Collax Business Server

Release Notes Version 4.1.4

Release date: 10/25/2007

Overview

Update Instructions

To install this update please follow these steps:

Procedure


Contents

Installation Notes

New in this Release

Problems Fixed in this Release

Notes

Restrictions


Installation 4.1.4

Upgrade from Release Version less than 3.0.26

To accomplish the upgrade to version 4.1.x the prior version 3.0.26 needs to be installed. To install the version 3.0.26 please follow the steps "Get Package List", "Get Packages" and "Install".

Please follow the steps "Accomplish Upgrade to Version 4.1.x" if the version CBS 3.0.26 is installed. Please read the release notes for version CBS 4.1.x.

Upgrade from Release 1.X

Please note the hardware requirements if you want to do an upgrade to version 4.1.x.

If your Collax Business Server version is below 2.0.0 please make sure that you do a backup of the intermediate Version 1.18b. To upgrade to the current version a further intermediate step to version 2.5.2, 3.0.6 and 3.0.26 will be accomplished.

Add-on Software: Exchange4Linux End of Life

Software Development for Exchange4Linux had been stalled at the end of year 2006. It is not available anymore within this Collax software upgrade. Please note: Do NOT accomplish the upgrade under any circumstances if you use Exchange4Linux in an active groupware environment. We will be pleased to give you further information for migration of data at sales@collax.com.

Add-on Software: Trend Micro Virus Scanner

Add-on software can be installed via the menu "System Operation -> Software -> Licences". With this update the add-on Trend Micro Virus Scanner can't be installed anymore. A working installation of Trend Micro Virus Scanner will not be effected and can be used further.


New in Release 4.1.4

GUI: New Form "Permissions"

Accesss to services of the Collax Server is controlled by setting permissions in the form "Groups". With this update a separate form "Permissions" is available, where static and dynamic policies are listed well arranged. These permissionis can also be allocated to groups or revoked from groups within this form with ease.

GUI: New Form "Administrative Roles"

With the permission "Roles" it is possible to delegate administrative roles to various user of the Collax Server. To extend these delegable roles the new form "Administrative Roles" is implemented within this software update. Access to selective admin forms can be granted to specific user groups i.e. all e-mail settings can be delegated to a user other than the global administrator "admin".

GUI: Acceleration of Displaying System Logfiles

To get detailed information about a server process system logfiles can be reviewed within the form "System -> Monitoring/Analysis -> Log Files". With this update an index for the system log files is implemented, which will accelerate the display of the selected logfile. The index causes a major improvement in displaying small and huge log files.

GUI: Improved Directory and File Listing in User Web Access

Documents and file shares can be accessed via the web access by users of the Collax Business Server. With this update the file listing and the file identification had been improved, so the files have appropriate icons as marker and file names are displayed in full length of characters within a well arranged table. Additionally the file list can be sorted ascending or descending by the file name, by the date "Last modified" and by the file size.

File: Option "Rekursiv" for Synchronisation

To replicate data of file shares a syncronisation job can be set up in the menu "Settings -> Services -> File Shares -> Synchronisation". With this update the option "Recursive" is available for syncing via "rsync", wich tells the rsync process to copy directories recursively.

E-Mail: Delay Warning Time of a queued email

An email is undeliverable for the Collax Server if the email couldn't be handed over within 5 days. With this update a delay warning message is sent after four hours to the sender. The Server will still try to deliver the email.

E-Mail: Expansion of Address Field "Deliver e-mail to"

For a straight forwarding of incoming emails to addresses other than the user email address the field "Deliver e-mail to" can be used in the user form. The possible values of this field will be expanded within this update, so that a local user, a mailing list or an email alias can be filled in as well as an external email address.

Backup: Backup Directory Using NFS and CIFS/SMB Backup Target

To backup up all system data to various media the integrated backup can be used for that with ease. Using the network media NFS this update renders the definition of subdirectories on such a share to simplify administration. For using a CIFS/SMB network directory the update enables the definition of a hidden share, i.e.fileshare$, as backup target to secure the backup data in the network.

