authenticate itself against a different proxy.

Add-on Software: Cobion URL Filter

Refer to the release notes for version 3.0.0 if you update from a version older than 3.0.0.

Add-on Software: TrendMicro Virus Filter and Spam Filter

If the TrendMicro virus filter is used together with the spam filter, and the option "Forward as text attachment" is selected for the spam filter, e-mail messages identified as spam and forwarded as text attachments are processed by the TrendMicro virus filter, but not checked for viruses. However, the virus check works with all other options offered under this menu item ("Do not change" or "Forward as e-mail attachment"). If a second virus filter is used, infested spam e-mails will be intercepted by this virus filter.

Misc: Licensing - Restriction to 5 Users on CD-Installed Systems

If your CBS was installed from a CD, after this update only the first five users will be shown in the administration GUI. All other users are still existent on the system and do not affect the functionality of the server. In order to unmake these restrictions you can clear your license with our support: support@collax.com. Wether you own a CD-installed system or not can be seen from the text on the top of the administration GUI.

Misc: Printer Support over IPP

The print service itself offers its services over the Internet Printing Protocol (IPP). This protocol is directly supported by MacOS X and most Linux distributions. Printers with Ethernet ports can be added to the queues on the Collax Business Server. These printers are also exported over the printer support of the SMB/CIFS server and can be addressed directly over IPP by Windows clients.