Collax Business Server

Release Notes Version 5.0.2

Release date: 06/29/2008

Accomplish Upgrade to Version 5.0.2

To install this update please follow these steps:



Contents

New in this Version

Issues Fixed in this Version

Known Issues

Upgrade from Version less than 4.1.26

To accomplish the upgrade to version Collax Business Server 5.0.2 the prior version 4.1.26 needs to be installed. To install the version 4.1.26 please follow the steps "Get Package List", "Get Packages" and "Install".


Please follow the steps "Accomplish Upgrade to Collax Business Server Version 5.0.2" if the version 4.1.26 is installed. Please read the release notes to the appropriate version.


Check File System

Before upgrading the server a check of the file system should be carried out. The file system check is available in the boot menu of the server. To lead the check by, a display and a keyboard must be connected to the server and afterwards a restart needs to be executed. After loading the BIOS the file system check can be selected in the boot menu. As a result the file system is checked and suitable state messages are displayed. If the file system is in order the server starts and the upgrade can be carried out. Technical questions to the file system check can be placed to your certificated Collax partner or to the support team by Collax.


Duration of Upgrade

Depending on your existing server installation up to 320 software components will be downloaded and replaced. So the total duration of the upgrade process will take between 45 minutes and 180 minutes.



New in Version 5.0.2

Security: Firewall Tftp Connection Tracker

If services use undeterminable ports for the data transfer connection tracker are used for the firewall to establish and track such connections. With this update the connection tracker for the trivial file transfer protocol (tftp) can be activated in the firewall when required. Connections about this protocol can be set up and logged with it.


GUI: SMTP outbound and SMTP receiption Forms

With the new version the setup of the e-mail service SMTP is split in two forms instead of one. The setup of SMTP is directed now whether e-mails are dispatched (SMTP outbound for system information e-mails), or whether e-mails in different accounts, e-mail lists, or several e-mail domains should be administered (SMTP reception).


GUI: X.509 certificates and Certificate Signing Requests Forms

The administration of certificates become easier with the new version where the content was split into two forms: X.509 certificates and Certificate Signing Requests (CSR).


GUI: Wizard for registration of license keys

From this version the new wizard is available for the simplistic registration of licence data used. The wizard resembles with Collax deposited licensee's information from leads the user gradual through the registration process.


E-Mail: Primary Email Address

From this version it is possibly to define a primary e-mail address on the Collax server. Just by the use of several e-mail domains the Collax server offers now centrally very adaptable setting possibilities to assign a primary sender's address for user groups. The primary e-mail address can be customised by means of a determinable address structure and the weighting of the e-mail domains for the needs of single groups. These settings are able in the form Settings-> Mail and Messaging-> SMTP receiption within the tab Options. Furthermore the possibility to set an individually sender's address for every user exists within the form Settings-> Usage Policy -> Users.


Add-on Software: New Version of Collax Virus Protection

The virus scanner Collax Virus Protection offers comprehensive antivirus protection for email services. Within this Collax system update the scanner is updated to the newest version.


The options for "Email disinfection", "Damaged Email" and "Alerts" are omitted from this update on. Emails can additionally be copied to quarantine (mail queue for hold mails) if they had been cleaned or before they shall be deleted.


Attention: Please start a manual pattern update by clicking the button "Get Updates" at the bottom of the form in Settings -> Filter -> Collax Virus Protection, Tab Mail. This update is necessary to start the services successfully.


System Management: Monitoring of Services

All enabled services of the Collax servers are checked on their working mode, f.e.: running or stopped. The status is indicated in the form "System-> monitoring / evaluation-> state-> services". If the active monitoring is switched on, the services are also tested qualitatively. The status whether the function of the service is all right, or whether problems occured during operation have appeared (Bsp: OK, WARNING, CRITICAL). Configuration -> Monitoring" is indicated in the new column "Test".


System Management: Extension of System Information

Up to now information about CPU, RAM and hard disks were displayed as system information. From this update it is possible to gather detailed graphic information about file system, hard disks and network interfaces.