Add-on Software: Outlook-Oxtender 4.2.19 for Windows clients

With this software update a new version of the Outlook-OXtender for Windows clients is available for download, if the software Open-Xchange had been installed. The version 4.2.19 can be downloaded from https://server:8001/oxtender/outlook/ .


Problems Fixed in Release 4.1.4

Security: Cryptography Toolkit OpenSSL

In the source code of the cryptography toolkit OpenSSL security holes have been discovered. These holes will be closed within this Collax software update.

Assigned Common Vulnerabilities and Exposures (CVE) numbers:

CVE-2007-4995 CVE-2007-5135

GUI: State of VPN(IPSec) Connection

In the menu "System -> Monitoring/Analysis -> Status -> VPN(IPSec)" details of VPN connections are displayed. A few details hadn't been displayed correctly since version 4.1.0. With this software update the overview shows again all information of the VPN connections properly.

GUI: Link Status

In the menu "System -> Monitoring/Analysis -> Status -> Link Status" all defined network connections and links can be monitored. A few details hadn't been displayed correctly since version 4.1.0. With this software update the overview shows again all information about the network links properly.

GUI: Forward incoming Fax as Printjob

Incoming faxes can be forwarded via email in variuos formats and to various targets like shares and printers. With this update the form validation is improved if forwarding a fax to a printer. The form can be saved if a printer is set up and the print service had been activated before.

GUI: Display Log if Revoking a Certificate

With the certificate management CA certificates or signed certificates can be generated or exported. For revoking a certificate a Certificate Revokation List (CRL) is needed. With this update the display of the log message is improved if a certificate is revoked or a CRL is generated.

File: SMB-File Shares and MS Office Files

Working in a SMB share and editing Mircosoft Office files has the effect that permissions to read and write this file were revoked from the original owner. To avoid this effect, caused by Microsof Office, the Collax Business Server enforces the read and the write permission for the original owner from this software version on.

File: SMB-File Shares with Write Access for All and Read Access for specific Groups

If "Write permission for all" and "Read permission for specific groups" were set coeval the permission to write did not work for all users. With this update "Write permissions for all" is always effective, even though "Read permissions" were set for specific groups.

File: Apple File Shares with Write Access and Read Access for specific Groups

If "Write permission" or "Read permission" were set to grant access to an Apple share, an owner or an owner group had to be set coeval. With this update it won't be necessary anymore to specify an owner or an owner group to grant read or write permission to the Apple share.

Web Proxy: Delete Custom List from the Web Content Filter

For flexible filtering of URLs the web content filter can be extended with custom URLs lists. Deleting such a custom list had been resulted in an error. With this update this is fixed, custom lists can be deleted as usual.

Certificates: Export and Import of Certificates with Private Key

VPN: Particular Routing to VPN Gateway

For VPN tunnel that use IPSec and have the security gateway also as reachable network routing of the network packets did not work properly within the encrypted connection. With this software update this erroneous routing is fixed, the VPN tunnel will be established and routed correctly.

VPN: VPN to Peer, which uses strikt DH-Groups

To establish a VPN tunnel specific Diffie-Hellman groups are used for key exchange. With this update the negotiation process with gateways that use strict DH groups (NCP clients and other road warriors) is modified, so the VPN tunnel can be established as before.

Fax: Store incoming Facsimile in Share

If working as a fax server it is possible to store incoming facsimiles into a defined share. The showed list of defined shares was faulty and is fixed with this software update.

Hardware: Driver Tigon3 for Broadcom Network Interfaces

With this software update a new version of Tigon3 driver for Broadcom NICs is available.

Add-on Software: Invoke of "Setup" in Groupware Open-XChange

With Version CBS 4.1.2 the invocation of the menu item "Setup" in Open-Xchange groupware resulted with the error "SESSIOND_PORT NOT FOUND". This is fixed with this software update of Collax Business Server.


Notes

Security: 3.0.16: PHP Safe Mode

All web server entities of Collax servers use PHP safe mode from this update on. The following security issues are addressed:

Find details at http://www.php.net/manual/en/features.safe-mode.php

Some software needs safe mode deactivated. To deactivate PHP safe mode globally, enter the following lines as additional options to Web server -> General -> Extras.

