Search found 96 matches

by milauria
Thu Sep 08, 2022 3:24 am
Forum: Administrators
Topic: Why does peolple recommend dnsmasq for zimbra ?
Replies: 13
Views: 5507

Re: Why does peolple recommend dnsmasq for zimbra ?

In addition to the "split dns" and caching functionalities as mentioned above and in the zimbra wiki, dnsmasq could/should be also be configured to support "dnssec". However the package that comes with Centos7 does not have dnssec built in (and it's outdated). I read that dnsmasq...
by milauria
Wed Sep 07, 2022 7:52 am
Forum: Mobility
Topic: Z-push php8.1 problem
Replies: 9
Views: 11684

Re: Z-push php8.1 problem

If not directly related to Zimbra might be worth posting this question in the Kopano forum: https://forum.kopano.io/category/25/syn ... via-z-push
by milauria
Wed Sep 07, 2022 1:48 am
Forum: Mobility
Topic: Z-push php8.1 problem
Replies: 9
Views: 11684

Re: Z-push php8.1 problem

Sorry for the silly question: did you forced the update to php8.1 or did it come from the yum repos ?
Just asking because I am also running z-push on a Centos7 server separate from the zimbra server and regularly update with yum update but never had this issue
Thanks
by milauria
Fri Sep 02, 2022 12:40 am
Forum: Administrators
Topic: https://wiki.zimbra.com/wiki/Anti-spam updated - but only applies to ZCS 9.0?
Replies: 1
Views: 1208

Re: https://wiki.zimbra.com/wiki/Anti-spam updated - but only applies to ZCS 9.0?

This is interesting, it would be good to be tested on 8.8.15 as well.
I guess it links to the same topic that was recently blogged?
https://blog.zimbra.com/2022/08/are-you ... attention/
by milauria
Sat Aug 27, 2022 1:08 am
Forum: Administrators
Topic: Upgrade 8.8.15 and two warnings. TLS and DNSSEC
Replies: 3
Views: 5752

Re: Upgrade 8.8.15 and two warnings. TLS and DNSSEC

Hello I am trying to clear the same error I see in the daily report : warning: permit_tls_clientcerts is requested, but "smtpd_tls_ask_ccert = no" I am on Zimbra FOSS 8.8.15 P33 under Centos 7 Aug 26 14:40:57 mail postfix/smtpd[24230]: connect from unknown[95.110.216.95] Aug 26 14:40:57 ma...
by milauria
Mon Aug 15, 2022 4:28 am
Forum: Administrators
Topic: warning tls smtpd_tls_ask_ccert = no please help
Replies: 6
Views: 10753

Re: warning tls smtpd_tls_ask_ccert = no please help

Hello, just checking if there is a fix for this warning as I am experiencing the same from what i read in the daily mail report.

Appreciate any guidance you may provide where to look in the Zimbra installation

I am on Zimbra FOSS 8.8.15 Patch 32 with Centos 7
by milauria
Wed Aug 03, 2022 3:19 am
Forum: Administrators
Topic: New Zimbra Webinar Series: Email Security
Replies: 9
Views: 5606

Re: New Zimbra Webinar Series: Email Security

Hello, I missed this webinar, anywhere where I can find the material ?

for DNSSEC I tried to configure dnsmasq (I use it for split DNS) but lookups fail with unreachable hosts if enabling dnssec
for DANE I found the Zimbra wiki and seems it can be enabled with 2 configuration settings ?
thanks
by milauria
Thu Jun 09, 2022 11:07 pm
Forum: Administrators
Topic: MTA-STS email security
Replies: 11
Views: 9696

Re: MTA-STS email security

Excellent, many thanks for the full explanation and looking forward to the DANE webinar !
by milauria
Thu Jun 09, 2022 2:08 am
Forum: Administrators
Topic: MTA-STS email security
Replies: 11
Views: 9696

Re: MTA-STS email security

Hello, I made it work by having the wildcard certificate configured on both the reverse-proxy server (where the MTA_STS.txt is located) as well as on the Zimbra server. To achieve this I have created the letsencrypt wildcard certificate on the reverse proxy server using cerbot, I created the certifi...
by milauria
Mon Jun 06, 2022 3:23 am
Forum: Installation and Upgrade
Topic: Letsencrypt issue
Replies: 2
Views: 2539

Re: Letsencrypt issue

I have just installed mine following the wiki and it worked perfectly (https://wiki.zimbra.com/wiki/Installing_a_LetsEncrypt_SSL_Certificate) I just created the certificate manually using the certbot command line and followed the prompts certbot certonly --manual --preferred-chain "ISRG Root X1...