System Management: Logging of Firewall Rules

It is regulated within the Firewall matrix which network connections running thru the Collax server are permitted or are forbidden. To simplify the logging of these regulated network connections the option "Logging for the Firewall Matrix" can be set now in the form "Settings->Networking->Firewall->General->Options". Up to now this setting needed to be activated for each single connection. The logging of permissible or forbidden connections will be applied in general on all firewall rules, explicitly or implicitly, and thereby it eases the use and the reporting of the rules.


System Management: Extended Active-Directory Integration

Up to now the integration of Collax server in Microsoft ActiveDirectory was used to authenticate the users against in the ActiveDirectory. This function is going to be extended with this software version to read user-related data from the ActiveDirectory, this data is going to be used within the Collax services to provide a full centralized user management via Microsoft ActiveDirectory. This function can be activated via Settings -> Usage Policy -> PDC/ADS -> Enable Active Directory proxy.


Misc: Add-on Modul Collax Net Security available

Ab diesem Software-Update kann das Modul im Menü "System->Systembetrieb->Software->Lizenzen und Module" mit einer zusätzlichen Lizenz aktiviert werden, anschließend kann das Modul installiert werden.


The module Collax Net Security unites all important security and network functionalities, those of a gateway can be expected. With this module new functions like Multi-WAN-Access, L2TP-VPN, SSL-VPN, VPN Wizard, Intrusion Detection and Intrusion Prevention (IDS/IPS) are available for the Collax Business Server within this add-on.


From this software update the module can be activated in the menu "System -> System Operation -> Software -> Licences and Modules" with an additional licence, afterwards the add-on can be installed.


Misc: Add-on Modul Collax Mail Security available

Ab diesem Software-Update kann das Modul im Menü "System->Systembetrieb->Software->Lizenzen und Module" mit einer zusätzlichen Lizenz aktiviert werden, anschließend kann das Modul installiert werden.


The module Collax Mail Security protects workstations and servers against all dangers which e-mail traffic can include. This module has available the Spam filter steps Greylisting, tar pit emulation and a reputation filter (Razor check) as well as the virus scanner ClamAV as add-ins for the Collax Business Server.


From this software update the module can be activated in the menu "System -> System Operation -> Software -> Licences and Modules" with an additional licence, afterwards the module can be installed.


Hardware: iSCSI Initiator

iSCSI makes the use of the SCSI protocol on a TCP/IP network possible. From this version the function of the controller, the iSCSI initiator, is implemented in the Collax server. With the iSCSI initiator storage devices in the network (iSCSI Targets) are integrated transparent as local storage devices. To the functions of the iSCSI initiator counts the target discovery, to integrate storage devices fast on the network, as well as the possibility of the authentication to establish a reliable connection to the iSCSI-Target.


Hardware: Driver for 10GB Network Interface Cards

The driver for 10gigabit network interface cards will be implemented within kernel version 2.6.25.20. These driver support the following NICs: Chelsio 10Gb Ethernet, Chelsio Communications T3 10Gb Ethernet, Intel(R) 10GbE PCI Express, Intel(R) PRO/10GbE PCI-X, S2IO 10Gbe XFrame NIC, NetXen Multi port (1/10) Gigabit, Sun Neptune 10Gbit, Tehuti Networks 10G, Broadcom NetXtremeII 10Gb.



Problems Fixed in Version 5.0.2

Security: Cryptography Toolkit OpenSSL

In the source code of the cryptography toolkit OpenSSL 0.9.8k security holes have been discovered. These holes will be closed within this Collax software update.


Assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2009-0590 CVE-2009-0591 CVE-2009-0789


Security: GNU TLS and SSL implementation

In the source code of GnuTLS security holes have been discovered. These holes will be closed within this Collax software update.


GnuTlS 2.6.6 is going to be installed and fixes the assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2008-4089 CVE-2009-1415 CVE-2009-1416 CVE-2009-1417


Security: Udev, Dynamic Device Management

In the source code of GnuTLS security holes have been discovered. These holes will be closed within this Collax software update.