You can also disable the safe mode for individual shares, instead of disabling globally, by writing the options like this:

Here the safe mode is disabled only for the share "TestShare".

GUI: 4.1.0: Use of Config Files from Versions before 3.0.0

Configuration files of Collax server are used for easy managing of one or more servers. From this update on the validation of the files has been tightened to increase the usibility Please check the imported files that were saved before version 3.0.0 via the new AJAX gui and correct the values if necessary. The gui will give the information, if any value needs to be modified.

E-Mail: 1.0.2: Sender rewriting and multiple mail domains

The setting "Canonicalize sender address" can be used to rewrite internal email addresses to addresses that can be reached externally.

If you create multiple mail domains, the address is always rewritten to the first matching rewrite address. The order in which mail domains within the LDAP directory are considered for matches can change, though, and is more or less random.

You can work around this problem by configuring the email clients such that the external address is always used for outgoing e-mail.

E-Mail: 3.0.0: Internal User mailadmin with non-local User Database

When the authentication of users is made against a non-local database, e. g. ADS/PDC, please be aware that the user "mailadmin" does not exist on the ADS/PD, because this user is used internally in CBS. Otherwise problems will occur, e. g. during the creation of local mailboxes.

Web Proxy: 2.0.0: Filtering with squidGuard

When using the web-content filter with custom lists which contain URLS and/or domains and/or expressions, it is possible that the filter is not working correctly, and doesn’t block anything. In order to fix this problem please save each list and activate the configuration.

Web Proxy: 3.0.0: Enabling NTLM Authentication Whenever Possible

The NTLM authentication scheme that is usually used by windows client software is now enabled when the support for windows networks has been enabled. It is no longer necessary to enable it separately.

Web Proxy: 3.0.0: NTLM Authentication with Windows 2003 Server

Please note that for being able to authenticate with NTLM against a Windows 2003 Server Service Pack 1 has to be installed.

Web Proxy: 3.0.10: Access Denied Due to Error 250

If the above error message is displayed when surfing over the web proxy and rules are used to limit the web traffic, please check the rules configured under "Settings -> Filter -> Web-Content Filter -> Rules". Load every individual rule by double-clicking the entry. If the message "Please specify at least one URL or Cobion list" is displayed, specify the respective list to be associated with this rule or enable the menu item "All". If no such error message is displayed, you can return to the list of rules by clicking "Cancel". If you changed any of the rules, activate the configuration.

VPN: 4.1.0: VPN tunnel, Connection method Always

To establish an initiating VPN tunnel an additional VPN link with connection method "dial-in" was always required. With this update VPN tunnel with connection method "Always" don't presume a VPN "dial-in" link anymore.

Fax: 2.0.6: Spamlists

It can happen, that hylafax denies facsimiles from callers. In this case, you should deactivate fax spamlists. Please follow this description: The left menu shows Messaging/Fax/General. Deactivate 'Switch on number control'. You can save now and activate the configuration.

Hardware: 3.0.0: FritzCard AVM PCMCIA

It is possible, that problems occur when a FritzCard-AVM-PCMCIA and another different PCMCIA-card are used at the same time. In this case please call the support hotline.

Hardware: 1.1.4: Support for Class-1 Modems and Sedlbauer ISDN Cards

In some cases it was possible that faxes were not submitted correctly so that the header was cut or missing wholly.

If you experience these problems you should set the maximum receive rate to a value below 14.400 Bit/s. You can set this in the MODEM-Page on the GUI.

In order to be able to use the Sedlbauer-ISDN-Card for an analog connection to a provider, the following must be set in "Additional Hayes-Options" : "AT&FS14=10S15=0S18=1&E" followed by the MSN of the ISDN-Card.

Hardware: 1.1.4: Support for Analog Modems

The configuration used within CBS works properly with the most commonly used modems. Nevertheless, it is possible that specific modems cannot be initialized correctly. At the moment, analog links are not used as fallback by the "Link monitoring" .