A patch for udev 126 is going to be installed and fixes the assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2009-1185


Security: VPN IKE Daemon Pluto

In the source code of the IKE daemon Pluto security holes have been discovered. These holes will be closed within this Collax software update.


A patch for Pluto 2.4.9 is going to be installed and fixes the assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2009-0790


Security: GNU data type library glib2

In the source code of glib2 security holes have been discovered. These holes will be closed within this Collax software update.


A patch for glib2 2.18.2 is going to be installed and fixes the assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2008-4316


Security: Authentification library libsasl2

In the source code of system library libsasl2 security holes have been discovered. These holes will be closed within this Collax software update.


A patch for libsasl2 is going to be installed and fixes the assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2009-0688


Security: System library libfreetype

In the source code of system libraries libfreetyp security holes have been discovered. These holes will be closed within this Collax software update.


A patch for libfreetype is going to be installed and fixes the assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2009-1416


Security: SquirrelMail Web Mail

In the source code of web mailer SquirrelMail security holes have been discovered. These holes will be closed within this Collax software update.


SquirrelMail 1.4.18 is going to be installed and fixes the assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2009-1578 CVE-2009-1579 CVE-2009-1580 CVE-2009-1581


Security: Samba, Windows SMB/CIFS Server for UNIX

In the source code of the Windows SMB/CIFS fileserver Samba security holes have been discovered. These holes will be closed within this Samba software patch for version 3.0.34.


Assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2009-1888


GUI: Implicit Rules of Services Firewall-Matrix

The Firewall matrix offers a unique visual representation of regulated network connections. In addition, the matrix prevents unintentional false configuration of Firewall rules by the fact, that the order of the rules automatically and properly is generated. The visual representation of implied rules with uncertain networks and certain services was not correct, this is corrected from this update on.



Known Issues

Security: Cryptography Toolkit OpenSSL

In the source code of the cryptography toolkit OpenSSL 0.9.8k security holes have been discovered. These holes will be closed within this Collax software update.


Assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2009-1387


Security: Grafic Tool ImageMagick

In the source code of the grafic tool ImageMagick security holes have been discovered. These holes will be closed within this Collax software update.


Assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2009-1882


Security: Library for Layout and Rendering of Text Pango

In the source code of the library pango security holes have been discovered. These holes will be closed within this Collax software update.


Assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2009-1194


Security: Linux Kernel

In the source code of the Linux kernel a critical security hole has been discovered. This hole is going to be closed within this patch for the Linux kernel version 2.6.25.


Assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2009-2692


Security: Web Server Apache

In the source code of the Apache webserver security holes have been discovered. These holes will be closed within this Collax software update.


Apache 2.2.12 will be installed. Assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2009-1891 CVE-2009-1195 CVE-2009-1890 CVE-2009-1191 CVE-2009-0023 CVE-2009-1955 CVE-2009-1956


Security: DHCP Server

In the source code of the dhcp server security holes have been discovered. These holes will be closed within this Collax software update.


Dhcpd 3.1.2p1 will be installed. Assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2009-0692


Security: Internet Domain Name Server Bind

In the source code of the Internet Domain Name Server security holes have been discovered. These holes will be closed within this patch update for Bind version 9.5.1.


Assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2009-0696


Security: Download Tool Curl

In the source code of the download tool curl security holes have been discovered. These holes will be closed within this patch update for curl version 7.19.0


Assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2009-2417


Security: VPN IKE Daemon Pluto

In the source code of the IKE daemon pluto security holes have been discovered. These holes will be closed within this patch update for pluto version 2.4.9


Assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2009-2185


Security: Graphics Librarie Libpng3

In the source code of the graphics library Libpng3 security holes have been discovered. These holes will be closed within this Collax software update to version libpng3 1.2.39.


Assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2009-2042


Security: Internet Domain Name Server Bind

In the source code of the Internet Domain Name Server security holes have been discovered. These holes will be closed within this patch update for Bind version 9.5.1.


Assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2009-4022


Security: Unix printing system CUPS

In the source code of the unix printing system CUPS security holes have been discovered. These holes will be closed within this Collax software patches for version cups 1.3.11.


Assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2009-2820


Security: IMAP Service Cyrus

In the source code of the unix printing system CUPS security holes have been discovered. These holes will be closed within this Collax software patches for version cyrus 2.3.13.


Assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2009-2632


Security: Fetchmail Service

In the source code of the unix printing system CUPS security holes have been discovered. These holes will be closed within this Collax software patches for version fetchmail 6.3.11.


Assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2009-2666


Security: Directory Service OpenLDAP

In the source code of the directory service OpenLDAP security holes have been discovered. These holes will be closed within this Collax software update to version OpenLDAP 2.4.19.


Assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2009-3767


Security: MySQL Administration phpmyadmin

In the source code of the MySQL administration phpmyadmin security holes have been discovered. These holes will be closed within this Collax patch update of version phpmyadmin 2.11.9.5.


Assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2009-3697 CVE-2009-3696


Security: Samba, Windows SMB/CIFS Server for UNIX

In the source code of the Windows SMB/CIFS fileserver Samba security holes have been discovered. These holes will be closed within this Samba software patch for version 3.0.34.


Assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2009-2813 CVE-2009-2906 CVE-2009-2948


Security: Linux Kernel

In the source code of the Linux Kernel security holes have been discovered which will be closed within this update. Furthermore newer versions of the e1000e- and igb-driver for intel networkcards will be installed.


Security: Network Time Protocol Daemon Ntp

In the source code of the network time protocol daemon Ntp security holes have been discovered. These holes will be closed within this Collax software update.


Assigned CVE numbers: CVE-2009-3563


Security: Linux Kernel 2.6.25

In the source code of the Linux kernel security holes have been discovered. These holes will be closed within these patches for the Linux kernel 2.6.25.


Assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2005-4881 CVE-2009-1633 CVE-2009-2848 CVE-2009-2903 CVE-2009-2910 CVE-2009-3001 CVE-2009-3002 CVE-2009-3238 CVE-2009-3547 CVE-2009-3612 CVE-2009-3621 CVE-2009-3726 CVE-2009-3939 CVE-2010-0007 CVE-2010-0415


Security: Internet Domain Name Server Bind

In the source code of the Internet Domain Name Server security holes have been discovered. These holes will be closed within this patch update for Bind version 9.5.2.


Assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2010-0382 CVE-2010-0290 CVE-2010-0097


Security: Cryptography Toolkit OpenSSL

In the source code of the cryptography toolkit OpenSSL 0.9.8k security holes have been discovered. These holes will be closed within this Collax software update.


Assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2009-4355


Security: Compression Utility gzip

In the source code of the compression utility gzip security holes have been discovered. These holes will be closed within this patch update for the gzip 1.3.12.


Assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2009-2624 CVE-2010-0001


Security: ClamAV

In the source code of the virus scanner ClamAV security holes have been discovered. These holes will be closed within this software update to the version 0.96.


After updating and the automatically reboot of your Collax Server you have to do a manual pattern update under Settings->Filter->Virus Scanner->ClamAV.


Security: Samba, Windows SMB/CIFS Server for UNIX

In the source code of the Windows SMB/CIFS fileserver Samba security holes have been discovered. These holes will be closed within this Samba software patch for version 3.0.37.


Assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2010-2063


Security: GNU data type library glib2

In the source code of glib2 security holes have been discovered. These holes will be closed within this Collax software update.


A patch for glib2 2.18.2 is going to be installed and fixes the assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2009-3289


Security: Graphics Librarie Libpng3

In the source code of the graphics library Libpng3 security holes have been discovered. These holes will be closed within this Collax software update to version libpng3 1.2.44.


Assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2010-0205 CVE-2010-1205


Security: Graphics Libraries Libtiff

In the source code of the graphics library Libtiff security holes have been discovered. These holes will be closed within this Collax software update.


Assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2010-1411


Security: Python Language Interpreter and Runtime

In the source code of the Python language interpreter and runtime security holes have been discovered. These holes will be closed within this Collax software update to version 2.6.5.