Add-on Software: 1.1.4: AntiVir-Webgate

The AntiVir-WebGate does not yet support HTTPS which means that HTTPS-connections are not possible in combination with AntiVir-WebGate. So at the moment HTTPS-traffic bypasses this filter.

Misc: 3.0.6: Printer Support over IPP

The print service itself offers its services over the Internet Printing Protocol (IPP). This protocol is directly supported by MacOS X and most Linux distributions. Printers with Ethernet ports can be added to the queues on the Collax Business Server. These printers are also exported over the printer support of the SMB/CIFS server and can be addressed directly over IPP by Windows clients.

Misc: 3.0.10: Replication Logs of the MySQL Database

From update 3.0.12 on, replication logs of the MySQL database are no longer written. If you need these logs, enable the option "log-bin" in the file "/etc/mysql/my.cnf.template" by removing the comment sign preceding this option. Subsequently, run a full configuration over the web interface.

Misc: 3.0.0: SMB/CIFS Service and Group Policy

To integrate the Collax Server for authentification in a Windows server network, the SMB/CIFS service can be used. It is important, that this service has at least one policy group containing a local network.


Restrictions

File: 3.0.0: FTP and virtual hosts

Exporting virtual hosts via FTP is only possible with IP-based virtual hosts. Name-based virtual hosting with FTP is not possible due to limitations in the FTP protocol itself.

E-Mail: 3.0.0: Alternative Namespace and Web Mail

The initial setup of the mailboxes is in conjunction with the option "Alternative namespace". This means that you should decide which format you want to use before the mailboxes are created. When this option is enabled the folders Sent, Draft and Trash are below the folder Inbox. When this option is disabled the folders Sent, Draft and Trash are on the same level as the folder Inbox. When you change the option "Alternative namespace" after the creation of the mailboxes, the Webmailer will show up a error in the following form: "Query: CREATE "INBOX.Sent" and "Reason Given: Invalid mailbox name". The name of the folder can vary.

Web Proxy: 3.0.0: NTLM-Authorization with imported groups

In order to accomplish NTLM-Authorization with an imported group, this group must be a global group on the AD-Server and must be the primary group of the user.

VPN: 2.0.0: Asymmetric Routing

It is not possible to use VPN connections with asymmetric routes if the system is both a router and an IPSec gateway.

This is because IPSec accumulates a checksum of the IP header contents. With asymmetric routing, the IP addresses of the links - over which the data is transmitted and received - do not correspond.

VPN: 2.0.0: Multiple IPSec Connections Between Two Security Gateways

It is not possible to establish multiple IPSec connections for the same networks and the same two security gateways. This is due to how OpenSWAN works internally (keyword "eroutes". Those having trouble with OpenSWAN know what is meant here; a deeper analysis would go beyond the scope of these release notes).

You can set up a GRE-tunnel over the IPSec-tunnel to bypass this problem.

VPN: 4.1.0: SHA2 encryption

The encryption algorhithm SHA2 is used in VPN tunnels. In kernel 2.6 this encryption method causes errors in the service OpenSwan and the VPN tunnel crashs. For that reason this method can't be chosen for VPN links on Collax Server until it is fixed. As an alternativ the method SHA1 can be chosen. Please note that the encryption method needs to be changed and the other VPN gateway modified. The upgrade will choose SHA1 if SHA2 was setup before.

LDAP: 4.1.0: Change of LDAP Base DN

The base DN of the LDAP directory cannot be changed retroactively through the GUI. The reason for this is that not all directory data can be rebuilt from the configuration.

Although data is lost, the easier way is to delete the files in the "/var/lib/openldap/openldap-data" directory, and then recreate the directory.

To achieve that, proceed as follows:

Procedure

Beware: all passwords of all users will be lost after having changed the base DN. You have to enter them again via the Admin GUI.

Add-on Software: 3.0.10: Transparent Proxy, AntiVir Web, and "Show download status"

If a transparent web proxy is activated and the Antivir Web virus scanner is activated together with the "Show download status" option, the download no longer works properly. The download progress is displayed but does not change; after a short while, the browser displays an error message indicating that antivir.webgate cannot be found. To make the download work with the progress bar, enter the proxy in the client or disable the "Show download status" option.