Assigned Common Vulnerabilities and Exposures (CVE) numbers:


CVE-2010-1449 CVE-2010-1450 CVE-2010-1634


GUI: Support of Firefox 3.6

The Firefox browser version 3.6 uses a new method getBoundingClientRect to provide offset coordinates of an element. Previous Firefox versions use the method getBoxObjectFor. Both methods are supported by the administration GUI from this update on. Operations, like right mouse click can be executed using Firefox 3.6.


File: FTP Command NLST

Executing the NLST command on a non matching file within a ftp connection the ftp server gave the feedback "150 Opening ASCII mode data connection for file list", afterwards "450 No files found" and the data connection quits. This behaviour it is corrected with this update. After a NLST command on a file that is not available the message "450 No files found" is correctly returned and the data connection remains established.


File: File Download via SSL and Internet Explorer

If downloading files from the Collax server via HTTPS on Collax Webaccess with Internet Explorer the message


could be displayed. With this Collax update the option "unsetCacheControl" can be set for the according file share. If the Internet Explorer is provided with the Hotfix, files can be downloaded correctly afterwards.


File: Web access and File Share Access

In the Collax Webaccess file share can be accessed via a browser. Under circumstances access to file shares via webaccess was not possible any more. From this update the webaccess authorisations are corrected in relation on file shares which the authorised group may read or write.


File: Domain Single-Sign-On

To be able to use Single-Sign-On you have to reactivate all settings after joining a domain.


E-Mail: SIEVE und Squirrel Web Mail

Since the version 5.0.2 Sieve rules (Absence note / holiday note) couldn't be set up with the Squirrel webmail: "Could not log on to timsieved daemon on your IMAP server 127.0.0.1:2000. Please contact your administrator." With the version 5.0.4 this behaviour is repaired, rules for absence notes etc. are created.


E-Mail: Display of SIEVE Rules and Squirrel Web Mail

In version 5.0.4 Sieve rules (Absence note / holiday note) were not displayed within Squirrel. With the version 5.0.6 this behaviour is repaired, rules for absence notes etc. are displayed.


Note! For the correct functionality it can be necessary to execute the following steps within Squirrel-Webmail: "Options" -> "Display Preferences" -> "Use Javascript" -> "Always", then klick "Submit" again.


E-Mail: Spam False Positives at the year 2010

Emails had been qualified more and more incorrectly as Spam if they had sent in 2010. This is fixed with this update, such emails are going to be qualified correctly.


E-Mail: Fetch Emails and Email Lists

When fetching emails from external email boxes the option "Forward to mailing list" can be used. If no mailing list was defined this led to the fact that the service to fetch emails had not been launched. With this update the field will be validated, thereby a faulty input is not possible any more.


E-Mail: Train Spam Filter; manual and automatic

Up to now it was not possibly to train the spam filter exclusive by hand with spam and Ham folder. From this update it is possibly to feed the spam and ham folder by hand at first. In the following the option "Automatic training" can be used to reach the best possible spam filtering result.


E-Mail: Release of Held Emails

If e-mails are stopped by defined filters for attachments or MIME under circumstances it was not possible to release this e-mail again. The release of such to hold e-mails is corrected with this update. If e-mails are released via the administration GUI they are passed to the next instance of the SMTP server and they are delivered to the receiver.


E-Mail: Filtering E-Mails globally and per Domain

If e-mails were fetched via POP3 or IMAP from external servers, e-mails are delivered directly as "user@FQDN" . In this case e-mails can be filtered only if the option "Global mail filter" was set. If this option was not set, but was substituted with selective filtering per e-mail domain, e-mails hadn't been neither stored into e-mail archives nor filtered on Spam or viruses. From this update the option "Global mail filter" needs to be set to archive e-mails or to filter fetched e-mails on Spam and viruses. If at least one of both functions is used, the update sets the option "Global mail filter" automatically.


E-Mail: Size Limit Not Identical for Incoming and Outgoing E-Mail

If the e-mail size limit was changed for outgoing e-mail, this value was not automatically set for the fetchmail process. This has been corrected with this update.


Web Proxy: Anonymize HTTP Header and Authentication

If the web proxy option "Anonymize HTTP header" was set to "Paranoid" the web proxy authentication didn't work correctly. With this update some settings for "Anonymize HTTP header Paranoid" have been improved so the web proxy authentication is going to work.


Certificates: CSR and Certificates Signed by Official CA

Previously, the import of certificates signed by an official CA did not work, as the signature by the official CA changes the value of the subject. This issue has been corrected with this update. Certificates signed by an official CA can now be imported.


VPN: Multiple IP Addresse in PPTP connection

If a VPN (PPTP) with several IP addresses was used for a secure remote access, the routing table had been set incorrectly from the third active client connection on. A network connection was thereby not possible. With this update the allocation between devices and IP addresses is being corrected. After the third incoming client connection by PPTP the routing table is correctly allocated with the IP address the device uses. Then the destination network can be reach with the established remote access connection.


VPN: VPN Nets with NAT

VPN tunnels can connect several networks securely. If one of these networks was translated by the Firewall via SNAT or DNAT the network packets had not been routed correctly via the VPN tunnel. From this update on the correct routing rules are set if VPN is used in combination with SNAT/DNAT. The network packets are going to be routed correctly between the VPN networks.


VPN: VPN Tunnel with Dyndns-Connection stops

VPN tunnels can connect several networks securely. Under circumstances using dynamic DNS can lead to unfunctional VPN tunnels. The service for updating the DynDNS name is then crashed. This update installs a new version of ez-ipupdate resolving this issue.


Fax: Missing Sender in Notification

If a facsimile is received a notification is sent by e-mail to the receiver. In this notification the sender was given only in the e-mail text. From this update the sender's number is also displayed within the notifications subject.


Fax: Forwarding Fax to specific Mail Address

Receiving a facsimile and forwarding to a certain e-mail address, containing a hyphen resulted in not receiving faxes any more. This is repaired with this update, faxes can be receive and forwared to a certain e-mail address, even if the e-mail address contains a hyphen.


Fax: Size of Fax (TIFF) Stored to Share 0 Bytes

Fax messages stored as TIFF had a size of 0 bytes. On the Collax server itself, the fax messages were stored in the correct size. This error has been corrected with this update. Fax messages are now stored to a share in the correct size in TIFF image format.


Backup: Backup Data on Streamer after Upgrade

After the upgrade from version 4 to version 5 of the Collax server backups on tape were interrupted with following message: "Please mount volumes Tape1 or label a new one for:". The suitable tape drive could not be mounted properly into the system. This error is repaired with this update. The Tape drive is mounted correctly into the system and the associated backup job is executed completely.


Backup: Backup on USB Disks

With this update the system behavior for the backup to USB-harddisks has been improved if USB-harddisks temporarily are not connected.


Backup: Changing Password for CIFS Backup Targets

From this update the password for a CIFS backup target can be changed. The GUI blocked this process if multiple backup targets to the same CIFS-server were defined.


Backup: USB Backup Targets

If an USB device should be setup as a backup target, the warning "diskid:The object does not exist" was displayed under certain circumstances and the USB device could not be used as backup target. This error is repaired with this update, USB devices can be set up as backup targets.


Backup: Backup to SMB Share Includes IMAP Folder Admin.Virus

Previously, the backup element "Mailboxes" also contained administrative folders like Admin.Virus or Admin.Spam, which is used for storing virus-infected incoming e-mail for review by the administrator. This caused problems when the mailboxes including the Admin.Virus folder were stored as data backup to a SMB share monitored by a virus scanner. As of this update, the administrative folders are separated from the backup element "Mailboxes".


Backup: Spooling Option is not used

Since the version 5.0.20 the option Spooling activate had not been used any more. This is repaired with this software update. The option combined with tape drives it is correctly used again.


Backup: Import of Backup Catalog File

In the version 5.0.20 a new version of the data backup was installed. With that version it was not possible to import the catalogue files BackupCatalog.bsr from versions before 5.0.20. This is corrected with this update, catalogue files by all previous versions can be imported.


Add-on Software: Invalid SMTP response of Collax Virus Protection

The active monitoring tests the functionality of the email filter chain via the SMTP protocol. If the Kaspersky virus scanner is activated in the filter chain a warning is responded, because the Kaspersky email scanner replies with status code 250 even it is working correctly. The e-mail traffic and the virus scanner function perfectly. Error message: "Disabled SMTP response received from host on port 10029: 250 filters KAV4LMS"


Add-on Software: Log Rotation of Collax Virus Protection

The file scan executed by the Collax virus Protection generates log file entries for every search. The rotation of these log files had been irregular up to now. With this update this process is going to be integrated within the system-specific rotation for log files.


System Management: System Information of HP/Compaq SmartArray HDD

The system information for hard disks connected to HP/Compaq SmartArray controller in version 5.0.2 was incorrect. The message "Error, no graph specified" was displayed. This error is fixed with the version 5.0.4, the values for input/output of the hard disks are graphically indicated.


System Management: Monitoring of a URL

The active monitoring enables the check of certain URLs of other servers. If characters like = & ? are used within the URL string the monitoring service displayed an error message concerting the service description:


With this update the illegal characters will be deleted from the service description. So the service check can be executed correctly and the URL is going to be monitored.


System Management: Service Alert when monitoring Webproxy with Nagios

If the system is monitored actively and the Webproxy service is enabled "service alerts" are reported sometimes, even if the Webproxy perfectly works. With this update the suitable Nagios check is corrected.


System Management: Monthly Log File Rotation is omitted

Up to now the contents of the system log file could be kept for 1 day, 1 week or 1 month. Then the file was saved and moved. To process and search through the system log file the optin to store the file monthly is cancelled and replaced with the weekly rotation from this update on.


System Management: E-Mail Notification of Admin Login

Collax server inform the administrator about various events via e-mail. Under circumstances the notification could fail if the login on the administration gui is performed. This issue is repaired with this update.


System Management: Delegated Administrator can not manage all Forms

Administration roles are used to delegate individual rights to users who shall administer the system. Under circumstances not all forms were displayed in the GUI whithin such deligated administration. With this update the display of refered administration forms is corrected for users who are delegated for system administration.


Collax Mail Archive: Forwarding to Receiver within Subdomains

In the search form of the Collax E-Mail Archive e-mails can be forwarded to certain receivers. The declaration of the receiver's address was very restrictive up to now. Did the domain part contain more than one dot the e-mail was not forwarded. With this update this restriction is canceled. E-mails from the archive can be forwarded to any receivers.


Collax Mail Archive: Size of a DVD-5 ISO File

With the E-Mail Archive all in- and outgoing e-mails can be stored into archives. Afterwards archive volumes can be burnt on CD, DVD or Blu-Ray. The ISO file size for DVD-5 was given wrong, so these ISO files could not be burnt on 4.7 GB DVD medias. With this update ISO file size is calculated correctly for DVD-5, archiv volumes can be burnt on a 4.7 GB DVD media. Archiv volumes which ISO file size is up to now greater than 4.7 GB, can be burnt alternatively on DVD-9 or DVD-10 media.


Collax Mail Archive: E-Mail from a CD/DVD Exported from a Windows PC Is Not Loaded

Archive volumes written to ROM media can be provided for the archive search via a Windows share for the Collax e-mail archive in the network. The export of the archive from Windows systems is faulty in some cases, as the files end with a dot, which, however, is not exported by Windows. This update solves this problem, enabling the Collax e-mail archive to load incorrectly exported files, making them available for the archive search.


Collax Mail Archive: Archive Status Not Displayed

Volumes created by the e-mail archive have a certain status that can be viewed in the archive status dialog. If there were many archive volumes, the dialog could not be viewed. This update corrects the display, enabling the status of the archive volumes to be viewed.


Collax Mail Archive: Indexing of Archive Volumes

The indexing of e-mail in an archive volume is performed once a day. When a new archive volume was created between two indexing cycles, filled with incoming and outgoing e-mail in the specified size, and subsequently closed, it was previously impossible to index this archive volume. This update corrects the indexing for this case.


Collax Mail Archive: Split Backup of Archive Volumes and Archive ISOs

The e-mail archive does distinguish between the active archive volume, the inactive archive volume and the ISO files. Up to now all these data was backuped together within one backup job. Under circumstances this led to big storage requirements on the backup target. With this update the archive elements can be separated for backups. Now it is possible to backup just the active archive volume, instead of saving the complete archive inkluding all ISO files.


Collax Mail Archive: Error Messages from Index Process

For the e-mail archive the search index is updated daily. If e-mails are edited, on this occasion, the index process states that a wrong encoding or another error is given. The e-mail is still taken up into the search index. Up to now these error messages had been sent daily to the administrator. From this update on they will be written in the system log file.


Misc: Zarafa 6.30.9 and Zarafa Webaccess

With this Collax software update the new version 6.30.9 of Zarafa Groupware is available. A problem within the Zarafa Webaccess that effects all prior Zarafa versions has been fixed.


The problem prevented calendar items from being created through the standard appointment dialog.


Misc: Backup of Zarafa locks E-Mail Ttraffic

During a backup of the Zarafa database no e-mails could be processed by the Zarafa server. From this update the backup of the Zarafa database is optimised by the option --single-transaction. E-mails can be thereby processed by the Zarafa server during a backup.


Misc: Zarafa caused high System Load

Zarafa Groupware can swap e-mail attachments from the database into the file system. Up to now the calculation of the necessary size for swapping was executed by the call of the configuration form "Mail and Messaging -> Zarafa Groupware -> Configuration" as well as when doing a configuration activation. and led to a high system load. This is corrected with this update, now the calculation takes place exclusively before deleting attachements from the database.


Misc: Collax Backup of Zarafa E-Mail Attachments Includes Zarafa Bricklevel Backup Files

Stored Zarafa Groupware attachments can easily be backed up with Collax backup. When backing up attachments, individual elements from Zarafa Bricklevel Backup were also backed up, which slightly increased the hard-disk space occupied on the target system. As of this update, Zarafa attachments and Zarafa Bricklevel Backup data can be administered by means of separate backup jobs.


Misc: Dynamic DNS Does Not Work with DHCP (Cable Modem)

The objective of dynamic DNS is to address hosts with dynamic IP addresses over a fixed name. When DynDNS was selected with the connection type DHCP (cable modem), an empty configuration file was generated, and the DynDNS name of the server could not be updated. This issue has been corrected with this update.


Security: Read Access to Collax Web Access File Lists without Authentication

Previously, the system directory of the Collax Web access could be accessed without authentication in a browser. The form, CSS, and image directories of the Web access were listed, and it was possible to view the files. As of this update, the Collax Web Server denies read access to this directory.


Misc: Further Improvements

This update offers also some more improvements which are listes here:

  • 33995: Double auth at phpmyadmin
  • 34398: Brick Level Backup alerts Permission denied
  • 34847: Delete/Revoke Certs does not work correkt
  • 34870: Fetch email process does not evaluate right the fetchmailrc
  • 33744: Services are restartet without reason, update to Nagios 3.2.3

  • Hardware: Boot Setup for HP/Compaq Smart Array Controllers

    The entry in the Bootloader to boot HP/Compaq Smart Array controller devices, had been put falsely to /dev/sda in version 5.0.2. With this update to version 5.0.4 the correct device /dev/cciss/c0d0p3 is selected, if a HP/Compaq Smart Array controller is used.


    Hardware: HP/Compaq Smart Array Controllers

    The entry in the Bootloader to boot HP/Compaq Smart Array controller devices, had been put falsely to /dev/sda in version 5.0.6. With this update to version 5.0.8 the correct device /dev/cciss/c0d0p3 is selected, if a HP/Compaq Smart Array controller is used.


    Hardware: Detection of SAS Tape Drives

    The detection of SAS devices failed because of device names longer than 63 characters. This issiue is corrected within this update, such devices can be inserted into local processes like backup.